Hello guys,
How third-party device work with 802.1AE 0x888e frame?
For example we need create this Topology
EX4300 macsec port -------access port SW access port ---------macsec port EX4300.
its should work?
Hello guys,
How third-party device work with 802.1AE 0x888e frame?
For example we need create this Topology
EX4300 macsec port -------access port SW access port ---------macsec port EX4300.
its should work?
Does your intermediate switch support MACSEC? If yes, then 'theoritcally' this should work but may need some tweaking to get settings properly done. If not, and device is indeed a switch, then answer is most likely will not work,ever. MACSEC is a point-to-point protocol and is not designed to support pass-through where MAC headers would change. I would fully expect the MACSEC link to not even come up - key exchange will fail.
Now if your intermediate device acted like a 'hub' then it might work. Likewise, IPSEC, would also not work in such a configuration, without IPSEC support at intermediate SW.
Good luck.
Just FYI. This enhanced supported is scheduled for 17.4 release, but will most likely only be supported (tested) with QFX5110, at least at that time frame. For any new deployments, people should only consider QFX5110, and not QFX5100. Whether EX4600 also receives this support is to be determined.
Again, just FYI.
i try test in lab:
EX4300 macsec port >>> bridge domain MX >>>> macsec port EX4550
this not working
EX4300 macsec port >>> L2Circ/connections MX >>>> macsec port EX4550
this working.
I don't understand why we can't wrap our 802.1AE in 802.1Q, then we will be able to forward on TAGs 802.1q
cisco support:
Support for VLAN tag in the clear option to enable Carrier Ethernet Service Multiplexing.
Dear All
I have a pair of EX 4550 running 12.3R7.7 in a virtual Chassis as dedicated iSCSI switches, we have been having xome issue with one of the storage units connected to the switches and the manufacture says we need to enable flow-control and have RX on and TX off.
When I connect to the switches the only option I have is to enable flow-control under ether-opitions or no-flow-control.
Does any one know is this a feature in a newer version of junos?
From some research I can see it is possible on the 4600 but can not find anything for the 4550.
Regards
Richard
Hi ,
I could see this workingin 12.3 , what error you are getting ?
# show | compare [edit interfaces] + xe-0/0/29 { + ether-options { + flow-control; + } + }
Hi,
we have ex4550 as core with ex4300 as edge switches. I would like to setup another ex4550 as an edge switch due to its 10G ports. I am not farmilar with the vstp setup on this model.
since this is an edge, would something like this
set protocols vstp vlan all bridge-priority 60k
set protocols vstp vlan 10 interface xe-0/0/0.0 edge
thank you in advance.
Why run any form of STP at all? STP designs (outside of Cisco) went out 10+ years ago. Just change the 2 x 10GE connections from remote EX4550 to EX4550 in the code to an AE/LAG and you'll have active-active on both links, without need to STP.
With today's various other technologies, STP should really never be needed. Primary case (for Juniper) is interoperability with previously configured/designed Cisco networks. For EX to EX, you could also use default RSTP config to start with.
I believe for EX4550 the only options are on or off for flow-control. You can not configure at the RX/TX levels.
For EX4600 and QFX51xx switches it is configureable at that level
Sorry!!
Because in 1st case you are changing the frame, as MX acts like a switch. In 2nd it is just pass through, where MX functions more like dark fiber connection, with no frame manipluation.
It is the way MX config options work. I am sure for Cisco their config option does the same thing, just different command structure.
My 2 cents worth.
Hi
Thank you for confirming that, such a basic reqirement on these switches but not supported. Hope Juniper get this sorted at some point.
Richard
Thank you for reply.
I want to know if supports Juniper this feature ( clear 802.1q tag)
See if this article shed some l;ight:
Sep 20 07:02:17 rcv: ch_ipc_dispatch() null ipc read for args 0x6c2800 pipe 0x6c60c0, fru FPC 0 errno 60 Sep 20 07:02:17 ch_connection_shutdown: Destroying the IPC pipe Sep 20 07:02:17 pic detach portinfo, pic 0 fpc 0 Sep 20 07:02:17 pic detach portinfo, pic 1 fpc 0 Sep 20 07:02:17 fpc_disconnect_generic: fpc 0 state Online cargs 0x6c2800 clean_shutdown 0, offline_reason=None Sep 20 07:02:17 -- FPC 0, last request 132, state Online Sep 20 07:02:17 CHASSISD_IPC_CONNECTION_DROPPED: Dropped IPC connection for FPC 0 Sep 20 07:02:17 CHASSISD_IFDEV_DETACH_FPC: ifdev_detach_fpc(0) Sep 20 07:02:46 ifdev_detach: skipping ifd vcp-255/0/0 Sep 20 07:02:46 ifdev_detach: skipping ifd vcp-255/0/1 Sep 20 07:05:19 ifd ge-0/0/2 marked as gone Sep 20 07:05:21 ifd ge-0/0/3 marked as gone Sep 20 07:05:21 ifd ge-0/0/4 marked as gone Sep 20 07:05:21 ifd ge-0/0/5 marked as gone Sep 20 07:05:22 ifd ge-0/0/6 marked as gone Sep 20 07:05:22 ifd ge-0/0/7 marked as gone Sep 20 07:05:22 ifd ge-0/0/8 marked as gone Sep 20 07:05:22 ifd ge-0/0/9 marked as gone Sep 20 07:05:22 ifd ge-0/0/10 marked as gone Sep 20 07:05:24 ifd ge-0/0/11 marked as gone Sep 20 07:05:24 ifd ge-0/0/12 marked as gone Sep 20 07:05:24 ifd ge-0/0/13 marked as gone Sep 20 07:05:24 ifd ge-0/0/14 marked as gone Sep 20 07:05:24 ifd ge-0/0/15 marked as gone Sep 20 07:05:25 ifd ge-0/0/16 marked as gone Sep 20 07:05:25 ifd ge-0/0/17 marked as gone Sep 20 07:05:25 ifd ge-0/0/18 marked as gone Sep 20 07:05:25 ifd ge-0/0/19 marked as gone Sep 20 07:05:25 ifd ge-0/0/20 marked as gone Sep 20 07:05:25 ifd ge-0/0/21 marked as gone Sep 20 07:05:25 ifd ge-0/0/22 marked as gone Sep 20 07:05:26 ifd ge-0/0/23 marked as gone Sep 20 07:05:27 fpc_offline_now - slot 0, reason: None, error Chassis connection dropped transition state 1 Sep 20 07:05:27 mic_get_mic_slot: clp1: fpc_slot=0, pic_slot=0, i2c=0xf037 Sep 20 07:05:27 mic_get_mic_slot: clp1: fpc_slot=0, pic_slot=1, i2c=0xf0c2 Sep 20 07:05:27 hwdb: entry for fpc 1335 at slot 0 deleted Sep 20 07:05:27 CHASSISD_SNMP_TRAP7: SNMP trap generated: FRU removal (jnxFruContentsIndex 7, jnxFruL1Index 1, jnxFruL2Index 0, jnxFruL3Index 0, jnxFruName FPC: EX2200-24T-4G @ 0/*/*, jnxFruType 3, jnxFruSlot 0) Sep 20 07:05:27 CHASSISD_SNMP_TRAP7: SNMP trap generated: FRU removal (jnxFruContentsIndex 7, jnxFruL1Index 1, jnxFruL2Index 0, jnxFruL3Index 0, jnxFruName FPC: EX2200-24T-4G @ 0/*/*, jnxFruType 3, jnxFruSlot 0) Sep 20 07:05:27 FPC 1 removed Sep 20 07:05:27 CHASSISD_SNMP_TRAP7: SNMP trap generated: FRU removal (jnxFruContentsIndex 7, jnxFruL1Index 2, jnxFruL2Index 0, jnxFruL3Index 0, jnxFruName FPC: EX2200-24T-4G @ 1/*/*, jnxFruType 3, jnxFruSlot 1) Sep 20 07:05:27 CHASSISD_FRU_OFFLINE_NOTICE: Taking FPC 1 offline: Removal Sep 20 07:05:27 fpc_down slot 1 reason Removal cargs 0x6c2b20 Sep 20 07:05:27 pic detach portinfo, pic 0 fpc 1 Sep 20 07:05:27 pic detach portinfo, pic 1 fpc 1 Sep 20 07:05:27 fpc_disconnect_generic: fpc 1 state Empty cargs 0x6c2b20 clean_shutdown 0, offline_reason=Removal Sep 20 07:05:27 -- FPC 1, last request 132, state Empty Sep 20 07:05:27 fpc_disconnect_generic - FPC 1 was removed! Sep 20 07:05:27 CHASSISD_IPC_CONNECTION_DROPPED: Dropped IPC connection for FPC 1 Sep 20 07:05:27 CHASSISD_IFDEV_DETACH_FPC: ifdev_detach_fpc(1) Sep 20 07:05:28 ifdev_detach: skipping ifd vcp-255/0/0 Sep 20 07:05:28 ifdev_detach: skipping ifd vcp-255/0/1 Sep 20 07:05:28 ifd ge-1/0/2 marked as gone Sep 20 07:05:28 ifd ge-1/0/3 marked as gone Sep 20 07:05:28 ifd ge-1/0/4 marked as gone Sep 20 07:05:28 ifd ge-1/0/5 marked as gone Sep 20 07:05:28 ifd ge-1/0/6 marked as gone Sep 20 07:05:29 ifd ge-1/0/7 marked as gone Sep 20 07:05:29 ifd ge-1/0/8 marked as gone Sep 20 07:05:29 ifd ge-1/0/9 marked as gone Sep 20 07:05:29 ifd ge-1/0/10 marked as gone Sep 20 07:05:29 ifd ge-1/0/11 marked as gone Sep 20 07:05:29 ifd ge-1/0/12 marked as gone Sep 20 07:05:29 ifd ge-1/0/13 marked as gone Sep 20 07:05:29 ifd ge-1/0/14 marked as gone Sep 20 07:05:30 ifd ge-1/0/15 marked as gone Sep 20 07:05:30 ifd ge-1/0/16 marked as gone Sep 20 07:05:30 ifd ge-1/0/17 marked as gone Sep 20 07:05:30 ifd ge-1/0/18 marked as gone Sep 20 07:05:30 ifd ge-1/0/19 marked as gone Sep 20 07:05:30 ifd ge-1/0/20 marked as gone Sep 20 07:05:30 ifd ge-1/0/21 marked as gone Sep 20 07:05:31 ifd ge-1/0/22 marked as gone Sep 20 07:05:31 ifd ge-1/0/23 marked as gone Sep 20 07:05:31 fpc_offline_now - slot 1, reason: Removal, error Chassis connection dropped transition state 1
I believe that link talks about how to set up promiscous mode on an SRX, generally used for off-line traffic analysis via a port mirror with a SRX.
Nishant1, if you want assistance please tell us which product, what SW release, and more details, such as maybe the whole log file.
What do the logs on the missing VC member say? This essentially just says the missing member became disconnected.
HI
As mentioned we need logs from other members as well to understand why its dropping connection to the FPC.
Suggest if you could raise a JTAC case.
Regards
Partha
Hi thx for answer here's related log from backup member
Sep 20 07:02:13 op 3 for ifd bme0 Sep 20 07:02:13 op 1 for ifd lo0 Sep 20 07:02:13 could not retrive old mac address 0 Sep 20 07:02:13 CHASSISD_ACQUIRE_MASTERSHIP: Acquire mastership notification Sep 20 07:02:13 if_init Sep 20 07:02:13 ifdev_learn_pic_types: Sep 20 07:02:13 skipping ifd vcp-255/0/0 Sep 20 07:02:13 skipping ifd vcp-255/0/1 Sep 20 07:02:13 mcontrol_acquire_mastership Calling reconnect Sep 20 07:02:13 ch_ipc_reconnect Sep 20 07:02:13 ch_ipc_reconnect reconnect configured Sep 20 07:02:13 ch_ipc_reconnect reconnect proceed Sep 20 07:02:13 ch_ipc_reconnect_wait for 10 seconds Sep 20 07:02:13 hw.vc.member_valid_bitmap = 2 Sep 20 07:02:13 CHASSISD_IFDEV_DETACH_FPC: ifdev_detach_fpc(0) Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/0 Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/1 Sep 20 07:02:13 CHASSISD_IFDEV_DETACH_FPC: ifdev_detach_fpc(2) Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/0 Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/1 Sep 20 07:02:13 CHASSISD_IFDEV_DETACH_FPC: ifdev_detach_fpc(3) Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/0 Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/1 Sep 20 07:02:13 CHASSISD_IFDEV_DETACH_FPC: ifdev_detach_fpc(4) Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/0 Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/1 Sep 20 07:02:13 CHASSISD_IFDEV_DETACH_FPC: ifdev_detach_fpc(5) Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/0 Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/1 Sep 20 07:02:13 CHASSISD_IFDEV_DETACH_FPC: ifdev_detach_fpc(6) Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/0 Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/1 Sep 20 07:02:13 CHASSISD_IFDEV_DETACH_FPC: ifdev_detach_fpc(7) Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/0 Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/1 Sep 20 07:02:13 CHASSISD_IFDEV_DETACH_FPC: ifdev_detach_fpc(8) Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/0 Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/1 Sep 20 07:02:13 CHASSISD_IFDEV_DETACH_FPC: ifdev_detach_fpc(9) Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/0 Sep 20 07:02:13 ifdev_detach: skipping ifd vcp-255/0/1 Sep 20 07:02:13 rtsock_handle_mastership_switch Sep 20 07:02:13 rtsock_init non ifstate async socket Sep 20 07:02:13 Learnt system mac base f0:1c:2d:5e:3e:40 Sep 20 07:02:13 create_pseudo_entry: pic desc 161, speed 0, hw qs 8supported qs 8, flags 0x0 Sep 20 07:02:13 CHASSISD_IFDEV_CREATE_NOTICE: create_pseudos: created pseudo interface device for ae0 Sep 20 07:02:13 ifdev_create entered ae0 Sep 20 07:02:13 create_pseudo_entry: pic desc 161, speed 0, hw qs 8supported qs 8, flags 0x0 Sep 20 07:02:13 CHASSISD_IFDEV_CREATE_NOTICE: create_pseudos: created pseudo interface device for ae1 Sep 20 07:02:13 ifdev_create entered ae1 Sep 20 07:02:13 create_pseudo_entry: pic desc 161, speed 0, hw qs 8supported qs 8, flags 0x0 Sep 20 07:02:13 CHASSISD_IFDEV_CREATE_NOTICE: create_pseudos: created pseudo interface device for ae2 Sep 20 07:02:14 ifdev_create entered ae2 Sep 20 07:02:14 create_pseudo_entry: pic desc 161, speed 0, hw qs 8supported qs 8, flags 0x0 Sep 20 07:02:14 CHASSISD_IFDEV_CREATE_NOTICE: create_pseudos: created pseudo interface device for ae3 Sep 20 07:02:14 ifdev_create entered ae3 Sep 20 07:02:14 create_pseudo_entry: pic desc 161, speed 0, hw qs 8supported qs 8, flags 0x0 Sep 20 07:02:14 CHASSISD_IFDEV_CREATE_NOTICE: create_pseudos: created pseudo interface device for ae4 Sep 20 07:02:14 ifdev_create entered ae4 Sep 20 07:02:14 create_pseudo_entry: pic desc 161, speed 0, hw qs 8supported qs 8, flags 0x0 Sep 20 07:02:14 CHASSISD_IFDEV_CREATE_NOTICE: create_pseudos: created pseudo interface device for ae5 Sep 20 07:02:14 ifdev_create entered ae5 Sep 20 07:02:14 create_pseudo_entry: pic desc 161, speed 0, hw qs 8supported qs 8, flags 0x0 Sep 20 07:02:14 CHASSISD_IFDEV_CREATE_NOTICE: create_pseudos: created pseudo interface device for ae6 Sep 20 07:02:14 ifdev_create entered ae6 Sep 20 07:02:14 create_pseudo_entry: pic desc 161, speed 0, hw qs 8supported qs 8, flags 0x0 Sep 20 07:02:14 CHASSISD_IFDEV_CREATE_NOTICE: create_pseudos: created pseudo interface device for ae7 Sep 20 07:02:14 ifdev_create entered ae7 Sep 20 07:02:14 create_pseudo_entry: pic desc 161, speed 0, hw qs 8supported qs 8, flags 0x0 Sep 20 07:02:14 CHASSISD_IFDEV_CREATE_NOTICE: create_pseudos: created pseudo interface device for ae8 Sep 20 07:02:14 ifdev_create entered ae8 Sep 20 07:02:14 create_pseudo_entry: pic desc 161, speed 0, hw qs 8supported qs 8, flags 0x0 Sep 20 07:02:14 CHASSISD_IFDEV_CREATE_NOTICE: create_pseudos: created pseudo interface device for ae9 Sep 20 07:02:14 ifdev_create entered ae9 Sep 20 07:02:14 create_pseudo_entry: pic desc 161, speed 0, hw qs 8supported qs 8, flags 0x0 Sep 20 07:02:14 CHASSISD_IFDEV_CREATE_NOTICE: create_pseudos: created pseudo interface device for ae10 Sep 20 07:02:14 ifdev_create entered ae10 Sep 20 07:02:14 create_pseudo_entry: pic desc 161, speed 0, hw qs 8supported qs 8, flags 0x0 Sep 20 07:02:14 CHASSISD_IFDEV_CREATE_NOTICE: create_pseudos: created pseudo interface device for ae11 Sep 20 07:02:14 ifdev_create entered ae11 Sep 20 07:02:14 create_pseudo_entry: pic desc 161, speed 0, hw qs 8supported qs 8, flags 0x0 Sep 20 07:02:14 CHASSISD_IFDEV_CREATE_NOTICE: create_pseudos: created pseudo interface device for ae12 Sep 20 07:02:14 ifdev_create entered ae12 Sep 20 07:02:15 create_pseudo_entry: pic desc 161, speed 0, hw qs 8supported qs 8, flags 0x0 Sep 20 07:02:15 CHASSISD_IFDEV_CREATE_NOTICE: create_pseudos: created pseudo interface device for ae13 Sep 20 07:02:15 ifdev_create entered ae13 Sep 20 07:02:15 create_pseudo_entry: pic desc 161, speed 0, hw qs 8supported qs 8, flags 0x0 Sep 20 07:02:15 CHASSISD_IFDEV_CREATE_NOTICE: create_pseudos: created pseudo interface device for ae14 Sep 20 07:02:15 ifdev_create entered ae14 Sep 20 07:02:15 create_pseudo_entry: pic desc 161, speed 0, hw qs 8supported qs 8, flags 0x0 Sep 20 07:02:15 CHASSISD_IFDEV_CREATE_NOTICE: create_pseudos: created pseudo interface device for ae15 Sep 20 07:02:15 ifdev_create entered ae15 Sep 20 07:02:15 CHASSISD_IFDEV_CREATE_NOTICE: ch_vlan_ifd_add: created interface device for vlan Sep 20 07:02:15 CHASSISD_IFDEV_CREATE_NOTICE: ch_vlan_ifd_add: created interface device for vme Sep 20 07:02:15 snmp_rfc3621_init: Initializing the POE MIB OIDs Sep 20 07:02:15 main_snmp_init Sep 20 07:02:15 snmp_init: snmp_chassis_id = 0, chas_type = 2 Sep 20 07:02:15 chas_do_registration: or_obj = 0x4b3600, or_rows = 21 Sep 20 07:02:15 chas_do_registration: or_obj = 0x4b3a00, or_rows = 21 Sep 20 07:02:15 chas_do_registration: or_obj = 0x4b3800, or_rows = 21 Sep 20 07:02:15 chas_do_registration: or_obj = 0x4b3c00, or_rows = 21 Sep 20 07:02:15 chas_do_registration: or_obj = 0x4b3e00, or_rows = 21 Sep 20 07:02:34 CHASSISD_SNMP_TRAP10: SNMP trap generated: redundancy switchover (jnxRedundancyContentsIndex 9, jnxRedundancyL1Index 1, jnxRedundancyL2Index 0, jnxRedundancyL3Index 0, jnxRedundancyDescr Routing Engine 1, jnxRedundancyConfig 3, jnxRedundancyState 1, jnxRedundancySwitchoverCount 1, jnxRedundancySwitchoverTime -731504074, jnxRedundancySwitchoverReason 4) Sep 20 07:02:34 ch_ipc_reconnect_expired: timer expired Sep 20 07:02:34 FM ch_java_restart_ipc_reconnect_window: fpc_reconnects=0, fpc_present=1 Sep 20 07:02:34 ch_ipc_reconnect_expired: restarting reconnect window Sep 20 07:02:34 ch_ipc_reconnect_wait for 10 seconds Sep 20 07:02:34 ipc pipe 0x6c81c0 created Sep 20 07:02:34 ch_signal_proc: Sent signal 1 to tnp.sntpd, pid=1210 Sep 20 07:02:34 fpc 1 ready, pipe 0x0x6c81c0 Sep 20 07:02:34 ifdev_detach_check: skipping ifd vcp-255/0/0 (what=0) Sep 20 07:02:34 ifdev_detach_check: skipping ifd vcp-255/0/1 (what=0) Sep 20 07:02:35 fpc 1 clean, bringing online Sep 20 07:02:35 send_chassisd_capabs: send chassisd capabilities Sep 20 07:02:35 send: fpc 1 online cmd Sep 20 07:02:35 op 1 for ifd ae0 Sep 20 07:02:35 FPC 1 online ack Sep 20 07:02:35 fpc_announce_online_generic: fpc 1 Sep 20 07:02:35 fpc_online_now - slot 1 - Online Sep 20 07:02:35 ch_java_sfpplus_send_config_to_cm: sending info fpc 1 pic 1 mode 10 Sep 20 07:02:35 send: fpc 1 Disk Mon stats Sep 20 07:02:35 send: fpc 1 Disk Mon stats Sep 20 07:02:35 send: fpc 1 Disk Mon stats Sep 20 07:02:35 send: fpc 1 Disk Mon stats Sep 20 07:02:35 fpc 1 creates device Sep 20 07:02:35 fpc_create_devs: No fpc based dev is required for fpc slot 1, skip fpc dev creationWhen I connected to the switch after 8:00 the chasis status was ok and all members are online
Preprovisioned Virtual Chassis Virtual Chassis ID: d63b.2fbd.4ee5 Virtual Chassis Mode: Enabled Mstr Mixed Neighbor List Member ID Status Serial No Model prio Role Mode ID Interface 0 (FPC 0) Prsnt CW0214440178 ex2200-24t-4g 129 Master* NA 1 vcp-255/0/0 1 vcp-255/0/1 1 (FPC 1) Prsnt CW0214440364 ex2200-24t-4g 129 Backup NA 0 vcp-255/0/0 0 vcp-255/0/1thanks
Looks like the virtual chassis interface connection dropped between the switches and was then restored.
Use the show interface command on the VC port and see when the "last flap" was. If this lines up with the time of the logs then the loss of link on the VC is confirmed.
show interface ge-x/x/x
HI
Are you seeing these message in switch or SRX?
https://www.juniper.net/documentation/en_US/junos/topics/concept/interface-security-ethernet-promiscuous-mode-understanding.html
Regards
Partha