Cabletron Systems SmartSwitch Router User's Reference Manual

Other manuals for SmartSwitch Router: User's Reference Manual, Reference Manual
Manual is about: Cabletron SmartSwitch Router User Reference Manual

Summary of SmartSwitch Router

  • Page 1

    Smartswitch router user reference manual 9032578-04.

  • Page 2: Notice

    Notice 2 smartswitch router user reference manual notice cabletron systems reserves the right to make changes in specifications and other information contained in this document without prior notice. The reader should in all cases consult cabletron systems to determine whether any such changes have b...

  • Page 3: Industry Canada Notice

    Smartswitch router user reference manual 3 notice industry canada notice this digital apparatus does not exceed the class a limits for radio noise emissions from digital apparatus set out in the radio interference regulations of the canadian department of communications. Le présent appareil numériqu...

  • Page 4: Cabletron Systems, Inc.

    Notice 4 smartswitch router user reference manual cabletron systems, inc. Program license agreement important: this license applies for use of product in the following geographical regions: canada mexico central america south america before opening or utilizing the enclosed product, carefully read t...

  • Page 5

    Smartswitch router user reference manual 5 notice sections 1 or 2 of this agreement, you agree not to (i) reexport or release the program, the source code for the program or technology to a national of a country in country groups d:1 or e:2 (albania, armenia, azerbaijan, belarus, bulgaria, cambodia,...

  • Page 6: Program License Agreement

    Notice 6 smartswitch router user reference manual cabletron systems sales and service, inc. Program license agreement important: this license applies for use of product in the united states of america and by united states of america government end users. Before opening or utilizing the enclosed prod...

  • Page 7

    Smartswitch router user reference manual 7 notice kazakhstan, kyrgyzstan, laos, latvia, libya, lithuania, moldova, north korea, the people’s republic of china, romania, russia, rwanda, tajikistan, turkmenistan, ukraine, uzbekistan, vietnam, or such other countries as may be designated by the united ...

  • Page 8: Cabletron Systems Limited

    Notice 8 smartswitch router user reference manual cabletron systems limited program license agreement important: this license applies for the use of the product in the following geographical regions: europe middle east africa asia australia pacific rim before opening or utilizing the enclosed produc...

  • Page 9

    Smartswitch router user reference manual 9 notice if the program is exported from the united states pursuant to the license exception tsr under the u.S. Export administration regulations, in addition to the restriction on transfer set forth in sections 1 or 2 of this agreement, you agree not to (i) ...

  • Page 10: Safety Information

    Notice 10 smartswitch router user reference manual safety information class 1 laser transceivers the ssr-hfx11-08 100base-fx module, ssr-gsx11-02 1000base-lx module, ssr-glx19-02 1000base-lx module, ssr-hfx29-08 100base-fx smf module, ssr-glx70-01 1000base-llx module, ssr-2-sx 1000base-sx module, ss...

  • Page 11: Declaration Of Conformity

    Smartswitch router user reference manual 11 notice declaration of conformity addendum application of council directive(s): 89/336/eec 73/23/eec manufacturer’s name: cabletron systems, inc. Manufacturer’s address: 35 industrial way po box 5005 rochester, nh 03867 european representative name: mr. J. ...

  • Page 12

    Notice 12 smartswitch router user reference manual.

  • Page 13: Contents

    Smartswitch router user reference manual 13 contents preface ..................................................................................................... 25 about this manual ................................................................................................................25 w...

  • Page 14

    Contents 14 smartswitch router user reference manual chapter 2: hot swapping line cards and control modules ................ 49 hot swapping overview...................................................................................................... 49 hot swapping line cards.........................

  • Page 15

    Smartswitch router user reference manual 15 contents creating a non-ip/non-ipx vlan ..............................................................................67 chapter 4: smarttrunk configuration guide...................................... 69 overview ..............................................

  • Page 16

    Contents 16 smartswitch router user reference manual monitoring ip parameters............................................................................................. 92 configuring router discovery ............................................................................................ 92 c...

  • Page 17

    Smartswitch router user reference manual 17 contents configuring ospf over non-broadcast multiple access .......................................120 monitoring ospf..................................................................................................................121 ospf configuration ...

  • Page 18

    Contents 18 smartswitch router user reference manual authentication .............................................................................................................. 170 authentication methods ...................................................................................... 170 aut...

  • Page 19

    Smartswitch router user reference manual 19 contents igmp overview ............................................................................................................199 dvmrp overview ........................................................................................................20...

  • Page 20

    Contents 20 smartswitch router user reference manual using dynamic nat ............................................................................................ 228 dynamic nat with ip overload (pat) configuration ......................................... 229 using dynamic nat with ip overload .....

  • Page 21

    Smartswitch router user reference manual 21 contents enabling ipx rip...........................................................................................................249 enabling sap ..............................................................................................................

  • Page 22

    Contents 22 smartswitch router user reference manual configuring layer-2 static entry filters................................................................... 277 configuring layer-2 secure port filters ................................................................... 277 monitoring layer-2 secu...

  • Page 23

    Smartswitch router user reference manual 23 contents control tables ...............................................................................................................303 using rmon .............................................................................................................

  • Page 24

    Contents 24 smartswitch router user reference manual compression on mlp bundles or links............................................................ 329 monitoring ppp wan ports.............................................................................................. 330 ppp port configuration ....

  • Page 25: Preface

    Smartswitch router user reference manual 25 preface about this manual this manual provides detailed information and procedures for configuring the smartswitch router (ssr) software. If you have not yet installed the ssr, use the instructions in the smartswitch router getting started guide to install...

  • Page 26

    Preface 26 smartswitch router user reference manual configure vrrp chapter 7 , “vrrp configuration guide” on page 95 configure rip routing chapter 8 , “rip configuration guide” on page 109 configure ospf routing chapter 9 , “ospf configuration guide” on page 115 configure bgp routing chapter 10 , “b...

  • Page 27: Related Documentation

    Smartswitch router user reference manual 27 preface related documentation the smartswitch router documentation set includes the following items. Refer to these other documents to learn more about your product. For information about see the installing and setting up the ssr smartswitch router getting...

  • Page 28

    Preface 28 smartswitch router user reference manual.

  • Page 29: Chapter 1

    Smartswitch router user reference manual 29 chapter 1 ssr product overview the smartswitch router (ssr) provides non-blocking, wire-speed layer-2 (switching), layer-3 (routing) and layer-4 (application) switching. The hardware provides wire-speed performance regardless of the performance monitoring,...

  • Page 30

    Chapter 1: ssr product overview 30 smartswitch router user reference manual capacity • 4,096 virtual lans (vlans) • 3 mb input/output buffering per gigabit port • 1 mb input/output buffering per 10/100 port ssr 2000: • up to 16,000 routes • up to 128,000 layer-4 application flows • up to 180,000 lay...

  • Page 31: Supported Routing Protocols

    Smartswitch router user reference manual 31 chapter 1: ssr product overview supported media (encapsulation type) the ssr supports the following industry-standard networking media: • ip: ieee 802.3 snap and ethernet type ii • ipx: ieee 802.3 snap, ethernet type ii, ipx 802.3, 802.2 • 802.1q vlan enca...

  • Page 32

    Chapter 1: ssr product overview 32 smartswitch router user reference manual – routing information protocol (rip) version 1, 2 chapter 6 , “ip routing configuration guide” on page 85 describes these protocols in detail. • exterior gateway protocol: – border gateway protocol (bgp) version 2,3,4 chapte...

  • Page 33

    Smartswitch router user reference manual 33 chapter 1: ssr product overview basic line editing commands the cli supports emacs-like line editing commands. The following table lists some commonly used commands. Access modes the ssr cli has four access modes. • user – allows you to display basic infor...

  • Page 34

    Chapter 1: ssr product overview 34 smartswitch router user reference manual note: the command prompt will show the name of the smartswitch router in front of the mode character(s). The default name is “ssr”. When you are in configure or enable mode, enter the exit command or press ctrl+z to exit to ...

  • Page 35

    Smartswitch router user reference manual 35 chapter 1: ssr product overview enable mode enable mode provides more facilities than user mode. You can display critical features within enable mode including router configuration, access control lists, and snmp statistics. To enter enable mode, enter the...

  • Page 36

    Chapter 1: ssr product overview 36 smartswitch router user reference manual to exit enable mode and return to user mode, use one of the following commands: ip - show ip related parameters ip-policy - show ip policy information ip-redundancy - show ip redundancy information (vrrp) ip-router - show un...

  • Page 37

    Smartswitch router user reference manual 37 chapter 1: ssr product overview configure mode configure mode provides the capabilities to configure all features and functions on the ssr. You can configure features and functions within configure mode including router configuration, access control lists ...

  • Page 38

    Chapter 1: ssr product overview 38 smartswitch router user reference manual to exit configure mode and return to enable mode, use one of the following commands: boot prom mode if your ssr does not find a valid system image on the external pcmcia flash, the system might enter programmable read-only m...

  • Page 39

    Smartswitch router user reference manual 39 chapter 1: ssr product overview disabling a function or feature the cli provides for an implicit negate. This allows for the “disabling” of a feature or function which has been “enabled”. Use the negate command on a specific line of the active configuratio...

  • Page 40

    Chapter 1: ssr product overview 40 smartswitch router user reference manual loading system image software by default, the ssr boots using the system image software installed on the control module’s pcmcia flash card. To upgrade the system software and boot using the upgraded image, use the following...

  • Page 41

    Smartswitch router user reference manual 41 chapter 1: ssr product overview 6. Enter the system image list command to verify the change. Note: you do not need to activate this change. Loading boot prom software the ssr boots using the boot prom software installed on the control module’s internal mem...

  • Page 42

    Chapter 1: ssr product overview 42 smartswitch router user reference manual 1. If you have not already done so, enter the enable command to enter enable mode in the cli. 2. If you have not already done so, enter the configure command to enter configure mode in the cli. 3. Enter the following command...

  • Page 43: Managing The Ssr

    Smartswitch router user reference manual 43 chapter 1: ssr product overview displaying configuration changes while in configure mode, you can display the configuration of the running system as well as non-activated changes that are in the scratchpad by entering the following command: while in enable...

  • Page 44

    Chapter 1: ssr product overview 44 smartswitch router user reference manual • configuring dns • connecting between the ssr and other systems setting the ssr name the ssr name is set to ssr by default. You may customize the name for the ssr by entering the following command in configure mode: setting...

  • Page 45

    Smartswitch router user reference manual 45 chapter 1: ssr product overview configuring the ssr cli you can customize the cli display format to a desired line length or row count. To configure the cli terminal display, enter the following command in enable mode: configuring snmp services the ssr acc...

  • Page 46

    Chapter 1: ssr product overview 46 smartswitch router user reference manual connecting between the ssr and other systems to test a connection between the ssr and an ip host, enter the following command in user or enable mode: to open a telnet session from the ssr to an ip host, enter the following c...

  • Page 47: Monitoring Configuration

    Smartswitch router user reference manual 47 chapter 1: ssr product overview monitoring configuration the ssr provides many commands for displaying configuration information. After you add configuration items and commit them to the active configuration, you can display them using the following comman...

  • Page 48

    Chapter 1: ssr product overview 48 smartswitch router user reference manual show ssr location. System show location show the ssr login banner. System show login-banner show ssr name. System show name show the type of power-on self test (post) that should be performed. System show poweron-selftest- m...

  • Page 49: Chapter 2

    Smartswitch router user reference manual 49 chapter 2 hot swapping line cards and control modules hot swapping overview this chapter describes the hot swapping functionality of the ssr. Hot swapping is the ability to replace a line card or control module while the ssr is operating. Hot swapping allo...

  • Page 50

    Chapter 2: hot swapping line cards and control modules 50 smartswitch router user reference manual deactivating the line card to deactivate the line card, do one of the following: • press the hot swap button on the line card. The hot swap button is recessed in the line card's front panel. Use a pen ...

  • Page 51

    Smartswitch router user reference manual 51 chapter 2: hot swapping line cards and control modules warning : do not remove the line card unless the offline led is lit. Doing so can cause the ssr to crash. 2. Loosen the captive screws on each side of the line card. 3. Carefully remove the line card f...

  • Page 52

    Chapter 2: hot swapping line cards and control modules 52 smartswitch router user reference manual warning : you can only hot swap an inactive control module. You should never remove the active control module from the ssr. Doing so will crash the system. The procedure for hot swapping a control modu...

  • Page 53: Only)

    Smartswitch router user reference manual 53 chapter 2: hot swapping line cards and control modules installing the control module to install a new control module or line card into the slot: note: you can install either a line card or a control module in slot cm/1, but you can install only a control m...

  • Page 54

    Chapter 2: hot swapping line cards and control modules 54 smartswitch router user reference manual the online led goes out and the offline led lights. Figure 3 shows the location of the offline led and hot swap button on a switching fabric module. Figure 3. Location of offline led and hot swap butto...

  • Page 55: Chapter 3

    Smartswitch router user reference manual 55 chapter 3 bridging configuration guide bridging overview the smartswitch router provides the following bridging functions: • compliance with the ieee 802.1d standard • compliance with the igmp multicast bridging standard • wire-speed address-based bridging...

  • Page 56: Vlan Overview

    Chapter 3: bridging configuration guide 56 smartswitch router user reference manual bridging modes (flow-based and address-based) the ssr provides the following types of wire-speed bridging: address-based bridging - the ssr performs this type of bridging by looking up the destination address in an l...

  • Page 57

    Smartswitch router user reference manual 57 chapter 3: bridging configuration guide • multicast based • policy based detailed information about these types of vlans is beyond the scope of this manual. Each type of vlan is briefly explained in the following subsections. Port-based vlans ports of l2 d...

  • Page 58

    Chapter 3: bridging configuration guide 58 smartswitch router user reference manual multicast-based vlans multicast-based vlans are created dynamically for multicast groups. Typically, each multicast group corresponds to a different vlan. This ensures that multicast frames are received only by those...

  • Page 59

    Smartswitch router user reference manual 59 chapter 3: bridging configuration guide the ssr as a result of creating l3 interfaces for ip and/or ipx. However, these implicit vlans do not need to be created or configured manually. The implicit vlans created by the ssr are subnet-based vlans. Most comm...

  • Page 60

    Chapter 3: bridging configuration guide 60 smartswitch router user reference manual for example, if port 1 belongs to vlan ipx_vlan for ipx, vlan ip_vlan for ip and vlan other_vlan for any other protocol, then an ip frame received by port 1 is classified as belonging to vlan ip_vlan. Trunk ports (80...

  • Page 61

    Smartswitch router user reference manual 61 chapter 3: bridging configuration guide the corresponding bridge tables for address-based and flow-based bridging are shown below. As shown, the bridge table contains more information on the traffic patterns when flow-based bridging is enabled compared to ...

  • Page 62

    Chapter 3: bridging configuration guide 62 smartswitch router user reference manual the ssr supports per vlan spanning tree. By default, all the vlans defined belong to the default spanning tree. You can create a separate instance of spanning tree using the following command: by default, spanning tr...

  • Page 63

    Smartswitch router user reference manual 63 chapter 3: bridging configuration guide to set the bridge priority, enter the following command in configure mode: setting a port priority you can set a priority for an interface. When two bridges tie for position as the root bridge, you configure an inter...

  • Page 64

    Chapter 3: bridging configuration guide 64 smartswitch router user reference manual • define the maximum idle interval adjusting the interval between hello times you can specify the interval between hello time. To adjust this interval, enter the following command in configure mode: defining the forw...

  • Page 65

    Smartswitch router user reference manual 65 chapter 3: bridging configuration guide configuring a port or protocol based vlan to create a port or protocol based vlan, perform the following steps in the configure mode. 1. Create a port or protocol based vlan. 2. Add physical ports to a vlan. Creating...

  • Page 66: Monitoring Bridging

    Chapter 3: bridging configuration guide 66 smartswitch router user reference manual configuring layer-2 filters layer-2 security filters on the ssr allow you to configure ports to filter specific mac addresses. When defining a layer-2 security filter, you specify to which ports you want the filter t...

  • Page 67: Configuration Examples

    Smartswitch router user reference manual 67 chapter 3: bridging configuration guide configuration examples vlans are used to associate physical ports on the ssr with connected hosts that may be physically separated but need to participate in the same broadcast domain. To associate ports to a vlan, y...

  • Page 68

    Chapter 3: bridging configuration guide 68 smartswitch router user reference manual.

  • Page 69: Chapter 4

    Smartswitch router user reference manual 69 chapter 4 smarttrunk configuration guide overview this chapter explains how to configure and monitor smarttrunks on the ssr. A smarttrunk is cabletron systems’ technology for load balancing and load sharing. For a description of the smarttrunk commands, se...

  • Page 70: Configuring Smarttrunks

    Chapter 4: smarttrunk configuration guide 70 smartswitch router user reference manual configuring smarttrunks to create a smarttrunk: 1. Create a smarttrunk and specify a control protocol for it. 2. Add physical ports to the smarttrunk. 3. Specify the policy for distributing traffic across smarttrun...

  • Page 71: Monitoring Smarttrunks

    Smartswitch router user reference manual 71 chapter 4: smarttrunk configuration guide to add ports to a smarttrunk, enter the following command in configure mode:: specify traffic distribution policy (optional) the default policy for distributing traffic across the ports in a smarttrunk is “round- r...

  • Page 72: Example Configurations

    Chapter 4: smarttrunk configuration guide 72 smartswitch router user reference manual example configurations the following shows a network design based on smarttrunks. R1 is an ssr operating as a router, while s1 and s2 are ssrs operating as switches. The following is the configuration for the cisco...

  • Page 73

    Smartswitch router user reference manual 73 chapter 4: smarttrunk configuration guide the following is the smarttrunk configuration for the ssr labeled ‘r1’ in the diagram: the following is the smarttrunk configuration for the ssr labeled ‘s1’ in the diagram: the following is the smarttrunk configur...

  • Page 74

    Chapter 4: smarttrunk configuration guide 74 smartswitch router user reference manual.

  • Page 75: Chapter 5

    Smartswitch router user reference manual 75 chapter 5 dhcp configuration guide dhcp overview the dynamic host configuration protocol (dhcp) server on the ssr provides dynamic address assignment and configuration to dhcp capable end-user systems, such as windows 95/98/nt and apple macintosh systems. ...

  • Page 76: Configuring Dhcp

    Chapter 5: dhcp configuration guide 76 smartswitch router user reference manual configuring dhcp by default, the dhcp server is not enabled on the ssr. You can selectively enable dhcp service on particular interfaces and not others. To enable dhcp service on an interface, you must first define a dhc...

  • Page 77

    Smartswitch router user reference manual 77 chapter 5: dhcp configuration guide to define the parameters that the dhcp server gives the clients, enter the following command in configure mode: configuring a static ip address to define a static ip address that the dhcp server can assign to a client wi...

  • Page 78: Updating The Lease Database

    Chapter 5: dhcp configuration guide 78 smartswitch router user reference manual configuring dhcp server parameters you can configure several “global” parameters that affect the behavior of the dhcp server itself. To configure global dhcp server parameters, enter the following commands in configure m...

  • Page 79: Dhcp Configuration Examples

    Smartswitch router user reference manual 79 chapter 5: dhcp configuration guide dhcp configuration examples the following configuration describes dhcp configuration for a simple network with just one interface on which dhcp service is enabled to provide both dynamic and static ip addresses. 1. Creat...

  • Page 80

    Chapter 5: dhcp configuration guide 80 smartswitch router user reference manual 9. Specify a remote lease database on the tftp server 10.1.89.88. 10. Specify a database update interval of every 15 minutes. Configuring secondary subnets in some network environments, multiple logical subnets can be im...

  • Page 81

    Smartswitch router user reference manual 81 chapter 5: dhcp configuration guide 6. Include ‘scope2’ in the superscope ‘super1’. Since there are multiple pools of ip addresses, the pool associated with ‘scope1’ is used first since ‘scope1’ is applied to the interface before ‘scope2’. Clients that are...

  • Page 82

    Chapter 5: dhcp configuration guide 82 smartswitch router user reference manual 6. Define the address pool for ‘scope2’. 7. Create a superscope ‘super1’ that includes ‘scope1’. 8. Include ‘scope2’ in the superscope ‘super1’. For clients on the secondary subnet, the default gateway is 10.2.1.1, which...

  • Page 83

    Smartswitch router user reference manual 83 chapter 5: dhcp configuration guide 4. Define the address pool for ‘scope1’. Dhcp scope1 define pool 10.5.1.10-10.5.1.20

  • Page 84

    Chapter 5: dhcp configuration guide 84 smartswitch router user reference manual.

  • Page 85: Chapter 6

    Smartswitch router user reference manual 85 chapter 6 ip routing configuration guide this chapter describes how to configure ip interfaces and general non-protocol-specific routing parameters. Ip routing overview internet protocol (ip) is a packet-based protocol used to exchange data over computer n...

  • Page 86

    Chapter 6: ip routing configuration guide 86 smartswitch router user reference manual the ssr supports standards-based tcp, udp, and ip. Ip routing protocols the ssr supports standards-based unicast and multicast routing. Unicast routing protocol support includes interior gateway protocols and exter...

  • Page 87

    Smartswitch router user reference manual 87 chapter 6: ip routing configuration guide configuring ip interfaces and parameters this section provides an overview of configuring various ip parameters and setting up ip interfaces. Configuring ip addresses to ports you can configure one ip interface dir...

  • Page 88

    Chapter 6: ip routing configuration guide 88 smartswitch router user reference manual • 802.3 snap: snap ieee 802.3 encapsulation, in which the type code becomes the frame length for the ieee 802.2 llc encapsulation (destination and source service access points, and a control byte) to configure ip e...

  • Page 89

    Smartswitch router user reference manual 89 chapter 6: ip routing configuration guide configuring reverse address resolution protocol (rarp) reverse address resolution protocol (rarp) works exactly the opposite of arp. Taking a mac address as input, rarp determines the associated ip address. Rarp is...

  • Page 90

    Chapter 6: ip routing configuration guide 90 smartswitch router user reference manual monitoring rarp you can use the following commands to obtain information about the ssr’s rarp configuration: configuring dns parameters the ssr can be configured to specify dns servers, which supply name services f...

  • Page 91

    Smartswitch router user reference manual 91 chapter 6: ip routing configuration guide configuring ip helper you can configure the ssr to forward udp broadcast packets received on a given interface to all other interfaces or to a specified ip address. You can specify a udp port number for which udp b...

  • Page 92

    Chapter 6: ip routing configuration guide 92 smartswitch router user reference manual packets to be processed on the ssr even if directed broadcast is not enabled on the interface receiving the packet. Similarly, the ssr installs flows to drop packets destined for the ssr for which service is not pr...

  • Page 93: Configuration Examples

    Smartswitch router user reference manual 93 chapter 6: ip routing configuration guide address or an interface is configured for the limited broadcast address 255.255.255.255, the router advertisement includes all ip addresses configured on the physical interface. When router advertisements are sent ...

  • Page 94

    Chapter 6: ip routing configuration guide 94 smartswitch router user reference manual you can also assign an ip or ipx interface directly to a physical port. For example, to assign an ip interface ‘red’ to physical port et.3.4, perform the following: ssr(config)# interface create ip red address-netm...

  • Page 95: Chapter 7

    Smartswitch router user reference manual 95 chapter 7 vrrp configuration guide vrrp overview this chapter explains how to set up and monitor the virtual router redundancy protocol (vrrp) on the ssr. Vrrp is defined in rfc 2338. End host systems on a lan are often configured to send packets to a stat...

  • Page 96

    Chapter 7: vrrp configuration guide 96 smartswitch router user reference manual basic vrrp configuration figure 4 shows a basic vrrp configuration with a single virtual router. Routers r1 and r2 are both configured with one virtual router ( vrid=1 ). Router r1 serves as the master and router r2 serv...

  • Page 97

    Smartswitch router user reference manual 97 chapter 7: vrrp configuration guide in vrrp, the router that owns the ip address associated with the virtual router is the master. Any other routers that participate in this virtual router are backups. In this configuration, router r1 is the master for vir...

  • Page 98

    Chapter 7: vrrp configuration guide 98 smartswitch router user reference manual figure 5. Symmetrical vrrp configuration in this configuration, half the hosts use 10.0.0.1/16 as their default route, and half use 10.0.0.2/16. Ip address 10.0.0.1/16 is associated with virtual router vrid=1 , and ip ad...

  • Page 99

    Smartswitch router user reference manual 99 chapter 7: vrrp configuration guide on line 5, router r1 associates ip address 10.0.0.2/16 with virtual router vrid=2 . However, since router r1 does not own ip address 10.0.0.2/16, it is not the default master for virtual router vrid=2 . Configuration of ...

  • Page 100

    Chapter 7: vrrp configuration guide 100 smartswitch router user reference manual figure 6. Multi-backup vrrp configuration in this configuration, router r1 is the master for virtual router vrid=1 and the primary backup for virtual routers vrid=2 and vrid=3 . If router r2 or r3 were to go down, route...

  • Page 101

    Smartswitch router user reference manual 101 chapter 7: vrrp configuration guide configuration of router r1 the following is the configuration file for router r1 in figure 6 . Router r1’s ip address on interface test is 10.0.0.1. There are three virtual routers on this interface: • vrid=1 – ip addre...

  • Page 102

    Chapter 7: vrrp configuration guide 102 smartswitch router user reference manual the following table shows the priorities for each virtual router configured on router r1. Configuration of router r2 the following is the configuration file for router r2 in figure 6 . Line 8 sets the backup priority fo...

  • Page 103

    Smartswitch router user reference manual 103 chapter 7: vrrp configuration guide note: since 100 is the default priority, line 9, which sets the priority to 100, is actually unnecessary. It is included for illustration purposes only. Configuration of router r3 the following is the configuration file...

  • Page 104

    Chapter 7: vrrp configuration guide 104 smartswitch router user reference manual setting the backup priority as described in “multi-backup configuration” on page 99 , you can specify which backup router takes over when the master router goes down by setting the priority for the backup routers. To se...

  • Page 105: Monitoring Vrrp

    Smartswitch router user reference manual 105 chapter 7: vrrp configuration guide setting an authentication key by default, no authentication of vrrp packets is performed on the ssr. You can specify a clear-text password to be used to authenticate vrrp exchanges. To enable authentication, enter the f...

  • Page 106: Vrrp Configuration Notes

    Chapter 7: vrrp configuration guide 106 smartswitch router user reference manual ip-redundancy show the ip-redundancy show command reports information about a vrrp configuration. To display vrrp information, enter the following commands in enable mode. Vrrp configuration notes • the master router se...

  • Page 107

    Smartswitch router user reference manual 107 chapter 7: vrrp configuration guide • a virtual router will respond to arp requests with a virtual mac address. This virtual mac depends on the virtual router id: virtual mac address = 00005e:0001xx where xx is the virtual router id this virtual mac addre...

  • Page 108

    Chapter 7: vrrp configuration guide 108 smartswitch router user reference manual.

  • Page 109: Chapter 8

    Smartswitch router user reference manual 109 chapter 8 rip configuration guide rip overview this chapter describes how to configure the routing information protocol (rip) on the smartswitch router. Rip is a distance-vector routing protocol for use in small networks. Rip is described in rfc 1723. A r...

  • Page 110

    Chapter 8: rip configuration guide 110 smartswitch router user reference manual enabling and disabling rip to enable or disable rip, enter one of the following commands in configure mode. Configuring rip interfaces to configure rip in the ssr, you must first add interfaces to inform rip about attach...

  • Page 112: Monitoring Rip

    Chapter 8: rip configuration guide 112 smartswitch router user reference manual configuring rip route preference you can set the preference of routes learned from rip. To configure rip route preference, enter the following command in configure mode. Configuring rip route default-metric you can defin...

  • Page 113: Configuration Example

    Smartswitch router user reference manual 113 chapter 8: rip configuration guide configuration example show rip information on the specified interface. Rip show interface show rip interface policy information. Rip show interface-policy show detailed information of all rip packets. Rip trace packets d...

  • Page 114

    Chapter 8: rip configuration guide 114 smartswitch router user reference manual ! ! Change default metric-out rip set interface ssr1-if1 metric-out 3.

  • Page 115: Chapter 9

    Smartswitch router user reference manual 115 chapter 9 ospf configuration guide ospf overview open shortest path first (ospf) is a link-state routing protocol that supports ip subnetting and authentication. The ssr supports ospf version 2.0 as defined in rfc 1583. Each link-state message contains al...

  • Page 116: Configuring Ospf

    Chapter 9: ospf configuration guide 116 smartswitch router user reference manual ospf multipath the ssr also supports ospf and static multi-path. If multiple equal-cost ospf or static routes have been defined for any destination, then the ssr “discovers” and uses all of them. The ssr will automatica...

  • Page 117

    Smartswitch router user reference manual 117 chapter 9: ospf configuration guide configuring ospf interface parameters you can configure the ospf interface parameters shown in the table below. To configure ospf interface parameters, enter one of the following commands in configure mode: table 4. Osp...

  • Page 118

    Chapter 9: ospf configuration guide 118 smartswitch router user reference manual configuring an ospf area ospf areas are a collection of subnets that are grouped in a logical fashion. These areas communicate with other areas via the backbone area. Once ospf areas are created, you can add interfaces,...

  • Page 119

    Smartswitch router user reference manual 119 chapter 9: ospf configuration guide configuring ospf area parameters the ssr allows configuration of various ospf area parameters, including stub areas, stub cost and authentication method. Stub areas are areas into which information on external routes is...

  • Page 120

    Chapter 9: ospf configuration guide 120 smartswitch router user reference manual to configure virtual links, enter the following commands in the configure mode. Configuring autonomous system external (ase) link advertisements these parameters specify the defaults used when importing ospf as external...

  • Page 121: Monitoring Ospf

    Smartswitch router user reference manual 121 chapter 9: ospf configuration guide monitoring ospf the ssr lets you display ospf statistics and configurations contained in the routing table. Information displayed provides routing and performance information. To display ospf information, enter the foll...

  • Page 122: Ospf Configuration Examples

    Chapter 9: ospf configuration guide 122 smartswitch router user reference manual ospf configuration examples for all examples in this section, refer to the configuration shown in figure 7 on page 126 . The following configuration commands for router r1: • determine the ip address for each interface ...

  • Page 123

    Smartswitch router user reference manual 123 chapter 9: ospf configuration guide exporting all interface & static routes to ospf router r1 has several static routes. We would export these static routes as type-2 ospf routes. The interface routes would be redistributed as type-1 ospf routes. 1. Creat...

  • Page 124

    Chapter 9: ospf configuration guide 124 smartswitch router user reference manual router r1 would like to redistribute its ospf, ospf-ase, rip, static and interface/direct routes into rip. 1. Enable rip on interface 120.190.1.1/16. 2. Create a ospf export destination for type-1 routes. 3. Create a os...

  • Page 125

    Smartswitch router user reference manual 125 chapter 9: ospf configuration guide 9. Create a rip export destination. 10. Create ospf export source. 11. Create ospf-ase export source. 12. Create the export-policy for redistributing all interface, rip, static, ospf and ospf- ase routes into rip. Ip-ro...

  • Page 126

    Chapter 9: ospf configuration guide 126 smartswitch router user reference manual f igu re 7 . E x p o rti ng t o o s p f bg p r1 r2 r3 r4 1 r4 2 r6 r1 1 a r e a b a c k b o n e a r e a 1 4 0 .1 .0 .0 (rip v2) 1 40. 1. 1. 1/24 1 40. 1. 2. 1/24 14 0. 1. 5/24 140. 1. 4/2 4 190. 1. 1. 1/1 6 12 0. 190 .1...

  • Page 127: Chapter 10

    Smartswitch router user reference manual 127 chapter 10 bgp configuration guide bgp overview the border gateway protocol (bgp) is an exterior gateway protocol that allows ip routers to exchange network reachability information. Bgp became an internet standard in 1989 (rfc 1105) and the current versi...

  • Page 128: Basic Bgp Tasks

    Chapter 10: bgp configuration guide 128 smartswitch router user reference manual the ssr bgp implementation the ssr routing protocol implementation is based on gated 4.0.3 code ( http://www.Gated.Org ). Gated is a modular software program consisting of core services, a routing database, and protocol...

  • Page 129

    Smartswitch router user reference manual 129 chapter 10: bgp configuration guide setting the autonomous system number an autonomous system number identifies your autonomous system to other routers. To set the ssr’s autonomous system number, enter the following command in configure mode. The autonomo...

  • Page 130

    Chapter 10: bgp configuration guide 130 smartswitch router user reference manual where: peer-group is a group id, which can be a number or a character string. Type specifies the type of bgp group you are adding. You can specify one of the following: external in the classic external bgp group, full p...

  • Page 131

    Smartswitch router user reference manual 131 chapter 10: bgp configuration guide adding and removing a bgp peer there are two ways to add bgp peers to peer groups. You can explicitly add a peer host, or you can add a network. Adding a network allows for peer connections from any addresses in the ran...

  • Page 132

    Chapter 10: bgp configuration guide 132 smartswitch router user reference manual ( aspath_regexp ) parentheses group subexpressions. An operator, such as * or ? Works on a single element or on a regular expression enclosed in parentheses. An as-path operator is one of the following: aspath_term {m,n...

  • Page 133

    Smartswitch router user reference manual 133 chapter 10: bgp configuration guide as-path regular expression examples to import mci routes with a preference of 165: to import all routes (.* matches all as paths) with the default preference: to export all active routes from 284 or 813 or 814 or 815 or...

  • Page 134: Bgp Configuration Examples

    Chapter 10: bgp configuration guide 134 smartswitch router user reference manual the following is an example: notes on using the as path prepend feature • use the as-count option for external peer-hosts only. • if the as-count option is entered for an active bgp session, routes will not be resent to...

  • Page 135

    Smartswitch router user reference manual 135 chapter 10: bgp configuration guide • bgp multi-exit discriminator (med) attribute • ebgp aggregation • route reflection bgp peering session example the router process used for a specific bgp peering session is known as a bgp speaker. A single router can ...

  • Page 136

    Chapter 10: bgp configuration guide 136 smartswitch router user reference manual figure 8 illustrates a sample bgp peering session. Figure 8. Sample bgp peering session the cli configuration for router ssr1 is as follows: interface create ip et.1.1 address-netmask 10.0.0.1/16 port et.1.1 # # set the...

  • Page 137

    Smartswitch router user reference manual 137 chapter 10: bgp configuration guide the gated.Conf file for router ssr1 is as follows: the cli configuration for router ssr2 is as follows: the gated.Conf file for router ssr2 is as follows: ibgp configuration example connections between bgp speakers with...

  • Page 138

    Chapter 10: bgp configuration guide 138 smartswitch router user reference manual an igp, like ospf, could possibly be used instead of ibgp to exchange routing information between ebgp speakers within an as. However, injecting full internet routes (50,000+ routes) into an igp puts an expensive burden...

  • Page 139

    Smartswitch router user reference manual 139 chapter 10: bgp configuration guide figure 9 shows a sample bgp configuration that uses the routing group type. Figure 9. Sample ibgp configuration (routing group type) ssr6 ssr1 cisco ssr4 lo0 172.23.1.25/30 10.12.1.6/30 10.12.1.5/30 172.23.1.10/30 172.2...

  • Page 140

    Chapter 10: bgp configuration guide 140 smartswitch router user reference manual in this example, ospf is configured as the igp in the autonomous system. The following lines in the router ssr6 configuration file configure ospf: the following lines in the cisco router configure ospf: the following li...

  • Page 141

    Smartswitch router user reference manual 141 chapter 10: bgp configuration guide the following lines on the cisco router set up ibgp peering with router ssr6. Ibgp internal group example the ibgp internal group expects all peers to be directly attached to a shared subnet so that, like external peers...

  • Page 142

    Chapter 10: bgp configuration guide 142 smartswitch router user reference manual figure 10 illustrates a sample ibgp internal group configuration. Figure 10. Sample ibgp configuration (internal group type) the cli configuration for router ssr1 is as follows: as-1 ssr2 ssr1 17.122.128.2/24 17.122.128...

  • Page 143

    Smartswitch router user reference manual 143 chapter 10: bgp configuration guide the gated.Conf file for router ssr1 is as follows: the cli configuration for router ssr2 is as follows: the gated.Conf file for router ssr2 is as follows: autonomoussystem 1 ; routerid 16.122.128.1 ; bgp yes { traceopti...

  • Page 144

    Chapter 10: bgp configuration guide 144 smartswitch router user reference manual the configuration for router c1 (a cisco router) is as follows: the configuration for router c2 (a cisco router) is as follows: ebgp multihop configuration example ebgp multihop refers to a configuration where external ...

  • Page 145

    Smartswitch router user reference manual 145 chapter 10: bgp configuration guide this sample configuration shows external bgp peers, ssr1 and ssr4, which are not connected to the same subnet. The cli configuration for router ssr1 is as follows: physical link legend: peering relationship ssr1 16.122....

  • Page 146

    Chapter 10: bgp configuration guide 146 smartswitch router user reference manual the gated.Conf file for router ssr1 is as follows: the cli configuration for router ssr2 is as follows: the gated.Conf file for router ssr2 is as follows: the cli configuration for router ssr3 is as follows: autonomouss...

  • Page 147

    Smartswitch router user reference manual 147 chapter 10: bgp configuration guide the gated.Conf file for router ssr3 is as follows: the cli configuration for router ssr4 is as follows: the gated.Conf file for router ssr4 is as follows: community attribute example the following configuration illustra...

  • Page 148

    Chapter 10: bgp configuration guide 148 smartswitch router user reference manual figure 11. Sample bgp configuration (specific community) as-64902 r11 172.26.1.2/16 172.25.1.2/16 192.168.20.2/16 172.25.1.1/16 1.1 r13 1.6 r10 192.169.20.1/16 192.169.20.2/16 100.200.13.1/24 10.200.15.1/24 1.6 r14 as-6...

  • Page 149

    Smartswitch router user reference manual 149 chapter 10: bgp configuration guide figure 12. Sample bgp configuration (well-known community) the community attribute can be used in three ways: 1. In a bgp group statement: any packets sent to this group of bgp peers will have the communities attribute ...

  • Page 150

    Chapter 10: bgp configuration guide 150 smartswitch router user reference manual in figure 12 , router ssr11 has the following configuration: # # create an optional attribute list with identifier color1 for a community # attribute (community-id 160 as 64901) # ip-router policy create optional-attrib...

  • Page 151

    Smartswitch router user reference manual 151 chapter 10: bgp configuration guide in figure 12 , router ssr13 has the following configuration: 3. In an export statement: the optional-attributes-list option of the ip-router policy create bgp-export-destination command may be used to send the bgp commu...

  • Page 152

    Chapter 10: bgp configuration guide 152 smartswitch router user reference manual in figure 12 , router ssr10 has the following configuration: in figure 12 , router ssr14 has the following configuration: any communities specified with the optional-attributes-list option are sent in addition to any re...

  • Page 153

    Smartswitch router user reference manual 153 chapter 10: bgp configuration guide the community attribute may be a single community or a set of communities. A maximum of 10 communities may be specified. The community attribute can take any of the following forms: • specific community the specific com...

  • Page 154

    Chapter 10: bgp configuration guide 154 smartswitch router user reference manual notes on using communities when originating bgp communities, the set of communities that is actually sent is the union of the communities received with the route (if any), those specified in group policy (if any), and t...

  • Page 155

    Smartswitch router user reference manual 155 chapter 10: bgp configuration guide in the sample network in figure 13 , all the traffic exits autonomous system 64901 through the link between router ssr13 and router ssr11. This is accomplished by setting the local_pref attribute. Figure 13. Sample bgp ...

  • Page 156

    Chapter 10: bgp configuration guide 156 smartswitch router user reference manual in router ssr12’s cli configuration file, the import preference is set to 160: using the formula for local preference [local_pref = 254 - (global protocol preference for this route) + metric], the local_pref value put o...

  • Page 157

    Smartswitch router user reference manual 157 chapter 10: bgp configuration guide figure 14. Sample bgp configuration (med attribute) routers ssr4 and ssr6 inform router c1 about network 172.16.200.0/24 through external bgp (ebgp). Router ssr6 announced the route with a med of 10, whereas router ssr4...

  • Page 158

    Chapter 10: bgp configuration guide 158 smartswitch router user reference manual ebgp aggregation example figure 15 shows a simple ebgp configuration in which one peer is exporting an aggregated route to its upstream peer and restricting the advertisement of contributing routes to the same peer. The...

  • Page 159

    Smartswitch router user reference manual 159 chapter 10: bgp configuration guide router ssr9 has the following cli configuration: route reflection example in some isp networks, the internal bgp mesh becomes quite large, and the ibgp full mesh does not scale well. For such situations, route reflectio...

  • Page 160

    Chapter 10: bgp configuration guide 160 smartswitch router user reference manual figure 16 shows a sample configuration that uses route reflection. Figure 16. Sample bgp configuration (route reflection) in this example, there are two clusters. Router ssr10 is the route reflector for the first cluste...

  • Page 161

    Smartswitch router user reference manual 161 chapter 10: bgp configuration guide router ssr11 has router ssr12 and router ssr13 as client peers and router ssr10 as non- client peer. The following line in router ssr11’s configuration file specifies it to be a route reflector even though the ibgp peer...

  • Page 162

    Chapter 10: bgp configuration guide 162 smartswitch router user reference manual notes on using route reflection • two types of route reflection are supported: – by default, all routes received by the route reflector from a client are sent to all internal peers (including the client’s group, but not...

  • Page 163: Chapter 11

    Smartswitch router user reference manual 163 chapter 11 routing policy configuration guide route import and export policy overview the ssr family of routers supports extremely flexible routing policies. The ssr allows the network administrator to control import and export of routing information base...

  • Page 164

    Chapter 11: routing policy configuration guide 164 smartswitch router user reference manual preference preference is the value the ssr routing process uses to order preference of routes from one protocol or peer over another. Preference can be set using several different configuration commands. Pref...

  • Page 165

    Smartswitch router user reference manual 165 chapter 11: routing policy configuration guide import policies import policies control the importation of routes from routing protocols and their installation in the routing databases (routing information base and forwarding information base). Import poli...

  • Page 166

    Chapter 11: routing policy configuration guide 166 smartswitch router user reference manual it is only possible to restrict the importation of ospf ase routes when functioning as an as border router. Like the other interior protocols, preference cannot be used to choose between ospf ase routes. That...

  • Page 167

    Smartswitch router user reference manual 167 chapter 11: routing policy configuration guide the routes to be exported can be identified by their associated attributes: • their protocol type (rip, ospf, bgp, static, direct, aggregate). • interface or the gateway from which the route was received. • a...

  • Page 168

    Chapter 11: routing policy configuration guide 168 smartswitch router user reference manual a route will match the most specific filter that applies. Specifying more than one filter with the same destination, mask, and modifiers generates an error. There are three possible formats for a route filter...

  • Page 169

    Smartswitch router user reference manual 169 chapter 11: routing policy configuration guide route aggregation is also used by regional and national networks to reduce the amount of routing information passed around. With careful allocation of network addresses to clients, regional networks can just ...

  • Page 170

    Chapter 11: routing policy configuration guide 170 smartswitch router user reference manual route-filter this component specifies the individual routes that are to be aggregated or summarized. The preference to be associated with these routes can also be explicitly specified using this component. Th...

  • Page 171

    Smartswitch router user reference manual 171 chapter 11: routing policy configuration guide many protocols allow the specification of two authentication keys per interface. Packets are always sent using the primary keys, but received packets are checked with both the primary and secondary keys befor...

  • Page 172

    Chapter 11: routing policy configuration guide 172 smartswitch router user reference manual the from-proto parameter specifies the protocol of the source routes. The values for the from-proto parameter can be rip, ospf, bgp, direct, static, aggregate and ospf-ase. The to- proto parameter specifies t...

  • Page 173

    Smartswitch router user reference manual 173 chapter 11: routing policy configuration guide redistributing rip into rip the ssr routing process requires rip redistribution into rip if a protocol is redistributed into rip. To redistribute rip into rip, enter the following command in configure mode: r...

  • Page 174

    Chapter 11: routing policy configuration guide 174 smartswitch router user reference manual to redistribute aggregate routes, enter one of the following commands in configure mode: simple route redistribution examples example 1: redistribution into rip for all examples given in this section, refer t...

  • Page 175

    Smartswitch router user reference manual 175 chapter 11: routing policy configuration guide exporting a given static route to all rip interfaces router r1 has several static routes of which one is the default route. We would export this default route over all rip interfaces. Exporting all static rou...

  • Page 176

    Chapter 11: routing policy configuration guide 176 smartswitch router user reference manual • specify the static routes configured on the router • determine its ospf configuration exporting all interface & static routes to ospf router r1 has several static routes. We would like to export all these s...

  • Page 177

    Smartswitch router user reference manual 177 chapter 11: routing policy configuration guide in the configuration shown in figure 18 on page 187 , suppose we decide to run rip version 2 on network 120.190.0.0/16, connecting routers r1 and r2. Router r1 would like to export all rip, interface, and sta...

  • Page 178

    Chapter 11: routing policy configuration guide 178 smartswitch router user reference manual routes to be exported can be identified by their associated attributes, such as protocol type, interface or the gateway from which the route was received, and so on. • route filter - this component provides t...

  • Page 179

    Smartswitch router user reference manual 179 chapter 11: routing policy configuration guide creating an export destination to create an export destination, enter one the following commands in configure mode: creating an export source to create an export source, enter one of the following commands in...

  • Page 180

    Chapter 11: routing policy configuration guide 180 smartswitch router user reference manual to create route import policies, enter the following command in configure mode: the is the identifier of the import-source that determines the source of the imported routes. If no routes from a particular sou...

  • Page 181

    Smartswitch router user reference manual 181 chapter 11: routing policy configuration guide • aggregate-destination - this component specifies the aggregate/summarized route. It also specifies the attributes associated with the aggregate route. The preference to be associated with an aggregate route...

  • Page 182

    Chapter 11: routing policy configuration guide 182 smartswitch router user reference manual creating an aggregate destination to create an aggregate destination, enter the following command in configure mode: creating an aggregate source to create an aggregate source, enter the following command in ...

  • Page 183

    Smartswitch router user reference manual 183 chapter 11: routing policy configuration guide the following configuration commands for router r1 • determine the ip address for each interface. • specify the static routes configured on the router. • determine its rip configuration. F ig u re 17. Exp o r...

  • Page 184

    Chapter 11: routing policy configuration guide 184 smartswitch router user reference manual importing a selected subset of routes from one rip trusted gateway router r1 has several rip peers. Router r41 has an interface on the network 10.51.0.0. By default, router r41 advertises network 10.51.0.0/16...

  • Page 185

    Smartswitch router user reference manual 185 chapter 11: routing policy configuration guide 1. Add the peer 140.1.1.41 to the list of trusted and source gateways. 2. Create a rip import source with the gateway as 140.1.1.4 since we would like to import all routes except the 10.51.0.0/16 route from t...

  • Page 186

    Chapter 11: routing policy configuration guide 186 smartswitch router user reference manual it is only possible to restrict the importation of ospf ase routes when functioning as an as border router. Like the other interior protocols, preference cannot be used to choose between ospf ase routes. That...

  • Page 187

    Smartswitch router user reference manual 187 chapter 11: routing policy configuration guide f ig u re 1 8 . Exp or ti n g to os pf bg p r1 r2 r3 r41 r4 2 r6 r1 1 a r e a b a c k b o n e a r e a 1 4 0 .1 .0 .0 (rip v2) 1 4 0 .1 .1 .1 /2 4 1 4 0 .1. 2. 1/ 2 4 1 40. 1. 5/24 14 0. 1. 4/24 19 0. 1. 1. 1/...

  • Page 188

    Chapter 11: routing policy configuration guide 188 smartswitch router user reference manual the following configuration commands for router r1: • determine the ip address for each interface • specify the static routes configured on the router • determine its ospf configuration importing a selected s...

  • Page 189

    Smartswitch router user reference manual 189 chapter 11: routing policy configuration guide examples of export policies example 1: exporting to rip exporting to rip is controlled by any of protocol, interface or gateway. If more than one is specified, they are processed from most general (protocol) ...

  • Page 190

    Chapter 11: routing policy configuration guide 190 smartswitch router user reference manual exporting a given static route to all rip interfaces router r1 has several static routes, of which one is the default route. We would export this default route over all rip interfaces. 1. Create a rip export ...

  • Page 191

    Smartswitch router user reference manual 191 chapter 11: routing policy configuration guide 4. Create a direct export source since we would like to export direct/interface routes. 5. Create the export-policy redistributing the statically created default route, and all (rip, direct) routes into rip. ...

  • Page 192

    Chapter 11: routing policy configuration guide 192 smartswitch router user reference manual exporting all static routes reachable over a given interface to a specific rip- interface in this case, router r1 would export/redistribute all static routes accessible through its interface 130.1.1.1 to its ...

  • Page 193

    Smartswitch router user reference manual 193 chapter 11: routing policy configuration guide 1. Create an aggregate-destination which represents the aggregate/summarized route. 2. Create an aggregate-source which qualifies the source of the routes contributing to the aggregate. Since in this case, we...

  • Page 194

    Chapter 11: routing policy configuration guide 194 smartswitch router user reference manual 8. Create the export-policy redistributing all (rip, direct) routes and the aggregate route 140.1.0.0/16 into rip. Example 2: exporting to ospf it is not possible to create ospf intra- or inter-area routes by...

  • Page 195

    Smartswitch router user reference manual 195 chapter 11: routing policy configuration guide exporting all interface & static routes to ospf router r1 has several static routes. We would export these static routes as type-2 ospf routes. The interface routes would redistributed as type 1 ospf routes. ...

  • Page 196

    Chapter 11: routing policy configuration guide 196 smartswitch router user reference manual 4. Create a direct export source since we would like to export interface/direct routes. 5. Create the export-policy for redistributing all interface routes and static routes into ospf. Exporting all rip, inte...

  • Page 197

    Smartswitch router user reference manual 197 chapter 11: routing policy configuration guide 5. Create a rip export source. 6. Create a static export source. 7. Create a direct export source. 8. Create the export-policy for redistributing all interface, rip and static routes into ospf. 9. Create a ri...

  • Page 198

    Chapter 11: routing policy configuration guide 198 smartswitch router user reference manual 12. Create the export-policy for redistributing all interface, rip, static, ospf and ospf- ase routes into rip. Ip-router policy export destination ripexpdst source statexpsrc network all ip-router policy exp...

  • Page 199: Chapter 12

    Smartswitch router user reference manual 199 chapter 12 multicast routing configuration guide ip multicast overview multicast routing on the ssr is supported through dvmrp and igmp. Igmp is used to determine host membership on directly attached subnets. Dvmrp is used to determine forwarding of multi...

  • Page 200

    Chapter 12: multicast routing configuration guide 200 smartswitch router user reference manual the ssr allows per-interface control of the host query interval and response time. Query interval defines the time between igmp queries. Response time defines the time the ssr will wait for host responses ...

  • Page 201: Configuring Igmp

    Smartswitch router user reference manual 201 chapter 12: multicast routing configuration guide configuring igmp you configure igmp on the ssr by performing the following configuration tasks: • creating ip interfaces • setting global parameters that will be used for all the interfaces on which dvmrp ...

  • Page 202: Configuring Dvmrp

    Chapter 12: multicast routing configuration guide 202 smartswitch router user reference manual to configure the host response wait time, enter the following command in configure mode: configuring per-interface control of igmp membership you can configure the ssr to control igmp membership on a per-i...

  • Page 203

    Smartswitch router user reference manual 203 chapter 12: multicast routing configuration guide to start or stop dvmrp, enter one of the following commands in configure mode: configuring dvmrp on an interface dvmrp can be controlled/configured on per-interface basis. An interface does not have to run...

  • Page 204

    Chapter 12: multicast routing configuration guide 204 smartswitch router user reference manual configuring dvmrp ttl & scope for control over internet traffic, per-interface control is allowed through scopes and ttl thresholds. The ttl value controls whether packets are forwarded from an interface. ...

  • Page 205: Monitoring Igmp & Dvmrp

    Smartswitch router user reference manual 205 chapter 12: multicast routing configuration guide dvmrp tunnels need to be created before being enabled. Tunnels are recognized by the tunnel name. Once a dvmrp tunnel is created, you can enable dvmrp on the interface. The ssr supports a maximum of eight ...

  • Page 206: Configuration Examples

    Chapter 12: multicast routing configuration guide 206 smartswitch router user reference manual configuration examples the following is a sample ssr configuration for dvmrp and igmp. Seven subnets are created. Igmp is enabled on 4 ip interfaces. The igmp query interval is set to 30 seconds. Dvmrp is ...

  • Page 207

    Smartswitch router user reference manual 207 chapter 12: multicast routing configuration guide.

  • Page 208

    Chapter 12: multicast routing configuration guide 208 smartswitch router user reference manual.

  • Page 209: Chapter 13

    Smartswitch router user reference manual 209 chapter 13 ip policy-based forwarding configuration guide overview you can configure the ssr to route ip packets according to policies that you define. Ip- policy-based routing allows network managers to engineer traffic to make the most efficent use of t...

  • Page 210: Configuring Ip Policies

    Chapter 13: ip policy-based forwarding configuration guide 210 smartswitch router user reference manual different isps. You can also create ip policies to select service providers based on various traffic types. Other uses for ip policy routing include transparent web caching, where all http request...

  • Page 211

    Smartswitch router user reference manual 211 chapter 13: ip policy-based forwarding configuration guide cause packets matching a defined profile to be forwarded to a next-hop gateway, enter the following command in configure mode: for example, the following command creates an ip policy called “p1” a...

  • Page 212

    Chapter 13: ip policy-based forwarding configuration guide 212 smartswitch router user reference manual which means it is evaluated before the ip policy deny statement, which has a sequence number of 900. Setting load distribution for next-hop gateways you can specify up to four next-hop gateways in...

  • Page 213

    Smartswitch router user reference manual 213 chapter 13: ip policy-based forwarding configuration guide to set the ip policy action with respect to dynamic or statically configured routes, enter one of the following commands in configure mode: checking the availability of next-hop gateways the ssr c...

  • Page 214

    Chapter 13: ip policy-based forwarding configuration guide 214 smartswitch router user reference manual to apply an ip policy to an interface, enter one of the following commands in configure mode: applying an ip policy to locally generated packets you can apply an ip policy to locally generated pac...

  • Page 215

    Smartswitch router user reference manual 215 chapter 13: ip policy-based forwarding configuration guide in the sample configuration in figure 19 , the policy router is configured to divide traffic originating within the corporate network between different isps (100.1.1.1 and 200.1.1.1). Figure 19. U...

  • Page 216

    Chapter 13: ip policy-based forwarding configuration guide 216 smartswitch router user reference manual prioritizing service to customers an isp can use policy-based routing on an access router to supply different customers with different levels of service. The sample configuration in figure 20 show...

  • Page 217

    Smartswitch router user reference manual 217 chapter 13: ip policy-based forwarding configuration guide the following is the ip policy configuration for the policy router in figure 20 : authenticating users through a firewall you can define an ip policy that authenticates packets from certain users ...

  • Page 218

    Chapter 13: ip policy-based forwarding configuration guide 218 smartswitch router user reference manual the following is the ip policy configuration for the policy router in figure 21 : firewall load balancing the next hop gateway can be selected by the following information in the ip packet: source...

  • Page 219: Monitoring Ip Policies

    Smartswitch router user reference manual 219 chapter 13: ip policy-based forwarding configuration guide the following is the configuration for policy router 1 in figure 22 . The following is the configuration for policy router 2 in figure 22 . Monitoring ip policies the ip-policy show command report...

  • Page 220

    Chapter 13: ip policy-based forwarding configuration guide 220 smartswitch router user reference manual for example, to display information about an active ip policy called “p1”, enter the following command in enable mode: legend: 1. The name of the ip policy. 2. The interface where the ip policy wa...

  • Page 221

    Smartswitch router user reference manual 221 chapter 13: ip policy-based forwarding configuration guide 5. The source address and filtering mask of this flow. 6. The destination address and filtering mask of this flow. 7. For tcp or udp, the number of the source tcp or udp port. 8. For tcp or udp, t...

  • Page 222

    Chapter 13: ip policy-based forwarding configuration guide 222 smartswitch router user reference manual.

  • Page 223: Chapter 14

    Smartswitch router user reference manual 223 chapter 14 network address translation configuration guide overview note: some commands in this facility require updated ssr hardware. Please refer to the release notes for details. Network address translation (nat) allows an ip address used within one ne...

  • Page 224: Configuring Nat

    Chapter 14: network address translation configuration guide 224 smartswitch router user reference manual • static, one-to-one binding of inside, local address or address pool to outside, global address or address pool. A static address binding does not expire until the command that defines the bindi...

  • Page 225: Managing Dynamic Bindings

    Smartswitch router user reference manual 225 chapter 14: network address translation configuration guide setting nat rules static you create nat static bindings by entering the following command in configure mode. Dynamic you create nat dynamic bindings by entering the following command in configure...

  • Page 226: Nat and Ftp

    Chapter 14: network address translation configuration guide 226 smartswitch router user reference manual nat and ftp file transfer protocol (ftp) packets require special handling with nat, because the ftp port command packets contain ip address information within the data portion of the packet. It i...

  • Page 227

    Smartswitch router user reference manual 227 chapter 14: network address translation configuration guide the first step is to create the interfaces: next, define the interfaces to be nat “inside” or “outside”: then, define the nat static rules: using static nat static nat can be used when the local ...

  • Page 228

    Chapter 14: network address translation configuration guide 228 smartswitch router user reference manual dynamic configuration the following example configures a dynamic address binding for inside addresses 10.1.1.0/24 to outside address 192.50.20.0/24: the first step is to create the interfaces: ne...

  • Page 229

    Smartswitch router user reference manual 229 chapter 14: network address translation configuration guide dynamic bindings are removed when the flow count for that binding goes to zero or the timeout has been reached. The free globals are used again for the next packet. A typical problem is that if t...

  • Page 230

    Chapter 14: network address translation configuration guide 230 smartswitch router user reference manual using dynamic nat with ip overload dynamic nat with ip overload can be used when the local network (inside network) will be initializing the connections using tcp or udp protocols. It creates a b...

  • Page 231

    Smartswitch router user reference manual 231 chapter 14: network address translation configuration guide next, define the interfaces to be nat “inside” or “outside”: then, define the nat dynamic rules by first creating the source acl pool and then configuring the dynamic bindings: using dynamic nat ...

  • Page 232

    Chapter 14: network address translation configuration guide 232 smartswitch router user reference manual.

  • Page 233: Chapter 15

    Smartswitch router user reference manual 233 chapter 15 web hosting configuration guide overview accessing information on websites for both work or personal purposes is becoming a normal practice for an increasing number of people. For many companies, fast and efficient web access is important for b...

  • Page 234: Load Balancing

    Chapter 15: web hosting configuration guide 234 smartswitch router user reference manual load balancing note: some commands in this facility require updated ssr hardware. Please refer to the release notes for details. You can use the load balancing feature on the ssr to distribute session load acros...

  • Page 235

    Smartswitch router user reference manual 235 chapter 15: web hosting configuration guide new session. The weighted round robin policy is a variation of the round-robin policy, where each server takes on new sessions according to its assigned weight. If you choose the weighted round robin policy, you...

  • Page 236

    Chapter 15: web hosting configuration guide 236 smartswitch router user reference manual load balancing and ftp file transfer protocol (ftp) packets require special handling with load balancing, because the ftp port command packets contain ip address information within the data portion of the packet...

  • Page 237

    Smartswitch router user reference manual 237 chapter 15: web hosting configuration guide displaying load balancing information to display load balancing information, enter the following commands in enable mode. Configuration examples this section shows examples of load balancing configurations. Web ...

  • Page 238

    Chapter 15: web hosting configuration guide 238 smartswitch router user reference manual the network shown above can be created with the following load-balance commands: web hosting with multiple virtual groups and multiple destination servers in the following example, two different servers are used...

  • Page 239

    Smartswitch router user reference manual 239 chapter 15: web hosting configuration guide the network shown above can be created with the following load-balance commands: virtual ip address ranges isps who provide web hosting services for their clients require a large number of virtual ip addresses (...

  • Page 240: Web Caching

    Chapter 15: web hosting configuration guide 240 smartswitch router user reference manual the network shown in the previous example can be created with the following load- balance commands: web caching web caching provides a way to store frequently accessed web objects on a cache of local servers. Ea...

  • Page 241

    Smartswitch router user reference manual 241 chapter 15: web hosting configuration guide creating the cache group you can specify either a range of ip addresses or a list of up to four ip addresses to define the servers when the cache group is created. If you specify multiple servers, load balancing...

  • Page 242

    Chapter 15: web hosting configuration guide 242 smartswitch router user reference manual configuration example in the following example, a cache group of seven local servers is configured to store web objects for users in the local network: the following commands configure the cache group ‘cache1’ t...

  • Page 243

    Smartswitch router user reference manual 243 chapter 15: web hosting configuration guide which http requests are not redirected to the cache servers, enter the following command in configure mode: proxy server redundancy some networks use proxy servers that receive http requests on a non-standard po...

  • Page 245: Chapter 16

    Smartswitch router user reference manual 245 chapter 16 ipx routing configuration guide ipx routing overview the internetwork packet exchange (ipx) is a datagram connectionless protocol for the novell netware environment. You can configure the ssr for ipx routing and sap. Routers interconnect differ...

  • Page 246

    Chapter 16: ipx routing configuration guide 246 smartswitch router user reference manual this information is immediately broadcast to any neighboring routers. Routers also send periodic rip broadcast packets containing all routing information known to the router. The ssr uses ipx rip to create and m...

  • Page 247: Configuring Ipx Rip & Sap

    Smartswitch router user reference manual 247 chapter 16: ipx routing configuration guide configuring ipx rip & sap this section provides an overview of configuring various ipx parameters and setting up ipx interfaces. Ipx rip on the ssr, rip automatically runs on all ipx interfaces. The ssr will kee...

  • Page 248

    Chapter 16: ipx routing configuration guide 248 smartswitch router user reference manual configuring ipx interfaces and parameters this section provides an overview of configuring various ipx parameters and setting up ipx interfaces. Configuring ipx addresses to ports you can configure one ipx inter...

  • Page 249: Configuring Ipx Routing

    Smartswitch router user reference manual 249 chapter 16: ipx routing configuration guide • 802.2: 802.2 encapsulation method used within novell ipx environments configuring ipx routing by default, ipx routing is enabled on the ssr. Enabling ipx rip ipx rip is enabled by default on the ssr. You must ...

  • Page 250

    Chapter 16: ipx routing configuration guide 250 smartswitch router user reference manual configuring static sap table entries servers in an ipx network use sap to advertise services via broadcast packets. Services from servers are stored in the server information table. If you want to have a service...

  • Page 251

    Smartswitch router user reference manual 251 chapter 16: ipx routing configuration guide creating an ipx type 20 access control list ipx type 20 access control lists control the forwarding of ipx type 20 packets. To create an ipx type 20 access control list, enter the following command in configure ...

  • Page 252: Monitoring An Ipx Network

    Chapter 16: ipx routing configuration guide 252 smartswitch router user reference manual creating an ipx rip access control list ipx rip access control lists control which rip updates are allowed. To create an ipx rip access control list, perform the following task in the configure mode: once an ipx...

  • Page 253

    Smartswitch router user reference manual 253 chapter 16: ipx routing configuration guide • adds a sap access list • adds a gns access list ! Create interface ipx1 with ipx address aaaaaaaa interface create ipx ipx1 address aaaaaaaa port et.1.1 output-mac- encapsulation ethernet_802.2_ipx ! ! Create ...

  • Page 254

    Chapter 16: ipx routing configuration guide 254 smartswitch router user reference manual.

  • Page 255: Chapter 17

    Smartswitch router user reference manual 255 chapter 17 access control list configuration guide note: some commands in this facility require updated ssr hardware. Please refer to the release notes for details. This chapter explains how to configure and use access control lists (acls) on the ssr. Acl...

  • Page 256: Acl Basics

    Chapter 17: access control list configuration guide 256 smartswitch router user reference manual acl basics an acl consists of one or more rules describing a particular type of ip or ipx traffic. Acls can be simple, consisting of only one rule, or complicated with many rules. Each rule tells the ssr...

  • Page 258

    Chapter 17: access control list configuration guide 258 smartswitch router user reference manual always be listed ahead of rules that are less specific. For example, the following acl permits all tcp traffic except those from subnet 10.2.0.0/16: when a tcp packet comes from subnet 10.2.0.0/16, it fi...

  • Page 259

    Smartswitch router user reference manual 259 chapter 17: access control list configuration guide although the implicit deny rule may seem obvious in the above example, this is not always the case. For example, consider the following acl rule: if a packet comes in from a network other than 10.1.20.0/...

  • Page 260

    Chapter 17: access control list configuration guide 260 smartswitch router user reference manual otherwise, it will be rejected. To do this, enter the following command in configure mode: the following acl illustrates this feature: any incoming tcp packet on interface int1 is examined, and if the pa...

  • Page 261

    Smartswitch router user reference manual 261 chapter 17: access control list configuration guide 101 by entering, no acl 101 *. The negation of all related acl commands is important because it removes any potential confusion caused by the addition of new acl rules to existing rules. Basically, the n...

  • Page 262: Using Acls

    Chapter 17: access control list configuration guide 262 smartswitch router user reference manual using acls it is important to understand that an acl is simply a definition of packet characteristics specified in a set of rules. An acl must be enabled in one of the following ways: • applying an acl t...

  • Page 263

    Smartswitch router user reference manual 263 chapter 17: access control list configuration guide interface. Nonetheless, for performance reasons, whenever possible, you should create and apply an acl to the inbound interface. To apply an acl to an interface, enter the following command in configure ...

  • Page 264

    Chapter 17: access control list configuration guide 264 smartswitch router user reference manual the following ssr features use acl profiles: note the following about using profile acls: • only ip acls can be used as profile acls. Acls for non-ip protocols cannot be used as profile acls. • the permi...

  • Page 265

    Smartswitch router user reference manual 265 chapter 17: access control list configuration guide 15.1.1.0/24). Then you use an ip-policy command to specify what happens to packets that match the selection criteria (in this example, forward them to address 10.10.10.10). The following commands illustr...

  • Page 266

    Chapter 17: access control list configuration guide 266 smartswitch router user reference manual see “limiting traffic rate” on page 291 for more information on using the rate-limit command. Using profile acls with dynamic nat network address translation (nat) allows you to map an ip address used wi...

  • Page 267

    Smartswitch router user reference manual 267 chapter 17: access control list configuration guide this command creates a profile acl called prof3 that uses as its selection criteria all igmp traffic on the ssr: the following command causes packets matching profile acl prof3’s selection criteria (that...

  • Page 268: Enabling Acl Logging

    Chapter 17: access control list configuration guide 268 smartswitch router user reference manual and a destination address of 1.2.3.4) from being redirected to a cache server. Packets that match the profile’s selection criteria are sent to the internet instead. When the web caching policy is applied...

  • Page 269: Monitoring Acls

    Smartswitch router user reference manual 269 chapter 17: access control list configuration guide creating additional delay. Therefore, you should consider the potential performance impact before turning on acl logging. Monitoring acls the ssr provides a display of acl configurations active in the sy...

  • Page 270

    Chapter 17: access control list configuration guide 270 smartswitch router user reference manual.

  • Page 271: Chapter 18

    Smartswitch router user reference manual 271 chapter 18 security configuration guide security overview the ssr provides security features that help control access to the ssr and filter traffic going through the ssr. Access to the ssr can be controlled by: • enabling radius • enabling tacacs • enabli...

  • Page 272

    Chapter 18: security configuration guide 272 smartswitch router user reference manual configuring ssr access security this section describes the following methods of controlling access to the ssr: • radius • tacacs • tacacs plus • passwords configuring radius you can secure login or enable mode acce...

  • Page 273

    Smartswitch router user reference manual 273 chapter 18: security configuration guide monitoring radius you can monitor radius configuration and statistics within the ssr. To monitor radius, enter the following commands in enable mode: configuring tacacs in addition, enable mode access to the ssr ca...

  • Page 274

    Chapter 18: security configuration guide 274 smartswitch router user reference manual configuring tacacs plus you can secure login or enable mode access to the ssr by enabling a tacacs plus client. A tacacs plus server responds to the ssr tacacs plus client to provide authentication. You can configu...

  • Page 275: Layer-2 Security Filters

    Smartswitch router user reference manual 275 chapter 18: security configuration guide to monitor tacacs plus, enter the following commands in enable mode: configuring passwords the ssr provides password authentication for accessing the user and enable modes. If tacacs is not enabled on the ssr, only...

  • Page 276

    Chapter 18: security configuration guide 276 smartswitch router user reference manual configuring layer-2 address filters if you want to control access to a source or destination on a per-mac address basis, you can configure an address filter. Address filters are always configured and applied to the...

  • Page 277

    Smartswitch router user reference manual 277 chapter 18: security configuration guide configuring layer-2 static entry filters static entry filters allow or force traffic to go to a set of destination ports based on a frame's source mac address, destination mac address, or both source and destinatio...

  • Page 278

    Chapter 18: security configuration guide 278 smartswitch router user reference manual • combine a destination secure port filter with a flow static entry to drop all received traffic but allow any frame coming from specific source mac address that is destined to specific destination mac address to g...

  • Page 279

    Smartswitch router user reference manual 279 chapter 18: security configuration guide layer-2 filter examples figure 23. Source filter example example 1: address filters source filter: the consultant is not allowed to access any file servers. The consultant is only allowed to interact with the engin...

  • Page 280

    Chapter 18: security configuration guide 280 smartswitch router user reference manual destination static entry: restrict "login multicasts" originating from the engineering segment (port et.1.1) from reaching the finance servers. Or flow static entry: restrict "login multicasts" originating from the...

  • Page 281

    Smartswitch router user reference manual 281 chapter 18: security configuration guide destination secure port: to block access to all file servers on all ports from port et.1.1 use the following command: to allow all engineers access to the engineering servers, you must "punch" a hole through the se...

  • Page 282

    Chapter 18: security configuration guide 282 smartswitch router user reference manual.

  • Page 283: Chapter 19

    Smartswitch router user reference manual 283 chapter 19 qos configuration guide qos & layer-2/layer-3/layer-4 flow overview the ssr allows network managers to identify traffic and set quality of service (qos) policies without compromising wire speed performance. The ssr can guarantee bandwidth on an...

  • Page 284

    Chapter 19: qos configuration guide 284 smartswitch router user reference manual • control • high • medium • low by assigning priorities to network traffic, you can ensure that critical traffic will reach its destination even if the exit ports for the traffic are experiencing greater-than-maximum ut...

  • Page 285

    Smartswitch router user reference manual 285 chapter 19: qos configuration guide ssr queuing policies you can use one of two queuing policies on the ssr: • strict priority : assures the higher priorities of throughput but at the expense of lower priorities. For example, during heavy loads, low-prior...

  • Page 286

    Chapter 19: qos configuration guide 286 smartswitch router user reference manual • the frame gets assigned a priority within the switch. Select “low, medium, high or control”. • the frame gets assigned a priority within the switch, and if the exit ports are trunk ports, the frame is assigned an 802....

  • Page 287

    Smartswitch router user reference manual 287 chapter 19: qos configuration guide setting an ip qos policy to set a qos policy on an ip traffic flow, enter the following command in configure mode: for example, the following command assigns control priority to any traffic coming from the 10.10.11.0 ne...

  • Page 288: Tos Rewrite

    Chapter 19: qos configuration guide 288 smartswitch router user reference manual specifying precedence for an ipx qos policy to specify the precedence for an ipx qos policy, enter the following command in configure mode: configuring ssr queueing policy the ssr queuing policy is set on a system-wide ...

  • Page 289

    Smartswitch router user reference manual 289 chapter 19: qos configuration guide the tos octet part of the ip specification, however, has not been widely employed in the past. The ietf is looking into using the tos octet to help resolve ip quality problems. Some newer routing protocols, like ospf an...

  • Page 290

    Chapter 19: qos configuration guide 290 smartswitch router user reference manual the and parameters use values ranging from 0 to 255. They are used in conjunction with each other to define which bit in the field of the packet is significant. The value ranges from 0 to 7 and is the value that is rewr...

  • Page 291: Monitoring Qos

    Smartswitch router user reference manual 291 chapter 19: qos configuration guide and the tos field set to 7. (in this example, the mbz bit is included in the tos field.) the figure below shows how the parameter values are derived. The tos-mask> value determines the tos bit to be examined, which is a...

  • Page 292

    Chapter 19: qos configuration guide 292 smartswitch router user reference manual prioritization, traffic rate limiting is a mechanism to control bandwidth usage of incoming traffic on a per flow basis. A traffic profile is used to define the traffic characteristics before an upper limit is assigned....

  • Page 293

    Smartswitch router user reference manual 293 chapter 19: qos configuration guide traffic from two interfaces, ‘ipclient1’ with ip address 1.2.2.2 and ‘ipclient2’ with ip address 3.1.1.1, is restricted to 10 mbps for each flow with the following configuration: displaying rate limit information to sho...

  • Page 294

    Chapter 19: qos configuration guide 294 smartswitch router user reference manual.

  • Page 295: Chapter 20

    Smartswitch router user reference manual 295 chapter 20 performance monitoring guide performance monitoring overview the ssr is a full wire-speed layer-2, 3 and 4 switching router. As packets enter the ssr, layer-2, 3, and 4 flow tables are populated on each line card. The flow tables contain inform...

  • Page 296

    Chapter 20: performance monitoring guide 296 smartswitch router user reference manual show information about the master mac table. L2-tables show mac-table-stats show information about a particular mac address. L2-tables show mac show info about multicasts registered by igmp. L2-tables show igmp-mca...

  • Page 297

    Smartswitch router user reference manual 297 chapter 20: performance monitoring guide configuring the ssr for port mirroring the ssr allows you to monitor activity with port mirroring. Port mirroring allows you to monitor the performance and activities of one or more ports on the ssr or for traffic ...

  • Page 298

    Chapter 20: performance monitoring guide 298 smartswitch router user reference manual.

  • Page 299: Chapter 21

    Smartswitch router user reference manual 299 chapter 21 rmon configuration guide rmon overview you can employ remote network monitoring (rmon) in your network to help monitor traffic at remote points on the network. With rmon, data collection and processing is done with a remote probe, namely the ss...

  • Page 301

    Smartswitch router user reference manual 301 chapter 21: rmon configuration guide rmon groups the rmon mib groups are defined in rfcs 1757 (rmon 1) and 2021 (rmon 2). On the ssr, you can configure one or more levels of rmon support for a set of ports. Each level—lite, standard, or professional—enabl...

  • Page 302

    Chapter 21: rmon configuration guide 302 smartswitch router user reference manual standard rmon groups this section describes the rmon groups that are enabled when you specify the standard support level. The standard rmon groups are shown in the table below. Professional rmon groups the professional...

  • Page 303

    Smartswitch router user reference manual 303 chapter 21: rmon configuration guide control tables many rmon groups contain both control and data tables. Control tables specify what statistics are to be collected. For example, you can specify the port for which statistics are to be collected and the o...

  • Page 304: Using Rmon

    Chapter 21: rmon configuration guide 304 smartswitch router user reference manual a row in the control table is created for each port on the ssr, with the owner set to “monitor”. If you want, you can change the owner by using the appropriate rmon command. See the section “configuring rmon groups” in...

  • Page 305: Configuring Rmon Groups

    Smartswitch router user reference manual 305 chapter 21: rmon configuration guide following command: configuring rmon groups as mentioned previously, control tables in many rmon groups specify the data that is to be collected for the particular rmon group. If the information you want to collect is i...

  • Page 307

    Smartswitch router user reference manual 307 chapter 21: rmon configuration guide configuration examples this section shows examples of configuration commands that specify an event that generates an snmp trap and the alarm condition that triggers the event. The rmon alarm group allows the ssr to pol...

  • Page 308

    Chapter 21: rmon configuration guide 308 smartswitch router user reference manual • samples taken at 300 second (5 minute) intervals. • a “startup” alarm generation condition instructing the ssr to generate an alarm if the sample is greater than or equal to the rising threshold or less than or equal...

  • Page 309

    Smartswitch router user reference manual 309 chapter 21: rmon configuration guide 1 to display ethernet statistics and related statistics for wan ports, rmon has to be activated on that port. To activate rmon on a port, use the frame-relay define service or ppp define service command, and the frame-...

  • Page 310

    Chapter 21: rmon configuration guide 310 smartswitch router user reference manual the following shows host table output without a cli filter: the following shows the same rmon show hosts command with a filter applied so that only hosts with inpkts greater than 500 are displayed: rmon cli filters can...

  • Page 311: Troubleshooting Rmon

    Smartswitch router user reference manual 311 chapter 21: rmon configuration guide creating rmon cli filters to create rmon cli filters, use the following cli command in configure mode: using rmon cli filters to see and use rmon cli filters, use the following cli command in user or enable mode: troub...

  • Page 312

    Chapter 21: rmon configuration guide 312 smartswitch router user reference manual check the following fields on the rmon show status command output: 1. Make sure that rmon has been enabled on the ssr. When the ssr is booted, rmon is off by default. Rmon is enabled with the rmon enable command. 2. Ma...

  • Page 313: Allocating Memory To Rmon

    Smartswitch router user reference manual 313 chapter 21: rmon configuration guide allocating memory to rmon rmon allocates memory depending on the number of ports enabled for rmon, the rmon groups that have been configured, and whether or not default tables have been turned on or off. Enabling rmon ...

  • Page 314

    Chapter 21: rmon configuration guide 314 smartswitch router user reference manual to set the amount of memory allocated to rmon, use the following cli command in user or enable mode: specifies the total amount of mbytes of memory allocated to rmon. Rmon set memory.

  • Page 315: Chapter 22

    Smartswitch router user reference manual 315 chapter 22 wan configuration guide this chapter provides an overview of wide area network (wan) applications as well as an overview of both frame relay and ppp configuration for the ssr. In addition, you can view an example of a multi-router wan configura...

  • Page 316

    Chapter 22: wan configuration guide 316 smartswitch router user reference manual using the same approach, a ppp high-speed serial interface (hssi) wan port located at router slot 3, port 2 would be identified as “hs.3.2”. Configuring wan interfaces configuring ip & ipx interfaces for the wan is gene...

  • Page 317

    Smartswitch router user reference manual 317 chapter 22: wan configuration guide the following command line displays an example for a vlan: mapped addresses mapped peer ip/ipx addresses are very similar to static addresses in that inarp is disabled for frame relay and the address negotiated in ipcp/...

  • Page 318

    Chapter 22: wan configuration guide 318 smartswitch router user reference manual the following command line displays an example for a vlan: forcing bridged encapsulation wan for the ssr has the ability to force bridged packet encapsulation. This feature has been provided to facilitate seamless compa...

  • Page 319

    Smartswitch router user reference manual 319 chapter 22: wan configuration guide average packet size in most cases, the larger the packet size, the better the potential compression ratio. This is due to the overhead involved with compression, as well as the compression algorithm. For example a link ...

  • Page 320

    Chapter 22: wan configuration guide 320 smartswitch router user reference manual the following command line displays an example for ppp: packet encryption packet encryption allows data to travel through unsecured networks. You can enable packet encryption for ppp ports, however, both ends of a link ...

  • Page 321

    Smartswitch router user reference manual 321 chapter 22: wan configuration guide source filtering and acls source filtering and acls can be applied to a wan interface; however, they affect the entire module, not an individual port. For example, if you want to apply a source mac address filter to a w...

  • Page 322: Frame Relay Overview

    Chapter 22: wan configuration guide 322 smartswitch router user reference manual works with ip precedence or priority, as defined in the qos configuration command line, to provide preferential traffic handling for higher-priority traffic. The cli commands related to red in both the frame relay and p...

  • Page 323

    Smartswitch router user reference manual 323 chapter 22: wan configuration guide permanent virtual circuits (pvcs) wan interfaces can take advantage of connections that assure a minimum level of available bandwidth at all times. These standing connections, called permanent virtual circuits (pvcs), a...

  • Page 324

    Chapter 22: wan configuration guide 324 smartswitch router user reference manual setting up a frame relay service profile once you have defined the type and location of your frame relay wan interface(s), you can configure your ssr to more efficiently utilize available bandwidth for frame relay commu...

  • Page 325

    Smartswitch router user reference manual 325 chapter 22: wan configuration guide monitoring frame relay wan ports once you have configured your frame relay wan interface(s), you can use the cli to monitor status and statistics for your wan ports. The following table describes the monitoring commands...

  • Page 326

    Chapter 22: wan configuration guide 326 smartswitch router user reference manual • committed information rate (cir) of 20 million bits per second • leave high-, low-, and medium-priority queue depths set to factory defaults • random early discard (red) disabled • rmon enabled the command line necess...

  • Page 327: Configuring Ppp Interfaces

    Smartswitch router user reference manual 327 chapter 22: wan configuration guide point-to-point protocol (ppp) overview because of its ability to quickly and easily accommodate ip and ipx protocol traffic, point- to-point protocol (ppp) routing has become a very important aspect of wan configuration...

  • Page 328

    Chapter 22: wan configuration guide 328 smartswitch router user reference manual wan interfaces, then apply a service profile to the desired interface(s). Examples of this process are displayed in “ppp port configuration” on page 330 . Defining the type and location of a ppp interface to configure a...

  • Page 329

    Smartswitch router user reference manual 329 chapter 22: wan configuration guide note: if it is necessary to specify a value for bridging, ip, and/or ipx, you must specify all three of these values at the same time. You cannot specify just one or two of them in the command line without the other(s)....

  • Page 330: Monitoring Ppp Wan Ports

    Chapter 22: wan configuration guide 330 smartswitch router user reference manual processing by mlp. If compression is enabled on a link, the packets will be compressed after the mlp processing. In general, choose bundle compression over link compression whenever possible. Compressing packets before ...

  • Page 331

    Smartswitch router user reference manual 331 chapter 22: wan configuration guide suppose you wish to set up a service profile called “profile2” that includes the following characteristics: • bridging enabled • leave high-, low-, and medium-priority queue depths set to factory defaults • ip and ipx e...

  • Page 332: Wan Configuration Examples

    Chapter 22: wan configuration guide 332 smartswitch router user reference manual wan configuration examples simple configuration file the following is an example of a simple configuration file used to test frame relay and ppp wan ports: for a broader, more application-oriented wan configuration exam...

  • Page 333

    Smartswitch router user reference manual 333 chapter 22: wan configuration guide multi-router wan configuration the following is a diagram of a multi-router wan configuration encompassing three subnets. From the diagram, you can see that r1 is part of both subnets 1 and 2; r2 is part of both subnets...

  • Page 334

    Chapter 22: wan configuration guide 334 smartswitch router user reference manual router r1 configuration file the following configuration file applies to router r1. Router r2 configuration file the following configuration file applies to router r2. ---------------------------------------------------...

  • Page 335

    Smartswitch router user reference manual 335 chapter 22: wan configuration guide router r3 configuration file the following configuration file applies to router r3. Router r4 configuration file the following configuration file applies to router r4. Rip add interface all rip set interface all version...

  • Page 336

    Chapter 22: wan configuration guide 336 smartswitch router user reference manual router r5 configuration file the following configuration file applies to router r5. Router r6 configuration file the following configuration file applies to router r6. Port set et.1.* duplex full frame-relay create vc p...

  • Page 337

    Smartswitch router user reference manual 337 chapter 22: wan configuration guide port set hs.3.1 wan-encapsulation frame-relay speed 45000000 frame-relay create vc port hs.3.1.106 frame-relay define service cirforr1tor6 cir 45000000 bc 450000 frame-relay apply service cirforr1tor6 ports hs.3.1.106 v...

  • Page 338

    Chapter 22: wan configuration guide 338 smartswitch router user reference manual.