Index Manuals Cisco Industrial Ethernet 4000, 4010 and 5000 Switch Software. Configuration Guide (2022)
|
|
|
Contents
Preface
liii
Audience
liii
Purpose
liii
Conventions
liii
Related Publications
liv
Communications, Services, and Additional Information
liv
Cisco Bug Search Tool
lv
. lv
Configuration Overview
1
Feature Availability
1
Feature Software Licensing
1
Right to Use Licenses
1
Defaults
2
Configuring RTU Licenses
2
Ease-of-Deployment and Ease-of-Use Features
3
Performance Features
3
Management Options
4
Industrial Application
5
Default Settings After Initial Switch Configuration
5
Using the Command-Line Interface
9
Information About Using the Command-Line Interface
9
Command Modes
9
Help System
10
Understanding Abbreviated Commands
11
No and default Forms of Commands
11
CLI Error Messages
11
Configuration Logging
12
How to Use the CLI to Configure Features
12
Configuring the Command History
12
Changing the Command History Buffer Size
12
Recalling Commands
13
Disabling the Command History Feature
13
Using Editing Features
13
Enabling and Disabling Editing Features
13
Editing Commands Through Keystrokes
14
Editing Command Lines That Wrap
15
Searching and Filtering Output of show and more Commands
16
Accessing the CLI
16
Accessing the CLI through a Console Connection or through Telnet
16
Configuring Interfaces
17
Understanding Interface Types
17
UNI, NNI, and ENI Port Types
17
Port-Based VLANs
18
Switch Ports
19
Access Ports
19
Trunk Ports
19
Tunnel Ports
19
Routed Ports
20
Switch Virtual Interfaces
20
EtherChannel Port Groups
20
Power over Ethernet Ports
21
Supported Protocols and Standards
21
Powered-Device Detection and Initial Power Allocation
22
Power Management Modes
22
Power Monitoring and Power Policing
23
Dual-Purpose Ports on IE 4000
25
Connecting Interfaces
25
Using the Switch USB Port
26
Console Port Change Logs
26
Configuring the Console Media Type
27
Using Interface Configuration Mode
27
Procedures for Configuring Interfaces
28
Configuring a Range of Interfaces
29
Configuring and Using Interface Range Macros
30
Configuring Ethernet Interfaces
31
Default Ethernet Interface Configuration
32
Configuring the Port Type
33
Configuring Interface Speed and Duplex Mode
34
Speed and Duplex Configuration Guidelines
34
Setting the Interface Speed and Duplex Parameters
35
Configuring a Power Management Mode on a PoE Port
36
Budgeting Power for Devices Connected to a PoE Port
37
Configuring IEEE 802.3x Flow Control
39
Configuring Auto-MDIX on an Interface
40
Adding a Description for an Interface
41
iv
Configuring Layer 3 Interfaces
42
Configuring the System MTU
43
Monitoring and Maintaining the Interfaces
45
Monitoring Interface Status
45
Using FEFI to Maintain the Fiber FE Interfaces
46
Default FEFI Configuration
46
Using FEFI on GE SFP Ports
47
Clearing and Resetting Interfaces and Counters
47
Shutting Down and Restarting the Interface
47
Configuring Switch Alarms
49
Information About Switch Alarms
49
Global Status Monitoring Alarms
49
FCS Error Hysteresis Threshold
49
Port Status Monitoring Alarms
50
Triggering Alarm Options
50
Default Switch Alarm Settings
51
How to Configure Switch Alarms
51
Configuring the Power Supply Alarms
51
Configuring the Switch Temperature Alarms
52
Associating the Temperature Alarms to a Relay
52
Configuring the FCS Bit Error Rate Alarm
52
Setting the FCS Error Threshold
52
Setting the FCS Error Hysteresis Threshold
53
Configuring Alarm Profiles
53
Creating an Alarm Profile
53
Modifying an Alarm Profile
54
Attaching an Alarm Profile to a Specific Port
54
Enabling SNMP Traps
54
Monitoring and Maintaining Switch Alarms Status
54
Configuration Examples for Switch Alarms
55
Configuring External Alarms: Example
55
Associating Temperature Alarms to a Relay: Examples
55
Configuring a Dual Power Supply: Examples
55
Displaying Alarm Settings: Example
56
Additional References
57
Related Documents
58
Standards
58
MIBs
58
RFCs
58
Technical Assistance
58
v
Performing Switch Setup Configuration
59
Restrictions for Performing Switch Setup Configuration
59
Information About Performing Switch Setup Configuration
59
Switch Boot Process
59
Default Switch Boot Settings
60
Switch Boot Optimization
60
Switch Information Assignment
61
Switch Default Settings
62
DHCP-Based Autoconfiguration Overview
62
DHCP Client Request Process
62
DHCP-Based Autoconfiguration and Image Update
63
DHCP Autoconfiguration
64
DHCP Auto-Image Update
64
DHCP Server Configuration Guidelines
64
TFTP Server
65
DNS Server
65
Relay Device
65
How to Obtain Configuration Files
66
How to Control Environment Variables
67
Common Environment Variables
67
Scheduled Reload of the Software Image
68
How to Perform Switch Setup Configuration
69
Configuring DHCP Autoconfiguration (Only Configuration File)
69
Configuring DHCP Auto-Image Update (Configuration File and Image)
69
Configuring the Client
70
Manually Assigning IP Information on a Routed Port
71
Manually Assigning IP Information to SVIs
71
Modifying the Startup Configuration
72
Specifying the Filename to Read and Write the System Configuration
72
Manually Booting the Switch
72
Booting a Specific Software Image
73
Monitoring Switch Setup Configuration
74
Verifying the Switch Running Configuration
74
Configuration Examples for Performing Switch Setup Configuration
75
Retrieving IP Information Using DHCP-Based Autoconfiguration: Example
75
Scheduling Software Image Reload: Examples
76
Configuring DHCP Auto-Image Update: Example
76
Configuring a Switch as a DHCP Server: Example
77
Configuring Client to Download Files from DHCP Server
77
Additional References
78
Standards
78
MIBs
78
vi
RFCs
78
Technical Assistance
78
Configuring Cisco IOS Configuration Engine
79
Prerequisites for Configuring Cisco IOS Configuration Engine
79
Information About Configuring Cisco IOS Configuration Engine
80
Configuration Service
81
Event Service
81
NameSpace Mapper
82
CNS IDs and Device Hostnames
82
ConfigID
82
DeviceID
82
Hostname and DeviceID Interaction
83
Using Hostname, DeviceID, and ConfigID
83
Cisco IOS Agents
83
Initial Configuration
83
Incremental (Partial) Configuration
84
Synchronized Configuration
84
How to Configure Cisco IOS Configuration Engine
84
Configuring Cisco IOS Agents
84
Enabling CNS Event Agent
84
Enabling Cisco IOS CNS Agent and an Initial Configuration
85
Enabling a Partial Configuration
88
Monitoring and Maintaining Cisco IOS Configuration Engine
89
Configuration Examples for Cisco IOS Configuration Engine
89
Enabling the CNS Event Agent: Example
89
Configuring an Initial CNS Configuration: Examples
89
Additional References
90
Related Documents
90
Standards
90
MIBs
90
RFCs
90
Technical Assistance
90
Configuring Switch Clusters
91
Cluster Command Switch Characteristics
91
Standby Cluster Command Switch Characteristics
91
Candidate Switch and Cluster Member Switch Characteristics
91
Restrictions for Configuring Switch Clusters
92
Information About Configuring Switch Clusters
92
Benefits of Clustering Switches
92
Eligible Cluster Switches
93
vii
How to Plan for Switch Clustering
93
Automatic Discovery of Cluster Candidates and Members
94
Discovery Through CDP Hops
94
Discovery Through Non-CDP-Capable and Noncluster-Capable Devices
95
Discovery Through Different VLANs
96
Discovery Through Different Management VLANs
97
Discovery Through Routed Ports
97
Discovery of Newly Installed Switches
98
IP Addresses
99
Hostnames
99
Passwords
100
SNMP Community Strings
100
TACACS+ and RADIUS
100
LRE Profiles
100
Managing Switch Clusters
101
Using the CLI to Manage Switch Clusters
101
Using SNMP to Manage Switch Clusters
101
Additional References
102
Related Documents
103
Standards
103
MIBs
103
RFCs
103
Technical Assistance
103
Performing Switch Administration
105
Information About Performing Switch Administration
105
System Time and Date Management
105
System Clock
105
Network Time Protocol
105
NTP Version 4
107
DNS
107
Default DNS Configuration
107
Login Banners
107
System Name and Prompt
108
MAC Address Table
108
Address Table
108
MAC Addresses and VLANs
108
Default MAC Address Table Configuration
109
Address Aging Time for VLANs
109
MAC Address Change Notification Traps
109
Static Addresses
109
Unicast MAC Address Filtering
110
viii
MAC Address Learning on a VLAN
110
ARP Table Management
111
How to Perform Switch Administration
111
Configuring Time and Date Manually
111
Setting the System Clock
111
Configuring the Time Zone
112
Configuring Summer Time (Daylight Saving Time)
112
Configuring Summer Time (Exact Date and Time)
113
Configuring a System Name
113
Setting Up DNS
113
Configuring Login Banners
114
Configuring a Message-of-the-Day Login Banner
114
Configuring a Login Banner
114
Managing the MAC Address Table
115
Changing the Address Aging Time
115
Configuring MAC Address Change Notification Traps
116
Configuring MAC Address Move Notification Traps
117
Configuring MAC Threshold Notification Traps
117
Adding and Removing Static Address Entries
119
Configuring Unicast MAC Address Filtering
119
Disabling MAC Address Learning on a VLAN
119
Monitoring and Maintaining Switch Administration
120
Configuration Examples for Performing Switch Admininistration
120
Setting the System Clock: Example
120
Configuring Summer Time: Examples
120
Configuring a MOTD Banner: Examples
121
Configuring a Login Banner: Example
121
Configuring MAC Address Change Notification Traps: Example
121
Sending MAC Address Move Notification Traps: Example
121
Configuring MAC Threshold Notification Traps: Example
122
Adding the Static Address to the MAC Address Table: Example
122
Configuring Unicast MAC Address Filtering: Example
122
Additional References
122
Related Documents
123
Standards
123
MIBs
123
RFCs
123
Technical Assistance
123
Configuring PTP
125
ix
Configuring PROFINET
127
Restrictions for Configuring PROFINET
127
Information About Configuring PROFINET
127
PROFINET Device Roles
128
PROFINET Device Data Exchange
128
How to Configure PROFINET
130
Configuring PROFINET
130
Default Configuration
130
Enabling PROFINET
130
Monitoring and Maintaining PROFINET
131
Troubleshooting PROFINET
131
Additional References
131
Related Documents
132
Standards
132
MIBs
132
RFCs
132
Technical Assistance
132
Configuring CIP
133
Restrictions for Configuring CIP
133
Information About Configuring CIP
133
How to Configure CIP
133
Default Configuration
133
Enabling CIP
133
Monitoring CIP
134
Troubleshooting CIP
134
Additional References
134
Related Documents
135
Standards
135
MIBs
135
RFCs
135
Technical Assistance
135
Configuring SDM Templates
137
Prerequisites for Configuring SDM Templates
137
Restrictions for Configuring SDM Templates
137
Information About Configuring SDM Templates
137
SDM Templates
137
Dual IPv4 and IPv6 SDM Default Template
138
How to Configure the Switch SDM Templates
139
Setting the SDM Template
139
Configuration Examples for Configuring SDM Templates
139
Configuring IP Services Templates: Examples
139
x
Configuring Lanbase Templates: Example
141
Configuring Switch-Based Authentication
143
Prerequisites for Configuring Switch-Based Authentication
143
Restrictions for Configuring Switch-Based Authentication
143
Information About Configuring Switch-Based Authentication
143
Prevention for Unauthorized Switch Access
143
Password Protection
144
Default Password and Privilege Level Configuration
144
Enable Secret Passwords with Encryption
144
Password Recovery
144
Telnet Password for a Terminal Line
145
Username and Password Pairs
145
Multiple Privilege Levels
145
Switch Access with TACACS+
145
TACACS+
145
TACACS+ Operation
147
Default TACACS+ Configuration
147
TACACS+ Server Host and the Authentication Key
147
TACACS+ Login Authentication
148
TACACS+ Authorization for Privileged EXEC Access and Network Services
148
TACACS+ Accounting
148
Switch Access with RADIUS
148
RADIUS
148
RADIUS Operation
150
Default RADIUS Configuration
150
RADIUS Change of Authorization
150
CoA Request Commands
153
RADIUS Server Host
155
RADIUS Login Authentication
156
Radius Method List
156
AAA Server Groups
156
RADIUS Authorization for User Privileged Access and Network Services
156
RADIUS Accounting
157
Establishing a Session with a Router if the AAA Server is Unreachable
157
Vendor-Specific RADIUS Attributes
157
Vendor-Proprietary RADIUS Server Communication
157
Switch Access with Kerberos
157
Understanding Kerberos
158
Kerberos Operation
160
xi
Kerberos Configuration
161
Local Authentication and Authorization
161
Secure Shell
161
SSH
161
SSH Servers, Integrated Clients, and Supported Versions
161
Limitations
162
SSH Configuration Guidelines
162
Switch for Secure Socket Layer HTTP
162
Secure HTTP Servers and Clients
163
Default SSL Settings
163
Certificate Authority Trustpoints
163
CipherSuites
164
Secure Copy Protocol
164
How to Configure Switch-Based Authentication
165
Configuring Password Protection
165
Setting or Changing a Static Enable Password
165
Protecting Enable and Enable Secret Passwords with Encryption
166
Disabling Password Recovery
166
Setting a Telnet Password for a Terminal Line
167
Configuring Username and Password Pairs
167
Setting the Privilege Level for a Command
168
Changing the Default Privilege Level for Lines
168
Logging Into and Exiting a Privilege Level
169
Configuring TACACS+
169
Identifying the TACACS+ Server Host and Setting the Authentication Key
170
Configuring TACACS+ Login Authentication
170
Configuring TACACS+ Authorization for Privileged EXEC Access and Network
Services
172
Starting TACACS+ Accounting
172
Configuring Radius Server Communication
172
Defining AAA Server Groups
174
Configuring RADIUS Login Authentication
175
Configuring RADIUS Authorization for User Privileged Access and Network Services
176
Starting RADIUS Accounting
176
Configuring Settings for All RADIUS Servers
176
Configuring the Switch for Vendor-Proprietary RADIUS Server Communication
177
Configuring CoA on the Switch
177
Configuring the Switch for Local Authentication and Authorization
178
Configuring Secure Shell
179
Setting Up the Switch to Run SSH
179
xii
Configuring the SSH Server
179
Configuring Secure HTTP Servers and Clients
181
Configuring a CA Trustpoint
181
Configuring the Secure HTTP Server
181
Configuring the Secure HTTP Client
183
Monitoring and Maintaining Switch-Based Authentication
183
Configuration Examples for Configuring Switch-Based Authentication
184
Changing the Enable Password: Example
184
Configuring the Encrypted Password: Example
184
Setting the Telnet Password for a Terminal Line: Example
184
Setting the Privilege Level for a Command: Example
184
Configuring the RADIUS Server: Examples
184
Defining AAA Server Groups: Example
184
Configuring Vendor-Specific RADIUS Attributes: Examples
185
Configuring a Vendor-Proprietary RADIUS Host: Example
185
Sample Output for a Self-Signed Certificate: Example
185
Verifying Secure HTTP Connection: Example
186
Additional References
186
Related Documents
187
Standards
187
MIBs
187
RFCs
187
Technical Assistance
187
Configuring IEEE 802.1x Port-Based Authentication
189
Restrictions for Configuring IEEE 802.1x Port-Based Authentication
189
Information About Configuring IEEE 802.1x Port-Based Authentication
189
IEEE 802.1x Port-Based Authentication
189
Device Roles
189
Authentication Process
190
Switch-to-RADIUS-Server Communication
192
Authentication Initiation and Message Exchange
192
Authentication Manager
194
Port-Based Authentication Methods
194
Per-User ACLs and Filter-Ids
195
Authentication Manager CLI Commands
195
Ports in Authorized and Unauthorized States
195
802.1x Host Mode
196
Multidomain Authentication
197
802.1x Multiple Authentication Mode
198
MAC Move
198
xiii
MAC Replace
199
802.1x Accounting
199
802.1x Accounting Attribute-Value Pairs
200
802.1x Readiness Check
200
802.1x Authentication with VLAN Assignment
201
Voice Aware 802.1x Security
202
802.1x Authentication with Per-User ACLs
203
802.1x Authentication with Downloadable ACLs and Redirect URLs
204
Cisco Secure ACS and Attribute-Value Pairs for the Redirect URL
205
Cisco Secure ACS and Attribute-Value Pairs for Downloadable ACLs
205
VLAN ID-Based MAC Authentication
205
802.1x Authentication with Guest VLAN
206
802.1x Authentication with Restricted VLAN
207
802.1x Authentication with Inaccessible Authentication Bypass
207
Support on Multiple-Authentication Ports
208
Authentication Results
208
Feature Interactions
208
802.1x Authentication with Voice VLAN Ports
209
802.1x Authentication with Port Security
209
802.1x Authentication with Wake-on-LAN
209
802.1x Authentication with MAC Authentication Bypass
210
802.1x User Distribution
211
802.1x User Distribution Configuration Guidelines
211
Network Admission Control Layer 2 802.1x Validation
211
Flexible Authentication Ordering
212
Open1x Authentication
212
802.1x Supplicant and Authenticator Switches with Network Edge Access Topology
(NEAT)
212
802.1x Supplicant and Authenticator Switch Guidelines
213
Using IEEE 802.1x Authentication with ACLs and the RADIUS Filter-Id Attribute . .
214
Authentication Manager Common Session ID
214
Default 802.1x Authentication Settings
214
802.1x Accounting
215
802.1x Authentication Guidelines
216
VLAN Assignment, Guest VLAN, Restricted VLAN, and Inaccessible Authentication
Bypass Guidelines
216
MAC Authentication Bypass Guidelines
217
Maximum Number of Allowed Devices Per Port Guidelines
217
How to Configure IEEE 802.1x Port-Based Authentication
218
802.1x Authentication Configuration Process
218
Configuring the Switch-to-RADIUS-Server Communication
219
Configuring 802.1x Readiness Check
220
Enabling Voice Aware 802.1x Security
221
xiv
Configuring 802.1x Violation Modes
221
Configuring the Host Mode
222
Configuring Periodic Reauthentication
223
Configuring Optional 802.1x Authentication Features
224
Configuring 802.1x Accounting
225
Configuring a Guest VLAN
226
Configuring a Restricted VLAN
226
Configuring the Maximum Number of Authentication Attempts
227
Configuring Inaccessible Authentication Bypass
227
Configuring 802.1x User Distribution
229
Configuring NAC Layer 2 802.1x Validation
229
Configuring an Authenticator and Supplicant
230
Configuring an Authenticator
230
Configuring a Supplicant Switch with NEAT
230
Configuring 802.1x Authentication with Downloadable ACLs and Redirect URLs . . .
231
Configuring Downloadable ACLs
231
Configuring a Downloadable Policy
232
Configuring Open1x
233
Resetting the 802.1x Authentication Configuration to the Default Values
233
Monitoring and Maintaining IEEE 802.1x Port-Based Authentication
234
Configuration Examples for Configuring IEEE 802.1x Port-Based Authentication
234
Enabling a Readiness Check: Example
234
Enabling 802.1x Authentication: Example
234
Enabling MDA: Example
234
Disabling the VLAN Upon Switch Violoation: Example
234
Configuring the Radius Server Parameters: Example
235
Configuring 802.1x Accounting: Example
235
Enabling an 802.1x Guest VLAN: Example
235
Displaying Authentication Manager Common Session ID: Examples
235
Configuring Inaccessible Authentication Bypass: Example
236
Configuring VLAN Groups: Examples
236
Configuring NAC Layer 2 802.1x Validation: Example
237
Configuring an 802.1x Authenticator Switch: Example
237
Configuring an 802.1x Supplicant Switch: Example
237
Configuring a Downloadable Policy: Example
237
Configuring Open 1x on a Port: Example
237
Additional References
238
Related Documents
239
Standards
239
MIBs
239
RFCs
239
Technical Assistance
239
xv
MACsec
241
Guidelines and Limitations
241
MKA-PSK: CKN Behavior Change
241
PSK Based MKA Support for MACsec
243
Information about PSK Based MKA
243
Configuring PSK Based MKA
243
Configuring MKA
243
Configuring MACsec and MKA on Interfaces
245
Configuring MKA Pre-shared Key
246
Certificate-based MACsec Encryption
247
Prerequisites for Certificate-based MACsec Encryption
247
Restrictions for Certificate-based MACsec Encryption
247
Information About Certificate-based MACsec Encryption
248
Configuring Certificate-based MACsec Encryption using Remote Authentication . .
248
Configuring Certificate Enrollment Manually
248
Enabling 802.1x Authentication and Configuring AAA
250
Configuring EAP-TLS Profile and 802.1x Credentials
251
Applying the 802.1x MKA MACsec Configuration on Interfaces
251
Verifying Certificate-based MACsec Encryption
252
Configuration examples for Certificate-based MACsec Encryption
253
Example: Enrolling the Certificate
253
Example: Enabling 802.1x Authentication and AAA Configuration
253
Example: Configuring EAP-TLS Profile and 802.1X Credentials
253
Example: Applying 802.1X, PKI, and MACsec Configuration on the Interface . .
253
Configuring Web-Based Authentication
255
Prerequisites for Configuring Web-Based Authentication
255
Restrictions for Configuring Web-Based Authentication
255
Information About Configuring Web-Based Authentication
255
Web-Based Authentication
255
Device Roles
256
Host Detection
256
Session Creation
257
Authentication Process
257
Local Web Authentication Banner
258
Web Authentication Customizable Web Pages
260
Web Authentication Guidelines
260
Web-Based Authentication Interactions with Other Features
261
Port Security
262
LAN Port IP
262
Gateway IP
262
ACLs
262
xvi
Context-Based Access Control
262
802.1x Authentication
262
EtherChannel
263
Default Web-Based Authentication Settings
263
Configuring Switch-to-RADIUS-Server Communication
263
How to Configure Web-Based Authentication
263
Configuring the Authentication Rule and Interfaces
263
Configuring AAA Authentication
264
Configuring Switch-to-RADIUS-Server Communication
264
Configuring the HTTP Server
265
Customizing the Authentication Proxy Web Pages
265
Specifying a Redirection URL for Successful Login
265
Configuring the Web-Based Authentication Parameters
266
Configuring a Web Authentication Local Banner
266
Removing Web-Based Authentication Cache Entries
266
Monitoring and Maintaining Web-Based Authentication
267
Configuration Examples for Configuring Web-Based Authentication
267
Enabling and Displaying Web-Based Authentication: Examples
267
Enabling AAA: Example
267
Configuring the RADIUS Server Parameters: Example
267
Configuring a Custom Authentication Proxy Web Page: Example
268
Verifying a Custom Authentication Proxy Web Page: Example
268
Configuring a Redirection URL: Example
268
Verifying a Redirection URL: Example
268
Configuring a Local Banner: Example
268
Clearing the Web-Based Authentication Session: Example
269
Additional References
269
Related Documents
270
Standards
270
MIBs
270
RFCs
270
Technical Assistance
270
Configuring Smartports Macros
271
Information About Configuring Smartports Macros
271
How to Configure Smartports Macros
271
Default Smartports Settings
271
Smartports Configuration Guidelines
273
Applying Smartports Macros
273
Monitoring and Maintaining Smartports Macros
274
Configuration Examples for Smartports Macros
275
Applying the Smartports Macro: Examples
275
xvii
Additional References
275
Related Documents
276
Standards
276
MIBs
276
RFCs
276
Technical Assistance
276
Configuring SGACL Monitor Mode and SGACL Logging
277
Restrictions for Configuring SGACL Policies
277
SGACL Monitor Mode
277
Configuring SGACL Monitor Mode - CLI
278
Configuring SGACL Monitor Mode - Radius (ISE)
278
Verifying Configuration
280
SGACL Logging
280
Configuring SGT Exchange Protocol over TCP (SXP) and Layer 3 Transport
281
Cisco TrustSec SGT Exchange Protocol Feature Histories
281
Configuring Cisco TrustSec SXP
281
Enabling Cisco TrustSec SXP
282
Configuring an SXP Peer Connection
282
Configuring the Default SXP Password
284
Configuring the Default SXP Source IP Address
284
Changing the SXP Reconciliation Period
284
Changing the SXP Retry Period
285
Creating Syslogs to Capture Changes of IP Address to SGT Mapping Learned Through SXP
285
Verifying the SXP Connections
285
Configuring Cisco TrustSec Caching
286
Enabling Cisco TrustSec Caching
286
Clearing the Cisco TrustSec Cache
287
Configuring VLANs
289
Information About Configuring VLANs
289
VLANs
289
Supported VLANs
290
VLAN Port Membership Modes
290
Normal-Range VLANs
291
Token Ring VLANs
292
Normal-Range VLAN Configuration Guidelines
293
Default Ethernet VLAN Configuration
293
Ethernet VLANs
294
VLAN Removal
294
Static-Access Ports for a VLAN
294
xviii
Extended-Range VLANs
295
Default VLAN Configuration
295
Extended-Range VLAN Configuration Guidelines
295
VLAN Trunks
296
Trunking Overview
296
IEEE 802.1Q Configuration Guidelines
296
Default Layer 2 Ethernet Interface VLAN Settings
297
Ethernet Interface as a Trunk Port
297
Trunking Interaction with Other Features
297
Allowed VLANs on a Trunk
298
Native VLAN for Untagged Traffic
298
Load Sharing Using Trunk Ports
298
Load Sharing Using STP Port Priorities
299
Load Sharing Using STP Path Cost
299
VMPS
300
Dynamic-Access Port VLAN Membership
300
Default VMPS Client Settings
301
VMPS Configuration Guidelines
301
VMPS Reconfirmation Interval
302
Dynamic-Access Port VLAN Membership
302
How to Configure VLANs
302
Creating or Modifying an Ethernet VLAN
302
Deleting a VLAN
303
Assigning Static-Access Ports to a VLAN
303
Creating an Extended-Range VLAN
303
Creating an Extended-Range VLAN with an Internal VLAN ID
304
Configuring an Ethernet Interface as a Trunk Port
304
Defining the Allowed VLANs on a Trunk
305
Changing the Pruning-Eligible List
305
Configuring the Native VLAN for Untagged Traffic
305
Load Sharing Using STP Port Priorities
306
Configuring Load Sharing Using STP Path Cost
306
Configuring the VMPS Client
307
Entering the IP Address of the VMPS
307
Configuring Dynamic-Access Ports on VMPS Clients
308
Monitoring and Maintaining VLANs
308
Configuration Examples for Configuring VLANs
308
VMPS Network: Example
308
Configuring a VLAN: Example
309
Configuring an Access Port in a VLAN: Example
310
xix
Configuring an Extended-Range VLAN: Example
310
Configuring a Trunk Port: Example
310
Removing a VLAN: Example
310
Show VMPS Output: Example
310
Additional References
310
Related Documents
311
Standards
311
MIBs
311
RFCs
311
Configuring VTP
313
Prerequisites for Configuring VTP
313
Restrictions for Configuring VTP
313
Information About Configuring VTP
313
VTP
313
VTP Domain
314
VTP Modes
315
VTP Mode Guidelines
315
VTP Advertisements
316
VTP Version 2
316
VTP Version 3
317
VTP Version Guidelines
317
VTP Pruning
318
Default VTP Settings
320
VTP Configuration Guidelines
320
Domain Names
320
Passwords
321
Adding a VTP Client Switch to a VTP Domain
321
How to Configure VTP
321
Configuring VTP Domain and Parameters
321
Configuring a VTP Version 3 Password
322
Enabling the VTP Version
323
Enabling VTP Pruning
323
Configuring VTP on a Per-Port Basis
323
Adding a VTP Client Switch to a VTP Domain
323
Monitoring and Maintaining VTP
324
Configuration Examples for Configuring VTP
325
Configuring a VTP Server: Example
325
Configuring a Hidden VTP Password: Example
325
Configuring a VTP Version 3 Primary Server: Example
325
Additional References for Configuring VTP
325
Related Documents
326
Standards
326
xx
MIBs
326
RFCs
326
Configuring Voice VLAN
327
Information About Configuring Voice VLAN
327
Voice VLAN
327
Cisco IP Phone Voice Traffic
328
Cisco IP Phone Data Traffic
328
Default Voice VLAN Configuration
329
Voice VLAN Configuration Guidelines
329
Port Connection to a Cisco 7960 IP Phone
330
Priority of Incoming Data Frames
330
How to Configure Voice VLAN
330
Configuring the Priority of Incoming Data Frames
330
Monitoring and Maintaining Voice VLAN
330
Configuration Examples for Configuring Voice VLAN
331
Configuring the Cisco IP Phone Priority of Incoming Data Frames: Example
331
Additional References for Configuring Voice VLAN
331
Related Documents
332
Standards
332
MIBs
332
RFCs
332
Configuring STP
333
Prerequisites for Configuring STP
333
Restrictions for Configuring STP
333
Information About Configuring STP
333
STP
333
Spanning-Tree Topology and BPDUs
334
Bridge ID, Switch Priority, and Extended System ID
335
Spanning-Tree Interface States
335
Blocking State
337
Listening State
337
Learning State
337
Forwarding State
337
Disabled State
338
How a Switch or Port Becomes the Root Switch or Root Port
338
Spanning Tree and Redundant Connectivity
339
Spanning-Tree Address Management
339
Accelerated Aging to Retain Connectivity
339
Spanning-Tree Modes and Protocols
340
Supported Spanning-Tree Instances
340
xxi
Spanning-Tree Interoperability and Backward Compatibility
340
STP and IEEE 802.1Q Trunks
341
VLAN-Bridge Spanning Tree
341
Default Spanning-Tree Settings
342
Disabling Spanning Tree
342
Root Switch
342
Secondary Root Switch
343
Port Priority
343
Path Cost
343
Spanning-Tree Timers
344
Spanning-Tree Configuration Guidelines
344
How to Configure STP
345
Changing the Spanning-Tree Mode
345
Configuring the Root Switch
346
Configuring a Secondary Root Switch
346
Configuring Port Priority
347
Configuring Path Cost
347
Configuring Optional STP Parameters
347
Monitoring and Maintaining STP
348
Additional References
348
Related Documents
349
Standards
349
MIBs
349
RFCs
349
Configuring MSTP
351
Information About Configuring MSTP
351
MSTP
351
Multiple Spanning-Tree Regions
351
IST, CIST, and CST
352
Operations Within an MST Region
352
Operations Between MST Regions
352
IEEE 802.1s Terminology
353
Hop Count
354
Boundary Ports
354
IEEE 802.1s Implementation
355
Port Role Naming Change
355
Interoperation Between Legacy and Standard Switches
355
Detecting Unidirectional Link Failure
356
Interoperability with IEEE 802.1D STP
356
RSTP
357
Port Roles and the Active Topology
357
Rapid Convergence
358
xxii
Synchronization of Port Roles
359
Bridge Protocol Data Unit Format and Processing
360
Processing Superior BPDU Information
361
Processing Inferior BPDU Information
361
Topology Changes
361
Default MSTP Settings
362
MSTP Configuration Guidelines
362
MST Region Configuration and Enabling MSTP
363
Root Switch
363
Secondary Root Switch
363
Port Priority
364
Path Cost
364
Link Type to Ensure Rapid Transitions
364
Neighbor Type
364
Restarting the Protocol Migration Process
364
How to Configure MSTP
364
Specifying the MST Region Configuration and Enabling MSTP
364
Configuring the Root Switch
365
Configuring the Optional MSTP Parameters
366
Monitoring and Maintaining MSTP
368
Configuration Examples for Configuring MSTP
369
Configuring the MST Region: Example
369
Additional References
369
Related Documents
370
Standards
370
MIBs
370
RFCs
370
Configuring Optional Spanning-Tree Features
371
Prerequisites for the Optional Spanning-Tree Features
371
Restrictions for the Optional Spanning-Tree Features
371
Information About Configuring the Optional Spanning-Tree Features
371
PortFast
371
BPDU Guard
372
Enabling BPDU Guard
372
BPDU Filtering
373
Enabling BPDU Filtering
373
UplinkFast
373
Enabling UplinkFast for Use with Redundant Links
375
BackboneFast
376
Enabling BackboneFast
377
EtherChannel Guard
378
xxiii
Root Guard
378
Enabling Root Guard
379
Loop Guard
379
Enabling Loop Guard
379
Default Optional Spanning-Tree Settings
380
How to Configure the Optional Spanning-Tree Features
380
Enabling Optional SPT Features
380
Maintaining and Monitoring Optional Spanning-Tree Features
381
Additional References
382
Related Documents
382
Standards
382
MIBs
382
RFCs
382
Configuring Resilient Ethernet Protocol
383
Information About Configuring REP
383
REP
383
Link Integrity
385
REP Negotiated
385
Fast Convergence
385
VLAN Load Balancing
386
Spanning Tree Interaction
387
REP Ports
387
REP Segments
388
Default REP Configuration
388
REP Configuration Guidelines
388
REP Administrative VLAN
389
How to Configure REP
390
Configuring the REP Administrative VLAN
390
Configuring REP Interfaces
390
Configuring REP Negotiated
392
REP Segment ID Validation
394
Setting Manual Preemption for VLAN Load Balancing
395
Configuring SNMP Traps for REP
396
Monitoring and Maintaining REP
396
Configuration Examples for Configuring REP
396
Configuring the Administrative VLAN: Example
396
Configuring a Primary Edge Port: Examples
397
Configuring VLAN Blocking: Example
397
Feature History
398
Additional References
398
Related Documents
399
Standards
399
xxiv
MIBs
399
RFCs
399
Configuring FlexLinks and the MAC Address-Table Move Update
401
Restrictions for the FlexLinks and the MAC Address-Table Move Update
401
Information About Configuring the FlexLinks and the MAC Address-Table Move Update 401
FlexLinks
401
VLAN FlexLinks Load Balancing and Support
402
FlexLinks Multicast Fast Convergence
402
Learning the Other FlexLinks Port as the mrouter Port
402
Generating IGMP Reports
403
Leaking IGMP Reports
403
MAC Address-Table Move Update
403
Default Settings for FlexLinks and MAC Address-Table Move Update
404
Configuration Guidelines for FlexLinks and MAC Address-Table Move Update
404
How to Configure the FlexLinks and MAC Address-Table Move Update
405
Configuring FlexLinks
405
Configuring a Preemption Scheme for FlexLinks
406
Configuring VLAN Load Balancing on FlexLinks
406
Configuring the MAC Address-Table Move Update Feature
407
Configuring the MAC Address-Table Move Update Messages
407
Maintaining and Monitoring the FlexLinks and MAC Address-Table Move Update
408
Configuration Examples for the FlexLinks and MAC Address-Table Move Update
408
Configuring FlexLinks Port: Examples
408
Configuring a Backup Interface: Example
409
Configuring a Preemption Scheme: Example
410
Configuring VLAN Load Balancing on FlexLinks: Examples
410
Configuring MAC Address-Table Move Update: Example
411
Additional References
412
Related Documents
412
Standards
412
MIBs
412
RFCs
412
Configuring DHCP
413
Information About Configuring DHCP
413
DHCP Snooping
413
DHCP Server
413
DHCP Relay Agent
413
DHCP Snooping
413
Option-82 Data Insertion
414
Cisco IOS DHCP Server Database
417
xxv
DHCP Snooping Binding Database
417
Default DHCP Snooping Settings
418
DHCP Snooping Configuration Guidelines
419
DHCP Snooping Binding Database Guidelines
420
Packet Forwarding Address
420
DHCP Server Port-Based Address Allocation
420
Port-Based Address Allocation Configuration Guidelines
420
How to Configure DHCP
421
Configuring the DHCP Relay Agent
421
Specifying the Packet Forwarding Address
421
Enabling DHCP Snooping and Option 82
422
Enabling the DHCP Snooping Binding Database Agent
423
Enabling DHCP Server Port-Based Address Allocation
424
Preassigning an IP Address
424
Monitoring and Maintaining DHCP
425
Configuration Examples for Configuring DHCP
425
Enabling DHCP Server Port-Based Address Allocation: Examples
425
Enabling DHCP Snooping: Example
426
Additional References
426
Related Documents
427
Standards
427
MIBs
427
RFCs
427
Configuring Dynamic ARP Inspection
429
Prerequisites for Dynamic ARP Inspection
429
Restrictions for Dynamic ARP Inspection
429
Information About Dynamic ARP Inspection
429
Dynamic ARP Inspection
429
Interface Trust States and Network Security
430
Rate Limiting of ARP Packets
431
Relative Priority of ARP ACLs and DHCP Snooping Entries
431
Logging of Dropped Packets
432
Default Dynamic ARP Inspection Settings
432
Dynamic ARP Inspection Configuration Guidelines
432
How to Configure Dynamic ARP Inspection
433
Configuring Dynamic ARP Inspection in DHCP Environments
433
Configuring ARP ACLs for Non-DHCP Environments
434
Limiting the Rate of Incoming ARP Packets
436
Performing Validation Checks
437
Configuring the Log Buffer
438
Monitoring and Maintaining Dynamic ARP Inspection
439
Configuration Examples for Dynamic ARP Inspection
439
xxvi
Configuring Dynamic ARP Inspection in DHCP Environments: Example
439
Configuring ARP ACLs for Non-DHCP Environments: Example
439
Additional References
439
Related Documents
440
Standards
440
MIBs
440
RFCs
440
Technical Assistance
440
Configuring IP Source Guard
441
Prerequisites for IP Source Guard
441
Restrictions for IP Source Guard
441
Information About IP Source Guard
441
IP Source Guard
441
Source IP Address Filtering
441
Source IP and MAC Address Filtering
442
IP Source Guard for Static Hosts
442
IP Source Guard Configuration Guidelines
442
How to Configure IP Source Guard
443
Enabling IP Source Guard
443
Configuring IP Source Guard for Static Hosts on a Layer
2 Access Port
444
Monitoring and Maintaining IP Source Guard
445
Configuration Examples for IP Source Guard
445
Enabling IPSG with Source IP and MAC Filtering: Example
445
Disabling IPSG with Static Hosts: Example
445
Enabling IPSG for Static Hosts: Examples
446
Displaying IP or MAC Binding Entries: Examples
446
Additional References
448
Related Documents
448
Standards
448
MIBs
448
RFCs
448
Configuring IGMP Snooping and MVR
449
Restrictions for IGMP Snooping and MVR
449
Information About IGMP Snooping and MVR
449
IGMP Snooping
449
IGMP Versions
450
Joining a Multicast Group
450
Leaving a Multicast Group
452
Immediate Leave
452
IGMP Configurable-Leave Timer
453
xxvii
IGMP Report Suppression
453
Default IGMP Snooping Configuration
453
Snooping Methods
453
Multicast Flooding Time After a TCN Event
454
Flood Mode for TCN
454
Multicast Flooding During a TCN Event
454
IGMP Snooping Querier Guidelines
454
IGMP Report Suppression
455
Multicast VLAN Registration
455
MVR in a Multicast Television Application
456
Default MVR Settings
457
MVR Configuration Guidelines and Limitations
457
IGMP Filtering and Throttling
458
Default IGMP Filtering and Throttling Configuration
458
IGMP Profiles
458
IGMP Throttling Action
459
How to Configure IGMP Snooping and MVR
459
Configuring IGMP Snooping
459
Enabling or Disabling IGMP Snooping
459
Setting IGMP Snooping Parameters
460
Configuring TCN
461
Configuring the IGMP Snooping Querier
461
Disabling IGMP Report Suppression
462
Configuring MVR
462
Configuring MVR Global Parameters
462
Configuring MVR Interfaces
463
Configuring IGMP
464
Configuring IGMP Profiles
464
Configuring IGMP Interfaces
464
Monitoring and Maintaining IGMP Snooping and MVR
465
Configuration Examples for IGMP Snooping
466
Configuring IGMP Snooping: Example
466
Disabling a Multicast Router Port: Example
466
Statically Configuring a Host on a Port: Example
466
Enabling IGMP Immediate Leave: Example
467
Setting the IGMP Snoopng Querier Parameters: Examples
467
Enabling MVR: Examples
467
Creating an IGMP Profile: Example
468
Applying an IGMP Profile: Example
468
Limiting IGMP Groups: Example
468
Additional References
468
xxviii
Related Documents
469
Standards
469
MIBs
469
RFCs
469
Technical Assistance
469
Configuring Port-Based Traffic Control
471
Restrictions for Port-Based Traffic Control
471
Information About Port-Based Traffic Control
471
Storm Control
471
Default Storm Control Configuration
472
Storm Control and Threshold Levels
472
Small-Frame Arrival Rate
472
Protected Ports
473
Protected Port Configuration Guidelines
473
Port Blocking
473
Port Security
473
Secure MAC Addresses
473
Security Violations
474
Default Port Security Configuration
475
Port Security Configuration Guidelines
475
Port Security Aging
477
Port Security and Private VLANs
477
Protocol Storm Protection
478
How to Configure Port-Based Traffic Control
479
Configuring Storm Control
479
Configuring Storm Control and Threshold Levels
479
Configuring Small-Frame Arrival Rate
480
Configuring Protected Ports
480
Configuring Port Blocking
481
Blocking Flooded Traffic on an Interface
481
Configuring Port Security
481
Enabling and Configuring Port Security
481
Enabling and Configuring Port Security Aging
485
Configuring Protocol Storm Protection
485
Enabling Protocol Storm Protection
485
Monitoring and Maintaining Port-Based Traffic Control
486
Configuration Examples for Port-Based Traffic Control
486
Enabling Unicast Storm Control: Example
486
Enabling Broadcast Address Storm Control on a Port: Example
486
Enabling Small-Frame Arrival Rate: Example
487
xxix
Configuring a Protected Port: Example
487
Blocking Flooding on a Port: Example
487
Configuring Port Security: Examples
487
Configuring Port Security Aging: Examples
488
Configuring Protocol Storm Protection: Example
488
Additional References
488
Related Documents
489
Standards
489
MIBs
489
RFCs
489
Technical Assistance
489
Configuring SPAN and RSPAN
491
Prerequisites for SPAN and RSPAN
491
Information About SPAN and RSPAN
491
SPAN and RSPAN
491
Local SPAN
491
Remote SPAN
492
SPAN Sessions
493
Monitored Traffic Types for SPAN Sessions
494
Source Ports
495
Source VLANs
496
VLAN Filtering
496
Destination Port
496
RSPAN VLAN
497
Spanned Traffic Timestamping (IE 5000 only)
498
SPAN and RSPAN Interaction with Other Features
498
Local SPAN Configuration Guidelines
499
RSPAN Configuration Guidelines
499
Spanned Traffic Timestamping Configuration Guidelines
500
Default SPAN and RSPAN Settings
501
How to Configure SPAN and RSPAN
501
Creating a Local SPAN Session
501
Creating a Local SPAN Session and Configuring Incoming Traffic
503
Specifying VLANs to Filter
504
Configuring a VLAN as an RSPAN VLAN
505
Creating an RSPAN Source Session
506
Creating an RSPAN Destination Session
507
Creating an RSPAN Destination Session and Configuring Incoming Traffic
508
Specifying VLANs to Filter
509
Creating a Local SPAN Session with Timestamp
510
Creating an RSPAN Source Session with Timestamp
512
Monitoring and Maintaining SPAN and RSPAN
512
xxx
Spanned Traffic Timestamping Statistics
513
Configuration Examples for SPAN and RSPAN
513
Configuring a Local SPAN Session: Example
513
Modifying Local SPAN Sessions: Examples
514
Configuring an RSPAN: Example
514
Configuring a VLAN for a SPAN Session: Example
515
Modifying RSPAN Sessions: Examples
515
Configuring an RSPAN Session with Timestamp: Example
515
Additional References
516
Related Documents
516
Standards
516
MIBs
516
RFCs
516
Configuring LLDP, LLDP-MED, and Wired Location Service
517
Information About LLDP, LLDP-MED, and Wired Location Service
517
LLDP-MED
517
Wired Location Service
518
Default LLDP Configuration
520
LLDP, LLDP-MED, and Wired Location Service Configuration Guidelines
520
LLDP-MED TLVs
520
How to Configure LLDP, LLDP-MED, and Wired Location Service
521
Enabling LLDP
521
Configuring LLDP Characteristics
521
Configuring LLDP-MED TLVs
522
Configuring Network-Policy TLV
522
Configuring Location TLV and Wired Location Service
523
Monitoring and Maintaining LLDP, LLDP-MED, and Wired Location Service
524
Configuration Examples for Configuring LLDP, LLDP-MED, and Wired Location Service
524
Enabling LLDP: Examples
524
Configuring LDP Parameters: Examples
525
Configuring TLV: Example
525
Configuring Network Policy: Example
525
Configuring Voice Application: Example
525
Configuring Civic Location Information: Example
525
Enabling NMSP: Example
526
Additional References
526
Related Documents
526
Standards
526
MIBs
526
RFCs
526
Technical Assistance
526
xxxi
///////////////////////////////////////
|
|