Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
oliver_gao36
Participant

Cisco port channel member is suspended

Jump to solution

Hi all,

Here we have a CP6200p NGFW, i set a bond group to connect with Cisco switch, below is the configurations on both Checkpoint & Cisco side.

Cisco:

interface Port-channel2
switchport access vlan 254
switchport mode access

interface TenGigabitEthernet1/0/11
switchport access vlan 254
switchport mode access
channel-protocol lacp
channel-group 2 mode active

interface TenGigabitEthernet2/0/11
switchport access vlan 254
switchport mode access
channel-protocol lacp
channel-group 2 mode active

 

Checkpoint:

 

CP_1.pngCP_2.pngCP_3.png

 

My question is: after setting, i found there is only one link member is active, is it normal? or are there anything that i setup wrong? please advise, thanks a lot.

CP_4.png

 

 

0 Kudos
Reply
1 Solution

Accepted Solutions
Timothy_Hall
Champion
Champion

Once a port goes into a suspended state due to a configuration mismatch, I don't believe it will try to recover on its own (kind of like errdisable).  It is possible a mismatch was detected when you were still setting things up, try a shut/no shut on Te1/0/11 and see what happens.  If it goes right back to a suspended state, do a show log which should have an error message showing the suspension reason.

"Max Capture: Know Your Packets" Video Series
now available at http://www.maxpowerfirewalls.com

View solution in original post

0 Kudos
Reply
5 Replies
mk1
Contributor

Hello Oliver,

Is there any particular reason to leave "Transmit Hash Policy" to Layer 2 instead of Layer 3+4? Could you also send the result from command: cat /proc/net/bonding/bond10

0 Kudos
Reply
oliver_gao36
Participant

Hi Nickel,

Actually no other particular reason, i just use the default settings in Advanced Option.

0 Kudos
Reply
oliver_gao36
Participant

Hi Nickel,

Thank you for your reply first.

In fact, we don't have any particular reason to set that, the screenshot above(Bond group advanced option) is the default settings when i configuring ether-channel on CP side.

0 Kudos
Reply
Timothy_Hall
Champion
Champion

Once a port goes into a suspended state due to a configuration mismatch, I don't believe it will try to recover on its own (kind of like errdisable).  It is possible a mismatch was detected when you were still setting things up, try a shut/no shut on Te1/0/11 and see what happens.  If it goes right back to a suspended state, do a show log which should have an error message showing the suspension reason.

"Max Capture: Know Your Packets" Video Series
now available at http://www.maxpowerfirewalls.com

View solution in original post

0 Kudos
Reply
oliver_gao36
Participant

Thank you very much Timothy_Hall, i tried your suggestion, and then the portchannel came back normally.

0 Kudos
Reply