08-09-2024 01:28 AM
#sh etherchannel summary
Flags: D - down P - bundled in port-channel
I - stand-alone s - suspended
H - Hot-standby (LACP only)
R - Layer3 S - Layer2
U - in use f - failed to allocate aggregator
M - not in use, minimum links not met
u - unsuitable for bundling
w - waiting to be aggregated
d - default port
A - formed by Auto LAG
Number of channel-groups in use: 13
Number of aggregators: 13
Group Port-channel Protocol Ports
------+-------------+-----------+-----------------------------------------------
1 Po1(SU) LACP Te1/1/1(s) Te2/1/1(P)
2 Po2(SU) LACP Te1/1/2(s) Te2/1/2(P)
#sh interfaces te2/1/1 switchport
Name: Te2/1/1
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk (member of bundle Po1)
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: dot1q
Negotiation of Trunking: On
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
Administrative private-vlan host-association: none
Administrative private-vlan mapping: none
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk Native VLAN tagging: enabled
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk associations: none
Administrative private-vlan trunk mappings: none
Operational private-vlan: none
Trunking VLANs Enabled: ALL
Pruning VLANs Enabled: 2-1001
Capture Mode Disabled
Capture VLANs Allowed: ALL
Protected: false
Unknown unicast blocked: disabled
Unknown multicast blocked: disabled
Vepa Enabled: false
App Interface: false
Appliance trust: none
#sh interfaces te2/1/2 switchport
Name: Te2/1/2
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk (member of bundle Po2)
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: dot1q
Negotiation of Trunking: On
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
Administrative private-vlan host-association: none
Administrative private-vlan mapping: none
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk Native VLAN tagging: enabled
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk associations: none
Administrative private-vlan trunk mappings: none
Operational private-vlan: none
Trunking VLANs Enabled: ALL
Pruning VLANs Enabled: 2-1001
Capture Mode Disabled
Capture VLANs Allowed: ALL
Protected: false
Unknown unicast blocked: disabled
Unknown multicast blocked: disabled
Vepa Enabled: false
App Interface: false
Appliance trust: none
08-09-2024 01:32 AM
can I see the topology ?
MHM
08-09-2024 01:59 AM
Simple HA of Two firewalls uplink is connected to this switches uplinks
1.Firewall x1 is connected to Te1/1/1
x2 is connected to Te2/1/1
2.Firewall x1 is connected to Te 1/1/2
x2 is connected to Te2/1/2
08-09-2024 02:06 AM
in SW
show lacp neighbor <<- check the neighbor is same in both port member of PO's
show lacp counter <<- check the "S" interface send/receive lacp
MHM
08-09-2024 02:15 AM
#sh lacp neighbor
Flags: S - Device is requesting Slow LACPDUs
F - Device is requesting Fast LACPDUs
A - Device is in Active mode P - Device is in Passive mode
Channel group 1 neighbors
LACP port Admin Oper Port Port
Port Flags Priority Dev ID Age key Key Number State
Te1/1/1 SA 255 ac71.2e06.f052 19s 0x0 0x21 0x1 0x5
Te2/1/1 SA 255 ac71.2e07.2f1a 1s 0x0 0x21 0x1 0x3D
Channel group 2 neighbors
LACP port Admin Oper Port Port
Port Flags Priority Dev ID Age key Key Number State
Te1/1/2 SA 255 ac71.2e07.2f1a 17s 0x0 0x21 0x2 0x5
Te2/1/2 SA 255 ac71.2e06.f052 10s 0x0 0x21 0x2 0x3D
#sh lacp counter
LACPDUs Marker Marker Response LACPDUs
Port Sent Recv Sent Recv Sent Recv Pkts Err
--------------------------------------------------------------------------
Channel group: 1
Te1/1/1 142 164 0 0 0 0 0
Te2/1/1 90214 83448 0 0 0 0 0
LACPDUs Marker Marker Response LACPDUs
Port Sent Recv Sent Recv Sent Recv Pkts Err
--------------------------------------------------------------------------
Channel group: 2
Te1/1/2 144 129 0 0 0 0 0
Te2/1/2 90236 83451 0 0 0 0 0
LACPDUs Marker Marker Response LACPDUs
08-09-2024 02:19 AM
Friend
it issue of cable you misconnect cable
see in each PO the Dev ID is different
so only check if cable of one FW connect to correct port of PO in SW
MHM
08-09-2024 04:15 AM
the all network went down.
08-09-2024 04:37 AM - edited 08-09-2024 04:43 AM
Channel group 1 neighbors <<- ONE PO have two different Neighbor that wrong
LACP port Admin Oper Port Port
Port Flags Priority Dev ID Age key Key Number State
Te1/1/1 SA 255 ac71.2e06.f052 19s 0x0 0x21 0x1 0x5
Te2/1/1 SA 255 ac71.2e07.2f1a 1s 0x0 0x21 0x1 0x3D
the SW have two PO, PO and PO
the FW HA config one port channel POx
so am I correct ?
more reference
MHM
08-09-2024 04:44 AM
note above for only HA active/standby not active/active FW
MHM
08-16-2024 03:53 PM
any update
MHM
08-20-2024 11:48 PM
no still im facing the same issue
issue was not resolved
08-20-2024 11:52 PM
did you check link ?
the two link from one FW must use one PO in SW
you mix the link and SW see two different neighbor in one PO
MHM
08-20-2024 11:54 PM
yes i did
now this is the status
SW#sh etherchannel summary
Flags: D - down P - bundled in port-channel
I - stand-alone s - suspended
H - Hot-standby (LACP only)
R - Layer3 S - Layer2
U - in use f - failed to allocate aggregator
M - not in use, minimum links not met
u - unsuitable for bundling
w - waiting to be aggregated
d - default port
A - formed by Auto LAG
Number of channel-groups in use: 13
Number of aggregators: 13
Group Port-channel Protocol Ports
------+-------------+-----------+-----------------------------------------------
1 Po1(SU) LACP Te1/1/1(P) Te1/1/2(s)
2 Po2(SU) LACP Te2/1/1(P) Te2/1/2(s)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide