Professional Documents
Culture Documents
Content
Content
CHAPTER 1 VLAN CONFIGURATION 1
1.1 Commands for VLAN Configuration.......................................................................1 1 1 1 de!ug g"r# 1 1 1 $ g"r# 1 1 1 % gar# timer &o'd 1 1 1 ( gar# timer )oin $ 1 1 * gar# timer 'ea"e $ 1 1 + gar# timer 'ea"ea'' % 1 1 , name % 1 1 - #ri"ate."'an % 1 1 / #ri"ate."'an asso0iation ( 1 1 11 s&o2 gar# * 1 1 11 s&o2 g"r# * 1 1 1$ s&o2 "'an * 1 1 1% s2it0&#ort a00ess "'an + 1 1 1( s2it0&#ort interfa0e , 1 1 1* s2it0&#ort mode , 1 1 1+ s2it0&#ort trun3 a''o2ed "'an , 1 1 1, s2it0&#ort trun3 nati"e "'an 1 1 1- "'an 1 1 1/ "'an ingress ena!'e /
2.1 Commands for MAC Address Table Configuration................................................1 $ 1 1 ma0.address.ta!'e aging.time 1 $ 1 $ ma0.address.ta!'e stati07!'a03&o'e 1 $ 1 % s&o2 ma0.address.ta!'e $ 2.2 Commands for Mac Address Binding configuration...............................................2 $ $ 1 0'ear #ort.se0urit8 d8nami0 $ $ $ $ ma0.address.ta!'e #eriodi0.monitor.time % $ $ % ma0.address.ta!'e s8n0&roni9ing ena!'e % $ $ ( s&o2 #ort.se0urit8 % $ $ * s&o2 #ort.se0urit8 address ( $ $ + s&o2 #ort.se0urit8 interfa0e * $ $ , s2it0&#ort #ort.se0urit8 * 1
Commands for VLAN and MAC Address Configuration $ $ - s2it0&#ort #ort.se0urit8 0on"ert $ $ / s2it0&#ort #ort.se0urit8 'o03 $ $ 11 s2it0&#ort #ort.se0urit8 ma0.address $ $ 11 s2it0&#ort #ort.se0urit8 ma:imum $ $ 1$ s2it0&#ort #ort.se0urit8 timeout $ $ 1% s2it0&#ort #ort.se0urit8 "io'ation
Content + + , , , -
1 1 $ g"r#
Command; g"r# no g"r# Fun0tion; Enable the GV ! function for the s,itch or the current Trun* %ort. the # no g"r#& command disables the GV ! function globall' or for the %ort. Command mode; !ort Mode and Global Mode. 4efau't; GV ! is disabled b' default. Usage Guide; !ort GV ! can onl' be enabled after global GV ! is enabled. /hen global GV ! is disabled) the GV ! configurations in the %orts are also disabled. Note" GV ! can onl' be enabled on Trun* %orts. E:am#'e; Enable the GV ! function globall' and for Trun* %ort 10. +,itch1config2-g$r% +,itch1config2-interface ethernet 1310 +,itch1Config45f4Ethernet13102-g$r% +,itch1config2-e6it
Parameter; <timer-value> is the $alue for GA ! hold timer) the $alid range is 100 to 7289:0 ms. Command mode; !ort Mode. 4efau't; The default $alue for hold timer is 100 ms. Usage Guide; /hen GA ! a%%lication entities recei$e a ;oin message) ;oin message ,ill not be sent immediatel'. 5nstead) hold timer is started. After hold timer timeout) all ;oin messages recei$ed ,ith the hold time ,ill be sent in one GV ! frame) thus effecti$el' reducing %rotocol message traffic. E:am#'e; +et the GA ! hold timer $alue of %ort 1310 to :00 ms. +,itch1Config45f4Ethernet13102-gar% timer hold :00
1 1 , name
Command; name <vlan-name> no name Fun0tion; +%ecif' a name) a descri%ti$e string) for the VLAN. the no o%eration of the command ,ill delete the name of the VLAN. Parameters; <"'an.name= is the s%ecified name string. Command Mode; VLAN Configuration Mode. 4efau't; The default VLAN name is $lan===) ,here 666 is V5>. Usage Guide; The s,itch can s%ecif' names for different VLANs) ma*ing it easier for users to identif' and manage VLANs. E:am#'es; +%ecif' the name of VLAN100 as TestVlan. +,itch1Config4Vlan1002-name TestVlan
1 1 - #ri"ate."'an
Command; #ri"ate."'an >#rimar8 7 iso'ated 7 0ommunit8? no #ri"ate."'an Fun0tion; Configure current VLAN to !ri$ate VLAN. The #no #ri"ate."'an& command cancels the !ri$ate VLAN configuration. Parameter; #rimar8 set current VLAN to !rimar' VLAN) iso'ated set current VLAN to 5solated VLAN) 0ommunit8 set current VLAN to Communit' VLAN. Command Mode; VLAN mode 4efau't; !ri$ate VLAN is not configured b' default. Usage Guide; There are three !ri$ate VLANs" Primar8 VLAN) Iso'ated VLAN and Communit8 VLAN. !orts in !rimar' there are three !ri$ate VLANs" !rimar' VLAN) %
5solated VLAN and Communit' VLAN can communicate ,ith %orts of 5solated VLAN and Communit' VLAN related to this !rimar' VLAN. !orts in 5solated VLAN are isolated bet,een each other and onl' communicate ,ith %orts in !rimar' VLAN the' related to. %orts in Communit' VLAN can communicate both ,ith each other and ,ith !rimar' VLAN %orts the' related to. there is no communication bet,een %orts in Communit' VLAN and %ort in 5solated VLAN. <nl' VLANs containing em%t' Ethernet %orts can be set to !ri$ate VLAN) and onl' the !ri$ate VLANs configured ,ith associated %ri$ate relationshi%s can set the Access Ethernet %orts their member %orts. Normal VLAN ,ill clear its Ethernet %orts ,hen set to !ri$ate VLAN. 5t is to be noted !ri$ate VLAN messages ,ill not be transmitted b' GV !. E:am#'e; +et VLAN100) 200) 700 to %ri$ate $lans) ,ith res%ecti$el' %rimar') 5solated) Communit' t'%es. +,itch1config2-$lan 100 +,itch1Config4Vlan1002-%ri$ate4$lan %rimar' Note"This ,ill remo$e all the %orts from $lan 100 +,itch1Config4Vlan1002-e6it +,itch1config2-$lan 200 +,itch1Config4Vlan2002-%ri$ate4$lan isolated Note"This ,ill remo$e all the %orts from $lan 200 +,itch1Config4Vlan2002-e6it +,itch1config2-$lan 700 +,itch1Config4Vlan7002-%ri$ate4$lan communit' Note"This ,ill remo$e all the %orts from $lan 700 +,itch1Config4Vlan7002-e6it
1 1 / #ri"ate."'an asso0iation
Command; #ri"ate."'an asso0iation <secondary-vlan-list> no #ri"ate."'an asso0iation Fun0tion; +et !ri$ate VLAN association. the #no #ri"ate."'an asso0iation& command cancels !ri$ate VLAN association. Parameter; <secondary-vlan-list> +ets +econdar' VLAN list ,hich is associated to !rimar' VLAN. There are t,o t'%es of +econdar' VLAN" 5solated VLAN and Communit' VLAN. (sers can set multi%le +econdar' VLANs b' #.&. Command mode; VLAN Mode. 4efau't; There is no !ri$ate VLAN association b' default. Usage Guide; This command can onl' used for !ri$ate VLAN. The %orts in +econdar' VLANs ,hich are associated to !rimar' VLAN can communicate to the %orts in !rimar' VLAN. Before setting !ri$ate VLAN association) three t'%es of !ri$ate VLANs should ha$e no member %orts. the !ri$ate VLAN ,ith !ri$ate VLAN association can?t be deleted. /hen users delete !ri$ate VLAN association) all the member %orts in the !ri$ate VLANs ,hose
association is deleted are remo$ed from the !ri$ate VLANs. E:am#'e; Associate 5solated VLAN200 and Communit' VLAN700 to !rimar' VLAN100. +,itch1Config4Vlan1002-%ri$ate4$lan association 200.700
1 1 11 s&o2 gar#
Command; s&o2 gar# @<interface-name>A Fun0tion; >is%la' the global and %ort information for GA !. Parameter; <interface-name> stands for the name of the Trun* %ort to be dis%la'ed. Command mode; Admin Mode and other configuration Mode. Usage Guide; N3A. E:am#'e; >is%la' global GA ! information. +,itch -sho, gar%
1 1 11 s&o2 g"r#
Command; s&o2 g"r# @<interface-name>A Fun0tion; >is%la' the global and %ort information for GV !. Parameter; <interface-name> stands for the name of the Trun* %ort to be dis%la'ed. Command mode; Admin Mode and other configuration Mode. Usage Guide; N3A. E:am#'e; >is%la' global GV ! information. +,itch-sho, g$r% configuration 4444444444444444 G$r% 5nformation 444444444444444444 G$r% status " enable G$r% Timers1milliseconds2 Lea$eAll " 10000
1 1 1$ s&o2 "'an
Command; s&o2 "'an @!rief 7 summar8A @id <vlan-id>A @name <vlan-name=A @interna' usage @id <vlan-id> 7 name <vlan-name>AA Fun0tion; >is%la' detailed information for all VLANs or s%ecified VLAN. Parameter; !rief stands for brief information. summar8 for VLAN statistics. <vlan-id> for VLAN 5> of the VLAN to dis%la' status information) the $alid range is 1 to @0A@. <vlan-name> is the VLAN name for the VLAN to dis%la' status information) $alid length is 1 to 11 characters. Command mode; Admin Mode and configuration Mode. Usage Guide; 5f no <vlan-id> or <vlan-name> is s%ecified) then information for all VLANs in the s,itch ,ill be dis%la'ed. E:am#'e; >is%la' the status for the current VLAN. dis%la' statistics for the current VLAN. +,itch-sho, $lan VLAN Name T'%e Media !orts
4444 444444444444 4444444444 444444444 4444444444444444444444444444444444444444 1 default +tatic ENET Ethernet131 Ethernet132 Ethernet137 Ethernet13@ Ethernet13A Ethernet1310 Ethernet1311 Ethernet1312 2 VLAN0002 +tatic ENET Ethernet13: Ethernet139 Ethernet138 Ethernet13B +,itch-sho, $lan summar' The ma6. $lan entr's" @0A@ E6isting Vlans" (ni$ersal Vlan" 1 12 17 1: 19 22 Total E6isting Vlans is"9 >is%la'ed information VLAN Name T'%e Media !orts E6%lanation VLAN number VLAN name VLAN t'%e) staticall' d'namicall' learned. Access %ort ,ithin a VLAN configured or
1 1 1( s2it0&#ort interfa0e
Command; s2it0&#ort interfa0e @et&ernet 7 #ort0&anne'A @interfa0e.name 7 interfa0e. 'istA no s2it0&#ort interfa0e @et&ernet 7 #ort0&anne'A @interfa0e.name 7 interfa0e.'istA Fun0tion; +%ecif' Ethernet %ort to VLAN. the # no s2it0&#ort interfa0e @et&ernet 7 #ort0&anne'A @<interface-name | interface-list>A& command deletes one or one set of %orts from the s%ecified VLAN. Parameter; et&ernet is the Ethernet %ort to be added. #ort0&anne' means that the %ort to be added is a lin*4aggregation %ort. interfa0e.name %ort name) such as e131. 5f this o%tion is selected) ethernet or %ortchannel should not be. interfa0e.'ist is the %ort list to be added or deleted) #.& and #4& are su%%orted) for e:am#'e; ethernet131.7.@48.B. Command mode; VLAN Mode. 4efau't; A ne,l' created VLAN contains no %ort b' default. Usage Guide; Access %orts are normal %orts and can ;oin a VLAN) but a %ort can onl' ;oin one VLAN for a time. E:am#'e; Assign Ethernet %ort 1) 7) @48) B of VLAN100. +,itch1Config4Vlan1002-s,itch%ort interface ethernet 131.7.@48.B
1 1 1* s2it0&#ort mode
Command; s2it0&#ort mode >trun3 7 a00ess? Fun0tion; +et the %ort in access mode or trun* mode. Parameter; trun3 means the %ort allo,s traffic of multi%le VLAN. a00ess indicates the %ort belongs to one VLAN onl'. Command mode; !ort Mode. 4efau't; The %ort is in Access mode b' default. Usage Guide; !orts in trun* mode is called Trun* %orts. Trun* %orts can allo, traffic of multi%le VLANs to %ass through. VLAN in different s,itches can be interconnected ,ith the Trun* %orts. !orts under access mode are called Access %orts. An access %ort can be assigned to one and onl' one VLAN at a time. E:am#'e; +et %ort : to trun* mode and %ort B to access mode. +,itch1config2-interface ethernet 13: +,itch1Config45f4Ethernet13:2-s,itch%ort mode trun* +,itch1Config45f4Ethernet13:2-e6it +,itch1config2-interface ethernet 13B +,itch1Config45f4Ethernet13B2-s,itch%ort mode access +,itch1Config45f4Ethernet13B2-e6it
Command; s2it0&#ort trun3 a''o2ed "'an >BOR4 7 a'' 7 add BOR4 7 e:0e#t BOR4 7 remo"e BOR4? no s2it0&#ort trun3 a''o2ed "'an Fun0tion; +et trun* %ort to allo, VLAN traffic. the # no s2it0&#ort trun3 a''o2ed "'an& command restores the default setting. Parameter; BOR4; s%ecified V5>s. *e',ord. a''; all V5>s) the range from 1 to @0A@. add; add assigned V5>s behind a''o2 "'an. e:0e#t; all V5> add to a''o2 "'an e6ce%t assigned V5>s. remo"e; delete assigned a''o2 "'an from a''o2 "'an list. Command mode; !ort Mode. 4efau't; Trun* %ort allo,s all VLAN traffic b' default. Usage Guide; The user can use this command to set the VLAN traffic allo,ed to %assthrough the Trun* %ort. traffic of VLANs not included are %rohibited. E:am#'e; +et Trun* %ort to allo, traffic of VLAN1) 7) :420. +,itch1config2-interface ethernet 13: +,itch1Config45f4Ethernet13:2-s,itch%ort mode trun* +,itch1Config45f4Ethernet13:2-s,itch%ort trun* allo,ed $lan 1.7.:420 +,itch1Config45f4Ethernet13:2-e6it
1 1 1- "'an
Command; "'an BOR4 no "'an BOR4 Fun0tion; Create VLANs and enter VLAN configuration mode. 5f using D.D and D4D connect
,ith multi4VLANs) then onl' create these VLANs. 5f onl' e6isting VLAN) then enter VLAN configuration mode. if the VLAN is not e6ist) then create VLAN and enter VLAN configuration mode. 5n VLAN Mode) the user can set VLAN name and assign the s,itch %orts to the VLAN. The no command deletes s%ecified VLANs. Parameter; /< > is the VLAN 5> to be created3deleted) $alid range is 1 to @0A@) connect ,ith D.D and D4D. Command mode; Global Mode. 4efau't; <nl' VLAN1 is set b' default. Usage Guide; VLAN1 is the default VLAN and cannot be configured or deleted b' the user. The ma6imal VLAN number is @0A@. 5t should be noted that d'namic VLANs learnt b' GV ! cannot be deleted b' this command. E:am#'e; Create VLAN100 and enter the configuration mode for VLAN 100. +,itch1config2-$lan 100 +,itch1Config4Vlan1002-
$ 1 $ ma0.address.ta!'e stati07!'a03&o'e
Command; ma0.address.ta!'e >stati0 7 !'a03&o'e? address <mac-addr> "'an <vlanid> @interfa0e et&ernet <interface-name>A 7 @sour0e 7 destination 7 !ot&A no ma0.address.ta!'e >stati0 7 !'a03&o'e 7 d8nami0? @address <macaddr>A @"'an <vlan-id>A @interfa0e ethernet <interface-name>A Fun0tion; Add or modif' static address entries and filter address entries. The no command deletes the t,o entries. Parameter; stati0 is the static entries. !'a03&o'e is filter entries) ,hich is for discarding frames from s%ecific MAC address) it can filter source address) destination address or the both. /hen choose the filter entries) blac*hole address can?t based on %ort) and not configure to interface. d8nami0 is d'namic address entries. <mac-addr> MAC address to be added or deleted.<interface-name> name of the %ort transmitting the MAC data %ac*et.<vlan-id> is the $lan number. sour0e is based on source address filter. destination is based on destination address filter. !ot& is based on source address and destination address filter) the default is both. Command Mode; Global Mode 1
4efau't; /hen VLAN interface is configured and is u%) the s'stem ,ill generate an static address ma%%ing entr' of ,hich the inherent MAC address corres%onds to the VLAN number. Usage Guide; 5n certain s%ecial a%%lications or ,hen the s,itch is unable to d'namicall' learn the MAC address) users can use this command to manuall' establish ma%%ing relation bet,een the MAC address and %ort and VLAN. no ma0.address.ta!'e command is for deleting all d'namic) static) filter MAC address entries e6isting in the s,itch MAC address list) e6ce%t for the ma%%ing entries retained in the s'stem default. E:am#'e; !ort 131 belongs to VLAN200) and establishes address ma%%ing ,ith MAC address 0040740f4f040041B. +,itch1config2-mac4address4table static address 0040740f4f040041B $lan 200 interface ethernet 131
$ 1 % s&o2 ma0.address.ta!'e
Command; s&o2 ma0.address.ta!'e @stati0 7 !'a03&o'e 7 mu'ti0ast 7 aging.time <aging-time= 7 0ountA @address <mac-addr=A @"'an <"'an.id=A @0ountA @interfa0e <interfa0e.name=A Fun0tion; +ho, the current MAC table. Parameter; stati0 static entries. !'a03&o'e filter entries. aging.time <aging-time= address aging time. 0ount entr'?s number) mu'ti0ast multicast entries. <mac-addr> entr'?s MAC address. <vlan-id> entr'?s VLAN number. <interface-name> entr'?s interface name. Command mode; Admin Mode and Configuration Mode. 4efau't; MAC address table is not dis%la'ed b' default. Usage guide; This command can dis%la' $arious sorts of MAC address entries. (sers can also use s&o2 ma0.address.ta!'e to dis%la' all the MAC address entries. E:am#'e; >is%la' all the filter MAC address entries. +,itch-sho, mac4address4table blac*hole
MAC in all loc*ed secure %orts ,ill be cleared. if onl' %ort but no MAC address is s%ecified) then all MAC addresses in the s%ecified %ort ,ill be cleared. E:am#'e; >elete all d'namic MAC in %ort1. +,itch-clear %ort4securit' d'namic interface Ethernet 131
$ $ $ ma0.address.ta!'e #eriodi0.monitor.time
Command; ma0.address.ta!'e #eriodi0.monitor.time <*.-+(11= Fun0tion; +et the MAC monitor inter$al to count the added and deleted MAC in time) and send out them ,ith tra% message. Parameter; <*.-+(11=; the inter$al is : to B9@00 seconds. Command mode; Global Mode. 4efau't; 90 seconds. Usage Guide; Associate this command ,ith mac4address4table s'nchroniEing enable command to use. E:am#'e; +et the MAC monitor inter$al as 120 seconds. +,itch1Config2-mac4address4table %eriodic4monitor4time 120
$ $ ( s&o2 #ort.se0urit8
Command; s&o2 #ort.se0urit8 Fun0tion; >is%la' the secure MAC addresses of the %ort. Command mode; Admin Mode and other configuration Mode. 4efau't; The s,itch is not dis%la' %ort4securit' configuration. Usage Guide; This command dis%la's the secure %ort MAC address information. E:am#'e; +,itch-sho, %ort4securit'
Ma6+ecurit' Addr CurrentAddr +ecurit' Action 1count2 1count2 44444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444 Ethernet131 1 1 !rotect Ethernet137 10 1 !rotect Ethernet13: 1 0 !rotect 44444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444444 Ma6 Addresses limit in +'stem "12B Total Addresses in +'stem "2 >is%la'ed information +ecurit' !ort Ma6+ecurit'Addr CurrentAddr +ecurit' Action Total Addresses in +'stem Ma6 Addresses +'stem limit in E6%lanation 5s %ort enabled as a secure %ort. The ma6imum secure MAC address number set for the securit' %ort. The current secure MAC address number of the securit' %ort. The $iolation mode of the %ort configuration. The current secure MAC address number of the s'stem. The ma6imum secure MAC address number of the s'stem.
Commands for VLAN and MAC Address Configuration !orts Total Addresses
C&a#ter $ Commands for MAC Address Ta!'e Configuration The %ort that the secure MAC address belongs to. Current secure MAC address number in the s'stem.
Current secure MAC address number for the %ort. Current secure static MAC address number for the %ort. /hether loc*ing timer 1timer timeout2 is enabled for the %ort. 5s the MAC address learning function enabled.
$ $ , s2it0&#ort #ort.se0urit8
*
Command; s2it0&#ort #ort se0urit8 no s2it0&#ort #ort se0urit8 Fun0tion; Enable MAC address binding function for the %ort. the # no s2it0&#ort #ort. se0urit8& command disables the MAC address binding function for the %ort. Command mode; !ort Mode. 4efau't; MAC address binding is not enabled b' default. Usage Guide; The MAC address binding function and !ort Aggregation functions are mutuall' e6clusi$e. Therefore) if MAC binding function for a %ort is to be enabled) the !ort Aggregation functions must be disabled) and the %ort enabling MAC address binding must not be a Trun* %ort. E:am#'e; Enable MAC address binding function for %ort 1and. +,itch1config2-interface Ethernet 131 +,itch1Config45f4Ethernet1312- s,itch%ort %ort securit'
no s2it0&#ort #ort.se0urit8 timeout Fun0tion; +et the timer for %ort loc*ing. the # no s2it0&#ort #ort.se0urit8 timeout& command restores the default setting. Parameter; < value> is the timeout $alue) the $alid range is 0 to 700s. Command mode; !ort Mode. 4efau't; !ort loc*ing timer is not enabled b' default. Usage Guide; The %ort loc*ing timer function is a d'namic MAC address loc*ing function. MAC address loc*ing and con$ersion of d'namic MAC entries to secure address entries ,ill be %erformed on loc*ing timer timeout. The MAC address binding function must be enabled %rior to running this command. E:am#'e; +et %ort1 loc*ing timer to 70 seconds. +,itch1config2-interface Ethernet 131 +,itch1Config45f4Ethernet1312- s,itch%ort %ort4securit' timeout 70