Routing Table
Link State and Advanced Distance Vector Protocols
In addition to distance vector-based routing, the second basic algorithm used for routing is the link-state algorithm. Link-state protocols build routing tables based on a topology database. This database is built from link-state packets that are passed between all the routers to describe the state of a network. The shortest path first algorithm uses the database to build the routing table. Figure 3-26 shows the components of a link-state protocol. Understanding the operation of link-state...
Q Trunking Configuration
The 802.1Q protocol carries traffic for multiple VLANs over a single link on a multivendor network. 802.1Q trunks impose several limitations on the trunking strategy for a network. You should consider the following Ensure that the native VLAN for an 802.1Q trunk is the same on both ends of the trunk link. If they are different, spanning-tree loops might result. Native VLAN frames are untagged. Table 2-6 shows how 802.1Q trunking interacts with other switch features. Table 2-6 Switch Feature...
Review Questions
Use the questions here to review what you learned in this chapter. The correct answers and solutions are found in the appendix, Answers to Chapter Review Questions. 1. What are two characteristics of OSPF (Choose two.) a. OSPF uses a two-layer hierarchy. b. OSPF is a proprietary routing protocol. d. OSPF is similar to the RIP routing protocol. e. OSPF is a distance vector routing protocol. 2. OSPF routes packets within a single_. 3. With OSPF, each router builds its SPF tree using the same...
Medium Sized Routed Network Construction
Routing is the process of determining where to send data packets that are destined for addresses outside the local network. Routers gather and maintain routing information to enable the transmission and receipt of these data packets. Routing information takes the form of entries in a routing table, with one entry for each identified route. The router can use a routing protocol to create and maintain the routing table dynamically so that network changes can be accommodated whenever they occur....
Scaling the Network with NAT and PAT
Two Internet scalability challenges are the depletion of registered IP version 4 (IPv4) address space and scaling in routing. Cisco IOS Network Address Translation (NAT) and Port Address Translation (PAT) are mechanisms for conserving registered IPv4 addresses in large networks and simplifying IPv4 address management tasks. NAT and PAT translate IPv4 addresses within private internal networks to legal IPv4 addresses for transport over public external networks, such as the Internet, without...
Reviewing Subnets
Prior to working with VLSM, it is important to have a firm grasp on IP subnetting. When you are creating subnets, you must determine the optimal number of subnets and hosts. Computing Usable Subnetworks and Hosts Remember that an IP address has 32 bits and comprises two parts a network ID and a host ID. The length of the network ID and host ID depends on the class of the IP address. The number of hosts available also depends on the class of the IP address. The default number of bits in the...
Spanning Tree Operation
STP performs three steps to provide a loop-free logical network topology 1. Elects one root bridge STP has a process to elect a root bridge. Only one bridge can act as the root bridge in a given network. On the root bridge, all ports are designated ports. Designated ports are in the forwarding state and are designated to forward traffic for a given segment. When in the forwarding state, a port can send and receive traffic. In Figure 2-22, switch X is elected as the root bridge. 2. Selects the...
Configuring Numbered Extended IPv4 ACLs
For more precise traffic-filtering control, use extended IPv4 ACLs, numbered 100 to 199 and 2000 to 2699 or named, which check for the source and destination IPv4 address. In addition, at the end of the extended ACL statement, you can specify the protocol and optional TCP or User Datagram Protocol (UDP) application to filter more precisely. Figure 6-16 illustrates the IP header fields that can be examined with an extended access list. Figure 6-16 Extended IPv4 Access Lists Figure 6-16 Extended...
Transitioning to IPv6
The ability to scale networks for future demands requires a limitless supply of IP addresses and improved mobility. IP version 6 (IPv6) satisfies the increasingly complex requirements of hierarchical addressing that IP version 4 (IPv4) does not provide. IPv6 uses some different address types that make IPv6 more efficient than IPv4. This section describes the different types of addresses that IPv6 uses and how to assign these addresses. Transitioning to IPv6 from IPv4 deployments can require a...
Show Ipv4 Routing Table
To conserve the IPv4 address space, you can use three types of Network Address Translation (NAT) static NAT, dynamic NAT, and Port Address Translation (PAT). Static NAT provides a one-to-one mapping of inside-local to inside-global addresses. With Dynamic NAT, the inside global addresses are automatically picked from a pool. PAT, also known as NAT overloading, allows you to translate many internal addresses into just one or a few inside global addresses. IPv6 addresses the exhaustion of IP...
Establishing OSPF Neighbor Adjacencies
Neighbor OSPF routers must recognize each other on the network before they can share information because OSPF routing depends on the status of the link between two routers. This process is done using the Hello protocol. The Hello protocol establishes and maintains neighbor relationships by ensuring bidirectional (two-way) communication between neighbors. Bidirectional communication occurs when a router recognizes itself listed in the hello packet received from a neighbor. Figure 4-2 illustrates...
Configuring Named ACLs
The named ACL feature allows you to identify standard and extended IP ACLs with an alphanumeric string (name) instead of the current numeric representations. Named IP ACLs allow you to delete individual entries in a specific ACL. If you are using Cisco IOS Release 12.3, you can use sequence numbers to insert statements anywhere in the named ACL. If you are using a software version earlier than Cisco IOS Release 12.3, you can insert statements only at the bottom of the named ACL. Because you can...
EIGRP Authentication
You can configure EIGRP neighbor authentication, also known as neighbor router authentication or route authentication, such that routers can participate in routing based on predefined passwords. By default, no authentication is used for EIGRP packets. EIGRP can be configured to use Message Digest Algorithm 5 (MD5) authentication. When you configure neighbor authentication on a router, the router authenticates the source of each routing update packet that it receives. For EIGRP MD5...
Components of Troubleshooting EIGRP
When troubleshooting any network protocol, it is important to follow a defined flow or methodology. The main aspect of troubleshooting routing protocols involves ensuring that communication exists between the routers. The following sections describe the basic components of troubleshooting a network that is running EIGRP. Figure 5-8 shows an example of the flow used for diagnosing EIGRP problems. The major components of EIGRP troubleshooting include the following items EIGRP neighbor...
Troubleshooting Eigrp Neighbor Relationships
The first step in the flow is to troubleshoot neighbor relationships. Figure 5-9 shows the steps for troubleshooting these issues. Figure 5-9 Troubleshooting EIGRP Neighbor Issues Figure 5-9 Troubleshooting EIGRP Neighbor Issues Example 5-9 shows output from the show ip eigrp neighbors command, which indicates that a successful neighbor relationship exists with two routers. Example 5-9 Confirming EIGRP Neighbor Relationships Example 5-9 Confirming EIGRP Neighbor Relationships For EIGRP routers...
Configuring RSTP
Cisco Catalyst switches support three types of spanning-tree protocols PVST+, PVRST+, and MSTP. PVST+ Based on the 802.1D standard, this includes Cisco proprietary extensions, such as BackboneFast, UplinkFast, and PortFast, which improve STP convergence time. PVRST+ Based on the 802.1w standard, this has a faster convergence than 802.1D. MSTP (802.1s) Combines the best aspects of PVST+ and the IEEE standards. To implement PVRST+, perform these steps Step 2 Designate and configure a switch to be...
Introduction To On Multirouter
Since the introduction of the personal computer in the early 1970s, businesses have found more uses and applications for technology in the workplace. With the introduction of local-area networks, file sharing, and print sharing in the 1980s, it became obvious that distributed computing was no longer a passing fad. By the 1990s, computers became less expensive, and innovations such as the Internet allowed everyone to connect to computer services worldwide. Computing services have become large...
Port Based Authentication
The IEEE 802.1X standard defines a port-based access control and authentication protocol that restricts unauthorized workstations from connecting to a LAN through publicly accessible switch ports. The authentication server authenticates each workstation that is connected to a switch port before making available any services offered by the switch or the LAN. Figure 2-36 shows the roles of each device in port-based authentication. Figure 2-36 802.1X Port-Based Authentication Requests Access and...
Verifying the OSPF Configuration
You can use any one of a number of show commands to display information about an OSPF configuration. The show ip protocols command displays parameters about timers, filters, metrics, networks, and other information for the entire router. The show ip route command displays the routes that are known to the router and how they were learned. This command is one of the best ways to determine connectivity between the local router and the rest of the internetwork. Example 4-1 shows the output from the...
Load Balancing with EIGRP
Typically, networks are configured with multiple paths to a remote network. When these paths are equal or nearly equal, it makes sense to utilize all the available paths. Unlike Layer 2 forwarding, Layer 3 forwarding has the capability to load-balance between multiple paths. That is, the router can send frames out multiple interfaces to reduce the amount of traffic sent to a single network connection. The key to this feature is that the network paths must be of equal cost (or nearly equal for...
ACL Wildcard Masking
Address filtering occurs when you use ACL address wildcard masking to identify how to check or ignore corresponding IP address bits. Wildcard masking for IP address bits uses the numbers 1 and 0 to identify how to treat the corresponding IP address bits, as follows Wildcard mask bit 0 Match the corresponding bit value in the address. Wildcard mask bit 1 Do not check (ignore) the corresponding bit value in the address. NOTE A wildcard mask is sometimes referred to as an inverse mask. By...
OSPF Authentication
OSPF neighbor authentication (also called neighbor router authentication or route authentication) can be configured such that routers can participate in routing based on predefined passwords. When you configure neighbor authentication on a router, the router authenticates the source of each routing update packet that it receives. This authentication is accomplished by the exchange of an authenticating key (sometimes referred to as a password) that is known to both the sending and receiving...
Configuring and Verifying EIGRP
Use the router eigrp and network commands to create an EIGRP routing process. Note that EIGRP requires an autonomous system (AS) number. The AS number does not have to be registered as is the case when routing on the Internet with the Border Gateway Protocol (BGP) routing protocol. However, all routers within an AS must use the same AS number to exchange routing information with each other. Figure 5-3 shows the EIGRP configuration of a simple network. 172.16.1.1 10.1.1.1 10.1.1.2 10.2.2.2...
Configuring InterVLAN Routing
To be able to route between VLANs on a switch, you will need to be able to configure inter-VLAN routing. In Figure 2-33, the FastEthernet 0 0 interface is divided into multiple subinterfaces FastEthernet 0 0.1 and FastEthernet 0 0.2. Each subinterface represents the router in each of the VLANs for which it routes. Figure 2-33 Inter-VLAN Routing Configuration Figure 2-33 Inter-VLAN Routing Configuration Use the encapsulation dot1q vlan identifier command (where vlan identifier is the VLAN...
Example Selecting the Root Bridge
In Figure 2-23, both switches use the same default priority. The switch with the lowest MAC address is the root bridge. In the example, switch X is the root bridge, with a BID of 0x8000 (0c00.1111.1111). When STP is enabled, every bridge in the network goes through the blocking state and the transitory states of listening and learning at power-up. If properly configured, the ports then stabilize to the forwarding or blocking state. Forwarding ports provide the lowest-cost path to the root...
ACL Identification
When you create numbered ACLs, you enter an ACL number as the first argument of the global ACL statement. The test conditions for an ACL vary depending on whether the number identifies a standard or extended ACL. You can create many ACLs for a protocol. Select a different ACL number for each new ACL within a given protocol. However, you can apply only one ACL per protocol, per direction, and per interface. Specifying an ACL number from 1 to 99 or 1300 to 1999 instructs the router to accept...
PVST Operation
In a Cisco PVST+ environment, you can tune the spanning-tree parameters so that half of the VLANs forward on each uplink trunk. To easily achieve this, you configure one switch to be elected the root bridge for half of the total number of VLANs in the network and a second switch to be elected the root bridge for the other half of the VLANs. Providing different STP root switches per VLAN creates a more redundant network. Spanning-tree operation requires that each switch has a unique BID. In the...
Cisco Catalyst Switches Do Not Exchange VTP Information
When Cisco switches do not exchange VTP information, you need to be able to determine why they are not functioning properly. Use the following guidelines to troubleshoot this problem There are several reasons why VTP fails to exchange the VLAN information. Verify these items if switches that run VTP fail to exchange VLAN information. VTP information passes only through a trunk port. Ensure that all ports that interconnect switches are configured as trunks and are actually trunking. Ensure that...
VLAN Creation
Before you create VLANs, you must decide whether to use VTP to maintain global VLAN configuration information for your network. The maximum number of VLANs is switch dependent. Many access layer Cisco Catalyst switches can support up to 250 user-defined VLANs. Cisco Catalyst switches have a factory default configuration in which various default VLANs are preconfigured to support various media and protocol types. The default Ethernet VLAN is VLAN 1. Cisco Discovery Protocol and VTP...
Understanding Distance Vector Routing Protocols
Distance vector-based routing algorithms (also known as Bellman-Ford-Moore algorithms) pass periodic copies of a routing table from router to router and accumulate distance vectors. (Distance means how far, and vector means in which direction.) Regular updates between routers communicate topology changes. Each router receives a routing table from its direct neighbor. For example, in Figure 3-5, Router B receives information from Router A. Router B adds a distance vector metric (such as the...
Route Summarization with VLSM
In large internetworks, hundreds or even thousands of network addresses can exist. In these environments, it is often not desirable for routers to maintain many routes in their routing table. Route summarization, also called route aggregation or supernetting, can reduce the number of routes that a router must maintain by representing a series of network numbers in a single summary address. This section describes and provides examples of route summarization, including implementation...
Troubleshooting OSPF Neighbor Adjacencies
The first component to troubleshoot and verify is the OSPF neighbor adjacency. Figure 4-9 shows the verification troubleshooting components for neighbor adjacencies. Figure 4-9 Troubleshooting OSPF Neighbor Adjacencies Figure 4-9 Troubleshooting OSPF Neighbor Adjacencies A healthy OSPF neighbor state is Full. If the OSPF neighbor state remains in any other state, it may indicate a problem. Example 4-12 demonstrates sample output from the show ip ospf neighbor command to gather this information....
RSTP Port Roles
RSTP defines the port roles as follows Root A forwarding port elected for the spanning-tree topology. Designated A forwarding port elected for every switched LAN segment. Alternate An alternate path to the root bridge that is different from the path that the root port takes. Backup A backup path that provides a redundant (but less desirable) connection to a segment to which another switch port already connects. Backup ports can exist only where two ports are connected in a loopback by a...
Hardware Issues
Hardware issues can be one of the reasons a switch has connectivity issues. To rule out hardware issues, verify the following The port status for both ports involved in the link Ensure that neither is shut down. The administrator may have manually shut down one or both ports, or the switch software may have shut down one of the ports because of a configuration error. If one side is shut down and the other is not, the status on the enabled side will be notconnected (because it does not sense a...
Troubleshooting OSPF Routing Tables
After you have verified that the adjacencies are correct, the next step is to troubleshoot verify the routing tables. Figure 4-10 shows the procedures for verifying the routing tables. Figure 4-10 Troubleshooting OSPF Routing Tables Figure 4-10 Troubleshooting OSPF Routing Tables An OSPF route found in the routing table can have a variety of different codes O OSPF intra-area, within the same area, route from a router within the same OSPF area O IA OSPF inter-area, from another area in the OSPF...
Introducing VLSMs
When an IP network is assigned more than one subnet mask for a given major network, it is considered a network with VLSMs, overcoming the limitation of a fixed number of fixed-size subnetworks imposed by a single subnet mask. Figure 3-30 shows the 172.16.0.0 network with four separate subnet masks. VLSMs provide the capability to include more than one subnet mask within a network and the capability to subnet an already subnetted network address. In addition, VLSM offers the following benefits...
Configuring and Verifying OSPF
The router ospf command uses a process identifier as an argument. The process ID is a unique, arbitrary number that you select to identify the routing process. The process ID does not need to match the OSPF process ID on other OSPF routers. The network command identifies which IP networks on the router are part of the OSPF network. For each network, you must also identify the OSPF area to which the networks belong. The network command takes the three arguments listed in Table 4-1. The table...
Load Balancing with OSPF
Load balancing is a standard functionality of Cisco IOS Software that is available across all router platforms. It is inherent to the forwarding process in the router, and it enables a router to use multiple paths to a destination when it forwards packets. The number of paths used is limited by the number of entries that the routing protocol puts in the routing table. Four entries is the default in Cisco IOS Software for IP routing protocols except for BGP. BGP has a default of one entry. The...
SPF Algorithm
The SPF algorithm places each router at the root of a tree and calculates the shortest path to each node, using Dijkstra's algorithm, based on the cumulative cost that is required to reach that destination. LSAs are flooded throughout the area using a reliable algorithm, which ensures that all routers in an area have the same topological database. Each router uses the information in its topological database to calculate a shortest path tree, with itself as the root. The router then uses this...
Configuring Numbered Standard IPv4 ACLs
To configure numbered standard IPv4 ACLs on a Cisco router, you must create a standard IPv4 ACL and activate an ACL on an interface. The access-list command creates an entry in a standard IPv4 traffic filter list. The ip access-group command links an existing ACL to an interface. Only one ACL per protocol, per direction, and per interface is allowed. NOTE To remove an IP ACL from an interface, first enter the no ip access-group name number in out command on the interface then enter the global...
Troubleshooting Eigrp Authentication
The last step in the flowchart in Figure 5-8 is to troubleshoot EIGRP authentication problems, if configured. This is accomplished by verifying that EIGRP authentication is successful. Example Successful MD5 Authentication The output of the debug eigrp packets command on Router X, shown in Example 5-17, illustrates that Router X is receiving EIGRP packets with MD5 authentication and a key ID equal to 1 from Router Y. Example 5-17 Confirming MD5 Authentication on Router X QUERY, REPLY, HELLO,...
Native VLAN Mismatches
The native VLAN that is configured on each end of an IEEE 802.1Q trunk must be the same. Remember that a switch receiving an untagged frame assigns the frame to the native VLAN of the trunk. If one end of the trunk is configured for native VLAN 1 and the other end is configured for native VLAN 2, a frame sent from VLAN 1 on one side is received on VLAN 2 on the other. VLAN 1 leaks into the VLAN 2 segment. There is no reason this behavior would be required, and connectivity issues will occur in...
Example Broadcast Storms
Figure 2-18 illustrates the problem of a broadcast storm. The following describes the sequence of events that start a broadcast storm 1. When host X sends a broadcast frame, such as an Address Resolution Protocol (ARP) for its default gateway (Router Y), switch A receives the frame. Figure 2-18 Broadcast Storm Server Host X 2. Switch A examines the destination address field in the frame and determines that the frame must be flooded onto the lower Ethernet link, segment 2. 3. When this copy of...
Understanding VLANs
Understanding how VLANs operate and what the associated protocols are is important for configuring, verifying, and troubleshooting VLANs on Cisco access switches. This section describes VLAN operations and their associated protocols. A poorly designed network has increased support costs, reduced service availability, security risks, and limited support for new applications and solutions. Less-than-optimal performance affects end users and access to central resources directly. Some of the issues...
Per VLAN Spanning Tree
The 802.1D standard defines a Common Spanning Tree (CST) that assumes only one spanning-tree instance for the entire switched network, regardless of the number of VLANs. In a network running CST, these statements are true No load sharing is possible one uplink must block for all VLANs. The CPU is spared only one instance of spanning tree must be computed. Per VLAN Spanning Tree Plus (PVST+) defines a spanning-tree protocol that has several spanning-tree instances running for the network, one...
ACL Operation
ACLs express the set of rules that give added control for packets that enter inbound interfaces, packets that relay through the router, and packets that exit outbound interfaces of the router. ACLs do not act on packets that originate from the router. Instead, ACLs are statements that specify conditions of how the router handles the traffic flow through specified interfaces. Inbound ACLs Incoming packets are processed before they are routed to an outbound interface. An inbound ACL is efficient...
Troubleshooting ACLs
When you finish the ACL configuration, use the show commands to verify the configuration. Use the show access-lists command to display the contents of all ACLs, as demonstrated in Example 6-13. By entering the ACL name or number as an option for this command, you can display a specific ACL. To display only the contents of all IP ACLs, use the show ip access-list command. Example 6-13 Verifying Access List Configuration 10 deny 10.1.1.0, wildcard bits 0.0.0.255 20 permit 10.3.3.1 30 permit...
Switch Behavior with Broadcast Frames
Switches handle broadcast and multicast frames differently from the way they handle unicast frames. Because broadcast and multicast frames may be of interest to all stations, the switch or bridge normally floods broadcast and multicast frames to all ports except the originating port. A switch or bridge never learns a broadcast or multicast address because broadcast and multicast addresses never appear as the source address of a frame. This flooding of broadcast and multicast frames can cause a...
Trademark Acknowledgments
All terms mentioned in this book that are known to be trademarks or service marks have been appropriately capitalized. Cisco Press or Cisco Systems, Inc., cannot attest to the accuracy of this information. Use of a term in this book should not be regarded as affecting the validity of any trademark or service mark. Americas Headquarters Asia Pacific H Cisco Systems, Ina Cisco Systems, Inc. Cisco Systems International BV 170 West Tasman Drive 168 Robinson Road Haarler berg park San Jose. CA...
Problem Host Connectivity
Host 10.1.1.1 has no connectivity with 10.100.100.1. The following output reveals information about the access list(s) in place to help determine the possible cause of the problem 10 deny 10.1.1.0, wildcard bits 20 permit 10.1.1.1 30 permit ip any any The cause of this problem is that Host 10.1.1.1 has no connectivity with 10.100.100.1 because of the order of the access list 10 rules. Because the router processes ACLs from the top down, statement 10 would deny host 10.1.1.1, and statement 20...
MAC Database Instability
MAC database instability results when multiple copies of a frame arrive on different ports of a switch. This subtopic describes how MAC database instability can arise and explains what problems can result. Figure 2-20 illustrates this problem switch B installs a database entry, mapping the MAC address of host X to port 1. Sometime later, when the copy of the frame transmitted through switch A arrives at port 2 of switch B, switch B removes the first entry and installs an entry that incorrectly...




























