10-20-2020 10:02 PM
Hi,
We have the following setup:
MPLS switch--Cisco FTD--Switch
Cisco FTD is configured in high availability mode. The primary FTD is connected to the primary MPLS switch and the standby FTD to the standby MPLS switch. Recently, the ftd failover happened and the standby ftd became active, however the MPLS switch did not failover as the link connecting the switch to the ftd was still up. Is there anyway to make the link down when the ftd is in standby mode?
10-20-2020 10:42 PM
10-21-2020 12:26 AM
we do see that kind of environment, some places they want to extend Layer 2 using the different path in the network layer2 switch
to meet the best do you have an alternative layer 2 paths for that? if not you need to use some kind of tracking, but Layer2 will be always up once side, others go down also. this is a bit tricky, as suggested you can use EEM script to keep monitor each side and shutdown or failover.
but it will have a small interruption of traffic.
10-22-2020 11:51 PM
Thanks All,
can you please share a sample EEM script that i can use?
Thanks,
10-21-2020 01:25 AM
Hi,
I would suggest to use the switch in stack for MPLS and in LAN side you can use both the switches connected via Trunk.
In this condition if case active firewall failover also you do not need to do switch side failover.
IN HA at a time only one firewall will be processing traffic and other will be in standby mode hence even it secondary firewall port is up also it does not create any issue.
Regards,
AKK
10-23-2020 01:25 AM
I don't think using EEM would be recommended tbh, I think best practice would be as already mentioned to connect MPLS and FTD devices to the same switch or switch stack. That way, when failover happens, the traffic will still flowing out of the active MPLS, regardless which one is going to be.
Or maybe if you are pointing to a floating IP address for MPLS routes with HSRP or VRRP, you can ask your ISP to condition HSRP or VRRP to failover the MPLS circuit if they can't reach a specific IP behind your primary FTD.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide