[c-nsp] IOS Firewall sessions

Phil Mayers p.mayers at imperial.ac.uk
Mon May 29 11:28:59 EDT 2006


Joe Maimon wrote:
> 
> Gert Doering wrote:
> 
>> Hi,
> 
>> Or did I miss the long-asked-for feature that will remove the "connected"
>> router for HSRP passive interfaces (to enforce symmetric routing)? 
> 

+1

"standby track spanning-tree-root" would be another handy feature.

> That one has my vote. I dont know any vendors who get this right.

Really? Extreme ESRP and Foundry VSRP both provide it. Certainly I've 
not seen anyone who provides it for VRRP but I don't think that's a 
surprise.

For info ESRP and VSRP both use layer2 hellos to put the entire vlan 
including the layer3 interface into active or standby. This has some 
other nice properties that allow you to avoid running STP if the network 
goes to multiple downstream layer2 switches.

Though they're obviously just as proprietary as HSRP, ESRP and VSRP are 
far more useful in many problem domains I've come across.


More information about the cisco-nsp mailing list