Upgrade to Pro — share decks privately, control downloads, hide ads and more …

L2 Features Training for Edge-Core Switch (CLI)

CK
April 28, 2016

L2 Features Training for Edge-Core Switch (CLI)

L2 Features Training for Edge-Core Switch (CLI)

CK

April 28, 2016
Tweet

More Decks by CK

Other Decks in Technology

Transcript

  1. All Rights Reserved Edge-Core Networks Corp. 2013 www.edge-core.com All Rights

    Reserved Edge-Core Networks Corp. 2013 L2 Technical Training Dec 2013 04/28/2016
  2. All Rights Reserved Edge-Core Networks Corp. 2013 Agenda High Availability

    RSTP,MSTP, ITU-T G.8032 ERPS,Link Aggregation Comprehensive Security 802.1x, Web auth, MAC auth, Guest vlan, Voice vlan Port security, DHCP snooping, IPSG, DAI, Traffic Segementation, ACL Robust Multicast Control IGMP Snooping, MVR Advanced QoS Policy map, TRTCM Superior Manageability AAA Advanced Metro Ethernet Features L2VPN, OAM
  3. All Rights Reserved Edge-Core Networks Corp. 2013 Spanning Tree Protocol

    Spanning-Tree Protocol is a function to preventing undesirable loops in the network and provides path redundancy. Only one active path can exist between two stations Automatically Detect Loop on the Network Calculate path capacities and then place high-cost ( or lowest capacity) links in a backup state automatically and deterministically
  4. All Rights Reserved Edge-Core Networks Corp. 2013 Rapid Spanning Tree

    Protocol RSTP provides rapid convergence of the spanning tree in less than 1 second. Provides rapid recovery of connectivity following the failure of a Bridge, Bridge Ports, or a LAN. A new Root Port can transit rapidly to the Forwarding Port State. The use of explicit acknowledgements between Bridges allow Designated Ports to transit rapidly to the Forwarding Port State. RSTP allows Bridge Ports connected to a LAN segment that is at the edge of the Bridged LAN to be configured to transit directly to Forwarding State
  5. All Rights Reserved Edge-Core Networks Corp. 2013 Rapid Convergence Edges

    ports—A port configured as an edge port will immediately transit to the forwarding state after link up Root ports—A new root port will transit immediately to forwarding state and the old root port will be blocked Point-to-point links—A port connect to another switch via a point-to-point-link will become designated port and will negotiate a rapid transition with the other port by using proposal-agreement handshake to ensure a loop-free topology
  6. All Rights Reserved Edge-Core Networks Corp. 2013 RSTP-Looping Broadcasts, Multicast

    or Unknown Unicast lead to Broadcast storm in the network SW 2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 Broadcast Multicast Unknown Unicast
  7. All Rights Reserved Edge-Core Networks Corp. 2013 BPDU Format Total

    length = 36 bytes BPDU Type BPDU Flags Version Protocol ID Root ID Cost of Path Bridge ID 2 octets 1 octet 1 octets 1 octets 8 octets 4 octets 8 octets 2 octets Port ID Message Age 2 octets Max Age Hello Time Forward Delay 2 octets 2 octets 2 octets 02 RST BPDU 2 Seconds 15 Seconds 2-byte priority 6-byte MAC Cost of the path to root 20 Seconds Root Message Age =0 Ver2 RSTP TCA Agreement Fowarding Learning Port Role Proposal TC 0 1 2 3 4 5 6 7 Version 1 Length
  8. All Rights Reserved Edge-Core Networks Corp. 2013 Root Bridge Selection

    At startup each switch assumes itself as root bridge and set bridge ID equal to Root ID in the BPDU it send out Bridge ID consist of 2-bytes priority and 6-bytes MAC Address Priority range 0-65535 Default 32,768 or 0x8000 Bridge with highest priority (lowest value) will become root bridge If all devices have the same priority, the bridge with lowest MAC address becomes the root bridge
  9. All Rights Reserved Edge-Core Networks Corp. 2013 Spanning Tree Protocol

    SW 2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 32768. 7072CF75BC86 32768. 7072CF78A019 32768. 0012CFF3DF86 32768. 0012CFF3DEB6 I am the root BPDU 32768. 7072cf78A019 Root Path cost: 0 Priority ID MAC Address Bridge ID
  10. All Rights Reserved Edge-Core Networks Corp. 2013 Spanning Tree Protocol

    SW 2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 32768. 7072CF75BC86 32768. 7072CF78A019 32768. 0012CFF3DF86 32768. 0012CFF3DEB6 BPDU 32768. 0012CFF3DEB6 Root Path cost: 0 Priority ID MAC Address Bridge ID No, You are not the Root I am the root ROOT
  11. All Rights Reserved Edge-Core Networks Corp. 2013 RSTP-Port Role Root

    Port The port offers the lowest cost path to the root. The port which receives BPDU from designated port Designated Port The bridge which designated port attached offer the lowest cost to the root for the LAN. Designated port regenerates BPDU to the downstream bridge Alternate Port The port neither the root port nor the designated will become blocked port. Blocked port doesn’t forward packet. Blocked port receives BPDU from the designated port but doesn’t forward it
  12. All Rights Reserved Edge-Core Networks Corp. 2013 Bridge Port State

    Disabled Blocking Listening Learning Forwarding No Link Fast Spanning Tree 15 s 15 s 1s Before Forwarding Forward Delay Forward Delay Max Age 20 s
  13. All Rights Reserved Edge-Core Networks Corp. 2013 STP Port States

    Forwarding - Learning - - Listening - - - Blocking - - - - Disabled Forward Data Learn Address Transmit BPDU Receive BPDU
  14. All Rights Reserved Edge-Core Networks Corp. 2013 Spanning Tree Protocol

    SW 2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 0 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 10,000 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 0 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 10,000 Received BPDUs from 2 ports Telling 32768. 0012CFF3DEB6 is Root Loop Same Path cost to root 20,000 32768.00012CFF3DF86 <32768. 7072CF78A019> DP RP DP RP Alternate Port RP DP DP ROOT
  15. All Rights Reserved Edge-Core Networks Corp. 2013 Spanning Tree Protocol—Redundant

    Path SW 2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 ROOT
  16. All Rights Reserved Edge-Core Networks Corp. 2013 Spanning Tree Protocol—Topology

    Change SW 2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 ROOT
  17. All Rights Reserved Edge-Core Networks Corp. 2013 Path Cost 2

    500 2 1000 2 10Gbps 3 5,000 4 10,000 5 1Gbps 15 50,000 18 100,000 19 200,000 100Mbps 90 500,000 95 1,000,000 100 2,000,000 10Mbps Path Cost Full Link Speed Half Trunk (STP) (RSTP) (STP) (RSTP) (STP) (RSTP) (STP) (RSTP)
  18. All Rights Reserved Edge-Core Networks Corp. 2013 Spanning Tree Protocol—Path

    Cost SW 2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 0 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 10,000 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 0 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 10,000 DP RP DP RP Alternate Port RP DP DP 100Full Path cost= 100,000 1000Full Path cost= 10,000 1000Full Path cost= 10,000 1000Full Path cost= 10,000 Received BPDUs from 2 ports Telling 32768.0012CFF3DEB6 is Root Loop Smaller Path cost to root 20,000 via port 25 (vs 110,000) via port 26 ROOT
  19. All Rights Reserved Edge-Core Networks Corp. 2013 RSTP-Priority ID SW

    2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 32768.7072CF78A019 32768.0012CFF3DF86 32768.0012CFF3DEB6 4096. 7072CF75BC86 ROOT
  20. All Rights Reserved Edge-Core Networks Corp. 2013 RSTP-Port Priority SW

    2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 4096.7072CF75BC86 32768.7072CF78A019 32768.0012CFF3DF86 32768.0012CFF3DEB6 128.26 Priority ID Port ID 128.27 Alternate Port 27 ROOT
  21. All Rights Reserved Edge-Core Networks Corp. 2013 RSTP-Port Priority SW

    2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 4096.7072CF75BC86 32768.7072CF78A019 32768.0012CFF3DF86 32768.0012CFF3DEB6 128.26 Priority ID Port ID 16 27 Alternate Port 27 ROOT
  22. All Rights Reserved Edge-Core Networks Corp. 2013 MSTP MSTP uses

    RSTP for rapid convergence to provide loop-free network and redundant path MSTP enables VLANs to be grouped into a spanning-tree instance, with each instance having a spanning-tree topology, provides multiple forwarding paths for data traffic and enables load balancing
  23. All Rights Reserved Edge-Core Networks Corp. 2013 MSTP-Instance 1 SW

    2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLAN2) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 32768.7072CF78A019 32768.0012CFF3DF86 32768.0012CFF3DEB6 4096.7072CF75BC86 PC2 (VLAN 4) 192.168.1.112 MST1: VLAN2,3 MST2: VLAN4,5 MST1 Priority:4096 MST2 Priority:61440 MST1: VLAN2,3 MST2: VLAN4,5 MST1 Priority:61440 MST2 Priority:4096
  24. All Rights Reserved Edge-Core Networks Corp. 2013 SW1 MSTP Create

    VLAN 2-5 and configure uplink port to vlan 2-5 trunk port Switch Spanning-tree mode to MSTP Add VLAN 2,3 to MSTP instance 1 Add VLAN 4,5 to MSTP instance 2 Configure MSTP name
  25. All Rights Reserved Edge-Core Networks Corp. 2013 SW1 MSTP Configure

    instance 1 priority 4096 so SW1 become root for MSTP instance 1 Configure instance 2 priority 61440 so SW1 is non root for MSTP instance 2
  26. All Rights Reserved Edge-Core Networks Corp. 2013 SW2 MSTP Create

    VLAN 2-5 and configure uplink port to vlan 2-5 trunk port Switch Spanning-tree mode to MSTP Add VLAN 2,3 to MSTP instance 1 Add VLAN 4,5 to MSTP instance 2 Configure MSTP name
  27. All Rights Reserved Edge-Core Networks Corp. 2013 SW3 MSTP Create

    VLAN 2-5 and configure uplink port to vlan 2-5 trunk port Switch Spanning-tree mode to MSTP Add VLAN 2,3 to MSTP instance 1 Add VLAN 4,5 to MSTP instance 2 Configure MSTP name
  28. All Rights Reserved Edge-Core Networks Corp. 2013 SW3 MSTP Configure

    instance 2 priority 4096 so SW1 become root for MSTP instance 2 Configure instance 1 priority 61440 so SW1 is non root for MSTP instance 1
  29. All Rights Reserved Edge-Core Networks Corp. 2013 SW3 MSTP Create

    VLAN 2-5 and configure uplink port to vlan 2-5 trunk port Switch Spanning-tree mode to MSTP Add VLAN 2,3 to MSTP instance 1 Add VLAN 4,5 to MSTP instance 2 Configure MSTP name
  30. All Rights Reserved Edge-Core Networks Corp. 2013 MSTP Configuration Information

    Check MSTP configuration, the Configuration name need to be identical for all switches to run MSTP together The VLANs for each instance need to be identical for all switches to run MSTP together
  31. All Rights Reserved Edge-Core Networks Corp. 2013 SW1 MSTP Instance

    1 SW1 is the Root, port 25 and 26 are designated port
  32. All Rights Reserved Edge-Core Networks Corp. 2013 SW2 MSTP Instance

    1 SW1 is the Root, port 25 is root port, the path cost to root is 10,000, 26 is designated port
  33. All Rights Reserved Edge-Core Networks Corp. 2013 SW3 MSTP Instance

    1 SW1 is the Root, port 10 is root port, the path cost to root is 20,000, port 9 is alternate port under blocking state
  34. All Rights Reserved Edge-Core Networks Corp. 2013 SW4 MSTP Instance

    1 SW1 is the Root, port 10 is root port, the path cost to root is 10,000, port 9 is designated port
  35. All Rights Reserved Edge-Core Networks Corp. 2013 MSTP-Instance 2 SW

    2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLAN2) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 32768.7072CF78A019 32768.0012CFF3DF86 32768.0012CFF3DEB6 4096.7072CF75BC86 PC2 (VLAN 4) 192.168.1.112 MST1: VLAN2,3 MST2: VLAN4,5 MST1 Priority:4096 MST2 Priority:61440 MST1: VLAN2,3 MST2: VLAN4,5 MST1 Priority:61440 MST2 Priority:4096
  36. All Rights Reserved Edge-Core Networks Corp. 2013 SW1 MSTP Instance

    2 SW3 is the Root, port 25 is root port, the path cost to root is 20,000, port 25 is alternate port under blocking state
  37. All Rights Reserved Edge-Core Networks Corp. 2013 SW2 MSTP Instance

    2 SW3 is the Root, port 26 is root port, the path cost to root is 10,000, port 25 is designated port
  38. All Rights Reserved Edge-Core Networks Corp. 2013 SW3 MSTP Instance

    2 SW3 is the Root, port 25 and 26 are designated port
  39. All Rights Reserved Edge-Core Networks Corp. 2013 SW4 MSTP Instance

    2 SW3 is the Root, port 9 is root port, the path cost to root is 10,000, port 10 is designated port
  40. All Rights Reserved Edge-Core Networks Corp. 2013 RSTP-Root Guard SW

    2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 32768.7072CF78A019 0.0012CFF3DF86 32768.0012CFF3DEB6 4096.7072CF75BC86 BPDU 0. 0012CFF3DEB6 Is Root Path cost: 0 ROOT
  41. All Rights Reserved Edge-Core Networks Corp. 2013 RSTP-BPDU Guard SW

    2 192.168.1.2 SW 3 192.168.1.3 26 9 SW 1 192.168.1.1 SW 4 192.168.1.4 25 10 9 10 25 26 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 32768.7072CF78A019 32768.0012CFF3DF86 32768.0012CFF3DEB6 4096.7072CF75BC86 BPDU 32768. 0012CFF3DEB6 Is Root Path cost: 0 ROOT
  42. All Rights Reserved Edge-Core Networks Corp. 2013 ERPS (ITU-T G.8032)

    • Ethernet Ring Protection Switch the capability to rapidly detect and recover from node, link, or service failure to offer a very high availability service to the end user • Recovery from failures occurs in less than 50 milliseconds • This capability meets the most demanding quality and availability requirements for the delivery of mission-critical enterprise applications, high-quality voice and video services, and in the most generic case any application requiring a demanding SLA
  43. All Rights Reserved Edge-Core Networks Corp. 2013 ERPS SW 2

    192.168.1.2 Vlan 10 SW 23 192.168.1.3 Vlan 10 26 9 SW 1 192.168.1.1 Vlan 10 SW 4 192.168.1.4 Vlan 10 25 10 9 10 25 East West 26 West East West RPL Owner East 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 East West East 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 MEP 23
  44. All Rights Reserved Edge-Core Networks Corp. 2013 Configure ERPS Control

    VLAN Create management vlan 10 Add port to vlan 10 Assign IP address to interface vlan 10 Disable spanning-tree on port running erps
  45. All Rights Reserved Edge-Core Networks Corp. 2013 Configure ERPS Create

    erps domain name test id 1 Configure control-vlan 10 Assign switch as rpl owner Assign ring port east on port 25 Configure ring port west on port 25 Enable the erps
  46. All Rights Reserved Edge-Core Networks Corp. 2013 ERPS Result SW1,

    RPL Owner west ring port will be blocked SW2
  47. All Rights Reserved Edge-Core Networks Corp. 2013 ERPS Protection mode

    SW 2 192.168.1.2 Vlan 10 SW 23 192.168.1.3 Vlan 10 26 9 SW 1 192.168.1.1 Vlan 10 SW 4 192.168.1.4 Vlan 10 25 10 9 10 25 East West 26 West East West RPL Owner East 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 East West East 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 MEP 21 MEP 12 MEP 14 MEP 23
  48. All Rights Reserved Edge-Core Networks Corp. 2013 Ring Failure Recovery

    SW 2 192.168.1.2 Vlan 10 SW 23 192.168.1.3 Vlan 10 26 9 SW 1 192.168.1.1 Vlan 10 SW 4 192.168.1.4 Vlan 10 25 10 9 10 25 East West 26 West East West RPL Owner East 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 East West East 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 MEP 21 MEP 12 MEP 14 MEP 23
  49. All Rights Reserved Edge-Core Networks Corp. 2013 Revertive Mode SW

    2 192.168.1.2 Vlan 10 SW 23 192.168.1.3 Vlan 10 26 9 SW 1 192.168.1.1 Vlan 10 SW 4 192.168.1.4 Vlan 10 25 10 9 10 25 East West 26 West East West RPL Owner East 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 East West East 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 MEP 21 MEP 12 MEP 14 MEP 23
  50. All Rights Reserved Edge-Core Networks Corp. 2013 Non-revertive mode SW

    2 192.168.1.2 Vlan 10 SW 23 192.168.1.3 Vlan 10 26 9 SW 1 192.168.1.1 Vlan 10 SW 4 192.168.1.4 Vlan 10 25 10 9 10 25 East West 26 West East West RPL Owner East 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 East West East 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 MEP 21 MEP 12 MEP 14 MEP 23
  51. All Rights Reserved Edge-Core Networks Corp. 2013 Groups physical links

    together as a single logical link to provide bigger uplink bandwidth Traffic load balancing and protection against link failure Port Trunk Link Down Increase Uplink bandwidth to 8Gbps full duplex Internet SW 2 192.168.1.2 SW 1 192.168.1.1 7072CF75BC86 7072CF78A019
  52. All Rights Reserved Edge-Core Networks Corp. 2013 SW1 STP Status

    Port 25 is forwarding, port 26-28 are blocking by Spanning- Tree protocol when there is no port trunk enabled
  53. All Rights Reserved Edge-Core Networks Corp. 2013 Static Trunk Configuration

    Create port-channel Add port 25-28 to channel group
  54. All Rights Reserved Edge-Core Networks Corp. 2013 Trunk Port Status

    Port 25-28 had been grouped to port-channel 1
  55. All Rights Reserved Edge-Core Networks Corp. 2013 SW2 Configuration and

    STP Status Need to configure static trunk on SW2 before connecting the cable to prevent loop SW2 Spanning tree protocol status
  56. All Rights Reserved Edge-Core Networks Corp. 2013 802.3ad LACP (Link

    Aggregation Control Protocol) Protocol for automatically and dynamically groups physical link of the same media type and speed together Link Down Capability to group upto 8 links as a trunk Ports with same media type and speed, duplex mode trunk automatically
  57. All Rights Reserved Edge-Core Networks Corp. 2013 SW1 & SW2

    Negate the static trunk setting Enable LACP on port 25-28
  58. All Rights Reserved Edge-Core Networks Corp. 2013 LACP Status Port

    channel 1 automatically established and port 25-28 became the member ports using LACP
  59. All Rights Reserved Edge-Core Networks Corp. 2013 Port Channel Load

    Balance Port Channel load-balance options Display current port-channel load-balance mode
  60. All Rights Reserved Edge-Core Networks Corp. 2013 802.1x Port-based Authentication

    The IEEE 802.1X standards is a port-based access control and authentication protocol It forces a client that is connected to a switch port to authenticate to a RADIUS Server, such as Windows Internet Authentication Services (IAS) Server , before gaining access to a network. The client must be running 802.1X compliant software, which is available in operation systems such as Windows XP Ensuring only authorized users can access the network. Centralized management of username and password on RADIUS server Automatically assign the customer’s VLAN from RADIUS server to access switch
  61. All Rights Reserved Edge-Core Networks Corp. 2013 802.1x Port-based Authentication-

    Single Host Router Internet RADIUS Server Notebook 00-1C-C4- 0D-15-BF Request Username Password Username Password OK
  62. All Rights Reserved Edge-Core Networks Corp. 2013 802.1x configuration Define

    the RADIUS Server, IP address and key Enable 802.1x globally Enable 802.1x per port
  63. All Rights Reserved Edge-Core Networks Corp. 2013 802.1x Port-based Authentication-

    Mac-based Router Internet Notebook 20-6A-8A- 15-A2-41 Notebook 00-1C-C4- 0D-15-BF Desktop PC 00-12-CF- F3-DE-86
  64. All Rights Reserved Edge-Core Networks Corp. 2013 802.1x Web Authentication

    Web authentication authenticate end users that do not run the IEEE 802.1X supplicant When a user open a web browser, the Web Authentication feature intercepts the http packet and redirect to a login web page for entering username and password After the username and password have been authenticated by RADIUS server then the user can access the network Web authentication provides simple authentication without a supplicant or client Provide the friendly interface for non-802.1x clients Without any effort in trouble shooting for 802.1x client software Still can provide the centralized management.
  65. All Rights Reserved Edge-Core Networks Corp. 2013 802.1x Web Authentication

    Router Internet RADIUS Server Notebook 00-1C-C4- 0D-15-BF Username Password OK Web Redirect
  66. All Rights Reserved Edge-Core Networks Corp. 2013 Web-Authentication Configuration Enable

    Web authentication globally Enable Web authentication per port
  67. All Rights Reserved Edge-Core Networks Corp. 2013 Web-Authentication Status Check

    global Web authentication status Check port web authentication status
  68. All Rights Reserved Edge-Core Networks Corp. 2013 MAC-Authentication Some network

    devices which are 802.1x unaware like Printer can’t send EAPOL (Extensible Authentication Packet over LAN) to switch Switch help to send authentication information with MAC as user name and password to RADIUS server insuring only authorized devices can access to the network Network administrator can even control the 802.1x unaware devices from access the network Avoid user using the switch port connect to 802.1x unaware device Access right for 802.1x unaware devices can also be controlled by the centralized RADIUS Server for ease of management
  69. All Rights Reserved Edge-Core Networks Corp. 2013 802.1x MAC Authentication

    Router Internet RADIUS Server Notebook 00-1C-C4- 0D-15-BF Username:MAC Password: MAC OK
  70. All Rights Reserved Edge-Core Networks Corp. 2013 Guest VLAN Visitors

    who don’t have the access right to the corporate network still need to access the internet Visitors connect to the switch port providing incorrect or no username and password will be group to the Guest VLAN automatically so can only access the internet Automatically isolate visitor to Guest VLAN so corporate network can’t be accessed for ensuring network security In the mean time, provide prestige for visitor to surf internet
  71. All Rights Reserved Edge-Core Networks Corp. 2013 Guest VLAN Router

    Internet RADIUS Server Notebook 00-1C-C4- 0D-15-BF Username:XXX Password: YYY NG Internet
  72. All Rights Reserved Edge-Core Networks Corp. 2013 Guest VLAN Port

    5 had been dynamically group to Guest VLAN after client failed 802.1x authentication
  73. All Rights Reserved Edge-Core Networks Corp. 2013 Voice VLAN To

    provide service of voice over IP, it is recommended to put all voice traffic into separate voice VLAN(s) for ease of management and control Automatically detect VoIP device by OUI of MAC-address or LLDP and group to Voice VLAN Automatically change port priority Switches can detect the IP phone automatically Easily associate to a logically separate VLAN for Voice used Higher CoS value be assigned for guaranteed voice quality
  74. All Rights Reserved Edge-Core Networks Corp. 2013 Voice VLAN Router

    Internet RADIUS Server Notebook 00-1C-C4- 0D-15-BF PSTN OUI Description 00-EO-BB 3Com Phones 00-03-6B Cisco Phones 00-E0-75 Polycom Phones 00-D0-1E Pingtel Phones 802.1ab LLDP System Capability TLV
  75. All Rights Reserved Edge-Core Networks Corp. 2013 Voice VLAN Configuration

    Create Voice VLAN, and define the OUI of the devices (ex. IP phone) which will group to the voice vlan Enable Voice VLAN per port
  76. All Rights Reserved Edge-Core Networks Corp. 2013 Voice VLAN Port

    7 connected with device match the OUI group to voice vlan dynamically
  77. All Rights Reserved Edge-Core Networks Corp. 2013 Port Security Port

    Security function Limit the maximum number of dynamically learned MAC addresses per subscriber interface The maximum MAC count is configurable from 1 to 1024 Dynamically learned MAC by port security will be added to static entry until the switch reboot so only devices with certain MAC addresses can access the network The Port Security learned MAC addresses is configurable to aging out with MAC-address-table aging time to make sure only certain number of MAC can access the network at a time, in cased subscriber change their device, there is no need operator intervention Port security violation action trap and shutdown MAC Notification
  78. All Rights Reserved Edge-Core Networks Corp. 2013 Port Security Router

    Internet Notebook 20-6A-8A- 15-A2-41 Notebook 00-1C-C4- 0D-15-BF Desktop PC 00-12-CF- F3-DE-86 2 1 3
  79. All Rights Reserved Edge-Core Networks Corp. 2013 Port Security Configuration

    Configure port security max-mac-count before enable port security function Check port security configuration
  80. All Rights Reserved Edge-Core Networks Corp. 2013 Port Security Configuration

    Other way of showing port security configuration Show interfaces status Show mac-address-table
  81. All Rights Reserved Edge-Core Networks Corp. 2013 Port Security Action

    Trap Configure port security action trap Check configure of port security action trap Show port security trap event log
  82. All Rights Reserved Edge-Core Networks Corp. 2013 Configure port security

    action shutdown Check port security action Port Security Action Shutdown
  83. All Rights Reserved Edge-Core Networks Corp. 2013 Check port security

    shutdown action by show interfaces Check port security shutdown event log Check port security shutdown action by show interfaces brief Port Security Action Shutdown
  84. All Rights Reserved Edge-Core Networks Corp. 2013 Configure port security

    action trap-and-shutdown Port Security Action Trap and Shutdown
  85. All Rights Reserved Edge-Core Networks Corp. 2013 Port Security Router

    Internet Notebook 20-6A-8A- 15-A2-41 Notebook 00-1C-C4- 0D-15-BF Desktop PC 00-12-CF- F3-DE-86 2 1 3
  86. All Rights Reserved Edge-Core Networks Corp. 2013 Port Security Network

    Access Aging Router Internet Notebook 20-6A-8A- 15-A2-41 Notebook 00-1C-C4- 0D-15-BF 2 3
  87. All Rights Reserved Edge-Core Networks Corp. 2013 Port Security Network

    Access Aging Configure Port Security network access aging Check port security network access aging configuration
  88. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Snooping DHCP

    snooping allows a switch to protect a network from rogue DHCP servers Only DHCP Snooping trust port which connected to legal DHCP Server can offer IP to DHCP client Any rogue DHCP servers connected to un-trust port can no longer offer illegal IP to DHCP client and break down the network (By filters out DHCP-offer, DHCP ACK, DHCP NAK) The IP and MAC binding table can be used for IP source guard to avoid hackers changing the IP or MAC to fake valid customers. Automatically create the mapping table to reduce the operator expense
  89. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Snooping Router

    Internet trust port DHCP Discover/ DHCP Request DHCP Server DHCP Offer/ DHCP ACK untrust port DHCP Discover/ DHCP Request DHCP Discover/ DHCP Request DHCP Offer/ DHCP ACK
  90. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Snooping Router

    Internet trust port DHCP Server untrust port DHCP Offer/ DHCP ACK
  91. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Snooping configuration

    Configure ip dhcp snooping Check ip dhcp snooping configuration
  92. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Snooping Option

    82 DHCP Snooping Option 82 provides a mechanism for assigning IP address based on the location where the client device is in the network Information about its location can be sent along with the request to the server. The DHCP server makes a decision on what IP should be assigned based on this information. Switch acts as a DHCP relay agent intercepting the DHCP requests, appends the circuit ID and remote ID in the option 82 field and forwards the request message to DHCP server a) remote-id ip-address [encode hex/ascii] b) remote-id mac-address [encode hex/ascii] c) remote-id [WORD] d) circuit-id vlan ID and Unit/Port e) circuit-id [WORD]
  93. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Snooping Option

    82 Router Internet trust port DHCP Discover/ DHCP Request DHCP Discover/ Request + DHCP Option 82 (Circuit ID: VLAN & Port Remote ID: MAC,or IP or SW1 DHCP Server DHCP Offer/ ACK + DHCP Option 82 (Circuit ID: VLAN & Port Remote ID: SW1 DHCP Offer/ DHCP ACK SW1
  94. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Snooping Option

    82 Configure IP DHCP Snooping option 82 By default Circuit ID and Remote ID
  95. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Option 82

    Format Circuit ID (extra subtype included) and Remote ID (MAC (hex) 01 N 00 04 00 01 01 01 Sub-option type Length Circuit ID Type Length VLAN ID Module Port Number 1byte 1byte 1byte 1byte 2bytes 1byte 1byte 02 08 00 06 Sub-option type Length Remote ID Type Length 1byte 1byte 1byte 1byte 6byte 70 72 cf 75 bc 86 MAC Address
  96. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Option 82

    Format No extra subtype included 01 04 00 01 01 01 Circuit ID Type Length VLAN ID Module Port Number 1byte 1byte 2bytes 1byte 1byte
  97. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Snooping relay

    Option 82 Router Internet trust port DHCP Discover/ DHCP Request DHCP Discover/ Request + DHCP Option 82 (Circuit ID: VLAN & Port Remote ID: SW1 DHCP Server 192.168.1.200 DHCP Offer/ ACK + DHCP Option 82 (Circuit ID: VLAN & Port Remote ID: SW1 DHCP Offer/ DHCP ACK SW1 192.168.1.1 Vlan 2 Client 192.168.2.100
  98. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Snooping option

    82 relay Configure ip dhcp relay server Enable ip dhcp relay Configure DHCP Snooping Configure Client VLAN
  99. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Snooping option

    82 relay Check DHCP Snooping option 82 relay configuration
  100. All Rights Reserved Edge-Core Networks Corp. 2013 DHCP Relay Client

    DHCP Discover broadcast packet Switch Change DHCP Discover broadcast packet to unicast with Switch source IP
  101. All Rights Reserved Edge-Core Networks Corp. 2013 IP Source Guard

    A security feature that restricts IP traffic on Layer 2 interfaces by filtering traffic. based on the DHCP snooping binding database on manually configured IP source bindings Prevent traffic attacks when a host tries to attack the network by claiming neighbor host's IP address. Stop malicious people from using IP addresses that weren‘t assigned to them Stop clients from forging their MAC address. MAC address filtering makes flooding the switch impossible.
  102. All Rights Reserved Edge-Core Networks Corp. 2013 IP Source Guard

    Router Internet trust port DHCP Discover DHCP Server DHCP Snooping Table MAC IP Address 20-6a-8a-15-a2-41 192.168.1.112 xx-xx-xx-xx-xx-xx 192.168.1.113 yy-yy-yy-yy-yy-yy 192.168.1.114 ….. 192.168.1.112 20-6a-8a-15-a2-41 192.168.1.112 00-1c-c4-od-15-bf DHCP Offer/ ACK DHCP Offer/ DHCP ACK
  103. All Rights Reserved Edge-Core Networks Corp. 2013 IP Source Guard

    Configuration Configure IP source-guard sip-mac on port Check IP source-guard configuration Check IP source-guard binding table
  104. All Rights Reserved Edge-Core Networks Corp. 2013 IP Source Guard

    Configuration Configure static ip source guard entry Check static ip source guard entry
  105. All Rights Reserved Edge-Core Networks Corp. 2013 ARP Inspection ARP

    inspection uses DHCP Snooping binding database to verify the validity of received ARP packets. Use access-list arp command to create ARP ACL Use permit statement to allow valid ARP packets; use deny to reject the invalid ARP packets. Additional ARP validation for Source MAC, Destination MAC, sender/ target IP The ARP inspection is CPU intensive. Should rate limit the rate to CPU. DAI will log the dropped ARP packets. The information includes receiving VLAN, port number, source IP and source MAC.
  106. All Rights Reserved Edge-Core Networks Corp. 2013 Dynamic ARP Inspection

    Router Internet trust port ARP Request for gateway 192.168.1.25 4 DHCP Server ARP Reply 192.168.1.254 is at 00-1c-c4-od-15-bf ARP Reply 192.168.1.254 is at 00-1c-c4-od-15-bf 192.168.1.112 20-6a-8a-15-a2-41 192.168.1.254 00-21-91-18-52-55 192.168.1.12 00-1c-c4-0d-15-bf\ ,Man In The Middle Attack
  107. All Rights Reserved Edge-Core Networks Corp. 2013 ARP Inspection Configuration

    Configure ARP inspection Enable ARP Inspection globally Enable ARP Inspection on certain VLAN Configure trust port (ARP packets received from trust port won’t be checked) Check ARP Inspection configuration
  108. All Rights Reserved Edge-Core Networks Corp. 2013 ARP Inspection Configuration

    Check ARP Inspection status on interface Check ARP Inspection status on VLAN
  109. All Rights Reserved Edge-Core Networks Corp. 2013 ARP Inspection and

    DHCP Snooping Binding Table Router Internet trust port ARP Request for gateway 192.168.1.25 4 DHCP Server ARP Reply 192.168.1.254 is at 00-21-91-18-52-55 ARP Request What MAC is 192.168.1.254 192.168.1.112 20-6a-8a-15-a2-41 192.168.1.254 00-21-91-18-52-55 192.168.1.12 00-1c-c4-0d-15-bf ARP Packet was dropped because 192.168.1.12 is not in DHCP binding table DHCP Snooping Table MAC IP Address 20-6a-8a-15-a2-41 192.168.1.112 xx-xx-xx-xx-xx-xx 192.168.1.113 yy-yy-yy-yy-yy-yy 192.168.1.114 ….. untrust port untrust port
  110. All Rights Reserved Edge-Core Networks Corp. 2013 ARP Inspection Statistic

    and Log ARP Inspection statistic Possible reason of ARP packets dropped by DHCP Snooping Static IP IP doesn’t dynamically get from DHCP server, so there is no entry in the DHCP Snooping binding table Clear dhcp snooping binding table, the arp entry age out
  111. All Rights Reserved Edge-Core Networks Corp. 2013 ARP Inspection based

    on ACL Use ACL to permit only certain IP and mac address of the default gateway Bind the ACL to vlan Check the ARP Inspection filter
  112. All Rights Reserved Edge-Core Networks Corp. 2013 Validate ARP Packet

    ARP Inspection supports the validation of arp packet based on Destination MAC, IP or source MAC IP validation supports allow-zeros for 0.0.0.0 sender address
  113. All Rights Reserved Edge-Core Networks Corp. 2013 Traffic Segmentation Traffic

    Segmentation provides segregation of traffic at Layer 2 for security Host in the same broadcast segment are unable to talk to each other and they are only able to access the ISP network
  114. All Rights Reserved Edge-Core Networks Corp. 2013 Traffic Segmentation Router

    Internet Notebook Traffic-segmentation downlink Ethernet 1/1-24 Traffic-segmentation uplink Ethernet 1/25-28
  115. All Rights Reserved Edge-Core Networks Corp. 2013 Traffic Segmentation Configure

    Traffic Segmentation Check Traffic-segmentation configuration
  116. All Rights Reserved Edge-Core Networks Corp. 2013 Traffic Segmentation Router

    Internet Data_Subscribers VLAN 3 Voice VLAN 2 Data VLAN 4 IPTV VLAN 2 Data VLAN 4 IPTV Isolated VLAN 2 downlink ports Triple Play_Subscribers Traffic segmentation Downlink Ethernet 1/1-24 Sw all vlan add 2,3,4 tagged Traffic Segmentation uplink Ethernet 1/25 Sw all vlan add 2,3,4 tagged PSTN IP-TV Server
  117. All Rights Reserved Edge-Core Networks Corp. 2013 Traffic Segmentation Create

    3 vlan for Data, VoIP and IPTV users Configure subscriber port for triple-play service or data service and uplink port Configure traffic-segmentation uplink and downlink port
  118. All Rights Reserved Edge-Core Networks Corp. 2013 Traffic Segmentation Check

    Traffic Segmentation configuration Supports 4 sessions for separate uplink and downlink port Traffic from uplink port pfdifferent session can configure to blocking of forwarding
  119. All Rights Reserved Edge-Core Networks Corp. 2013 Access Control List

    DSCP Preamble DEST SRC Type 0800 IP Header TCP/UDP Header DATA CRC Src Port Dest Port TOS IP Precedence TOS Preamble DEST SRC Type 0800 IP Header DATA CRC SIP DIP Preamble DEST MAC SRC MAC Type DATA CRC Preamble DEST SRC 8100 PID/VID Type DATA CRC MAC ACL IP Standard ACL IP Extended ACL
  120. All Rights Reserved Edge-Core Networks Corp. 2013 MAC ACL Create

    MAC ACL Permit or Deny any source MAC, host, mac address range, tagged, untagged packet Destination MAC, host, address range
  121. All Rights Reserved Edge-Core Networks Corp. 2013 IP Standard ACL

    Create IP Standard ACL Permit or Deny source IP host, any IP, IP network
  122. All Rights Reserved Edge-Core Networks Corp. 2013 IP Extended ACL

    Create IP Extended ACL Deny or permit specific protocol, tcp, udp, host, any, source ip/network Destination ip, host or any
  123. All Rights Reserved Edge-Core Networks Corp. 2013 IP Extended ACL

    Ip precedence, dscp, source-port, Destination-port
  124. All Rights Reserved Edge-Core Networks Corp. 2013 IPv6 Standard ACL

    Create IPv6 standard ACL, deny/permit ipv6 host, bind to ingress port
  125. All Rights Reserved Edge-Core Networks Corp. 2013 IPv6 Standard ACL

    Create IPv6 standard ACL, deny/permit ipv6 source network Deny/permit any ipv6 source address
  126. All Rights Reserved Edge-Core Networks Corp. 2013 IPv6 Extended ACL

    Create ipv6 extended ACL, permit/deny source host/network/any And destination network/any Dscp and next-header
  127. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Snooping Layer

    2 switches can use IGMP snooping to prevent the flooding of multicast traffic by dynamically configuring switch port so that multicast traffic is forwarded to only those ports associated with IP multicast receiver By implementing the IGMP snooping feature, it makes Layer 2 switch increase the performance of network for reducing multicast traffics flooding
  128. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Snooping Router

    Internet VLAN 1 IPTV Triple Play_Subscribers IP-TV Server VLAN 1 IPTV 224.1.1.1 224.1.1.2 224.1.1.3 224.1.1.4 SW1 192.168.1.1 AGG_1 192.168.1.2
  129. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Snooping IGMP

    Snooping can be enabled per vlan, by default IGMP Snooping is enable on VLAN1
  130. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Snooping mrouter

    port IGMP Snooping only start to work when there is a multicast router in the network, the port which connect to the multicast router and receive general query is mrouter port Mrouter port can be configured statically
  131. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Querier Configure

    the switch to act as querier if there is no multicast router in the network
  132. All Rights Reserved Edge-Core Networks Corp. 2013 Multicast Filtering Multicast

    Group dynamically learned to mrouter port or null port in order to prevent flooding of unregistered Multicast group traffic
  133. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Snooping- Multicast

    Filtering Multicast Group dynamically learned to mrouter port in order to prevent flooding of unregistered Multicast group traffic Unregistered multicast data can be changed to flooded
  134. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Snooping-Join Router

    Internet VLAN 1 IPTV Triple Play_Subscribers IP-TV Server VLAN 1 IPTV 224.1.1.1 224.1.1.2 224.1.1.3 224.1.1.4 SW1 192.168.1.1 AGG_1 192.168.1.2 Join Join Multicast Group Ports 01005E010101 1 Multicast Group Ports 01005E010101 25
  135. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Snooping-Join IGMP

    membership report Multicast registration table
  136. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Snooping-Leave Router

    Internet VLAN 1 IPTV Triple Play_Subscribers IP-TV Server VLAN 1 IPTV 224.1.1.1 224.1.1.2 224.1.1.3 224.1.1.4 SW1 192.168.1.1 AGG_1 192.168.1.2 Leave Leave GS-Q GS-Q Multicast Group Ports 01005E010101 Multicast Group Ports 01005E010101
  137. All Rights Reserved Edge-Core Networks Corp. 2013 Leave Leave, wait

    for 2 group specific query then remove from multicast table Immediate leave will remove the group without waiting GS- Query
  138. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Filtering Router

    Internet VLAN 1 IPTV Triple Play_Subscribers IP-TV Server VLAN 1 IPTV 224.1.1.1 224.1.1.2 224.1.1.3 224.1.1.4 224.1.1.1 224.1.1.2 224.1.1.3 Multicast Router 192.168.1.10 IGMP filtering IGMP profile 1 Permit Range 224.1.1.1 224.1.1.3
  139. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Filter Configuration

    Enable ip igmp filter Check ip igmp filter Create ip igmp profile Check ip igmp profile
  140. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Filter Configuration

    Apply igmp filter to port Check igmp filter interface
  141. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Filter Only

    multicast group match the profile are permitted, Join packet for Group 224.1.1.4 had been filtered
  142. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Throttling Router

    Internet IP IGMP max-group 2 IP-TV Server 224.1.1.1 224.1.1.2 224.1.1.3 224.1.1.4 224.1.1.1 224.1.1.2 Multicast Router 192.168.1.10
  143. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Throttle Configure

    IGMP Throttling Configure action exceed max-groups Check IGMP Throttle
  144. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Snooping Priority

    Router Internet IP IGMP snooping priority 6 IP-TV Server 224.1.1.1 224.1.1.2 224.1.1.3 224.1.1.4 Multicast Router 192.168.1.10 VLAN 2 Data VLAN 4 IPTV 6 vid 2,3,4 tagged 4 6 4
  145. All Rights Reserved Edge-Core Networks Corp. 2013 IGMP Snooping Priority

    Configure IGMP Snooping Priority Check priority
  146. All Rights Reserved Edge-Core Networks Corp. 2013 MVR Router Internet

    IP-TV Server Data IPTV Pvid=1 Vid=1,10,20 tagged Mvr source Pvid=10 Vid=10 untagged mvr receiver Pvid=1 Vid=1,10,20 tagged
  147. All Rights Reserved Edge-Core Networks Corp. 2013 MVR Configure port

    1 to vlan 10 Configure uplink port 25,26 to 10.20 tagged port Configure SW2 port 24 which connected to Video Server to multicast vlan 20 Configure port 25-26 to 10,20 tagged port
  148. All Rights Reserved Edge-Core Networks Corp. 2013 MVR Create MVR

    domain 1 Associate domain 1 to vlan 20 Create mvr profile 1 Configure receiver port and source port
  149. All Rights Reserved Edge-Core Networks Corp. 2013 Quality of Service

    • Offers a wide range of granular bandwidth and QoS options Strict Priority Queue Weighted Round-Robin (WRR) Queue SWRR Incoming packets Classify W1 W2 W5 W4 W3 W6 W7 W8 Outgoing packets Classification Queuing (8 hardware Queues) Scheduling Policing QoS-based traffic Management
  150. All Rights Reserved Edge-Core Networks Corp. 2013 Traffic Policing Router

    Internet VLAN 3 Voice VLAN 2 Data VLAN 4 IPTV Triple Play_Subscribers PSTN IP-TV Server 1Mbps Burst 4MBps Exceed drop
  151. All Rights Reserved Edge-Core Networks Corp. 2013 Traffic Policing Classify

    Data Traffic by VLAN Create Policy-map for Data Traffic, match data (vlan 2) traffic, set the permitted uploading data flow to1Mbps Check Class-map and Policy-map
  152. All Rights Reserved Edge-Core Networks Corp. 2013 Traffic Policing Check

    Class-map and Policy-map Check policy-map used by interface
  153. All Rights Reserved Edge-Core Networks Corp. 2013 Bandwidth Profile •

    Traffic can be classified per service with different bandwidth profile • Two rate: Committed Information Rate, Excess information rate • Three color: Green, Yellow, Red (Discard) C-Bucket “Green” Tokens E-Bucket “Yellow” Tokens Overflow Overflow Committed Information Rate Excess Information Rate Committed Burst Size Excess Burst Size
  154. All Rights Reserved Edge-Core Networks Corp. 2013 Bandwidth Profile •

    Three color – Green: deliver service frame with performance levels as per SLA for the CoS instance – Yellow: deliver service frame but performance levels as per SLA for the CoS instance does not apply – Red :Discard
  155. All Rights Reserved Edge-Core Networks Corp. 2013 Two Rate Three

    Color Mapping Classify VLAN 2 Data traffic and configure trTCM with Committed Information rate 5Mbps (Green), committed burst size 20MB, Excessive Information Rate 10Mbps (Yellow), Excessive burst size 40MB, exceed set DCSP to 3, violate set DSCP to 6 Check trTCM configuration
  156. All Rights Reserved Edge-Core Networks Corp. 2013 Configuration on switch

    Config the Radius/Tacacs+ server parameters Defines login authentication method/precedence
  157. All Rights Reserved Edge-Core Networks Corp. 2013 Configuration on FreeRadius

    Server /etc/freeradius/clients.conf /etc/freeradius/users
  158. All Rights Reserved Edge-Core Networks Corp. 2013 Authentication and authorization

    on Radius server Can’t use local account(admin/admin) login to switch, only can use the account on Radius server. User Access Verification Username: admin Password: Username: root Password: CLI session with the ECS4510-28F is opened. To end the CLI session, enter [Exit]. Console#show privilege Current privilege level is 15 Console# User Access Verification Username: user1 Password: CLI session with the ECS4510-28F is opened. To end the CLI session, enter [Exit]. Console>show privilege Current privilege level is 8 Console> User Access Verification Username: user2 Password: CLI session with the ECS4510-28F is opened. To end the CLI session, enter [Exit]. Console>show privilege Current privilege level is 3 Console> User Access Verification Username: user3 Password: CLI session with the ECS4510-28F is opened. To end the CLI session, enter [Exit]. Console>show privilege Current privilege level is 0 Console>
  159. All Rights Reserved Edge-Core Networks Corp. 2013 Authentication and authorization

    on Tacacs+ server If Radius server unreachable, then will use the account on Tacacs+ server. User Access Verification Username: root Password: Username: ecroot Password: CLI session with the ECS4510-28F is opened. To end the CLI session, enter [Exit]. Console#show privilege Current privilege level is 15 Console# User Access Verification Username: user11 Password: CLI session with the ECS4510-28F is opened. To end the CLI session, enter [Exit]. Console>show privilege Current privilege level is 11 Console> User Access Verification Username: user22 Password: CLI session with the ECS4510-28F is opened. To end the CLI session, enter [Exit]. Console>show privilege Current privilege level is 8 Console> User Access Verification Username: other Password: CLI session with the ECS4510-28F is opened. To end the CLI session, enter [Exit]. Console>show privilege Current privilege level is 0 Console>
  160. All Rights Reserved Edge-Core Networks Corp. 2013 Authentication and authorization

    on local Create the account on local switch Display all the user on switch and privilege level
  161. All Rights Reserved Edge-Core Networks Corp. 2013 Authentication and authorization

    on local Both Radius and Tacacs+ server are unavailable, we still can login with local account. User Access Verification Username: ecroot Password: Username: admin Password: CLI session with the ECS4510-28F is opened. To end the CLI session, enter [Exit]. Console#show privilege Current privilege level is 15 Console# User Access Verification Username: customer Password: CLI session with the ECS4510-28F is opened. To end the CLI session, enter [Exit]. Console>show privilege Current privilege level is 8 Console> User Access Verification Username: guest Password: CLI session with the ECS4510-28F is opened. To end the CLI session, enter [Exit]. Console>show privilege Current privilege level is 0 Console>
  162. All Rights Reserved Edge-Core Networks Corp. 2013 Solution for New

    Services Edge-Core introduce Carrier Ethernet services devices for business, wholesale and mobile backhaul Helps service providers on shortening deployment times, increasing operational efficiency and minimizing TCO (total cost of ownership) to ensure profitable service delivery Providing service provider a comprehensive set of tools to help them provision, monitor and control E-Line, E- Tree and E-LAN services more efficiently Optimize network operations and meet customer service expectations, provides substantial cost reductions and revenue gains
  163. All Rights Reserved Edge-Core Networks Corp. 2013 Branch HQ QinQ

    VPN service between branches and headquarter SW 2 192.168.1.2 Vlan 1 SW 3 192.168.1.3 Vlan 1 26 9 SW 1 192.168.1.1 Vlan 1 SW 4 192.168.1.4 Vlan 1 25 10 25 26 8 1 90E6BA472080 PC1 (Branch Client) 192.168.1.112 206A8A15A241 HQ Server 192.168.1.200 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6
  164. All Rights Reserved Edge-Core Networks Corp. 2013 QinQ Configuration Enable

    QinQ globally Configure QinQ uplink port Configure QinQ access port
  165. All Rights Reserved Edge-Core Networks Corp. 2013 QinQ Configuration Checking

    Check QinQ configuration QinQ configuration checking by interface
  166. All Rights Reserved Edge-Core Networks Corp. 2013 QinQ—Untagged Packet Untagged

    packets received from QinQ access port will be tagged with svid 800, MAC Address showed learn to vlan 800 QinQ packet captured from uplink port of SW1
  167. All Rights Reserved Edge-Core Networks Corp. 2013 Branch HQ QinQ

    –Tagged Packet 1 SW 2 192.168.1.2 Vlan 1 SW 3 192.168.1.3 Vlan 1 26 9 SW 1 192.168.1.1 Vlan 1 SW 4 192.168.1.4 Vlan 1 25 10 25 26 8 1 90E6BA472080 PC1 (Branch Client) 192.168.1.112 206A8A15A241 HQ Server 192.168.1.200 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 111 111
  168. All Rights Reserved Edge-Core Networks Corp. 2013 QinQ—Tagged Packet 1

    Configure SW2 port 8 and SW3 port 1 to vlan 111, uplink port to 111 tagged QinQ packet svid 800, cvid 111 captured from uplink port of SW1
  169. All Rights Reserved Edge-Core Networks Corp. 2013 Branch HQ QinQ—Tagged

    Packet 2 SW 2 192.168.1.2 Vlan 1 SW 3 192.168.1.3 Vlan 1 26 9 SW 1 192.168.1.1 Vlan 1 SW 4 192.168.1.4 Vlan 1 25 10 25 26 8 1 90E6BA472080 PC1 (Branch Client) 192.168.1.112 206A8A15A241 HQ Server 192.168.1.200 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 222 222
  170. All Rights Reserved Edge-Core Networks Corp. 2013 QinQ Tagged Packet

    2 Configure SW2 port 8 and SW3 port 1 to vlan 222, uplink port to 222 tagged QinQ packet svid 800, cvid 222 captured from uplink port of SW1
  171. All Rights Reserved Edge-Core Networks Corp. 2013 Branch HQ Selective

    QinQ SW 2 192.168.1.2 Vlan 1 SW 3 192.168.1.3 Vlan 1 26 9 SW 1 192.168.1.1 Vlan 1 SW 4 192.168.1.4 Vlan 1 25 10 25 26 8 1 90E6BA472080 PC1 (Branch Client) 192.168.1.112 206A8A15A241 HQ Server 192.168.1.200 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 222 222 111 111
  172. All Rights Reserved Edge-Core Networks Corp. 2013 IEEE 802.3ah OAM

    IEEE 802.3ah OAM provides tools for link monitoring, remote failure indication, and remote loopback on a link
  173. All Rights Reserved Edge-Core Networks Corp. 2013 Connectivity Fault Management

    IEEE 802.1ag Connectivity Fault Management which provides tools for service level OAM and detecting, isolating and reporting connectivity faults in a provider network
  174. All Rights Reserved Edge-Core Networks Corp. 2013 CFM SW 2

    192.168.1.2 Vlan 10 SW 23 192.168.1.3 Vlan 10 26 9 SW 1 192.168.1.1 Vlan 10 SW 4 192.168.1.4 Vlan 10 25 10 9 10 25 East West 26 West East West RPL Owner East 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 East West East 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 MEP 21 MEP 12 MEP 14 MEP 23
  175. All Rights Reserved Edge-Core Networks Corp. 2013 CFM Configuration on

    SW1 Create CFM domain and assign the level Create Maintenance associate and mapping to vlan Define the remote MEP ID for crosscheck Create Maintenance End Point 12 and 14 on port 25 and 26
  176. All Rights Reserved Edge-Core Networks Corp. 2013 CFM Configuration on

    SW2 Create CFM domain and assign the level on SW2 Create Maintenance associate and mapping to vlan Define the remote MEP ID for crosscheck Create Maintenance End Point 21 and 23 on port 25 and 26
  177. All Rights Reserved Edge-Core Networks Corp. 2013 CFM Configuration Check

    Check remote cross check MEP statis Check remote cross check MEP 21 detail information
  178. All Rights Reserved Edge-Core Networks Corp. 2013 CFM Configuration Check

    Check remote cross check MEP 23 detail information
  179. All Rights Reserved Edge-Core Networks Corp. 2013 Linktrace Linktrace the

    MEP on SW2 which connect directly to SW1 Linktrace the MEP on SW2 which connect directly to SW1
  180. All Rights Reserved Edge-Core Networks Corp. 2013 Maintenance Intermediate Point

    Configure CFM on SW3 and SW4 MIP automatically created
  181. All Rights Reserved Edge-Core Networks Corp. 2013 CFM-Link Trace SW

    2 192.168.1.2 Vlan 10 SW 3 192.168.1.3 Vlan 10 26 9 SW 1 192.168.1.1 Vlan 10 SW 4 192.168.1.4 Vlan 10 25 10 9 10 25 26 RPL Owner 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 East RAPS-SF 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 MEP 21 MEP 12 MEP 14 MEP 23 MIP MIP MIP MIP 0012CFF3DF8F 0012CFF3DF90 0012CFF3DEC0 0012CFF3DEBF 7072CF78A033 7072CF78A032
  182. All Rights Reserved Edge-Core Networks Corp. 2013 CFM-Loopback SW 2

    192.168.1.2 Vlan 10 SW 3 192.168.1.3 Vlan 10 26 9 SW 1 192.168.1.1 Vlan 10 SW 4 192.168.1.4 Vlan 10 25 10 9 10 25 RPL Owner 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 East RAPS-SF 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 MEP 21 MEP 12 MEP 14 MEP 23 MIP MIP MIP MIP 0012CFF3DF90 0012CFF3DEBF 7072CF78A032 0012CFF3DEC0 0012CFF3DF8F 7072CF78A033 26
  183. All Rights Reserved Edge-Core Networks Corp. 2013 Y.1731 Delay &

    Delay Variation ITU-T Y.1731 which covers connectivity management and also provides tools to measure performance parameters for a service such as frame delay and frame delay variation
  184. All Rights Reserved Edge-Core Networks Corp. 2013 Y.1731 Delay &

    Delay Variation SW 2 192.168.1.2 Vlan 10 SW 3 192.168.1.3 Vlan 10 26 9 SW 1 192.168.1.1 Vlan 10 SW 4 192.168.1.4 Vlan 10 25 10 9 10 25 East 26 RPL Owner 24 1 90E6BA472080 PC1 (VLC Client) 192.168.1.112 206A8A15A241 VLC Server 192.168.1.200 East 7072CF75BC86 7072CF78A019 0012CFF3DF86 0012CFF3DEB6 MEP 21 MEP 12 MEP 14 MEP 23
  185. All Rights Reserved Edge-Core Networks Corp. 2013 Y.1731 Delay &

    Delay Variation Delay measure the MEP 23 Delay measure the MEP 23