S7650_Series Configuration Guide
# Chapter 1 Basic Management Configuration ## 1.1 Switch Management ### 1.1.1 Management Options After purchasing the switch, the user needs to configure the switch for network management. Switch provides two management options: in-band management and out-of-band management. #### 1.1.1.1 Out-Of-Band Management Out-of-band management is the management through Console interface. Generally, the user will use out-of-band management for the initial switch configuration, or when in-band management is not available. For instance, the user must assign an IP address to the switch via the Console interface to be able to access the switch through Telnet. The procedures for managing the switch via Console interface are listed below: 1. setting up the environment: @img 1-1 @fig Figure 1-1 Out-of-band Management Configuration Environment As shown in above, the serial port (RS-232) is connected to the switch with the serial cable provided. The table below lists all the devices used in the connection. [Table start] Device Name Description PC machine Has functional keyboard and RS-232, with terminal emulator installed, such as HyperTerminal included in Windows 9x/NT/2000/XP. Serial port cable One end attach to the RS-232 serial port, the other end to the Console port. Switch Functional Console port required. [Table end] 2. Entering the HyperTerminal Open the HyperTerminal included in Windows after the connection established. The example below is based on the HyperTerminal included in Windows XP. (1) Click Start menu - All Programs -Accessories -Communication - HyperTerminal. @img 1-2 @fig Figure 1-2 Opening Hyper Terminal (2) Type a name for opening HyperTerminal, such as "Switch". @img 1-3 @fig Figure 1-3 Opening HyperTerminal (3) In the "Connecting using" drop-list, select the RS-232 serial port used by the PC, e.g. COM1, and click "OK". @img 1-4 @fig Figure 1-4 Opening HyperTerminal (4) COM1 property appears, select "115200" for "Baud rate", "8" for "Data bits", "none" for "Parity checksum", "1" for stop bit and "none" for traffic control; or, you can also click "Restore default" and click "OK". @img 1-5 @fig Figure 1-5 Opening HyperTerminal 3. Entering switch CLI interface Power on the switch, the following appears in the HyperTerminal windows, that is the CLI configuration mode for Switch. Testing RAM... 0x077C0000 RAM OK Loading MiniBootROM... Attaching to file system ... Loading nos.img ... done. Booting...... Starting at 0x10000... Attaching to file system ... ...... --- Performing Power-On Self Tests (POST) --- DRAM Test....................PASS! PCI Device 1 Test............PASS! FLASH Test...................PASS! FAN Test.....................PASS! Done All Pass. ------------------ DONE --------------------- Current time is SUN JAN 01 00:00:00 2006 ...... Switch> The user can now enter commands to manage the switch. For a detailed description for the commands, please refer to the following chapters. #### 1.1.1.2 In-band Management In-band management refers to the management by login to the switch using Telnet, or using HTTP, or using SNMP management software to configure the switch. In-band management enables management of the switch for some devices attached to the switch. In the case when in-band management fails due to switch configuration changes, out-of-band management can be used for configuring and managing the switch. ##### 1.1.1.2.1 Management via Telnet To manage the switch with Telnet, the following conditions should be met: 1. Switch has an IPv4/IPv6 address configured; 2. The host IP address (Telnet client) and the switch's VLAN interface IPv4/IPv6 address is in the same network segment; 3. If 2 is not met, Telnet client can connect to an IPv4/IPv6 address of the switch via other devices, such as a router. The switch is a Layer 3 switch that can be configured with several IPv4/IPv6 addresses, the configuration method refers to the relative chapter. The following example assumes the shipment status of the switch where only VLAN1 exists in the system. The following describes the steps for a Telnet client to connect to the switch's VLAN1 interface by Telnet(IPV4 address example): @img 1-6 @fig Figure 1-6 Manage the switch by Telnet Step 1: Configure the IP addresses for the switch and start the Telnet Server function on the switch. First is the configuration of host IP address. This should be within the same network segment as the switch VLAN1 interface IP address. Suppose the switch VLAN1 interface IP address is 10.1.128.251/24. Then, a possible host IP address is 10.1.128.252/24. Run "ping 10.1.128.251" from the host and verify the result, check for reasons if ping failed. The IP address configuration commands for VLAN1 interface are listed below. Before in-band management, the switch must be configured with an IP address by out-of-band management (i.e. Console mode), the configuration commands are as follows (All switch configuration prompts are assumed to be "Switch" hereafter if not otherwise specified): [Box start] Switch> Switch>enable Switch#config Switch(config)#interface vlan 1 Switch(Config-if-Vlan1)#ip address 10.1.128.251 255.255.255.0 Switch(Config-if-Vlan1)#no shutdown [Box end] To enable the Telnet Server function, users should type the CLI command telnet-server enable in the global mode as below: [Box start] Switch>enable Switch#config Switch(config)# telnet-server enable [Box end] Step 2: Run Telnet Client program. Run Telnet client program included in Windows with the specified Telnet target. @img 1-7 @fig Figure 1-7 Run telnet client program included in Windows Step 3: Login to the switch. Login to the Telnet configuration interface. Valid login name and password are required, otherwise the switch will reject Telnet access. This is a method to protect the switch from unauthorized access. As a result, when Telnet is enabled for configuring and managing the switch, username and password for authorized Telnet users must be configured with the following command: username
privilege
[password {0 | 7}
]. To open the local authentication style with the following command: authentication line vty login local. Privilege option must exist and just is 15. Assume an authorized user in the switch has a username of "test", and password of "test", the configuration procedure should like the following: [Box start] Switch>enable Switch#config Switch(config)#username test privilege 15 password 0 test Switch(config)#authentication line vty login local [Box end] Enter valid login name and password in the Telnet configuration interface, Telnet user will be able to enter the switch's CLI configuration interface. The commands used in the Telnet CLI interface after login is the same as that in the Console interface. @img 1-8 @fig Figure 1-8 Telnet Configuration Interface ##### 1.1.1.2.2 Management via HTTP To manage the switch via HTTP, the following conditions should be met: 1. Switch has an IPv4/IPv6 address configured; 2. The host IPv4/IPv6 address (HTTP client) and the switch's VLAN interface IPv4/IPv6 address are in the same network segment; 3. If 2 is not met, HTTP client should connect to an IPv4/IPv6 address of the switch via other devices, such as a router. Similar to management the switch via Telnet, as soon as the host succeeds to ping/ping6 an IPv4/IPv6 address of the switch and to type the right login password, it can access the switch via HTTP. The configuration list is as below: Step 1: Configure the IP addresses for the switch and start the HTTP server function on the switch. For configuring the IP address on the switch through out-of-band management, see the telnet management chapter. To enable the WEB configuration, users should type the CLI command IP http server in the global mode as below: [Box start] Switch>enable Switch#config Switch(config)#ip http server [Box end] Step 2: Run HTTP protocol on the host. Open the Web browser on the host and type the IP address of the switch, or run directly the HTTP protocol on the Windows. For example, the IP address of the switch is "10.1.128.251"; @img 1-9 @fig Figure 1-9 Run HTTP Protocol When accessing a switch with IPv6 address, it is recommended to use the Firefox browser with 1.5 or later version. For example, if the IPv6 address of the switch is 3ffe:506:1:2::3. Input the IPv6 address of the switch is http://[3ffe:506:1:2::3] and the address should draw together with the square brackets. Step 3: Login to the switch. Login to the Web configuration interface. Valid login name and password are required, otherwise the switch will reject HTTP access. This is a method to protect the switch from unauthorized access. As a result, when Telnet is enabled for configuring and managing the switch, username and password for authorized Telnet users must be configured with the following command: username
privilege
[password {0 | 7}
]. To open the local authentication style with the following command: authentication line web login local. Privilege option must exist and just is 15. Assume an authorized user in the switch has a username of "admin", and password of "admin", the configuration procedure should like the following: [Box start] Switch>enable Switch#config Switch(config)#username admin privilege 15 password 0 admin Switch(config)#authentication line web login local [Box end] The Web login interface is as below: @img 1-10 @fig Figure 1-10 Web Login Interface Input the right username and password, and then the main Web configuration interface is shown as below @img 1-11 @fig Figure 1-11 Main Web Configuration Interface Notice: When configure the switch, the name of the switch is composed with English letters. ##### 1.1.1.2.3 Manage the Switch via SNMP Network Management Software The necessities required by SNMP network management software to manage switches: 1. IP addresses are configured on the switch; 2. The IP address of the client host and that of the VLAN interface on the switch it subordinates to should be in the same segment; 3. If 2 is not met, the client should be able to reach an IP address of the switch through devices like routers; 4. SNMP should be enabled. The host with SNMP network management software should be able to ping the IP address of the switch, so that, when running, SNMP network management software will be able to find it and implement read/write operation on it. Details about how to manage switches via SNMP network management software will not be covered in this manual, please refer to "Snmp network management software user manual". ### 1.1.2 CLI Interface The switch provides thress management interface for users: CLI (Command Line Interface) interface, Web interface, Snmp netword management software. We will introduce the CLI interface and Web configuration interface in details, Web interface is familiar with CLI interface function and will not be covered, please refer to "Snmp network management software user manual". CLI interface is familiar to most users. As aforementioned, out-of-band management and Telnet login are all performed through CLI interface to manage the switch. CLI Interface is supported by Shell program, which consists of a set of configuration commands. Those commands are categorized according to their functions in switch configuration and management. Each category represents a different configuration mode. The Shell for the switch is described below: 1. Configuration Syntax 2. Shortcut keys 3. Help function 4. Input verification 5. Fuzzy match support 6. Configuration Modes #### 1.1.2.1 Configuration Modes @img 1-12 @fig Figure 1-12 Shell Configuration Modes ##### 1.1.2.1.1 User Mode On entering the CLI interface, entering user entry system first. If as common user, it is defaulted to User Mode. The prompt shown is "Switch>", the symbol ">" is the prompt for User Mode. When exit command is run under Admin Mode, it will also return to the User Mode. Under User Mode, no configuration to the switch is allowed, only clock time and version information of the switch can be queries. ##### 1.1.2.1.2 Admin Mode To Admin Mode sees the following: In user entry system, if as Admin user, it is defaulted to Admin Mode. Admin Mode prompt "Switch#" can be entered under the User Mode by running the enable command and entering corresponding access levels admin user password, if a password has been set. Or, when exit command is run under Global Mode, it will also return to the Admin Mode. Switch also provides a shortcut key sequence "Ctrl+z", this allows an easy way to exit to Admin Mode from any configuration mode (except User Mode). Under Admin Mode, the user can query the switch configuration information, connection status and traffic statistics of all ports; and the user can further enter the Global Mode from Admin Mode to modify all configurations of the switch. For this reason, a password must be set for entering Admin mode to prevent unauthorized access and malicious modification to the switch. ##### 1.1.2.1.3 Global Mode Type the config command under Admin Mode will enter the Global Mode prompt "Switch(config)#". Use the exit command under other configuration modes such as Port Mode, VLAN mode will return to Global Mode. The user can perform global configuration settings under Global Mode, such as MAC Table, Port Mirroring, VLAN creation, IGMP Snooping start and STP, etc. And the user can go further to Port Mode for configuration of all the interfaces. Interface Mode Use the interface command under Global Mode can enter the interface mode specified. Switch provides three interface type: 1. VLAN interface; 2. Ethernet port; 3. port-channel, accordingly the three interface configuration modes. [Table start] Interface Type Entry Operates Exit VLAN Interface Type interface vlan
command under Global Mode. Configure switch IPs, etc Use the exit command to return to Global Mode. Ethernet Port Type interface ethernet
command under Global Mode. Configure supported duplex mode, speed, etc. of Ethernet Port. Use the exit command to return to Global Mode. port-channel Type interface port-channel
command under Global Mode. Configure port-channel related settings such as duplex mode, speed, etc. Use the exit command to return to Global Mode. [Table end] VLAN Mode Using the vlan
command under Global Mode can enter the corresponding VLAN Mode. Under VLAN Mode the user can configure all member ports of the corresponding VLAN. Run the exit command to exit the VLAN Mode to Global Mode. DHCP Address Pool Mode Type the ip dhcp pool
command under Global Mode will enter the DHCP Address Pool Mode prompt "Switch(dhcp-
-config)#". DHCP address pool properties can be configured under DHCP Address Pool Mode. Run the exit command to exit the DHCP Address Pool Mode to Global Mode. Route Mode [Table start] Routing Protocol Entry Operates Exit RIP Routing Protocol Type router rip command under Global Mode. Configure RIP protocol parameters. Use the exit command to return to Global Mode. OSPF Routing Protocol Type router ospf command under Global Mode. Configure OSPF protocol parameters. Use the exit command to return to Global Mode. BGP Routing Protocol Type router bgp
command under Global Mode. Configure BGP protocol parameters. Use the exit command to return to Global Mode. [Table end] ACL Mode [Table start] ACL type Entry Operates Exit Standard IP ACL Mode Type ip access-list standard command under Global Mode. Configure parameters for Standard IP ACL Mode. Use the exit command to return to Global Mode. Extended IP ACL Mode Type ip access-list extanded command under Global Mode. Configure parameters for Extended IP ACL Mode. Use the exit command to return to Global Mode. [Table end] #### 1.1.2.2 Configuration Syntax Switch provides various configuration commands. Although all the commands are different, they all abide by the syntax for Switch configuration commands. The general commands format of Switch is shown below: cmdtxt
{enum1 | ... | enumN } [option1 | ... | optionN] Conventions: cmdtxt in bold font indicates a command keyword;
indicates a variable parameter; {enum1 | ... | enumN } indicates a mandatory parameter that should be selected from the parameter set enum1~enumN; and the square bracket ([ ]) in [option1 | ... | optionN] indicate an optional parameter. There may be combinations of "< >", "{ }" and "[ ]" in the command line, such as [
], {enum1
| enum2}, [option1 [option2]], etc. Here are examples for some actual configuration commands: show version, no parameters required. This is a command with only a keyword and no parameter, just type in the command to run. vlan
, parameter values are required after the keyword. firewall {enable | disable}, user can enter firewall enable or firewall disable for this command. snmp-server community {ro | rw} {0 | 7}
, the followings are possible: snmp-server community ro 0
snmp-server community rw 0
#### 1.1.2.3 Shortcut Key Support Switch provides several shortcut keys to facilitate user configuration, such as up, down, left, right and Blank Space. If the terminal does not recognize Up and Down keys, ctrl +p and ctrl +n can be used instead. [Table start] Key(s) Function Function Back Space Delete a character before the cursor, and the cursor moves back. Delete a character before the cursor, and the cursor moves back. Up "^" Show previous command entered. Up to ten recently entered commands can be shown. Show previous command entered. Up to ten recently entered commands can be shown. Down "v" Show next command entered. When use the Up key to get previously entered commands, you can use the Down key to return to the next command Show next command entered. When use the Up key to get previously entered commands, you can use the Down key to return to the next command Left "<-" The cursor moves one character to the left. You can use the Left and Right key to modify an entered command. Right "->" The cursor moves one character to the right. You can use the Left and Right key to modify an entered command. Ctrl +p The same as Up key "^". The same as Up key "^". Ctrl +n The same as Down key "v". The same as Down key "v". Ctrl +b The same as Left key "<-". The same as Left key "<-". Ctrl +f The same as Right key "->". The same as Right key "->". Ctrl +z Return to the Admin Mode directly from the other configuration modes (except User Mode). Return to the Admin Mode directly from the other configuration modes (except User Mode). Ctrl +c Break the ongoing command process, such as ping or other command execution. Break the ongoing command process, such as ping or other command execution. Tab When a string for a command or keyword is entered, the Tab can be used to complete the command or keyword if there is no conflict. When a string for a command or keyword is entered, the Tab can be used to complete the command or keyword if there is no conflict. [Table end] #### 1.1.2.4 Help Function There are two ways in Switch for the user to access help information: the "help" command and the "?". [Table start] Access to Help Usage and function Help Under any command line prompt, type in "help" and press Enter will get a brief description of the associated help system. "?" Under any command line prompt, enter "?" to get a command list of the current mode and related brief description. Enter a "?" after the command keyword with an embedded space. If the position should be a parameter, a description of that parameter type, scope, etc, will be returned; if the position should be a keyword, then a set of keywords with brief description will be returned; if the output is "
", then the command is complete, press Enter to run the command. A "?" immediately following a string. This will display all the commands that begin with that string. [Table end] #### 1.1.2.5 Input Verification ##### 1.1.2.5.1 Returned Information: success All commands entered through keyboards undergo syntax check by the Shell. Nothing will be returned if the user entered a correct command under corresponding modes and the execution is successful. ##### 1.1.2.5.2 Returned Information: error [Table start] Output error message Explanation Unrecognized command or illegal parameter! The entered command does not exist, or there is error in parameter scope, type or format. Ambiguous command At least two interpretations is possible basing on the current input. Invalid command or parameter The command is recognized, but no valid parameter record is found. This command is not exist in current mode The command is recognized, but this command can not be used under current mode. Please configure precursor command "*" at first! The command is recognized, but the prerequisite command has not been configured. syntax error : missing '"' before the end of command line! Quotation marks are not used in pairs. [Table end] ##### 1.1.2.5.3 Fuzzy Match Support Switch shell support fuzzy match in searching command and keyword. Shell will recognize commands or keywords correctly if the entered string causes no conflict. For example: 1. For command 'show interfaces status ethernet1/0/1', typing 'sh in status ethernet1/0/1' will work. 2. However, for command "show running-config", the system will report a "> Ambiguous command!" error if only "show r" is entered, as Shell is unable to tell whether it is "show run" or "show running-config". Therefore, Shell will only recognize the command if "sh ru" is entered. ## 1.2 Basic Switch Configuration ### 1.2.1 Basic Configuration Basic switch configuration includes commands for entering and exiting the admin mode, commands for entering and exiting interface mode, for configuring and displaying the switch clock, for displaying the version information of the switch system, etc. [Table start] Command Explanation Normal User Mode/ Admin Mode enable [<1-15>] disable The User uses enable command to step into admin mode from normal user mode or modify the privilege level of the users. The disable command is for exiting admin mode. Admin Mode config [terminal] Enter global mode from admin mode. Various Modes exit Exit current mode and enter previous mode, such as using this command in global mode to go back to admin mode, and back to normal user mode from admin mode. show privilege Show privilege of the current users. Except User Mode/ Admin Mode end Quit current mode and return to Admin mode when not at User Mode/ Admin Mode. Admin Mode clock set
[YYYY.MM.DD] Set system date and time. show version Display version information of the switch. set default Restore to the factory default. write Save current configuration parameters to Flash Memory. reload Hot reset the switch. show cpu usage Show CPU usage rate. show cpu utilization Show current CPU utilization rate. show memory usage Show memory usage rate. Global Mode banner motd
no banner motd Configure the information displayed when the login authentication of a telnet or console user is successful. web-auth privilege <1-15> no web-auth privilege Configure the level of logging in the switch by web. [Table end] ### 1.2.2 Telnet Management #### 1.2.2.1 Telnet ##### 1.2.2.1.1 Introduction to Telnet Telnet is a simple remote terminal protocol for remote login. Using Telnet, the user can login to a remote host with its IP address of hostname from his own workstation. Telnet can send the user's keystrokes to the remote host and send the remote host output to the user's screen through TCP connection. This is a transparent service, as to the user, the keyboard and monitor seems to be connected to the remote host directly. Telnet employs the Client-Server mode, the local system is the Telnet client and the remote host is the Telnet server. Switch can be either the Telnet Server or the Telnet client. When switch is used as the Telnet server, the user can use the Telnet client program included in Windows or the other operation systems to login to switch, as described earlier in the In-band management section. As a Telnet server, switch allows up to 5 telnet client TCP connections. And as Telnet client, using telnet command under Admin Mode allows the user to login to the other remote hosts. Switch can only establish TCP connection to one remote host. If a connection to another remote host is desired, the current TCP connection must be dropped. ##### 1.2.2.1.2 Telnet Configuration Task List 1.Configure Telnet Server 2.Telnet to a remote host from the switch. 1. Configure Telnet Server [Table start] Command Explanation Global Mode telnet-server enable no telnet-server enable Enable the Telnet server function in the switch: the no command disables the Telnet function. username
[privilege
] [password [0 | 7]
] no username
Configure user name and password of the telnet. The no form command deletes the telnet user authorization. aaa authorization config-commands no aaa authorization config-commands Enable command authorization function for the login user with VTY (login with Telnet and SSH). The no command disables this function. Only enabling this command and configuring command authorization manner, it will request to authorize when executing some command. authentication securityip
no authentication securityip
Configure the secure IP address to login to the switch through Telnet: the no command deletes the authorized Telnet secure address. authentication securityipv6
no authentication securityipv6
Configure IPv6 security address to login to the switch through Telnet; the no command deletes the authorized Telnet security address. authentication ip access-class {
|
} in no authentication ip access-class Binding standard IP ACL protocol to login with Telnet/SSH/Web; the no form command will cancel the binding ACL. authentication ipv6 access-class {
|
} in no authentication ipv6 access-class Binding standard IPv6 ACL protocol to login with Telnet/SSH/Web; the no form command will cancel the binding ACL. authentication line {console | vty | web} login method1 [method2 ...] no authentication line {console | vty | web} login Configure authentication method list with telnet. authentication enable method1 [method2 ...] no authentication enable Configure the enable authentication method list. authorization line {console | vty | web} exec method1 [method2 ...] no authorization line {console | vty | web} exec Configure the authorization method list with telnet. authorization line vty command <1-15> {local | radius | tacacs} [none] no authorization line vty command <1-15> Configure command authorization manner and authorization selection priority of login user with VTY (login with Telnet and SSH). The no command recovers to be default manner. accounting line {console | vty} command <1-15> {start-stop | stop-only | none} method1 [method2...] no accounting line {console | vty} command <1-15> Configure the accounting method list. Admin Mode terminal monitor terminal no monitor Display debug information for Telnet client login to the switch; the no command disables the debug information. show users Show the user information who logs in through telnet or ssh. It includes line number, user name and user IP. clear line vty <0-31> Delete the logged user information on the appointed line, force user to get down the line who logs in through telnet or ssh. [Table end] 2. Telnet to a remote host from the switch [Table start] Command Explanation Admin Mode telnet [vrf
] {
|
| host
} [
] Login to a remote host with the Telnet client included in the switch. [Table end] #### 1.2.2.2 SSH ##### 1.2.2.2.1 Introduction to SSH SSH (Secure Shell) is a protocol which ensures a secure remote access connection to network devices. It is based on the reliable TCP/IP protocol. By conducting the mechanism such as key distribution, authentication and encryption between SSH server and SSH client, a secure connection is established. The information transferred on this connection is protected from being intercepted and decrypted. The switch meets the requirements of SSH2.0. It supports SSH2.0 client software such as SSH Secure Client and putty. Users can run the above software to manage the switch remotely. The switch presently supports RSA authentication, 3DES cryptography protocol and SSH user password authentication etc. ##### 1.2.2.2.2 SSH Server Configuration Task List [Table start] Command Explanation Global Mode ssh-server enable no ssh-server enable Enable SSH function on the switch; the no command disables SSH function. username
[privilege
] [password [0 | 7]
] no username
Configure the username and password of SSH client software for logging on the switch; the no command deletes the username. ssh-server timeout
no ssh-server timeout Configure timeout value for SSH authentication; the no command restores the default timeout value for SSH authentication. ssh-server authentication-retires
no ssh-server authentication-retries Configure the number of times for retrying SSH authentication; the no command restores the default number of times for retrying SSH authentication. ssh-server host-key create rsa modulus
Generate the new RSA host key on the SSH server. Admin Mode terminal monitor terminal no monitor Display SSH debug information on the SSH client side; the no command stops displaying SSH debug information on the SSH client side. show crypto key Show the secret key of ssh crypto key clear rsa Clear the secret key of ssh. [Table end] ##### 1.2.2.2.3 Example of SSH Server Configuration Example1: Requirement: Enable SSH server on the switch, and run SSH2.0 client software such as Secure shell client or putty on the terminal. Log on the switch by using the username and password from the client. Configure the IP address, add SSH user and enable SSH service on the switch. SSH2.0 client can log on the switch by using the username and password to configure the switch. [Box start] Switch(config)#ssh-server enable Switch(config)#interface vlan 1 Switch(Config-if-Vlan1)#ip address 100.100.100.200 255.255.255.0 Switch(Config-if-Vlan1)#exit Switch(config)#username test privilege 15 password 0 test [Box end] In IPv6 networks, the terminal should run SSH client software which support IPv6, such as putty6. Users should not modify the configuration of the switch except allocating an IPv6 address for the local host. ### 1.2.3 Configure Switch IP Addresses All Ethernet ports of switch are default to Data Link layer ports and perform layer 2 forwarding. VLAN interface represent a Layer 3 interface function which can be assigned an IP address, which is also the IP address of the switch. All VLAN interface related configuration commands can be configured under VLAN Mode. Switch provides three IP address configuration methods: Manual BOOTP DHCP Manual configuration of IP address is assign an IP address manually for the switch. In BOOTP/DHCP mode, the switch operates as a BOOTP/DHCP client, send broadcast packets of BOOTPRequest to the BOOTP/DHCP servers, and the BOOTP/DHCP servers assign the address on receiving the request. In addition, switch can act as a DHCP server, and dynamically assign network parameters such as IP addresses, gateway addresses and DNS server addresses to DHCP clients DHCP Server configuration is detailed in later chapters. #### 1.2.3.1 Switch IP Addresses Configuration Task List 1.Enable VLAN port mode 2.Manual configuration 3.BOOTP configuration 4.DHCP configuration 1. Enable VLAN port mode [Table start] Command Explanation Global Mode interface vlan
no interface vlan
Create VLAN interface (layer 3 interface); the no command deletes the VLAN interface. [Table end] 2. Manual configuration [Table start] Command Explanation VLAN Interface Mode ip address
[secondary] no ip address
[secondary] Configure IP address of VLAN interface; the no command deletes IP address of VLAN interface. ipv6 address
[eui-64] no ipv6 address
Configure IPv6 address, including aggregation global unicast address, local site address and local link address. The no command deletes IPv6 address. [Table end] 3. BOOTP configuration [Table start] Command Explanation VLAN Interface Mode ip bootp-client enable no ip bootp-client enable Enable the switch to be a BootP client and obtain IP address and gateway address through BootP negotiation; the no command disables the BootP client function. [Table end] 4. DHCP configuration [Table start] Command Explanation VLAN Interface Mode ip dhcp-client enable no ip dhcp-client enable Enable the switch to be a DHCP client and obtain IP address and gateway address through DHCP negotiation; the no command disables the DHCP client function. [Table end] ### 1.2.4 SNMP Configuration #### 1.2.4.1 Introduction to SNMP SNMP (Simple Network Management Protocol) is a standard network management protocol widely used in computer network management. SNMP is an evolving protocol. SNMP v1 [RFC1157] is the first version of SNMP which is adapted by vast numbers of manufacturers for its simplicity and easy implementation; SNMP v2c is an enhanced version of SNMP v1, which supports layered network management; SNMP v3 strengthens the security by adding USM (User-based Security Mode) and VACM (View-based Access Control Model). SNMP protocol provides a simple way of exchange network management information between two points in the network. SNMP employs a polling mechanism of message query, and transmits messages through UDP (a connectionless transport layer protocol). Therefore it is well supported by the existing computer networks. SNMP protocol employs a station-agent mode. There are two parts in this structure: NMS (Network Management Station) and Agent. NMS is the workstation on which SNMP client program is running. It is the core on the SNMP network management. Agent is the server software runs on the devices which need to be managed. NMS manages all the managed objects through Agents. The switch supports Agent function. The communication between NMS and Agent functions in Client/Server mode by exchanging standard messages. NMS sends request and the Agent responds. There are seven types of SNMP message: Get-Request Get-Response Get-Next-Request Get-Bulk-Request Set-Request Trap Inform-Request NMS sends queries to the Agent with Get-Request, Get-Next-Request, Get-Bulk-Request and Set-Request messages; and the Agent, upon receiving the requests, replies with Get-Response message. On some special situations, like network device ports are on Up/Down status or the network topology changes, Agents can send Trap messages to NMS to inform the abnormal events. Besides, NMS can also be set to alert to some abnormal events by enabling RMON function. When alert events are triggered, Agents will send Trap messages or log the event according to the settings. Inform-Request is mainly used for inter-NMS communication in the layered network management. USM ensures the transfer security by well-designed encryption and authentication. USM encrypts the messages according to the user typed password. This mechanism ensures that the messages can't be viewed on transmission. And USM authentication ensures that the messages can't be changed on transmission. USM employs DES-CBC cryptography. And HMAC-MD5 and HMAC-SHA are used for authentication. VACM is used to classify the users' access permission. It puts the users with the same access permission in the same group. Users can't conduct the operation which is not authorized. #### 1.2.4.2 Introduction to MIB The network management information accessed by NMS is well defined and organized in a Management Information Base (MIB). MIB is pre-defined information which can be accessed by network management protocols. It is in layered and structured form. The pre-defined management information can be obtained from monitored network devices. ISO ASN.1 defines a tree structure for MID. Each MIB organizes all the available information with this tree structure. And each node on this tree contains an OID (Object Identifier) and a brief description about the node. OID is a set of integers divided by periods. It identifies the node and can be used to locate the node in a MID tree structure, shown in the figure below: @img 1-13 @fig Figure 1-13 ASN.1 Tree Instance In this figure, the OID of the object A is 1.2.1.1. NMS can locate this object through this unique OID and gets the standard variables of the object. MIB defines a set of standard variables for monitored network devices by following this structure. If the variable information of Agent MIB needs to be browsed, the MIB browse software needs to be run on the NMS. MIB in the Agent usually consists of public MIB and private MIB. The public MIB contains public network management information that can be accessed by all NMS; private MIB contains specific information which can be viewed and controlled by the support of the manufacturers. MIB-I [RFC1156] is the first implemented public MIB of SNMP, and is replaced by MIB-II [RFC1213]. MIB-II expands MIB-I and keeps the OID of MIB tree in MIB-I. MIB-II contains sub-trees which are called groups. Objects in those groups cover all the functional domains in network management. NMS obtains the network management information by visiting the MIB of SNMP Agent. The switch can operate as a SNMP Agent, and supports both SNMP v1/v2c and SNMP v3. The switch supports basic MIB-II, RMON public MIB and other public MID such as BRIDGE MIB. Besides, the switch supports self-defined private MIB. #### 1.2.4.3 Introduction to RMON RMON is the most important expansion of the standard SNMP. RMON is a set of MIB definitions, used to define standard network monitor functions and interfaces, enabling the communication between SNMP management terminals and remote monitors. RMON provides a highly efficient method to monitor actions inside the subnets. MID of RMON consists of 10 groups. The switch supports the most frequently used group 1, 2, 3 and 9: Statistics: Maintain basic usage and error statistics for each subnet monitored by the Agent. History: Record periodical statistic samples available from Statistics. Alarm: Allow management console users to set any count or integer for sample intervals and alert thresholds for RMON Agent records. Event: A list of all events generated by RMON Agent. Alarm depends on the implementation of Event. Statistics and History display some current or history subnet statistics. Alarm and Event provide a method to monitor any integer data change in the network, and provide some alerts upon abnormal events (sending Trap or record in logs). #### 1.2.4.4 SNMP Configuration ##### 1.2.4.4.1 SNMP Configuration Task List 1.Enable or disable SNMP Agent server function 2.Configure SNMP community string 3.Configure IP address of SNMP management base 4.Configure engine ID 5.Configure user 6.Configure group 7.Configure view 8.Configuring TRAP 9.Enable/Disable RMON 1. Enable or disable SNMP Agent server function [Table start] Command Explanation Global Mode snmp-server enabled no snmp-server enabled Enable the SNMP Agent function on the switch; the no command disables the SNMP Agent function on the switch. [Table end] 2. Configure SNMP community string [Table start] Command Explanation Global Mode snmp-server community {ro | rw} {0 | 7}
[access {
|
}] [ipv6-access {
|
}] [read
] [write
] no snmp-server community
[access {
|
}] [ipv6-access {
|
}] Configure the community string for the switch; the no command deletes the configured community string. [Table end] 3. Configure IP address of SNMP management station [Table start] Command Explanation Global Mode snmp-server securityip {
|
} no snmp-server securityip {
|
} Configure IPv4/IPv6 security address which is allowed to access the switch on the NMS; the no command deletes the configured security address. snmp-server securityip enable snmp-server securityip disable Enable or disable secure IP address check function on the NMS. [Table end] 4. Configure engine ID [Table start] Command Explanation Global Mode snmp-server engineid
no snmp-server engineid Configure the local engine ID on the switch. This command is used for SNMP v3. [Table end] 5. Configure user [Table start] Command Explanation Global Mode snmp-server user
[{authPriv [3des|aes|des] | authNoPriv} auth {md5 | sha}
] [access {
|
}] [ipv6-access {
|
}] no snmp-server user
[access {
|
}] [ipv6-access {
|
}] Add a user to a SNMP group. This command is used to configure USM for SNMP v3. [Table end] 6. Configure group [Table start] Command Explanation Global Mode snmp-server group
{noauthnopriv|authnopriv|authpriv} [[read
] [write
] [notify
]] [access {
|
}] [ipv6-access {
|
}] no snmp-server group
{noauthnopriv|authnopriv|authpriv} [access {
|
}] [ipv6-access {
|
}] Set the group information on the switch. This command is used to configure VACM for SNMP v3. [Table end] 7. Configure view [Table start] Command Explanation Global Mode snmp-server view
{include|exclude} no snmp-server view
[
] Configure view on the switch. This command is used for SNMP v3. [Table end] 8. Configuring TRAP [Table start] Command Explanation Global Mode snmp-server enable traps no snmp-server enable traps Enable the switch to send Trap message. This command is used for SNMP v1/v2/v3. [no] snmp-server host [
|
] [{v1 | v2c [0 | 7]} | {v3 [NoauthNopriv | AuthNopriv | AuthPriv]}]
Set the host IPv4/IPv6 address which is used to receive SNMP Trap information. For SNMP v1/v2, this command also configures Trap community string; for SNMP v3, this command also configures Trap user name and security level. The "no" form of this command cancels this IPv4 or IPv6 address. snmp-server trap-source {
|
} no snmp-server trap-source {
|
} Set the source IPv4 or IPv6 address which is used to send trap packet, the no command deletes the configuration. Port mode Port mode [no] switchport updown notification enable Enable/disable the function of sending the trap message to the port of UP/DOWN event. [Table end] 9. Enable/Disable RMON [Table start] Command Explanation Global mode rmon enable no rmon enable Enable/disable RMON. [Table end] #### 1.2.4.5 Typical SNMP Configuration Examples The IP address of the NMS is 1.1.1.5; the IP address of the switch (Agent) is 1.1.1.9. Scenario 1: The NMS network administrative software uses SNMP protocol to obtain data from the switch. The configuration on the switch is listed below: [Box start] Switch(config)#snmp-server enable Switch(config)#snmp-server community rw private Switch(config)#snmp-server community ro public Switch(config)#snmp-server securityip 1.1.1.5 [Box end] The NMS can use private as the community string to access the switch with read-write permission, or use public as the community string to access the switch with read-only permission. Scenario 2: NMS will receive Trap messages from the switch (Note: NMS may have community string verification for the Trap messages. In this scenario, the NMS uses a Trap verification community string of usertrap). The configuration on the switch is listed below: [Box start] Switch(config)#snmp-server enable Switch(config)#snmp-server host 1.1.1.5 v1 usertrap Switch(config)#snmp-server enable traps [Box end] Scenario 3: NMS uses SNMP v3 to obtain information from the switch. The configuration on the switch is listed below: [Box start] Switch(config)#snmp-server Switch(config)#snmp-server user tester UserGroup authPriv 3des 0 admin123 auth sha 0 admin123 Switch(config)#snmp-server group UserGroup AuthPriv read max write max notify max Switch(config)#snmp-server view max 1 include [Box end] Scenario 4: NMS wants to receive the v3Trap messages sent by the switch. The configuration on the switch is listed below: [Box start] Switch(config)#snmp-server enable Switch(config)#snmp-server host 10.1.1.2 v3 authpriv tester Switch(config)#snmp-server enable traps [Box end] Scenario 5: The IPv6 address of the NMS is 2004:1:2:3::2; the IPv6 address of the switch (Agent) is 2004:1:2:3::1. The NMS network administrative software uses SNMP protocol to obtain data from the switch. The configuration on the switch is listed below: [Box start] Switch(config)#snmp-server enable Switch(config)#snmp-server community rw private Switch(config)#snmp-server community ro public Switch(config)#snmp-server securityip 2004:1:2:3::2 [Box end] The NMS can use private as the community string to access the switch with read-write permission, or use public as the community string to access the switch with read-only permission. Scenario 6: NMS will receive Trap messages from the switch (Note: NMS may have community string verification for the Trap messages. In this scenario, the NMS uses a Trap verification community string of usertrap). The configuration on the switch is listed below: [Box start] Switch(config)#snmp-server host 2004:1:2:3::2 v1 usertrap Switch(config)#snmp-server enable traps [Box end] #### 1.2.4.6 SNMP Troubleshooting When users configure the SNMP, the SNMP server may fail to run properly due to physical connection failure and wrong configuration, etc. Users can troubleshoot the problems by following the guide below: 1. Good condition of the physical connection. 2. Interface and datalink layer protocol is Up (use the "show interface" command), and the connection between the switch and host can be verified by ping (use "ping" command). 3. The switch enabled SNMP Agent server function (use "snmp-server" command) 4. Secure IP for NMS (use "snmp-server securityip" command) and community string (use "snmp-server community" command) are correctly configured, as any of them fails, SNMP will not be able to communicate with NMS properly. 5. If Trap function is required, remember to enable Trap (use "snmp-server enable traps" command). And remember to properly configure the target host IP address and community string for Trap (use "snmp-server host" command) to ensure Trap message can be sent to the specified host. 6. If RMON function is required, RMON must be enabled first (use "rmon enable" command). 7. Use "show snmp" command to verify sent and received SNMP messages; Use "show snmp status" command to verify SNMP configuration information; Use "debug snmp packet" to enable SNMP debugging function and verify debug information. If users still can't solve the SNMP problems, Please contact our technical and service center. ### 1.2.5 Switch Upgrade Switch provides two ways for switch upgrade: BootROM upgrade and the TFTP/FTP upgrade under Shell. #### 1.2.5.1 Switch System Files The system files includes system image file and boot file. The updating of the switch is to update the two files by overwrite the old files with the new ones. The system image files refers to the compressed files of the switch hardware drivers, and software support program, etc, namely what we usually call the IMG update file. For this device, the system image file is saved in the MMC storage medium, with a filename typically as "nos.img". The boot file is for initiating the switch, namely what we usually call the ROM update file (It can be compressed into IMG file if it is of large size). In switch, the boot file is allowed to save in ROM only. Switch mandates the name of the boot file to be boot.rom. The update method of the system image file and the boot file is the same. The switch supplies the user with two modes of updating: 1. BootROM mode; 2. TFTP and FTP update at Shell mode. This two update method will be explained in details in following two sections. #### 1.2.5.2 BootROM Upgrade There is one method for BootROM upgrade: TFTP which can be configured at BootROM command. @img 1-14 @fig Figure 1-14 Typical topology for switch upgrade in BootROM mode The upgrade procedures are listed below: Step 1: As shown in the figure, a PC is used as the console for the switch. A console cable is used to connect PC to the management port on the switch. The PC should have TFTP server software installed and has the boot file required for the upgrade. Step 2: Press 'ctrl+b' on switch boot up until the switch enters BootROM monitor mode. The operation result is shown below: [Box start] [Boot]: [Box end] Step 3: Under BootROM mode, run 'setconfig' to set the IP address and mask of the switch under BootROM mode, server IP address and mask. Suppose the switch address is 192.168.1.2, and PC address is 192.168.1.66, and select TFTP upgrade, the configuration should like: [Box start] [Boot]: setconfig Host IP Address: [10.1.1.1] 192.168.1.2 Server IP Address: [10.1.1.2] 192.168.1.66 [Boot]: [Box end] Step 4: Enable TFTP server in the PC. run TFTP server program. Before start downloading upgrade file to the switch, verify the connectivity between the server and the switch by ping from the switch. If ping succeeds, run 'load' command in the BootROM mode from the switch; if it fails, perform troubleshooting to find out the cause. The following update file boot.rom. [Box start] [Boot]: load boot.rom TFTP from server 192.168.1.66; our IP address is 192.168.1.2 Filename 'boot.rom'. Load address: 0x300000 Loading: ################################################################# ################################ done Bytes transferred = 496240 (79270 hex) [Boot]: [Box end] Step 5: Execute write boot.rom in BootROM mode. The following saves the update file. [Box start] [Boot]: write boot.rom File exists, overwrite? (Y/N)[N] y Writing flash:/boot.rom...... Write flash:/boot.rom OK. [Boot]: [Box end] Step 6: After successful upgrade, execute run or reboot command in BootROM mode to return to CLI configuration interface. [Boot]: run(or reboot) Other commands in BootROM mode 1. DIR command Used to list existing files in the MMC. [Box start] [Boot]: dir mmc:/ 5399893 nos.img [Boot]: [Box end] #### 1.2.5.3 FTP/TFTP Upgrade ##### 1.2.5.3.1 Introduction to FTP/TFTP FTP(File Transfer Protocol)/TFTP(Trivial File Transfer Protocol) are both file transfer protocols that belonging to fourth layer(application layer) of the TCP/IP protocol stack, used for transferring files between hosts, hosts and switches. Both of them transfer files in a client-server model. Their differences are listed below. FTP builds upon TCP to provide reliable connection-oriented data stream transfer service. However, it does not provide file access authorization and uses simple authentication mechanism (transfers username and password in plain text for authentication). When using FTP to transfer files, two connections need to be established between the client and the server: a management connection and a data connection. A transfer request should be sent by the FTP client to establish management connection on port 21 in the server, and negotiate a data connection through the management connection. There are two types of data connections: active connection and passive connection. In active connection, the client transmits its address and port number for data transmission to the server, the management connection maintains until data transfer is complete. Then, using the address and port number provided by the client, the server establishes data connection on port 20 (if not engaged) to transfer data; if port 20 is engaged, the server automatically generates some other port number to establish data connection. In passive connection, the client, through management connection, notify the server to establish a passive connection. The server then creates its own data listening port and informs the client about the port, and the client establishes data connection to the specified port. As data connection is established through the specified address and port, there is a third party to provide data connection service. TFTP builds upon UDP, providing unreliable data stream transfer service with no user authentication or permission-based file access authorization. It ensures correct data transmission by sending and acknowledging mechanism and retransmission of time-out packets. The advantage of TFTP over FTP is that it is a simple and low overhead file transfer service. Switch can operate as either FTP/TFTP client or server. When switch operates as a FTP/TFTP client, configuration files or system files can be downloaded from the remote FTP/TFTP servers (can be hosts or other switches) without affecting its normal operation. And file list can also be retrieved from the server in ftp client mode. Of course, switch can also upload current configuration files or system files to the remote FTP/TFTP servers (can be hosts or other switches). When switch operates as a FTP/TFTP server, it can provide file upload and download service for authorized FTP/TFTP clients, as file list service as FTP server. Here are some terms frequently used in FTP/TFTP. ROM: Short for EPROM, erasable read-only memory. EPROM is repalced by FLASH memory in switch. SDRAM: RAM memory in the switch, used for system software operation and configuration sequence storage. MMC: Used to store system image files (e.g., nos.img), supports high-capacity read/write operations, and directly participates in device boot-up and runtime operations. Additionally, it can store configuration files. FLASH: Used to store small-volume data such as configuration files (e.g., startup.cfg) and logs, featuring power-loss protection to ensure data persistence during unexpected shutdowns. System file: including system image file and boot file. System image file: refers to the compressed file for switch hardware driver and software support program, usually refer to as IMAGE upgrade file. The system image file of the switch is usually stored in the MMC. The system image file via FTP in Global Configuration Mode, the filename is usually nos.img. other IMAGE system files will be rejected. Boot file: refers to the file initializes the switch, also referred to as the ROM upgrade file (Large size file can be compressed as IMAGE file). In switch, the boot file is allowed to save in ROM only. Switch mandates the name of the boot file to be boot.rom. Configuration file: including start up configuration file and running configuration file. The distinction between start up configuration file and running configuration file can facilitate the backup and update of the configurations. Start up configuration file: refers to the configuration sequence used in switch startup. Startup configuration file stores in nonvolatile storage, corresponding to the so-called configuration save. If the device does not support CF, the configuration file stores in FLASH or MMC only, if the device supports CF, the configuration file stores in FLASH, MMC or CF, if the device supports multi-config file, names the configuration file to be .cfg file, the default is startup.cfg. If the device does not support multi-config file, mandates the name of startup configuration file to be startup-config. Running configuration file: refers to the running configuration sequence use in the switch. In switch, the running configuration file stores in the RAM. In the current version, the running configuration sequence running-config can be saved from the RAM to FLASH by write command or copy running-config startup-config command, so that the running configuration sequence becomes the start up configuration file, which is called configuration save. To prevent illicit file upload and easier configuration, switch mandates the name of running configuration file to be running-config. Factory configuration file: The configuration file shipped with switch in the name of factory-config. Run set default and write, and restart the switch, factory configuration file will be loaded to overwrite current start up configuration file. ##### 1.2.5.3.2 FTP/TFTP Configuration The configurations of switch as FTP and TFTP clients are almost the same, so the configuration procedures for FTP and TFTP are described together in this manual. ###### 1.2.5.3.2.1 FTP/TFTP Configuration Task List 1. FTP/TFTP client configuration (1) Upload/download the configuration file or system file. (2) For FTP client, server file list can be checked. 2. FTP server configuration (1) Start FTP server (2) Configure FTP login username and password (3) Modify FTP server connection idle time (4) Shut down FTP server 3. TFTP server configuration (1) Start TFTP server (2) Configure TFTP server connection idle time (3) Configure retransmission times before timeout for packets without acknowledgement (4) Shut down TFTP server 1. FTP/TFTP client configuration (1) FTP/TFTP client upload/download file [Table start] Command Explanation Admin Mode copy
[ascii | binary] FTP/TFTP client upload/download file. [Table end] (2) For FTP client, server file list can be checked. [Table start] Admin Mode ftp-dir
For FTP client, server file list can be checked. FtpServerUrl format looks like: ftp: //user: password@IPv4|IPv6 Address. [Table end] 2. FTP server configuration (1) Start FTP server [Table start] Command Explanation Global Mode ftp-server enable no ftp-server enable Start FTP server, the no command shuts down FTP server and prevents FTP user from logging in. [Table end] (2) Configure FTP login username and password [Table start] Command Explanation Global Mode ip ftp username
password [0 | 7]
no ip ftp username
Configure FTP login username and password; this no command will delete the username and password. [Table end] (3) Modify FTP server connection idle time [Table start] Command Explanation Global Mode ftp-server timeout
Set connection idle time. [Table end] 3. TFTP server configuration (1) Start TFTP server [Table start] Command Explanation Global Mode tftp-server enable no tftp-server enable Start TFTP server, the no command shuts down TFTP server and prevents TFTP user from logging in. [Table end] (2) Modify TFTP server connection idle time [Table start] Command Explanation Global Mode tftp-server retransmission-timeout
Set maximum retransmission time within timeout interval. [Table end] (3) Modify TFTP server connection retransmission time [Table start] Command Explanation Global Mode tftp-server retransmission-number
Set the retransmission time for TFTP server. [Table end] ##### 1.2.5.3.3 FTP/TFTP Configuration Examples The configuration is same for IPv4 address or IPv6 address. The example only for IPv4 address. @img 1-15 @fig Figure 1-15 Download nos.img file as FTP/TFTP client Scenario 1: The switch is used as FTP/TFTP client. The switch connects from one of its ports to a computer, which is a FTP/TFTP server with an IP address of 10.1.1.1; the switch acts as a FTP/TFTP client, the IP address of the switch management VLAN is 10.1.1.2. Download "nos.img" file in the computer to the switch. FTP Configuration Computer side configuration: Start the FTP server software on the computer and set the username "Switch", and the password "superuser". Place the "12_30_nos.img" file to the appropriate FTP server directory on the computer. The configuration procedures of the switch are listed below: [Box start] Switch(config)#interface vlan 1 Switch(Config-if-Vlan1)#ip address 10.1.1.2 255.255.255.0 Switch(Config-if-Vlan1)#no shut Switch(Config-if-Vlan1)#exit Switch(config)#exit Switch#copy ftp: //Switch:switch@10.1.1.1/12_30_nos.img mmc:/nos.img [Box end] With the above commands, the switch will have the "nos.img" file in the computer downloaded to the MMC. TFTP Configuration Computer side configuration: Start TFTP server software on the computer and place the "12_30_nos.img" file to the appropriate TFTP server directory on the computer. The configuration procedures of the switch are listed below: [Box start] Switch(config)#interface vlan 1 Switch(Config-if-Vlan1)#ip address 10.1.1.2 255.255.255.0 Switch(Config-if-Vlan1)#no shut Switch(Config-if-Vlan1)#exit Switch(config)#exit Switch#copy tftp: //10.1.1.1/12_30_nos.img mmc:/nos.img [Box end] Scenario 2: The switch is used as FTP server. The switch operates as the FTP server and connects from one of its ports to a computer, which is a FTP client. Transfer the "nos.img" file in the switch to the computer and save as 12_25_nos.img. The configuration procedures of the switch are listed below: [Box start] Switch(config)#interface vlan 1 Switch(Config-if-Vlan1)#ip address 10.1.1.2 255.255.255.0 Switch(Config-if-Vlan1)#no shut Switch(Config-if-Vlan1)#exit Switch(config)#ftp-server enable Switch(config)#ip ftp username Switch password 0 superuser [Box end] Computer side configuration: Login to the switch with any FTP client software, with the username "Switch" and password "superuser", use the command "get mmc:/nos.img 12_25_nos.img" to download "nos.img" file from the switch to the computer. Scenario 3: The switch is used as TFTP server. The switch operates as the TFTP server and connects from one of its ports to a computer, which is a TFTP client. Transfer the "nos.img" file in the switch to the computer. The configuration procedures of the switch are listed below: [Box start] Switch(config)#interface vlan 1 Switch(Config-if-Vlan1)#ip address 10.1.1.2 255.255.255.0 Switch(Config-if-Vlan1)#no shut Switch(Config-if-Vlan1)#exit Switch(config)#tftp-server enable [Box end] Computer side configuration: Login to the switch with any TFTP client software, use the "tftp" command to download "nos.img" file from the switch to the computer. Scenario 4: Switch acts as FTP client to view file list on the FTP server. Synchronization conditions: The switch connects to a computer by an Ethernet port, the computer is a FTP server with an IP address of 10.1.1.1; the switch acts as a FTP client, and the IP address of the switch management VLAN1 interface is 10.1.1.2. FTP Configuration: PC side: Start the FTP server software on the PC and set the username "Switch", and the password "superuser". Switch: [Box start] Switch(config)#interface vlan 1 Switch(Config-if-Vlan1)#ip address 10.1.1.2 255.255.255.0 Switch(Config-if-Vlan1)#no shut Switch(Config-if-Vlan1)#exit Switch#copy ftp: //Switch: superuser@10.1.1.1 220 Serv-U FTP-Server v2.5 build 6 for WinSock ready... 331 User name okay, need password. 230 User logged in, proceed. 200 PORT Command successful. 150 Opening ASCII mode data connection for /bin/ls. recv total = 480 nos.img nos.rom parsecommandline.cpp position.doc qmdict.zip ...(some display omitted here) show.txt snmp.TXT 226 Transfer complete. [Box end] ##### 1.2.5.3.4 FTP/TFTP Troubleshooting ###### 1.2.5.3.4.1 FTP Troubleshooting When upload/download system file with FTP protocol, the connectivity of the link must be ensured, i.e., use the "Ping" command to verify the connectivity between the FTP client and server before running the FTP program. If ping fails, you will need to check for appropriate troubleshooting information to recover the link connectivity. 1. The following is what the message displays when files are successfully transferred. Otherwise, please verify link connectivity and retry "copy" command again. [Box start] 220 Serv-U FTP-Server v2.5 build 6 for WinSock ready... 331 User name okay, need password. 230 User logged in, proceed. 200 PORT Command successful. nos.img file length = 1526021 read file ok send file 150 Opening ASCII mode data connection for nos.img. 226 Transfer complete. close ftp client. [Box end] 2. The following is the message displays when files are successfully received. Otherwise, please verify link connectivity and retry "copy" command again. [Box start] 220 Serv-U FTP-Server v2.5 build 6 for WinSock ready... 331 User name okay, need password. 230 User logged in, proceed. 200 PORT Command successful. recv total = 1526037 ************************ write ok 150 Opening ASCII mode data connection for nos.img (1526037 bytes). 226 Transfer complete. [Box end] If the switch is upgrading system file or system start up file through FTP, the switch must not be restarted until "close ftp client" or "226 Transfer complete." is displayed, indicating upgrade is successful, otherwise the switch may be rendered unable to start. If the system file and system start up file upgrade through FTP fails, please try to upgrade again or use the BootROM mode to upgrade. ###### 1.2.5.3.4.2 TFTP Troubleshooting When upload/download system file with TFTP protocol, the connectivity of the link must be ensured, i.e., use the "Ping" command to verify the connectivity between the TFTP client and server before running the TFTP program. If ping fails, you will need to check for appropriate troubleshooting information to recover the link connectivity. 1. The following is the message displays when files are successfully transferred. Otherwise, please verify link connectivity and retry "copy" command again. [Box start] nos.img file length = 1526021 read file ok begin to send file, wait... file transfers complete. Close tftp client. [Box end] 2. The following is the message displays when files are successfully received. Otherwise, please verify link connectivity and retry "copy" command again. [Box start] begin to receive file, wait... recv 1526037 ************************ write ok transfer complete close tftp client. [Box end] If the switch is upgrading system file or system start up file through TFTP, the switch must not be restarted until "close tftp client" is displayed, indicating upgrade is successful, otherwise the switch may be rendered unable to start. If the system file and system start up file upgrade through TFTP fails, please try upgrade again or use the BootROM mode to upgrade. ## 1.3 File System ### 1.3.1 Introduction to File Storage Devices The switch's primary file storage medium is the MMC.The MMC is commonly used to store system image files (IMG files),FLASH is designated for storing system boot files (ROM files) and configuration files (CFG files). MMC can copy, delete, or rename files under Shell or Bootrom mode. ### 1.3.2 File System Operation Configuration Task list 1. The creation of sub-directories 2. The deletion of sub-directory 3. Changing the current working directory of the storage device 4. The display operation of the current working directory 5. The display operation of information about a designated file or directory 6. The deletion of a designated file in the file system 7. The renaming operation of files 8. The copying operation of files 1. The creation of sub-directories [Table start] Command Explanation Admin Configuration Mode mkdir
Create a sub-directory in a designated directory on a certain device. [Table end] 2. The deletion of sub-directory [Table start] Command Explanation Admin Configuration Mode rmdir
Delete a sub-directory in a designated directory on a certain device. [Table end] 3. Changing the current working directory of the storage device [Table start] Command Explanation Admin Configuration Mode cd
Change the current working directory of the storage device. [Table end] 4. The display operation of the current working directory [Table start] Command Explanation Admin Configuration Mode pwd Display the current working directory. [Table end] 5. The display operation of information about a designated file or directory [Table start] Command Explanation Admin Configuration Mode dir [
|all] Display information about a designated file or directory on the storage device. [Table end] 6. The deletion of a designated file in the file system [Table start] Command Explanation Admin Configuration Mode delete
Delete the designated file in the file system. [Table end] 7. The renaming operation of files [Table start] Command Explanation Admin Configuration Mode rename
Change the name of a designated file on the switch to a new one. [Table end] 8. The copy operation of files [Table start] Command Explanation Admin Configuration Mode copy
Copy a designated file one the switch and store it as a new one. [Table end] ### 1.3.3 Typical Applications Copy an IMG file mmc:/nos.img stored in the MMC on the boardcard, to mmc:/nos-6.1.11.0.img. The configuration of the switch is as follows: [Box start] Switch#copy mmc:/nos.img mmc:/nos-6.1.11.0.img Copy mmc:/nos.img to mmc:/nos-6.1.11.0.img? [Y:N] y Copyed file mmc:/nos.img to mmc:/nos-6.1.11.0.img. Copy an CFG file flash:/startup.cfg stored in the mmc on the boardcard, to mmc:/startup.cfg. [Box end] The configuration of the switch is as follows: [Box start] Switch#copy flash:/startup.cfg mmc:/startup.cfg Write ok. [Box end] ### 1.3.4 Troubleshooting If errors occur when users try to implement file system operations, please check whether they are caused by the following reasons 1. Whether file names or paths are entered correctly. 2. When renaming a file, whether it is in use or the new file name is already used by an existing file or directory. ## 1.4 Cluster ### 1.4.1 Introduction to cluster network management Cluster network management is an in-band configuration management. Unlike CLI, SNMP and Web Config which implement a direct management of the target switches through a management workstation, cluster network management implements a direct management of the target switches (member switches) through an intermediate switch (commander switch). A commander switch can manage multiple member switches. As soon as a Public IP address is configured in the commander switch, all the member switches which are configured with private IP addresses can be managed remotely. This feature economizes public IP addresses which are short of supply. Cluster network management can dynamically discover cluster feature enabled switches (candidate switches). Network administrators can statically or dynamically add the candidate switches to the cluster which is already established. Accordingly, they can configure and manage the member switches through the commander switch. When the member switches are distributed in various physical locations (such as on the different floors of the same building), cluster network management has obvious advantages. Moreover, cluster network management is an in-band management. The commander switch can communicate with member switches in existing network. There is no need to build a specific network for network management. Cluster network management has the following features: Save IP addresses Simplify configuration tasks Indifference to network topology and distance limitation Auto detecting and auto establishing With factory default settings, multiple switches can be managed through cluster network management The commander switch can upgrade and configure any member switches in the cluster ### 1.4.2 Cluster Network Management Configuration Sequence Cluster Network Management Configuration Sequence: 1.Enable or disable cluster function 2.Create cluster (1)Configure private IP address pool for member switches of the cluster (2)Create or delete cluster (3)Add or remove a member switch 3.Configure attributes of the cluster in the commander switch (1)Enable or disable automatically adding cluster members (2)Set automatically added members to manually added ones (3)Set or modify the time interval of keep-alive messages on switches in the cluster. (4)Set or modify the max number of lost keep-alive messages that can be tolerated (5)Clear the list of candidate switches maintained by the switch 4.Configure attributes of the cluster in the candidate switch (1))Set the time interval of keep-alive messages of the cluster (2)Set the max number of lost keep-alive messages that can be tolerated in the cluster 5.Remote cluster network management (1))Remote configuration management (2))Remotely upgrade member switch (3)Reboot member switch 6.Manage cluster network with web (1)Enable http 7.Manage cluster network with snmp (1))Enable snmp server 1. Enable or disable cluster [Table start] Command Explanation Global Mode cluster run [key
] [vid
] no cluster run Enable or disable cluster function in the switch. [Table end] 2. Create a cluster [Table start] Command Explanation Global Mode cluster ip-pool
no cluster ip-pool Configure the private IP address pool for cluster member devices. cluster commander [
] no cluster commander Create or delete a cluster. cluster member {nodes-sn
| mac-address
[id
]} no cluster member {id
| mac-address
} Add or remove a member switch. [Table end] 3. Configure attributes of the cluster in the commander switch [Table start] Command Explanation Global Mode cluster auto-add no cluster auto-add Enable or disable adding newly discovered candidate switch to the cluster. cluster member auto-to-user Change automatically added members into manually added ones. cluster keepalive interval
no cluster keepalive interval Set the keep-alive interval of the cluster. cluster keepalive loss-count
no cluster keepalive loss-count Set the max number of lost keep-alive messages that can be tolerated in the cluster. Admin mode clear cluster nodes [nodes-sn
| mac-address
] Clear nodes in the list of candidate switches maintained by the switch. [Table end] 4. Configure attributes of the cluster in the candidate switch [Table start] Command Explanation Global Mode cluster keepalive interval
no cluster keepalive interval Set the keep-alive interval of the cluster. cluster keepalive loss-count
no cluster keepalive loss-count Set the max number of lost keep-alive messages that can be tolerated in the clusters. [Table end] 5. Remote cluster network management [Table start] Command Explanation Admin Mode rcommand member
In the commander switch, this command is used to configure and manage member switches. rcommand commander In the member switch, this command is used to configure the commander switch. cluster reset member [id
| mac-address
] In the commander switch, this command is used to reset the member switch. cluster update member
[ascii | binary] In the commander switch, this command is used to remotely upgrade the member switch. It can only upgrade nos.img file. [Table end] 6. Manage cluster network with web [Table start] Command Explanation Global Mode ip http server Enable http function in commander switch and member switch. Notice: must insure the http function be enabled in member switch when commander switch visiting member switch by web. The commander switch visit member switch via beat member node in member cluster topology. [Table end] 7. Manage cluster network with snmp [Table start] Command Explanation Global Mode snmp-server enable Enable snmp server function in commander switch and member switch. Notice: must insure the snmp server function be enabled in member switch when commander switch visiting member switch by snmp. The commander switch visit member switch via configure character string
@sw
. [Table end] ### 1.4.3 Examples of Cluster Administration Scenario: The four switches SW1-SW4, amongst the SW1 is the command switch and other switches are member switch. The SW2 and SW4 is directly connected with the command switch, SW3 connects to the command switch through SW2. @img 1-16 @fig Figure 1-16 Examples of Cluster Configuration Procedure 1. Configure the command switch Configuration of SW1: [Box start] Switch(config)#cluster run Switch(config)#cluster ip-pool 10.2.3.4 Switch(config)#cluster commander 5526 Switch(config)#cluster auto-add [Box end] 2. Configure the member switch Configuration of SW2-SW4 [Box start] Switch(config)#cluster run [Box end] ### 1.4.4 Cluster Administration Troubleshooting When encountering problems in applying the cluster admin, please check the following possible causes: 1. If the command switch is correctly configured and the auto adding function (cluster auto-add) is enabled. If the ports connected the command switch and member switch belongs to the cluster vlan. 2. After cluster commander is enabled in VLAN1 of the command switch, please don't enable a routing protocol (RIP, OSPF, BGP) in this VLAN in order to prevent the routing protocol from broadcasting the private cluster addresses in this VLAN to other switches and cause routing loops. 3. Whether the connection between the command switch and the member switch is correct. We can use the debug cluster packets to check if the command and the member switches can receive and process related cluster admin packets correctly. ## 1.5 USB ### 1.5.1 Introduction When there is USB device inserted or pulled out, the switch can detect that information of USB hot inserting and pulling out and the switch will mount or uninstall the USB device. When there is USB device inserted, the switch will mount the USB file system. It can read, copy, delete, rename the files in USB, and it can also recover the configuration, download the files and save the files. This device supports the flow-passed warning function of the USB. When the actual electric current exceeds the rated current of the device, the switch will prompt user that the temperature is too high. And then, there is the danger of burning out the device if the USB is inserted. ### 1.5.2 USB Function Configuration List 1. Mount the USB device and enter in the USB letter 2. Show the USB letter information 3. Copy the source file to be the destination file 4. Delete the file content 5. Rename the file name 6. Update the config file under the USB letter to the switch 7. Update the bootrom file under the USB letter to the switch 8. Update the img file under the USB letter to the switch 9. Create the content 10. Delete the existed content 11. Uninstall the USB device 1. Mount the USB device and enter in the USB letter [Table start] Command Explanation Admin Mode cd usb: Enter in the USB letter. [Table end] 2. Show the USB letter information [Table start] Command Explanation Admin Mode dir Show the USB letter information. [Table end] 3. Copy the source file to be the destination file [Table start] Command Explanation Admin Mode copy source destination Copy the source file to be the destination file. [Table end] 4. Delete the file content [Table start] Command Explanation Admin Mode delete filename Delete the file. [Table end] 5. Rename the file name [Table start] Command Explanation Admin Mode rename source destitation Rename the source file name to be the destination file name. [Table end] 6. Update the config file under the USB letter to the switch [Table start] Command Explanation Admin Mode copy usb:/startup.cfg startup.cfg Update the config file under the USB letter to the switch. The reverse transmission is supported: copy startup.cfg usb:/startup.cfg [Table end] 7. Update the bootrom file under the USB letter to the switch [Table start] Command Explanation Admin Mode copy usb:/boot.rom boot.rom Update the bootrom file under the USB letter to the switch. The reverse transmission is supported: copy boot.rom usb:/boot.rom [Table end] 8. Update the img file under the USB letter to the switch [Table start] Command Explanation Admin Mode copy usb:/nos.img nos.img Update the img file under the USB letter to the switch. The reverse transmission is supported: copy nos.img usb:/nos.img [Table end] 9. Create the content [Table start] Command Explanation Admin Mode mkdir Create the content. [Table end] 10. Delete the existed content [Table start] Command Explanation Admin Mode rmdir Delete the existed content. [Table end] ### 1.5.3 USB Function Examples Delete source1.txt in the usb letter, and rename tt.txt in the usb letter as tttt.txt. Create the new content of sw1 in the usb letter. Switch#delete source1.txt Switch#rename usb:/tt.txt usb:/tttt.txt Switch#mkdir sw1 ### 1.5.4 USB Function Troubleshooting 1. Currently, only the USB device mounting and uninstalling under the CLI user operation page mode is supported. This command is not supported under the non-CLI user operation page mode. 2. Make sure the switch is power-on and the USB device is inserted correctly. The file content in the USB device will mount to the file system of the switch automatically. 3. For the reading and writing function of USB, the hot inserting and pulling out are not supported currently. 4. Insert the USB device, the file content will not mount to the switch file system. 5. Input dir command directly, show the file content under the flash letter as default. If user want it to show the file information of the usb, input cd usb: to enter the usb letter, and then input dir to show the file information. User can also use the absolute path and input dir usb: to show the file content. 6. This command does not support the big file showing currently. ## 1.6 Device Management ### 1.6.1 Device Management Brief The device management function of switch provides information about line card status, line card operation debugging, power supply and fan status. This function enables the maintenance and management of the physical devices and restart of the switch and line cards, and hot swapping of the cards. Switch supports dual-master mode. If 2 master management cards are present in the system, the master control board in the smaller slot number becomes the Active Master and the other board becomes the Standby Master. ### 1.6.2 Device Management Configuration #### 1.6.2.1 Monitor and Debug Task 1. Display the chip information 2. Display information of the fan status 3. Display information of the power status 1. Display the chip information [Table start] Command Explanation Admin Mode show [member
] slot
Show basic information of each chip. [Table end] 2. Display the information of the fan status [Table start] Command Explanation Admin Mode show fan Shows whether the fan tray is in place and its running status, and shows the speed of the fan. [Table end] 3. Display the information of the power status [Table start] Command Explanation Admin Mode show power Shows if the power supply is in place and its running status. [Table end] # Chapter 2 Network Security Operations Manual ## 2.1 Introduction to Network Security Features Network security refers to the ability to protect networks from attacks, intrusions, interference, damage, and unauthorized use, as well as accidents, by taking necessary measures, so that networks can operate stably and reliably, and ensure the integrity, confidentiality, availability, authenticity, and controllability of network data. It covers all aspects of computer networks, including hardware, software, data, and the overall security of the system. The importance of network security lies in the fact that it has become an important part of national security and is directly related to the stability and development of all fields such as politics, economy, culture, society, ecology, and defense. The focus of this chapter is mainly to ensure the security of passwords through encryption and the complexity of passwords, and to ensure the integrity and confidentiality of data. ## 2.2 Network Security Feature Configuration ### 2.2.1 Modification of Port Number Function Configuration Task Sequence 1.Modify the default SSH/TELNET/SNMP service port on the server side 1.Modify the default SSH/TELNET/SNMP service port on the server side [Table start] Command Explain Global configuration mode [no] ssh-server dst-port
Modify (disable) the default port number function of the SSH server. [no] telnet-server dst-port
Modify (disable) the function of the default port number of the TELNET server. [no] snmp-server dst-port
Modify (disable) the function of the default port number of the SNMP server. [Table end] ### 2.2.2 Modify the configuration task sequence of the encryption algorithm function 1.Modify the SSL encryption algorithm 1.Modify the SSH encryption algorithm [Table start] Command Explain Global configuration mode [no] ip http secure-ciphersuite{aes128-gcm-sha256 | aes128-sha | aes128-sha256 | aes256-sha | aes256-sha256 | ecdhe-rsa-aes128-gcm-sha256 | ecdhe-rsa-aes128-sha | ecdhe-rsa-aes256-sha} Enable or disable the SSL encryption algorithm. All algorithms are selected by default. [no] ssh-server encryption-algorithm {add | remove}{aes128-cbc | 3des-cbc | aes128-ctr | aes256-ctr | aes256-cbc | 3des-ctr | all} The SSH encryption algorithm component is added (removed). When the SSH encryption algorithm is deleted, only aes-128-ctr, aes-256-ctr, and 3des-ctr algorithms are available by default. [Table end] ### 2.2.3 Password security function configures task sequence 1.Cryptographic strength check 2.Password validity period 3.Error message prompt 4.Password echo 5.User forces secure input 1.Cryptographic strength check [Table start] Command Explain Global configuration mode [no] userpassword restriction {min-length <1-32> | format-mix [<2-4>] | max-consecutive-char <2-32> | max-consecutive-identical-char <2-32>} (Cancel) Configure password strength checks, which include length, type, and combination. The length is 1-32; The value can be uppercase letters, lowercase letters, digits, and special characters, including 2 to 4 types. The combination contains a maximum number of adjacent characters and a maximum number of consecutive identical characters. [Table end] 2.Password validity period [Table start] Command Explain Global configuration mode [no] service user password valid-time <0-90> Set the password validity period. no indicates that the password is valid permanently. [Table end] 3.Error message prompt [Table start] Command Explain Global configuration mode [no] user-login failed msg neutral When a user fails to log in, the prompt message does not contain the specific cause of the authentication failure, such as the incorrect password and the user does not exist. The neutral message is only displayed, and no indicates the specific content. [Table end] 4.Password echo [Table start] Command Explain Global configuration mode [no] password feedback {none | star} The default value is asterisk (*). [Table end] 5.User forces secure input [Table start] Command Explain Global configuration mode [no] userpassword security-config (Cancel) Configure mandatory user password security [Table end] ### 2.2.4 Configure the task sequence of the sensitive information encryption function 1.The encryption function was enabled 1.Configuring the encryption Mode [Table start] Command Explain Global configuration mode [no] service password-encryption Configure (disable) the trial encryption mode [no] service password-encryption type user algo {md5 | sha256 | aes [salt] | sm4 [salt]} Configure (delete) the encryption method, encryption algorithm used, and salt value [Table end] ### 2.2.5 Configure the task sequence of the important file verification function 1.The IMG and configuration file verification function was enabled [Table start] Command Explain Global configuration mode [no] boot {img | startup-config} check enable Enable or disable img verification or configuration file verification [Table end] # Chapter 3 Layer 2 services Configuration ## 3.1 Port Configuration ### 3.1.1 Introduction to Port If the user needs to configure some network ports, he/she can use the interface ethernet
command to enter the appropriate Ethernet port configuration mode, where
stands for one or more ports. If
contains multiple ports, special characters such as ';' or '-' can be used to separate ports, ';' is used for discrete port numbers and '-' is used for consecutive port numbers. Suppose an operation should be performed on ports 2,3,4,5 the command would look like: interface ethernet 1/0/2-5. Port speed, duplex mode and traffic control can be configured under Ethernet Port Mode causing the performance of the corresponding network ports to change accordingly. ### 3.1.2 Network Port Configuration Task List 1. Enter the network port configuration mode 2. Configure the properties for the network ports (1) Enable/Disable ports (2) Configure port names (3) Configure port cable types (4) Configure port speed and duplex mode (5) Configure bandwidth control (6) Configure traffic control (7) Enable/Disable port loopback function (8) Configure broadcast storm control function for the switch (9) Configure scan port mode (Global Mode) (10) Configure rate-violation control of the port (11) Configure interval of port-rate-statistics (12) Configure the port not to receive the packet 1. Enter the Ethernet port configuration mode [Table start] Command Explanation Global Mode interface ethernet
Enters the network port configuration mode. [Table end] 2. Configure the properties for the network ports [Table start] Command Explanation Port Mode shutdown no shutdown Enables/Disables specified ports. description
no description Names or cancels the name of specified ports. speed-duplex {auto [10 [100 [1000 [2500]]]] [auto | full | half] | force10-full | force100-full | force100-half | force100-fx [module-type {auto-detected | no-phy-integrated | phy-integrated}] | force1g-full | force1g-half | force2500m-full | force10g-full | force40g-full | force100g-full} no speed-duplex Sets the speed and duplex mode of Ethernet ports. Supported speed and duplex parameters depend on the interface type (such as 10/100/1000/2500M, 1G/10G/40G/100G, and 100Base-FX). The no format of this command restores the default setting, i.e., negotiates speed and duplex mode automatically. negotiation {on|off} Enables/Disables the auto-negotiation function of 1000Base-FX ports. bandwidth control
[both | receive | transmit] no bandwidth control Sets or cancels the bandwidth used for incoming/outgoing traffic for specified ports. flow control no flow control Enables/Disables traffic control function for specified ports. loopback no loopback Enables/Disables loopback test function for specified ports. storm-control {unicast | broadcast | multicast} {kbps | pps}
Enables the storm control function for broadcasts, multicasts and unicasts with unknown destinations (short for broadcast), and sets the allowed broadcast packet number or traffic; the no format of this command disables the broadcast storm control function. rate-violation all <200-148809523> no rate-violation Set the max reception rate of all packets on a port, in the range of <200-148809523>. If the received packet rate violates this rate, shut down this port. The no command will disable the rate-violation function of a port. switchport discard packet { tag | untag } no switchport discard packet { tag | untag } Configure the port not to receive the packet of tag or untag; the no command cancel the restriction of discard, it means the port is allowed to receive the packet of tag or untag. Global Mode port-scan-mode {interrupt | poll} no port-scan-mode Configure port-scan-mode as interrupt or poll mode, the no command restores the default port-scan-mode. port-rate-statistics interval
Configure the interval of port-rate-statistics. [Table end] ### 3.1.3 Port Configuration Example @img 3-1 @fig Figure 3-1 Port Configuration Example No VLAN has been configured in the switches, default VLAN1 is used. [Table start] Switch Port Property Switch1 1/0/7 Ingress bandwidth limit: 50 M Switch2 1/0/8 Mirror source port Switch2 1/0/9 100Mbps full, mirror source port Switch2 1/0/10 1000Mbps full, mirror destination port Switch3 1/0/12 100Mbps full [Table end] The configurations are listed below: Switch1: [Box start] Switch1(config)#interface ethernet 1/0/7 Switch1(Config-If-Ethernet1/0/7)#bandwidth control 50000 both [Box end] Switch2: [Box start] Switch2(config)#interface ethernet 1/0/9 Switch2(Config-If-Ethernet1/0/9)#speed-duplex force100-full Switch2(Config-If-Ethernet1/0/9)#exit Switch2(config)#interface ethernet 1/0/10 Switch2(Config-If-Ethernet1/0/10)#speed-duplex force1g-full Switch2(Config-If-Ethernet1/0/10)#exit Switch2(config)#monitor session 1 source interface ethernet 1/0/8;1/0/9 Switch2(config)#monitor session 1 destination interface ethernet 1/0/10 [Box end] Switch3: [Box start] Switch3(config)#interface ethernet 1/0/12 Switch3(Config-If-Ethernet1/0/12)#speed-duplex force100-full Switch3(Config-If-Ethernet1/0/12)#exit [Box end] ### 3.1.4 Port Troubleshooting Here are some situations that frequently occurs in port configuration and the advised solutions: 1. Two connected fiber interfaces won't link up if one interface is set to auto-negotiation but the other to forced speed/duplex. This is determined by IEEE 802.3. 2. The following combinations are not recommended: enabling traffic control as well as setting multicast limiting for the same port; setting broadcast, multicast and unknown destination unicast control as well as port bandwidth limiting for the same port. If such combinations are set, the port throughput may fall below the expected performance. 3. For Combo port, it supports the forced copper mode and the forced fiber mode (default mode), here, copper port will not be up. ## 3.2 Port Isolation ### 3.2.1 Introduction to Port Isolation Function Port isolation is an independent port-based function working in an inter-port way, which isolates flows of different ports from each other. With the help of port isolation, users can isolate ports within a VLAN to save VLAN resources and enhance network security. After this function is configured, the ports in a port isolation group will be isolated from each other, while ports belonging to different isolation groups or no such group can forward data to one another normally. No more than 30 port isolation groups can a switch have. ### 3.2.2 Task Sequence of Port Isolation 1. Create an isolate port group 2. Add Ethernet ports into the group 3. Specify the flow to be isolated 4. Display the configuration of port isolation 1. Create an isolate port group [Table start] Command Explanation Global Mode isolate-port group
no isolate-port group
Set a port isolation group; the no operation of this command will delete the port isolation group. [Table end] 2. Add Ethernet ports into the group [Table start] Command Explanation Global Mode isolate-port group
switchport interface [ethernet | port-channel]
no isolate-port group
switchport interface [ethernet | port-channel]
Add one port or a group of ports into a port isolation group to isolate, which will become isolated from the other ports in the group; the no operation of this command will remove one port or a group of ports out of a port isolation group. [Table end] 3. Specify the flow to be isolated [Table start] Command Explanation Global Mode isolate-port apply [
] Apply the port isolation configuration to isolate layer-2 flows, layer-3 flows or all flows. [Table end] 4. Display the configuration of port isolation [Table start] Command Explanation Admin Mode and global Mode show isolate-port group [
] Display the configuration of port isolation, including all configured port isolation groups and Ethernet ports in each group. [Table end] ### 3.2.3 Port Isolation Function Typical Examples @img 3-2 @fig Figure 3-2 Typical example of port isolation function The topology and configuration of switches are showed in the figure above, with e1/0/1, e1/0/10 and e1/0/15 all belonging to VLAN 100. The requirement is that, after port isolation is enabled on switch S1, e1/0/1 and e1/0/10 on switch S1 can not communicate with each other, while both of them can communicate with the uplink port e1/0/15. That is, the communication between any pair of downlink ports is disabled while that between any downlink port and a specified uplink port is normal. The uplink port can communicate with any port normally. The configuration of S1: [Box start] Switch(config)#isolate-port group test Switch(config)#isolate-port group test switchport interface ethernet 1/0/1;1/0/10 [Box end] ## 3.3 Port Loopback Detection ### 3.3.1 Introduction to Port Loopback Detection Function With the development of switches, more and more users begin to access the network through Ethernet switches. In enterprise network, users access the network through layer-2 switches, which means urgent demands for both internet and the internal layer 2 Interworking. When layer 2 Interworking is required, the messages will be forwarded through MAC addressing the accuracy of which is the key to a correct Interworking between users. In layer 2 switching, the messages are forwarded through MAC addressing. Layer 2 devices learn MAC addresses via learning source MAC address, that is, when the port receives a message from an unknown source MAC address, it will add this MAC to the receive port, so that the following messages with a destination of this MAC can be forwarded directly, which also means learn the MAC address once and for all to forward messages. When a new source MAC is already learnt by the layer 2 device, only with a different source port, the original source port will be modified to the new one, which means to correspond the original MAC address with the new port. As a result, if there is any loopback existing in the link, all MAC addresses within the whole layer 2 network will be corresponded with the port where the loopback appears (usually the MAC address will be frequently shifted from one port to another ), causing the layer 2 network collapsed. That is why it is a necessity to check port loopbacks in the network. When a loopback is detected, the detecting device should send alarms to the network management system, ensuring the network manager is able to discover, locate and solve the problem in the network and protect users from a long-lasting disconnected network. Since detecting loopbacks can make dynamic judgment of the existence of loopbacks in the link and tell whether it has gone, the devices supporting port control (such as port isolation and port MAC address learning control) can maintain that automatically, which will not only reduce the burden of network managers but also response time, minimizing the effect caused loopbacks to the network. ### 3.3.2 Port Loopback Detection Function Configuration Task List 1.Configure the time interval of loopback detection 2.Enable the function of port loopback detection 3.Configure the control method of port loopback detection 4.Display and debug the relevant information of port loopback detection 5.Configure the loopback-detection control mode (automatic recovery enabled or not) 1.Configure the time interval of loopback detection [Table start] Command Explanation Global Mode loopback-detection interval-time
no loopback-detection interval-time Configure the time interval of loopback detection. [Table end] 2.Enable the function of port loopback detection [Table start] Command Explanation Port Mode loopback-detection specified-vlan
no loopback-detection specified-vlan
Enable and disable the function of port loopback detection. [Table end] 3.Configure the control method of port loopback detection [Table start] Command Explanation Port Mode loopback-detection control {block | shutdown} no loopback-detection control Enable and disable the function of port loopback detection control. [Table end] 4.Display and debug the relevant information of port loopback detection [Table start] Command Explanation Admin Mode debug loopback-detection no debug loopback-detection Enable the debug information of the function module of port loopback detection. The no operation of this command will disable the debug information. show loopback-detection [interface
] Display the state and result of the loopback detection of all ports, if no parameter is provided; otherwise, display the state and result of the corresponding ports. [Table end] 5. Configure the loopback-detection control mode (automatic recovery enabled or not) [Table start] Command Explanation Global Mode loopback-detection control-recovery timeout <0-3600> Configure the loopback-detection control mode (automatic recovery enabled or not) or recovery time. [Table end] ### 3.3.3 Port Loopback Detection Function Example @img 3-3 @fig Figure 3-3 Typical example of port loopback detection As shown in the above configuration, the switch will detect the existence of loopbacks in the network topology. After enabling the function of loopback detection on the port connecting the switch with the outside network, the switch will notify the connected network about the existence of a loopback, and control the port on the switch to guarantee the normal operation of the whole network. The configuration task sequence of SWITCH: [Box start] Switch(config)#loopback-detection interval-time 35 15 Switch(config)#interface ethernet 1/0/1 Switch(Config-If-Ethernet1/0/1)#loopback-detection specified-vlan 1-3 Switch(Config-If-Ethernet1/0/1)#loopback-detection control block [Box end] If adopting the control method of block, MSTP should be globally enabled. And the corresponding relation between the spanning tree instance and the VLAN should be configured. [Box start] Switch(config)#spanning-tree Switch(config)#spanning-tree mst configuration Switch(Config-Mstp-Region)#instance 1 vlan 1 Switch(Config-Mstp-Region)#instance 2 vlan 2 Switch(Config-Mstp-Region)# [Box end] ### 3.3.4 Port Loopback Detection Troubleshooting The function of port loopback detection is disabled by default and should only be enabled if required. ## 3.4 ULDP ### 3.4.1 Introduction to ULDP Function Unidirectional link is a common error state of link in networks, especially in fiber links. Unidirectional link means that only one port of the link can receive messages from the other port, while the latter one can not receive messages from the former one. Since the physical layer of the link is connected and works normal, via the checking mechanism of the physical layer, communication problems between the devices can not be found. As shown in Graph, the problem in fiber connection can not be found through mechanisms in physical layer like automatic negotiation. @img 3-4 @fig Figure 3-4 Fiber Cross Connection @img 3-5 @fig Figure 3-5 One End of Each Fiber Not Connected This kind of problem often appears in the following situations: GBIC (Giga Bitrate Interface Converter) or interfaces have problems, software problems, hardware becomes unavailable or operates abnormally. Unidirectional link will cause a series of problems, such as spinning tree topological loop, broadcast black hole. ULDP (Unidirectional Link Detection Protocol) can help avoid disasters that could happen in the situations mentioned above. In a switch connected via fibers or copper Ethernet line (like ultra five-kind twisted pair), ULDP can monitor the link state of physical links. Whenever a unidirectional link is discovered, it will send warnings to users and can disable the port automatically or manually according to users' configuration. The ULDP of switches recognizes remote devices and check the correctness of link connections via interacting ULDP messages. When ULDP is enabled on a port, protocol state machine will be started, which means different types of messages will be sent at different states of the state machine to check the connection state of the link by exchanging information with remote devices. ULDP can dynamically study the interval at which the remote device sends notification messages and adjust the local TTL (time to live) according to that interval. Besides, ULDP provides the reset mechanism, when the port is disabled by ULDP, it can check again through reset mechanism. The time intervals of notification messages and reset in ULDP can be configured by users, so that ULDP can respond faster to connection errors in different network environments. The premise of ULDP working normally is that link works in duplex mode, which means ULDP is enabled on both ends of the link, using the same method of authentication and password. ### 3.4.2 ULDP Configuration Task Sequence 1. Enable ULDP function globally 2. Enable ULDP function on a port 3. Configure aggressive mode globally 4. Configure aggressive mode on a port 5. Configure the method to shut down unidirectional link 6. Configure the interval of Hello messages 7. Configure the interval of Recovery 8. Reset the port shut down by ULDP 9. Display and debug the relative information of ULDP 1. Enable ULDP function globally [Table start] Command Explanation Global configuration mode uldp enable uldp disable Globally enable or disable ULDP function. [Table end] 2. Enable ULDP function on a port [Table start] Command Explanation Port configuration mode uldp enable uldp disable Enable or disable ULDP function on a port. [Table end] 3. Configure aggressive mode globally [Table start] Command Explanation Global configuration mode uldp aggressive-mode no uldp aggressive-mode Set the global working mode. [Table end] 4. Configure aggressive mode on a port [Table start] Command Explanation Port configuration mode uldp aggressive-mode no uldp aggressive-mode Set the working mode of the port. [Table end] 5. Configure the method to shut down unidirectional link [Table start] Command Explanation Global configuration mode uldp manual-shutdown no uldp manual-shutdown Configure the method to shut down unidirectional link. [Table end] 6. Configure the interval of Hello messages [Table start] Command Explanation Global configuration mode uldp hello-interval
no uldp hello-interval Configure the interval of Hello messages, ranging from 5 to 100 seconds. The value is 10 seconds by default. [Table end] 7. Configure the interval of Recovery [Table start] Command Explanation Global configuration mode uldp recovery-time
no uldp recovery-time
Configure the interval of Recovery reset, ranging from 30 to 86400 seconds. The value is 0 second by default. [Table end] 8. Reset the port shut down by ULDP [Table start] Command Explanation Global configuration mode or port configuration mode uldp reset Reset all ports in global configuration mode; Reset the specified port in port configuration mode. [Table end] 9. Display and debug the relative information of ULDP [Table start] Command Explanation Admin mode show uldp [interface ethernet
] Display ULDP information. No parameter means to display global ULDP information. The parameter specifying a port will display global information and the neighbor information of the port. debug uldp fsm interface ethernet
no debug uldp fsm interface ethernet
Enable or disable the debug switch of the state machine transition information on the specified port. debug uldp error no debug uldp error Enable or disable the debug switch of error information. debug uldp event no debug uldp event Enable or disable the debug switch of event information. debug uldp packet {receive|send} no debug uldp packet {receive|send} Enable or disable the type of messages can be received and sent on all ports. debug uldp {hello|probe|echo| unidir|all} [receive|send] interface ethernet
no debug uldp {hello|probe|echo| unidir|all} [receive|send] interface ethernet
Enable or disable the content detail of a particular type of messages can be received and sent on the specified port. [Table end] ### 3.4.3 ULDP Function Typical Examples @img 3-6 @fig Figure 3-6 Fiber Cross Connection In the network topology in Graph, port g1/0/1 and port g1/0/2 of SWITCH A as well as port g1/0/3 and port g1/0/4 of SWITCH B are all fiber ports. And the connection is cross connection. The physical layer is connected and works normally, but the data link layer is abnormal. ULDP can discover and disable this kind of error state of link. The final result is that port g1/0/1, g1/0/2 of SWITCH A and port g1/0/3, g1/0/4 of SWITCH B are all shut down by ULDP. Only when the connection is correct, can the ports work normally (won't be shut down). Switch A configuration sequence: [Box start] SwitchA(config)#uldp enable SwitchA(config)#interface ethernet 1/0/1 SwitchA(Config-If-Ethernet1/0/1)#uldp enable SwitchA(Config-If-Ethernet1/0/1)#exit SwitchA(config)#interface ethernet 1/0/2 SwitchA(Config-If-Ethernet1/0/2)#uldp enable [Box end] Switch B configuration sequence: [Box start] SwitchB(config)#uldp enable SwitchB(config)#interface ethernet1/0/3 SwitchB(Config-If-Ethernet1/0/3)#uldp enable SwitchB(Config-If-Ethernet1/0/3)#exit SwitchB(config)#interface ethernet 1/0/4 SwitchB(Config-If-Ethernet1/0/4)#uldp enable [Box end] As a result, port g1/0/1, g1/0/2 of SWITCH A are all shut down by ULDP, and there is notification information on the CRT terminal of PC1. [Box start] %Oct 29 11:09:50 2007 A unidirectional link is detected! Port Ethernet1/0/1 need to be shutted down! %Oct 29 11:09:50 2007 Unidirectional port Ethernet1/0/1 shut down! %Oct 29 11:09:50 2007 A unidirectional link is detected! Port Ethernet1/0/2 need to be shutted down! %Oct 29 11:09:50 2007 Unidirectional port Ethernet1/0/2 shutted down! [Box end] Port g1/0/3, and port g1/0/4 of SWITCH B are all shut down by ULDP, and there is notification information on the CRT terminal of PC2. [Box start] %Oct 29 11:09:50 2007 A unidirectional link is detected! Port Ethernet1/0/3 need to be shutted down! %Oct 29 11:09:50 2007 Unidirectional port Ethernet1/0/3 shutted down! %Oct 29 11:09:50 2007 A unidirectional link is detected! Port Ethernet1/0/4 need to be shutted down! %Oct 29 11:09:50 2007 Unidirectional port Ethernet1/0/4 shutted down! [Box end] ### 3.4.4 ULDP Troubleshooting Configuration Notice: 1. In order to ensure that ULDP can discover that the one of fiber ports has not connected or the ports are incorrectly cross connected, the ports have to work in duplex mode and have the same rate. 2. If the automatic negotiation mechanism of the fiber ports with one port misconnected decides the working mode and rate of the ports, ULDP won't take effect no matter enabled or not. In such situation, the port is considered as "Down". 3. In order to make sure that neighbors can be correctly created and unidirectional links can be correctly discovered, it is required that both end of the link should enable ULDP, using the same authentication method and password. At present, no password is needed on both ends. 4. The hello interval of sending hello messages can be changed (it is10 seconds by default and ranges from 5 to 100 seconds) so that ULDP can respond faster to connection errors of links in different network environments. But this interval should be less than 1/3 of the STP convergence time. If the interval is too long, a STP loop will be generated before ULDP discovers and shuts down the unidirectional connection port. If the interval is too short, the network burden on the port will be increased, which means a reduced bandwidth. 5. ULDP does not handle any LACP event. It treats every link of TRUNK group (like Port-channel, TRUNK ports) as independent, and handles each of them respectively. 6. ULDP does not compact with similar protocols of other vendors, which means users can not use ULDP on one end and use other similar protocols on the other end. 7. ULDP function is disabled by default. After globally enabling ULDP function, the debug switch can be enabled simultaneously to check the debug information. There are several DEBUG commands provided to print debug information, such as information of events, state machine, errors and messages. Different types of message information can also be printed according to different parameters. 8. The Recovery timer is disabled by default and will only be enabled when the users have configured recovery time (30-86400 seconds). 9. Reset command and reset mechanism can only reset the ports automatically shut down by ULDP. The ports shut down manually by users or by other modules won't be reset by ULDP. ## 3.5 LLDP ### 3.5.1 Introduction to LLDP Function Link Layer Discovery Protocol (LLDP) is a new protocol defined in 802.1ab. It enables neighbor devices to send notices of their own state to other devices, and enables all ports of every device to store information about them. If necessary, the ports can also send update information to the neighbor devices directly connected to them, and those neighbor devices will store the information in standard SNMP MIBs. The network management system can check the layer-two connection state from MIB. LLDP won't configure or control network elements or flows, but only report the configuration of layer-two. Another content of 802.1ab is to utilizing the information provided by LLDP to find the conflicts in layer-two. IEEE now uses the existing physical topology, interfaces and Entity MIBs of IETF. To simplify, LLDP is a neighbor discovery protocol. It defines a standard method for Ethernet devices, such as switches, routers and WLAN access points, to enable them to notify their existence to other nodes in the network and store the discovery information of all neighbor devices. For example, the detail information of the device configuration and discovery can both use this protocol to advertise. In specific, LLDP defines a general advertisement information set, a transportation advertisement protocol and a method to store the received advertisement information. The device to advertise its own information can put multiple pieces of advertisement information in one LAN data packet to transport. The type of transportation is the type length value (TLV) field. All devices supporting LLDP have to support device ID and port ID advertisement, but it is assumed that, most devices should also support system name, system description and system performance advertisement. System name and system description advertisement can also provide useful information for collecting network flow data. System description advertisement can include data such as the full name of the advertising device, hardware type of system, the version information of software operation system and so on. 802.1AB Link Layer Discovery Protocol will make searching the problems in an enterprise network an easier process and can strengthen the ability of network management tools to discover and maintain accurate network topology structure. Many kinds of network management software use "Automated Discovery" function to trace the change and condition of topology, but most of them can reach layer-three and classify the devices into all IP subnets at best. This kind of data are very primitive, only referring to basic events like the adding and removing of relative devices instead of details about where and how these devices operate with the network. Layer 2 discovery covers information like which devices have which ports, which switches connect to other devices and so on, it can also display the routs between clients, switches, routers, application servers and network servers. Such details will be very meaningful for schedule and investigate the source of network failure. LLDP will be a very useful management tool, providing accurate information about network mirroring, flow data and searching network problems. ### 3.5.2 LLDP Function Configuration Task Sequence 1. Globally enable LLDP function 2. Configure the port-based LLDP function switch 3. Configure the operating state of port LLDP 4. Configure the intervals of LLDP updating messages 5. Configure the aging time multiplier of LLDP messages 6. Configure the sending delay of updating messages 7. Configure the intervals of sending Trap messages 8. Configure to enable the Trap function of the port 9. Configure the optional information-sending attribute of the port 10. Configure the size of space to store Remote Table of the port 11. Configure the type of operation when the Remote Table of the port is full 12. Display and debug the relative information of LLDP 1.Globally enable LLDP function [Table start] Command Explanation Global Mode lldp enable lldp disable Globally enable or disable LLDP function. [Table end] 2.Configure the port-base LLDP function switch [Table start] Command Explanation Port Mode lldp enable lldp disable Configure the port-base LLDP function switch. [Table end] 3.Configure the operating state of port LLDP [Table start] Command Explanation Port Mode lldp mode {send | receive | both | disable} Configure the operating state of port LLDP. [Table end] 4.Configure the intervals of LLDP updating messages [Table start] Command Explanation Global Mode lldp tx-interval
no lldp tx-interval Configure the intervals of LLDP updating messages as the specified value or default value. [Table end] 5.Configure the aging time multiplier of LLDP messages [Table start] Command Explanation Global Mode lldp msgTxHold
no lldp msgTxHold Configure the aging time multiplier of LLDP messages as the specified value or default value. [Table end] 6.Configure the sending delay of updating messages [Table start] Command Explanation Global Mode lldp transmit delay
no lldp transmit delay Configure the sending delay of updating messages as the specified value or default value. [Table end] 7.Configure the intervals of sending Trap messages [Table start] Command Explanation Global Mode lldp notification interval
no lldp notification interval Configure the intervals of sending Trap messages as the specified value or default value. [Table end] 8.Configure to enable the Trap function of the port [Table start] Command Explanation Port Configuration Mode lldp trap
Enable or disable the Trap function of the port. [Table end] 9.Configure the optional information-sending attribute of the port [Table start] Command Explanation Port Configuration Mode lldp transmit optional tlv [portDesc] [sysName] [sysDesc] [sysCap] no lldp transmit optional tlv Configure the optional information-sending attribute of the port as the option value of default values. [Table end] [Table start] Command Explanation Port Configuration Mode lldp management-address tlv [
] no lldp management-address tlv Configure to enable/disable the management address tlv of lldp port. [Table end] 10.Configure the size of space to store Remote Table of the port [Table start] Command Explanation Port Configuration Mode lldp neighbors max-num
no lldp neighbors max-num Configure the size of space to store Remote Table of the port as the specified value or default value. [Table end] 11.Configure the type of operation when the Remote Table of the port is full [Table start] Command Explanation Port Configuration Mode lldp tooManyNeighbors {discard | delete} Configure the type of operation when the Remote Table of the port is full. [Table end] 12.Display and debug the relative information of LLDP [Table start] Command Explanation Admin, Global Mode show lldp Display the current LLDP configuration information. show lldp interface ethernet
Display the LLDP configuration information of the current port. show lldp traffic Display the information of all kinds of counters. show lldp neighbors interface ethernet
Display the information of LLDP neighbors of the current port. show debugging lldp Display all ports with LLDP debug enabled. Admin Mode debug lldp no debug lldp Enable or disable the DEBUG switch. debug lldp packets interface ethernet
no debug lldp packets interface ethernet
Enable or disable the DEBUG packet-receiving and sending function in port or global mode. Port configuration mode clear lldp remote-table Clear Remote-table of the port. [Table end] ### 3.5.3 LLDP Function Typical Example @img 3-7 @fig Figure 3-7 LLDP Function Typical Configuration Example In the network topology graph above, the port 1,3 of SWITCH B are connected to port 2,4 of SWITCH A. Port 1 of SWITCH B is configured to message-receiving-only mode, Option TLV of port 4 of SWITCH A is configured as portDes and SysCap. SWITCH A configuration task sequence: [Box start] SwitchA(config)# lldp enable SwitchA(config)#interface ethernet 1/0/4 SwitchA(Config-If-Ethernet1/0/4)#lldp transmit optional tlv portDesc sysCap SwitchA(Config-If-Ethernet1/0/4)exit [Box end] SWITCH B configuration task sequence: [Box start] SwitchB(config)#lldp enable SwitchB(config)#interface ethernet1/0/1 SwitchB(Config-If-Ethernet1/0/1)#lldp mode receive SwitchB(Config-If-Ethernet1/0/1)#exit [Box end] ### 3.5.4 LLDP Function Troubleshooting 1. LLDP function is disabled by default. After enabling the global switch of LLDP, users can enable the debug switch "debug lldp" simultaneously to check debug information. 2. Using "show" function of LLDP function can display the configuration information in global or port configuration mode. ## 3.6 LLDP-MED ### 3.6.1 Introduction to LLDP-MED LLDP-MED (Link Layer Discovery Protocol-Media Endpoint Discovery) based on 802.1AB LLDP (Link Layer Discovery Protocol) of IEEE. LLDP provides a standard link layer discovery mode, it sends local device information (including its major capability, management IP address, device ID and port ID) as TLV (type/length/value) triplets in LLDPDU (Link Layer Discovery Protocol Data Unit) to the direct connection neighbors. The device information received by the neighbors will be stored with a standard management information base (MIB). This allows a network management system to quickly detect and identify the communication status of the link. In 802.1AB LLDP, there is no transmission and management about the voice device information. To deploy and manage voice device expediently, LLDP-MED TLVs provide multiple information, such as PoE (Power over Ethernet), network policy, and the location information of the emergent telephone service. ### 3.6.2 LLDP-MED Configuration Task Sequence 1. Basic LLDP-MED configuration [Table start] Command Explanation Port mode lldp transmit med tlv all no lldp transmit med tlv all Configure the specified port to send all LLDP-MED TLVs. The no command disables the function. lldp transmit med tlv capability no lldp transmit med tlv capability Configure the specified port to send LLDP-MED Capability TLV. The no command disables the capability. lldp transmit med tlv networkPolicy no lldp transmit med tlv networkPolicy Configure the specified port to send LLDP-MED Network Policy TLV. The no command disables the capability. lldp transmit med tlv extendPoe no lldp transmit med tlv extendPoe Configure the specified port to send LLDP-MED Extended Power-Via-MDI TLV. The no command disables the capability. lldp transmit med tlv location no lldp transmit med tlv location Configure the specified port to send LLDP-MED Location Identification TLV. The no command disables the capability. lldp transmit med tlv inventory no lldp transmit med tlv inventory Configure the port to send LLDP-MED Inventory Management TLVs. The no command disables the capability. network policy {voice | voice-signaling | guest-voice | guest-voice-signaling | softphone-voice | video-conferencing | streaming-video | video-signaling} [status {enable | disable}] [tag {tagged | untagged}] [vid {
| dot1p}] [cos
] [dscp
] no network policy {voice | voice-signaling | guest-voice | guest-voice-signaling | softphone-voice | video-conferencing | streaming- video | video-signaling} Configure network policy of the port, including VLAN ID, the supported application (such as voice and video), the application priority and the used policy, and so on. civic location {dhcp-server | switch | endpointDev}
no civic location Configure device type and country code of the location with Civic Address LCI format and enter Civic Address LCI address mode. The no command cancels all configurations of the location with Civic Address LCI format. ecs location
no ecs location Configure the location with ECS ELIN format on the port, the no command cancels the configured location. lldp med trap {enable | disable} Enable or disable LLDP-MED trap for the specified port. Civic Address LCI address mode {description-language | province-state | city | county | street | locationNum | location | floor | room | postal | otherInfo}
no {description-language | province-state | city | county | street | locationNum | location | floor | room | postal | otherInfo} Configure the detailed address after enter Civic Address LCI address mode of the port. Global mode lldp med fast count
no lldp med fast count When the fast LLDP-MED startup mechanism is enabled, it needs to fast send the LLDP packets with LLDP-MED TLV, this command is used to set the value of the fast sending packets, the no command restores the default value. Admin mode show lldp Show the configuration of the global LLDP and LLDP-MED. show lldp [interface ethernet
] Show the configuration of LLDP and LLDP-MED on the current port. show lldp neighbors [interface ethernet
] Show LLDP and LLDP-MED configuration of the neighbors. show lldp traffic Show the statistics of the sent and received packets of port LLDP and LLDP-MED. [Table end] ### 3.6.3 LLDP-MED Example @img 3-8 @fig Figure 3-8 Basic LLDP-MED configuration topology Configure Switch A [Box start] SwitchA(config)#interface ethernet1/0/1 SwitchA (Config-If-Ethernet1/0/1)# lldp enable SwitchA (Config-If-Ethernet1/0/1)# lldp mode both(this configuration can be omitted, the default mode is RxTx) SwitchA (Config-If-Ethernet1/0/1)# lldp transmit med tlv capability SwitchA (Config-If-Ethernet1/0/1)# lldp transmit med tlv networkPolicy SwitchA (Config-If-Ethernet1/0/1)# lldp transmit med tlv inventory SwitchB (Config-If-Ethernet1/0/1)# network policy voice tag tagged vid 10 cos 5 dscp 15 SwitchA (Config-If-Ethernet1/0/1)# exit SwitchA (config)#interface ethernet1/0/2 SwitchA (Config-If-Ethernet1/0/2)# lldp enable SwitchA (Config-If-Ethernet1/0/2)# lldp mode both [Box end] Configure Switch B [Box start] SwitchB (config)#interface ethernet1/0/1 SwitchB(Config-If-Ethernet1/0/1)# lldp enable SwitchB (Config-If-Ethernet1/0/1)# lldp mode both SwitchB (Config-If-Ethernet1/0/1)# lldp transmit med tlv capability SwitchB (Config-If-Ethernet1/0/1)# lldp transmit med tlv networkPolicy SwitchB (Config-If-Ethernet1/0/1)# lldp transmit med tlv inventory SwitchB (Config-If-Ethernet1/0/1)# network policy voice tag tagged vid 10 cos 4 [Box end] Verify the configuration # Show the global status and interface status on Switch A. [Box start] SwitchA# show lldp neighbors interface ethernet 1/0/1 Port name : Ethernet1/0/1 Port Remote Counter : 1 TimeMark :20 ChassisIdSubtype :4 ChassisId :00-01-01-00-00-02 PortIdSubtype :Local PortId :1 PortDesc :**** SysName :**** SysDesc :***** SysCapSupported :4 SysCapEnabled :4 LLDP MED Information : MED Codes: (CAP)Capabilities, (NP) Network Policy (LI) Location Identification, (PSE)Power Source Entity (PD) Power Device, (IN) Inventory MED Capabilities:CAP,NP,PD,IN MED Device Type: Endpoint Class III Media Policy Type :Voice Media Policy :Tagged Media Policy Vlan id :10 Media Policy Priority :3 Media Policy Dscp :5 Power Type : PD Power Source :Primary power source Power Priority :low Power Value :15.4 (Watts) Hardware Revision: Firmware Revision:4.0.1 Software Revision:6.2.30.0 Serial Number: Manufacturer Name:**** Model Name:Unknown Assert ID:Unknown IEEE 802.3 Information : auto-negotiation support: Supported auto-negotiation support: Not Enabled PMD auto-negotiation advertised capability: 1 operational MAU type: 1 SwitchA# show lldp neighbors interface ethernet 1/0/2 Port name : interface ethernet 1/0/2 Port Remote Counter:1 Neighbor Index: 1 Port name : Ethernet1/0/2 Port Remote Counter : 1 TimeMark :20 ChassisIdSubtype :4 ChassisId :00-01-01-00-00-02 PortIdSubtype :Local PortId :1 PortDesc :Ethernet1/0/1 SysName :**** SysDesc :***** SysCapSupported :4 SysCapEnabled :4 [Box end] Explanation: 1. Both Ethernet2 of switch A and Ethernet1 of switch B are the ports of network connection device, they will not send LLDP packets with MED TLV information forwardly. Although configure Ethernet1 of switch B to send MED TLV information, it will not send the related MED information, that results the corresponding Remote table without the related MDE information on Ethernet2 of switch A. 2. LLDP-MED device is able to send LLDP packets with MED TLV forwardly, so the corresponding Remote table with LLDP MED information on Ethernet1 of switch A. ### 3.6.4 LLDP-MED Troubleshooting If problems occur when configuring LLDP-MED, please check whether the problem is caused by the following reasons: 1. Check whether the global LLDP is enabled. 2. Only network connection device received LLDP packets with LLDP-MED TLV from the near MED device, it sends LLDP-MED TLV. If network connection device configured the command for sending LLDP-MED TLV, the packets also without LLDP-MED TLV sent by the port, that means no MED information is received and the port does not enable the function for sending LLDP-MED information. 3. If neighbor device has sent LLDP-MED information to network connection device, but there is no LLDP-MED information by checking show lldp neighbors command, that means LLDP-MED information sent by neighbor is error. ## 3.7 Port Channel ### 3.7.1 Introduction to Port Channel To understand Port Channel, Port Group should be introduced first. Port Group is a group of physical ports in the configuration level; only physical ports in the Port Group can take part in link aggregation and become a member port of a Port Channel. Logically, Port Group is not a port but a port sequence. Under certain conditions, physical ports in a Port Group perform port aggregation to form a Port Channel that has all the properties of a logical port, therefore it becomes an independent logical port. Port aggregation is a process of logical abstraction to abstract a set of ports (port sequence) with the same properties to a logical port. Port Channel is a collection of physical ports and used logically as one physical port. Port Channel can be used as a normal port by the user, and can not only add network's bandwidth, but also provide link backup. Port aggregation is usually used when the switch is connected to routers, PCs or other switches. @img 3-9 @fig Figure 3-9 Port aggregation As shown in the above, S1 is aggregated to a Port Channel, the bandwidth of this Port Channel is the total of all the four ports. If traffic from S1 needs to be transferred to S2 through the Port Channel, traffic allocation calculation will be performed based on the source MAC address and the lowest bit of target MAC address. The calculation result will decide which port to convey the traffic. If a port in Port Channel fails, the other ports will undertake traffic of that port through a traffic allocation algorithm. This algorithm is carried out by the hardware. Switch offers two methods for configuring port aggregation: manual Port Channel creation and LACP (Link Aggregation Control Protocol) dynamic Port Channel creation. Port aggregation can only be performed on ports in full-duplex mode. For Port Channel to work properly, member ports of the Port Channel must have the same properties as follows: 1. All ports are in full-duplex mode. 2. All Ports are of the same speed. 3. All ports are Access ports and belong to the same VLAN or are all TRUNK ports, or are all Hybrid ports. 4. If the ports are all TRUNK ports or Hybrid ports, then their "Allowed VLAN" and "Native VLAN" property should also be the same. If Port Channel is configured manually or dynamically on switch, the system will automatically set the port with the smallest number to be Master Port of the Port Channel. If the spanning tree function is enabled in the switch, the spanning tree protocol will regard Port Channel as a logical port and send BPDU frames via the master port. Port aggregation is closely related with switch hardware. Switch allow physical port aggregation of any two switches, maximum 128 groups and 8 ports in each port group are supported. Once ports are aggregated, they can be used as a normal port. Switch have a built-in aggregation interface configuration mode, the user can perform related configuration in this mode just like in the VLAN and physical interface configuration mode. ### 3.7.2 Brief Introduction to LACP LACP (Link Aggregation Control Protocol) is a kind of protocol based on IEEE802.3ad standard to implement the link dynamic aggregation. LACP protocol uses LACPDU (Link Aggregation Control Protocol Data Unit) to exchange the information with the other end. After LACP protocol of the port is enabled, this port will send LACPDU to the other end to notify the system priority, the MAC address of the system, the priority of the port, the port ID and the operation Key. After the other end receives the information, the information is compared with the saving information of other ports to select the port which can be aggregated, accordingly, both sides can reach an agreement about the ports join or exit the dynamic aggregation group. The operation Key is created by LACP protocol according to the combination of configuration (speed, duplex, basic configuration, management Key) of the ports to be aggregated. After the dynamic aggregation port enables LACP protocol, the management Key is 0 by default. After the static aggregation port enables LACP, the management Key of the port is the same with the ID of the aggregation group. For the dynamic aggregation group, the members of the same group have the same operation Key, for the static aggregation group, the ports of Active have the same operation Key. The port aggregation is that multi-ports are aggregated to form an aggregation group, so as to implement the out/in load balance in each member port of the aggregation group and provides the better reliability. #### 3.7.2.1 Static LACP Aggregation Static LACP aggregation is enforced by users configuration, and do not enable LACP protocol. When configuring static LACP aggregation, use "on" mode to force the port to enter the aggregation group. #### 3.7.2.2 Dynamic LACP Aggregation 1. The summary of the dynamic LACP aggregation Dynamic LACP aggregation is an aggregation created/deleted by the system automatically, it does not allow the user to add or delete the member ports of the dynamic LACP aggregation. The ports which have the same attribute of speed and duplex, are connected to the same device, have the same basic configuration, can be dynamically aggregated together. Even if only one port can create the dynamic aggregation, that is the single port aggregation. In the dynamic aggregation, LACP protocol of the port is at the enable state. 2. The port state of the dynamic aggregation group In dynamic aggregation group, the ports have two states: selected or standby. Both selected ports and standby ports can receive and send LACP protocol, but standby ports can not forward the data packets. Because the limitation of the max port number in the aggregation group, if the current number of the member ports exceeds the limitation of the max port number, then the system of this end will negotiates with the other end to decide the port state according to the port ID. The negotiation steps are as follows: Compare ID of the devices (the priority of the system + the MAC address of the system). First, compare the priority of the systems, if they are same, then compare the MAC address of the systems. The end with a small device ID has the high priority. Compare the ID of the ports (the priority of the port + the ID of the port). For each port in the side of the device which has the high device priority, first, compare the priority of the ports, if the priorities are same, then compare the ID of the ports. The port with a small port ID is selected, and the others become the standby ports. In an aggregation group, the port which has the smallest port ID and is at the selected state will be the master port, the other ports at the selected state will be the member port. ### 3.7.3 Introduction to Load balance The current visits and data flow of the network are increasing; the processing capability and calculated strength are both increasing. If the large amount of the data flow is transmitted from one physical port of the switch at the same, it will cause the network congestion. If there are many physical ports of the switch, it will cause the ports wasting. So there is a method which can expand the network device and server bandwidth, increase the throughout, improve the network flexibility and strengthen the data processing, it is Load Balance. ### 3.7.4 Port Channel Configuration Task List 1. Create a port group in Global Mode 2. Add ports to the specified group from the Port Mode of respective ports 3. Enter port-channel configuration mode 4. Set load-balance method for switch 5. Set the system priority of LACP protocol 6. Set the port priority of the current port in LACP protocol 7. Set the timeout mode of the current port in LACP protocol 1. Creating a port group [Table start] Command Explanation Global Mode port-group
no port-group
Create or delete a port group. [Table end] 2. Add physical ports to the port group [Table start] Command Explanation Port Mode port-group
mode {active | passive | on} no port-group Add the ports to the port group and set their mode. [Table end] 3. Enter port-channel configuration mode. [Table start] Command Explanation Global Mode interface port-channel
Enter port-channel configuration mode. [Table end] 4. Set load-balance method for switch [Table start] Command Explanation Global configuration mode load-balance {dst-src-mac | dst-src-ip | dst-src-mac-ip} Set load-balance for switch, it takes effect on port-group and ECMP function at the same time. [Table end] 5. Set the system priority of LACP protocol [Table start] Command Explanation Global mode lacp system-priority
no lacp system-priority Set the system priority of LACP protocol, the no command restores the default value. [Table end] 6. Set the port priority of the current port in LACP protocol [Table start] Command Explanation Port mode lacp port-priority
no lacp port-priority Set the port priority in LACP protocol. The no command restores the default value. [Table end] 7. Set the timeout mode of the current port in LACP protocol [Table start] Command Explanation Port mode lacp timeout {short | long} no lacp timeout Set the timeout mode in LACP protocol. The no command restores the default value. [Table end] ### 3.7.5 Port Channel Examples Scenario 1: Configuring Port Channel in LACP. @img 3-10 @fig Figure 3-10 Configure Port Channel in LACP The switches in the description below are all switch and as shown in the figure, ports 1, 2, 3, 4 of S1 are access ports and add them to group1 with active mode. Ports 6, 8, 9, 10 of S2 are access ports and add them to group2 with passive mode. All the ports should be connected with cables. The configuration steps are listed below: [Box start] Switch1#config Switch1(config)#interface ethernet 1/0/1-4 Switch1(Config-If-Port-Range)#port-group 1 mode active Switch1(Config-If-Port-Range)#exit Switch1(config)#interface port-channel 1 Switch1(Config-If-Port-Channel1)# Switch2#config Switch2(config)#port-group 2 Switch2(config)#interface ethernet 1/0/6 Switch2(Config-If-Ethernet1/0/6)#port-group 2 mode passive Switch2(Config-If-Ethernet1/0/6)#exit Switch2(config)#interface ethernet 1/0/8-10 Switch2(Config-If-Port-Range)#port-group 2 mode passive Switch2(Config-If-Port-Range)#exit Switch2(config)#interface port-channel 2 Switch2(Config-If-Port-Channel2)# [Box end] Configuration result: Shell prompts ports aggregated successfully after a while, now ports 1, 2, 3, 4 of S1 form an aggregated port named "Port-Channel1", ports 6, 8, 9, 10 of S2 form an aggregated port named "Port-Channel2"; can be configured in their respective aggregated port mode. Scenario 2: Configuring Port Channel in ON mode. @img 3-11 @fig Figure 3-11 Configure Port Channel in ON mode As shown in the figure, ports 1, 2, 3, 4 of S1 are access ports and add them to group1 with "on" mode. Ports 6, 8, 9, 10 of S2 are access ports and add them to group2 with "on" mode. The configuration steps are listed below: [Box start] Switch1#config Switch1(config)#interface ethernet 1/0/1 Switch1(Config-If-Ethernet1/0/1)#port-group 1 mode on Switch1(Config-If-Ethernet1/0/1)#exit Switch1(config)#interface ethernet 1/0/2 Switch1 (Config-If-Ethernet1/0/2)#port-group 1 mode on Switch1 (Config-If-Ethernet1/0/2)#exit Switch1 (config)#interface ethernet 1/0/3 Switch1 (Config-If-Ethernet1/0/3)#port-group 1 mode on Switch1 (Config-If-Ethernet1/0/3)#exit Switch1 (config)#interface ethernet 1/0/4 Switch1 (Config-If-Ethernet1/0/4)#port-group 1 mode on Switch1 (Config-If-Ethernet1/0/4)#exit Switch2#config Switch2(config)#port-group 2 Switch2(config)#interface ethernet 1/0/6 Switch2 (Config-If-Ethernet1/0/6)#port-group 2 mode on Switch2 (Config-If-Ethernet1/0/6)#exit Switch2 (config)#interface ethernet 1/0/8-10 Switch2(Config-If-Port-Range)#port-group 2 mode on Switch2(Config-If-Port-Range)#exit [Box end] Configuration result: Add ports 1, 2, 3, 4 of S1 to port-group1 in order, and we can see a group in 'on' mode is completely joined forcedly, switch in other ends won't exchange LACP PDU to complete aggregation. Aggregation finishes immediately when the command to add port 1/0/2 to port-group 1 is entered, port 1 and port 2 aggregate to be port-channel 1, when port 1/0/3 joins port-group 1, port-channel 1 of port 1 and 2 are ungrouped and re-aggregate with port 3 to form port-channel 1, when port 1/0/4 joins port-group 1, port-channel 1 of port 1, 2 and 3 are ungrouped and re-aggregate with port 4 to form port-channel 1. (It should be noted that whenever a new port joins in an aggregated port group, the group will be ungrouped first and re-aggregated to form a new group.) Now all four ports in both S1 and S2 are aggregated in 'on' mode and become an aggregated port respectively. ### 3.7.6 Troubleshooting #### 3.7.6.1 Port Channel Troubleshooting If problems occur when configuring port aggregation, please first check the following for causes. 1. Ensure all ports in a port group have the same properties, i.e., whether they are in full-duplex mode, forced to the same speed, and have the same VLAN properties, etc. If inconsistency occurs, make corrections. 2. Some commands cannot be used on a port in port-channel, such as arp, bandwidth, ip, ip-forward, etc. #### 3.7.6.2 Load Balance Troubleshooting None ## 3.8 MTU ### 3.8.1 Introduction to MTU So far the Jumbo (Jumbo Frame) has not reach a determined standard in the industry (including the format and length of the frame). Normally frames sized within 1519-12000 should be considered jumbo frame. Networks with jumbo frames will increase the speed of the whole network by 2% to 5%. Technically the Jumbo is just a lengthened frame sent and received by the switch. However considering the length of Jumbo frames, they will not be sent to CPU. We discard the Jumbo frames sent to CPU in the packet receiving process. ### 3.8.2 MTU Configuration Task Sequence 1. Configure enable MTU function [Table start] Command Explanation Global Mode mtu [
] no mtu enable Enable the receiving/sending function of MTU frame. The no command disables sending and receiving function of MTU frames. [Table end] ## 3.9 bpdu-tunnel ### 3.9.1 Introduction to bpdu-tunnel BPDU Tunnel is a Layer 2 tunnel technology. It allows Layer 2 protocol packets of geographically dispersed private network users to be transparently transmitted over specific tunnels across a service provider network. #### 3.9.1.1 bpdu-tunnel function In MAN application, multi-branches of a corporation may connect with each other by the service provider network. VPN provided by the service provider enables the geographically dispersed networks to form a local LAN, so the service provider needs to provide the tunnel function, namely, data information generated by user's network is able to inextenso arrive at other networks of the same corporation through the service provider network. To maintain a local concept, it not only needs to transmit the data within the user's private network across the tunnel, but also transmit layer 2 protocol packets within the user's private network. #### 3.9.1.2 Background of bpdu-tunnel Special lines are used in a service provider network to build user-specific Layer 2 networks. As a result, a user network is broken down into parts located at different sides of the service provider network. As shown in Figure, User A has two devices (CE 1 and CE 2) and both devices belong to the same VLAN. User's network is divided into network 1 and network 2, which are connected by the service provider network. When Layer 2 protocol packets cannot implement the passthrough across the service provider network, the user's network cannot process independent Layer 2 protocol calculation (for example, spanning tree calculation), so they affect each other. @img 3-12 @fig Figure 3-12 BPDU Tunnel application ### 3.9.2 bpdu-tunnel Configuration Task List bpdu-tunnel configuration task list: 1. Configure tunnel protocol globally 2. Configure the port to support the tunnel 1. Configure tunnel protocol globally [Table start] Command Explanation Global mode bpdu-tunnel-protocol {stp | gvrp | dot1x} {group-mac
| default-group-mac} no bpdu-tunnel-protocol {stp | gvrp | dot1x} Register the tunnel protocol and specify the group MAC. default-group-mac uses the default group MAC. [Table end] 2. Configure the port to support the tunnel [Table start] Command Explanation Port mode bpdu-tunnel-protocol {dot1x | gvrp | stp | user-defined-protocol
} no bpdu-tunnel-protocol {dot1x | gvrp | stp | user-defined-protocol
} Enable the port to support the tunnel, the no command disables the function. [Table end] ### 3.9.3 Examples of bpdu-tunnel Special lines are used in a service provider network to build user-specific Layer 2 networks. As a result, a user network is broken down into parts located at different sides of the service provider network. As shown in Figure, User A has two devices (CE 1 and CE 2) and both devices belong to the same VLAN. User's network is divided into network 1 and network 2, which are connected by the service provider network. When Layer 2 protocol packets cannot implement the passthrough across the service provider network, the user's network cannot process independent Layer 2 protocol calculation (for example, spanning tree calculation), so they affect each other. @img 3-13 @fig Figure 3-13 BPDU Tunnel application environment With BPDU Tunnel, Layer 2 protocol packets from user's networks can be passed through over the service provider network in the following work flow: 1. After receiving a Layer 2 protocol packet from network 1 of user A, PE 1 in the service provider network encapsulates the packet, replaces its destination MAC address with a specific multicast MAC address, and then forwards the packet in the service provider network. 2. The encapsulated Layer 2 protocol packet (called BPDU Tunnel packet) is forwarded to PE 2 at the other end of the service provider network, which de-encapsulates the packet, restores the original destination MAC address of the packet, and then sends the packet to network 2 of user A. bpdu-tunnel configuration of edge switches PE1 and PE2 in the following: PE1 configuration: [Box start] PE1(config)# bpdu-tunnel-protocol stp default-group-mac PE1(config-if-ethernet1/0/1)# bpdu-tunnel-protocol stp [Box end] PE2 configuration: [Box start] PE2(config)# bpdu-tunnel-protocol stp default-group-mac PE2(config-if-ethernet1/0/1)# bpdu-tunnel-protocol stp [Box end] ### 3.9.4 bpdu-tunnel Troubleshooting The port cannot be configured with bpdu-tunnel when stp, gvrp, or dot1x is enabled on it. Disable these functions on the port first before configuring bpdu-tunnel. ## 3.10 DDM ### 3.10.1 Introduction to DDM #### 3.10.1.1 Brief Introduction to DDM DDM (Digital Diagnostic Monitor) makes the detailed digital diagnostic function standard in SFF-8472 MSA. It set that the parameter signal is monitored and make it to digitize on the circuit board of the inner module. After that, providing the demarcated result or the digitize measure result and the demarcate parameter which are saved in the standard memory framework, so as to expediently read by serial interface with double cables. Normally, intelligent fiber modules support Digital Diagnostic function. Network management units is able to monitor the parameters (temperature, voltage, bias current, tx power and rx power) of the fiber module to obtain theirs thresholds and the real-time state of the current fiber module by the inner MCU of the fiber module. That is able to help the network management units to locate the fault in the fiber link, reduce the maintenance workload and enhance the system reliability. DDM applications are shown in the following: 1. Module lifetime forecast Monitoring the bias current is able to forecast the laser lifetime. Administrator is able to find some potential problems by monitoring voltage and temperature of the module. (1) High Vcc voltage will result in the breakdown CMOS, low Vcc voltage will result in the abnormity work. (2) High rx power will damage the receiving module, low rx power will result that the receiving module cannot work normally. (3) High temperature will result in the fast aging of the hardware. (4) Monitoring the received fiber power to monitor the capability of the link and the remote switch. 2. Fault location In fiber link, locating the fault is important to the fast overload of the service, fault isolation is able to help administrator to fast locate the location of the link fault within the module (local module or remote module) or on the link, it also reduce the time for restoring the fault of the system. Analyzing warning and alarm status of real-time parameters (temperature, voltage, bias current, tx power and rx power) can fast locate the fault through Digital Diagnostic function. Besides, the state of Tx Fault and Rx LOS is important for analyzing the fault. 3. Compatibility verification Compatibility verification is used to analyze whether the environment of the module accords the data manual or it is compatible with the corresponding standard, because the module capability is able to be ensured only in the compatible environment. Sometimes, environment parameters exceed the data manual or the corresponding standard, it will make the falling of the module capability that result in the transmission error. Environment is not compatible with the module are as below: (1) Voltage exceeds the set range (2) Rx power is overload or is under the sensitivity of the transceiver (3) Temperature exceeds the range of the running temperature #### 3.10.1.2 DDM Function DDM descriptions are shown in the following: 1. Show the monitoring information of the transceiver Administrator is able to know the current working state of the transceiver and find some potential problems through checking the real-time parameters (including TX power, RX power, Temperature, Voltage, Bias current) and querying the monitoring information (such as warning, alarm, real-time state and threshold, and so on). Besides, checking the fault information of the fiber module helps administrator to fast locate the link fault and saves the restored time. 2. Threshold defined by the user For real-time parameters (TX power, RX power, Temperature, Voltage, Bias current), there are fixed thresholds. Because the user's environments are difference, the users is able to define the threshold (including high alarm, low alarm, high warn, low warn) to flexibly monitor the working state of the transceiver and find the fault directly. The thresholds configured by the user and the manufacturer can be shown at the same time. When the threshold defined by the user is irrational, it will prompt the user and automatically process alarm or warning according to the default threshold. (the user is able to restore all thresholds to the default thresholds or restore a threshold to the default threshold) Threshold rationality: high/low warn should be between high alarm and low alarm and high threshold should be higher than low threshold, namely, high alarm>= high warn>= low warn>= low alarm. For fiber module, verification mode of the receiving power includes inner verification and outer verification which are decided by the manufacturer. Besides the verification mode of the real-time parameters and the default thresholds are same. 3. Transceiver monitoring Besides checking the real-time working state of the transceiver, the user needs to monitor the detailed status, such as the former abnormity time and the abnormity type. Transceiver monitoring helps the user to find the former abnormity status through checking the log and query the last abnormity status through executing the commands. When the user finds the abnormity information of the fiber module, the fiber module information may be remonitored after processing the abnormity information, here, the user is able to know the abnormity information and renew the monitoring. ### 3.10.2 DDM Configuration Task List DDM configuration task list: 1. Show the real-time monitoring information of the transceiver 2. Configure the alarm or warning thresholds of each parameter for the transceiver 3. Configure the state of the transceiver monitoring (1) Configure the interval of the transceiver monitoring (2) Configure the enable state of the transceiver monitoring (3) Show the information of the transceiver monitoring (4) Clear the information of the transceiver monitoring 1. Show the real-time monitoring information of the transceiver [Table start] Command Explanation User mode, admin mode and global mode show transceiver [interface ethernet
][detail] Show the monitoring of the transceiver. [Table end] 2. Configure the alarm or warning thresholds of each parameter for the transceiver [Table start] Command Explanation Port mode transceiver threshold {default | {temperature | voltage | bias | rx-power | tx-power} {high-alarm | low-alarm | high-warn | low-warn} {
| default}} Set the threshold defined by the user. [Table end] 3. Configure the state of the transceiver monitoring (1) Configure the interval of the transceiver monitoring [Table start] Command Explanation Global mode transceiver-monitoring interval
no transceiver-monitoring interval Set the interval of the transceiver monitor. The no command sets the interval to be the default interval of 15 minutes. [Table end] (2) Configure the enable state of the transceiver monitoring [Table start] Command Explanation Port mode transceiver-monitoring {enable | disable} Set whether the transceiver monitoring is enabled. Only the port enables the transceiver monitoring, the system records the abnormity state. After the port disables the function, the abnormity information will be clear. [Table end] (3) Show the information of the transceiver monitoring [Table start] Command Explanation Admin mode and global mode show transceiver threshold-violation [interface ethernet
] Show the information of the transceiver monitoring, including the last threshold-violation informatijon, the interval of the current transceiver monitoring and whether the port enables the transceiver monitoring. [Table end] (4) Clear the information of the transceiver monitoring [Table start] Command Explanation Admin mode clear transceiver threshold-violation [interface ethernet
] Clear the threshold violation of the transceiver monitor. [Table end] ### 3.10.3 Examples of DDM Example1: Ethernet 21 and Ethernet 23 are inserted the fiber module with DDM, Ethernet 24 is inserted the fiber module without DDM, Ethernet 22 does not insert any fiber module, show the DDM information of the fiber module. a,Show the information of all interfaces which can read the real-time parameters normally,(No fiber module is inserted or the fiber module is not supported, the information will not be shown), for example: [Box start] Switch#show transceiver Interface Temp( deg C) Voltage(V) Bias(mA) RX Power(dBM) TX Power(dBM) 1/0/21 33 3.31 6.11 -30.54(A-) -6.01 1/0/23 33 5.00(W+) 6.11 -20.54(W-) -6.02 [Box end] b,Show the information of the specified interface. (N/A means no fiber module is inserted or does not support the fiber module), for example: [Box start] Switch#show transceiver interface ethernet 1/0/21-22;23 Interface Temp( deg C) Voltage(V) Bias(mA) RX Power(dBM) TX Power(dBM) 1/0/21 33 3.31 6.11 -30.54(A-) -6.01 1/0/22 N/A N/A N/A N/A N/A 1/0/23 33 5.00(W+) 6.11 -20.54(W-) -6.02 [Box end] c,Show the detailed information, including base information, parameter value of the real-time monitoring, warning, alarm, abnormity state, threshold information and the serial number, for example: [Box start] Switch#show transceiver interface ethernet 1/0/21-22;24 detail Ethernet 1/0/21 transceiver detail information: Base information: SFP found in this port, manufactured by company, on Sep 29 2010. Type is 1000BASE-SX. Serial Number is 1108000001. Link length is 550 m for 50um Multi-Mode Fiber. Link length is 270 m for 62.5um Multi-Mode Fiber. Nominal bit rate is 1300 Mb/s, Laser wavelength is 850 nm. Brief alarm information: RX loss of signal Voltage high RX power low Detail diagnostic and threshold information: Diagnostic Threshold Realtime Value High Alarm Low Alarm High Warn Low Warn -------------- ----------- ----------- ------------ --------- Temperature(C) 33 70 0 70 0 Voltage(V) 7.31(A+) 5.00 0.00 5.00 0.00 Bias current(mA) 6.11(W+) 10.30 0.00 5.00 0.00 RX Power(dBM) -30.54(A-) 9.00 -25.00 9.00 -25.00 TX Power(dBM) -6.01 9.00 -25.00 9.00 -25.00 Ethernet 1/0/22 transceiver detail information: N/A Ethernet 1/0/24 transceiver detail information: Base information: SFP found in this port, manufactured by company, on Sep 29 2010. Type is 1000BASE-SX. Serial Number is 1108000001. Link length is 550 m for 50um Multi-Mode Fiber. Link length is 270 m for 62.5um Multi-Mode Fiber. Nominal bit rate is 1300 Mb/s, Laser wavelength is 850 nm. Brief alarm information: N/A Detail diagnostic and threshold information: N/A [Box end] Explanation: If the serial number is 0, it means that it is not specified as bellow: [Box start] SFP found in this port, manufactured by company, on Sep 29 2010. Type is 1000BASE-SX. Serial Number is not specified. Link length is 550 m for 50um Multi-Mode Fiber. Link length is 270 m for 62.5um Multi-Mode Fiber. Nominal bit rate is 1300 Mb/s, Laser wavelength is 850 nm. [Box end] Example2: Ethernet 21 is inserted the fiber module with DDM. Configure the threshold of the fiber module after showing the DDM information. Step1: Show the detailed DDM information. [Box start] Switch#show transceiver interface ethernet 1/0/21 detail Ethernet 1/0/21 transceiver detail information: Base information: ...... Brief alarm information: RX loss of signal Voltage high RX power low Detail diagnostic and threshold information: Diagnostic Threshold Realtime Value High Alarm Low Alarm High Warn Low Warn -------------- ----------- ----------- ------------ --------- Temperature(C) 33 70 0 70 0 Voltage(V) 7.31(A+) 5.00 0.00 5.00 0.00 Bias current(mA) 6.11(W+) 10.30 0.00 5.00 0.00 RX Power(dBM) -30.54(A-) 9.00 -25.00 9.00 -25.00 TX Power(dBM) -13.01 9.00 -25.00 9.00 -25.00 [Box end] Step2: Configure the tx-power threshold of the fiber module, the low-warn threshold is -12, the low-alarm threshold is -10.00. [Box start] Switch#config Switch(config)#interface ethernet 1/0/21 Switch(config-if-ethernet1/0/21)#transceiver threshold tx-power low-warn -12 Switch(config-if-ethernet1/0/21)#transceiver threshold tx-power low-alarm -10.00 [Box end] Step3: Show the detailed DDM information of the fiber module. The alarm uses the threshold configured by the user, the threshold configured by the manufacturer is labeled with the bracket. There is the alarm with 'A-' due to -13.01 is less than -12.00. [Box start] Switch#show transceiver interface ethernet 1/0/21 detail Ethernet 1/0/21 transceiver detail information: Base information: ...... Brief alarm information: RX loss of signal Voltage high RX power low TX power low Detail diagnostic and threshold information: Diagnostic Threshold Realtime Value High Alarm Low Alarm High Warn Low Warn -------------- ----------- ----------- ---------- --------- Temperature(C) 33 70 0 70 0 Voltage(V) 7.31(A+) 5.00 0.00 5.00 0.00 Bias current(mA) 6.11(W+) 10.30 0.00 5.00 0.00 RX Power(dBM) -30.54(A-) 9.00 -25.00 9.00 -25.00 TX Power(dBM) -13.01(A-) 9.00 -12.00(-25.00) 9.00 -10.00(-25.00) [Box end] Example3: Ethernet 21 is inserted the fiber module with DDM. Enable the transceiver monitoring of the port after showing the transceiver monitoring of the fiber module. Step1: Show the transceiver monitoring of the fiber module. Both ethernet 21 and ethernet 22 do not enable the transceiver monitoring, its interval is set to 30 minutes. [Box start] Switch(config)#show transceiver threshold-violation interface ethernet 1/0/21-22 Ethernet 1/0/21 transceiver threshold-violation information: Transceiver monitor is disabled. Monitor interval is set to 30 minutes. The last threshold-violation doesn't exist. Ethernet 1/0/22 transceiver threshold-violation information: Transceiver monitor is disabled. Monitor interval is set to 30 minutes. The last threshold-violation doesn't exist. [Box end] Step2: Enable the transceiver monitoring of ethernet 21. [Box start] Switch(config)#interface ethernet 1/0/21 Switch(config-if-ethernet1/0/21)#transceiver-monitoring enable [Box end] Step3: Show the transceiver monitoring of the fiber module. In the following configuration, ethernet 21 enabled the transceiver monitoring, the last threshold-violation time is Jan 02 11:00:50 2011, the detailed DDM information exceeding the threshold is also shown. [Box start] Switch(config-if-ethernet1/0/21)#quit Switch(config)#show transceiver threshold-violation interface ethernet 1/0/21-22 Ethernet 1/0/21 transceiver threshold-violation information: Transceiver monitor is enabled. Monitor interval is set to 30 minutes. The current time is Jan 02 12:30:50 2011. The last threshold-violation time is Jan 02 11:00:50 2011. Brief alarm information: RX loss of signal RX power low Detail diagnostic and threshold information: Diagnostic Threshold Realtime Value High Alarm Low Alarm High Warn Low Warn ------------ ----------- ----------- ------------ --------- Temperature(C) 33 70 0 70 0 Voltage(V) 7.31 10.00 0.00 5.00 0.00 Bias current(mA) 3.11 10.30 0.00 5.00 0.00 RX Power(dBM) -30.54(A-) 9.00 -25.00(-34) 9.00 -25.00 TX Power(dBM) -1.01 9.00 -12.05 9.00 -10.00 Ethernet 1/0/22 transceiver threshold-violation information: Transceiver monitor is disabled. Monitor interval is set to 30 minutes. The last threshold-violation doesn't exist. [Box end] ### 3.10.4 DDM Troubleshooting If problems occur when configuring DDM, please check whether the problem is caused by the following reasons: 1. Ensure that the transceiver of the fiber module has been inserted fast on the port, or else DDM configuration will not be shown. 2. Ensure that SNMP configuration is valid, or else the warning event cannot inform the network management system. 3. Because only some boards and box switches support SFP with DDM or XFP with DDM, ensure the used board and switch support the corresponding function. 4. When using show transceiver command or show transceiver detail command, it cost much time due to the switch will check all ports, so it is recommended to query the monitoring information of the transceiver on the specified port. 5. Ensure the threshold defined by the user is valid. When any threshold is error, the transceiver will give an alarm according to the default setting automatically. ## 3.11 EFM OAM ### 3.11.1 Introduction to EFM OAM Ethernet is designed for Local Area Network at the beginning, but link length and network scope is extended rapidly while Ethernet is also applied to Metropolitan Area Network and Wide Area Network along with development. Due to lack the effectively management mechanism, it affects Ethernet application to Metropolitan Area Network and Wide Area Network, implementing OAM on Ethernet becomes a necessary development trend. There are four protocol standards about Ethernet OAM, they are 802.3ah (EFM OAM), 802.3ag (CFM), E-LMI and Y.1731. EFM OAM and CFM are set for IEEE organization. EFM OAM works in data link layer to validly discover and manage the data link status of rock-bottom. Using EFM OAM can effectively advance management and maintenance for Ethernet to ensure the stable network operation. CFM is used for monitoring the whole network connectivity and locating the fault in access aggregation network layer. Compare with CFM, Y.1731 standard set by ITU (International Telecommunications Union) is more powerful. E-LMI standard set by MEF is only applied to UNI. So above protocols can be used to different network topology and management, between them exist the complementary relation. EFM OAM (Ethernet in the First Mile Operation, Administration and Maintenance) works in data link layer of OSI model to implement the relative functions through OAM sublayer, figure is as bleow: @img 3-14 @fig Figure 3-14 OAM location in OSI model OAM protocol data units (OAMPDU) use destination MAC address 01-80-c2-00-00-02 of protocol, the max transmission rate is 10Pkt/s. EFM OAM is established on the basis of OAM connection, it provides a link operation management mechanism such as link monitoring, remote fault detection and remote loopback testing, the simple introduction for EFM OAM in the following: 1. Ethernet OAM connection establishment Ethernet OAM entity discovers remote OAM entities and establishes sessions with them by exchanging Information OAMPDUs. EFM OAM can operate in two modes: active mode and passive mode. One session can only be established by the OAM entity working in the active mode and ones working in the passive mode need to wait until it receives the connection request. After an Ethernet OAM connection is established, the Ethernet OAM entities on both sides exchange Information OAMPDUs continuously to keep the valid Ethernet OAM connection. If an Ethernet OAM entity receives no Information OAMPDU for five seconds, the Ethernet OAM connection is disconnected. 2. Link Monitoring Fault detection in an Ethernet is difficult, especially when the physical connection in the network is not disconnected but network performance is degrading gradually. Link monitoring is used to detect and discover link faults in various environments. EFM OAM implements link monitoring through the exchange of Event Notification OAMPDUs. When detecting a link error event, the local OAM entity sends an Event Notification OAMPDU to notify the remote OAM entity. At the same time it will log information and send SNMP Trap to the network management system. While OAM entity on the other side receives the notification, it will also log and report it. With the log information, network administrators can keep track of network status in time. The link event monitored by EFM OAM means that the link happens the error event, including Errored symbol period event, Errored frame event, Errored frame period event, Errored frame seconds event. Errored symbol period event: The errored symbol number can not be less than the low threshold. (Symbol: the min data transmission unit of physical medium. It is unique for coding system, the symbols may be different for different physical mediums, symbol rate means the changed time of electron status per second. ) Errored frame period event: Specifying N is frame period, the errored frame number within the period of receiving N frames can not be less than the low threshold. (Errored frame: Receiving the errored frame detected by CRC.) Errored frame event: The number of detected error frames over M seconds can not be less than the low threshold. Errored frame seconds event: The number of error frame seconds detected over M seconds can not be less than the low threshold. (Errored frame second: Receiving an errored frame at least in a second.) 3. Remote Fault Detection In a network where traffic is interrupted due to device failures or unavailability, the flag field defined in Ethernet OAMPDUs allows an Ethernet OAM entity to send fault information to its peer. As Information OAMPDUs are exchanged continuously across established OAM connections, an Ethernet OAM entity can inform one of its OAM peers of link faults through Information OAMPDUs. Therefore, the network administrator can keep track of link status in time through the log information and troubleshoot in time. There are three kinds of link faults for Information OAMPDU, they are Critical Event, Dying Gasp and Link Fault, and their definitions are different for each manufacturer, here the definitions are as below: Critical Event: EFM OAM function of port is disabled. Link Fault: The number of unidirectional operation or fault can not be less than the high threshold in local. Unidirectional Operation means unidirectional link can not work normally on full-duplex link without autonegotiaction. EFM OAM can detect the fault and inform the remote OAM peers through sending Information OAMPDU. Dying Gasp: There is no definition present. Although device does not generate Dying Gasp OAMPDU, it still receives and processes such OAMPDU sent by its peer. 4. Remote loopback testing Remote loopback testing is available only after an Ethernet OAM connection is established. With remote loopback enabled, operating Ethernet OAM entity in active mode issues remote loopback requests and the peer responds to them. If the peer operates in loopback mode, it returns all packets except Ethernet OAMPDUs to the senders along the original paths. Performing remote loopback testing periodically helps to detect network faults in time. Furthermore, performing remote loopback testing by network segments helps to locate network faults. Note: The communication will not be processed normally in remote loopback mode. Typical EFM OAM application topology is in the following, it is used for point-to-point link and emulational IEEE 802.3 point-to-point link. Device enables EFM OAM through point-to-point connection to monitor the link fault in the First Mile with Ethernet access. For user, the connection between user to telecommunication is "the First Mile", for service provider, it is "the Last Mile". @img 3-15 @fig Figure 3-15 Typical OAM application topology ### 3.11.2 EFM OAM Configuration EFM OAM configuration task list 1. Enable EFM OAM function of port 2. Configure link monitor 3. Configure remote failure 4. Enable EFM OAM loopback of port Note: it needs to enable OAM first when configuring OAM parameters. 1. Enable EFM OAM function of port [Table start] Command Explanation Port mode ethernet-oam mode {active | passive} Configure work mode of EFM OAM, default is active mode. ethernet-oam no ethernet-oam Enable EFM OAM of port, no command disables EFM OAM of port. ethernet-oam period
no ethernet-oam period Configure transmission period of OAMPDU (optional), no command restores the default value. ethernet-oam timeout
no ethernet-oam timeout Configure timeout of EFM OAM connection, no command restores the default value. [Table end] 2. Configure link monitor [Table start] Command Explanation Port mode ethernet-oam link-monitor no ethernet-oam link-monitor Enable link monitor of EFM OAM, no command disables link monitor. ethernet-oam errored-symbol-period {threshold low
| window
} no ethernet-oam errored-symbol-period {threshold low | window } Configure the low threshold and window period of errored symbol period event, no command resotores the default value. (optional) ethernet-oam errored-frame-period {threshold low
| window
} no ethernet-oam errored-frame-period {threshold low | window } Configure the low threshold and window period of errored frame period event, no command resotores the default value. ethernet-oam errored-frame {threshold low
| window
} no ethernet-oam errored-frame {threshold low | window } Configure the low threshold and window period of errored frame event, no command resotores the default value. (optional) ethernet-oam errored-frame-seconds {threshold low
| window
} no ethernet-oam errored-frame-seconds {threshold low | window } Configure the low threshold and window period of errored frame seconds event, no command resotores the default value. (optional) [Table end] 3. Configure remote failure [Table start] Command Explanation Port mode ethernet-oam remote-failure no ethernet-oam remote-failure Enable remote failure detection of EFM OAM (failure means critical-event or link-fault event of the local), no command disables the function. (optional) ethernet-oam errored-symbol-period threshold high {high-symbols | none} no ethernet-oam errored-symbol-period threshold high Configure the high threshold of errored symbol period event, no command restores the default value. (optional) ethernet-oam errored-frame-period threshold high {high-frames | none} no ethernet-oam errored-frame-period threshold high Configure the high threshold of errored frame period event, no command restores the default value. (optional) ethernet-oam errored-frame threshold high {high-frames | none} no ethernet-oam errored-frame threshold high Configure the high threshold of errored frame event, no command restores the default value. (optional) ethernet-oam errored-frame-seconds threshold high {high-frame-seconds | none} no ethernet-oam errored-frame-seconds threshold high Configure the high threshold of errored frame seconds event, no command restores the default value. (optional) [Table end] 4. Enable EFM OAM loopback of port [Table start] Command Explanation Port mode ethernet-oam remote-loopback no ethernet-oam remote-loopback Enable remote EFM OAM entity to enter OAM loopback mode (its peer needs to configure OAM loopback supporting), no command cancels remote OAM loopback. ethernet-oam remote-loopback supported no ethernet-oam remote-loopback supported Enable remote loopback supporting of port, no command cancels remote loopback supporting of port. [Table end] ### 3.11.3 EFM OAM Example Example: CE and PE devices with point-to-point link enable EFM OAM to monitor "the First Mile" link performance. It will report the log information to network management system when occurring fault event and use remote loopback function to detect the link in necessary instance @img 3-16 @fig Figure 3-16 Typical OAM application topology Configuration procedure: (Omitting SNMP and Log configuration in the following) Configuration on CE: [Box start] CE(config)#interface ethernet1/0/1 CE (config-if-ethernet1/0/1)#ethernet-oam mode passive CE (config-if-ethernet1/0/1)#ethernet-oam CE (config-if-ethernet1/0/1)#ethernet-oam remote-loopback supported [Box end] Other parameters use the default configuration. Configuration on PE: [Box start] PE(config)#interface ethernet 1/0/1 PE (config-if-ethernet1/0/1)#ethernet-oam [Box end] Other parameters use the default configuration. Execute the following command when using remote loopback. [Box start] PE(config-if-ethernet1/0/1)#ethernet-oam remote-loopback [Box end] Execute the following command to make one of OAM peers exiting OAM loopback after complete detection. [Box start] PE(config-if-ethernet1/0/1)# no ethernet-oam remote-loopback [Box end] Execute the following command without supporting remote loopback. [Box start] CE(config-if-ethernet1/0/1)#no ethernet-oam remote-loopback supported [Box end] ### 3.11.4 EFM OAM Troubleshooting When using EFM OAM, it occurs the problem, please check whether the problem is resulted by the following reasons: 1. Check whether OAM entities of two peers of link in passive mode. If so, EFM OAM connection can not be established between two OAM entities. 2. Ensuring SNMP configuration is correct, or else errored event can not be reported to network management system. 3. Link does not normally communicate in OAM loopback mode, it should cancel remote loopback in time after detect the link performance. 4. Ensuring the used board supports remote loopback function. 5. Port should not configure STP, MRPP, ULPP, Flow Control, loopback detection functions after it enables OAM loopback function, because OAM remote loopback function and these functions are mutually exclusive. 6. When enabling OAM, the negotiation of the port will be disabled automatically. So the negotiation in the peer of the link must be disabled, otherwise the link connection will unsuccessful. When disabling OAM, the negotiation of the port will be restored. Therefore, to ensure the link connection is normal, the negotiations must be accordant in two peers of the link. 7. After enabling OAM, when the link negotiations in two peers are successful, the state is up. After the fiber in RX redirection of the peer is pulled out, TX of the peer and RX with OAM are normal, so the port with OAM will be at up state all along. ## 3.12 PORT SECURITY ### 3.12.1 Introduction to PORT SECURITY Port security is a MAC address-based security mechanism for network access controlling. It is an extension to the existing 802.1x authentication and MAC authentication. It controls the access of unauthorized devices to the network by checking the source MAC address of the received frame and the access to unauthorized devices by checking the destination MAC address of the sent frame. With port security, you can define various port security modes to make that a device learns only legal source MAC addresses, so as to implement corresponding network security management. After port security is enabled, the device detects an illegal frame, it triggers the corresponding port security feature and takes a pre-defined action automatically. This reduces user's maintenance workload and greatly enhances system security. ### 3.12.2 PORT SECURITY Configuration Task List 1. Basic configuration for PORT SECURITY [Table start] Command Explanation Port mode switchport port-security no switchport port-security Configure port-security of the interface. switchport port-security mac-address
[vlan
] no switchport port-security mac-address
[vlan
] Configure the static security MAC of the interface. switchport port-security maximum
[vlan
] no switchport port-security maximum
[vlan
] Configure the maximum number of the security MAC address allowed by the interface. switchport port-security violation {protect | recovery | restrict | shutdown} no switchport port-security violation When exceeding the maximum number of the configured MAC addresses, MAC address accessing the interface does not belongs to this interface in MAC address table or a MAC address is configured to several interfaces in same VLAN, both of them will violate the security of the MAC address. switchport port-security aging {static | time
| type {absolute | inactivity}} no switchport port-security violation aging {static | time | type} Enable port-security aging entry of the interface, specify aging time or aging type. Admin mode clear port-security {all | configured | dynamic | sticky} [[address
| interface
] [vlan
]] Clear the secure MAC entry of the interface. show port-security [interface
] [address | vlan] Show port-security configuration. [Table end] ### 3.12.3 Example of PORT SECURITY @img 3-17 @fig Figure 3-17 Typical topology chart for port security When the interface enabled Port security function, configure the maximum number of the secure MAC addresses allowed by a interface to be 10, the interface allows 10 users to access the internet at most. If it exceeds the maximum number, the new user cannot access the internet, so that it not only limit the user's number but also access the internet safely. If configuring the maximum number of the secure MAC addresses as 1, only HOST A or HOST B is able to access the internet. Configuration process: #Configure the switch. [Box start] Switch(config)#interface Ethernet 1/0/1 Switch(config-if-ethernet1/0/1)#switchport port-security Switch(config-if- ethernet1/0/1)#switchport port-security maximum 10 Switch(config-if- ethernet1/0/1)#exit Switch(config)# [Box end] ### 3.12.4 PORT SECURITY Troubleshooting If problems occur when configuring PORT SECURITY, please check whether the problem is caused by the following reasons: 1. Check whether PORT SECURITY is enabled normally 2. Check whether the valid maximum number of MAC addresses is configured ## 3.13 VLAN ### 3.13.1 Introduction to VLAN VLAN (Virtual Local Area Network) is a technology that divides the logical addresses of devices within the network to separate network segments basing on functions, applications or management requirements. By this way, virtual workgroups can be formed regardless of the physical location of the devices. IEEE announced IEEE 802.1Q protocol to direct the standardized VLAN implementation, and the VLAN function of switch is implemented following IEEE 802.1Q. The key idea of VLAN technology is that a large LAN can be partitioned into many separate broadcast domains dynamically to meet the demands. @img 3-18 @fig Figure 3-18 VLAN network defined logically Each broadcast domain is a VLAN. VLANs have the same properties as the physical LANs, except VLAN is a logical partition rather than physical one. Therefore, the partition of VLANs can be performed regardless of physical locations, and the broadcast, multicast and unicast traffic within a VLAN is separated from the other VLANs. With the aforementioned features, VLAN technology provides us with the following convenience: 1. Improving network performance 2. Saving network resources 3. Simplifying network management 4. Lowering network cost 5. Enhancing network security Switch Ethernet Ports can works in three kinds of modes: Access, Hybrid and Trunk, each mode has a different processing method in forwarding the packets with tagged or untagged. The ports of Access type only belongs to one VLAN, usually they are used to connect the ports of the computer. The ports of Trunk type allow multi-VLANs to pass, can receive and send the packets of multi-VLANs. Usually they are used to connect between the switches. The ports of Hybrid type allow multi-VLANs to pass, can receive and send the packets of multi-VLANs. They can be used to connect between the switches, or to a computer of the user. Hybrid ports and Trunk ports receive the data with the same process method, but send the data with different method: Hybrid ports can send the packets of multi-VLANs without the VLAN tag, while Trunk ports send the packets of multi-VLANs with the VLAN tag except the port native VLAN. The switch implements VLAN and GVRP (GARP VLAN Registration Protocol) which are defined by 802.1Q. The chapter will explain the use and the configuration of VLAN and GVRP in detail. ### 3.13.2 VLAN Configuration Task List 1. Create or delete VLAN 2. Set or delete VLAN name 3. Assign Switch ports for VLAN 4. Set the switch port type 5. Set Trunk port 6. Set Access port 7. Set Hybrid port 8. Enable/Disable VLAN ingress rules on ports 9. Configure Private VLAN 10. Set Private VLAN association 11. Specify internal VLAN ID 1. Create or delete VLAN [Table start] Command Explanation Global Mode vlan
no vlan
Create/delete VLAN or enter VLAN Mode [Table end] 2. Set or delete VLAN name [Table start] Command Explanation VLAN Mode name
no name Set or delete VLAN name. [Table end] 3. Assigning Switch ports for VLAN [Table start] Command Explanation VLAN Mode switchport interface
no switchport interface
Assign Switch ports to VLAN. [Table end] 4. Set the Switch Port Type [Table start] Command Explanation Port Mode switchport mode {trunk | access | hybrid} Set the current port as Trunk, Access or Hybrid port. [Table end] 5. Set Trunk port [Table start] Command Explanation Port Mode switchport trunk allowed vlan {
| all | add
| except
| remove
} no switchport trunk allowed vlan Set/delete VLAN allowed to be crossed by Trunk. The "no" command restores the default setting. switchport trunk native vlan
no switchport trunk native vlan Set/delete PVID for Trunk port. [Table end] 6. Set Access port [Table start] Command Explanation Port Mode switchport access vlan
no switchport access vlan Add the current port to the specified VLAN. The "no" command restores the default setting. [Table end] 7. Set Hybrid port [Table start] Command Explanation Port Mode switchport hybrid allowed vlan {
| all | add