cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1091
Views
0
Helpful
6
Replies

Nexus 5500 Port-channels down on ASA 5500 interfaces

Rodrigo Belo
Level 1
Level 1

Hi all,

After upgrading NEXUS 5548 switches from version 6.0(2)N2(4)  to version 7.0(5)N1(1) a few port-channels did not come up (diagram attached).

 

Funny enough, those port-channels that stayed down are all connecting Cisco ASA 5525 Firewalls. I have another firewall connected to those switches (Cisco ASA 5515) and had no issue with that one.

The NEXUS are on a vPC domain and every port-channel is vPC with LACP.

All Port-channels are configured the same way, on the NEXUS side and on the Firewalls side.

6 Replies 6

Dear Rodrigo,

Could you please share the below output from bothe the nexus switches. Also please share the relevant logs if you have any.

 

sh int po<>

sh int <member ports>

sh run int po <>

Thanks,

M

 

Hi Madhukrishnan,

unfortunately I had to roll back because this is a Data Centre production infrastructure.

Attached is the output you requested but beare in mind that it`s from version 6.0(2)N2(4) where everything has always worked fine.

 

Thanks

Did you happen to collect the logs at the time. If so we could take a look at to see what was going on.

 

Also one thing you could have checked was whether the interface staying up individually  or not out of PO.

 

Thanks,

M

 

 

Hi Madhukrishnan,

Troubleshooting revealed that there was an issue with LACP negotiation, which I'm not quite sure what it is.

If we configure the port-channels to mode "on" everything works well...which is something I really don't want to do.

Never got to fix it but I will soon upgrade the ASAs and NEXUS and let you know how it goes.

 

cheers

Thanks for updating Rodrigo

Rodrigo Belo
Level 1
Level 1

Finally found the issue...counterfeit SFPs!!

The fact that the only interfaces failing were the ones connecting the ASA 5500 was just a coincidence.

Review Cisco Networking for a $25 gift card