|
Supported security protocols and services are not affected during a switchover or
failover, with the following exceptions:
- IPsec, when enabled on an ICX 7450 stack, does not support hitless stacking because
IPsec sessions must be re-established by device firmware. Stacking split, merge, and
member reload follow normal stacking behaviors.
- Media Access Control Security (MACsec), 802.1ae,
when configured on a stack, does not support hitless stacking
because MACsec sessions must be re-established by device
firmware.
- 802.1X is affected if re-authentication does not occur in a specific time window.
- MAC authentication is affected if re-authentication does not occur in a variable-length
time window.
- In some cases, a few IP source guard packets may be permitted or dropped.
- If 802.1X and MAC authentication are enabled together on the same port, both will
be affected during a switchover or failover. Hitless stacking support for these features
applies to ports with 802.1X only or multi-device port authentication only.
- For MAC port security, secure MAC addresses are synchronized between the active and
standby controllers, so they are hitless. However, denied MAC addresses are lost during
a switchover or failover but may be relearned if traffic is present.
Configured ACLs will operate in a hitless manner. That is, the system will continue
to permit and deny traffic during the switchover or failover process. However, dynamic
ACLs are not supported for hitless switchover and failover.
After a switchover or failover, the new active controller will re-authenticate 802.1X
or MAC authentication sessions that were being forwarded in hardware.
|