cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1506
Views
1
Helpful
22
Replies

Firewall unable to learn mac address of vip of Cisco Nexus 7706

DJay11
Level 1
Level 1

Seek help on why the Firewall (Checkpoint) is unable to learn the vip interface of our Cisco Nexus 7706 vip. Both are connected under the same vlan. We have no problem with the physical interface of the Cisco Switch. As a work around, FW team configured the switch vip mac address statically. Is this a switch of Firewall issue? Another brand of FW in our organization encountered the same issue. 

 

DJay11_0-1706772926107.png

 

22 Replies 22

DJay11_0-1706772926107.png

this must config between FW and two NSK
MHM

I return to home and make topolgy with point 
can you confirm each config 
Screenshot (686).png

Yes. Config is correct. 

show port-channel summary <<- share this from both Nexus 
MHM

DJay11_0-1706840385513.png

 

as per the diagram you have 1 connection to each Switch, but the output shows both connected switch 2 (VDC2) only ?

Can you post the same output other vPC switch ?

Do you have 4 links connected  (example 2-Switch1 and 2- switch 2 ?)

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

for what I see all config is correct and both Port members is "P"
so it seem that the FW learn the MAC from first packet receive not from GARP. 
the solution I think here is use 
peer gateway under the vPC domain in both NSK 
MHM

I see. I'll explore on this. Thanks for the help. 

Review Cisco Networking for a $25 gift card