D-Link DES-3326SR User Manual

Page 1
DES-3326SR
Layer 3 Switch
User’s Guide
First Edition (May 2003)
6513326SR015
RECYCLABLE
Page 2
Wichtige Sicherheitshinweise
1. Bitte lesen Sie sich diese Hinweise sorgfältig durch.
2. Heben Sie diese Anleitung für den spätern Gebrauch auf.
3. Vor jedem Reinigen ist das Gerät vom Stromnetz zu trennen. Vervenden Sie keine Flüssig- oder Aerosolreiniger. Am besten dient ein angefeuchtetes Tuch zur Reinigung.
4. Um eine Beschädigung des Gerätes zu vermeiden sollten Sie nur Zubehörteile verwenden, die vom Hersteller zugelassen sind.
5. Das Gerät is vor Feuchtigkeit zu schützen.
6. Bei der Aufstellung des Gerätes ist auf sichern Stand zu achten. Ein Kippen oder Fallen könnte Verletzungen hervorrufen. Verwenden Sie nur sichere Standorte und beachten Sie die Aufstellhinweise des Herstellers.
7. Die Belüftungsöffnungen dienen zur Luftzirkulation die das Gerät vor Überhitzung schützt. Sorgen Sie dafür, daß diese Öffnungen nicht abgedeckt werden.
8. Beachten Sie beim Anschluß an das Stromnetz die Anschlußwerte.
9. Die Netzanschlußsteckdose muß aus Gründen der elektrischen Sicherheit einen Schutzleiterkontakt haben.
10. Verlegen Sie die Netzanschlußleitung so, daß niemand darüber fallen kann. Es sollete auch nichts auf der Leitung abgestellt werden.
11. Alle Hinweise und Warnungen die sich am Geräten befinden sind zu beachten.
12. Wird das Gerät über einen längeren Zeitraum nicht benutzt, sollten Sie es vom Stromnetz trennen. Somit wird im Falle einer Überspannung eine Beschädigung vermieden.
13. Durch die Lüftungsöffnungen dürfen niemals Gegenstände oder Flüssigkeiten in das Gerät gelangen. Dies könnte einen Brand bzw. Elektrischen Schlag auslösen.
14. Öffnen Sie niemals das Gerät. Das Gerät darf aus Gründen der elektrischen Sicherheit nur von authorisiertem Servicepersonal geöffnet werden.
15. Wenn folgende Situationen auftreten ist das Gerät vom Stromnetz zu trennen und von einer qualifizierten Servicestelle zu überprüfen:
a – Netzkabel oder Netzstecker sint beschädigt. b – Flüssigkeit ist in das Gerät eingedrungen. c – Das Gerät war Feuchtigkeit ausgesetzt. d – Wenn das Gerät nicht der Bedienungsanleitung ensprechend funktioniert oder Sie
mit Hilfe dieser Anleitung keine Verbesserung erzielen. e – Das Gerät ist gefallen und/oder das Gehäuse ist beschädigt. f – Wenn das Gerät deutliche Anzeichen eines Defektes aufweist.
16. Bei Reparaturen dürfen nur Orginalersatzteile bzw. den Orginalteilen entsprechende Teile verwendet werden. Der Einsatz von ungeeigneten Ersatzteilen kann eine weitere Beschädigung hervorrufen.
17. Wenden Sie sich mit allen Fragen die Service und Repartur betreffen an Ihren Servicepartner. Somit stellen Sie die Betriebssicherheit des Gerätes sicher.
ii
Page 3
18. Zum Netzanschluß dieses Gerätes ist eine geprüfte Leitung zu verwenden, Für einen Nennstrom bis 6A und einem Gerätegewicht grőßer 3kg ist eine Leitung nicht leichter als H05VV-F, 3G, 0.75mm2 einzusetzen.
Page 4
WARRANTIES EXCLUSIVE
IF THE D-LINK PRODUCT DOES NOT OPERATE AS WARRANTED ABOVE, THE CUSTOMER'S SOLE REMEDY SHALL BE, AT D-LINK'S OPTION, REPAIR OR REPLACEMENT. THE FOREGOING WARRANTIES AND REMEDIES ARE EXCLUSIVE AND ARE IN LIEU OF ALL OTHER WARRANTIES, EXPRESSED OR IMPLIED, EITHER IN FACT OR BY OPERATION OF LAW, STATUTORY OR OTHERWISE, INCLUDING WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. D-LINK NEITHER ASSUMES NOR AUTHORIZES ANY OTHER PERSON TO ASSUME FOR IT ANY OTHER LIABILITY IN CONNECTION WITH THE SALE, INSTALLATION MAINTENANCE OR USE OF D-LINK'S PRODUCTS D-LINK SHALL NOT BE LIABLE UNDER THIS WARRANTY IF ITS TESTING AND EXAMINATION DISCLOSE THAT THE ALLEGED DEFECT IN THE PRODUCT DOES NOT EXIST OR WAS CAUSED BY THE CUSTOMER'S OR ANY THIRD PERSON'S MISUSE, NEGLECT, IMPROPER INSTALLATION OR TESTING, UNAUTHORIZED ATTEMPTS TO REPAIR, OR ANY OTHER CAUSE BEYOND THE RANGE OF THE INTENDED USE, OR BY ACCIDENT, FIRE, LIGHTNING OR OTHER HAZARD.
LIMITATION OF LIABILITY
IN NO EVENT WILL D-LINK BE LIABLE FOR ANY DAMAGES, INCLUDING LOSS OF DATA, LOSS OF PROFITS, COST OF COVER OR OTHER INCIDENTAL, CONSEQUENTIAL OR INDIRECT DAMAGES ARISING OUT THE INSTALLATION, MAINTENANCE, USE, PERFORMANCE, FAILURE OR INTERRUPTION OF A D- LINK PRODUCT, HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY. THIS LIMITATION WILL APPLY EVEN IF D-LINK HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. IF YOU PURCHASED A D-LINK PRODUCT IN THE UNITED STATES, SOME STATES DO NOT ALLOW THE LIMITATION OR EXCLUSION OF LIABILITY FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES, SO THE ABOVE LIMITATION MAY NOT APPLY TO YOU.
Limited Warranty
Hardware:
D-Link warrants each of its hardware products to be free from defects in workmanship and materials under normal use and service for a period commencing on the date of purchase from D-Link or its Authorized Reseller and extending for the length of time stipulated by the Authorized Reseller or D-Link Branch Office nearest to the place of purchase.
This Warranty applies on the condition that the product Registration Card is filled out and returned to a D-Link office within ninety (90) days of purchase. A list of D-Link offices is provided at the back of this manual, together with a copy of the Registration Card.
If the product proves defective within the applicable warranty period, D-Link will provide repair or replacement of the product. D-Link shall have the sole discretion whether to repair or replace, and replacement product may be new or reconditioned. Replacement product shall be of equivalent or better specifications, relative to the defective product, but need not be identical. Any product or part repaired by D-Link pursuant to this warranty shall have a warranty period of not less than 90 days, from date of such repair,
iv
Page 5
irrespective of any earlier expiration of original warranty period. When D-Link provides replacement, then the defective product becomes the property of D-Link.
Warranty service may be obtained by contacting a D-Link office within the applicable warranty period, and requesting a Return Material Authorization (RMA) number. If a Registration Card for the product in question has not been returned to D-Link, then a proof of purchase (such as a copy of the dated purchase invoice) must be provided. If Purchaser's circumstances require special handling of warranty correction, then at the time of requesting RMA number, Purchaser may also propose special procedure as may be suitable to the case.
After an RMA number is issued, the defective product must be packaged securely in the original or other suitable shipping package to ensure that it will not be damaged in transit, and the RMA number must be prominently marked on the outside of the package. The package must be mailed or otherwise shipped to D-Link with all costs of mailing/shipping/insurance prepaid. D-Link shall never be responsible for any software, firmware, information, or memory data of Purchaser contained in, stored on, or integrated with any product returned to D-Link pursuant to this warranty.
Any package returned to D-Link without an RMA number will be rejected and shipped back to Purchaser at Purchaser's expense, and D-Link reserves the right in such a case to levy a reasonable handling charge in addition mailing or shipping costs.
Software:
Warranty service for software products may be obtained by contacting a D-Link office within the applicable warranty period. A list of D-Link offices is provided at the back of this manual, together with a copy of the Registration Card. If a Registration Card for the product in question has not been returned to a D-Link office, then a proof of purchase (such as a copy of the dated purchase invoice) must be provided when requesting warranty service. The term "purchase" in this software warranty refers to the purchase transaction and resulting license to use such software.
D-Link warrants that its software products will perform in substantial conformance with the applicable product documentation provided by D-Link with such software product, for a period of ninety (90) days from the date of purchase from D-Link or its Authorized Reseller. D-Link warrants the magnetic media, on which D-Link provides its software product, against failure during the same warranty period. This warranty applies to purchased software, and to replacement software provided by D-Link pursuant to this warranty, but shall not apply to any update or replacement which may be provided for download via the Internet, or to any update which may otherwise be provided free of charge.
D-Link's sole obligation under this software warranty shall be to replace any defective software product with product which substantially conforms to D-Link's applicable product documentation. Purchaser assumes responsibility for the selection of appropriate application and system/platform software and associated reference materials. D-Link makes no warranty that its software products will work in combination with any hardware, or any application or system/platform software product provided by any third party, excepting only such products as are expressly represented, in D-Link's applicable product documentation as being compatible. D-Link's obligation under this warranty shall be a reasonable effort to provide compatibility, but D-Link shall have no obligation to provide compatibility when there is fault in the third-party hardware or software. D-Link makes no warranty that operation of its software products will be uninterrupted or
Page 6
absolutely error-free, and no warranty that all defects in the software product, within or without the scope of D-Link's applicable product documentation, will be corrected.
vi
Page 7
D-Link Offices for Registration and Warranty Service
The product's Registration Card, provided at the back of this manual, must be sent to a D-Link office. To obtain an RMA number for warranty service as to a hardware product, or to obtain warranty service as to a software product, contact the D-Link office nearest you. An address/telephone/fax/e-mail/Web site list of D-Link offices is provided in the back of this manual.
Trademarks
Copyright 2003 D-Link Corporation. Contents subject to change without prior notice. D-Link is a registered trademark of D-Link Corporation/D-Link Systems, Inc. All other trademarks belong to their respective proprietors.
Copyright Statement
No part of this publication may be reproduced in any form or by any means or used to make any derivative such as translation, transformation, or adaptation without permission from D-Link Corporation/D-Link Systems Inc., as stipulated by the United States Copyright Act of 1976.
Page 8
FCC Warning
This equipment has been tested and found to comply with the limits for a Class A digital device, pursuant to Part 15 of the FCC Rules. These limits are designed to provide reasonable protection against harmful interference when the equipment is operated in a commercial environment. This equipment generates, uses, and can radiate radio frequency energy and, if not installed and used in accordance with this user’s guide, may cause harmful interference to radio communications. Operation of this equipment in a residential area is likely to cause harmful interference in which case the user will be required to correct the interference at his own expense.
CE Mark Warning
This is a Class A product. In a domestic environment, this product may cause radio interference in which case the user may be required to take adequate measures.
VCCI Warning
viii
Page 9
Table of Contents
Introduction ............................................................................1
Layer 3 Switching ................................................................. 1
Features ............................................................................... 2
Ports ..................................................................................2
Performance Features........................................................... 2
Redundant Power Supply ...................................................2
Layer 2 Features ................................................................3
Layer 3 Switch Features..................................................... 5
Traffic Classification and Prioritization ...............................6
Management ......................................................................6
Switch Stacking.................................................................... 7
Fast Ethernet Technology .....................................................8
Gigabit Ethernet Technology................................................. 8
Unpacking and Setup.............................................................. 9
Unpacking ............................................................................9
Installation ........................................................................... 9
Desktop or Shelf Installation ............................................ 10
Rack Installation.............................................................. 11
Power on............................................................................. 12
Power Failure ...................................................................13
Redundant Power Supply ................................................. 13
Identifying External Components ..........................................14
Front Panel.........................................................................14
Rear Panel .......................................................................... 15
Side Panels .........................................................................16
Optional Plug-in Modules ...................................................16
100BASE-FX Fiber Module (2Km/15Km) .........................17
1000BASE-T Module........................................................ 18
1000BASE-SX Fiber Module ............................................18
1000BASE-LX Fiber Module............................................. 19
GBIC Two-Port Module..................................................... 20
ix
Page 10
Stacking Module with GBIC Port ......................................20
Switch LED Indicators ........................................................ 23
Stacking Module LED Indicators.........................................24
Connecting The Switch.......................................................... 25
Switch to End Node ............................................................25
Switch to Hub or Switch .....................................................26
Switch Stack Connections ..................................................27
10BASE-T Device ............................................................. 28
100BASE-TX Device......................................................... 29
Switch Management and Operating Concepts ....................... 30
Local Console Management ................................................30
Diagnostic (console) port (RS-232 DCE)............................ 31
Managing Switch Stacks..................................................... 32
Switch IP Address............................................................... 35
Traps.................................................................................. 37
SNMP .................................................................................38
MIBs................................................................................... 41
Packet Forwarding ..............................................................42
Filtering.............................................................................. 43
802.1w Rapid Spanning Tree ..............................................44
Link Aggregation.................................................................47
VLANs ................................................................................49
IP Addresses .......................................................................58
Internet Protocols ...............................................................67
Packet Headers................................................................... 74
The Domain Name System ..................................................81
DHCP Servers .....................................................................83
IP Routing ..........................................................................84
ARP ....................................................................................86
Multicasting .......................................................................87
Multicast Routing Protocols ................................................ 95
Routing Protocols ...............................................................97
Web-Based Switch Management.......................................... 143
Introduction .....................................................................143
Before You Start ...............................................................144
x
Page 11
General Deployment Strategy......................................... 144
VLAN Layout ..................................................................145
Assigning IP Network Addresses and Subnet Masks to
VLANs............................................................................ 146
Defining Static Routes....................................................146
Getting Started ................................................................. 146
Management..................................................................... 147
Configuring the Switch .....................................................148
User Accounts Management........................................... 148
Saving Changes ................................................................ 150
Factory Reset....................................................................152
USING WEB-BASED MANAGEMENT ................................ 153
NETWORK MANAGEMENT ............................................... 181
SNMP Settings ...............................................................181
Advanced Setup................................................................196
Layer 3 IP Networking....................................................... 204
IP Multicasting .................................................................231
Port Mirroring................................................................... 246
Forwarding ....................................................................... 249
Configure QOS (Quality of Service).................................... 258
Bandwidth Control......................................................... 268
Spanning Tree ..................................................................269
MAC Notification............................................................... 276
Link Aggregation...............................................................279
802.1X Configuration .......................................................283
System Log Server ............................................................289
Utilities.............................................................................291
Network Monitoring ..........................................................302
Technical Specifications ...................................................... 332
Brief Review of Bitwise Logical Operations........................... 335
Index................................................................................... 337
xi
Page 12
Page 13
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
1
INTRODUCTION
This section describes the functionality features of the DES­3326SR. Some background information about Ethernet/Fast Ethernet, Gigabit Ethernet, and switching technology is presented.
Layer 3 Switching
Layer 3 switching is the integration of two proven technologies: switching and routing. In fact, Layer 3 switches are running the same routing routines and protocols as traditional routers. The main difference between traditional routing and Layer 3 switching is the addition of a group of Layer 2 switching domains and the execution of routing routines for most packets via an ASIC – in hardware instead of software.
The DES-3326SR can also replace key traditional routers for data centers and server farms, routing between these locations and the rest of the network, and providing 24 ports of Layer 2 switching performance combined with wire-speed routing.
1
Page 14
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Features
The DES-3326SR Switch was designed for easy installation and high performance in an environment where traffic on the network and the number of users increase continuously.
Switch features include:
Ports
24 high performance NWay ports all operating at 10/100 Mbps with Auto-MDIX function for connecting to end stations, servers and hubs.
• All ports can auto-negotiate (NWay) between 10Mbps/ 100Mbps, half-duplex or full duplex and flow control for half-duplex ports.
• One front panel slide-in module interface for a 2-port 1000BASE-SX, 1000BASE-LX, 1000BASE-T, 100BASE-FX, GBIC or 1-port GBIC & Stack module.
• RS-232 DCE Diagnostic port (console port) for setting up and managing the Switch via a connection to a console terminal or PC using a terminal emulation program.
Performance Features
Redundant Power Supply
The DES-3326SR can be equipped with a redundant power supply - the D-Link DPS-200 - to ensure continuation of service if the main power unit fails. An integrated detection
2
Page 15
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
circuit continuously monitors the internal power supply. In the event of a power interruption, the redundant power supply is immediately triggered so that the DES-3326SR and connected devices can continue providing service.
This results in a more reliable network infrastructure and protects a network from a single failure of a network device power supply.
The redundant power supply may be purchased with and included in the original system installation, or may be added to an existing system at a later time.
Layer 2 Features
• 8.8 Gbps switching fabric capacity
• Store and forward switching scheme.
• Full and half-duplex for both 10Mbps and 100Mbps
connections. The front-port Gigabit Ethernet module operates at full-duplex only. Full-duplex allows the switch port to simultaneously transmit and receive data, and only works with connections to full-duplex capable end stations and switches. Connections to hubs must take place at half­duplex.
• Supports IEEE 802.3x flow control for full-duplex mode ports.
• Supports Back-pressure flow control for half-duplex mode ports.
• Auto-polarity detection and correction of incorrect polarity on the transmit and receive twisted-pair at each port.
• IEEE 802.3z compliant for all Gigabit ports (optional module).
3
Page 16
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
• IEEE 802.3x compliant Flow Control support for all Gigabit ports (optional module).
• IEEE 802.3ab compliant for 1000BASE-T (Copper) Gigabit ports (optional module).
• Data forwarding rate 14,880 pps per port at 100% of wire­speed for 10Mbps speed.
• Data forwarding rate 148,800 pps per port at 100% of wire­speed for 100Mbps speed.
• Data filtering rate eliminates all error packets, runts, etc. at 14,880 pps per port at 100% of wire-speed for 10Mbps speed.
• Data filtering rate eliminates all error packets, runts, etc. at 148,800 pps per port at 100% of wire-speed for 100Mbps speed.
• 8K active MAC address entry table per device with automatic learning and aging (10 to 9999 seconds).
• 8 MB packet buffer per device.
• Broadcast and Multicast storm filtering.
• Supports Port Mirroring.
• Supports Port Trunking – up to six trunk groups (each
consisting of up to eight ports) may be set up.
• 802.1D Spanning Tree support.
• 802.1Q Tagged VLAN support – up to 63 User-defined
VLANs per device (one VLAN is reserved for internal use).
• GVRP – (GARP VLAN Registration Protocol) support for dynamic VLAN registration.
4
Page 17
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
• 802.1p Priority support with 4 priority queues.
• IGMP Snooping support.
Layer 3 Switch Features
• Wire speed IP forwarding.
• Hardware-based Layer 3 IP switching.
• IP packet forwarding rate of 6.6 Mpps.
• 2K active IP address entry table per device.
• Supports RIP – (Routing Information Protocol) version I and
II.
• Supports OSPF − (Open Shortest Path First)
• Supports MD5 and Password OSPF Packet Authentication
• Supports IP version 4.
• IGMP version 1 and 2 support (RFC 1112 and RFC 2236).
• Supports PIM Dense Mode.
• Supports DVMRP.
• Supports IP multi-netting.
• Supports IP packet de-fragmentation.
• Supports 802.1D frame support.
5
Page 18
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Traffic Classification and Prioritization
• Based on 802.1p priority bits
• 4 priority queues
Management
• RS-232 console port for out-of-band network management via a console terminal or PC.
• Spanning Tree Algorithm Protocol for creation of alternative backup paths and prevention of network loops.
• SNMP v.1 Agent.
• Fully configurable either in-band or out-of-band control via
SNMP based software.
• Flash memory for software upgrades. This can be done in­band via TFTP or out-of-band via the console.
• Built-in SNMP management:
• Bridge MIB (RFC 1493)
• MIB-II (RFC 1213)
• Mini-RMON MIB (RFC 1757) – 4 groups
• CIDR MIB (RFC 2096), except IP Forwarding Table.
• 802.1p MIB (RFC 2674).
• RIP MIB v2 (RFC 1724).
• IF MIB (RFC 2233)
6
Page 19
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
• Ether-Like MIB (RFC 1643)
• OSPF MIB (RFC 1850)
• Supports Web-based management.
• CLI management support
• TFTP support.
• BOOTP support.
• BOOTP Relay Agent.
• IP filtering on the management interface.
• DCHP Client support.
• DCHP Relay Agent.
• DNS Relay Agent.
• Password enabled.
Switch Stacking
The DES-3326SR can be used as a standalone or stacked switch − using the optional stacking module. Up to 8 Switches may be stacked and managed as a unit with a single IP address.
Management for the entire stack is done through the Master Switch.
You may add Switches later as needed.
7
Page 20
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Fast Ethernet Technology
100Mbps Fast Ethernet (or 100BASE-T) is a standard specified by the IEEE 802.3 LAN committee. It is an extension of the 10Mbps Ethernet standard with the ability to transmit and receive data at 100Mbps, while maintaining the Carrier Sense Multiple Access with Collision Detection (CSMA/CD) Ethernet protocol.
Gigabit Ethernet Technology
Gigabit Ethernet is an extension of IEEE 802.3 Ethernet utilizing the same packet structure, format, and support for CSMA/CD protocol, full duplex, flow control, and management objects, but with a tenfold increase in theoretical throughput over 100Mbps Fast Ethernet and a one hundred-fold increase over 10Mbps Ethernet. Since it is compatible with all 10Mbps and 100Mbps Ethernet environments, Gigabit Ethernet provides a straightforward upgrade without wasting a company’s existing investment in hardware, software, and trained personnel.
8
Page 21
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
2
UNPACKING AND SETUP
This chapter provides unpacking and setup information for the Switch.
Unpacking
Open the shipping carton of the Switch and carefully unpack its contents. The carton should contain the following items:
• One DES-3326SR 24-port Fast Ethernet Layer 3 Switch
• Mounting kit: 2 mounting brackets and screws
• Four rubber feet with adhesive backing
• One AC power cord
• This User’s Guide with Registration Card
If any item is found missing or damaged, please contact your local D-Link reseller for replacement.
Installation
Use the following guidelines when choosing a place to install the Switch:
9
Page 22
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
• The surface must support at least 3 kg (6.6 lb)
• The power outlet should be within 1.82 meters (6 feet) of
the device
• Visually inspect the power cord and see that it is secured to the AC power connector
• Make sure that there is proper heat dissipation from and adequate ventilation around the switch. Do not place heavy objects on the switch
Desktop or Shelf Installation
When installing the Switch on a desktop or shelf, the rubber feet included with the device should first be attached. Attach these cushioning feet on the bottom at each corner of the device. Allow adequate space for ventilation between the device and the objects around it.
Figure 2-1. Installing rubber feet for desktop installation
10
Page 23
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Rack Installation
The DES-3326SR can be mounted in an EIA standard-sized, 19-inch rack, which can be placed in a wiring closet with other equipment. To install, attach the mounting brackets on the switch’s side panels (one on each side) and secure them with the screws provided.
Figure 2- 2. Attaching the mounting brackets to the switch
Then, use the screws provided with the equipment rack to mount the switch on the rack.
11
Page 24
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Figure 2-3. Installing the switch on an equipment rack
Power on
The DES-3326SR switch can be used with AC power supply 100-240 VAC, 50 - 60 Hz. The power switch is located at the rear of the unit adjacent to the AC power connector and the system fan. The switch’s power supply will adjust to the local power source automatically and may be turned on without having any or all LAN segment cables connected.
After the power switch is turned on, the LED indicators should respond as follows:
• All LED indicators will momentarily blink. This blinking of the LED indicators represents a reset of the system
12
Page 25
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
• The power LED indicator is always on after the power is turned ON
• The console LED indicator will blink while the Switch loads onboard software and performs a self-test. will remain ON if there is a connection at the RS-232 port, otherwise this LED indicator is OFF
• The 100M LED indicator may remain ON or OFF depending on the transmission speed
Power Failure
As a precaution in the event of a power failure, unplug the switch. When the power supply is restored, plug the switch back in.
Redundant Power Supply
The DES-3326SR can be equipped with a redundant power supply - the D-Link DPS-200 - to ensure continuation of service in a failure of the main power unit. An integrated detection circuit continuously monitors the internal power supply. In the event of a power interruption, the redundant power supply is immediately triggered so that the DES-3326SR and connected devices can continue providing service.
The redundant power supply may be purchased with and included in the original system installation, or may be added to an existing system at a later time.
13
Page 26
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
3
IDENTIFYING EXTERNAL
COMPONENTS
This chapter describes the front panel, rear panel, optional plug-in modules, and LED indicators of the DES-3326SR.
Front Panel
The front panel of the Switch consists of LED indicators, an RS-232 communication port, a slide-in module slot, and 24 (10/100 Mbps) Ethernet/Fast Ethernet ports.
Figure 3-1. Front panel view of the Switch
• Comprehensive LED indicators display the status of the
switch and the network (see the LED Indicators section below).
• An RS-232 DCE console port for setting up and managing the switch via a connection to a console terminal or PC using a terminal emulation program.
14
Page 27
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
• A front-panel slide-in module slot for Gigabit Ethernet ports can accommodate a 2-port 1000BASE-T Gigabit Ethernet module, a 2-port 1000BASE-SX Gigabit Ethernet module, a 2-port 1000BASE-LX Gigabit Ethernet module, or a 2-port GBIC-based Gigabit Ethernet module.
• Twenty-four high-performance, NWay Ethernet ports all of which operate at 10/100 Mbps with Auto-MDIX function for connections to end stations, servers and hubs. All ports can auto-negotiate between 10Mbps or 100Mbps, full or half duplex, and flow control.
Rear Panel
The rear panel of the switch contains an AC power connector.
Figure 3-2. Rear panel view of the Switch
The AC power connector is a standard three-pronged connector that supports the power cord. Plug-in the female connector of the provided power cord into this socket, and the male side of the cord into a power outlet. Supported input voltages range from 100 ~ 240 VAC at 50 ~ 60 Hz.
Between the fan outlet and the power cord is the outlet for the redundant power supply. Using the DPS-200 14-pin DC power cable, connect the DES-3326SR to the DPS-200 redundant power supply. The redundant power supply ensures that service will not be interrupted in the event of an internal power supply failure.
15
Page 28
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
For detailed instructions on connecting the DES-3326SR and the DPS-200, please refer to the Redundant Power Supply Quick Installation Guide supplied with your switch.
Side Panels
The right side panel of the Switch contains two system fans (see the top part of the diagram below). The left side panel contains heat vents.
Figure 3-4. Side panel views of the Switch
The system fans are used to dissipate heat. The sides of the system also provide heat vents to serve the same purpose. Do not block these openings, and leave at least 6 inches of space at the rear and sides of the switch for proper ventilation. Be reminded that without proper heat dissipation and air circulation, system components might overheat, which could lead to system failure.
Optional Plug-in Modules
The DES-3326SR 24-port Fast Ethernet Layer 3 Switch is able to accommodate a range of optional plug-in modules in order to
16
Page 29
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
increase functionality and performance. These modules must be purchased separately.
100BASE-FX Fiber Module (2Km/15Km)
Figure 3-5. 100BASE-FX two-port module
• Front-panel module.
• Two 100BASE-FX (with SC type connector) Fiber ports.
• Fully compliant with IEEE802.3u.
• Support Full-duplex operation only.
• IEEE 802.3x compliant Flow Control support for full-
duplex.
17
Page 30
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
1000BASE-T Module
Figure 3-6. 1000BASE-TX two-port module
• Front-panel module.
• Connects to 1000BASE-T devices.
• Supports Category 5e UTP or STP cable connections of up
to 100 meters.
1000BASE-SX Fiber Module
Figure 3-7. 1000BASE-SX two-port module
• Front-panel module.
• Connects to 1000BASE-SX devices at full-duplex.
18
Page 31
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
• Allows connections using multi-mode fiber optic cable in the following configurations:
Modal bandwidth
(min. overfilled launch)
Unit: MHz*km
Operating distance
Unit: meters
Channel insertion loss
Unit: dB
62.5µm 62.5µm 50µm 50µm
160 200 400 500
220 275 500 550
2.33 2.53 3.25 3.43
1000BASE-LX Fiber Module
Figure 3-8. 1000BASE-LX two-port module
• Front-panel module.
• Connects to 1000BASE-LX devices at full-duplex.
• Supports multi-mode fiber-optic cable connections of up
to 550 meters or 5 km single-mode fiber-optic cable connections.
19
Page 32
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
GBIC Two-Port Module
Figure 3-9. GBIC two-port module
• Front-panel module.
• Connects to GBIC devices at full duplex only.
• Allows multi-mode fiber optic connections of up to 550
m (SX and LX) and single-mode fiber optic connections of up to 5 km (LX only). GBIC modules are available in –SX and –LX fiber optic media.
• IEEE 802.3x compliant Flow Control for full-duplex.
Stacking Module with GBIC Port
Figure 3-10. Stacking Module with one GBIC port
20
Page 33
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
GBIC Port
• Front-panel module
• One Stacking port and one GBIC fiber port
• Connects to GBIC devices at full duplex only
• Allows multi-mode fiber optic connections of up to 550
m (SX and LX) and single-mode fiber optic connections of up to 5 km (LX only). GBIC modules are available in –SX and –LX fiber optic media
• IEEE 802.3x compliant Flow Control for full-duplex
Stacking Port
• One transmitting port and one receiving port
• Use the connector of IEEE 1394b
• Data rate up to 1250 Mbps
• 7-segment LED display to indicate switch ID number
within the switch stack
The optional Stacking Module allows up to 8 DES-3326SR Switches to be interconnected via their individual Stacking Modules. This forms a 8-switch stack that can then be managed and configured as thought the entire stack were a single switch. The switch stack is then accessed through a single IP address or alternatively, through the master switch’s serial port (via the management station’s console and the switch’s Command Line Interface).
21
Page 34
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Figure 3-11. Up to 8 Switches in a Switch Stack
The stacking ports are marked IN and OUT. The IEEE 1394 compliant cable must be connected from an IN port on one switch to an OUT port on the next switch in the stack. The last two switches (at the top and bottom of the stack) must also be connected from the IN port on one switch to the OUT port on the other switch. In this way, a loop is made such that all of the switches in the switch stack have the IN stacking port connected to another switch’s OUT stacking port.
The Stacking Module’s LED indicators are described below.
22
Page 35
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Switch LED Indicators
The LED indicators of the Switch include Power, Console, and Link/Act. The following shows the LED indicators for the Switch along with an explanation of each indicator.
Figure 3-12. The LED Indicators
• Power This indicator on the front panel should be lit
during the Power-On Self Test (POST). It will light green approximately 2 seconds after the switch is powered on to indicate the ready state of the device.
• Console This indicator is lit green when the switch is being
managed via out-of-band/local console management through the RS-232 console port using a straight-through serial cable.
• Act/Link These indicators are located to the left and right
of each port. They are lit when there is a secure connection (or link) to a device at any of the ports.
• The left-hand LEDs blink whenever there is reception or
transmission (i.e. Activity--Act) of data occurring at a port.
• The right-hand LEDs are steady green when the
transmission rate is 10Mpbs; at 100Mpbs, the right-hand LEDs will flash green.
• RPS Indicator. The bottom LED on the left-hand side of the switch, the Redundant Power Supply (RPS) indicator will show a steady amber when in standby mode. When the RPS is triggered, the LED will show steady green.
23
Page 36
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Stacking Module LED Indicators
The switch’s current order in the switch stack is also displayed on the Stacking Module’s front panel − under the STACK NO. heading:
Figure 3-13. Stacking Module LED Indicators
The Link and Act LEDs have the same function as the corresponding LEDs for the switch’s Ethernet ports. The Link LED lights to confirm a valid link, while the ACT LED blinks to indicate activity on the link.
The Stack No. seven-segment LED displays the Unit number assigned to the switch. A 0 (a zero) in the display indicates that the stacking module is in the process of determining the stack status and has not yet resolved the switch’s Unit number.
The stacking order can be automatically configured using the switch’s MAC address − the lower the numerical value of a given switch’s MAC address, the lower the number in the stacking order the switch will be assigned. The switch with the lowest MAC address, will then become the Master Switch. This is the Stacking Module’s default mode.
Alternatively, the stacking order can be manually assigned using the console’s Command Line Interface (CLI).
24
Page 37
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
4
CONNECTING THE
SWITCH
This chapter describes how to connect the DES 3326SRSR to your Fast Ethernet network.
Switch to End Node
End nodes include PCs outfitted with a 10, 100 or 10/100 Mbps RJ-45 Ethernet/Fast Ethernet Network Interface Card (NIC) and most routers. The RJ-45 UTP ports on NICs and most routers are MDI-II. When using a normal straight-through cable, an MDI-II port must connect to an MDI-X port.
An end node can be connected to the Switch via a two-pair Category 3, 4, 5 UTP/STP straight cable (be sure to use Category 5e UTP or STP cabling for 100 Mbps Fast Ethernet connections). The end node should be connected to any of the twenty-four ports (2x - 24x) of the DES-3326SR or to either of the two 100BASE-TX ports on the front-panel module that came preinstalled on the switch.
25
Page 38
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Figure 4-1. Switch connected to an End Node
The LED indicators for the port the end node is connected to are lit according to the capabilities of the NIC. If LED indicators are not illuminated after making a proper connection, check the PC’s LAN card, the cable, switch conditions, and connections.
The following LED indicator states are possible for an end node to switch connection:
• The 100 LED indicator comes ON for a 100 Mbps and stays OFF for 10 Mbps.
• The Link/Act LED indicator lights up upon hooking up a PC that is powered on.
Switch to Hub or Switch
These connections can be accomplished at any port in either straight-through cable or a crossover cable because the switch supports Auto-MDIX function.
• A 10BASE-T hub or switch can be connected to the Switch via a two-pair Category 3, 4 or 5 UTP/STP cable.
• A 100BASE-TX hub or switch can be connected to the Switch via a two-pair Category 5e UTP/STP cable.
26
Page 39
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Switch Stack Connections
Up to 8 DES-3326SR switches can be stacked, using the optional stacking module, into a switch stack that can then be configured and managed as a single unit. The Web-based Management agent of the Master Switch can configure and manage all of the switches in a switch stack − using a single IP address (the IP address of the Master Switch).
The Command Line Interface (CLI) can be also be used to manage and configure all of the switches in a switch stack − from the serial port on the master switch.
The CLI can also be used to configure and manage the switch stack via the TELNET protocol − using a single IP address (the IP address of the Master Switch).
The stacking ports are marked IN and OUT. The IEEE 1394 compliant cable must be connected from an IN port on one switch to an OUT port on the next switch in the stack. The last two switches (at the top and bottom of the stack) must also be connected from the IN port on one switch to the OUT port on the other switch. In this way, a loop is made such that all of the switches in the switch stack have the IN stacking port connected to another switch’s OUT stacking port.
An example stacking port interconnection is shown below:
27
Page 40
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Figure 4-. Switch Stack connections between optional stacking
modules
10BASE-T Device
For a 10BASE-T device, the Switch’s LED indicators should display the following:
• 100 LED speed indicator is OFF.
• Link/Act indicator is ON.
28
Page 41
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
100BASE-TX Device
For a 100BASE-TX device, the Switch’s LED indicators should display the following:
• 100 LED speed indicator is ON.
• Link/Act is ON.
29
Page 42
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
5
SWITCH MANAGEMENT
AND OPERATING
CONCEPTS
This chapter discusses many of the concepts and features used to manage the switch, as well as the concepts necessary for the user to understand the functioning of the switch. Further, this chapter explains many important points regarding these features.
Configuring the switch to implement these concepts and make use of its many features is discussed in detail in the next chapters.
Local Console Management
A local console is a terminal or a workstation running a terminal emulation program that is connected directly to the switch via the RS-232 serial console port on the front of the switch. A console connection is referred to as an ‘Out-of-Band’ connection, meaning that console is connected to the switch using a different circuit than that used for normal network communications. So, the console can be used to set up and manage the switch even if the network is down.
30
Page 43
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Local console management uses the terminal connection to operate the console program built-in to the switch. A network administrator can manage, control and monitor the switch from the console program.
The DES-3326SR contains a CPU, memory for data storage, flash memory for configuration data, operational programs, and SNMP agent firmware. These components allow the switch to be actively managed and monitored from either the console port or the network itself (out-of-band, or in-band).
Diagnostic (console) port (RS-232 DCE)
Out-of-band management requires connecting a terminal, such as a VT-100 or a PC running a terminal emulation program (such as HyperTerminal, which is automatically installed with Microsoft Windows) a to the RS-232 DCE console port of the Switch. Switch management using the RS-232 DCE console port is called Local Console Management to differentiate it from management performed via management platforms, such as D­View, HP OpenView, etc. Web-based Management describes management of the switch performed over the network (in­band) using the switch’s built-in Web-based management program. The operations to be performed and the facilities provided by these two built-in programs are identical.
The console port is set at the factory for the following configuration:
• Baud rate: 9,600
• Data width: 8 bits
• Parity: none
• Stop bits: 1
31
Page 44
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
• Flow Control none
• Make sure the terminal or PC you are using to make this
connection is configured to match these settings.
If you are having problems making this connection on a PC, make sure the emulation is set to VT-100. If you still don’t see anything, try hitting <Ctrl> + r to refresh the screen.
Managing Switch Stacks
The Switch is designed to be stacked in stacks of up to eight Switches, all managed as a single unit with a single IP address. The stack order is hardware-determined, that is, the unique MAC address of each Switch determines where the Switch stands in the stack order. This fact can be taken into account when you are placing the Switches in the equipment rack. Administrators may find it convenient to place the Switches in the rack in the same order they appear logically in the Switch stack. However, you also may prefer to override the auto-detect stack order feature if for example, you add Switches to a stack that is already in place. Regardless of the method used to determine Switch stack order, remember some important points:
• All management of all the Switches in the stack is done through the Master Switch
• It is recommended that the Master Switch be used to uplink to the Ethernet backbone
• If the link between any two switches fails or is disconnected, all of the switches in the stack will automatically reboot
• A switch stack has a single IP address − if the link to a given switch fails or is disconnected, that switch will reboot
32
Page 45
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
with the IP settings it had before becoming a member of the switch stack
• If a new Master is elected, all Switches in the stack will automatically reboot. This includes situations where the new Master is determined by MAC address, for example, if the original Master is removed from the stack.
• The Master Switch can be chosen automatically. Switch software auto-detects the MAC address of each Switch in the stack. The Switch with the lowest value MAC address is elected to function as the Master. The remaining Switches are ordered according to the relative value of their respective MAC addresses (see the following example).
Determining the Switch Stack Order
Using the auto stacking mode, five MAC addresses appear in the order listed in the table below:
Stack Order MAC Address
1(Master)
2
3 001122334453 4 001122334454 5 001122334455 6 Not in use 7 Not in use 8 Not in use
Table 5-1. Switch Stack Order − First
001122334451
001122334452
Now let us suppose you wish to add another Switch to this stack. The new Switch has a MAC address 001122334450. After rebooting all the Switches in the stack, the newly added Switch becomes the Master Switch. The new automatically determined stack order becomes
:
33
Page 46
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Stack Order MAC Address
1(added Switch)
2(original Master)
001122334450
001122334451
3 001122334452 4 001122334453 5 001122334454 6 001122334455 7 Not in use 8 Not in use
Table 5-2. Switch Stack Order − Second
You can override the automatic stack order selection to use the original Master Switch as the Master of the new stack (read Switch Stacking Information in Chapter 6 for information on how to override the stack order auto-detect function).
To override the automatic selection of the stack order you must attach the serial cable to the newly added Switch (MAC address
001122334450). Now you can reconfigure the stack to place the original Master Switch (MAC address 001122334451) again into the number 1 position and the newly added Switch into the number 6 position.
After reconfiguration and restarting the Switches, the new stack order becomes:
Stack Order MAC Address
1(original Master)
2
001122334451
001122334452
3 001122334453 4 001122334454 5 001122334455
34
Page 47
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
6 (added Switch) 001122334450
7 Not in use 8 Not in use
Table 5-3. Switch Stack Order − Final
Switch IP Address
Each Switch must be assigned its own IP Address, which is used for communication with an SNMP network manager or other TCP/IP application (for example BOOTP, TFTP). The switch’s default IP address is 10.90.90.90. You can change the default Switch IP Address to meet the specification of your networking address scheme.
The switch is also assigned a unique MAC address by the factory. This MAC address cannot be changed, and can be found from the initial boot console screen – shown below.
Figure 5-1. Console Boot Screen
35
Page 48
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
The switch’s MAC address can also be found from the console program under the Switch Information menu item, as shown below.
Setting an IP Address
The IP address for the switch must be set before it can be managed with the web-based manager. The switch IP address may be automatically set using BOOTP or DHCP protocols, in which case the actual address assigned to the switch must be known.
The IP address may alternatively be set using the Command Line Interface (CLI) over the console serial port as follows:
1. Starting at the command line prompt DES3326S4#
− enter the commands config ipif System ipaddress xxx.xxx.xxx.xxx/yyy.yyy.yyy.yyy.
Where the x’s represent the IP address to be assigned to the IP interface named System and the
y’s represent the corresponding subnet mask.
2. Alternatively, you can enter DES3326S4# − enter the commands config ipif system ipaddress xxx.xxx.xxx.xxx/z. Where the x’s represent the IP
address to be assigned to the IP interface named System and the z represents the corresponding number of subnets in CIDR notation.
Using this method, the switch can be assigned an IP address and subnet mask which can then be used to connect a management station to the switch’s web-based management agent.
36
Page 49
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Traps
Traps are messages that alert you of events that occur on the Switch. The events can be as serious as a reboot (someone accidentally turned OFF the Switch), or less serious like a port status change. The Switch generates traps and sends them to the network manager (trap recipient).
Trap recipients are special users of the network who are given certain rights and access in overseeing the maintenance of the network. Trap recipients will receive traps sent from the Switch; they must immediately take certain actions to avoid future failure or breakdown of the network.
You can also specify which network managers may receive traps from the Switch by entering a list of the IP addresses of authorized network managers. Up to four trap recipient IP addresses, and four corresponding SNMP community strings can be entered.
SNMP community strings function like passwords in that the community string entered for a given IP address must be used in the management station software, or a trap will be sent.
The following are trap types the switch can send to a trap recipient:
• Cold Start This trap signifies that the Switch has been
powered up and initialized such that software settings are reconfigured and hardware systems are rebooted. A cold start is different from a factory reset in that configuration settings saved to non-volatile RAM used to reconfigure the switch.
• Warm Start This trap signifies that the Switch has been
rebooted, however the POST (Power On Self-Test) is skipped.
37
Page 50
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
• Authentication Failure This trap signifies that someone
has tried to logon to the switch using an invalid SNMP community string. The switch automatically stores the source IP address of the unauthorized user.
• New Root This trap indicates that the Switch has become
the new root of the Spanning Tree, the trap is sent by the switch soon after its election as the new root. This implies that upon expiration of the Topology Change Timer the new root trap is sent out immediately after the Switch’s election as the new root.
• Topology Change (STP) A Topology Change trap is sent by
the Switch when any of its configured ports transitions from the Learning state to the Forwarding state, or from the Forwarding state to the Blocking state. The trap is not sent if a new root trap is sent for the same transition.
• Link Up This trap is sent whenever the link of a port
changes from link down to link up.
• Link Down This trap is sent whenever the link of a port
changes from link up to link down.
SNMP
The Simple Network Management Protocol (SNMP) is an OSI layer 7 (the application layer) protocol for remotely monitoring and configuring network devices. SNMP enables network management stations to read and modify the settings of gateways, routers, switches, and other network devices. SNMP can be used to perform many of the same functions as a directly connected console, or can be used within an integrated network management software package such as DView.
38
Page 51
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
SNMP performs the following functions:
• Sending and receiving SNMP packets through the IP protocol.
• Collecting information about the status and current configuration of network devices.
• Modifying the configuration of network devices.
The DES-3326SR has a software program called an ‘agent’ that processes SNMP requests, but the user program that makes the requests and collects the responses runs on a management station (a designated computer on the network). The SNMP agent and the user program both use the UDP/IP protocol to exchange packets.
Authentication
The authentication protocol ensures that both the router SNMP agent and the remote user SNMP application program discard packets from unauthorized users. Authentication is accomplished using ‘community strings’, which function like passwords. The remote user SNMP application and the router SNMP must use the same community string. SNMP community strings of up to 20 characters may be entered under the Remote Management Setup menu of the console program.
Traps
Traps are messages that alert network personnel of events that occur on the Switch. The events can be as serious as a reboot (someone accidentally turned OFF the Switch), or less serious like a port status change. The Switch generates traps and sends them to the trap recipient (or network manager).
39
Page 52
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Trap recipients are special users of the network who are given certain rights and access in overseeing the maintenance of the network. Trap recipients will receive traps sent from the Switch; they must immediately take certain actions to avoid future failure or breakdown of the network.
You can also specify which network managers may receive traps from the Switch by entering a list of the IP addresses of authorized network managers. Up to four trap recipient IP addresses, and four corresponding SNMP community strings can be entered.
SNMP community strings function like passwords in that the community string entered for a given IP address must be used in the management station software, or a trap will be sent.
The following are trap types the switch can send to a trap recipient:
• Cold Start This trap signifies that the Switch has been powered up and initialized such that software settings are reconfigured and hardware systems are rebooted. A cold start is different from a factory reset in that configuration settings saved to non-volatile RAM used to reconfigure the switch.
• Warm Start This trap signifies that the Switch has been rebooted, however the POST (Power On Self-Test) is skipped.
• Authentication Failure This trap signifies that someone has tried to logon to the switch using an invalid SNMP community string. The switch automatically stores the source IP address of the unauthorized user.
• Topology Change A Topology Change trap is sent by the Switch when any of its configured ports transitions from the Learning state to the Forwarding state, or from the Forwarding state to the Blocking state. The trap is not sent if a new root trap is sent for the same transition.
• Link Change Event This trap is sent whenever the link of a port changes from link up to link down or from link down to link up.
• Port Partition This trap is sent whenever the port state enters the partition mode (or automatic partitioning, port disable) when more than thirty-two collisions occur while transmitting at 10Mbps or more than sixty-four collisions occur while transmitting at 100Mbps.
40
Page 53
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
• Broadcast\Multicast Storm This trap is sent whenever the port reaches the threshold (in packets per second) set globally for the switch. Counters are maintained for each port, and separate counters are maintained for broadcast and multicast packets. The switch’s default setting is 128 kpps for both broadcast and multicast packets.
MIBs
Management and counter information are stored in the Switch in the Management Information Base (MIB). The Switch uses the standard MIB-II Management Information Base module. Consequently, values for MIB objects can be retrieved from any SNMP-based network management software. In addition to the standard MIB-II, the Switch also supports its own proprietary enterprise MIB as an extended Management Information Base. These MIBs may also be retrieved by specifying the MIB’s Object-Identity (OID) at the network manager. MIB values can be either read-only or read-write.
Read-only MIBs variables can be either constants that are programmed into the Switch, or variables that change while the Switch is in operation. Examples of read-only constants are the number of port and type of ports. Examples of read-only variables are the statistics counters such as the number of errors that have occurred, or how many kilobytes of data have been received and forwarded through a port.
Read-write MIBs are variables usually related to user­customized configurations. Examples of these are the Switch’s IP Address, Spanning Tree Algorithm parameters, and port status.
If you use a third-party vendors’ SNMP software to manage the Switch, a diskette listing the Switch’s propriety enterprise MIBs can be obtained by request. If your software provides functions to browse or modify MIBs, you can also get the MIB values and change them (if the MIBs’ attributes permit the write
41
Page 54
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
operation). This process however can be quite involved, since you must know the MIB OIDs and retrieve them one by one.
Packet Forwarding
The Switch enters the relationship between destination MAC or IP addresses and the Ethernet port or gateway router the destination resides on into its forwarding table. This information is then used to forward packets. This reduces the traffic congestion on the network, because packets, instead of being transmitted to all ports, are transmitted to the destination port only. Example: if Port 1 receives a packet destined for a station on Port 2, the Switch transmits that packet through Port 2 only, and transmits nothing through the other ports. This process is referred to as ‘learning’ the network topology.
MAC Address Aging Time
The Aging Time affects the learning process of the Switch. Dynamic forwarding table entries, which are made up of the source MAC addresses and their associated port numbers, are deleted from the table if they are not accessed within the aging time.
The aging time can be from 10 to 1,000,000 seconds with a default value of 300 seconds. A very long aging time can result in dynamic forwarding table entries that are out-of-date or no longer exist. This may cause incorrect packet forwarding decisions by the switch.
If the Aging Time is too short however, many entries may be aged out too soon. This will result in a high percentage of received packets whose source addresses cannot be found in the forwarding table, in which case the switch will broadcast
42
Page 55
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
the packet to all ports, negating many of the benefits of having a switch.
Static forwarding entries are not affected by the aging time.
Filtering
The switch uses a filtering database to segment the network and control communication between segments. It can also filter packets off the network for intrusion control. Static filtering entries can be made by MAC Address or IP Address filtering.
Each port on the switch is a unique collision domain and the switch filters (discards) packets whose destination lies on the same port as where it originated. This keeps local packets from disrupting communications on other parts of the network.
For intrusion control, whenever a switch encounters a packet originating from or destined to a MAC address or an IP Address entered into the filter table, the switch will discard the packet.
Some filtering is done automatically by the switch:
• Dynamic filtering – automatic learning and aging of MAC addresses and their location on the network. Filtering occurs to keep local traffic confined to its segment.
• Filtering done by the Spanning Tree Protocol, which can filter packets based on topology, making sure that signal loops don’t occur.
• Filtering done for VLAN integrity. Packets from a member of a VLAN (VLAN 2, for example) destined for a device on another VLAN (VLAN 3) will be filtered.
Some filtering requires the manual entry of information into a filtering table:
43
Page 56
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
• MAC address filtering – the manual entry of specific MAC addresses to be filtered from the network. Packets sent from one manually entered MAC address can be filtered from the network. The entry may be specified as either a source, a destination, or both.
• IP address filtering – the manual entry of specific IP addresses to be filtered from the network (switch must be in IP Routing mode). Packets sent from one manually entered IP address to another can be filtered from the network. The entry may specified as either a source, a destination, or both (switch must be in IP Routing mode).
802.1w Rapid Spanning Tree
The Switch implements two versions of the Spanning Tree Protocol, the Rapid Spanning Tree Protocol (RSTP) as defined by the IEE 802.1w specification and a version compatible with the IEEE 802.1d STP. RSTP can operate with legacy equipment implementing IEEE 802.1d, however the advantages of using RSTP will be lost.
The IEEE 802.1w Rapid Spanning Tree Protocol (RSTP) evolved from the 802.1d STP standard. RSTP was developed in order to overcome some limitations of STP that impede the function of some recent switching innovations, in particular, certain Layer 3 function that are increasingly handled by Ethernet switches.
44
Page 57
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
The basic function and much of the terminology is the same as STP. Most of the settings configured for STP are also used for RSTP. This section introduces some new Spanning Tree concepts and illustrates the main differences between the two protocols.
Port Transition States
An essential difference between the two protocols is in the way ports transition to a forwarding state and the in the way this transition relates to the role of the port (forwarding or not forwarding) in the topology. RSTP combines the transition states disabled, blocking and listening used in 802.1d and creates a single state Discarding. In either case, ports do not forward packets; in the STP port transition states disabled, blocking or listening or in the RSTP port state discarding there is no functional difference, the port is not active in the network topology. Table 5-7 below compares how the two protocols differ regarding the port state transition.
Both protocols calculate a stable topology in the same way. Every segment will have a single path to the root bridge. All bridges listen for BPDU packets. However, BPDU packets are sent more frequently – with every Hello packet. BPDU packets are sent even if a BPDU packet was not received. Therefore, each link between bridges are sensitive to the status of the link. Ultimately this difference results faster detection of failed links, and thus faster topology adjustment. A drawback of
802.1d is this absence of immediate feedback from adjacent bridges.
802.1d STP 802.1w RSTP Forwarding? Learning?
Disabled Discarding No No
Blocking Discarding No No
45
Page 58
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Listening Discarding No No
Learning Learning No Yes
Forwarding Forwarding Yes Yes
Table 5-5. Comparing Port States
RSTP is capable of more rapid transition to a forwarding state – it no longer relies on timer configurations – RSTP compliant bridges are sensitive to feedback from other RSTP compliant bridge links. Ports do not need to wait for the topology to stabilize before transitioning to a forwarding state. In order to allow this rapid transition, the protocol introduces two new variables: the edge port and the point-to-point (P2P) port.
Edge Port
The edge port is a configurable designation used for a port that is directly connected to a segment where a loop cannot be created. An example would be a port connected directly to a single workstation. Ports that are designated as edge ports, transition to a forwarding state immediately without going through the listening and learning states. An edge port loses its status if it receives a BPDU packet, immediately becoming a normal spanning tree port.
P2P Port
A P2P port is also capable of rapid transition. P2P ports may be used to connect to other bridges. Under RSTP, all ports operating in full-duplex mode are considered to be P2P ports, unless manually overridden through configuration.
46
Page 59
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
802.1d/802.1w Compatibility
RSTP can interoperate with legacy equipment and is capable of automatically adjusting BPDU packets to 802.1d format when necessary. However, any segment using 802.1 STP will not benefit from the rapid transition and rapid topology change detection of RSTP. The protocol also provides for a variable used for migration in the event that legacy equipment on a segment is updated to use RSTP.
Link Aggregation
Link aggregation is used to combine a number of ports together to make a single high-bandwidth data pipeline. The participating parts are called members of a link aggregation group, with one port designated as the master port of the group. Since all members of the link aggregation group must be configured to operate in the same manner, the configuration of the master port is applied to all members of the link aggregation group. Thus, when configuring the ports in a link aggregation group, you only need to configure the master port.
The DES-3326SR supports link aggregation groups, which may include from 2 to 8 switch ports each, except for a Gigabit link aggregation group which consists of the 2 (optional) Gigabit Ethernet ports of the front panel. These ports are the two 1000BASE-SX, -LX, 10/100BASE –TX or GBIC ports contained in a front-panel mounted module.
47
Page 60
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Figure 5-5. Link Aggregation Group
Data transmitted to a specific host (destination address) will always be transmitted over the same port in a link aggregation group. This allows packets in a data stream to arrive in the same order they were sent. A aggregated link connection can be made with any other switch that maintains host-to-host data streams over a single link aggregate port. Switches that use a load-balancing scheme that sends the packets of a host-to-host data stream over multiple link aggregation ports cannot have a aggregated connection with the DES-3326SR switch.
48
Page 61
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
VLANs
A VLAN is a collection of end nodes grouped by logic rather than physical location. End nodes that frequently communicate with each other are assigned to the same VLAN, regardless of where they are located physically on the network. Logically, a VLAN can be equated to a broadcast domain, because broadcast packets are forwarded only to members of the VLAN on which the broadcast was initiated.
Notes About VLANs on the DES-3326SR
1. The DES-3326SR supports IEEE 802.1Q VLANs. The port untagging function can be used to remove the
802.1Q tag from packet headers to maintain compatibility with devices that are tag-unaware (that is, network devices that do not support IEEE 802.1Q VLANs or tagging).
2. The switch’s default is to assign all ports to a single
802.1Q VLAN named
3. The switch allows the assignment of an IP interface to each VLAN, in IP Routing mode. The VLANs must be configured before setting up the IP interfaces
4. A VLAN that is not assigned an IP interface will behave as a layer 2 VLAN – and IP routing, by the switch, will not be possible to this VLAN regardless of the switch’s operating mode.
IEEE 802.1Q VLANs
Some relevant terms:
49
Page 62
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Tagging - The act of putting 802.1Q VLAN information into the header of a packet.
Untagging - The act of stripping 802.1Q VLAN information out of the packet header.
Ingress port - A port on a switch where packets are flowing into the switch and VLAN decisions must be made.
Egress port - A port on a switch where packets are flowing out of the switch, either to another switch or to an end station, and tagging decisions must be made.
IEEE 802.1Q (tagged) VLANs are implemented on the DES­3326SR Layer 3 switch. 802.1Q VLANs require tagging, which enables the VLANs to span an entire network (assuming all switches on the network are IEEE 802.1Q-compliant).
Any port can be configured as either tagging or untagging. The untagging feature of IEEE 802.1Q VLANs allow VLANs to work with legacy switches that don’t recognize VLAN tags in packet headers. The tagging feature allows VLANs to span multiple
802.1Q-compliant switches through a single physical connection and allows Spanning Tree to be enabled on all ports and work normally.
802.1Q VLAN Packet Forwarding
Packet forwarding decisions are made based upon the following three types of rules:
• Ingress rules – rules relevant to the classification of received frames belonging to a VLAN.
• Forwarding rules between ports – decides filter or forward the packet
50
Page 63
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
• Egress rules – determines if the packet must be sent tagged or untagged.
Figure 5-6. IEEE 802.1Q Packet Forwarding
802.1Q VLAN Tags
The figure below shows the 802.1Q VLAN tag. There are four additional octets inserted after the source MAC address. Their presence is indicated by a value of 0x8100 in the EtherType field. When a packet’s EtherType field is equal to 0x8100, the packet carries the IEEE 802.1Q/802.1p tag. The tag is contained in the following two octets and consists of 3 bits or user priority, 1 bit of Canonical Format Identifier (CFI – used for encapsulating Token Ring packets so they can be carried across Ethernet backbones) and 12 bits of VLAN ID (VID). The 3 bits of user priority are used by 802.1p. The VID is the VLAN
51
Page 64
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
identifier and is used by the 802.1Q standard. Because the VID is 12 bits long, 4094 unique VLANs can be identified.
The tag is inserted into the packet header making the entire packet longer by 4 octets. All of the information contained in the packet originally is retained.
Figure 5-7. IEEE 802.1Q Tag
The EtherType and VLAN ID are inserted after the MAC source address, but before the original EtherType/Length or Logical Link Control. Because the packet is now a bit longer than it was originally, the Cyclic Redundancy Check (CRC) must be recalculated.
52
Page 65
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Figure 5-8. Adding an IEEE 802.1Q Tag
Port VLAN ID
Packets that are tagged (are carrying the 802.1Q VID information) can be transmitted from one 802.1Q compliant network device to another with the VLAN information intact. This allows 802.1Q VLANs to span network devices (and indeed, the entire network – if all network devices are 802.1Q compliant).
Unfortunately, not all network devices are 802.1Q compliant. These devices are referred to as tag-unaware. 802.1Q devices are referred to as tag-aware.
Prior to the adoption 802.1Q VLANs, port-based and MAC­based VLANs were in common use. These VLANs relied upon a Port VLAN ID (PVID) to forward packets. A packet received on a given port would be assigned that port’s PVID and then be forwarded to the port that corresponded to the packet’s destination address (found in the switch’s forwarding table). If the PVID of the port that received the packet is different from the PVID of the port that is to transmit the packet, the switch will drop the packet.
53
Page 66
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Within the switch, different PVIDs mean different VLANs. (remember that two VLANs cannot communicate without an external router). So, VLAN identification based upon the PVIDs cannot create VLANs that extend outside a given switch (or switch stack).
Every physical port on a switch has a PVID. 802.1Q ports are also assigned a PVID, for use within the switch. If no VLANs are defined on the switch, all ports are then assigned to a default VLAN with a PVID equal to 1. Untagged packets are assigned the PVID of the port on which they were received. Forwarding decisions are based upon this PVID, in so far as VLANs are concerned. Tagged packets are forwarded according to the VID contained within the tag. Tagged packets are also assigned a PVID, but the PVID is not used to make packet forwarding decisions, the VID is.
Tag-aware switches must keep a table to relate PVIDs within the switch to VIDs on the network. The switch will compare the VID of a packet to be transmitted to the VID of the port that is to transmit the packet. If the two VIDs are different, the switch will drop the packet. Because of the existence of the PVID for untagged packets and the VID for tagged packets, tag­aware and tag-unaware network devices can coexist on the same network.
A switch port can have only one PVID, but can have as many VIDs as the switch has memory in its VLAN table to store them.
Because some devices on a network may be tag-unaware, a decision must be made at each port on a tag-aware device before packets are transmitted – should the packet to be transmitted have a tag or not? If the transmitting port is connected to a tag-unaware device, the packet should be untagged. If the transmitting port is connected to a tag-aware device, the packet should be tagged.
54
Page 67
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Tagging and Untagging
Every port on an 802.1Q compliant switch can be configured as tagging or untagging.
Ports with tagging enabled will put the VID number, priority and other VLAN information into the header of all packets that flow into and out of it. If a packet has previously been tagged, the port will not alter the packet, thus keeping the VLAN information intact. The VLAN information in the tag can then be used by other 802.1Q compliant devices on the network to make packet forwarding decisions.
Ports with untagging enabled will strip the 802.1Q tag from all packets that flow into and out of those ports. If the packet doesn’t have an 802.1Q VLAN tag, the port will not alter the packet. Thus, all packets received by and forwarded by an untagging port will have no 802.1Q VLAN information. (Remember that the PVID is only used internally within the switch). Untagging is used to send packets from an 802.1Q­compliant network device to a non-compliant network device.
Ingress Filtering
A port on a switch where packets are flowing into the switch and VLAN decisions must be made is referred to as an ingress port. If ingress filtering is enabled for a port, the switch will examine the VLAN information in the packet header (if present) and decide whether or not to forward the packet.
If the packet is tagged with VLAN information, the ingress port will first determine if the ingress port itself is a member of the tagged VLAN. If it is not, the packet will be dropped. If the ingress port is a member of the 802.1Q VLAN, the switch then determines if the destination port is a member of the 802.1Q VLAN. If it is not, the packet is dropped. If the destination port is a member of the 802.1Q VLAN, the packet is forwarded
55
Page 68
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
and the destination port transmits it to its attached network segment.
If the packet is not tagged with VLAN information, the ingress port will tag the packet with its own PVID as a VID (if the port is a tagging port). The switch then determines if the destination port is a member of the same VLAN (has the same VID) as the ingress port. If it does not, the packet is dropped. If it has the same VID, the packet is forwarded and the destination port transmits it on its attached network segment.
This process is referred to as ingress filtering and is used to conserve bandwidth within the switch by dropping packets that are not on the same VLAN as the ingress port at the point of reception. This eliminates the subsequent processing of packets that will just be dropped by the destination port.
VLANs in Layer 2 Only Mode
The switch initially configures one VLAN, VID = 1, called the DEFAULT_VLAN. The factory default setting assigns all ports on the switch to the DEFAULT_VLAN.
Packets cannot cross VLANs if the switch is in Layer 2 Only mode. If a member of one VLAN wants to connect to another VLAN, the link must be through an external router.
When the switch is in Layer 2 Only mode, 802.1Q VLANs are supported.
If no VLANs are configured on the switch and the switch is in Layer 2 Only mode, then all packets will be forwarded to any destination port. Packets with unknown source addresses will be flooded to all ports. Broadcast and multicast packets will also be flooded to all ports.
56
Page 69
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
A VLAN that does not have a corresponding IP interface defined for it, will function as a Layer 2 Only VLAN – regardless of the Switch Operation mode.
Layer 3-Based VLANs
Layer 3-based VLANs use network-layer addresses (subnet address for TCP/IP) to determine VLAN membership. These VLANs are based on layer 3 information, but this does not constitute a ‘routing’ function.
The DES-3326SR allows an IP subnet to be configured for each
802.1Q VLAN that exists on the switch.
Even though a switch inspects a packet’s IP address to determine VLAN membership, no route calculation is performed, the RIP protocol is not employed, and packets traversing the switch are bridged using the Spanning Tree algorithm.
A switch that implements layer 3 (or ‘subnet’) VLANs without performing any routing function between these VLANs is referred to as performing ‘IP Switching’.
IP Addressing and Subnetting
This section gives basic information needed to configure your Layer 3 switch for IP routing. The information includes how IP addresses are broken down and how subnetting works. You will learn how to assign each interface on the router an IP address with a unique subnet.
Definitions
• IP Address – the unique number ID assigned to each host or interface on a network. IP addresses have the form xxx.xxx.xxx.xxx.
57
Page 70
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
• Subnet – a portion of a network sharing a particular network address.
• Subnet mask – a 32-bit number used to describe which portion of a Network Address refers to the subnet and which portion refers to the host. Subnet masks have the form xxx.xxx.xxx.xxx.
• Interface – a network connection
• IP Interface – another name for subnet.
• Network Address – the resulting 32-bit number from a
bitwise logical AND operation performed between an IP address and a subnet mask.
• Subnet Address – another name for network address.
IP Addresses
The Internet Protocol (IP) was designed for routing data between network sites. Later, it was adapted for routing between networks (referred to as “subnets”) within a site. The IP defines a way of generating a unique number that can be assigned each network in the internet and each of the computers on each of those networks. This number is called the IP address.
IP addresses use a “dotted decimal” notation. Here are some examples of IP addresses written in this format:
1. 210.202.204.205
2. 189.21.241.56
3. 125.87.0.1
This allows IP address to be written in a string of 4 decimal (base 10) numbers. Computers can only understand binary (base 2) numbers, and these binary numbers are usually grouped together in bytes, or eight bits. (A bit is a binary digit – either a “1” or a “0”). The dots (periods) simply make the IP
58
Page 71
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
address easier to read. A computer sees an IP address not as four decimal numbers, but as a long string of binary digits (32 binary digits or 32 bits, IP addresses are 32-bit addresses).
The three IP addresses in the example above, written in binary form are:
1. 11010010.11001010.11001100.11001101
2. 10111101.00010101.11110001.00111000
3. 01111101.01010111.00000000.00000001
The dots are included to make the numbers easier to read.
Eight binary bits are called a ‘byte’ or an ‘octet’. An octet can represent any decimal value between ‘0’ (00000000) and ‘255’ (11111111). IP addresses, represented in decimal form, are four numbers whose value is between ‘0’ to ‘255’. The total range of IP addresses are then:
Lowest possible IP address - 0.0.0.0 Highest possible IP address - 255.255.255.255
To convert decimal numbers to 8-bit binary numbers (and vice­versa), you can use the following chart:
7
Binary Octet Digit 2
26 25 24 23 22 21 2
0
Decimal Equivalent 128 64 32 16 8 4 2 1
Binary Number
1 1 1 1 1 1 1 1
128+64+32+16+8+4+2+1=
255
Table 5-8. Binary to Decimal Conversion
Each digit in an 8-bit binary number (an octet) represents a power of two. The left-most digit represents 2 raised to the 7 power (2x2x2x2x2x2x2=128) while the right-most digit
59
th
Page 72
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
represents 2 raised to the 0th power (any number raised to the
th
0
power is equal to one, by definition).
IP addresses actually consist of two parts, one identifying the network and one identifying the destination (node) within the network.
The IP address discussed above is one part and a second number called the Subnet mask is the other part. To make this a bit more confusing, the subnet mask has the same numerical form as an IP address.
Address Classes
Address classes refer to the range of numbers in the subnet mask. Grouping the subnet masks into classes makes the task of dividing a network into subnets a bit easier.
There are 5 address classes. The first 4 bits in the IP address determine which class the IP address falls in.
• Class A addresses begin with 0xxx, or 1 to 126 decimal.
• Class B addresses begin with 10xx, or 128 to 191 decimal.
• Class C addresses begin with 110x, or 192 to 223 decimal.
• Class D addresses begin with 1110, or 224 to 239 decimal.
• Class E addresses begin with 1111, or 240 to 254 decimal.
Addresses beginning with 01111111, or 127 decimal, are reserved. They are used for internal testing on a local machine (called loopback). The address 127.0.0.1 can always be pinged from a local node because it forms a loopback and points back to the same node.
Class D addresses are reserved for multicasting.
Class E Addresses are reserved for future use. They are not used for node addresses.
60
Page 73
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
The part of the IP address that belongs to the network is the part that is ‘hidden’ by the ‘1’s in the subnet mask. This can be seen below:
• Class A NETWORK.node.node.node
• Class B NETWORK.NETWORK.node.node
• Class C NETWORK.NETWORK.NETWORK.node
For example, the IP address 10.42.73.210 is a Class A address, so the Network part of the address (called the Network Address) is the first octet (10.x.x.x). The node part of the address is the last three octets (x.42.73.210).
To specify the network address for a given IP address, the node part is set to all “0”s. In our example, 10.0.0.0 specifies the network address for 10.42.73.210. When the node part is set to all “1”s, the address specifies a broadcast address. So,
10.255.255.255 is the broadcast address for the network
10.0.0.0.
Subnet Masking
A subnet mask can be applied to an IP address to identify the network and the node parts of the address. A bitwise logical AND operation between the IP address and the subnet mask results in the Network Address.
For example:
00001010.00101010.01001001.11010010 10.42.73.210 Class A IP address
11111111.00000000.00000000.00000000 255.0.0.0 Class A Subnet Mask
00001010.00000000.00000000.00000000 10.0.0.0 Network Address The Default subnet masks are:
61
Page 74
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
• Class A – 11111111.00000000.00000000.00000000
255.0.0.0
• Class B – 11111111.11111111.00000000.00000000
255.255.0.0
• Class C – 1111111.11111111.11111111.00000000
255.255.255.0
Additional bits can be added to the default subnet mask for a given Class to further subnet a network. When a bitwise logical AND operation is performed between the subnet mask and the IP address, the result defines the Subnet Address.
Some restrictions apply to subnet addresses. Addresses of all “0”s and all “1”s are reserved for the local network (when a host does not know it’s network address) and for all hosts on the network (the broadcast address). This also applies to subnets. A subnet address cannot be all “0”s or all “1”s. A 1-bit subnet mask is also not allowed.
Calculating the Number of Subnets and Nodes
To calculate the number of subnets and nodes, use the formula
n
(2
– 2) where n = the number of bits in either the subnet mask or the node portion of the IP address. Multiplying the number of subnets by the number of nodes available per subnet gives the total number of nodes for the entire network.
Example
00001010.00101010.01001001.11010010 10.42.73.210 Class A IP address
11111111.11100000.00000000.00000000 255.224.0.0 Subnet Mask
00001010.00100000.00000000.00000000 10.32.0.0 Network Address
00001010.00101010.11111111.11111111 10.32.255.255 Broadcast Address
62
Page 75
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
This example uses an 11-bit subnet mask. (There are 3 additional bits added to the default Class A subnet mask). So the number of subnets is:
3
2
– 2 = 8 – 2 = 6
Subnets of all “0”s and all “1”s are not allowed, so 2 subnets are subtracted from the total.
The number of bits used in the node part of the address is 24 – 3 = 21 bits, so the total number of nodes is:
2
21
– 2 = 2,097,152 – 2 = 2,097,150
Multiplying the number of subnets times the number of nodes gives 12,582,900 possible nodes.
Note that this is less than the 16,777,214 possible nodes that an unsubnetted class A network would have.
Subnetting reduces the number of possible nodes for a given network, but increases the segmentation of the network.
Classless Inter-Domain Routing – CIDR
Under CIDR, the subnet mask notation is reduced to a simplified shorthand. Instead of specifying all of the bits of the subnet mask, it is simply listed as the number of contiguous “1”s (bits) in the network portion of the address. Look at the subnet mask of the above example in binary -
11111111.11100000.00000000.00000000 – and you can see that there are 11 “1”s or 11 bits used to mask the network address from the node address. Written in CIDR notation this becomes:
10.32.0.0/11
63
Page 76
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
# of
Subnet Mask CID
Bits
2 255.192.0.0 /10 2 4194302 8388604
3 255.224.0.0 /11 6 2097150 12582900
4 255.240.0.0 /12 14 1048574 14680036
5 255.248.0.0 /13 30 524286 15728580 6 255.252.0.0 /14 62 262142 16252804 7 255.254.0.0 /15 126 131070 16514820 8 255.255.0.0 /16 254 65534 16645636 9 255.255.128.0 /17 510 32766 16710660 10 255.255.192.0 /18 1022 16382 16742404 11 255.255.224.0 /19 2046 8190 16756740 12 255.255.240.0 /20 4094 4094 16760836 13 255.255.248.0 /21 8190 2046 16756740 14 255.255.252.0 /22 16382 1022 16742404 15 255.255.254.0 /23 32766 510 16710660 16 255.255.255.0 /24 65534 254 16645636 17 255.255.255.1
28
18 255.255.255.1
92
19 255.255.255.2
24
20 255.255.255.2
40
21 255.255.255.2
48
22 255.255.255.2
52
R Nota tion
/25 131070 126 16514820
/26 262142 62 16252804
/27 525286 30 15728580
/28 1048574 14 14680036
/29 2097150 6 12582900
/30 4194302 2 8388604
# of Subnets
# of Hosts
Total Hosts
Table 5-9. Class A Subnet Masks
64
Page 77
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
# of
Subnet Mask CIDR Bits 2 255.255.192 /18 2 16382 32764 3 255.255.224.0 /19 6 8190 49140 4 255.255.240.0 /20 14 4094 57316 5 255.255.248.0 /21 30 2046 61380 6 255.255.252.0 /22 62 1022 63364 7 255.255.254.0 /23 126 510 64260 8 255.255.255.0 /24 254 254 64516 9 255.255.255.128 /25 510 126 64260 10 255.255.255.192 /26 1022 62 63364 11 255.255.255.224 /27 2046 30 61380 12 255.255.255.240 /28 4094 14 57316 13 255.255.255.248 /29 8190 6 49140 14 255.255.255.252 /30 16382 2 32764
Notation
# of Subnets
# of Hosts
Total Hosts
Table 5-10. Class B Subnet Masks
# of
Subnet Mask CIDR Bits 2 255.255.255.192 /26 2 62 124 3 255.255.255.224 /27 6 30 180 4 255.255.255.240 /28 14 14 196 5 255.255.255.248 /29 30 6 180 6 255.255.255.252 /30 62 2 124
Notation
# of Subnets
# of Hosts
Total Hosts
Table 5-11. Class C Subnet Masks
Setting up IP Interfaces
The Layer 3 switch allows ranges of IP addresses (OSI layer 3) to be assigned to VLANs (OSI layer 2). Each VLAN must be
65
Page 78
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
configured prior to setting up the corresponding IP interface. An IP addressing scheme must then be established, and implemented when the IP interfaces are set up on the switch.
An example is presented below:
VLAN Name VID Switch Ports
System (default) 1 5, 6, 7, 8, 21, 22, 23, 24
Engineering 2 9, 10, 11, 12
Marketing 3 13, 14, 15, 16
Finance 4 17, 18, 19, 20
Sales 5 1, 2, 3, 4
Backbone 6 25, 26
Table 5-12. VLAN Example – Assigned Ports
In this case, 6 IP interfaces are required, so a CIDR notation of
10.32.0.0/11 (or a 11-bit) addressing scheme will work. This addressing scheme will give a subnet mask of
11111111.11100000.00000000.00000000 (binary) or
255.224.0.0 (decimal).
Using a 10.xxx.xxx.xxx IP address notation, the above example would give 6 network addresses and 6 subnets.
Any IP address from the allowed range of IP addresses for each subnet can be chosen as an IP address for an IP interface on the switch.
For this example, we have chosen the next IP address above the network address:
66
Page 79
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
VLAN Name VID Network Address IP Address
System (default) 1 10.32.0.0 10.32.0.1
Engineering 2 10.64.0.0 10.64.0.1
Marketing 3 10.96.0.0 10.96.0.1
Finance 4 10.128.0.0 10.128.0.1
Sales 5 10.160.0.0 10.160.0.1
Backbone 6 10.192.0.0 10.192.0.1
Table 5-13. VLAN Example – Assigned IP Addresses
The 6 IP interfaces, each with an IP address (listed in the table above), and a subnet mask of 255.224.0.0 can be entered into the Setup IP Interface menu.
A switch that implements layer 3 (or ‘subnet’) VLANs without performing any routing function between these VLANs is referred to as performing ‘IP Switching’.
Internet Protocols
This is a brief introduction to the suite of Internet Protocols frequently referred to as TCP/IP. It is intended to give the reader a reasonable understanding of the available facilities and some familiarity with terminology. It is not intended to be a complete description.
Protocol Layering
The Internet Protocol (IP) divides the tasks necessary to route and forward packets across networks by using a layered
67
Page 80
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
approach. Each layer has clearly defined tasks, protocol, and interfaces for communicating with adjacent layers, but the exact way these tasks are accomplished is left to individual software designers. The Open Systems Interconnect (OSI) seven-layer model has been adopted as the reference for the description of modern networking, including the Internet.
A diagram of the OSI model is shown below (note that this is not a complete listing of the protocols contained within each layer of the model):
Figure 5-8. OSI Seven Layer Network Model
Each layer is a distinct set of programs executing a distinct set of protocols designed to accomplish some necessary tasks.. They are separated from the other layers within the same system or network, but must communicate and interoperate. This requires very well-defined and well-known methods for transferring messages and data. This is accomplished through the protocol stack.
68
Page 81
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Protocol layering as simply a tool for visualizing the organization of the necessary software and hardware in a network. In this view, Layer 2 represents switching and Layer 3 represents routing. Protocol layering is actually a set of guidelines used in writing programs and designing hardware that delegate network functions and allow the layers to communicate. How these layers communicate within a stack (for example, within a given computer) is left to the operating system programmers.
Figure 5-9. The Protocol Stack
Between two protocol stacks, members of the same layer are known as peers and communicate by well-known (open and published) protocols. Within a protocol stack, adjacent
69
Page 82
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
layers communicate by an internal interface. This interface is usually not publicly documented and is frequently proprietary. It has some of the same characteristics of a protocol and two stacks from the same software vendor may communicate in the same way. Two stacks from different software vendors (or different products from the same vendor) may communicate in completely different ways. As long as peers can communicate and interoperate, this has no impact on the functioning of the network.
The communication between layers within a given protocol stack can be both different from a second stack and proprietary, but communication between peers on the same OSI layer is open and consistent.
A brief description of the most commonly used functional layers is helpful to understand the scope of how protocol layering works.
Layer 1
This is referred to as the physical layer. It handles the electrical connections and signaling required to make a physical link from one point in the network to another. It is on this layer that the unique Media Access Control (MAC) address is defined.
Layer 2
This layer, commonly called the switching layer, allows end station addressing and the establishment of connections between them.
Layer 2 switching forwards packets based on the unique MAC address of each end station and offers high-performance, dedicated-bandwidth of Fast or Gigibit Ethernet within the network.
70
Page 83
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Layer 2 does not ordinarily extend beyond the intranet. To connect to the Internet usually requires a router and a modem or other device to connect to an Internet Service Provider’s WAN. These are Layer 3 functions.
Layer 3
Commonly referred to as the routing layer, this layer provides logical partitioning of networks (subnetting), scalability, security, and Quality of Service (QoS).
The backbone of the Internet is built using Layer 3 functions. IP is the premier Layer 3 protocol.
IP is itself, only one protocol in the IP protocol suite. More extensive capabilities are found in the other protocols of the IP suite. For example; the Domain Name System (DNS) associates IP addresses with text names, the Dynamic Host Configuration Protocol (DCHP) eases the administration of IP addresses, and routing protocols such as the Routing Information Protocol (RIP), the Open Shortest Path First (OSPF), and the Border Gateway Protocol (BGP) enable Layer 3 devices to direct data traffic to the intended destination. IP security allows for authentication and encryption. IP not only allows for user-to­user communication, but also for transmission from point-to­multipoint (known as IP multicasting).
Layer 4
This layer, known as the transport layer, establishes the communication path between user applications and the network infrastructure and defines the method of communicating. TCP and UDP are well-known protocols in the transport layer. TCP is a “connection-oriented” protocol, and requires the establishment of parameters for transmission prior to the exchange of data. Web technology is based on TCP. UDP is “connectionless” and requires no connection setup.
71
Page 84
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
This is important for multicast traffic, which cannot tolerate the overhead and latency of TCP. TCP and UDP also differ in the amount of error recovery provided and whether or not it is visible to the user application. Both TCP and UDP are layered on IP, which has minimal error recovery and detection. TCP forces retransmission of data that was lost by the lower layers, UDP does not.
Layer 7
This layer, known as the application layer, provides access to either the end user application software such as a database. Users communicate with the application, which in turn delivers data to the transport layer. Applications do not usually communicate directly with lower layers They are written to use a specific communication library, like the popular WinSock library.
Software developers must decide what type of transport mechanism is necessary. For example, Web access requires reliable, error-free access and would demand TCP, Multimedia, on the other hand, requires low overhead and latency and commonly uses UDP.
TCP/IP
The TCP/IP protocol suite is a set of protocols that allow computers to share resources across a network. TCP and IP are only two of the Internet suite of protocols, but they are the best known and it has become common to refer the entire family of Internet protocols as TCP/IP.
TCP/IP is a layered set of protocols. An example, such as sending e-mail, can illustrate this. There is first a protocol for sending and receiving e-mail. This protocol defines a set of commands to identify the sender, the recipient, and the content of the e-mail. The e-mail protocol will not handle the actual
72
Page 85
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
communication between the two computers, this is done by TCP/IP. TCP/IP handles the actual sending and receiving of the packets that make up the e-mail exchange.
TCP makes sure the e-mail commands and messages are received by the appropriate computers. It keeps track of what is sent and what is received, and retransmits any packets that are lost or dropped. TCP also handles the division of large messages into several Ethernet packets, and makes sure these packets are received and reassembled in the correct order.
Because these functions are required by a large number of applications, they are grouped into a single protocol, rather than being the part of the specifications for just sending e-mail. TCP is then a library of routines that application software can use when reliable network communications are required.
IP is also a library of routines, but with a more general set of functions. IP handles the routing of packets from the source to the destination. This may require the packets to traverse many different networks. IP can route packets through the necessary gateways and provides the functions required for any user on one network to communicate with any user on another connected network.
The communication interface between TCP and IP is relatively simple. When IP received a packet, it does not know how this packet is related to others it has sent (or received) or even which connection the packet is part of. IP only knows the address of the source and the destination of the packet, and it makes its best effort to deliver the packet to its destination.
The information required for IP to do its job is contained in a series of octets added to the beginning of the packet called headers. A header contains a few octets of data added to the packet by the protocol in order to keep track of it.
Other protocols on other network devices can add and extract their own headers to and from packets as they cross networks.
73
Page 86
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
This is analogous to putting data into an envelope and sending the envelope to a higher-level protocol, and having the higher­level protocol put the entire envelope into it’s own, larger envelope. This process is referred to as encapsulation.
Many levels of encapsulation are required for a packet to cross the Internet.
Packet Headers
TCP
Most data transmissions are much longer that a single packet. The data must then be divided up among a series of packets. These packets must be transmitted, received and then reassembled into the original data. TCP handles these functions.
TCP must know how large a packet the network can process. To do this, the TCP protocols at each end of a connection state how large a packet they can handle and the smaller of the two is selected.
The TCP header contains at least 20 octets. The source and destination TCP port numbers are the most important fields. These specify the connection between two TCP protocols on two network devices.
The header also contains a sequence number that is used to ensure the packets are received in the correct order. The packets are not numbered, but rather the octets the packets contain are. If there are 100 octets of data in each packet, the first packet is numbered 0, the second 100, the third 200, etc.
To insure that the data in a packet is received uncorrupted, TCP adds the binary value of all the octets in the packet and
74
Page 87
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
writes the sum in the checksum field. The receiving TCP recalculates the checksum and if the numbers are different, the packet is dropped.
Figure 5-10. TCP Packet Header
When packets have been successfully received, TCP sends an acknowledgement. This is simply a packet that has the acknowledgement number field filled in.
An acknowledgement number of 1000 indicates that all of the data up to octet 1000 has been received. If the transmitting TCP does not receive an acknowledgement in a reasonable amount of time, the data is resent.
The window field controls the amount of data being sent at any one time. It would require too much time and overhead to acknowledge each packet received. Each end of the TCP connection declares how much data it is able to receive at any one time by writing this number of octets in the window field.
The transmitting TCP decrements the number in the window field and when it reaches zero, the transmitting TCP stops sending data. When the receiving TCP can accept more data, it
75
Page 88
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
increases the number in the window field. In practice, a single packet can acknowledge the receipt of data and give permission for more data to be sent.
IP
TCP sends its packets to IP with the source and destination IP addresses. IP is only concerned with these IP addresses. It is not concerned with the contents of the packet or the TCP header.
IP finds a route for the packet to get to the other end of the TCP connection. IP adds its own header to the packet to accomplish this.
The IP header contains the source and destination addresses, the protocol number, and another checksum.
The protocol number tells the receiving IP which protocol to give the packet to. Although most IP traffic uses TCP, other protocols can be used (such as UDP).
The checksum is used by the receiving IP in the same way as the TCP checksum.
76
Page 89
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Figure 5-11. IP Packet Header
The flags and fragment offset are used to keep track of packets that must be divided among several smaller packets to cross networks for which they are too large.
The Time-to-Live (TTL) is the number of gateways the packet is allowed to cross between the source and destination. This number is decremented by one when the packet crosses a gateway and when the TTL reaches zero, the packet is dropped. This helps reduce network traffic if a loop develops.
Ethernet
Every active Ethernet device has its own Ethernet address (commonly called the MAC address) assigned to it by the manufacturer. Ethernet uses 48 bit addresses.
The Ethernet header is 14 octets that include the source and destination MAC address and a type code.
There is no relationship between the MAC address of a network node and its IP address. There must be a database of Ethernet addresses and their corresponding IP addresses.
Different protocol families can be in use on the same network. The type code field allows each protocol family to have its own entry.
A checksum is calculated and when the packet is received, the checksum is recalculated. If the two checksums are different, the packet is dropped.
77
Page 90
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Figure 5-12. Ethernet Packet Header
When a packet is received, the headers are removed. The Ethernet Network Interface Card (NIC) removes the Ethernet header and checks the checksum. It then looks at the type code. If the type code is for IP, the packet is given to IP. IP then removes the IP header and looks at its protocol field. If the protocol field is TCP, the packet is sent to TCP. TCP then looks at the sequence number and uses this number and other data from the headers to reassemble the data into the original file.
TCP and UDP Well-Known Ports
Application protocols run ‘on top of’ TCP/IP. When an application wants to send data or a message, it gives the data to TCP. Because TCP and IP take care of the networking details, the application can look at the network connection as a simple data stream.
To transfer a file across a network using the File Transfer Protocol (FTP), a connection must first be established. The
78
Page 91
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
computer requesting the file transfer must connect specifically to the FTP server on the computer that has the file.
This is accomplished using sockets. A socket is a pair of TCP port numbers used to establish a connection from one computer to another. TCP uses these port numbers to keep track of connections. Specific port numbers are assigned to applications that wait for requests. These port numbers are referred to as ‘well-known’ ports.
TCP will open a connection to the FTP server using some random port number, 1234 for example, on the local computer. TCP will specify port 21 for the FTP server. Port 21 is the well­known port number for FTP servers. Note that there are two different FTP programs running in this example – an FTP client that requests the file to be transferred, and an FTP server that sends the file to the FTP client. The FTP server accepts commands from the client, so the FTP client must know how to connect to the server (must know the TCP port number) in order to send commands. The FTP Server can use any TCP port number to send the file, so long as it is sent as part of the connection setup.
A TCP connection is then described by a set of four numbers – the IP address and TCP port number for the local computer, and the IP address and TCP port number for the remote computer. The IP address is in the IP header and the TCP port number is in the TCP header.
No two TCP connection can have the same set of numbers, but only one number needs to be different. It is possible, for example, for two users to send files to the same destination at the same time. This could give the following connection numbers:
Internet addresses TCP ports
Connection 1 10.42.73.23, 10.128.12.1 1234, 21
79
Page 92
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Connection 2 10.42.73.23, 10.128.12.1 1235, 21
The same computers are making the connections, so the IP addresses are the same. Both computers are using the same well-known TCP port for the FTP server. The local FTP clients are using different TCP port numbers.
FTP transfers actually involve two different connections. The connection begins by the FTP sending commands to send a particular file. Once the commands are sent, a second connection is opened for the actual data transfer. Although it is possible to send data on the same connection, it is very convenient for the FTP client to be able to continue to send commands (such as ‘stop sending this file’).
UDP and ICMP
There are many applications that do not require long messages that cannot fit into a single packet. Looking up computer names is an example. Users wanting to make connections to other computers will usually use a name rather than the computer’s IP or MAC address. The user’s computer must be able to determine the remote computer’s address before a connection can be made. A designated computer on the network will contain a database of computer names and their corresponding IP and MAC addresses. The user’s computer will send a query to the name database computer, and the database computer will send a response. Both the query and the response are very short. There is no need to divide the query or response between multiple packets, so the complexity of TCP is not required. If there is no response to the query after a period of time, the query can simply be resent.
The User Datagram Protocol (UDP) is designed for communications that do not require division among multiple packets and subsequent reassembly. UDP does not keep track of what is sent.
80
Page 93
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
UDP uses port numbers in a way that is directly analogous to TCP. There are well-known UDP port numbers for servers that use UDP.
Figure 5-13. Ethernet Packet Header
The UDP header is shorter than a TCP header. UDP also uses a checksum to verify that data is received uncorrupted.
The Internet Control Message Protocol (ICMP) is also a simplified protocol used for error messages and messages used by TCP/IP. ICMP, like UDP, processes messages that will fit into a single packet. ICMP does not, however use ports because its messages are processed by the network software.
The Domain Name System
Computer users usually prefer to use text names for computers they may want to open a connection with. Computers themselves, require 32 bit IP addresses. Somewhere, a database of network devices’ text names and their corresponding IP addresses must be maintained.
81
Page 94
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
The Domain Name System (DNS) is used to map names to IP addresses throughout the Internet and has been adapted for use within intranets.
For two DNS servers to communicate across different subnets, the DNS Relay of the DES-3326SR must be used. The DNS servers are identified by IP addresses.
Mapping Domain Names to Addresses
Name-to-address translation is performed by a program called a Name server. The client program is called a Name resolver. A Name resolver may need to contact several Name servers to translate a name to an address.
The Domain Name System (DNS) servers are organized in a somewhat hierarchical fashion. A single server often holds names for a single network, which is connected to a root DNS server – usually maintained by an ISP.
Domain Name Resolution
The domain name system can be used by contacting the name servers one at a time, or by asking the domain name system to do the complete name translation. The client makes a query containing the name, the type of answer required, and a code specifying whether the domain name system should do the entire name translation, or simply return the address of the next DNS server if the server receiving the query cannot resolve the name.
When a DNS server receives a query, it checks to see if the name is in its subdomain. If it is, the server translates the name and appends the answer to the query, and sends it back to the client. If the DNS server cannot translate the name, it determines what type of name resolution the client requested. A complete translation is called recursive resolution and
82
Page 95
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
requires the server to contact other DNS servers until the name is resolved. Iterative resolution specifies that if the DNS server cannot supply an answer, it returns the address of the next DNS server the client should contact.
Each client must be able to contact at least one DNS server, and each DNS server must be able to contact at least one root server.
The address of the machine that supplies domain name service is often supplied by a DCHP or BOOTP server, or can be entered manually and configured into the operating system at startup.
DHCP Servers
The Dynamic Host Configuration Protocol (DHCP) is used to dynamically assign a TCP/IP network configuration to network devices and computers on the network. It also ensures that IP address conflicts do not occur.
IP addresses are assigned from a pool of free addresses. Each IP address assigned has a ‘lease’ and a ‘lease expiration period’. The lease must be periodically renewed. If the lease is expires, the IP address is returned to the pool of available IP addresses.
Usually, it is a network policy to assign the same IP address to a given network device or computer each time.
If the IP address lease expires, the network device sends a message to the DHCP server requesting a lease renewal. The DHCP server can send an acknowledgement containing a new lease and updated configuration information.
If an IP address lease cannot be renewed, the network device or computer sends a request to all local DHCP servers attempting to renew the lease. If the DHCP returns a negative
83
Page 96
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
acknowledgement, the network device must release its TCP/IP configuration and reinitialize.
When a new TCP/IP configuration is received from a DHCP server, the network device checks for a possible IP address conflict by sending an Address Resolution Protocol (ARP) request that contains its new IP address.
For two DHCP servers to communicate across different subnets, the BOOTP/DHCP Relay of the DES-3326SR must be used. The DHCP servers are identified by IP addresses.
IP Routing
IP handles the task of determining how packets will get from their source to their destination. This process is referred to as routing.
For IP to work, the local system must be attached to a network. It is safe to assume that any system on this network can send packets to any other system, but when packets must cross other networks to reach a destination on a remote network, these packets must be handled by gateways (also called routers).
Gateways connect a network with one or more other networks. Gateways can be a computer with two network interfaces or a specialized device with multiple network interfaces. The device is designed to forward packets from one network to another.
IP routing is based on the network address of the destination IP address. Each computer has a table of network addresses. For each network address, a corresponding gateway is listed. This is the gateway to use to communicate with that network. The gateway does not have to be directly connected to the remote network, it simply needs to be the first place to go on the way to the remote network.
84
Page 97
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Before a local computer sends a packet, it first determines whether the destination address is on the local network. If it is, the packet can be sent directly to the remote device. If it is not, the local computer looks for the network address of the destination and the corresponding gateway address. The packet is then sent to the gateway leading to the remote network. There is often only one gateway on a network.
A single gateway is usually defined as a default gateway, if that gateway connects the local network to a backbone network or to the Internet. This default gateway is also used whenever no specific route is found for a packet, or when there are several gateways on a network.
Local computers can use default gateways, but the gateways themselves need a more complete routing table to be able to forward packets correctly. A protocol is required for the gateways to be able to communicate between themselves and to keep their routing tables updated.
Packet Fragmentation and Reassembly
TCP/IP can be used with many different types of networks, but not all network types can handle the same length packets.
When IP is transmitting large files, large packets are much more efficient than small ones. It is preferable to use the largest possible packet size, but still be able to cross networks that require smaller packets.
To do this, IP can ‘negotiate’ packet size between the local and remote ends of a connection. When an IP connection is first made, the IPs at both ends of the connection state the largest packet they can handle. The smaller of the two is selected.
When a IP connection crosses multiple networks, it is possible that one of the intermediate networks has a smaller packet size limit than the local or remote network. IP is not able to
85
Page 98
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
determine the maximum packet size across all of the networks that may make up the route for a connection. IP has, therefore, a method to divide packets into multiple, smaller packets to cross such networks. This division of large packets into smaller packets is referred to as fragmentation.
A field in the TCP header indicates that a packet has been fragmented, and other information aids in the reassembly of the packets into the original data.
Gateways that connect networks of different packet size limits split the large packets into smaller ones and forward the smaller packets on their attached networks.
ARP
The Address Resolution Protocol (ARP) determines the MAC address and IP address correspondence for a network device.
A local computer will maintain an ARP cache which is a table of MAC addresses and the corresponding IP addresses. Before a connection with another computer is made, the local computer first checks its ARP cache to determine whether the remote computer has an entry. If it does, the local computer reads the remote computer’s MAC address and writes it into the destination field of the packets to be sent.
If the remote computer does not have an ARP cache entry, the local computer must send an ARP request and wait for a reply.
When the local computer receives the ARP reply packet, the local ARP reads the IP MAC address pair, and then checks the ARP cache for this entry. If there is an entry, it is updated with the new information. If there is no entry, a new entry is made.
There are two possible cases when an ARP packet is received by a local computer. First, the local computer is the target of
86
Page 99
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
the request. If it is, the local ARP replies by sending its MAC IP address pair back to the requesting system. Second, if the local computer is not the target of the request, the packet is dropped.
Multicasting
Multicasting is a group of protocols and tools that enable a single source point to send packets to groups of multiple destination points with persistent connections that last for some amount of time. The main advantage to multicasting is a decrease in the network load compared to broadcasting.
Multicast Groups
Class D IP addresses are assigned to a group of network devices that comprise a multicast group. The four most
significant four bits of a Class D address are set to “1110”. The following 28 bits is referred to as the ‘multicast group ID’. Some of the range of Class D addresses are registered with the Internet Assigned Numbers Authority (IANA) for special purposes. For example, the block of multicast addresses ranging from 224.0.0.1 to 224.0.0.225 is reserved for use by routing protocols and some other low-level topology discovery and maintenance protocols.
Figure 5-14. Class D Multicast Address
87
Page 100
DES-3326SR Layer 3 Fast Ethernet Switch User’s Guide
Some of the reserved IP multicast addresses are as follows:
Address Assignment
224.0.0.0
224.0.0.1
224.0.0.2
224.0.0.3
224.0.0.4
224.0.0.5
224.0.0.6
224.0.0.7
224.0.0.8
224.0.0.9
224.0.0.10
224.0.0.11
224.0.0.12
224.0.0.13
224.0.0.14
224.0.0.15
224.0.0.16
224.0.0.17
224.0.0.18
224.0.0.19
Base Address (reserved) All Systems on this subnet All Routers on this subnet Unassigned DVMRP Routers OSPF IGP Routers OSPF IGP Designated Routers ST Routers ST Hosts All RIP2 Routers All IGRP Routers Mobile Agents DHCP Servers and Relay Agents All PIM Routers RSVP Encapsulation All CBT Routers Designated Sbm All Sbms VRRP Unassigned
through
224.0.0.225
224.0.0.21
DVMRP on MOSPF
Table 5-13. Reserved Multicast Address Assignment
88
Loading...