Configuration Guide

Table Of Contents
©2021 Extreme Networks, Inc. All rights reserved
October 2021
76
Fabric Attach Discovery and Signaling
TLV Type
[127]
TLV
Length
[50
octets]
Extreme
OUI [00-
04-0D]
Subtype
[11]
HMAC-
SHA
Digest
Element
Type
State Mgmt
VLAN
Rsvd System
ID
7 bits 9 bits 3 octets 1 octet 32 octets 6 bits 6 bits 12 bits 1 octet 10 octets
IEEE 802.1AB Logical Link Discovery Protocol (LLDP) is exchanged between Fabric Attach Client, Proxy,
and Server components as part of an FA solution. The FA Client or Proxy will send LLDP PDUs to the FA
Server switch, i.e. a Discovery Element TLV is used as the initial handshake between FA Server and FA
Proxy or FA Client. LLDP is used to relay the I-SID and VLAN Mapping to the FA Server to allow the FA
Server to create a Switched UNI ELAN.
The LLDP PDUs are received per port or all ports in an MLT where FA has been enabled. The LLDP Type
field will indicate whether the FA element is a FA Client or FA Proxy. The Management VLAN is the value
advertised by the FA Client and FA Proxy in the Discovery TLV. If the Management VLAN is configured on
the FA Server, this will in return be relayed to the FA Proxy where it will automatically create the
management VLAN and use DHCP to get an IP address. LLDP message authentication is enabled by
default and uses a default 32 bit Extreme key. Please note that FA authentication is only available with the
Secure Image if the Proxy switch is an ERS 4800 switch; the ERS 4800 supports both a secure and a non-
secure image where only the secure image supports FA authentication. Please note FA message
authentication can be disabled and the authentication key can also be changed if you do not wish to use
the default Extreme 32 bit key.
FA Client is enabled on the WLAN 9100, FA Proxy is enabled on the ERS 4800 and ERS 5900,
and FA Server is enabled on the VSP 4000/7200/8000 by default. FA is also enabled on all ports
on the WLAN 9100, ERS 4800, and ERS 5900. FA needs to be enabled on a port or MLT
level on the VSP 4000/7200/8000.
FA Auto Attach / Zero Touch
On an FA Server, an FA port can be configured with the management VLAN using an I-SID and VLAN ID
value (c-vid). The c-vid is optional and if not specified, then the management traffic will be untagged. The
I-SID is mandatory and is required for a network wide L2VSN. The FA server will announce this information
in FA LLDP messages where only the management VLAN ID is announced as the ISID is not required. For
untagged management, a VLAN ID of 4095 is announced.
On the FA Proxy, upon receiving the FA Message via LLDP, will create the corresponding management
VLAN, set the uplink port to TagAll, add the management VLAN to the uplink port, and set QoS of trusted
on the uplink port. It will also use DHCP to get an IP address if one has not already been configured – this
is assuming a platform VLAN has been provisioned on the FA server with DHCP relay enabled. If you do
not wish to use DHCP, this can be disabled by removing the default zero touch option ip-addr-dhcp on the
FA Proxy switch.