Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Cisco: NSP

glbp migration to hsrp anycast

 

 

Cisco nsp RSS feed   Index | Next | Previous | View Threaded


arla at rn

Jun 11, 2012, 9:55 AM

Post #1 of 3 (377 views)
Permalink
glbp migration to hsrp anycast

Hi all

Can someone help me out here.
If we want to migrate from glbp to hsrp anycast in the future, can that be done with out any downtime.
Will all servers update their arp table, if the hsrp function propagates gratious arp.

/Arne

_______________________________________________
cisco-nsp mailing list cisco-nsp [at] puck
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


p.mayers at imperial

Jun 12, 2012, 12:56 AM

Post #2 of 3 (358 views)
Permalink
Re: glbp migration to hsrp anycast [In reply to]

On 06/11/2012 05:55 PM, Arne Larsen / Region Nordjylland wrote:
> Hi all
>
> Can someone help me out here.
> If we want to migrate from glbp to hsrp anycast in the future, can that be done with out any downtime.

Not zero. You can do it with very little downtime though. Bear in mind
that, when you configure HSRP, HSRP will transition between the
LISTEN/SPEAK states before going active.

When making changes like this (e.g. moving from HSRPv1 to HSRPv2 to gain
IPv6 support) we normally do the following:

1. Shutdown the interface on the secondary, to avoid confusion
2. Turn the HSRP timers down to very (unreasonably) aggressive
settings, e.g. "standby X timers msec 50 msec 100"
3. Config/reconfigure HSRP; fast timers mean it takes over rapidly
4. Re-set the timers to something more reasonable
5. Configure the standby, then enable its interface

For your case, I would imagine you'll need to prepare a blob of config
that disables GLBP, sets HSRP timers to ultra-aggressive and then
enables HSRP, and paste it all in at once.

> Will all servers update their arp table, if the hsrp function propagates gratious arp.

I've never seen this fail except on REALLY REALLY old things; Solaris
2.6 had a problem, IIRC.
_______________________________________________
cisco-nsp mailing list cisco-nsp [at] puck
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


nsp-list at pollok

Jun 12, 2012, 1:08 AM

Post #3 of 3 (354 views)
Permalink
Re: glbp migration to hsrp anycast [In reply to]

Gents and Ladies,

[...]

>> Will all servers update their arp table, if the hsrp function propagates
>> gratious arp.
>
> I've never seen this fail except on REALLY REALLY old things; Solaris 2.6 had
> a problem, IIRC.

We saw firewalls of customers not accepting ARP-Replies when no ARP
whohas was sent before. We debugged ARP and found out that it refreshes
its ARP-table every 30 minutes so we waited 2 seconds before end of the
30-minutes interval and made the switch so the new MAC was there once
the firewall expired its ARP cache.

Very annoying security feature ;-)

-Sascha

_______________________________________________
cisco-nsp mailing list cisco-nsp [at] puck
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Cisco nsp RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.