cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
887
Views
0
Helpful
3
Replies

Port channel at firewall

Rizwan
Level 1
Level 1

Hi, 

I have two ASA firewalls working on fail over, a vPC is configured between firewalls and two nexus switches. 

vPC is up and port channel is configured. Now I made a virtual interface on firewall as inside interface and assign a vlan id 15 same as 

configured at nexus as shown below but I am unable to ping vlan IP at nexus switch. Please suggest

 

interface GigabitEthernet0/3.15
 vlan 15
 nameif inside
 security-level 100
 ip address 10.23.15.10 255.255.255.0 standby 10.23.15.11 

3 Replies 3

James Leinweber
Level 4
Level 4

Could we see the output of "show port-channel detail"

-- Jim Leinweber, WI state Lab of Hygiene

Rizwan
Level 1
Level 1

sh port-channel detail 
                Channel-group listing: 
                -----------------------

Group: 2
----------
Span-cluster port-channel: No
Ports: 2   Maxports = 16
Port-channels: 1 Max Port-channels = 48
Protocol: LACP/ active
Minimum Links: 1
Maximum Bundle: 8
Load balance: src-dst-ip
                Ports in the group:
                -------------------
Port: Gi0/1
------------
Port state    = bndl
Channel group =    2        Mode = LACP/ active
Port-channel  = Po2 

Flags:  S - Device is sending Slow LACPDUs   F - Device is sending fast LACPDUs.
        A - Device is in active mode.        P - Device is in passive mode.

Local information: 
                             LACP port     Admin     Oper    Port        Port
Port      Flags   State      Priority      Key       Key     Number      State
-----------------------------------------------------------------------------
Gi0/1     SA      bndl       32768         0x2       0x2     0x2         0x3d  

Partner's information:
          Partner Partner    LACP Partner  Partner   Partner  Partner     Partner
Port      Flags   State      Port Priority Admin Key Oper Key Port Number Port State
-----------------------------------------------------------------------------------
Gi0/1     SA      bndl       32768         0x0       0x8066   0x4401      0x3d  

I have multiple vlans at my core switch how I will configure inside interface of firewall to make all vlans reachable to the firewall?

Review Cisco Networking for a $25 gift card