Upgrade to Pro — share decks privately, control downloads, hide ads and more …

ECS2100 Series L2 Features Web GUI Training

CK
April 28, 2016

ECS2100 Series L2 Features Web GUI Training

Entry Level L2 Managed Access Switch ECS2100 Series L2 Features Web GUI Training

CK

April 28, 2016
Tweet

More Decks by CK

Other Decks in Technology

Transcript

  1. All Rights Reserved Edge-Core Networks Corp. 2013 www.edge-core.com All Rights

    Reserved Edge-Core Networks Corp. 2013 Entry Level L2 Managed Switch ECS2100 Series Technical Training Dec 2015 04/28/2016
  2. All Rights Reserved Edge-Core Networks Corp. 2013 Agenda High Availability

    RSTP, MSTP, Link Aggregation Comprehensive Security 802.1x, Web auth, MAC auth, Guest VLAN, Voice VLAN Port security, DHCP snooping, IPSG, DAI, Traffic Segmentation, ACL Robust Multicast Control IGMP Snooping Advanced QoS Policy map, TRTCM MISC Ping, Traceroute, Upgrade Firmware
  3. All Rights Reserved Edge-Core Networks Corp. 2013 Spanning Tree Protocol

    Spanning-Tree Protocol is a function to prevent undesirable loops in the network and provides path redundancy. Only one active path can exist between two stations Automatically Detect Loop on the Network Calculate path capacities and then place high-cost ( or lowest capacity) links in a backup state automatically and deterministically
  4. All Rights Reserved Edge-Core Networks Corp. 2013 Rapid Spanning Tree

    Protocol RSTP provides rapid convergence of the spanning tree in less than 1 second. Provides rapid recovery of connectivity following the failure of a Bridge, Bridge Ports, or a LAN. A new Root Port can transit rapidly to the Forwarding Port State. The use of explicit acknowledgements between Bridges allow Designated Ports to transit rapidly to the Forwarding Port State. RSTP allows Bridge Ports connected to a LAN segment that is at the edge of the Bridged LAN to be configured to transit directly to Forwarding State
  5. All Rights Reserved Edge-Core Networks Corp. 2013 Rapid Convergence Edges

    ports—A port configured as an edge port will immediately transit to the forwarding state after link up Root ports—A new root port will transit immediately to forwarding state and the old root port will be blocked Point-to-point links—A port connect to another switch via a point-to-point-link will become designated port and will negotiate a rapid transition with the other port by using proposal-agreement handshake to ensure a loop-free topology
  6. All Rights Reserved Edge-Core Networks Corp. 2013 RSTP-Looping Broadcasts, Multicast

    or Unknown Unicast lead to Broadcast storm in the network SW 2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 00E00C11CC00 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 Broadcast Multicast Unknown Unicast
  7. All Rights Reserved Edge-Core Networks Corp. 2013 BPDU Format Total

    length = 36 bytes BPDU Type BPDU Flags Version Protocol ID Root ID Cost of Path Bridge ID 2 octets 1 octet 1 octets 1 octets 8 octets 4 octets 8 octets 2 octets Port ID Message Age 2 octets Max Age Hello Time Forward Delay 2 octets 2 octets 2 octets 02 RST BPDU 2 Seconds 15 Seconds 2-byte priority 6-byte MAC Cost of the path to root 20 Seconds Root Message Age =0 Ver2 RSTP TCA Agreement Fowarding Learning Port Role Proposal TC 0 1 2 3 4 5 6 7 Version 1 Length
  8. All Rights Reserved Edge-Core Networks Corp. 2013 Root Bridge Selection

    At startup each switch assumes itself as root bridge and set bridge ID equal to Root ID in the BPDU it send out Bridge ID consist of 2-bytes priority and 6-bytes MAC Address Priority range 0-65535 Default 32,768 or 0x8000 Bridge with highest priority (lowest value) will become root bridge If all devices have the same priority, the bridge with lowest MAC address becomes the root bridge
  9. All Rights Reserved Edge-Core Networks Corp. 2013 Spanning Tree Protocol

    SW 2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 32768. 00E00C11CC00 32768. 7072CF78A019 32768. 0012CFF3DF86 32768. 0012CFF3DEB6 I am the root BPDU 32768. 7072cf78A019 Root Path cost: 0 Priority ID MAC Address Bridge ID
  10. All Rights Reserved Edge-Core Networks Corp. 2013 Spanning Tree Protocol

    SW 2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 32768. 00E00C11CC0 32768. 7072CF78A019 32768. 0012CFF3DF86 32768. 0012CFF3DEB6 BPDU 32768. 0012CFF3DEB6 Root Path cost: 0 Priority ID MAC Address Bridge ID No, You are not the Root I am the root ROOT
  11. All Rights Reserved Edge-Core Networks Corp. 2013 RSTP-Port Role Root

    Port The port offers the lowest cost path to the root. The port which receives BPDU from designated port Designated Port The bridge which designated port attached offer the lowest cost to the root for the LAN. Designated port regenerates BPDU to the downstream bridge Alternate Port The port neither the root port nor the designated will become blocked port. Blocked port doesn’t forward packet. Blocked port receives BPDU from the designated port but doesn’t forward it
  12. All Rights Reserved Edge-Core Networks Corp. 2013 Bridge Port State

    Disabled Blocking Listening Learning Forwarding No Link Fast Spanning Tree 15 s 15 s 1s Before Forwarding Forward Delay Forward Delay Max Age 20 s
  13. All Rights Reserved Edge-Core Networks Corp. 2013 STP Port States

    Forwarding - Learning - - Listening - - - Blocking - - - - Disabled Forward Data Learn Address Transmit BPDU Receive BPDU
  14. All Rights Reserved Edge-Core Networks Corp. 2013 Spanning Tree Protocol

    SW 2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 00E00C11CC00 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 0 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 10,000 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 0 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 10,000 Received BPDUs from 2 ports Telling 32768. 0012CFF3DEB6 is Root Loop Same Path cost to root 20,000 32768.00012CFF3DF86 <32768. 7072CF78A019> DP RP DP RP Alternate Port RP DP DP ROOT
  15. All Rights Reserved Edge-Core Networks Corp. 2013 Spanning Tree Protocol

    -- Logical Topology SW 2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 00E00C11CC00 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 ROOT
  16. All Rights Reserved Edge-Core Networks Corp. 2013 Spanning Tree Protocol—Redundant

    Path SW 2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 00E00C11CC00 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 ROOT
  17. All Rights Reserved Edge-Core Networks Corp. 2013 Spanning Tree Protocol

    -- Recovery SW 2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 00E00C11CC00 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 ROOT
  18. All Rights Reserved Edge-Core Networks Corp. 2013 Path Cost 2

    500 2 1000 2 10Gbps 3 5,000 4 10,000 5 1Gbps 15 50,000 18 100,000 19 200,000 100Mbps 90 500,000 95 1,000,000 100 2,000,000 10Mbps Path Cost Full Link Speed Half Trunk (STP) (RSTP) (STP) (RSTP) (STP) (RSTP) (STP) (RSTP)
  19. All Rights Reserved Edge-Core Networks Corp. 2013 Spanning Tree Protocol—Path

    Cost SW 2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 00E00C11CC00 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 0 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 10,000 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 0 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 10,000 DP RP DP RP Alternate Port RP DP DP 100Full Path cost= 100,000 1000Full Path cost= 10,000 1000Full Path cost= 10,000 1000Full Path cost= 10,000 Received BPDUs from 2 ports Telling 32768.0012CFF3DEB6 is Root Loop Smaller Path cost to root 20,000 via port 25 (vs 110,000) via port 26 ROOT
  20. All Rights Reserved Edge-Core Networks Corp. 2013 Change Port 26

    to 100Full Please make sure the counter part also set to media type SFP-Forced 100FX, otherwise there will be no connection
  21. All Rights Reserved Edge-Core Networks Corp. 2013 RSTP-Priority ID SW

    2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 32768.7072CF78A019 32768.0012CFF3DF86 32768.0012CFF3DEB6 4096. 00E00C11CC00 ROOT
  22. All Rights Reserved Edge-Core Networks Corp. 2013 RSTP-Port Priority SW

    2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 32768. 00E00C11CC00 32768.7072CF78A019 32768.0012CFF3DF86 32768.0012CFF3DEB6 Priority ID 128.26 Port ID Alternate Port 128.27 27 ROOT 9 27
  23. All Rights Reserved Edge-Core Networks Corp. 2013 RSTP-Port Priority SW

    2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 32768. 00E00C11CC00 32768.7072CF78A019 32768.0012CFF3DF86 32768.0012CFF3DEB6 Priority ID 128.26 Port ID Alternate Port 16.27 27 ROOT 9 27
  24. All Rights Reserved Edge-Core Networks Corp. 2013 MSTP MSTP uses

    RSTP for rapid convergence to provide loop-free network and redundant path MSTP enables VLANs to be grouped into a spanning-tree instance, with each instance having a spanning-tree topology, provides multiple forwarding paths for data traffic and enables load balancing
  25. All Rights Reserved Edge-Core Networks Corp. 2013 MSTP-Instance 1 SW

    2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLAN2) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 32768.7072CF78A019 32768.0012CFF3DF86 32768.0012CFF3DEB6 4096.7072CF75BC86 PC2 (VLAN 4) 192.168.1.112 MST1: VLAN2,3 MST2: VLAN4,5 MST1 Priority:4096 MST2 Priority:61440 MST1: VLAN2,3 MST2: VLAN4,5 MST1 Priority:61440 MST2 Priority:4096
  26. All Rights Reserved Edge-Core Networks Corp. 2013 Set Region Name

    Region name need to be identical for all switches running the MSTP
  27. All Rights Reserved Edge-Core Networks Corp. 2013 MSTP-Instance 2 SW

    2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLAN2) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 32768.7072CF78A019 32768.0012CFF3DF86 32768.0012CFF3DEB6 4096.7072CF75BC86 PC2 (VLAN 4) 192.168.1.112 MST1: VLAN2,3 MST2: VLAN4,5 MST1 Priority:4096 MST2 Priority:61440 MST1: VLAN2,3 MST2: VLAN4,5 MST1 Priority:61440 MST2 Priority:4096
  28. All Rights Reserved Edge-Core Networks Corp. 2013 RSTP-Root Guard SW

    2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 32768.7072CF78A019 0.0012CFF3DF86 32768.0012CFF3DEB6 4096.7072CF75BC86 BPDU 0. 0012CFF3DEB6 Is Root Path cost: 0 ROOT
  29. All Rights Reserved Edge-Core Networks Corp. 2013 RSTP-BPDU Guard SW

    2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 32768.7072CF78A019 32768.0012CFF3DF86 32768.0012CFF3DEB6 4096.7072CF75BC86 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 0 ROOT
  30. All Rights Reserved Edge-Core Networks Corp. 2013 Groups physical links

    together as a single logical link to provide bigger uplink bandwidth Traffic load balancing and protection against link failure Port Trunk Link Down Increase Uplink bandwidth to 8Gbps full duplex Internet SW 2 192.168.1.2 SW 1 192.168.1.1 7072CF75BC86 7072CF78A019
  31. All Rights Reserved Edge-Core Networks Corp. 2013 802.3ad LACP (Link

    Aggregation Control Protocol) Protocol for automatically and dynamically groups physical link of the same media type and speed together Link Down Capability to group upto 8 links as a trunk Ports with same media type and speed, duplex mode trunk automatically
  32. All Rights Reserved Edge-Core Networks Corp. 2013 802.1x Port-based Authentication

    The IEEE 802.1X standards is a port-based access control and authentication protocol It forces a client that is connected to a switch port to authenticate to a RADIUS Server, such as Windows Internet Authentication Services (IAS) Server , before gaining access to a network. The client must be running 802.1X compliant software, which is available in operation systems such as Windows XP Ensuring only authorized users can access the network. Centralized management of username and password on RADIUS server Automatically assign the customer’s VLAN from RADIUS server to access switch
  33. All Rights Reserved Edge-Core Networks Corp. 2013 802.1x Port-based Authentication-

    Single Host Router Internet RADIUS Server Notebook 00-1C-C4- 0D-15-BF Request Username Password Username Password OK
  34. All Rights Reserved Edge-Core Networks Corp. 2013 802.1x Port-based Authentication-

    Mac-based Router Internet Notebook 20-6A-8A- 15-A2-41 Notebook 00-1C-C4- 0D-15-BF Desktop PC 00-12-CF- F3-DE-86
  35. All Rights Reserved Edge-Core Networks Corp. 2013 Guest VLAN Visitors

    who don’t have the access right to the corporate network still need to access the internet Visitors connect to the switch port providing incorrect or no username and password will be group to the Guest VLAN automatically so can only access the internet Automatically isolate visitor to Guest VLAN so corporate network can’t be accessed for ensuring network security In the mean time, provide prestige for visitor to surf internet
  36. All Rights Reserved Edge-Core Networks Corp. 2013 Guest VLAN Router

    Internet RADIUS Server Notebook 00-1C-C4- 0D-15-BF Username:XXX Password: YYY NG Internet
  37. All Rights Reserved Edge-Core Networks Corp. 2013 Voice VLAN To

    provide service of voice over IP, it is recommended to put all voice traffic into separate voice VLAN(s) for ease of management and control Automatically detect VoIP device by OUI of MAC-address or LLDP and group to Voice VLAN Automatically change port priority Switches can detect the IP phone automatically Easily associate to a logically separate VLAN for Voice used Higher CoS value be assigned for guaranteed voice quality
  38. All Rights Reserved Edge-Core Networks Corp. 2013 Voice VLAN Router

    Internet RADIUS Server Notebook 00-1C-C4-0D-15-BF PSTN OUI Description 00-EO-BB 3Com Phones 00-03-6B Cisco Phones 00-E0-75 Polycom Phones 00-D0-1E Pingtel Phones 802.1ab LLDP System Capability TLV
  39. All Rights Reserved Edge-Core Networks Corp. 2013 Port Security Port

    Security function Limit the maximum number of dynamically learned MAC addresses per subscriber interface The maximum MAC count is configurable from 1 to 1024 Dynamically learned MAC by port security will be added to static entry until the switch reboot so only devices with certain MAC addresses can access the network The Port Security learned MAC addresses is configurable to aging out with MAC-address-table aging time to make sure only certain number of MAC can access the network at a time, in cased subscriber change their device, there is no need operator intervention Port security violation action trap and shutdown MAC Notification
  40. All Rights Reserved Edge-Core Networks Corp. 2013 Port Security Router

    Internet Notebook 20-6A-8A- 15-A2-41 Notebook 00-1C-C4- 0D-15-BF Desktop PC 00-12-CF- F3-DE-86 2 1 3
  41. All Rights Reserved Edge-Core Networks Corp. 2013 Port Security Router

    Internet Notebook 20-6A-8A- 15-A2-41 Notebook 00-1C-C4- 0D-15-BF Desktop PC 00-12-CF- F3-DE-86 2 1 3
  42. All Rights Reserved Edge-Core Networks Corp. 2013 Port Security Network

    Access Aging Router Internet Notebook 20-6A-8A- 15-A2-41 Notebook 00-1C-C4- 0D-15-BF 2 3
  43. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Snooping DHCP

    snooping allows a switch to protect a network from rogue DHCP servers Only DHCP Snooping trust port which connected to legal DHCP Server can offer IP to DHCP client Any rogue DHCP servers connected to un-trust port can no longer offer illegal IP to DHCP client and break down the network (By filters out DHCP-offer, DHCP ACK, DHCP NAK) The IP and MAC binding table can be used for IP source guard to avoid hackers changing the IP or MAC to fake valid customers. Automatically create the mapping table to reduce the operator expense
  44. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Snooping Router

    Internet trust port DHCP Discover/ DHCP Request DHCP Server DHCP Offer/ DHCP ACK untrust port DHCP Discover/ DHCP Request DHCP Discover/ DHCP Request DHCP Offer/ DHCP ACK
  45. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Snooping Router

    Internet trust port DHCP Server untrust port DHCP Offer/ DHCP ACK
  46. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Snooping Option

    82 DHCP Snooping Option 82 provides a mechanism for assigning IP address based on the location where the client device is in the network Information about its location can be sent along with the request to the server. The DHCP server makes a decision on what IP should be assigned based on this information. Switch acts as a DHCP relay agent intercepting the DHCP requests, appends the circuit ID and remote ID in the option 82 field and forwards the request message to DHCP server a) remote-id mac-address [encode hex] b) circuit-id vlan ID and Unit/Port
  47. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Snooping Option

    82 Router Internet trust port DHCP Discover/ DHCP Request DHCP Discover/ Request + DHCP Option 82 (Circuit ID: VLAN & Port Remote ID: MAC,or IP or SW1 DHCP Server DHCP Offer/ ACK + DHCP Option 82 (Circuit ID: VLAN & Port Remote ID: SW1 DHCP Offer/ DHCP ACK SW1
  48. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Option 82

    Format Circuit ID (extra subtype included) and Remote ID (MAC (hex) 01 N 00 04 00 01 01 01 Sub-option type Length Circuit ID Type Length VLAN ID Module Port Number 1byte 1byte 1byte 1byte 2bytes 1byte 1byte 02 08 00 06 Sub-option type Length Remote ID Type Length 1byte 1byte 1byte 1byte 6byte 0e 00 c1 11 cc 00 MAC Address
  49. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Option 82

    Format No extra subtype included 01 04 00 01 01 01 Circuit ID Type Length VLAN ID Module Port Number 1byte 1byte 2bytes 1byte 1byte
  50. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Snooping relay

    Option 82 Router Internet trust port DHCP Discover/ DHCP Request DHCP Discover/ Request + DHCP Option 82 (Circuit ID: VLAN & Port Remote ID: SW1 DHCP Server 192.168.1.200 DHCP Offer/ ACK + DHCP Option 82 (Circuit ID: VLAN & Port Remote ID: SW1 DHCP Offer/ DHCP ACK SW1 192.168.1.1 Vlan 2 Client 192.168.2.100
  51. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Relay Client

    DHCP Discover broadcast packet Switch Change DHCP Discover broadcast packet to unicast with Switch source IP
  52. All Rights Reserved Edge-Core Networks Corp. 2013 IP Source Guard

    A security feature that restricts IP traffic on Layer 2 interfaces by filtering traffic. based on the DHCP snooping binding database on manually configured IP source bindings Prevent traffic attacks when a host tries to attack the network by claiming neighbor host's IP address. Stop malicious people from using IP addresses that weren‘t assigned to them Stop clients from forging their MAC address. MAC address filtering makes flooding the switch impossible.
  53. All Rights Reserved Edge-Core Networks Corp. 2013 IP Source Guard

    Router Internet trust port DHCP Discover DHCP Server DHCP Snooping Table MAC IP Address 20-6a-8a-15-a2-41 192.168.1.112 xx-xx-xx-xx-xx-xx 192.168.1.113 yy-yy-yy-yy-yy-yy 192.168.1.114 ….. 192.168.1.112 20-6a-8a-15-a2-41 192.168.1.112 00-1c-c4-od-15-bf DHCP Offer/ ACK DHCP Offer/ DHCP ACK
  54. All Rights Reserved Edge-Core Networks Corp. 2013 IP Source Guard

    Configuration Configure IP source-guard sip-mac on port Check IP source-guard configuration Check IP source-guard binding table
  55. All Rights Reserved Edge-Core Networks Corp. 2013 IP Source Guard

    Configuration Configure static ip source guard entry Check static ip source guard entry
  56. All Rights Reserved Edge-Core Networks Corp. 2013 ARP Inspection ARP

    inspection uses DHCP Snooping binding database to verify the validity of received ARP packets. Use access-list arp command to create ARP ACL Use permit statement to allow valid ARP packets; use deny to reject the invalid ARP packets. Additional ARP validation for Source MAC, Destination MAC, sender/ target IP The ARP inspection is CPU intensive. Should rate limit the rate to CPU. DAI will log the dropped ARP packets. The information includes receiving VLAN, port number, source IP and source MAC.
  57. All Rights Reserved Edge-Core Networks Corp. 2013 Dynamic ARP Inspection

    Router Internet trust port ARP Request for gateway 192.168.1.25 4 DHCP Server ARP Reply 192.168.1.254 is at 00-1c-c4-od-15-bf ARP Reply 192.168.1.254 is at 00-1c-c4-od-15-bf 192.168.1.112 20-6a-8a-15-a2-41 192.168.1.254 00-21-91-18-52-55 192.168.1.12 00-1c-c4-0d-15-bf\ ,Man In The Middle Attack
  58. All Rights Reserved Edge-Core Networks Corp. 2013 Configure trust port

    (ARP packets received from trust port won’t be checked)
  59. All Rights Reserved Edge-Core Networks Corp. 2013 Show ARP Inspection

    Log Possible reason of ARP packets dropped by DHCP Snooping Static IP IP doesn’t dynamically get from DHCP server, so there is no entry in the DHCP Snooping binding table Clear dhcp snooping binding table, the arp entry age out
  60. All Rights Reserved Edge-Core Networks Corp. 2013 ARP Inspection and

    DHCP Snooping Binding Table Router Internet trust port ARP Request for gateway 192.168.1.25 4 DHCP Server ARP Reply 192.168.1.254 is at 00-21-91-18-52-55 ARP Request What MAC is 192.168.1.254 192.168.1.112 20-6a-8a-15-a2-41 192.168.1.254 00-21-91-18-52-55 192.168.1.12 00-1c-c4-0d-15-bf ARP Packet was dropped because 192.168.1.12 is not in DHCP binding table DHCP Snooping Table MAC IP Address 20-6a-8a-15-a2-41 192.168.1.112 xx-xx-xx-xx-xx-xx 192.168.1.113 yy-yy-yy-yy-yy-yy 192.168.1.114 ….. untrust port untrust port
  61. All Rights Reserved Edge-Core Networks Corp. 2013 ARP Inspection based

    on ACL Use ACL to permit only certain IP and mac address of the default gateway Bind the ACL to vlan Check the ARP Inspection filter
  62. All Rights Reserved Edge-Core Networks Corp. 2013 Validate ARP Packet

    ARP Inspection supports the validation of arp packet based on Destination MAC, IP or source MAC IP validation supports allow-zeros for 0.0.0.0 sender address
  63. All Rights Reserved Edge-Core Networks Corp. 2013 Access Control List

    DSCP Preamble DEST SRC Type 0800 IP Header TCP/UDP Header DATA CRC Src Port Dest Port TOS IP Precedence TOS Preamble DEST SRC Type 0800 IP Header DATA CRC SIP DIP Preamble DEST MAC SRC MAC Type DATA CRC Preamble DEST SRC 8100 PID/VID Type DATA CRC MAC ACL IP Standard ACL IP Extended ACL
  64. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Snooping Layer

    2 switches can use IGMP snooping to prevent the flooding of multicast traffic by dynamically configuring switch port so that multicast traffic is forwarded to only those ports associated with IP multicast receiver By implementing the IGMP snooping feature, it makes Layer 2 switch increase the performance of network for reducing multicast traffics flooding
  65. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Snooping Router

    Internet VLAN 1 IPTV Triple Play_Subscribers IP-TV Server VLAN 1 IPTV 224.1.1.1 224.1.1.2 224.1.1.3 224.1.1.4 SW1 192.168.1.1 AGG_1 192.168.1.2
  66. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Snooping mrouter

    port IGMP Snooping only start to work when there is a multicast router in the network, the port which connect to the multicast router and receive general query is mrouter port Mrouter port can be configured statically
  67. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Snooping-Join Router

    Internet VLAN 1 IPTV Triple Play_Subscribers IP-TV Server VLAN 1 IPTV 224.1.1.1 224.1.1.2 224.1.1.3 224.1.1.4 SW1 192.168.1.1 AGG_1 192.168.1.2 Join Join Multicast Group Ports 01005E010101 1 Multicast Group Ports 01005E010101 25
  68. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Snooping-Leave Router

    Internet VLAN 1 IPTV Triple Play_Subscribers IP-TV Server VLAN 1 IPTV 224.1.1.1 224.1.1.2 224.1.1.3 224.1.1.4 SW1 192.168.1.1 AGG_1 192.168.1.2 Leave Leave GS-Q GS-Q Multicast Group Ports 01005E010101 Multicast Group Ports 01005E010101
  69. All Rights Reserved Edge-Core Networks Corp. 2013 Leave Leave, wait

    for 2 group specific query then remove from multicast table Immediate leave will remove the group without waiting GS- Query
  70. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Filtering Router

    Internet VLAN 1 IPTV Triple Play_Subscribers IP-TV Server VLAN 1 IPTV 224.1.1.1 224.1.1.2 224.1.1.3 224.1.1.4 224.1.1.1 224.1.1.2 224.1.1.3 Multicast Router 192.168.1.10 IGMP filtering IGMP profile 1 Permit Range 224.1.1.1 224.1.1.3
  71. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Throttling Router

    Internet IP IGMP max-group 2 IP-TV Server 224.1.1.1 224.1.1.2 224.1.1.3 224.1.1.4 224.1.1.1 224.1.1.2 Multicast Router 192.168.1.10
  72. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Snooping Priority

    Router Internet IP IGMP snooping priority 6 IP-TV Server 224.1.1.1 224.1.1.2 224.1.1.3 224.1.1.4 Multicast Router 192.168.1.10 VLAN 2 Data VLAN 4 IPTV 6 vid 2,3,4 tagged 4 6 4
  73. All Rights Reserved Edge-Core Networks Corp. 2013 Quality of Service

    • Offers a wide range of granular bandwidth and QoS options Strict Priority Queue Weighted Round-Robin (WRR) Queue SWRR Incoming packets Classify W1 W2 W5 W4 W3 W6 W7 W8 Outgoing packets Classification Queuing (8 hardware Queues) Scheduling Policing QoS-based traffic Management
  74. All Rights Reserved Edge-Core Networks Corp. 2013 Traffic Policing Router

    Internet VLAN 3 Voice VLAN 2 Data VLAN 4 IPTV Triple Play_Subscribers PSTN IP-TV Server 1Mbps Burst 4MBps Exceed drop