Hi All
I have a wired problem when using LACP from a pair of Juniper SRX 1500's and connecting to a Pair of Juniper EX4200 and Extreme Networks Summit X460-G1 Stacks.
The problem is when I have both connection from SRX's node0 Reth1 connected to the Extreme Stack 1, web sites that are hosted from windows machines on the 4200 VC have speed issue's and random drops of data which causes the site to display an error message. If I remove one of the connection, so basically turning it back to a single connection RETH interface everything seems to work perfectly fine.
I installed a Pair of SRX 1500 into a Chassis Cluster a couple of months ago to replace a SRX240 Cluster. At the time I had the wrong XFP's in the EX4200 Virtual Chassis so I could not connect from the 1500's to the EX4200 at 10GB so had to leave these on 1GB links running LACP. I have 2 Extreme Network stacks with 3 switches in each stack, 2 X460's and 1X440 per stack. The X460's have a 10GB module in the back, which I have connect to the 1500's and then setup LACP on both the Firewall’s and the switches. When I first installed the new Firewall's I connected the node0 to 1 Extreme stack and node 1 to the second stack, when I did this we had the problem I described above so at the time I just dropped the extra connection from the firewall's. Last night I went into our data centre and replaced the XFP's in the Virtual Chassis and connected up the VC to SRX Cluster with redundant links from the SRX's to the VC and configured LACP. I also reconnected the redundant links from the SRX's to the Extreme stack's.
I had several users working from home to test the web sites and they all complained of speed issue's and getting error's on the web sites. As it was getting very late I removed the redundant links for both the EX VC and Extreme Stacks, so basically each firewall is back down to a single connection from the firewall to the switches.
SRX config
Reth1 - connects to Extreme Stacks
Reth1 interfaces xe-0/0/16(Connects to stack1 port 1:30), xe-0/0/17(Connects to stack1 port 2:30), xe-7/0/16(Connects to stack2 port 1:30) and xe-7/0/17(Connects to stack2 port 2:30).
Reth1 redundant-ether-options lacp passive
Reth1 redundant-ether-options lacp periodic slow
Reth0 - Connects to Juniper EX4200 VC
Reth1 interfaces xe-0/0/18, xe-0/0/19, xe-7/0/18 and xe-7/0/19.
Reth0 redundant-ether-options lacp passive
Reth0 redundant-ether-options lacp periodic slow
EX4200 AE2 connects to node0 interface xe-0/0/18 and xe-0/0/19 and AE3 connects to node1 interfaces xe-7/0/18 and xe-7/0/19
xe-0/1/0 ether-options 802.3ad ae2
xe-1/1/0 ether-options 802.3ad ae2
xe-0/1/1 ether-options 802.3ad ae3
xe-1/1/1 ether-options 802.3ad ae3
ae2 aggregated-ether-options lacp active
ae2 aggregated-ether-options lacp periodic slow
ae3 aggregated-ether-options lacp active
ae3 aggregated-ether-options lacp periodic slow
Extreme X460 Sharing Stack 1 connects to Node 0
enable sharing 1:30 grouping 1:30,2:30
configure sharing 1:30 lacp
Extreme X460 Sharing Stack 2 connects to Node 0
enable sharing 1:30 grouping 1:30,2:30
configure sharing 1:30 lacp
As you can see on the Extreme stacks I don't have the LACP mode configured or the time out configured. Could this be the issue?
When I check the timeout values for Extreme LACP and Juniper LACP, Extreme have either a 3 second timeout or a 90 second timeout and juniper have either a 1 second timeout or a 30 second timeout.
One the Juniper SRX's I have 15.1X49-D75.5 installed. On the Extreme stacks I am running 16.1.3.6 running.
I think the problems are all caused by LACP between SRX's and Extreme stacks, so if any one has any suggestion or has configured SRX to Extreme networks before any help would be grate full.
I can create a diagram if that would help
Richard