Thursday, February 25, 2021

Firepower 4110 Cluster - Once device shows it's Port-channels and associated interfaces as down

I've been assigned a issue that seems to be baffling me and I'm hoping someone has experienced the issue. I'm fairly new to Cisco Firepower devices.

I have 2 x FP4110's in a cluster, FTD1 and FTD2. The cluster is operational, which I can see in the Diagnostics out in the GUI.

  • 2 x Port-channels are configured, in additional to the Cluster Port-Channel.
  • Port Channel 3 is using Eth1/1 and Eth1/2
  • Port-Channel 2 is using Eth1/3 and Eth1/4

On FTD1...

  • Both PO2 and PO3 are down showing no operational members.
  • Each of the associated interfaces belonging to the respective Port-Channels are showing down (suspended(no LACP PDU)).

On FTD2...

  • Both PO2 and PO3 and all associated interfaces are up and fully operational.

On FTD1, I noticed in both PO2 and PO3 Port-Channel configs, the following config line...

lacp cluster-detach

Other than that line, the configs for each of the port-channels is identical. I'm leaning toward this being the issue, but I also have the questions of how did it get this way and how to resolve it. I don't see anything in the logs.

My searches turned up limited results for this config line, only finding reference in release notes referring to the CCL PO48 and it going into this mode after an upgrade.

Both FTD1 and FTD2 have been up for over 800+ days, and no upgrades have been performed.

To resolve the issue, can I simply run "no lacp cluster detach" under the Port-Channel interface config?

On top of the issue, the device is located in the UK and I'm managing it remotely from Los Angeles.

Has anyone seen this before or have any ideas what may be causing this issue?

Thank you in advance! Your assistance and expertise is appreciated.



No comments:

Post a Comment