cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
733
Views
0
Helpful
5
Replies

CISCO fail to LACP

azzamrifki
Level 1
Level 1

I have problem like this

Two cisco catalyst 2960-x 24 L is stacked, port gi1/0/23,gi1/0/24,gi2/0/23, and gi2/0/24 is bundle together in Port-channel 5 and using LACP mode active. Those 4 port is connected to two juniper firewall with configuration like in the picture on file Capture.PNG,

note: the picture i use bellow is only to describe the topology ,the real firewall is juniper

the problem is everytime i disconnect one of the 4 LACP port the connection is fails i cannot ping my detination address,

i check my CISCO ios and it is already the latest one so right now im kinda stuck

5 Replies 5

Francesco Molino
VIP Alumni
VIP Alumni
Hi

4 ports bundled into 1 PO are physically connected to 2 different devices. I'm not very familiar with Juniper but I believe you should have a PO of 2 ports going to 1 firewall and another PO if 2 ports going to the other firewall.

When all ports are connected, what do you see on the output show etherchannel?
Can you run a quick lacp debug, disconnect 1 cable and share the output of this debug?

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

When all ports are connected, what do you see on the output show etherchannel?

 

Switch#show etherchannel
Channel-group listing:
----------------------

Group: 5
----------
Group state = L2
Ports: 4 Maxports = 16
Port-channels: 1 Max Port-channels = 16
Protocol: LACP
Minimum Links: 0

 

Can you do a sh etherch summ? and what is the mac address you're learning on all links?
did you do a debug while disconnecting a port from the PO?

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

4 ports bundled into 1 PO are physically connected to 2 different devices. I'm not very familiar with Juniper but I believe you should have a PO of 2 ports going to 1 firewall and another PO if 2 ports going to the other firewall.

 

i'm sorry but the juniper firewall is also stack, is it still consider as two different devices?????

julian.bendix
Level 3
Level 3

Hi!
You will most likely need to configure two different port-channels on the Cisco Switch.
One with two physical ports going to Firewall 1,

and one with the other two physical ports going to Firewall 2.

To confirm, can you please post the output of the following commands:
#show etherchannel 5 summary
#show etherchannel 5 detail

 

Best regards!

Review Cisco Networking products for a $25 gift card