OT: Cisco CSS Firewall LoadBalancing

From: twdaniel@xxxxxxxxxxxxx
Date: Fri Oct 26 2001 - 16:41:17 GMT-3


   
I have configured firewall loadbalancing using the Cisco CSS 11000 series switc
hes. Loadbalancing works perfectly with the CSS switches working in a primary a
nd backup mode using VRRP and static routes. I am trying use OSPF throughout t
he backbone. This also works correctly with the primary/backup CSS configuratio
n as shown. However, the convergence time can be over 20 secs. The backup CSS d
oes not intilize the Fastethernet Interfaces until it sees that the primary CSS
's interface has gone down. This delays the building of OSPF adjancies and incr
ease the convergence time. I would like to decrease this time by having the CSS
 operate in an ACTIVE/ACTIVE mode instead of an ACTIVE/PASSIVE mode. This would
 allow the both CSS switches to learn the OSPF routes and eliminate convergence
 time all together. Is this feasible??? Anyone else have any other ideas or com
ments. The firewalls are Nokia IP600 running Checkpoint. Thanks for your assist
ance.

http://www.cisco.com/warp/public/117/fw_load_balancing.html



This archive was generated by hypermail 2.1.4 : Thu Jun 20 2002 - 22:33:26 GMT-3