Installation Guide
Table Of Contents
- Extreme Routing MLX Series Hardware Installation Guide
- Preface
- About This Document
- Product Overview
- ExtremeRouting MLX Series device overview
- MLX Series router applications
- Hardware features
- MLX Series router modules
- Management modules
- Interface modules
- 2x100GbE CFP2 optics based high density module
- PBIF Recovery
- 2x100GbE CFP2 P2010 specifications
- 2x100GbE CFP2 DDR3 SDRAM memory specifications
- BR-MLX-10GX20-X2 and BR-MLX-100GX2-CFP2-X2 Router Software
- BR-MLX-10GX20-X2 and BR-MLX-100GX2-CFP2-X2 scalability for IPv4 and IPv6 routes
- MLX Series 2x100G XPP ILKN monitoring
- MLX Series CPU threshold monitoring
- MLX Series BR-MLX-10Gx4-M IPsec and IKEv2
- MLX Series Encryption and Decryption of IPv4 Unicast Data and Control Packets
- MLX Series IKEv2 Authentication
- MLX Series IPsec and IKEv2 configuration
- MLX Series Configuring Global IKEv2 Options
- MLX Series Configuring the IKEv2 Proposal
- MLX Series Configuring the IKEv2 Policy
- MLX Series Configuring the IKEv2 Profile
- MLX Series Configuring the IKEv2 authentication proposal
- MLX Series Configuring the IPsec Proposal
- MLX Series Configuring the IPsec Profile
- MLX Series IKEv2 Show Commands
- MLX Series IKEv2 Clear Commands
- MLX-10GX4-IPSEC-M Forwarding
- MLX Series 2x100G XPP ILKN monitoring
- 10Gx24-port interface module
- MLX 24-port 10Gbps (BR-MLX-10Gx24-DM) Interface Modules
- 8x10GE-X interface modules
- Gen-1 10Gx2 and 10Gx4 Ethernet interface modules
- BR-MLX-10GX4-X and BR-MLX-10Gx4-X-ML interface module LEDs
- Gen-1.1 4-port 10 Gbps Ethernet interface modules
- 8-port 10 Gbps M and D interface modules
- 24-port 1 Gbps Ethernet copper RJ-45 interface module
- 24-port 1 Gbps fiber interface module
- 20-port 100/1000 Ethernet interface module
- 20-port 10/100/1000 Ethernet interface module
- NI-MLX-1Gx48-T-A interface module
- BR-MLX-40Gx4-M 4-port 40GbE module
- Auto-tuning links
- Forward Error Correction mode
- Switch fabric modules
- High-speed switch fabric modules
- CFP2 to QSFP28 conversion module
- Power supplies
- Rack mounting brackets
- Cooling system for MLX Series routers
- NIBI-16-FAN-EXH-A high-speed fan assemblies
- Rack mount kit
- Supported software features
- Installing an ExtremeRouting MLX Series device
- Pre-Installation notice for the ExtremeRouting MLX chassis bundles
- Installation precautions
- Installing 2x100GbE CFP2 interface modules
- Installing BR-MLX-10Gx24-DM interface modules
- Installing an MLXe-4 router
- Installing an MLX-8 router
- Installing an MLXe-16 router
- Mounting the MLX-4, MLX-8 or MLX-16 router in a 4-post rack or EIA rack
- Installing an MLXe-32 router
- Preparing the installation site
- MLXe-32 router shipping carton contents
- Unpacking your MLXe-32 router
- Installing an MLXe-32 router in an EIA rack
- Installing modules in the MLXe-32 router
- MLXe-32 router cable management
- Accessing modules for service
- Installing power supplies in an MLXe-32 router
- Connecting AC power
- Connecting DC power
- Removing the MLXe-32 router DC power supplies
- Final steps
- Attaching a management station
- Activating the power source
- Verifying proper operation
- Using Extreme Structured Cabling Components
- Cable cinch overview
- mRJ21 procedures
- RJ-45 procedures
- Cable cinch with one group of RJ-45 cables
- Cable cinch with two groups of RJ-45 cables
- Cable cinch with three groups of RJ-45 cables
- Cable cinch with four groups of RJ-45 cables
- Cable cinch with five groups of RJ-45 cables
- Cable cinch with six groups of RJ-45 cables
- Cable cinch with seven groups of RJ-45 cables
- Cable cinch with eight groups of RJ-45 cables
- Connecting a Router to a Network Device
- Managing Routers and Modules
- Managing the device
- Disabling and re-enabling power to interface modules
- Monitoring I2C failures on management modules
- Displaying device status and temperature readings
- Displaying the Syslog configuration and static and dynamic buffers
- Router Headless State by MP Presence from LP
- Rolling Reboot
- Line Module Configuration Deletion in Interactive Boot Mode
- Managing switch fabric modules
- Managing the cooling system
- Managing interface modules
- Configuring interface module boot parameters
- Synchronizing the software image between management modules and interface modules
- Changing the boot source
- Specifying an immediate boot
- Specifying an immediate boot from the auxiliary flash slots on the management module
- Specifying an immediate boot from management module flash memory
- Specifying an immediate boot from flash memory on the interface module
- Specifying an immediate boot from a TFTP server
- Specifying an immediate interactive boot
- Configuring an automatic boot
- Configuring an automatic boot from the auxiliary flash slot on the management module
- Configuring an automatic boot from flash memory on the management module
- Configuring an automatic boot from flash memory on the interface module
- Configuring an automatic boot from a TFTP server
- Configuring an automatic interactive boot
- Changing priority of slots for interface modules
- Disabling and re-enabling power to interface modules
- Configuring interface module boot parameters
- Monitoring Link Status
- Traffic Manager XPP link monitoring
- Using alarms to collect and monitor device status
- Displaying MR2 management module memory usage
- Enabling and disabling management module CPU usage calculations
- Displaying management module CPU usage
- Removing MAC address entries
- IPv6 ND Proxy
- DRBG Health Test on IPsec LP
- Managing the device
- Maintenance and Field Replacement
- Maintenance and field replacement overview
- Hardware maintenance schedule
- Replacing a management module
- Replacing an interface module
- Replacing a switch fabric module
- Replacing a fiber-optic transceiver
- Replacing a power supply
- Replacing fan assemblies
- Hardware Specifications
- ExtremeRouting MLX Series Chassis Bundles
- Regulatory Statements
- Caution and Danger Notices
IKEv2 Option Description
• aes-cbc-256
NOTE
For the rst release, only aes-cbc-128 and aes-cbc-256 will be supported. Support for other
encryption for IKEv2 will be considered for inclusion in the next major release.
integrity {sha1} {sha256}
{sha384} {sha512}
Integrity algorithm to be used to protect IKEv2 data. Multiple algorithms may be specied. The following are
supported:
• sha1 — species SHA-1 (HMAC variant) as the hash algorithm.
• sha256 — species SHA-2 family 256-bit (HMAC variant) as the hash algorithm.
• sha384 — species SHA-2 family 384-bit (HMAC variant) as the hash algorithm.
• sha512 — species SHA-2 family 512-bit (HMAC variant) as the hash algorithm.
NOTE
For the rst release, only sha256 and sha384 will be supported. Support for other crypto for IKEv2
will be considered for inclusion in the next major release.
MLX Series Conguring the IKEv2 Policy
After you create the IKEv2 proposal, the proposal must be attached to a policy to pick the proposal for negotiation.
The IKE policy states which security parameters will be used to protect IKE negotiations. An IKEv2 policy must contain at least one
proposal to be considered as complete. It can have local-address and VRF statements which are used as selection criteria to select a
policy for negotiation. During the initial exchange, the local address and the VRF of the negotiating SA are matched with the policy and
the proposal is selected.
There will be a default IKEv2 policy named ikev2-default-policy and it will have the following parameters:
• Proposal: ikev2-default-proposal
• local_address: not set, match all local addresses
• VRF: not set so will match any-vrf
If no suitable IKE policy is found, the IKE session will be established using the ikev2-default-policy.
For a given local ip-address only one policy can be chosen.
Conguration of overlapping policies is considered a misconguration. In the case of multiple, possible policy matches, the rst policy is
selected.
IKEv2 Option Description
ikev2 policy <name> Congure IKE policy parameters, enter ikev2 policy conguration mode.
Proposal <name> Specify at least one proposal; optionally, you can specify additional proposals. This is only for IKE SA.
match address-local <ipaddress>
<mask>
(Optional) Matches the policy based on the local IPv4. If not congured, it will match all the local IPv4 addresses.
match fvrf { vrf-name <name> |
any }
(Optional) The FVRF in which the local IP address on the IKEv2 packet should be matched. If not congured, it will
match the any-vrf.
MLX Series router modules
Extreme Routing MLX Series Hardware Installation Guide
48 9035627-01