I'm trying to migrate a Nokia-based Check Point firewall from connecting into multiple switch ports on a 4506 switch to using trunk ports over etherchannel.
I've configured four 10/100 ports over two blades on the switch to use Etherchannel, e.g:
interface Port-channel10 switchport switchport trunk encapsulation dot1q switchport mode trunk duplex full
interface FastEthernet5/39 switchport trunk encapsulation dot1q switchport mode trunk speed 100 duplex full no cdp enable channel-group 10 mode on
Interfaces 5/40, 6/39 & 6/40 have identical configuration to 5/39.
I've configured the Nokia to aggregate four 10/100 ports connected into the 4506 and configured a number of VLAN interfaces.
The 4506 connects into each of our core switches (6509s), which in turn connect into our four distribution switches (also 6509s) and finally into my access switches.
I'm experiencing a number of problems carrying out tasks on the Nokia over the new virtual interface (basic pings and web access work, but payloads over 1468 bytes time out, FTP transfers fail etc.) which suggested MTU problems. Having checked the Nokia docs it made a specific note of ensuring the switches support a MTU of 1504 bytes, so I made this change on the 4506 into which the Nokia connects; however the intermittent problems remain. When I check the interfaces linking the 4506 to the core switches, they show a MTU of 1500; however the
6509's will not let me configure a system-wide MTU of 1504 (it only lets me configure jumbo frames) or on the gigabit interfaces linking the 4506 (again, it only lets me configure a jumbo frame side). For reference, the 6509's are running IOS 12.1(13E11) and the 4506 is running IOS 12.2(25EWA1). Also for reference, this is the first device other than the switches themselves that have been configured as trunking ports (e.g. all other servers / routers connect into access ports).It definitely appears to be an issue only when the traffic passes through the core/distribution/access layers - when I connect a laptop directly into the same 4506 as the Nokia, it is able to connect without any problems.
I'd appreciate any thoughts!
Cheers, Chris