Presentation is loading. Please wait.

Presentation is loading. Please wait.

Clustering Role & Flow selection

Similar presentations


Presentation on theme: "Clustering Role & Flow selection"— Presentation transcript:

1 Clustering Role & Flow selection
Roles below determined On a per flow basis Owner Receives first packet of flow Select director based on Hash ASA1 Flow 1 Hash = 2 [5 tuple] Owner Flow 1&2 Director Receives & backs up state Flow from Owner over CCL Director selected by HASH Director queried by others For owner of Flow, Does not Over flow Flow 2 Hash = 3 [5 tuple] Hash table Flow1 = ASA 2 ASA2 Flow2 = ASA 3 Director Flow 1 ASA3 Director Flow 2 Backup Director Both Owner & Director As a result of Hash Then second hash used ASA4 Forwarder Receives packet not owned Forwards to owner over CCL

2 ASA Like a Router on a stick
0/6 0/7 0/8 0/9 Port-Ch1 Port-Ch2 Port-Ch2.201 Vlan 201 out Port-Ch2.200 Vlan 200 in M0/0 ASA Like a Router on a stick 0/6 0/7 0/8 0/9 Port-Ch1 Port-Ch2 Port-Ch2.201 Vlan 201 out Port-Ch2.200 Vlan 200 in M0/0 Port-Ch4 Port-Ch1 VLAN 101 To Port-Ch1 VLAN 200 Port-Ch2 Trunk VLAN 101 To Port-Ch1 VLAN 201 Port-Ch3 Port-Ch4 to 2 VLAN 101 To Port-Ch1 Mang Vlan 0/6 0/7 0/8 0/9 Port-Ch1 Port-Ch2 Port-Ch2.201 Vlan 201 out Port-Ch2.200 Vlan 200 in M0/0

3 SPANNED EtherChannel Configuration
Notes: Channel-group 10 mode on On is recommended as no LACP chat SPANNED EtherChannel Configuration

4 PART 1 Clustering Lab Configuration (Switches Pre-configured) ASA
cluster interface-mode spanned ASA+1 ASA & ASA+1 boot system disk0:/asa941-smp-k8.bin asdm image disk0:/asdm-741.bin wr/reload hostname P1-P2-cluster ASA & ASA+1 Configure the CCL in interface gigabitethernet 0/2 channel-group 3 mode active !could be on therefore no LACP great for CCL no shutdown interface gigabitethernet 0/3 interface Port-channel3 description CCL show interface port-channel 3 The switch configuration for CCL shown in the notes is for reference only :-) ASA only. Configure the Management interface ip local pool mgmt interface Mangement 0/0 nameif management management-only security-level 0 ip address cluster-pool mgmt no shut The switch configuration for Mangement shown In the notes is for reference only :-) PART 1

5 PART 2 Clustering Lab Configuration (Switches Pre-configured)
ASA only Config the Inside & Outside Data Interfaces interface Gigabitethernet 0/0 channel-group 1 mode active no shut interface Gigabitethernet 0/1 channel-group 2 mode active interface Gigabitethernet 0/4 interface Gigabitethernet 0/5 interface Port-channel1 port-channel span-cluster mac-address aaaa.aaaa.1111 nameif outside security-level 0 ip address interface Port-channel2 mac-address aaaa.aaaa.2222 security-level 100 ip address The switch configuration for Data interface shown in the notes is for reference only  PART 2

6 PART 3 Clustering Lab Configuration (Switches Pre-configured)
Config bootstrap configs ASA/ASA+1 ASA cluster group training key c!sco!23 local-unit P1=ASA cluster-interface port-channel3 ip priority 1 ASA+1 local-unit P2=ASA cluster-interface port-channel3 ip priority 2 ASA Enable clustering enable ASA+1 Enable clustering enable as-slave ASA Verify and manage prompt hostname cluster-unit state show cluster interface-mode show cluster info show cluster info health cluster exec show port-channel summary show cluster cpu show cluster memory PART 3


Download ppt "Clustering Role & Flow selection"

Similar presentations


Ads by Google