Supported Hitless Stacking Protocols and Services

The following table highlights the impact of a hitless switchover or failover on the major functions of the system.

Note: Services and protocols that are not listed in the following table encounter disruptions, but resume normal operation once the new active controller is back up and running.

Supported Hitless Stacking Protocols and Services

Traffic Type

Supported Protocols and Services

Impact

Layer 2 switched traffic, including

unicast and multicast

+

System-level

+

Layer 4

  • 802.1p and 802.1Q
  • 802.3ad - LACP
  • 802.3af - PoE
  • 802.3at - PoE+
  • DSCP honoring and Diffserv
  • Dual-mode VLAN
  • IGMP v1, v2, and v3 snooping
  • Layer 2 switching (VLAN and 802.1Q-in-Q)
  • MLD v1 and v2 snooping
  • MRP
  • Multiple Spanning Tree (MSTP)
  • Physical port/link state
  • PIM SM snooping
  • Port mirroring and monitoring
  • Port trunking
  • Rapid Spanning Tree (RSTP)
  • Spanning Tree (STP)
  • ToS-based QoS
  • Policy Based Routing
  • Traffic policies
  • UDLD
  • VSRP

Layer 2 switched traffic is not affected during a hitless stacking event. All existing switched traffic flows continue without interruption.

New switched flows are not learned by the switch during the switchover process and are flooded to the VLAN members in hardware. After the new active controller becomes operational, new switched flows are learned and forwarded accordingly. The Layer 2 control protocol states are not interrupted during the switchover process.

Layer 3 IPv4 routed traffic (unicast)

  • IPv4 unicast forwarding
  • Static routes
  • OSPF v2
  • OSPF v2 with ECMP
  • VRRP
  • VRRP-E
  • BGP4+

Layer 3 routed traffic for supported protocols is not affected during a hitless stacking event.

Other Layer 3 protocols that are not supported will be interrupted during the switchover or failover.

If BGP4+ graceful restart or OSPF graceful restart is enabled, traffic converges to normalcy after the new active module becomes operational. For details about OSPF graceful restart and BGP4+ graceful restart, refer to the RUCKUS FastIron Layer 3 Routing Configuration Guide.

Layer 3 IPv6 routed traffic (unicast and multicast)

  • IPv6 Unicast forwarding
  • OSPF V3
  • VRRP V3
  • VRRP-E V3
  • BGP 4+

OSPF (V2 or V3) has graceful restart enabled by default. Existing traffic flows will not be disturbed. To achieve hitless functionality, "non-stop routing" must be enabled under OSPF.

Management traffic

N/A

All existing management sessions (SNMP, Telnet, HTTP, HTTPS, FTP, TFTP, SSH, and so on) are interrupted during the switchover process. Sessions are terminated and can be re-established after the new active controller takes over.

Security

  • ACLs
  • Dos attack prevention (TCP syn/ICMP)
  • DHCP snooping
  • Dynamic ARP inspection
  • IP source guard
  • MAC filter
  • MAC port security

Supported security protocols and services are not affected during a switchover or failover, with the following exceptions:

  • IPsec, when enabled on an ICX 7450 stack, does not support hitless stacking because IPsec sessions must be re-established by device firmware. Stacking split, merge, and member reload follow normal stacking behaviors.
  • Media Access Control Security (MACsec), 802.1ae, when configured on a stack, does not support hitless stacking because MACsec sessions must be re-established by device firmware.
  • 802.1X is affected if re-authentication does not occur in a specific time window.
  • MAC authentication is affected if re-authentication does not occur in a variable-length time window.
  • In some cases, a few IP source guard packets may be permitted or dropped.
  • If 802.1X and MAC authentication are enabled together on the same port, both will be affected during a switchover or failover. Hitless stacking support for these features applies to ports with 802.1X only or multi-device port authentication only.
  • For MAC port security, secure MAC addresses are synchronized between the active and standby controllers, so they are hitless. However, denied MAC addresses are lost during a switchover or failover but may be relearned if traffic is present.

Configured ACLs will operate in a hitless manner. That is, the system will continue to permit and deny traffic during the switchover or failover process. However, dynamic ACLs are not supported for hitless switchover and failover.

After a switchover or failover, the new active controller will re-authenticate 802.1X or MAC authentication sessions that were being forwarded in hardware.

Other services to management

  • AAA
  • DHCP
  • sFlow
  • SNMP v1, v2, and v3
  • SNMP traps
  • SNTP
  • Traceroute

Supported protocols and services are not affected during a switchover or failover.

DNS lookups will continue after a switchover or failover. This information is not synchronized.

Ping traffic will be minimally affected.