<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LACP issue Between Extreme and PaloAlto in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/lacp-issue-between-extreme-and-paloalto/m-p/76289#M19419</link>
    <description>I have an X670-G2 Stack running 21.1.4.4-patch1-6.xos&lt;BR /&gt;
&lt;BR /&gt;
This connects to a PaloAlto Firewall using a lacp lag group. Things have been running well for 220 days without issue.&lt;BR /&gt;
&lt;BR /&gt;
This morning the district lost internet and PaloAlto claims it was a switch problem. Looking at the switch I see the below info message:&lt;BR /&gt;
 Slot-1: Remove port 1:17 from aggregator&lt;BR /&gt;
&lt;BR /&gt;
Full log segment:&lt;BR /&gt;
03/28/2019 08:54:36.83  Slot-1: Add port 2:18 to aggregator&lt;BR /&gt;
03/28/2019 08:54:36.83  Slot-1: Add port 1:17 to aggregator&lt;BR /&gt;
03/28/2019 08:54:34.34  Slot-1: Port 2:18 link UP at speed 1 Gbps and full-duplex&lt;BR /&gt;
03/28/2019 08:54:33.79  Slot-1: Port 1:17 link UP at speed 1 Gbps and full-duplex&lt;BR /&gt;
03/28/2019 08:54:30.61  Slot-1: Port 2:18 link down&lt;BR /&gt;
03/28/2019 08:54:30.08  Slot-1: Port 1:17 link down&lt;BR /&gt;
03/28/2019 08:52:54.92  Slot-1: Port 2:18 link UP at speed 1 Gbps and full-duplex&lt;BR /&gt;
03/28/2019 08:52:53.37  Slot-1: Port 1:17 link UP at speed 1 Gbps and full-duplex&lt;BR /&gt;
03/28/2019 08:51:20.09  Slot-1: Port 1:17 link down&lt;BR /&gt;
03/28/2019 08:51:19.68  Slot-1: Port 2:18 link down&lt;BR /&gt;
03/28/2019 08:49:57.46  Slot-1: Remove port 2:18 from aggregator&lt;BR /&gt;
03/28/2019 08:49:57.40  Slot-1: Remove port 1:17 from aggregator&lt;BR /&gt;
&lt;BR /&gt;
I of-course want to say it was the firewalls fault, but am not certain how to interpret the message.&lt;BR /&gt;
Why was the port removed from the aggregator?&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
Looking at the below output it seems as though the PaloAlto is not responding at the same rate the Extreme does. Could this imbalance have led to the link resetting.&lt;BR /&gt;
&lt;BR /&gt;
Lag    Member   Rx    Rx Drop Rx Drop Rx Drop Tx    Tx    &lt;BR /&gt;
Group   Port    Ok    PDU Err Not Up  Same MAC Sent Ok Xmit Err&lt;BR /&gt;
--------------------------------------------------------------------------------&lt;BR /&gt;
1:3    1:3    651003  0    0    0    651051  0     &lt;BR /&gt;
          1:4    0    0    0    0    0    0     &lt;BR /&gt;
          2:3    0    0    0    0    0    0     &lt;BR /&gt;
          2:4    651005  0    0    0    651053  0     &lt;BR /&gt;
&lt;BR /&gt;
1:17    1:17    &lt;B&gt;1160   0    0    0    34740  0   &lt;/B&gt;  &lt;BR /&gt;
            1:18    0    0    0    0    0    0     &lt;BR /&gt;
            2:17    0    0    0    0    0    0     &lt;BR /&gt;
            2:18    &lt;B&gt;1160   0    0    0    34739  0  &lt;/B&gt;   &lt;BR /&gt;
&lt;BR /&gt;
Thanks for your help,</description>
    <pubDate>Fri, 29 Mar 2019 05:58:42 GMT</pubDate>
    <dc:creator>davidj_cogliane</dc:creator>
    <dc:date>2019-03-29T05:58:42Z</dc:date>
    <item>
      <title>LACP issue Between Extreme and PaloAlto</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/lacp-issue-between-extreme-and-paloalto/m-p/76289#M19419</link>
      <description>I have an X670-G2 Stack running 21.1.4.4-patch1-6.xos&lt;BR /&gt;
&lt;BR /&gt;
This connects to a PaloAlto Firewall using a lacp lag group. Things have been running well for 220 days without issue.&lt;BR /&gt;
&lt;BR /&gt;
This morning the district lost internet and PaloAlto claims it was a switch problem. Looking at the switch I see the below info message:&lt;BR /&gt;
 Slot-1: Remove port 1:17 from aggregator&lt;BR /&gt;
&lt;BR /&gt;
Full log segment:&lt;BR /&gt;
03/28/2019 08:54:36.83  Slot-1: Add port 2:18 to aggregator&lt;BR /&gt;
03/28/2019 08:54:36.83  Slot-1: Add port 1:17 to aggregator&lt;BR /&gt;
03/28/2019 08:54:34.34  Slot-1: Port 2:18 link UP at speed 1 Gbps and full-duplex&lt;BR /&gt;
03/28/2019 08:54:33.79  Slot-1: Port 1:17 link UP at speed 1 Gbps and full-duplex&lt;BR /&gt;
03/28/2019 08:54:30.61  Slot-1: Port 2:18 link down&lt;BR /&gt;
03/28/2019 08:54:30.08  Slot-1: Port 1:17 link down&lt;BR /&gt;
03/28/2019 08:52:54.92  Slot-1: Port 2:18 link UP at speed 1 Gbps and full-duplex&lt;BR /&gt;
03/28/2019 08:52:53.37  Slot-1: Port 1:17 link UP at speed 1 Gbps and full-duplex&lt;BR /&gt;
03/28/2019 08:51:20.09  Slot-1: Port 1:17 link down&lt;BR /&gt;
03/28/2019 08:51:19.68  Slot-1: Port 2:18 link down&lt;BR /&gt;
03/28/2019 08:49:57.46  Slot-1: Remove port 2:18 from aggregator&lt;BR /&gt;
03/28/2019 08:49:57.40  Slot-1: Remove port 1:17 from aggregator&lt;BR /&gt;
&lt;BR /&gt;
I of-course want to say it was the firewalls fault, but am not certain how to interpret the message.&lt;BR /&gt;
Why was the port removed from the aggregator?&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
Looking at the below output it seems as though the PaloAlto is not responding at the same rate the Extreme does. Could this imbalance have led to the link resetting.&lt;BR /&gt;
&lt;BR /&gt;
Lag    Member   Rx    Rx Drop Rx Drop Rx Drop Tx    Tx    &lt;BR /&gt;
Group   Port    Ok    PDU Err Not Up  Same MAC Sent Ok Xmit Err&lt;BR /&gt;
--------------------------------------------------------------------------------&lt;BR /&gt;
1:3    1:3    651003  0    0    0    651051  0     &lt;BR /&gt;
          1:4    0    0    0    0    0    0     &lt;BR /&gt;
          2:3    0    0    0    0    0    0     &lt;BR /&gt;
          2:4    651005  0    0    0    651053  0     &lt;BR /&gt;
&lt;BR /&gt;
1:17    1:17    &lt;B&gt;1160   0    0    0    34740  0   &lt;/B&gt;  &lt;BR /&gt;
            1:18    0    0    0    0    0    0     &lt;BR /&gt;
            2:17    0    0    0    0    0    0     &lt;BR /&gt;
            2:18    &lt;B&gt;1160   0    0    0    34739  0  &lt;/B&gt;   &lt;BR /&gt;
&lt;BR /&gt;
Thanks for your help,</description>
      <pubDate>Fri, 29 Mar 2019 05:58:42 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/lacp-issue-between-extreme-and-paloalto/m-p/76289#M19419</guid>
      <dc:creator>davidj_cogliane</dc:creator>
      <dc:date>2019-03-29T05:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: LACP issue Between Extreme and PaloAlto</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/lacp-issue-between-extreme-and-paloalto/m-p/76290#M19420</link>
      <description>Not that I know, but with all the recent PANOS updates, has anything changed?&lt;BR /&gt;
Are the Palos perhaps similar to Ciscos where you have to put something like "configure sharing  lacp system-priority 32768" in the config to make everyone happy?&lt;BR /&gt;
&lt;BR /&gt;
Sorry, just guessing - my PAs don't run LACP.&lt;BR /&gt;
&lt;BR /&gt;
   Frank</description>
      <pubDate>Fri, 29 Mar 2019 19:28:16 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/lacp-issue-between-extreme-and-paloalto/m-p/76290#M19420</guid>
      <dc:creator>Frank</dc:creator>
      <dc:date>2019-03-29T19:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: LACP issue Between Extreme and PaloAlto</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/lacp-issue-between-extreme-and-paloalto/m-p/76291#M19421</link>
      <description>Frank,&lt;BR /&gt;
&lt;BR /&gt;
Thanks for the reply, I was thinking the same thing as you.&lt;BR /&gt;
&lt;BR /&gt;
We are waiting to here back from PA on how they want to the link configured, and was hoping perhaps someone here had encountered this issue and ironed out the config already.&lt;BR /&gt;
&lt;BR /&gt;
The weirdest part to me is that it has run fine for 220 days before becoming an issue. I  spoke with the customer today and confirmed there have been no code changes on the PA and I know there have not been any changes on the Extreme.&lt;BR /&gt;
&lt;BR /&gt;
I will post the final config once we get it figured out.</description>
      <pubDate>Fri, 29 Mar 2019 22:34:19 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/lacp-issue-between-extreme-and-paloalto/m-p/76291#M19421</guid>
      <dc:creator>davidj_cogliane</dc:creator>
      <dc:date>2019-03-29T22:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: LACP issue Between Extreme and PaloAlto</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/lacp-issue-between-extreme-and-paloalto/m-p/76292#M19422</link>
      <description>David,&lt;BR /&gt;
&lt;BR /&gt;
We run 7050s, LACP to cores and OSPF to our ISP.  During a DDoS attack the dataplane was saturated and our 7050s weren't able to maintain LACP to our cores.&lt;BR /&gt;
&lt;BR /&gt;
Active 7050s system log had...&lt;BR /&gt;
LACP interface ethernet7/21 moved out of AE-group ae1. Selection state Selected&lt;BR /&gt;
&lt;BR /&gt;
HTH&lt;BR /&gt;
Nabil</description>
      <pubDate>Tue, 28 May 2019 07:47:18 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/lacp-issue-between-extreme-and-paloalto/m-p/76292#M19422</guid>
      <dc:creator>Naoman_Ghani</dc:creator>
      <dc:date>2019-05-28T07:47:18Z</dc:date>
    </item>
  </channel>
</rss>

