BCMSN
Unidirectional Link Detection
UDLD protocol detects and shuts down unidirectional links. The loop guard STP feature is intended to improve stability of Layer 2 networks. UDLD allows devices connected through fiber-optic or copper Ethernet cables (for example, Category 5 cabling) to monitor the physical configuration of the cables and detect when a unidirectional link exists. A unidirectional link occurs when traffic transmitted by the local device over a link is received by the neighbor, but traffic transmitted from the...
Configuring SRM
Enables redundancy and enters redundancy configuration mode Switch(config-r) high-availability Enables high availability Enables SRM 2004, Cisco Systems, Inc. All rights reserved. BCMSN v2.1 6-59 Note Before going from Dual Router Mode (DRM) to SRM redundancy, Cisco recommends that you use the copy running-config command on the MSFCs to save the non-SRM configuration to boot flash memory. When going to SRM redundancy, the alternative configuration (the configuration following the alt keyword)...
Configuring the SLB Server Farm
Switch(config) ip slb serverfarm serverfarm-name Creates a server farm definition and enters server farm configuration mode Switch(config-slb-sfarm) real ip-addreaa Specifies the IP address of a real server in the server farm 2004, Cisco Systems, Inc. All lights reserved. BCMSN v2.1 6-63 Configuring IOS SLB involves identifying server farms, configuring groups of real servers in server farms, and configuring the virtual servers that represent the real servers to the clients. The table lists the...
Issues in a Poorly Designed Network
Reduced support for services and solutions 2004, Cisco Systems, Inc. All rights reserved. BCMSN v2.1 1-37 A poorly designed network has increased support costs, reduced services and solutions that can be supported, and nonoptimal performance issues that most likely will affect end users directly. Here are some of the issues that stem from a poorly designed network Failure domains One of the most important reasons to implement an effective design is to reduce the impact of network problems...
Example Broadcast Frames and Bridging Loops
Station A has two potential paths to station B by way of the two intermediate switches. What happens if station A sends to station B, while a Layer 2 loop exists without STP Station A transmits the frame destined for station B to segment A. Both bridges on segment A pick up the frame on their switch ports 1 1 and 2 1, respectively. Both switches populate their respective MAC tables indicating that station A resides on segment A on switch ports 1 1 and 2 1. Both switches forward the frame to...
RSTP Port States
All rights re RSTP provides rapid convergence following the failure or re-establishment of a switch, switch port, or link. An RSTP topology change will cause a transition in the appropriate switch ports to the forwarding state through explicit handshakes or a proposal and agreement process and synchronization. With RSTP, the role of a port is separated from the state of a port. For example, a designated port may be in the discarding state, even though this condition...
AAA Network Configuration
- Verifies a user identify Authorization - Specifies the permitted tasks for the user - Provides billing, auditing, and monitoring 2004, Cisco Systems, Inc. All rights re AAA is an architectural framework for configuring a set of three independent security functions in a consistent manner. AAA provides a modular way of performing these services Authentication Provides the method of identifying users, including login and password dialog, challenge and response, messaging support, and, depending...
Four Step Spanning Tree Decision Process
All rights reserved. BCMSN 2.1-3-35 When determining the loop-free topology, STP identifies the root switch by evaluating BPDUs. Four criteria are used in the decision-making process, in the following order Lowest path cost to the root switch Lowest sender BID Lowest local port ID When STP determines the root switch of an STP topology, the switch first examines the received BPDUs for the lowest root BID. If there are equal BID values reported by two different switches...
Example Configuring SPAN
This example shows how to configure session 1 to monitor bidirectional traffic from Fast Ethernet port 5 1 Switch(config) monitor session 1 source interface fastethernet 5 1 both When configuring a SPAN source port, the specified interfaces can be a single interface, a comma-separated list of interfaces, a range of interfaces, or a combination. This example shows how to configure Fast Ethernet port 5 48 as the destination for SPAN session 1 Switch(config) monitor session 1 destination interface...
Example Configuring RSPAN
This example shows how to configure RSPAN source session 2 Switch(config) monitor session 2 source interface fastethernetl 1 - 3 rx Switch(config) monitor session 2 destination remote vlan 901 This example shows how to configure an RSPAN source session with multiple sources Switch(config) monitor session 2 source interface fastethernet 5 15 , 7 3 rx Switch(config) monitor session 2 source interface gigabitethernet 1 2 tx Switch(config) monitor session 2 source interface portchannel 102...
References Ekc
For additional information, refer to these resources Creating Ethernet VLANs on Catalyst Switches at httpV www cisco com How To Configure InterVLAN Routing on Layer 3 Switches at http www cisco com Use the practice items here to review what you learned in this lesson. The correct answers are found in the Quiz Answer Key. Q1) Which two network characteristics apply to VLANs (Choose two.) A) All devices in a VLAN are members of the same broadcast domain. B) The most common type of VLAN is a...
RSTP Topology Change Mechanism
The originator of thcTC dircctly floods this, information through the network. 2004, Cisco Systems, Inc. All rights reserved. BCMSN v2.1 4-12 When an 802.1D bridge detects a topology change, the bridge first notifies the root bridge. After the root bridge is aware of a change in the topology of the network, the root bridge sets the TC flag on the outbound BPDUs. Those BPDUs are then relayed to all the bridges in the network. When a bridge receives a BPDU with the TC flag bit set, the bridge...
IGMP v3 Query Message Format
Croup address 5 QRV QQIC riurnheroUsurcealN 2004, Cisco Systems, Inc. All rights re IGMP version 3 IGMP v3 is the next step in the evolution of IGMP. IGMP v3 adds support for source filtering. This enables a multicast receiver host to signal to a router the groups from which it wants to receive multicast traffic and from which sources this traffic is expected. This membership information enables IOS software to forward traffic from only those sources from which receivers requested the traffic....
Enterprise Campus Infrastructure
The Campus Infrastructure module connects users within a campus with the Server Farm and Edge Distribution modules. This module is composed of one or more floors or buildings connected to the Campus Backbone submodule. Each building contains a Building Access and Building Distribution submodule. The Campus Infrastructure module includes these submodules Building Access submodule (also known as Building Access layer) Contains end-user workstations, IP Phones, and Layer 2 access switches that...
Example Extending STP to Multiple Spanning Trees
In this example, there are two links and 1000 VLANs. The 1000 VLANs are mapped to two MST instances (MSTI). Rather than maintaining 1000 spanning trees, each switch needs to maintain only two. This reduces the need for switch resources. If there were 2000 VLANs, they would be reduced to two spanning tree instances also. MST converges faster than Per VLAN Spanning Tree+ (PVST+) and is backward-compatible with 802.1D STP, 802.1w (RSTP), and the Cisco PVST+ architecture. MST allows you to build...
Source Trees vs Shared Trees
Both source trees and shared trees are loop-free. Messages are replicated only where the tree branches. Members of multicast groups can join or leave at any time therefore, the distribution trees must be dynamically updated. When all the active receivers on a particular branch stop requesting the traffic for a particular multicast group, the routers prune that branch from the distribution tree and stop forwarding traffic down that branch. If one receiver on that branch becomes active and...
IGMP v2 Packet Format
- Max. time before sending a responding report in 1 10 secs (default 10 secs) - Multicast group address (0.0.0.0 for general queries) 2004, Cisco Systems, Inc. All rights reserved. BCMSN v2.1 7-17 Version 2 of IGMP (IGMP v2) made some enhancements to the previous version, including the definition of a Group Specific Query. This type of message allows the router to transmit a specific query to one particular group. IGMP v2 also defines a Leave Group Message for the hosts, which results in lower...
Enabling BPDU Filtering
This topic identifies the command used to enable BPDU filtering. This topic identifies the command used to enable BPDU filtering. Enabling and Verifying BPDU Filtering r . , m Switch(config) spanning-tree portfast bpdufilter default Switch show spanning-tree summary totals Displays BPDU filtering configuration information Switch show spanning-tree summary totals Root bridge for VLAN0010 EtherChannel misconfiguration guard is enabled Extended system ID is disabled Portfast is enabled by default...
Configuring HSRP Tracking
Switch(config-if) standby group-number track type number interface-priority 2004, Cisco Systems, Inc. All rights reserved. BCMSN v2.1 6-48 To configure HSRP tracking, enter this command in interface configuration mode Switch(config-if) standby group-number track type number interface-priority Switch(config-if) standby group-number track type number interface-priority (Optional) Indicates the group number on the interface to which the tracking applies. The default number is 0. Indicates the...
Enabling BPDU Skewing Detection
This topic identifies the possible causes of BPDU skewing. Is the difference between when the BPDUs are expected to be received and the time BPDUs are actually received - Expected BPDUs are not received - Spanning tree detects topology changes 2004, Cisco Systems, Inc. All nghts reserved. BCMSN v2.1 4-50 BPDU skewing is the difference between when the BPDUs are expected to be received and the time BPDUs are actually received. Skewing occurs when the following occurs Spanning tree detects...
Identifying the Features of Multilayer Switches
This topic identifies the features of multilayer switches. This topic identifies the features of multilayer switches. 2004, Cisco Systems, Inc. All rights reserved. Multilayer switching is hardware-based switching and routing integrated into a single platform. In some cases, the frame and packet forwarding operation is handled by the same specialized hardware ASICs and other specialized circuitry. A multilayer switch does everything to a frame and packet that a traditional switch and router...
Problem Using Proxy ARP
Address Resolution Protocol (ARP), proxy ARP, and Reverse Address Resolution Protocol (RARP) are defined in RFCs 826, 1027, and 903, respectively. IP hosts use ARP to select a router. ARP is used to associate IP addresses with media or MAC addresses. You can configure a router as a proxy ARP server. Cisco IOS software uses proxy ARP (as defined in RFC 1027) to help hosts that have no knowledge of routing to determine the media addresses of hosts on other networks or subnets. For example, if the...
Switched Network with Fault Tolerant Devices and Single Points of Failure
All rights re One approach to building highly available networks is to use extremely fault-tolerant network devices throughout the network. To achieve high availability end -to end, the fault tolerance of each device is optimized. This is achieved by providing redundant backup within the device for each of its key components. Fault tolerance offers these benefits Minimizes time periods during which the system is nonresponsive to requests (for example, while the system...
Ethernet Leased Line over DWDM
The advantages of WDM technology have long been recognized in the long-distance, ultrahigh-bandwidth transport market. In these environments, the laying of additional fibers is an extremely expensive and time-consuming process, leaving WDM-based solutions as the only real answer to the fast growth in bandwidth demand. In the figure, the DWDM Metro Ethernet network appears to the end user as a point-to-point Gigabit Ethernet link. The Metro Ethernet system has essentially created a long...
Port Based Authentication
Restricts unauthorized clients from connecting to a LAN through publicly accessible ports The IEEE 802.1x standard defines a port-based access control and authentication protocol that restricts unauthorized workstations from connecting to a LAN through publicly accessible ports. The authentication server authenticates each workstation connected to a switch port before making available any services offered by the switch or the LAN. Until the workstation is authenticated, 802.1x access control...
Comparing Port and Link Aggregation Protocols
This topic discusses the features the Port Aggregation Protocol (PAgP) and Link Aggregation Control Protocol (LACP). A Cisco proprietary protocol Expedites the automatic creation of EtherChannels by exchanging packets between Ethernet interfaces Link Aggregation Control Protocol (LACP) Configures the maximum number of compatible ports in a channel, up to the maximum allowed by the hardware (eight ports) 2004, Cisco Systems, Inc. All rights re PAgP and LACP are two different protocols that allow...
Example HSRP on Preempt Configured Router Coming Up
DSW111 is configured with a priority of 100. This priority is higher than the priority of the active router DSW112 (172.16.11.112). DSW111 is also configured with preempt. Only when a router is configured with preempt will that router with a higher priority transition into the active state. At time-stamp Mar 1 00 16 43.099, the interface VLAN11 on DSW111 comes up and transitions into the listen state. At time-stamp Mar 1 00 16 43.295, DSW111 receives a hello message from the active router...
Example Displaying HSRP Preempt
The following example states that interface VLAN10 is configured to resume its role as the active router in HSRP group 47, assuming that interface VLAN10 on this router has the highest priority in that standby group. ip address 172.16.10.82 255.255.255.0 Configuring the Hello Message Timers The holdtime parameter value should be at least three times the value of the hellotime parameter. 2004, Cisco Systems, Inc. All rights re An HSRP-enabled router sends hello messages to indicate that the...
Endto End VLANs
Users are grouped into VLANs independent of physical location. As users move, VLAN membership remains the same. Users are grouped into VLANs independent of physical location. As users move, VLAN membership remains the same. 2004, Cisco Systems, Inc. All rights reserved. BCMSN v2.1 2-9 An end-to-end VLAN spans the entire switched network, while a local VLAN is restricted to a single switch. An end-to-end VLAN network comprises these characteristics Users are grouped into VLANs independent of...
Security in the Multilayer Switched Network
Network security vulnerabilities include loss of privacy, data theft, impersonation, and loss of integrity. Cisco recommends tasks that you should complete to secure your switched network from attack. This topic introduces security in a multilayer switched network. r.cn, 2004, Cisco Systems, Inc. All rights reserved. You should implement a basic security configuration on every installed Cisco IOS device. The primary focus is to apply minimal security to mitigate user negligence in regards the...
Configuring HSRP Standby Priority
The router in an HSRP group with the highest priority becomes the forwarding router. The default priority is 100. The router in an HSRP group with the highest priority becomes the forwarding router. The default priority is 100. 2004, Cisco Systems, Inc. All rights re Each standby group has its own active and standby routers. The network administrator can assign a priority value to each router in a standby group, allowing the administrator to control the order in which active routers for that...
Importance of Native VLANs
802.1Q trunks define a native VLAN for frames that are not tagged by default. An 802.1Q native VLAN is defined as one of the following The VLAN that a port is in when not in trunking operational mode The VLAN from which Layer 2 frames will be transmitted untagged on an 802.1Q trunk port The VLAN to which Layer 2 frames will be forwarded if received untagged on an 802.1Q trunk port With an 802.1Q native VLAN, a switch can forward any Layer 2 frame received on a trunk port, whether tagged or not,...
Ternary Content Addressable Memory Table
Matches only the important values (not all values) Matches based on three values 0, 1, or X (either) Masks used to wildcard some content fields 1 Mid > . h All 32 Bits of Smircc IP A ddreRE TCAM is a specialized piece of memory designed for rapid table lookups based on packets passing through the switch performed by the ACL engine. The result of the ACL engine lookup into the TCAM table determines how the switch handles a packet. For example, the packet might be permitted or denied. The TCAM...
ISL and Layer 2 Encapsulation
All rights re Switch ports configured as ISL trunk ports encapsulate each Layer 2 frame before sending it out the trunk port. With ISL, the original frame is encapsulated and an additional header is added before the frame is carried over a trunk link. At the receiving end, the header is removed and the packet is forwarded to the assigned VLAN. For each frame that is received on a trunk port, the switch recalculates the total frame cyclic redundancy check (CRC) and...
VLAN Trunking
All rights re Trunks transport VLAN information between connected Layer 2 devices. Each frame passed on a trunk is either encapsulated or tagged, depending on the protocol. The trunking protocol, which defines the type and method of trunking, can be Inter-Switch Link (ISL), which does encapsulation, or IEEE 802.1Q, which tags. Cisco supports the following multiple trunking methodologies ISL A Cisco proprietary encapsulation protocol for interconnecting multiple...
Outline Mqc
This lesson includes these topics Overview Comparing ISL and 802.1Q Trunking Protocols Identifying the Features and Benefits of the ISL Protocol Comparing the ISL and Layer 2 Encapsulation Processes Identifying the Features and Benefits of 802.1Q Trunking Comparing 802.1Q Tagging Process and Layer 2 Encapsulation Protocol Supporting Native VLANs Using Trunking Protocols in the Enterprise Composite Network Model Summary Comparing ISL and 802.1Q Trunking Protocols This topic compares the features...
Configuring HSRP Standby Preempt
Ml I I I I I I I I I I I I f-ul - rikftfihrkti iir-iinrilry vLan 1(5 1 n'hrirr.iri' VLnrjLCi ip adIdzoflQ 1TB.1 . IV. 9 EB5.aE5.SM i ii& vp ftKti root1* tandhv 7 priority L5Q atiLTdt-y 47 pi a-amp t. nfULnrthy ip 173 . IE . 10 .11 D Preempt enables a router to resume the forwarding router role. 2004, Cisco Systems, Inc. All rights reserved. BCMSN v2.1 6-44 The standby router automatically assumes the active router role when the active router fails or is removed from service. This new active...
HSRP Interface Tracking
In some situations, the status of an interface directly affects which router needs to become the active router. This is particularly true when each of the routers in an HSRP group has a different path to resources within the campus network. In this example, router A and router B reside in a branch office. These two routers each support a T1 link to the headquarters. Router A has the higher priority and is the active forwarding router for standby group 47. Router B is the standby router for that...
Implementing Redundant Supervisor Engines in Catalyst Switches
Route processor redundancy enables a second Supervisor Engine to provide failover capabilities within a Catalyst switch. This topic explains how to implement redundant Supervisor Engines. Single Supervisor Engine means single point of failure for the switch. Redundant Supervisor Engine allows configuration for automatic failover. I I'jjgt1 l-TH HajM j L l f c-V ' -> r y- - < 1 i jffl ' ILOJtUF,T. yv-f+H, t feggggj sxm J J jwsm Jifmj sjWiiSBsr > jffl ' ILOJtUF,T. yv-f+H, t feggggj sxm J J...
Router on a Stick
The router can support a single trunk for multiple VLANs. 2004, Cisco Systems, Inc. All rights re To maintain integrity between VLAN traffic, the router on a stick is required to identify each VLAN frame. A single trunk can carry traffic from multiple VLANs. When implementing an 802.1Q trunk, it is important to ensure that the native VLAN assigned on each side of the link matches. In the figure, the clients on VLAN10 and VLAN20 need to establish sessions with a server that is attached to a...
Spanning Tree debug Commands
Displays all debugging messages for spanning tree Displays spanning tree topology events debug messages Switch debug spanning-tree backbonefast Displays spanning tree BackboneFast events debug messages Switch debug spanning-tree uplinkfast Displays spanning tree UplinkFast events debug messages 2004, Cisco Systems, Inc. All rights reserved. BCMSN v2.1 4-53 The debug spanning-tree command is used to troubleshoot spanning-tree activities.
Logical Packet Flow for a Layer 2Switched Packet
Layer 2 forwarding in hardware is based on the destination MAC address. The Layer 2 switch learns the address based on the source MAC address. The MAC address table lists MAC and VLAN pairs with associated interfaces. The figure describes how a Layer 2 switch forwards packets. Step 1 The Layer 2 engine receives a frame or the frame header over the data bus. Step 2 The switch performs these operations The Layer 2 lookup engine looks up the destination MAC address. The Layer 2 engine performs the...
Configuring PAgP and LACP
This topic identifies the commands used to configure PAgP and LACP. Switch(config-if) channel-protocol lacp pagp Restricts the channel-group command to the specified EtherChannel protocol for this port Switch(config-if) lacp port-priority priority_value Configures the LACP port priority Switch(config) lacp system-priority priority_value Configures the LACP system priority 2004, Cisco Systems, Inc. All rights reserved. BCMSN 2.1-3-41 To configure LACP or PAgP (configured by default), complete...
Weighted Random Early Detection
WRED is similar to RED in the fact that both define some threshold, and that threshold starts to randomly drop packets. WRED is also CoS-aware, which means that a CoS value is added to each of the thresholds. When the threshold is exceeded, WRED randomly drops packets with the CoS assigned. Consider this example, where there are two thresholds in the queue CoS 0 and 1 are assigned to threshold 1, which is set to 50 percent of buffer filling CoS 2 and 3 are assigned to threshold 2, which is set...
Metro Ethernet EoMPLS Encapsulation Pointto Multipoint
EoMPLS multipoint extends EoMPLS to include point-to-multipoint capabilities. This topic explains the operations of EoMPLS point-to-multipoint. Excellent enterprise isolation from the backbone QoS support for traffic engineering is problematic Efficient distribution in a WAN Emulates an Ethernet switch 2004, Cisco Systems, Inc. All rights re EoMPLS multipoint provides all the advantages of point-to-point EoMPLS with the addition of multipoint switching in the core network. This option solves...
Transparent LAN Service TLS
Switches see the service as an Ethernet segment. Supports point-to-point and multipoint-to-multipoint. Viewed as hublike, shared environment. 2004, Cisco Systems, Inc. All rights reserved. BCMSN v2.1 10-1S In a TLS, the network looks like an Ethernet hub. The TLS supports point-to-point and point-to-multipoint operation. As far as the enterprise is concerned, all of its routers and multilayer switches are on the same subnet. The service provider can easily provide a TLS solution for the...
VTP Pruning
Increases available bandwidth by reducing unnecessary flooded traffic Example Station A sends broadcast broadcast flooded only toward any Increases available bandwidth by reducing unnecessary flooded traffic Example Station A sends broadcast broadcast flooded only toward any VTP Pruning uses VLAN advertisements to determine when a trunk connection is flooding traffic needlessly. By default, a trunk connection carries traffic for all VLANs in the VTP management domain. Commonly, some switches...
Verifying the Modular QoS CLI Configuration
Switch show class-map class-map-name Switch show policy-map interface interface-spec Switch show policy-map max-pol-ipp5 Policy Map max-pol-ipp5 class ipp5 class ipp5 police flow 10000000 10000 conform-action set-prec-transmit 6 exceed-action policed-dscp-transmit trust precedence police 2000000000 2000000 2000000 co nform-action set-prec-transmit 6exceed-action policed-dscp-transmit 2004, Cisco Systems, Inc. All rights reserved. BCMSN v2.1 8-48 Verifying the Modular QoS CLI Configuration...
Cisco Metro Ethernet Switching Products
Customer premises equipment High-density metro access (up to 240 10 100 ports) High-end metro access (up to 576 10 100 ports) 2004, Cisco Systems, Inc. All rights reserved. BCMSN v2.1 10-8 2004, Cisco Systems, Inc. All rights reserved. BCMSN v2.1 10-8 The table describes the Cisco Metro Ethernet products. Metro access (12 ports or stackable to 96 ports) Access control lists (ACLs) (Layer 2 and 3) Unidirectional Link Detection (UDLD) Protocol UplinkFast and BackboneFast EtherChannel Jumbo...
Example Flooded Unicast Frames and Bridging Loops
Station A has two potential paths to station B by way of the switches. What happens if station A sends to station B, but neither of the switches has station B in its address table Station A transmits the frame to segment A. Both bridges on segment A pick up the frame on their ports 1 1 and 2 1, respectively. Both switches populate their respective address tables indicating that station A resides on segment A on ports 1 1 and 2 1. Both switches forward the frame to segment B. Notice that not...





























