<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Disable going multicast between subvlans in supervlan. in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37370#M7880</link>
    <description>Dear Colleagues, &lt;BR /&gt;
&lt;BR /&gt;
 &lt;BR /&gt;
If I use separate vlans on Extreme X450-24 ver.  15.3.2.11 on default settings multicast trafic doesn't route between these vlans. But if I use 2 subvlans (or more) in supervlan multicast trafic begins to route between these subvlans.   &lt;BR /&gt;
I don't need this. Please, help me.   &lt;BR /&gt;
How can I disable multicast routing between subvlans in 1 supervlan without using ACL?  &lt;BR /&gt;
 &lt;BR /&gt;
Thank you.&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Thu, 19 Jan 2017 17:23:00 GMT</pubDate>
    <dc:creator>Victor_Vit</dc:creator>
    <dc:date>2017-01-19T17:23:00Z</dc:date>
    <item>
      <title>Disable going multicast between subvlans in supervlan.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37370#M7880</link>
      <description>Dear Colleagues, &lt;BR /&gt;
&lt;BR /&gt;
 &lt;BR /&gt;
If I use separate vlans on Extreme X450-24 ver.  15.3.2.11 on default settings multicast trafic doesn't route between these vlans. But if I use 2 subvlans (or more) in supervlan multicast trafic begins to route between these subvlans.   &lt;BR /&gt;
I don't need this. Please, help me.   &lt;BR /&gt;
How can I disable multicast routing between subvlans in 1 supervlan without using ACL?  &lt;BR /&gt;
 &lt;BR /&gt;
Thank you.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 19 Jan 2017 17:23:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37370#M7880</guid>
      <dc:creator>Victor_Vit</dc:creator>
      <dc:date>2017-01-19T17:23:00Z</dc:date>
    </item>
    <item>
      <title>RE: Disable going multicast between subvlans in supervlan.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37371#M7881</link>
      <description>what do you mean by subvlan and supervlan?&lt;BR /&gt;
&lt;BR /&gt;
I can imagine secondary interface on the same vlan or QinQ.&lt;BR /&gt;
&lt;BR /&gt;
What kind of multicast you refer to ? L2 multicast or L3 multicast?&lt;BR /&gt;
You mention multicast routing, can you elaborate more? = multicast routing protocol do you use?&lt;BR /&gt;
&lt;BR /&gt;
Z.</description>
      <pubDate>Thu, 19 Jan 2017 17:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37371#M7881</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2017-01-19T17:39:00Z</dc:date>
    </item>
    <item>
      <title>RE: Disable going multicast between subvlans in supervlan.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37372#M7882</link>
      <description>subvlan and supervlan - &lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-configure-subvlan-with-super-vlan" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-configure-subvlan-with-super-vlan&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
L3 multicast. Mvr, pim is disable.&lt;BR /&gt;</description>
      <pubDate>Thu, 19 Jan 2017 17:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37372#M7882</guid>
      <dc:creator>Victor_Vit</dc:creator>
      <dc:date>2017-01-19T17:39:00Z</dc:date>
    </item>
    <item>
      <title>RE: Disable going multicast between subvlans in supervlan.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37373#M7883</link>
      <description>Did you run &lt;BR /&gt;
#disable subvlan-proxy-arp vlan all as was suggested at the bottom of that article?&lt;BR /&gt;
&lt;BR /&gt;
Why are you using this method as opposed to just creating smaller subnets on separate vlans?</description>
      <pubDate>Thu, 19 Jan 2017 17:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37373#M7883</guid>
      <dc:creator>Ty_Kolff</dc:creator>
      <dc:date>2017-01-19T17:39:00Z</dc:date>
    </item>
    <item>
      <title>RE: Disable going multicast between subvlans in supervlan.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37374#M7884</link>
      <description>Hello, Ty Kolff!&lt;BR /&gt;
&lt;BR /&gt;
#disable subvlan-proxy-arp vlan all&lt;BR /&gt;
The isolation option works for normal, dynamic, ARP-based client communication.&lt;BR /&gt;
&lt;BR /&gt;
Thank you!</description>
      <pubDate>Thu, 19 Jan 2017 17:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37374#M7884</guid>
      <dc:creator>Alexandr_P</dc:creator>
      <dc:date>2017-01-19T17:39:00Z</dc:date>
    </item>
    <item>
      <title>RE: Disable going multicast between subvlans in supervlan.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37375#M7885</link>
      <description>Hello, Ty Kolff!&lt;BR /&gt;
But this command does not isolation multicast. It works for ARP.&lt;BR /&gt;
In our situation we must use supervlan.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 19 Jan 2017 17:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37375#M7885</guid>
      <dc:creator>Victor_Vit</dc:creator>
      <dc:date>2017-01-19T17:39:00Z</dc:date>
    </item>
    <item>
      <title>RE: Disable going multicast between subvlans in supervlan.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37376#M7886</link>
      <description>Hi Victor,&lt;BR /&gt;
&lt;BR /&gt;
I don't see any other way to deny mcast communication between the subvlans. Even ACL might be tricky.&lt;BR /&gt;
&lt;BR /&gt;
Only broadcast and unknown traffic remain local to the subvlans.&lt;BR /&gt;
&lt;BR /&gt;
I would recommend you (if possible) to use normal vlans instead of using Vlan Aggregation feature if this issue is critical to your environment.</description>
      <pubDate>Thu, 19 Jan 2017 17:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37376#M7886</guid>
      <dc:creator>Henrique</dc:creator>
      <dc:date>2017-01-19T17:39:00Z</dc:date>
    </item>
    <item>
      <title>RE: Disable going multicast between subvlans in supervlan.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37377#M7887</link>
      <description>Hi, all!&lt;BR /&gt;
&lt;BR /&gt;
As a continuation of this topic:&lt;BR /&gt;
When using Supervlan - if numbers of IPARP and FDB entries less then 3000 - all work fine.&lt;BR /&gt;
If entries more then 3000 - then higher ping, higher bcmRX (as I understand - because loop) process and appear below messages in logs:&lt;BR /&gt;
Mar 22 20:02:02  192.168.x.xx  Mar 22 20:02:03 DOSProt: Notify-threshold for L3 Protect  packet count of 3000 reached    Mar 22  20:02:03 192.168.x.xx  Mar 22 20:02:04 DOSProt: Added an ACL to port 25,  srcIP 0.0.0.0 to destIP 77.yyy.yyy.yyy, protocol tcp&lt;BR /&gt;
&lt;BR /&gt;
    Mar 22  20:02:03 192.168.x.xx  Mar 22 20:02:04 DOSProt: Removed ACL from port 25,  srcIP 0.0.0.0 to destIP 77.yyy.yyy.yyy, protocol tcp&lt;BR /&gt;
&lt;BR /&gt;
    Mar 22  20:02:12 192.168.x.xx  Mar 22 20:02:04 DOSProt: Notify-threshold for L3  Protect packet count of 3000 reached&lt;BR /&gt;
&lt;BR /&gt;
    Mar 22  20:02:12 192.168.x.xx  Mar 22 20:02:05 DOSProt: Added an ACL to port 25,  srcIP 0.0.0.0 to destIP 77.yyy.yyy.yyy, protocol tcp&lt;BR /&gt;
&lt;BR /&gt;
    Mar 22  20:02:12 192.168.x.xx  Mar 22 20:02:05 DOSProt: Notify-threshold for L3  Protect packet count of 3000 reached&lt;BR /&gt;
&lt;BR /&gt;
Any ideas?&lt;BR /&gt;
&lt;BR /&gt;
Thank you!&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 18 Apr 2017 11:41:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37377#M7887</guid>
      <dc:creator>Alexandr_P</dc:creator>
      <dc:date>2017-04-18T11:41:00Z</dc:date>
    </item>
    <item>
      <title>RE: Disable going multicast between subvlans in supervlan.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37378#M7888</link>
      <description>Hi Alexandr,&lt;BR /&gt;
&lt;BR /&gt;
is the DoS Protect ACL matching traffic &lt;I&gt;to&lt;/I&gt; the switch or traffic &lt;I&gt;through&lt;/I&gt; the switch? From the looks of it, it should be traffic through the switch to an SMTP server. If so, that traffic should not reach the CPU during normal operation.&lt;BR /&gt;
&lt;BR /&gt;
One reason through traffic reaches the CPU is a missing ARP entry for a local end system, resulting in software based forwarding. You might want to check the hardware capabilities and the configured maximum ARP entries in hardware:&lt;BR /&gt;
show iproute reserved-entries statistics  show iparp  show iparp stats summary  Older EXOS had a default of 4096 ARP entries max, newer EXOS uses 8192, you might want to check that you use the newer default value, if the hardware permits this. This can be configured using&lt;BR /&gt;
configure iparp max_entries [vr &lt;I&gt;VR_NAME&lt;/I&gt;] &lt;I&gt;MAX_ENTRIES  &lt;/I&gt;&lt;BLOCKQUOTE&gt;The maximum IP ARP entries include dynamic, static, and incomplete IP ARP entries.&lt;BR /&gt;
&lt;/BLOCKQUOTE&gt;Thanks,&lt;BR /&gt;
Erik</description>
      <pubDate>Tue, 18 Apr 2017 12:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37378#M7888</guid>
      <dc:creator>Erik_Auerswald</dc:creator>
      <dc:date>2017-04-18T12:48:00Z</dc:date>
    </item>
    <item>
      <title>RE: Disable going multicast between subvlans in supervlan.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37379#M7889</link>
      <description>Hi, Erik!&lt;BR /&gt;
&lt;BR /&gt;
X450a have limits IP ARP:&lt;BR /&gt;
8K with minimum LPM entries - 100 and less&lt;BR /&gt;
2K with max LPM - 12K&lt;BR /&gt;
&lt;BR /&gt;
In this switch configured max LPM:&lt;BR /&gt;
sh iproute reserved-entries                          IPv4       # Reserved Routes            Minimum #&lt;BR /&gt;
&lt;BR /&gt;
  Slot  Type              Routes      IPv4   (or IPv6)            IPv4 Hosts&lt;BR /&gt;
&lt;BR /&gt;
  ----  ----------------  --------   ------  ------------------   ----------&lt;BR /&gt;
&lt;BR /&gt;
  1     X450a-24x         Internal    12240  (  6120) [default]           16&lt;BR /&gt;
&lt;BR /&gt;
So there is few factors:&lt;BR /&gt;
&lt;BR /&gt;
- hardware limit&lt;BR /&gt;
&lt;BR /&gt;
- possible loop and mcast traffic because using Supervlan feature.&lt;BR /&gt;
&lt;BR /&gt;
Main question in this case is still - how to block mcast between SubVlans?&lt;BR /&gt;
&lt;BR /&gt;
Thank you!&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 18 Apr 2017 12:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37379#M7889</guid>
      <dc:creator>Alexandr_P</dc:creator>
      <dc:date>2017-04-18T12:48:00Z</dc:date>
    </item>
    <item>
      <title>RE: Disable going multicast between subvlans in supervlan.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37380#M7890</link>
      <description>Hi, Erik&lt;BR /&gt;
I'm sorry, but can you explain what do the numbers in the output of "Show iproute reserved-entries statistics" represent?&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 18 Apr 2017 12:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37380#M7890</guid>
      <dc:creator>Victor_Vit</dc:creator>
      <dc:date>2017-04-18T12:48:00Z</dc:date>
    </item>
    <item>
      <title>RE: Disable going multicast between subvlans in supervlan.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37381#M7891</link>
      <description>Hi Victor,&lt;BR /&gt;
&lt;BR /&gt;
the numbers in the table show how many entries of the different types that are stored in hardware tables are used, the numbers after the table show the limits of different switches.&lt;BR /&gt;
&lt;BR /&gt;
An exclamation mark (!) next to a number signals that the hardware limit is reached, see e.g. &lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/Multicast-Entry-not-Added-Hardware-Table-Full" target="_blank" rel="nofollow noreferrer noopener"&gt;Multicast Entry not Added. Hardware Table Full&lt;/A&gt; and &lt;A href="https://gtacknowledge.extremenetworks.com/articles/Solution/Known-traffic-gets-forwarded-in-the-CPU-of-an-X670-X440-stack" target="_blank" rel="nofollow noreferrer noopener"&gt;Known traffic gets forwarded in the CPU of an X670-X440 stack&lt;/A&gt;. Some entries need to be added up against the hardware limit, e.g. IPv6 routes use the same resources as IPv4 routes, see e.g. &lt;A href="https://gtacknowledge.extremenetworks.com/articles/Q_A/Space-occupied-by-IPv6-route-in-hardware-table" target="_blank" rel="nofollow noreferrer noopener"&gt;Space occupied by IPv6 route in hardware table&lt;/A&gt;. The &lt;I&gt;HW Route Table&lt;/I&gt; stores prefixes for longest prefix match (LPM) lookup, the &lt;I&gt;HW L3 Hash Table&lt;/I&gt; stores direct lookup entries, e.g. ARP entries or multicast groups.&lt;BR /&gt;
&lt;BR /&gt;
For some switches, the table usage can be configured, see &lt;A href="https://gtacknowledge.extremenetworks.com/articles/Q_A/Can-the-maximum-reserved-route-entries-be-increased-for-a-specific-switch-model" target="_blank" rel="nofollow noreferrer noopener"&gt;Can the maximum reserved route entries be increased for a specific switch model?&lt;/A&gt; This depends on the hardware, newer Broadcom switch chips use so called Unified Forwarding Tables (UFT) that can be used with different partitioning variants.&lt;BR /&gt;
&lt;BR /&gt;
Additional information can be found in the GTAC Knowledge articles &lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/Check-for-Table-full-conditions" target="_blank" rel="nofollow noreferrer noopener"&gt;Check for Table full conditions&lt;/A&gt; and &lt;A href="https://gtacknowledge.extremenetworks.com/articles/Q_A/FDB-entry-not-added-on-slot-Hardware-Table-full" target="_blank" rel="nofollow noreferrer noopener"&gt;How to troubleshoot FDB entry not added on slot X. Hardware Table full&lt;/A&gt;.&lt;BR /&gt;
&lt;BR /&gt;
Some effects of needing too many ARP entries are explained in &lt;A href="https://gtacknowledge.extremenetworks.com/articles/Solution/Slot-reboot-on-BD8K-due-to-Async-Queue-growing-with-CustomType-42-messages" target="_blank" rel="nofollow noreferrer noopener"&gt;Slot reboot on BD8K due to Async Queue growing with CustomType 42 messages&lt;/A&gt;.&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Erik</description>
      <pubDate>Tue, 18 Apr 2017 12:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/disable-going-multicast-between-subvlans-in-supervlan/m-p/37381#M7891</guid>
      <dc:creator>Erik_Auerswald</dc:creator>
      <dc:date>2017-04-18T12:48:00Z</dc:date>
    </item>
  </channel>
</rss>

