06-16-2023 08:09 AM
Hello,
I have a cluster of two firepower 3120 in high availability (active/stanby).
It's managed by FMC.
Everything is running in version 7.3.0.
For now, an ECMP zone is configured and load balance the trafic between my two ISP, which both have a bandwidht of 1Gbps.
We will upgrade one of this link to 2Gbps.
Does the ECMP will work?
I have done that before on Palo Alto with weighted round-robin algorithm but on FMC, it seems that i can't choose the repartition's algorithm.
Have you any advice about this configuration?
Thank you.
Regards
Solved! Go to Solution.
06-16-2023 11:52 AM
as I mention before the static route to care about the BW of link, not like OSPF/EIGRP
here you config two default route with same metric which make firepower add two path as equal cost.
I check the firepower guide, the firepower for equal cost multi path use hash it not use weight as Palo.
06-16-2023 08:27 AM
The bandwidth mismatch not effect ecmp if you use default route for both path.
defualt route dont care about bw of link
06-16-2023 08:37 AM
Hello @MHM Cisco World ,
Thanks for your reply.
I have defaut route for both path with the same metric.
How the difference of bandwidth will be handled?
If i understand it good, the traffic is balanced equally between the links.
So in my case 50%/50% between the two 1Gbs links.
But with my new link, i would probably prefer a repartition of 66%/33%.
Am i wrong?
On my ex Palo Alto firewall, i can achieve this using a weight on the interfaces but it seems not possible with FTD.
Regards
06-16-2023 08:41 AM
This firepower 1k or 2k?
06-16-2023 08:43 AM
It's a cluster of two FPR 2130.
Managed by FMC and using FTD v7.3.0
06-16-2023 08:46 AM
It spanned link' etherchannel what uou use for cluster ?
06-16-2023 09:21 AM
Sorry, i'm not sure i understand your question.
The cluster is active/standby, so only one device is passing the trafic.
The topology is as follow:
The FRP are connected to my core switch (Catalyst 9500 in stackwise virtual) using :
- 1 Port channel (2x10G) for inside (LAN).
- 1 Port channel (2x10G) for outside (WAN)
This Port-channel is cut in sub-interfaces which each connected to a different ISP in diffèrent VLANs.
ISP routers are connected to my core switch with 10Gbps optical fiber module.
06-16-2023 11:52 AM
as I mention before the static route to care about the BW of link, not like OSPF/EIGRP
here you config two default route with same metric which make firepower add two path as equal cost.
I check the firepower guide, the firepower for equal cost multi path use hash it not use weight as Palo.
06-18-2023 03:00 PM
Helllo @MHM Cisco World ,
Thank you.
You confirm what i was thinking.
I can't have the load balanced correspondingly to the link capacity.
Regards
02-28-2024 01:27 PM
Hi all, does FPR 1000 support ECMP? I´m considering connect it to two ISP with ECMP. Thanks in advance.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide