Nokia Network Voyager Reference Guide for IPSO 6.0 - Check Point
Nokia Network Voyager Reference Guide for IPSO 6.0 - Check Point Nokia Network Voyager Reference Guide for IPSO 6.0 - Check Point
2 Configuring InterfacesYou can specify a minimum number of ports that must be active for the logical interface toremain active. If the number of active ports is less than this number, the logical interface isdeactivated. This option is particularly useful in VRRP configurations. For example, you mighthave a VRRP pair in which both the master and backup systems use two aggregated GigabitEthernet ports as their external connection. If one of the Gigabit Ethernet ports in the masterfails, you probably would prefer that the backup system becomes the master so that there is noloss of bandwidth in the external connection. In this case, you would set the minimum number ofactive ports to be two.You can aggregate as many as four ports in one aggregation group, and you can have as many aseight aggregation groups on one appliance.You can hot swap NICs that have ports participating in an aggregation group. If the group hasports on other NICs, the traffic is distributed to those ports and the aggregation group continuesto function when you remove a NIC in this manner. If you reinsert the NIC, the appropriate portsrejoin the aggregation group and resume forwarding traffic automatically.You can view statistical information about link aggregation groups and the individual interfacesin the groups by clicking Configuration > Monitor > System Health > Interface TrafficStatistics > Link Aggregation Statistics.Static Link AggregationThe IPSO implementation of link aggregation complies with the IEEE 802.3ad standard forstatic link aggregation. Nokia has also tested IPSO link aggregation with the following CiscoCatalyst switches:• 6500 Series• 3550 Series• 2950 SeriesIPSO 6.0 does not support LACP, which is used for dynamic link aggregation. IPSO 4.2 doessupport LACP.CautionMake sure that dynamic link aggregation (LACP) is disabled before you upgrade fromIPSO 4.2 to IPSO 6.0. If you do not, the ports in the aggregation group will loseconnectivity after the upgrade.Managing Link Aggregation Using SNMPNokia IPSO systems use a proprietary SNMP MIB to manage link aggregation. To incorporatelink aggregation into your SNMP-based management, perform the following tasks:• Copy the file NOKIA-IPSO-LINKAGGREGATION-MIB.txt to your management system.This file is located at /etc/snmp/mibs/.• In Network Voyager or the IPSO CLI, enable the following traps:32 Nokia Network Voyager Reference Guide for IPSO 6.0
Link Aggregation• Enable lamemberActive traps• Enable lamemberInactive trapsNoteIPSO does not use the standard IEEE8023-LAG-MIB to support link aggregation.Configuring Switches for Link AggregationObserve the following considerations when you configure a switch to support link aggregationin combination with a Nokia appliance:• You must configure the appropriate switch ports to use static link aggregation. (On Ciscoswitches, this means you must enable EtherChannel.) That is, if you aggregate four portsinto one group on your Nokia appliance, the four switch ports that they connect to muststatic link aggregation.• When you assign switch ports to an EtherChannel group, set the channel mode to on toforce the ports to form a channel without using the Link Aggregation Control Protocol(LACP) or Port Aggregation Protocol (PAgP).• If your switch supports it, configure the aggregated ports to distribute the traffic usingsource and destination IP addresses.• If your switch can only distribute traffic based on source or destination MAC addresses,configure it to use the source MAC addresses. If it uses the destination MAC address todistribute the load, all the traffic flowing from the switch to the IPSO system over theaggregated link is sent to the primary port of the aggregation group.• You must configure the switch ports to have the same physical characteristics (link speed,duplicity, autoadvertise/autonegotiation setting, and so on) as the corresponding aggregatedports on the Nokia system.• On Cisco switches, trunking must be enabled if you create more than one tagged VLAN onan aggregated link. (You can configure as many as 1015 VLANs for an IPSO system.).• If you use IOS on a Cisco switch, trunking is enabled automatically.• If you run CatOS on a Cisco switch, use the following command to configure VLANtrunking on the EtherChannel:set trunk ports nonegotiate dot1q vlansConfiguring Link AggregationTo set up link aggregation in Network Voyager1. Physically configure the interfaces.2. Create the aggregation group.3. Logically configure the aggregation group.These steps are explained in the following sections.Nokia Network Voyager Reference Guide for IPSO 6.0 33
- Page 2 and 3: COPYRIGHT©2007 Nokia. All rights r
- Page 4 and 5: 4 Nokia Network Voyager Reference G
- Page 6 and 7: Deleting Aggregation Groups . . . .
- Page 8 and 9: Choosing Global Settings. . . . . .
- Page 11 and 12: Monitoring Cryptographic Accelerati
- Page 13 and 14: Route Dampening . . . . . . . . . .
- Page 15 and 16: iclid Commands. . . . . . . . . . .
- Page 17 and 18: About the Nokia Network VoyagerRefe
- Page 19 and 20: Related DocumentationTable 1 Text C
- Page 21 and 22: 1 About Network VoyagerThis chapter
- Page 23 and 24: Logging In to Network VoyagerObtain
- Page 25 and 26: Navigating in Network Voyager• Ne
- Page 27 and 28: 2 Configuring InterfacesThis chapte
- Page 29 and 30: Ethernet InterfacesEvents that can
- Page 31: Link AggregationExample: eth-s2p13.
- Page 35 and 36: Link AggregationGroup Configuration
- Page 37 and 38: Gigabit Ethernet InterfacesTable 4
- Page 39 and 40: Gigabit Ethernet InterfacesThe Noki
- Page 41 and 42: Loopback Interfacesa secure private
- Page 43 and 44: GRE TunnelsEach time you select a t
- Page 45 and 46: GRE Tunnels3. Select a value from t
- Page 47 and 48: GRE Tunnelsof this reference guide,
- Page 49 and 50: DVMRP TunnelsDVMRP TunnelsDVMRP (Di
- Page 51 and 52: DVMRP TunnelsA router forwards Mult
- Page 53 and 54: ARP Table EntriesThe Retry Limit sp
- Page 55 and 56: Virtual Tunnel Interfaces (FWVPN) f
- Page 57 and 58: Virtual Tunnel Interfaces (FWVPN) f
- Page 59 and 60: 3 Configuring System FunctionsThis
- Page 61 and 62: Configuring DHCPDHCP Client Configu
- Page 63 and 64: Configuring DHCP22. If you configur
- Page 65 and 66: Configuring DHCPAssigning a Fixed-I
- Page 67 and 68: Configuring DHCP12. Enter the Simpl
- Page 69 and 70: Configuring Disk MirroringThe sourc
- Page 71 and 72: Configuring System TimeConfiguring
- Page 73 and 74: Configuring System TimeNoteIPSO wil
- Page 75 and 76: Using an Optional Disk (Flash-Based
- Page 77 and 78: Configuring System LoggingTo remove
- Page 79 and 80: Configuring System Logging4. Click
- Page 81 and 82: Configuring System LoggingConfiguri
Link Aggregation• Enable lamemberActive traps• Enable lamemberInactive trapsNote<strong>IPSO</strong> does not use the standard IEEE8023-LAG-MIB to support link aggregation.Configuring Switches <strong>for</strong> Link AggregationObserve the following considerations when you configure a switch to support link aggregationin combination with a <strong>Nokia</strong> appliance:• You must configure the appropriate switch ports to use static link aggregation. (On Ciscoswitches, this means you must enable EtherChannel.) That is, if you aggregate four portsinto one group on your <strong>Nokia</strong> appliance, the four switch ports that they connect to muststatic link aggregation.• When you assign switch ports to an EtherChannel group, set the channel mode to on to<strong>for</strong>ce the ports to <strong>for</strong>m a channel without using the Link Aggregation Control Protocol(LACP) or Port Aggregation Protocol (PAgP).• If your switch supports it, configure the aggregated ports to distribute the traffic usingsource and destination IP addresses.• If your switch can only distribute traffic based on source or destination MAC addresses,configure it to use the source MAC addresses. If it uses the destination MAC address todistribute the load, all the traffic flowing from the switch to the <strong>IPSO</strong> system over theaggregated link is sent to the primary port of the aggregation group.• You must configure the switch ports to have the same physical characteristics (link speed,duplicity, autoadvertise/autonegotiation setting, and so on) as the corresponding aggregatedports on the <strong>Nokia</strong> system.• On Cisco switches, trunking must be enabled if you create more than one tagged VLAN onan aggregated link. (You can configure as many as 1015 VLANs <strong>for</strong> an <strong>IPSO</strong> system.).• If you use IOS on a Cisco switch, trunking is enabled automatically.• If you run CatOS on a Cisco switch, use the following command to configure VLANtrunking on the EtherChannel:set trunk ports nonegotiate dot1q vlansConfiguring Link AggregationTo set up link aggregation in <strong>Network</strong> <strong>Voyager</strong>1. Physically configure the interfaces.2. Create the aggregation group.3. Logically configure the aggregation group.These steps are explained in the following sections.<strong>Nokia</strong> <strong>Network</strong> <strong>Voyager</strong> <strong>Reference</strong> <strong>Guide</strong> <strong>for</strong> <strong>IPSO</strong> <strong>6.0</strong> 33