Supported security protocols and services are not
affected during a switchover or failover, with the following
exceptions: - Media Access Control Security (MACsec), IEEE 802.1ae,
when configured on a stack, does not support hitless stacking
because MACsec sessions must be re-established by device
firmware.
- IEEE 802.1X is affected if re-authentication does not
occur in a specific time window.
- MAC authentication is affected if re-authentication does not occur in a variable-length
time window.
- In some cases, a few IP source guard packets may be permitted or dropped.
- If IEEE 802.1X and MAC authentication are enabled
together on the same port, both will be affected during a
switchover or failover. Hitless stacking support for these
features applies to ports with IEEE 802.1X only or multi-device
port authentication only.
- For MAC port security, secure MAC addresses are synchronized between the active and
standby controllers, so they are hitless. However, denied MAC addresses are lost during
a switchover or failover but may be relearned if traffic is present.
Configured ACLs will operate in a hitless manner. That is, the system will continue
to permit and deny traffic during the switchover or failover process. However, dynamic
ACLs are not supported for hitless switchover and failover.
After a switchover or failover, the new active
controller will re-authenticate IEEE 802.1X or MAC authentication
sessions that were being forwarded in hardware.
|