3 interfaces in port channel for inter fwsm HA

Unanswered Question
Mar 20th, 2008
User Badges:

all sample config ive seen for FWSM interswitch failover config shows using 3 interfaces in port channel mode...


any reason why this is usually 3?


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
tstanik Wed, 03/26/2008 - 12:25
User Badges:
  • Bronze, 100 points or more
cfajardo1_2 Wed, 03/26/2008 - 23:06
User Badges:

FROM THE LINK YOUVE GIVEN, THEY ARE ALSO SHOWING 3 INTERFACES. SEE BELOW WHICH I JUST CUT AND PASTE FROM ONE OFTHE LINK YOUVE GIVEN



interface range gigabitethernet 2/1-3

channel-group 2 mode on

switchport trunk encapsulation dot1q

no shutdown


Jon Marshall Thu, 03/27/2008 - 00:49
User Badges:
  • Super Blue, 32500 points or more
  • Hall of Fame,

    Founding Member

  • Cisco Designated VIP,

    2017 LAN, WAN

Hi


When you deploy inter-chassis FWSM's trunks between the 6500 switches are used for 2 things


1) Failover, to send the state table, keepalives etc. There is no reason why this has to be a separate trunk dedicated to the FWSM although Cisco say if you run it across a L2 trunk that is also used for other traffic QOS should enabled and the failover packets marked with IP Prec 5.


It really depends on how busy the trunk link is with other traffic. If you decide to create a separate trunk for this then you can use whatever number of ports (up to 8) that you want. 2 would give you redundancy and enough bandwidth, provided they were Gbps ports, for the stateful traffic.


2) The actual data traffic between the FWSM. Bear in mind that the L2 trunk between the 6500 chassis may well be needed for FWSM user traffic because the active gateway on the FWSM may be across the trunk link from the sender.


Again it depends on what else the L2 trunk is used for, how busy it is and how much firewall traffic there will be but there is a strong case to create a dedicated trunk for the FWSM user traffic. I would say at a minimum 3 ports at each end but it really does depend on traffic requirements.


Don't get hung up on the number of ports used in the configuration examples as they are generic examples and may not suit your traffic profile.


HTH


Jon

Actions

This Discussion