Creating a VSX pair
Deployments using VSX Active-Gateway configuration can leverage the VLAN profile at a higher scope to configure the required parameters, while the device-specific IP address is configured at the Device scope.
The goal of this use case is to create an alias, reference it in an active gateway enabled VLAN, then creating a VSX pair.
Creating an Alias
To create an alias, complete the following steps:
-
In the HPE Aruba Networking Central landing page, select a site from the Sites menu.
Alternatively, you can click the expand
icon on the Sites menu to search for a site from the list.The site dashboard is displayed with the network and connectivity information for the site.
-
Click the configuration
icon.The Configuration Overview page is displayed.
-
Click Library.
-
Click Named Objects.
-
Under Aliases tile, click Manage Aliases.
The Aliases table is displayed with a list of aliases.
-
Click Create Alias.
The Create an Alias side panel is displayed.
-
Configure the following parameters:
-
Name—Enter a name of the alias.
-
Description—Enter a description of the alias.
-
Attributes—Enter the following values to create an Active Gateway alias.
-
Attribute—Active Gateway
-
Active Gateway L3 Source MAC—Enable the check box to configure the virtual gateway MAC address as the source MAC for routed packets.
-
Active Gateway IPv4 Address—Enter the IPv4 address used as the default gateway for clients, which must be part of the subnet but not the same as the SVI IP.
-
Active Gateway MAC Address v4—Enter the virtual MAC address used by the active gateway, allowing both peers to be active.
-
Active Gateway IPv6 Address—Optionally, enter the IPv6 address used as the default gateway for clients, which must be part of the subnet but not the same as the SVI IP.
-
Active Gateway MAC Address v6—Optionally, enter the virtual MAC address used by the active gateway, allowing both peers to be active.
-
-
-
Click Create.
The new alias is added to the Aliases table.
-
Hover on the newly created alias in the Aliases table to which you want to assign a scope and click the Ellipsis
icon. -
Select Assign.
The Assign Profile side panel is displayed.
-
Select the device types from Device Function list.
-
To add a scope, click the Add
icon on the Scopes table. -
Select a scope from the following Scope Level options in the drop-down list.
-
Global—Selecting this option assigns the scope at the Global level.
-
Site Collections—Select the site collections from the Assign to Scope drop-down list.
-
Sites—Select the sites from the Assign to Scope drop-down list.
-
Devices—Select the devices from the Assign to Scope drop-down list.
-
-
Click Add.
The Scopes table displays the newly added scopes.
-
Review your changes to the Device Function and Scopes list and then click Assign.
The Aliases list displays the device functions and number of scopes assigned to the alias.
Applying the Alias in the VLAN
To reference the newly created alias in a VLAN configuration, complete the following steps:
-
In the HPE Aruba Networking Central landing page, select a site from the Sites menu.
Alternatively, you can click the expand
icon on the Sites menu to search for a site from the list.The site dashboard is displayed with the network and connectivity information for the site.
-
Click the configuration
icon.The Configuration Overview page is displayed.
-
On the VLANs & Networks card, click VLAN.
Alternatively, you can complete the following steps:-
On the VLANs & Networks card, click Manage.
-
On the VLAN card, click Manage.
The VLAN list view is displayed.
-
-
Select the target VLAN profile and click Edit.
-
Navigate to Switch Layer 3 Parameters > VSX and enable the Enable Active Gateway checkbox. Use the Active Gateway Alias drop-down to reference the newly created alias.
-
Click Save.
Creating a VSX profile
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
In the left navigation menu, select one of the following options:
-
Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.
Note:Profiles must be created at the Site level if creating a VSX pair.
-
Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.
-
-
Select the required site or device group from the list.
The Profiles Management view for the selected site is displayed.
-
Select the applicable switch device function from the Device Function drop-down menu.
-
On the High Availability card, click VSX.
Alternatively, you can complete the following steps:
-
On the High Availability card, click Manage.
-
On the VSX card, click Manage.
The VSX list view is displayed.
-
-
Click Create VSX.
The Create Profile UI is displayed.
-
Complete the following set of procedures:
-
Configure the following Device & Role Selection parameters:
-
Name—Enter the profile name.
-
Description (Optional)—Enter a description.
-
Role Selection—Set the role either to Manual or Auto.
Note:-
By default, when Auto is selected, the Peer 1 Role and Peer 2 Role fields are set to Primary and Secondary respectively.
-
To change the Peer roles, set the Role Selection to Manual.
-
-
Peer 1 Select Device—Select the newly created primary VLAN.
-
Peer 1 Role—Set the Peer 1 device role as Primary.
-
Peer 2 Select Device—Select the newly created secondary VLAN.
-
Peer 2 Role—Set the Peer 2 device role as Secondary.
-
-
Configure the following System parameters:
-
System MAC—Enter the system MAC address to be used for the VSX cluster for MSTP and LACP functions. This is a user-defined field. See the AOS-CX documentation for recommended formats.
-
Link Up Delay Timer—Click and drag the slider to the required duration.
-
Reset above timers to default—Select the Reset timers to default checkbox to reset the timer values, if necessary.
-
Split Recovery—Enable Split Recovery to prevent traffic loss when the ISL goes out-of-sync and keepalive subsequently fails. When the ISL goes out-of-sync and keepalive is established, the secondary VSX LAGs are brought down. This field is enabled by default.
-
-
Configure the following Inter-switch Link parameters:
-
In the Peer 1 and Peer 2 sections, select the intended physical interface or LAG from the ISL Link drop-down menus. If a new LAG needs to be created, click the Create New LAG link in the drop-down menus and enter the following parameters:
-
LAG ID—Enter the LAG interface ID.
-
Description—Enter the description for LAG interface.
-
LAG Type—Set the type as LAG.
-
LACP—Select the check box.
-
LACP Mode—Select Active from the drop-down list.
-
VLAN Mode—Set the VLAN mode to Trunk.
Click Add.
A new LAG is created and made available in the Peer 1 and Peer 2 drop-down menus in the VSX UI. -
-
ISL Hello-Interval—click and drag the knob to the required duration.
-
ISL Peer Detect Interval—click and drag the knob to the required duration.
-
ISL Hold Timer—click and drag the knob to the required duration.
-
ISL Dead Timer—click and drag the knob to the required duration.
-
Reset above timers to default—Select the Reset timers to default checkbox.
-
-
Configure the following Keepalive parameters:
-
Keepalive—Set the Keepalive type to Dedicated Peer-to-Peer, Upstream Routing, or Management Interface.
-
Select Dedicated Peer-to-Peer to use an ROP interface for keepalive.
-
Select Upstream routing to use a loopback address for keepalive.
-
Select Management Interface to use an out-of-band management interface for keepalive. When management interface is selected, the VRF profile field is set to mgmt by default.
-
-
Configure the following Keepalive Timer parameters:
-
Hello-Interval—click and drag the knob to the required duration.
-
Dead-Interval—click and drag the knob to the required duration.
-
Reset above timers to default—Enable the checkbox to revert the interval time pickers to default.
-
UDP port—Select the UDP port used by keepalive.
-
IP Address Family—Select whether the keepalive peers use IPv4 or IPv6 addresses.
-
-
Configure the following Peer 1 Keepalive and Peer 2 Keepalive parameters:
-
Device Selection and Role assignment—Choose the routed interface IP:
-
New Routed Interface IP—Create a new routed interface IP on an unused interface.
-
Existing Routed Interface IP—Assign an existing routed interface IP on a configured interface.
-
-
VRF Profile—Select a dedicated VRF profile for the Keepalive from the drop-down menu, under the Peer 1 Keepalive and Peer 2 Keepalive sections. By default, a VRF Profile called default is available.
If there is no VRF profile available, create a new VRF profile as follows:
-
In the VRF Profile drop-down menu, click New VRF Profile.
The Create VRF UI is displayed.
-
Create as a local profile—Select this checkbox if you want to configure this profile as local.
Note:The Create as a local profile checkbox is available at the Global, Site Collections, Sites, Devices, and Device Groups levels. It is not available at the Library level.
-
Name—Enter the profile name.
-
(Optional) Description—Enter the profile description.
-
Click Add.
A new VRF profile is created and made available in the VRF drop-down in the VSX profile UI.
-
-
-
-
-
Click Add.
Note:It may take a few minutes for the VSX configuration to process.
-
To confirm that the VSX creation is successful, select the hamburger icon and click on the Audit Trail card.
-
Search for the VSX profile you created.
-
Once created, the description will read Configuration Successfully Pushed to the Device.