cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
714
Views
5
Helpful
1
Replies

FWSM failover configuration

bapatsubodh
Level 1
Level 1

Hi,

We are in process of configuring FWSM failover. On cisco's website example is given with all the necessary commands.

I still have one doubt :(

Following is the configuration:

on FWSM

nameif 4000 failover 50

ip add failover 10.40.40.1 / 24

fail ip address failover 10.40.40.2 /24

fail lan int failover ( makes "failover" interface as failover interface and corresponding VLAN-in this case 4000 )

Now my doubt is if this VLAN 4000 is a failover interface over which all the connection tables and other signalling will be flowing for autofailover.

We will create VLAN 4000 and add it to this modeule vlan-group, by firewall vlan-group command. Do we need to add some ports to this vlan ( that is VLAN 4000) on both the switches and connect a cables between the corresponding ports.

For example : port gig2/5 will be made member of VLAN 4000 on both switches and connect a cable between these tow ports.

Or existing trunk which by default carries traffic for all VLAN's is sufficient.

Please share the experience.

Thanks in advance.

subodh

1 Reply 1

Jon Marshall
Hall of Fame
Hall of Fame

Subodh

"We will create VLAN 4000 and add it to this modeule vlan-group, by firewall vlan-group command. Do we need to add some ports to this vlan ( that is VLAN 4000) on both the switches and connect a cables between the corresponding ports.

For example : port gig2/5 will be made member of VLAN 4000 on both switches and connect a cable between these tow ports.

Or existing trunk which by default carries traffic for all VLAN's is sufficient."

It's really up to you. You can do it either way. What is important is if you use the existing trunk link that link must be reliable and not be overutilised as you do not want state information to be dropped.

The alternative as you say is to use another physical connection as a separate trunk and you can then use this trunk link to carry traffic for the stateful vlan and also all the other vlans for the FWSM.

Jon

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card