LINUXOR.SK ... open source notes ...

Balabit - Switch ports (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Hardware, cabling and networks

The configuration of the network switch ports that the two site 1 appliances are cabled to, one table per datacenter, as my design document records it "as is configured": switch, model, port, VLAN and port mode for the IPMI port, ports 1 to 4 of the appliance and the serial console.

ItemValue
SourceMy design document, version 0.5 of 2017-12-01 (draft), chapters 5.1.4 and 5.1.5
SwitchesDC1-x-SOOB003 (Catalyst 2960-X, out-of-band), DC1-x-SPRO001 and DC1-x-SPRO002 (Nexus 9396PX), DC1-x-ROOB002 (Cisco 2901, serial console)
Not in itThe switch configuration itself (no show running-config), the allowed-VLAN lists of the trunks beyond the VLANs named, the SFP+ ports 5 and 6 (not cabled)

The listing

output 17 lines
### Configuration of ports on network switches – datacenter A
| Switch | Model | Port | VLAN | Port mode |
| DC1-A-SOOB003 | Catalyst 2960-x | Gi1/0/16 | 12 | ACCESS |
| DC1-A-SPRO001 | Nexus 9396PX | Eth 1/5 | 1010 | TRUNK |
| DC1-A-SPRO002 | Nexus 9396PX | Eth 1/5 | 1009 | TRUNK |
| DC1-A-SPRO001 | Nexus 9396PX | Eth 1/21 | 1018, 1020 | TRUNK, NATIVE VLAN=1018 |
| DC1-A-SPRO002 | Nexus 9396PX | Eth 1/21 | 1016 | ACCESS |
| DC1-A-ROOB002 | Cisco 2901 | Async port 19  / (patchpanel 20) | N/A | N/A |

### Configuration of ports on network switches – datacenter B
| Switch | Model | Port | VLAN | Port mode |
| DC1-B-SOOB003 | Catalyst 2960-x | Gi1/0/16 | 12 | ACCESS |
| DC1-B-SPRO001 | Nexus 9396PX | Eth 1/5 | 1010 | TRUNK |
| DC1-B-SPRO002 | Nexus 9396PX | Eth 1/5 | 1009 | TRUNK |
| DC1-B-SPRO001 | Nexus 9396PX | Eth 1/21 | 1018, 1020 | TRUNK, NATIVE VLAN=1018 |
| DC1-B-SPRO002 | Nexus 9396PX | Eth 1/21 | 1016 | ACCESS |
| DC1-B-ROOB002 | Cisco 2901 | Async port 19  / (patchpanel 20) | N/A | N/A |

The rows do not say which appliance port is on which switch port; the cabling pictures and the L1 sheet do. Joined, the rows read like this:

Switch portAppliance portNetwork
SOOB003 Gi1/0/16, access VLAN 12IPMIOut-of-band management, 10.11.15.0/24 (A) or 10.11.23.0/24 (B)
SPRO001 Eth 1/5, trunk VLAN 10101, EXT (eth0)IBM, in-band management, 10.11.16.80/29
SPRO002 Eth 1/5, trunk VLAN 10092, MGMT (eth1)PRO, production, 10.11.16.64/29 and 2001:db8:a1:c0e::/64
SPRO001 Eth 1/21, trunk VLANs 1018 and 1020, native 10183, INT (eth2)CLS2, redundant heartbeat 10.11.18.208/28, and BCK, backup and archive 10.11.18.224/28
SPRO002 Eth 1/21, access VLAN 10164, HA (eth3)CLS1, the primary HA link 1.2.4.0/24
ROOB002 async port 19, patch panel 20Serial consolenone; the 2901 router serves as a console server, as I read the row

Three things to notice. The ports of each appliance are spread over the two Nexus switches of its datacenter, ports 1 and 3 on SPRO001, ports 2 and 4 on SPRO002, which, as I read it, means one switch failure does not cut both the management and the production side. The HA link is not a cable between the appliances but an access port in VLAN 1016 on each side, which has to reach the other datacenter through the network. And port 3 is a trunk whose native VLAN is 1018, while the SCB sends VLAN 1018 tagged (eth2.1018); as I understand Nexus trunks, the switch sends frames of the native VLAN untagged, which the tagged interface on the appliance would not receive. The material does not show whether the redundant heartbeat ever worked over this port.

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
HA port 4 on an access port in VLAN 1016, through the network to the other datacenterThe SPS 9.0 guide: "One Identity recommends a direct physical connection between the nodes"
IPMI on an access port of the out-of-band switchThe vendor recommends connecting the IPMI only to well-protected, separated management networks with restricted accessibility; IPMI supports only 100 Mbps full duplex
No bonding: one port per role, spread over two switchesNo bonding, teaming or link aggregation is documented in SPS 9.0 either

The nodes stood in two datacenters and the design took the HA link through the switches; it does not say whether a direct cable was considered. The recommendation is worth knowing when the nodes stand closer together.

← solutionz