Juniper MC-LAG ICCP Flapping: MTU and Keepalive Tuning - 夜莺博客

Juniper MC-LAG ICCP Flapping: MTU and Keepalive Tuning

An MC-LAG that flaps every few minutes is almost never an LACP problem — it is an ICCP problem. When the Inter-Chassis Control Protocol session between the two Junos peer switches goes down and comes back, both peers re-elect the LACP system ID owner, the inter-chassis link (ICL) is torn down, and every dual-homed server sees a brief but real outage. This guide walks through the three mechanisms that most often cause ICCP to flap silently: an MTU mismatch between the ICCl control path and the data path, keepalive timers tuned too aggressively for the ICL load, and ICL congestion that starves ICCP keepalive packets.

What ICCP Actually Does on Junos

ICCP is a TCP session (port 2021) between the two MC-LAG peers. It carries the state that makes the pair look like one LACP partner: the shared system ID, the ICL link status, and the MC-AE state machine. If ICCP drops, each peer reverts to its own system ID — if you have not configured a common lacp-system-id, the server's LAG splits and traffic is black-holed on the standby member.

Cause 1: MTU Mismatch on the Path Between Peers

ICCP runs over IP between local-ip and the peer address, which is usually the IRB or a loopback. If the physical path between peers uses jumbo frames but one side is left at 1500, large ICCP state updates fragment or are silently dropped, which manifests as a session that establishes and then resets under load.

Verification

show interfaces ge-0/0/0 | match mtu
show interfaces irb.100 | match mtu
show configuration protocols iccp
test ipv4 ping 10.50.1.2 size 9000 count 3 do-not-fragment

A do-not-fragment ping that succeeds at 1472 bytes but fails at 9000 bytes on a path you believe is jumbo is the confirmation you need.

Fix

set interfaces ge-0/0/0 mtu 9192
set interfaces ae0 mtu 9192

Cause 2: Keepalive and Session-Establishment Timers

ICCP uses a three-way handshake with a configurable session establishment hold time. On QFX Series switches the default is 300 seconds, and Juniper requires the session establishment time to be at least 100 seconds higher than the init delay. On a busy fabric where ICCP is slow to converge, a timer set below the platform guidance produces a session that never fully establishes — and each retry looks like a flap in the logs.

Verification

show iccp
show iccp statistics
show log messages | match iccp | last 50

Fix

set protocols iccp peer 10.50.1.2 session-establishment-hold-time 340
set protocols iccp peer 10.50.1.2 local-ip 10.50.1.1

Cause 3: ICL Congestion Starving Keepalives

ICCP keepalive packets share the ICL with data traffic. If the ICL is a single 10G member while the MC-AE bundles two 100G uplinks, a microburst can delay keepalives past the hold time. This is the classic “it only flaps during the nightly backup” pattern. Give ICCP its own path or protect it with a forwarding class and scheduler.

show interfaces ae0 extensive | match "input rate|output rate"
show class-of-service interface ae0
set class-of-service forwarding-classes queue 7 iccp-control
set firewall family inet filter protect-iccp term iccp from protocol tcp
set firewall family inet filter protect-iccp term iccp then forwarding-class iccp-control

Verification Checklist

  • show iccp — session must read Established on both peers simultaneously.
  • show mc-ae status — check that the AE is active on one peer and standby on the other, with the same system ID.
  • show lacp interfaces ae0 — the LACP system ID must match on both chassis.
  • monitor traffic interface irb.100 no-resolve — confirm ICCP packets are actually flowing.

Prevention

Configure the ICL as a static LAG with no LACP, keep the ICCP path MTU identical end to end, enable BFD liveness detection on the ICL so a data-plane failure is detected in milliseconds rather than waiting for ICCP hold time, and always define an explicit lacp-system-id so a single ICCP blip cannot split the LAG. Finally, alert on syslog pattern ICCP_PEER_DOWN rather than waiting for a customer ticket.

Related Reading

Deeper dives on the same topics from our archive:

原文链接:https://www.juniper.net/documentation/us/en/software/junos/mc-lag/topics/topic-map/examples-mc-lag.html