{"id":884,"date":"2014-11-13T12:33:50","date_gmt":"2014-11-13T12:33:50","guid":{"rendered":"https:\/\/fir3netwp.gmsrrpobkbd.com\/2014\/11\/13\/configuring-etherchannel-on-an-asa-firewall\/"},"modified":"2021-08-01T00:25:34","modified_gmt":"2021-08-01T00:25:34","slug":"configuring-etherchannel-on-an-asa-firewall","status":"publish","type":"post","link":"https:\/\/www.fir3net.com\/Firewalls\/Cisco\/configuring-etherchannel-on-an-asa-firewall.html","title":{"rendered":"Configuring EtherChannel on an ASA Firewall"},"content":{"rendered":"
The ability to configure EtherChannels on ASA models 5510 and above was introduced within 8.4\/8.6. An Etherchannel provides a method of aggregating multiple Ethernet links into a single logical channel. Within this article we will provide the steps required to create an Etherchannel link on the Cisco ASA along with providing the main troubleshooting\/show commands.<\/p>\n Below shows the configuration to create am EtherChannel that will act as a trunk with the VLAN 1000 enabled.<\/p>\n By default when you configure a port channel the\u00a0 port channel will remain up as long as there is one active member interface. Meaning that even if you are monitoring the port-channel if a single link goes down within the bundle it will not trigger a device-level failover.<\/p>\n To ensure a device-level failover occurs in the event of a single member link failure the port-channel min-bundle<\/span> command is used. Below shows the necessary commands,<\/p>\n Note : the command monitor-interface only allows you to monitor interfaces that have been configured with nameif. i.e so you can only monitor the portchannel interface rather then each of the member links.<\/p>\n Below shows 2 of the main show commands,<\/p>\n The ability to configure EtherChannels on ASA models 5510 and above was introduced within 8.4\/8.6. An Etherchannel provides a method of aggregating multiple Ethernet links into a single logical channel. Within this article we will provide the steps required to create an Etherchannel link on the Cisco ASA along with providing the main troubleshooting\/show commands. … Read more<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[],"yoast_head":"\n
\n<\/span><\/p>\nConfiguration<\/h2>\n
interface GigabitEthernet0\/1\r\n\u00a0 speed 1000\r\n\u00a0 duplex full\r\n\u00a0 <\/strong>channel-group 1 mode active\r\n\u00a0 no nameif\r\n\u00a0 no security-level\r\n\u00a0 no ip address\r\n\r\ninterface GigabitEthernet0\/2\r\n\u00a0 speed 1000\r\n\u00a0 duplex full\r\n\u00a0 channel-group 1 mode active\r\n\u00a0 no nameif\r\n\u00a0 no security-level\r\n\u00a0 no ip address\r\n\r\ninterface Port-channel1.1000\r\n\u00a0 vlan 1000\r\n\u00a0 nameif INSIDE\r\n\u00a0 security-level 100\r\n\u00a0 ip address 172.16.1.1 255.255.255.0<\/pre>\n
HA<\/h2>\n
monitor-interface port-channel 1.1000\r\n interface port-channel 1.1000 port-channel min-bundle 2<\/pre>\n
Show Commands<\/h2>\n
asa\/pri\/act# sh interface port-channel 1<\/strong>\r\nInterface Port-channel1 \"\", is up, line protocol is up\r\n\u00a0 Hardware is EtherChannel\/LACP, BW 2000 Mbps, DLY 10 usec\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Full-Duplex(Full-duplex), 1000 Mbps(1000 Mbps)\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Input flow control is unsupported, output flow control is off\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Available but not configured via nameif\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 MAC address 1c6a.7ac1.3db9, MTU not set\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 IP address unassigned\r\n\u00a0 Members in this channel:\r\n\u00a0\u00a0\u00a0\u00a0\u00a0 Active:\u00a0\u00a0 Gi0\/1 Gi0\/2\r\n \r\nasa\/pri\/act# sh port-channel 1<\/strong>\r\nPorts: 2\u00a0\u00a0 Maxports = 16\r\nPort-channels: 2 Max Port-channels = 48\r\nProtocol: LACP\/ active\r\nMinimum Links: 1\r\nMaximum Bundle: 8\r\nLoad balance: src-dst-ip<\/pre>\n","protected":false},"excerpt":{"rendered":"