cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
688
Views
0
Helpful
3
Replies

Port channel at firewall

Rizwan
Level 1
Level 1

Hi, 

I have two ASA firewalls working on fail over, a vPC is configured between firewalls and two nexus switches. 

vPC is up and port channel is configured. Now I made a virtual interface on firewall as inside interface and assign a vlan id 15 same as 

configured at nexus as shown below but I am unable to ping vlan IP at nexus switch. Please suggest

 

interface GigabitEthernet0/3.15
 vlan 15
 nameif inside
 security-level 100
 ip address 10.23.15.10 255.255.255.0 standby 10.23.15.11 

3 Replies 3

James Leinweber
Level 4
Level 4

Could we see the output of "show port-channel detail"

-- Jim Leinweber, WI state Lab of Hygiene

Rizwan
Level 1
Level 1

sh port-channel detail 
                Channel-group listing: 
                -----------------------

Group: 2
----------
Span-cluster port-channel: No
Ports: 2   Maxports = 16
Port-channels: 1 Max Port-channels = 48
Protocol: LACP/ active
Minimum Links: 1
Maximum Bundle: 8
Load balance: src-dst-ip
                Ports in the group:
                -------------------
Port: Gi0/1
------------
Port state    = bndl
Channel group =    2        Mode = LACP/ active
Port-channel  = Po2 

Flags:  S - Device is sending Slow LACPDUs   F - Device is sending fast LACPDUs.
        A - Device is in active mode.        P - Device is in passive mode.

Local information: 
                             LACP port     Admin     Oper    Port        Port
Port      Flags   State      Priority      Key       Key     Number      State
-----------------------------------------------------------------------------
Gi0/1     SA      bndl       32768         0x2       0x2     0x2         0x3d  

Partner's information:
          Partner Partner    LACP Partner  Partner   Partner  Partner     Partner
Port      Flags   State      Port Priority Admin Key Oper Key Port Number Port State
-----------------------------------------------------------------------------------
Gi0/1     SA      bndl       32768         0x0       0x8066   0x4401      0x3d  

I have multiple vlans at my core switch how I will configure inside interface of firewall to make all vlans reachable to the firewall?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card