Showing posts with label LAN. Show all posts
Showing posts with label LAN. Show all posts

Radia Perlman Talk on TRILL and Spanning Tree

Radia Perlman
I found this YouTube Google Tech Talks presentation by Radia Perlman. She is often referred to as the "Mother of the Internet". She invented the spanning tree algorithm. She also invented concepts that made "link state routing" stable, scalable, and easy to manage. The protocol was adopted and renamed IS-IS. She is credited as creating the original concept of TRILL.

Her presentation is titled "Routing Without Tears; Bridging Without Danger". She discusses the creation of spanning tree, link state routing protocols and finally TRILL or Transparent Interconnection of Lots of Links. Those of of working with network infrastructure and Cloud Computing can really appreciate everything she has done.




Cisco Configuration Tip - 3rd Party SFP Modules

Network Engineer's Assistant New Haircut
It is possible to use non-Cisco SPF modules in a Cisco Catalyst switch. By default this is forbidden not allowed, but a top secret hidden command can make this happen.

switch(config)#service unsupported-transceiver
switch(config)#no errdisable detect cause gbic-invalid


In the SFP modules EEPROM, a Serial Number, Vendor Name & ID, Security code and a CRC. The switch reads these values and if they are not "Cisco" values reports an error such as:


%PHY-4-UNSUPPORTED_TRANSCEIVER: Unsupported transceiver found in Gi1/0/1
%GBIC_SECURITY_CRYPT-4-VN_DATA_CRC_ERROR: GBIC in port 65538 has bad crc


The official position from Cisco is:
Q. Do the Cisco Catalyst 3750 Series Switches interoperate with SFPs from other vendors?
A. Yes, starting from 12.2(25)SE release, the user has the option via CLI to turn on the support for 3rd party SFPs. However, the Cisco TAC will not support such 3rd party SFPs. In the event of any link error involving such 3rd party SFPs the customer will have to replace 3rd party SFPs with Cisco SFPs before any troubleshooting can be done by TAC.


Cisco Press eBook Deal of the Day
234X60


Configuration Tricks - Catalyst 4900M with CVR-X2-SFP and 1Gb SFP


Cisco Catalyst 4900M

The Cisco Catalyst 4900M is a high performance, low latency, layer-3 switch suitable for Top of Rack 10Gb link aggregation or small data centers server connectivity. eWeek testing validated 320 Gbps throughput, or 16 10G ports running at full line speed with latency of ~2.6 microseconds.

The 4900M chassis includes 8 fixed wire-speed X2 ports. Two half-card module slots can be added for additional ports. Supported modules available are:
  • WS-X4920-GB-RJ45 - 20 port 10/100/1000 RJ45
  • WS-X4904-10GE - 4 port wire speed 10GE (X2)
  • WS-X4908-10GE - 8 PORT 2:1 over subscription 10GE (X2)
  • WS-X4908-10G-RJ45 -  8 PORT 2:1 over subscription 10GbaseT
I recently had a situation were we deployed a Catalyst 4900M with the WS-X4920-GB-RJ45 and WS-X4908-10GE modules. The switch needed to connect a 1GB metro Ethernet circuit. No problem, with the 20 port 10/100/1000 module we had it covered...So I thought.



Network Engineer #SMH
#SMH
The service provider handed off 1GB multi-mode fiber.









How Do I Connect 1GB Multi-Mode Fiber To This Thing?

Cisco 4900M 8port 10Gb Module
WS-X4908-10GE
The WS-X4908-10GE offers 8 10GE ports at a 2:1 over subscribed ratio. A feature of this card is the ability to convert 10GB ports to dual-1GB ports with SFP transceivers.



CVR-X2-SFP
CVR-X2-SF

The CVR-X2-SFP Cisco TwinGig Converter is installed into an X2 port and 2 SFPs are plugged into the TwinGig






(Note: The CVR-X2-SFP10G can be used to convert a 10GB X2 port into a 10GB SFP+ port)


Pre-Sales - Cisco Dynamic Configuration Tool
The first step happens in the sales process. Using the Cisco Configuration tool, you choose the WS-X4908-10GE module.

Second, click the "+" next to the 4908 part number, click the "+" next to the Port Group 1, click "SFP options" then choose the GLC part needed.

Now you can't see it, but this adds the CVR-X2-SFP TwinGig Converter Module.

Using this method, the CVR-X2-SFP is included at no-cost. Otherwise the converter sells for $195 list price.

Installation - Good 'ol CLI
The half-card slot the WS-X4908-10GE is divided into 4 port-groups. 8 ports divided by 4 port groups = 2 ports per group. A command is required to convert a port-group into 1GB ports. Since an entire port-group is converted, two of the X2 ports are switched to 1GB.

The Catalyst 4900M is based on the Catalyst 4500 family of switches. the 4900M carries over the configuration concept of modules. Module 1 is the fixed 8 ports of 10GB, module 2 is the top left slot, and module 3 is the top right slot.

To see the current port-group can be seen with:


4900# show hw-module module 3 port-group
Module Port-group Active                         Inactive
-------------------------------------------------------------
   3        1     Te3/1-2                        Gi3/9-12
   3        2     Te3/3-4                        Gi3/13-16
   3        3     Te3/5-6                        Gi3/17-20
   3        4     Te3/7-8                   Gi3/21-24


To change the configuration the command is:
4900(config)# hw-module module 3 port-group 4 select gigabitethernet

Verify the configuration with:


4900# show hw-module module 3 port-group
Module Port-group Active                         Inactive
-------------------------------------------------------------
   3        1     Te3/1-2                        Gi3/9-12
   3        2     Te3/3-4                        Gi3/13-16
   3        3     Te3/5-6                        Gi3/17-20
   3        4     Gi3/21-24                      Te3/7-8

Next a reboot is required.

We ran into a small caveat. We created interfaces G3/23 and G3/24, connected the 1GB SFP into G3/24 but the interface would not connect. We had to move the 1GB SFP to interface G3/23.




Home

The IT Conflict: The Network vs. Users. Part 1


We can all agree, working in IT has its challenges. A friend recently asked me "What has been the most significant challenges in IT recently?"

To that I say "how much time do you have?"

Over the years we have seen many technology innovations.  Some have been business focused while others have been consumer focused.  Business focused innovations improved network performance and reliability, application intelligence, business efficiencies, and security. Consumer innovations have focused on features, functionality, and ease of use. Often, consumer innovations have created headaches for the IT department.

I remember, back in the day, installing VPN servers when dial-up modems were the norm. Who would use a VPN when they could just dial in? A short time later, broadband Internet connections exploded, end user signed up like mad, and nobody wanted to access corporate resources through a dial-up modem any more. We struggled to install VPN servers with enough capacity.

Then wireless Ethernet appeared. Business users could connect their company provided laptops to their home wireless networks, but still had to plug-in at work. Why did they have to plug-in at work?  “Can’t the IT department implement wireless as easy as at home?”

So we struggled to install standalone wireless access points. They were cumbersome, then we figured out centrally managed wireless networks were much more efficient.

Today many organizations have deployed remote-access VPNs and centrally managed wireless networks. Business users, from home, hotel rooms, conference rooms, airports, Starbucks, or other locations, can securely connect to the corporate network. In the physical office, business users can connect with wired or wireless connections and easily access the same systems. We even can support “Guest” wireless connections
We could finally rest,  IT finally caught up to the users. But, like Steve Jobs likes to say, “but there’s more”. ...Great!@$%

Now we have business users bringing in other devices not provided by the IT department. I have a customer who has a XBOX in a conference requiring wireless Internet access.

It is now a reality; IT Departments now have to support Smartphones. Business users expect “always on” connectivity.  Users expect to not only have continuous access regardless of their platform.

Not only does the IT department have to pay for the Data plans, they now have to support the wireless Ethernet connectivity requirements. It would be easy to not support wireless Ethernet connectivity, but the cost of cellular data usage has to be considered. It is now financially prudent to allow Smartphones onto the business network.
Now, do we want the smartphones on the “Guest” wireless network, or the “internal”. Both have their advantages. “Guest” lets the user connect like they are at home but they may have to sign in to a “Guest” splash screen.  An “internal” wireless connection may open up the network to security hazards.

And then someone in management had to go and get a tablet. It could be an iPad or an Android device, it doesn’t matter. The IT department didn’t buy it, but it needs to connect to the network.  When the connection doesn’t work, we hear “what do you mean ‘no more IP addresses are available’”, “when I’m in my office, Angry Birds is slow”.

In my next installment; Unified Communications – home user features vs. business users’ functionalit


Home

4900M connection to HP Virtual Connect Flex 10 - Not Working

HP Virtual Connect Flex-10

Update: The configuration on the HP Virtual Connect side was incorrect. Once the server team reconfigured their side, all was good.

Today I am posting something I submitted to supportforums.cisco.com.

The customer has consultants configuring the HP side of things. I was asked to configure a Catalyst 4900M to work with the HP Virtual Connect Flex-10. From the Cisco side, this is not complex.

Tomorrow I am going onsite. I will open a TAC case on the way and sit beside the server guys.

4900M connection to HP Virtual Connect Flex 10

I'm Trying to connect a HP-C7000 blade server with a Virtual Connect Flex 10 connection with 10Gb links to a Catalyst 4900M. I have no control of the HP side.

From the HP guide, we are following "HP Virtual Connect Ethernet Cookbook" "Scenario 1:5 - VLAN Tagging (802.1q) with Shared Uplink Set (SUS) with Link Aggregation using LACP (802.3ad) - VMware ESX"

On the 4900M, LLDP sees the Virtual Connect and LCAP up with 2 active links.

Show interface on Ten1/1, Ten1/2, Port-Channel 1 shows 0 packets input.

Basically, we can not get any packets from the HP Server/VMware server side through the Catalyst 4900.

IOS version: 12.2(54)SG

Switch ports are as follows:
!
interface Port-channel1
description HP FLEX-10-VC
switchport trunk allowed vlan 4,8,10,11,16,22-24,69,99-  101,156,192,300,500
switchport mode trunk
switchport nonegotiate
spanning-tree portfast trunk
!
interface TenGigabitEthernet1/1
description HP FLEX-10-VC
switchport trunk allowed vlan 4,8,10,11,16,22-24,69,99-101,156,192,300,500
switchport mode trunk
switchport nonegotiate
spanning-tree portfast trunk
channel-protocol lacp
channel-group 1 mode active
!
interface TenGigabitEthernet1/2
description HP FLEX-10-VC
switchport trunk allowed vlan 4,8,10,11,16,22-24,69,99-101,156,192,300,500
switchport mode trunkswitchport nonegotiate
spanning-tree portfast trunk
channel-protocol lacp
channel-group 1 mode active
!

https://supportforums.cisco.com/thread/2063375

Do we need spanning tree ?

I had an interesting experience last week at a customers. I happened to be onsite to discuss why 4 Catalyst 4500 chassis had failed in 6 months. Each of them had similar symptoms, packets would no longer pass through them and a "show module" would either show the modules as not present or failed.

First we need a description of how the network is designed. This network is divided into "Network A" and "Network B". The separate networks represent the "business users" and the "operations users and systems". At the core of the network they have a single Catalyst 6500 with down links to Network A and Network B Catalyst 4500 switches.

The respective Catalyst 4500s have multiple down links to their respective Network A and Network B distribution Catalyst 4500s. These Catalyst 4500s have uplinks to access-layer switches. Each wiring closet has two switches, one for each network. If it is not clear, there are NO redundant links. There should be no loops in the network.

Here is a very simplified few of the network.



Now we get to the origins of the problem I would experience. The situation has been explained to me as this "when we implemented the network spanning tree was very buggy. So we disabled spanning tree on the 6500. I thought spanning tree would be enabled at some point." Oh boy!!!



So back to my incredibly good timing onsite. We were in a car heading to a building to look at the wiring closet were multiple Catalyst 4500s had failed the past few months. The customer driving the car got a call, users connected to Network B, or the operations and systems network, were unable to connect to their systems. Essentially, the operators were not able to see how the plant was operating. It also looked like the operations management systems were not able to see how the systems were operating. uh oh!!!

We headed back to the main building and I began troubleshooting the network. The CIO and multiple managers were standing behind me anxiously waiting for a diagnosis. I found the top Catalyst 4500s for the Network B side of the house, had its 1 GB uplink running at 95% utilization.


From previous work here, I knew spanning tree was disabled on the 6500, so I was worried about a loop (I have worked with this customer for 2 years. Each time I met with them, I recommend they should enable spanning tree, but there was always strict change controls which discouraged the customer's engineers from enabling spanning tree and a fear of something bad happening).

Suspecting a loop, my suggested to the CIO that I enable spanning tree. Asked about the impact, I said there could be 2 minutes when un-affected users and servers could have connectivity disrupted while spanning tree converged (yes 2 minutes is longer than required I wanted them to have appropriate expectations). He agreed, and on the core Catalyst 6500, I enabled spanning tree for all VLANs and set the switch as the spanning tree root of the network.

I thought I had the Loop in the network blocked. I now expected the network to spontaneously recover. Operations still couldn't connect to their systems. What was wrong?

I looked at the top-most Catalyst 4500 "B" switch. On this switch, I checked the CPU utilization. The CPU was pegged at 99%. A CPU running at 99% is an indication of a switch process switching a ton of packets. There are several types of packets which are processed switched, but I suspected Broadcast packets.

I need to find were the broadcast packets came from. I cleared the interface counters, then ran this command several times over a minute: show interface | include Gigabit|broadcast.

I quickly saw a single interface with a lot of broadcast packets. I connected to the downstream switch connected to the interface and repeated the command looking for an offending interface. I found it and connected to the access-layer switch. Remember, the network is divided between Network A and Network B.

I was connected to a switch named 3560-B-Bldg1. show cdp neighbor revealed the switch was also connected to a switch named 3560-A-Bldg1. I had suspected a loop, but hadn't looked for one or found one. I thought enabling spanning tree on the core switch would take care of it. I had finally found the loop!!



Things should have calmed down, but the had not, why? I looked at the interfaces on the 3560s that connected them together. The interface connected to each other on 3560-A-Bldg1 and 3560-B-Bldg1 had the same configuration:


interface GigabitEthernet 0/#
   switchport access vlan 500
 spanning-tree portfast

Both interfaces were configured as access ports to VLAN 500 and had portfast enabled. What is on VLAN 500? This is the VLAN used by the operations systems, users, and management systems. I had enabled spanning tree at the core, but this did not stop the loop. When spanning-tree port fast is enabled on an access interface, that interface does not participate in spanning tree.

As Astro says, "rut ro!"

I shut down the Gigabit interface on 3560-B-Bldg1. Finally, this should have corrected the problem...

When you have a loop in the network, what is the most damaging type of traffic...Broadcast..So I went back to looking for broadcast traffic. On 3560-B-Bldg1 I resumed running the show interface | include Gigabit|broadcast command. One interface appeared to receive an abnormally large amount of broadcast traffic. In fact the interface received about 55 million broadcast packets in 60 seconds. So I shut down that port.


The network finally recovered!


Observations / Lessons learned

  • Never disable spanning tree globally on a switch
  • Spanning-tree portfast disables spanning tree on an interface
  • consider running on every switch bpduguard