LACP Nego-fail issue between firewall and CPE router - Expected Behaviour?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

LACP Nego-fail issue between firewall and CPE router - Expected Behaviour?

L2 Linker

Hi Live,

 

I'm experiencing an issue with a setup of aggregated ethernet interfaces configured with LACP simply for redundancy connections between our HA Active/Passive firewalls and Cisco ISR 4451 routers.

 

I'm wondering what steps to take as regards packet captures on firewall interfaces to figure out why negotiation will fail.

Or is this expected behaviour?

 

ethernet1/1 and ethernet1/2 = AE1

 

Virtual IP (public/ default gateway) presented to firewalls from CPE Cisco routers.

 

SirchRettop_1-1603974307593.png

 

SirchRettop_0-1603973539042.png

So far we have tried all modes of LACP and transmission rates w/ active, passive, fast, slow but there has been still no change as regards ethernet1/2 and lacp negotiation failure with the router interface of GE0/0/2

 

I have reviewed >less mp-log l2ctrld.log but no indicators there either.

 

SirchRettop_2-1603974600046.png

 

As far as I'm aware, physical layer 1 hasn't been checked.

 

Interface and AE/LACP settings

SirchRettop_4-1603975405930.png

 

SirchRettop_5-1603975432038.png

 

SirchRettop_3-1603975359628.png

>show lacp aggregate-ethernet ae1

SirchRettop_6-1603975735329.png

 

3 REPLIES 3

Cyber Elite
Cyber Elite

@SirchRettop,

 

How your routers are configured? Make sure both these routers are virtually into one cluster.

 

Regards,

Mayur Sutare

M

Thanks Mayur,

 

Yes the Cisco routers are configured virtually into one cluster where we use the virtual ip as the default gateway

 

 

@SirchRettop,

 

I would recommend you to verify configuration on switch side first. Also verify the transmission rate and the mode that you're using. You can also try to configure AE group to SLOW MODE.

 

You can even check more related logs in the file l2ctrld.log under mp-log.

M
  • 4091 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!