Balabit - Switch ports (site 1)
Balabit SCB Solution · Config document · referenced from Hardware, cabling and networks
The configuration of the network switch ports that the two site 1 appliances are cabled to, one table per datacenter, as my design document records it "as is configured": switch, model, port, VLAN and port mode for the IPMI port, ports 1 to 4 of the appliance and the serial console.
| Item | Value |
|---|---|
| Source | My design document, version 0.5 of 2017-12-01 (draft), chapters 5.1.4 and 5.1.5 |
| Switches | DC1-x-SOOB003 (Catalyst 2960-X, out-of-band), DC1-x-SPRO001 and DC1-x-SPRO002 (Nexus 9396PX), DC1-x-ROOB002 (Cisco 2901, serial console) |
| Not in it | The switch configuration itself (no show running-config), the allowed-VLAN lists of the trunks beyond the VLANs named, the SFP+ ports 5 and 6 (not cabled) |
The listing
output 17 lines
### Configuration of ports on network switches – datacenter A | Switch | Model | Port | VLAN | Port mode | | DC1-A-SOOB003 | Catalyst 2960-x | Gi1/0/16 | 12 | ACCESS | | DC1-A-SPRO001 | Nexus 9396PX | Eth 1/5 | 1010 | TRUNK | | DC1-A-SPRO002 | Nexus 9396PX | Eth 1/5 | 1009 | TRUNK | | DC1-A-SPRO001 | Nexus 9396PX | Eth 1/21 | 1018, 1020 | TRUNK, NATIVE VLAN=1018 | | DC1-A-SPRO002 | Nexus 9396PX | Eth 1/21 | 1016 | ACCESS | | DC1-A-ROOB002 | Cisco 2901 | Async port 19 / (patchpanel 20) | N/A | N/A | ### Configuration of ports on network switches – datacenter B | Switch | Model | Port | VLAN | Port mode | | DC1-B-SOOB003 | Catalyst 2960-x | Gi1/0/16 | 12 | ACCESS | | DC1-B-SPRO001 | Nexus 9396PX | Eth 1/5 | 1010 | TRUNK | | DC1-B-SPRO002 | Nexus 9396PX | Eth 1/5 | 1009 | TRUNK | | DC1-B-SPRO001 | Nexus 9396PX | Eth 1/21 | 1018, 1020 | TRUNK, NATIVE VLAN=1018 | | DC1-B-SPRO002 | Nexus 9396PX | Eth 1/21 | 1016 | ACCESS | | DC1-B-ROOB002 | Cisco 2901 | Async port 19 / (patchpanel 20) | N/A | N/A |
The rows do not say which appliance port is on which switch port; the cabling pictures and the L1 sheet do. Joined, the rows read like this:
| Switch port | Appliance port | Network |
|---|---|---|
SOOB003 Gi1/0/16, access VLAN 12 | IPMI | Out-of-band management, 10.11.15.0/24 (A) or 10.11.23.0/24 (B) |
SPRO001 Eth 1/5, trunk VLAN 1010 | 1, EXT (eth0) | IBM, in-band management, 10.11.16.80/29 |
SPRO002 Eth 1/5, trunk VLAN 1009 | 2, MGMT (eth1) | PRO, production, 10.11.16.64/29 and 2001:db8:a1:c0e::/64 |
SPRO001 Eth 1/21, trunk VLANs 1018 and 1020, native 1018 | 3, INT (eth2) | CLS2, redundant heartbeat 10.11.18.208/28, and BCK, backup and archive 10.11.18.224/28 |
SPRO002 Eth 1/21, access VLAN 1016 | 4, HA (eth3) | CLS1, the primary HA link 1.2.4.0/24 |
ROOB002 async port 19, patch panel 20 | Serial console | none; the 2901 router serves as a console server, as I read the row |
Three things to notice. The ports of each appliance are spread over the two Nexus switches of its datacenter, ports 1 and 3 on SPRO001, ports 2 and 4 on SPRO002, which, as I read it, means one switch failure does not cut both the management and the production side. The HA link is not a cable between the appliances but an access port in VLAN 1016 on each side, which has to reach the other datacenter through the network. And port 3 is a trunk whose native VLAN is 1018, while the SCB sends VLAN 1018 tagged (eth2.1018); as I understand Nexus trunks, the switch sends frames of the native VLAN untagged, which the tagged interface on the appliance would not receive. The material does not show whether the redundant heartbeat ever worked over this port.
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
| HA port 4 on an access port in VLAN 1016, through the network to the other datacenter | The SPS 9.0 guide: "One Identity recommends a direct physical connection between the nodes" |
| IPMI on an access port of the out-of-band switch | The vendor recommends connecting the IPMI only to well-protected, separated management networks with restricted accessibility; IPMI supports only 100 Mbps full duplex |
| No bonding: one port per role, spread over two switches | No bonding, teaming or link aggregation is documented in SPS 9.0 either |
The nodes stood in two datacenters and the design took the HA link through the switches; it does not say whether a direct cable was considered. The recommendation is worth knowing when the nodes stand closer together.