REDES I
CONFIGURACIN DE SPANNING
TREE
INTEGRANTES:
DOCENTE:
Umezawa Yokoyama, Julio
LIMA - PER
DEDICATORIA:
A nuestra familia por tu apoyo
incondicional que nos brindan en todo
este camino de desarrollo profesional.
A Dios, por iluminar y bendecir nuestros
hogares, llenarnos de vida, voluntad y
sabidura para lograr nuestras metas.
Al profesor Alfredo, Rodrguez Gutirrez,
por su gran apoyo, exigencia y
constante motivacin para la
culminacin de este trabajo, ayudarnos
as a impulsar el desarrollo de nuestra
formacin profesional.
Vlan
Vlan
Vlan
Vlan
99
10
20
30
:
:
:
:
Management.
Administracin.
Ventas.
Ingeniera.
OS6860E-P24
OS6860E-P48
OS6860E-24
OS6860E-48
OS6860E-U28
OS6860-P24
OS6860-P48
OS6860-24
OS6860-48
CARACTERSTICAS:
BENEFICIOS:
Port Mirroring
On chassis-based or standalone switches, you can set up port mirroring sessions
between Ethernet ports within the same switch, while on stackable switches,
you can set up port mirroring sessions across switches within the same stack.
Ethernet
ports
supporting
port
mirroring
include
10BaseT/100BaseTX/1000BaseT (RJ-45), 1000BaseSX/LX/LH, and 10GBaseS/L
(LC) connectors. When port mirroring is enabled, the active mirrored port
transmits and receives network traffic normally, and the mirroring port
receives a copy of all transmit and receive traffic to the active port. You can
connect an RMON probe or network analysis device to the mirroring port to see
an exact duplication of traffic on the mirrored port without disrupting network
traffic to and from the mirrored port.
Port mirroring runs in the Chassis Management software and is supported for
Ethernet (10 Mbps), FastEthernet (100 Mbps), Gigabit Ethernet (1000 Mpbs), and
R62A | CONECTIVIDAD DE REDES I
10 Gigabit Ethernet (10000 Mbps) ports. In addition, the switch supports N-to1 port mirroring, where up to 24 (OmniSwitch 6800) or 128 (OmniSwitch 6400,
6850, 6855, and 9000) source ports can be mirrored to a single destination port.
Note the following restriction when configuring a port mirroring session:
Two (2) port mirroring sessions are supported per standalone chassis-based
switch or in a stack consisting of two or more switches.
You cannot configure a port mirroring and a port monitoring session on the
same NI module in an OmniSwitch chassis-based switch.
You cannot configure port mirroring and monitoring on the same switching
ASIC on OmniSwitch 6400, 6850, and 6855 switches. Each switching ASIC
controls 24 ports (e.g., ports 124, 2548, etc.). For example, if a port
mirroring session is configured for ports 1/12 and 1/22, then configuring a
port monitoring session for any of the ports between 1 and 24 is not
allowed.
You cannot configure port mirroring and monitoring on the same switching
ASIC on OmniSwitch 6800 Series switches. Each switching ASIC controls 12
ports (e.g., ports 112, 1324, etc.). For example, if a port mirroring session
is configured for ports 1/6 and 1/10, then configuring a port monitoring
session for any of the ports between 1 and 12 is not allowed.
If a port mirroring session is configured across two switching ASICs, then
configuring a monitoring session is not allowed on any of the ports
controlled by each of the ASICs involved. For example, if a port mirroring
session is configured for ports 1/8 and 1/30 on a 48-port switch, then
configuring a port monitoring session involving any of the ports between 1
and 48 is not allowed.
mirrored port so that the mirroring port receives data from different ports. In this
way, you can roam the switch and monitor traffic at various ports.
The diagram on the following page illustrates how port mirroring can be used
with an external RMON probe to copy RMON probe frames and Management
frames to and from the mirroring and mirrored ports.
Frames received from an RMON probe attached to the mirroring port can be
seen as being received by the mirrored port. These frames from the mirroring
port are marked as if they are received on the mirrored port before being sent
over the switch backplane to an NMS station. Therefore, management frames
destined for the RMON probe are first forwarded out of the mirrored port.
After being received on the mirrored port, copies of the frames are mirrored out
of the mirroring portthe probe attached to the mirroring port receives the
management frames.
Spanning Tree must be disabled for the Remote Port Mirroring VLAN on all
switches.
There must not be any physical loop present in the Remote Port Mirroring
VLAN.
On the intermediate and destination switches, source learning must be
disabled or overridden on the ports belonging to the Remote Port Mirroring
VLAN.
The QoS redirect feature can be used to override source learning on an
OmniSwitch. The following types of traffic will not be mirrored:
Link Aggregation Control Packets (LACP)
802.1AB (LLDP)
802.1x port authentication
802.3ag (OAM)
Layer 3 control packets
Generic Attribute Registration Protocol (GARP)
BPDUs will not be mirrored on OmniSwitch 6400, 6850, and 6855 switchess
but will be mirrored on OmniSwitch 9000 switches.
RRSTP is only supported on VLAN Stacking NNI ports; UNI ports are not
supported.
An RRSTP ring must consist of either all VLAN Stacking NNI ports or all
standard switch ports; a mixture of the two port types in the same ring is
not supported.
If an RRSTP ring contains NNI ports, the VLAN tag configured for the ring
must match the SVLAN tag that VLAN Stacking appends to packets before
they are received or forwarded on NNI ports.
Spanning Tree
2. Assign all the necessary ports with the static agg agg num command. For
example:
-> static agg 1/1 agg num 1
-> static agg 1/2 agg num 1
-> static agg 1/3 agg num 1
-> static agg 1/4 agg num 1
3. Create a VLAN for this static link aggregate group with the vlan command.
For example:
-> vlan 10 port default 1
4. Create the equivalent static aggregate link on the remote switch with the
static linkagg size command. For example:
-> static linkagg 1 size 4
5. Assign all the necessary ports with the static agg agg num command. For
example:
-> static agg 1/9 agg num 1
-> static agg 1/10 agg num 1
-> static agg 1/11 agg num 1
6. Create a VLAN for this static link aggregate group with the vlan command.
For example:
-> vlan 10 port default 1
Note. Optional. You can verify your static link aggregation settings with the
show linkagg command. For example:
Static Aggregate
SNMP Id : 40000001,
Aggregate Number : 1,
Name : ,
Aggregate Size : 4,
And an example of what these commands look like entered sequentially on the
command line on the remote switch:
-> static linkagg 1 size 4
-> static agg 1/9 agg num 1
-> static agg 1/10 agg num 1
-> static agg 1/11 agg num 1
-> static agg 1/12 agg num 1
-> vlan 10 port default 1
an OmniSwitch 6400, 6800, 6850, 6855, or 9000 switch and an earlygeneration Alcatel-Lucent switch, such as an Omni Switch/Router.
The figure below shows a static aggregate group that has been configured
between Switch A and Switch B. The static aggregate group links four ports on a
single OS9-GNI-C24 on Switch A to two ports on one OS9-GNI-C24 and two ports
on another OS9-GNI-C24 on Switch B. The network administrator has created a
separate VLAN for this group so users can use this high speed link.
1. Create the dynamic aggregate group on the local (actor) switch with the
lacp linkagg size command as shown below:
-> lacp linkagg 2 size 8 actor admin key 5
2. Configure ports (the number of ports should be less than or equal to the size
value set in step 1) with the same actor administrative key (which allows
them to be aggregated) with the lacp agg actor admin key command. For
example:
-> lacp agg 1/1 actor admin key 5
-> lacp agg 1/4 actor admin key 5
-> lacp agg 3/3 actor admin key 5
-> lacp agg 5/4 actor admin key 5
-> lacp agg 6/1 actor admin key 5
-> lacp agg 6/2 actor admin key 5
-> lacp agg 7/3 actor admin key 5
-> lacp agg 8/1 actor admin key 5
3. Create a VLAN for this dynamic link aggregate group with the vlan
command. For example:
-> vlan 2 port default 2
5. Configure ports (the number of ports should be less than or equal to the size
value set in step 4) with the same actor administrative key (which allows
them to be aggregated) with the lacp agg actor admin key command. For
example:
-> lacp agg 2/1 actor admin key 5
-> lacp agg 3/1 actor admin key 5
-> lacp agg 3/3 actor admin key 5
-> lacp agg 3/6 actor admin key 5
-> lacp agg 5/1 actor admin key 5
-> lacp agg 5/6 actor admin key 5
-> lacp agg 8/1 actor admin key 5
-> lacp agg 8/3 actor admin key 5
6. Create a VLAN for this dynamic link aggregate group with the vlan
command. For example:
-> vlan 2 port default 2
Note. As an option, you can verify your dynamic aggregation group settings
with the show linkagg
command on either the actor or the partner switch. For example:
Dynamic Aggregate
SNMP Id : 40000002,
Aggregate Number : 2,
Name : ,
Aggregate Size : 8,
LACP
MACAddress : [00:1f:cc:00:00:00],
You can create Virtual LANs (VLANs), 802.1Q framing, configure Quality of
Service (QoS) conditions,
and other networking features on link aggregation groups because switch
software treats these virtual links just like physical links. (See Relationship to
Other Features on page 23-9 for more information on how link aggregation
interacts with other software features.)
Link aggregation groups are identified by unique MAC addresses, which are
created by the switch but can be modified by the user at any time. Load
balancing for Layer 2 non-IP packets is on a MAC address basis and for IP
packets the balancing algorithm uses the IP address as well. Ports must be of
the same speed within the same aggregate group.
Alcatel-Lucents link aggregation software allows you to configure the following
two different types of link aggregation groups:
A configurable source learning time limit that applies to all LPS ports.
A configurable limit on the number of MAC addresses allowed on an LPS
port.
Dynamic configuration of a list of authorized source MAC addresses.
Static configuration of a list of authorized source MAC addresses.
Two methods for handling unauthorized traffic: stopping all traffic on the
port or only blocking traffic that violates LPS criteria.
Note that LPS is supported on Ethernet and gigabit Ethernet fixed, mobile,
tagged and authenticated ports.
Link aggregate and tagged (trunked) link aggregate ports are not eligible for LPS
monitoring and control.
2. Set the total number of learned MAC addresses allowed on the same ports
to 25 using the following command:
-> port-security 3/6-12 4/6-12 5/6-12 maximum 25
3. Configure the amount of time in which source learning is allowed on all LPS
ports to 30 minutes using the following command:
-> port-security shutdown 30
4. Select shutdown for the LPS violation mode using the following command:
-> port-security 3/6-12 4/6-12 5/6-12 violation shutdown
Note. Optional. To verify LPS port configurations, use the port-security learntrap-threshold command. For example:
Port: 1/30
-------------------+------+-------------------
00:20:95:00:fa:5c 1 STATIC
To verify the new source learning time limit value, use the show port-security
shutdown command. For example:
Convert-to-static = DISABLE
A specific amount of time in which the switch allows source learning to occur
on all LPS ports.
A maximum number of learned MAC addresses allowed on the port.
A list of configured authorized source MAC addresses allowed on the port.
Additional LPS functionality allows the user to specify how the LPS port handles
unauthorized traffic. The following two options are available for this purpose:
Block only traffic that violates LPS port restrictions; authorized traffic is
forwarded on the port.
Disable the LPS port when unauthorized traffic is received; all traffic is
stopped and a port reset is required to return the port to normal operation.
Fixed (non-mobile)
Mobile
802.1Q tagged
Authenticated
802.1x
Link aggregate
Tagged (trunked) link aggregate
CONFIGURIN VLANs
In a flat bridged network, a broadcast domain is confined to a single LAN
segment or even a specific physical location, such as a department or building
floor. In a switch-based network, such as one comprised of Alcatel-Lucent
switching systems, a broadcast domainor VLAN can span multiple physical
switches and can include ports from a variety of media types. For example, a
single VLAN could span three different switches located in different buildings
and include 10/100 Ethernet, Gigabit Ethernet, 802.1q tagged ports and/or a
link aggregate of ports.
R62A | CONECTIVIDAD DE REDES I
VLAN Specifications
Note that the maximum limit values provided in the following Specifications
table are subject to available system resources:
VLAN Defaults
Note. Optional. Creating a new VLAN involves specifying a VLAN ID that is not
already assigned to an existing VLAN. To determine if a VLAN already exists in
the switch configuration, enter show vlan. If VLAN 255 does not appear in the
show vlan output, then it does not exist on the switch. For example:
1. Create VLAN 255 with a description (e.g., Finance IP Network) using the
following command:
-> vlan 255 name Finance IP Network
Note. Optional. To verify the VLAN 255 configuration, use the show vlan
command. For example:
Authentication : disabled,
To verify that ports 3/2-4 were assigned to VLAN 255, use the show vlan port
command. For example:
--------+---------+--------------
One of the main benefits of using VLANs to segment network traffic, is that
VLAN configuration and port assignment is handled through switch software.
This eliminates the need to physically change a network device connection or
location when adding or removing devices from the VLAN broadcast domain.
The VLAN management software handles the following VLAN configuration tasks
performed on an Alcatel-Lucent switch:
BIBLIOGRAFIA