Zero-touch and SPX interactive-setup deployment considerations

SPX interactive-setup is a superset of zero-touch provisioning. Both Campus Fabric provisioning methods use the same discovery procedures, algorithms, and configured probing ports. In fact, zero-touch provisioning generates the same results that SPX interactive-setup would if you accepted all default values presented by pressing Enter or Y when prompted.

Ruckus recommends SPX interactive-setup over zero-touch provisioning for the following reasons:

  • SPX interactive-setup triggers a topology discovery as soon as you launch the utility. In contrast, zero-touch does topology discovery every 3 minutes in background (although zero-touch discovery is triggered within one minute when the probing ports first become active).
    Note: You should connect all physical links before running SPX interactive-setup or enabling zero-touch provisioning so that all new units and links are discovered in one process. Furthermore, although you have control over when SPX interactive-setup runs, if zero-touch provisioning is enabled, it could be triggered in background before you have finished all the physical connections.
    Note: If you use zero-touch provisioning, you should remove zero-touch-enable configuration after SPX system construction is complete. Otherwise, the system continues to send periodic zero-touch probes in background. While the continued probes are harmless, they waste CPU time and generate unnecessary packets.
  • SPX interactive-setup displays the discovered topology.
  • SPX interactive-setup includes options that allow you to select units or IDs.
  • SPX interactive-setup also includes options that allow you to select units or links to transform an invalid topology into a valid topology.

Zero-touch and SPX interactive-setup deployment limitation

Zero-touch provisioning and SPX interactive-setup cannot detect a standalone unit that is connected behind a PE that has not joined the SPX system. Consider the following illustration. On the left is the original PE chain topology. Assume that you are replacing PE units 2, 3, and 5 with new units. Zero-touch and SPX interactive-setup can detect new units 2 and 3 (shown in the new topology on the right as NU 2 and NU 3). Neither utility can detect the new unit NU 5 because it is separated from the SPX system by PE unit 4, which has not joined the SPX system yet. PE unit 4 does not rejoin the SPX system until new units NU 2 and NU 3 have joined the system as PE units. To detect and convert NU 5 to a PE, you can initiate SPX interactive-setup again. If zero-touch provisioning is running, it will discover NU 5 the next time it is triggered (after three minutes).

Undetected standalone separated from active PE chain

Zero-touch and SPX interactive-setup deployment recommendations

Keep the following points in mind when configuring the Campus Fabric domain with the zero-touch or SPX interactive-setup utility.

  • Before LAGs are formed, individual links may cause loops, especially if CB or PE units are connected to clients running any control protocols.
  • Multiple links between any two units cause loops until they are converted to an SPX LAG. SPX ports and SPX LAGs are recommended to avoid loops.
  • Loops cause high traffic in the looped ports and may cause high CPU if looped packets are trapped to the CPU.
  • The zero-touch utility does not run if the CPU level is greater than 96%. Instead, the utility issues a warning that suggests using the SPX interactive-setup utility.
  • Loops should be resolved once the zero-touch or SPX interactive-setup utility has converted multiple links between any two units to SPX LAGs.
  • As a best practice, you should remove zero-touch-ports configuration once PE discovery is complete. You should also disable zero-touch-enable.
  • After PE discovery is complete and you have removed zero-touch-enable configuration, you can always run SPX interactive-setup to make changes to the existing system, for example, to move PE units or change PE IDs.
  • Do not connect hosts or access points to PE candidates until zero-touch provisioning is complete.
  • We recommend the SPX interactive-setup utility in a live production environment with connected hosts and access points.
  • Zero-touch configuration works for PE candidates that have no configuration.
  • Once new units have been connected to the Campus Fabric domain, check for loops by entering the clear statistics and then the show statistics brief commands on the CB. The packet counts displayed in command output should be low. If packet counts are high, that indicates loops in the system. The SPX interactive-setup utility can resolve all loops.

Manual configuration can always be used instead of zero-touch provisioning or SPX interactive-setup for greater control over the discovery process and to avoid loops and high CPU. Manual configuration requires these steps:

  1. Configure correct SPX ports or LAGs on the CB and on new PE candidates.
  2. Configure and reload new units to convert them to PEs. For more information, refer to Manually enabling and configuring PE units.
  3. Physically connect the links.

Note: Zero-touch and SPX interactive-setup have enhancements to harden the discovery process as of FastIron release 8.0.61. Previously, if live clients were connected to switches waiting to be converted to PE units, there was a chance of loops. Now, loop packets are dropped until discovery is complete. This enhances the reliability of discovering all PE candidates and links under severe situations. The loops are removed after zero-touch or SPX interactive-setup changes multiple inter-switch links between two units into a LAG. If your system has no live traffic, you can connect new units the way you want without being concerned about creating loops. If your system has clients carrying live traffic, there are going to be temporary loops. As long as you allow zero-touch or SPX interactive-setup to discover all units and links, and change discovered units to PEs to generate appropriate running-configuration, the loops are handled and should resolve automatically.