Friday, July 19, 2019

Cisco 6840/6880 VSS or Nexus 9K (Greenfield DC WAN Aggregation Design) ?

Hoping for some real world feedback and input on a WAN Aggregation design constraint our organization is dealing with. We also are getting conflicting information from our SE team at Cisco. High Level Diagram Link.

Voice outsourcing vendor environment. We are building out a greenfield DC and are having internal discussions on WAN Aggregation [switch block] design for the datacenter. We have VRF-lite within the datacenter (and full VRF implementations across multiple MPLS providers) that we extend (L2) down from the WAN aggregation block to our telephony environment (SBCs). We have a lot of customers dropping connectivity directly into the DC also that we have to terminate. Business requirements also mandate use of WCCP redirection for web filtering appliances (more on that below).

We have two options available (mostly because we already have these in inventory) for use for the project, Cat6840s (also could use Cat6880s if anyone can provide a tangible benefit to using that vs 6840) or Nexus 93180-YC-EX switches for the core WAN Aggregation switches.

Our (WCCP) design requires the use of Cat switches somewhere in the design as they natively support WCCP-redirect. Our web filtering infrastructure hangs directly off the 6800s in the design. We looked briefly at N9K ITD (Intelligent Traffic Redirection) but it did not work with our requirements (multiple service groups and server clusters).

In a perfect Utopian world, we would (and management wants) a 6800 'Core' WAN Aggregation switch block in a VSS configuration with pairs of Nexus 93180s hanging off of it in an etherchannel/vPC configuration for additional port density. I however have concerns about the single control plane (and single point of failure it presents) with the VSS configuration. I know VSS has come a long way in terms of stability from when it first was implemented and I guess I have some biased due to past issues.

Do I bother fighting/pushing management towards using N9Ks as the 'core' switch block and reverse the design so that that Cat6800s hang off of them (router on a stick design solely to support the WCCP-redirect)?

I posed this exact question to our (usually very helpful) SE team at Cisco and was surprised with the response of using Cat vs N9K due to concerns about routing protocol peering over vPC. Their quotes were

"I spoke to "X-Senior Engineer" briefly about the 9k positioning. He agreed with me about the peering of routing protocols over vPC. He did not see any reason for concern but did prefer the 6800/VSS. He didn’t cite [additional] technical reasons, I think we’ve just been ‘raised’ @ Cisco to position Cat in those scenarios."

I asked for any CVDs they could share and they never got back to me.

Am I crazy to not want Cat6800 VSS as Core [WAN Aggregation] switch in a datacenter? Thank you all in advance for any input or advice and for reading this long blurb.



No comments:

Post a Comment