Вы находитесь на странице: 1из 182

.466534.

012-324

. ______
: 403530 _____________________

: .466534.012-324


NETXPERT

L3

NetXpert NX-5124-G10

NetXpert NX-5124-G10F


. .
. .

. .
2

.466534.012-324
.
.
.

. . . . . .
.466534.012-324

.466534.012-324 -
NX-5124-G10 (NX-5124-G10F) -
.
:
.466534.012-324 ;
.466534.012-324 .


. .
. .

.466534.012-324
. . .
. . .
. .

. . NX-5124G-10 3 182
NX-5124G-10F
.. .

. .

1 .................................................................................................................................. 9
1.1 ............................................................................................................................. 9
1.2 ....................................................................................................................... 9
1.3 ........................................................................................................................................ 9
1.4 ..................................................................................................................................... 9
1.5 ............................................................................................................................................. 10
1.6 .................................................................................................................................. 10
2 ......................................................................................................................................... 11
2.1 ................................................................................................................. 11
2.1.1 ................................................................................... 11
2.1.2 ..................................................................................... 13
2.1.3 HTTP............................................................................................................................. 14
2.2 .................................................................................................................................. 15
2.2.1 VTY. ................................................................................................................... 15
2.2.2 ........................................................................................................................... 15
2.2.3 ......................................................................................................... 15
2.2.4 VTY.................................................................................................................. 15
2.3 ...................................................................................................................... 15
2.3.1 SNMP............................................................................................................................ 15
2.3.2 RMON ........................................................................................................................... 19
2.4 SSH ............................................................................................................................. 21
2.4.1 SSH...................................................................................................................................... 21
2.4.2 ........................................................................................................................... 22
2.4.3 Ssh.................................................................................................... 22
3 .................................................................................................................................. 23
3.1 ............................................................................................................................................................ 23
3.1.1 ........................................................................................... 23
3.1.2 .............................................................................................. 23
3.2 ................................................................................................................................ 24
3.2.1 ........................................................................................ 24
3.2.2 .................................................................................... 24
3.2.3 ............................................................................... 25
3.3 .................................................................................................................. 27


3.3.1 ........................................................................................ 27
4 ...................................................................................................... 28
4.1 ............................................................................................................................................................ 28
4.1.1 ........................................................................................... 28
4.1.2 .............................................................................................. 28
4.2 ................................................................................................................................ 29
4.2.1 Ethernet ................................................................................................... 29
5 ................................................................................ 31

. .
5.1 .................................................................................................................. 31
5.1.1 Ethernet ................................................................................................... 31
5.2 ................................................................................................................... 31
5.2.1 .............................................................................................................................................. 31
5.2.2 ................................................................... 32
5.2.3 ............................................................................... 32
5.3 .................................................................................................................. 33
. .

5.3.1 .................................................................................................... 33
6 ........................................................................................................... 34
6.1 ................................................................................................. 34
6.1.1 ....................................................................................... 34
6.1.2 ........................................................................ 34
7 ............................................................................................................ 35
7.1 ................................................................................. 35

7.2 ............................................................................................. 35
7.2.1 ................................................................................................ 35
7.2.2 .................................................................. 35
8 VLAN.................................................................................................................................................. 36
8.1 VLAN .................................................................................................................................................. 36
8.2 VLAN ............................................................................................................. 36
8.3 VLAN ....................................................................................................................... 36
. .

4
.466534.012-324
. . .
8.3.1 / VLAN ......................................................................................................... 36
8.3.2 ...................................................................................... 36
8.3.3 / VLAN ........................................................................................ 37
8.3.4 Super-VLAN ............................................................................................. 37
8.3.5 VLAN .......................................................................................... 38
8.4 ........................................................................................................................................ 38
9 STP .................................................................................................................................................... 39
9.1 (STP) ....................................................................................... 39
9.1.1 STP. ...............................................................................................................................39
9.1.2 STP .......................................................... 39
9.1.3 RSTP...................................................................................................... 39
9.1.4 SSTP ................................................................................................................ 40
9.1.5 vLAN............................................................................................ 41
9.1.6 RSTP...................................................................................................... 42
9.1.7 RSTP ................................................................................................................ 42
9.2 MSTP .......................................................................................................................................... 44
9.2.1 MSTP ................................................................................................................................... 44
9.2.2 MSTP ..................................................................................................... 49
9.2.3 MSTP................................................................................................................ 50
10 STP ................................................................................ 56
10.1 STP ....................................................................................... 56
10.1.1 STP. ....................................................................... 56
10.1.2 STP ......................................................................... 59
11 MAC- .............................................................................................................. 63
11.1 MAC- ........................................................................................................ 63
11.2 MAC-................................................................................................................... 63
11.2.1 Mac- ............................................................................................ 63
11.2.2 MAC-.................................................................................. 63
11.2.3 - VLAN....................................................................................................... 63
11.2.4 MAC-........................................................................................... 63
11.2.5 MAC- ........................................................................................ 64
12 ......................................................................................................................... 65
12.1 ............................................................................................................................................................ 65
12.2 ........................................................................................... 65

12.3 ............................................................................................................. 65
12.3.1 , ........................................... 65
12.3.2 ....................................................................................................... 65
12.3.3 ............................................................ 66
12.3.4 ....................................................................................................... 66
13 GVRP ................................................................................................................................................. 67
13.1 ............................................................................................................................................................ 67
13.2 .............................................................................................................................. 67
. .

13.2.1 GVPR ..................................................................................................... 67


13.3 GVPR.............................................................................................................................. 67
13.3.1 / GVPR ......................................................................................... 67
13.3.2 / GVPR ....................................................................................... 67
13.3.3 GVRP.............................................................................................. 67
13.4 ........................................................................................................................................ 67
14 IGMP-SNOOPING ............................................................................................................................. 69
. .

14.1 IGMP-snooping ............................................................................................................... 69


14.1.1 / IGMP-snooping VALN ........................................................................ 69
14.1.2 / VLAN................................................... 69
14.1.3 VLAN ................................................................... 69
14.1.4 ............ 70
14.1.5 IGMP-snooping ................................................. 70
14.1.6 IGMP-snooping ................................................................... 70
14.1.7 IGMP-snooping ........................................................................................................... 70

14.1.8 IGMP-snooping ............................................................................... 71


14.1.9 IGMP-snooping ................................................................................................ 72
15 802.1................................................................................................................................................ 73
15.1 802.1 .................................................................................................................. 73
15.2 802.1 .............................................................................................................................. 73
15.2.1 802.1.................................................................................... 73
15.2.2 802.1 .............................................................. 73
. .


.466534.012-324 5
. . .
15.2.3 802.1.................................. 74
15.2.4 802.1............................................................................ 74
15.2.5 802.1 ........................................................................................... 74
15.2.6 802.1................................................................................. 74
15.2.7 802.1....................................................................... 74
15.2.8 802.1 ........................................................................... 74
15.2.9 802.1............................................................................................... 75
15.2.10 VLAN 802.1................................................................................................. 75
15.2.11 ........................................................... 75
15.2.12 802.1 ........................................................................ 76
15.2.13 802.1 ......................................................... 76
15.3 802.1x ............................................................................................................................ 76
16 -............................................................................................... 77
16.1 - ........................................................................................ 77
16.1.1 MAC- ...................................................................................... 77
16.1.2 -....................................................................... 77
16.1.3 -.................................................................................. 77
17 IP- .......................................................... 78
17.1 IP- ....................................................................... 78
17.1.1 IP .................................................................................................................. 78
17.1.2 IP-........................................ 78
17.1.3 IP- ....................................................................... 78
17.1.4 ........................................................................................ 79
18 ................................................................................................................ 80
18.1 IP-.............................................................................................................................. 80
18.1.1 .............................................................................................................................................. 80
18.1.2 IP-............................................................................................... 81
18.1.3 IP-................................................................................................................ 81
18.1.4 IP- .................................................................................................................... 84
18.2 NAT ...................................................................................................................................... 84
18.2.1 .............................................................................................................................................. 84
18.2.2 NAT ........................................................................................................ 86
18.2.3 NAT .................................................................................................................. 86
18.2.4 NAT ............................................................................................................... 91
18.3 DHCP .......................................................................................................................................... 93


18.3.1 .............................................................................................................................................. 93
18.3.2 DHCP- ............................................................................................................. 93
18.3.3 DHCP- ............................................................................................................. 94
18.4 IP ................................................................................................................................ 96
18.4.1 IP- .................................................................................................................... 96
18.4.2 ......................................................................................................... 100
18.4.3 IP- ....................................................... 101
19 ........................................................................................................................ 104

. .
19.1 RIP ............................................................................................................................................ 104
19.1.1 ............................................................................................................................................ 104
19.1.2 RIP ..................................................................................................... 104
19.1.3 RIP.................................................................................................................. 104
19.2 BEIGRP..................................................................................................................................... 108
19.2.1 ............................................................................................................................................ 108
19.2.2 BEIGRP................................................................................................ 108
. .

19.2.3 BEIGRP .......................................................................................................... 108


19.2.4 BEIGRP ......................................................................................................... 111
19.3 OSPF ........................................................................................................................................ 111
19.3.1 ............................................................................................................................................ 111
19.3.2 OSPF ................................................................................................... 112
19.3.3 OSPF.............................................................................................................. 112
19.3.4 OSPF .......................................................................................................... 115
19.4 BGP........................................................................................................................................... 119

19.4.1 ............................................................................................................................................ 119


19.4.2 BGP ................................................................................................................ 120
19.4.3 BGP .................................................................................................... 126
19.4.4 BGP............................................................................................................. 127
20 VRRP ....................................................................................................................................... 133
20.1 .......................................................................................................................................................... 133
20.2 VRRP ................................................................................................................. 133
20.3 VRRP............................................................................................................................ 133
. .

6
.466534.012-324
. . .
20.3.1 / VRRP ................................................................................... 133
20.3.2 VRRP.............................................................................................. 133
20.3.3 VRRP............................................................................. 133
20.3.4 VRRP ...................................................................................................... 134
20.3.5 VRRP ........................................................................... 134
20.3.6 VRRP ............................................................................................ 134
20.3.7 VRRP .......................................................................................................... 134
21 IP MULTICAST ................................................................................................................................ 136
21.1 ..................................................................................... 136
21.1.1 ............................................................................. 136
21.1.2 .......................................................... 136
21.2 ........................................................................ 137
21.2.1 IP .......................................................................... 137
21.2.2 .......................................................................... 137
21.2.3 TTL.................................................................................................................. 138
21.2.4 .............................................. 138
21.2.5 ............................................. 138
21.2.6 IP Multicast................................................................................................... 139
21.2.7 IP Multicast............................................................................... 139
21.2.8 IP Multicast Helper ...................................................................................................... 139
21.2.9 ........................................................................ 140
21.2.10 ......................................................... 141
21.3 IGMP ......................................................................................................................................... 141
21.3.1 ......................................................................................................................... 141
21.3.2 IGMP ........................................................................................................................... 141
21.3.3 IGMP ( VLAN)................................. 144
21.4 PIM-DM ..................................................................................................................................... 145
21.4.1 PIM-DM ....................................................................................... 145
21.4.2 PIM-DM ....................................................................................................................... 146
21.4.3 PIM-DM................................................................... 147
21.5 PIM-SM ..................................................................................................................................... 147
21.5.1 PIM-SM........................................................................................ 147
21.5.2 PIM-SM ....................................................................................................................... 148
21.5.3 ..................................................................................................................... 149
22 QOS ................................................................................................................................................. 151

22.1 .......................................................................................................................................................... 151


22.1.1 QoS ............................................................................................................................ 151
22.1.2 P2P QoS.......................................................................................................................... 151
22.1.3 QoS .......................................................................................... 151
22.2 QoS .................................................................................................................... 152
22.3 QoS............................................................................................................................... 152
22.3.1 oS ......................................................................... 152
22.3.2 CoS .................................... 152
22.3.3 CoS .................................................. 153
. .

22.3.4 CoS .......................................................................... 153


22.3.5 QoS ........................................................................................ 153
22.3.6 QoS .................................................................... 154
22.3.7 QoS ........................................................ 154
22.3.8 QoS................................. 154
22.3.9 QoS ......................................................................................... 155
22.3.10 QoS ....................................................................................... 155
. .

22.4 QoS ...........................................................................................................................155


22.4.1 QoS Strategy ............................................................. 155
23 (LAYER 2) ........................................... 156
23.1 .......................................................................................................................................................... 156
23.2 (Layer 2) ........................................................... 156
23.3 (Layer 2) .............................................. 156
24 IP ................................................ 157

24.1 IP .................................................................... 157


24.1.1 IP .................................................. 157
24.1.2 IP ................................................................... 157
24.1.3 IP .................................................. 157
24.2 ............................................................................................................................. 157
25 ......................................................................................................................... 159
25.1 .......................................................................................................................................................... 159
. .


.466534.012-324 7
. . .
25.2 .................................................................................................. 159
25.3 ......................................................................................................................... 159
25.3.1 ................................................................................. 159
25.3.2 ............................................................................................. 159
25.3.3 ......................................................................................................... 159
25.3.4 ....................................................................... 159
25.4 ........................................................................................................... 159
26 ........................................................................................................................... 161
26.1 AAA ........................................................................................................................................... 161
26.1.1 AAA .................................................................................................................................... 161
26.1.2 AAA .............................................................................................................. 162
26.1.3 AAA.......................................................................... 163
26.1.4 AAA.................................................................................... 163
26.1.5 AAA ................................................................................... 166
26.1.6 AAA ................................................................................ 166
26.1.7 AAA .......................................................................................... 166
26.1.8 AAA ......................................................................................................... 167
26.1.9 AAA ................................................................................. 168
26.1.10 AAA ............................................................................................ 168
26.2 RADIUS..................................................................................................................................... 169
26.2.1 ...................................................................................................................................... 169
26.2.2 RADIUS................................................................................................ 170
26.2.3 RADIUS................................................................................................ 170
26.2.4 RADIUS .......................................................................................................... 170
26.2.5 RADIUS....................................................................................................... 171
26.3 - ............................................................................................................... 172
26.3.1 ............................................................................................................................................ 172
26.3.2 ................................................................................ 174
26.3.3 - ................................................................... 175
26.3.4 ................................................................ 176
27 ......................................................................................................... 178
27.1 .......................................................................................................................................................... 178
27.2 ..................................................................................... 178
27.3 ................................................................................................ 178
27.3.1 .............................................................................................................. 178
27.3.2 ...................................................................................................................... 178


27.3.3 ..................................................................................................................... 179
27.3.4 .................................................................................. 179
27.3.5 SNMP ................................................................... 179
27.3.6 Web ...................................................................... 179
28 PBR.................................................................................................................................................. 180
28.1 PBR.................................................................................................................................................. 180
28.2 PBR .................................................................................................................... 180
28.3 PBR .............................................................................................................................. 180

. .
28.3.1 ............................................................................................................ 180
28.3.2 ........................................................................................................ 180
28.3.3 PBR ............................................................................................... 180
28.3.4 PBR............................................................................................................................ 180
28.4 PBR........................................................................................................................... 180
........................................................................................................................... 182
. .

. .

8
.466534.012-324
. . .
1
,
, .. ,
.





1.1
0.
, 1.
<type><slot>/<port>; -
:

10M Ethernet Ethernet E
100M FastEthernet Ethernet F
1000M Ethernet Ethernet G
, 1.
, 1.
: .

1.2
:
, .
.
IP- IP.

1.3
(?) :
,
.
Switch> ?
( ),
. .

, ( ).
Switch> s?
,
.
Switch> show?
,
. , -
. .

. -
, .

1.4
.
. ,

, . -
(?).
:

System Supervision Mode ( Ctrl-p
monitor# quit
)
. .


.466534.012-324 9
. . .
User Mode ( ) Switch> exit quit
input
Administration Mode (
enable Switch# exit quit
)

exit quit
config
Global Configuraton Mode ( Ctrl-Z , -
Switch_config#
) -

inter- exit quit
Interface Configuration Mode
face Ctrl-Z , -
( Switch_config_f0/1#
, , in- -
)
terface f0/1 .

. -
, (?) .

.

:
Switch> enter
Password: <enter password>
Switch# config
Switch_config# interface f0/1
Switch_config
_f0/1# quit
Switch_config# quit
Switch#

1.5
, no -
.
, no ip routing


1.6
-
, . -
write.

. .
. .

. .

10
.466534.012-324
. . .
2
2.1
2.1.1
2.1.1.1
- 20 .

2.1.1.2
, . -
. [ ] .

Format .
. [ ]
, .
dir [filename] :
Index number Filename <FILE> Size of the file Establishment time (
<FILE> )
delete filename . , .
md directory .
. , -
rd dirname
.
.
more filename
, .
cd .
pwd .

2.1.1.3
monitor#boot flash <local_filename>
-,
.



local_filename , -

: monitor#boot flash switch.bin

2.1.1.4
. .

-

( ).

1. TFTP
monitor#copy tftp flash [ip_addr]
. .

tftp -.
.


IP- Tftp. , IP- -
ip_addr
copy

main.bin switch.bin.
monitor#copy tftp flash
: Source file name[]?main.bin
: Remote-server ip address[]?192.168.20.1
: Destination file name[main.bin]?switch.bin
please wait ...
. .


.466534.012-324 11
. . .
######################################################################
######################################################################
######################################################################
######################################################################
######################################################################
#############################################
TFTP:successfully receive 3377 blocks ,1728902 bytes
monitor#
2. zmodem
download . download ? -
.
monitor#download c0 <local_filename>
- -
zmodem. .


local_filename , -.


Hyper Terminal WINDOWS 95, NT 4.0 -
WINDOWS 3.X.
monitor#download c0 switch.bin
: speed[9600]?115200
115200 send file
Send - ( ). send file:


2.1-1 Send
main.bin, -
, , Zmodem. Send -
.
:
ZMODEM: successfully receive 36 blocks, 18370 bytes
, .

. .
- 9600.
:
NX-5124G 10 zmodem -
, 38400.

2.1.1.5
. .

startup-config. -
, , .
1. TFTP
monitor#copy tftp flash startup-config
2. zmodem
monitor#download c0 startup-config

2.1.1.6 ftp
config #copy ftp flash [ip_addr|option]
ftp -
. copy ftp .
-
ftp. .
. .

12
.466534.012-324
. . .
copy{ftp:[[[//login-name:[login-password]@]location]/directory]/filename}|flash:
filename>}{flash<:filename>|ftp:[[[//login-name:[login-password]@]location]
/directory]/filename}<blksize><mode><type>


Login-nam FTP . ,
copy.
login-password ftp ,
copy.
nchecksize .
Vrf vrf , MPLS.
blksize ( 512)
ip_addr IP- ftp. ,
copy.
Active ftp .
passive ftp .


"main.bin", "switch.bin"
.
config#copy ftp flash
: ftp user name [anonymous]? login-nam
: ftp user password [anonymous]? login-password
: Source file name []? main. bin
: Remote-server ip address []? 192.168.20.1
: Destination file name [main. bin]? switch. bin or
config#copy ftp://login-nam:login-password@192.168.20.1/main.bin flash:switch.bin
######################################################################
######################################################################
FTP:successfully receive 3377 blocks, 1728902 bytes
config#
:
ftp - tcp (75 ), -

ip tcp synwait-time tcp.


.
FTP, FTP,
. 512 ,
.

2.1.2
. .

2.1.2.1 IP- Ethernet


monitor#ip address <ip_addr> <net_mask>
IP- Ethernet,
192.168.0.1 - 255 255 255.0.


. .

ip_addr IP- Ethernet


net_mask Ethernet

:
monitor#ip address 192.168.1.1 255.255.255.0

2.1.2.2

monitor#ip route default <ip_addr>


.


ip_addr IP-


. .


.466534.012-324 13
. . .
monitor#ip route default 192.168.1.1

2.1.2.3 PING
monitor#ping <ip_address>
.


ip_address IP-


monitor#ping 192.168.20.100
PING 192.168.20.100:56 data bytes
64 bytes from 192.168.20.100:icmp_seq=0. time=0. ms
64 bytes from 192.168.20.100:icmp_seq=1. time=0. m
64 bytes from 192.168.20.100:icmp_seq=2. time=0. ms
64 bytes from 192.168.20.100:icmp_seq=3. time=0. ms
----192.168.20.100 PING Statistics----
4 packets transmitted, 4 packets received, 0% packet loss
round-trip (ms) min/avg/max = 0/0/0

2.1.3 HTTP
2.1.3.1 HTTP
http
http
http
http
1. http
: http .
http:

Ip http server http

2. http


: http - 80.

http:

Ip http port number http

3. http
Http enables .

. .
http.
http:

Enable password {0|7} line enable.

4. http
http, -
. .

http :

http access-class STRING http

2.1.3.2 http
(80) http.

192.168.20.0/24.
ip :
p access-list standard http-acl
permit 192.168.20.0 255.255.255.0
:
ip http access-class http-acl
ip http server
. .

14
.466534.012-324
. . .
2.2
2.2.1 VTY.
line; -
. line
, .

2.2.2
: (console), (AUX), -
(asynchronous) (virtual terminal).
. -
.

CON(CTY) - 0.
Telnet, X.25 PAD, HTTP
VTY Rlogin (, - 1 32.
Ethernet ).

2.2.2.1
VTY
.
VTY, .
.
, Telnet (Ethernet -
).
VTY :
(1).
(2). .
VTY
VTY".

2.2.3

show line VTY.

2.2.4 VTY
VTY
more.
config#line vty 0 32
config_line#length 0
. .

2.3
2.3.1 SNMP
2.3.1.1
SNMP , :
SNMP (NMS)
. .

SNMP (AGENT)
(Management Information Base - MIB)
, SNMP -
SNMP .
SNMP (NMS), CiscoWorks.
MIB . SNMP , -
.
SNMP MIB, SNMP .

SNMP
. (MIB),
. -
. SNMP , -
. -
, , ( ), TCP, -
.
. .


.466534.012-324 15
. . .
1. SNMP
SNMP ( ) -
SNMP . , ,
SNMP .
SNMP . -
, , ,
, . , SNMP -
, , PDU, . -
, . ,
, . , -
.
,
. , ,
.
, .
. ,
. , SNMP
, . -
, -
.

.
2. SNMP
SNMP:
SNMPv1 - , ,
RFC1157.
SNMPv2C - SNMPv2, -, -
RFC1901.
(Layer 3) SNMP:
SNMPv3 - , 3, RFC3410.
SNMPv1 . (community) ,
MIB , IP- .
SNMPv3 -
; SNMPv3 :
, .


, .
-
.
SNMPv3 .
, ( ), -
.
. SNMPv3 , :
, , . -
MD5 SHA ( ) -

. .
MD5 SHA -
. DES
. -,
.
. , -
.
SNMP SNMP, -
. .

. -
.
3. MIB
SNMP MIBII ( RFC 1213)
SNMP ( RFC 1215).
MIB .

2.3.1.2 SNMP
SNMP :
SNMP
SNMP

SNMP
. .

16
.466534.012-324
. . .
SNMP
SNMP
SNMPv3
SNMPv3
SNMPv3 Engine ID
1. SNMP
SNMP MIB (
). SNMP:

OID MIB name
snmp-server view name oid] SNMP
[exclude | include] SNMP. Exclude , ; include ,
.

, SNMP MIB -
.
.
SNMP, SNMP
SNMP.
2. SNMP
SNMP -
SNMP . , -
. , -
:

IP- SNMP.
MIB MIB, -
.
MIB.
, -
:

snmp-server community string [view

view-name] [ro | rw] [word] SNMP

. -
, no snmp-server community.
, SNMP.
3.
SysContact sysLocation MIB,
.
. .

.
:

snmp-server contact text
snmp-server location text
. .

4. SNMP
SNMP ,
. :

snmp-server packetsize byte-count

5. SNMP

SNMP, -
,
.

show snmp SNMP

6. SNMP
. .


.466534.012-324 17
. . .
SNMP ( -
):
SNMP
,
:

snmp-server host host community-
SNMP
string [trap-type]
snmp-server host host , , ..
[traps|informs]{version {v1 | v2c | : SNMPv3
v3 {auth | noauth | priv } }}commu- eybrfkmysq SNMP ,
nity-string [trap-type] .
SNMP
. snmp-server host , -
.
. ,
snmp trap link-status, ,
SNMP . -no snmp trap link-stat -
.
, snmp-server host.

, .
.

:

snmp-server trap-source interface , .
IP- .
snmp-server queue-length length .
- 10.
snmp-server trap-timeout seconds .
- 30 .


7. SNMP
,
SNMP.

snmp source-addr ipaddress SNMP

8. SNMPv3 SNMP:

. .

snmp-server group [groupname {v1 | v2c
|v3 [auth | noauth | priv]}][read read- SNMPv3.
view][write writeview] [notify notify-
view] [access access-list]

9. SNMPv3
. .

. -
, , -
. ,
; , .

snmp-server user username groupname {v1
| v2c | v3 [encrypted] [auth {md5 | sha} SNMPv3

auth-password ]} [access access-list]

. -
-
; . -

; , .
. .

18
.466534.012-324
. . .

SNMPv3.
snmp-server user username groupname re-
mote ip-address [udp-port port] {v1 | :
v2c | v3 [encrypted] [auth {md5 | sha}
auth-password ]} [access access-list] SNMP IP-
.

10. SNMPv3 (Engine ID)


SNMP engine ID SNMP.
SNMP SNMP SNMPv3.

snmp-server engineID remote ip-address
[udp-port port-number] engineid-string SNMP

2.3.1.3
1. 1:
snmp-server community public RO
snmp-server community private RW
snmp-server host 192.168.10.2 public
public -
MIB private MIB.
public private MIB private
MIB . , public -
192.168.20.2. ,
down, link down 192.168.20.2.
2. 2:
snmp-server engineID remote 90.0.0.3 80000523015a000003
snmp-server group getter v3 auth
snmp-server group setter v3 priv write v-write
snmp-server user get-user getter v3 auth sha 12345678
snmp-server user set-user setter v3 encrypted auth md5 12345678
snmp-server user notifier getter remote 90.0.0.3 v3 auth md5 abcdefghi
snmp-server host 90.0.0.3 informs version v3 auth notifier
snmp-server view v-write internet included

SNMPv3 . getter
, setter .
get-user getter,
sha 12345678. set-user
setter,
md5 12345678.
notifier inform
90.0.0.3.
. .

2.3.2 RMON
2.3.2.1 RMON
RMON :
RMON
RMON
. .

RMON
RMON
RMON
1. RMON
rMon
SNMP NMS. SNMP -
. rMon .

rMon :

Configure
rmon alarm index variable in- rMon.
terval {absolute | delta} ris-
ing-threshold value [eventnum- index . 1
ber] falling-threshold value 65535.
. .


.466534.012-324 19
. . .
[eventnumber] [owner string] variable MIB,
MIB INTEGER, Counter Gauge
Time Ticks.
interval -
. 1 4294967295.
absolute -
MIB; delta -
MIB .
value ,
. event
number , -
. event number -
.
owner string -
.
exit .
write .

rMon OID, vari-


able interval (absolute
delta). , , -
rising-threshold , , event number (
event number 0 , , -
) . OID , invalid. rmon
alarm
. no rmon alarm index
, index.
2. RMON
rMon :

1. configure
rMon.
Index . 1 65535.
rmon event index [de- Description .


scription string] log -
2. [log] [owner string] .
[trap community] trap , -
. community .
owner string .
3. exit .
4. write .

. .
rMon, eventLastTimeSent field -
sysUpTime rMon. log ,
log. trap , trap
community. rmon event -
. -
no rmon event index , in-
dex.
. .

3. RMON
rMon -
. rMon :

1. configure

2. interface if type ifid Iftype .


Ifid .
rmon .
rmon collection stat index [owner
3. string] Index .
owner string .
4. exit .
. .

20
.466534.012-324
. . .
5. exit .
6. write .

rmon eventcollection stat -


.
no rmon collection stats index , index.
4. RMON
rMon
. rMon :

1. configure

2. interface if type ifid Iftype .
Ifid .
.
Index .
, -
bucket-number. -
Rmon collection history index [buck-
ets bucket-number] [interval second] Ethernet -
3.
[owner owner-name] ; : 50 .
second -
;
: 1800 ( )
owner string .
4. exit .
5. exit .
6. write

,
, second. -
. rmon eventcollection stat -
-
. no rmon collection stats index
, index. , bucket-number

interval second , -
.
5. RMON
show RMON.

rmon.
Alarm .
Event ,
. .

show rmon [alarm] [event] [sta- log, .


tistics] [history] Static
, .
History
, .
. .

2.4 SSH
2.4.1 SSH
2.4.1.1 SH
SSH ,
, SSH . , -
telnet. SSH , Data Encryption Standard (DES),
the Triple DES (3DES) blowfish.

2.4.1.2 SSH
SSH , ssh.
,
SSH, ,, -
SSH. SSH :
des, 3des blowfish.
. .


.466534.012-324 21
. . .
2.4.1.3
sh ssh 1.5 ssh shell.

2.4.2
2.4.2.1
ssh .
.
:

Ip sshd auth_method STRING

2.4.2.2
ssh , -
.
-
:

Ip sshd access-class STRING

2.4.2.3
,
, .

:

Ip sshd timeout <60-65535>

2.4.2.4
,
SSH , . -
3 .


-
:

Ip sshd auth-retries <0-65535>

2.4.2.5 ssh
SSH . SSH- -

. .
ras (client). -
- .
SSH-:

Ip sshd enable
. .

2.4.3 Ssh
, , IP- 192.16.20.40 ssh.
.

2.4.3.1
ip access-list standard ssh-acl
permit 192.168.20.40

2.4.3.2
aaa authentication login ssh-auth local
ip sshd auth-method ssh-auth
ip sshd access-class ssh-acl
ip sshd enable
. .

22
.466534.012-324
. . .
3
3.1
, -
.
, ,
. ,
, .
, .

3.1.1
.

Ethernet
Ethernet Ethernet
Ethernet
Ethernet





VLAN

: Ethernet -
. Ethernet -
, . -
, .
Ethernet :
Ethernet
Ethernet
Ethernet
:



VLAN

3.1.2
.
:
1) interface ; -
config_ , -
. .

. .
. show in-
terface . , -
, :
Switch#show interface
GigaEthernet1/1 is down, line protocol is down
Hardware is Fast Ethernet, Address is 0009.7cf7.7dc1
. .

MTU 1500 bytes, BW 10000 Kbit, DLY 1000 usec,


reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Auto-duplex, Auto-speed
input flow-control is off, output flow-control is off
ARP type: ARPA, ARP Timeout 04:00:00
Last input never, output 17:52:52, output hang never
Last clearing of "show interface" counters never

Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0


Queueing strategy: fifo
Output queue :0/40 (size/max)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute input rate 0 bits/sec, 0 packets/sec
1 packets input, 64 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
. .


.466534.012-324 23
. . .
0 watchdog, 0 multicast, 0 pause input
0 input packets with dribble condition detected
1 packets output, 64 bytes, 0 underruns
0 output errors, 0 collisions, 1 interface resets
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier, 0 PAUSE output
0 output buffer failures, 0 output buffers swapped out
Gigabit Ethernet g1/1, :
interface GigaEthernet0/1
config_g1/1 .
:
. -
, g 1/1, g 1/1.
2) .
, ;
,
.
3) show, -
, .

3.2
3.2.1
, .
.
:

3.2.1.1
, -
. , -
. show interface
running-config . -
.



description string
-
.

3.2.1.2

. .
. bandwidth -
.

bandwidth kilobps
, -
.
. .

3.2.1.3

. bandwidth
.

delay tensofmicroseconds
. delay -
.

3.2.2
:

. .

24
.466534.012-324
. . .

3.2.2.1
,
, . -
, , : -

:

show interface [type [slot|port]] .
show running-config .
-
show version , , ,
.

3.2.2.2
.
- . , -
, . -
:

no interface type [slotport]

3.2.2.3
, . -
-
. -
. .
DTR .
shutdown no shutdown -
.


shutdown
no shutdown
show interface show running-
config. administratively down.
.
. .

3.2.3
, ,
:



VLAN
. .

3.2.3.1
. -
, . ,
. no ip unreachable
. -
, , -

; -
.
-
:

interface null 0
. .


.466534.012-324 25
. . .
,
. IP-
192.168.20.0.
ip route 192.168.20.0 255.255.255.0 null 0

3.2.3.2
. -
BGP .
BGP. -
,
. , , -
. ,
, .
.
, -
:

interface loopback number

3.2.3.3

Ethernet.
, .
:

Interface port-aggregator number

3.2.3.4 VLAN
Vlan - . VLAN -
2 VLAN . -
, VLAN. VLAN -
, .
VLAN :



Interface vlan number VLAN

3.2.3.5 Super-VLAN
Super VLAN : VLAN
Ipv4 .
IP-. Super VLAN VLAN ,
. IPv4 .

. .
VLAN, Super VLAN, SubVLAN. SubVLAN -
IP-. Ip- Super
VLAN.
Super VLAN :

super VLAN.
. .

[no] interface superv- Super VLAN , Super VLAN.


lan index index super Vlan, :
1~32. no (prefix) super VLAN
SubVLAN Super VLAN. Sub VLAN -
Super VLANs. -
Super VLAN Sub VLAN.
Setstr Sub Vlan. , List 2, 4-
[no] subvlan [setstr] 6 VLAN 2, 4, 5, 6.

[add addstr] [remove add VLAN


remstr] Sub VLAN. addstr -
, . remove VLAN -
SubVLAN. remstr -
. , . no SubVLANs
SuperVLAN. no .
Ip- Super VLAN.
. .

26
.466534.012-324
. . .
Super VLAN ,
.

3.3
3.3.1
3.3.1.1
, ;
.
interface vlan 1interface vlan 1
ip address 192.168.1.23 255.255.255.0ip address 192.168.1.23 255.255.255.0

3.3.1.2
Ethernet 1.
interface GigaEthernet0/1
shutdown
.
interface GigaEthernet0/1
no shutdown

. .
. .

. .


.466534.012-324 27
. . .
4
4.1
, ,
.
, ,
. ,
, .
, .

4.1.1
.

Ethernet
Ethernet Ethernet Ethernet
Ethernet




VLAN
: Ethernet -
. Ethernet -
, . -
, .
Ethernet :
Ethernet
Ethernet
Ethernet
:



VLAN


4.1.2
.
:
1) interface ; -
config_ , .
.
. show interface
. , , -

. .
:
Switch#show interface
GigaEthernet1/1 is down, line protocol is down
Hardware is Fast Ethernet, Address is 0009.7cf7.7dc1
MTU 1500 bytes, BW 10000 Kbit, DLY 1000 usec,
reliability 255/255, txload 1/255, rxload 1/255
. .

Encapsulation ARPA, loopback not set


Auto-duplex, Auto-speed
input flow-control is off, output flow-control is off
ARP type: ARPA, ARP Timeout 04:00:00
Last input never, output 17:52:52, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0

Queueing strategy: fifo


Output queue :0/40 (size/max)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute input rate 0 bits/sec, 0 packets/sec
1 packets input, 64 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
. .

28
.466534.012-324
. . .
0 watchdog, 0 multicast, 0 pause input
0 input packets with dribble condition detected
1 packets output, 64 bytes, 0 underruns
0 output errors, 0 collisions, 1 interface resets
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier, 0 PAUSE output
0 output buffer failures, 0 output buffers swapped out
Gigabit Ethernet g0/1, :
interface GigaEthernet0/1
config_g0/1 .
:
. -
, g 1/1, g 1/1.
2) .
, ;
,
.
3) show, -
, .

4.2
4.2.1 Ethernet
Ethernet . Ethernet
: 10 / 100 /. :
, - .

4.2.1.1 Ethernet

Ethernet:


interface fastethernet [slot\port ] Ethernet
interface gigaethernet [slot\port ] Ethernet
show interface fastEthernet
Fast Ethernet show interface gigaEthernet Gigabit
Ethernet.

4.2.1.2 Ethernet
. .

Ethernet
.

Ethernet 10, 100
Speed {10|100|1000|auto}

No speed ()
. .

:
. , GBIC GE-FX 1000M,
FE-FX - 100M. speed auto,
. .

4.2.1.3

,
. Ethernet
. Ethernet
.

duplex {full|half|auto} Ethernet
No duplex ()
. .


.466534.012-324 29
. . .
4.2.1.4

PAUSE ( 802.3).

flow-control on/off /

no flow-control


. .
. .

. .

30
.466534.012-324
. . .
5
5.1
5.1.1 Ethernet
Ethernet . proce-
dures . Ethernet : 10 / 100
/. : , - -
.

5.1.1.1
keepalive,
.

keepalive .
keepalive period Period , -
.
no keepalive keepalive

5.1.1.2
. -
.

Configure
interface f0/0 , .
.
band , .
[no] switchport rate- ingress , -
limit band ingress } .
egress , -
.
exit .
exit .

5.1.1.3

PAUSE ( 802.3).

flow-control on/off /
no flow-control
. .

5.1.1.4 -
, -
( MAC )
, .
.

. .

storm-control {broadcast | multicast -


} threshold count
no storm-control {broadcast | multi-
cast } threshold -

5.2
5.2.1

,
, . -
MAC , MAC
. MAC- -
, . -
.
. .


.466534.012-324 31
. . .
: -
-. MAC- -
MAC , ,
MAC-.
, , .
.

5.2.2
/

-
-


-
MAC- IP-

5.2.3
5.2.3.1 /
:
, -
.
:

configure
interface f0/1 , .
[no] switchport port-security /
exit .
exit .
write

5.2.3.2
, -


.
: protect.
-
:

configure
interface f0/1 , .

. .
[no] switchport port-security viola-
protect:
tion [protect\restrict]
restrict:
exit .
exit .
write
. .

5.2.3.3 -
-
-.
-:

configure
interface f0/1 , .

[no] switchport port-security mac- / -. -


address mac-addr mac-addr MAC-.
exit .
exit .
write
. .

32
.466534.012-324
. . .
5.2.3.4
show, -
, , MAC-
, MAC- , -.
show -
:

show port-security [interface inter-
face-id] interface-id: ID

5.2.3.5 -
show, -
, MAC- MAC- -
.
show -
-:

show mac address-table [interface in- -
terface-id] interface-id: ID

5.2.3.6 MAC- IP-


IP- - .
:
IP- -, IP-
, , .
, -
:

switchport port-security bind {ip
A.B.C.D | mac H.H.H} MAC- IP-

5.3
5.3.1
5.3.1.1
, ;
.
interface vlan 1
ip address 192.168.1.23 255.255.255.0
. .

5.3.1.2
Ethernet 1.
interface fastEthernet 0/1
flow-control on
. .

.
interface fastEthernet 0/1
flow-control off

. .


.466534.012-324 33
. . .
6
6.1
6.1.1
,
.
, interface range,
. interface range,
, , .

6.1.2
:

interface range, , -
, :
interface range type slot/<port1 - (1) slot
port2 | port3>[ , <port1 - (2) 1 2
port2|port3>] 3.
(3) 2 , 1
(4) /
fast Ethernet,
Ethernet 1, 2, 3, 6, 8, 10, 11, 12, 0.
switch_config#interface range 1 - 3 , 6 , 8 , 10 - 12
switch_config_if_range#


. .
. .

. .

34
.466534.012-324
. . .
7
7.1

7.2
7.2.1
, -
.
-
:

Configure

Session-number -
.
mirror session session_number {desti-
Destination -
nation {interface interface-id} |
source {interface interface-id [, | - .
]rx ] } Source .
rx .
-
.
exit .
write .

7.2.2
show.

.
show mirror [session session_number]
Session-number

. .
. .

. .


.466534.012-324 35
. . .
8 VLAN
8.1 VLAN
(Virtual Local Area Network) ,
, . 1999 . IEEE -
IEEE 802.1Q, VLAN. -
, . -
VLAN ,
. VLAN , -
, , -
; -
,
, , ,
.
:
VLAN
, 802.1Q
Visiting port
Vlan , VLAN,
. ,
; VLAN , -
. vlan , -
vlan , vlan id vlan (PVID).
VLAN
Vlan-allowed vlan,
. Vlan-untagged
vlan vlan.

8.2 VLAN
/ VLAN

/ VLAN
superVLAN
VLAN


8.3 VLAN
8.3.1 / VLAN
- , -
, . VLAN
, LAN,
LAN. VLAN -
, -
. VLAN .

. .
VLAN, .
VLAN:

vlan vlan-id VLAN
name str VLAN
Exit vlan vlan.
. .

vlan vlan-range VLAN .


no vlan vlan-id | vlan-range VLAN.
VLAN -
GVRP.

8.3.2

, ,
VLAN.
, VLAN
Ethernet .
,
Ethernet .
VLAN , -
, , . -
. .

36
.466534.012-324
. . .
port pvid,
VLAN. ,
. .
VLAN PVID. VLAN
.
.
VLAN, , -
, , VLAN, -
.
:

switchport pvid vlan-id PVID .
switchport mode access|trunk|dot1q-tunnel .
switchport trunk vlan-allowed ... vlan-allowed .
switchport trunk vlan-untagged ... vlan-untagged .
:
dot1q-tunnel.
/ ,
.
dot1q-tunnel:

double-tagging double-tagging
dot1q-tunnel :
dot1q-

tunnel
2116 / 2224 / 2224M / 2226 / 2448B / 3224 / 3224M / 3424 / 6508
2224D
2448 / 2516 / 2524 / 3448 / 3512
, , , -
.

8.3.3 / VLAN
Vlan -
3. vlan :

[no] interface vlan vlan-id / VLAN

8.3.4 Super-VLAN
. .

Super VLAN : -
, VLAN Ipv4; -
, IP-. Super VLAN -
. VLAN -

IPv4 . , Super VLAN,
IP-.
. .


Super VLAN. -
, .
[no] interface supervlan index Index Super VLAN. 1
32.
no , Super VLAN.
Super VLAN. Sub
VLAN -

Super VLANs. Super VLAN -


[no] subvlan [setstr] [add . .
addstr] [remove remstr] Setstr Sub VLAN Sub VLAN. -
, 2,4-6 VLAN2,4,5,6.
Add VLAN
Sub VLAN. addstr
.
. .


.466534.012-324 37
. . .
Remove VLAN
Sub VLAN. remstr
.
No SubVLAN SuperVLAN. -
no
VLAN interface , Ip-.
Super VLAN , -
.

8.3.5 VLAN
VLAN -
:

show vlan [ id x | interface intf ] VLAN
show interface {vlan | supervlan} x /supervlan

8.4
, :

PC1~PC6 1~6 IP- -


192.168.1.0/24. , 2-6 -
ping, IP- 192.168.1.100. 1-3 4-6


2. 1-3 VLAN1,
4-6 - VLAN2. VLAN1 VLAN2 SuperVlan.
SuperVla :

interface fastethernet 0/4


switchport pvid 2
!
interface fastethernet 0/5

. .
switchport pvid 2
!
interface fastethernet 0/6
switchport pvid 2
!
interface supervlan 1
. .

subvlan 1,2
ip address 192.168.1.100 255.255.255.0
ip proxy-arp subvlan
!

. .

38
.466534.012-324
. . .
9 STP
9.1 (STP)
9.1.1 STP.
(Spanning Tree Protocol - STP)
IEEE 802.1D; , -
, .
-
-
. ,
. -
. , ,
.
STP
. LAN -
. ,
, , , LAN.
, .
.
( ) . ,
, .
:
(1) .
(2) .
(3) .
( )
. Root Path Cost, ,
.
, .
, (
LAN) . LAN
-
.
, -
.
STP ,

Ethernet. STP -
.
(Rapid Spanning Tree) -
802.1D ST. RSTP
, LAN.
. -
.
802.1D STP 802.1w RSTP. -
. .

PVST MSTP. 2: "


STP ".
, , -
.
:
802.1D STP 802.1w RSTP SSTP RSTP; SSTP -
Single Spanning-tree.
. .

9.1.2 STP
Single STP PVST RSTP MSTP
NX-5124G 10

9.1.3 RSTP

STP
/ STP





. .


.466534.012-324 39
. . .


STP

9.1.4 SSTP
9.1.4.1 STP
STP :

spanning-tree mode {sstp | rstp} STP

9.1.4.2 / STP
.
, .
:

no spanning-tree STP

, :

spanning-tree STP (SSTP)
spanning-tree mode {sstp | rstp} STP

9.1.4.3
-
.
:

spanning-tree sstp priority value sstp
no spanning-tree sstp priority sstp -
(32768)


9.1.4.4
STP -
, .
SSTP :

spanning-tree sstp hello-time value sstp

. .
no spanning-tree sstp hello-time sstp -
(4 )

9.1.4.5
,
, .
-
. .

:

spanning-tree sstp max-age value sstp
no spanning-tree sstp max-age
(20 )

9.1.4.6
sstp ,
, learning listening
(forwarding).
sstp :

spanning-tree sstp forward-time sstp
. .

40
.466534.012-324
. . .
no spanning-tree sstp forward time
(15 )

9.1.4.7
.
.
:

spanning-tree port-priority value
spanning-tree sstp port-priority value sstp
no spanning-tree sstp port-priority
(128)

9.1.4.8
:

spanning-tree cost value
spanning-tree sstp cost value sstp
no spanning-tree sstp cost

9.1.4.9
6500.
BPDU -
, MSU.
STP.
,
6500 :

spanning-tree designated-auto
no spanning-tree designated-auto

9.1.4.10 STP
STP, -
:

show spanning-tree
show spanning-tree detail
show spanning-tree interface
. .

9.1.5 vLAN
9.1.5.1
SSTP .
vLAN. vLAN, -
SSTP vLAN .
. .

vLAN,
.
,
30 ; -
STP.
NX-5124G10 -
vLAN. , , -
.

9.1.5.2 STP vLAN



STP :

spanning-tree mode pvst STP vLAN
. .


.466534.012-324 41
. . .
STP VLAN.
spanning-tree vlan vlan-list vlan-list: vLAN ( )
SSTP 30 -
.
no spanning-tree vlan vlan-list
vLAN.
spanning-tree vlan vlan-list prior-
ity value vLAN.
no spanning-tree vlan-list priority .
spanning-tree vlan vlan-list for-
ward-time value VLAN.
no spanning-tree vlan vlan-list for-
ward-time VLAN.
spanning-tree vlan vlan-list max-age
VALN
value
no spanning-tree vlan vlan-list max-
age VLAN.
spanning-tree vlan vlan-list hello-
time value VLAN.
no spanning-tree vlan vlan-list
hello-time VLAN.

:

spanning-tree vlan vlan-list cost VLAN.
no spanning-tree vlan vlan-list cost VLAN.
spanning-tree vlan vlan-list port-
priority VLAN.
no spanning-tree vlan vlan-list
port-priority VLAN.
-
vLAN:

show spanning-tree vlan vlan-list VLAN


9.1.6 RSTP
/ RSTP




. .

9.1.7 RSTP
9.1.7.1 / RSTP
:
. .


spanning-tree mode rstp RSTP
no spanning-tree mode STP (SSTP)

9.1.7.2
,
. , -

.
:

spanning-tree rstp priority value
no spanning-tree rstp priority
. .

42
.466534.012-324
. . .
, MAC-
. , RSTP,
, .
32768.

9.1.7.3
,
. -
, . -
, . -
. -
, , ;
. -
. , , -
.
:

spanning-tree rstp forward-time value
no spanning-tree rstp forward-time (15)
, -
. , -
. -
.
(Forward Delay Time) 15
.

9.1.7.4
, -
, .
:

spanning-tree rstp hello-time value
no spanning-tree rstp hello-time

,
. , -
. ,
,
. .
4 .

9.1.7.5
. .

,
. -
.
:

spanning-tree rstp max-age value
. .

no spanning-tree rstp max-age (20 )


, , . -
. ,
Max Age, -
. Max
Age, .
20 .

9.1.7.6
Ethernet . -
, . RST
Ethernet
.
. .


.466534.012-324 43
. . .
-
:

spanning-tree rstp cost value
no spanning-tree rstp cost
, Ethernet
. RSTP -
Ethernet.
, Ethernet 2000000, -
10 / 200000, 100/.

9.1.7.7
Ethernet , -
. , ,
. Ethernet , -

.
:

spanning-tree rstp port-priority value
no spanning-tree rstp port-priority
, Ethernet
.
Ethernet 128.

9.1.7.8
RST
802.1D STP, . STP,
STP, .
STP, RSTP
802.1D STP BPDU. span-
ning-tree rstp migration-check
RSTP.


:
, IEEE 802.1D 2004 RSTP, -
migration-check.

RSTP:

spanning-tree rstp migration-check
-

. .
:

spanning-tree rstp migration-check

9.2 MSTP
. .

9.2.1 MSTP
9.2.1.1
Multiple Spanning Tree Protocol (MSTP) -
LAN. MSTP (Spanning
Tree Protocol (STP)) (Rapid Spanning Tree Protocol (RSTP)).
STP
RSTP vLAN . STP -

. RSTP
.
MSTP RSTP
VLAN STP,
. , MSTP, VLAN
VLAN.
. .

44
.466534.012-324
. . .
PvSTP, MSTP VLAN STP,
STP, VLAN.
NX-5124G10 MSTP. , -
, .

9.2.1.2 MST
MSTP VLAN STP MSTP. -
MSTP, MST.
, MST -
, MST. MST
VLAN, VLAN MST.

9.2.1.3 IST, CST, CIST MSTI


9.2-1 MSTP, MST ,
802.1D STP.

9.2-1 MSTP
1. CIST
Common and Internal Spanning Tree (CIST) , -
LAN.
MST STP RSTP;
. .

.
, CIST CIST. -
CIST ,
CIST.
2. CST
(Common Spanning Tree). MST
. .

, Common Spanning Tree (CST) ,


. 2.1, 1, 2 3 STP -
CST.
3. IST
(Internal Spanning Tree (IST)) CIST, -
MST. , IST CST CIST.
4. MSTI

(Multiple Spanning Tree Instance). MSTP


VLAN ,
Multiple spanning tree. , CIST,
. , No.1,
. -
VLAN. , VLAN CIST.
MSTI MST .
. 3 2.1 MSTI01 -
. .


.466534.012-324 45
. . .
, . MSTI00, CIST, -
, .

9.2.1.4
MSTP , RSTP.
1.

9.2-2
,
.
2.


9.2-3
. -
,
, .
3.

. .
. .

9.2-4
LAN .

LAN .
. .

46
.466534.012-324
. . .
4.

9.2-5
LAN,
, . -
, .
5.

9.2-6

MST CIST.
CIST.
6.
CIST MSTI. CIST -
, MST. MSTI,
, .
7.
. .

RSTP MSTP, ,
. ,
.
. .

9.2-7
. .


.466534.012-324 47
. . .
, MTSP RSTP ,
. , BPDU ,
. 802.1D STP BPDU,

.

9.2.1.5 MSTP BPDU


STP RSTP, , MSTP, -
Bridge Protocol Data Unit (BPDU). CIST MSTI -
BPDU. 9.2-1 9.2-2 BPDU, MSTP.
9.2-1 MSTP BPDU

(Protocol Identifier) 1-2
(Protocol version Identifier) 3
BPDU (BPDU Type) 4
CIST (CIST Flags) 5
CIST (CIST Root Identifier) 6 - 13
CIST (CIST External Root Path Cost) 14 - 17
CIST (CIST Regional Root Identifier) 18 - 25
CIST (CIST Port Identifier) 26 - 27
(Message Age) 28 - 29
(Max Age) 30 -31
(Hello Time) 32- 33
(Forward Delay) 34 - 35
1 (version 1 Length) 36
3 (version 3 Length) 37 - 38
(Format Selector) 39
(Configuration Name) 40 - 71
(Revision) 72 - 73
(Configuration Digest) 74 - 89
CIST (CIST Internal Root Path Cost) 90 - 93
CIST (CIST Bridge Identifier) 94 - 101
CIST (CIST Remaining Hops) 102


MSTI (MSTI Configuration Messages) 103~
9.2-2 MST

MSTI (MSTI FLAGS) 1
MSTI (MSTI Regional Root Identifier) 2-9
MSTI (MSTI Internal Root Path Cost) 10 - 13
MSTI (MSTI Bridge Priority) 14

. .
MSTI (MSTI Port Priority) 15
MSTI (MSTI Remaining Hops) 16

9.2.1.6
MSTP
BPDU, .
. .

1) CIST .
2) LAN
CIST, .
3) , CIST -
.
4) MSTI MSTI.
5) LAN
MSTI.

6) CIST
CIST CIST.
7) CIST LAN
CIST.
8) , ,
LAN .
9) MSTI MSTI.
. .

48
.466534.012-324
. . .
10) MSTI MSTI.
11) CIST. -
CIST MSTI .

9.2.1.7
STP RSTP, MSTP STP (Hop Count)
Message Age Max Age BPDU.
, MSTP
. BPDU -
CIST MSTI .
0, .

9.2.1.8 STP
MSTP STP
. STP, -
STP. , , STP,
.
:
, STP, -
MSTP, STP. , -
spanning-tree mstp migration-check STP, ,
the MSTP.
, RSTP,
MSTP. , MSTP -
RSTP.

9.2.2 MSTP
MSTP
MSTP
MSTP



STP






MST

9.2.2.1 MST
MSTP, , IEEE 802.1s.
. .

MSTPs, MSTP, Cisco,


MSTP , MST. , , -
MSTP, MSTP, -
MST MST.
, MST, , STP, -
MSTP. BPDU ,
BPDU .
. .

MST, spanning-tree mstp migration-check.


, MST,
:

spanning-tree mstp mst-compatible MST
no spanning-tree mstp mst-compatible MST
:

MST -
, MSTP. ,
. ,
MSTP, CIST, -
.
. .


.466534.012-324 49
. . .
MST , -
BPDU RSTP BPDU.
, MST, .
-
MST BPDU, .
migration-check.

MSTP

9.2.3 MSTP
9.2.3.1 MSTP

STP SSTP (PVST, RSTP MSTP )
MAC-
0
MST VLANs CIST (MST00)
(CIST MSTI) 32768
(CIST MSTI) 128
1000 /: 20000
(CIST MSTI) 100 /: 200000
10 /: 2000000
(Hello Time) 2
15
20
20

9.2.3.2 MSTP
STP PVST SSTP . -
, .
STP MSTP :

spanning-tree STP


spanning-tree mode mstp MSTP
STP :

no spanning-tree STP

9.2.3.3 MST
MST, , : ,

. .
, VLAN MSTI. -
. ,
, .
MST -
MAC- . VLANs CIST (MST00). 0 VLAN
CIST (MST00). MAC-,
MSTP . span-
. .

ning-tree mstp instance instance-id vlan vlan-list MSTI -


VLAN. MSTI , VLAN CIST.
MST :

MST
string
spanning-tree mstp name string 32 ; -

.
MAC-
no spanning-tree mstp name MST
MST.
spanning-tree mstp revision value value , 0 65535.
0.
No spanning-tree mstp revision MST
. .

50
.466534.012-324
. . .
instance-id -
, MSTI. 1 15.
spanning-tree mstp instance in- vlan-list vlan,
stance-id vlan vlan-list 1 4094. instance-id -
, ;
vlan-list vlan,
1,2,3, 1-5, 1,2,5-10 ..
VLAN MSTI
no spanning-tree mstp instance in- . instance-id -
stance-id , MSTI. 1
15.
MSTP :

show spanning-tree mstp region MSTP

9.2.3.4
MSTP ID ,
MAC- .
ID .
MSTP . -
32768..
,
, Spanning-tree mstp in-
stance-id root.
, ID
ID 24576, 24576 ,
.
24576, MSTP
4096 , . -
, 4096 .
, diameter -
. ID 0.
, MSTP
STP , ,
. Hello-time

.
:

-

instance-id
spanning-tree mstp instance-id root
primary [diameter net- , 0 15.
. .

diameter[hello-time seconds]] net-diameter (


).
seconds -
. 1 10 .
No spanning-tree mstp instance-id
root instance-id
, 0 15.
. .

MSTP :

show spanning-tree mstp[instance in-
stance-id] MSTP

9.2.3.5
, spanning-tree mstp instance-id

root secondary,
.
, .
, MSTP -
28672. ,
32768, .
. .


.466534.012-324 51
. . .
diameter hello-
time STP. -
, .
:



spanning-tree mstp instance-id root
secondary instance-id -
[diameter net-diameter [hello-time sec- , 0 15
onds]] net-diameter (-
), instance-id
0; 2 7.

No spanning-tree mstp instance-id root instance-id -
, 0 15.
MSTP :

show spanning-tree mstp
[instance instance-id] MSTP

9.2.3.6
, , -
root. -
.
:


instance-id -
spanning-tree mstp instance-id pri- , 0 15; value -
ority value ; -
: 0, 4096, 8192, 12288, 16384, 20480, 24576, 28672, 32768,
36864, 40960, 45056, 49152, 53248, 57344, 61440


no spanning-tree mstp instance-id .
priority instance-id
, 0 15.

9.2.3.7 STP
STP:
Hello Time ( )
,

. .
.
Forward Delay ( )
, , Blocking learning for-
warding STP.
Max Age ( )

-
. .

:
2 x (fwd_delay 1.0) >= max_age
max_age >= (hello_time + 1) x 2
, MSTP:

:

spanning-tree mstp hello-time seconds 1 10 ; 2


.
No spanning-tree mstp hello-time
-
spanning-tree mstp forward-time seconds : 6 40 ;
- 15 .
no spanning-tree mstp forward-time -
.
. .

52
.466534.012-324
. . .
:
spanning-tree mstp max-age seconds 6 40 ; - 20
.
no spanning-tree mstp max-age -
.
STP -
.
-
.
.

9.2.3.8
.
.
MSTP, spanning-tree mstp diameter net-
diameter. CIST.
STP .
:

spanning-tree mstp diameter net- .
net diameter 2 7;
diameter
7.
no spanning-tree mstp diameter net diameter
.
.

9.2.3.9
(maximum hops) .

spanning-tree mstp max-hops hop- .
count hop count 1 40; -
20.

no spanning-tree mstp hop-count -


9.2.3.10
, -
(forwarding), -
. ,
. .

forwarding.
, MSTP:

STP
instance-id
spanning-tree mstp instance-id port-priority , 0 15.
. .

priority ; -
priority
:
0, 16, 32, 48, 64, 80, 96, 112
128, 144, 160, 176, 192, 208, 224, 240
-
.
spanning-tree port-priority value value -
:0, 16, 32, 48, 64, 80, 96, 112

128, 144, 160, 176, 192, 208, 224, 240


no spanning-tree mstp instance-id port-
priority
no spanning-tree port-priority

MSTP :
. .


.466534.012-324 53
. . .

show spanning-tree mstp interface MSTP
interface-id ,
interface-id
F0/1, FastEtnernet0/3 ..

9.2.3.11
MSTP . -
, -
. , . -
, .
:


spanning-tree mstp instance-id cost cost instance-id -
, 0 15.
-
spanning-tree cost value .
value .
1 200000000.
no spanning-tree mstp instance-id cost -

no spanning-tree cost -

9.2.3.12
, MSTP -
-,
(handshake mechanism). ,
-.
, -
. , -
-. ,
.
, , RSTP MSTP, -


point-to-point, -
.
, :

spanning-tree mstp point-to-point force-true -.
spanning-tree mstp point-to-point force-
false (shared)
spanning-tree mstp point-to-point auto

. .
no spanning-tree mstp point-to-point

9.2.3.13 MST
MSTP, , IEEE 802.1s.
MSTPs, MSTP, Cisco,
. .

MSTP , MST. , , -
MSTP, MSTP, -
MST MST.
, MST, , STP, -
MSTP. BPDU ,
BPDU .
MST, spanning-tree mstp migration-check.
, MST,

:

spanning-tree mstp mst-compatible MST
no spanning-tree mstp mst-compatible MST
:
. .

54
.466534.012-324
. . .
MST -
, MSTP. ,
. ,
MSTP, CIST, -
.
MST , -
BPDU RSTP BPDU.
, MST, .
-
MST BPDU, .
migration-check.

9.2.3.14
MSTP STP -
. STP,
STP. STP . -
, STP, .
:
, STP,
MSTP, STP; STP,
, MSTP, spanning-tree
mstp migration-check .
RSTP,
MSTP. , MSTP -
RSTP.
STP, , -
:

spanning-tree mstp migration-check STP,

STP, ,
:

spanning-tree mstp migration-check STP,

9.2.3.15 MSTP
MSTP, ,
:

show spanning-tree MSTP ( SSTP, PVST,
. .

RSTP MSTP)
show spanning-tree detail STP (
SSTP, PVST, RSTP MSTP)
show spanning-tree interface interface-id STP ( SSTP,
PVST, RSTP MSTP)
show spanning-tree mstp MST
show spanning-tree mstp region MST
. .

show spanning-tree mstp instance in-


MST
stance-id
show spanning-tree mstp detail MST
show spanning-tree mstp interface inter-
MST
face-id
show spanning-tree mstp protocol-
migration

. .


.466534.012-324 55
. . .
10 STP
10.1 STP
10.1.1 STP.

( ); .

:
-
Single STP PVST RSTP MSTP

Port Fast
BPDU Guard
BPDU Filter
Uplink Fast
Backbone Fast
Root Guard
Loop Guard

10.1.1.1 Port Fast


Port Fast , , -
, . SSTP
PVST Port Fast , ,
.
, .
BPDU ;
, . Port
Fast , , .
Port Fast -
. ,
Port Fast .
. Port Fast
BPDU Guard BPDU Filter .


. .
. .

10.1-1 Port Fast


:
, RSTP MSTP, -
. Port Fast.

10.1.1.2 BPDU Guard


Port Fast BPDU, , -


- . BPDU -
Port Fast, BPDU guard.
BPDU STP. , Port
Fast, BPDU SSTP/PVST, BPDU guard
. , BPDU
guard, BPDU SSTP/PVST, -
. .

56
.466534.012-324
. . .
.
BPDU guard Port Fast. STP
BPDU Guard BPDU , -
BPDU. RSTP/MSTP BPDU Guard
, , , , BPDU.
BPDU Guard -
. spanning-tree portfast bpduguard -
, BPDU . , -
BPDU guard .

10.1.1.3 BPDU Filter


BPDU BPDU SSTP/PVST, -
, Port Fast.
, Port Fast, BPDU SSTP/PVST,
BPDU Filter Forwarding, -
Listening Learning.
bpdu
. spanning-tree portfast bpdufilter
bpdu ; ,
bpdu.

10.1.1.4 Uplink Fast


Uplink Fast Forwarding
.
, 10.1-2.
, , -
. STP .

. .

10.1-2
. .

( Direct Link
Failure), STP ,
Forwarding, Listening Learning.
Uplink Fast spanning-tree uplinkfast
, , -
.
10.1-3 Uplink Fast. -
C B , .

C A, -
, .
. .


.466534.012-324 57
. . .
10.1-3 Uplink Fast
:
Uplink Fast SSTP PVST.
RSTP MSTP, Uplink
Fast.

10.1.1.5 Backbone Fast


Backbone Fast Uplink Fast. Uplink Fast -
,
Backbone Fast
.
10.1-3, L2 C A


c ; Uplink
Fast. L1 A B C.
L1 ,
backbone fast.
Backbone Fast 10.1-4.

. .
. .

10.1-4 Backbone Fast


. .

58
.466534.012-324
. . .
, C , B.
L1, B bpdu C, -
. C , bpdu -
. Backbone Fast ,
C B
. . -
spanning-tree backbonefast,
C BPDU , C -
, indirect-link root-switch-reachable ; C
, .
Backbone Fast, BPDU -
, . ,
. -
, .
, Backbone Fast . -
: listening,
learning forwarding.
Uplink Fast, Backbone Fast SSTP PVST.

10.1.1.6 Root Guard


Root Guard - BPDU
.
2 ,
. -
, ( - ,
). -
, (core switch) .
Root Guard ,
,
. Root Guard -
BPDU , Root Guard
.
PVST MSTP Root Guard
. MSTP, Root Guard CIST,
MSTI. , LAN
, STP, RSTP MSTP .

, spanning-tree guard root


Root Guard .
:
Root Guard - SSTP/PVST RSTP/MSTP.
SSTP/PVST, Root Guard, RSTP/MSTP,
BPDU . , ,
.
. .

10.1.1.7 Loop Guard


loop guard -
- , BPDU -
.
, spanning-tree loopguard
default. Loop guard
. BPDU , -
. .

.
PVST MSTP Loop Guard
. MSTP, Loop Guard CIST,
MSTI.
:
Loop Guard SSTP/PVST RSTP/MSTP. SSTP/PVST,
Loop Guard, RSTP/MSTP,

- BPDU. Loop Guard ,


- BPDU .

10.1.2 STP
10.1.2.1 STP
Port Fast
. .


.466534.012-324 59
. . .
BPDU Guard
BPDU Filter
Uplink Fast
Backbone Fast
Root Guard
Loop Guard

10.1.2.2 Port Fast


Port Fast
SSTP/PVST .
Port Fast STP.
port fast :

spanning-tree port fast default port fast,
.
no spanning-tree portfast default port fast
.
:
port fast , ; BPDU Guard
BPDU Filter port fast.
port fast -
:

spanning-tree port fast Port Fast
no spanning-tree portfast port fast -

10.1.2.3 BPDU Guard


BPDU guard , BPDU.
Port Fast BPDU.
BPDU Guard STP. , -
Port Fast, BPDU SSTP/PVST,
. , BPDU guard, BPDU
RSTP/MSTP, .


BPDU Guard :

spanning-tree portfast bpduguard bpdu guard,

no spanning-tree portfast bpduguard bpdu guard
:
port fast . BPDU

. .
Guard BPDU Filter .
BPDU guard :

spanning-tree bpduguard enable bpdu guard
spanning-tree bpduguard disable bpdu guard

. .

no spanning-tree bpduguard bpdu guard


10.1.2.4 BPDU Filter


BPDU Filter, BPDU, -
Port Fast.
BPDU

Filter:

spanning-tree portfast bpdufilter BPDU Filter,

no spanning-tree portfast bpdufilter bpdu filter
:
port fast . BPDU
. .

60
.466534.012-324
. . .
Guard BPDU Filter .
BPDU filter :

spanning-tree bpdufilter enable bpdu filter
spanning-tree bpdufilter disable bpdu filter

no spanning-tree bpdufilter bpdu filter

10.1.2.5 Uplink Fast


Uplink Fast Forwarding
.
Uplink Fast SSTP/PVST.
Uplink
Fast:

spanning-tree uplinkfast uplink fast
no spanning-tree uplinkfast uplink fast

10.1.2.6 Backbone Fast


BackboneFast UplinkFast. Uplink Fast
,
Backbone Fast -
.
Backbone fast SSTP/PVST.
Backbone Fast -
:

spanning-tree backbonefast backbone fast
no spanning-tree backbonefast backbone fast

10.1.2.7 Root Guard


Root Guard - BPDU


.
Loop Guard SSTP/PVST RSTP/MSTP. SSTP/PVST,
Root Guard, RSTP/MSTP,
BPDU . , , .
, Root Guard:

. .

spanning-tree guard root root guard


no spanning-tree guard root guard loop guard
spanning-tree guard none root guard loop guard

10.1.2.8 Loop Guard


loop guard -
- , BPDU -
. .

.
Loop Guard SSTP/PVST RSTP/MSTP. SSTP/PVST,
Loop Guard, RSTP/MSTP,
- BPDU. Loop Guard ,
- BPDU .
Loop
Guard:


spanning-tree loopguard default Loop Guard, -
.
no spanning-tree loopguard default loop guard.
loop guard :
. .


.466534.012-324 61
. . .

spanning-tree guard loop loop guard .
no spanning-tree guard root guard loop guard .
spanning-tree guard none root guard loop guard .


. .
. .

. .

62
.466534.012-324
. . .
11 MAC-
11.1 MAC-
- :
-
-
-
-

11.2 MAC-
11.2.1 Mac-
MAC- , .
. ,
MAC-. MAC-
.

Configure
/ MAC-
[no] mac address-table static mac- mac-addr MAC-;
addr vlan vlan-id interface inter- Vlan-id VLAN; -
face-id 1 4094;
interface-id .
exit .
write .

11.2.2 MAC-
MAC- , -
MAC- MAC-. MAC-
; 300
.
MAC- -
:

configure
-.
mac address-table aging-time [0 | 0 , MAC- .
10-1000000] -: 10
1000000 .
exit .
write .
. .

11.2.3 - VLAN
- VALN, - VALN - -
VLAN. VLAN -.
- VALN :

. .

configure
interface f0/1 ,
switchport shared-learning - VALN
exit .
exit .
write .

11.2.4 MAC-

, -
MAC- . MAC-
show.
. .


.466534.012-324 63
. . .

MAC-
dynamic -, -
.
show mac address-table {dynamic [inter-
face interface-id | vlan vlan-id] | Vlan-id VLAN; -
static} 1 4094.
Interface-id .
Static MAC-

11.2.5 MAC-
MAC- .
MAC-
:

MAC-
dynamic -, -
clear mac address-table dynamic [address .
mac-addr | interface interface-id | vlan Mac-addr MAC-;
vlan-id] Interface-id .
Vlan-id VLAN; -
1 4094.


. .
. .

. .

64
.466534.012-324
. . .
12
.

12.1
- -
. -
. -
, , LACP.
:

, , ,
, -
.
LACP
, LACP,
. .

-
.

12.2
,


12.3
12.3.1 ,
, -
.
:


interface port-aggregator id

12.3.2
-
LACP .
,
, VLAN , , -
. .

, .
, , -
, LACP.
, -
( ). -
, , -
-
. .

. vlan
.
LACP .
, -
. , -
, , .
VLAN: PVID, , VLAN (vlan-
allowed) VLAN (vlan-untagged).

:

aggregator-group agg-id mode { lacp | static }
. .


.466534.012-324 65
. . .
12.3.3
,
.
.
src-mac
MAC-,
MAC- .
dst-mac
MAC- ,
, MAC- .
both-mac
MAC- MAC-
, MAC-
.
src-ip
IP-,
IP- .
dst-ip
IP- , ,
IP- .
both-ip
IP- IP-
, IP-
.
:

aggregator-group load-balance
:
,
. , ,
, . -
, :
src-mac dst-mac both-mac src-ip dst-ip both-ip


NX-5124G 10

12.3.4
-
:

show aggregator-group

. .
. .

. .

66
.466534.012-324
. . .
13 GVRP
13.1
GVRP ( , , -
vlan (garp vlan registration protocol GARP VLAN) -
GARP ( ). GVRP GARP
VLAN . GVRP -
VLAN -
VLAN, VLAN, .
GVRP
VLAN ( VLAN VLAN )
, VLAN
GVRP .

13.2
13.2.1 GVPR
/ GVPR
/ GVPR
GVRP

13.3 GVPR
13.3.1 / GVPR
:

[no] gvrp / GVRP
: GVRP .

13.3.2 / GVPR
:

[no] gvrp / GVPR

GVRP , ; GVRP
. GVRP
; GVRP .
: GVRP .

13.3.3 GVRP
.

. .

show gvrp statistics [interface port_list] GVRP.


show gvrp status GVRP.
/ GVRP -
[ no ] debug gvrp [ packet | event ] . ,
-
/.
. .

GVRP.
switch#show gvrp statistics interface Tthernet0/1
GVRP statistics on port Ethernet0/1
GVRP Status: Enabled
GVRP Failed Registrations: 0
GVRP Last Pdu Origin: 0000.0000.0000
GVRP Registration Type: Normal

GVRP.
switch#show gvrp status gvrp is enabled!

13.4
:
VLAN A B, GVRP A -
B.
. .


.466534.012-324 67
. . .
8 :
Switch_config_f0/8# switchport mode trunk
GVRP A
Switch_config#gvrp
GVRP 8 A
Switch_config_f0/8#gvrp
VLAN 10, VLAN 20 VLAN 30 A
Switch_config#vlan 10
Switch_config#vlan 20
Switch_config#vlan 30
9 :
Switch_config_f0/9# switchport mode trunk
GVRP
Switch_config#gvrp
GVRP 9
Switch_config_f0/9#gvrp
VLAN 40, VLAN 50 VLAN 60
Switch_config#vlan 40
Switch_config#vlan 50
Switch_config#vlan 60
, VLAN
A B. VLAN10, VLAN20, VLAN30, VLAN40, VLAN50 VLAN60
.


. .
. .

. .

68
.466534.012-324
. . .
14 IGMP-SNOOPING
14.1 IGMP-snooping
IGMP VLAN -
VLAN.
. -
IGMP ,
VLAN, IGMP IGMP
.
, IGMP , -
, IGMP-
, ,
IGMP . , IGMP-
-
. show ip igmp-snooping -
VLAN igmp-snooping.
/ IGMP-snooping VALN
/ VLAN
VLAN

IGMP-snooping
IGMP-snooping
IGMP-snooping
IGMP-snooping
IGMP-snooping

14.1.1 / IGMP-snooping VALN


:

ip igmp-snooping [vlan vlan_id] / IGMP-snooping VALN
no ip igmp-snooping [vlan vlanid]
vlan , vlan , vlans,
.
IGMP-snooping VLAN , ip igmp-
snooping.

: IGMP-snooping 16 VLAN.
IGMP-snooping VLAN3, no ip IGMP-
snooping, IGMP-snooping VLAN, ip IGMP-snooping VLAN 3
.

14.1.2 / VLAN
, IGMP,
.
. .

:

ip igmp-snooping vlan vlan_id static
A.B.C.D interface intf VLAN
no ip igmp-snooping vlan vlan_id static
A.B.C.D interface intf VLAN
. .

14.1.3 VLAN
(immediate-leave),
leave; , -
, , -
.
, ;
, immediate-leave .

:

ip igmp-snooping vlan vlan_id immediate-leave VLAN
no ip igmp-snooping vlan vlan_id immediate- VLAN
leave
VLA
. .


.466534.012-324 69
. . .
14.1.4
, (DHL,
igmp-snooping),
VLAN.
, ,
.

ip igmp-snooping dlf-frames filter ,

no ip igmp-snooping dlf-frames ()
:
VLAN.
(
VLAN).

14.1.5 IGMP-snooping
(Router Age) IGMP.
IGMP -
. IGMP .
:

ip igmp-snooping timer router-age IGMP-
timer_value snooping
no ip igmp-snooping timer router-age IGMP-
snooping
:
IGMP inquirer. -
.
260 .

14.1.6 IGMP-snooping
(response time)


IGMP inquirer . -
, .
:

ip igmp-snooping timer response-time
timer_value IGMP-snooping

no ip igmp-snooping timer response-time IGMP-snooping -


. .
:
; , -
. 10 .

14.1.7 IGMP-snooping
VLAN,
. .

IGMP-snooping, IGMP-snooping
IGMP query.( ,
VLAN, IGMP-snooping ).
LAN
, IGMP
snooping, IGMP snooping.
:


[no] ip igmp-snooping querier [address IGMP-snooping -
[ip_addr] address Ip- -

IGMP-snooping .
(Pseudo Query packet) - 10.0.0.200.
:
. .

70
.466534.012-324
. . .
, -
VLAN.
.

14.1.8 IGMP-snooping
:

show ip igmp-snooping IGMP-snooping
show ip igmp-snooping timer IGMP-snooping
show ip igmp-snooping groups IGMP-snooping
show ip igmp-snooping statistics IGMP-snooping
/ IGMP-
[ no ] debug ip igmp-snooping [ packet | snooping ////.
timer | event | error ] ,
/.
VLAN IGMP-snooping:

IGMP-snooping:

IGMP-snooping:

IGMP-snooping:
. .
. .

IGMP-snooping:

. .


.466534.012-324 71
. . .
IGMP-snooping:

14.1.9 IGMP-snooping
:


(1) IGMP-snooping VLAN 1,
Switch_config#ip igmp-snooping vlan 1
(2) IGMP-snooping VLAN 2,
Switch_config#ip igmp-snooping vlan 2

. .
. .

. .

72
.466534.012-324
. . .
15 802.1
15.1 802.1
802.1
802.1
802.1
802.1
802.1
802.1
802.1
802.1
802.1
VLAN

802.1
802.1

15.2 802.1
15.2.1 802.1
802.1x : , -
802.1x.
, -
. .
.
, ,
.
.
802.1x , 802.1x
.
. 802.1x ,
AAA.
802.1x :


dotlx enable 802.1
802.1:

dotlx port-control auto 802.1
aaa authentication dotlx {default |list
802.1
name} method
802.1
. .

:

dot1x port-control auto 802.1x
dot1x port-control force-authorized
dot1x port-control force-unauthorized
. .

15.2.2 802.1
802.1x . -
.
, -
.
, 802.1 (, 1108).
-

.
802.1x,
. , ( -
MAC- ). , 802.1x ,
- . -
- , MAC- .
802.1 -
:
. .


.466534.012-324 73
. . .

()
dot1x multiple-hosts
802.1

15.2.3 802.1
802.1x 802.1x, -
. - -
, - . -
, 802.1x , -
.

, .

:

,
dot1x max-req count EAP-
request/identity

15.2.4 802.1
-
. -
.
-
.
:

( -
dot1x re-authentication
)
dot1x timeout re-authperiod time
-
dot1x reauth-max time


15.2.5 802.1
802.1 .
802.1x ,
.
:

dot1x timeout tx-period time 802.1

. .
15.2.6 802.1
802.1 ,
. 802.1
:

dot1x user-permit xxxz
. .

15.2.7 802.1
802.1 -
. default 802.1.
802.1
:


dot1x authentication method yyy 802.1

15.2.8 802.1
802.1;
Chap Eap (eap md5-challenge eap-tls), .
Challenge, MD5, Chap,
. .

74
.466534.012-324
. . .
challenge eap. -
-
. ,
, No .
Eap-tls
handshake Translation Layer Security (tls),
.
802.1
:

dot1x authen-type {chapjeap} chap eap
:

dot1x authentication type {chapjeap} chap, eap

15.2.9 802.1
802.1 .
dot1x 802.1 , .
,
.
. -
.
, dot1x AAA -
update . ,
.
dot1x, , -
- (supplicant).
dot1x -
:

dot1x accounting enable 802.1
; -
dot1x accounting method {method name}
default

15.2.10 VLAN 802.1


VLAN, (-
, ) . -
VLAN . -
VLAN , -
.
: .
. .

VLAN, -
:

Dot1x guest-vlan guest-vlan
0. -
, .
. .

guest-vlan id .
guest-vlan id:

VLAN VLAN
Dot1x guest-vlan {id(1-4094)}
802.1. 1 4094

15.2.11

(Supplicant) .
:

dot1x forbid multi-network-adapter
. .


.466534.012-324 75
. . .
15.2.12 802.1
. -
:

dot1x default 802.1

15.2.13 802.1
802.1 -
:

show dot1x {interface ....} 802.1

15.3 802.1x
:

F0/10 , F0/12. IP- -


- : 192.168.20.2. : TST. F0/10 -
.
F0/12. F0/12
.
1.
username switch password 0 TST
username TST password 0 TST


aaa authentication dot1x TST-F0/10 radius
aaa authentication dot1x TST-F0/12 local
interface VLAN1
ip address 192.168.20.24 255.255.255.0
radius-server host 192.168.20.2 auth-port 1812 acct-port 1813
radius-server key TST
2. F0/10
interface FastEthernet0/10

. .
dot1x port-control auto
dot1x authentication method TST-F0/10
dot1x user-permit radius-TST
3. F0/12
interface FastEthernet0/12
dot1x Multiple-host dot1x port-control auto
. .

dot1x authentication method TST-F0/12


dot1x authentication type eap

. .

76
.466534.012-324
. . .
16 -
:
MAC-
-
MAC-

16.1 -
16.1.1 MAC-
.
- .
MAC-
.

Configure
/ -
[no] mac access-list name

16.1.2 -
permit/deny , -
. -
-. -
.
-
.

-
permit deny
[no] {deny | permit} {any | host src-mac-
- - -
addr} {any | host dsf-mac-addr} [ether-
- .
type]
ethertype
Ethernet
-
exit

-
exit
write

Switch_config#mac acce 1
Switch-config-macl#permit host 1.1.1 any
Switch-config-macl#permit host 2.2.2 any
- -
. .

. .

16.1.3 -
- -
. - -
.
. .


Configure
-
.
[no] mac access-group name
name -
.
exit .

exit .
write .
. .


.466534.012-324 77
. . .
17 IP-
17.1 IP-
17.1.1 IP
,
.

. :
-

, IP- .
IP- , -
. ROS
. , : . -
, -
. , .
:
(1) .
(2) .

17.1.2 IP-
IP-. :
, .

:

ip access-list standard name name -
IP
deny {source [source-mask] | any} or per-
mit {source [source-mask] | any}

exit

:



ip access-list extended name name -
IP
{deny | permit} protocol source source-
mask destination destination-mask [prece-
dence precedence] [tos tos] . ( precedence -
{deny | permit} protocol any any IP ; TOS )

. .
exit
, ( ) -
. , add access list -
. no permit no deny -
.
:
,
. .

deny. IP-
, 255.255.255.255 .
,
IP- .

17.1.3 IP-
.

:

ip access-group name
,
. ,
. , -
. .

78
.466534.012-324
. . .
. ICMP, ,
-.
, .

17.1.4
,
SMTP 130.2.1.2.
ip access-list extended aaa
permit tcp any 130.2.1.2 255.255.255.255 eq 25
interface g0/10
ip access-group aaa

. .
. .

. .


.466534.012-324 79
. . .
18
18.1 IP-
18.1.1
18.1.1.1 IP-
(Internet protocol - IP) - ,
. IP , -
. IP- (-
IP ). , IP -
, .
(Transmission Control Protocol (TCP)) IP. TCP -
, , ,
. ,
, . TCP
, -
.
IP-, (Address Resolution Protocol (ARP)),
IP-. IP-, ICMP, HSRP, IP- -
IP-.

18.1.1.2 IP-
IP- , -
.
IP 2 : Interior Gateway Protocol (IGP) Exterior
Gateway Protocol (EGP). RIP,
OSPF, BGP BEIGRP. RIP, OSPF, BGP BEIGRP -
. , ,
,
OSOF ( ), BGP, RIP, BEIGRP.
redistribute, -
,
.
,

, . -
, , -


.
1.
.
.


. .




, , -

.
. .

2.
IGP . IP
(, ) -
. -
, .
IGRP:
RIP
OSPF

BEIGRP
3.
EGP -
. , , -
, . EGRP,
BGP.
. .

80
.466534.012-324
. . .
18.1.2 IP-
IP IP -
. -
, IP. IP
.
IP- . , -
.
, IP- , IP .
IP-:
IP-
IP-



IP-

18.1.3 IP-
18.1.3.1 IP-
IP- IP . IP- -
. -
IP 1, IP-
.

0.0.0.0
1.0.0.0 126.0.0.0
127.0.0.0
128.0.0.0 191.254.0.0

191.255.0.0
192.0.0.0
192.0.1.0 223.255.254
223.255.255.0
D 224.0.0.0 239.255.255.255
240.0.0.0 255.255.255.254
E
255.255.255.255

IP- RFC 1166 .


, .
IP-. IP-
, -
:

ip address ip-address mask IP-
. .

IP-.
: ,
.

18.1.3.2 IP-
IP-, IP- -
. .

IP-. IP-
:
IP . ,
254 IP-,
300 . IP-
.
2 , -
. IP-

.
, IP.
, -
IP-, -
.
:
,
IP- .
. .


.466534.012-324 81
. . .
,
:

ip address ip-address mask secondary IP-
:
IP -
.

18.1.3.3
IP IP- . -
, :
1.
IP- ( -
), ( , -
). , -
, .
MAC- , MAC
.
, Ethernet ,
48- MAC- .
IP- . IP-
.
: (Ad-
dress Resolution Protocol (ARP)) -ARP. RFC 826 1027.
ARP IP- MAC-. IP-
ARP -. MAC-
, IP- MAC- ARP . IP-
.
ARP
ARP
IP- . -
, ARP. , -
ARP.
, 32- IP- 48 .


, , ARP -
.
ARP , ARP.
, IP / .
:

arp ip-address hardware-address IP- ARP

. .
arp ip-address hardware-address alias
ARP- IP-
:

arp timeout seconds ARP
show interfaces - ARP -
. Use show arp, ARP. -
. .

clear arp-cache ARP.


ARP
-ARP ( RFC 1027), -
, . , -
ARP , , , -
ARP . -
, ,
-ARP, . -

, . -ARP .
-ARP, -
:

ip proxy-arp ARP
Free ARP
. .

82
.466534.012-324
. . .
, IP- , -
ARP. IP- ARP
. - MAC- .
ARP . -
ARP, IP- IP-,
ARP , ARP -
IP-. , .
ARP . Free
ARP , .

arp send-gratuitous ARP
arp send-gratuitous interval value ARP -
; : 120 .
2. IP-
IP- , .
Telnet, Ping .
IP-,
:

ip host name address IP

18.1.3.4

. -
-. IP- , BGP, RIP OSPF, , -
.

18.1.3.5
-
. . -
, -
. IP
. ,

. .
IP -
. , . -
, .
1. -

IP- -
. "Deny of Service" IP-
. .

.
-
. ,
, ,
, .

. , IP- -
. .

-
.
IP, -
:

ip directed-broadcast [access-list-name]

2. UDP
UDP , -
. , , UDP -
, . , -
-
. .
UDP, , UDP
. .


.466534.012-324 83
. . .
. , UDP, -
NetBIOS ( 137).
,
:

ip helper-address address
UDP
, , -
:

ip forward-protocol udp [port] ,

18.1.3.6 IP-
, :
1. ,
, . -
, ,
.
, , EXEC,
:

clear arp-cache IP ARP
2.
, IP-
, . -
.
, .
.
" IP-". :


show arp ARP
,
show hosts ,

show ip interface [type number]
show ip route [protocol]
ping {host | address} (
)

. .
18.1.4 IP-
IP VLAN 11.
interface vlan 11
ip address 202.96.2.3 255.255.255.0
. .

18.2 NAT
18.2.1
, -
IP . NAT - , IP-
IP- , -
. , NAT -

-
. NAT ,
-
(CIDR). NAT RFC 1631.

18.2.1.1 NAT
(NAT) -
. .

84
.466534.012-324
. . .
:
, -
. NAT IP , -
IP , . NAT
( ) , -
( ). NAT -
IP .
. ,
, NAT.
TCP.
IP- IP- TCP.
, NAT -
-
. , IP
IP-, .
.

18.2.1.2 NAT
NAT ,
. , NAT ,
. -
, , IP-,
NAT. ( -
) NAT. NAT , , -
.
NAT
. NAT
. NAT -
, . NAT -
, .
, NAT . -
, ,
ICMP .
NAT .
, , NAT , ,
, .

18.2.1.3 NAT
, (inside) , -
. , -
; ,
NAT. , -
.
, (outside) , -
. .

. ,
/ -
.
, NAT :
: IP-, . ,
, IP- (NIC)
.
. .

IP- ( NIC ), -
IP .
: IP- .
, -
.
: IP-, .
.

18.2.1.4 NAT
NAT NAT -
. NAT : ,
. -
. -
, NAT- :
. .


.466534.012-324 85
. . .
TCP/UDP



PAT
, -
, , , .
show running NAT.

18.2.2 NAT
NAT, -
. , NAT -
:



TCP

NAT

18.2.3 NAT
18.2.3.1
, IP-
IP-. -
.
-
. -
, .

.
, -
.

18.2-1 NAT
. .
, .
1.1.1.1 B.
. .

, 1.1.1.1, -
NAT .
, 3.
,
(SA) 1.1.1.1. -
, , , , .
, -
1.1.1.1 .

B IP- (DA) 2.2.2.2,


1.1.1.1.
, -
NAT, IP-.
1.1.1.1
1.1.1.1.
1.1.1.1 . -
. .

86
.466534.012-324
. . .
.
1.
,
:

ip nat inside source static local-ip -
global-ip
interface type number
ip nat inside ,
interface type number
ip nat outside ,
. -
.
2.
, -
:

ip nat pool name start-ip end-ip netmask , -

ip access-list standard access-list-name
permit source [source-mask]
ip nat inside source list
access-list-name pool name ,

interface type number
ip nat inside ,
interface type number
ip nat outside ,
:
, . (-
, deny all .) ,
, .

"
" .

18.2.3.2
, -
. -
(, TCP UDP)
. -
. .

, TCP UDP -
.
NAT, -
.
. .

18.2-2 NAT
.
. .


.466534.012-324 87
. . .
B C , 2.2.2.2. -
, . ,
IP- .
1.1.1.1 B.
, 1.1.1.1,
NAT. , , -
1.1.1.1
1.1.1.1 . , -
. -
, . -
.
,
1.1.1.1 .
B 1.1.1.1, IP-
2.2.2.2.
IP-, -
NAT, , ,
, -
1.1.1.1 1.1.1.1.
1.1.1.1 . -
.
overloadeding ,
:

ip nat pool name start-ip end-ip netmask , -

ip access-list standard access-list-name
permit source [source-mask]

ip nat inside source list


access-list-name pool name overload ,

interface type number
ip nat inside ,
interface type number
ip nat outside ,


:
, . (-
, deny all .) ,
, .

.

18.2.3.3

. .
, -
, . , NAT -
.
. .

18.2-3 NAT
. .

88
.466534.012-324
. . .
, :
1.1.1.1 C, -
, DNS.
DNS- C 1.1.1.1. DNS -
.
1.1.1.1 3.3.3.3.
.
,
.
IP- , 1.1.1.1 C, -
3.3.3.3.
, ,
.
C .
1.
, -
:

ip nat outside source static global-ip -
local-ip
interface type number
ip nat inside

interface type number
ip nat outside ,
2.
,
:

ip nat pool name start-ip end-ip netmask

ip access-list standard access-list-name

permit source [source-mask]


ip nat outside source list -
access-list-name pool name ,

interface type number
ip nat inside ,
interface type number
ip nat outside ,
. .

:
, . (-
, deny all .) ,
, .
-
.
. .

18.2.3.4 TCP
NAT -. -
, . -
NAT , -
. , ,
. ,
.

( ). -
.
. .


.466534.012-324 89
. . .
18.2-4 NAT TCP
, :
B (9.6.7.3)
1.1.1.127.
,
(1.1.1.1) IP-.

.
1.1.1.1 .
NAT ,
, .
.
1.1.1.2
. ,


.
. TCP -
.

ip nat pool name start-ip end-ip netmask ,

ip access-list standard access-list-name
permit source [source-mask]

. .
ip nat inside destination list access-
list-name pool name , ,

interface type number
ip nat inside ,
interface type number
. .

ip nat outside ,
:
, . (-
, deny all .) ,
, .
TCP -
.

18.2.3.5
, , -
. , . -
, 1 . ,
:
. .

90
.466534.012-324
. . .

ip nat translation timeout seconds

, ,
. , -
.

ip nat translation udp-timeout seconds UPD ( 5 )
ip nat translation dns-timeout seconds DNS ( 1 )
ip nat translation tcp-timeout seconds - TCP ( 1 )
ip nat translation icmp-timeout seconds NAT ICMP ( 60 )
ip nat translation syn-timeout seconds NAT TCP SYN ( 60 -
)
ip nat translation finrst-timeout seconds TCP FIN RST ( 1 -
)
NAT.
:

ip nat translation max-entries numbers NAT (
4000)
ip nat translation max-links A.B.C.D num- IP-,
ber NAT
IP-
IP-, -
ip nat translation max-links all numbers NAT
IP-;
Max-

18.2.3.6 NAT
-
NAT . .

clear ip nat translation *


NAT
clear ip nat translation inside local-ip ,
global-p [outside local-ip global-p]

clear ip nat translation outside local-ip , -
global-ip
clear ip nat translation inside local-ip
. .

local-port global-ip global-port [outside


local-ip local-port global-ip global-
port]
, -
:

. .

show ip nat translations [verbose]


show ip nat statistics

18.2.4 NAT
NAT.

18.2.4.1

, 1
(192.168.1.0/24), Net-208. NAT
171.69.233.208 171.69.233.233.
ip nat pool net-208 171.69.233.208 171.69.233.233 255.255.255.240
ip nat inside source list a1 pool net-208
!
interface vlan10
ip address 171.69.232.182 255.255.255.240
. .


.466534.012-324 91
. . .
ip nat outside
!
interface vlan11
ip address 192.168.1.94 255.255.255.0
ip nat inside
!
ip access-list standard a1
permit 192.168.1.0 255.255.255.0
!

18.2.4.2
net-208, 171.69.233.208 171.69.233.233.
1 192.168.1.0 192.168.1.255. -
, 1
. ( 192.168.1.0 192.168.1.255),
. ,
.
ip nat pool net-208 171.69.233.208 171.69.233.233 255.255.255.240
ip nat inside source list a1 pool net-208 overload
!
interface vlan10
ip address 171.69.232.182 255.255.255.240
ip nat outside
!
interface vlan11
ip address 192.168.1.94 255.255.255.0
ip nat inside
!
ip access-list standard a1
permit 192.168.1.0 255.255.255.0
!

18.2.4.3
, -
. , .
Net-10 IP-. ip nat outside source list 1 pool
net-10 .


ip nat pool net-208 171.69.233.208 171.69.233.223 255.2555.255.240
ip nat pool net-10 10.0.1.0 10.0.1.255 255.255.255.0
ip nat inside source list a1 pool net-208
ip nat outside source list a1 pool net-10
!
interface vlan10
ip address 171.69.232.192 255.255.255.240
ip nat outside
!

. .
interface vlan11
ip address 192.168.1.94 255.255.255.0
ip nat inside
!
ip access-list standard a1
permit 192.168.1.0 255.255.255.0
!
. .

18.2.4.4 TCP
, , -
. .
. 1/0 ( -
) TCP .
ip nat pool real-hosts 192.168.15.2 192.168.15.15 255.255.255.240

ip nat inside destination list a2 pool real-hosts


!
interface vlan10
ip address 192.168.15.129 255.255.255.240
ip nat outside
!
interface vlan11
ip address 192.168.15.17 255.255.255.240
. .

92
.466534.012-324
. . .
ip nat inside
!
ip access-list standard a2
permit 192.168.15.1 255.255.255.0

18.3 DHCP
18.3.1
(DHCP (Dynamic Host Configuration Protocol)) -
, IP- ,
TCP/IP. DHCP RFC 2131. DHCP -
IP- . DHCP IP-:

DHCP- IP- . -

DHCP- IP-
.

DHCP- IP- DHCP
.

18.3.1.1 DHCP
DHCP. DHCP .
DHCP IP-, -
(, ) -
Ethernet.
, DHCP, DHCP -
, IP DHCP -
.

18.3.1.2 DHCP
, DHCP -
Ethernet. :


IP DHCP -

18.3.1.3 DHCP
DHCP /, , DHCP- DHCP-
DHCP .
. .

DHCP-
(, IP-, -
..) DHCP.
DHCP-
IP- DHCP- -
.
, -
. .

DHCP.
- , , -
IP-. IP- DHCP-
. ,
DHCP- .

18.3.2 DHCP-

18.3.2.1 DHCP-
IP-
DHCP-
DHCP
DHCP
. .


.466534.012-324 93
. . .
18.3.2.2 DHCP-
1. IP-
IP- DHCP. -
VLAN.

ip address dhcp IP- Ethernet DHCP
2. DHCP-
DHCP- , ,
. -
:

ip dhcp-server ip-address IP- DHCP
get an IP address.
3. DHCP
, DHCP . -
.

ip dhcp client minlease seconds
ip dhcp client retransmit count
ip dhcp client select seconds SELECT
, , get an IP ad-
dress.
4. DHCP
DHCP- ( ),
, . -
:

Show dhcp server DHCP-, -

DHCP-, , -


. :

Show dhcp lease IP- , -

, show interface : IP-
Ethernet DHCP IP-
Ethernet.

. .
18.3.2.3 DHCP-
NAT. IP-
IP Ethernet 1/1
DHCP.
interface vlan 11 ip address dhcp
. .

18.3.3 DHCP-
18.3.3.1 DHCP
DHCP-
DHCP-
ICMP

DHCP-

DHCP-
DHCP-
DHCP-

18.3.3.2 DHCP-
1. DHCP-
IP- DHCP- DHCP- -
. .

94
.466534.012-324
. . .
(DHCP- .
, , -
ip helper-address DHCP ):

ip dhcpd enable DHCP-
2. DHCP-
IP- DHCP-, DHCP-
, :

ip dhcpd disable DHCP-
3. ICMP
ICMP, -
.
ICMP , -
:

ip dhcpd ping packets pkgs ICMP

ICMP , -
:

ip dhcpd ping timeout timeout ICMP
4.
,
. :

ip dhcpd write-time time -

5. DHCP-
DHCP-, -

:

ip dhcpd pool name DHCP-
DHCP
6. DHCP-
DHCP, -
. , , -
. .

.

network ip-addr netsubnet

, ,
.
. .


range low-addr high-addr , -

DNS-, -


default-router ip-addr... , -

, -


dns-server ip-addr... DNS- .
. .


.466534.012-324 95
. . .

domain-name name ,
,


lease {days [hours][minutes] | infi- , -
nite}
NetBIOS,


netbios-name-server ip-addr... NetBIOS, -

, : IP-
, Mac- - " ".

hw-access deny hardware-address IP , Mac-
- " "
7.