hpcTech

updated

5 years ago

H

hpcTech

1 Rookie

27 Posts

0

751

December 21st, 2021 20:00

Needle in a haystack on two 6248s

Hello,

I have 2 6248s stacked, 14 hypervisors running between 6-20 VM (on each hypervisor) and noticed I'm not getting decent traffic bandwidth to the ISP or over VPN or the SSH servers behind the firewalls.  We have 100/100, but my speed tests plugged directly into the switch on my laptop give me 45/90.  I really do not know what to look for on these old switches that I can use as data to go to the manager and say "these are the problems". 

Speed tests from the ISP RJ45 drop give us 100/100.  Speed tests from the 4 VLAN switch that the ISP and firewalls + LAN of the firewalls are plugged into give me 45/90.  We have HA WatchGuards and HA Palo Altos that are plugged into each switch in the event of a failure.  Speed test directly attached to each firewall device give us the same 45/90, making it seem that the problem is NOT with any of the firewalls and the switches directly.  I just don't have a "smoking gun" and my manager is very head strong, seeing as he's the one that built out this network configuration before I was employed here, however, since I've gotten everyone using the VPN the people that never used it before are complaining that it's slower than performing SCP transfers with the SSH servers using firewall forwarding policies.  I was trying to get all servers behind the firewall via VPN/2FA so we don't constantly have to worry about things like log4j (if they aren't publicly accessible).  He told me to look into it, I have, and it's my sneaking suspicion that the switch just cannot keep up with the packet forwarding rates of all the servers+VMs.  Unfortunately it's not my dime, so I can't just ask him to "trust me" either.  Similar situations, newer switches with higher forwarding rates and more switch fabric bandwidth have solved my problems.  The 6248s are 186GBps total fabric bandwidth, but I don't see us using anywhere near that amount of bandwidth leading me to think it's the amount of total packets being sent through the switch stack?

It's like trying to find a needle in a haystack - so what should I be looking for on the 6248s?  I do see high dropped transmit and received packets.  The only thing that's stood out to me in the specs of the switches is the forwarding rate is 143Mpps - how can I tell if this is enough for our current operation?

Thanks,

Lost Admin