Benutzeranleitung / Produktwartung 6600 des Produzenten Alcatel-Lucent
Zur Seite of 654
Part No. 060179-10, Rev. F April 2006 OmniSwitch 6600 Family Network Configuration Guide www.alcatel.com.
i i O mniSw i t ch 6 6 00 Fa m ily Network Co n f igu r ation Gui d e Ap r il 2 0 06 This user guide docume nts release 5.4 of the OmniSwitch 6600 Family Ne twork Configuration Guide. The functionality described in this guid e is subject to change without notice.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 iii Contents About This Guide ...................... ................ ................ ................... ................ .............. xxv Supported Platforms ................... .....
Contents iv OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Setting Interface Line Sp eed .......... ................ ................... ................ ................... 15-16 Configuring Duplex Mode ............. ................ .
Contents OmniSwitch 6600 Family Network Configurati on Guide April 2006 v Configuring the Number of MAC Addresses Allowed .................... .................... ......... 17-8 Configuring Authorized MAC Addresses ......... ................ ........
Contents vi OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Spanning Tree Operating Modes .............................. ............... .................... ................ . 19-9 Using the Flat Spanning Tree Mode .......... .........
Contents OmniSwitch 6600 Family Network Configurati on Guide April 2006 vii MST Interoperability and Migration ..................... ................... ................ ................... 20-12 Migrating from Flat Mode STP/RSTP to Flat Mode MSTP ...
Contents viii OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Custom (User Defined) Rules ................. ................... ................ .................... . 22-7 Port Rules ................. ................... ..............
Contents OmniSwitch 6600 Family Network Configurati on Guide April 2006 ix Chapter 10 Using Interswitch Protocols ............... ................ ................... ................ ................ . 24-1 In This Chapter ....... ................ ..
Contents x OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Adding Ports to a Static Aggregate Gr oup .. ................... ................ ................. 26-9 Removing Ports from a Static Aggregat e Group ................ .........
Contents OmniSwitch 6600 Family Network Configurati on Guide April 2006 xi Modifying the Partner Port System ID ....................... .................... ............... 27-30 Modifying the Partne r Port System Priority ........ ...................
Contents xii OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Displaying UDP Information ..... .................... ................... ................ ................... 28-24 Verifying the IP Configuration ............. .............
Contents OmniSwitch 6600 Family Network Configurati on Guide April 2006 xiii RIP Options .................... ............... .................... ................ ................... ................ ......... 30-9 Configuring the RIP Forced Hold-down Interval .
Contents xiv OmniSwi tch 6600 Family Network Configuration Guid e April 2006 DHCP Relay Overview ................. .................... ................ ................... ................ ......... 32-5 DHCP .............. .................... .....
Contents OmniSwitch 6600 Family Network Configurati on Guide April 2006 xv VRRP Tracking ............... ............... ............ .... ................... ................ ................ ..... 3 3-7 Interaction With Othe r Feature s ............
Contents xvi O mniSwitch 6600 Family Network Configuration Guid e April 2006 Retrieving Directory Search Results ....................... ............... .................... ... 34-18 Directory Modificat ions .............. ................ ..........
Contents OmniSwitch 6600 Family Network Configurati on Guide April 2006 xvii Configuring the Server Aut hority Mode ........... .................... ............... .................... ... 35-32 Configuring Single Mode ............... ...............
Contents xviii OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Modifying Policy Servers ...... ............... .................... ................... ................ ................. 37-4 Modifying LDAP Policy Server Parameters ....
Contents OmniSwitch 6600 Family Network Configurati on Guide April 2006 xi x Returning the Global Configuration to Defaults .... ....................... ................ ....... 38-18 Verifying Global Settings ............................... .........
Contents xx O mniSwitch 6600 Family Network Configuration Guid e April 2006 Policy Applications ............................... ................ ................... ................ ................... 38-49 Basic QoS Policies ...... .................
Contents OmniSwitch 6600 Family Network Configurati on Guide April 2006 xx i Chapter 26 Configuring IP Multicast Switching ..................... ............... ................ ................ . 40-1 In This Chapter ....... ................ ........
Contents xxii OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Chapter 27 Diagnosing Switch Problems ................ ................ ............... .................... ............. 41-1 In This Chapter ....... ................ .....
Contents OmniSwitch 6600 Family Network Configurati on Guide April 2006 xxiii Enabling or Disabling RMON Probes ........................ ................... ................ ....... 41-27 Displaying RMON Tables .......................... .............
Contents xxiv O mniSwitch 6600 Family Network Configuration Guide April 2006 Configuring Debug Memory Commands ...................... ............... .................... ............. 43-4 Enabling/Disabl ing Memory Monitoring Function s ...... .....
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page xxv About This Guide This OmniSwitch 6600 F amily Network Con figuration Guid e describes how to set up and moni tor soft- ware features that will allow your sw itch to operate in a live network envi ronment.
Who Should Read this Manual? About This Guide page xxvi OmniSwitch 6600 Family Network Configuration Guide April 2006 Unsupported Platforms The information i n this guide d oes not app ly to the fo ll.
About This Guide What is in this Manual? OmniSwitch 6600 Family Network Configurati on Guide April 2006 page xxvii What is in this Manual? This configuration guide includes informatio n about config uring the followi ng features: • VLANs, VLAN router ports, mob ile ports, and VLAN rules.
What is Not in this Manual? About This Guide page xxviii OmniSwitch 6600 Family Network Configuration Guide April 2006 What is Not in this Manual? The configuration p rocedures in this manual use Command Line Interface (CLI) commands in all exam- ples.
About This Guide Documentation Roadmap OmniSwitch 6600 Family Network Configurati on Guide April 2006 page xxix Documentation Roadmap The OmniSwitch user document ation suite was designed to supply you with in formation at severa l critical junctures of t he configuration p rocess.
Documentation Roadmap About This Guide page xxx OmniSwitch 6600 Family Network Configuration Guide April 2006 Stage 3: Integrating the Switch Into a Network Pertinent Documentation: OmniSw itch 6600 F.
About This Guide Related Documentation OmniSwitch 6600 Family Network Configurati on Guide April 2006 page xxxi Related Documentation The following are the titl es an d descript ions of all the OmniSw.
Related Documentation About This Guide page xxxii OmniSwitch 6600 Family Network Configuration Guide April 2006 • OmniSwitch 66 00 Family Advanced Routing Config uration Gu ide Includes network conf.
About This Guide User Manuals Web Site OmniSwitch 6600 Family Network Configurati on Guide April 2006 page xxxiii User Manuals W eb Site All related use r guides for the Omn iSwitch 6600 Fa mily can be found on ou r web site at http://www.alca tel.com/enterprise/e n/resource_lib rary/user_manuals.
Technical Support About This Guide page xxxiv OmniSwitch 660 0 Family Network Configuration Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 1-1 1 Configuring Ethernet Por ts The Ethernet software is re sponsible for a variety of funct ions that suppor t the Ethernet an d Gigabit Eth er- net ports on OmniSwitch 6600 Family switches.
Ethernet Specifications Configuring Ethernet Ports page 1-2 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Ethernet Specifications IEEE Standards Supported 802.3 Carrier Sense Multiple Acce ss with Collision Detection (CSMA/CD) Ports Supported Ethernet (10 Mbps) Fast Ethernet (100 Mbps) Gigabit Ether net (1 Gb/1000 Mbps) .
Configuring Ethernet Ports Ethernet Port Defaults OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 1-3 Ethernet Por t Defaults The following ta ble shows Ethern et port defa ult values.
Configuring Ethernet Ports Tutorial Configuring Ethernet Ports page 1-4 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring Ethernet Por ts T utorial This tutoria l describes typic al steps involv ed in conf iguring an Ethern et port.
Configuring Ethernet Ports Configuring Ethernet Ports Tutorial OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 1-5 Note. Optional. To verify the Ethe rnet port co nfiguration, use the show interfaces command.
Ethernet Ports Overview Configuring Ethernet Ports page 1-6 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Ethernet Por ts Over view This chapter descri bes the Ethernet software CLI command s used for configuring and monitoring your switch’s Ethern et port paramete rs.
Configuring Ethernet Ports Et hernet Ports Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 1-7 OmniSwitch 6624 The OmniSwitch 6624 provi des 24 10/100 Mb ps ports and two expansi on slots. The expansion slot s are empty by default.
Ethernet Ports Overview Configuring Ethernet Ports page 1-8 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 OmniSwitch 6600-P24 The OmniSwi tch 6600-P24 provides 24 10/1 00 Mbps Power over Ethernet (PoE ) ports and t wo expansion slots.
Configuring Ethernet Ports Et hernet Ports Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 1-9 OmniSwitch 6602-48 The OmniSwi tch 6602-48 p rovides 48 10/1 00 Mbps po rts, two Gigabit M iniGBIC ports, and two stack - ing ports.
Ethernet Ports Overview Configuring Ethernet Ports page 1-10 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 V alid Port Settings This table below lists valid sp eed, duplex, an d auto nego tiation settings for the different O mniSwitch 66 00 Family port types.
Configuring Ethernet Ports Et hernet Ports Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 1-11 OmniSwit ch 6600-U24 (ports 1–24) 100 Mbps fiber SFP ports 100 full/half Y es OmniSwit ch 6600-U24 (ports 25–26) W ire-rate when an OS6600- GNI-U2 is installed us ing LC fiber SFPs or copper 1000Base-T SFPs.
Ethernet Ports Overview Configuring Ethernet Ports page 1-12 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 OmniSwit ch 6602-24 (ports 1–24) Copper twisted pair (RJ-45) auto/10/100 auto/full/half Y es OmniSwit ch 6602-24 (ports 25–26) W ire-rate when an LC fiber SFP or copper 1000Base-T SFP is installed.
Configuring Ethernet Ports Setti ng Ethernet Port Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 1-13 Setting Ethernet Por t Parameters When using CLI command s to set .
Setting Ethernet Port Parameters Configuring Ethernet Ports page 1-14 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Setting Flow Contr ol The flow command can be used to enable or di sable (the de fault) flow control on a specific port, a ra nge of ports, or all po rts on an enti re switch (slot).
Configuring Ethernet Ports Setti ng Ethernet Port Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 1-15 As an option, you can document the interface type by entering ethernet , fastethernet , or gigaethernet before the slot number.
Setting Ethernet Port Parameters Configuring Ethernet Ports page 1-16 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Restoring the Flow Control W ait Time To restore the fl ow control wait time (i.e., set it back to 0) fo r an entire switch , enter flow followed by the slot number an d no wait .
Configuring Ethernet Ports Setti ng Ethernet Port Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 1-17 As an option, you can document the interface type by entering ethernet , fastethernet , or gigaethernet before the slot number.
Setting Ethernet Port Parameters Configuring Ethernet Ports page 1-18 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Enabling and Disabling Inter faces The interfaces a dmin command is used to enable (the default) or disable a specific po rt, a range of ports, or all ports on an ent ire switch (slot).
Configuring Ethernet Ports Setti ng Ethernet Port Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 1-19 As an option, you can document the interface type by entering ethernet , fastethernet , or gigaethernet before the slot number.
Setting Ethernet Port Parameters Configuring Ethernet Ports page 1-20 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Configuring Flood Rates The following su bsections descri be how t.
Configuring Ethernet Ports Setti ng Ethernet Port Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 1-21 Configuring Flood Rate V alues By default, the flood rate is 42 Mbp s on 10/100 ports and 49 6 Mbps on Gigabit po rts.
Setting Ethernet Port Parameters Configuring Ethernet Ports page 1-22 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Configuring Auto Negotiation, Crossover , and Flow Contr ol Settin.
Configuring Ethernet Ports Setti ng Ethernet Port Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 1-23 Configuring Crossover Settings To configure crossover settings on a single po rt, a range of ports, or an entire slot u se the interfaces crossover command.
Setting Ethernet Port Parameters Configuring Ethernet Ports page 1-24 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 As an option, you can document the interface type by entering ethernet , fastethernet , or gigaethernet before the slot number.
Configuring Ethernet Ports Verifying Ethernet Port Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 1-25 V erifying Ethernet Por t Configuration To display information abo ut Ethernet port configurat ion settings, use the show commands listed in the following t able.
Verifying Ethernet Port Configuration Configuring Ethernet Ports page 1-26 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 2-1 2 Managing Source Learning Transparent b ridging rel ies on a proces s referred to as source learning to handle traffic flow. Netwo rk devices communicate by sending and receiving data pa ckets that e ach contain a source MAC address and a destination MAC address.
Source Learning Specifications Managing Source Learning page 2-2 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Source Learning Specifications Source Learning Defaults Sample MAC Addre.
Managing Source Learning Sample MAC Address Table Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 2-3 2 Assign switch ports 2 t hrough 5 on slot 3 to VLAN 200--if the.
MAC Address Table Overview Managing Source Learning page 2-4 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 MAC Address T able Over view Source learning bu ilds and maintains the MAC ad dress table on each swit ch. New MAC address table entries are created in one of two ways: they are dynamically learne d or statically assigned.
Managing Source Learning Using Static MAC Addresses OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 2-5 • There are two type s of static MAC address beh avior supported: bridging (default) or filtering . Enter filtering to set up a denial of service to block potential hostile attacks.
Using Static Multicast MAC Addresses Managing Source Learning page 2-6 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Static MAC Addresses on Link Aggregate Ports Static MAC Addresses are not assigned to ph ysical ports th at belong to a link aggregate.
Managing Source Learning Configuring MAC Address Table Aging Time OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 2-7 Use the no form of the mac-address-table static-multicast command to delete static multi cast MAC address en tries.
Configuring MAC Address Table Aging Time Managing Source Learning page 2-8 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Note. The MAC address table aging time is also use d as the t imeout value for t he Address Reso lution Protocol (ARP) table.
Managing Source Learning Displayi ng MAC Address Table Information OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 2-9 Displaying MAC Address T able Information To display MAC Addr.
Displaying MAC Address Table Info rmation Managing Source Learning page 2-10 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 3-1 3 Configuring Learned Por t Security Learned Port Security (LPS) pr ovides a mechanis m for authorizing source lear ning of MAC addresses on Ethernet and Gigabi t Ethernet ports.
Learned Port Security Specifications Configuring Learned Port Security page 3-2 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Learned Por t Security Specifications Learned Por t Security Defaults RFCs supported Not applicable at this time.
Configuring Learned Port Securi ty Sample Learned Port Security Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 3-3 Sample Learned Por t Security Configuration This section provides a quick tutoria l that demonstrates the fo llowing tasks: • Enabling LPS on a se t of switch ports.
Learned Port Security Overview Configuring Learned Port Security page 3-4 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Learned Por t Security Over view Learned Port Security (LPS) provides a mecha nism for controlling network de vice access on one or more switch ports.
Configuring Learned Por t Security Learned Port Security Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 3-5 How LPS Authorizes Source MAC Addresses When a packet is recei.
Learned Port Security Overview Configuring Learned Port Security page 3-6 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Static Configuration of Authorized MAC Addresses It is also possible to st atically configure aut horized source MAC a ddress entries into the LPS table.
Configuring Learned Port Security Enabling/Disabling Learned Port Security OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 3-7 Enabling/Disabling Learned Por t Security By default, LPS is disabled on all switch po rts. To enable LPS on a port, use the port-security command.
Configuring the Number of MAC Addresses A llowed Configuring Learned Port Security page 3-8 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring the Number of MAC Addresses Allowed By default, one MAC address is allowed on an LPS port .
Configuring Learned Por t Security Config uring an Authorized MAC Address Range OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 3-9 Configuring an Authorized MAC Address Range By default, each LPS port is set to a range of 00:0 0:00:00:00:00–ff:ff:ff:ff:ff:ff , which includes all MAC addresses.
Selecting the Security Violation Mode Configuring Learned Port Security page 3-10 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Selecting the Security V iolation Mode By default, the se curity violation mode for an LPS port is set to restr ict .
Configuring Learned Port Securi ty Displaying Learned Port Security Informatio n OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 3-11 Displaying Learned Por t Security Information .
Displaying Learned Port Security Inform ation Configuring Learned Port Security page 3-12 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 4-1 4 Configuring VLANs In a flat bridged network, a broa dcast domain is c o nfined to a sing le LAN segment or even a spec ific physical loca tion, such as a department or bui lding floor.
VLAN Specifications Configuring VLANs page 4-2 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 VLAN Specifications VLAN Defaults RFCs Supported 2674 - Definitions of Managed Ob jects for Bridges with Traffic Classes, Multic ast Filtering and Virtual LAN Extensions IEEE Standards Supported 802.
Configuring VLANs Sample VLAN Configuratio n OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 4-3 Sample VLAN Configuration The following steps p rovide a quick tutorial that will create VLAN 255 on a stack config uration that includes four switc hes.
Sample VLAN Configuration Configuring VLANs page 4-4 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 To verify that ports 3/2 -4 were assigned t o VLAN 255, use the show vlan port command.
Configuring VLANs VLAN Management Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 4-5 VLAN Management Over view One of the main benefi ts of using VLANs to segment network traffic, is that VLAN configuration and port assignment is han dled throu gh switch softwa re.
Creating/Modifying VL ANs Configuring VLANs page 4-6 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Creating/Modifying VLANs The initial con figuration fo r all Alcatel switche s consists of a defaul t VLAN 1 and all swit ch ports are initially assigne d to this VLAN.
Configuring VLANs Defining VLAN Port Assignments OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 4-7 Enabling/Disabling the VLAN Administrative Status To enable or disable the administrative status for an existing VLAN, enter vlan followed by a n existing VLAN ID and either enable or disable .
Defining VLAN Port Assignments Configuring VLANs page 4-8 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Changing the Default VLAN Assignment for a Por t To assign a switch port to a new default VLAN, enter vlan followed by an existi ng VLAN ID number, port default , then the slot/port design ation.
Configuring VLANs Defining VLAN Port Assignments OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 4-9 Configuring VLAN Ru le Classificati on VLAN rule classifi cation triggers dynamic VLAN po rt assignment when t raffic received on a mobile port matches the criteri a defined in a VLAN rule.
Defining VLAN Port Assignments Configuring VLANs page 4-10 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Enabling/Disabling VLAN M obile T ag Classification Use the vlan mobile-tag command to enable or disable the cla ssi fication of mo bile port packets b ased on 802.
Configuring VLANs Enabling/Disabling Span ning Tree for a VLAN OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 4-11 Enabling/Disabling Spanning T ree for a VLAN When a VLAN is created, an 802.1D standard Spanning Tree Al gorithm and Prot ocol (STP) instance is enabled for the VLAN by default.
Enabling/Disabling VLAN Authentication Configuring VLANs page 4-12 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Enabling/Disabling VLAN Authentication Layer 2 authentication uses VLAN membership to gr ant access to network re sources.
Configuring VLANs Bridging VLANs Across Multiple Switches OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 4-13 Bridging VLANs Acr oss Multiple Switches To create a VLAN brid ging domai n that extends across multiple swi tches: 1 Create a VLAN on each switch wit h the same VLAN ID number (e.
Verifying the VLAN Configuration Configuring VLANs page 4-14 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 The connection between Stack C and D is shown with a brok en line because the ports tha t provide this connection are in a bl ocking state.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 5-1 5 Configuring Spanning T ree Parameters The Spanning Tree Algorith m and Protocol (STP) is a self-configuring algorith m that maintains a loop- free topology while pr oviding data path redundancy and network scalabi lity.
Spanning Tree Specifications Conf iguring Spanning Tree Parameters page 5-2 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Spanning T ree Specifications Spanning T ree Bridge Parameter Defaults IEEE Standards supported 802.1D– Media Acce ss Control (MAC) Bridges 802.
Configuring Spanning Tree Parameters Sp anning Tree Port Parameter Defaults OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 5-3 Spanning T ree Por t Parameter Defaults Multiple Spanning T ree (MST) Region Defaults Although the following parameter values are specific to the MSTP (802.
Spanning Tree Overview Configuring Spanning Tree Parameters page 5-4 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Spanning T ree Over view Alcatel switches sup port the use of the 802.1D Sp anning Tree Algorith m and Protocol (STP), th e 802.
Configuring Spanning Tree Parameters Spanning Tree Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 5-5 Note. The distinction between a backup port and an alternate port was introduced with the IEEE 802.1w standard to he lp define rapid transi tion of an alte rnate port to a root port.
Spanning Tree Overview Configuring Spanning Tree Parameters page 5-6 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 The sending and receiv ing of Configuratio n BPDU between switches p.
Configuring Spanning Tree Parameters Spanning Tree Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 5-7 2 The best root path cost. 3 If root path costs are equal, t he bridge ID of the bridge sendin g the BPDU. 4 If the previous three values ti e, then the port ID (lowest priority value , th en lowest port number).
Spanning Tree Overview Configuring Spanning Tree Parameters page 5-8 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 The following d iagram shows the l ogical connectiv ity of the sa me physical to pology as det ermined by the Spanning Tree Algo rithm.
Configuring Spanning Tr ee Parame ters Spanning Tree Operating Modes OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 5-9 Spanning T ree Operating Modes The switch can operate in one o f two Spanning Tree modes: flat and 1x1 .
Spanning Tree Operating Modes Confi guring Spanning Tree Parameters page 5-10 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Flat Spanning T ree Example In the above example , if port.
Configuring Spanning Tr ee Parame ters Spanning Tree Operating Modes OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 5-11 The following diagram shows a switch runn ing in the 1x1 Spanning Tree mode and sh ows Spanning Tree participation for bo th fixed and tagged ports.
Configuring Spanning Tree Bridge Parame ters Configuring Spanning Tree Parameters page 5-12 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Configuring Spanning T ree Bridge Parameters.
Configuring Spanning Tr ee Parameters Conf iguring Spanning Tree Bridge Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 5-13 Note that exp licit command s using the cist and msti keywords are required to define an MSTP (802.
Configuring Spanning Tree Bridge Parame ters Configuring Spanning Tree Parameters page 5-14 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 The following sec tions provide i nformation and pr ocedures fo r using implicit bridge configurat ion commands and also includes explicit comma nd examples.
Configuring Spanning Tr ee Parameters Conf iguring Spanning Tree Bridge Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 5-15 Note.
Configuring Spanning Tree Bridge Parame ters Configuring Spanning Tree Parameters page 5-16 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Note that lowering t he hello time i nterval improv es the robu stness of the Spanning Tree algorithm.
Configuring Spanning Tr ee Parameters Conf iguring Spanning Tree Bridge Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 5-17 The explicit bridge 1x1 max age command configures the max age t i me for a VLAN instance when the switch is running in either mode (1x1 o r flat).
Configuring Spanning Tree Bridge Parame ters Configuring Spanning Tree Parameters page 5-18 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 -> bridge forward delay 10 -> bridge c.
Configuring Spanning Tr ee Parameters Co nfiguring Spanning Tree Port Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 5-19 Configuring Spanning T ree Por t Parameters The following sectio ns provide informat ion and procedures for using CLI commands to configure STP port parameters.
Configuring Spanning Tree Port Paramete rs Configuring Spanning Tree Parameters page 5-20 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 The following is a summary of Spanning Tree port configuratio n commands. For more information ab out these comman ds, see the Omn iSwitch CLI Reference Gu ide.
Configuring Spanning Tr ee Parameters Co nfiguring Spanning Tree Port Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 5-21 The following sec tions provide i nformation and proced ures for usi ng implicit Sp anning Tree po rt configu- ration command s and also inc lud es explicit command examples.
Configuring Spanning Tree Port Paramete rs Configuring Spanning Tree Parameters page 5-22 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 To enable or disable the Spanning Tree status for a li nk aggreg ate, use the bridge slot/port commands described above but specify a link aggregate control nu mber instead of a slot an d port.
Configuring Spanning Tr ee Parameters Co nfiguring Spanning Tree Port Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 5-23 STP or RSTP protocols are in use. See Chapter 6, “Using 802.1s Multiple Spanni ng Tree,” for more infor- mation.
Configuring Spanning Tree Port Paramete rs Configuring Spanning Tree Parameters page 5-24 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 By default, Span ning Tree is enab led on a port and the path cost is set to zero.
Configuring Spanning Tr ee Parameters Co nfiguring Spanning Tree Port Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 5-25 Path Cost for Link Aggregate Ports Physical ports that belong to a link aggregate do no t participate in the Span ning Tree Algorithm.
Configuring Spanning Tree Port Paramete rs Configuring Spanning Tree Parameters page 5-26 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 To change the path cost value for a link aggregate, use the bridge slot/port path cost commands described above, but specify a link aggregate cont ro l number instead of a slot and port.
Configuring Spanning Tr ee Parameters Co nfiguring Spanning Tree Port Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 5-27 Mode for Link Aggregate Ports Physical ports that belong to a link aggregate do no t participate in the Span ning Tree Algorithm.
Configuring Spanning Tree Port Paramete rs Configuring Spanning Tree Parameters page 5-28 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 To change the port connection type for a VLAN insta nce, specify a VL AN ID with the bridge slot/port connection command when th e switch is runnin g in the 1x1 mode.
Configuring Spanning Tr ee Parameters Sample Spanning Tree Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 5-29 Sample Spanning T ree Configuration This section provid es an example network configurati on in which Spanni ng Tree has calculated a loop - free topology.
Sample Spanning Tree Configuration C onfiguring Spanning Tree Parameters page 5-30 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 • Ports 2/1-3, 2 /8-10, 3/1-3, an d 3/8-10 provid e connection s to other swi tches and are all assigned to VLAN 255 on their respective switch es.
Configuring Spanning Tr ee Parameters Sample Spanning Tree Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 5-31 -> bridge 255 priority 10 VLAN 255 on Switch D will.
Verifying the Spanning Tree Configurat ion Configuring Spanning Tree Parameters page 5-32 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 V erifying the Spanning T ree Configuration To.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 6-1 6 Using 802.1s Multiple Spanning T ree The Alcatel Multiple Spanning Tree (M ST) implementation provides su pport for the IEEE 802.1s Multi- ple Spanni ng Tree Protocol (MSTP). In add ition to the 802.
MST Specifications Using 802.1s Multiple Spanning Tree page 6-2 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 MST Specifications Spanning T ree Bridge Parameter Defaults IEEE Standards supported 802.1D– Media Acce ss Control (MAC) Bridges 802.
Using 802.1s Multiple Spanning T ree Spanning Tree Port Parameter Defaults OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 6-3 Spanning T ree Por t Parameter Defaults MST Region Defaults Although the following parameter values are specific to the MSTP (802.
MST General Overview Using 802 .1s Multiple Spanning Tree page 6-4 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 MST General Over view The Multiple Span ning Tr ee (M ST) featur e all.
Using 802.1s Multiple Spanning T ree MST General Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 6-5 1x1 Mode STP/RSTP In the above 1x 1 mode example: • Both switches are running in the 1x1 mo de (one Spanning Tree inst ance per VLAN).
MST General Overview Using 802 .1s Multiple Spanning Tree page 6-6 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Flat Mode MSTP (802.1s) In the above flat mode MSTP example: • Both switches are running in the flat mode and using MSTP.
Using 802.1s Multiple Spanning T ree MST General Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 6-7 Comparing MSTP with STP and RSTP Using MSTP (802.1s) has the foll owing items in common wit h STP (802.1D) and RSTP (802.
MST General Overview Using 802 .1s Multiple Spanning Tree page 6-8 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 What is a Multiple Spanning T ree Region A Multiple Sp anning Tree regio n re presents a group of 802.1s switches. An MST regio n appears as a single, flat mode instance to switc hes outside the region.
Using 802.1s Multiple Spanning T ree MST General Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 6-9 number of hops for the region, however, i s not one o f the attribut es that define s whether or not a switch is a member of a re gion.
MST Configuration Overvi ew Using 802.1s Multiple Spanning Tree page 6-10 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 MST Configuration Over view The following g eneral step s are requir ed to set up a Multiple Span ning Tree (MST) config uration: • Select the flat Spanning Tree mode.
Using 802.1s Multiple Spanning T ree MST Configuration Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 6-11 Implicit commands resemble previously implemen ted Spanning Tree co mmands, but appl y to the appro- priate instance based on t he current mode and protocol that is active on the switch.
MST Interoperability and Mi gration U sing 802.1s Multiple Spanning Tree page 6-12 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 MST Inter operability and Migration Connecting an MSTP (802.1s) swit ch to a non-MSTP flat mode switch is supp orted.
Using 802.1s Multiple Spanning T ree MST Interoperability and Migratio n OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 6-13 Migrating fr om 1x1 Mode to Flat Mode MSTP As previously described, the 1x1 mo de is an Alcatel propri etary implementation th at applies one Span - ning Tree instance to each VLAN.
Quick Steps for Configuring an MST Reg ion Using 802.1s Multiple Spanning Tree page 6-14 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Quick Steps for Configuring an MST Region An MST region ident ifies a group of MSTP (80 2.1s) swit ches that is seen as a si ngle, flat mode instance by other regions and/ or non-MSTP switche s.
Using 802.1s Multiple Spanning T ree Quick Step s for Configuring an MST Region OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 6-15 3 Map VLANs 100 and 200 to MSTI 2 and VLAN s 300 and 400 to MSTI 4 using t he bridge msti vl an command to define the con figuration digest.
Quick Steps for Configuring MSTIs Usi ng 802.1s Multiple Spanning Tree page 6-16 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Quick Steps for Configuring MSTIs By default the Spa nning Tree software is a ctive on all swit ches and op erating in the 1x1 mode using the standard 802.
Using 802.1s Multiple Spanning T ree Quick Steps for Configuring MSTIs OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 6-17 The follow ing commands assign ports 2/1, 5/1 , 5/2, and.
Quick Steps for Configuring MSTIs Usi ng 802.1s Multiple Spanning Tree page 6-18 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Note that of the two data paths a vailable to MSTI 1 VLANs, one is still b locked because i t is seen as redundant for that instance.
Using 802.1s Multiple Spanning T r ee Verifying the MST Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 6-19 V erifying the MST Configuration To display information a.
Verifying the MST Configuration Using 802 .1s Multiple Spanning Tree page 6-20 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 7-1 7 Assigning Por ts to VLANs Initially all switch ports are no n-mobile and are assigned to VLAN 1, which is also their configured default VLAN.
Port Assignment Specific ations Assigning Ports to VLANs page 7-2 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Por t Assignment Specifications Por t Assignment Defaults IEEE Standards Supported 802.1Q– Virtual Bridged Local Area Networks 802.
Assigning Ports to VLANs Sample VLAN Port Assignment OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 7-3 Sample VLAN Por t Assignment The following ste ps provide a qu ick tutorial.
Statically Assigning Ports to VLANs Assigning Ports to VLANs page 7-4 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Statically Assigning Por ts to VLANs The vlan port default command is used to static ally assign bot h mobile and non -mobile port s to another VLAN.
Assigning Ports to VLANs Dynamic ally Assigning Ports to VLANs OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 7-5 How Dynamic Por t Assignment W orks Traffic received on mobile po.
Dynamically Assigning Ports to VLANs Assigning Ports to VLANs page 7-6 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 In the initial VLAN port assignment configuration shown below, • All three port s have worksta tions that ar e configured to se nd packets wi th an 802.
Assigning Ports to VLANs Dynamic ally Assigning Ports to VLANs OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 7-7 T agged Mobile Port T raffic T r iggers Dynamic VLAN Assignment OmniSwitch 6648 OmniSwitch 6648 OmniSwitch 6648 OmniSwitch 6648 OmniSwitch Port 2 VLAN 2 VLAN 1 VLAN 4 IP Network 130.
Dynamically Assigning Ports to VLANs Assigning Ports to VLANs page 7-8 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 VLAN Rule Classification VLAN rule classifi cation triggers dynamic VLAN po rt assignment when t raffic received on a mobile port matches the criteri a defined in a VLAN rule.
Assigning Ports to VLANs Dynamic ally Assigning Ports to VLANs OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 7-9 VLAN Rule Cla ssification : Initial Configuratio n As soon as the.
Dynamically Assigning Ports to VLANs Assigning Ports to VLANs page 7-10 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Mobile Port T raffic T rigge rs Dynamic VLAN Assignment Configur.
Assigning Ports to VLANs Dynamic ally Assigning Ports to VLANs OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 7-11 Enabling/Disabling Por t Mobility To enable mo bility on a port , use the vlan por t mobile command.
Dynamically Assigning Ports to VLANs Assigning Ports to VLANs page 7-12 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 When BPDU ignore is enabled and the mobile port r eceive s a BPDU, the following occurs: • The port reta ins its mobi le status and remai ns eligible fo r dynamic VLAN assignme nt.
Assigning Ports to VLANs Underst anding Mobile Port Properties OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 7-13 Understanding Mobile Por t Pr oper ties Dynamic assignme nt of mobile ports occurs witho ut user interve ntion when mo bile port traffic matches VLAN criteria.
Understanding Mobile Port Prop erties Assigning Ports to VLANs page 7-14 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 VLAN Management software on each switch tracks VPAs .
Assigning Ports to VLANs Underst anding Mobile Port Properties OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 7-15 How Mobile Port VLAN Assignments Age OmniSwitch OmniSwitch 6648 .
Understanding Mobile Port Prop erties Assigning Ports to VLANs page 7-16 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Configuring Mobile Por t Properties Mobile port pr operties indicat e mobile port status a nd affect port beh avior when the port is dynamically assigned to one or more VLANs.
Assigning Ports to VLANs Underst anding Mobile Port Properties OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 7-17 Enable/Disable De fault VLAN Restore To enable or disable defa ult VLAN restore, enter vlan port followed by the port’s slot/port designation then default vlan restore followed by enable or disable .
Understanding Mobile Port Prop erties Assigning Ports to VLANs page 7-18 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Enable/Disable 802.1X Por t -Based Access Contr ol To enable or disab le 802.1X on a mobile port, enter vlan port followed by the port’s slot/port designa- tion then 802.
Assigning Ports to VLANs Verifying VLAN Po rt Associations and Mobile Port Properties OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 7-19 V erifying VLAN Por t Associations and Mo.
Verifying VLAN Port Associations and Mobile Port Properties Assigning Ports to VLANs page 7-20 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 The following ex ample uses the show vlan.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 8-1 8 Defining VLAN Rules VLAN rules are used to classify mo bile port traffic for dy namic VLAN port assign ment.
VLAN Rules Specifications Defining VLAN Rules page 8-2 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 VLAN Rules Specifications VLAN Rules Defaults IEEE Standards Supported 802.1Q– Virtual Bridged Local Area Networks 802.1v– VLAN Classification by Prot ocol and P ort 802.
Defining VLAN Rules Sample VLAN Rule Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 8-3 Sample VLAN Rule Configuration The following steps p rovide a qu ick tutorial.
VLAN Rules Overview Defining VLAN Rules page 8-4 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 VLAN Rules Over view The mobile po rt feature availa ble on the swi tch allows dy namic VLAN po rt assignment ba sed on VLAN rules that are applied to mobile port traffic.
Defining VLAN Rules VLAN Rules Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 8-5 DHCP Rules Dynamic Host Config uration Protocol (DH CP) frames ar e sent from client workstations to request an IP address from a DHC P server.
VLAN Rules Overview Defining VLAN Rules page 8-6 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Binding Rules Binding rules restrict VLAN a ssignme nt to specifi c devices by requiring that devic e traffic match all crite- ria specified in the rule.
Defining VLAN Rules VLAN Rules Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 8-7 IP protocol rules also c apture DHCP traffic, i f no other DHCP rule exists that would classify the DHCP traffic into anot her VLAN. Therefore, it is not necessary to c ombine DHCP rules with IP protoco l rules for the same VLAN.
VLAN Rules Overview Defining VLAN Rules page 8-8 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Understanding VLAN Rule Precedence In addition to configurable VLAN rule types, there are t wo internal rule types fo r processing mobile port frames.
Defining VLAN Rules VLAN Rules Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 8-9 Prece dence S tep/Rule T ype Condition Result 1. Frame T ype Frame is a DHCP frame. Frame is not a DHCP frame. Go to Step 2. Skip Steps 2, 3, 4, and 5.
VLAN Rules Overview Defining VLAN Rules page 8-10 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 8. MAC-Port Bi nding Frame contains a matching sou rce MAC address and source port. Frame only contains a matching source MAC address; port does not match.
Defining VLAN Rules Configuring VLAN Rule Definitions OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 8-11 Configuring VLAN Rule Definitions Consider the followin g when config uring rule s for a VLAN: • The VLAN must already exist.
Configuring VLAN Rule Definitions Defining VLAN Rules page 8-12 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Refer to the following sections (liste d in the order of rule precedenc .
Defining VLAN Rules Configuring VLAN Rule Definitions OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 8-13 Defining DHCP MAC Range Rules A DHCP MAC rang e rule is similar t o a DHCP MAC ad dress rule, but allows the user to specify a ra nge of MAC addresses.
Configuring VLAN Rule Definitions Defining VLAN Rules page 8-14 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Defining DHCP Generic Rules DHCP generic rules capture all DHCP traffic t hat does no t match an existing DHCP MAC or DHCP port rule.
Defining VLAN Rules Configuring VLAN Rule Definitions OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 8-15 How to Define a MAC-Por t-IP Address Binding Rule To define a MAC-po rt-I.
Configuring VLAN Rule Definitions Defining VLAN Rules page 8-16 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 How to Define a MA C-Por t Binding Rule To define a MAC-port binding rule, enter vlan followed by a n existing VLAN ID then bind ing mac-po rt followed by a valid MAC address and a slot/port designat ion.
Defining VLAN Rules Configuring VLAN Rule Definitions OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 8-17 How to Define a Por t -Pro tocol Binding Rule To define a port- protocol .
Configuring VLAN Rule Definitions Defining VLAN Rules page 8-18 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Defining MAC Range Rules A MAC range rule is simi lar to a MAC address rul e, but allows th e user to specify a ran ge of MAC addresses.
Defining VLAN Rules Configuring VLAN Rule Definitions OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 8-19 Use the no form of the vlan ip command to remove an IP network addr ess rule.
Configuring VLAN Rule Definitions Defining VLAN Rules page 8-20 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Defining Protocol Rules Protocol rules cap ture frames that contain a prot ocol type that matches the protocol value specified in the rule.
Defining VLAN Rules Configuring VLAN Rule Definitions OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 8-21 Defining Custom (User) Rules A custom rule captures mobile port fra mes that contai n a specified pattern of data at a specified location.
Application Example: DHCP Rules Defining VLAN Rules page 8-22 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Application Example: DHCP Rules This application example shows how Dynamic Host Co nfiguration Protocol (D HCP) port an d MAC address rules are used in a DHCP-ba s ed netwo rk.
Defining VLAN Rules Applica tion Example: DHCP Rules OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 8-23 The following tabl e summarizes th e VLAN architectu re and rules fo r all devices in this network co nfigu- ration. The di agram on the follo wing page il lustrates th is network configurat ion.
Application Example: DHCP Rules Defining VLAN Rules page 8-24 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 DHCP Port and MAC Rule Application Example OmniSwitch 6648 OmniSwitch 6648.
Defining VLAN Rules Verifying VLAN Rule Co nfiguration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 8-25 V erifying VLAN Rule Configuration To display info rmation about VLAN ru.
Verifying VLAN Rule Configuration Defining VLAN Rules page 8-26 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 9-1 9 Configuring Por t Mapping Port Mapping is a security feature, which controls communic ation betwee n p eer users. Each session comprises a session ID, a set of user ports, and/or a set of network ports.
Port Mapping Specifications Configuring Port Mapping page 9-2 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Por t Mapping Specifications Por t Mapping Defaults The following ta ble shows port ma pping default values.
Configuring Port Mappin g Creating/ Deleting a Port Mapping Session OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 9-3 Creating/Deleting a Por t Mapping Session Before port mapping can be used, it is necessary to creat e a port mapping session.
Enabling/Disabling a Port Mapping Session Configuring Port Mapping page 9-4 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Enabling/Disabling a Por t Mapping Session By default, the port mapping session will be disabl ed.
Configuring Port Mappin g Sample Port Mapping Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 9-5 Sample Por t Mapping Configuration This section provi des an example port mapping netwo rk configuratio n.
Verifying the Port Mapping Configuration Configuring Port Mapping page 9-6 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Example Por t Mapping Configuration Steps The following ste ps provide a quick tutorial that configures t he port mapping sessi on shown in the diagram on page 9-5 .
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 10-1 10 Using Interswitch Pr otocols Alcatel Interswitch Proto col s (AIP) are used to di scover adja cent switches and retain mobile port informa- tion across switches.
AIP Specifications Using Interswitch Protocols page 10-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 AIP Specifications AMAP Defaults Sta ndards Not applica ble at this time.
Using Interswitch Protocols AMAP Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 10-3 AMAP Over view The Alcatel Mapping Adjacency Prot ocol (AMAP) is used to discover the topology of Om niSwitches or Omni S/Rs in a particul ar installation.
AMAP Overview Using Interswitch Protocols page 10-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 The transmission states are illu strated here. Discover y T r ansmission State When AMAP is active, at startup al l act ive switch ports are in the discov ery transmission state.
Using Interswitch Protocols Config uring A MAP OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 10-5 Common T ransmission and Remote Switches If an AMAP switch is connected to multiple AM AP switches via a h u b, the switch sends and receives Hello traffic to and from t he remote switc hes throug h the same port .
Configuring AMAP Using Interswitch Protocols page 10-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Configuring the AMAP Common Timeout Inter val The common timeout in terval is used on ly in the common transmission state to det ermine the time int er- val between sending Hell o update packets.
Using Interswitch Protocols Config uring A MAP OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 10-7 Displaying AMAP Information Use the show amap command to view a list of adjacent sw itches and the ir associated MAC addresses, interfaces, VLANs, and IP addresses.
Configuring AMAP Using Interswitch Protocols page 10-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 A simplified vi sual illustrati on of these conn ections is show n here for exampl e purposes only: See the OmniSwitch CLI Reference Guide for informatio n about the show amap command.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 11-1 11 Configuring 802.1Q 802.1Q is the IEEE standard for se gmenting networks into VLANs. 80 2.1Q segmentation is done by adding a specific tag to a packet. In this Chapter This chapter describ es the basic components of 802.
802.1Q Specifications Configuring 802.1Q page 11-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 802.1Q Specifications Note. Up to 4093 V LANs can be assigned to a tagged port or link aggregation group. However, each assignment coun ts as a sing le VL AN port associ ation.
Configuring 802.1Q 802.1Q Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 11-3 802.1Q Over view Alcatel’s 802.1Q is an IEEE sta ndard for sending fra mes through the network ta gged with VL AN identifi - cation. This chap ter details procedure s for configuring and mon itoring 802.
802.1Q Overview Configuring 802.1Q page 11-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 The port can only be assigned to one unta gged VLAN (in every case, this w ill be the defa ult VLAN). In the example above the de fault VLA N is VLAN 1.
Configuring 802.1Q Configuring an 802.1Q VLAN OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 11-5 Configuring an 802.1Q VLAN The following sec tions detail p rocedures for crea ting 802.1Q V LANs and assigni ng ports to 802.1Q VLANs.
Configuring an 802.1Q VLAN Configuring 802.1Q page 11-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Enabling T agging with Link Aggregation To enable tag ging on link a ggregation g roups, enter t he link aggr egation group identification number in place of the slot and port number, as shown: -> vlan 5 802.
Configuring 802.1Q Configuring an 802.1Q VLAN OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 11-7 Configuring the Frame T ype Once a port has been set to receive and send tagged fra mes, it will be able to receive or send tagged or untagged traffic.
Configuring an 802.1Q VLAN Configuring 802.1Q page 11-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Show 802.1Q Information After configur ing a port or link aggregation group to be a tagged port, y ou can view the settings by using the show 802.
Configuring 802.1Q Application Example OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 11-9 Application Example In this section the steps to create 8 02. 1Q conne ctions between switches are show n. The following d iagram shows a simple n etwork employing 802.
Application Example Configuring 802.1Q page 11-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 The following steps apply to Stack 2. They wil l attach port 2/1 to VLAN 2, and set the port to accept 802.
Configuring 802.1Q Verifying 802.1Q Configuratio n OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 11-11 The following steps ap ply to Stack 3.
Verifying 802.1Q Configuration Configuring 802.1Q page 11-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 12-1 12 Configuring Static Link Aggregation Alcatel’s static link aggregation software allows yo u to combine several physi cal links into one lar ge virtual link know n as a link aggregation gro up .
Static Link Aggregation Specifications Configuring Static Link Aggregation page 12-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Static Link Aggregation Specifications The table below lists specifi cations for stat ic groups.
Configuring Static Link Aggregati on Quick Steps for Configuring Static L ink Aggregation OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 12-3 Quick Steps for Configuring Static Link Aggregation Follow the steps belo w for a quick tutorial on conf iguring a static aggregate link betwe en two switches.
Quick Steps for Configuring Static Link Aggr egation Configuring Static Link Aggregation page 12-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Note. Optional . You can verify your static link aggregation settin gs with the show linkagg command.
Configuring Static Link Aggregation Static Link Aggregation Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 12-5 Static Link Aggregation Over view Link aggregati on allows.
Static Link Aggregation Overview Co nfiguring Static Link Aggregation page 12-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Relationship to Other Features Link aggregat ion groups are supported by other switch software featu res.
Configuring Static Link Aggregation Configuring Static Link Aggregation Groups OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 12-7 Configuring Static Link Aggregation Gr oups This section describes how t o use Alcatel’s Command Line Interface (CLI) comman ds t o configure static link aggregate groups.
Configuring Static Link Aggregation Grou ps Configuring Static Link Aggregation page 12-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Creating and Deleting a Static Link Aggregate Gr oup The following subsections desc ribe how to create and dele te static lin k aggregate groups with th e static linkagg size command.
Configuring Static Link Aggregation Configuring Static Link Aggregation Groups OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 12-9 Adding and Deleting Por ts in a Static Aggregate Group The following su bsections desc ribe how to add and dele te ports in a static agg regate group with the static agg agg num command.
Configuring Static Link Aggregation Grou ps Configuring Static Link Aggregation page 12-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 OmniSwitch 6624/660 0-U24/6600-P24 V alid Port.
Configuring Static Link Aggregation Configuring Static Link Aggregation Groups OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 12-11 OmniSwitch 66 48 V alid Port Assi gnment Locati.
Configuring Static Link Aggregation Grou ps Configuring Static Link Aggregation page 12-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 OmniSwitch 6624/660 0-U24/6600 -P24 V alid Por.
Configuring Static Link Aggregation Configuring Static Link Aggregation Groups OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 12-13 OmniSwitch 66 02-48 V alid Port Config uration .
Configuring Static Link Aggregation Grou ps Configuring Static Link Aggregation page 12-14 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 On an OmniSwitch 66 24 or 6600-U24 you must in.
Configuring Static Link Aggregati on Modif ying Static Aggregation Group Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 12-15 Modifying Static Aggregation Gr oup Parame.
Application Example Configuring Static L ink Aggregation page 12-16 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Application Example Static link aggregation groups are tr eated by the switch’s software the same way it treat s individual physi - cal ports.
Configuring Static Link Aggregati on Application Example OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 12-17 5 Repeat steps 1 through 4 on Switch B. All the co mmands wou ld be the same except yo u would substi - tute the appropriat e port numbers.
Displaying Static Link Aggregation Con figuration and Statistics Configuring Static Link Aggregation page 12-18 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Displaying Static Link Ag.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-1 13 Configuring Dynamic Link Aggregation Alcatel’s dynamic l ink aggregation software allows you to combine severa l physical link s into one large virtual link know n as a link aggregation gro up .
Dynamic Link Aggregation Specifications C onfiguring Dynamic Link Aggregation page 13-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Dynamic Link Aggregation Specifications The table below lists specifications for dynami c aggregation gr oups and ports: IEEE Specifications Su pported 802.
Configuring Dynamic Link Aggregation Dy namic Link Aggregation Default Values OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-3 Dynamic Link Aggregation Default V alues The table below lists default values fo r dynamic aggregate groups.
Quick Steps for Configuring Dynamic Lin k Aggr egation Configuring Dynamic Link Aggregation page 13-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Quick Steps for Configuring Dynamic Link Aggregation Follow the steps below for a quic k tutorial o n configurin g a dynamic aggregate link between two switches.
Configuring Dynamic Link Aggregation Quick Step s for Configur ing Dynamic Link Aggregation OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-5 Note. As an option, you can verify your dynamic aggregat ion group settings with the show linkagg command on ei ther the act or or partner switch.
Quick Steps for Configuring Dynamic Lin k Aggr egation Configuring Dynamic Link Aggregation page 13-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 An example of what these commands .
Configuring Dynamic Link Aggregation Dynamic Link Aggregation Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-7 Dynamic Link Aggregation Over view Link aggregati on all.
Dynamic Link Aggregation Overview Co nfiguring Dynamic Link Aggregation page 13-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Example of a Dyna mic Aggr egate Gr oup Network Dynami.
Configuring Dynamic Link Aggregation Dynamic Link Aggregation Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-9 Relationship to Other Features Link aggregation groups are supp orted by other switch software features. For ex ampl e, you can co nfigure 802.
Configuring Dynamic Link Aggregate Groups Configuring Dynamic Link Aggregation page 13-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring Dynamic Link Aggregate Gr oups This section describes how t o use Alcatel’s Command Line Inte rface (CLI) commands to create, modi fy, and delete dynamic aggregate g roups.
Configuring Dynamic Link Aggregation Conf iguring Dynamic Link Aggregate Gr oups OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-11 Creating and Deleting a Dynamic Aggregate Group The following su bsections descri be how to crea te and delete dynamic aggregat e groups with t he lacp linkagg size command.
Configuring Dynamic Link Aggregate Groups Configuring Dynamic Link Aggregation page 13-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring Por ts to Join and Removing Ports i.
Configuring Dynamic Link Aggregation Conf iguring Dynamic Link Aggregate Gr oups OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-13 OmniSwitch 6624 /6600-U24/660 0-P24 V alid Po.
Configuring Dynamic Link Aggregate Groups Configuring Dynamic Link Aggregation page 13-14 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 OmniSwitch 6648 V alid Port Configuratio n Loca.
Configuring Dynamic Link Aggregation Conf iguring Dynamic Link Aggregate Gr oups OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-15 OmniSwitch 6624 /6600-U24/660 0-P24 V alid Po.
Configuring Dynamic Link Aggregate Groups Configuring Dynamic Link Aggregation page 13-16 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 OmniSwitch 6602-48 V alid Port Configur ation L.
Configuring Dynamic Link Aggregation Conf iguring Dynamic Link Aggregate Gr oups OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-17 On an OmniSwitch 6624, 6600-U24 , or 6600-P24.
Configuring Dynamic Link Aggregate Groups Configuring Dynamic Link Aggregation page 13-18 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 As an option, you can use the ethernet , fastet.
Configuring Dynamic Link Aggregation Mo difyin g Dynamic Link Aggregate Group Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-19 Modifying Dynamic Link Aggregate Gr oup Parameters The table on page 13 -3 lists default group and port settings fo r Alcatel’s dynamic link aggregation soft- ware.
Modifying Dynamic Link Aggregate Group Para meters Configuring Dynamic Link Aggregation page 13-20 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 For example, to n ame dynamic aggregat e group 4 “Eng ineering” you w ould enter: -> lacp linkagg 4 name Engineering Note.
Configuring Dynamic Link Aggregation Mo difyin g Dynamic Link Aggregate Group Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-21 Deleting a Dynamic Aggregate Actor Ad.
Modifying Dynamic Link Aggregate Group Para meters Configuring Dynamic Link Aggregation page 13-22 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Restoring the Dynamic Aggre gate Gr ou.
Configuring Dynamic Link Aggregation Mo difyin g Dynamic Link Aggregate Group Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-23 For example, to reset t he partner sy.
Modifying Dynamic Link Aggregate Group Para meters Configuring Dynamic Link Aggregation page 13-24 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Note. A port may belong to only one aggregate grou p. In addition, mobile ports cann ot be aggregated.
Configuring Dynamic Link Aggregation Mo difyin g Dynamic Link Aggregate Group Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-25 Note. Specifying none remove s all administrativ e states from the LACPDU co nfigurat ion.
Modifying Dynamic Link Aggregate Group Para meters Configuring Dynamic Link Aggregation page 13-26 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 For exampl e, to modify the system ID .
Configuring Dynamic Link Aggregation Mo difyin g Dynamic Link Aggregate Group Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-27 Modifying the Actor Port Priority By default, the actor port priority (used to converge dynamic key changes) is 0.
Modifying Dynamic Link Aggregate Group Para meters Configuring Dynamic Link Aggregation page 13-28 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Modifying Dynamic Aggregat e Par tner .
Configuring Dynamic Link Aggregation Mo difyin g Dynamic Link Aggregate Group Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-29 Note. Specifying none remove s all administrativ e states from the LACPDU co nfigurat ion.
Modifying Dynamic Link Aggregate Group Para meters Configuring Dynamic Link Aggregation page 13-30 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Note.
Configuring Dynamic Link Aggregation Mo difyin g Dynamic Link Aggregate Group Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-31 Configuring the Partner Por t System .
Modifying Dynamic Link Aggregate Group Para meters Configuring Dynamic Link Aggregation page 13-32 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Restoring the Partner Por t System Pri.
Configuring Dynamic Link Aggregation Mo difyin g Dynamic Link Aggregate Group Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-33 For example, to modify the port prior.
Application Examples Configuring Dynamic Link Aggregation page 13-34 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Application Examples Dynamic link aggregatio n groups are treated by the switch’s software th e same way it tr eats individu al physical ports.
Configuring Dynamic Link A ggregation Application Examples OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-35 Link Aggregation and Spanning T ree Example As shown in the figu re on page 13-34 , VLAN 10, which uses the Spanning Tree Protocol (S TP) with a priority of 15, has been configu red to use dynamic aggrega te group 7.
Application Examples Configuring Dynamic Link Aggregation page 13-36 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Link Aggregation and QoS Example As shown in the figu re on page 13-34 , VLAN 12, wh ich uses 802 .1Q frame tagg ing and 802.
Configuring Dynamic Link A ggregation Application Examples OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-37 10 Repeat steps 1 through 9 on Switch C. All the co mmands wou ld be the same except yo u would substi - tute the appropriat e port numbers.
Displaying Dynamic Link Aggregation Configuration a nd Statistics Configuring Dynamic Link Aggregatio n page 13-38 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Displaying Dynamic Lin.
Configuring Dynamic Link Aggregat ion Displaying Dynami c Link Aggregation Configuration and Statistics OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 13-39 A screen similar to th.
Displaying Dynamic Link Aggregation Configuration a nd Statistics Configuring Dynamic Link Aggregatio n page 13-40 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 14-1 14 Configuring IP Internet Protocol (IP) is primarily a ne twork-layer (La yer 3) protoco l that contain s addressing and control information that en ables packets to be forwarded.
IP Specifications Configuring IP page 14-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 • Managing IP – “Internet Control M essage Protocol (ICMP)” on page 14-19 – “Usin.
Configuring IP Quick Steps for Configuring IP Forwarding OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 14-3 Quick Steps for Configuring IP For warding Using only IP, which is always enabled on the switch, devi ces connected to ports on the same VLAN are able to commun icate at Laye r 2.
IP Overview Configuring IP page 14-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 IP Over view IP is a network-layer (Laye r 3) protocol t hat contains add ressing and control information t hat enables packets to be forwarded on a netwo rk.
Configuring IP IP Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 14-5 Additional IP Protocols There are several additional IP-relate d protocols that may be used with IP forwarding. These protocols are included as part of the base code.
IP Forwarding Configuring IP page 14-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 IP For warding Network device traffic is br idged (switched) at the Layer 2 level between ports that are assig ned to the same VLAN.
Configuring IP IP Forwarding OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 14-7 Configuring an IP Router Inter face IP is enabled by de fault.
IP Forwarding Configuring IP page 14-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Note. Assign only ports to th e VLAN th at are ca pable of handling t he MTU size restrictions configured for the IP interface(s) asso ciated with the VLAN.
Configuring IP IP Forwarding OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 14-9 Creating a Static Route Static routes are user-def in ed and carry a hi gher priority tha n routes created b y dynamic routing proto- cols.That is, stat ic routes always ha ve priority over dyn amic routes regardless o f the metric val ue.
IP Forwarding Configuring IP page 14-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring Address Resolution Protocol (ARP) To send packets on a locally connect ed network, the switch use s ARP to matc h the IP address of a devi ce with its physical (MAC) address.
Configuring IP IP Forwarding OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 14-11 Note. You can also use the no arp command to delete a dynami c entry from the table. Clearing Dynamic ARP Entries Dynamic entries can be cleared using t he clear arp-cache command.
IP Forwarding Configuring IP page 14-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 • An IP mask (e. g. 255.0.0.0 ) used to identi fy which pa rt of the ARP pa cket IP address is compa red to the filter IP address. • An optional VLAN ID to specify tha t the filter is only app lied to ARP packets from t hat VLAN.
Configuring IP IP Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 14-13 IP Configuration IP is enabled on the switch by de fault and th ere are few option s that can, or ne ed to be, c onfigured. This section provides instruct ions for some basic IP configurat ion options.
IP Configuration Configuring IP page 14-14 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 IP-Directed Broadcasts An IP directed broadcast is an IP datagram th at has al l zeroes or a ll 1’s in the ho st portion of the destina- tion IP address.
Configuring IP IP Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 14-15 • Trap generation . If the total penalty v alue exceeds th e set port scan p enalty value threshold, a tra p is generated to alert the administrator tha t a port scan may be in progress.
IP Configuration Configuring IP page 14-16 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 In the next minute, 10 more T CP and UDP closed po rt packets are rec eived, along with 200 UDP open port packets.
Configuring IP IP Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 14-17 Setting the Port Scan Penalty V alue Threshold The port scan pena lty value t hreshold is the .
IP Configuration Configuring IP page 14-18 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 The following ta ble lists ip servic e command options for specifying TCP/ UDP services and al.
Configuring IP Managing IP OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 14-19 Managing IP The following sec tions descri be IP commands th at can be used t o monitor and trouble shoot IP forward ing on the switch.
Managing IP Configuring IP page 14-20 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Activating ICMP Contr ol Messages ICMP messages are ident ified by a type and a code . This number pa ir speci fies an ICMP message. For example, ICMP type 4, code 0, speci fies the source quench ICMP message.
Configuring IP Managing IP OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 14-21 In additi on to th e icmp type command, several common ly used ICMP messages have been separate CLI commands for co nvenience .
Managing IP Configuring IP page 14-22 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Setting the Minimum Packet Gap The minimum packet g ap is the time required between se nding messages of a like type.
Configuring IP Managing IP OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 14-23 Using the Ping Command The ping command is used to test whethe r an IP destination can be reach ed from the loc al switch. This command sends an ICMP e cho request to a destination an d then waits for a reply.
Verifying the IP Configuration Configuring IP page 14-24 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Displaying UDP Information UDP is a secondary transport-laye r pr otocol that uses IP for del ivery. UDP is not connection-o riented and does not prov ide reliable end-to-end de livery of data grams.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 15-1 15 Configuring IPv6 Internet Protocol version 6 (IPv6) is the ne xt generation of Internet Pr otocol version 4 (IPv4 ). Both versions are support ed along with the abilit y to tunnel IPv6 traffic over IPv4 .
IPv6 Specifications Configur ing IPv6 page 15-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 IPv6 Specifications IPv6 Defaults The following ta ble lists the de faults for IPv6 confi guration thro ugh the ip command.
Configuring IPv6 Quick Steps for Configuring IPv6 Routing OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 15-3 Quick Steps for Configuring IPv6 Routing The following tuto rial assumes that VLAN 200 and VLAN 300 already exist in the switch conf iguration.
IPv6 Overview Configur ing IPv6 page 15-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 IPv6 Over view IPv6 provides the b asic functiona lity that i s offered with IPv4 but includes.
Configuring IPv6 IPv6 Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 15-5 IPv6 Addressing One of the main differences between IP v6 and IPv4 is that the address si ze increased from 32 bits to 128 bits.
IPv6 Overview Configur ing IPv6 page 15-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Since the last four words of the ab ove a ddress are uncompressed values, th e double colo n indicates tha t the first four words of the address all conta in zeros.
Configuring IPv6 IPv6 Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 15-7 Stateless autoconfig uration is not a vailable for a ssigning a global unicast or an ycast address to an IPv6 interface. In other words, manu al configuratio n is required to a ssign a non-li nk-local add ress to an inte r- face.
IPv6 Overview Configur ing IPv6 page 15-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 6to4 Site to 6to4 Site over IPv4 Domain In this scenario, isolated IPv6 sites have connecti vity over an IPv4 network through 6to4 bor der routers.
Configuring IPv6 IPv6 Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 15-9 In the above diagram: 1 6to4 relay router ad vertises a route to 2002:: /16 on its IPv6 router interface.
Configuring an IPv6 Interface Configuring IPv6 page 15-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring an IPv6 Inter face The ipv6 interface command is used t o create an IPv6 interfac e for a VLAN or a tunn el.
Configuring IPv6 Configuring an IPv6 Interface OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 15-11 Use the show ipv6 interf ace command to verify t he interface configu ration for the swit ch. For more info r- mation about this command, see the OmniSwitch CLI Reference Guide.
Assigning IPv6 Addresses Configur ing IPv6 page 15-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Assigning IPv6 Addresses As was previously mentione d, when an IPv6 interface is crea ted for a VLAN or a configured tunnel, an IPv6 link-local a ddress is automatical ly created for that interface.
Configuring IPv6 Assigning IPv6 Addresses OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 15-13 Removing an IPv6 Address To remove an IPv6 address from an interfac e, use the no form of the ipv6 address command.
Configuring IPv6 Tunnel Interfaces Configuring IPv6 page 15-14 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring IPv6 T unnel Inter faces There are two type s of tunnels supp orted: 6to4 and conf igured .
Configuring IPv6 Verifying the IPv6 Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 15-15 V erifying the IPv6 Configuration A summary of the show command s used for v.
Verifying the IPv6 Configuration Configuring IPv6 page 15-16 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 16-1 16 Configuring RIP Routing Information Prot ocol (RIP) is a widely used Interior G ateway Protocol (IGP) th at uses hop count as its routin g metric. RIP-enab led routers update neighbo ring routers by transmitting a copy of their own routing table.
RIP Specifications Configuring RIP page 16-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 RIP Specifications RIP Defaults The following table list s the defaults for RI P configuratio n through the ip ri p command.
Configuring RIP Quick Steps for Configuring RIP R outing OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 16-3 Quick Steps for Configuring RIP Routing To forward packets to a devic e on a different VLAN , you must create a router port on each VLAN.
RIP Overview Configuring RIP page 16-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 14 Use the ip rip redist-filter command to redistribute all local routes. For example: -> ip rip redist-filter local 0.0. 0.0 0.0.0.0 15 Enable RIP redistri bution using the ip rip redist status command.
Configuring RIP RIP Routing OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 16-5 RIP deletes rout es from the database if th e next switch to that destinati on says the route co ntains more than 15 hops.
RIP Routing Configuring RIP page 16-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 RIP Routing Loading RIP When the switch i s initially co nfigured, RIP must be l oaded into switc h memory. Use th e ip load rip command to load RIP.
Configuring RIP RIP Routing OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 16-7 Creating a RIP Inter face You must create a RIP interfa ce on a VLAN’s IP router p ort to enable RI P routing. Ente r the ip rip inter- face command followed by the IP ad dress of the VLAN ro uter port.
RIP Routing Configuring RIP page 16-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Configuring the RIP In terface Receive Option The RIP receive option defi nes the type(s) of RIP packets that the interface wi ll accept. Using thi s command will overri de RIP default behavior.
Configuring RIP RIP Opti ons OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 16-9 RIP Options The following sec tions detail p rocedures for config uring RIP option s. RIP must be load ed and enabled o n the switch before you can configu re any of the RIP configurati on options.
RIP Redistribution Configuring RIP page 16-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 3 Configuring a RIP Redistribut ion Filter – Creating a Filter – Configuri ng a Redistributio n Filter Action (o ptional) – Configuri ng a Redistribut ion Metric (opti onal).
Configuring RIP RIP Redistribution OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 16-11 Configuring a Redistribution Metric When redist ributing routes into RIP, th e metric for th e redistributed route is calcula ted as a summation of the route’s met ric and the corre sponding metric in the redistrib ution polic y.
RIP Redistribution Configuring RIP page 16-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Creating a Redistribution Filter Use the ip rip redist-filter command to create a RIP redist ribution fi lter. Enter the command, the ro ute type, and destin ation IP address and mask of the traffic you w ant to redi stribute.
Configuring RIP RIP Redistribution OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 16-13 Configuring a Redistribu tion Filter Metric You can priori tize redistribu tion of route ty pes to a net work by assig ning a metric val ue to a route t ype(s).
RIP Security Configuring RIP page 16-14 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 RIP Security By default, th ere is no authen tication u sed for a RIP.
Configuring RIP Verifying the RIP Co nfiguration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 16-15 Configuring Passwords If you configure si mple or MD5 aut hentication y ou must configure a t ext string that will be used a s the password for the R IP interface.
Verifying the RIP Configuration Configuring RIP page 16-16 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 17-1 17 Configuring RDP The Router Discov ery Protocol (RDP) is an extensio n of ICMP that allows end hosts to dis cover routers on their networks. Th is implementation of R DP suppor ts th e router requ irements as defi ned in RFC 12 56.
RDP Specifications Configuring RDP page 17-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 RDP Specifications RDP Defaults RFCs Supported RFC 1256–ICMP Route r Discovery Messages Router advertisem ents Supported Host solicitations Only responses to solicita tions support ed in this release.
Configuring RDP Quick Steps for Configuring RDP OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 17-3 Quick Steps for Configuring RDP Configuring RDP i nvolves enabling RDP operation on the switch and creating RDP interfa ces to adver- tise VLAN route r IP addres ses on the LAN.
Quick Steps for Configuring RDP Configuring RDP page 17-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 -> show ip router-discovery interface Marketing Name = Marketing, IP Address = 11.
Configuring RDP RDP Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 17-5 RDP Over view End hosts (clients) sen ding traffic to other n etworks need to forward their traffic to a router. In order to do this, hosts need t o find out if one or more ro uters ex ist o n their LAN and learn th eir IP addresses.
RDP Overview Configuring RDP page 17-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 RDP Inter face s An RDP interface is created by enabling RDP on an IP router interface. Onc e en abled, the RDP interface becomes active and joins the all -ro uters IP mult icast group (224.
Configuring RDP RDP Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 17-7 Security Concerns ICMP RDP packets are not authenticated, whic h ma kes th em vulnerable to th e following attac ks: • Passive monitoring —Attackers can use RDP to re-route traffi c from vulnerable sy stems through the attacker’s sy stem.
Enabling/Disabling RDP Configuring RDP page 17-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Enabling/Disabling RDP RDP is included in t he base softwa re and is av ailable when th e switch starts up . However, by defa ult this feature is no t operationa l until it is enab led on the swit ch.
Configuring RDP Creating an RDP Interface OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 17-9 When an RDP interface is created, it is automatical ly config ured with the following defau lt paramete r values: It is only necessary t o change the abo ve parameter value s if the defa ult value is no t sufficient .
Creating an RDP Interface Configuring RDP page 17-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Setting the Maximum Advertisement Inter val To set the maximum amo unt of time, in secon ds, that RDP wi ll allow between adv ertisements, use the ip router-discovery interfa ce max-advertisement-interval command.
Configuring RDP Verifying the RDP Co nfiguration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 17-11 Setting the Preference Levels for Router IP Addresses A preferen ce level is a ssigned to ea ch router IP ad dress contai ned within a n advertise ment pack et.
Verifying the RDP Configuration Configuring RDP page 17-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 18-1 18 Configuring DHCP Relay The User Datagram Protocol (UDP) is a conn ectionless transpo rt protocol that runs on top of IP ne tworks. The DHCP Relay allows you to use nonroutable protocols (such as UDP) in a routing envir onment.
DHCP Relay Specifications Configuring DHCP Relay page 18-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 DHCP Relay Specifications The following ta ble lists specifica tions for th e DHCP Relay.
Configuring DHCP Relay DHCP Relay Defaults OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 18-3 DHCP Relay Defaults The following tabl e describes the defa ult values of th e DHCP Relay parameters. Parameter Description Comma nd Default V alue/Comments Default UDP service.
Quick Steps for Setting Up DHCP Relay Configuring DHCP Relay page 18-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Quick Steps for Setting Up DHCP Relay You should config ure DHCP Relay on switches wh ere packets are rout ed between IP ne tworks.
Configuring DHCP Relay DHCP Relay Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 18-5 DHCP Relay Over view The DHCP Relay service, its correspond ing port numbers, and co.
DHCP Relay Overview Configuring DHCP Relay page 18-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 DHCP and the OmniSwitch The unique characteristi cs of the DHCP protocol requ ire a good plan be fore setting up the switch in a DHCP environment.
Configuring DHCP Relay DHCP Relay Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 18-7 External DHCP Relay Application The DHCP Relay may be configured on a router that is external to the switch. In this app licati on exampl e the switched ne twork has a single VLAN configured with mu ltiple segments.
DHCP Relay Overview Configuring DHCP Relay page 18-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Internal DH CP Relay The intern al DHCP R elay is configur ed using the UDP forwarding feature in the switch, avail able through the ip helper address command.
Configuring DHCP Relay DHCP Relay Implementation OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 18-9 DHCP Relay Implementation The OmniSwitch allows you t o configure the DHCP Re lay feature in one of tw o ways. You can set up a global DHCP request or you can set up the DHCP Re lay based on the VLAN of the DHCP request.
DHCP Relay Implementation Configuring DHCP Relay page 18-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Per-VLAN DHCP For the Per-VLAN DHCP service , you must identif y the number of the VLAN th at makes the relay request.
Configuring DHCP Relay DHCP Relay Implementation OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 18-11 Setting the For ward Delay Forward Delay is a time period that gives the local se rver a chance to respond to a client before the relay forwards it further out in the netw ork.
Using Automatic IP Configuratio n Configuring DHCP Relay page 18-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Using Automatic IP Configuration An additional functio n of the DHCP Relay feature enables a switch to broadc ast a BootP or DHCP request packet at boot time to ob tain an IP address for default VLAN 1.
Configuring DHCP Relay Configuring UDP Port Relay OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 18-13 Configuring UDP Por t Relay In addition to configuring a relay operatio n for BOOTP/DHCP traf fic on the switc h, it is also possi ble to configure rel ay for generic UD P se rvice ports (i.
Configuring UDP Port Relay Configuring DHCP Relay page 18-14 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Enabling/Disabling UDP Por t Relay By default, a global relay operation i s enabled for BOOTP/DHCP relay well-known ports 67 and 68, which becomes active when an IP network host addre ss for a DHCP server is sp ecified.
Configuring DHCP Relay Configuring DHCP Security Features OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 18-15 Configuring DHCP Security Features There are two DHCP security features avai lable: DHCP re lay agent info rmation optio n (Optio n-82) and DHCP Snooping.
Configuring DHCP Security Features Configuring DHCP Relay page 18-16 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 How the Relay Agent Processes DHCP Packets fr om the Client The foll.
Configuring DHCP Relay Configuring DHCP Security Features OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 18-17 Enabling the Relay Agent Information Option-82 Use the ip helper a gent-infor mation command to enable the DHCP Opti on-82 feature for the switch.
Configuring DHCP Security Features Configuring DHCP Relay page 18-18 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 When DHCP Snooping is fi rst enabled, all ports are con sidered untr usted. It is important to then config ure ports connected to a DHCP server inside the network as a truste d port.
Configuring DHCP Relay Configuring DHCP Security Features OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 18-19 • Make sure th at Option-8 2 data insert ion is alway s enabled a t the switch o r VLAN level. See “Enabling DHCP Snooping” on page 18-19 for more information.
Configuring DHCP Security Features Configuring DHCP Relay page 18-20 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 VLAN-Level DHCP Snooping To enable DHCP Snooping at the VLAN level, use the ip helper dhcp-snooping vlan command.
Configuring DHCP Relay Configuring DHCP Security Features OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 18-21 Note it is necessa ry to configure po rts that are connected to DHCP serv ers within the network and/or fire- wall as truste d ports so that necessary DHCP tr affic to /from the server is not bloc ked.
Configuring DHCP Security Features Configuring DHCP Relay page 18-22 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Synchronizing the Binding T able To synchronize the contents of t he dhcpBinding.db file with the bi nding table contents that resi des in memory, use the ip helper dhcp-snoo ping b inding action command.
Configuring DHCP Relay Verifying the DHCP Relay Co nfiguration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 18-23 V erifying the DHCP Relay Configuration To display information about the DHCP Relay and BOOTP/DHCP, use the show commands listed below.
Verifying the DHCP Relay Configuration Configuring DHCP Relay page 18-24 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 19-1 19 Configuring VRRP The Virtual Route r Redundancy Pro tocol (VRRP) is a standard router redu ndancy protoco l supported in IP version 4. It is based on RFC 2338 an d provides redundancy by eliminating the single poi nt of failure inherent in a default route environment.
VRRP Specifications Configuring VRRP page 19-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 VRRP Specifications VRRP Defaults The following ta ble lists the de faults for VRRP con f.
Configuring VRRP Quick Steps for Creating a Virtual Router OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 19-3 Quick Steps for Creating a V ir tual Router 1 Create a virtual router. Specify a virtual ro uter ID (VRID) and a VLAN ID.
VRRP Overview Configuring VRRP page 19-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 VRRP Over view VRRP allows rou ters on a LAN to ba ck up a defau lt route. VRRP dyn amically assi gns responsibi lity for a virtual router to a physical router (VRRP ro uter) on th e LAN.
Configuring VRRP VRRP Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 19-5 If OmniSwitch A becomes unavai lable, Omn iSwitch B beco mes the master r outer. OmniSwit ch B will then respond to ARP requests for IP addre ss A using the virtual router’s MAC address (00:00:5E:00:01 :01).
VRRP Overview Configuring VRRP page 19-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 If backup routers are configured with priori ty values th at are close in value, there may be a.
Configuring VRRP Interaction With Other Features OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 19-7 VRRP T racking A virtual router’s prior ity may be conditionally modified to prevent ano ther router from ta king over as master.
Configuration Overview Configuring VRRP page 19-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Configuration Over view VRRP is part of the base software . At startup, VRRP is loaded onto the switch and is enabled. Virtual routers must first be configured and enabled as desc ribed in the sections .
Configuring VRRP Configuration Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 19-9 • Preempt mode . By default, p reempt mode is e nabled. Use no preempt to turn it off, and preempt to turn it back on. For more informati on about the p reempt mode, see “Setting Preemp tion for Virtua l Routers” on page 19-11 .
Configuration Overview Configuring VRRP page 19-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring the Adver tisement Inter val The advertisement interval is c onfigurable, b ut all vi rtual routers with the same VR ID should be confi g- ured with the same va lue.
Configuring VRRP Configuration Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 19-11 In the above example, virtual router 6 is disabled. (If you are modi fying an existi ng virtual ro uter, the virtual router m ust be disabled b efore it m ay be modified.
Configuration Overview Configuring VRRP page 19-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 A virtual router must be disabled before it may be modified. Use the vrrp command to disable the virtual router first; then use the command agai n to modify the parameters.
Configuring VRRP Configuration Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 19-13 Creating T racking Policies To create a tracking poli cy, use the vrr p track command and specify the amou nt to decrease a virt ual router’s priority an d the slot/port, IP address, or IP int erface name to b e tracked.
Verifying the VRRP Configuration Configuring VRRP page 19-14 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 V erifying the VRRP Configuration A summary of the show commands used for ve.
Configuring VRRP VRRP Application Example OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 19-15 VRRP Application Example In addition to pro viding redund ancy, VRRP can assist in load balan cing outgoin g traffic. The figu re below shows two virtual rou ters with th eir hosts splitting traffic between t hem.
VRRP Application Example Configuring VRRP page 19-16 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Note. The same VRRP configuration mu st be set up on each OmniSwitch 6600 stack. The VRRP router that contains, or owns, the IP address will automatica lly become the ma ster for that virtua l router.
Configuring VRRP VRRP Application Example OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 19-17 VRRP T racking Example The figure below sh ows two VRRP routers with two virtu al routers backing up one IP address on each VRRP router respectivel y.
VRRP Application Example Configuring VRRP page 19-18 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Note. The preempt o ption must be enabled on virtual r outer 1; otherwise the origi nal master will not be able to take over.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 20-1 20 Managing Authentication Ser vers This chapter desc ribes authent ication servers a nd how th ey are used with t he swit ch.
Authentication Server Specification s Managing Authentication Servers page 20-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Authentication Ser ver Specifications RADIUS RFCs Suppor.
Managing Authentication Servers Server Defaults OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 20-3 Ser ver Defaults The defaults for authentica tion server configuration on the swit ch are listed in the t ables in the n ext sections.
Quick Steps For Configuring Authentication Servers Managing Auth entication Servers page 20-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Quick Steps For Configuring Authentication Ser vers 1 For RADIUS or LDAP servers, config ure user attribute informati on on the servers.
Managing Authentication Servers Se rver Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 20-5 Ser ver Over view Authentication servers are somet imes referred to as AAA servers (authenti cation, authorization, and accounting).
Server Overview Managing Authentication Servers page 20-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 A RADIUS server supporting the chall enge and response mechanism as defined in RADIUS RFC 2865 may access an ACE/Server for authentication purposes.
Managing Authentication Servers Se rver Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 20-7 Por t-Based Network Access Contro l (802.1X) For devices authenticati ng on an 802.1X port on the switch, only RADIUS authenticati on servers are supported.
ACE/Server Managing Authentication Servers page 20-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 ACE/Ser ver An external ACE/Server may be used for authenticat ed switch access. It cannot be used for Layer 2 authentication or for policy management.
Managing Authentication Servers RADIUS Servers OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 20-9 RADIUS Ser vers RADIUS is a st andard authent ication and accounting protocol de fined in RFC 2865 and RFC 286 6. A built-in RADIUS client is available in th e switch .
RADIUS Servers Managing Authentication Servers page 20-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 19 20 21 22 23 Callbac k-Num ber Callback-Id Unassigned Frame-Route Framed-IPX-Network Not supported. These attr ibutes are used fo r dial-up sessions; not applicab le to the RADIUS c lient in the sw itch.
Managing Authentication Servers RADIUS Servers OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 20-11 V endor-Specific Attributes for RADIUS The Alcatel RADIUS c lient supports at tribute 26, wh ich includes a vendor ID and some a dditional sub - attributes call ed subtypes.
RADIUS Servers Managing Authentication Servers page 20-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring Functional Pr ivileges on the Ser ver Configuring t he functional p.
Managing Authentication Servers RADIUS Servers OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 20-13 RADIUS Accounting Serv er Attributes The following tabl e lists the standard a ttributes supp orted for RADIU S accounting serv ers.
RADIUS Servers Managing Authentication Servers page 20-14 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 The following table lists the VSAs supported for RADIUS accounting servers. Th e attributes in the radius.ini file may be modifi ed if ne cessary.
Managing Authentication Servers LDAP Servers OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 20-15 LDAP Ser vers Lightweight Direct ory Access Protocol (LDAP) is a st an dard directory server protocol. The LDAP client in the switch is based on several RFCs: 179 8, 2247, 2251, 2252, 2253, 2254, 2255, and 22 56.
LDAP Servers Managing Au thentication Servers page 20-16 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 LDAP servers are a lso able to im port and expo rt di rectory dat abases using LDIF (LDAP Data Interchange Format).
Managing Authentication Servers LDAP Servers OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 20-17 uid: yname ou: people description: <list of option al attributes> . . . Directory Entries Directory entries are used to store d ata in directory servers.
LDAP Servers Managing Au thentication Servers page 20-18 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Directory Searches DNs are always the starting poi nt for searches un less indicate d otherwise in the directory schema.
Managing Authentication Servers LDAP Servers OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 20-19 Modified attribute values ar e replaced with other giv en values by su bmitting repla ce requests to the se rver, which then translates an d pe rforms the requests.
LDAP Servers Managing Au thentication Servers page 20-20 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Password Policies an d Directory Ser vers Password policies applied to user accounts va ry slightly from o ne director y server to ano ther.
Managing Authentication Servers LDAP Servers OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 20-21 Director y Ser ver Schema for LDAP Authentication Object classes and attribute s .
LDAP Servers Managing Au thentication Servers page 20-22 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 For more information about configur ing users on the switch, see t he Switch Security chapter of the OmniSwitch 6600 Family Switch Ma nagement Guide .
Managing Authentication Servers LDAP Servers OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 20-23 • Switch VLAN number cli ent joins in mu ltiple authorit y mode (0=single authority; 2=mu ltiple author- ity); variabl e-length d igits.
LDAP Servers Managing Au thentication Servers page 20-24 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Dynamic Logging Dynamic loggin g may be performed by an LDAP-e nabled directory .
Managing Authentication Servers LDAP Servers OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 20-25 For exampl e: “ASA 0 : CONSOLE IP 65.97.233.108 Jones” Configuring the LDAP Authentication Client Use the aaa ldap-server command to configure LD AP authenticati on parameters on the switch.
LDAP Servers Managing Au thentication Servers page 20-26 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Note. The distingu ished name must be di fferent from the searchbase name.
Managing Authentication Servers Verifying the Authentication Server Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 20-27 V erifying the Authentication Ser ver Config.
Verifying the Authentication Server Configuration Managing Authentication Servers page 20-28 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-1 21 Configuring Authenticated VLANs Authenticated VLANs control user access to network resources based on VLAN assignmen t and a user log-in process; the process is someti mes called user authenticat ion or Layer 2 Authe ntication.
Authenticated Network Overview Co nfiguring Authenticated VLANs page 21-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Authenticated Network Over view An authenticat ed network invo lves several comp onents as show n in this illust ration.
Configuring Authenticated VLANs A uthenticated Network Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-3 • Web browser client . Any standard Web browser may be used (Netscape or Internet Explorer). An IP address is required prio r to authenticatio n.
AVLAN Configuration Overview Configuring Authenticated VLANs page 21-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 A VLAN Configuration Over view Configuring authent icated VLANs requires several majo r steps. The steps are ou tlined here and descri bed throughout th is chapter.
Configuring Authenticated VLANs AVLAN Configuration Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-5 Sample A VLAN Configuration 1 Enable at lea st one authent icated VLAN: -> vlan 2 authentication enable Note that this command does not create a VLAN; th e VLAN must already be created.
AVLAN Configuration Overview Configuring Authenticated VLANs page 21-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 6 Enable authe ntication by specifying the authentication mo de (single mode o r multiple mod e) and the server. Use the R ADIUS or LDAP serv er name(s) co nfigured in step 5.
Configuring Authenticated VLANs Setting Up Authentication Clients OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-7 Setting Up Authentication Clients The following sec tions describe the Telnet aut hentication c lient, Web bro wser authenticat ion client , and Alcatel’s proprietary AV-Client.
Setting Up Authentication Clients Configuring Authenticated VLANs page 21-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 with one authenticated VLAN. The addres s may be a ssigned dynamically if a DHCP server is located in the netwo rk.
Configuring Authenticated VLANs Setting Up Authentication Clients OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-9 Installing Files for Mac OS 9.x Clients 1 In the browser URL command line, enter the au thentication DNS name (con figured through the aaa avlan dns command).
Setting Up Authentication Clients Configuring Authenticated VLANs page 21-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 To set root access: 1 Open the NetInfo from t he HardDisk/Applica tion/Utilities fol der. 2 Select Domain > Security > Authentic ate.
Configuring Authenticated VLANs Setting Up Authentication Clients OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-11 SSL for W eb Browser Clients A Secure Socket Layer (SSL) is used to authent icate Web browser clie nts.
Setting Up Authentication Clients Configuring Authenticated VLANs page 21-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Installing the A V -Client The AV-Client is a proprietary Windo ws-based applicat ion that i s installed on c lient end st ations.
Configuring Authenticated VLANs Setting Up Authentication Clients OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-13 Windows 95 Install the 32-bit DLC pr otocol program and the update patch from the Microsoft FTP site (ftp.microsoft.
Setting Up Authentication Clients Configuring Authenticated VLANs page 21-14 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 3 We recommend that you foll ow the instructions on the screen regarding closing all Wi ndows programs before proceedin g with the instal lation.
Configuring Authenticated VLANs Setting Up Authentication Clients OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-15 4 From this window you may install the cl ient at the de fault destinat ion folder shown o n the screen or you may click the Brow se button to select a different directory.
Setting Up Authentication Clients Configuring Authenticated VLANs page 21-16 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Windows 95 and Windows 98 1 Download the AV-Cl ient from the Alc atel website on to the Windows deskt op. 2 Double-click the AV-Client icon .
Configuring Authenticated VLANs Setting Up Authentication Clients OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-17 4 From this window you may install the cl ient at the de fault destinat ion folder shown o n the screen or you may click the Brow se button to select a different directory.
Setting Up Authentication Clients Configuring Authenticated VLANs page 21-18 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Setting the A V -Client as Primar y Network Login Windows 95 and Windows 98 If your operating system is Windo ws 95 or Windows 98, yo u must configure the AV-C lient as the primary network logi n.
Configuring Authenticated VLANs Setting Up Authentication Clients OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-19 Selecting a Dialog Mode The AV-Client has two dialo g modes, basic and extended . In basic dia log mode, the clie nt prompts the user for a username and a password onl y.
Setting Up Authentication Clients Configuring Authenticated VLANs page 21-20 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Viewing A V -Client Components The configuration u tility includes a screen that lists each component, version and build date for the AV- Client.
Configuring Authenticated VLANs Setting Up Authentication Clients OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-21 Logging Into the Network Through an A V -Client Once the AV-Client softwa re has been loaded on a user’s PC workstat ion , an AV-Clien t icon will be created on the Windows deskto p in the task b ar.
Setting Up Authentication Clients Configuring Authenticated VLANs page 21-22 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Logging Off the A V - Client 1 To log off the AV -Client, point yo ur mouse to the A V-Client icon in your Windows syst em tray and execute a right-cl ick to select Logo ff.
Configuring Authenticated VLANs Setting Up Authentication Clients OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-23 Configuring the A V -Client for DHCP For an AV-Client , DHCP configuratio n is not re quired.
Setting Up Authentication Clients Configuring Authenticated VLANs page 21-24 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 1 To configure the DHCP p arameters, access the AV-Client configu ration utility and select the DHCP tab. The following screen di splays: 2 Click the box ne xt to “Enable DHCP Operations ”.
Configuring Authenticated VLANs Setting Up Authentication Clients OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-25 4 To apply the change, click the Apply button. Wh en you clic k the OK button, the screen will close and the change will take effect.
Configuring Authenticated VLANs Configuring Authenticated VLANs page 21-26 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring Authenticated VLANs At least one authenticat ed VLAN must be configured on the switch. For more informati on about VLANs in general, see Chapter 4, “Confi guring VLA Ns.
Configuring Authenticated VLANs Configuring Authenticated VLANs OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-27 Configuring Authentication IP Addresses Authentication c lients connect to an IP address on the switch for authen tication.
Configuring Authenticated Ports Configuring Authenticated VLANs page 21-28 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Por t Binding and Authenticated VLANs By default, au thenticated VLANs d o not support po rt binding rules.
Configuring Authenticated VLANs Setting Up a DNS Path OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-29 Setting Up a DNS Path A Domain Name Server (DNS) name may be configured so that Web browser clients may enter a URL on the browser co mmand line in stead of an au thentica tion IP address.
Setting Up the DHCP Server Configuring Authenticated VLANs page 21-30 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Before Authentication Normally, authentic ation clients c annot traffic in th e default VLAN, so authenticati on clients do not belong to any VLAN whe n they connect to the switch.
Configuring Authenticated VLANs Setting Up the DHCP Server OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-31 When this command is specified, the switch will act as a relay for aut hentication DHCP pack ets only; non- authentica tion DHCP pa ckets will not b e relayed.
Configuring the Server Authority Mo de Configuring Authenticated VLANs page 21-32 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring the Ser ver Authority Mode Authenticatio n servers for Layer 2 authentication are configured in one of two mod es: single authorit y or multiple authorit y.
Configuring Authenticated VLANs Configuring the Server Authority Mode OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-33 To configure au thentication in single mode, use the aaa authentication vlan command with the single-mode keyword and name(s) of the relevant server an d any backups.
Configuring the Server Authority Mo de Configuring Authenticated VLANs page 21-34 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring Multiple Mode Multiple autho rity mode assoc iates different serve rs with particu lar VLANs.
Configuring Authenticated VLANs Specifying Accounting Servers OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 21-35 To configure au thentication in multiple mode, use the aaa authentication vlan command with the multiple-mode keyword, the relevant VLAN ID, an d the names of the servers.
Verifying the AVLAN Configuration C onfiguring Au thenticated VLANs page 21-36 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 V erifying the A VLAN Configuration To verify the authenticated VLAN configuration, use the following show commands: For more information about these commands, see the OmniSwitch CLI Reference Guide .
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 22-1 22 Configuring 802.1X Physical devices attached to a LAN port on the swit ch throu gh a point- to-point LAN c onnection may be authentica ted through the switch thro ugh port-base d network acc ess control.
802.1X Specifications Conf iguring 802.1X page 22-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 802.1X Specifications 802.1X Defaults The following table lists the defaults for 802 .1X port co nfiguration con figuration th rough the 802.
Configuring 802.1X Quick Steps for Configuring 802 .1X OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 22-3 Quick Steps for Configuring 802.1X 1 Configure the port as a mobi le port and an 802.1X port usin g the following vlan port commands: -> vlan port mobile 3/1 -> vlan port 3/1 802.
Quick Steps for Configuring 802.1X Configuring 802.1X page 22-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Optional. To display the number of 802.
Configuring 802.1X 802.1X Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 22-5 802.1X Over view The 802.1X standard defines port-based network access controls, and provides th e structure for authe nti- cating physi cal devices atta ched to a LAN.
802.1X Overview Configuring 802.1X page 22-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 • If the authentication server doe s not return a VLAN ID, then the supplicant is classified according t o any device cla ssification policies tha t are configured for the port.
Configuring 802.1X 802.1X Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 22-7 802.1X ports may also be init ialized if there a pro blem on the port. Init ializing a port dro ps connectivity to the port and requ ires the port to be re-authenticated.
Using Access Guardian Po licies Configuring 802.1X page 22-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Using Access Guardian Policies In addition to the authent ication and VLAN classi fica tion of 802.1x clients (supplicants), the Access Guardian exten ds this type of functional ity to no n-802.
Configuring 802.1X Using Access Guardian Poli cies OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 22-9 The order in which policies are applied to cl ient traf fic i s determined by the order in which t he policy wa s configured.
Setting Up Port-Based Network A ccess Control Configu ring 802.1X page 22-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Setting Up Por t-Based Network Access Contro l For port-based network access cont rol, 802.1X must be enabl ed for the switch and the switch must know which servers to use for authent icating 802.
Configuring 802.1X Setting Up Port-Based Network Access Control OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 22-11 Configuring 802.1X Por t Parameters By default, when 802.1X is enabled o n a port, the po rt is configured for bidir ectional cont rol, automa tic authorization, a nd re-authentica tion.
Setting Up Port-Based Network A ccess Control Configu ring 802.1X page 22-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Note. The authentication server timeout ma y also be configu.
Configuring 802.1X Setting Up Port-Based Network Access Control OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 22-13 Initializing an 802.1X Por t An 802.1X port may be reinitializ ed. This is useful i f there is a pro blem on the port.
Configuring Access Guardian Policies Configuring 802.1X page 22-14 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring Access Guardian Policies The Access Guardian provides fu nctionality that allows the confi guration of 802.1x device classification policies for supplicants (8 02.
Configuring 802.1X Configuring Access Guardian Policies OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 22-15 Configuring Supplicant Policies Supplicant policies are used to cl assify 802. 1x devices c onnected to 802 .1x-enabled switc h ports when 802.
Configuring Access Guardian Policies Configuring 802.1X page 22-16 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring Non-supplicant Policies Non-supplicant policies are used to classify non-802.1x devices connected to 802.1x-enabl ed switch ports.
Configuring 802.1X Configuring Access Guardian Policies OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 22-17 Note that this type of policy d oes not use 802.
Configuring Access Guardian Policies Configuring 802.1X page 22-18 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 802.1x 2/10 non-sup plicant policy aut hentication pass vlan 10 blo ck.
Configuring 802.1X Verifying the 802.1X Port Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 22-19 V erifying the 802.
Verifying the 802.1X Port Configuration Configuring 802.1X page 22-20 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 23-1 23 Managing Policy Ser vers Quality of Service (QoS) policies that are configur ed through Alcatel’s PolicyView networ k management application are stored on a Lightweight Director y Access Protoco l (LDAP) server.
Policy Server Specification s Managing Policy Servers page 23-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Policy Ser ver Specifications The following ta bles lists import ant inf.
Managing Policy Servers Policy Server Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 23-3 Policy Server Over view The Lightweigh t Directory Acce ss Protocol (LDA P) is a stand ard directory server prot ocol. The LDAP policy server client in the sw itch is based on RFC 2251.
Modifying Policy Servers Managing Policy Ser vers page 23-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Modifying Policy Ser vers Policy servers are automatically conf igured when the server is installe d; however, policy server parame- ters may be modified i f necessary.
Managing Policy Servers Modifying Policy Servers OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 23-5 Modifying the Por t Number To modify the port, enter the policy server command with the port keyword an d the releva nt port number.
Modifying Policy Servers Managing Policy Ser vers page 23-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Configuring a Secure Socket Layer for a Policy Ser ver A Secure Socket Layer (SSL) may be configured be tween the polic y server an d the swit ch.
Managing Policy Servers Verifying the Policy Server Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 23-7 Interaction With CLI Policies Policies configured via PolicyView can only be modi fied through PolicyView. Th ey cannot be modified through the CLI.
Verifying the Policy Server Conf iguration Managing Policy Servers page 23-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-1 24 Configuring QoS Alcatel’s QoS software prov ides a way to manipulate flows coming th rough the switch based on user- configur ed policie s.
QoS Specifications Configuring QoS page 24-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 QoS Specifications Maximum number of po licy rules 128 Limits for Layer 3 rules with particular action s: ACL (Filter rules) Priority rules Bandwidth/ T o S rules 802.
Configuring QoS QoS General Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-3 QoS General Over view Quality of Service (QoS) refers to transmission quality and available service that is measured an d some- times guaranteed in advance for a particular ty pe of traffic in a network.
QoS Policy Overview Configuring QoS page 24-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 QoS Policy Over view A policy (or a policy rule ) is made up of a condition and an actio n. The condition specifi es pa rameters that the switch will examine in inc oming flows, such as destination address or Type of Serv ice (ToS) bits.
Configuring QoS Interaction With Other Features OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-5 It is possible to configure a vali d QoS rule that is ac tive on the swit ch, however the swit ch is not able to enforce the rule b ecause some ot her switch function (for example, rout ing) is disa bled.
Condition Combinations Configuring QoS page 24-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Condition Combinations The CLI prevents you from configuring in valid condition combinations that are never allowed; ho wever, it does allow you to create combinat ions that are supporte d in some scenario.
Configuring QoS Condition /Action Combinations OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-7 Condition/Action Combinations Conditions and acti ons are combined in policy rules.
Condition/Action Combinations Configuring QoS page 24-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 destination IP address or network group destination TCP/UDP port IP protocol 802.
Configuring QoS QoS Defaults OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-9 QoS Defaults The following ta bles list the defa ults for global QoS p a rameters, individual port settin gs, policy rules, and default policy rules.
QoS Defaults Configuring QoS page 24-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 QoS Por t Defaults Use the qos port reset command to reset port settings to the defaults.
Configuring QoS QoS Defaults OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-11 Policy Action Defaults The following are defaults for t he poli cy action command: Note that in the current software release, the deny and dr op options produce the same effect that is, the traffic is si lently drop ped.
QoS Configuration Overview Configuring QoS page 24-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 QoS Configuration Over view QoS configuratio n involves the following general steps: 1 Configuring Global Par ameters .
Configuring QoS Configurin g Global QoS Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-13 Configuring Global QoS Parameters This section describes the glob al QoS co.
Configuring Global QoS Parameters Configuring QoS page 24-14 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Using the QoS Log The QoS software in the switch creates its own log for QoS-spe cific eve nts. You may modi fy the number of lines in the log or change the level of detail given in the log.
Configuring QoS Configurin g Global QoS Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-15 Note. If you change the number of log l ines, the QoS log may be comp letely cleare d. To chang e the log lines without c learing the log, set the lo g lines in the boot.
Configuring Global QoS Parameters Configuring QoS page 24-16 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Displaying the QoS Log To view the QoS log, use the show qos log command.
Configuring QoS Configurin g Global QoS Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-17 To change the flow timeout, enter the qos flow timeout com i mand with the desired number of seconds.
Configuring Global QoS Parameters Configuring QoS page 24-18 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Classifying Bridged T raffic as Layer 3 In some network configurati ons you may want to force the switch to cla ssify bridged traffic as routed (Layer 3) traffic.
Configuring QoS Configurin g Global QoS Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-19 V erifying Global Settings To display information abo ut the glob al config.
QoS Ports and Queues Configuring QoS page 24-20 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 QoS Por ts and Queues Queue para meters may be mo dified on a port basis. Fo ur default queues are creat ed for each port on t he switch at start up.
Configuring QoS QoS Ports and Queues OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-21 To configure th e global settin g on the switch , use the qos trust ports command. For exampl e: -> qos trust ports To configure indivi dual ports as truste d, use the qos port trusted command with the desired sl ot/port number.
Creating Policies Configuring QoS page 24-22 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Creating Policies This section describ es how to create polic ies in general. Fo r information about configuri ng specific types of policies, see “Policy Applications” on pa ge 24-49 .
Configuring QoS Creating Policies OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-23 4 Use the qos apply command to apply the po licy to the configuration. For example: -> qos apply Note. ( Optional ) To verify that the rule has been configured, use the show policy rule command.
Creating Policies Configuring QoS page 24-24 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Creating Policy Conditions This section describ es how to create po licy condition s in general. C reating policy co nditions for partic ular types of network sit uations is described late r in this chapter.
Configuring QoS Creating Policies OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-25 Note. You cannot remove al l parameters from a polic y cond ition. A condition must be configured with at least one parameter. Deleting Policy Conditions To remove a policy condition, use the no form of the command.
Creating Policies Configuring QoS page 24-26 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Note. If you combine priority with 802.1p , dscp , tos , or map , in an action, the priority value is use d to prioritiz e the flow.
Configuring QoS Creating Policies OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-27 In addition, a policy rule may be admi nistratively disabled or re-enabled using the policy rule command. By default rules are enab led. Fo r a list of rule defaults, see “Policy Rule Defaults” on page 24-10 .
Creating Policies Configuring QoS page 24-28 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Layer 3 Rules With Compatible Ac tions More than one rule may have the same co ndition. Fo r example, two La yer 3 rules may h ave the same IP address con dition but differen t actions.
Configuring QoS Creating Policies OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-29 Saving Rules The save option marks the policy rule so that the rule will be captured in an A.
Creating Policies Configuring QoS page 24-30 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 V erifying Policy Configuration To view information ab out policy rules, conditions, a nd ac.
Configuring QoS Creating Policies OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-31 In this example, the rule my_rule does not displa y because it is inactive . Rules are i nactive if they are administratively di sabled through the policy rule command, or if the rule cannot be enforced by the current h ardware.
Creating Policies Configuring QoS page 24-32 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 T esting Conditions Before applying poli cies to the configuration thro ugh the qos apply command, you may want to see how the policies will be used to classify traffic.
Configuring QoS Creating Policies OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-33 To test a theo retical con dition again st the set of applied policies, enter the command with the applied keyword.
Using Condition Groups in Policies Configuring QoS page 24-34 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Using Condition Gr oups in Policies Condition groups ar e made up of multiple IP addre sses, MAC addresses, servic es, or ports to which you want to apply the same action or poli cy rule.
Configuring QoS Using Condition Groups in Policies OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-35 3 Attach the condi tion to a polic y rule. (For more i nformation about co nfiguring rule s, see “Creati ng Policy Rules” on page 24 -26 .
Using Condition Groups in Policies Configuring QoS page 24-36 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 To remove addresses from a network group, use no and the rel evant address(es) . For example: -> policy network group netgroup3 no 173.
Configuring QoS Using Condition Groups in Policies OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-37 In this example, a policy service calle d telnet1 is created with the TCP protocol number ( 6 ) and the well- known Telnet destination por t number ( 23 ).
Using Condition Groups in Policies Configuring QoS page 24-38 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 This command conf igures a conditi on called c6 with service grou p serv_group . All of the service s speci- fied in the service group will be included i n the condit ion.
Configuring QoS Using Condition Groups in Policies OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-39 Note. MAC group configuration is not acti ve until the qos apply command is entered.
Using Condition Groups in Policies Configuring QoS page 24-40 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 This command specifies tha t port 2/1 will be d eleted from the techpubs port group at the next qos apply . To delete a port group, use the no form of the policy port gro up command with the relev ant port group name.
Configuring QoS Using Condition Groups in Policies OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-41 -> policy action MaxBw maximum ban dwidth 10k -> policy rule PortRule condition Ports action MaxBw In this example, if both ports 1 and 2 are active p orts, 10000 bps is distrib uted over the two p orts.
Using Condition Groups in Policies Configuring QoS page 24-42 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 V erifying Condition Gr oup Configuration To display information abo ut con.
Configuring QoS Using Map Groups OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-43 Using Map Gr oups Map groups are u sed to map 802. 1p, ToS, or DSCP va lues to different values. On the Om niSwitch 6600 , the followi ng mapping sc enarios are su pported: • 802.
Using Map Groups Configuring QoS page 24-44 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 How Map Groups W ork When mapping from 802.1p to 802.1p, the acti on will result in remapping the sp ecified values. Any values that are not specified in th e map gr oup are preser ved.
Configuring QoS Using Map Groups OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-45 To delete a map group, use the no form of the policy map group command.
Applying the Configuration Configuring QoS page 24-46 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Applying the Configuration Configuratio n for policy rules and many global QoS pa rameters must sp ecifically be ap plied to the config- uration with the qos apply command.
Configuring QoS Applying the Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-47 Deleting the Pending Configuration Policy settings that have been configured but not applied thro ugh the qos apply command may be returned to the la st applied se ttings through the qos revert command.
Applying the Configuration Configuring QoS page 24-48 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Interaction W ith LDAP Policies The qos apply , qos revert , and qos flush commands do not af fect policies created thro ugh the Policy- View application .
Configuring QoS Policy Applications OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-49 Policy Applications Policies are used to classify incoming flows and treat the relevant outgoing flows. There are many ways to classify the traffic and many ways to apply QoS parameters to the traffic.
Policy Applications Configuring QoS page 24-50 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Note. If multiple addresses, services, or po rts should be gi ven the same prio rity, use a policy condi tion group to specify the group and associat e the group wit h the condit ion.
Configuring QoS Policy Applications OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 24-51 -> policy condition ip_traffic2 so urce ip 10.
Policy Applications Configuring QoS page 24-52 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 -> policy condition my_condition s ource ip 10.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 25-1 25 Configuring ACLs Access Control L ists (ACLs) are Quality o f Service (Qo S) policies used to control wh ether or not packets are allo wed or denied at the swit ch or router interf ace.
ACL Specifications Configuring ACLs page 25-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 ACL Specifications These specifications are t he same as those for QoS in general: ACL Def.
Configuring ACLs Quick Steps for Creating ACLs OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 25-3 Quick Steps for Creating ACLs 1 Set the global disposi tion for bridged or rout ed traffic. By default, all flow s that do match any pol icies are allowed on t he switch.
ACL Overview Configuring ACLs page 25-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 ACL Over view ACLs provide mo derate security bet ween networks. The following il lustration sho ws how ACLs may be used to filter sub network traffic throug h a private net work, func tioning like an internal fi rewall for LANs.
Configuring ACLs ACL Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 25-5 Rule Precedence The switch attempts to classify fl ows c oming into the switc h according to pre cedence. For Lay er 2 flows, the rule wi th the highe st precedence will be appli ed to the flow .
ACL Overview Configuring ACLs page 25-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Example: Layer 3 Rules With Compatible Actions More than one rule may have the same co ndition. Fo r example, two La yer 3 rules may h ave the same IP address con dition but differen t actions.
Configuring ACLs ACL Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 25-7 Interaction With Other Features • IP Routing —IP routing must b e enabled on th e switch for Layer 3 ACLs. See Chapter 14, “Configur- ing IP,” for more information about setting up ro uting.
ACL Configuration Overview Configuring ACLs page 25-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 ACL Configuration Over view This section describes the QoS CLI commands used spec ifically to configure ACLs.
Configuring ACLs Setting the Global Disposition OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 25-9 Important. If you set the glob al bridged d isposition (u sing the q os defaul .
Creating Condition Groups For ACLs Configuring ACLs page 25-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Creating Condition Gr oups For ACLs Condition grou ps for ACLs are ma de up of multipl e IP addresses, MAC addresses, services, or IP ports to which you wan t to apply the sa me disposition .
Configuring ACLs Configuring ACLs OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 25-11 For exampl e: -> policy port group pgroup1 3/1-2 4/3 5/4 -> policy condition c2 source port group pgroup1 In this example, a Layer 2 condition ( c2 ) specifies that traffic matche s the ports incl uded of the pgroup1 port group.
Configuring ACLs Configuring ACLs page 25-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 rule7 will take precedence over the other rules. (For more information about precedence, se e “Rule Prece- dence” on page 25-5 .) The action config ured for the rule, a1 , allows traffic from 10.
Configuring ACLs Configuring ACLs OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 25-13 Layer 2 ACL: Example 1 In this example, the default bridge d disposition i s accept (the default).
Configuring ACLs Configuring ACLs page 25-14 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Layer 3 ACLs The QoS software in the switch fi lters routed traffic at Layer 3. For Lay er 3 filters, ty pically IP routing must be enabled; however, the switc h may be configured to filt er Layer 3 headers in bridged traffic.
Configuring ACLs Configuring ACLs OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 25-15 Layer 3 ACL: Example 2 This example uses condition gro ups to combine mult iple IP addre sses in a single co ndition. The default disposition is set to deny .
Configuring ACLs Configuring ACLs page 25-16 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 To filter multicast cli ents, specify the mul ticast IP ad dre ss, which is the add ress of the multic ast group or stream, and sp ecify the cli ent IP address, VL AN, MAC address, or slot/port .
Configuring ACLs Using ACL Security Features OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 25-17 Using ACL Security Features The following ad ditional AC L features are available.
Using ACL Security Features Configuring ACLs page 25-18 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring a DisablePor ts ACL An additional met hod for dealing with spoofed IP traffic is t o create a Disabl ePorts ACL that will adminis- tratively disab le ports that rece ive this type of traffic.
Configuring ACLs Using ACL Security Features OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 25-19 5 Create a rule that denies all source IP addres ses rece iv ed on the port group defi ned in Step 1 a nd spec- ify a precedence for t his rule.
Using ACL Security Features Configuring ACLs page 25-20 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 2 Add the services c reated in St ep 1 to a se rvice group ca lled DropServices using the policy service group command.
Configuring ACLs Using ACL Security Features OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 25-21 Configuring ICMP Dr op Rules Combining a L ayer 2 condi tion for sour ce VLAN with a Layer 3 condition fo r IP protocol is supported.
Verifying the ACL Configuration Configuring ACLs page 25-22 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 V erifying the ACL Configuration To display information abo ut ACLs, use the same show commands that are used for displaying any QoS policies.
Configuring ACLs Verifying the ACL Configuration OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 25-23 To display only policy rules th at are active (enabled) on the switch, use th e show active policy rule command.
ACL Application Exa mple Configuring ACLs page 25-24 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 ACL Application Example In this applica tion for IP filt ering, a policy is created to deny Telnet traffic from the outside world to an engineering group in a private network.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 26-1 26 Configuring IP Multicast Switching IP Multicast Switc hing is a on e-to-many commu nication tech nique employ ed by emerging a pplications such as video distribution , news feeds, con ferencing, net casting, and resour ce discovery (OSPF, RIP2, BOOTP).
IPMS Specifications Configuring IP Multicast Switching page 26-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 IPMS Specifications The table below lists specifications for Alcatel’s IPMS software. IPMS Default V alues The table below lists default valu es for Alcatel’ s IPMS software.
Configuring IP Multicast Switching IPMS Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 26-3 IPMS Over view A multicast group is defined by a multi cast group address, wh ich is a Class D IP address in the range 224.0.0.0 to 239.
IPMS Overview Configuring IP Multicast Switching page 26-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Reserved Multicast Addresses The Internet Assigned Numbers Au thority (IANA) created the range fo r multicast addr esses, which is 224.
Configuring IP Multicast Switching Configuring IPMS on a Switch OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 26-5 Configuring IPMS on a Switch This section describes how to use .
Configuring IPMS on a Switch Configuring IP Multicast Switching page 26-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Configuring a Static Neighbor You can configure a port as an I.
Configuring IP Multicast Switching Configuring IPMS on a Switch OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 26-7 Removing a Static Querier To reset the port so th at it is no l.
Modifying IPMS Parameters Configuring IP Multicast Switching page 26-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Modifying IPMS Parameters The table in “IPMS Default Values” on page 26-2 lists defa ult values for IPMS parameters.
Configuring IP Multicast Switch ing Modifying IPMS Parameters OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 26-9 Configuring the Membership Timeout You can modify the IPMS membership timeout from 0 to 42949672 95 seconds by entering ip multicast membership-timeout followed by the new value.
Modifying IPMS Parameters Configuring IP Multicast Switching page 26-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Restoring the Querier Timeout To restore the neighbor querier to its default (i.
Configuring IP Multicast Switching IPMS Application Example OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 26-11 IPMS Application Example The figure below shows a samp le network with the sw itch sending multicast video.
IPMS Application Example C onfiguring IP Multicast Switching page 26-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 5 Modify the leave timeout from its default value of 10 seconds t.
Configuring IP Multicast Switching Displaying IPMS Configurations and Statistics OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 26-13 Displaying IPMS Configurations and Statistics Alcatel’s IP Multicast Switching (IPMS ) show commands provide t ools to moni tor IPMS traf fic and settings and to t roubleshoot problems.
Displaying IPMS Configurations and Statis tics Configuring IP Multicast Switching page 26-14 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-1 27 Diagnosing Switch Pr oblems Several tools are available for diagn osing problems that may occur with the switch.
In This Chapter Diagnosing Switch Problems page 27-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 • Deleting a Po rt Monitoring Session —see “Deleting a Port Monito ring Sessio n” on page 27-21 . • Pausing a Port Mo nitoring Session —see “Pausing a Port Monitoring Session” on page 27-21 .
Diagnosing Switch Problems Port Mirroring Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-3 Por t Mirroring Overview The following sectio ns detail the specificatio ns, defaults, a nd quick set u p steps for the po rt mirroring feature.
Port Mirroring Overview Diagnosing Switch Problems page 27-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Por t Mirroring Defaults The following table shows port mir roring default values.
Diagnosing Switch Problems Port Mirroring Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-5 Quick Steps for Configuring Port Mirroring 1 Create a port mirrori ng session .
Port Monitoring Overview Diagnosing Switch Problems page 27-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Por t Monitoring Over view The following sec tions detail the specifica tions, defa ults, and quick se t up steps for the port mirroring feature.
Diagnosing Switch Problems Port Monitoring Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-7 Quick Steps for Configuring Port Monitoring 1 To create a port monitori ng .
Remote Monitoring (RMON) Overview Diagnosing Switch Problems page 27-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Remote Monitoring (RMON) Over view The following sec tions detail th e specifica tions, defaul ts, and quick set u p steps for the RMON feat ure.
Diagnosing Switch Problems Remote Monitoring (RMON) Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-9 RMON Probe Defaults The following ta ble shows Remote Network Moni toring defaul t values.
Switch Health Overview Di agnosing Switch Problems page 27-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Switch Health Over view The following sec tions detail the specifica tions, defa ults, and quick se t up steps for the switch health feature.
Diagnosing Switch Problems Switch Health Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-11 Switch Health Defaults The following tabl e shows Switch Health d efault values.
Port Mirroring Diagnosing Switch Problems page 27-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Por t Mirroring You can set u p port mirroring for any pair of Et hernet port s within the same switch chassi s. Ethernet port s supporting port mirro ring include 10BaseT/100BaseTX (RJ-45) and 1000BaseLX (LC) M iniGBIC connectors.
Diagnosing Switch Problems Port Mirroring OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-13 How Por t Mirroring W orks When a frame is received on a mirrored port, it is copied and sent to the mi rroring port.
Port Mirroring Diagnosing Switch Problems page 27-14 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Using Por t Mirr oring with External RMON Pr obes Port mirroring is a help ful monitoring tool when used in co njunction with an external RMON probe.
Diagnosing Switch Problems Port Mirroring OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-15 Creating a Mirroring Session Before port mirroring can be used, it is nece ssary to create a port mirro ring session.
Port Mirroring Diagnosing Switch Problems page 27-16 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 This command line specifies mir roring session 6, with the source (m irrored) port located in slot 2/po rt 3, and the destination (mi rroring) port located in slot 2/port 4.
Diagnosing Switch Problems Port Mirroring OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-17 In this example the command specifies port mirroring sessi on 6, with the mirro red (active) port locat ed in slot 2/port 3, and th e mirroring port l ocated in slot 6/port 4.
Port Mirroring Diagnosing Switch Problems page 27-18 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Enabling or Disabling a Por t Mirroring Session (Shorthand) Once a port mirroring se.
Diagnosing Switch Problems Port Mirroring OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-19 Deleting A Mirr oring Session The no form of the port mirroring command can be used to delete a previously created mirro ring session configuratio n between a mi rrored port and a mirroring po rt.
Port Monitoring Diagnosin g Switch Problems page 27-20 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Por t Monitoring An essential tool of the network engineer is a net work packet capture device.
Diagnosing Switch Problems Port Monitoring OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-21 In addition, you can also sp ecify optional parameters sh own in the t able below. These parameters mu st be entered af ter the slot and port numbe r.
Port Monitoring Diagnosin g Switch Problems page 27-22 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring Por t Monitoring Session Persistence By default, a p ort monitoring sessi on will neve r be disabled .
Diagnosing Switch Problems Port Monitoring OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-23 For example, to c onfigure port mo nitoring session 6 o n port 2/3 with a data fil .
Port Monitoring Diagnosin g Switch Problems page 27-24 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Displaying Por t Monitoring Status and Data A summary of the sho w commands used f.
Diagnosing Switch Problems Remote Monitoring (RMON) OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-25 Remote Monitoring (RMON) Remote Network Monit oring (RMON) is an SNMP protocol used to manage networks remo tely.
Remote Monitoring (RMON) Diagnosing Switch Pro blems page 27-26 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 RMON probes can be enabled or disabled via CLI commands. Configuratio n of Alarm threshold valu es for RMON traps is a function reserv ed for RMON-monitoring NMS stations.
Diagnosing Switch Problems Remote Monitoring (RMON) OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-27 Enabling or Disabling RMON Pr obes To enable or disable an indi vidual RMON probe, enter the rmon probes CLI command.
Remote Monitoring (RMON) Diagnosing Switch Pro blems page 27-28 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Displaying RMON T ables Two separate commands can be used to retrieve and vi ew Remote Monitoring data: show rmon probes and show rmon events .
Diagnosing Switch Problems Remote Monitoring (RMON) OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-29 Displaying Statistics for a Particular RMON Probe To view statistics for a.
Remote Monitoring (RMON) Diagnosing Switch Pro blems page 27-30 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Sample Display fo r Histor y Probe The display shown here identifies RMON Pro be 10325’s Owner descri ption and interfac e location (Analyzer-p:12 8.
Diagnosing Switch Problems Remote Monitoring (RMON) OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-31 Displaying a List of RMON Events RMON Events are actions that occur based on Alarm co nditions detect ed by an RMON probe.
Monitoring Switch Health Diagnosing Switch Problems page 27-32 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Monitoring Switch Health To monitor resource availability, the NMS (Netwo rk Manageme nt System) nee ds to collect si gnificant amounts of data from each switch.
Diagnosing Switch Problems Monitoring Switch Health OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-33 The following sections incl ude a discussion of CLI command s that can be used to conf igure resource parameters and monito r or reset statistics for switch resources.
Monitoring Switch Health Diagnosing Switch Problems page 27-34 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring Resource and T emperature Thresholds Health Monito ring softwa.
Diagnosing Switch Problems Monitoring Switch Health OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-35 Displaying Health Threshold Limits The show health threshold command is us.
Monitoring Switch Health Diagnosing Switch Problems page 27-36 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Configuring Sampling Intervals The sampling interval is the period of time be tween polls of the switch’s consumable reso urces to moni- tor performance vis-a-vis previ o usly specified thresholds.
Diagnosing Switch Problems Monitoring Switch Health OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 27-37 V iewing Health Statistics for the Switch The show health command can be used t o display health statistics for the switch.
Monitoring Switch Health Diagnosing Switch Problems page 27-38 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 V iewing Health Statistics for a Specific Inter face To view health statistics fo r slot 4/port 3, ente r the show health command, followed by the approp riate slot and port numbers.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 28-1 28 Using Switch Logging Switch logging is a n event logg ing utility t hat is useful in ma intaining an d servicing th e switch. Switch logging uses a formatted string mech anism to either reco rd or discard ev ent data from switc h applications.
Switch Logging Specifications Using Switch Logging page 28-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Switch Logging Specifications Functionality Sup ported High-level event logging mechanism that for- wards requests from applications to enabled logging devic es.
Using Switch Logging Switch Logging Defaults OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 28-3 Switch Logging Defaults The following ta ble shows switch l ogging default v alues.
Quick Steps for Configuring Switc h Logging Using Switch Logging page 28-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Quick Steps for Configuring Switch Logging 1 Enable switch lo gging by usi ng the following c ommand: -> swlog 2 Specify the ID of the appl ication to be logged al ong with the logging se verity le vel.
Using Switch Logging Switch Logging Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 28-5 Switch Logging Over view Switch logging uses a format ted string me chanism to proc ess log requests fro m switch application s.
Switch Logging Commands Overview Using Switch Logging page 28-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Switch Logging Commands Over view This section describ es the switch lo .
Using Switch Logging Switch Logging Commands Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 28-7 STP 11 APPID_SP ANNI NG TREE LINKAGG 12 APPID_LINKAGG REGA TION QOS 13 AP.
Switch Logging Commands Overview Using Switch Logging page 28-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 The level keywor d assigns the error-type severity level to the specified applica tion IDs. Values range from 2 (highest seve rity) to 9 (low est severity).
Using Switch Logging Switch Logging Commands Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 28-9 Removing the Severity Level To remove the switch l ogging severity l evel, enter the no swlog appid level command, including the application ID and severity-level values.
Switch Logging Commands Overview Using Switch Logging page 28-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Disabling an IP Address from Receiving Switch Logging Output To disable .
Using Switch Logging Switch Logging Commands Overview OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 28-11 Configuring the Switch Logging File Size By default, th e size of the switch logging file i s 128000 byt es. To configure the size of the switch loggin g file use the swlog output flash file- size command.
Switch Logging Commands Overview Using Switch Logging page 28-12 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006 Displaying Switch Logging Records The show log swlog command can produce.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 29-1 29 Monitoring Memor y Debug memory mo nitor commands ca n monitor memory allocation an d free memory (such as detect ion of invalid free addresses and maintena nce of size statis tics).
Memory Monitoring Specifications Monitoring Memory page 29-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Memor y Monitoring Specifications The following ta ble shows Memory Mo nito.
Monitoring Memory Quick Steps for Configuring Memory Monitoring OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 29-3 Quick Steps for Configuring Memor y Monitoring 1 Use the following com mands to enable Memory Mo nitoring. (Memory Monit oring is factory disabl ed by default.
Debug Memory Commands Overview Monitoring Memory page 29-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Debug Memor y Commands Over view The Debug Memory Commands prov ide monitoring of memory allocat ion and free memory.
Monitoring Memory Configuring Debug Memory Commands OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 29-5 Displaying the Memor y Monitor Log The debug memory monitor show log command displays memo ry monitoring lo g information.
Configuring Debug Memory Commands Monitoring Memory page 29-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Displaying the Memor y Monitor Global Statistics The debug memory monitor show log global command can display memory monito ring global statis- tics.
Monitoring Memory Configuring Debug Memory Commands OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 29-7 Displaying the Memor y Monitor T ask Statistics The debug memory monitor show log task command can disp lay memory monitoring task statistics.
Configuring Debug Memory Commands Monitoring Memory page 29-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Task Name Current Cumulative -------------+-------------+-------- --------.
Monitoring Memory Configuring Debug Memory Commands OmniSwitch 6600 Family Network Configurati on Guide April 2006 page 29-9 Displaying the Memor y Monitor Size Statistics The debug memory moni tor show log size command can display memory monitoring size st atistics.
Configuring Debug Memory Commands Monitoring Memory page 29-10 OmniSwitch 6600 Fam ily Network Configuration Guide April 2006.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 page A-1 A Software License and Copyright Statements This appendix co ntains Alcate l and third-pa rty software ven dor license and copyright st atements. Alcatel License Agreement ALCA TEL INTERNETWORKING, INC.
Alcatel License Agreement Software License and Copyright Statements page A-2 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 3. Confidentiality. AII considers the Licensed File s to contain valuable t rade secrets of AII, t he unautho- rized disclosure of which could cause irrepa rable harm to AII.
Software License and Copyright St atements Alcatel License Agreement OmniSwitch 6600 Family Network Configurati on Guide April 2006 page A-3 10. Governing Law. This License Agreement shall be constr ued and governed in accordance with the laws of the Sta te of Califo rnia.
Third Party Licenses and Notices Software License and Copyright Statements page A-4 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 Third Par ty Licenses and Notices The licenses and notices related only to su ch third party software are set forth below: A.
Software License and Copyright Statements Third Party Licenses and Notices OmniSwitch 6600 Family Network Configurati on Guide April 2006 page A-5 C. Linux Linux is wri tten and distrib uted under the GNU General Public License w hich means th at its source co de is freely- distrib uted and ava ilable to the general public.
Third Party Licenses and Notices Software License and Copyright Statements page A-6 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 verbatim or with mod ifications and/or t ranslated into another language. (Hereinafter , translation is included wi thout limitati on in the term “mo difi cation”.
Software License and Copyright Statements Third Party Licenses and Notices OmniSwitch 6600 Family Network Configurati on Guide April 2006 page A-7 b Accompany it wi th a written of fer, valid for at l.
Third Party Licenses and Notices Software License and Copyright Statements page A-8 OmniSwitch 6600 Fam ily Network Configur ation Guide April 2006 consistent application o f that syste m; it is up to th e author/do nor to decide i f he or she is willing to dist rib- ute software throug h any other system an d a licensee cannot impose t hat choice.
Software License and Copyright Statements Third Party Licenses and Notices OmniSwitch 6600 Family Network Configurati on Guide April 2006 page A-9 Appendix: How to Apply These T erms to Y our New Prog.
Third Party Licenses and Notices Software License and Copyright Statements page A-10 OmniSwitch 6600 Family Network Con figuration Guide April 2006 Material copyright Li nux Online Inc.
Software License and Copyright Statements Third Party Licenses and Notices OmniSwitch 6600 Family Network Configurati on Guide April 2006 page A-11 H. Apptitude, Inc. Provided with th is product is certai n network moni toring software (“Me terWorks/RMON”) licensed from Apptitude, Inc.
Third Party Licenses and Notices Software License and Copyright Statements page A-12 OmniSwitch 6600 Family Network Con figuration Guide April 2006 L. Wind River Systems, Inc. Provided with th is product is certain software (“ Run-Time Module”) licensed from Wind River Sy stems, Inc.
OmniSwitch 6600 Family Network Configurati on Guide April 2006 Index-1 Index Numerics 802.1p trusted ports 38-20 802.1Q 25-1 application examples 25-9 defaults 25-2 enabling tagging 25-5, 25-6 frame type 25-7 overview 25-3 specifications 25-2 trusted ports 38-5, 38-20 verify information about 25-11 802.
Index Index-2 O mniSwitch 6600 Family Network Configuration Guid e Apr il 2006 policies 38-49 policy map groups 38-43 Port Mapping 23-2 port mirroring 41-5 port monitoring 41-7 QoS 38-22, 38-49 RIP 30.
Index OmniSwitch 6600 Family Network Configurati on Guide April 2006 Index-3 dynamic link aggregation 27-3 ethernet port 15-3 IP 28-2, 29-2 IPMS 40-2 memory monitoring 43-2 mobile ports 21-2 policy se.
Index Index-4 O mniSwitch 6600 Family Network Configuration Guid e Apr il 2006 F Fast Spanning Tree 19-4 filtering lists see ACLs flow command 15-14 flow control 15-14, 15-23 flow control wait time 15.
Index OmniSwitch 6600 Family Network Configurati on Guide April 2006 Index-5 ip multicast switc hing command 40-5 ip rip force-holddowntimer command 30-9 ip rip host-route command 30-9 ip rip interfac.
Index Index-6 O mniSwitch 6600 Family Network Configuration Guid e Apr il 2006 LDAP servers see policy servers used for QoS policies 37-3 Lightweight Director y Access Protocol see LDAP servers line speed 15-16 link aggregation 802.
Index OmniSwitch 6600 Family Network Configurati on Guide April 2006 Index-7 policy server flush command 37-6 compared to qos flush command 37-7 policy server load command 37-6 policy servers defaults.
Index Index-8 O mniSwitch 6600 Family Network Configuration Guid e Apr il 2006 qos stats interval command 38-18 qos trust ports command 38-21 Quality of Service see QoS queues shared 38-20 R RADIUS accounting servers standard attributes 34- 13 used for 802.
Index OmniSwitch 6600 Family Network Configurati on Guide April 2006 Index-9 show 802.1q command 25-8, 25-11 show 802.1x command 36-3 show aaa accounting vlan command 35-6 show aaa authentication alva.
Index Index-10 OmniSwi tch 6600 Family Network Configuration Guid e Apr il 2006 static VLAN port assignment 21-4 STP see Spanning Tree Algor ithm and Protocol subnet mask 28-9 switch health applicatio.
Index OmniSwitch 6600 Family Network Configurati on Guide April 2006 Index-11 VLANs 18-1, 18-6 802.1Q 25-3 administrative st atus 1 8-7 application examples 18-3, 18-13, 21-3 authentication 18-12 defa.
Index Index-12 OmniSwi tch 6600 Family Network Configuration Guid e Apr il 2006.
Ein wichtiger Punkt beim Kauf des Geräts Alcatel-Lucent 6600 (oder sogar vor seinem Kauf) ist das durchlesen seiner Bedienungsanleitung. Dies sollten wir wegen ein paar einfacher Gründe machen:
Wenn Sie Alcatel-Lucent 6600 noch nicht gekauft haben, ist jetzt ein guter Moment, um sich mit den grundliegenden Daten des Produkts bekannt zu machen. Schauen Sie zuerst die ersten Seiten der Anleitung durch, die Sie oben finden. Dort finden Sie die wichtigsten technischen Daten für Alcatel-Lucent 6600 - auf diese Weise prüfen Sie, ob das Gerät Ihren Wünschen entspricht. Wenn Sie tiefer in die Benutzeranleitung von Alcatel-Lucent 6600 reinschauen, lernen Sie alle zugänglichen Produktfunktionen kennen, sowie erhalten Informationen über die Nutzung. Die Informationen, die Sie über Alcatel-Lucent 6600 erhalten, werden Ihnen bestimmt bei der Kaufentscheidung helfen.
Wenn Sie aber schon Alcatel-Lucent 6600 besitzen, und noch keine Gelegenheit dazu hatten, die Bedienungsanleitung zu lesen, sollten Sie es aufgrund der oben beschriebenen Gründe machen. Sie erfahren dann, ob Sie die zugänglichen Funktionen richtig genutzt haben, aber auch, ob Sie keine Fehler begangen haben, die den Nutzungszeitraum von Alcatel-Lucent 6600 verkürzen könnten.
Jedoch ist die eine der wichtigsten Rollen, die eine Bedienungsanleitung für den Nutzer spielt, die Hilfe bei der Lösung von Problemen mit Alcatel-Lucent 6600. Sie finden dort fast immer Troubleshooting, also die am häufigsten auftauchenden Störungen und Mängel bei Alcatel-Lucent 6600 gemeinsam mit Hinweisen bezüglich der Arten ihrer Lösung. Sogar wenn es Ihnen nicht gelingen sollte das Problem alleine zu bewältigen, die Anleitung zeigt Ihnen die weitere Vorgehensweise – den Kontakt zur Kundenberatung oder dem naheliegenden Service.