MCT Feature Interaction and Unsupported Features

The following FastIron features are supported with MCT. All security features are locally significant and are not synchronized across an MCT cluster.

  • LACP on the Cluster Client Edge Port (CCEP).
  • VRRP on the CCEP.
  • MRP and MRP II, with the restriction that the ICL port cannot be the secondary port of the MRP ring.
  • Flooding features (such as VLAN CPU protection and multicast flooding) on MCT VLANs.
  • Unidirectional Link Detection (UDLD) as independent boxes (configured independently).
  • ARP as independent boxes (configured independently).
  • STP and RSTP.
  • Ingress ACLs on all MCT ports, except for ICL ports. Egress ACLs are supported only on MCT Cluster Edge Ports (CEPs).
  • QoS and MAC ACLs and profiles with the same configuration on both cluster devices.
  • IPv4 ACLs and rate limits. If the rules are applied on the CCEPs, the same rules must be applied to the CCEP ports on both cluster devices.
  • Layer 3 routing. VE with IP address assignment is supported on CCEPs for VRRP.
  • Static multiport MAC.
  • Multiport authentication and IEEE 802.1X on CEPs.
  • Static MAC address configuration. Static MAC addresses are programmed on both local and remote peers as static entries.
  • DAI and DHCP snooping for clients connected through CEPs. They must be configured independently on both cluster devices.
    • If the trusted ports are off the CCEP, the arp inspection trust or dhcp snoop trust command must be used on the CCEPs and ICL ports.
    • DHCP and ARP entries are created on both MCT cluster devices if the flow traverses both the CCEP and ICL.
  • Hitless failover. If the failover operation is performed with a cluster configuration, the TCP session is re-established. The MAC addresses from the cluster peer devices are revalidated and programmed accordingly.
  • Hitless upgrade. If the upgrade operation is performed with a cluster configuration, the TCP session is re-established. The MAC addresses from the cluster peer devices are revalidated and programmed accordingly. Hitless upgrades are only supported between minor (letter, patch) releases, for example, FastIron 08.0.70a to 08.0.70b. Hitless upgrades between major releases, for example, FastIron 08.0.70 to 08.0.80, are not supported.

Features Not Supported with MCT

  • ACLs on VLAN session (ICL) ports.
  • LACP on ICL.
  • MSTP, VSRP, and RIP.
  • MSDP, Anycast RP, and embedded RP.
  • IPv6, VRRP-E (IPv6), and VRRPv3.
  • GRE on the ICL VE interfaces.
  • DAI on the CCEPs.
  • Host security features (port MAC security, multiport authentication, IEEE 802.1X, DAI, DHCP snooping) on CCEPs.
  • Multiport ARP on ICL or CCEPs.
  • Port MAC security is not supported on CEPs. However, the ICX devices do not restrict the port MAC security commands to be enabled on the CEPs.
  • Web authentication on MCT VLANs.