Root Bridge

Modular Network Design

Server Block Cisco

Recall from Chapter 1, Campus Network Overview, that a network is best constructed and maintained using a three-tiered hierarchical approach. Making a given network conform to a layered architecture might seem a little confusing. You can design a campus network in a logical manner, using a modular approach. In this approach, each layer of the hierarchical network model can be broken into basic functional units. These units, or modules, then can be sized appropriately and connected, while...

Scenario 8 Answers

On a Catalyst 3750, you can use the following commands Switch(config) interface range fastethernet 1 0 1 - 48 Switch(config-if) switchport port-security 2. On a Catalyst 3750, you can use the following commands Switch(config) interface fastethernet 1 0 18 Switch(config-if) switchport port-security Switch(config-if) switchport port-security maximum 24 Switch(config-if) switchport port-security violation restrict The first command line enables port-level security on the switch port. The second...

DHCP Snooping

A DHCP server normally provides all the basic information a client PC needs to operate on a network. For example, the client might receive an IP address, a subnet mask, a default gateway address, DNS addresses, and so on. Suppose that an attacker could bring up a rogue DHCP server on a machine in the same subnet as that same client PC. Now when the client broadcasts its DHCP request, the rogue server could send a carefully crafted DHCP reply with its own IP address substituted as the default...

Do I Know This Already Quiz

The purpose of the Do I Know This Already quiz is to help you decide whether you need to read the entire chapter. If you already intend to read the entire chapter, you do not necessarily need to answer these questions now. The 14-question quiz, derived from the major sections in the Foundation Topics portion of the chapter, helps you determine how to spend your limited study time. Table 2-1 outlines the major topics discussed in this chapter and the Do I Know This Already quiz questions that...

Evaluating an Existing Network

If you are building an enterprise network from scratch, you might find that it is fairly straightforward to build it in a hierarchical fashion. After all, you can begin with switches in the core layer and fan out into lower layers to meet the users, server farms, and service providers. In the real world, you might be more likely to find existing networks that need an overhaul to match the hierarchical model. Hopefully, if you are redesigning your own network, you already know its topology and...

Verifying Voice VLAN Operation

You can verify the switch port mode (access or trunk) and the voice VLAN by using the show interface switchport command. As demonstrated in Example 14-3, the port is in access mode and uses access VLAN 10 and voice VLAN 110. Example 14-3 Verifying Switch Port Mode and Voice VLAN Switch show interfaces fastEthernet 1 0 1 switchport Administrative Trunking Encapsulation negotiate Operational Trunking Encapsulation native Trunking Native Mode VLAN 1 (default) Administrative Native VLAN tagging...

Verifying Voice QoS

A switch port can be configured with a QoS trust state with the connected device. If that device is an IP Phone, the switch can instruct the phone on whether to extend QoS trust to an attached PC. To verify how QoS trust has been extended to the IP Phone itself, use the following EXEC command Switch show mls qos interface type mod num If the port is trusted, all traffic forwarded by the IP Phone is accepted with the QoS information left intact. If the port is not trusted, even the voice packets...

VTP Advertisements

Each Cisco switch participating in VTP advertises VLANs (only VLANs 1 to 1005), revision numbers, and VLAN parameters on its trunk ports to notify other switches in the management domain. VTP advertisements are sent as multicast frames. The switch intercepts frames sent to the VTP multicast address and processes them with its supervisory processor. VTP frames are forwarded out trunk links as a special case. Because all switches in a management domain learn of new VLAN configuration changes, a...

Switch Spoofing

Recall from Chapter 5, VLANs and Trunks, that two switches can be connected by a common trunk link that can carry traffic from multiple VLANs. The trunk doesn't have to exist all the time. The switches dynamically can negotiate its use and its encapsulation mode by exchanging Dynamic Trunking Protocol (DTP) messages. Although DTP can make switch administration easier, it also can expose switch ports to be compromised. Suppose that a switch port is left to its default configuration, in which the...

Do I Know This Already Quiz Mlp

The purpose of the Do I Know This Already quiz is to help you decide what parts of this chapter to use. If you intend to read the entire chapter, you do not necessarily need to answer these questions now. The quiz, derived from the major sections in the Foundation Topics portion of the chapter, helps you determine how to spend your limited study time. Table 10-1 outlines the major topics discussed in this chapter and the Do I Know This Already quiz questions that correspond to those topics....

CCNP Exam Topics

Carefully consider the exam topics Cisco has posted on its website as you study, particularly for clues to how deeply you should know each topic. Beyond that, you cannot go wrong by developing a broader knowledge of the subject matter. You can do that by reading and studying the topics presented in this book. Remember that it is in your best interest to become proficient in each of the CCNP subjects. When it is time to use what you have learned, being well rounded counts more than being well...

Dynamic Trunking Protocol

You manually can configure trunk links on Catalyst switches for either ISL or 802.1Q mode. In addition, Cisco has implemented a proprietary, point-to-point protocol called Dynamic Trunking Protocol (DTP) that negotiates a common trunking mode between two switches. The negotiation covers the encapsulation (ISL or 802.1Q) and whether the link becomes a trunk at all. This allows trunk links to be used without a great deal of manual configuration or administration. The use of DTP is explained in...

Voice VLAN Configuration

Although you can configure the IP Phone uplink as a trunk or nontrunk, the real consideration pertains to how the voice traffic will be encapsulated. The voice packets must be carried over a unique voice VLAN (known as the voice VLAN ID or WD) or over the regular data VLAN (known as the native VLAN or the port VLAN ID, PVID). The QoS information from the voice packets also must be carried. To configure the IP Phone uplink, just configure the switch port where it connects. The switch instructs...

Tuning Spanning Tree Convergence

STP uses several timers, a sequence of states that ports must move through, and specific topology change conditions to prevent bridging loops from forming in a complex network. Each of these parameters or requirements is based on certain default values for a typical network size and function. For the majority of cases, the default STP operation is sufficient to keep the network loop free and enable users to communicate. However, in certain situations, the default STP can cause network access to...

RSTP Convergence

Overhead Crane Collector Shoes

The convergence of STP in a network is the process that takes all switches from a state of independence (each thinks it must be the STP root) to one of uniformity, in which each switch has a place in a loop-free tree topology. You can think of convergence as a two-stage process 1. One common Root Bridge must be elected, and all switches must know about it. 2. The state of every switch port in the STP domain must be brought from a Blocking state to the appropriate state to prevent loops....

Ethernet Concepts

This section reviews the varieties of Ethernet and their application in a campus network. Recall how the bandwidth requirements for each network segment are determined by the types of applications in use, the traffic flows within the network, and the size of the user community served. Ethernet scales to support increasing bandwidths and should be chosen to match the need at each point in the campus network. As network bandwidth requirements grow, you can scale the links between access,...

Uplink Fast Access Layer Uplinks

Consider an access-layer switch that has redundant uplink connections to two distribution-layer switches. Normally, one uplink would be in the Forwarding state and the other would be in the Blocking state. If the primary uplink went down, up to 50 seconds could elapse before the redundant uplink could be used. The UplinkFast feature on Catalyst switches enables leaf-node switches or switches at the ends of the spanning-tree branches to have a functioning root port while keeping one or more...

Troubleshooting Port Connectivity

Suppose that you are experiencing problems with a switch port. How would you troubleshoot it The following sections cover a few common troubleshooting techniques. Use the show interfaces EXEC command to see complete information about the switch port. The port's current state is given in the first line of output, as in Example 4-2. Example 4-2 Determining Port State Information Switch show interfaces fastethernet 0 1 FastEthernet0 1 is up, line protocol is up Hardware is Fast Ethernet, address...

Tuning the Port ID

The fourth criteria of an STP decision is the port ID. The port ID value that a switch uses is actually a 16-bit quantity 8 bits for the port priority and 8 bits for the port number. The port priority is a value from 0 to 255 and defaults to 128 for all ports. The port number can range from 0 to 255 and represents the port's actual physical mapping. Port numbers begin with 1 at port 0 1 and increment across each module. (The numbers might not be consecutive because each module is assigned a...

Configuring a LACP Ether Channel

To configure switch ports for LACP negotiation, use the following commands Switch(config) lacp system-priority priority Switch(config) interface type mod num Switch(config-if) channel-protocol lacp Switch(config-if) channel-group number mode on I passive I active Switch(config-if) lacp port-priority priority First, the switch should have its LACP system priority defined (1 to 65,535 default 32,768). If desired, one switch should be assigned a lower system priority than the other so that it can...

Supplying Power to a Device

A switch first offers a default power allocation to the powered device. On a Catalyst 3750-24-PWR, for example, an IP Phone first receives 15.4W (0.32 amps at 48V DC). For Cisco ILP, inline power is provided over data pairs 2 and 3 (RJ-45 pins 1,2 and 3,6) at 48V DC. For IEEE 802.3af, power can be supplied in the same fashion (pins 1,2 and 3,6) or over pairs 1 and 4 (RJ-45 pins 4,5 and 7,8). Now the device has a chance to power up and bring up its Ethernet link, too. The power budget offered to...

Traditional WLAN Architecture

In Chapter 17, Wireless LAN Overview, and Chapter 18, Wireless Architecture and Design, the wireless LAN (WLAN) architecture centered around the wireless access point (AP). Each AP served as the central hub of its own BSS, where clients located with the AP cell gained an association. The traffic to and from each client had to pass through the AP in order to reach any other part of the network. Notice that even though an AP is centrally positioned to support its clients, it is quite isolated and...

Layer 2 Switch Operation

Recall that with shared Ethernet networks using hubs, many hosts are connected to a single broadcast and collision domain. In other words, shared Ethernet media operate at OSI Layer 1. Each host must share the available bandwidth with every other connected host. When more than one host tries to talk at one time, a collision occurs, and everyone must back off and wait to talk again. This forces every host to operate in half-duplex mode, by either talking or listening at any given time. In...

Tables Used in Switching

Catalyst switches maintain several types of tables to be used in the switching process. The tables are tailored for Layer 2 switching or MLS and are kept in very fast memory so that many fields within a frame or packet can be compared in parallel. All Catalyst switch models use a CAM table for Layer 2 switching. As frames arrive on switch ports, the source MAC addresses are learned and recorded in the CAM table. The port of arrival and the VLAN both are recorded in the table, along with a time...

Topology Changes

Bridge Mib Topology Change

To announce a change in the active network topology, switches send a TCN BPDU. Table 8-4 shows the format of these messages. Table 8-4 Topology Change Notification BPDU Message Content Table 8-4 Topology Change Notification BPDU Message Content Message Type (Configuration or TCN BPDU) A topology change occurs when a switch either moves a port into the Forwarding state or moves a port from the Forwarding or Learning states into the Blocking state. In other words, a port on an active switch comes...

Hot Standby Router Protocol

Briges And Vlan

HSRP is a Cisco-proprietary protocol developed to allow several routers (or multilayer switches) to appear as a single gateway IP address. RFC 2281 describes this protocol in more detail. Basically, each of the routers that provides redundancy for a given gateway address is assigned to a common HSRP group. One router is elected as the primary, or active, HSRP router another is elected as the standby HSRP router and all the others remain in the listen HSRP state. The routers exchange HSRP hello...

LAP Configuration

Cisco Lap 1042n Show Firmware Command

Cisco lightweight APs are designed to be zero-touch devices, which can be installed and used with little or no manual intervention. The WLC can manage every aspect of LAP operation, including code image synchronization, so almost no information needs to be primed or preconfigured in the LAP itself. This section covers the tasks you should consider prior to an LAP installation. A lightweight AP can require up to 15 W of power at 48 VDC. The exact amount of power depends upon the model and the...

Port Fast Access Layer Nodes

An end-user workstation is usually connected to a switch port in the access layer. If the workstation is powered off and then turned on, the switch will sense that the port link status has gone down and back up. The port will not be in a usable state until STP cycles from the Blocking state to the Forwarding state. With the default STP timers, this transition takes at least 30 seconds (15 seconds for Listening to Learning, and 15 seconds for Learning to Forwarding). Therefore, the workstation...

VLAN Membership

When a VLAN is provided at an access-layer switch, an end user must have some means of gaining membership to it. Two membership methods exist on Cisco Catalyst switches Static VLANs offer port-based membership, in which switch ports are assigned to specific VLANs. End user devices become members in a VLAN based on the physical switch port to which they are connected. No handshaking or unique VLAN membership protocol is needed for the end devices they automatically assume VLAN connectivity when...

Troubleshooting an Ether Channel

If you find that an EtherChannel is having problems, remember that the whole concept is based on consistent configurations on both ends of the channel. Here are some reminders about EtherChannel operation and interaction EtherChannel on mode does not send or receive PAgP or LACP packets. Therefore, both ends should be set to on mode before the channel can form. EtherChannel desirable (PAgP) or active (LACP) mode attempts to ask the far end to bring up a channel. Therefore, the other end must be...

WLC Configuration

A Cisco WLC has several types of interfaces that are used for various purposes. Perhaps the most difficult part of configuring a WLC is deciding how to lay out and connect the interfaces. Regardless of the hardware model, a WLC has the following interface types. Refer to Figure 19-14, which depicts the interfaces as they are commonly used in a network. Management An interface with a static IP address used for in-band management traffic you connect to this interface for web, Secure Shell (SSH),...

Troubleshooting VLANs and Trunks

Remember that a VLAN is nothing more than a logical network segment that can be spread across many switches. If a PC in one location cannot communicate with a PC in another location, where both are assigned to the same IP subnet, make sure that both of their switch ports are configured for the same VLAN. If they are, examine the path between the two. Is the VLAN carried continuously along the path If there are trunks along the way, is the VLAN being carried across the trunks To verify a VLAN's...

Gateway Load Balancing Protocol

Briges And Vlan

You should now know how both HSRP and VRRP can effectively provide a redundant gateway (virtual router) address. You can accomplish load balancing by configuring only multiple HSRP VRRP groups to have multiple virtual router addresses. More manual configuration is needed so that the client machines are divided among the virtual routers. Each group of clients must point to the appropriate virtual router. This makes load balancing somewhat labor-intensive, having a more or less fixed, or static,...

Link Aggregation Control Protocol

LACP is a standards-based alternative to PAgP, defined in IEEE 802.3ad (also known as IEEE 802.3 Clause 43, Link Aggregation). LACP packets are exchanged between switches over EtherChannel-capable ports. As with PAgP, neighbors are identified and port group capabilities are learned and compared with local switch capabilities. However, LACP also assigns roles to the EtherChannel's endpoints. The switch with the lowest system priority (a 2-byte priority value followed by a 6-byte switch MAC...

VTP Pruning

Recall that, by definition, a switch must forward broadcast frames out all available ports in the broadcast domain because broadcasts are destined everywhere there is a listener. Unless forwarded by more intelligent means, multicast frames follow the same pattern. In addition, frames destined for an address that the switch has not yet learned or has forgotten (the MAC address has aged out of the address table) must be forwarded out all ports in an attempt to find the destination. These frames...

Scenario 8 Securing Access and Managing Traffic in a Switched Network

This scenario is designed to stir your thinking about how to control access to switched networks, how to control traffic within a VLAN, and how to monitor traffic. 1. Network administrators want to have tight control over hosts moving around within their network. A Catalyst 3750 needs to have port-level security enabled on all 48 of its FastEthernet access-layer ports. Only one host should be connected per port, so the default behavior of shutting down the port is acceptable. What commands are...

Forwarding Information Base

The Layer 3 engine (essentially a router) maintains routing information, whether from static routes or dynamic routing protocols. Basically, the routing table is reformatted into an ordered list with the most specific route first, for each IP destination subnet in the table. The new format is called a Forwarding Information Base (FIB) and contains routing or forwarding information that the network prefix can reference. In other words, a route to 10.1.0.0 16 might be contained in the FIB along...

Electing Root Ports

Strategy Deployment After Use Case

Now that a reference point has been nominated and elected for the entire switched network, each nonroot switch must figure out where it is in relation to the Root Bridge. This action can be performed by selecting only one Root Port on each nonroot switch. The Root Port always points toward the current Root Bridge. STP uses the concept of cost to determine many things. Selecting a Root Port involves evaluating the Root Path Cost. This value is the cumulative cost of all the links leading to the...

Root Bridge Placement

What Root Bridge Cisco

Although STP is wonderfully automatic with its default values and election processes, the resulting tree structure might perform quite differently than expected. The Root Bridge election is based on the idea that one switch is chosen as a common reference point, and all other switches choose ports that have the best-cost path to the root. The Root Bridge election is also based on the idea that the Root Bridge can become a central hub that interconnects other legs of the network. Therefore, the...

WLAN Antennas

A variety of antennas suited for wireless LANs are available. Each type of antenna is designed for a specific application, either due to its ability to cover a certain area or pattern, or its capability to add gain to the signal. Omnidirectional antennas, such as the one shown in Figure 17-18, can be made in the shape of a thin cylinder. The rubber duckie-style antenna that is pictured can be folded up or down, depending on how the AP is mounted. Other omnidirectional antennas include the...

VLAN Frame Identification

Because a trunk link can transport many VLANs, a switch must identify frames with their respective VLANs as they are sent and received over a trunk link. Frame identification, or tagging, assigns a unique user-defined ID to each frame transported on a trunk link. Think of this ID as the VLAN number or VLAN color, as if each VLAN were drawn on a network diagram in a unique color. VLAN frame identification was developed for switched networks. As each frame is transmitted over a trunk link, a...

VTP Configuration

By default, every switch operates in VTP server mode for the management domain NULL (a blank string), with no password or secure mode. If the switch hears a VTP summary advertisement on a trunk port from any other switch, it automatically learns the VTP domain name, VLANs, and the configuration revision number it hears. This makes it easy to bring up a new switch in an existing VTP domain. However, be aware that the new switch stays in VTP server mode, something that might not be desirable. TIP...

Rapid PerVLAN Spanning Tree Protocol

Chapter 8, Traditional Spanning Tree Protocol, described PVST+ as the default STP mode on Catalyst switches. In PVST+, one spanning tree instance is created and used for each active VLAN that is defined on the switch. Each STP instance behaves according to the traditional 802.1D STP rules. You can improve the efficiency of each STP instance by configuring a switch to begin using RSTP instead. This means that each VLAN will have its own independent instance of RSTP running on the switch. This...

Cisco Unified Wireless Network Architecture

Cisco has collected a complete set of functions that are integral to wireless LANs and called them the Cisco Unified Wireless Network. This new architecture offers the following capabilities, which are centralized so that they affect wireless LAN devices located anywhere in the network To centralize these aspects of a WLAN, many of the functions found within autonomous APs have to be shifted toward some central location. The top portion of Figure 19-3 lists most of the activities performed by...

Electing Designated Ports

Electing Designated Port

By now, you should begin to see the process unfolding A starting or reference point has been identified, and each switch connects itself toward the reference point with the single link that has the best path. A tree structure is beginning to emerge, but links have only been identified at this point. All links still are connected and could be active, leaving bridging loops. To remove the possibility of bridging loops, STP makes a final computation to identify one Designated Port on each network...

Multiple Spanning Tree Protocol

Paulmann Light Easy Wire System

Chapter 8 covered two flavors of spanning-tree implementations IEEE 802.1Q and PVST+ both based on the 802.1D STP. These also represent the two extremes of STP operation in a network 802.1Q Only a single instance of STP is used for all VLANs. If there are 500 VLANs, only one instance of STP will be running. This is called the Common Spanning Tree (CST) and operates over the trunk's native VLAN. PVST+ One instance of STP is used for each active VLAN in the network. If there are 500 VLANs, 500...

Foundation Summary Kwi

The Foundation Summary is a collection of tables, lists, and other information that provides a convenient review of many key concepts in this chapter. If you are already comfortable with the topics in this chapter, this summary might help you recall a few details. If you just read this chapter, this review should help solidify some key facts. If you are doing your final prep before the exam, the following information is a convenient way to review the day before the exam Layer 2 switches learn...

Multilayer Switch Operation

Catalyst switches, such as the 3560 (with the appropriate Cisco IOS Software image), 4500, and 6500, also can forward frames based on Layer 3 and 4 information contained in packets. This is known as multilayer switching (MLS). Naturally, Layer 2 switching is performed at the same time because even the higher-layer encapsulations still are contained in Ethernet frames. Catalyst switches have supported two basic generations or types of MLS route caching (first generation MLS) and topology based...

Packet Rewrite

When a multilayer switch finds valid entries in the FIB and adjacency tables, a packet is almost ready to be forwarded. One step remains The packet header information must be rewritten. Keep in mind that multilayer switching occurs as quick table lookups to find the next-hop address and the outbound switch port. The packet is untouched and still has the original destination MAC address of the switch itself. The IP header also must be adjusted, as if a traditional router had done the forwarding....

Verifying InterVLAN Routing

To verify the configuration of a Layer 2 port, you can use the following EXEC command Switch show interface type mod num switchport The output from this command displays the access VLAN or the trunking mode and native VLAN. The administrative modes reflect what has been configured for the port, whereas the operational modes show the port's active status. You can use this same command to verify the configuration of a Layer 3 or routed port. In this case, you should see the switchport (Layer 2)...

MST Configuration

You must manually configure the MST configuration attributes on each switch in a region. There is currently no method to propagate this information from one switch to another, as is done with a protocol such as VLAN Trunking Protocol (VTP). To define the MST region, use the following configuration commands in the order shown Switch(config) spanning-tree mode mst Step 2 Enter the MST configuration mode Switch(config) spanning-tree mst configuration Step 3 Assign a region configuration name (up...

VLAN Trunks

At the access layer, end user devices connect to switch ports that provide simple connectivity to a single VLAN each. The attached devices are unaware of any VLAN structure and simply attach to what appears to be a normal physical network segment. Remember, sending information from an access link on one VLAN to another VLAN is not possible without the intervention of an additional device either a Layer 3 router or an external Layer 2 bridge. Note that a single switch port can support more than...

Access Point Operation

An AP's primary function is to bridge wireless data from the air to a normal wired network. An AP can accept connections from a number of wireless clients so that they become members of the LAN, as if the same clients were using wired connections. An AP can also act as a bridge to form a single wireless link from one LAN to another over a long distance. In that case, an AP is needed on each end of the wireless link. AP-to-AP or line-of-sight links are commonly used for connectivity between...

Scenario 7 IP Telephony in a Switched Network

This scenario uses a simple two-switch network to reinforce the concepts needed to properly implement IP telephony. Think about supplying power to the Cisco IP Phone, as well as how to implement QoS trust within this network. Use Figure 20-7 as a reference for the following questions. Figure 20-7 Network Diagram for Scenario 7 Figure 20-7 Network Diagram for Scenario 7 1. Assume that Catalyst B supports Power over Ethernet. If interface Fa1 0 1 has its default configuration, will power be...

Troubleshooting Switching Tables

If you see strange behavior in a Catalyst switch, it might be useful to examine the contents of the various switching tables. In any event, you might sometimes need to find out on which switch port a specific MAC address has been learned. To view the contents of the CAM table, you can use the following form of the show mac address-table EXEC command Switch show mac address-table dynamic address mac-address I interface type mod num I vlan vlan-id The entries that have been learned dynamically...

RF Characteristics

Signal Scattering

RF signals travel through the air as electromagnetic waves. In an ideal setting, a signal would arrive at the receiver exactly as it was sent by the transmitter. In the real world, this isn't always the case. RF signals are affected by the objects and materials they meet as they travel from the transmitter to the receiver. This section briefly explores the conditions that can affect wireless signal propagation. If an RF signal traveling through the air as a wave meets a dense reflective...

Configuring the VTP Mode

Next, you need to choose the VTP mode for the new switch. The three VTP modes of operation and their guidelines for use are as follows Server mode Server mode can be used on any switch in a management domain, even if other server and client switches are in use. This mode provides some redundancy in case of a server failure in the domain. Each VTP management domain should have at least one server. The first server defined in a network also defines the management domain that will be used by...

Network Traffic Models

To design and build a successful campus network, you must gain a thorough understanding of the traffic generated by applications in use, plus the traffic flow to and from the user communities. All devices on the network will produce data to be transported across the network. Each device can involve many applications that generate data with differing patterns and loads. Applications such as email, word processing, printing, file transfer, and most web browsers bring about data traffic patterns...

RF Signal Strength Terminology

Because so many variables exist in a wireless environment, being able to quantify an RF signal as it is transmitted and received is handy. Other factors that affect the signal strength can be taken into account, too. An RF signal can be measured as a function of its power or energy in units of Watts (W) or milliWatts (mW) one milliWatt is one-thousandth of one Watt. To put signal power into perspective, Table 17-3 shows typical power output from a variety of sources. Power values can vary over...

Spanning Tree Communication Bridge Protocol Data Units

STP operates as switches communicate with one another. Data messages are exchanged in the form of Bridge Protocol Data Units (BPDU). A switch sends a BPDU frame out a port, using the unique MAC address of the port itself as a source address. The switch is unaware of the other switches around it, so BPDU frames are sent with a destination address of the well-known STP multicast address 01-80-c2-00-00-00. Configuration BPDU, used for spanning-tree computation Topology Change Notification (TCN)...

Switch Port Aggregation with Ether Channel

As discussed in Chapter 4, Switch Port Configuration, switches can use Ethernet, Fast Ethernet, Gigabit, or 10-Gigabit Ethernet ports to scale link speeds by a factor of ten. Cisco offers another method of scaling link bandwidth by aggregating, or bundling, parallel links, termed the EtherChannel technology. Two to eight links of either Fast Ethernet (FE), Gigabit Ethernet (GE), or 10-Gigabit Ethernet (10GE) are bundled as one logical link of Fast EtherChannel (FEC), Gigabit EtherChannel (GEC),...

Layer 2 QoS Classification

Layer 2 frames themselves have no mechanism to indicate the priority or importance of their contents. One frame looks just as important as another. Therefore, a Layer 2 switch can forward frames only according to a best-effort delivery. When frames are carried from switch to switch, however, an opportunity for classification occurs. Recall that a trunk is used to carry frames from multiple VLANs between switches. The trunk does this by encapsulating the frames and adding a tag indicating the...

Selecting Ports to Configure

Before you can modify port settings, you must select one or more switch ports. Catalyst switches running the Catalyst operating system (CatOS) refer to these as ports, whereas switches running the Cisco IOS Software refer to them as interfaces. The BCMSN exam is based on IOS-based switches only. To select a single switch port, enter the following command in global configuration mode Switch(config) interface type module number The port is identified by its Ethernet type (fastethernet,...

Distributing Traffic in Ether Channel

Traffic in an EtherChannel is distributed across the individual bundled links in a deterministic fashion however, the load is not necessarily balanced equally across all the links. Instead, frames are forwarded on a specific link as a result of a hashing algorithm. The algorithm can use source IP address, destination IP address, or a combination of source and destination IP addresses, source and destination MAC addresses, or TCP UDP port numbers. The hash algorithm computes a binary pattern...

Virtual Router Redundancy Protocol

The Virtual Router Redundancy Protocol (VRRP) is a standards-based alternative to HSRP, defined in IETF standard RFC 2338. VRRP is so similar to HSRP that you need to learn only slightly different terminology and a couple of slight functional differences. When you understand HSRP operation and configuration, you will also understand VRRP. This section is brief, highlighting only the differences between HSRP and VRRP. VRRP provides one redundant gateway address from a group of routers. The...

Redundant Power Supplies

The Cisco Catalyst 6500 and 4500R platforms can accept two power supply modules in a single chassis. The power supplies must be identical, having the same power input and maximum power output ratings. The switch can be configured to operate in one of two possible power modes Combined mode Both power supplies work together to share the total power load for all modules that are installed in the switch chassis. The total load required can exceed the maximum power output rating of one power supply...

Layer 3 QoS Classification with DSCP

From the beginning, IP packets have always had a type of service (ToS) byte that can be used to mark packets. This byte is divided into a 3-bit IP Precedence value and a 4-bit ToS value. This offers a rather limited mechanism for QoS because only the 3 bits of IP Precedence are used to describe the per-hop QoS behavior. The DiffServ model keeps the existing IP ToS byte but uses it in a more scalable fashion. This byte also is referred to as the Differentiated Services (DS) field, with a...

RSTP Port Behavior

In 802.1D, each switch port is assigned a role and a state at any given time. Depending on the port's proximity to the Root Bridge, it takes on one of the following roles Blocking port (neither root nor designated) The Cisco-proprietary UplinkFast feature also reserved a hidden alternate port role for ports that offered parallel paths to the root but were in the Blocking state. Recall that each switch port also is assigned one of five possible states Only the Forwarding state allows data to be...

Can I Use Layer 2 Distribution Switches

Distribution Layer Switch

This chapter covers the best practice design that places Layer 3 switches at both the core and distribution layers. What would happen if you could not afford Layer 3 switches at the distribution layer Figure 2-5 shows a dual-core campus network with Layer 2 distribution switches. Notice how each access VLAN extends not only throughout the switch block but also into the core. This is because the VLAN terminates at a Layer 3 boundary present only in the core. As an example, VLAN A's propagation...

Managing Error Conditions on a Switch Port

Traditionally, a network-management application was used to detect a serious error condition on a switch port. A switch periodically was polled and switch port error counters were examined to see if an error condition had occurred. If so, an alert was issued so that someone could take action to correct the problem. Catalyst switches can detect error conditions automatically, without any further help. If a serious error occurs on a switch port, that port can be shut down automatically until...

Tuning the Root Path Cost

The Root Path Cost for each active port of a switch is determined by the cumulative cost as a BPDU travels along. As a switch receives a BPDU, the port cost of the receiving port is added to the root path cost in the BPDU. The port or port path cost is inversely proportional to the port's bandwidth. If desired, a port's cost can be modified from the default value. NOTE Before modifying a switch port's path cost, you should always calculate the Root Path Costs of other alternative paths through...

Modifying STP Timers

Recall that STP uses three timers to keep track of various port operation states and communication between bridges. The three STP timers can be adjusted by using the commands documented in the sections that follow. Remember that the timers need to be modified only on the Root Bridge because the Root Bridge propagates all three timer values throughout the network as fields in the configuration BPDU. Use one or more of the following global configuration commands to modify STP timers...

Exam Overview

Cisco offers three levels of certification, each with an increasing level of proficiency Associate, Professional, and Expert. These are commonly known by their acronyms CCNA CCDA (Cisco Certified Network Design Associate), CCNP CCDP (Cisco Certified Network Design Professional), and CCIE (Cisco Certified Internetworking Expert). There are others as well, but this book focuses on the certifications for enterprise networks.

Electing a Root Bridge

For all switches in a network to agree on a loop-free topology, a common frame of reference must exist to use as a guide. This reference point is called the Root Bridge. (The term bridge continues to be used even in a switched environment because STP was developed for use in bridges. Therefore, when you see bridge, think switch.) An election process among all connected switches chooses the Root Bridge. Each switch has a unique Bridge ID that identifies it to other switches. The Bridge ID is an...

Inter Controller Roaming

In some cases, a client might roam from one controller to another. For example, a large wireless network might consist of too many LAPs to be supported by a single WLC. The LAPs could also be distributed over several controllers for load balancing or redundancy purposes. In Figure 19-10, a wireless client is using an association with WLC1 through API. This is similar to Figure 19-8, but now each of the adjacent LAP cells belongs to a different WLC. All the client's traffic passes through the...

WLAN Building Blocks

At the most basic level, a wireless medium has no inherent organization. For example, a PC with wireless capability can simply bring up its wireless adapter anywhere at any time. Naturally, there must be something else that can also send and receive over the wireless media before the PC can communicate. TIP In IEEE 802.11 terminology, any group of wireless devices is known as a service set. The devices must share a common service set identifier (SSID), which is a text string included in every...

WLAN Security

As the central hub of a Basic Service Set (BSS), an AP effectively manages the WLAN for all clients within its range. Remember that all traffic going to or from a wireless client must go through the AP to reach other WLAN clients in the BSS or wired clients located elsewhere as illustrated in Figure 18-1. Clients cannot communicate directly with each other. Figure 18-1 An AP Serving as the Central Point of Contact in a WLAN Figure 18-1 An AP Serving as the Central Point of Contact in a WLAN The...

Spanning Tree Instances Within MST

Cut Pusheen

MST was designed to interoperate with all other forms of STP. Therefore, it also must support STP instances from each. This is where MST can get confusing. Think of the entire enterprise network as having a single CST topology so that one instance of STP represents any and all VLANs and MST regions present. The CST maintains a common loop-free topology while integrating all forms of STP that might be in use. To do this, CST must regard each MST region as a single black box bridge because it has...

WLAN Channel Layout

To minimize channel overlap and interference, AP cells should be designed so that adjacent APs use different channels. With 802.11b and 802.11g, you are limited to using channels 1, 6, and 11. The cells could be laid out in a regular, alternating pattern, as Figure 18-6 illustrates. Figure 18-6 Holes in an Alternating Channel Pattern in 802.11b g Figure 18-6 Holes in an Alternating Channel Pattern in 802.11b g However, notice what is happening in the center where the cells meet there is a small...