Wired Intelligent Edge

 View Only
last person joined: yesterday 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

Aruba Virtual Switch OS CX 8400 Dynamic Segmentation Possible?

This thread has been viewed 32 times
  • 1.  Aruba Virtual Switch OS CX 8400 Dynamic Segmentation Possible?

    Posted Sep 05, 2020 06:08 AM

    Hello

     

    Can i practice dynamic segmentation/Tunneled user node on virtual OS CX switch 8400? as i do not have 29xx switch at the moment .



  • 2.  RE: Aruba Virtual Switch OS CX 8400 Dynamic Segmentation Possible?

    MVP GURU
    Posted Sep 06, 2020 11:56 AM

    Hi,

     

    What do you mean by Virtual Switch OS CX ?

     

    the 8400 don't not supported Dynamic Segmentation (need to use 6300 or 6200)



  • 3.  RE: Aruba Virtual Switch OS CX 8400 Dynamic Segmentation Possible?

    Posted Sep 06, 2020 02:14 PM

    The virtual VM/OVA of Aruba OS CX , installed under ESXi for example , any chance it can run user profile/port based user / Dynamic segmentation? (cause i do not have access to real 29xxF/M switch)



  • 4.  RE: Aruba Virtual Switch OS CX 8400 Dynamic Segmentation Possible?

    EMPLOYEE
    Posted Sep 07, 2020 03:31 AM

    Hello,

    Unfortunately, dynamic segmentation (User Based Tunneling: switch to Mobility gateway) is not yet supported on the AOS-CX OVA.



  • 5.  RE: Aruba Virtual Switch OS CX 8400 Dynamic Segmentation Possible?

    MVP EXPERT
    Posted Dec 04, 2020 05:26 PM
    Should be awesome if this could be possible to practice for the new ACMX training. But thinks isn't easy to virtualize this.

    ------------------------------
    Marcel Koedijk | MVP Expert 2020 | ACMP | ACCP | Ekahau ECSE
    ------------------------------



  • 6.  RE: Aruba Virtual Switch OS CX 8400 Dynamic Segmentation Possible?

    Posted Dec 05, 2020 09:13 AM
    I'd love to have virtual AOS-CX too with EVPN/VXLAN + dynseg support. In the end you can already run VXLAN, EVPN, GRE tunnels whatnot on linux so this is not something that would require specific hardware or anything. CX is LInux based so I don't think it would be that hard to actually have the features that everyone really needs to lab with :)

    This is one reason where for example Arista shines, you can have the exactly same software running in a virtual switch and you can practice/lab huge scenarios. Their webinars are also awesome, and they had a really good point in one of their automation webinars: software guys can do test scenarios for everything in their software, networking guys just do "reload in 15" and then just pray their configs would work and they wouldn't lose connectivity :) If we had good enough virtualization environments with all the features we would be sure that the configs we're going to push are going to be fine as they were already tested in a lab environment.

    If we need to get hw for labbing to do something like EVPN/VXLAN between two DCs it will cost huge amounts of money to build even remotely something to simulate the setup. If we could just spin 50 switches in virtual machines we would be able to test all our configs before pushing it to production.


  • 7.  RE: Aruba Virtual Switch OS CX 8400 Dynamic Segmentation Possible?

    EMPLOYEE
    Posted Dec 07, 2020 03:00 AM
    Hi,

    Have a look into the release notes for the CX OVA image:

    VXLAN with EVPN is supported and working. I already tested. User or Port-based tunnels are not supported. But you can learn at least most of the VXLAN stuff. 


    ------------------------------
    Florian Baaske
    ------------------------------



  • 8.  RE: Aruba Virtual Switch OS CX 8400 Dynamic Segmentation Possible?

    EMPLOYEE
    Posted Dec 08, 2020 04:37 AM
    As Florian mentioned, there are already some key components for EVPN based VXLAN that work: 
    - L3 underlay (OSPF or BGP)
    - MP-BGP EVPN control-plane
    - pure L2VNI
    Aruba is very aware on these OVA limitations (no ECMP yet, no L3 VTEP yet, no L3VNI yet) and impact on self-training,
    but I would say that 80/90% of the EVPN learning being around control-plane, you can already do a lot with the existing OVA for learning EVPN and more. For UBT, this is different and this is not available yet.
    OVA is getting improved release after release, not at the pace we all would like, but this is not as straightforward as assumed in this forum.
    Thanks for exchanging on this topic as he OVA is a great tool to learn.

    ------------------------------
    Vincent Giles
    ------------------------------



  • 9.  RE: Aruba Virtual Switch OS CX 8400 Dynamic Segmentation Possible?

    MVP GURU
    Posted Dec 08, 2020 04:17 PM
    it is should nice to have also Captive Portal !

    ------------------------------
    PowerArubaSW : Powershell Module to use Aruba Switch API for Vlan, VlanPorts, LACP, LLDP...

    PowerArubaCP: Powershell Module to use ClearPass API (create NAD, Guest...)

    PowerArubaCX: Powershell Module to use ArubaCX API (get interface/vlan/ports info)..

    ACEP / ACMX #107 / ACDX #1281
    ------------------------------



  • 10.  RE: Aruba Virtual Switch OS CX 8400 Dynamic Segmentation Possible?

    EMPLOYEE
    Posted Dec 09, 2020 04:52 AM
    Indeed, and more. Progressing release after release...

    ------------------------------
    Vincent Giles
    ------------------------------