ArubaOS-CX VSX Active Gateway Configuration Guide - 夜莺博客

ArubaOS-CX VSX Active Gateway Configuration Guide

An active gateway removes the standby half of first-hop redundancy. Instead of one switch answering ARP for the gateway IP while the other waits, both ArubaOS-CX VSX peers own the same virtual IP and the same virtual MAC, and either one routes the traffic locally. The result is active-active forwarding, no VRRP protocol state to converge, and roughly half the inter-switch-link traffic during normal operation because a server's default gateway reply never has to cross the ISL. This article covers the VSX prerequisites, the per-SVI active gateway configuration, the mutual-exclusion rules that trip people up, and how to verify the virtual MAC is really programmed.

Prerequisites

  • The active gateway can only be configured on an SVI — never on a routed physical port.
  • The SVI must already hold an IP address in the same subnet as the active gateway IP you are about to configure. The CLI will accept a mismatched address, but the gateway will not be programmed in the kernel and will be unreachable.
  • The configuration must be identical on both VSX peers — same virtual IP, same virtual MAC.
  • VRRP and active forwarding cannot coexist with active gateway on the same SVI. Pick one.

Configuring the Active Gateway

Both peers get the same virtual MAC and the same virtual IP, but their own unique SVI addresses. vsx-sync active-gateways makes the gateway configuration synchronize across the VSX pair so a single change propagates.

# AGG-1
interface vlan10
    vsx-sync active-gateways
    ip address 10.1.10.2/24
    ip address 10.2.10.2/24 secondary
    active-gateway ip mac 12:01:00:00:01:00
    active-gateway ip 10.1.10.1
    active-gateway ip 10.2.10.1
    ip helper-address 10.99.10.9

# AGG-2
interface vlan10
    vsx-sync active-gateways
    ip address 10.1.10.3/24
    ip address 10.2.10.3/24 secondary
    active-gateway ip mac 12:01:00:00:01:00
    active-gateway ip 10.1.10.1
    active-gateway ip 10.2.10.1

The virtual MAC must be a locally administered address distinct from any physical MAC in the fabric. Reusing a hardware MAC from one of the peers works until that peer is replaced, at which point the gateway MAC changes and every ARP cache in the VLAN is stale.

Scale Limits Worth Knowing

  • Maximum 4,000 active gateways per switch.
  • Maximum 500 unique active gateway IP + MAC pairs.
  • Optionally, active-gateway ip mac ... extended-mac gives you extra MAC entries in overlay environments, up to the platform limit. Extended MAC is mutually exclusive with MAC lockout: if lockout entries exist the extended-mac configuration fails, and vice versa.
  • If the active gateway uses the same IPv6 address as the SVI, IPv6 DAD cannot be configured and the SVI address becomes unchangeable.

Verification

AGG-1# show vsx status
AGG-1# show vsx status keepalive
AGG-1# show interface vlan10
AGG-1# show ip route
AGG-1# show arp | include 10.1.10.1

show vsx status should report ISL channel: In-Sync, Keepalive State: Keepalive-Established and Config Sync Status: in-sync on both members. show interface vlan10 is where you confirm the virtual MAC is actually present on the SVI — if it is missing, the usual cause is an SVI IP outside the gateway subnet.

Failure Behaviour to Test Before You Need It

Active gateway survives an ISL failure because each peer keeps its own forwarding table, but the behaviour during a simultaneous ISL and keepalive failure is what determines whether you get a split brain. Confirm the keepalive is not sharing a physical path with the ISL — the recommended design puts keepalive over a dedicated link or a VRF riding the upstream Layer 3 domain, precisely so a fibre cut cannot take out both the ISL and the heartbeat at once.

For the surrounding design, see ArubaOS-CX VSX Configuration: Active-Active Switch HA and the split-brain recovery workflow. If you are comparing this against a protocol-based approach, Junos VRRP Configuration: VIP, Priority and Accept-Data covers the active-standby alternative and ArubaOS-CX VRRP and Active Gateway: First Hop Redundancy shows the VSX-specific syntax.

原文链接:https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedAssets/AOS-CX%20VSX%20-%20Technical%20Whitepaper%20-%20v1.0.pdf