Re: HA: pair of firewalls, 2 switches and 1 server

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Jussi Peltola
Date: Thursday, May 20, 2010 - 11:59 am

On Thu, May 20, 2010 at 08:17:48PM +0200, Henning Brauer wrote:
 
Bad wording on my part, the routers run OSPF and the switches are dumb
L2 devices.

Still, without OSPF et al there would be no way to detect a crappy
switch failing in funny ways, which was my point.

As an extra note, if you do get a crappy switch, be very careful with
its management interface. The cheapest ones have unbelievably slow CPUs
that are easily overloaded by broadcasts making the whole thing stop
responding. Even worse, the interrupt load seems to trigger some other
bugs, like LACP mysteriously failing and disabling one port on a trunk
and blackholing half of your traffic (this happened on a ZyXEL GS-4024,
which has otherwise totally Just Worked as a L2 switch for years) or
even the whole switch ASIC "crashing" after a broadcast storm and
requiring a reboot (though the management CPU was still responding
through the out of band ether and serial port after the storm was gone)

Also, it's a very obvious DoS; a malicious person needs to send a rather
small amount of BPDUs to overload the tiny CPU and the cheap switches
obviously have no rate limiting for packets going to the CPU (only on
all broadcasts). So, blocking BPDUs from non-trusted devices should be
enabled (but that should probably be done anyway.)

Even among "trusted" devices STP and LACP involve the shitty code
running on the underpowered management CPU, and that is not the part
that shines in the cheap switches. Static link aggregation works OK.
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
HA: pair of firewalls, 2 switches and 1 server, Axel Rau, (Tue May 18, 5:02 am)
Re: HA: pair of firewalls, 2 switches and 1 server, Guido Tschakert, (Tue May 18, 5:11 am)
Re: HA: pair of firewalls, 2 switches and 1 server, Leonardo Carneiro - ..., (Tue May 18, 5:20 am)
Re: HA: pair of firewalls, 2 switches and 1 server, Guido Tschakert, (Tue May 18, 10:59 pm)
Re: HA: pair of firewalls, 2 switches and 1 server, Henning Brauer, (Wed May 19, 3:04 pm)
Re: HA: pair of firewalls, 2 switches and 1 server, Axel Rau, (Thu May 20, 10:02 am)
Re: HA: pair of firewalls, 2 switches and 1 server, Graham Allan, (Thu May 20, 10:18 am)
Re: HA: pair of firewalls, 2 switches and 1 server, Henning Brauer, (Thu May 20, 10:28 am)
Re: HA: pair of firewalls, 2 switches and 1 server, Jussi Peltola, (Thu May 20, 11:00 am)
Re: HA: pair of firewalls, 2 switches and 1 server, Henning Brauer, (Thu May 20, 11:17 am)
Re: HA: pair of firewalls, 2 switches and 1 server, Henning Brauer, (Thu May 20, 11:41 am)
Re: HA: pair of firewalls, 2 switches and 1 server, Axel Rau, (Thu May 20, 11:41 am)
Re: HA: pair of firewalls, 2 switches and 1 server, Jussi Peltola, (Thu May 20, 11:59 am)
Re: HA: pair of firewalls, 2 switches and 1 server, Graham Allan, (Thu May 20, 12:02 pm)
Re: HA: pair of firewalls, 2 switches and 1 server, Reyk Floeter, (Thu May 20, 1:07 pm)
Re: HA: pair of firewalls, 2 switches and 1 server, Jussi Peltola, (Thu May 20, 1:31 pm)
Re: HA: pair of firewalls, 2 switches and 1 server, Reyk Floeter, (Thu May 20, 3:22 pm)
Re: HA: pair of firewalls, 2 switches and 1 server, Tomoyuki Sakurai, (Thu May 20, 4:53 pm)
Re: HA: pair of firewalls, 2 switches and 1 server, Olivier Cherrier, (Thu May 20, 11:01 pm)
Re: HA: pair of firewalls, 2 switches and 1 server, Jussi Peltola, (Fri May 21, 1:11 am)
Re: HA: pair of firewalls, 2 switches and 1 server, Axel Rau, (Sat May 22, 12:41 pm)
Re: HA: pair of firewalls, 2 switches and 1 server, Axel Rau, (Sat May 22, 12:42 pm)