<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Fabric Attach pros/cons in ExtremeSwitching (VSP/Fabric Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8755#M336</link>
    <description>More testing with the FA/LLDP VLAN provionning delay on EXOS.&lt;BR /&gt;I did not see any noticeable difference in FA provisionning time between EXOS 22.7.3.5, 30.7.2.1 and 31.5.1.6.&lt;BR /&gt;It was not as bad as I said before: about 36-37 seconds, with the default LLDP transmit interval, in my environment (I may have hit another issue when I consistenly got a 1 min delay initially).&lt;BR /&gt;But that's still way too slow if you ask me.&lt;BR /&gt;&lt;BR /&gt;I also tried explicitly configuring the management I-SID/VLAN on the port/MLT in VOSS (fa management i-sid &amp;lt;isid&amp;gt; c-vid &amp;lt;vlanid&amp;gt;).&lt;BR /&gt;I guess this feature is really aiming at provisionning native FA devices (cams, APs, ..), and I don't have any, but it was still worth a try.&lt;BR /&gt;(Also EXOS has a similar command, "configure fabric attach management vlan", which seems to only makes sense in standalone proxy mode.)&lt;BR /&gt;As could be expected, this configuration does make the said management VLAN come up almost instantly, as VOSS will map it without waiting for LLDP advertisements to be sent back and forth, but this does not affect the provisionning delay for the other VLANs.&lt;BR /&gt;&lt;BR /&gt;So, I'll be sticking with EXOS 30.7 with static VLANs for now.&lt;BR /&gt;Thanks all for your help.</description>
    <pubDate>Tue, 21 Dec 2021 20:18:00 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2021-12-21T20:18:00Z</dc:date>
    <item>
      <title>Fabric Attach pros/cons</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8748#M329</link>
      <description>Hi all,&lt;BR /&gt;&lt;BR /&gt;I'm halfway through my first Fabric Connect deployment, and looking for in the field experience with Fabric Attach.&lt;BR /&gt;At this network's core are two server rooms, with a VSP 7400 and a 5520-24t running VOSS in each one, then we have X450G2 stacks for distribution, along with a few old B5 stacks.&lt;BR /&gt;Software versions are VOSS 8.4.2.0 and EXOS 30.7.2.1.&lt;BR /&gt;&lt;BR /&gt;So, Fabric Attach.&lt;BR /&gt;Automatically pulling VLANs from the edge switches sounded great initially.&lt;BR /&gt;&lt;BR /&gt;That is, until I realized that:&lt;BR /&gt;- FA is dog slow, VLANs get mapped about 1 min after you link comes up, with default LLDP timings&lt;BR /&gt;- FA requires full trust in your edge switches, as any I-SID/VLAN in your core is "attachable", and apparently can't be protected from it&lt;BR /&gt;- FA cannot handle multiple paths, but relies on LACP for redundancy, so I still need to set this up on both core and edge&lt;BR /&gt;- and I still have to deal with port-based VLANs on VOSS anyway, for B5 stacks, servers, routers, etc&lt;BR /&gt;&lt;BR /&gt;Lowering the LLDP transmit interval from 30s to 10s only made FA barely usable, mapping VLANs still takes from 15s to 20s.&lt;BR /&gt;I consider using a smaller LLDP interval to be unreasonable, as it's a global value for all ports in the EXOS stack, I and don't want this to affect other devices in any way.&lt;BR /&gt;Didn't find any KB article dealing with this issue.&lt;BR /&gt;I guess the problem is LLDP advertisements are sent in sync globally to all ports, and we end-up waiting for the next scheduled dispatch, and that's what makes it so painfully slow, but really FA on the edge should trigger a "gratuitous" LLDP advertisement when the link comes up and be done with it.&lt;BR /&gt;So long for the Fabric Connect super fast convergence time...&lt;BR /&gt;&lt;BR /&gt;Then, the lack of any core-side control over which VLAN/I-SID can be mapped really annoys me.&lt;BR /&gt;We do use FA authentication (no one should use unauth'ed FA in its current state IMO), but that's not enough.&lt;BR /&gt;I don't want the edge switches to be able to extend the server or infrastructure VLANs, it just doesn't feel safe.&lt;BR /&gt;I can see the value in only provisioning edge VLANs in only one place, but I want to be able to selectively enable VLANs/I-SIDs for FA on the core/server side.&lt;BR /&gt;&lt;BR /&gt;And ultimately, I don't feel that I'm really gaining that much from FA in return.&lt;BR /&gt;I still have to configure core to edge ports for MLT/LACP (maybe even switch to trunk mode manually, I don't remember).&lt;BR /&gt;I still need to map I-SIDs to actual VLANs on the 7400s in order to provide IP subnets gateways, routing and so on (so I end-up with a double I-SID to VLAN mapping).&lt;BR /&gt;&lt;BR /&gt;Did I miss something here?&lt;BR /&gt;Does FA bring any other benefit?&lt;BR /&gt;Is there a well hidden trick to make VLAN mappings happen faster?&lt;BR /&gt;Is there a way to whitelist I-SIDs for FA? (and prevent any other I-SID from being ever mapped)&lt;BR /&gt;Does FA really only make sense in a "real" larger Fabric Connect network?&lt;BR /&gt;Am I wrong in considering dropping it in favor of static VLANs?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Nicolas</description>
      <pubDate>Fri, 17 Dec 2021 08:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8748#M329</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-12-17T08:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fabric Attach pros/cons</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8749#M330</link>
      <description>Hi Nicolas,&lt;BR /&gt;&lt;BR /&gt;A lot of questions there.&lt;BR /&gt;Let's answer the main one: "Am I wrong in considering dropping it in favor of static VLANs?"&lt;BR /&gt;It depends of you business requirements. For some environments, the FA process is indeed seen as too slow while on others it is ok.&lt;BR /&gt;By experience, the standard timers are ok for most of the customers.&lt;BR /&gt;&lt;BR /&gt;Here few comments:&lt;BR /&gt;I would urgently upgrade to 8.4.2.1, the 8.4.2.0 has an ugly bug and has been removed from the support site.&lt;BR /&gt;&lt;BR /&gt;On the last EXOS releases you also have the "Fabric Attach Automatic LAG Creation". This automates the LAG creation and VLANs mapping between EXOS and SMLT clusters.&lt;BR /&gt;I remember one hospital who cannot cope with the base timers and went&amp;nbsp; for static LAG configuration.&lt;BR /&gt;&lt;BR /&gt;You can specify a white list of i-sid's allowed via radius authentication, see here : https://extremeportal.force.com/ExtrArticleDetail?an=000073262 &lt;BR /&gt;&lt;BR /&gt;On the edge switches you can have a minimalistic config with netlogin on all ports.&lt;BR /&gt;The radius will then return the couple VLAN/I-SID (or a role) on an authentication based approach for the clients.&lt;BR /&gt;&lt;BR /&gt;With those features you have a full automated port configuration.&lt;BR /&gt;This is not solving the lag time to have the VLAN provisioning but this is happening only for the first client. The second client on the same VLAN will just get the VLAN on the port activated, the uplink will be already provisioned.&lt;BR /&gt;&lt;BR /&gt;I hope this helps,&lt;BR /&gt;Mig</description>
      <pubDate>Sat, 18 Dec 2021 18:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8749#M330</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2021-12-18T18:55:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fabric Attach pros/cons</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8750#M331</link>
      <description>I would consider upgrading to your EXOS switch to 31.5 and see if you can replicate the issue.&amp;nbsp; &lt;BR /&gt;Also are you VSPs core devices in vIST clusters?&lt;BR /&gt;&lt;BR /&gt;to answer some of your questions.&amp;nbsp; &lt;BR /&gt;- FA is dog slow.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;FA is not a resiliency protocol. Its an automation/ztp feature. FA needs to go through a ton of order of operations to make sure that new switch get adopted proper.&amp;nbsp; If you want to speed it up, make sure Spanning Tree is disabled on your VSP ports.&amp;nbsp;&amp;nbsp; FA won't start its Mojo until spanning tree is done its business.&amp;nbsp; I usually see the FA assignments kick in after 10-20 seconds.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;- FA requires full trust in your edge switches, as any I-SID/VLAN in your core is "attachable", and apparently can't be protected from it.&lt;BR /&gt;&lt;BR /&gt;FA gives the user granularity in the moves/add/changes in vlans in the edge.&amp;nbsp; The VLAN needs to exist on the edge switch and the VLAN needs an explicit i-sid. This can be done manually or with XIQ-SE/Control. This is full control. &amp;nbsp;&amp;nbsp; If you think about how some vendors do tagging.&amp;nbsp; Some automatically put all VLANs on all trunks and one needs to explicitly prune the vlans away.&amp;nbsp; Or protocols like VTP that just send VLANs everywhere.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;FA also has security with authentication so only trusted edge switches can receive the FA assignments and elements&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;- FA cannot handle multiple paths, but relies on LACP for redundancy, so I still need to set this up on both core and edge.&lt;BR /&gt;&lt;BR /&gt;Not true.&amp;nbsp; You can manually create a LAG group on the EXOS switch.&amp;nbsp;&amp;nbsp; Also, with EXOS 31.X there is an auto-lag feature that will sense that the two or more links are connected to an MLT/SMLT from the VSP and will automatically create the lag group on the EXOS switch.&amp;nbsp; I have tested this a lot. It actually works very fast.&amp;nbsp; But you need to be running the newest code.&lt;BR /&gt;&lt;BR /&gt;- and I still have to deal with port-based VLANs on VOSS anyway, for B5 stacks, servers, routers, etc.&lt;BR /&gt;&lt;BR /&gt;Not necessarily.&amp;nbsp; FA will auto create VLANs in the core.&amp;nbsp;&amp;nbsp; &lt;BR /&gt;But usually network admins want that control.</description>
      <pubDate>Sun, 19 Dec 2021 19:43:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8750#M331</guid>
      <dc:creator>EXTR_Paul</dc:creator>
      <dc:date>2021-12-19T19:43:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fabric Attach pros/cons</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8751#M332</link>
      <description>Nicolas&lt;BR /&gt;we are aware that in some scenarios we are relying on LLDP timers to signal service bindings. We will be addressing that by sending triggered updates (LLDP). Stay tuned, we hope to have this addressed by 1H 2022. There will be SW updates required on VOSS and EXOS.&lt;BR /&gt;&lt;BR /&gt;Roger</description>
      <pubDate>Mon, 20 Dec 2021 10:58:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8751#M332</guid>
      <dc:creator>Roger_Lapuh</dc:creator>
      <dc:date>2021-12-20T10:58:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fabric Attach pros/cons</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8752#M333</link>
      <description>Hello Mig,&lt;BR /&gt;&lt;BR /&gt;Yes, I guess for many/most customers, VLAN automation is worth the delay.&lt;BR /&gt;My use case is a medical devices factory, where a longer than expected interruption will cause a chain reaction and escalate very quickly.&lt;BR /&gt;&lt;BR /&gt;Thanks for the reminder about the 8.4.2.0 DHCP issue, upgrade is planned already for the next maintenance window, i.e. next week.&lt;BR /&gt;&lt;BR /&gt;OK, I missed the automatic LAG creation in EXOS 31.x.&lt;BR /&gt;I think I'll still stay on 30.7 for now (actually upgrading from 22.7 as part of the network upgrade) until 31.x gets more widely spread.&lt;BR /&gt;&lt;BR /&gt;I'm only using FA between X450G2 stacks and VSP7400's, not sure if provisionning I-SIDs over RADIUS would work here, but I don't feel like making the network infrastructure (vs. user devices) rely on a RADIUS server.&lt;BR /&gt;Already using ExtremeControl NAC on X450G2 with netlogin on all ports, but you I think you have more of an ERS scenario in your mind, don't you?</description>
      <pubDate>Tue, 21 Dec 2021 03:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8752#M333</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-12-21T03:46:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fabric Attach pros/cons</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8753#M334</link>
      <description>Hello Paul,&lt;BR /&gt;&lt;BR /&gt;No, I did not try running 31.x yet, and I'll stay on 30.7 for now, but will definitely give a try as time permits.&lt;BR /&gt;&lt;BR /&gt;&amp;gt; If you want to speed it up, make sure Spanning Tree is disabled on your VSP ports.&lt;BR /&gt;But I do want STP! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; I actually got hit hard last week by the lack of STP support for "multihomed" devices in the default VSP configuration (https://extremeportal.force.com/ExtrArticleDetail?an=000082836)&lt;BR /&gt;The 30-60 seconds delay is clearly not due to STP though, ports are up in forwarding state loooong before VLANs get mapped by FA.&lt;BR /&gt;Also have a deep hate for Cisco's "help me I'm stuck in the 90s" VLANs, but TBH, VOSS makes it difficult and painful as well, especially compared to EOS/EXOS.&lt;BR /&gt;&lt;BR /&gt;Yes, I get your arguments for FA.&lt;BR /&gt;I still believe you should not be allowed to pull just any VLAN in your core network from an edge device.&lt;BR /&gt;&lt;BR /&gt;Thanks for telling about the automatic LAG creation in EXOS 31.7 as Mig did, and glad it worked for you.&lt;BR /&gt;I need to look into this.&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &amp;gt; and I still have to deal with port-based VLANs on VOSS anyway, for B5 stacks, servers, routers, etc.&lt;BR /&gt;&amp;gt; Not necessarily. FA will auto create VLANs in the core. &lt;BR /&gt;Unless I missed something, FA won't help with non FA-enabled devices.</description>
      <pubDate>Tue, 21 Dec 2021 03:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8753#M334</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-12-21T03:48:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fabric Attach pros/cons</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8754#M335</link>
      <description>Roger,&lt;BR /&gt;&lt;BR /&gt;Thanks for the good news!&lt;BR /&gt;I'm really looking forward to this triggered LLDP updates feature.&lt;BR /&gt;A global "fa allowed-vlans" command (only allow specified VLANs to be pulled by FA) is also high on my Xmas wish list. &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;</description>
      <pubDate>Tue, 21 Dec 2021 03:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8754#M335</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-12-21T03:51:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fabric Attach pros/cons</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8755#M336</link>
      <description>More testing with the FA/LLDP VLAN provionning delay on EXOS.&lt;BR /&gt;I did not see any noticeable difference in FA provisionning time between EXOS 22.7.3.5, 30.7.2.1 and 31.5.1.6.&lt;BR /&gt;It was not as bad as I said before: about 36-37 seconds, with the default LLDP transmit interval, in my environment (I may have hit another issue when I consistenly got a 1 min delay initially).&lt;BR /&gt;But that's still way too slow if you ask me.&lt;BR /&gt;&lt;BR /&gt;I also tried explicitly configuring the management I-SID/VLAN on the port/MLT in VOSS (fa management i-sid &amp;lt;isid&amp;gt; c-vid &amp;lt;vlanid&amp;gt;).&lt;BR /&gt;I guess this feature is really aiming at provisionning native FA devices (cams, APs, ..), and I don't have any, but it was still worth a try.&lt;BR /&gt;(Also EXOS has a similar command, "configure fabric attach management vlan", which seems to only makes sense in standalone proxy mode.)&lt;BR /&gt;As could be expected, this configuration does make the said management VLAN come up almost instantly, as VOSS will map it without waiting for LLDP advertisements to be sent back and forth, but this does not affect the provisionning delay for the other VLANs.&lt;BR /&gt;&lt;BR /&gt;So, I'll be sticking with EXOS 30.7 with static VLANs for now.&lt;BR /&gt;Thanks all for your help.</description>
      <pubDate>Tue, 21 Dec 2021 20:18:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8755#M336</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-12-21T20:18:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fabric Attach pros/cons</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8756#M337</link>
      <description>&lt;P&gt;Hi Roger,&lt;BR /&gt;&lt;BR /&gt;Any news on the triggered LLDP updates? I couldn't find mention of this in release notes of VOSS 8.6 or 8.7.&lt;/P&gt;
&lt;STYLE&gt;&lt;/STYLE&gt;
&lt;P&gt;We ran into an issue with devices for which the FA takes too long, the device has given up trying to reach its gateway before traffic is passed on the uplink of the exos switch (the FA vlan assingment is pending).&lt;/P&gt;
&lt;P&gt;Thank you in advance!&lt;BR /&gt;Evert.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 15:59:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8756#M337</guid>
      <dc:creator>Evert</dc:creator>
      <dc:date>2022-08-19T15:59:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fabric Attach pros/cons</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8757#M338</link>
      <description>Hi Evert&lt;BR /&gt;yes Release 8.8 will support this from the VSP perspective. GA end of August. Roger</description>
      <pubDate>Fri, 19 Aug 2022 16:54:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8757#M338</guid>
      <dc:creator>Roger_Lapuh</dc:creator>
      <dc:date>2022-08-19T16:54:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fabric Attach pros/cons</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8758#M339</link>
      <description>Hello Roger,&lt;BR /&gt;That's good news, thank you!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;
&lt;STYLE&gt;&lt;/STYLE&gt;</description>
      <pubDate>Fri, 19 Aug 2022 18:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-attach-pros-cons/m-p/8758#M339</guid>
      <dc:creator>Evert</dc:creator>
      <dc:date>2022-08-19T18:48:00Z</dc:date>
    </item>
  </channel>
</rss>

