<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LACP Nego-fail issue between firewall and CPE router - Expected Behaviour? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-nego-fail-issue-between-firewall-and-cpe-router-expected/m-p/359615#M87999</link>
    <description>&lt;P&gt;Hi Live,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm experiencing an issue with a setup of aggregated ethernet interfaces configured with LACP simply for redundancy connections between our HA Active/Passive firewalls and Cisco ISR 4451 routers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm wondering what steps to take as regards packet captures on firewall interfaces to figure out why negotiation will fail.&lt;/P&gt;&lt;P&gt;Or is this expected behaviour?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ethernet1/1 and ethernet1/2 = AE1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Virtual IP (public/ default gateway) presented to firewalls from CPE Cisco routers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SirchRettop_1-1603974307593.png" style="width: 527px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28414i71C1AEB617B23FAA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SirchRettop_1-1603974307593.png" alt="SirchRettop_1-1603974307593.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SirchRettop_0-1603973539042.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28413i75F81EA65920E058/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SirchRettop_0-1603973539042.png" alt="SirchRettop_0-1603973539042.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So far we have tried all modes of LACP and transmission rates w/ active, passive, fast, slow but there has been still no change as regards ethernet1/2 and lacp negotiation failure with the router interface of GE0/0/2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have reviewed &amp;gt;less mp-log l2ctrld.log but no indicators there either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SirchRettop_2-1603974600046.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28415iC58F47D550E03DC0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SirchRettop_2-1603974600046.png" alt="SirchRettop_2-1603974600046.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I'm aware, physical layer 1 hasn't been checked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface and AE/LACP settings&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SirchRettop_4-1603975405930.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28417i26966432EC97B852/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SirchRettop_4-1603975405930.png" alt="SirchRettop_4-1603975405930.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SirchRettop_5-1603975432038.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28418iE67DE6BB65E8E0E3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SirchRettop_5-1603975432038.png" alt="SirchRettop_5-1603975432038.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SirchRettop_3-1603975359628.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28416i0ECAF6CD68FEB47B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SirchRettop_3-1603975359628.png" alt="SirchRettop_3-1603975359628.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;show lacp aggregate-ethernet ae1&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SirchRettop_6-1603975735329.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28420i4E86B1B18358E25B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SirchRettop_6-1603975735329.png" alt="SirchRettop_6-1603975735329.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Oct 2020 12:52:36 GMT</pubDate>
    <dc:creator>SirchRettop</dc:creator>
    <dc:date>2020-10-29T12:52:36Z</dc:date>
    <item>
      <title>LACP Nego-fail issue between firewall and CPE router - Expected Behaviour?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-nego-fail-issue-between-firewall-and-cpe-router-expected/m-p/359615#M87999</link>
      <description>&lt;P&gt;Hi Live,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm experiencing an issue with a setup of aggregated ethernet interfaces configured with LACP simply for redundancy connections between our HA Active/Passive firewalls and Cisco ISR 4451 routers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm wondering what steps to take as regards packet captures on firewall interfaces to figure out why negotiation will fail.&lt;/P&gt;&lt;P&gt;Or is this expected behaviour?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ethernet1/1 and ethernet1/2 = AE1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Virtual IP (public/ default gateway) presented to firewalls from CPE Cisco routers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SirchRettop_1-1603974307593.png" style="width: 527px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28414i71C1AEB617B23FAA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SirchRettop_1-1603974307593.png" alt="SirchRettop_1-1603974307593.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SirchRettop_0-1603973539042.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28413i75F81EA65920E058/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SirchRettop_0-1603973539042.png" alt="SirchRettop_0-1603973539042.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So far we have tried all modes of LACP and transmission rates w/ active, passive, fast, slow but there has been still no change as regards ethernet1/2 and lacp negotiation failure with the router interface of GE0/0/2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have reviewed &amp;gt;less mp-log l2ctrld.log but no indicators there either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SirchRettop_2-1603974600046.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28415iC58F47D550E03DC0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SirchRettop_2-1603974600046.png" alt="SirchRettop_2-1603974600046.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I'm aware, physical layer 1 hasn't been checked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface and AE/LACP settings&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SirchRettop_4-1603975405930.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28417i26966432EC97B852/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SirchRettop_4-1603975405930.png" alt="SirchRettop_4-1603975405930.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SirchRettop_5-1603975432038.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28418iE67DE6BB65E8E0E3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SirchRettop_5-1603975432038.png" alt="SirchRettop_5-1603975432038.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SirchRettop_3-1603975359628.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28416i0ECAF6CD68FEB47B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SirchRettop_3-1603975359628.png" alt="SirchRettop_3-1603975359628.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;show lacp aggregate-ethernet ae1&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SirchRettop_6-1603975735329.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28420i4E86B1B18358E25B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SirchRettop_6-1603975735329.png" alt="SirchRettop_6-1603975735329.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 12:52:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lacp-nego-fail-issue-between-firewall-and-cpe-router-expected/m-p/359615#M87999</guid>
      <dc:creator>SirchRettop</dc:creator>
      <dc:date>2020-10-29T12:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: LACP Nego-fail issue between firewall and CPE router - Expected Behaviour?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-nego-fail-issue-between-firewall-and-cpe-router-expected/m-p/359668#M88000</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110661"&gt;@SirchRettop&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How your routers are configured? Make sure both these routers are virtually into one cluster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mayur Sutare&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 14:12:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lacp-nego-fail-issue-between-firewall-and-cpe-router-expected/m-p/359668#M88000</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-10-29T14:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: LACP Nego-fail issue between firewall and CPE router - Expected Behaviour?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-nego-fail-issue-between-firewall-and-cpe-router-expected/m-p/359670#M88001</link>
      <description>&lt;P&gt;Thanks Mayur,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes the Cisco routers are configured virtually into one cluster where we use the virtual ip as the default gateway&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 14:25:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lacp-nego-fail-issue-between-firewall-and-cpe-router-expected/m-p/359670#M88001</guid>
      <dc:creator>SirchRettop</dc:creator>
      <dc:date>2020-10-29T14:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: LACP Nego-fail issue between firewall and CPE router - Expected Behaviour?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lacp-nego-fail-issue-between-firewall-and-cpe-router-expected/m-p/360168#M88068</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110661"&gt;@SirchRettop&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would recommend you to verify configuration on switch side first. Also verify the transmission rate and the mode that you're using. You can also try to configure AE group to &lt;STRONG&gt;SLOW MODE.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can even check more related logs in the file &lt;STRONG&gt;l2ctrld.log&lt;/STRONG&gt; under mp-log.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 07:17:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lacp-nego-fail-issue-between-firewall-and-cpe-router-expected/m-p/360168#M88068</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-11-02T07:17:52Z</dc:date>
    </item>
  </channel>
</rss>

