Enterprise Switching Architectures and Best Practices Webinar March 07

Plan to attend the Enterprise Switching Architectures and Best Practices Webinar on March 07 at Noon Central time.

Learn about enterprise network switch features and benefits, and what to look for when selecting products. Understand enterprise network architectures with specific examples in education, hospitality and multi-dwelling units. Learn best practices to optimize performance and user satisfaction. John Mead, Senior Director of Engineering, Cambium Networks shares his experience and responds to your questions.

REGISTER HERE

Hi Ray,

Will this be something offered to other regions - APAC for example?

1 Like

Hi Brook, This webinar will also be recorded and posted to the Community for replaying. We may do one at a time more convenient for APAC in the future.

In the mean time, Please post any questions that you have to this thread and I will be glad to present them at the webinar.

Thanks

Ray

Hi Brook, This webinar will also be recorded and posted to the Community for replaying. We may do one at a time more convenient for APAC in the future.

In the mean time, Please post any questions that you have to this thread and I will be glad to present them at the webinar.

Thanks

Ray

QUESTIONS:

1. I didn't see stacking port behind the switch.
will it support stacking through SFP

2. I need comparison guide between cnMatrix and switch from Aruba Ruckus Cisco Juniper

3. any doc for connecting cnMatrix with existing switch Aruba Ruckus Cisco Juniper
4. policy based automation doc
5. can I use cnMatrix with on-premise cnMaestro?
and can I set cnMaestro can only being managed from my pc ip
6. does it support dual flash firmware like Aruba and Juniper switch, so that I can test upgrade using primary flash first. if is not ok then I can swith to old fw by just rebooting

7. because sfp and the cable are expensive. Can I use twinax copper instead
if yes, what brand has been tested

8. in CLI. can I show portion of config i.e in Mikrotik
/export = full config

/interface export = interface config only

9. in CLI can I do pipe i.e in Cisco

# sh run | b Port-channel

10. do you plan to release cnMatrix OS for GNS3 or Eve-NG.

Like Aruba, Cisco, Ruckus, Juniper, Mikrotik did.

So that I don't have to buy physical hardware in order for me to make me familiar with GUI and CLI.

Or test it in simulation first before implemented on field

tq

1 Like

thank you - we will ask these in the webinar.

  1. I didn't see stacking port behind the switch.
    will it support stacking through SFP

Stacking is currently not supported in SW version 2.0.4-r1 (our latest as of 2-26-2019).   The HW is cable of supporting stacking and any ports can be used, but would recommend 2 of the 4 SFP+ ports on the EX2028/EX2028-P. We currently do not have firm plans to add stacking support. However, let me elaborate. There’s true stacking(as discussed above) that provides a single data plane, control plane and management plane across all the switches in a stack. There’s also virtual stacking that provides a single management plane, but not a data plane/control plane. Virtual stacking can be very useful, and is in Cambium’s roadmap.

  1. I need comparison guide between cnMatrix and switch from Aruba Ruckus Cisco Juniper

cnMatrix is in the same class of switching as some of the switching lines from Aruba, Ruckus, Cisco, and Juniper. We all support L2, L3 and QOS/ACL/filtering based features. cnMatrix does stand out with our cloud based management using cnMaestro, our Policy Based automation capability, and our LLW (5 year) warranty. Also, some of the switches from the other vendors only have 1 G SFP uplinks or require a license fee to enable the full 10G of an SFP+. The EX2028 has 4 10G SFP+ ports that are included in the base price of the switch. For a switch with 24 gig ports, having 1 Gbps uplinks is not sufficient in most deployment scenarios. One more major benefit that stands out with cnMatrix is the comprehensive solution that Cambium now offers with the other Cambium devices. This allows us to provide more advanced functionality.

  1. any doc for connecting cnMatrix with existing switch Aruba Ruckus Cisco Juniper

There is no specific documentation for connecting our switches with other industry switches. We support all standards based connectivity so there should be no problems here.

  1. policy based automation doc

For the PBA documentation please see the cnMatrix user guide on our support site. We will be coming out with additional white papers on this topic.

  1. can I use cnMatrix with on-premise cnMaestro?
    and can I set cnMaestro can only being managed from my pc ip

Yes, cnMatrix will work with both cloud and on-premise cnMaestro.   Not sure about your question on IP address.

  1. does it support dual flash firmware like Aruba and Juniper switch, so that I can test upgrade using primary flash first. if is not ok then I can swith to old fw by just rebooting

We do support dual images in Flash for fail safe image corruption, however we currently don’t expose this to the user.   This is a possible roadmap item to provide dual boot capability.

  1. because sfp and the cable are expensive. Can I use twinax copper instead
    if yes, what brand has been tested

Yes, we do support DAC (twinax).   We support all known vendors such as, Amphenol, TE, Leoni.

  1. in CLI. can I show portion of config i.e in Mikrotik
    /export = full config

/interface export = interface config only

Yes, we can show partial config. Ie. “show running-config vlan”

  1. in CLI can I do pipe i.e in Cisco

# sh run | b Port-channel

We don’t support pipe, but we do support grep.   Pipe is something being considered as a roadmap item.

  1. do you plan to release cnMatrix OS for GNS3 or Eve-NG.

Like Aruba, Cisco, Ruckus, Juniper, Mikrotik did.

So that I don't have to buy physical hardware in order for me to make me familiar with GUI and CLI.

Or test it in simulation first before implemented on field

No current plans.

2 Likes
  1. any doc for connecting cnMatrix with existing switch Aruba Ruckus Cisco Juniper
    There is no specific documentation for connecting our switches with other industry switches. We support all standards based connectivity so there should be no problems here.


I am proposing you a WIN-WIN Solution
I have lab with switches from
-Cisco L2 L3
-HP Procurve
-Force10
-Cisco Nexus
-Juniper
-Ruckus

I have some experiences with those switches

If Cambium Indonesia can loan me cnMatrix 10ports POE.

I can test cnMatrix with those 3rd Party and come up with cookbook like this

https://nbctcp.wordpress.com/2015/04/20/lacp/

1 Like

I want to know whether you can do these tests:

1. connect pc1 to port1 and make sure it get vlan10
move pc1 to port2 and make sure pc1 still get vlan10

connect pc2 to port1 and make sure it didn't get any vlan

2. connect pc1 to port1 and make sure it get vlan10
unplug pc1

set pc2 mac address same as pc1

connect pc2 to port1

what will happen?

tq

Thank you. I will be sure to ask these in the live webinar.

Ray

I want to know whether you can do these tests:

1. connect pc1 to port1 and make sure it get vlan10
move pc1 to port2 and make sure pc1 still get vlan10

connect pc2 to port1 and make sure it didn't get any vlan

 

Our PBA feature is perfect for this.  Currently we use any data that is contained in a LLDP TLV to detect the device.  In our next SW release we will also support MAC addresses for device detection.  Based on device detection VLAN setting is an example of dynamic configuration we support.  So, you will see the behavior you described above.  This includes PC2 on port 1, not being put on VLAN 10.  This is because when you remove PC1 from port 1 the dynamic configuration is automatically removed.

2. connect pc1 to port1 and make sure it get vlan10
unplug pc1

set pc2 mac address same as pc1

connect pc2 to port1

what will happen?

 

Using the PBA feature we will follow the MAC address.  So, port 1 will become a member of VLAN 10 after PC2 is connected.  However, if you combine the MAC detection mechanism with LLDP(if supported on PC) detection, then both have to be met and port one will not become a member for VLAN 10.

1. PBA+LLDP

Using the PBA feature we will follow the MAC address.  So, port 1 will become a member of VLAN 10 after PC2 is connected.  However, if you combine the MAC detection mechanism with LLDP(if supported on PC) detection, then both have to be met and port one will not become a member for VLAN 10.

I think is more difficult to force user to enable LLDP on their NIC because maybe I need these method to enable LLDP

LINUX:
https://community.mellanox.com/s/article/howto-enable-lldp-on-linux-servers-for-link-discovery
 
MAC:
 
MICROSOFT:
https://community.mellanox.com/s/article/howto-enable-lldp-on-windows-servers---ldwin
 
I have alternative option that I haven't tried myself
https://networkguy.de/?p=1649
 
In that link he create 2 policies
1. Computer account policy
2. Username, Password, MAC address policy
MAC policy is failback of Computer policy.
Usefull for printer, ipcam, iptv etc
 
So if let say someone spoof my MAC address, he/she still can't connect without knowing my username and password

2. I want to ask how you add user information such as username, password, mac address, etc

Where to add those info. Is it in cnMeastro
 
tq
1 Like

Thanks - I will be sure to present these to the speakers.

Ray

Just checking if there is a mistake in specification sheet on page 2:


Specification is available under "Spec sheet" on the bottom of the page. On the other hand, using link on the top of the page we get old spec sheet from december 2018:

https://www.cambiumnetworks.com/products/switching/cnmatrix-ex2028-p/

https://3fdumf3rqw5xx4mjgywguwz9-wpengine.netdna-ssl.com/wp-content/uploads/2018/11/SS_cnMatrix_02282019.pdf


Kind regards

1. I also didn't see routing protocols in the datasheet.

Is this real L3 switch?

This is example of Cisco switch
Cat3550#show ip route
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route

2. Can I use USB port for save backup config to flash disk or
restore firmware from flash disk

tq

1 Like

Great catch!  Yes, this is a mistake.  We'll have this updated soon.

John

You are correct, we should add more details in our specification sheet.  Here are the L3 details:

Static Routes - 64

Intevlan routing - Yes

Dynamic routing (RIP, OSPF) - Yes* (2.1 release in mid summer)(512 routes)

DHCP Relay - Yes

2. Can I use USB port for save backup config to flash disk or
restore firmware from flash disk

The USB port is not supported in 2.0.  Both features that you've mentioned will be supported in the upcoming 2.1 release, mid summer.

John

Some really good questions!

For authenticating the user, I would suggest using 802.1x.  You can combine this with PBA, so that it will now check for user name and password with 802.1x, and then PBA can automate the specific configuration based on the MAC.

Note:

Current release supports PBA via LLDP.

our 2.1 release will add MAC authentication to PBA in addition to LLDP.  We can authentication based on specific MAC addresses, a range of addresses, or OUI.

John

I'd like to respond with a more comprehensive list of our L3 features:

 

Static Routes - 64

DHCP Relay - Yes

Intevlan routing - Yes

Dynamic routing (RIP, OSPF) - Yes* (2.1 release, mid summer)(512 routes)

Route redistribution* (2.1 release, mid summer)

Route Map* (Roadmap item)

 

John