Monday, December 30, 2019

Routing packet loss on Nexus running VPC

Trying to get my head wrapped around a packet loss issue we're experiencing on a pair of Nexus Switches.

2x Nexus 3548's in VPC cluster

https://imgur.com/Zhkbjmn

The Nexus switches are acting as the routing core for our network. The Nexus share OSPF routes to/from our firewall cluster on a stick for MPLS and internet.

We have a variety of edge switches + switch stacks connected to our Nexus core. Each switch has 2x 10GB fiber uplinks back to the nexus, split 50/50 between the two Nexus switches for redundancy. All uplinks are layer 2 LACP trunks.

Aside from this weird packet loss issue when routing between VLANs everything else seems to be working fine.

Packet loss issue is not reported when routing from internal VLANs outbound to the MPLS or internet. Issue only occurs between VLANs terminated to the Nexus.

Scenario: New server is connected directly to the Nexus switches, 1x 10gb cable to each switch in a VPC LACP etherchannel. Windows Server is set in LACP mode for load balancing. LACP comes online and traffic gets through. Uplink ports to the server are untagged on VLAN 40.

From a layer 2 perspective everything seems ok. The server can communicate with anything on the same VLAN without issue.

But when it tries to route to any of other other VLANs terminated on the Nexus we get about 50% packet loss. Instinct tells me that when packets are sent to Nexus A they get routed fine, but when the hit Nexus B the packets are being dropped or aren't getting routed.

Relevant config:

feature vrrp feature ospf feature interface-vlan feature hsrp feature lacp feature vpc feature lldp 

vrf context vpc_keepalive

vpc domain 5

peer-switch peer-keepalive destination 123.1.1.2 source 123.1.1.1 vrf vpc_keepalive peer-gateway auto-recovery 

spanning-tree vlan 1-3,10,40,50,80,101,200-205,2011,2020,2030 priority 0

interface Vlan10

no shutdown no ip redirects ip address 10.20.1.2/24 ip ospf passive-interface ip router ospf 100 area 0.0.0.0 hsrp 201 preempt delay minimum 300 priority 110 ip 10.20.1.1 

interface Vlan40

no shutdown no ip redirects ip address 10.1.40.1/24 ip ospf passive-interface ip router ospf 100 area 0.0.0.0 hsrp 40 preempt delay minimum 300 priority 110 ip 10.1.40.5 

interface Vlan101

no shutdown no ip redirects ip address 10.0.101.4/24 no ip ospf passive-interface ip router ospf 100 area 0.0.0.0 

interface port-channel30

speed 10000 switchport switchport mode access switchport access vlan 40 vpc 30 

interface Ethernet1/45

switchport switchport mode access switch access vlan 40 channel-group 30 mode active no shutdown 


PoE Wirless Router

Hi,

Does anyone know a wireless router with 4 ports and at least two of them with PoE?

Thanks



Potential MTU issue between Meraki MX and ASA5515

We have a client with a Meraki MX utilizing SDWAN (bonding two internet circuits) connecting to our ASA5515 via IPSEC tunnel.

After deploying SDWAN at the client site, we have started to see sporadic issues with HTTPS and other TCP traffic across the tunnel. PCAPS show a successful TCP handshake and so far the only issues I can see are the occasional TCP retransmission and a MTU fragmentation rarely. These issues are only remedied temporarily by bouncing the VPN from the Meraki side. When performing a TCP dump from the SDWAN bonder at the client site, I am seeing sporadic MTU errors:

14:29:26.018413 IP SDWANBONDER > CLIENTMX: ICMP (ASA5515) unreachable - need to frag (mtu 1452), length 556

I've done some pings across the tunnel from a client device to a server hosted behind the ASA5515 and found that the MTU of next hop is 1374. After finding this MTU, I configured the MTU of the SDWAN bonder interfaces to 1346 but started noticing other progressive network issues, so I have since reverted these changes.

Does anyone have any suggestions for how I can approach this problem? I have not experienced it when doing MX to MX VPN with SDWAN, only MX to ASA so far.



Bandwidth to edge devices, when is enough really enough?

Hopefully this makes sense. But I understand Server bandwidth inside a data center will always increase to handle the workload of thousands of connections occurring simultaneously. But traditionally we can see that Data Centers have backbones that are far GREATER speeds compared to end devices (workstations etc...).

With this being said what I'm trying to think about is, will we ever reach a limit in terms of bandwidth speeds to end devices that will be able to accommodate for any type of applications/software/connections/resolution that it needs? Like, even the most bandwidth intense applications with the highest resolutions possible, what does that look like from a bandwidth perspective for an end user?

I would think that the biggest player in figuring out what speed will be needed (10GIG/100GIG etc..) is the resolution of the application being used. 4k, 8k, 16k, virtual reality?

Have there been any bandwidth tests using these resolutions? I know youtube videos now support 4k, but I have no idea how to find any information on 16k and Virtual Reality bandwidth specifications.

Anyone have any clue where to find this information?



Cisco SD-WAN versioning meaning?

I think I follow Cisco's versioning for routers/switches. From what I read, every third release is a "stable" release. For instance 16.3, 16.6, 16.9, 16.12 are the releases that receive longer term maintenance.

What about for SD-WAN? They have 17.2, 18.3, 18.4, 19.1, 19.2, and now 19.3.

Basically they just released 19.3, I was on 19.2, it's unclear to me whether I should upgrade to 19.3, or stay on 19.2 and wait for further maintenance releases to that branch

EDIT:

I should add, this is the only actual notice I can find: https://www.cisco.com/c/en/us/products/collateral/routers/sd-wan/eos-eol-notice-c51-743306.html Stating that anything 18.3 and older is end of support Dec 24 2020.



54% higher efficiency for Starlink: Network topology design at 27,000 km/hour

/r/spacex/comments/efhz3x/54_higher_efficiency_for_starlink_network/

static routes

Hello,

First of all I would like to say that I am new in networking and I have no idea how things work. I have really bad ethernet connection speed so I bought cheap USB WiFi adapter, I connected it to pc and everything works fine. Now I have 2 connections 1 via ethernet and 1 via WiFi. I would like to use ethernet for everything except streaming live on youtube via obs. I already searched up some things and come to find out that I need to set a static route. After about 4h of research and I still have no idea how to set that up. Any help would be very welcome, thanks in advance, Nejc.



Have a situation...need to battery power a POE switch in the field

So the issue I'm running into is that I'm seeing that most are 48V input...which is quite high and requires a large battery......any POE which runs at a lower input voltage. Anything hooked to iit will be only 5V at most...



Hey everyone, I'm trying to reach people who would be interested in MRP/ERP software for small-medium sized manufacturing businesses (more details in the description)

Hi, i'm a representative of MRPeasy - a provider of cloud-based MRP/ERP software for manufacturers. Our goal is to reach as many businesses as possible, who might benefit from such a system.

Instead of spamming subreddits with links, I prefer to engage with people directly, and attempt to present something of value - after all, why should you bother clicking a link? Did anyone actually ask your permission? Attention is arguably one of the most important things in life, and in business.

Transparency and honesty are two things I also regard as essential in business, and with that in mind, this is why i'm writing to you all today! So if you know someone who might be interested, please consider sending them our way!

Here's a link to our website, for anyone who might be interested in learning more: https://www.mrpeasy.com/

Thank you and all the best to you!

Christian



Best Practice for Stack Uplinks

Hi Folks,

How many up links to core I need for this fully connected stack (1-2-3-4-5-6-7-1) ?

Any suggestions?