HP ProCurve 3400cl-24G, ProCurve 5304xl, ProCurve 5308xl, ProCurve 5348xl, ProCurve 5372xl Advanced Traffic Management Guide

...
Advanced Traffic
Management Guide
HP ProCurve Series 6400cl Switches Series 5300xl Switches Series 3400cl Switches
www.hp.com/go/hpprocurve
HP Procurve
January 2005 (Rev. B)
E.09.xx or Greater M.08.6x or Greater
Advanced Traffic Management Guide
© Copyright 2000-2005 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change with­out notice. All Rights Reserved.
This document contains proprietary information, which is protected by copyright. No part of this document may be photocopied, reproduced, or translated into another language without the prior written consent of Hewlett­Packard.
Publication Number
5990-6051 January 2005 (Rev. B)
Applicable Products
HP ProCurve Switch 5308XL (J4819A) HP ProCurve Switch 5372XL (J4848A) HP ProCurve Switch 5348XL (J4849A) HP ProCurve Switch 5304XL (J4850A) HP ProCurve Switch 3400cl-24G (J4905A) HP ProCurve Switch 3400cl-48G (J4906A) HP ProCurve Switch 10G CX4 6400cl-6XG (J8433A) HP ProCurve Switch 10G X2 6400cl-6XG (J8474A)
Trademark Credits
Microsoft, Windows, Windows 95, and Microsoft Windows NT are US registered trademarks of Microsoft Corporation. Internet Explorer is a trademark of Microsoft Corporation. Ethernet is a registered trademark of Xerox Corporation. Netscape is a registered trademark of Netscape Corporation. Cisco® is a trademark of Cisco Systems, Inc.
Disclaimer
The information contained in this document is subject to change without notice.
HEWLETT-PACKARD COMPANY MAKES NO WARRANTY OF ANY KIND WITH REGARD TO THIS MATERIAL, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. Hewlett-Packard shall not be liable for errors contained herein or for incidental or consequential damages in connection with the furnishing, performance, or use of this material.
The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein.
Hewlett-Packard assumes no responsibility for the use or reliability of its software on equipment that is not furnished by Hewlett-Packard.
Warranty
See the Customer Support/Warranty booklet included with the product.
A copy of the specific warranty terms applicable to your Hewlett-Packard products and replacement parts can be obtained from your HP Sales and Service Office or authorized dealer.
Hewlett-Packard Company 8000 Foothills Boulevard, m/s 5551 Roseville, California 95747-5551 http://www.hp.com/go/hpprocurve

Contents

1 Getting Started
Contents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-1
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-2
Conventions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-2
Command Syntax Statements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-2
Command Prompts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-3
Screen Simulations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-3
Keys . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-4
Related Publications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-4
Getting Documentation From the Web . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-6
Sources for More Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-7
Need Only a Quick Start? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-8
IP Addressing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-8
To Set Up and Install the Switch in Your Network . . . . . . . . . . . . . . . . 1-8
Contents
2 Static Virtual LANs (VLANs)
Contents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-1
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-2
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-3
General VLAN Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-3
Types of Static VLANs Available in the Switch . . . . . . . . . . . . . . . . . . . 2-4
Port-Based VLANs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-4
Protocol-Based VLANs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-4
Designated VLANs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-4
Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-5
Static VLAN Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-6
VLAN Environments . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-7
VLAN Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-8
Routing Options for VLANs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-9
Overlapping (Tagged) VLANs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-9
iii
Contents
VLAN Operating Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-13
General Steps for Using VLANs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-16
Multiple VLAN Considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-17
Single Forwarding Database Operation . . . . . . . . . . . . . . . . . . . . . . . . 2-18
Example of an Unsupported Configuration and How To Correct It
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-19
Multiple Forwarding Database Operation . . . . . . . . . . . . . . . . . . . . . . 2-20
Configuring VLANs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-21
Menu: Configuring Port-Based VLAN Parameters . . . . . . . . . . . . . . . 2-21
To Change VLAN Support Settings . . . . . . . . . . . . . . . . . . . . . . . . 2-21
Adding or Editing VLAN Names . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-24
Adding or Changing a VLAN Port Assignment . . . . . . . . . . . . . . . 2-25
CLI: Configuring Port-Based and Protocol-Based VLAN
Parameters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-27
Web: Viewing and Configuring VLAN Parameters . . . . . . . . . . . . . . . 2-37
802.1Q VLAN Tagging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-38
Special VLAN Types . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-43
VLAN Support and the Default VLAN . . . . . . . . . . . . . . . . . . . . . . . . . . 2-43
The Primary VLAN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-43
The Secure Management VLAN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-44
Preparation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-46
Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-47
Deleting the Management VLAN . . . . . . . . . . . . . . . . . . . . . . . . . . 2-48
Operating Notes for Management VLANs . . . . . . . . . . . . . . . . . . . 2-48
Voice VLANs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-49
Operating Rules for Voice VLANs . . . . . . . . . . . . . . . . . . . . . . . . . 2-49
Components of Voice VLAN Operation . . . . . . . . . . . . . . . . . . . . . 2-50
Voice VLAN QoS Prioritizing (Optional) . . . . . . . . . . . . . . . . . . . . 2-50
Voice VLAN Access Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-51
iv
Effect of VLANs on Other Switch Features . . . . . . . . . . . . . . . . . . . . . . . . 2-51
Spanning Tree Operation with VLANs . . . . . . . . . . . . . . . . . . . . . . . . . 2-51
IP Interfaces . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-52
VLAN MAC Address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-52
Port Trunks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-52
Port Monitoring . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-52
Jumbo Packet Support on the Series 3400cl and Series 6400cl Switches
VLAN Restrictions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-53
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-53
3 GVRP
Contents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-1
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-2
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-3
General Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-4
Per-Port Options for Handling GVRP “Unknown VLANs” . . . . . . . . . . . . . . 3-7
Per-Port Options for Dynamic VLAN Advertising and Joining . . . . . . . . . . 3-9
Contents
GVRP and VLAN Access Control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-11
Port-Leave From a Dynamic VLAN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-11
Planning for GVRP Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-12
Configuring GVRP On a Switch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-13
Menu: Viewing and Configuring GVRP . . . . . . . . . . . . . . . . . . . . . . . . . 3-13
CLI: Viewing and Configuring GVRP . . . . . . . . . . . . . . . . . . . . . . . . . . 3-14
Web: Viewing and Configuring GVRP . . . . . . . . . . . . . . . . . . . . . . . . . . 3-18
GVRP Operating Notes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-18
4 Multimedia Traffic Control with IP Multicast (IGMP)
Contents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-1
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-2
IGMP General Operation and Features . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-3
IGMP Terms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-4
IGMP Operating Features . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-5
v
Contents
CLI: Configuring and Displaying IGMP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-6
Web: Enabling or Disabling IGMP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-11
How IGMP Operates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-11
Operation With or Without IP Addressing . . . . . . . . . . . . . . . . . . . . . . 4-13
Automatic Fast-Leave IGMP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-13
Forced Fast-Leave IGMP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-15
Configuration Options for Forced Fast-Leave . . . . . . . . . . . . . . . 4-15
Listing the Forced Fast-Leave Configuration . . . . . . . . . . . . . . . . 4-16
Configuring Per-Port Forced Fast-Leave IGMP . . . . . . . . . . . . . . . . . . 4-18
Using the Switch as Querier . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-19
Excluding Well-Known or Reserved Multicast Addresses from IP
Multicast Filtering . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-20
5 PIM-DM (Dense Mode) on the 5300xl Switches
Contents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-1
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-2
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-3
vi
Feature Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-4
PIM-DM Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-4
Multicast Flow Management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-7
General Configuration Elements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-9
Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-9
PIM-DM Operating Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-10
Configuring PIM-DM on the Series 5300xl Switches . . . . . . . . . . . . . . . . . 5-11
PIM Global Configuration Context . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-12
PIM VLAN (Interface) Configuration Context . . . . . . . . . . . . . . . . . . . 5-15
Displaying PIM Data and Configuration Settings on the Series
5300xl Switches . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-22
Displaying PIM Route Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-23
Displaying PIM Status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-27
Operating Notes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-34
Troubleshooting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-36
Messages Related to PIM Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-37
Applicable RFCs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-40
Exceptions to Support for RFC 2932 - Multicast Routing MIB . . . . . . . . . 5-41
6 Spanning-Tree Operation
Contents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-1
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-2
The RSTP (802.1w) and STP (802.1D) Spanning Tree Options . . . . . . . . . 6-5
RSTP (802.1w) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-6
STP (802.1D) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-6
How STP and RSTP Operate . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-7
Configuring Rapid Reconfiguration Spanning Tree (RSTP) . . . . . . . . . . . . 6-9
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-9
Transitioning from STP to RSTP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-10
Configuring RSTP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-11
Optimizing the RSTP Configuration . . . . . . . . . . . . . . . . . . . . . . . 6-11
CLI: Configuring RSTP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-12
Menu: Configuring RSTP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-18
Web: Enabling or Disabling RSTP . . . . . . . . . . . . . . . . . . . . . . . . . 6-20
Contents
802.1D Spanning-Tree Protocol (STP) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-21
Menu: Configuring 802.1D STP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-21
CLI: Configuring 802.1D STP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-24
STP Fast Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-28
Fast-Uplink Spanning Tree Protocol (STP) . . . . . . . . . . . . . . . . . . . . . 6-29
Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-31
Operating Rules for Fast Uplink . . . . . . . . . . . . . . . . . . . . . . . . . . 6-32
Menu: Viewing and Configuring Fast-Uplink STP . . . . . . . . . . . . 6-33
CLI: Viewing and Configuring Fast-Uplink STP . . . . . . . . . . . . . . 6-39
Operating Notes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-42
Web: Enabling or Disabling STP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-43
vii
Contents
802.1s Multiple Spanning Tree Protocol (MSTP) . . . . . . . . . . . . . . . . . . . . 6-44
MSTP Structure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-45
How MSTP Operates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-47
MST Regions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-47
Regions, Legacy STP and RSTP Switches, and the Common Spanning Tree (CST)
MSTP Operation with 802.1Q VLANs . . . . . . . . . . . . . . . . . . . . . . 6-49
Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-50
Operating Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-52
Transitioning from STP or RSTP to MSTP . . . . . . . . . . . . . . . . . . . . . . 6-53
Tips for Planning an MSTP Application . . . . . . . . . . . . . . . . . . . . . . . . 6-54
Steps for Configuring MSTP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-55
Configuring MSTP Operation Mode and Global Parameters . . . . . . . 6-57
Configuring Basic Port Connectivity Parameters . . . . . . . . . . . . . . . . 6-61
Configuring MST Instance Parameters . . . . . . . . . . . . . . . . . . . . . . . . . 6-63
Configuring MST Instance Per-Port Parameters . . . . . . . . . . . . . . . . . 6-66
Enabling or Disabling Spanning Tree Operation . . . . . . . . . . . . . . . . . 6-69
Enabling an Entire MST Region at Once or Exchanging One
Region Configuration for Another . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-69
Displaying MSTP Statistics and Configuration. . . . . . . . . . . . . . . . . . . 6-71
Displaying MSTP Statistics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-71
Displaying the MSTP Configuration . . . . . . . . . . . . . . . . . . . . . . . 6-74
Operating Notes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-78
Troubleshooting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-78
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-49
viii
7 Switch Meshing
Contents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-1
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-2
Switch Meshing Fundamentals . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-4
Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-4
Operating Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-5
Using a Heterogeneous Switch Mesh . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-8
Bringing Up a Switch Mesh Domain: . . . . . . . . . . . . . . . . . . . . . . . . . . 7-10
Further Operating Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-10
Configuring Switch Meshing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-11
Preparation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-11
Menu: To Configure Switch Meshing . . . . . . . . . . . . . . . . . . . . . . . . . . 7-11
CLI: To View and Configure Switch Meshing . . . . . . . . . . . . . . . . . . . 7-14
Viewing Switch Mesh Status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-14
CLI: Configuring Switch Meshing . . . . . . . . . . . . . . . . . . . . . . . . . 7-17
Operating Notes for Switch Meshing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-18
Flooded Traffic . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-18
Unicast Packets with Unknown Destinations . . . . . . . . . . . . . . . . . . . 7-19
Spanning Tree Operation with Switch Meshing . . . . . . . . . . . . . . . . . 7-20
Filtering/Security in Meshed Switches . . . . . . . . . . . . . . . . . . . . . . . . . 7-22
IP Multicast (IGMP) in Meshed Switches . . . . . . . . . . . . . . . . . . . . . . 7-22
Static VLANs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-23
Dynamic VLANs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-24
Jumbo Packets (3400cl and 6400cl Switches Only) . . . . . . . . . . . . . . 7-24
Requirements and Restrictions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-25
8 Quality of Service (QoS): Managing Bandwidth More
Effectively
Contents
Contents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-1
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-2
Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-5
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-6
Classifiers for Prioritizing Outbound Packets . . . . . . . . . . . . . . . . . . . . 8-9
5300xl Packet Classifiers and Evaluation Order . . . . . . . . . . . . . . 8-9
3400cl/6400cl Packet Classifiers and Evaluation Order . . . . . . . 8-10
Preparation for Configuring QoS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-13
Planning QoS for the Series 3400cl/6400cl Switches . . . . . . . . . . . . . 8-15
Prioritizing and Monitoring QoS, ACL, and Rate Limiting Feature Usage on the 3400cl/6400cl Switches
QoS Resource Usage and Monitoring on 3400cl/6400cl Switches
Managing QoS Resource Consumption on the 3400cl/6400cl
Switches . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-17
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-16
. . . . . . . . . . . . . . . 8-15
ix
Contents
Troubleshooting a Shortage of Per-Port Rule Resources on
the 3400cl/6400cl Switches . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-18
Examples of QoS Resource Usage on 3400cl/6400cl
Switches . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-19
Using QoS Classifiers To Configure Quality of Service for
Outbound Traffic . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-22
Viewing the QoS Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-22
No Override . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-23
QoS UDP/TCP Priority . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-24
Assigning an 802.1p Priority Based on TCP or UDP Port Number
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-25
Assigning a DSCP Policy Based on TCP or UDP Port Number
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-26
QoS IP-Device Priority . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-30
Assigning a Priority Based on IP Address . . . . . . . . . . . . . . . . . . . 8-31
Assigning a DSCP Policy Based on IP Address . . . . . . . . . . . . . . 8-32
QoS IP Type-of-Service (ToS) Policy and Priority . . . . . . . . . . . . . . . 8-36
Assigning an 802.1p Priority to IPv4 Packets on the Basis of the ToS Precedence Bits
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-37
Assigning an 802.1p Priority to IPv4 Packets on the Basis of Incoming DSCP
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-38
Assigning a DSCP Policy on the Basis of the DSCP in IPv4 Packets Received from Upstream Devices
. . . . . . . . . . . . . 8-42
Details of QoS IP Type-of-Service . . . . . . . . . . . . . . . . . . . . . . . . . 8-46
QoS Layer-3 Protocol Priority (5300xl Switches Only) . . . . . . . . . . . 8-49
Assigning a Priority Based on Layer-3 Protocol . . . . . . . . . . . . . . 8-49
QoS VLAN-ID (VID) Priority . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-51
Assigning a Priority Based on VLAN-ID . . . . . . . . . . . . . . . . . . . . 8-51
Assigning a DSCP Policy Based on VLAN-ID (VID) . . . . . . . . . . . 8-53
QoS Source-Port Priority . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-57
Assigning a Priority Based on Source-Port . . . . . . . . . . . . . . . . . . 8-57
Assigning a DSCP Policy Based on the Source-Port . . . . . . . . . . 8-59
Differentiated Services Codepoint (DSCP) Mapping . . . . . . . . . . . . . 8-62
Default Priority Settings for Selected Codepoints . . . . . . . . . . . . 8-64
Quickly Listing Non-Default Codepoint Settings . . . . . . . . . . . . . 8-64
Note On Changing a Priority Setting . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-65
x
IP Multicast (IGMP) Interaction with QoS . . . . . . . . . . . . . . . . . . . . . . . . . 8-69
QoS Messages in the CLI . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-69
QoS Operating Notes and Restrictions . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-70
9 Access Control Lists (ACLs) for the Series 5300xl
Switches
Contents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-1
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-3
Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-5
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-8
Types of IP ACLs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-8
ACL Inbound and Outbound Application Points . . . . . . . . . . . . . . . . . . 9-8
Features Common to All ACLs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-9
General Steps for Planning and Configuring ACLs . . . . . . . . . . . . . . . 9-10
ACL Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-12
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-12
The Packet-Filtering Process . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-13
Planning an ACL Application . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-16
Traffic Management and Improved Network Performance . . . . . . . . 9-16
Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-17
Guidelines for Planning the Structure of an ACL . . . . . . . . . . . . . . . . 9-18
ACL Configuration and Operating Rules . . . . . . . . . . . . . . . . . . . . . . . 9-18
How an ACE Uses a Mask To Screen Packets for Matches . . . . . . . . 9-20
What Is the Difference Between Network (or Subnet) Masks and the Masks Used with ACLs?
Rules for Defining a Match Between a Packet and an Access Control Entry (ACE)
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-21
. . . . . . . . . . . . . . . . . . . . 9-20
Contents
Configuring and Assigning an ACL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-25
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-25
General Steps for Implementing ACLs . . . . . . . . . . . . . . . . . . . . . 9-25
Types of ACLs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-26
ACL Configuration Structure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-26
Standard ACL Structure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-27
Extended ACL Configuration Structure . . . . . . . . . . . . . . . . . . . . 9-28
xi
Contents
ACL Configuration Factors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-29
The Sequence of Entries in an ACL Is Significant . . . . . . . . . . . . 9-29
In Any ACL, There Will Always Be a Match . . . . . . . . . . . . . . . . . 9-31
A Configured ACL Has No Effect Until You Apply It to an Interface
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-31
You Can Assign an ACL Name or Number to a VLAN Even if the ACL Does Not Yet Exist in the Switch’s Configuration
. . 9-31
Using the CLI To Create an ACL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-31
General ACE Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-32
Using CIDR Notation To Enter the ACL Mask . . . . . . . . . . . . . . . 9-32
Configuring and Assigning a Numbered, Standard ACL . . . . . . . . . . 9-33
Configuring and Assigning a Numbered, Extended ACL . . . . . . . . . . 9-38
Configuring a Named ACL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-44
Enabling or Disabling ACL Filtering on a VLAN . . . . . . . . . . . . . . . . . 9-46
Deleting an ACL from the Switch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-47
Displaying ACL Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-48
Display an ACL Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-48
Display the Content of All ACLs on the Switch . . . . . . . . . . . . . . . . . . 9-49
Display the ACL Assignments for a VLAN . . . . . . . . . . . . . . . . . . . . . . 9-50
Displaying the Content of a Specific ACL . . . . . . . . . . . . . . . . . . . . . . 9-51
Display All ACLs and Their Assignments in the Switch
Startup-Config File and Running-Config File . . . . . . . . . . . . . . . . . . . . 9-53
xii
Editing ACLs and Creating an ACL Offline . . . . . . . . . . . . . . . . . . . . . . . . . 9-53
Using the CLI To Edit ACLs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-53
General Editing Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-54
Deleting Any ACE from an ACL . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-54
Working Offline To Create or Edit an ACL . . . . . . . . . . . . . . . . . . . . . 9-56
Enable ACL “Deny” Logging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-59
Requirements for Using ACL Logging . . . . . . . . . . . . . . . . . . . . . . . . . . 9-59
ACL Logging Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-60
Enabling ACL Logging on the Switch . . . . . . . . . . . . . . . . . . . . . . . . . . 9-60
Operating Notes for ACL Logging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-62
General ACL Operating Notes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-63
Contents
10 Access Control Lists (ACLs) for the Series 3400cl and
Series 6400cl Switches
Contents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-1
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-3
ACL Applications on Series 3400cl and 6400cl Switches . . . . . . . . . . 10-3
General Application Options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-3
Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-6
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-9
Types of IP ACLs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-9
ACL Inbound Application Points . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-9
Features Common to All ACLs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-10
General Steps for Planning and Configuring ACLs . . . . . . . . . . . . . . 10-11
ACL Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-12
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-12
The Packet-Filtering Process . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-13
Planning an ACL Application on a Series 3400cl or Series 6400cl
Switch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-16
Switch Resource Usage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-16
Prioritizing and Monitoring ACL, IGMP, QoS, and Rate Limiting Feature Usage
ACL Resource Usage and Monitoring . . . . . . . . . . . . . . . . . . . . . 10-17
Standard ACLs: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-18
Extended ACLs: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-18
Managing ACL Resource Consumption . . . . . . . . . . . . . . . . . . . . . . . 10-20
Oversubscribing Available Resources . . . . . . . . . . . . . . . . . . . . . 10-20
Troubleshooting a Shortage of Per-Port Resources . . . . . . . . . 10-21
Example of ACL Resource Usage . . . . . . . . . . . . . . . . . . . . . . . . 10-23
Viewing the Current Per-Port Rule and Mask Usage . . . . . . . . . 10-23
Traffic Management and Improved Network Performance . . . . . . . 10-26
Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-26
Guidelines for Planning the Structure of an ACL . . . . . . . . . . . . . . . 10-27
ACL Configuration and Operating Rules . . . . . . . . . . . . . . . . . . . . . . 10-28
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-17
xiii
Contents
How an ACE Uses a Mask To Screen Packets for Matches . . . . . . . 10-30
What Is the Difference Between Network (or Subnet) Masks and the Masks Used with ACLs?
. . . . . . . . . . . . . . . . . . . 10-30
Rules for Defining a Match Between a Packet and an Access Control Entry (ACE)
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-31
Configuring and Assigning an ACL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-35
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-35
General Steps for Implementing ACLs . . . . . . . . . . . . . . . . . . . . 10-35
Types of ACLs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-35
ACL Configuration Structure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-36
Standard ACL Structure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-37
Extended ACL Configuration Structure . . . . . . . . . . . . . . . . . . . 10-37
ACL Configuration Factors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-39
ACL Resource Consumption . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-39
The Sequence of Entries in an ACL Is Significant . . . . . . . . . . . 10-39
In Any ACL, There Will Always Be a Match . . . . . . . . . . . . . . . . 10-41
A Configured ACL Has No Effect Until You Apply It to an
Interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-41
Using the CLI To Create an ACL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-41
General ACE Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-41
Using CIDR Notation To Enter the ACL Mask . . . . . . . . . . . . . . 10-42
Configuring and Assigning a Numbered, Standard ACL . . . . . . . . . 10-43
Configuring and Assigning a Numbered, Extended ACL . . . . . . . . . 10-48
Configuring a Named ACL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-54
Enabling or Disabling ACL Filtering on an Interface . . . . . . . . . . . . 10-57
xiv
Deleting an ACL from the Switch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-58
Displaying ACL Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-58
Display an ACL Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-59
Display the Content of All ACLs on the Switch . . . . . . . . . . . . . . . . . 10-59
Display the ACL Assignments for an Interface . . . . . . . . . . . . . . . . . 10-60
Displaying the Content of a Specific ACL . . . . . . . . . . . . . . . . . . . . . 10-61
Displaying the Current Per-Port ACL Resources . . . . . . . . . . . . . . . 10-63
Display All ACLs and Their Assignments in the Switch
Startup-Config File and Running-Config File . . . . . . . . . . . . . . . . . . . 10-64
Editing ACLs and Creating an ACL Offline . . . . . . . . . . . . . . . . . . . . . . . . 10-65
Using the CLI To Edit ACLs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-65
General Editing Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-65
Deleting Any ACE from an ACL . . . . . . . . . . . . . . . . . . . . . . . . . . 10-66
Working Offline To Create or Edit an ACL . . . . . . . . . . . . . . . . . . . . 10-67
Enable ACL “Deny” Logging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-71
Requirements for Using ACL Logging . . . . . . . . . . . . . . . . . . . . . . . . . 10-71
ACL Logging Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-72
Enabling ACL Logging on the Switch . . . . . . . . . . . . . . . . . . . . . . . . . 10-72
Operating Notes for ACL Logging . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-74
General ACL Operating Notes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-75
11 IP Routing Features
Contents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-1
Overview of IP Routing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-3
IP Interfaces . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-4
IP Tables and Caches . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-4
ARP Cache Table . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-5
IP Route Table . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-5
IP Forwarding Cache . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-6
IP Route Exchange Protocols . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-7
IP Global Parameters for Routing Switches . . . . . . . . . . . . . . . . . . . . 11-7
IP Interface Parameters for Routing Switches . . . . . . . . . . . . . . . . . . 11-9
Contents
Configuring IP Parameters for Routing Switches . . . . . . . . . . . . . . . . . . 11-10
Configuring IP Addresses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-10
Changing the Router ID . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-10
Configuring ARP Parameters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-11
How ARP Works . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-11
Enabling Proxy ARP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-13
Configuring Forwarding Parameters . . . . . . . . . . . . . . . . . . . . . . . . . 11-13
Changing the TTL Threshold . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-14
Enabling Forwarding of Directed Broadcasts . . . . . . . . . . . . . . 11-14
xv
Contents
Configuring ICMP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-15
Disabling ICMP Messages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-15
Disabling Replies to Broadcast Ping Requests . . . . . . . . . . . . . . 11-15
Disabling ICMP Destination Unreachable Messages . . . . . . . . . 11-16
Disabling ICMP Redirects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-17
Configuring Static IP Routes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-17
Static Route Types . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-17
Static IP Route Parameters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-18
Static Route States Follow Port States . . . . . . . . . . . . . . . . . . . . . . . . 11-18
Configuring a Static IP Route . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-19
Configuring the Default Route . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-19
Configuring a “Null” Route . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-19
Configuring RIP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-21
Overview of RIP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-21
RIP Parameters and Defaults . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-22
RIP Global Parameters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-22
RIP Interface Parameters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-22
Configuring RIP Parameters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-23
Enabling RIP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-23
Changing the RIP Type on a VLAN Interface . . . . . . . . . . . . . . . 11-24
Changing the Cost of Routes Learned on a VLAN Interface . . . 11-24
Configuring RIP Redistribution . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-25
Define RIP Redistribution Filters . . . . . . . . . . . . . . . . . . . . . . . . . 11-25
Modify Default Metric for Redistribution . . . . . . . . . . . . . . . . . . 11-26
Enable RIP Route Redistribution . . . . . . . . . . . . . . . . . . . . . . . . . 11-26
Changing the Route Loop Prevention Method . . . . . . . . . . . . . . . . . 11-27
Displaying RIP Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-27
Displaying General RIP Information . . . . . . . . . . . . . . . . . . . . . . 11-28
Displaying RIP Interface Information . . . . . . . . . . . . . . . . . . . . . 11-30
Displaying RIP Peer Information . . . . . . . . . . . . . . . . . . . . . . . . . 11-31
Displaying RIP Redistribution Information . . . . . . . . . . . . . . . . 11-33
Displaying RIP Redistribution Filter (restrict) Information . . . 11-33
xvi
Contents
Configuring OSPF . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-34
Overview of OSPF . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-34
Designated Routers in Multi-Access Networks . . . . . . . . . . . . . 11-35
Designated Router Election . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-35
OSPF RFC 1583 and 2328 Compliance . . . . . . . . . . . . . . . . . . . . 11-36
Reduction of Equivalent AS External LSAs . . . . . . . . . . . . . . . . 11-36
Dynamic OSPF Activation and Configuration . . . . . . . . . . . . . . 11-38
Configuring OSPF . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-38
Configuration Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-39
OSPF Parameters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-39
Enabling OSPF . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-40
Assigning OSPF Areas . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-40
Assigning an Area Range (optional) . . . . . . . . . . . . . . . . . . . . . . 11-42
Assigning VLANs to an Area . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-43
Modifying Interface Defaults . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-43
OSPF Interface Parameters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-43
Assigning Virtual Links . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-45
Modifying Virtual Link Parameters . . . . . . . . . . . . . . . . . . . . . . . 11-47
Virtual Link Parameter Descriptions . . . . . . . . . . . . . . . . . . . . . . 11-47
Defining Redistribution Filters . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-48
Modifying Default Metric for Redistribution . . . . . . . . . . . . . . . 11-49
Enabling Route Redistribution . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-50
Modifying Redistribution Metric Type . . . . . . . . . . . . . . . . . . . . 11-50
Administrative Distance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-50
Modifying OSPF Traps Generated . . . . . . . . . . . . . . . . . . . . . . . . 11-51
Modifying OSPF Standard Compliance Setting . . . . . . . . . . . . . 11-52
Displaying OSPF Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-53
Displaying General OSPF Configuration Information . . . . . . . . 11-53
Displaying OSPF Area Information . . . . . . . . . . . . . . . . . . . . . . . 11-55
Displaying OSPF External Link State Information . . . . . . . . . . 11-56
Displaying OSPF Interface Information . . . . . . . . . . . . . . . . . . . 11-57
Displaying OSPF Interface Information for a Specific
VLAN or IP Address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-59
Displaying OSPF Link State Information . . . . . . . . . . . . . . . . . . 11-60
Displaying OSPF Neighbor Information . . . . . . . . . . . . . . . . . . . 11-62
Displaying OSFPF Redistribution Information . . . . . . . . . . . . . 11-64
xvii
Contents
Displaying OSFPF Redistribution Filter (restrict)
Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-64
Displaying OSPF Virtual Neighbor Information . . . . . . . . . . . . . 11-65
Displaying OSPF Virtual Link Information . . . . . . . . . . . . . . . . . 11-66
Displaying OSPF Route Information . . . . . . . . . . . . . . . . . . . . . . 11-68
Configuring IRDP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-70
Enabling IRDP Globally . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-71
Enabling IRDP on an Individual VLAN Interface . . . . . . . . . . . . . . . 11-71
Displaying IRDP Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-72
Configuring DHCP Relay . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-73
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-73
DHCP Packet Forwarding . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-73
Unicast Forwarding . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-73
Broadcast Forwarding . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-73
Minimum Requirements for DHCP Relay Operation . . . . . . . . . . . . 11-74
Enabling DHCP Relay . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-74
Configuring a Helper Address . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-74
Viewing the Current DHCP Relay Configuration . . . . . . . . . . . . 11-75
Syntax: show ip helper-address < vlan-id > . . . . . . . . . . . . . . . . . . . . . . 11-75
xviii
UDP Broadcast Forwarding on 5300xl Switches . . . . . . . . . . . . . . . . . . . 11-76
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-76
Subnet Masking for UDP Forwarding Addresses . . . . . . . . . . . . . . . 11-77
Configuring and Enabling UDP Broadcast Forwarding . . . . . . . . . . 11-78
Globally Enabling UDP Broadcast Forwarding . . . . . . . . . . . . . 11-78
Configuring UDP Broadcast Forwarding on Individual VLANs
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-78
Displaying the Current IP Forward-Protocol Configuration . . . . . . 11-80
Operating Notes for UDP Broadcast Forwarding . . . . . . . . . . . . . . . 11-81
Messages Related to UDP Broadcast Forwarding . . . . . . . . . . . . . . 11-81
Configuring Static Network Address Translation (NAT) for Intranet
Applications on the 5300xl Switches . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-82
Static NAT Operating Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-83
Configuring Static NAT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-83
Displaying Static NAT Statistics and Configuration . . . . . . . . . . . . . 11-85
Static NAT Operating Notes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-85
12 Router Redundancy Using XRRP
Contents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-1
Introduction to XRRP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-2
Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-2
Overview of XRRP Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-3
XRRP During Normal Router Operation . . . . . . . . . . . . . . . . . . . . . . . 12-4
XRRP Fail-Over Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-5
Single VLAN Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-5
Multiple VLAN Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-6
XRRP Operating Notes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-9
Configuring XRRP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-11
Customizing the XRRP Configuration . . . . . . . . . . . . . . . . . . . . . . . . 12-12
Enabling and Disabling XRRP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-15
Configuration Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-15
Configuration Examples . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-16
Configuration for Figure 12-2 – Single VLAN Example . . . . . . . 12-16
Configuration for Figure 12-4 – Multiple VLANs . . . . . . . . . . . . 12-17
Contents
Displaying XRRP Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-18
Comparison Between XRRP and VRRP . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-21
Messages Related to XRRP Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-22
13 Stack Management for the Series 3400cl and 6400cl
Switches
Contents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-1
Introduction to Stack Management on Series 3400cl and Series
6400cl Switches . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-2
Stacking Support on HP ProCurve Switches . . . . . . . . . . . . . . . . . . . . 13-2
Components of HP ProCurve Stack Management . . . . . . . . . . . . . . . 13-4
General Stacking Operation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-4
Operating Rules for Stacking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-6
General Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-6
Specific Rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-7
xix
Contents
Configuring Stack Management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-8
Overview of Configuring and Bringing Up a Stack . . . . . . . . . . . . . . . 13-8
Using the Menu Interface To View Stack Status and Configure
Stacking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-12
Using the Menu Interface To View and Configure a
Commander Switch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-12
Using the Menu To Manage a Candidate Switch . . . . . . . . . . . . 13-14
Using the Commander To Manage The Stack . . . . . . . . . . . . . . . . . . 13-16
Using the Commander To Access Member Switches for Configuration Changes and Monitoring Traffic
. . . . . . . . . . . . . 13-22
Converting a Commander or Member to a Member of Another Stack
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-23
Monitoring Stack Status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-24
Using the CLI To View Stack Status and Configure Stacking . . . . . 13-28
Using the CLI To View Stack Status . . . . . . . . . . . . . . . . . . . . . . 13-30
Using the CLI To Configure a Commander Switch . . . . . . . . . . 13-32
Adding to a Stack or Moving Switches Between Stacks . . . . . . 13-34
Using the CLI To Remove a Member from a Stack . . . . . . . . . . 13-39
Using the CLI To Access Member Switches for Configuration Changes and Traffic Monitoring
. . . . . . . . . . . . . . . . . . . . . . . . . . 13-41
SNMP Community Operation in a Stack . . . . . . . . . . . . . . . . . . . . . . 13-42
Using the CLI To Disable or Re-Enable Stacking . . . . . . . . . . . . . . . 13-43
Transmission Interval . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-43
Stacking Operation with Multiple VLANs Configured . . . . . . . . . . . 13-43
Status Messages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-44
xx
Index

Getting Started

Contents

Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-2
Conventions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-2
Command Syntax Statements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-2
Command Prompts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-3
Screen Simulations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-3
Keys . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-4
Related Publications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-4
Getting Documentation From the Web . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-6
Sources for More Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-7
1
Need Only a Quick Start? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-8
IP Addressing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-8
To Set Up and Install the Switch in Your Network . . . . . . . . . . . . . . . . 1-8
1-1
Getting Started

Overview

Overview
This Advanced Traffic Management Guide is intended for use with the following switches:
HP ProCurve Switch 10G CX4
6400cl-6xg
HP ProCurve Switch 5304xl HP ProCurve Switch 5348xl
HP ProCurve Switch 5308xl HP ProCurve Switch 5372xl
HP ProCurve Switch 3400cl-24G HP ProCurve Switch 3400cl-48G
This guide describes how to configure and use the advanced traffic manage­ment features covered in the following chapters. The Product Documentation CD-ROM shipped with the switch includes a copy of this guide. You can also download the latest version of this guide from the HP ProCurve website. (Refer to
“Getting Documentation From the Web” on page 1-6.)
For information on other product documentation available for the above­listed switches, refer to
“Related Publications” on page 1-4.
HP ProCurve Switch 10G X2
6400cl-6xg

Conventions

This guide uses the following conventions for command syntax and displayed information.

Command Syntax Statements

Syntax: aaa port-access authenticator < port-list >
[ control < authorized | auto | unauthorized >]
Vertical bars ( | ) separate alternative, mutually exclusive elements.
Square brackets ( [ ] ) indicate optional elements.
Braces ( < > ) enclose required elements.
Braces within square brackets ( [ < > ] ) indicate a required element within
an optional choice.
Boldface indicates use of a CLI command, part of a CLI command syntax,
or other displayed element in general text. For example:
“Use the copy tftp command to download the key from a TFTP server.”
Italics indicate variables for which you must supply a value when execut-
ing the command. For example, in this command syntax, you must provide one or more port numbers:
Syntax: aaa port-access authenticator < port-list >
1-2
Getting Started
Conventions

Command Prompts

In the default configuration, your Series 5300XL switch displays one of the following CLI prompts:
HP Procurve Switch 6400# HP Procurve Switch 5304# HP Procurve Switch 5308# HP ProCurve Switch 3400-24# HP ProCurve Switch 3400-48#
To simplify recognition, this guide uses HPswitch to represent command prompts for all models. For example:
HPswitch#
(You can use the hostname command to change the text in the CLI prompt.)

Screen Simulations

Displayed Text. Figures containing simulated screen text and command output look like this:
Figure 1-1. Example of a Figure Showing a Simulated Screen
In some cases, brief command-output sequences appear without figure iden­tification. For example:
HPswitch(config)# clear public-key HPswitch(config)# show ip client-public-key show_client_public_key: cannot stat keyfile
Port Numbering Conventions. HP ProCurve stackable switches designate individual ports with sequential numbers (1, 2, 3, etc.) HP ProCurve chassis switches designate individual ports with a letter/number combination to show the slot in which the port is found and the sequential number the port has in that slot (A1, A2, B1, B2, etc.) Examples that include port numbering informa­tion often include only one of these port numbering conventions. Unless otherwise noted, you can assume that the example applies to your switch, regardless of its port numbering convention.
1-3
Getting Started

Related Publications

Keys

Simulations of actual keys use a bold, sans-serif typeface with square brackets. For example, the “Tab” key appears as
[Tab], and the “Y” key appears as [Y].
Related Publications
Software Release Notes. Release notes are posted on the HP Procurve website and provide information on new software updates:
New features and how to configure and use them
Software management, including downloading software to the switch
Software fixes addressed in current and previous releases
To view and download a copy of the latest release notes for your switch, see “Getting Documentation From the Web” on page 1-6.
Product Notes and Software Update Information. The printed Read Me First shipped with your switch provides product notes, and other information.
For the latest version, refer to page 1-6.
Installation and Getting Started Guide. Use the Installation and Get- ting Started Guide shipped with your switch to prepare for and perform the
physical installation. This guide also steps you through connecting the switch to your network and assigning IP addressing, as well as describing the LED indications for correct operation and trouble analysis. A PDF version of this guide is also provided on the Product Documentation CD-ROM shipped with the switch. And you can download a copy from the HP Procurve website. (See “Getting Documentation From the Web” on page 1-6.)
“Getting Documentation From the Web” on
1-4
Management and Configuration Guide. Use the Management and Con- figuration Guide for information on:
Using the command line (CLI), Menu interface, and web browser interface
Learning how memory operates in the switch
IP addressing
Time protocols
Port configuration options
Interaction with network management applications
File transfers, including operation systems, configuration files, ACL com-
mand files, and diagnostic data files
Monitoring and troubleshooting switch software operation
MAC addressing
Daylight time rules
Getting Started
Related Publications
Access Security Guide. Use the Access Security Guide to learn how to use and configure the following access security features available in the switch:
Local username and password security
Web-Based and MAC-based authentication
RADIUS and TACACS+ authentication
SSH (Secure Shell) and SSL (Secure Socket Layer) operation
802.1X Port-Based Access Control
Port Security operation with MAC-based control
Authorized IP Manager security
KMS (Key Management System)
HP provides PDF versions of the switch documentation on the Product Documentation CD-ROM shipped with the switch. You can also download the
latest version of any HP ProCurve switch manual (PDF format) from the HP ProCurve website. (Refer to
“Getting Documentation From the Web” on
page 1-6.)
1-5
Getting Started

Getting Documentation From the Web

Getting Documentation From the Web
1. Go to the HP Procurve website at
2. Click on technical support.
3. Click on manuals.
4. Click on the product for which you want to view or download a manual.
2
http://www.hp.com/go/hpprocurve
3
4
Figure 1-2. Example of How To Locate Product Manuals on the HP ProCurve Website
1-6

Sources for More Information

Sources for More Information
If you need information on specific parameters in the menu interface,
refer to the online help provided in the interface. For example:
Online Help for Menu
Figure 1-3.Example of How To Display Online Help for the Menu Interface
Getting Started
If you need information on a specific command in the CLI, type the
command name followed by “help”. For example:
Figure 1-4.Example of How To Display Help for a CLI Command
If you need information on specific features in the HP Web Browser
Interface (hereafter referred to as the “web browser interface”), use the online help available for the web browser interface. For more information on web browser Help, refer to “Online Help for the HP Web Browser Interface” in the chapter titled “Using the HP Web Browser Interface” in the Management and Configuration Guide for your switch.
1-7
Getting Started

Need Only a Quick Start?

If you need further information on Hewlett-Packard switch technology,
visit the HP ProCurve website at:
http://www.hp.com/go/hpprocurve
Need Only a Quick Start?

IP Addressing

If you just want to give the switch an IP address so that it can communicate on your network, or if you are not using VLANs, HP recommends that you use the Switch Setup screen to quickly configure IP addressing. To do so, do one of the following:
Enter setup at the CLI Manager level prompt.
HPswitch# setup
In the Main Menu of the Menu interface, select
8. Run Setup
For more on using the Switch Setup screen, see the Installation and Getting Started Guide you received with the switch.

To Set Up and Install the Switch in Your Network

Important! Use the HP Procurve Installation and Getting Started Guide (shipped with
the switch) for the following:
Notes, cautions, and warnings related to installing and using the switch
and its related modules
Instructions for physically installing the switch in your network
Quickly assigning an IP address and subnet mask, set a Manager pass-
word, and (optionally) configure other basic features.
Interpreting LED behavior.
For the latest version of the Installation and Getting Started Guide for your switch, refer to “Getting Documentation From the Web” on page 1-6.
1-8
Loading...
+ 634 hidden pages