Wireless Access

 View Only
last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Removing port-channel allowed VLAN override

This thread has been viewed 17 times
  • 1.  Removing port-channel allowed VLAN override

    Posted Nov 08, 2023 03:02 AM

    Hello,

    We have a (currently) single controller overflow 'cluster', but that's due to grow soon. When it was configured the allowed VLANs list on the port-channel for it was configured at box level, but really that should have been configured at the level above. I can't see an easy 'remove override' option for that list of VLANs. What do I need to do to remove the config from box level and have the higher level config sync'd instead? Bearing in mind this is a live system so we're looking to try to do this with no downtime.

    Thank you

    Guy 



  • 2.  RE: Removing port-channel allowed VLAN override

    EMPLOYEE
    Posted Nov 08, 2023 10:04 AM

    What version of AOS are you referring to?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: Removing port-channel allowed VLAN override

    Posted Nov 08, 2023 10:09 AM

    Hello Carson,

     

    We're running 8.10.0.8. Cluster of 10 controllers (standby cluster of 4). MCR and standby MCR.

     

    Guy






  • 4.  RE: Removing port-channel allowed VLAN override

    EMPLOYEE
    Posted Nov 08, 2023 10:16 AM

    During a maintenance period, set the VLAN configuration back to default at the device level ("show configuration committed" at the device level will show the current device configuration) and then configure the appropriate VLAN settings at the group level.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: Removing port-channel allowed VLAN override

    Posted Nov 08, 2023 10:31 AM

    Hello Carson,

     

    This port-channel includes our management VLAN, when you say 'default' would I just remove all other VLANs from the PC apart from the mgmt VLAN? Or is there actually a command which will default this PC to the original config created when the box was set-up (which should include the mgmt. VLAN)?

     

    Note that the PC config we want is already present at the higher group level, I don't know if this helps or hinders!






  • 6.  RE: Removing port-channel allowed VLAN override

    EMPLOYEE
    Posted Nov 08, 2023 10:42 AM

    To be honest, dealing with a port channel configuration is a royal pain.  I find it easier to just make a temporary connection on a different port for management purposes, delete the port-channel configuration from the device, then set things up as they should be.  This assumes you didn't configure the port-channel during the system setup script, then I just blow the controller away and start over, and don't configure the port-channel until after managing the MC through the MCR.

    As for setting back to default, you should be able to issue a "no switchport trunk allowed vlan" at the device level which will remove the device level configuration, allowing for the group level configuration to be inherited.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 7.  RE: Removing port-channel allowed VLAN override

    Posted Nov 09, 2023 09:36 AM

    Okay thanks Carson, we'll look at how we can deal with this, I guess out of term time. I can practice on our dev system to see how badly I break things!