Infoblox’s global team of threat hunters uncovers a DNS operation with the ability to bypass traditional security measures and control the Great Firewall of China. Read about “Muddling Meerkat” and the many other threat actors discovered by Infoblox Threat Intel here.

Getting Started

Reply

HA pair on multipod ACI problem, multicast keepalives HA pair in different pods

[ Edited ]
Authority
Posts: 14
1006     0

With a physical HA pair with each node in a different ACI pod (Multipod setup)

During reboot of one of the IPN nodes and the heartbeats of the HA infoblox units is going over that IPN node in the ACI fabric, the passive node will resart it's nics (HA interface and the lan interface) this will take about 3 minutes.The active node keeps functioning without any issues and the clients using DNS/DHCP didn't notice this

We noticed this during troubleshooting of an A10 AVCS, vrrp-a cluster. When also one of the IPN nodes was rebooted both A10 nodes became active and this disrupted the traffic flow.

This was solved by setting HA keepalives to unicast instead of the default multicast mode.

It looks like devices using only multicast for heartbeats can have issues if there is a disruption.

on the interpod network of an ACI multipod fabric.

Maybe encrypted VPN tunnel between HA pairs can be used for extra keepalive check ?

Re: HA pair on multipod ACI problem, multicast keepalives HA pair in different pods

[ Edited ]
Techie
Posts: 2
1006     0

Hi, thanks for sharing this information that's good to know.

 

Mini Militia App Lock

Re: HA pair on multipod ACI problem, multicast keepalives HA pair in different pods

New Member
Posts: 1
1006     0

Hi IvandenOuden,

 

thanks for your post.

How did you solve this issue with Infoblox? How did switch the Infoblox HA-pair to VRRP unicast?

 

Kind regards,

frenne

Re: HA pair on multipod ACI problem, multicast keepalives HA pair in different pods

Authority
Posts: 14
1006     0

That is a long time ago :-).

I believe it solved itself with a higher NIOS version or with ACI 4.2.x and higher.

At another client were running NIOS 8.6.2.x and before that 8.5.x i believe and i have never seen it their. Also ACI version i already at 4.2.x and we  i did some upgrades from 4.2(3) to 4.2(7) ans also ipn nodes have been upgraded and i have not seen the behavoir since. So i think it was solved or in ACI 4.2.x and higher or in NIOS 8.5.x and higher.

Showing results for 
Search instead for 
Did you mean: 

Recommended for You