Skip to content

crs-fabric — Server-room fabric switch

CRS326 MLAG pairs for the server-room network. Worked example: sw-vm-1.

Model CRS326-24S+2Q+RM (24× SFP+ + 2× QSFP+)
NetBox role crs-fabric (pure L2 — no routing protocols)
Ansible playbook crs-fabric.yml (backup, baseline switch-profile, crs_fabric)
OOB 10.201.201.11/24 on ether1 (kept out of the fabric bridge)

Two pairs exist: a VM fabric (sw-vm-1/2) and a storage fabric (sw-storage-1/2, formerly sw-ceph-1/2; it now carries migration/replication 911 and corosync ring1 951; ports p4–6 are disabled, reserved as unbonded iSCSI 922 MPIO paths).

MTU

Jumbo l2mtu 9092 / mtu 9092 on all fabric ports — 9000 storage jumbo plus VLAN-tag headroom. Never touches a router or MPLS.

Interfaces (sw-vm-1)

Port Role Detail
ether1 OOB mgmt 10.201.201.11/24, outside the fabric bridge
bond-peer MLAG ISL 2×40G QSFP+ (80G), tagged-all (carries every VLAN)
bond-hv1 mlag-host LACP, tagged 932-936,940 (guest trunk), mlag_id=101
bond-fw1 mlag-host LACP, tagged 910,932-936,940, mlag_id=111 (OPNsense trunk)
sfp-sfpplus10 single-port access, untagged VLAN 910

Member ports are parented to their LAG; VLANs go on the bond, never on members. Host bonds carry the same mlag_id on both switches of the pair, and both switches carry the same VLAN table.

VLANs

Derived from the native 802.1Q assignments (server-room group): 910 backup, 922 iSCSI (reserved; L2-only, no gateway), 932–936 VM (apps, k8s, monitoring, data/SQL, dev), 940 hypervisor mgmt, 911 migration + replication (storage fabric), 950/951 corosync. 920/921 (ex-Ceph) are deprecated and no longer on any switch. The ISL is mode=tagged-all (member of every VLAN).

Cabling order

The MLAG peer-link must be cabled and LACP-up on both switches before the interface bridge mlag task runs. crs.bridge_vlans / crs.peer_port are config-context overrides only.

This role reproduces crs326-mlag-fabric.rsc. The fabric is deliberately hand-applied/versioned rather than fully NetBox-derived.