Pica8 Switch
September 14, 2017 | Network Linux SecurityA white box switch, QuantaMesh BMS T3048-LY2R, provides networking connectivity to the Ceph storage cluster Pulpos. We runs Pica8 PicOS on the switch. QuantaMesh BMS switches can also run other Network OSes, such as Cumulus.
Hardware Specifications
QuantaMesh BMS T3048-LY2R is a 1U top top-of-rack switch, based on the Broadcom Trident+ (BCM56840 Series) switching fabric, with:
- 48x 10GbE SFP+ ports
- 4x 40GbE QSFP+ ports
- Out-of-band management port (RJ-45, 10/100/1000Base-T)
The CPU is a dual-core 32-bit PowerPC e500v2 @ 1.2GHz, from Freescale Semiconductor:
As one can see from above, total memory is 2GB.
PicOS
As of this writing, the switch runs PicOS 2.9.1.2, which seems to be based on Debian 7.0:
It uses an ancient Linux kernel 2.6.32.69:
PicOS can run in 2 different modes of operation:
- Open vSwitch (OVS) mode: In this mode, PicOS is dedicated and optimized for OpenFlow applications
- Layer 2 / Layer 3 (L2/L3) mode: In this mode, PicOS can run both switching and routing protocols (using XORP) and OpenFlow applications
References:
- PicOS Overview
- PicOS Routing And Switching Configuration Guide
- PicOS Routing And Switching Commands Reference Guide
- PicOS System Configuration
- PicOS OVS Configuration Guide
- PicOS Openflow Tutorials
Accessing the Pica8 Switch
The Pica8 switch is heavily guarded. In order to gain remote access to the switch, one needs to go through the following steps:
1) Enter Data Center VPN (vpn-dc.ucsc.edu), using Cisco AnyConnect. Data Center VPN requires Multi-Factor Authentication (MFA). To authenticate to Data Center VPN, one needs to provide both the CruzID Gold password and a One-Time Passcode (OTP). Duo is the vendor that facilitates the passcodes for MFA at UCSC.
2) Once inside Data Center VPN, ssh to one of the sebastion hosts, using MFA (CruzID Blue password + OTP). There are 2 sebastion hosts:
- noc-prod-sebastion-1.ucsc.edu (alias: sebastion1.ucsc.edu)
- noc-prod-sebastion-2.ucsc.edu (alias: sebastion2.ucsc.edu)
3) Finally, one can ssh to the Pica8 switch, whose FQDN is sw7175-100-ve435.ucsc.edu and whose IP address is 128.114.109.93.
Curiously, although PicOS says the hostname of the switch is sw7175-100-pica8-1:
it is not the registered DNS name of the switch!
4) One can then enter CLI, by typing cli
:
Link Aggregation
My colleague George Peeks has configured Link Aggregation Control Protocol (LACP) on the Pica8 switch, in order to support bonding of two 10GbE interfaces on pulpo-dtn.