Interface Ethernet redundancy

Hello

Is it possible to use HSRP/VRRP internal router if you want to have redundancy between two interfaces?

Our client has a router with two Ethernet interfaces.

This two interfaces are connected to two switches, there is also a cable between switches.

On the other side of the switch, there are two other connected routers.

The client will not use routing protocols to get the redundancy between the stand-alone router and two separate routers.

Need some ideas how we can solve this.

Niklas

Hi Niklas,

You can use IRB integrated Routing and bridging: HSRP won't work as well explained by Jon.

Bridge Protocol ieee 1

1 channel ip bridge

Bridge 1 ip

int eth0

no ip addr

Bridge-Group 1

int eth1

no ip addr

Bridge-Group 1

bv1 int

IP x.x.x.x

! This Layer 3 interface

Be aware that STP will block a link but it will be ready to be used if the first fails

You can use the static routes IP hops then the ip addresses of the VIP of the HSRP on the other two routers (on them you can they are two different boxes)

the other two routers will have static routes to the BVI IP as the next hop

Be aware that until a router has an ARP entry for the next stretch of the ip and its own interface is up to the static route is considered valid

Hope to help

Giuseppe

Tags: Cisco Network

Similar Questions

  • Card crypto on Interface Ethernet

    Hi all

    I don't have that much experience but with VPN configs, so maybe this question will seem a bit silly. I have a Cisco 831 that I use to connect via VPN to a remote site. Everything works fine.

    Then I wanted to add a second tunnel to another location. I did all the configs needed, applied card encryption on ethernet external and everything was fine, I could connect. But then I noticed that the new encryption card has actually replaced the existing one. Of course, the first VPN was no longer works.

    Is this a limitation of the 831? Or y at - it another way to configure them so I can use the two (or even more than two) at the same time? Do I need another Cisco router if I want more than a tunnel?

    Any help is appreciated.

    Thank you

    Stefan

    This isn't a limitation of the router. But by design,.

    only one crypto map set can be assigned to an interface. If multiple crypto map entries have the same name but a different seq - num map, they are considered as part of the same set, and all apply to the interface.

    So what you need to do is create crypto-map with the same name for slot 2, but give a different sequence number. Apply this encryption card to the interface and it will work. From the seq - num lowest crypto card is considered to be the highest priority, and will be evaluated first.

  • Downgrade from Windows 7 - driver interface (ethernet) NETWORK does not!

    I bought the HP Envy 15-j030us portable and QUICKLY retired the suicidal call error Microsoft Windows 8.  Everything is ok except my ethernet driver HP does not work.

    The driver has been installed but there is a problem of access to materials or loading the driver, idk.

    In Device Manager, it is recognized as a Realtek NIC but does not correctly install the software.  When it is plugged in, two activity lights are flashing but there is no evidence of a network.  The taskbar displays only the ORANGE icon wifi available.

    I am quite frustrated to Macrosoft to put me there already, can someone please help?

    http://h10025.www1.HP.com/ewfrf/wc/softwareCategory?product=5395205&LC=en&cc=us&DLC=en&lang=en&cc=us

    Hello:

    You should be able to use all of the drivers W7 64 bit of this professional HP laptop except the audio.

    http://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/psi/swdHome/?sp4ts.oid=5405424&spf_p.tpst=swdMain&spf_p.prp_swdMain=wsrp-navigationalState%3DswEnvOID%253D4058%257CswLang%253D%257Caction%253DlistDriver&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

    If for any reason the realtek LAN driver does not work since the link above, you can get it directly from realtek to l'adresse--deuxieme file on the list.

    http://www.Realtek.com.tw/downloads/downloadsView.aspx?langid=1&PNid=13&pfid=5&level=5&Conn=4&DownTypeID=3&GETDOWN=false

    Make sure you install the Intel Chipset Installation Utility driver first before moving on if you have not already done so.

  • This allows traffic between two interfaces ethernet on a PIX

    I have a PIX with interface inside, IP 10.198.16.1. It also has an interface called WTS, IP 10.12.60.1. I'm having difficulty to allow traffic from the 10.198.16.0 network to cross the PIX in 10.12.60.0. I'm trying specifically to allow access to a server with an IP address of 10.12.60.2.

    I enclose my config. Any help would be greatly appreciated!

    OK, so the inside interface has a security level of 100, WTS has a security level of 75, so traffic from inside to WTS is considered outbound traffic, which is allowed by default. All you need is a pair of nat/global (or static) between both interfaces so that the PIX knows how NAT traffic between two interfaces (remember, the PIX do NAT).

    You have this in your config file:

    NAT (inside) 1 10.0.0.0 255.0.0.0 0 0

    who says all traffic inside, interface with the IP 10.x.x.x address will be NAT would have, but you must then a global for the interface WTS define what those IPS will be NAT would.

    Adding:

    Global (WTS) 1 interface

    will be PAT all inside resolves the IP address of the interface WTS and allow traffic to flow between the interfaces. If you prefer the hosts inside the interface to appear as their own IP address on the WTS network, then you can use a static command and NAT addresses themselves, actually doing NAT, but not actually change addresses:

    static (inside, WTS) 10.198.16.1 10.198.16.1 netmask 255.255.240.0

    Hope that helps.

  • Difference between the series & ethernet interface.

    Hello world

    I have some doubts in basic foods.

    Q1: What are the differences between the interface series and interfaces ethernet.

    Q2: Can we use ethernet interfaces to put an end to a WAN connectivity like series. Why always we use interfaces series to connect the Wan.

    Please help me by answering these questions.

    !!!! THANKS IN ADVANCE!

    Hello

    Fast Ethernet card is one of the option for a higher speed T1/E1, other TDM options that can be offered are DS-3 and STM1 that can be offered on infra nominal basis as well. For example, you can subscribe for 10 MB BW on 45 MB access.

    The answer to your second question, is that there could be a possibility that you have subscribed for VPN (EVPL or VPLS) L2 or L3 VPN (MPLS).

    Woks of L2 VPN on labels VLAN and L3 VPN termiantes on a device of L3.

    concerning

    Navin Parwal

  • Redundant interface of ASA

    on the ASA5520 I set up 2 interface as redundant Interface behavior of these interfaces will be active and the other must stand up to that active fail or forced to change my Question is there a way to make these redundant Interface in active active state because everyone on to connect to the different Switch

    No, it isn't because by definition it is redundant.

    If they were two separate interfaces and they were both active while they needed to have different IPs IE. be in different subnets which is not what you want.

    The alternative is if the switches that connect you to a stack or 4500/6500 using VSS or Nexus with vPC, then you could create an etherchannel with the two ports and then they would all be active.

    Jon

  • Ethernet adapter does not

    I can't get the hang of lightning Gigabit Ethernet Adapter (MD463LL/A) working on my Macbook Pro 15 inch 2014 (11.2).

    When I plug the unit in each port thunderbolt I don't see anything on the screen. However, when I look in the section "Thunderbolt" in system information, I see the following:

    When I look in Network preferences, I don't see anything:

    And when I try to add a new network interface, ethernet Thunderbolt is not listed:

    I searched around for this problem, and some have recommended the removal of all interfaces, killing the networkpreferences plist and restart. I tried this, and it did not help.

    Also, I went back the dongle assuming that I just got a bad copy and bought a new one. The same problem.

    Any ideas would be very appreciated.

    Did you turn off wifi and move the Thunder bolt to the top of the list. Set to zero if necessary

  • Using the second ethernet port to connect to the printer?

    Hi I have a Mac Pro 2.1 old school and I'm wondering if I can connect to the network with an ethernet port and connect the latter to a printer?

    If so, how?

    Yosemite running.

    Thank you

    Physically, you use a port and a cable to connect to your network and use the second port and a second cable to connect directly to the printer. The printer must obviously have an interface Ethernet himself.

    However, you need to configure the second port on the Mac and the Ethernet port on the printer for each manually configured the TCP/IP addresses and these should be in a range of different network to your main network.

    If you the main network is something like 192.168.1.1 then your printer and the port on the Mac connection to this need to be in another network, such as 192.168.11.1.

    In theory, if the printer supports Hello aka. mDNS, then maybe you can get away with not having to configure TCP/IP addresses for the connection.

    The main reasons to use a second separate connection as this would be the performance or security, and frankly I don't think that's really relevant here. This would mean that no other computers on your network will be able to access the printer.

  • Satellite 1730 - need driver for ethernet card

    Hello. I need driver for Toshiba S1730 for Windows Me ethernet card. Ethernet card deactivated in the BIOS or by button? Interface Ethernet not serving in Windows

    Hello

    As much as I know this unit has no Ethernet card onboard and there is a reason why it cannot be determined by the OS. I'm sorry.

    Good bye

  • newbie on getting interface question web work 3424 and 3448 (remailers)

    Hello - I'm over sale of this announcement because the situation has changed.

    We are a church and we try to expand our network.  the requirements are to install a public thread-access point (WAP) on port E1 and E2-48 ports to be part of a community for the Church Office staff.

    We do not want anyone on the E1 - WAP to access what anyone at the Church Office.   I have a configuration below script that works very well to meet our requirements, but as soon as I run one of the following commands, I'm more able to access the unit via a Web page:

    whenever I run one of the following commands:

    Switchport mode private - vlan community
    switchport mode private vlan isolated

    I'm more able to use Web page interface.

    Here is the script I used to set up our unit 3448 so far:

    Enable
    Configure
    interface vlan 1
    IP address 192.168.0.250/24
    output
    Default IP gateway 192.168.0.1
    username admin password admin level 15
    database of VLAN
    VLAN 1000
    output
    interface vlan 1000
    private - vlan primary school
    private - vlan community add 10
    private - vlan isolated 20
    serial interface ethernet e2, e4
    e2-48 ethernet serial interface
    Switchport mode private - vlan community
    switchport private vlan community 10
    e1 ethernet interface
    switchport mode private vlan isolated
    switchport private - vlan isolated 1000
    g4 ethernet interface
    switchport mode private - vlan promiscuity
    switchport private - vlan 1000 promiscuity

    with this script, I can continue to ping from any port E2 by E48 and no port 1.  I am also unable to ping any other port than port E1 according to the needs.   but I still need to be able to access the web interface of * ANY * port.

    Yes, that sounds like a good plan to use teamviewer to access it remotely. On the other hand love IE, the switch was released in 2005.

  • Change the IP address of the external Interface

    I need to change the IP address of the external interface remotely.  I have SSH in to the ASA plan and make a change.  I can't be there to make this change, since the site is out of State.  There will be problems?  The current configuration is

    interface Ethernet0/0
    nameif outside
    security-level 0
    IP 66.102.7.22 255.255.255.248

    The new IP address will be 66.102.7.18 255.255.255.248.  Also, is this the right syntax?

    interface Ethernet 0/0

    no address ip 66.102.7.22 255.255.255.248

    IP 66.102.7.18 255.255.255.248

    Thank you.

    Diane

    Diane,

    If you access the ASA via its public IP address on the external interface, and if you change this IP address, you will lose communication with the ASA.

    It's better if you can make the change from the inside.

    If you need to change remotely, you can change the IP address, and then try the SSH connection to the new IP address.

    However if a problem occurs, you cannot access the ASA.

    The syntax is correct.

    Federico.

  • interface maximum pix 525

    Hi all

    a question about the PIX-525-UR, the brochure said two 10/100 Fast Ethernet on board and the support of the Gigabit Ethernet, up to eight 10/100 FE or three interfaces Ethernet Gigabit.

    http://www.Cisco.com/univercd/CC/TD/doc/product/iaabu/PIX/pix_sw/v_63/hig63/525.htm

    I understand that we got 3 PCI ports and 2 10/100 onboard, but research on the above page

    i've got on the Options of unrestricted Interface

    2 4 - port FE, which makes a total of 10 interface.

    How can it be possible? It allows to disable two interface?

    Then I saw on the forum that the 525 supports a GigE interface (but not at full speed) and that about 1 to 4 FE + 2 GE ports?

    What limitation?

    Thank you

    Patrizio

    Q. did you means 'You may 8 interfaces to the maximum on the 525 UR'? (10-total 2 off = 8)

    A. that's correct. A 525 UR lights only 8 interfaces in the software. If you add two 4 ports, the last 2 ports on the 2nd map cards will be disabled.

    Q. I wondering what kind of constraint on the interface, GigE, example not at full speed, what it means?

    A. GigE interface on the PIX runs at full rate. What is meant when people say that a 525 is not a true firewall in concert, it's that the 525 has a flow of about 330 MB/s max, which is clearer than a concert. The 535 is a true firewall in concert because it has a flow of more than 1000 MB/s.

    Two interfaces Gig is supported on the 525 and both support the full power of concert on the map. However, there will be delays in passing the packets to the CPU if the PIX is trying to pass more than 330 MB/s or more.

    Make a little more sense?

    Scott

  • Disable the HTTP/HTTPS on public Interface Management

    I was able to do this on a VPN 3030 using the Configuration 3.6.7.F code running > Policy Management > traffic management > filters, select 'Public', click "Assign rules to filter", delete In incoming and Out for HTTP and HTTPS, then Save Config. I don't get the same behavior when I apply the same changes to a VPN 3030 running 4.1.7.F as I am still able to show management on the public interface. I want to keep managing HTTPS on the private interface.

    Hello

    Take a look in the folder 'WebVPN' under ' Configuration. Interfaces | Ethernet 2'. There you should find the point "Sessions allow management HTTPS.

    HTH

    Mark

  • What are the bare minimum commands to get a stack of PC6825 3 - switch with inter switch Link Aggregation?

    I am brand new to PowerConnect switches, even though I am familiar with the concepts of VLANS, aggregation of links and spanning tree.

    I am on a deadline to get some new ones installed 6248 in our baskets and get them functioning as a stack. What are the bare minimum commands for:

    • Three switches in a stack (master/Eve/member)
    • 2 ports grouped between each (total redundancy) switch with loops WITHOUT switching

    All the switches are running firmware v3.3.9.1 (January 2014).

    Thank you

    The range of interface Ethernet 1/g1-1 / g2 allows you to select the ports you want in the channel of the port. Page 293

    Channel-group 1 Auto mode to create 440 lacp lag page

    Select the Group of channels with interface port-channel 1

    Switchport page 601 in trunk mode

    Switchport trunk allowed vlan [VLAN you use]

    http://FTP.Dell.com/manuals/all-products/esuprt_ser_stor_net/esuprt_powerconnect/PowerConnect-6248_Reference%20Guide_en-us.PDF

  • MTU problem with power connect 6224

    Hello

    I try to use 2 6224 switches QinQ purposes. The two switches are connected via links XG 2, for reasons of redundancy. The two switches are:

    interface ethernet 1/g11
    Auto mode channel-group 1
    «Cisco links» description
    output
    !
    interface ethernet 1/g12
    Auto mode channel-group 1
    «Cisco links» description
    output
    !
    interface ethernet 1/g13
    Auto mode channel-group 2
    output
    !
    interface ethernet 1/g14
    Auto mode channel-group 2
    output

    .....

    interface ethernet 1/xg1

    MTU 9216
    switchport mode trunk
    switchport trunk allowed vlan add 101 299
    switchport trunk allowed vlan remove 1
    dvlan-tunnel mode
    output
    !
    interface ethernet 1/xg2
    MTU 9216
    switchport mode trunk
    switchport trunk allowed vlan add 102
    switchport trunk allowed vlan remove 1
    dvlan-tunnel mode
    output

    The idea is to use ports 11-14 to connecto to cisco switches, which are configured in trunk mode:

    Po           xg             Po

    /--- |===|-----|===|---\

    Cisco | Reference Dell |       | Reference Dell |     Cisco

    \--- |===| ----|===|---/

    XG in. in.

    The two drivers communicate with each other through the vlan 666, which is sent by tunnel via VLAN 102 and 102 in 6224. Catalysts also use rapid-pvst to avoid loops. Cisco (s) I have ips 1.1.1.1 and 1.1.1.2. If I am controlled:

    Switch to size #ping 1.1.1.2 1496

    Type to abort escape sequence.
    Send 5, echoes ICMP 1496 bytes to 1.1.1.2, time-out is 2 seconds:
    !!!!!
    Success rate is 100 per cent (5/5), round-trip min/avg/max = 1/1/1 ms

    If I increase the packet size, it will not work:

    Switch to size #ping 1.1.1.2 1497

    Type to abort escape sequence.
    Send 5, echoes ICMP 1497 bytes to 1.1.1.2, time-out is 2 seconds:
    .....
    Success rate is 0% (0/5)

    If the catalysts are directly connected, it works. Also, I used other 6224 2 ports to connect 2 PCs with plu MTU, and it did not work, worked when the computers were connected directly.

    Version of Dell #show

    Descriptions of images

    Image1: default image
    Image2:

    Images currently available on Flash

    --------------------------------------------------------------------
    Unit image1 image2 current-next active
    --------------------------------------------------------------------

    1 2.1.0.13 2.0.0.12 image1 image1

    Image2 served before, I've updated to 2.1.0.13 only today, hoping that would solve the problem. Thank you in advence, I really hope to solve this "mystery".

    Message edited by alex.dragoi on 08/08/2008 16:49

Maybe you are looking for