Mr.Ben Posted May 12 Posted May 12 I've inherited a challenge with this in my latest post - they had just replaced the 5406zl core with a single, 24 port Aruba 6300M fibre switch (all 10G). That was ok - it's powerful enough, but didn't meet the DfE requirements, so I stacked it with 3 more switches in this year's budget - all 6300s, 1 more fiber and 2 ethernet. All of our fiber runs now have 2 paths to 2 separate switches, which is great! The total cost of the core was £20k, but I am serving the whole building from the additional, unused ethernet interfaces and can meet the WiFi standards for APs in the building. 1 1
FragglePete Posted May 15 Posted May 15 While I have the sort of green light from Governors to get our Core Switch replaced and I have a 'rough' budget to work too, they're still querying how much it'll actually be - engaging suppliers on what will be a small tender competition is only going to p*** them of if I don't go through and I know pricing for hardware is volatile at the moment, so a quote I get may only be limited for a short period of time; not enough time for when the finance committee meet again - it's bit of a joke really; the joys of internal public sector finance. Ours core switch is a 5406zl - running since 2009 (!) and the modules have been upgraded over the years (with re-conditioned units) to give us some 10Gb connectivity to the Servers and some 'heavy use' Edge switches. I've got some options I'm looking at, with some feedback from suppliers and what I've garnished on here. Option 1. Get a new 5412zl2 which is still supported and sold by Aruba, so the warranty will follow their 'Limited Lifetime Warranty End Of Sale + 5 Years' - which at a minimum will be 5 years and possibly more as there is no published EOS date yet - almost a like to like new replacement for our current switch but with more capacity for getting all our edge links to 10Gb along with Dual Managment Cards, Multiple PSU, etc meeting from what I can tell the DfE Specs (although I need to confirm the finer details). Fully populated, it'll completely use up our 'rough' budget leaving nothing left for other projects I would like to get done. Option 2. These 5412zl2 's are popping up on eBay from various refurbs companies, and fully populated are a third of the cost of new - come with a warranty from the suppliers of at least 3 years, and who knows, it may fall under the Aruba LLWE-EOS + 5 Years warranty. Option 3. eBay again, but find a 'cold spare' of a 5406zl that we have as I know some people on here are doing this - but, it feels like it's just kicking the can down the road especially as the Firmware is not being updated for these devices so would fall foul of things like Secure Schools philosophy in running up to date supported firmware of all hardware. Massive saving, but just delaying the inevitable. Option 4. Stack Baby, Stack! Again, as mentioned on this thread, get something like a few CX6300's and build a stack with MLAG and build a Core with no single point of failure but will need a fair bit of reconfiguring of the network to do this. Cost wise, looking at @Mr.Ben's post, this could be cheaper than a new chassis based in terms of hardware. Option 5. Move to something like UniFi for the Core Switch - over the years, I've been replacing our aging HP ProCure Switches with UniFi switches purely because the cost savings - but would I trust their line up for the Core? Could be a big saver, and get everything on to that 'Single Pane of Glass' that the DfE are keen for us to have on things like this. I'd have to get assistance from a UniFi expert to help get this in place. Or, something else ? Appreciate anybody reading this. Just a bit of sanity check. Our current Core does our Inter-VLAN routing with ACLs in place to control access where required - and from what I've been reading up on, this approach may be outdated and some reading indicates this routing should be done on the Firewall, but our Firewall (Sophos XGS) forms part of our managed Internet Connection so not wanting to touch this as it may change if we ever change provider, etc in the future - we just have static routes setup for each of the VLANs on it to allow Internet traffic to flow. I need to now put together the documentation to send to suppliers and see what comes in, but would welcome any input here which judging by the number of 'core switch upgrade' posts over the years on here, may help others too. TIA Pete
Boredguy Posted May 15 Posted May 15 Our "Core" switch at several sites now consists of a Unifi 32 port Aggregation switch for the fibre links and at least a single Unifi 48 Port Pro Switch which has a lag back to the Agg switch to give between 10-40Gb depending on our requirements. As we have the Unifi OS Server setup, we've also got several of our school sites configured within it so management is easier. Certainly works out cheaper (and lighter) than the HP 5xxx units but maybe not as compact depending on how many ports you need 1 1
FragglePete Posted May 15 Posted May 15 26 minutes ago, Boredguy said: Our "Core" switch at several sites now consists of a Unifi 32 port Aggregation switch for the fibre links and at least a single Unifi 48 Port Pro Switch which has a lag back to the Agg switch to give between 10-40Gb depending on our requirements. As we have the Unifi OS Server setup, we've also got several of our school sites configured within it so management is easier. Certainly works out cheaper (and lighter) than the HP 5xxx units but maybe not as compact depending on how many ports you need Do you route between VLANs at all with this setup? Pete
Boredguy Posted May 15 Posted May 15 We didn't bother with any L3 routing at the sites, as most of our vLans are just for CCTV or BYoD traffic (which we NAT using Opnsense before it goes to our router) 1
psydii Posted May 15 Posted May 15 1) gives you five or six years of support since they'll eol these soon, since its replacement was launched about 12 months ago. 2/3 are for when you've got a £40K core out of warranty and no money to replace it, so you have to keep it going by hook or by crook. But this is just daft now you've got the green light from governors. Replace with new! 4) yup. hate the idea of replacing a chasis with a stack, but its hard to dismiss it when the equivalent chasis solution is 5x the price. 5) warranty and support - if you need things with warranty and support coverage, you'll be replacing these every few years (compared to the venerable procurve you currently have). This might not actually be a bad thing. 1
FN-GM Posted May 15 Posted May 15 (edited) 12 hours ago, FragglePete said: Do you route between VLANs at all with this setup? Pete Technically, by best design practise, core switches don't do routing. This will be the job of the distribution switches and firewall. In OT networks, only the firewalls route between networks. Edited May 15 by FN-GM 1 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now