04-07-2022 10:14 AM
Hi Guys,
I have a firepower cluster, 2 on DC and 2 on DR connected through a nexus switch ( dark fiber) , i am getting mac flapping on the nexus , the Site ID on the chassis is both different.
Can anyone advise please
Solved! Go to Solution.
04-18-2022 05:31 AM
That's odd. I'd suggest opening a TAC case so that the engineer can work with you in real time to trace the root cause.
04-07-2022 10:58 AM
Can you share a diagram of your setup?
Are the Nexus' in a VPC configuration?
04-07-2022 10:35 PM
04-13-2022 04:10 AM
04-13-2022 10:36 AM
Are all four firewalls in a single cluster?
Are there vPCs between the Nexus switches?
04-13-2022 11:49 PM
Hi @Marvin Rhoads ,
Yes, all the firewall are in the same cluster, and yes there's vPV between the Nexus.
04-17-2022 05:02 AM
If I understand it correctly you are using what Cisco calls "Split Spanned Etherchannel Cluster". They mention in Cisco Live presentation BRKSEC-3032 that filtering is required is such a use case to avoid MAC/IP conflicts.
04-18-2022 05:18 AM
I have applied mac acl on the HO nexus , but still same issue , there's a port-channel/vPC between the HO and DR Nexus, when one link is up it works fine, however when both links are up, we get the mac flap issues.
04-18-2022 05:31 AM
That's odd. I'd suggest opening a TAC case so that the engineer can work with you in real time to trace the root cause.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide