06-14-2011 07:53 AM - edited 03-10-2019 05:22 AM
Hi everyone ...
I have two 6509 configured with VSS, in each 6509 we have one FWSM and IDSM2.
We have configured the FWSM with contexts and we have Failover working fine.
Now we want to configure IDMS as IPS inline but we want to use both IDSM in load balance for improve the performance and get high availability with security.
Is this possible ?
I know we can get load balance with IPS appliances using etherchannel in switching (ECLB) but I don't know if we can do this with the IDSM modules in catalyst 6509 considering VSS.
Any suggestions ?
06-16-2011 09:57 AM
Hello
Why don't you make some context active on one FWSM and some on the other? This will not 'load-balance' the traffic, but it will at least load-share the traffic between the two IDSM-2 modules.
Regards
Farrukh
10-12-2011 11:49 AM
The VSS is a special configuration.
You can configure the FWSM modules to be Failover partners but in IDSM modules you need to configure the same input/output VLANs to get the Failover or balance behaviour. The Cisco IPS architecture has not Failover configuration. you can find some examples with Etherchannels or Port-Channels configuration shared with some IPS units to balance the bandwith. That's the case in VSS solucion, both chasis shared the VLANs and it's necesary to configure the input/output VLANs pairs shared between the modules to balance the bandwith.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide