Cisco Switching/Routing :: 6504 VSS Pair Shows Active / Standby On Led But Not In Config

Oct 30, 2012

After rebooting a pair of 6504's configured for vss, both switches show active on the sup modules. A show switch virtual redundancy however shows the pair working in an active/standby mode. We have 6509's in vss pairs and they show active on switch1 and standby on switch2 led's. For the 6504's switch 1 was booted first and then the second switch about 30 seconds later. Is there something different with the 6504's? [code]

View 4 Replies


ADVERTISEMENT

Cisco Firewall :: IPS Modules In ASA5510 Active / Standby Pair

Feb 6, 2012

I am looking to add the IPS module to my ASA 5510's. I am contemplating only purchasing one module and placing it in the active ASA. I am willing to accept that in a failure scenario I will loose the IPS functionality until the primary ASA is recovered. I have not had a chance to talk to my SE to see if this is even possible. Has anyone attempted a deployment such as this? Will it work and is it supported?

View 3 Replies View Related

Cisco Firewall :: Can Upgrade Active / Standby Pair From 7.2(4) To 8.0(5)25 Directly

Jan 17, 2012

Can I upgrade Active/standby pair from 7.2(4) to 8.0(5)25 directly or need to upgrade to 8.0.2/4 first? Upgrade an Active/Standby Failover ConfigurationComplete these steps in order to upgrade two units in an Active/Standby failover configuration:Download the new software to both units, and specify the new image to load with the boot system command.Refer to Upgrade a Software Image and ASDM Image using CLI for more information.Reload the standby unit to boot the new image by entering the failover reload-standby command on the active unit as shown below:active#failover reload-standbyWhen the standby unit has finished reloading and is in the Standby Ready state, force the active unit to fail over to the standby unit by entering the no failover active command on the active unit.active#no failover activeNote: Use the show failover command in order to verify that the standby unit is in the Standby Ready state.Reload the former active unit (now the new standby unit) by entering the reload command:newstandby#reloadWhen the new standby unit has finished reloading and is in the Standby Ready state, return the original active unit to active status by entering the failover active command:newstandby#failover activeThis completes the process of upgrading an Active/Standby Failover pair.

View 10 Replies View Related

Cisco Firewall :: ASA 5540 - Active / Standby Failover Pair

Apr 13, 2011

I currently have two 5540's in an Active/Standby pair. The primary unit failed on February 12th, so the secondary ASA is now the active one. My question is this - we have made a lot of changes since February 12th and I am planning on fixing this failover issue over the weekend. Will the secondary (now active) FW sync it's config to the non-active FW, or will the failed FW sync it's out-of-date config - removing any changes that we've made in the last month or so.

View 1 Replies View Related

Cisco Security :: Pair Of 5520s Running 8.2(3) In Fail Over Active / Standby

Jun 29, 2011

I have a pair of 5520s running 8.2(3) in failover active/standby, routed mode. I have an issue with SSH as it's stopped worked after a short time, less than 8hrs during the network being installed, telnet is working fine as is https/asdm. I have re-created the crypto key and the ssh access is allowed. When I try to connect I just get a flashing cursor, telnet to the ip and port 22 also works.

View 1 Replies View Related

Cisco Firewall :: ASA 5505 Security Plus Licenses - HA Pair Using Active / Standby

Apr 24, 2012

I have two ASA 5505's with Security Plus licenses on both.I am trying to force them to becoming an HA pair using active/standby.When I enable failover I get this message:
 
Mate's license (Licensed Cores ) is not compatible with my license (Licensed Cores ). Failover will be disabled.Do I need to apply new licenses to the ASA's?
 
Device licence details (same on both):Cisco Adaptive Security Appliance Software Version 8.2(1) [code] This platform has an ASA 5505 Security Plus license.

View 1 Replies View Related

Cisco Firewall :: ASA5520 - AnyConnect License On Active / Standby Failover Pair?

Mar 6, 2013

Our customer has purchased 2 x L-ASA-AC-E-5520= Anyconnect Essentials VPN Licenses (750 Users)Ive installed both activated licenses as per the cisco guides, I didnt get any errors on the install. I did a reload on both, they are both back up and running as active/standby but when I do a sh ver the license still shows "ASA 5520 VPN Plus License"Am I being dumb and has this worked successfully or should it not now display Anyconnect when I do a sh ver?

View 8 Replies View Related

Cisco Security :: Implement Active / Standby Cluster With A Pair Of 5550 ASAs?

Aug 19, 2012

I want to implement Active/Standby cluster with a pair of 5550 ASAs and I have a licensing question. Here is the "sh activation-key detail" output from both devices...
 
ASA1:
 
sh activation-key detail:
 Serial Number:  XXXXX
No active temporary key.
Running Activation Key: XXXXX XXXXX XXXXX XXXXX XXXXX

[code]....
 
This platform has an ASA 5550 VPN Premium license.The flash activation key is the SAME as the running key.So it looks obvious that I'll have to upgrade the first ASA to support 25 SSL VPN Peers in order to build HA cluster, right?Now I want to know do I need the "ASA5505-SSL25-K9" license or something else.

View 12 Replies View Related

Cisco Firewall :: Active / Standby Fail Over Config On ASA5510

Apr 10, 2011

I have two ASA5510 configured in an active/standby failover configuration. Everything is working well, but I would like to remove DMZ2 as it is no longer needed. On my DMZ2 interface, I have removed the security level and the IP address and shutdown the interface. However, when I do a "show failover" DMZ2 is still showing up. I would like to remove it completely so that failover isn't even "monitoring" this interface. What command am I missing or what do I need to do to completely remove this interface from this "show failover" listing? [code]

View 7 Replies View Related

Cisco Firewall :: Monitoring ASA 5505 Firewall Active / Standby Pair Using SNMP?

Sep 7, 2011

How I can actively monitor the interfaces and overall status of 2 x ASA 5500s in an Active/Standby configuration?
 
I can setup monitoring of the interfaces on the Active member but I'm not sure how to manage the Standby member?

View 1 Replies View Related

Cisco Switching/Routing :: 4506 HSRP Active To Standby And ARP Impact

Mar 4, 2013

I am running HSRP on three 4506 switches..S1(active) S2( standby) and S3(listen)..S1 is active for all the vlansRight now, I wanted to  make S3 active for two vlans: vlan 10 and 19What would be the impact to the end hosts?Also, can you tell me why the arp is not syncing for all the three devices? [code]

View 4 Replies View Related

Cisco Switching/Routing :: Nexus 7000 - HSRP Active / Standby?

Dec 16, 2011

I am working on two Nexus 7010 with 5.1.5 NX-OS version. I configure HSRP traditionnaly, Nexus 1 with a priority of 200 and Nexus 2 with a priority of 100 for all vlan.

When I change the priority of a vlan to 200 to 50 for example, Nexus 2 become active and Nexus 1 standby. The problem is that when I do a traceroute from a PC the packet take the Nexus 1 as defaut gateway all the time.....

For information I have a peer link between the 2 Nexus for vPC.

View 9 Replies View Related

Cisco Switching/Routing :: 6509 (HA) And FWSM (active / Standby) System Upgrade?

Sep 30, 2012

I have 2 6509 chasis with one SUP720-3B in each and current IOS is s72033-ipservicesk9_wan-mz.122-18.SXF4 and 2 FWSM with version is 3.3.1 I need to upgrade FWSM system software to 4.1, after checking FWSM 4.1 release notes, I thought of upgrading IOS to latest version  to 12.2(33)SXJ.I got new 2 CF of 512MB and downloaded the new IOS on them and need to upgrade 6509 IOS first to meet the requirement for FWSM upgrade.

View 1 Replies View Related

Cisco Switching/Routing :: 4500 Requirement For NSF / SSO Commands On Standby / Active Supervisor

Apr 22, 2012

I went through the configuration guide for 4500 series switches for NSF/SSO for failover between Sup's. I just wanted to know that that are we supposed to run the SSO command on both of the supervisors? Secondly, are we only supposed to run the nsf process under EIGRP on the secondary supervisor and routing peers and not on the primary supervisor?

View 2 Replies View Related

Cisco Switching/Routing :: 2690 - SFP Ports On Active And Standby Supervisor Engine

Oct 19, 2012

We are expanding out LAN network with more 2960 access switches. All the access switches are suppose to be connected to core switch (4507R) but i have less port on the core switch.
 
On the core switch we have two supervisor engines (WS-X4515 ---description : "Supervisor IV with 2 1000BaseX GBIC ports"). I can see that on each supervisor engine i have two 1 GB SFP ports available and if i calculate for two supervioser engine i will have 4 1GB ports.
 
But at particular time only one supervisor engine is active and other is in standby mode (redundancy mode used is SSO between two SUP engines).
 
Can i used all 4 SFP ports for connecting 4 uplinks to the 4 access switch?Will all the 4 SFP ports active at one time or only 2 SFP ports will be active that is for only active supervisor engine.

View 10 Replies View Related

Cisco Switching/Routing :: Copying IOS From Standby To Active Supervisor 4507 Switch

Jun 4, 2012

I was upgrading IOS on 4507 R with dual supervisor.I download the IOS on Active supervisior and did reboot.After reboot i login to switch then i got switch standby prompt.I found that after reboot active supervisior  became standby supervisior.
 
Now new IOS  is on standby supervisior.Need to confirm below..So this means that IOS  does not syn  within the  supervisiors as compared to config  right ?
 
-Which command i can use that will copy IOS from standby supe to Active supe??
 -Which command i can use that will show both active and standby supe with new IOS?
 -Is there any command that i can use to switchover from active to standby supe??

View 3 Replies View Related

Cisco Switching/Routing :: Possibility For Nexus 7000 To Be HSRP Active Standby In Data

Nov 20, 2012

Normally when we do HSRP with vPC on N7K the device will be Active/Standby in control plane but it will be Active/Active in data plane. In this case any traffic reach to standby device it can forward traffic directly to uplink which is not my desire. My goal is all traffic should pass through active (control plane) device in every case unless active device totally dead. So Is it possible for Nexus 7000 to be HSRP Active/Standby in Data Plane ?

View 4 Replies View Related

Cisco Switching/Routing :: 4510R L3 / Make Active Sup6 In Slot 6 Which Is Currently Standby Sup In Chassis

Mar 25, 2013

I have cisco 4510R L3 switch with installed 2 Sup on slot 5 and 6. the current active Sup is in Slot5 i want to make active Sup6 in slot 6 which is currently standby sup in chassis. Is there any way to make standby Sup to ACTIVE without reloading any of the Supervisor. however there is two way as per my understanding -

1. we can reload the active Sup so that standby Sup will take charge. - (redundancy reload shelf)

2. we can focefully switchover the state of Sup's by (redundancy forcefully swithover) but in above both cases reload will be performed by one of the supervisor. which i don't want.

View 2 Replies View Related

Cisco Firewall :: ASA 5520s From Active / Standby To Active / Active

Jul 17, 2012

I have a pair of ASA 5520s operating in failover pair as active/standby, having two contexts on them. I am planning to share the load and make it active/active making first context active on the primary unit and second context active on the secondary unit. My question is if this will disrupt any connectivity thru these firewalls when I do "no failover" on the active/standby and assign the contexts to different failover groups and enable the failover back.

View 6 Replies View Related

Cisco WAN :: 4507 R - Active SUP Lost Connection And Standby Came Active

Apr 10, 2011

I faced one problem in our core switch 4507 R . Active sup lost connection and standby came active. We got lot of errors/alerts on console shown below. [Code] Also when I reloaded the switch with reload command only both sups got reloaded but I want to reload all the modules but reload command do not gives any options for that.

View 2 Replies View Related

Cisco Switching/Routing :: Pair Of N7K Distribution Switches Connected To A Pair Of Aggregation Switches

Mar 11, 2012

We have a pair of N7K distribution switches connected to a pair of N7K Aggregation switches.We run vPC on both pairs of n7k's.

-n7k-d1 has two interfaces in a Port-Channel connecting to n7k-a1 & n7k-a2. (PC1)
-n7k-d2 also has two interfaces in a Port-Channel connecting to n7k-a1 & n7k-a2. (PC2)
 
My problem is that Spanning-Tree is blocking PC2 and all traffic from n7k-d2 is traversing the Peer-Link before reaching the Aggregation layer. Is this the best design for connecting two pairs of n7k's with vPC or if a better design would be to connect all 4 links into the same Port-Channel and vPC?

View 7 Replies View Related

Cisco Switching/Routing :: 6504-E VSS And WLC 5508 Integration?

Dec 14, 2012

We have implemented VSS on Cisco 6504-E switches using the 10GE links on the Sup-720-10GE. Two Cisco WLC 5508 controllers are planned to be connected in a LAG configuration, (consisting of eight links per LAG bundle) to each of the  6504-E chassis( Total of four WLC, two for the primary location and two for secondary location). WLC HA feature may be implemented on the primary and secondary WLC controllers using the 7.3 latest code release.
 
In this scenario, i would like to seek clarification on some of the design /configuration requirements  on the 6504E switches:
 
1. VLAN 100 - 200 is configured for the Active Primary 6504-E switch and VLAN 200-300 for the Standby 6504-E switch. The IP scopes for the VLAN are defined in the 172.16.x.x range on the Primary and 172.17.x.x on the secondary. As there no cross links(Multichassis LAG) from the WLC controllers to the 6504-E switches, is it better off implementing a single common VLAN range on a single subnet block for the VSS, which in the event of say Primary switch failure, the Wireless APs do not have to re-associate with a different IP range on the secondary? What is the best design practise in this case?
 
2. What is the best practise for implementing a single management loopback address for the VSS domain-  is this implemented using a port channel (Layer 3 MEC) as below?  and is the loopback IP address on a totally different IP range reference to point 1 above?
 
Can the VLAN IP ranges on the 6504-E VSS be assigned in two different subnets say 172.16/12(100-200) and 17.17/12(300-400) and  the common loopback (lo0) in 172.18.x.x/32 or is it better to have one common 172.16/12 subnet spanning the entire VLAN range (100-400). Cisco documentation describes creating port channels from the line card card physical ports as opposed to just creating lo0 and advertising this into the IGP.

int g1/x/1
desc VSS Management
channel-group mode 101 active
int gi2/x/1
channel-group mode 101 active
int po101
desc VSS Management
ip ad 172.18.x.x/32

View 2 Replies View Related

Cisco Switching/Routing :: ASA 5505 Upload Config File Into Start-up Config

Apr 17, 2012

If i connected the latop to brand new out of the box ASA 5505 through consloe cable and i have a config file on this laptop from other ASA5505, is there anyway i can upload that config file into startup-config of this new ASA5505 through console cable, without using TFTP or FTP?

View 5 Replies View Related

Cisco Switching/Routing :: 6504 / Supervisor 720-3b Reboot Loop?

Apr 14, 2007

We recently wanted to swap our existing WS-SUP720-base with a WS-SUP720-3B in a 6513 chassis.Had the existing configuration config saved in a txt file and replaced the supervisor. Booting went fine and we pasted in the original config. There was one failure message about unnsupported command but didnt take further notice."boot system flash sup-bootflash:" was probaly the line that the 720-3B didnt support.After wr mem and reload it went in continious loop and rebooting due to inncorrect boot device. Had to put back the old supervisor and have now the 720-3B in a 6504 chassis. Tried some commands in rommon, but are not getting any further.

View 8 Replies View Related

Cisco Switching/Routing :: Replace Chassis By Ws-6504-E And Also Line-card

May 27, 2012

We currently have a WS-C6506 chassis with a line-card WS-X6408A-GBIC. Currently we need to replace the chassis by a Ws-6504-E and also the line-card. My question is: What must buy line-card and meets the same specifications of WS-X6408A-GBIC?.

View 4 Replies View Related

Cisco Switching/Routing :: Ping Error Between Two 6504 Trunking Switch?

Oct 17, 2012

We have network topo ( attach file)Two switch run VRRP, if I ping 10.0.10.3 from switch SW-6504-01 with source 10.0.10.2, ping lost one packet  every 10 packets.We have other interface vlan with same problem
 
this is some config:

!
interface Port-channel1
switchport
switchport trunk encapsulation dot1q
switchport mode trunk
no ip address
!
interface GigabitEthernet3/47

[code]....

View 5 Replies View Related

Cisco Switching/Routing :: 6509 Series Switches Support VSS Active-Active Chassis

Feb 7, 2012

The 6509 Series Switches support the scenario VSS Active-Active Chassis, I would like to setup both switch's as one virtual switch but working at the same time, not with Active - Stand By Chassis.
 
My plans it to create PortChannel accross both Switches 6509 in order to have 2 links one connected to one slot/switch and the other connected to slot/switch in the second 6509 for servers redundancy.

View 1 Replies View Related

Cisco Switching/Routing :: ASR1000 - Dual ISP Active / Active Connection On Single Router

Jun 10, 2012

I am working on a network which has two ISP connections (Active/Active) terminating on router (ASR1000). From the LAN side (6500 switch) all the traffic need to be route on ISP1 but some of the specific subnets like 10.250.0.0/16 need to be route on ISP2 connection.
 
I am planning to use PBR and NAT with route maps. any documents or refrences are provided.  
 
(access switches)---------(core switch)----------(routers)----------------(ISP1)
----------------------(ISP2) 

View 1 Replies View Related

Cisco Switching/Routing :: When Failed 6504 Comes Back Online With Higher Priority And Preempt Set

Jul 17, 2012

I'm having with VSS Failover.  Currently I have two 6504's setup for VSS with one connection to the sup engine (10Gig__Connection) and the other connection on the Module 3 10Gig Blade and the same setup on the other 6504.My question is: If the active 6504 has a power outage or the link on the sup engine goes down, and the standby 6504 becomes active, what happens when the Failed 6504 comes back online with a higher priority and preempt set? What happens with the 6504 that took over as Active and now eeds to go back to Standby, what's required?
 
What I'm seeing is once the Standby took over and became Active in order for him to go back to Standby mode it's asking for a reload to take place is this NORMAL?

View 2 Replies View Related

Cisco VPN :: 5512x Anyconnect Ssl Licensing For ASA Active / Passive Pair

Aug 7, 2012

I am purchasing 2 5512x ASAs to be configured as an Active/Passive pair as a VPN device. Do I need to purchase anyconnect licenses for both devices?

View 2 Replies View Related

Cisco :: How To Get LMS 4.2 Active / Standby

Dec 13, 2012

We are preparing to upgrade from LMS 3.2 where we run 2 seperate independant instances in seperate locations for redundancy.  Each instance forwards syslog traps to a seperate Openview system in the associated location.  Device updates are manually done on each system.
 
To reduce costs and administrative overhead we are considering switching to an active-standby environment when we upgrade to LMS 4.2 where the active system would forward traps to both Openview systems.
 
Any experience with an active-standby Ciscoworks LMS 4.2 environment, specifically; When one system becomes unavailable (due to network, system or application issues) is promoting the standby system to active automatic?How long does it take?
 
Does the standby system still monitor syslog events and initiate automated actions? Where the active system stops working or hangs and the standby system does not go active?
 
Are there any reliability issues with database updates or synchronization from the active system to the standby system? Is there a way to test communications from the standby system for new device turn-ups without making it active?

View 1 Replies View Related

Cisco Firewall :: ASA 5550 Active / Standby With SSL VPN

Jun 12, 2011

I would like to work with two ASA's 5550 in HA (Acitve-Standby)  like perimetral firewalls and also work with another ASA 5540 but like a SSL VPN Remote Access to end users.Which will be the best topology to this scenary?. Perhaps i need to put the ASA 5540 SSL VPN together with the ASA's in HA directly in a port.

View 1 Replies View Related

Cisco :: See An Active / Standby Mac Address Section In ADSM?

Dec 17, 2012

I'm not quite ready for the Automatic Failover feature that the ASA 5520 support. For now we have a cold stand by unit. I was wondering if I can change the mac addresses of the standby unit's interfaces to be exactly the same as the primary unit. I see an active/standby mac address section in ADSM, but I think that is used in the automatic failover function.

View 12 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved