Hello all,
I´m having a open question regarding number/limit of private vlans in a virtual chasiss setup.
In my company we wanted to implement private vlans for a specific network which is defined with vlan-id 516.
I have configured a virtual chasiss with ex3300 containig 5 switches (1xRE, 1xBRE, 3xLC).
After this I have placed all GE ports in VC switch in access mode and for every port defined a private vlan.
With this setup I have 5*48=240 private vlans in VC switch (which is far less than 4094).
Placing the VC in production I have found strange issue, that ports in private vlan on Sw0 and Sw1 are working correctly but ports on Sw2 are not receiving communication over the uplink. On the uplink ae0 there are all vlans defined i.e. management with vlan-id 10, data vlans with vlan id 37 and master private vlan with vlan id 516.
Here is the actual configuration for virtual chasiss (VC) - all chasiss member are correctly configured and placed.
Uplink agg.-interface (ae0, 2x1GE) is configured on Sw0-RE port ge0/1/0 and Sw1-BRE port ge-1/1/0.
root@sw> show virtual-chassis status
Preprovisioned Virtual Chassis
Virtual Chassis ID: 70fd.43f8.3704
Virtual Chassis Mode: Enabled
Mstr Mixed Neighbor List
Member ID Status Serial No Model prio Role Mode ID Interface
0 (FPC 0) Prsnt GB0212507879 ex3300-48p 129 Master* NA 1 vcp-255/1/2
4 vcp-255/1/3
1 (FPC 1) Prsnt GA0214050124 ex3300-48t 129 Backup NA 2 vcp-255/1/2
0 vcp-255/1/3
2 (FPC 2) Prsnt GA0214050392 ex3300-48t 0 Linecard NA 3 vcp-255/1/2
1 vcp-255/1/3
3 (FPC 3) Prsnt GA0214020272 ex3300-48t 0 Linecard NA 4 vcp-255/1/2
2 vcp-255/1/3
4 (FPC 4) Prsnt GA0214020116 ex3300-48t 0 Linecard NA 0 vcp-255/1/2
3 vcp-255/1/3
Here is the actual configuration for private vlans.
root@sw# show | display set | match n-av-m
set vlans n-av-m vlan-id 516
set vlans n-av-m-000 interface ge-0/0/0.0
set vlans n-av-m-000 primary-vlan n-av-m
set vlans n-av-m-001 interface ge-0/0/1.0
set vlans n-av-m-001 primary-vlan n-av-m
set vlans n-av-m-002 interface ge-0/0/2.0
set vlans n-av-m-002 primary-vlan n-av-m
set vlans n-av-m-003 interface ge-0/0/3.0
set vlans n-av-m-003 primary-vlan n-av-m
set vlans n-av-m-004 interface ge-0/0/4.0
--zip--
set vlans n-av-m-100 interface ge-1/0/0.0
set vlans n-av-m-100 primary-vlan n-av-m
set vlans n-av-m-101 interface ge-1/0/1.0
set vlans n-av-m-101 primary-vlan n-av-m
set vlans n-av-m-102 interface ge-1/0/2.0
set vlans n-av-m-102 primary-vlan n-av-m
set vlans n-av-m-103 interface ge-1/0/3.0
set vlans n-av-m-103 primary-vlan n-av-m
set vlans n-av-m-104 interface ge-1/0/4.0
set vlans n-av-m-104 primary-vlan n-av-m
set vlans n-av-m-105 interface ge-1/0/5.0
--zip--
set vlans n-av-m-147 interface ge-1/0/47.0
set vlans n-av-m-147 primary-vlan n-av-m
set vlans n-av-m-200 interface ge-2/0/0.0
set vlans n-av-m-200 primary-vlan n-av-m
set vlans n-av-m-201 interface ge-2/0/1.0
set vlans n-av-m-201 primary-vlan n-av-m
set vlans n-av-m-202 interface ge-2/0/2.0
set vlans n-av-m-202 primary-vlan n-av-m
set vlans n-av-m-203 interface ge-2/0/3.0
--zip--
set vlans n-av-m-347 interface ge-3/0/47.0
set vlans n-av-m-347 primary-vlan n-av-m
set vlans n-av-m-400 interface ge-4/0/0.0
set vlans n-av-m-400 primary-vlan n-av-m
set vlans n-av-m-401 interface ge-4/0/1.0
set vlans n-av-m-401 primary-vlan n-av-m
--zip--
set vlans n-av-m-446 interface ge-4/0/46.0
set vlans n-av-m-446 primary-vlan n-av-m
set vlans n-av-m-447 interface ge-4/0/47.0
set vlans n-av-m-447 primary-vlan n-av-m
Here is the actual configuration for a acces port.
root@deeurw037# show interfaces ge-0/0/0
unit 0 {
family ethernet-switching {
port-mode access;
}
}
...
root@deeurw037# show interfaces ge-4/0/47
unit 0 {
family ethernet-switching {
port-mode access;
}
}
...
root@deeurw037# show vlans
n-av-m {
vlan-id 516;
}
n-av-m-000 {
interface {
ge-0/0/0.0;
}
primary-vlan n-av-m;
}
n-av-m-001 {
interface {
ge-0/0/1.0;
}
primary-vlan n-av-m;
}
n-av-m-002 {
interface {
ge-0/0/2.0;
--snip--
n-av-m-446 {
interface {
ge-4/0/46.0;
}
primary-vlan n-av-m;
}
n-av-m-447 {
interface {
ge-4/0/47.0;
}
primary-vlan n-av-m;
}
s-data {
vlan-id 37;
}
s-mgmt {
vlan-id 10;
l3-interface vlan.10;
}
Can anybody point me in the right direction? What is wrong with the configuration? is there a limit of private vlans do define?
Thanks in advance.