ExtremeXOS 12.5.3 RelNote Rev02
ExtremeXOS 12.5.3 RelNote Rev02
Extreme Networks, Inc. 3585 Monroe Street Santa Clara, California 95051 (888) 257-3000 (408) 579-2800 http://www.extremenetworks.com
AccessAdapt, Alpine, Altitude, BlackDiamond, Direct Attach, ExtremeWorks Essentials, Ethernet Everywhere, Extreme Enabled, Extreme Ethernet Everywhere, Extreme Networks, Extreme Standby Router Protocol, Extreme Turbodrive, Extreme Velocity, ExtremeWare, ExtremeWorks, ExtremeXOS, Go Purple Extreme Solution, ExtremeXOS ScreenPlay, ReachNXT, Ridgeline, Sentriant, ServiceWatch, Summit, SummitStack, Triumph, Unified Access Architecture, Unified Access RF Manager, UniStack, XNV, the Extreme Networks logo, the Alpine logo, the BlackDiamond logo, the Extreme Turbodrive logo, the Summit logos, and the Powered by ExtremeXOS logo are trademarks or registered trademarks of Extreme Networks, Inc. or its subsidiaries in the United States and/or other countries. sFlow is the property of InMon Corporation. Specifications are subject to change without notice. All other registered trademarks, trademarks, and service marks are property of their respective owners. 2010-2011 Extreme Networks, Inc. All Rights Reserved.
Contents
Chapter 1: Overview................................................................................................................................... 5
Feature Corrections in ExtremeXOS 12.5.3 .............................................................................................................5 Feature Corrections in ExtremeXOS 12.5.2 .............................................................................................................6 New Features and Functionality in ExtremeXOS 12.5.1 ........................................................................................10 New Hardware Supported in ExtremeXOS 12.5.3 .................................................................................................13 New Hardware Supported in ExtremeXOS 12.5.1 .................................................................................................13 Hardware No Longer Supported ............................................................................................................................14 Supported Hardware ..............................................................................................................................................14 BlackDiamond 8800 Series of Switches Component Support ........................................................................14 BlackDiamond 10808 Switch Component Support .........................................................................................15 BlackDiamond 12800 Series Switches Component Support ..........................................................................17 BlackDiamond 20800 Series Switch Component Support ..............................................................................17 Summit X150 and X350 Component Support .................................................................................................19 Summit X250e Component Support ...............................................................................................................19 Summit X450a and X450e Component Support .............................................................................................19 Summit X460 Component Support .................................................................................................................20 Summit X480 Component Support .................................................................................................................21 Summit X650 Component Support .................................................................................................................21 SFP (Mini-GBIC) Support................................................................................................................................22 XENPAK Module Support ...............................................................................................................................27 XFP Module Support .......................................................................................................................................29 Upgrading to ExtremeXOS .....................................................................................................................................31 ExtremeXOS Command Line Support....................................................................................................................31 Tested Third-Party Products...................................................................................................................................31 Tested RADIUS Servers .................................................................................................................................31 Tested Third-Party Clients ..............................................................................................................................32 PoE Capable VoIP Phones .............................................................................................................................32 Extreme Switch Security Assessment ....................................................................................................................32 DoS Attack Assessment..................................................................................................................................32 ICMP Attack Assessment................................................................................................................................33 Port Scan Assessment ....................................................................................................................................33
CHAPTER
Overview
These Release Notes document ExtremeXOS 12.5.3, which resolves software deficiencies. This chapter contains the following sections:
Feature Corrections in ExtremeXOS 12.5.3 on page 5 Feature Corrections in ExtremeXOS 12.5.2 on page 6 New Features and Functionality in ExtremeXOS 12.5.1 on page 10 New Hardware Supported in ExtremeXOS 12.5.3 on page 13 New Hardware Supported in ExtremeXOS 12.5.1 on page 13 Hardware No Longer Supported on page 14 Supported Hardware on page 14 Upgrading to ExtremeXOS on page 31 Tested Third-Party Products on page 31 Extreme Switch Security Assessment on page 32
BFD Static RoutesThe Bidirectional Forwarding Detection (BFD) feature can be used to bring down static routes when the host link fails. Without BFD, static routes always remain operationally Up because there is no dynamic routing protocol to report network changes. This can lead to a black hole situation, where data is lost for an indefinite duration. Because upper layer protocols are unaware that a static link is not working, they cannot switch to alternate routes and continue to use system resources until the appropriate timers expire. IGMP Router AlertPer the current ExtremeXOS implementation, all IGMPv2 and IGMPv3 messages generated by a switch are sent without the Router Alert option in the IP header. IGMP packets are accepted and processed with or without the Router Alert option in the IP header. The IETF standard (RFC 2236 and RFC 3376) states that IGMPv2 and IGMPv3 messages should be sent with Router Alert Option in the IP header.
Overview
ELRP Port ShutdownWhen you have configured a switch to automatically disable the port where the looped packet arrived, there may be certain ports that you do not want disabled. You can then create a list of ports that are excluded from this automatic disabling and that will remain enabled. This list can also contain EAPS ring ports. You can also specify that EAPS ring ports are excluded. When this option is selected, the actual EAPS ring ports do not have to be explicitly listed. SNMP INFORMThis feature allows for confirmation of a message delivery. When an SNMP manager receives an INFORM message from an SNMP agent, it sends a confirmation response back to the agent. If the message has not been received and therefore no response is returned, the INFORM message is resent. You can configure the number of attempts to make and the interval between attempts. Autopolarity for Combo PortsAutopolarity is now supported on combo ports. This feature applies to only the 10/100/1000 BASE-T ports on the switch and copper medium on Summit combination ports.
Data Center SolutionsThe following section has been added to the Data Center Solutions chapter of the ExtremeXOS Concepts Guide: Introduction to Data Center Solutions. ELRP AdditionThe following has been added to Appendix D, Troubleshooting, Example: ELRP on Protocol-based VLANs of the ExtremeXOS Concepts Guide: For ELRP to detect loops on a protocol-based VLAN (other than the protocol any), you need to add the ethertype 0x00bb to the protocol. Example
# Create VLANs create vlan v1 create vlan v2 # Protocol filter configuration configure vlan v1 protocol IP configure vlan v2 protocol decnet # Add ports to the VLAN configure vlan v1 add ports 1 configure vlan v2 add ports 2 # Enable ELRP on the create VLANs enable elrp-client configure elrp-client periodic v1 ports all interval 5 log configure elrp-client periodic v2 ports all interval 5 log # Add the ethertype to the protocol configure protocol IP add snap 0x00bb configure protocol decnet add snap 0x00bb
VLANs v1 and v2 can then detect the loop on their respective broadcast domains.
EPICenter Name ChangeEPICenter is now called Ridgeline. Ridgeline is an Extreme Networksproprietary graphical user interface (GUI) network management system.
EXTREME-SYSTEM-MIB Table AdditionThe following Table/Group has been added to the EXTREMESYSTEM-MIB Table. extremeImageTableThis table contains image information for all images installed on the device. ExtremeXOS Feature Pack AdditionsThe following feature packs have been added to Table 143, ExtremeXOS Feature Pack Features, in Appendix A, of the ExtremeXOS Concepts Guide: CNA Feature Pack Legacy CLI Feature Pack SSH Feature Pack
Extreme Network Virtualization (XNV) FeatureThe XNV feature is updated in this release to allow you to specify the repository server directory on the FTP server that serves as the repository server. To specify the repository server directory, enter the following command:
configure vm-tracking repository [primary | secondary] server [<ipaddress> | <hostname>] {vr <vr-name>} {refresh-interval <seconds>} {path-name <path_name>}
The path_name specifies the path to the repository server files from the FTP server root directory. The default directory for repository server files is: pub. To display the configured repository server directory, use the following command:
show vm-tracking repository Primary VM-Map FTP server: Server name: IP address : 10.100.1.200 VR Name : VR-Mgmt Refresh-interval : 600 seconds Path Name : pub Secondary vm-map FTP server: Unconfigured Last sync Last sync status
: 16:35:15 : Successful
: Primary
Identity Management RevisionThe following note has been added to Chapter 22, Identity Management, in the ExtremeXOS Concepts Guide:
NOTE
This chapter discusses identity management features that are managed using the switch CLI. Related features are described in other chapters and in the Ridgeline product documentation. For a description of identity management that ties all the related components together, see the application note titled Deploying an Identity Aware Network, which is available from Extreme Networks.
Revised QoS Meters DescriptionFor ExtremeXOS 12.5.2 and later, the description of QoS meters is changed as follows: On BlackDiamond 8800 series switches, SummitStack, and Summit family switches that are supported by this software release, meters are a per-VLAN resource. For example, if you assign a 50 Mbps meter to a VLAN, the total throughput for all ports in that VLAN is limited to 50 Mbps. (PD4-1727668151)
Secure Shell (SSH) Serialized Licensing and DistributionExtreme Networks has enhanced its processes regarding SSH licensing. SSH contains strong encryption algorithms, which heightens the export controls required in the United States and other countries. SSH is now delivered and licensed on a serialized basis, with a separate license key required to activate SSH on each Extreme Networks switch. See the ExtremeXOS Concepts Guide, Software Version 12.5.2, for more detailed information.
Overview
For frequently asked questions (FAQs) pertaining to the SSH License Process Change, see Product Change Notice No. 2011002, ExtremeXOS SSH Process Change on eSupport. https://esupport.extremenetworks.com/eservice_enu/docs/pcn/ PCN2011002_EXOS_SSH_Process_Change_TEST.php
VM MIBsThe following VM MIBs are supportecd in ExtremeXOS 12.5.2 and will be added to the EXTREME-VM-MIB table in the next version of the ExtremeXOS Concepts Guide:
Table/Group extremeVMFTPServerTable Supported Variables extremeVMFTPServerEntry extremeVMFTPServerType The type of the FTP server. The backup server is contacted if the primary fails to respond. The FTP server directory name for the policies to be synchronized. A value of '/pub' will be used by default. The timestamp of the most recent synchronization attempt Triggers a synchronization cycle on demand. A synchronization will automatically download new or updated policies as well as delete policies to match those on the server. idle(1) is returned whenever this object is read. synchronizeNow(2) triggers an immediate synchronization, and will be reflected in extremeVMSynchOperState. Attempts to set this variable to synchronizeNow(2) will be rejected if a synchronization is currently in progress. Indicates if a synchronization is in progress, either on-demand or automatic This table contains the mapping of port policies to virtual machine MAC addresses. extremeVMMappingIngressVPPName The ingress policy associated with the VM/MAC address. Note that this may refer to a policy without a corresponding entry in the extremeVMVPPTable if a network policy mapping refers to a nonexistent policy. This would indicate an error in the policy mapping file that is consulted if network authentication fails. When creating an entry in this table, this name must refer to an existing, valid, local policy. The creation of a mapping to a network policy is not permitted. Those mappings must be created at the central policy server. Comments
extremeVMFTPPathName
extremeVMGeneral
extremeVMLastSynch extremeVMSynchAdminState
extremeVMSynchOperState
extremeVMMappingTable
extremeVMMappingEgressVPPName
The egress policy associated with the VM/MAC address. Note that this may refer to a policy without a corresponding entry in the extremeVMVPPTable if a network policy mapping refers to a nonexistent policy. This would indicate an error in the policy mapping file that is consulted if network authentication fails. When creating an entry in this table, this name must refer to an existing, valid, local policy. The creation of a mapping to a network policy is not permitted. Those mappings must be created at the central policy server.
An individual mapping of VPP to Policy. The row status for this mapping. An entry in the table of VM information of this device. The name of the policy applied (or attempted to apply) to this virtual machine. The name of the policy applied (or attempted to apply) to this virtual machine. Indicates the result of a VM entry into the network and indicates whether the policy applied or not in ingress direction policyApplied(1) indicates that the named policy was successfuly applied to the port. policyNotApplied(2) indicates that the named policy was not applied to the port. policyInvalid(3) indicates that the named policy was either invalid or missing, and could not be applied to the port. policyNotFound(4) indicates that the named policy was not found. policyNotMapped(5) indicates that the no policy was mapped to this VM Entry.
extremeVMDetectedEgressVPPName
extremeVMDetectedResultIngress
Overview
extremeVMDetectedResultEgress
Indicates the result of a VM entry into the network. and indicates whether the policy applied or not in egress direction policyApplied(1) indicates that the named policy was successfuly applied to the port. policyNotApplied(2) indicates that the named policy was not applied to the port. policyInvalid(3) indicates that the named policy was either invalid or missing, and could not be applied to the port. policyNotFound(4) indicates that the named policy was not found. policyNotMapped(5) indicates that the no policy was mapped to this VM Entry.
Upgrading ExtremeXOS SoftwareThe following note has been added to the Installing a Core Image section of Appendx B: Software Upgrade and Boot Options, in the ExtremeXOS Concepts Guide.
NOTE
When updating from ExtremeXOS 12.0.x or earlier to ExtremeXOS 12.5.x or later, you must first update to ExtremeXOS 12.3.4 and then update to ExtremeXOS 12.5.x or later.
Using Auto Provision of Edge Switches CorrectionParagraph three of theUsing Auto Provision of Edge Switches section of the ExtremeXOS Concepts Guide, page 105, should read: A switch enabled with auto provision can be identified as follows:
ACL Match ConditionBased on IEEE 802.1p, this feature provides the ability to create an access list (ACL) based on VLAN tag priority information. Access Profile LoggingThis feature provides ACL support for traffic reaching the following applications: SNMP, Telnet, SSH2, and HTTP/HTTPS. This is in addition to using policy files to add ACLs. Auto Provisioning for Edge SwitchesThis feature allows for the configuration of certain parameters on a switch automatically using DHCP and TFTP servers. This process can make an Extreme Networks switch ready to do the initial provisioning without any manual intervention. check firmware version CLI Command for the BlackDiamond 20800 Series SwitchUse the new check firmware version command to check whether any upgrade is to be done to any of the uC or FPGAs. If an upgrade is required, the output shows the running and expected versions for the boards. If there is no upgrade required, the same is printed. Refer to the ExtremeXOS Command Reference Guide for more details. CLEAR-Flow SupportCLEAR-Flow is now supported on BlackDiamond 20800 series switches. Direct AttachThe direct attach feature is a port configuration feature that supports VM-to-VM communication on a directly connected server that uses the Virtual Ethernet Port Aggregator (VEPA) feature on that server. Without VEPA and direct attach, a VM server must use a virtual Ethernet
10
bridge or switch on the VM server to enable Ethernet communications between VMs. With VEPA and direct attach, the VM server can rely on a directly connected switch to receive and reflect VM-toVM messages between VMs on the same server.
Distributed IP ARP Mode for BlackDiamond 8800 Series SwitchesThis feature increases the IPv4 ARP limit from 16,000 up to a maximum of 260,000 on a BlackDiamond 8800 series switch. The actual limit depends on the number and types of modules present on a BlackDiamond 8810 or BlackDiamond 8806 switch. DDMI OpticsDigital Diagnostic Monitoring Interface (DDMI) optics provide critical information about the installed Gigabit and 10 Gigabit optical transceiver modules. EAPS and PBB Redundant AccessEAPS now recognizes an SVLAN or CVLAN to BVLAN mapping and makes the BVLAN facing port the Active-Open port, which keeps the link to the core forwarding when the shared-port goes down. EAPS Priority DomainsEAPS now supports high and normal priority domains, allowing you to give priority response to the most important protected VLANs if a ring fault occurs. EAPS Secondary Control PortThe EAPS hello packet period now supports more values (configure eaps hellotime), and the software supports transmission of hello PDUs out of the secondary port (configure eaps hello-pdu-egress). Secondary port hello PDU transmission is provided for special circumstances; Extreme Networks recommends the default configuration, primary port hello PDU transmission. Enable and Disable DHCP/BOOTP Relay per VLANCurrently you can enable and disable BOOTP relay only on a virtual router (VR), which means the DHCP is enabled or disabled on all VLANs on that VR. With ExtremeXOS 12.5.1, you can enable or disable BOOTP relay a VR or on individual VLANs.
Enable and Disable SNMP per Virtual RouterTo provide SNMP support based on a virtual router, the existing enable/disable SNMP access CLI commands have been modified. These commands now include a VR option. SNMP access is enabled by default on all VRs. If SNMP access is disabled on a VR, the incoming SNMP request is dropped and an EMS log message is displayed. Extreme Network Virtualization (XNV)The Extreme Network Virtualization (XNV) feature, which is also known as Virtual Machine (VM) tracking, supports VM port movement, port configuration for VMs, and VM inventory on network switches. The XNV feature enables a switch to configure switch ports in response to VM detection and port movement and report VM activity to network management software. FDB Entry StatisticsThe show fdb stats command has been updated to display information that is dynamically updated. A no-refresh option is provided for those who prefer the static display. Identity Management, Phase 2The identity management feature has been extended to support identity authentication through a RADIUS server or local database. As part of the authentication, identities can be associated with hierarchical roles, to which policies or dynamic ACL rules are attached. These policies and rules can be used to configure port settings for the discovered identity. IP ARP Entry StatisticsThe show iparp stats command has been added to display IP ARP statistics in a display that is dynamically updated. Statistics can be displayed for VRs, ports, or VLANs. IPFIX Protocol SupportThe IP Flow Information Export (IPFIX) protocol captures information about traffic flows passing through network elements in a data network and sends the information to an external collector.
11
Overview
IP Multicast Scaling EnhancementTo support more IP multicast (IPMC) FDB entries, BlackDiamond 8900 series modules with external tables can now be configured to support additional IPMC FDB entries. This feature is configured with the configure forwarding external-tables command. LAG Port SelectionThis feature allows you to apply an ACL that causes matching packets to egress a specific port in a link aggregation (or load-sharing) group. Login Banner EnhancementsA user configurable banner can now be displayed after a successful login. Enhancements for banners used with network login have also been added. MIB Support for Extreme Target Address MIBSupport for the VR option has been added to the Extreme target-addr MIB. Mirroring ScalingOn all ExtremeXOS platforms, the maximum number of mirroring filters has been increased from 16 to 128. The maximum number of VLAN or virtual ports filters remains at 16. If there are no configured VLAN or virtual port filters, 128 ports can be mirrored. If you have the maximum of 16 VLAN or virtual ports filters configured, 112 ports (128-16) can be configured. MLAG Switch SupportThe multi-switch link aggregation group (MLAG) feature allows you to combine ports on two switches to form a single logical connection to another network device. The other network device can be either a server or a switch and is separately configured with a regular LAG (or appropriate server port teaming) to form the port aggregation. The basic operation of this feature requires two ExtremeXOS switches interconnected by an inter-switch connection (ISC). MPLS Support on BlackDiamond 8800 Series SwitchesMultiprotocol Label Switching (MPLS) is now supported on BlackDiamond 8800 series switches that contain only certain BlackDiamond 8900 series modules: 8900-10G8X-xl, 8900-G48T-xl, 8900-G48X-xl with MSM 8900-MSM128. Be sure to read the ExtremeXOS Concepts Guide, as this feature is only supported when the proper hardware, software, and feature pack is installed. MPLS Support on Summit X460 and X480 SwitchesMPLS is now also supported on Summit X460 and X480 switches. Be sure to read the ExtremeXOS Concepts Guide, as this feature is only supported when the proper hardware, software, and feature pack is installed. Packet Buffer ConfigurationThis feature provides more efficient buffer usage and more control of buffer usage on select BlackDiamond 8000 series modules and Summit family switches. Control is implemented through the configure port shared-packet-buffer command. Power over Ethernet plus (PoE+)PoE+ (IEEE 802.3at) has been implemented and supports up to 30W at the power sourcing equipment. Priority Flow ControlThis feature provides the functionality to allow traffic associated with certain priorities to be paused while traffic associated with other priorities on the same port continues to flow. Round Robin LAGThe round robin algorithm is used to select a member from a LAG to route a packet rather than using a hash algorithm that is based on the L2/l3 address fields of the packet. show tech Command EnhancementsThe commands show management and ls internalmemory have been added to the output of the show tech command. SummitStack-VThis feature uses 10 Gb or faster switch ports as stacking ports, which allows greater cable distances between stacking nodes and allows a stack to span between racks, building floors, or buildings. SyncESynchronous Ethernet (SyncE) allows the hardware to synchronize the clock time that is used for data transmission to a reference clock. The primary reference clock comes from a base station controller. Tunable DWDMTunable Dense Wavelength Division Multiplexing (DWDM) allows you to configure a DWDM channel to a DWDM capable XFP module on a port, providing the capability to multiplex 40x10G traffic over a single fiber. Supported on Summit X480 series switches, BlackDiamond 20800 series switches, and BlackDiamond 8800 series switches.
ExtremeXOS 12.5.3 Release Notes
12
Virtual Router ScalingThe software now supports Virtual Router and Forwarding instances (VRFs), which are an extension of the VR feature. VRFs function as children of VRs and support many more VR instances than previously provided by the VR feature. VLAN Statistics Support for BlackDiamond 8800 Series Switches and Summit Family Switches Support for VLAN statistics is based on the current implementation of VLAN statistics on the BlackDiamond 12800 series switch. Statistics gathering is initiated through the configure ports [<port_list>| all] monitor vlan <vlan_name> CLI command. Packet and byte counters are displayed on a per-port per-VLAN basis using the show ports {<port_list>} vlan statistics {no-refresh} CLI command or through SNMP Gets. VPLS MIB Enhancement for EPICenterExtremeXOS 12.5.1 introduces new VPLS MIBs for EPICenter. Virtual Router Support for OSPFv3 and RIPngIPv6 unicast routing protocols (OSPFv3 and RIPng) are now supported in user created virtual routers (VRs). Wide Key ACLThis feature allows the use of a 362-bit double wide match key instead of a standard 181-bit single wide key to be used with match conditions. It allows you to add more match conditions to an ACL and also allows matching on a full destination-source IPv6 address.
BlackDiamond 20800 Series Switch HM-2X24GA I/O module Summit X450e-24t Summit X450e -
Summit X450e-48t
Summit X460 Summit X460-24x Summit X460-24t Summit X460-24p Summit X460-48x Summit X460-48t Summit X460-48p
13
Overview
BlackDiamond 8800 original series modules: G48T G48P G24X 10G4X Summit X450-24x Summit X450-24t XGM-2xn module
Supported Hardware
Refer to the Extreme Networks hardware installation guides for more information about supported hardware. The following tables list the software filenames for the hardware that requires software.
ExtremeXOS Filenames bd8800-12.5.3.9.xos bd8800-12.5.3.9.xos bd8800-12.5.3.9.xos bd8800-12.5.3.9.xos N/A N/A bd8800-12.5.3.9.xos N/A N/A N/A N/A N/A N/A N/A N/A N/A
14
ExtremeXOS Filenames N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A N/A
N/A
11.3.2.6
N/A
NOTE Upgrading the BootROM on a BlackDiamond 8810 or BlackDiamond 8806 switch is not automatic when software is upgraded. The user must be running the minimum required BootROM version or later. Use the install firmware command after upgrading the ExtremeXOS image to insure the BootROM is at the latest level.
15
Overview
Following are the part numbers for the BlackDiamond 10808 modules with the Rev. D ASIC: Table 3: BlackDiamond 10808 I/O Modules with Part Numbers
I/O Module G60T 8000 Level Part No. 804403-00, after Rev. 16 804408-00, after Rev. 03 G60X 804402-00, after Rev. 16 804404-00, after Rev. 03 G20X 804407-00, after Rev. 03 804470-00, after Rev. 08 10G2X 804410-00, after Rev. 03 804471-00, after Rev. 11 10G2H 804406-00, after Rev. 09 804411-00, after Rev. 03 10G6X 804405-00, after Rev. 18 804409-00, after Rev. 03 9000 Level Part No. 904015-00 904015-10 904009-00/11 904009-10 904020-10 904020-00/11 904032-10 904032-00/11 904027-00/11 Description BlackDiamond 10808 60-port 10/100/1000BASET RJ-45 Module BlackDiamond 10808 60-port 10/100/1000BASET RJ-45 Module BlackDiamond 10808 60-port 1000BASE-X SFP (mini-GBIC) Module BlackDiamond 10808 60-port 1000BASE-X SFP (mini-GBIC) Module BlackDiamond 10808 20-port 1000BASE-X SFP (mini-GBIC) Module BlackDiamond 10808 20-port 1000BASE-X SFP (mini-GBIC) Module BlackDiamond 10808 2-port 10GBASE-X XENPAK Module BlackDiamond 10808 2-port 10GBASE-X XENPAK Module BlackDiamond 10808 Hybrid Module (2-port 10GBASE-X XENPAK, 20-port 1000BASE-X SFP, 20-port 10/100/1000BASE-T RJ-45) BlackDiamond 10808 Hybrid Module (2-port 10GBASE-X XENPAK, 20-port 1000BASE-X SFP, 20-port 10/100/1000BASE-T RJ-45) BlackDiamond 10808 6-port 10GBASE-X XENPAK Module BlackDiamond 10808 6-port 10GBASE-X XENPAK Module ExtremeXOS Required 11.2.1.3 11.2.1.3 11.2.1.3 11.2.1.3 11.2.1.3 11.2.1.3 11.2.1.3 11.2.1.3 11.2.1.3
904027-10
11.2.1.3
904016-00/11 904016-10
11.2.1.3 11.2.1.3
16
BlackDiamond 20800 Components GM-40X uC FPGA: A FPGA: P FPGA: T1 FPGA: W1 & W2 BootROM
17
Overview
BlackDiamond 20800 Components HM-2X24GA uC FPGA: A FPGA: P FPGA: T1 FPGA: W1 FPGA: D1 BootROM XM-8X uC FPGA: A FPGA: P FPGA: D1 and D2 (manual upgrade) FPGA: T1 & T2 FPGA: WH BootROM XFM-1 (shown as Fabric-1 through Fabric-5) (BlackDiamond 20808) uC XFM-2 (shown as Fabric-1 through Fabric-5) (BlackDiamond 20804) uC MM Basic uC FPGA: S BootROM PSUCTRL Fan Tray (BlackDiamond 20808) uC (shown as Revision) Fan Tray (BlackDiamond 20804) uC (shown as Revision)
NOTE Use the check firmware version command to verify that all components on the BlackDiamond 20800 series switches (I/O modules, fans, and so on) are running the latest version of ExtremeXOS firmware. If the command output shows that one or more component is not running the latest firmware, use the install firmware command to update all down level components. Be sure to run the show slot, show fans, show power, and show fabric commands to verify that all components are installed and operational before attempting to upgrade or downgrade the switch firmware.
18
ExtremeXOS Filenames summitX-12.5.3.9.xos summitX-12.5.3.9.xos summitX-12.5.3.9.xos summitX-12.5.3.9.xos summitX-12.5.3.9.xos summitX-12.5.3.9.xos summitX-12.5.3.9.xos summitX-12.5.3.9.xos
ExtremeXOS Filenames summitX-12.5.3.9.xos summitX-12.5.3.9.xos summitX-12.5.3.9.xos summitX-12.5.3.9.xos summitX-12.5.3.9.xos summitX-12.5.3.9.xos summitX-12.5.3.9.xos summitX-12.5.3.9.xos
ExtremeXOS Filenames
19
Overview
Option Cards and Stacking Modules XGM3-2sf SummitStack SummitStack-V80 summitX-12.5.3.9.xos summitX-12.5.3.9.xos summitX-12.5.3.9.xos 12.5.1 12.5.1 12.5.1
20
NOTE Upgrading the BootROM on Summit family switches is not automatic when software is upgraded. The user must be running the minimum required BootROM version. Use the download bootrom command to download a BootROM image.
21
Overview
SFPs supported on the BlackDiamond 10808 switch with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include: Table 14: BlackDiamond 10808 Switch SFP Support
SFP LX100 SFP SX SFP LX SFP ZX SFP 1000BASE-T SFP 1000BX SFP ExtremeXOS Required 12.0.1.11 10.1.0 10.1.0 10.1.0 11.1.1.9 11.6.1.9
SFPs supported on the BlackDiamond 12804 switch with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include: Table 15: BlackDiamond 12804 Switch SFP Support
SFP SX SFP LX SFP ZX SFP ExtremeXOS Required 11.4.1.4 11.4.1.4 11.4.1.4
22
SFPs supported on the BlackDiamond 12802 switch with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include: Table 16: BlackDiamond 12802 Switch SFP Support
SFP SX SFP LX SFP ZX SFP 1000BASE-T SFP 1000BX SFP LX100 SFP 100FX/1000LX SFP ExtremeXOS Required 12.0.1.11 12.0.1.11 12.0.1.11 12.0.1.11 12.0.1.11 12.0.1.11 12.0.1.11
SFPs supported on the BlackDiamond 20800 switch with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include: Table 17: BlackDiamond 20800 Switch SFP Support
SFP SX SFP LX SFP ZX SFP LX100 BXU BXD ExtremeXOS Required 12.2 12.2 12.2 12.2 12.2 12.2
SFPs supported on the Summit X150 series switches with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include: Table 18: Summit X150 Series Switches SFP Support
SFP 100BASE-FX (P/N 10067) 100BASE-BX SFP 100BASE LX10 SFP SX SFP LX SFP ZX SFP ExtremeXOS Required 12.0.2.25 12.0.2.25 12.0.2.25 12.0.2.25 12.0.2.25 12.0.2.25
23
Overview
SFPs supported on the Summit X250e switch with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include: Table 19: Summit X250e SFP Support
SFP SX SFP, ports 25 and 26 LX SFP, ports 25 and 26 ZX SFP, ports 25 and 26 LX100 SFP, ports 25 and 26 1000BX SFP, ports 25 and 26 100BASE FX SFP (P/N 10067), ports 1 through 26 100BASE BX SFP, ports 1 through 26 100BASE LX10 SFP, ports 1 through 26 ExtremeXOS Required 12.0.2.25 12.0.2.25 12.0.2.25 12.0.2.25 12.0.2.25 12.0.2.25 12.0.2.25 12.0.2.25
SFPs supported on the Summit X350 series switches with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include:
NOTE The XGM2-2sf ports are 10Gb SFP+ ports and do not support 1Gb optics (PD4-739782255).
Table 20: Summit X350 Series Switches SFP/SFP+ (XGM2-2sf Option Card Required) Support
SFP SX SFP LX SFP ZX SFP LX100 SFP 1000BX SFP ER SFP+ SR SFP+ LR SFP+ SFP+ twin coax cables ExtremeXOS Required 12.0.3.16 12.0.3.16 12.0.3.16 12.0.3.16 12.0.3.16 12.3.3 12.2.1 12.2.1 12.2.1
24
SFPs supported on the Summit X450a switch with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include:
NOTE The XGM2-2sf ports are 10Gb SFP+ ports and do not support 1Gb optics (PD4-739782255).
Table 21: Summit X450a Switch SFP/SFP+ (XGM2-2sf Option Card Required) Support
SFP 10/100/1000BASE-T Copper SFP Note: Not supported on combo ports. SX SFP LX SFP ZX SFP ER SFP+ SR SFP+ LR SFP+ SFP+ twin coax cables 100FX SFP (P/N 10063) Note: Not supported on combo ports. 100FX/1000LX SFP Summit X450a-24x, ports 1 through 20 12.0.1.11 11.6.1.9 Note: Not supported on combo ports. LX100 SFP 1000BX SFP 11.6.1.9 11.2.2.4 11.2.2.4 11.2.2.4 12.3.3 12.2.1 12.2.1 12.2.1 11.6.1.9 ExtremeXOS Required 12.0.2.25
SFPs supported on the Summit X450e switch with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include:
NOTE The XGM2-2sf ports are 10Gb SFP+ ports and do not support 1Gb optics (PD4-739782255).
Table 22: Summit X450e Switch SFP/SFP+ (XGM2-2sf Option Card Required) Support
SFP SX SFP LX SFP ZX SFP LX100 SFP 1000BX SFP ER SFP+ SR SFP+ LR SFP+ ExtremeXOS Required 11.6.1.9 11.6.1.9 11.6.1.9 12.0.1.11 11.6.1.9 12.3.3 12.2.1 12.2.1
25
Overview
Table 22: Summit X450e Switch SFP/SFP+ (XGM2-2sf Option Card Required) Support
SFP SFP+ twin coax cables ExtremeXOS Required 12.2.1
SFPs supported on the Summit X460 switch with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include: Table 23: Summit X460 SFP/SFP+ (XGM3-2sf Option Cared Required) Support
SFP 1000BASE-SX SFP 1000BASE-LX SFP 1000BASE-ZX SFP 1000BASE-BX SFP BX-D 1000BASE-BX SFP BX-U LX100 SFP 10/100/1000BASE-T SFP 100BASE-BX SFP BX-D 100BASE-BX SFP BX-U 100BASE-FX/1000BASE-LX SFP 10GBASE-ER SFP+ 10GBASE-SR SFP+ 10GBASE-LR SFP+ 100BASE-FX SFP 100BASE-LX10 SFP 100BASE-FX SFP ExtremeXOS Required 12.5.1 12.5.1 12.5.1 12.5.1 12.5.1 12.5.1 12.5.1 12.5.1 12.5.1 12.5.1 12.5.1 12.5.1 12.5.1 12.5.1 12.5.1 12.5.1
SFPs supported on the Summit X480 switch with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include: Table 24: Summit X480 SFP Support
SFP SX mini-GBIC LX mini-GBIC ZX mini-GBIC 1000BASE-BX mini-GBIC BX-D 1000BASE-BX mini-GBIC BX-U 100BASE-BX mini-GBIC BX-D 100BASE-BX mini-GBIC BX-U 100BASE LX10 mini-GBIC 100BASE FX mini-GBIC module LX100 mini-GBIC module 100 FX/1000LX mini-GBIC, not supported on combo ports ExtremeXOS Required 12.4.1 12.4.1 12.4.1 12.4.1 12.4.1 12.4.1 12.4.1 12.4.1 12.4.1 12.4.1 12.4.1
26
SFPs supported on the Summit X650 series switches with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include: Table 25: Summit X650 Series Switches SFP/SFP+ Support
SFP SR SFP+, ports 1 through 24, and ports 25 through 32 (for the VIM1-10G8X) LR SFP+, ports 1-24 and 25-32 for VIM1-10G8X SFP+ twin coax cable - 1-24 and 25-32 for VIM1-10G8X 10/100/1000BASE-T SFP+ Copper1000 speed support only Note: Not supported on port 23 and 24 ER SFP+ 1000BX SFP, not supported on ports 23, 24 1000SX SFP, not supported on ports 23, 24 1000LX SFP, not supported on ports 23, 24 1000 BASE-T SFP, not supported on ports 23, 24 LX100 SFP, not supported on ports 23, 24 ZX SFP, not supported on ports 23, 24 12.3.3 12.2.1 12.2.1 12.2.1 12.3.1 12.2.1 12.2.1 ExtremeXOS Required 12.3.1 12.3.1 12.3.1 12.3.3
27
Overview
XENPAK modules supported on the BlackDiamond 12804 switch with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include: Table 27: BlackDiamond 12804 Switch XENPAK Support
XENPAK Module LR ER SR LX4 ZR LW ExtremeXOS Required 11.4.1.4 11.4.1.4 11.4.1.4 11.4.1.4 11.4.1.4 11.4.1.4
XENPAK modules supported on the BlackDiamond 12802 switch with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include: Table 28: BlackDiamond 12802 Switch XENPAK Support
XENPAK Module LR ER SR LX4 ZR LW ExtremeXOS Required 12.0.1.11 12.0.1.11 12.0.1.11 12.0.1.11 12.0.1.11 12.0.1.11
XENPAK modules supported on the Summit X350 switch with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include: Table 29: Summit X350 Switch XENPAK Support
XENPAK Module SR LR ER LX4 ZR ExtremeXOS Required 12.0.3.16 12.0.3.16 12.0.3.16 12.0.3.16 12.0.3.16
XENPAK modules supported on the Summit X450a switch with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include: Table 30: Summit X450a Switch XENPAK Support
XENPAK Module SR LR ER LX4 ExtremeXOS Required 11.6.1.9 11.6.1.9 11.6.1.9 11.6.1.9
28
XENPAK modules supported on the Summit X450e switch with ExtremeXOS 12.5, and the minimum ExtremeXOS version required, include: Table 31: Summit X450e Switch XENPAK Support
XENPAK Module SR LR ER LX4 ZR CX4 ExtremeXOS Required 11.5.1.4 11.5.1.4 11.5.1.4 11.5.1.4 11.5.1.4 12.0.1.11
NOTE XENPAKs not supplied by Extreme Networks will show up as Unsupported Optic Module in the show port x:y information detail and show port x:y configuration command output.
29
Overview
XFP modules supported on the BlackDiamond 20800 switch with ExtremeXOS 12.5, the minimum ExtremeXOS version required include: Table 33: BlackDiamond 20800 Switch XFP Support
XFP Module SR LR ER ZR Tunable DWDM ExtremeXOS Required 12.2 12.2 12.2 12.2 12.5.1
XFP modules supported on the Summit X350 switch with ExtremeXOS 12.5, the minimum ExtremeXOS version required, and the manufacturers supported include: Table 34: Summit X350 Switch XFP Support
XFP Module SR LR ER DWDM ZR ExtremeXOS Required 12.0.3.16 12.0.3.16 12.0.3.16 12.5.1 12.1.2.17
XFP modules supported on the Summit X450a and X450e series switch with ExtremeXOS 12.5, the minimum ExtremeXOS version required, and the manufacturers supported include: Table 35: Summit X450a and X450e Series Switch XFP Support
XFP Module SR LR ER DWDM ZR ExtremeXOS Required 11.5.1.4 11.5.1.4 12.0.2.25 12.5.1 12.1.2.17
XFP modules supported on the Summit X480 series switch with ExtremeXOS 12.5, the minimum ExtremeXOS version required, and the manufacturers supported include: Table 36: Summit X480 Series Switch XFP Support
XFP Module SR LR ER ZR ExtremeXOS Required 12.4.1 12.4.1 12.4.1 12.4.1
30
Upgrading to ExtremeXOS
See Software Upgrade and Boot Options in the ExtremeXOS Concepts Guide for instructions on upgrading ExtremeXOS software. Following are miscellaneous hitless upgrade notes:
Beginning with ExtremeXOS 12.1, an ExtremeXOS core image (.xos file) must be downloaded and installed on the alternate (non-active) partition. If you try to download to an active partition, the error message "Error: Image can only be installed to the non-active partition." is displayed. An ExtremeXOS modular software package (.xmod file) can still be downloaded and installed on either the active or alternate partition. For the BlackDiamond 8800 series of switches, a hitless upgrade to ExtremeXOS 12.5.2 from an earlier release is not supported and should not be attempted. Use the normal software upgrade process for these switches. Hitless upgrade from ExtremeXOS 12.0 and earlier to ExtremeXOS 12.1 and later is not supported on the BlackDiamond 12800 switch.
Summit X150 and X350 series switches do not support L3 functionality; this platform does not support CLI commands for L3 functionality. Summit X150 and X350 series switches do not support stacking; all CLI commands for stacking are not supported on this platform. Summit X150 and X350 series switches do not support IP forwarding; however, CLI commands that configure IP addresses function in order to access the management functionality of the switch are supported. Upgrade or trial licensing is not available on the Summit X150 and X350 series switches.
31
Overview
Windows XP Linux
Avaya 4620 Avaya 4620SW IP telephone Avaya 9620 Avaya 4602 Avaya 9630 Avaya 4621SW Avaya 4610 Avaya 1616 Avaya one-X Cisco 7970 Cisco 7910 Cisco 7960 ShoreTel ShorePhone IP 212k ShoreTel ShorePhone IP 560 ShoreTel ShorePhone IP 560g ShoreTel ShorePhone IP 8000 ShoreTel ShorePhone IP BB 24 Siemens OptiPoint 410 standard2 Siemens OpenStage 20 Siemens OpenStage 40 Siemens OpenStage 60 Siemens OpenStage 80
32
Nessus
33
Overview
34
CHAPTER
Limits
Supported Limits
Table 37 summarizes tested metrics for a variety of features, as measured in a per-system basis unless otherwise noted. These limits may change but represent the current status. The contents of this table supersede any values mentioned in the ExtremeXOS Concepts Guide.
NOTE The term BlackDiamond 8000 e-series refers to all BlackDiamond 8500 e-series and 8800 e-series modules.The term BlackDiamond 8000 series refers to all BlackDiamond 8500, 8800, and 8900 series modules.
The scaling and performance information shown in Table 37 is provided for the purpose of assisting with network design. It is recommended that network architects and administrators design and manage networks with an appropriate level of network scaling head room. The scaling and performance figures provided have been verified using specific network topologies using limited switch configurations. There is no guarantee that the scaling and performance figures shown are applicable to all network topologies and switch configurations and are provided as a realistic estimation only. If you experience scaling and performance characteristics that you feel are sufficiently below what has been documented, contact Extreme Networks technical support for additional assistance. The route limits shown in Table 37 for IPv4 and IPv6 routing protocols are software limits only. The actual hardware limits may be lower than the software limits, based on platform. The hardware limits for specific platforms are specified as "IPv4/IPv6 routes (LPM entries in hardware)" in the following table. On certain BlackDiamond 8000 and Summit products, it is not advised to have greater than 25,000 total IP routes from all routing protocols. This includes a BlackDiamond 8000 series switch with an 8500MSM24, MSM-G8X or MSM-48, and Summit X250e, X450a, X450e, or X650 switches, either in a SummitStack or standalone. Adverse effects can occur with routing tables larger than this, especially when a single network event or CLI command affects a significant number of routes. For example, just after such a network event, the added system load will cause a save configuration command to time out.
35
Limits
36
Summit X650, group of 12 ports Access lists (slices)number of ACL slices. BlackDiamond 8000 series a- and c-series, group of 48 ports e-series, group of 24 ports BlackDiamond 8900 series 8900-10G24X-c modules, group of 12 ports 8900-G96T-c modules, group of 48 ports 8900 xl-series Summit X150, X250e, X350, X450e, group of 48 ports Summit X450a, group of 24 ports Summit 460 Summit X480 Summit X650, group of 12 ports ACL static ingress L2 entriesmaximum number of static ACL L2 entries. ACL static ingress L3 rulesmaximum number of static L3 ACL rules. BlackDiamond 12800 series BlackDiamond 20800 series BlackDiamond 12800 series BlackDiamond 20800 series
37
Limits
1,024 2,048 256* 512 512 256 256* 512 512 128* 512
All platforms (except BlackDiamond 8900 series, BlackDiamond 20800 series, and Summit X480) with Core license or higher BlackDiamond 8900 series BlackDiamond 20808 series Summit X480
BGP (policy entries)maximum number of BGP policy entries per route policy. BGP (policy statements)maximum number of BGP policy statements per route policy.
All platforms with Core license or higher All platforms with Core license or higher
38
BlackDiamond 8800 c-series BlackDiamond 8900 series BlackDiamond 20800 series Summit X450a and X650 Summit X480 All platforms
39
Limits
All platforms All platforms BlackDiamond 8800 with c-series MSM and I/O modules BlackDiamond 8900 series BlackDiamond 12800 series Summit X450a, X480, X650 with 50 DACLs with 500 DACLs
128 1,000
8 8 12 10 5 64 128 128 128 32 2,000 4,000 4,000 4,000 1,000 2,000 4,000 4,000 4,000 500
EAPS domainsmaximum number of EAPS domains. Note: An EAPS ring that is being spatially reused cannot have more than four configured EAPS domains. EAPSv1 protected VLANsmaximum number of protected VLANs.
BlackDiamond 8000 series BlackDiamond 10808 BlackDiamond 12800 series BlackDIamond 20800 series Summit series BlackDiamond 8000 series BlackDiamond 10808 BlackDiamond 12800 series BlackDiamond 20800 series Summit series
BlackDiamond 8000 series BlackDiamond 10808 BlackDiamond 12800 series BlackDIamond 20800 series Summit series
40
41
Limits
20,000
4,076 1,142/824
Identity management-maximum number of roles that can be created. Identity management-maximum role hierarchy depth allowed. Identity management-maximum number of attribute value pairs in a role match criteria. Identity management-maximum of child roles for a role. Identity management-maximum number of policies/dynamic ACLs that can be configured per role.
All platforms except BlackDiamond 20800 series All platforms except BlackDiamond 20800 series All platforms except BlackDiamond 20800 series All platforms except BlackDiamond 20800 series All platforms except BlackDiamond 20800 series
64 5 16
8 8
42
20
6449,152 100
BlackDiamond 8800 a-series BlackDiamond 8800 c-series BlackDiamond 8000 e-series 8900-10G24X-c modules 8900-G96T-c modules 8900 xl-series BlackDiamond 10808 BlackDiamond 12800 series BlackDiamond 20800 series Summit X150, X250e, X350, X450e Summit X450a Summit X480 Summit X460, X650
1,024 2,048c 500d 2,048c 4,096c 4,096c 15,000 15,000 3,700 500d 1,024 4,096 2,048 2,000d 6,000d 500d 6,000d 12,000b 500d 2,000d 6,000d 12,000b
IGMP sendermaximum number of IGMP senders per switch (IP multicast compression enabled).
BlackDiamond 8800 a-series BlackDiamond 8800 c-series BlackDiamond 8000 e-series BlackDiamond 8900 c-series BlackDiamond 8900 xl-series Summit X150, X250e, X350, X450e Summit X450a Summit X460, X650 Summit X480
43
Limits
All platforms
50
BBlackDiamond 8800 c-series BlackDiamond 8900 c-series BlackDiamond 10808 BlackDiamond 12800 series BlackDIamond 20800 series Summit series (except Summit X480, X650) Summit X460, X480, X650
2,000 2,000 5,000 5,000 5,000 1,000 2,000 20,000 20,000 30,000 30,000 30,000 10,000 20,000 250
BlackDiamond 8800 c-series BlackDiamond 8900 c-series BlackDiamond 10808 BlackDiamond 12800 series BlackDiamond 20800 series Summit series (except Summit X480, X650) Summit X460, X480, X650
IGMPv3 maximum source per group maximum number of source addresses per group. IGMPv3 subscribermaximum number of IGMPv3 subscribers per port.
All platforms
BlackDiamond 8800 a-, e-series BlackDiamond 8800 c-series BlackDiamond 8900 series BlackDiamond 10808 BlackDiamond 12800 series BlackDiamond 20800 series Summit series (except Summit X460) Summit X460
44
260,000
100,000 N/A 32,500b 16,250b 8,000 N/A 8,000 1,000d 16,000 224,000 49,000 224,000 32,000 1,000d 8,000 16,000
45
Limits
46
BlackDiamond 8000 series BlackDiamond 10808 BlackDiamond 12800 series BlackDiamond 20800 series Summit X460, X480, X650
512 1,024 1,024 1,024 512 1,000d 3,000d 250d 2,000d 4,000d 4,000d 112,000 24,500 112,000 40,000 250d 1,000d 4,000d 2,000d
BlackDiamond 8800 a-series BlackDiamond 8800 c-series BlackDiamond 8000 e-series BlackDiamond 8900-10G24X-c modules BlackDiamond 8900-G96T-c modules BlackDiamond 8900 xl-series BlackDiamond 10808 BlackDiamond 12800 series BlackDiamond 12800 R-series BlackDiamond 20800 series Summit X250e, X450e Summit X450a Summit X460, X480 Summit X650
47
Limits
65,000 25,000 65,000 65,000 65,000 25,000 65,000 512 4,096 1,024
1,024 2, 4, or 8 2, 4, or 8
48
49
Limits
50
51
Limits
52
128
All platforms BlackDiamond 10808 BlackDiamond 12800 series BlackDiamond 10808 BlackDiamond 12800 series
53
Limits
BlackDiamond 8800 series Summit series BlackDiamond 8800 series Summit series BlacDiamond 8900 xl-series BlackDiamond 10808 BlackDiamond 12800 R-series BlackDiamond 20800 series Summit X460, X480
768 768 1 1 32 32 32 50 32 32 32 32 64 32 50 64 64 64 50
BlacDiamond 8900 xl-series BlackDiamond 10808 BlackDiamond 12800 R-series BlackDiamond 20800 series Summit X460, X480
BlacDiamond 8900 xl-series BlackDiamond 10808 BlackDiamond 12800 series BlackDiamond 20800 series Summit X460, X480
54
55
Limits
BlackDiamond 8000 series BlackDiamond 8900 xl-series BlackDiamond 10808 BlackDiamond 12800 series BlackDiamond 20800 series Summit X250e, X460, X650 Summit X480
OSPF areasas an ABR, how many OSPF areas are supported within the same switch.
All platforms
56
All platforms with Core license or higher All platforms All platforms with Advanced Edge license All platforms with Core license or higher
32 419 4 16
57
Limits
58
59
Limits
All platforms
32
60
BlackDiamond 8800 a-, c-, e-series BlackDiamond 8900 series BlackDiamond 10808 BlackDiamond 12800 series Summit X250e, X450a, X450e, X460 Summit X480, X650
Provider Backbone Bridging (PBB) Service and Customer VLANsmaximum number of service and customer VLANs PBB Backbone VLANsmaximum number of backbone VLANs. PBB ISIDsmaximum number of ISIDs. Range is 256 to 330, 221. PBB Backbone Edge Bridges (BEBs) in a PBB Networkmaximum number of BEBs in a PBB network. PBB MAC Binding Entriesmaximum number of MAC-binding entries. PBB-Traffic Engineering (PBB-TE) maximum number of static MAC binding entries.
BlackDiamond 20800 series BlackDiamond 10808 MSM-1 MSM-1XL BlackDiamond 12800 series MSM-5 MSM-5R MSM-6R
400,000
98,000 100,000 49,000 100,000 100,000 10,000 10,000 10,000 10,000 10,000 3,000 10,000 10,000
Route policiessuggested maximum number of lines in a route policy file. RIP-learned routesmaximum number of RIP routes supported without aggregation.
All platforms BlackDiamond 8000 series BlackDiamond 8900 xl-series BlackDiamond 10808 BlackDiamond 20800 series Summit X250e, X450a Summit X460 Summit X480, X650
61
Limits
62
128 256
Spanning Treemaximum number of multiple spanning tree instances (MSTI) domains. Spanning Treemaximum number of VLANs per MSTI. Note: Maximum number of 10 active ports per VLAN when all 500 VLANs are in one MSTI. Spanning Treemaximum number of VLANs on all MSTP instances.
500 600
All platforms (except BlackDiamond 20800 series and Summit X460) BlackDiamond 20800 series Summit X460
Spanning Tree (802.1d domains) maximum number of 802.1d domains per port. Spanning Tree (number of ports) maximum number of ports including all Spanning Tree domains. Spanning Tree (maximum VLANs) maximum number of STP protected VLANs (dot1d and dot1w).
All platforms
All platforms
2,048
BlackDiamond 8900 series BlackDiamond 20800 series Summit X460 All other platforms
All platforms
63
Limits
BlackDiamond 10808, MSM-1 BlackDiamond 10808, MSM-1XL BlackDiamond 12800 series BlackDiamond 12800 R-series BlackDiamond 20800 series
Telnet (number of sessions)maximum number of simultaneous Telnet sessions. Virtual routersmaximum number of user-created virtual routers that can be created on a switch. Note: Virtual routers are not supported on Summit X150, X250e, X350, X450a, and X450e series switches.
All platforms
BlackDiamond 8000 c-series BlackDiamond 8900 xl-series BlackDiamond 10808 BlackDiamond 12800 series BlackDiamond 20800 series Summit X460, X480, X650 BlackDiamond 8000 c-series BlackDiamond 8900 xl-series BlackDiamond 10808 BlackDiamond 12800 series BlackDiamond 20800 series Summit X460, X480, X650
63 63 63 63 63 63 190 190 1000 1000 1000 190 190 190 800 800 400 190 8
Virtual router forwarding (VRFs) maximum number of VRFs that can be created on a switch. Note: VRF of type VPN-VRF are not supported in ExtremeXOS 12.5.1.
BlackDiamond 8000 c-series BlackDiamond 8900 xl-series BlackDiamond 10808 BlackDiamond 12800 series BlackDiamond 20800 series Summit X460, X480, X650
Virtual router protocols per VR maximum number of routing protocols per VR. Virtual router protocols per switch maximum number of VR protocols per switch. VLAN aggregationmaximum number of port-VLAN combinations on any one super VLAN and all of its sub VLANs. VLANsincludes all VLANs.
All platforms
All platforms
64
All platforms
1,000
All platforms
4,094
64
All platforms
15
BlackDiamond 8000 a-, c-, e-, xl-series with eight modules of 48 ports 8900-G96T-c modules BlackDiamond 10808 BlackDiamond 12800 series Summit X450a and X450e, group of 24 ports with two-port option cards without option cards Summit series (number of available user ports) 25 23 1 512 383 767 1,400 1,400
VLAN translationmaximum number of translation VLAN pairs with an IP address on the translation VLAN. VLAN translationmaximum number of translation VLAN pairs in an L2-only environment.
All platforms
BlackDiamond 8800 a-, c-, e-series BlackDiamond 8900 xl-series BlackDiamond 10808 BlackDiamond 12800 series Summit X250e, X450a, X450e, X460 Summit X480, X650
vMAN (maximum ACL rules for vMAN) maximum number of ACL rules for vMAN. vMAN (0x8100 ethertype vMANs) maximum number of vMANs configured on a port whose ethertype is 0x8100. VPLS: VCCV (pseudo wire Virtual Circuit Connectivity Verification) VPNs maximum number of VCCV enabled VPLS VPNs.
BlacDiamond 8900 xl-series BlackDiamond 10808 BlackDiamond 12800 R-series BlackDiamond 20800 series Summit X460, X480
16 16 16 16 16
65
Limits
BlacDiamond 8900 xl-series BlackDiamond 10808 BlackDiamond 12800 R-series BlackDiamond 20800 series Summit X460 Summit X480
524,288 (up to)b 100,000 80,000 500,000 32,768 524,288 (up to)b 1,023 2,000 2,000 4,000 1,023 32 32 32 64 32 7,090 2,000 2,000 16,000 7,090 4,000 4,000 4,000 4,000 1,000 4,000
BlackDiamond 8900 xl-series BlackDiamond 10808 BlackDiamond 12800 R-series BlackDiamond 20800 series Summit X460, X480
BlacDiamond 8900 xl-series BlackDiamond 10808 BlackDiamond 12800 R-series BlackDiamond 20800 series Summit X460, X480
BlacDiamond 8900 xl-series BlackDiamond 10808 BlackDiamond 12800 R-series BlackDiamond 20800 series Summit X460, X480
Virtual Private Wire Service (VPWS) VPNsmaximum number of virtual private networks per switch.
BlackDiamond 8900 xl-series BlackDiamond 10808 BlackDiamond 12800 series BlackDiamond 20800 series Summit X460 Summit X480
66
7 8
All platforms
2,048
67
Limits
All platforms Ingress Egress All platforms Ingress Egress 2,048 512 2,048 512
a. b. c. d.
The table shows the total available; see the note included in PD3-77983510. Limit depends on setting configured for configure forwarding external-tables. Applies only if all enabled BlackDiamond 8000 I/O modules are BlackDiamond 8000 c- or xl-series modules. Effective capacity varies based on actual IP addresses and hash algorithm selected, but is higher for BlackDiamond 8000 cseries and xl-series modules and Summit X460, X480 and X650 switches compared to BlackDiamond 8800 a-series and 8000 e-series modules and Summit X250e, X450e, and X450a switches. e. The number of XNV authentications supported based on system ACL limitations.
68
CHAPTER
This chapter describes items needing further clarification and behaviors that might not be intuitive. It also includes the items that have been resolved. This chapter contains the following section:
Open Issues on page 69 Known Behaviors on page 85 Resolved Issues in ExtremeXOS 12.5.3 on page 87 Resolved Issues in ExtremeXOS 12.5.2-patch1-1 on page 89 Resolved Issues in ExtremeXOS 12.5.2.6 on page 90 Resolved Issues in ExtremeXOS 12.5.2.5 on page 90 Resolved Issues in ExtremeXOS 12.5.1 on page 94
Open Issues
Following are the open issues for supported features in ExtremeXOS 12.5.3. They are organized into the following sections: Table 38: Platform-Specific and Feature PDs
PD Number General PD4-2011056021 After a reboot, I/O slots do not go into an operational state with identity management enabled (when I/O ports are part of identity manager). Workaround: Using the ExtremeXOS CLI, run the configure identity-management delete ports all command before the switch reboots. Once the switch has rebooted, run the configure identity-management add ports all command. PD4-1933787334 The RtMgr process may encounter the assertion failure ASSERTION FAILURE by rtmgr in rtMgrResolveEgressIf()@rtMgrTable.c:6892 REASON: IPGW_OUTIF_INDEX(tmpInfo) == ifIndex when an IP address is configured on a VLAN. DHCP/BOOTP relay does not work properly if iproute mpls-next-hops is enabled because they are unsupported features. EPM process crashes with signal 6 when upgrading a switch from ExtremeXOS 12.2.2 to ExtremeXOS 12.3.5 when an SSH license file has 100 or more SSH licenses. Description
PD4-1947340095 PD4-1922513168
69
A telnet access profile is not retained after running the save and reboot commands. A switch does not generate a "Remidfrmport" UPM event when disabling IdMgr globally. Co-existence of untagged vMAN VPLS and VLAN VPLS on LAG ports is not supported. The show fdb command output does not show the pseudo-wire FDBs after a port is disabled and enabled. A switch hangs while adding 52 RIPng processes to a user VR with eight processes already in the default VR. A netTools configuration is lost after a graceful termination of the netTools process followed by an MSM failover. When unconfiguring an IP address on an egress VLAN, or re-configuring the IP address of the egress VLAN, all the MVR cache entries that are ingressing via other VLANs are also cleared from the hardware. Because of this, momentary CPU bursts are observed. A HAL crash with signal 11 occurs when running the disable access-list refresh blackhole command. Whenever a (*, G) join is received, all hardware entries installed on non upstream interfaces (*, G) are cleared. Therefore, every 60 seconds, the L2 switching is affected, traffic comes to the CPU, and entries are re-learned. When using IdMgr, the configure identity-management add port all command is not enabling IdMgr on any ports. Workaround: Use the configure identity-management add port <portlist> command to enable IdMgr on ports.
PD4-1883558321
PD4-1687877872 PD4-1688055111
A switch hangs while adding 49 RIPng processes to a user VR and is then rebooted with seven processes already in the default VR. A system crash occurs when the system is configured with 2,000 VPLS and 1,000 CFM instances while running the restart ports, or save and reboot commands.
70
71
PD3-104885349
BlackDiamond 8800 Series Switch PD4-1941344101 PD4-1878642172 PD4-1680990961 PD4-1806034261 PD4-1827550796, PD4-1147104931 PD4-1557200360 PD4-1546542587 PD4-1637972971 PD4-1567438997 IP multicast error messages occur on slot G8X after clearing IGMP snooping or stopping and restarting multicast streams. Pseudo wire counters for Tx and Rx are not working on BlackDiamond 8900 series switches after a transport LSP path is changed. Process etmon is terminated with signal 6 on MSM-B during local AAA feature regression. Process snmpSubagent is terminated with signal 6 when clearing a counter after setting an SNMP session. A BlackDiamond 8800 series switch takes more than 30 minutes to boot up with VLAN aggregation configured. In ISIS, when the topology mode is changed from multi to single, not all routes are redistributed from OSPFv3. ISIS process crashes with signal 6 while trying to change the metric-style to wide under scaled conditions. Beginning with ExtremeXOS 12.5, the mirroring feature stops working after downgrading and then upgrading the switch software. When an ExtremeXOS switch receives an OSPF user group LSA advertisement with a router ID field as 0.0.0.0, the switch does not process the advertisement and reboots OSPF. When installing new PSU controller firmware, log messages starting with <Crit:Kern.Critical> or <Erro:Kern.Error> may be generated by the backup MSM and can be ignored. Due to the addition of new features in ExtremeXOS 12.5, BlackDiamond 8800 series switch configurations running older management modules (MSM-G8X and MSM-48) may run out of memory when a large number of VLANs are configured with multiple tagged ports added for each VLAN. For example, a configuration with 4,000 VLANs and 24 ports tagged on each VLAN is not supported. Newer BlackDiamond 8800 management modules (MSM-48c or 8900-MSM128) are recommended for larger configurations. An OSPF session goes down and stays in EX_START and continues flapping to EXCHANGE and EX_START states. If a failover occurs during a refresh policy the HAL process dies on a new master MSM. Workaround: Avoid performing a policy refresh if switching from one MSM to another. BlackDiamond 10800 Series Switch PD4-1659977270 A BlackDiamond 10800 switch does not forward L3 routed packets with MPLS PHP enabled. Workaround: Disable MPLS PHP.
PD4-1674379381
PD4-1627772844
PD4-1530729359 PD4-750014887
72
PD4-489592307
PD3-28320363 PD3-124124316
BlackDiamond 12800 Series Switch PD4-1598681891 When a BlackDiamond 12800 series switch is transmitting EAPS traffic, a dual master situation occurs and the backup MSM goes into a failed state causing the system to reboot with a higher number of routes and traffic. Error messages are displayed on the console when an MSM failover is performed, and when a PBB configuration exists with a high number of service VLANs. IPv6 ACL address masks are not working correctly after rebooting a switch.
PD4-1576028451 PD4-722565430
73
PD3-118914021
BlackDiamond 20800 Series Switch PD4-1885738914 PD4-1881467874 When using VPLS, pinging between service VLANs does not work after modifying the tag value of a service VLAN. After an MSM failover from MSM-A to MSM-B and back to MSM-A, ARP learning is not happening on some VLANs. This is causing upper layer protocols such as OSPF to go to the down state. Process HAL crashes when we have 2,000 (S, G) entries with 100 egress VLANs doing L3 multicast routing using PIM DM. BlackDiamond 20800 series switches displays critical error messages and becomes unstable when multicast traffic is received when there are 200 egress interfaces. A system crash occurs on a BlackDiamond 20800 series switch when more than 500 non-VPN VRF instances are created. Establishing 255 ISIS adjacencies in multi-topology mode on a BlackDiamond 20800 series switch causes a HAL crash. With 255 adjacencies, some of the adjacent OSPF peers are in different states, for example, one side shows OSPF neighbors are full, and the other side shows they are still in the exchange state. A BlackDiamond 20800 series switch with 100 egress VLANs crashes when multicast traffic for 1,000 (S,G) entries is received in a burst with varying packet sizes. Disabling a slot on a BlackDiamond 20800 series switch while booting the system removes the module type.
PD4-1618725742 PD4-1369879610
74
PD4-1614019101
PD4-1300795581 PD4-1329832744
PD4-1026932011
75
PD4-734160880, PD4-697230006
76
PD4-603229266
77
PD4-1592270392 PD4-1679652990
78
79
PD4-787052219, PD4-416129282
80
PD3-136493921
An ACL process crash occurs when scaling ESRP for 128 domains.
With graceful restart enabled and import-policy set, BGP routes are withdrawn from the adjacent peer after restarting process BGP (routes are re-advertised to adj only after grace period expires). Ping fails for remote loopback addresses.
CLEAR-Flow commands display on platforms that do not support this capability, including the Summit X150, X250, X350, and X450e series switches, as well as BlackDiamond 8800 non-c-series switches.
EAPS PD4-749215481 Disabling the EAPS master primary port when there are no other ports configured on a protected VLAN will cause a disruption of L2/L3 multicast traffic. Workaround: Enable loopback on all EAPS protected VLANs. PD4-471892924 Restarting the EAPS process on a controller generates the following error messages on a console, but does not impact switch performance. BD-8806.80 # restart process eaps Step 1: terminating process eaps gracefully ... Step 2: starting process eaps ... Restarted process eaps successfully BD-8806.81 # ERROR:VmgrProtocolIfRegister protoId:0 numIf:1 ERROR:VmgrProtocolIfRegister protoId:0 numIf:3 ERROR:VmgrProtocolIfRegister protoId:0 numIf:1
81
PD3-184989177
82
PD3-93630853 PD3-203917264
Multicast PD4-1601466451 PD4-581950231 PD4-521915271 PD4-339945634 When a switch is an IGMP querier, a group specific query is sent to all the ports in the VLAN whenever an IGMP leave is received on one port. Multicast traffic is not received even though the rendezvous point (RP) tree and source information is shown in the PIM cache table The Internet Group Management Protocol (IGMP) group reports may occasionally change from Version 2 to Version 3. When a load-sharing group is a member of a mirrored VLAN, packets ingressing on the member of the load-sharing group in the mirrored VLAN should be mirrored. On the Summit family switches and BlackDiamond 8800 modules, packets ingressing on member ports other than the master port of the load-sharing group in the VLAN are not mirrored. Workaround: Packets ingressing non-master ports in the load sharing group on the mirrored VLAN can be mirrored by adding virtual port mirroring filters for each of the nonmaster member ports. PD3-78144711 PD3-79383551 Network Login PD4-1842342791, PD4-1291631579 PD4-468366251 When working in network login, after a dot1x client logs out, the port is not moved to a MAC-based VLAN. A network login client is not authenticated if the username is 32 characters. Only 31 character user names are supported, even if the user can create a 32-character username. Hitless upgrade is not supported for network login in ExtremeXOS 12.3.1. You should not be able to enable network login if a VLAN is a VLAN-aggregation subVLAN. The system should generate a syntax error. The show ipstats command does not increment IGMPv3 statistics. IGMPv3 Report Record type "5" does not work as expected when sent after a type "2" or a type "4" message.
Configurations using a VR-Mgmt interface as a RADIUS client IP may not load at bootup. However, using an interface in VR-Default will load correctly.
83
Configuring an ingress traffic queue and an egress traffic queue association to multiple ports in sequential order generates the following error: Egress queue already associated to this ingress queue Configuration failed on backup MSM, command execution aborted!
RIP PD4-1650568630 RMON PD3-12950492 ScreenPlay PD3-111344472 Security PD3-205012219 PD3-186939931 The source IP lockdown dynamic deny ACL counter is not working properly and increments valid traffic from a trusted client. Ingress mirroring is not working for DHCP snooping when snooping is enabled on BlackDiamond 12800 series switches. DHCP snooping works correctly when DHCP snooping is disabled. The unconfigure radius and unconfigure tacacs commands do not reset the timeout value to the system default of 3 seconds. ScreenPlay allows you to configure DHCP but you cannot enable DHCP. Issuing the clear counter command might cause a high number to be displayed in variables such as etherHistoryOctets, etherHistoryPkts, and etherHistoryTable. A RIP/RIPng process crash occurs when scaling ESRP for 128 domains.
When an SNMP query is issued for non-existent IPv4 routes, the RtMgr process crashes with signal 11. When changing an SNMP master configuration using SNMP set, the changes are not immediately reflected in the show configuration snmp command output. Run the save configuration command to see the changed configuration in the show configuration snmp output.
PD4-705730556
AES/3des users created using ExtremeXOS 12.3.1 software cannot be used for SNMP operations in ExtremeXOS 12.1 or earlier releases. This may cause the SNMP master to crash.
84
Spanning Tree Protocol PD3-189927343 UPM PD4-1664927541 UPM profiles for events identity-detect and identity-undetect are not executed when many unique kerberos users login simultaneously from two client PCs. This happens when 50 unique users login continuously from PC1, and another 50 unique users login continuously from PC2 at the same time. A temporary loop occurs when a root bridge is taken down by disabling all ports or powering down the switch.
WAN PHY PD3-101226461 When show wan-phy commands are run on non WAN PHY ports, the ports display the headers. It should only display the error wan command is not supported on non-wanphy port 25.
Known Behaviors
The following are limitations in ExtremeXOS system architecture that have yet to be resolved. Table 39: Platform-Specific and Feature PDs
PD Number General PD4-1809333121 PD4-1842342695, PD4-1299398446 PD4-1876448855 PD4-1837408331, PD4-1445926371 PD4-1519936031 BFD sessions for static routes status is not hitless when run msm-failover is performed with minimal timers. Performing a check-policy for a policy containing @description fails after upgrading from ExtremeXOS 12.1.3 software. BFD sessions are not stable when scaled to maximum limits for non-default timer values. A link flap occurs on fiber links connected to a Summit family switch when a BlackDiamond 10800 series switch is rebooted with ports disabled. A kernel-error and reboot loop error occurs when upgrading a switch from ExtremeXOS 12.3.3.6 to ExtremeXOS 12.4 when an ACL is configured as a super VLAN. Description
85
BlackDiamond 20800 Series Switch PD4-1285717901 PD4-1644777015 PD4-1571801812 With 15 ports in a LAG, the maximum to minimum bandwidth utilization difference between ports is 21%. With 16 ports, bandwidth utilization is 8%. The internal QoS profile selected for a packet leaving the Provider Backbone Bridged Network (PBBN) is derived from the 802.1p bits of the B-tag in the packet. When a mirroring-to port is a LAG, load sharing is done only based on the mirror header and not on the configured LAG algorithm.
Summit Family Switches PD4-1642703687 Network Login PD4-1653484241 Network login cannot authenticate MAC addresses on more than 10 VLANs. The VLAN statistics transmit counter does not count the packets matching an egress ACL rule in a Summit X480 switch.
86
87
BlackDiamond 8800 Series Switch PD4-1921505342, PD4-1548261276 PD4-1899757948, PD4-1873304831 On a BlackDiamond 8800 series switch, traffic is not being redirected by the primary LACP port when the secondary MSM with secondary ports is rebooted on LACP during a process kill. ECMP related error messages are seen on BlackDiamond 8800 series switches when enable iproute sharing and LAG are configured on the switch.
BlackDiamond 20800 Series Switch PD4-1905529131, PD4-1536990491 When a BlackDiamond 20800 series switch is an EAPS master, port QP1 increments instead of port QP8.
Summit Family Switches PD4-1879276738, PD4-1506829269 PD4-1910625750 PD4-1967466724 On Summit family switches, ethernet loopback tests fail when running extended diagnostics without an active management port. Leaving a setup running overnight on a Summit X480 switch causes memory depletion. When a port is added as untagged in a service vMAN and tagged in a service VLAN, traffic received on the service VLAN port may be sent using the untagged service vMAN tunnel. An interoperability issue with a VPLS L2 VPN includes a dot1q tag option on untagged service vMAN tunnels between ExtremeXOS 12.4.3 and ExtremeXOS 12.5.2 software. Summit X460 and X480 switches fail to display the switch serial number due to EEPROM corruption. EMS takes approximately 1-minute to report power status on a a Summit switch with a redundant PSU. A Summit X460 switch displays serial interrupt error messages when creating a VLAN using the create vlan v1 CLI command but VLAN creation is fine. A Summit family switch does not send a PSU related SNMP trap when a secondary PSU fails. On a Summit X450a-24x switch, disabling two or more ports causes a port that is inserted as a 10/100/1000BASE-T SFP module to flap.
88
BlackDiamond 20800 Series Switch PD4-1646390158 When using an aggregate meter configuration on a BlackDiamond 20800 series switch, the system cannot use any unused reserved bandwidth.
89
90
The help text for the configure fdb vpls agingtime command displays the wrong possible values. The CLI allows RIP configurations for L2 VLANs. After completing a RIP configuration, running the show rip interface command causes the RIP process to die with signal 11. After configuring an EMS xml-notification target, the name of the target is not included in the output of the show configuration command. Using IdMgr, when running the clear iparp command or disabling IdMgr globally, an ACL/policy applied for a MAC-based identity is not correctly removed from the DUT, causing stale ACLs to remain in the DUT. With IdMgr enabled, an LDAP search fails for a dot1x client using EAP-TLS or EAPPEAP-certificate authentication. This causes a dot1x identity to remain in the authenticated role even though the user configured role exists in the DUT for this identity.
PD4-1575174331
BlackDiamond 8800 Series Switch PD4-1865375583, PD4-1854613879 PD4-1544795181 On a BlackDiamond 8800 series switch, multicast packets are sent directly to the CPU instead of being forwarded in hardware. On a BlackDiamond 8800 series switch, the aggregate number of user created VRs and VRFs bound to ports of an I/O module are limited to the supported number of VRs for that module. Each newly created user VR or VRF is internally assigned an increasing identifier starting with 3. Ports bound to user VRs and VRFs must support the number of VRs equal to the internally generated identifier minus 1 for the VR/VRF or traffic is dropped. Create VRs and VRFs bound to ports of lesser scaling I/O modules first. A BlackDiamond 8800 series switch takes more than 30 minutes to boot up with VLAN aggregation configured. BlackDiamond 8800 series switches report "conduit failures" during bootup if the switch is configured with diffserv replacement enabled for more ports, as well as diffserv replacement mapping. When running the run msm failover command on a BlackDiamond 8800 series switch with an MPLS configuration, the following error may be displayed. MPLS bcm_mpls_port_add failed
91
BlackDiamond 20800 Series Switch PD4-1633907245 A primary MSM may fail and reboot because of a dual master MSM while downloading and installing a new image using a larger number of routes and traffic. This issue is not reproducible using ExtremeXOS 12.5.2 software. After an I/O module hotswap, the show fdb command output does not show the FDB entries learned on particular slots. A BlackDiamond 20800 series switch forwards traffic with the wrong MAC address after receiving a gratuitous ARP request. IPv6 traffic stops forwarding on a BlackDiamond 20800 series switch after load sharing is disabled and enabled. RIPng convergence is not working correctly on a BlackDiamond 20800 series switch if a trunk port is removed and a new port is added. Establishing 255 ISIS adjacencies in multi-topology mode on a BlackDiamond 20800 series switch causes a HAL crash.
Summit Family Switches PD4-1662849321 IdMgr and HAL crashes with signal 11 occur after running UPM profiles for identity_detect, identity_undetect, identity_role_associate, and identity_role_disassociate. This issue is not reproducible in ExtremeXOS 12.5.2 software. Clients are not able to reach each other through a tunnel after running the clear fdb command or a link flap occurs on an MPLS cloud (LSR). Process BFD crashes on a Summit X460 switch after running the show bfd session command when scaling higher than 100 sessions. Workaround: Do not configure more than 75 sessions with an MPLS client. PD4-1588054183 PD4-1507160161 PD4-1820711421, PD4-1572169451 PD4-1851065925 PD4-1686001211 PD4-1681984346 PD4-1676753297, PD4-1240910931 Summit X480 switches are not using EXP bits to map VLAN traffic to the correct QoS profile. VPLS Tx and Rx counters are not incrementing on Summit X460 switches. Power cycling a stack node causes a packet drop of 8 seconds in some rare scenarios even though LAG is configured across stack nodes. The show fdb command output does not show the pseudo-wire FDBs after a port is disabled and enabled. TX VLAN statistics are not correct. Some ports count double and others do not count at all. Traffic is not going over a tagged VPLS service VLAN if an untagged service vMAN is configured on the same port. The cfgmgr crashes with signal 11 due to NULL pointer access.
PD4-1840662158 PD4-1606154901
92
93
94
PD4-1493262869, PD4-1350258611
The ExtremeXOS CLI may allow load sharing groups to be formed using ports with different link speeds. Workaround: Do not change the speed settings before enabling LACP on the remote switch.
95
BlackDiamond 8800 Series Switch PD4-1646744176, PD4-1646617211 PD4-1639563871, PD4-1633773021 PD4-1633677741 When rebooting a BlackDiamond 8800 series switch, ports remain active for approximately 10 seconds. There is a potential for a smbus_xfer:1 smbus_wait_rdy error with frequent SSH and telnet management login/logout sessions. On a BlackDiamond 8800 series switch, making link state changes during a large policy refresh can take more than 20 seconds and may cause duplicate packet forwarding in an MLAG configuration. When using BlackDiamond 8800 series switches or Summit family switches that support user VRs, IP multicast packets are slowpath forwarded with the default VLAN using the default configuration. Workaround: Change the VLAN tag of the default VLAN. PD4-1601047171, PD4-1598240578 PD4-1530467581, PD4-1535593829 PD4-1424690937, PD4-805462597 PD4-1518161071, PD4-1521499552 STP crashes when making topology changes to a domain name containing more than 29 characters. Workaround: Use STP domain names that are less than 30 characters. An untagged packet that is size 1,518 and ingressing an 8900-G48X-xl module is getting slowpath L3 forwarded. A slot fails on a BlackDiamond 8800 series switch when enabling dot1p examination inner-tag ports on more than 24 ports in a vMAN. L2 traffic ingressing a 10G8X-xl I/O module for a MAC that is learned in another slot (G48Tc) is being dropped in some cases.
PD4-1626795210, PD4-1625916850
BlackDiamond 10800 Switch PD4-1641608989, PD4-1108500108 PD4-1586364429, PD4-1566158665 PD4-1272650041, PD4-804225168 PD4-1215941529, PD4-1035637713 On a BlackDiamond 10800 switch with dual MSMs and a G20X module, CLEAR-Flow delta rules may be triggered on the backup MSM when not needed. On a BlackDiamond 10800 series switch, an MSM failover results in too many SNMP traps (extremePortMauChangeTrap) being sent. ESMI related warning messages are seen in the output of the show log command whenever an SSL certificate with a key length of 4,096 is created or the HTTPD process is restarted. Fans on a BlackDiamond 10800 switch may run at a higher RPM, causing unacceptable noise levels.
BlackDiamond 20800 Series Switch PD4-1527934161, PD4-1522821191 PD4-1438460992, PD4-1402199417 A BlackDiamond 20800 series switch crashes when a new VLAN translation member VLAN is added. The system appears to run out of multicast/flooding PSI resources. While running diagnostics on a BlackDiamond 20800 series switch with an XM-8XB module in slot 2, and only one XFM-1 in slot 1, the output of the run diagnostics command shows the following error. Diag Version=1.0.1.7. Exos Version=12.4.1.7 S/N=09366-80141 System Test | FABRIC Connectivity: Device 3 Link 19 Failed PD4-1265032583, PD4-1235317131 Running the show access-list counter command on a BlackDiamond 20800 series switch causes a buffer leak, which results in a slot failure and conduit error.
96
Summit Family Switches PD4-1634882180, PD4-1634368131 PD4-1101069206 PD4-1368980540 PD4-1601466170 When multiple FDB entries share a common set of egress ports spread across units, traffic to certain MAC addresses may not be forwarded on all the ports (ESP ports on alternate units). When configuring 2,000 VPWS instances, only 1,023 VPWS instances are created. Untagged vMAN VPLS service does not encapsulate all VLANS When configuring configure mlag ports convergence-control fast, no warning message appears when all the ACL slice resources have been used by the user ACL. This may lead to a major outage because if a user configures fast mode, traffic is not forwarded when the MLAG port goes down. When applying an ACL on a Summit X450a switch, the following error is generated: Error: ACL install operation failed - slice hardware full for port. A Summit X250-24P switch is unable to upgrade to ExtremeXOS 12.4.1 or later due to an unnecessary file in Compact Flash. Reinstalling the "pktcapt.o" debug module causes a switch to crash in certain scenarios. In a VPWS between a Summit X480 and a third-party switch that are directly attached, that is, no LSRs in the middle, if the third-party switch advertizing an implicit null next hop, the Summit X480 switch sends out the VPLS VPN traffic with only an explicit null label.
SummitStack PD4-1252408701, PD4-1249518348 PD4-1585599632, PD4-1049718893 PD4-1584840513, PD4-1236337241 PD4-1562370060, PD4-1544715651 PD4-1519888011, PD4-1354693709 ACL PD4-1370360717, PD4-902099498 A policy file created in a Windows environment using empty lines at the end of the policy file shows the error Incomplete entry in policy < policy-name > when applying or performing a "check policy." Workaround: Run the edit policy <policy-name> command and save the policy file. You do not need to change the contents of the policy file. BGP PD4-1227697209, PD4-1088907253 BGP does not withdraw routes that are not preferred routes from neighbors to which the routes were previously advertised. A test port remains active while the port is disabled and a 10/100/1000BASE-T miniGBIC and SFP I2C read/write failure 5557 occurs. On a SummitStack, WAN-PHY error counters are not correct on the backup or standby node. UPM becomes active before configuration check pointing is complete, causing the UPM script to fail. On a Summit X480-24x switch with a 10/100/1000 BASE-T copper SFP, ports do not work properly if the speed is set to Auto Off. In a SummitStack configuration, the switch sends the wrong SNMP traps when the link status of a stacking port changes.
97
Spanning Tree Protocol PD4-1696989802, PD4-863165251 PD4-1593308631, PD4-1531283743 PD4-1272649117, PD4-1101544951 When using a 32-character VLAN, the VLAN cannot be added to STP; the last character is removed. After setting dot1dStp SNMP OIDs, the switch experiences an STP process crash with signal 11. A "new root" trap is always generated when a link up or link down occurs on an edge safeguard port in an MSTP domain.
98
99
100