> don't understand why 9100 as MTU, I would have used 9198 instead in every interface
me either, just working down the study guide labs and they have you set those that way :p I agree the value is odd...
> there is a discrepancy about permitted VLANs
agreed :) I'd never use an allow all in production, but they are big on not pruning in the study guide ;)
It is very possible that it's something in eve, it was just very odd that it manifested like this
As to the requests:
Core-2 Config:
Current configuration:
!
!Version ArubaOS-CX Virtual.10.06.0001
!export-password: default
hostname ICX-T1-Core-2
user admin group administrators password ciphertext AQBapSQBB2dn5FuH5eRuT0V2gECncjlnn
8sN7cl7kY+1U0xcYgAAAPm7vxpZKQZqFiLNEP4GttzmQZbDhyxdKVGU4h50B23js6PYJwiKCyLUfV1UPofxC0
/GpTSmwaRWMlqLcn7M/yRLfHmmN0Gy8H/d+n0Ys7ljyXiswHhDhFZ4SvKg2Riudw4m
led locator on
clock timezone us/eastern
vrf ka
ntp server 10.253.1.15 iburst prefer
ntp server pool.ntp.org minpoll 4 maxpoll 4 iburst
ntp enable
ntp vrf mgmt
cli-session
timeout 43200
!
!
!
!
ssh server vrf mgmt
vlan 1
vlan 11
vsx-sync
vlan 12
vsx-sync
vlan 13
vsx-sync
interface mgmt
no shutdown
ip static 10.251.1.3/24
default-gateway 10.251.1.254
interface lag 1 multi-chassis
no shutdown
description access-1
no routing
vlan trunk native 1
vlan trunk allowed 1,11-13
lacp mode active
lacp rate fast
interface lag 2 multi-chassis
no shutdown
description access-2
no routing
vlan trunk native 1
vlan trunk allowed 1,11-13
lacp mode active
interface lag 256
no shutdown
no routing
vlan trunk native 1 tag
vlan trunk allowed all
lacp mode active
interface 1/1/1
no shutdown
mtu 9100
description access-1
lag 1
interface 1/1/2
no shutdown
mtu 9100
description access-2
lag 2
interface 1/1/7
no shutdown
mtu 9198
lag 256
interface 1/1/8
no shutdown
mtu 9198
lag 256
interface 1/1/9
no shutdown
vrf attach ka
ip address 192.168.0.1/31
interface vlan 1
vsx-sync active-gateways policies
ip address 10.1.1.3/24
active-gateway ip mac 02:02:00:00:01:00
active-gateway ip 10.1.1.1
interface vlan 11
vsx-sync active-gateways policies
ip address 10.1.11.3/24
active-gateway ip mac 02:02:00:00:01:00
active-gateway ip 10.1.11.1
ip helper-address 10.1.1.6
l3-counters
interface vlan 12
vsx-sync active-gateways policies
ip address 10.1.12.3/24
active-gateway ip mac 02:02:00:00:01:00
active-gateway ip 10.1.12.1
ip helper-address 10.1.1.6
l3-counters
vsx
system-mac 02:01:00:00:01:00
inter-switch-link lag 256
role secondary
keepalive peer 192.168.0.0 source 192.168.0.1 vrf ka
vsx-sync aaa bfd-global bgp dhcp-relay mclag-interfaces ospf qos-global route-map
vsx-global
ip dns server-address 10.251.1.21 vrf mgmt
!
!
!
!
!
https-server vrf default
https-server vrf mgmt
ICX-T1-Core-2#
What's the outputs of show vsx status and show vsx brief commands executed on VSX node 1 and/or VSX node 2?
ICX-T1-Core-1# show vsx status
VSX Operational State
---------------------
ISL channel : In-Sync
ISL mgmt channel : operational
Config Sync Status : In-Sync
NAE : peer_reachable
HTTPS Server : peer_reachable
Attribute Local Peer
------------ -------- --------
ISL link lag256 lag256
ISL version 2 2
System MAC 02:01:00:00:01:00 02:01:00:00:01:00
Platform X86-64 X86-64
Software Version Virtual.10.06.0001 Virtual.10.06.0001
Device Role primary secondary
ICX-T1-Core-1# show vsx brief
ISL State : In-Sync
Device State : Peer-Established
Keepalive State : Keepalive-Established
Device Role : Primary
Number of Multi-chassis LAG interfaces : 2
ICX-T1-Core-1#
What's the outputs of show lacp aggregates lag1 and show lacp aggregates lag1 vsx-peer commands both executed on VSX node 1?
ICX-T1-Core-1# show lacp aggregates lag1
Aggregate name : lag1 (multi-chassis)
Interfaces : 1/1/1
Peer interfaces : 1/1/1
Heartbeat rate : Fast
Hash : l3-src-dst
Aggregate mode : Active
ICX-T1-Core-1# show lacp aggregates lag1 vsx-peer
Aggregate name : lag1 (multi-chassis)
Interfaces : 1/1/1
Peer interfaces : 1/1/1
Heartbeat rate : Fast
Hash : l3-src-dst
Aggregate mode : Active
ICX-T1-Core-1#
What's the outputs of show lacp interfaces and show lacp interfaces vsx-peer commands both executed on VSX node 1?
ICX-T1-Core-1# show lacp interfaces
State abbreviations :
A - Active P - Passive F - Aggregable I - Individual
S - Short-timeout L - Long-timeout N - InSync O - OutofSync
C - Collecting D - Distributing
X - State m/c expired E - Default neighbor state
Actor details of all interfaces:
----------------------------------------------------------------------------------
Intf Aggr Port Port State System-ID System Aggr Forwarding
Name Id Pri Pri Key State
----------------------------------------------------------------------------------
1/1/1 lag1(mc) 1 1 ASFOE 02:01:00:00:01:00 65534 1 lacp-block
1/1/2 lag2(mc) 2 1 ALFOE 02:01:00:00:01:00 65534 2 lacp-block
1/1/7 lag256 8 1 ALFNCD 08:00:09:d0:51:08 65534 256 up
1/1/8 lag256 9 1 ALFNCD 08:00:09:d0:51:08 65534 256 up
Partner details of all interfaces:
----------------------------------------------------------------------------------
Intf Aggr Port Port State System-ID System Aggr
Name Id Pri Pri Key
----------------------------------------------------------------------------------
1/1/1 lag1(mc) 0 65534 PLFOEX 00:00:00:00:00:00 65534 0
1/1/2 lag2(mc) 0 65534 PLFOEX 00:00:00:00:00:00 65534 0
1/1/7 lag256 8 1 ALFNCD 08:00:09:6a:b9:73 65534 256
1/1/8 lag256 9 1 ALFNCD 08:00:09:6a:b9:73 65534 256
ICX-T1-Core-1#
ICX-T1-Core-1# show lacp interfaces vsx-peer
State abbreviations :
A - Active P - Passive F - Aggregable I - Individual
S - Short-timeout L - Long-timeout N - InSync O - OutofSync
C - Collecting D - Distributing
X - State m/c expired E - Default neighbor state
Actor details of all interfaces:
----------------------------------------------------------------------------------
Intf Aggr Port Port State System-ID System Aggr Forwarding
Name Id Pri Pri Key State
----------------------------------------------------------------------------------
1/1/1 lag1(mc) 1001 1 ASFOE 02:01:00:00:01:00 65534 1 lacp-block
1/1/2 lag2(mc) 1002 1 ALFOE 02:01:00:00:01:00 65534 2 lacp-block
1/1/7 lag256 8 1 ALFNCD 08:00:09:6a:b9:73 65534 256 up
1/1/8 lag256 9 1 ALFNCD 08:00:09:6a:b9:73 65534 256 up
Partner details of all interfaces:
----------------------------------------------------------------------------------
Intf Aggr Port Port State System-ID System Aggr
Name Id Pri Pri Key
----------------------------------------------------------------------------------
1/1/1 lag1(mc) 0 65534 PLFOEX 00:00:00:00:00:00 65534 0
1/1/2 lag2(mc) 0 65534 PLFOEX 00:00:00:00:00:00 65534 0
1/1/7 lag256 8 1 ALFNCD 08:00:09:d0:51:08 65534 256
1/1/8 lag256 9 1 ALFNCD 08:00:09:d0:51:08 65534 256
What's the outputs of show lacp interfaces 1/1/1 and show lacp interfaces 1/1/1 vsx-peer commands both executed on VSX node 1?
ICX-T1-Core-1# show lacp interfaces 1/1/1
State abbreviations :
A - Active P - Passive F - Aggregable I - Individual
S - Short-timeout L - Long-timeout N - InSync O - OutofSync
C - Collecting D - Distributing
X - State m/c expired E - Default neighbor state
Aggregate-name : lag1(multi-chassis)
-------------------------------------------------
Actor Partner
-------------------------------------------------
Port-id | 1 | 0
Port-priority | 1 | 65534
Key | 1 | 0
State | ASFOE | PLFOEX
System-ID | 02:01:00:00:01:00 | 00:00:00:00:00:00
System-priority | 65534 | 65534
ICX-T1-Core-1# show lacp interfaces 1/1/1 vsx-peer
State abbreviations :
A - Active P - Passive F - Aggregable I - Individual
S - Short-timeout L - Long-timeout N - InSync O - OutofSync
C - Collecting D - Distributing
X - State m/c expired E - Default neighbor state
Aggregate-name : lag1(multi-chassis)
-------------------------------------------------
Actor Partner
-------------------------------------------------
Port-id | 1001 | 0
Port-priority | 1 | 65534
Key | 1 | 0
State | ASFOE | PLFOEX
System-ID | 02:01:00:00:01:00 | 00:00:00:00:00:00
System-priority | 65534 | 65534
ICX-T1-Core-1#
What's the outputs of show lacp aggregates lag255 command executed on Access-1 Switch?
CX-T1-Access-1# show lacp aggregates lag255
Aggregate name : lag255
Interfaces : 1/1/9 1/1/8
Heartbeat rate : Fast
Hash : l3-src-dst
Aggregate mode : Active
ICX-T1-Access-1#
------------------------------
Allyn Crowe
------------------------------
Original Message:
Sent: Mar 03, 2021 04:58 PM
From: Davide Poletto
Subject: Aruba CX in EVE-NG VSX LAG: lacp blocking
Hello Allyn - apparently (I see VSX node 1 configuration only, VSX node 2 configuration lacks) - it looks correct (don't understand why 9100 as MTU, I would have used 9198 instead in every interface and I don't understand why between the VSX LAG lag1 configured on VSX switch(es) and non-VSX LAG lag255 configured on Access switch there is a discrepancy about permitted VLANs...allowed "1, 11-13" VSX side versus allowed "All" Access side...but, after all, this discrepancy shouldn't be too important here).
Could you show us the VSX node 2's configuration too?
What's the outputs of show vsx status and show vsx brief commands executed on VSX node 1 and/or VSX node 2?
What's the outputs of show lacp aggregates lag1 and show lacp aggregates lag1 vsx-peer commands both executed on VSX node 1?
What's the outputs of show lacp interfaces and show lacp interfaces vsx-peer commands both executed on VSX node 1?
What's the outputs of show lacp interfaces 1/1/1 and show lacp interfaces 1/1/1 vsx-peer commands both executed on VSX node 1?
What's the outputs of show lacp aggregates lag255 command executed on Access-1 Switch?
It looks like there is something wrong in the way lag255 is connected to (VSX) lag1 on VSX node 1 and VSX node 2 (assuming VSX is OK).
It's totally possible that - if this design is virtualized (OVA) as a Lab scenario - some feature could not work exactly as one expects.
------------------------------
Davide Poletto
Original Message:
Sent: Mar 03, 2021 01:18 PM
From: Allyn Crowe
Subject: Aruba CX in EVE-NG VSX LAG: lacp blocking
I'm working through the ACSP study guide labs using EVE-NG and running into what seems like a basic issue in the VSX lab.
Here's the lab topology:
Configs:
Core Side:
ICX-T1-Core-1# show running-config Current configuration:!!Version ArubaOS-CX Virtual.10.06.0001!export-password: defaulthostname ICX-T1-Core-1user admin group administrators password ciphertext AQBapSQBB2dn5FuH5eRuT0V2gECncjlnn8sN7cl7kY+1U0xcYgAAAPm7vxpZKQZqFiLNEP4GttzmQZbDhyxdKVGU4h50B23js6PYJwiKCyLUfV1UPofxC0/GpTSmwaRWMlqLcn7M/yRLfHmmN0Gy8H/d+n0Ys7ljyXiswHhDhFZ4SvKg2Riudw4mled locator onclock timezone us/easternvrf kantp server 10.253.1.15 iburst preferntp server pool.ntp.org minpoll 4 maxpoll 4 iburstntp enablentp vrf mgmtcli-session timeout 43200!!!!ssh server vrf mgmtvlan 1vlan 11 vsx-syncvlan 12 vsx-syncvlan 13 vsx-syncinterface mgmt no shutdown ip static 10.251.1.2/24 default-gateway 10.251.1.254interface lag 1 multi-chassis no shutdown description access-1 no routing vlan trunk native 1 vlan trunk allowed 1,11-13 lacp mode active lacp rate fastinterface lag 2 multi-chassis no shutdown description access-2 no routing vlan trunk native 1 vlan trunk allowed 1,11-13 lacp mode activeinterface lag 256 no shutdown no routing vlan trunk native 1 tag vlan trunk allowed all lacp mode activeinterface 1/1/1 no shutdown mtu 9100 description access-1 lag 1interface 1/1/2 no shutdown mtu 9100 description access-2 lag 2interface 1/1/7 no shutdown mtu 9198 lag 256interface 1/1/8 no shutdown mtu 9198 lag 256 interface 1/1/9 no shutdown vrf attach ka ip address 192.168.0.0/31interface vlan 1 vsx-sync active-gateways policies ip address 10.1.1.2/24 active-gateway ip mac 02:02:00:00:01:00 active-gateway ip 10.1.1.1interface vlan 11 vsx-sync active-gateways policies ip address 10.1.11.2/24 active-gateway ip mac 02:02:00:00:01:00 active-gateway ip 10.1.11.1 ip helper-address 10.1.1.6 l3-countersinterface vlan 12 vsx-sync active-gateways policies ip address 10.1.12.2/24 active-gateway ip mac 02:02:00:00:01:00 active-gateway ip 10.1.12.1 ip helper-address 10.1.1.6 l3-counters vsx system-mac 02:01:00:00:01:00 inter-switch-link lag 256 role primary keepalive peer 192.168.0.1 source 192.168.0.0 vrf ka vsx-sync aaa bfd-global bgp dhcp-relay mclag-interfaces ospf qos-global route-map vsx-globalip dns server-address 10.251.1.21 vrf mgmt!!!!!https-server vrf defaulthttps-server vrf mgmtICX-T1-Core-1#
Access:
ICX-T1-Access-1# show running-config Current configuration:!!Version ArubaOS-CX Virtual.10.06.0001!export-password: defaulthostname ICX-T1-Access-1user admin group administrators password ciphertext AQBapVP2a2ANo/d9wJvFUud2H0kW1I/MZb9b7sRdveQ1D1EAYgAAAKHS5OWKFDAqlM/T8Qs9HehJmSAed4LdgUkga1Rrn+s3aEQ6+ODO5RB8jgNCWpka6eq7oM1cUIiKa0MI/AxgPbvcG/pIFKzEUg0dIbI3YuY+dFXNFBlhnATph689FZQ+wGAUled locator onclock timezone us/easternntp server 10.253.1.15 iburst preferntp server pool.ntp.org minpoll 4 maxpoll 4 iburstntp enablentp vrf mgmtcli-session timeout 43200!!!!ssh server vrf mgmtvlan 1,11-13interface mgmt no shutdown ip static 10.251.1.4/24 default-gateway 10.251.1.254 interface lag 255 no shutdown description core no routing vlan trunk native 1 vlan trunk allowed all lacp mode active lacp rate fastinterface 1/1/8 no shutdown mtu 9100 lag 255interface 1/1/9 no shutdown mtu 9100 lag 255ip dns server-address 10.251.1.21 vrf mgmt!!!!!https-server vrf mgmt ICX-T1-Access-1#
Any help or ideas would be appreciated. :)
------------------------------
Allyn Crowe
------------------------------