01-31-2024 11:37 PM
Seek help on why the Firewall (Checkpoint) is unable to learn the vip interface of our Cisco Nexus 7706 vip. Both are connected under the same vlan. We have no problem with the physical interface of the Cisco Switch. As a work around, FW team configured the switch vip mac address statically. Is this a switch of Firewall issue? Another brand of FW in our organization encountered the same issue.
02-01-2024 02:23 AM
this must config between FW and two NSK
MHM
02-01-2024 08:05 AM
I return to home and make topolgy with point
can you confirm each config
02-01-2024 03:49 PM
Yes. Config is correct.
02-01-2024 04:02 PM
show port-channel summary <<- share this from both Nexus
MHM
02-01-2024 06:19 PM
02-02-2024 01:40 AM
as per the diagram you have 1 connection to each Switch, but the output shows both connected switch 2 (VDC2) only ?
Can you post the same output other vPC switch ?
Do you have 4 links connected (example 2-Switch1 and 2- switch 2 ?)
02-02-2024 04:14 AM
for what I see all config is correct and both Port members is "P"
so it seem that the FW learn the MAC from first packet receive not from GARP.
the solution I think here is use
peer gateway under the vPC domain in both NSK
MHM
02-04-2024 10:57 PM
I see. I'll explore on this. Thanks for the help.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide