12-27-2010 10:37 PM - edited 03-11-2019 12:28 PM
Hi All,
Please help me to configure FWSM in my VSS environment. I have two 6509s in my network, VSS is running in between. Each switch contains an FWSM module. I want to configure these modules with failover. What all things i need to consider before configuring these moduels? In which mode i can configure these modules, routed or transperent ? Can i configure active-active failover in these modules ?? Please help.
Thanks in advance.
Rgds,
Shijo.
12-28-2010 01:47 AM
Hello Shijo,
You can view the link below to configure failover on the two FWSM's. The configuration on the FWSM is independent of whether the switches are configured to operate in VSS mode or not.
http://www.cisco.com/en/US/docs/security/fwsm/fwsm40/configuration/guide/fail_f.html
Both inter and intrachassis models of FWSM failover are supported in VSS mode. The user has to make sure that all VLANs (including failover/state VLANs) are pushed on both failover units (regardless of which physical chassis they reside in). For example, VLAN group N needs to be pushed on switch 1 as well as switch 2 if VLAN group N contains the necessary VLANs (including failover and state).
01-20-2011 09:58 PM
Hello
You mentioned you don't use "autostate + interface monitoring" in FWSM within VSS. But in this link http://www.cisco.com/en/US/docs/solutions/Enterprise/Data_Center/vssdc_integrate.html it says :
"The services chassis uplink MEC provides a medium for fate sharing as the state of the integrated services modules depends on the state of the channel through autostate. Network administrators should rely on autostate for service availability and consider removing other forms of service tracking such as heartbeats or query interfaces"
Could you please clarify about using "autostate" or not ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide