cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
851
Views
3
Helpful
2
Replies

IDSM-2 - VSS Load Balance

guigonza
Level 1
Level 1

Hi everyone ...

I have two 6509 configured with VSS, in each 6509 we have one FWSM and IDSM2.

We have configured the FWSM with contexts and we have Failover working fine.

Now we want to configure IDMS as IPS inline but we want to use both IDSM in load balance for improve the performance and get high availability with security.

Is this possible ?

I know we can get load balance with IPS appliances using etherchannel in switching (ECLB) but I don't know if we can do this with the IDSM modules in catalyst 6509 considering VSS.  

Any suggestions ?

2 Replies 2

Farrukh Haroon
VIP Alumni
VIP Alumni

Hello

Why don't you make some context active on one FWSM and some on the other? This will not 'load-balance' the traffic, but it will at least load-share the traffic between the two IDSM-2 modules.

Regards


Farrukh

The VSS is a special configuration. 

You can configure the FWSM modules to be Failover partners but in IDSM modules you need to configure the same input/output VLANs to get the Failover or balance behaviour.  The Cisco IPS architecture has not Failover configuration.  you can find some examples with Etherchannels or Port-Channels configuration shared with some IPS units to balance the bandwith.   That's the case in VSS solucion, both chasis shared the VLANs and it's necesary to configure the input/output VLANs pairs shared between the modules to balance the bandwith.

Review Cisco Networking for a $25 gift card