Cisco ASA Series Cli Configuration Manual page 290

Software version 9.0 for the services module
Hide thumbs Also See for ASA Series:
Table of Contents

Advertisement

Guidelines and Limitations
Switch
VLAN 101
port-ch1
port-ch2
port-ch3
port-ch4
Additional Guidelines
See the
For unsupported features with clustering, see the
When significant topology changes occur (such as adding or removing an EtherChannel interface,
enabling or disabling an interface on the ASA or the switch, adding an additional switch to form a
VSS or vPC) you should disable the health check feature. When the topology change is complete,
and the configuration change is synced to all units, you can re-enable the health check feature.
When adding a unit to an existing cluster, or when reloading a unit, there will be a temporary, limited
packet/connection drop; this is expected behavior. In some cases, the dropped packets can hang your
connection; for example, dropping a FIN/ACK packet for an FTP connection will make the FTP
client hang. In this case, you need to reestablish the FTP connection.
If you use a Windows 2003 server connected to a Spanned EtherChannel, when the syslog server
port is down and the server does not throttle ICMP error messages, then large numbers of ICMP
messages are sent back to the ASA cluster. These messages can result in some units of the ASA
cluster experiencing high CPU, which can affect performance. We recommend that you throttle
ICMP error messages.
Cisco ASA Series CLI Configuration Guide
1-26
Device-local EtherChannels—For ASA Device-local EtherChannels including any
EtherChannels configured for the cluster control link, be sure to configure discrete
EtherChannels on the switch; do not combine multiple ASA EtherChannels into one
EtherChannel on the switch.
RIGHT
Cluster Control Link
port-ch1
ASA1
ten0/6
ten0/7
port-ch1
ASA2
ten0/6
ten0/7
port-ch1
ASA3
ten0/6
ten0/7
port-ch1
ASA4
ten0/6
ten0/7
"ASA Hardware and Software Requirements" section on page
Chapter 1
Configuring a Cluster of ASAs
Switch
WRONG
VLAN 101
Cluster Control Link
port-ch1
port-ch1
ten0/6
ten0/7
port-ch1
ten0/6
ten0/7
port-ch1
ten0/6
ten0/7
port-ch1
ten0/6
ten0/7
1-3.
"Unsupported Features" section on page
ASA1
ASA2
ASA3
ASA4
1-17.

Advertisement

Table of Contents
loading

Table of Contents