cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
542
Views
0
Helpful
3
Replies

etherchannel support between Active-passive FTD-VSS switch

yong khang NG
Level 5
Level 5

Hi All

Would like to check out is it feasible to do both end back-to-back etherchannel between these device

a pair of cisco FTD in active-passive HA setup connecting catalyst switch doing VSS.No cross connection, mean

FW01 g0/1- SW01 g0/1,

FW02 g0/1- SW02 g0/1.

 

Question: Can i do L2 etherchannel on this case, the challenge i se reside at the FTD side.

If not support, mean the loop prevention still stick back to STP, am i correct? 

 

Any comment welcome, thanks

Noel

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame
FW01 g0/1- SW01 g0/1,

FW02 g0/1- SW02 g0/1.

this is not best approach here, with the single Link to parent switch, Suggest model always have dual link to both the switches in VSS / vPC deployment

 

image.png

 

you can find deployment models as below :

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/clustering/ftd-cluster-solution.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi Sir,

 

Thanks for the comment.

 

But due to single connection from each device this constraint, can i say the link between sw02 - passive ftd unit will have STP block mode, to prevent loop?

 

Noel

 

 

 

if that is contrain of the deployment, and we need to consider as Risk and deploy.

 

where is the STP coming in to picture here ?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking products for a $25 gift card