LLDP on Maestro Orchestrator
LLDP on MaestroOrchestrator
This section applies only to external interfaces (Management ports and Uplink ports) on the MaestroOrchestrator.
| Important - Scalable Platform Security Groups do not support this feature (Known Limitation MBS-10753 for ElasticXL and MaestroSecurity Groups). |
You can configure Gaia to advertise and receive information from other network devices over the Link Layer Discovery Protocol (LLDP) protocol.
The LLDP is a vendor-neutral link layer protocol that network devices use to advertise their identity, capabilities (and so on) and to receive information about their neighbors on a local area network based on IEEE 802 standard.
The gathered information may include:
System Name
System Description
System Capabilities (switching, routing, etc.)
Port Description
Management Address
| Important - By default, LLDP is disabled in the Gaia operating system. |
| Notes - In a Maestro environment: - The Security Appliances send LLDP packets to the Orchestrator. Based on these LLDP packets, the Orchestrator maintains the internal database of the Security Appliances and the Orchestrator ports, to which they are connected. - After you assign Security Appliances to a Security Group, the Orchestrator sends the LLDP packets to the assigned Security Appliances. These LLDP packets contain the required Security Group ID and the Security Group Member ID. - If you change the state of the LLDPD daemon to " off" on the Orchestrator, it stops the LLDPD daemon from transmitting and processing LLDP PDUs on the Orchestrator's external interfaces (Management ports and Uplink ports).However, the LLDPD daemon continues to transmit and process LLDP PDUs on the Orchestrator's Downlink ports. It is not supported to disable LLDP PDUs on the Orchestrator's Downlink ports. - The external ports appear in the Gaia OS on the Orchestrator with these names: - eth<X>-Mgmt<X>Management ports - eth<X>-<XX>Uplink ports - eth<X>-Sync-<X>-<YZ>Ports for the internal synchronization and the external synchronization - The port for the external synchronization between Maestro Sites (" site_sync") on each Orchestrator appears in the Gaia OS with this interface name:eth<Orchestrator_Member_ID>-Sync-E-<Port_Logical_ID>Example: eth1-Sync-E-121- The port for the internal synchronization on the same Maestro Site (" ssm_sync") on each Orchestrator appears in the Gaia OS with this interface name:eth<Orchestrator_Member_ID>-Sync-I-<Port_Logical_ID>Example: eth1-Sync-I-125 |
Configuring LLDP in Gaia Portal on an Orchestrator
| Step | Instructions |
|---|---|
| 1 | In the navigation tree, click System Management > LLDP. |
| 2 | In the Type Length Value (TLV) section, select which information to send in the LLDP packets, and click Apply: - System Name To send the Gaia " <Hostname>.<Domainname>".Note - To configure the domain name, see System Name. - System Description To send the formatted output of the " uname -msr" command(which contains the kernel name, kernel release, and kernel machine hardware name). - System Capabilities To send the string " station" (regardless of the Check Point configuration).- Port Description To send the name of the interface. - Management Address - Select Send Management interface IP to send the IP address of the Gaia Management interface only. - Select Send Configured interface IP to send the IP address of each selected interface. |
| 3 | In the Timers section, it is not supported to change the default values: |
- Transmit Interval
This interval controls how frequently Gaia To send LLDP packets on the selected interfaces.
Default: 8 seconds.
- Hold Time Multiplier
This multiplier controls the Time-to Live (TTL) of the LLDP packets:
TTL = (Transmit Interval) x (Hold Time Multiplier).
This TTL is the duration, for which the receiving neighbor stores the LLDP information in its database.
Default: 3.
| Note - These values are global and apply to all selected interfaces. | |
| 4 | In the Interfaces section, add the applicable interfaces. By default, Gaia OS selects the ports for the internal synchronization and the internal synchronization. - To add all interfaces: 1. Click Add All. 2. Click Yes to confirm. 3. The default LLDP mode for all interfaces is Transmit and Receive. To change the LLDP mode: 1. Select an interface. 2. Click Edit. 3. Select the applicable LLDP mode. 4. Click Save. - To add a specific interface: 1. Click Add. 2. In the Interface Name field, select an interface. 3. In the Mode field, select the applicable LLDP mode. 4. Click Save. The available LLDP modes are: - Transmit and Receive The interface transmits and receives the LLDP packets. - Transmit only The interface only transmits the LLDP packets, but does not receive the LLDP packets. - Receive only The interface only receives the LLDP packets, but does not transmit the LLDP packets. |
| 5 | In the LLDP Configuration section: 1. Select Enable LLDP on external interfaces. 2. Click Apply. |
Configuring LLDP in Gaia Clish on an Orchestrator
By default, Gaia OS selects the ports for the internal synchronization and the internal synchronization.
Workflow:
| Step | Instructions |
|---|---|
| 1 | Enable the LLDP on the external ports: |
set lldp state on |
| 2 |
| 3 |
save config |
Syntax
- To configure LLDP on Orchestrator:
set lldp hold-time-multiplier <2-10> interface <Name of Interface>` receive {on |
Important - After you add, configure, or delete features, run the "save config" command to save the settings permanently. Scalable Platforms save the changes automatically. |
- To show the LLDP configuration on Orchestrator:
show lldp peers status interface <Name of Interface> timers tlv |
Parameters
| Parameter | Description |
|---|---|
hold-time-multiplier |
This multiplier controls the Time-to Live (TTL) of the LLDP packets: |
TTL = (Transmit Interval) x (Hold Time Multiplier).
This TTL is the duration, for which the receiving neighbor stores the LLDP information in its database.
Default: 3.
| Note - It is not supported to change the default value. | |
interface <Name of Interface> |
Specifies the name of an interface, which sends or receives the LLDP packets. |
| `interface |
off}` |
| `interface |
off}` |
| `interface |
off}` |
| `state {on | off}` |
| `tlv port-description {on |
off}` |
| `tlv system-name {on |
off}` |
| `tlv system-description {on |
off}` |
| `tlv system-capabilities {on |
off}` |
| `tlv management-address {on |
off}` |
transmit-interval <8-32768> |
This interval controls how frequently the LLDP-enabled interface sends the LLDP packets. |
Default: 8 seconds.
| Note - It is not supported to change the default value. | |
timers |
Shows the configured LLDP timers: - Hold Time Multiplier - Transmit Interval |
Example - Viewing the LLDP status
<br>MHO_1_1> show lldp status<br>LLDP is enabled on external interfaces<br>Interfaces<br>Mgmt1 - transmit and receive<br>eth1-05 - transmit and receive<br>eth1-09 - transmit and receive<br>eth1-17 - transmit and receive<br>eth1-21 - transmit and receive<br>eth1-25 - transmit and receive<br>eth1-29 - transmit and receive<br>eth1-33 - transmit and receive<br>eth1-37 - transmit and receive<br>eth1-41 - transmit and receive<br>eth1-45 - transmit and receive<br>eth1-49 - transmit and receive<br>eth1-53 - transmit and receive<br>eth1-57 - transmit and receive<br>eth1-61 - transmit and receive<br>eth1-Mgmt1 - transmit and receive<br>eth1-Sync-E-121 - transmit and receive<br>eth1-Sync-I-125 - transmit and receive<br>Optional Information<br>port-description off<br>system-name on<br>system-description off<br>system-capabilities off<br>management-address on from configured-interface<br>Timers<br>Hold time multiplier 3<br>Transmit interval 8<br>MHO_1_1><br> |
Example - Viewing the LLDP peers
<br>MHO_1_1> show lldp peers<br>-------------------------------------------------------------------------------<br>LLDP neighbors:<br>-------------------------------------------------------------------------------<br>Interface: Mgmt1, via: LLDP, RID: 138, Time: 0 day, 00:12:31<br> Chassis:<br> ChassisID: mac XX:XX:XX:XX:XX:XX<br> SysName: MyCiscoSwitch<br> SysDescr: Cisco Nexus Operating System (NX-OS)<br> TAC support: http://www.cisco.com/tac<br> Copyright (c) 2002-2019, Cisco Systems, Inc. All rights reserved.<br> MgmtIP: 172.16.2.182<br> Capability: Bridge, on<br> Capability: Router, on<br> Port:<br> PortID: ifname Ethernet1/31<br> PortDescr: MHO-1<br> TTL: 120<br> VLAN: 25, pvid: yes<br> Unknown TLVs:<br> TLV: OUI: 00,01,42, SubType: 1, Len: 1 01<br>-------------------------------------------------------------------------------<br>Interface: eth1-Sync-I-125, via: LLDP, RID: 131, Time: 1 day, 06:53:27<br> Chassis:<br> ChassisID: local MT2006X14198<br> SysName: MHO_1_2<br> MgmtIP: 172.16.25.102<br> Port:<br> PortID: mac 00:02:03:04:05:c4<br> PortDescr: eth2-Sync-I-125<br> TTL: 24<br>-------------------------------------------------------------------------------<br>Interface: eth1-Sync-E-121, via: LLDP, RID: 137, Time: 1 day, 06:09:43<br> Chassis:<br> ChassisID: local MT2006X14199<br> SysName: MHO_2_1<br> MgmtIP: 172.16.25.103<br> Port:<br> PortID: mac 00:02:03:04:05:c0<br> PortDescr: eth1-Sync-E-121<br> TTL: 24<br>-------------------------------------------------------------------------------<br>Interface: eth1-Mgmt1, via: LLDP, RID: 140, Time: 0 day, 00:12:19<br> Chassis:<br> ChassisID: mac XX:XX:XX:XX:XX:XX<br> Port:<br> PortID: ifname hundredGigE 1/15<br> TTL: 120<br>(truncated)<br>-------------------------------------------------------------------------------<br>MHO_1_1><br> |
Configuring LLDP in the Expert mode on an Orchestrator
You can configure advanced LLDP settings in the Expert mode.
To control the automatic LLDP configuration "transmit-and-receive on" on any new port with the type "ssm_sync" (internal sync) and "site_sync" (external sync):
By default, this feature is enabled.
| Step | Instructions |
|---|---|
| 1 | Connect to the command line on the Orchestrator. |
| 2 | Log in. |
| 3 | If your default shell is Gaia Clish, then go to the Expert mode: |
expert |
| 4 |
- To enable this feature (this is the default), run:
dbset maestro:lldp:set_lldp_rx_and_tx_to_on_upon_sync_interface_creation true |
- To disable this feature, run:
dbset maestro:lldp:set_lldp_rx_and_tx_to_on_upon_sync_interface_creation |
| 5 |
dbset :save |
To control the automatic LLDP configuration "transmit-and-receive on" of any new port:
By default, this feature is disabled.
expert |
| 4 |
- To enable this feature, run:
dbset maestro:lldp:set_lldp_rx_and_tx_to_on_upon_interface_creation true |
- To disable this feature (this is the default), run:
dbset maestro:lldp:set_lldp_rx_and_tx_to_on_upon_interface_creation |
| 5 |
dbset :save |