Catalyst 9300 StackWise Virtual Dual-Active Detection - 夜莺博客

Catalyst 9300 StackWise Virtual Dual-Active Detection

StackWise Virtual turns two physical switches into one logical switch with a single control plane, and it does so over a virtual switch link (SVL) that behaves like an ordinary port channel. The failure mode that makes it dangerous is the same one that affects every virtual chassis design: when the SVL breaks while both switches stay powered, both can believe they are active. Dual-active detection exists solely to make that state detectable and recoverable.

The building blocks

Component Purpose Design note
SVL port channel Carries control traffic and cross-chassis data forwarding Use at least two members on different line cards or ports where possible
Dual-active detection (DAD) link Independent path used only to detect a split Must be physically separate from the SVL
Fast Hello DAD Lightweight periodic check over the DAD link Widely supported and simple
ePAgP DAD Enhanced PAgP messages exchanged with a downstream switch Needs a cooperating neighbour; avoids a dedicated link

A representative implementation elects one switch active and the other standby for control-plane functions: the active switch runs management, bridging, routing protocols and the software data path, while the standby runs in hot standby ready to take over. In steady state that means a single management address and a single routing instance for what is physically two chassis.

Configuration

! SW1
configure terminal
stackwise-virtual domain 10
interface range TenGigabitEthernet1/1-2
 channel-group 10 mode on
 exit
interface Port-channel10
 no switchport
 stackwise-virtual link 1
 exit
stackwise-virtual dual-active-detection
stackwise-virtual dual-active-detection pagp        ! or fast-hello
exit

! SW2 - identical domain
configure terminal
stackwise-virtual domain 10
interface range TenGigabitEthernet1/1-2
 channel-group 10 mode on
 exit
interface Port-channel10
 no switchport
 stackwise-virtual link 1
 exit
stackwise-virtual dual-active-detection
exit

The domain ID must match on both switches and the SVL is built as a plain port channel with mode on - not LACP - because the link is internal control traffic rather than a negotiated bundle to a neighbour. DAD links must be configured manually on the platforms documented by Cisco, and a reload is required for the configuration to take effect.

Choosing transport for SVL and DAD

Cisco publishes a compatibility matrix, and it is narrower than most people assume. Direct-attach copper, active optical cables and the SR/LR optical modules at 10G, 25G and 40G are supported for both SVL and DAD; long-reach optics of the ER/ZR family, CWDM/DWDM modules, and some BiDi variants are supported for neither. If a dual-rate optic is used for the SVL or DAD link it will link up at the highest speed the optic supports, and lower speeds cannot be forced - so a 40/100G optic on a DAD link comes up at 100G whether or not that was the plan.

Power and line card priority

Because the SVL and DAD links live on line cards, power-constrained situations can remove exactly the wrong hardware. Platforms provide power supply autoLC configuration with per-slot priorities so that line cards holding SVL and DAD links are shut down last when power is insufficient. In a 1RU fixed platform this is less relevant; in a modular chassis it is a design requirement, not a nicety.

Verification

show stackwise-virtual
show stackwise-virtual link
show stackwise-virtual dual-active-detection
show platform svl links
show switch virtual

Confirm three things after commissioning: the SVL is up with the expected members and no errors, DAD is configured and reporting on both switches, and the pair presents one management address and one router ID to the rest of the network. Then test the failure path deliberately in a maintenance window - pull one SVL member, then simulate DAD failure - because a DAD link that was never exercised is indistinguishable from one that does not work.

Related reading: StackWise-480 versus StackWise Virtual, choosing between the two stacking modes and Dell OS10 VLT peer routing for the equivalent concept on a different vendor.

原文链接:https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9600/software/release/17-12/configuration_guide/ha/b_1712_ha_9600_cg/configuring_cisco_stackwise_virtual.html