Jump to content

Recommended Posts

Posted

I've inherited a challenge with this in my latest post - they had just replaced the 5406zl core with a single, 24 port Aruba 6300M fibre switch (all 10G).

 

That was ok - it's powerful enough, but didn't meet the DfE  requirements, so I stacked it with 3 more switches in this year's budget - all 6300s, 1 more fiber and 2 ethernet.

 

All of our fiber runs now have 2 paths to 2 separate switches, which is great!

 

The total cost of the core was £20k, but I am serving the whole building from the additional, unused ethernet interfaces and can meet the WiFi standards for APs in the building.

 

  • Like 1
  • Thanks 1
Posted

While I have the sort of green light from Governors to get our Core Switch replaced and I have a 'rough' budget to work too, they're still querying how much it'll actually be - engaging suppliers on what will be a small tender competition is only going to p*** them of if I don't go through and I know pricing for hardware is volatile at the moment, so a quote I get may only be limited for a short period of time; not enough time for when the finance committee meet again - it's bit of a joke really; the joys of internal public sector finance.  Ours core switch is a 5406zl - running since 2009 (!) and the modules have been upgraded over the years (with re-conditioned units) to give us some 10Gb connectivity to the Servers and some 'heavy use' Edge switches. 

 

I've got some options I'm looking at, with some feedback from suppliers and what I've garnished on here.

 

Option 1. Get a new 5412zl2 which is still supported and sold by Aruba, so the warranty will follow their 'Limited Lifetime Warranty End Of Sale + 5 Years' - which at a minimum will be 5 years and possibly more as there is no published EOS date yet - almost a like to like new replacement for our current switch but with more capacity for getting all our edge links to 10Gb along with Dual Managment Cards, Multiple PSU, etc meeting from what I can tell the DfE Specs (although I need to confirm the finer details).  Fully populated, it'll completely use up our 'rough' budget leaving nothing left for other projects I would like to get done.

 

Option 2. These 5412zl2 's are popping up on eBay from various refurbs companies, and fully populated are a third of the cost of new - come with a warranty from the suppliers of at least 3 years, and who knows, it may fall under the Aruba LLWE-EOS + 5 Years warranty.

 

Option 3. eBay again, but find a 'cold spare' of a 5406zl that we have as I know some people on here are doing this - but, it feels like it's just kicking the can down the road especially as the Firmware is not being updated for these devices so would fall foul of things like Secure Schools philosophy in running up to date supported firmware of all hardware.  Massive saving, but just delaying the inevitable. 

 

Option 4. Stack Baby, Stack!  Again, as mentioned on this thread, get something like a few CX6300's and build a stack with MLAG and build a Core with no single point of failure but will need a fair bit of reconfiguring of the network to do this.  Cost wise, looking at @Mr.Ben's post, this could be cheaper than a new chassis based in terms of hardware.

 

Option 5. Move to something like UniFi for the Core Switch - over the years, I've been replacing our aging HP ProCure Switches with UniFi switches purely because the cost savings - but would I trust their line up for the Core?  Could be a big saver, and get everything on to that 'Single Pane of Glass' that the DfE are keen for us to have on things like this.  I'd have to get assistance from a UniFi expert to help get this in place.  Or, something else ?

 

Appreciate anybody reading this.  Just a bit of sanity check.  Our current Core does our Inter-VLAN routing with ACLs in place to control access where required - and from what I've been reading up on, this approach may be outdated and some reading indicates this routing should be done on the Firewall, but our Firewall (Sophos XGS) forms part of our managed Internet Connection so not wanting to touch this as it may change if we ever change provider, etc in the future - we just have static routes setup for each of the VLANs on it to allow Internet traffic to flow.

 

I need to now put together the documentation to send to suppliers and see what comes in, but would welcome any input here which judging by the number of 'core switch upgrade' posts over the years on here, may help others too.

 

TIA

 

Pete

 

 

Posted

Our "Core" switch at several sites now consists of a Unifi 32 port Aggregation switch for the fibre links and at least a single Unifi 48 Port Pro Switch which has a lag back to the Agg switch to give between 10-40Gb depending on our requirements.

As we have the Unifi OS Server setup, we've also got several of our school sites configured within it so management is easier.

 

Certainly works out cheaper (and lighter) than the HP 5xxx units but maybe not as compact depending on how many ports you need

 

  • Like 1
  • Thanks 1
Posted
26 minutes ago, Boredguy said:

Our "Core" switch at several sites now consists of a Unifi 32 port Aggregation switch for the fibre links and at least a single Unifi 48 Port Pro Switch which has a lag back to the Agg switch to give between 10-40Gb depending on our requirements.

As we have the Unifi OS Server setup, we've also got several of our school sites configured within it so management is easier.

 

Certainly works out cheaper (and lighter) than the HP 5xxx units but maybe not as compact depending on how many ports you need

 

 

Do you route between VLANs at all with this setup?


Pete

 

Posted

We didn't bother with any L3 routing at the sites, as most of our vLans are just for CCTV or BYoD traffic (which we NAT using Opnsense before it goes to our router)

  • Thanks 1
Posted

1) gives you five or six years of support since they'll eol these soon, since its replacement was launched about 12 months ago.

 

2/3 are for when you've got a £40K core out of warranty and no money to replace it, so you have to keep it going by hook or by crook.  But this is just daft now  you've got the green light from governors. Replace with new! 

 

4) yup. hate the idea of replacing a chasis with a stack, but its hard to dismiss it when the equivalent chasis solution is 5x the price.

 

5) warranty and support - if you need things with warranty and support coverage, you'll be replacing these every few years (compared to the venerable procurve you currently have).  This might not actually be a bad thing.

  • Thanks 1
Posted (edited)
12 hours ago, FragglePete said:

 

Do you route between VLANs at all with this setup?


Pete

 

 

Technically, by best design practise, core switches don't do routing. This will be the job of the distribution switches and firewall. In OT networks, only the firewalls route between networks.

Edited by FN-GM
  • Like 1
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...