[j-nsp] SNMP on logical-system fxp0

Tore Anderson tore at fud.no
Thu Apr 25 13:20:38 EDT 2013


* Saku Ytti

>> That essentially what we are talking about.  Connect fxp0 to a
>> SEPARATE switch that is used for only out of band traffic.  You then
>> use this network to copy images, etc.  What am I missing here?
> 
> What are you winning by not doing this on-band in HW interface?

Cost. The fxp0 port is basically free. The ports on the line cards are
anything but - there's not a chance in hell I could reserve one of the
revenue ports on the line cards for emergency management access that I
could use to get at the box, should for example my IGP melt down.

Or procure a management switch with 10G ports I could connect the
revenue-turned-mgmt port to, for that matter. Unmanaged 100M switches,
is on the other hand practically free.

>> Sure you can, I've done it, others here have said they've done it.
>> Assuming the OOB network is well protected from outside traffic to
>> avoid attacks and the like, why not?
> 
> Additional ports, wiring.

Use of the fxp0 port doesn't require any more ports/wiring than the CMP
style approach you appear to be advocating?

It would be better to have an embedded iLO/BMC in the chassis like you
find on pretty much any x86 server these days - with internal serial
console port, power control, etc. I do have x86 servers with iLOs
connected to the same management switch I connect my fxp0s to. fxp0
isn't perfect, but IMHO it is better than nothing.

Tore




More information about the juniper-nsp mailing list