Cisco Firewall :: Link Aggregation On ASA 5550?

Jan 10, 2011

i'm installing a Firewall Cisco ASA 5550 with 8 Gigabit interfaces.
 
I have installed firmware 8.2.3.
 
Is it possible to make link aggregation on ASA to have more bandwith?

View 7 Replies


ADVERTISEMENT

Link Aggregation Vs STP?

Feb 13, 2012

what is the difference between "link aggregation" and "STP"?

For example:
I have two switches connected with two ethernet cables together. Why I will use link aggregation on trunk ports (without load balancing) when STP will do same service?

View 13 Replies View Related

Cisco WAN :: WAN Routing Between N5K (L3-vPC) And VSS (MEC) With Link Aggregation

Feb 16, 2012

We want a solution for routing between N5K and VSS with aggregated WAN links.
 
DC1: It has 2 cisco 6509 with VSS. There are 4 server farm cisco4948 switches connected with VSS with redundant uplink via MEC. Server gateway is the VSS. VSS is running Eigrp routing.
 
DC2: This is a new datacenter we are going to establish soon. We are planning 2 N5K at core layer with L3 daughter card and 4 N2K as server farm switch. 2 N5K will have vPC peer between them. Each 4 N2K will connect with redundant uplink via vPC with this N5K. N5K will run Eigrp routing and will be the gateway of this new DC server.
 
WAN between DC1 & DC2: DC1 VSS will connect with DC 2XN5K with 2X10G links. we want to do MEC at VSS side and L3 vPC at DC2 side. If we have VSS at both end it might not be a problem. Both the link will work together as 20G aggregated link. But as we are using N5K at one end, so it creates a confusion whether it will work properly is this scenerio or not.Also I would like to know,

1) In VSS I have configured 1 VLAN interface for server gateway. But in N5K do I have to configure at 2 switch seperately?

2) In WAN routing VSS shows as 1 device. Does this 2 N5K will show as 2 seperate hops or L3 vPC will allow them to act as a single device while traceroute from one end to another end.

View 19 Replies View Related

Cisco Switches :: Link Aggregation On SG 200-26

Mar 5, 2012

I'm trying to setup Link Aggregation on this switch for an HP server with a 4-port NIC which is teamed.  I create the LAG and see in the HP Network Utility where each port in the team disconnects then reconnects and the server has internet access, but workstations cannot access the server (can't browse UNC, RDP, ping, etc.) and vice versa.  This is the only switch at the site, all the workstations are plugged into it.  Rebooting the switch after creating the group didn't have any effect.

View 1 Replies View Related

How To Setup Link Aggregation

Jul 23, 2011

I am trying to setup a home network where I have multiple low bandwidth or rather lower bandwidth links coming in. They are suppose to be broadband but I do feel the need for a fatter pipe. Since this is in India and we have limited availability of bandwidth options like here in the US I thought if I could double or even get close to doubling my bandwidth using some sort of device for link aggregation or a network / pc setup which can achieve thisThe links I am getting are above 1mbps, possibly even 2mpbs and its relatively cheap, 100$/yr so I can add 3-4 to get desired results. A dedicated 10mbps connection costs nearly 12000$/yr so I have a lot of margin to create a substantial pipe without the cost if what I am thinking is possible.

View 4 Replies View Related

Intel NIC's 802.3ad Link Aggregation In Windows 7?

May 19, 2013

I've been having some issues lately where if I am copying large amounts of files two and from my NAS and thus saturating my gigabit ethernet, web browsing and internet streaming slows down which is a bit of a bummer. I figured I might fix this with link aggregation.

My switches (Procurve 1810G-24 in basement and 1810G-8 in office) both support 802.3ad Link Aggregation. It works beautifully to connect them together, as well as to connect my FreeNAS box to the switch as well.

how do I set it up to work with my Windows 7 box?

I can't find the options for 802.3ad in the windows menus anywhere, and googling has not led me to the answer yet...

My motherboard has two on board Intel gigabit ports (Intel 82574L and Intel 82579V). Is it possible to link these two, or do I need to pick up another Intel PRO PT dual port copper gigabit NIC like I have two of in my server?

View 1 Replies View Related

Cisco Switches :: SG300 Link Aggregation And Wake On Lan?

Aug 21, 2011

Having issues waking NAS devices using a magic packet when using link aggregation on an SG300-28 switch.
 
Without link aggregation everything works fine so I know the magic packet is being generated correctly and the NAS device is correctly configured to wake. After configuring link aggregation the device does not wake. Have tried dynamic (LACP) and static link aggregation but neither allowed the device to wake? When the NAS is powered off, the ports in the LAG still show as being connected at 100M but it appears the magic packet is not being transmitted.

View 1 Replies View Related

Cisco Switches :: SG200-18 Link Aggregation Setup

Jun 22, 2012

I have a Synology 1512+ and trying to setup Link Aggregation but no success. I have configured LAG Management with LACP enable or disable but still failed.
 
At the Synology 1512+ setting page, there are 2 options: IEEE 802.3ad Dynamic Link Aggregation and Network Fault Tolerance (Non-802.3ad network enirovement), I selected IEEE802.3ad, which i think S200-18 should be able to support. right?

View 3 Replies View Related

HP Pro-Curve SNMP Link Aggregation Configuration

Aug 7, 2012

I am looking after a mixed collection of Cisco and HP switches and use a Perl script to extract configuration data.I use the ifStackStatus table (OID: 1.3.6.1.2.1.31.1.2.1.3) from RFC1573 to sucesfully obtain the EtherChannel data from the Cisco switches but, though I do obtain data from the same table from the Procurve switches it seems to bear no resemblance to Link Agregation. I could look at other tables and may have to - but would like to use this one in order to simplify the code.

View 2 Replies View Related

Cisco Switching/Routing :: Does SA520w Support Link Aggregation

Sep 16, 2012

if my SA520w will support link aggregation for network devices within my LAN. If so, is there a Cisco wiki or how-to on how to setup this up in the SA520w? I only find a brief mention of this in Section D of the manaul.

View 1 Replies View Related

Cisco Switches :: SGE2010 Stacking Versus Link Aggregation?

Aug 14, 2011

answer regarding stacking the SGE2010 switches versus link aggregation if greater than 1 Gb connectivity is required between individual switches? Currently have several switches in a stack configuration but would like to increase the bandwidth between some or all of the switches. Does stacking support a link aggregation configuration? If so what ports can be used and how should the link aggregation be configured in conjunction with the stacking?

View 2 Replies View Related

Cisco Switching/Routing :: 2960 - Link Aggregation With Different Technologies?

Jan 8, 2012

I have two 2960 switches connected with two links. One of them is transparent modem connection with 2Mbps limit, and the other is optical link with media convertos on both sides. Is there a way to set up etherchannel, LACP or any other kind of link transparent to switches or I have to use some sort of STP?

View 1 Replies View Related

Cisco Switching/Routing :: SG500X-24 / Link Aggregation On Switch And Controller?

Nov 4, 2012

I have two workstations running 7 Pro, each has a quad port intel card (PCIe) which I have created teams for on both sides using link aggregation. On my switch, a Cisco SG500X-24, I set up two LAG's with 4-ports each and have both servers connected as necessary. I turned on Jumbo frames and disabled energy saving. The teams were set up without LACP turned on, however I tried it with LACP and I also ran into the same problem. Both workstations have a 26TB arrays running in RAID 6 (so plenty of read/write speed), however, with this setup, I can only get about 100MB/s (single port speed) and multiple data streams cause the speed to divide. Only single ports blink on the cards as well.
 
Questions 1 is probably a no-brainer, but it's my first time setting this up, but once this is working properly, would it allow a single file to transfer at ~400MB/s or would I need to start multiple datastreams to take advantage of link aggregation.
 
Question 2 is what do I need to change to make the link aggregation work?
 
I do have a little linksys router plugged into a non aggregated port to do DHCP but that wouldn't mess anything up, would it? Considering I can unplug it once everything is talking, all the transfer should take place at the switch level, correct?

View 1 Replies View Related

Cisco Firewall :: 5550 Firewall Set Up For Redundant Purpose

Mar 3, 2011

i two 5550 firewall set up for redundance purpose . in failover we define two different ip add one for primary and one for secondary .interface Ethernet0/0 nameif outside security-level 0 ip address xxxx.0.0.0.1 255.255.255.0 standby xxxx.0.0.2!interface Ethernet1/0 nameif inside security-level 100 ip address 10.0.0.12 255.255.255.0 standby 10.0.0.11.default gateway for host will be 10.0.0.12 (primary fw address) however in case of failover , the secondary fw will be up with ip address that was assigned for primary .in this case the secondary ip add 10.0.0.11 is actually nerver used? similarly do i need to have two public ip address for outside (one for primary and one for secondary )   ? or in case if primary fails the secondary comes onlie and take the ip of primary fw . hence i only need to purchase just one ip address.

View 6 Replies View Related

Cisco Firewall :: 5550 Firewall Syslog Message

Feb 22, 2013

I have cisco 5550 Firewall, one messages appear in syslog server from Firewall, (warning) i want to stop this message from appearing syslog traps.

View 2 Replies View Related

Cisco Firewall :: Secondary ASA 5550 Firewall Getting Down Automatically?

Apr 17, 2011

I am having two ASA 5550 firewall running in active/standby mode. With in last two months our secondary firewall got down automatically 3 times. Firewall is running with IOS version 7.1.2. how to proceed further troubleshooting because there are not any logs on firewall.

View 3 Replies View Related

Cisco Firewall :: ASA 5550 Two ACL From Outside To Inside

May 13, 2011

I have  ASA5550 ruuning Version 8.3(1) with inside and outside interfaces as below [code] On the inside : I have a server (10.20.10.36) that need to be accessed from an outside host (Y.Y.131.34) , so I have the below NAT/ACL  rules. [code] is it right that I have to add two ACL entry for outside host to the NATed IP of the inside server , then again add another ACL entry from the same outside host to the private IP of my inside server o get this communication done?

View 7 Replies View Related

Cisco Firewall :: ASA 5550 With IOS 8.0(2) Crashes

Jan 31, 2012

we had just installed our ASA 5550 with IOS 8.0(2) a couple of week ago.
 
2 interfaces from each slot are being used ie 0/0 for Branch users comming via MPLS cloud ,  0/1 for internal LAN users comming form Core Switch  & 1/0 for Server farm LAN   , 1/1  for Internet (outside)
 
the first 3 interface are considered inside with sec set at 100   while the 1/1 is outside with sec at 0.
 
Last night it suddenly started dropping all connections without any warning  or any noticible log form the ASDM logging.
 
the connection drop would happen for 2 - 3 minutes and would work fine for the next 15 minutes or so..
 
after conencting the console , we found out that the IOS would suddelny go abrupt and show this display ...
 
TP-ASA(config)# TP-ASA(config)# TP-ASA(config)# Thread Name: Dispatch UnitPage fault: Address not mapped    vector 0x0000000e       edi 0x24d184b0       esi 0x0000000d       ebp 0x1c6ceaf8       esp 0x1c6ceae0       ebx 0x09e965e0       edx

[Code]....

View 2 Replies View Related

Cisco Firewall :: 5550 - How To Do NAT Exemption With V8.4

Oct 4, 2011

I have looked in the books I have (Cisco ASA, PIX and FWSM; ASA 8.0) and googled a good bit but can't seem to find any specific mention of how to do NAT exemption with v8.4. It seems NAT exemption (NAT 0 access-list) was deprecated. Using ASDM, there's no corresponding menu item for this that is obvious.
 
We have public addresses inside the ASA and want to allow in/outbound connections using these IP's without NAT. The ASA is a 5550.

View 7 Replies View Related

Cisco Firewall :: ASA 5550 IPv6 Compatibility?

May 21, 2013

I need to understand if ASA 5550 ver 8.2(1) is comptible with IPv6, if not what is the upgrade path to make it IPv6 compatible. The requirement is dual stack of IPv4 and IPv6 should run in the same HA cluster and later will shift IPv6 completely.
 
The existing infrastructure is equipped with ASA with HA Active/Active mode. The command output for required details are attached here in txt mode.

View 2 Replies View Related

Cisco Firewall :: High CPU Utilization On ASA 5550?

Mar 10, 2013

I have Active Standby ASA5550 setup with VPN premium license. A few days back we had a requirement of SSL VPN connection for and we got a temporary from Cisco for same, this license expired and the ASA reverted to it's original license. 3 4 days after this we saw a sudden increase in CPU utilization (upto 90% + -5%) on the ASA during production hours but were not able to figure out the reason, in order to restore the services we failovered the firewall to secondary and everything worked fine. We were suspecting one of the following but there were no logs for any of this
 
1. The ASA hardware was haivng problem

2. Some client was doing a DoS attack to bring down the ASA (no logs for this as well).
 
We took a downtime to look further by failovering the ASA back to primary and it worked fine without any issues ruling out the 1st option. We also came across a licesing doc [URL]
  
Downgrading any license (for example, going from 10 contexts to 2 contexts).
 
# Note If  a temporary license expires, and the permanent license is a downgrade,  then you do not need to immediately reload the security appliance; the  next time you reload, the permanent license is restored.
  
As per this doc, sooner or later a restart was required on the ASA. We restarted secondary ASA and everthing was fine but when we restarted the primary ASA by swtiching over to secondary some of the server (not all) in the DMZ stopped working (even ICMP unreachable) and only came back to normal when the primary ASA was restored and working fine (with failover).
 
The reboot was done by shuting down the physical link between the Core switch and ASA inside individually.
 
I am not sure what could be the issue that the servers in the DMZ wen unreachable.

View 0 Replies View Related

Cisco Firewall :: ASA 5550 - Two Different Syslogs Servers?

Aug 9, 2010

In my Cisco ASA 5550, I need to set two different syslogs servers, and I need to send the system logs to the first one (only admins login/logout), and the traffic logs and all the rest (informational level) to the second one. Do you know if is it possible or not and, if yes, how to configure it?

View 6 Replies View Related

Cisco Firewall :: ASA 5550 Active / Standby With SSL VPN

Jun 12, 2011

I would like to work with two ASA's 5550 in HA (Acitve-Standby)  like perimetral firewalls and also work with another ASA 5540 but like a SSL VPN Remote Access to end users.Which will be the best topology to this scenary?. Perhaps i need to put the ASA 5540 SSL VPN together with the ASA's in HA directly in a port.

View 1 Replies View Related

Cisco Firewall :: How Many Outside Interfaces Are Allowed On ASA 5550

Apr 26, 2011

I am using an ASA5550 for a complex secure network that has at least six "outside" networks.  Each "outside" network is assigned to a specific port each set at level "0".  I also have a DMZ, set to level "50".  I am having difficulty with passing traffic from a host in the DMZ to all but one of the "outside" networks.  Is there a limit to the number of "outside" interfaces?  I will provide a redacted config file as soon as possible.

View 3 Replies View Related

Cisco Firewall :: ASA 5550 - URL Filtering Using Web Sense?

May 10, 2013

i have Cisco ASA 5550 and i want to do URL filtering using Web sense,can i use Micorsoft Forefront TMG2010 as websense server to do that?
 
the idea is to filter the HTTP & HTTPS URLs,if the  Micorsoft Forefront TMG2010 is not suitable,refer to suitable Websense URL filtering server?

View 2 Replies View Related

Cisco Firewall :: ASA 5550 Sending Reset With TTL Of 255

Oct 3, 2011

I have the following problem, right now we have an ASA 5550 connected to the client´s side. A reset is being received on the client´s side, but when we run the sniffers on both extremes of the network, we can see that the reset is not being sent by the server´s side.
 
We have narrowed it down to the 5550 ASA, but have found no bug that matches the description.
 
The characateristics of the reset packet are the following:
 
- It is the only packet with a TTL of 255.

- Both server and client have very different window sizes, and the reset packet even though has the server´s ip and port as source of the packet, it has the client´s window size.

- It has a correct ack number.

-Before the reset is received, there are a couple of retransmissions of the last packet sent.

- We´re handling a VPN tunnel between both servers.

View 1 Replies View Related

Cisco Firewall :: Does 5550 Contains Built In CSC / IPS Modules

Feb 7, 2011

i m looking for asa 5550 product.Part # ASA5550-BUN-K9 - Cisco ASA 5550 Appliance with SW, HA, 8GE+1FE, 3DES/AES
 
1) does 5550 contains built in CSC / IPS modules.? why i  m asking because the "quick refrence guide " indicates that expansion slots are not available.
 
2) can asa 5550 natively protects natively against networks attacks against virus / worms  etc with out CSC OR IPS MODULE.?

View 9 Replies View Related

Cisco Firewall :: ASA 5550 To ASA 5555-X Migration

Apr 23, 2013

I am about to carry out a migration from ASA 5550 to ASA 5555-X, however I cannot find any detailed document or reliable tool for this migration.

View 4 Replies View Related

Cisco Firewall :: ASA 5550 Cannot Logon With ADSM

May 22, 2012

I cannot logon with adsm anymore.when I run adsm, I type in my pw, and the screen keeps displaying "contacting the device". No timeout, just stays this way.I've updated the java version, no luck.I can connect with SSH with no problem. device = asa5550, 8.2(1) asdm 6.2(1) [code]

notice that there is no "with cookie-based authentication" here -- is this relevant?
 
Rebooting the device is not really an option.

View 7 Replies View Related

Cisco Firewall :: ASA 5550 Flags E Connection

May 2, 2012

I have an issue were thousands of connections on the ASA are marked with flags E, below is a visual of the connection. Any ideas what could cause this marking? Also, I can't grasp what the meaing of an outside back connection (ie flags E).
 
TCP DMZ:X.X.X.X/139 Inside:X.X.X.X/1828,    flags E, idle 9h37m, uptime 9h37m, timeout 15s, bytes 0

View 0 Replies View Related

Cisco Firewall :: ASA 5520 / 5550 - Cannot Upgrade To 8.3

Aug 7, 2011

I have a couple of ASA5520 and ASA5550, and I wanted to know if it is worth it to upgrade the software from 8.2(4) to 8.2(5)?  Because of the RAM I cannot upgrade to 8.3 for now.

View 1 Replies View Related

Cisco Firewall :: ASA 5550 - Cannot Copy IOS From Flash To PC

Jan 8, 2013

I just got a brand new ASA 5550, i configured the port g0/0  on asa with an ip address 192.168.10.1 then configure my computer with ip 192.168.10.2 and default gateway is 192.168.10.1. I'm able to ping the asa from my computer. I remote to ASA thru the console port  and try to copy iOS from flash to my pc but it doesn't work.
 
Cisco asa# copy flash tftp://192.168.10.2/asa804-k8.bin
Source file name []? asa804-k8.bin
Address or name of remote host [192.168.10.2]?
Destination file name [asa804-k8.bin]?
 Writing file tftp://192.168.10.2/asa804-k8.bin...
!%Error writing tftp://192.168.10.2/asa804-k8.bin (Timed out attempting to connect)
Cisco asa#

View 3 Replies View Related

Cisco Firewall :: How To Compress Data On ASA 5550

Apr 6, 2011

I have two box cisco asa 5550 in multiple context mode and failover.
 
My network topology is:
 
                                Outside Network
                                         •
                                         •
                                         •
DMZ2 Network • • • • (CISCO ASA 5550) • • • • DMZ1 Network
                                         •
                                         •
                                         •
                                Inside Netowork
   
My interface "Inside Network" is full(I think).I can't diagnose this, based on command "sh interface gigabitEthernet"
 
109042974565 packets input, 100691006385765 bytes 
94097614769 packets output, 59002295942465 bytes
999339444 packets dropped
 
My interface is 1GB, based on the above command, it is full?If interface is full, i have a problem! All the ports on asa firewall are using, how do resolve this? I can compress all data on this interface with class maps and policy maps?

View 4 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved