18 Posts
0
1365
June 16th, 2020 18:00
Swapping LAG from VLT to Juniper VC
I have a pair of S4810s configured via VLT, they are my core, running OSPF. I have 5 Juniper Access VCs LAG'd via VLT peer lag settings to the pair with stretched L2 and a L3 management IP. Works great. I have now added a Juniper QFX 5120 VC LAG'd to the S4810s via two of the 40G ports. Bundle forms and L2/L3 works as expected. LLDP shows neighbors, no problems.
What I want to do is swing the Juniper Access VC LAGs over from the S4810s to the QFX VC. When I do this, I get very odd results.
I can ping the moved Juniper Access VC from the QFX. I can also often ping it from one of the S4810s, but not both. But I'm no longer able to ping the moved VC from other segments. I'm aware that during a fault scenario, VLT will not pass ICMP but the disruption impacts more than just ICMP. If the same management segment is tagged to the Po on the Dells and the ae on the Juniper VC, I should be able to ping the access VC regardless of the Po/ae it is connected to.
We are using OSPF to advertise routes. show vlt mismatch indicates no errors. RSTP does not appear to be blocking.
VLT Config (for one of the two S4810s) for example :
vlt domain 999
peer-link port-channel 128
back-up destination 10.31.10.61
primary-priority 1
system-mac mac-address a0:10:10:00:03:e7
unit-id 0
peer-routing
peer-routing-timeout 10
interface fortyGigE 0/52
description VLTi
no ip address
mtu 9252
no shutdown
interface fortyGigE 0/60
description VLTi
no ip address
mtu 9252
no shutdown
interface Port-channel 128
description PCH-128-VLTi
no ip address
mtu 12000
channel-member fortyGigE 0/52,60
no shutdown
#show vlt stat
VLT Domain Statistics
-----------------------
HeartBeat Messages Sent: 106881849
HeartBeat Messages Received: 106897332
ICL Hello's Sent: 35627280
ICL Hello's Received: 35632444
Domain Mismatch Errors: 0
Version Mismatch Errors: 0
Config Mismatch Errors: 0
VLT MAC Statistics
--------------------
L2 Info Pkts sent:77828, L2 Mac-sync Pkts Sent:2508527
L2 Info Pkts Rcvd:116139, L2 Mac-sync Pkts Rcvd:2633496
L2 Reg Request sent:1
L2 Reg Request rcvd:2
L2 Reg Response sent:1
L2 Reg Response rcvd:1
VLT Igmp-Snooping Not Enabled
VLT ARP Statistics
--------------------
ARP Tunnel Pkts sent:17867057
ARP Tunnel Pkts Rcvd:130235814
ARP Tunnel Pkts sent Non Vlt:2893675
ARP Tunnel Pkts Rcvd Non Vlt:26952255
ARP-sync Pkts Sent:2453484
ARP-sync Pkts Rcvd:1120365
ARP Reg Request sent:2
ARP Reg Request rcvd:2
VLT NDP Statistics
--------------------
NDP NA VLT Tunnel Pkts sent:0
NDP NA VLT Tunnel Pkts Rcvd:0
NDP NA Non-VLT Tunnel Pkts sent:0
NDP NA Non-VLT Tunnel Pkts Rcvd:0
Ndp-sync Pkts Sent:0
Ndp-sync Pkts Rcvd:1
Ndp Reg Request sent:1
Ndp Reg Request rcvd:2
VLT multicast not enabled
#show vlt brief
VLT Domain Brief
------------------
Domain ID: 999
Role: Primary
Role Priority: 1
ICL Link Status: Up
HeartBeat Status: Up
VLT Peer Status: Up
Local Unit Id: 0
Version: 6(7)
Local System MAC address: f4:8e:38:04:7f:05
Remote System MAC address: f4:8e:38:03:92:0b
Configured System MAC address: a0:10:10:00:03:e7
Remote system version: 6(7)
Delay-Restore timer: 90 seconds
Delay-Restore Abort Threshold: 60 seconds
Peer-Routing : Enabled
Peer-Routing-Timeout timer: 10 seconds
Multicast peer-routing timeout: 150 seconds
Has anyone seen anything like this? I've played with making the Po that links to the QFX hybrid, but that has no impact on what is occurring.


dfollis
18 Posts
0
June 17th, 2020 10:00
Update on this. After way too much testing we realized the Junos version shipped on the QFXs did not support VC (even though the units DID for a virtual chassis!!!). So we updated to 19.3R2-S3 and that fixed the issue. Information wasn't immediately obvious on the Juniper support site.