02-27-2020 02:22 PM
Greetings HUB Community,
We have a VSP7024 which was configured prior to my involvement. It is behaving as a BCB in an SPBM environment connecting about 15 VSP 4850s in a hub/spoke configuration. System has been working flawlessly.
We recently acquired 8 Windows Servers that we plan on connecting via available 10Gb SFP+ interfaces on the VSP7024. When I took a look at the initial configuration of the 7024, all the ports were configured for ISIS/SPBM connections. I removed the ISIS/SPBM configuration from ports 6 and 8 (where a pair of Windows servers will connect), created vlan 150 and assigned that vlan to the ports. I added an i-sid designation for vlan 150. as well.
On the VSP 4850 I created vlan 150 and assigned that vlan to port 1 (our test laptop). I added the i-sid as well for vlan 150. Seemed simple enough. I can get the servers to ping each other locally. I can get the laptop to ping the 4850 and vice versa. However, I cannot get a successful ping across the SPBM interface. Both switches show vlan 150, both are recognizing the i-sid for vlan 150 (10150) and there is an established ISIS adjacency. Firewalls have been disabled.
I have extracted some relevant config and output info from the 2 switches for your review. Getting ready to involve TAC, but I wanted to start here.
******************* 7024 Config Excerpt ************************
vlan create 150 type port 1
vlan create 4050-4051 type spbm-bvlan
vlan ports 1-5,7,9-39 tagging tagAll
vlan configcontrol flexible
vlan members 1 NONE
vlan members 150 6,8
vlan ports 6,8 pvid 150
vlan configcontrol strict
spbm router isis
spbm 1
spbm 1
b-vid 4050-4051 primary 4050
spbm 1 nick-name 0.07.01
manual-area 10.0001
interface Ethernet 1-5,7,9-39
isis
isis spbm 1
isis enable
exit
router isis
system-id 0011.0011.0701
sys-name "VSP7K.1"
exit
i-sid 10150 vlan 150
router isis enable
***************** some 7024 output ******************
SWITCH# show isis adj
===============================================================================
ISIS Adjacencies
===============================================================================
INTERFACE L STATE UPTIME PRI HOLDTIME SYSID HOST-NAME
===============================================================================
[output ommited]
Port: 21 1 UP 13d 20:14:49 127 26 0011.0011.0421 VSP4K-21
[output ommited]
SWITCH# show isis spbm i-sid all 10150
===============================================================================
SPBM ISID INFO
===============================================================================
ISID SOURCE NAME VLAN SYSID TYPE HOST-NAME
===============================================================================
10150 0.04.21 4051 0011.0011.0421 discover VSP4K-21
10150 0.07.01 4051 0011.0011.0701 config VSP7K.1
-------------------------------------------------------------------------------
Total number of SPBM ISID entries configured: 1
-------------------------------------------------------------------------------
Total number of SPBM ISID entries discovered: 1
-------------------------------------------------------------------------------
Total number of SPBM ISID entries: 2
-------------------------------------------------------------------------------
************************** 4850 Config Excerpt ********************
spbm
interface GigabitEthernet 1/47-1/50
encapsulation dot1q
exit
router isis
spbm 1
spbm 1 nick-name 0.04.21
spbm 1 b-vid 4050-4051 primary 4050
spbm 1 multicast enable
spbm 1 multicast fwd-cache-timeout 60
spbm 1 ip enable
exit
vlan members remove 1 1/1,1/3-1/50
vlan i-sid 1 1
vlan create 150 type port-mstprstp 1
vlan members 150 1/1 portmember
vlan i-sid 150 10150
interface Vlan 150
ip address 10.10.150.1 255.255.255.0
ip spb-multicast enable
ip dhcp-relay
exit
vlan create 4050 type spbm-bvlan
vlan create 4051 type spbm-bvlan
interface GigabitEthernet 1/1-1/46
no shutdown
no spanning-tree mstp force-port-state enable
no spanning-tree mstp msti 1 force-port-state enable
exit
interface GigabitEthernet 1/47-1/50
default-vlan-id 0
no shutdown
isis
isis spbm 1
isis enable
no spanning-tree mstp force-port-state enable
no spanning-tree mstp msti 62 force-port-state enable
exit
interface loopback 1
ip address 1 172.16.4.21/255.255.255.255
exit
ip dhcp-relay fwd-path 10.10.6.3 10.10.1.202
ip dhcp-relay fwd-path 10.10.6.3 10.10.1.202 enable
ip dhcp-relay fwd-path 10.10.6.3 10.10.1.202 mode bootp_dhcp
router isis
sys-name "VSP4K-21"
ip-source-address 172.16.4.21
is-type l1
system-id 0011.0011.0421
manual-area 10.0001
exit
router isis enable
router isis
redistribute direct
redistribute direct metric 1
redistribute direct enable
exit
isis apply redistribute direct
Solved! Go to Solution.
03-03-2020 03:14 PM
Thanks for the support all. For future searches, a software upgrade from 10.4.0 to 10.4.6 solved the issue.
03-03-2020 03:14 PM
Thanks for the support all. For future searches, a software upgrade from 10.4.0 to 10.4.6 solved the issue.
02-28-2020 09:30 PM
Not sure exactly what I am looking at when I run that command (show isis lsdb detail), but I don’t see any incorrect addressing as far as I can tell.
Got a TAC engineer looking into it. Thanks Martin.
Mike S.
02-27-2020 11:03 PM
Hmm, the VLAN settings on the ports is fine. I guess the unreachable servers have IP addresses 10.10.150.21 and 10.10.150.22? The ARP table contains those records. I have seen the similar problem on VSP 7024. Other switches in fabric had wrong Chassis MAC for that VSP 7024 is LSDB.
I suggest checking show isis lsdb detail
on VSP 4850. Check Chassis MAC for VSP7K.1.
02-27-2020 04:36 PM
Thanks for the reply Martin. Here’s the output (sorry about the formatting):
****************** VSP4K ***************
show interface gig vlan 1/1
====================================================================================================
Port Vlans
====================================================================================================
PORT DISCARD DISCARD DEFAULT VLAN PORT UNTAG DYNAMIC UNTAG
NUM TAGGING TAGFRAM UNTAGFRAM VLANID IDS TYPE DEFVLAN VLANS VLANS
----------------------------------------------------------------------------------------------------
1/1 disable false false 150 150 normal disable P 150
----------------------------------------------------------------------------------------------------
DYNAMIC VLAN Legend:
P=Protocol enabled.
VSP4K-21:1#show ip arp
==========================================================================================
IP Arp - GlobalRouter
==========================================================================================
IP_ADDRESS MAC_ADDRESS VLAN PORT TYPE TTL(10 Sec) TUNNEL
------------------------------------------------------------------------------------------
[output omitted]
10.10.150.1 b4:a9:5a:2c:d0:83 150 - LOCAL 2160
10.10.150.21 b0:26:28:d6:eb:d1 150 1/49 DYNAMIC 2160 VSP7K.1
10.10.150.22 b0:26:28:7d:99:a1 150 1/49 DYNAMIC 2159 VSP7K.1
10.10.150.200 d8:d0:90:08:ed:aa 150 1/1 DYNAMIC 2156
10.10.150.255 ff:ff:ff:ff:ff:ff 150 - LOCAL 2160
[output omitted]
VSP4K-21:1#ping 10.10.150.21
ping: timeout
no answer from 10.10.150.21
************************* VSP7K ********************
Virtual Services Platform 7024XLS
HW:06 FW:10.1.0.6 SW:v10.4.0.003
VSP7K-1#show vlan interface vids 6,8
Port VLAN VLAN Name VLAN VLAN Name VLAN VLAN Name
---- ---- ---------------- ---- ---------------- ---- ----------------
6 150 VLAN #150
---- ---- ---------------- ---- ---------------- ---- ----------------
8 150 VLAN #150
---- ---- ---------------- ---- ---------------- ---- ----------------
show vlan interface info 6,8
Filter Filter
Untagged Unregistered
Port Frames Frames PVID PRI Tagging Name
---- -------- ------------ ---- --- ------------- ----------------
6 No Yes 150 0 UntagAll Port 6
8 No Yes 150 0 UntagAll Port 8