cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1945
Views
0
Helpful
8
Replies

Firepower cluster dc-dr

ashleybabajee
Level 1
Level 1

Hi Guys,

 

I have a firepower cluster, 2 on DC and 2 on DR connected through a nexus switch  ( dark fiber) , i am getting mac flapping on the nexus , the Site ID on the chassis is both different.

 

Can anyone advise please

1 Accepted Solution

Accepted Solutions

That's odd. I'd suggest opening a TAC case so that the engineer can work with you in real time to trace the root cause.

View solution in original post

8 Replies 8

Marvin Rhoads
Hall of Fame
Hall of Fame

Can you share a diagram of your setup?

Are the Nexus' in a VPC configuration?

Hi @Marvin Rhoads 

 

Yes they are in a vpc configuration

Hi @Marvin Rhoads , any idea ?, i have already uploaded the diagram, grateful to advise.

 

 

Are all four firewalls in a single cluster?

Are there vPCs between the Nexus switches?

Hi @Marvin Rhoads ,

 

Yes, all the firewall are in the same cluster, and yes there's vPV between the Nexus.

 

 

If I understand it correctly you are using what Cisco calls "Split Spanned Etherchannel Cluster". They mention in Cisco Live presentation BRKSEC-3032 that filtering is required is such a use case to avoid MAC/IP conflicts.

FTD Cluster with Split Spanned Etherchannel.PNG

I have applied mac acl on the HO nexus , but still same issue , there's a port-channel/vPC between the HO and DR Nexus, when one link is up it works fine, however when both links are up, we get the mac flap issues.

That's odd. I'd suggest opening a TAC case so that the engineer can work with you in real time to trace the root cause.

Review Cisco Networking products for a $25 gift card