Configuring the Switching Infrastructure for Mirage NAC Appliances
|
|
- Adela Bond
- 6 years ago
- Views:
Transcription
1 Configuring the Switching Infrastructure for Mirage NAC Appliances Executive Summary The purpose of this document is to explain how to configure the switch for use with the Mirage NAC appliance. Aside from deciding on where to deploy the Mirage NAC device, configuring the switch is one of the most important parts of deployment. The Mirage NAC device can be installed in two modes (a) Mirror Mode or (b) broadcast mode and this document covers only Mirror Mode. This document is broken into two sections. The first section discusses the Mirage NAC device and its needs in respect to the switch. The second section discusses how to configure Cisco switches for mirroring. Intended Audience This document is applicable to Mirage Networks customers and partners looking to integrate the Mirage NAC appliances into an existing network. General familiarity with the Mirage Networks technology and line of products is assumed.. Background The Mirage NAC Appliance is designed to be deployed out-of-band meaning that it can analyze traffic that traverses the network without having to be placed within a critical data path. Therefore, it is strongly recommended that the switch ports connected to the appliance be configured as Switched Port Analyzer (SPAN) ports or mirror ports. The Mirage NAC Appliance requires full read-write access to the ARP (Address Resolution Protocol) Horizon of each protected address range. In the event that the switch's mirror port connected to the Mirage NAC appliance is read-only it can be configured to pair with a read-write Ethernet port. For the purposes of this document, port pairing configurations are assumed, since that is the case for the majority of switches. Each segment's logical port(s) must be enabled and, in cases with read-only ports, paired with a writable port for the Mirage NAC appliance to begin monitoring network traffic on the segment. Information displayed is the state of the port, MAC Address, Read/Write State, Paired With state and the Segment Name. The Mirage NAC device is capable of monitoring and protecting one to thirty-two VLANs. In the case of monitoring and protecting more than one VLAN the switch has to be configured with two trunk ports to the Mirage NAC device with 80.Q encapsulation. One of these trunk ports will be defined as the SPAN destination or mirror destination. The reason for the 80.Q encapsulation is to ensure the Mirage NAC device is able to see the multiple VLANs on both the read-only and writable ports. VLAN- Virtual Local Area Network - A logical, or administratively configured, LAN or broadcast domain that is defined by software rather than by fixed, physical port connections. Qtag - The Institute of Electrical and Electronics Engineers (IEEE) standard 80.Q enables VLAN traffic to span many broadcast domains or switches. It does this by inserting a special Qtag that carries a VLAN identifier (VID) into each Ethernet frame. This tagged traffic carries VLAN membership information between switches, thus enabling a VLAN to span multiple switches. Configuring Common Switches for use with Mirage NAC Cisco switch configurations Cisco switches primarily come in two flavors, CatOS (Catalyst OS) and IOS (Internetworking OS). Cisco's flag ship 00 series switch can run either CatOS or IOS. Smaller switches like the 90 and the 0 all run IOS. Here is a breakdown of the Cisco Switches IOS CatOS 90 Series xxx Series SupII and 00 Series 0 Series 000 and 00 Series
2 0 Series 0 Series 00 Series Sup II and above 00 Series running IOS Configuration of the Mirage NAC appliance and network layer depends on the overall deployment mode. This port has the standard configuration on the switch that is similar to any workstation that is being plugged in. In a Mirrored deployment, two ports are used. This is because one port is used for the Mirror/SPAN and another. The second port is configured so the Mirage NAC device can write back into the networks that are configured for the mirror/span. Connection Reference Diagram The reference diagram below will be used for all following examples of configuring mirroring on Cisco switching gear. As shown in the diagram, interface ETH of the appliance is the mirror destination port, connected to port / of the switch. Interface ETH of the appliance is the writing interaction port and connected to port /8 of the switch. The VLAN access layer below the switch to which the appliance is connected carries 0 user VLANs, numbered -. CatOS Reference Configure an 80.q trunk for both ports that will be plugged into the Mirage NAC device set trunk mod/port [ on off desirable auto nonegotiate] dotq vlans Verify the trunking configuration. show trunk [ mod/port] Remove VLANs from the allowed VLANs list for a trunk. Add specific VLANs to the allowed VLANs list for a trunk. clear trunk mod/port vlans set trunk mod/port vlans Verify the allowed VLANs list for the trunk. show trunk [ mod/port] Configure the SPAN source and destination ports Verify the SPAN configuration. set span {srcmod/srcports src_vlans sc0} {destmod/destport*} [rx tx both] [inpkts {enable disable}] [learning {enable disable}] [multicast {enable disable}]* [filter vlans...] [create] show span IOS Reference
3 Selects the LAN port to configure. Configure the both ports the will be plugged into the Mirage NAC device as a Trunk. Configures the encapsulation, which configures the Layer switching port as either an ISL or 80.Q trunk. Configures the trunk not to use DTP. Router(config)# interface typeconfiguring the Switching Infrastructure for Mirage NAC Appliances^^ slot/port Router(config-if)# switchport trunk encapsulation { isl dotq } Configure the mirror source vlans Router(config)# monitor session session_number source {{ single_interface interface_list interface_range mixed_interface_list single_vlan vlan_list vlan_range mixed_vlan_list} [ rx tx both]} { remote vlan rspan_vlan_id}}ex: monitor session source vlan 0, 0, 0 both Configure the destination port of the mirror Verify Mirroring configuration Verify Trunking configuration Router(config)# monitor session session_number destination { single_interface interface_list interface_range mixed_interface_list} { remote vlan rspan_vlan_id}}ex: monitor session destination interface fa/8 Router# show monitor Router# show interface interface trunk Configuring Cisco 00 series switches Depending upon configuration, the Cisco 00 platform is capable of running either a hybrid of CatOS on the switching engine and IOS on the routing engine (Hybrid Mode); or of running IOS on both (Native Mode). While the syntactical elements of configuring mirroring differ according to the mode, both modes require that the mirror destination port must be configured as an unconditional trunk prior to configuring the mirroring session in order to encapsulate the mirrored traffic correctly. CatOS Example Ensure the Mirage NAC is turned on Plug Ethernet on the appliance into port / of the switch. Plug Ethernet on the appliance into port /8 of the switch.. Configure an 80.q trunk for the mirror destination port. Configure an 80.q trunk for the writing interaction port. set trunk / on nonegotiate dotq - set trunk /8 on nonegotiate dotq - Verify the trunking configuration for the mirror destination port. show trunk / Verify the trunking configuration for the mirror destination port. show trunk /8 8 Configure the SPAN source and destination ports Verify the SPAN configuration. set span - both [create] show span
4 00 Series switches with IOS Example Ensure the Mirage NAC is turned on Plug Ethernet on the appliance into port / of the switch. Plug Ethernet on the appliance into port /8 of the switch.. Configure the mirror destination port as an unconditional trunk with dotq encapsulation and no DTP carrying VLANs - Configure the writing interaction port as an unconditional trunk with dotq encapsulation and no DTP carrying VLANs - Router(config)# interface gigabit / Router(config-if)# switchport trunk encapsulation d otq vlan none vlan add - Router(config)# interface gigabit /8 Router(config-if)# switchport trunk encapsulation d otq vlan none vlan add - Verify trunking configuration for the mirror destination port. Router# show interface gigabit / trunk Verify trunking configuration for the writing interaction port Router# show interface gigabit /8 trunk Configure the source of the mirror Router(config)# monitor session source vlans Configure the destination port of the mirror Router(config)# monitor session destination interface gigabit/ Verify configuration Router# show monitor Reboot the Mirage NAC appliance Configuring 00 Series switches with IOS For the 00 series switches, the encapsulation of the mirror destination port is set as part of the monitor session command; therefore no interface-level configuration for the mirror destination port is required. 00 IOS Example Ensure the Mirage NAC is turned off Plug Ethernet on the appliance appliance into port / of the switch. Plug Ethernet of the appliance into port /8 of the switch..
5 Configure the writing interaction port as an unconditional trunk with dotq encapsulation and no DTP carrying VLANs - Verify the trunking configuration of the writing interaction port Router(config)# interface gigabit /8 Router(config-if)# switchport trunk encapsulation d otq vlan none vlan add - Router# show interface gigabit /8 trunk Configure the mirror source vlans Router(config)# monitor session source vlan - both Configure the destination port of the mirror Verify configuration Router(config)# monitor session destination interface gigabit /8 encapsulation dotq Router# show monitor Configuring 0/0 Series switches with IOS The 0 and 0 series switches do not support unconditional tagging of mirrored traffic. Instead, they support only replicating the presence/format of the tag contained in the source frame. In order to work within this limitation, deployments with 0 and 0 series switches should focus on mirroring ports rather than VLANs and mirroring only trunked uplink ports. 00 IOS Example Ensure the Mirage NAC is turned off Plug Ethernet on the appliance appliance into port / of the switch. Plug Ethernet of the appliance into port /8 of the switch.. Configure the writing interaction port as an unconditional trunk with dotq encapsulation and no DTP carrying VLANs - Verify the trunking configuration of the writing interaction port Configure the mirror source ports Configure the destination port of the mirror Verify configuration Router(config)# interface gigabit /8 Router(config-if)# switchport trunk encapsulation d otq vlan none vlan add - Router# show interface gigabit /8 trunk Router(config)# monitor session source interface gigabitethernet /, gigabitethernet /8 both Router(config)# monitor session destination interface gigabit /8 encapsulation dotq Router# show monitor Port Verification on the Mirage NAC device The command line interface provides access to the topology.pl script that checks and reports on the low-level topology discovery processes. This script provides insight into both the segment creation and interface discovery portions of the topology probe packets. The script is run without any arguments, and consists of two basic sections. The first section lists which interfaces are active under which segment. The second section lists which interfaces see topology discovery packets sent by the other. Running topology.pl in all of the examples outlined above would yield the following output:
6 topology.pl Segments to interfaces : [eth, eth, eth] : [eth0] : [eth., eth.] : [eth., eth.] : [eth., eth.] 8: [eth.8, eth.8] 9: [eth.9, eth.9] 0: [eth.0, eth.0] : [eth., eth.] : [eth., eth.] : [eth., eth.] : [eth., eth.] : [eth., eth.] : [eth., eth.] : [eth., eth.] 8: [eth.8, eth.8] 9: [eth.9, eth.9] 0: [eth.0, eth.0] : [eth., eth.] : [eth., eth.] : [eth., eth.] : [eth., eth.] : [eth., eth.] : [eth., eth.] : [eth., eth.] 8: [eth.8, eth.8] 9: [eth.9, eth.9] 0: [eth.0, eth.0] : [eth., eth.] : [eth., eth.] : [eth., eth.] : [eth., eth.] : [eth., eth.] Interface sees: eth0: [] eth: [eth, eth, eth] eth: [] eth: [eth, eth, eth] eth. [eth.] eth. [] eth. [eth.] eth. [] eth. [eth.] eth. [] eth. [eth.] eth. [] eth.8 [eth.8] eth.8 [] eth.9 [eth.9] eth.9 [] eth.0 [eth.0] eth.0 [] eth. [eth.] eth. [] eth. [eth.] eth. [] eth. [eth.] eth. [] eth. [eth.] eth. [] eth. [eth.] eth. [] eth. [eth.] eth. : [] [support@]$ Note that for the purposes of interface grouping, the logical OR condition is met, since the ETH.xxx interfaces ''sees'' the ETH.xxx interfaces and the ETH.xxx interfaces see the ETH.xxx interfaces. All ETH.xxx interfaces should be flagged as "Read Only" and paired with the corresponding ETH.xxx interface. Likewise, all ETH.xxx interfaces should be flagged as "Read Only" and paired with the corresponding ETH.xxx interface.
Configuring SPAN and RSPAN
34 CHAPTER This chapter describes how to configure the Switched Port Analyzer (SPAN) and Remote SPAN (RSPAN) on the Catalyst 4500 series switches. SPAN selects network traffic for analysis by a network
More informationConfiguring SPAN and RSPAN
41 CHAPTER This chapter describes how to configure the Switched Port Analyzer (SPAN) and Remote SPAN (RSPAN) on the Catalyst 4500 series switches. SPAN selects network traffic for analysis by a network
More informationConfiguring SPAN. Understanding SPAN CHAPTER. This chapter describes how to configure Switched Port Analyzer (SPAN) and on the Catalyst 2960 switch.
CHAPTER 23 This chapter describes how to configure Switched Port Analyzer (SPAN) and on the Catalyst 2960 switch. Note For complete syntax and usage information for the commands used in this chapter, see
More informationConfiguring SPAN and RSPAN
Finding Feature Information, page 1 Prerequisites for SPAN and RSPAN, page 1 Restrictions for SPAN and RSPAN, page 2 Information About SPAN and RSPAN, page 3 How to Configure SPAN and RSPAN, page 14 Monitoring
More informationConfiguring VLANs. Understanding VLANs CHAPTER
CHAPTER 10 This chapter describes how to configure normal-range VLANs (VLAN IDs 1 to 1005) and extended-range VLANs (VLAN IDs 1006 to 4094) on the switch. It includes information about VLAN membership
More informationConfiguring Access and Trunk Interfaces
Configuring Access and Trunk Interfaces Ethernet interfaces can be configured either as access ports or trunk ports. Trunks carry the traffic of multiple VLANs over a single link and allow you to extend
More informationConfiguring SPAN and RSPAN
CHAPTER 32 This chapter describes how to configure Switched Port Analyzer (SPAN) and Remote SPAN (RSPAN) on the Catalyst 3750-X or 3560-X switch. Unless otherwise noted, the term switch refers to a Catalyst
More informationConfiguring SPAN and RSPAN
24 CHAPTER This chapter describes how to configure Switched Port Analyzer (SPAN) and Remote SPAN (RSPAN) on your Catalyst 2950 or Catalyst 2955 switch. Note For complete syntax and usage information for
More informationConfiguring IEEE 802.1Q Tunneling
CHAPTER 26 This chapter describes how to configure IEEE 802.1Q tunneling in Cisco IOS Release 12.2SX. For complete syntax and usage information for the commands used in this chapter, see the Cisco IOS
More informationConfiguring SPAN and RSPAN
Prerequisites for SPAN and RSPAN, page 1 Restrictions for SPAN and RSPAN, page 1 Information About SPAN and RSPAN, page 3 How to Configure SPAN and RSPAN, page 14 Monitoring SPAN and RSPAN Operations,
More informationConfiguring VLANs. Understanding VLANs CHAPTER
CHAPTER 12 This chapter describes how to configure normal-range VLANs (VLAN IDs 1 to 1005) and extended-range VLANs (VLAN IDs 1006 to 4094) on the switch. It includes information about VLAN membership
More informationConfiguring VLANs. Understanding VLANs CHAPTER
CHAPTER 9 This chapter describes how to configure normal-range VLANs (VLAN IDs 1 to 1005) and extended-range VLANs (VLAN IDs 1006 to 4094). It includes information about VLAN membership modes, VLAN configuration
More informationConfiguring VLANs. Understanding VLANs CHAPTER
CHAPTER 14 This chapter describes how to configure normal-range VLANs (VLAN IDs 1 to 1005) and extended-range VLANs (VLAN IDs 1006 to 4094) on the Catalyst 3750 switch. It includes information about VLAN
More informationChapter 3: VLANs. Routing & Switching
Chapter 3: VLANs Routing & Switching VLAN Definitions A VLAN is a logical partition of a Layer 2 network. VLANs logically group hosts, regardless of physical location. Multiple partitions can be created,
More informationConfiguring IEEE 802.1Q Tunneling and Layer 2 Protocol Tunneling
CHAPTER 14 Configuring IEEE 802.1Q Tunneling and Layer 2 Protocol Tunneling With Release 12.1(13)E and later, the Catalyst 6500 series switches support IEEE 802.1Q tunneling and Layer 2 protocol tunneling.
More informationVLANs and Trunking C H A P T E R. 6-1: VLAN Configuration. Section 6-1
C H A P T E R 6 Section 6-1 VLANs and Trunking See the following sections for configuration information about these topics: 6-1: VLAN Configuration Describes the method for configuring, creating, and configuring
More informationApplication Notes for Mirage Networks CounterPoint in an Avaya IP Telephony Infrastructure Issue 1.0
Avaya Solution & Interoperability Test Lab Application Notes for Mirage Networks CounterPoint in an Avaya IP Telephony Infrastructure Issue 1.0 Abstract These Application Notes describe a configuration
More informationMonitor Commands. monitor session source, page 2 monitor session destination, page 4
monitor session source, page 2 monitor session destination, page 4 1 monitor session source monitor session source To create a SPAN or RSPAN source session, use the monitor session source command in switch
More informationApplication Notes for Mirage Networks Endpoint Controller in an Avaya IP Telephony Infrastructure Issue 1.0
Avaya Solution & Interoperability Test Lab Application Notes for Mirage Networks Endpoint Controller in an Avaya IP Telephony Infrastructure Issue 1.0 Abstract These Application Notes describe a configuration
More informationConfiguring Switched Port Analyzer
This document describes how to configure local Switched Port Analyzer (SPAN) and remote SPAN (RSPAN) on the router. Finding Feature Information, page 1 Prerequisites for Configuring Local Span and RSPAN,
More informationVLANs. LAN Switching and Wireless Chapter 3. Version Cisco Systems, Inc. All rights reserved. Cisco Public 1
VLANs LAN Switching and Wireless Chapter 3 Version 4.0 2006 Cisco Systems, Inc. All rights reserved. Cisco Public 1 Objectives Explain the role of VLANs in a converged network. Explain the role of trunking
More informationConfiguring Q-in-Q VLAN Tunnels
Information About Q-in-Q Tunnels, page 1 Licensing Requirements for Interfaces, page 7 Guidelines and Limitations, page 7 Configuring Q-in-Q Tunnels and Layer 2 Protocol Tunneling, page 8 Configuring Q-in-Q
More informationQuestion No: 1 What is the maximum number of switches that can be stacked using Cisco StackWise?
Volume: 283 Questions Question No: 1 What is the maximum number of switches that can be stacked using Cisco StackWise? A. 4 B. 5 C. 8 D. 9 E. 10 F. 13 Answer: D Question No: 2 A network engineer wants
More informationConfiguring Q-in-Q VLAN Tunnels
This chapter describes how to configure Q-in-Q VLAN tunnels. Finding Feature Information, page 1 Feature History for Q-in-Q Tunnels and Layer 2 Protocol Tunneling, page 1 Information About Q-in-Q Tunnels,
More informationCisco Exploration 3 Module 3 LAN Switching and Wireless Jim Johnston Class Notes September 9, 2008
Cisco Exploration 3 Module 3 LAN Switching and Wireless Jim Johnston Class Notes September 9, 2008 VLAN is a logically separate IP subnetwork. This allows multiple networks to exist on a switch and provide
More informationConfiguring VLANs. Understanding VLANs CHAPTER
CHAPTER 11 This chapter describes how to configure normal-range VLANs (VLAN IDs 1 to 1005) and extended-range VLANs (VLAN IDs 1006 to 4094) on your Catalyst 3550 switch. It includes information about VLAN
More informationT e c h n i c a l D o c u m e n t. Cisco 2960G, 2960S, and 2960X Configuration for WheatNet-IP
1 T e c h n i c a l D o c u m e n t Cisco 2960G, 2960S, and 2960X Configuration for WheatNet-IP Overview Let s take a look at what needs to be done to get your Cisco 2960 ready for the installation of
More informationVLAN Configuration via CLI on 300/500 Series Managed Switches
Article ID: 4986 4986 - VLAN Configuration via CLI on 300/500 Series Managed Switches Objective VLANs allow you to logically segment a LAN into different broadcast domains. In scenarios where sensitive
More informationConfiguring IEEE 802.1Q and Layer 2 Protocol Tunneling
CHAPTER 8 Configuring IEEE 802.1Q and Layer 2 Protocol Tunneling Virtual private networks (VPNs) provide enterprise-scale connectivity on a shared infrastructure, often Ethernet-based, with the same security,
More informationConfiguring IEEE 802.1Q Tunneling and Layer 2 Protocol Tunneling
9 CHAPTER Configuring IEEE 802.1Q Tunneling and Layer 2 Protocol Tunneling Virtual private networks (VPNs) provide enterprise-scale connectivity on a shared infrastructure, often Ethernet-based, with the
More informationConfiguring VLANs. Understanding VLANs CHAPTER
7 CHAPTER This chapter describes how to configure normal-range VLANs (VLAN IDs 1 to 1005) and extended-range VLANs (VLAN IDs 1006 to 4094) on the Cisco MWR 2941 router. It includes information about VLAN
More informationConfiguring Private VLANs
CHAPTER 15 This chapter describes how to configure private VLANs on the Cisco 7600 series routers. Note For complete syntax and usage information for the commands used in this chapter, refer to the Cisco
More informationImplementing Inter-VLAN Routing. 2003, Cisco Systems, Inc. All rights reserved. 2-1
Implementing Inter-VLAN Routing 2003, Cisco Systems, Inc. All rights reserved. 2-1 Internetwork Communications C:>ping 172.16.30.100 Can two hosts on different subnets communicate without a router? No
More informationConfiguring VLANs. Understanding VLANs CHAPTER
CHAPTER 16 This chapter describes how to configure normal-range VLANs (VLAN IDs 1 to 1005) and extended-range VLANs (VLAN IDs 1006 to 4094) on your Catalyst 2950 or Catalyst 2955 switch. It includes information
More informationConfiguring VLANs. Understanding VLANs CHAPTER
CHAPTER 14 This chapter describes how to configure normal-range VLANs (VLAN IDs 1 to 1005) and extended-range VLANs (VLAN IDs 1006 to 4094). It includes information about VLAN modes and the VLAN Membership
More information1. Which two statements are true about VLAN implementation? (Choose two.)
CCNA 2 Chapter 3 v5.0 Exam Answers 2015 (100%) 1. Which two statements are true about VLAN implementation? (Choose two.) The size of the collision domain is reduced. The number of required switches in
More informationInternetwork Expert s CCNP Bootcamp. VLANs, Trunking, & VTP. VLANs Overview
Internetwork Expert s CCNP Bootcamp VLANs, Trunking, & VTP http:// VLANs Overview Virtual Local Area Network Hosts in the same VLAN share the same broadcast domain Switches create a separate CAM table
More informationOn the Cisco Nexus 5548 Switch, Fibre Channel ports and VSAN ports cannot be configured as ingress source ports in a SPAN session.
This chapter includes the following sections:, page 1 SPAN Sources The Switched Port Analyzer (SPAN) feature (sometimes called port mirroring or port monitoring) selects network traffic for analysis by
More informationConfiguring Cisco IP Phone Support
CHAPTER 16 This chapter describes how to configure support for Cisco IP phones on the Catalyst 6500 series switches. For complete syntax and usage information for the commands used in this chapter, refer
More informationSybex CCENT Chapter 11: VLANs and Inter-VLAN Routing. Instructor & Todd Lammle
Sybex CCENT 100-101 Chapter 11: VLANs and Inter-VLAN Routing Instructor & Todd Lammle Chapter 11 Objectives The CCENT Topics Covered in this chapter include: LAN Switching Technologies Describe how VLANs
More informationLab 3.3 Configuring Wireshark and SPAN
Lab 3.3 Configuring Wireshark and SPAN Learning Objectives Install Wireshark on a host PC Configure a switch to use the SPAN monitoring tool. Topology Diagram Scenario In this lab, you will configure a
More informationConfiguring Interfaces
CHAPTER 9 This chapter defines the types of interfaces on the Cisco ME 3400 Ethernet Access switch and describes how to configure them. The chapter consists of these sections: Understanding Interface Types,
More informationConfiguring EtherChannel and 802.1Q Trunking Between Catalyst L2 Fixed Configuration Switches and Catalyst Switches Running CatOS
Configuring EtherChannel and 802.1Q Trunking Between Catalyst L2 Fixed Configuration Switches and Catalyst Switches Running CatOS Document ID: 23408 Contents Introduction Prerequisites Requirements Components
More informationConfiguring VLANs. Understanding VLANs CHAPTER
CHAPTER 11 This chapter describes how to configure normal-range VLANs (VLAN IDs 1 to 1005) and extended-range VLANs (VLAN IDs 1006 to 4094) on the Cisco ME 3400 Ethernet Access switch. It includes information
More informationCisco 4-Port and 8-Port Layer 2 Gigabit EtherSwitch Network Interface Module Configuration Guide for Cisco 4000 Series ISR
Cisco 4-Port and 8-Port Layer 2 Gigabit EtherSwitch Network Interface Module Configuration Guide for Cisco 4000 Series First Published: 2015-04-06 Last Modified: 2017-12-21 Cisco 4-Port and 8-Port Layer
More informationCCENT Study Guide. Chapter 11 VLANs and Inter-VLAN Routing
CCENT Study Guide Chapter 11 VLANs and Inter-VLAN Routing Chapter 11 Objectives The CCENT Topics Covered in this chapter include: 2.0 LAN Switching Technologies 2.4 Configure, verify, and troubleshoot
More informationCHAPTER 1: VLANS. Routing & Switching
CHAPTER 1: VLANS Routing & Switching CHAPTER 1 1.1 VLAN Segmentation 1.2 VLAN Implementation 1.3 VLAN Security and Design 1.4 Summary CHAPTER 1 : OBJECTIVES Explain the purpose of VLANs in a switched network.
More informationConfiguring Private VLANs
36 CHAPTER This chapter describes private VLANs (PVLANs) on Catalyst 4500 series switches. It also provides restrictions, procedures, and configuration examples. This chapter includes the following major
More informationConfiguring Q-in-Q VLAN Tunnels
This chapter contains the following sections: Information About Q-in-Q VLAN Tunnels, page 1 Licensing Requirements for Q-in-Q Tunnels, page 4 Guidelines and Limitations for Q-in-Q VLAN Tunnels, page 5
More informationConfiguring SPAN. Configuring SPAN. SPAN Sources. This chapter includes the following sections: Configuring SPAN, page 1
This chapter includes the following sections:, page 1 SPAN Sources The Switched Port Analyzer (SPAN) feature (sometimes called port mirroring or port monitoring) selects network traffic for analysis by
More informationConfiguring Interfaces
CHAPTER 9 This chapter defines the types of interfaces on the Cisco ME 3400 Ethernet Access switch and describes how to configure them. Understanding Interface Types, page 9-1 Using Interface Configuration
More informationConfiguring EtherChannels and Layer 2 Trunk Failover
28 CHAPTER Configuring EtherChannels and Layer 2 Trunk Failover This chapter describes how to configure EtherChannels on Layer 2 ports on the switch. EtherChannel provides fault-tolerant high-speed links
More informationConfiguring Private VLANs
36 CHAPTER This chapter describes private VLANs (PVLANs) on Catalyst 4500 series switches. It also provides restrictions, procedures, and configuration examples. This chapter includes the following major
More informationConfiguring the Catalyst 3750G Integrated Wireless LAN Controller Switch
APPENDIXA Configuring the Catalyst 3750G Integrated Wireless LAN Controller Switch The Catalyst 3750G Integrated Wireless LAN Controller Switch is an integrated Catalyst 3750 switch and Cisco 4400 series
More informationConfiguring EtherChannels and Link-State Tracking
CHAPTER 37 Configuring EtherChannels and Link-State Tracking This chapter describes how to configure EtherChannels on Layer 2 and Layer 3 ports on the switch. EtherChannel provides fault-tolerant high-speed
More informationVLAN Configuration. Understanding VLANs CHAPTER
CHAPTER 11 This chapter describes how to configure normal-range VLANs (VLAN IDs 1 to 1005) and extended-range VLANs (VLAN IDs 1006 to 4094) on the CGR 2010 ESM. It includes information about VLAN membership
More informationConfiguring SmartPort Macros
CHAPTER 10 This chapter describes how to configure and apply SmartPort macros on your switch. Note For complete syntax and usage information for the switch commands used in this chapter, look at the Cisco
More informationVLANs. 2003, Cisco Systems, Inc. All rights reserved. 2-1
VLANs 2003, Cisco Systems, Inc. All rights reserved. 2-1 Traditional Campus Networks Broadcast Domain Collision Domain 1 Collision Domain 2 Bridges terminate collision domains 2003, Cisco Systems, Inc.
More informationConfiguring EtherChannels and Link-State Tracking
30 CHAPTER Configuring EtherChannels and Link-State Tracking This chapter describes how to configure EtherChannels on Layer 2 ports on the Catalyst 2960 switch. EtherChannel provides fault-tolerant high-speed
More informationVLANs. 2003, Cisco Systems, Inc. All rights reserved. 2-1
VLANs 2003, Cisco Systems, Inc. All rights reserved. 2-1 Traditional Campus Networks Broadcast Domain Collision Domain 1 Collision Domain 2 Bridges terminate collision domains 2003, Cisco Systems, Inc.
More informationexamcollection.premium.exam.157q. Exam code: Exam name: Implementing Cisco IP Switched Networks. Version 15.0
300-115.examcollection.premium.exam.157q Number: 300-115 Passing Score: 800 Time Limit: 120 min File Version: 15.0 Exam code: 300-115 Exam name: Implementing Cisco IP Switched Networks Version 15.0 Question
More informationConfiguring MAC Address Tables
This chapter contains the following sections: Information About MAC Addresses, page 1 Configuring MAC Addresses, page 2 Configuring MAC Move Loop Detection, page 4 Verifying the MAC Address Configuration,
More informationConfiguring EtherChannels
27 CHAPTER This chapter describes how to configure EtherChannel on Layer 2 interfaces. EtherChannel provides fault-tolerant high-speed links between switches, routers, and servers. You can use it to increase
More informationImplementing Inter-VLAN Routing
Internetwork Communications C:>ping 72.6.30.00 Implementing Inter-VLN Routing Can two hosts on different subnets communicate without a router? No What would happen if a host tried to ping another host?
More informationChapter 3. Virtual Local Area Networks (VLANs) Part II
Chapter 3 Virtual Local Area Networks (VLANs) Part II CCNA3-1 Chapter 3-2 Note for Instructors These presentations are the result of a collaboration among the instructors at St. Clair College in Windsor,
More informationConfiguring SPAN. Finding Feature Information. About SPAN. SPAN Sources
This chapter describes how to configure an Ethernet switched port analyzer (SPAN) to analyze traffic between ports on Cisco NX-OS devices. Finding Feature Information, on page 1 About SPAN, on page 1 Licensing
More informationConfiguring EtherChannels and Layer 2 Trunk Failover
35 CHAPTER Configuring EtherChannels and Layer 2 Trunk Failover This chapter describes how to configure EtherChannels on Layer 2 and Layer 3 ports on the switch. EtherChannel provides fault-tolerant high-speed
More informationConfiguring Private Hosts
CHAPTER 25 This chapter describes how to configure the private hosts feature in Cisco IOS Release 12.2SX. Note For complete syntax and usage information for the commands used in this chapter, see the Cisco
More informationConfiguring VLAN ACLs
35 CHAPTER This chapter describes how to configure VLAN ACLs (VACLs) on Catalyst 6500 series switches. Note For complete syntax and usage information for the commands used in this chapter, refer to the
More informationConfiguring Ethernet Virtual Connections on the Cisco ASR 1000 Series Router
Configuring Ethernet Virtual Connections on the Cisco ASR 1000 Series Router Ethernet virtual circuit (EVC) infrastructure is a Layer 2 platform-independent bridging architecture that supports Ethernet
More informationConfiguring Catalyst Switches for Polycom Conference Phones
Configuring Catalyst Switches for Polycom Conference Phones Document ID: 97229 Contents Introduction Prerequisites Requirements Components Used Related Products Conventions Background Information Configure
More informationConfiguring VLAN Trunks
Finding Feature Information, page 1 Prerequisites for VLAN Trunks, page 1 Information About VLAN Trunks, page 2 How to Configure VLAN Trunks, page 5 Configuration Examples for VLAN Trunking, page 20 Where
More informationConfiguring Interface Characteristics
CHAPTER 10 This chapter defines the types of interfaces on the switch and describes how to configure them. Unless otherwise noted, the term switch refers to a standalone switch and to a switch stack. The
More informationVLANs. Traditional Campus Networks. Performance Issues. Broadcast Issues. Bridges terminate collision domains
Traditional Campus Networks Broadcast Domain VLANs Collision Domain 1 Collision Domain 2 Bridges terminate collision domains 2003, Cisco Systems, Inc. All rights reserved. 2-1 2003, Cisco Systems, Inc.
More informationConfiguring Smart Port Macros
CHAPTER 3 This chapter describes how to configure and apply smart port macros. Release 12.2(33)SXH and later releases support smart port macros. Note For complete syntax and usage information for the commands
More informationNote: Use two 2960 switches for ALS1 and ALS2 and two 3560 switches for DLS1 and DLS2
LAB 2 - Part I - VLANs, VLAN Trunking, and VTP Domains Topology: Objectives Set up a VTP domain. Create and maintain VLANs. Configure 802.1Q trunking. Background VLANs logically segment a network by function,
More informationMaintaining Specific VLAN Identification. Comparing ISL and 802.1Q. VLAN Trunking
Maintaining Specific VLAN Identification Specifically developed for multi-vlan interswitch communications Places a unique identifier in each frame Functions at Layer 2 2003, Cisco Systems, Inc. All rights
More informationIEEE 802.1ah on Provider Backbone Bridges
IEEE 802.1ah on Provider Backbone Bridges First Published: November 25, 2009 Last Updated: February 8, 2011 The IEEE 802.1ah on Provider Backbone Bridges feature enables MAC-in-MAC tunneling on Ethernet
More informationConfiguring IEEE 802.3ad LACP EtherChannels on the Cisco MWR 2941
29 CHAPTER Configuring IEEE 802.3ad LACP EtherChannels on the Cisco MWR 2941 Cisco MWR 2941 Release 3.5.1 and later supports IEEE 802.3ad Link Aggregation Control Protocol (LACP) EtherChannels. Note The
More informationThe following steps should be used when configuring a VLAN on the EdgeXOS platform:
EdgeXOS VLANs VLAN Overview This document provides an overview of what a VLAN is and how it is configured on the EdgeXOS platform. Use the step-by-step guide below to configure a VLAN on the Edge appliance
More informationNetwork Edge Authentication Topology
The Network Edge Access Topology (NEAT) feature enables extended secure access in areas outside the wiring closet (such as conference rooms). This secure access allows any type of device to authenticate
More informationConfiguring Layer 3 Interfaces
This chapter contains the following sections: Information About Layer 3 Interfaces, page 1 Licensing Requirements for Layer 3 Interfaces, page 4 Guidelines and Limitations for Layer 3 Interfaces, page
More informationConfiguring BPDU tunneling
Contents Configuring BPDU tunneling 1 Introduction to BPDU tunneling 1 Background 1 BPDU Tunneling implementation 2 Configuring BPDU tunneling 3 Configuration prerequisites 3 Enabling BPDU tunneling for
More informationSchool Site Design. Large School Modular Switch Design CHAPTER
CHAPTER 10 The core/distribution component of the schools SRA is a key element in delivering a resilient network, while providing a network configuration that is easy to manage and to deploy. This chapter
More informationConfiguring Voice VLAN
CHAPTER 15 This chapter describes how to configure the voice VLAN feature on the Catalyst 3750 switch. Unless otherwise noted, the term switch refers to a standalone switch and a switch stack. Voice VLAN
More informationNetwork Management Commands
Network Management Commands ip wccp, page 3 monitor capture (interface/control plane), page 5 monitor capture buffer, page 9 monitor capture clear, page 10 monitor capture export, page 11 monitor capture
More informationRouting Between VLANs Overview
Routing Between VLANs Overview This chapter provides an overview of VLANs. It describes the encapsulation protocols used for routing between VLANs and provides some basic information about designing VLANs.
More informationConfiguring Virtual Private LAN Services
Virtual Private LAN Services (VPLS) enables enterprises to link together their Ethernet-based LANs from multiple sites via the infrastructure provided by their service provider. This module explains VPLS
More informationConfiguring SPAN. About SPAN. SPAN Sources
This chapter describes how to configure an Ethernet switched port analyzer (SPAN) to analyze traffic between ports on Cisco NX-OS devices. This chapter contains the following sections: About SPAN, page
More informationQuestion No : 1 Which three of these statements regarding 802.1Q trunking are correct? (Choose three.)
Volume: 149 Questions Question No : 1 Which three of these statements regarding 802.1Q trunking are correct? (Choose three.) A. 802.1Q native VLAN frames are untagged by default. B. 802.1Q trunking ports
More informationConfiguring MAC Address Tables
This chapter contains the following sections: Information About MAC Addresses, page 1 Guidelines for Configuring the MAC Address Tables, page 2 MAC Address Movement, page 2 Configuring MAC Addresses, page
More informationFor information about configuring these settings from Cluster Management Suite (CMS), refer to the online help.
Configuring VLANs This chapter provides information about configuring virtual LANs (VLANs). It includes command-line interface (CLI) procedures for using commands that have been specifically created or
More informationChapter 2 Lab 2-1, Static VLANS, VLAN Trunking, and VTP Domains and Modes
Chapter 2 Lab 2-1, Static VLANS, VLAN Trunking, and VTP Domains and Modes Topology Objectives Background Set up a VTP domain. Create and maintain VLANs. Configure ISL and 802.1Q trunking. VLANs logically
More informationConfiguring Layer 3 Interfaces
This chapter contains the following sections: Information About Layer 3 Interfaces, page 1 Licensing Requirements for Layer 3 Interfaces, page 4 Guidelines and Limitations for Layer 3 Interfaces, page
More informationImplementing Inter-VLAN Routing
Internetwork Communications C:>ping 172.16.30.100 Implementing Inter-VLAN Routing Can two hosts on different subnets communicate without a router? No What would happen if a host tried to ping another host?
More informationConfiguring Link Aggregation
Information About Link Aggregation, page 1 Restrictions for Link Aggregation, page 1 (GUI), page 3 (CLI), page 4 Verifying Link Aggregation Settings (CLI), page 4 Configuring Neighbor Devices to Support
More informationVLAN Range. Feature Overview
VLAN Range Feature History Release 12.0(7)XE 12.1(5)T 12.2(2)DD 12.2(4)B 12.2(8)T 12.2(13)T Modification The interface range command was introduced. The interface range command was integrated into Cisco
More informationConfiguring Port-Based Traffic Control
CHAPTER 18 This chapter describes how to configure port-based traffic control features on the Catalyst 3750 Metro switch. For complete syntax and usage information for the commands used in this chapter,
More informationConfiguring OpenFlow. Information About OpenFlow. This chapter contains the following sections:
This chapter contains the following sections: Information About OpenFlow, page 1 OpenFlow Limitations, page 2 Supported Interface Types, page 2 Unsupported Interface Types, page 2 Supported Interface Modes,
More informationPracticeDump. Free Practice Dumps - Unlimited Free Access of practice exam
PracticeDump http://www.practicedump.com Free Practice Dumps - Unlimited Free Access of practice exam Instant Download - Best Exam Practice Material - 100% Money Back Guarantee IT Certification Guaranteed,
More information