Sie sind auf Seite 1von 91

AOS Training

OS9000 & OS6850 Products

Alcatel-Lucent - Enterprise Solutions Division

Agenda

Session 1
- Alcatel-Lucent Products Overview
- AOS Basic &

Session 2
- AOS L2 Training &

Session 3
- AOS L3 Training &

Session 4
- AOS Security Training, T.S &

Alcatel-Lucent - Enterprise Solutions Division 2

All Rights Reserved Alcatel-Lucent 2007

Session 1
Enterprise Business Group
NIBU

Agenda

Session 1
1) Alcatel-Lucent Products Overview
2) AOS Basic
- Switch
- Switch Booting
- Alcatel Operating System
- Hardware
- AOS Upgrade
- Switch
- SNMP
- DHCP
3)

Alcatel-Lucent - Enterprise Solutions Division 4

All Rights Reserved Alcatel-Lucent 2007

Alcatel-Lucent Products
Overview

Enterprise Business Group


NIBU

Alcatel EBG Product Portfolio


IP Networking
Core Layer/
Large Scale

Distributed Layer/
Medium Scale

Access Layer/
Small Scale

Router(WAN)

OmniStack 6200

OmniPCX Office

7750/7450
OmniSwitch
7800

OmniSwitch
6600/ 6602

OmniSwitch
6400

OmniSwitch
9800/9700
OmniSwitch
9600

OAW 6000s/SUP-III

OmniAccess 780

OmniSwitch
6855
OmniSwitch
7700

WLAN

VoIP

OAW4x04

OAW 4324/08/04
OmniPCX Enterprise

OmniAccess 740
OmniSwitch
6850/ 6850Lite

OmniAccess 720s

IP Phone

OAW-AP 4x/6x/70/12x/85

OmniVista 2500

Mobile


NAC

Brick Family

Vital Suite/QIP

Safeguard
Cybergatekeeper

Firewall/ VPN

Alcatel-Lucent - Enterprise Solutions Division 6

Performance Management

All Rights Reserved Alcatel-Lucent 2007

Quarantine Manager

NLG3500

AOS Training

OS9000 & OS6850 Products

Alcatel-Lucent - Enterprise Solutions Division

Agenda

Session 1
1) Alcatel-Lucent Products Overview
2) AOS Basic
- Switch
- Switch Booting
- Alcatel Operating System
- Hardware
- AOS Upgrade
- Switch
- SNMP
- DHCP
3)

Alcatel-Lucent - Enterprise Solutions Division 8

All Rights Reserved Alcatel-Lucent 2007

Part 1 : Switch

Switch
1. password

-> show system

User = admin
Password = switch
2. Switch system time timezone
->system timezone kst
->system time HH:MM:SS
->system time-and-date synchro
: CMM redundancy
->show system
3. Switch Reboot
->reload
->reload working no rollback-timeout
4. AAA - Web, telnet, ftp, etc.
->aaa authentication default local
5. Save configuration
->write memory

System:
Description: 6.1.1.645.R01 GA, February 02, 2006.,
Object ID: 1.3.6.1.4.1.6486.800.1.1.2.1.8.1.1,
Up Time:
1 Sessions 14 hours 6 minutes and 45 seconds,
Contact:
Alcatel Internetworking, www.alcatel.com/enterp
Name:
,
Location:
Unknown,
Services:
72,
Date & Time: WED MAR 14 2012 13:33:26 (GMT)
Flash Space:
Primary CMM:
Available (bytes): 79794176,
Comments
: None
Secondary CMM:
Available (bytes): 76961792,
Comments
: None

6.
-> copy working certified flash-synchro

Alcatel-Lucent - Enterprise Solutions Division 9

All Rights Reserved Alcatel-Lucent 2007

Part 1 : Switch

Switch AAA Authentication


1. AAA Authentication

-> show aaa authentication

- local
- Default console local
- aaa authentication denied login
id/pw

Service type = Default


1rst authentication server = local
Service type = Console
1rst authentication server = local
Service type = Telnet
Authentication = Use Default,
1rst authentication server = local
Service type = Ftp
Authentication = Use Default,
1rst authentication server = local
Service type = Http
Authentication = denied
Service type = Snmp
1rst authentication server = local
Service type = Ssh
Authentication = denied

2. AAA local
-> aaa authentication default local
3. AAA deny
-> no aaa authentication http

Alcatel-Lucent - Enterprise Solutions Division 10

All Rights Reserved Alcatel-Lucent 2007

Part 1 : Switch

Serial Connection Default Settings


baud rate

9600

parity

none

data bits (word size)

stop bits

Console Cable Pinouts

(OS9000, OS6800, OS6602)

( DB-9 to DB-9 Serial Cable)

Console Port

PC Com Port

DB-9(male)

DB-9(female)

Pins

Signals

DB9

RJ45

n/c

n/c

Pins

Signals

not used

not used

TXD

TXD

n/c

RXD

RXD

not used

not used

Ground

Ground

not used

not used

n/c

not used

not used

not used

not used

not used

not used

Alcatel-Lucent - Enterprise Solutions Division 11

Direction

DB-9 to RJ-45

All Rights Reserved Alcatel-Lucent 2007

Part 1 : Switch

Ethernet Cable Requirements


EMP to a Switch

Straightthrough

EMP to a Computer or
Workstation

Crossover

ENI Port to a Switch

Crossover

ENI Port to a Computer or


Workstation

Straightthrough

Component LEDs
CMM OK1

On

CMM OK2

CMM TEMP

On

CMM FAN

On

NI OK1

On

NI OK2

Power Supply AC OK

On

Power Supply DC OK

On

Power Supply OVER TEMP

Off

Alcatel-Lucent - Enterprise Solutions Division 12

All Rights Reserved Alcatel-Lucent 2007

Part 1 : Switch

CMM Module Status LEDs

- OK1 : Hardware Status.


- OK2: Software Status.
- CONTROL : Solid green Active, blinking green - standby
- FABRIC : solid green - active
- TEMP : green at 0-40C, blinking amber at 40-45C, and solid amber at over 45C.
- FAN : Solid green All fan tray OK
- PSU : Solid green power OK
- LINK : EMP port Link/Activity Status

Alcatel-Lucent - Enterprise Solutions Division 13

All Rights Reserved Alcatel-Lucent 2007

Part 2 : Switch Booting

Directory
1. OS9000 128MB flash Memory /flash /working, /certified directory
Image rollback .
(OS8800,OS7000, OS6600 : 32M OS6800 : 64M flash memory)
2. /flash/working /flash/certified , directory
Switch /flash/working
3. Booting /flash/working /flash/certified , /flash/certified
.
4. Switch /flash/working directory , write memory /flash
/working/boot.cfg .

Directory

Alcatel-Lucent - Enterprise Solutions Division 14

All Rights Reserved Alcatel-Lucent 2007

Part 2 : Switch Booting

Directory

-> show running-directory


CONFIGURATION STATUS
Running CMM
: PRIMARY,
CMM Mode
: DUAL CMMs,
Current CMM Slot
: A,
Running configuration : WORKING,
Certify/Restore Status : CERTIFIED
SYNCHRONIZATION STATUS
Flash Between CMMs
: SYNCHRONIZED,
Running Configuration : SYNCHRONIZED,
NIs Reload On Takeover : NONE

Configuration

-> show running-directory


CONFIGURATION STATUS
Running CMM
: PRIMARY,
CMM Mode
: DUAL CMMs,
Current CMM Slot
: A,
Running configuration : WORKING,
Certify/Restore Status : CERTIFY NEEDED
SYNCHRONIZATION STATUS
Flash Between CMMs
: NOT SYNCHRONIZED,
Running Configuration : SYNCHRONIZED,
NIs Reload On Takeover : ALL Nis (RUNNING
Directories OUT-OF-SYNC)

/flash/working boot.cfg reload .


-> reload working no rollback-timeout

CMM
Working directory certified directory
-> copy working certified
Primary CMM Secondary CMM
-> copy working certified flash-synchro

Alcatel-Lucent - Enterprise Solutions Division 15

All Rights Reserved Alcatel-Lucent 2007

Part 3 : Alcatel operating system


- Switch SNMP, CLI, Webview 3 CLI .

CLI help
-

CLI Line Editor & History


-

? .
vlan ? .
po? po .
<TAB> .

!! .
.
show history List .
!# (# = command number) .

Directory Structure
- Switch Unix command .
pwd show current directory.
cd change directory.
mkdir create a new directory.
ls list contents of a directory.
mv move a file.

rls /flash SecCMM list

cp copy a file.

rcp /flash/file name /flash/file name

rm remove a file.

SecCMM file PriCMM copy

Alcatel-Lucent - Enterprise Solutions Division 16

All Rights Reserved Alcatel-Lucent 2007

Part 3 : Alcatel operating system

Configuration Basic
- Omniswitch Configuration 3 version . Working, Certified, Running
version .
- Switch boot parameter working certified directory .
- Directory Configuration Running Configuration .

Running Configuration
- vlan 2 , vlan 3 , vlan 4 vlan Running Configuration .
- . .
- reload working no rollback-timeout reboot show vlan vlan
. Running Configuration flash memory .

Working Directory
- vlan 2 , vlan 3 , vlan 4 configuration snapshot all snap1 Running
Configuration snap1 ascii file .
- write memory Running Configuration Working Directory boot.cfg .
copy running-config working .
- cp snap1 /flash/working/boot.cfg Running Configuration file boot.cfg
.

Alcatel-Lucent - Enterprise Solutions Division 17

All Rights Reserved Alcatel-Lucent 2007

Part 3 : Alcatel operating system


Certified Directory
- reload reboot Switch certified directory .
- certified directory Certified .
- Certified . Running directory working
Directory write memory .
- Running directory working directory reload working no rollback-time
Working directory copy working certified Directory .
- certified copy certified working

Configuration Snapshot
- show configuration snapshot all Snapshot Current running configuration
.
- configuration snapshot all snapall snapall file configuration snapall
file view vi .

Alcatel-Lucent - Enterprise Solutions Division 18

All Rights Reserved Alcatel-Lucent 2007

Part 4 : Hardware

Gathering Switch Information


- show hardware info : Information on CPU, Memory, Miniboot.
- show microcode : Code descriptions and versions.
- show microcode history : List of upgrade path.
- show chassis : Chassis type and part numbers.
- show cmm : Processor and fabric board information.
- show ni : Networking interface information.
- show power : Power supply information.
- show fan : Fan Information.
- show temperature : Temperature and temperature threshold.

CMM Redundancy
- show cmm
- reload secondary
- reload primary
- Primary CMM failover Packet .
- copy flash-synchro Primary CMM Working, Certified directory Secondary CMM Working,
Certified directory .

Alcatel-Lucent - Enterprise Solutions Division 19

All Rights Reserved Alcatel-Lucent 2007

Part 4 : Hardware

Ethernet Port Configuration


- Show interfaces slot/port : Tells whether the port is active or not.
- Interfaces slot/port duplex [half,full,auto] : Sets the duplex mode.
- Interfaces slot/port speed [10,100,1000,auto] : Sets the speed.
- Interfaces slot/port admin [up,down] : enable or disable a port.
- Show interfaces slot/port accounting : gather frame statistics.
- Show interfaces slot/port counters : gather error and frame counts.
- interfaces slot/port no l2 statistics : interface count clear.

Hot swap / Reset


- Module Hot swap .

Ni Power
- no power ni [slot #] : NI module power down.
- power ni [slot #] : NI module power restore.

Alcatel-Lucent - Enterprise Solutions Division 20

All Rights Reserved Alcatel-Lucent 2007

Part 5 : AOS Upgrade

AOS Upgarde
- Ominswitch zmodem ftp switch Image .
- Ftp EMP port IP NI .
- Version .
-> show microcode loaded
-> show microcode working
-> show microcode certified
- show microcode working .
-> show microcode working
Package

Release

Size

Description

---------+--------------+--------+----------------------------------Jbase.img

6.1.1.534.R01 10927002

Alcatel Base Software

Jos.img

6.1.1.534.R01

1843725

Alcatel OS

Jadvrout.img

6.1.1.533.R01

1383444

Alcatel Advanced Routing

Jeni.img

6.1.1.534.R01

3625441

Alcatel NI software

Alcatel-Lucent - Enterprise Solutions Division 21

All Rights Reserved Alcatel-Lucent 2007

Part 5 : AOS Upgrade

Omniswitch OS9000 image .


- OS9000(Fuji) Jos.img OS8800(Eagle) Eos.Img, OS7000(Falcon) Fos.img
OS6600(Hawk) Hos.img, OS6800(Kite) Kos.img

Alcatel-Lucent - Enterprise Solutions Division 22

All Rights Reserved Alcatel-Lucent 2007

Part 5 : AOS Upgrade

EMP Port Parameter


- EMP Port Default IP Address 192.168.1.1 / 255.255.255.0 .
- Vlan router ip EMP IP Address IP .
- EMP Port IP .
modify boot parameters : modify boot parameter menu .
boot empipaddr 10.1.1.1 : EMP IP address
boot empnetmask ffffff00 : Mask
Show :
commit system : Running system
commit file : NVRAM reboot .
Exit : System prompt .
- IP PC EMP Port crossover cable .
- EMP PC ACL Policy .

Alcatel-Lucent - Enterprise Solutions Division 23

All Rights Reserved Alcatel-Lucent 2007

Part 5 : AOS Upgrade

Console / zmodem
- Switch Console PC cd Directory .
- Prompt rz PC Terminal Program zmodem file .
- zmodem FTP Image .

AOS upgrade
- FTP upgrade (EMP )
- upgrade
-> show system : version
-> cd working : working directory
-> ls : file
-> rm *.img : image , boot.cfg
PC switch ftp , binary /flash/ working
-> reload working no rollback-timeout : working directory reload
-> install *.img : image install
-> copy working certified : version
-> copy flash-synchro : CMM

DOS Commands : Bin, hash, prompt, mput *.img

Alcatel-Lucent - Enterprise Solutions Division 24

All Rights Reserved Alcatel-Lucent 2007

Part 6 : Switch

Switch Login
- show user Switch .
- admin, default default
Switch Permission .
Full

-> show user


Read/Write
User name = admin
Permission
Read right
= 0xffffffff 0xffffffff,
Write right
= 0xffffffff 0xffffffff,
Read for domains = All ,
Write for domains = All ,
Snmp not allowed
No
Read/Write
Permission

User name = default


Read right
= 0x00000000 0x00000000,
Write right
= 0x00000000 0x00000000,
Read for domains = None ,
Write for domains = None ,
Snmp authentication = NONE, Snmp encryption = NONE

Alcatel-Lucent - Enterprise Solutions Division 25

All Rights Reserved Alcatel-Lucent 2007

Part 6 : Switch
- .
-> user userread password 123456 read-only all : Read User userread
-> user userwrite password 123456 read-write all : Read-write User userwrite

Partition Management
- Partition Management User Access .
-> user userread read-only domain-layer2 : User userread Layer2 Read .
-> user userwrite read-write vlan : User userwrite Vlan Read-write .
-> user userwrite read-write ? : Option ? Option .

Authenticated Switch Access


- ASA Switch .
- Switch Longin RADIUS, LDAP, ACE- Local database remote database
.
- ASA Telnet, FTP, SNMP, SSH, HTTP, console modem port .
- show aaa authentication : Switch internal database authentication
- no aaa authentication telnet : Telnet access disable

Alcatel-Lucent - Enterprise Solutions Division 26

All Rights Reserved Alcatel-Lucent 2007

Switch file

rm userTable# reload Switch Default .

-> cd network
-> ls
Listing Directory /flash/network:
drw
drw
-rw
-rw
-rw
-rw
-rw

2048 Nov 28 2007 ./


2048 Jan 16 23:07 ../
23040 Dec 14 2007 userTable4
29 May 16 2006 policy.cfg
32 May 16 2006 qos.cfg
404 May 16 2006 ssh_host_dsa_key
359 May 16 2006 ssh_host_dsa_key.pub
26277888 bytes free

Alcatel-Lucent - Enterprise Solutions Division 27

All Rights Reserved Alcatel-Lucent 2007

Part 7 : SNMP

SNMP Configuration
-> aaa authentication snmp "local"
: SNMP access
-> snmp security no security
: security level command
BOP all SNMP(v1, v2, v3)
-> snmp community map mode enable
: access local user database enable
-> user "a12345" read-write all password "a1234567" no auth
: SNMP query read-write
-> snmp community map "public" user "a12345" on
: snmp community map
-> snmp station 156.146.93.100 162 "a12345" v3 enable
: account snmp station
-> snmp trap absorption enable
: trap table activity
-> snmp trap to webview enable
: Webview trap

Alcatel-Lucent - Enterprise Solutions Division 28

All Rights Reserved Alcatel-Lucent 2007

Part 8 : DHCP DHCP Relay


- DHCP relay Switch DHCP request DHCP Server

DHCP Relay
- IP helper standard mode : DHCP
-> ip helper address 10.10.10.10
- IP helper per VLAN mode : VLAN DHCP
-> ip helper per-vlan only
-> ip helper address 10.10.20.20 vlan 10
9800#1> show ip helper
Ip helper :
Forward Delay(seconds) = 3,
Max number of hops = 4,
Traffic Suppression
= Disabled,
DHCP Snooping Status
= Switch-Level Enabled,
Option 82 Data Insertion Per Switch = Enabled,
MAC Address Verification Per Switch = Enabled,
DHCP Snooping Binding DB Status = Enabled,
Database Sync Timeout
= 300,
Database Last Sync Time
= ,
Forward option
= per-vlan only
Bootup Option Disable
Forwarding Address :
Vlan Number 11
Forwarding Address :
10.10.10.10

Alcatel-Lucent - Enterprise Solutions Division 29

All Rights Reserved Alcatel-Lucent 2007

Part 8 : DHCP DHCP Snooping & ip-source-filtering

DHCP Snooping
- DHCP Server DHCP Server

IP-Source-filtering
- DHCP Static IP

Configuration Sample
- Per-vlan ip helper
- DHCP snooping vlan
- ip-source-filter port
- DHCP Server port Trust
ip helper per-vlan only
ip helper address 58.227.43.197 vlan 11
ip helper address 58.227.43.197 vlan 12
ip helper dhcp-snooping vlan 11
ip helper dhcp-snooping vlan 12
ip helper dhcp-snooping vlan 58
ip helper dhcp-snooping binding enable
ip helper dhcp-snooping port 2/1 ip-source-filter enable
ip helper dhcp-snooping port 2/2 ip-source-filter enable
ip helper dhcp-snooping port 2/3 ip-source-filter enable
ip helper dhcp-snooping port 2/4 ip-source-filter enable
ip helper dhcp-snooping port 2/24 trust

Alcatel-Lucent - Enterprise Solutions Division 30

All Rights Reserved Alcatel-Lucent 2007

Agenda

Session 1
1) Alcatel-Lucent Products Overview
2) AOS Basic
- Switch
- Switch Booting
- Alcatel Operating System
- Hardware
- AOS Upgrade
- Switch
- SNMP
- DHCP
3)

Alcatel-Lucent - Enterprise Solutions Division 31

All Rights Reserved Alcatel-Lucent 2007

LAB - Basic

AOS upgrade

Alcatel-Lucent - Enterprise Solutions Division 32

All Rights Reserved Alcatel-Lucent 2007

Session 2
Enterprise Business Group
NIBU

Agenda

Session 2
1) AOS L2 Training
- VLAN
- 802.1Q
- STP
- Link Aggregation
- VRRP
2)

Alcatel-Lucent - Enterprise Solutions Division 34

All Rights Reserved Alcatel-Lucent 2007

Part 1 : VLAN

Vlan Configuration
- Default vlan1 port vlan1

-> show vlan port

- ' show vlan ' : Vlan basic information

vlan port

-> show vlan


vlan admin oper stree auth ip ipx name
----+-----+----+-----+----+--+---+----1

on

on

on

- ' show vlan port ' : Vlan assign port list

off off off VLAN 1

type

status

----+-----+----+------1

2/1

default forwarding

2/2

default inactive

2/3

default inactive

:
:

- ' show vlan 1 ' : Vlan 1 information

-> show vlan 1


Name

: VLAN 1,

-> vlan 2

Operational State : enabled,

- vlan port assign (untag frame)

Spanning Tree State : enabled,


: disabled,

IP Router Port

: none,

IPX Router Port

: none

Alcatel-Lucent - Enterprise Solutions Division 35

default inactive

- vlan

Administrative State: enabled,

Authentication

2/24

-> vlan 2 port default slot/port-port


- vlan port assign port
-> vlan 2 no port default slot/port
All Rights Reserved Alcatel-Lucent 2007

Part 1 : VLAN

Vlan IP Configuration
- Multi-netting

- vlan port assign

- vlan ip interface

-> vlan 10 port default slot/port

- vlan
-> vlan 10

- Ip interface
-> no ip interface [name]

- vlan ip
-> ip interface vlan-10 address 10.10.10.1/24 vlan 10
: vlan10 name ip vlan10
- vlan ip
-> ip interface vlan-11 address 10.10.11.1/24 vlan 10
-> ip interface vlan-12 address 10.10.12.1/24 vlan 10
- vlan ip
-> show ip interface
Total 9 interfaces
Name
IP Address
Subnet Mask Status Forward
-----------+-------------+-------- ---+-----+------+-------EMP
192.168.1.1
255.255.255.0 DOWN NO
Loopback
127.0.0.1
255.0.0.0
UP
NO
vlan-10
10.10.10.1
255.255.255.0 DOWN NO
vlan-11
10.10.11.1
255.255.255.0 DOWN NO
vlan-12
10.10.12.1
255.255.255.0 DOWN NO
Alcatel-Lucent - Enterprise Solutions Division 36

Device
EMP
Loopback
vlan 10
vlan 10
vlan 10

All Rights Reserved Alcatel-Lucent 2007

Part 1 : VLAN

Group Mobility

- Group Mobility port Vlan Assign

- show vlan port G.M type

default vlan

mobile mobile port

Network Vlan Dynamic

Vlan .
-> show vlan port

vlan port

- IP Network

type

status

---+-----+------+-------

.
- Port mobile port

3/1

default forwarding

-> vlan port mobile slot/port

3/2

default

inactive

-> show vlan port mobile 2/24

9/3

mobile

forwarding

-> show vlan port mobile 2/24

9/3

mobile

forwarding

Mobility

9/5

mobile

forwarding

: on,

Dynamic Default Vlan: 0,

- Network Rule

Config Default Vlan: 2,

-> vlan 2 ip 192.168.10.0 255.255.255.0

Default Vlan Enabled: on,

-> show vlan rule

Default Vlan Perm : off,

Legend: type: * = binding rule

Default Vlan Restore: on,


Authentication

: off,

Ignore BPDUs

: off

Alcatel-Lucent - Enterprise Solutions Division 37

type

vlan

rule

---------+------+---------------------ip-net
All Rights Reserved Alcatel-Lucent 2007

192.168.11.0, 255.255.255.0

Part 1 : VLAN
- vlan port mobile 1/1 bpdu ignore enable
: bpdu ignore

- vlan port 9/1 default vlan restore disable


: mobile port Switch

Alcatel-Lucent - Enterprise Solutions Division 38

All Rights Reserved Alcatel-Lucent 2007

Part 2 : 802.1q
- 802.1q Link Multiple broadcast domain(Tag frame) Vlan
.
- Switch Vlan .

802.1q
-> vlan 4 802.1q 3/4 : vlan 4 3/4
-> vlan 50 no 802.1q 3/1 : 802.1q
-> show vlan port : type qtagged
-> Switch .
-> show vlan port : Vlan port type qtagged .
vlan

port

type

status

----+-------+---------+-----50
203

3/1

qtagged

1/21

default

forwarding
inactive

-> 802.1q Network STP .

Alcatel-Lucent - Enterprise Solutions Division 39

All Rights Reserved Alcatel-Lucent 2007

Part 3 : Spanning Tree

Spanning Tree Protocol


- Default Multiple STP enable
- 802.1D 802.1W(fast spantree), 802.1s
->
->
->
->
->
->
->

bridge mode 1x1 : Multiple STP


bridge mode FLAT : Single STP
bridge 101 priority 1 : root bridge
bridge 101 protocol 1d : Default
bridge 101 protocol 1w : 802.1w
bridge 101 1/1 path cost 100 : path cost
show spantree

- Default path cost


: 10Gbps = 2
: 1Gbps = 4
: 100Mbps = 19
: 10Mbps = 100
-> show vlan port
vlan port type
status
----+----+------+-----10 1/2 default forwarding
10 2/1 default blocking

Alcatel-Lucent - Enterprise Solutions Division 40

-> show spantree 10


Spanning Tree Parameters for Vlan 10
Spanning Tree Status :
ON,
Protocol
:
IEEE 802.1D,
mode
: 1X1 (1 STP per Vlan),
Priority
:
32768 (0x0001),
Bridge ID
:
0001-00:d0:95:8e:46:a2,
Designated Root
: 0001-00:d0:95:4d:02:84,
Cost to Root Bridge :
4,
Root Port
:
1/1,
Next Best Root Cost :
23,
Next Best Root Port :
1/24,
Hold Time
:
1,
Topology Changes
:
21,
Topology age
:
3:35:54
Current Parameters (seconds)
Max Age
= 20,
Forward Delay
= 15,
Hello Time
=
2
Parameters system uses when attempting to become
root
System Max Age
= 20,
System Forward Delay = 15,
System Hello Time =
2

All Rights Reserved Alcatel-Lucent 2007

Part 4 : Link Aggregation


- Link Aggregation Bandwidth takeover .
- Omni switch Link Aggregation Omnichannel(static) LACP(802.3ad) .

Link Aggregation Static


-> static linkagg 1 size 2 admin state enable : linkagg ID 1 port 2 Aggregation .
-> static agg 1/1 agg num 1 : 1/1 1/2 Aggregation . Switch 0/1 Port .
-> static agg 1/2 agg num 1
-> vlan 2 port default 1 : Linkagg port vlan
-> show linkagg
-> show linkagg 5
-> show linkagg port
-> static agg no 1/1 : linkagg port
-> no static linkagg 1 : linkagg group

Link Aggregation Dynamic


-> lacp linkagg 1 size 2 actor admin key 1
-> lacp agg 1/1 actor admin key 1
-> lacp agg 1/2 actor admin key 1
-> vlan 2 port default 1

Alcatel-Lucent - Enterprise Solutions Division 41

All Rights Reserved Alcatel-Lucent 2007

Part 5 : VRRP

VRRP
- Active switch .
-> vrrp 1 200 : Vrrp ID,Van ID
-> vrrp 1 200 ip 200.200.200.1 : Virtual IP
-> vrrp 1 200 priority 200 : Priority VRRP Master .
-> vrrp 1 200 enable : VRRP enable
-> show vrrp 1 : VRRP
-> show vrrp statistics
- Backup switch .
-> vrrp 1 200 : Vrrp ID,Van ID
-> vrrp 1 200 ip 200.200.200.1 : Virtual IP
-> vrrp 1 200 priority 100 : Priority VRRP Backup .
-> vrrp 1 200 enable : VRRP enable

Alcatel-Lucent - Enterprise Solutions Division 42

All Rights Reserved Alcatel-Lucent 2007

Agenda

Session 2
1) AOS L2 Training
- VLAN
- 802.1Q
- STP
- Link Aggregation
- VRRP
2)

Alcatel-Lucent - Enterprise Solutions Division 43

All Rights Reserved Alcatel-Lucent 2007

LAB L2

vlan 10
10.10.10.
1/24

Backbone
#1

vlan 20
10.10.20.
2/24

Backbone
#2
vlan 10
10.10.10.
2/24

Linkagg
2 port

vlan 20
10.10.20.
1/24

802.1q
Vlan10,20
VRRP
10.10.10.254
10.10.20.254

LAB

1) Backbone#1 Backbone#2 Link aggregation


Bandwidth .
2) Vlan 10, 20 Switch .
3) Vlan 10, 20 VRRP Gateway Backup .

802.1q
Vlan10,20

802.1q
Vlan10,20

4) Workgroup Traffic Backbone#1,2 .


5) STP 802.1w(RSTP) .

vlan 10
10.10.10.
3/24

Workgroup

vlan 20
10.10.20.
3/24

6) Backbone#1 Power Down VRRP .

LAB - 1
Alcatel-Lucent - Enterprise Solutions Division 44

All Rights Reserved Alcatel-Lucent 2007

Session 3
Enterprise Business Group
NIBU

Agenda

Session 3
1) AOS L3 Training
- Static Routing
- RIP
- OSPF
2)

Alcatel-Lucent - Enterprise Solutions Division 46

All Rights Reserved Alcatel-Lucent 2007

Part 1 : Routing Protocol

Static Routing
- Static Routing .
-> ip static-route 192.168.10.0 mask 255.255.255.0 gateway 10.10.10.1
- Default gateway .
-> ip static-route 0.0.0.0 mask 0.0.0.0 gateway 203.229.229.1
- Routing table .
: Protocol NETMGMT static routing .
-> show ip route
+ = Equal cost multipath routes
Total 7 routes
Dest Address
Subnet Mask
Gateway Addr
------------------+--------+-------------+---------+----------0.0.0.0
0.0.0.0
203.229.229.1
10.10.10.0
255.255.255.0 10.10.10.2
127.1.0.0
255.255.0.0
127.1.65.0
192.168.10.0
255.255.255.0 10.10.10.1

Alcatel-Lucent - Enterprise Solutions Division 47

Age

Protocol

16:32:51 NETMGMT
4d22h
LOCAL
6d 1h
LOCAL
00:00:02 NETMGMT

All Rights Reserved Alcatel-Lucent 2007

Part 2 : Routing Protocol - RIP

Dynamic Routing RIP


- Omniswitch RIP V1 RIP V2 .
-> ip load rip : RIP Demon load .
-> ip rip interface 104.2.71.4 : RIP Interface
-> ip rip interface 104.2.71.4 status enable : RIP Interface Status enable
-> ip rip interface 10.10.10.1 send-version v1(v2) : RIP Send Version
-> ip rip interface 10.10.10.1 recv-version v1(v2) : RIP Receive Version
-> ip rip redist LOCAL : Local Network Redist
-> ip rip redist STATIC : Static Network Redist
-> ip rip redist-filter LOCAL 0.0.0.0 0.0.0.0 : Local Network Redist
-> ip rip redist-filter STATIC 0.0.0.0 0.0.0.0 : Static Network Redist
-> ip rip status enable : RIP Status enable
-> ip rip redist status enable : RIP Redist Status enable

Alcatel-Lucent - Enterprise Solutions Division 48

All Rights Reserved Alcatel-Lucent 2007

Part 2 : Routing Protocol - RIP


-> show ip route : Protocol Rip
+ = Equal cost multipath routes
Total 70 routes
Dest Address

Subnet Mask

Gateway Addr

Age

Protocol

-------------+---------------+-----------------+--------+----------0.0.0.0

0.0.0.0

166.104.192.254

00:14:15 NETMGMT

127.0.0.1

255.255.255.255

127.0.0.1

166.104.0.6

255.255.255.255

166.104.192.252

00:14:10

RIP

166.104.192.8

00:12:10

RIP

166.104.184.0

255.255.255.0

00:15:50

LOCAL

-> show ip rip interface : RIP Interface


-> show ip rip route : RIP Route

Alcatel-Lucent - Enterprise Solutions Division 49

All Rights Reserved Alcatel-Lucent 2007

Part 3 : Routing Protocol - OSPF


- OSPF Routing .
-> ip router router-id 200.200.200.200 : Router ID DR .
-> ip load ospf : OSPF Demon enable
-> ip ospf area 0.0.0.0 : OSPF area ID
-> ip ospf interface vlan-name : ospf interface
-> ip ospf interface vlan-name area 0.0.0.0 : Interface OSPF area
-> ip ospf interface vlan-name status enable : ospf interface status eable
-> ip ospf asbr : asbr (redist router )
-> ip ospf status enable

Alcatel-Lucent - Enterprise Solutions Division 50

All Rights Reserved Alcatel-Lucent 2007

Part 3 : Routing Protocol - OSPF


- OSPF Redist .
- AOS 6.1.1 Version
-> ip ospf redist LOCAL : Local Network redist
-> ip ospf redist STATIC : Static Network Redist
-> ip ospf redist-filter LOCAL 0.0.0.0 0.0.0.0 : Local Network Redist
-> ip ospf redist-filter STATIC 0.0.0.0 0.0.0.0 : Static Network Redist
-> ip ospf redist status enable
- AOS 6.1.3 Version
-> ip route-map ospf_local sequence-number 50 action permit
-> ip route-map ospf_local sequence-number 50 match ip-address 0.0.0.0/0 redist-control all-subnets
permit
-> ip route-map ospf_static sequence-number 50 action permit
-> ip route-map ospf_static sequence-number 50 match ip-address 0.0.0.0/0 redist-control
all-subnets permit
-> ip redist local into ospf route-map ospf_local status enable
-> ip redist static into ospf route-map ospf_static status enable

Alcatel-Lucent - Enterprise Solutions Division 51

All Rights Reserved Alcatel-Lucent 2007

Part 3 : Routing Protocol - OSPF


-> show ip route : ECMP
+ = Equal cost multipath routes
Total 26 routes
Dest Address

Subnet Mask

Gateway Addr

Age

Protocol

-------------+----------- -+-------------+------+----------158.44.3.0
158.44.4.0

255.255.255.0
255.255.255.0

+158.44.4.4

1d23h OSPF

+158.44.9.1

1d23h OSPF

158.44.4.1

1d23h LOCAL

-> show ip ospf interface : DR BDR


show ip ospf interface
IP
DR
Backup DR
Admin Oper
Address
Address
Address
Vlan Status
Status State
------------+-------------+-------------+----+--------+------+------156.147.76.38 156.147.76.41 156.147.76.33 501 enabled
up DRother
156.147.76.70 156.147.76.65 156.147.76.73 502 enabled
up DRother
-> show ip ospf neighbor : Neighbor
IP Address
Area Id
Router Id
Vlan
State Mode
------------+----------+----------------+----+-------+-------156.147.76.33 0.0.0.0
200.200.200.200
501
Full
Slave
156.147.76.34 0.0.0.0
60.60.60.60
501
2way
Slave
Alcatel-Lucent - Enterprise Solutions Division 52

All Rights Reserved Alcatel-Lucent 2007

Agenda

Session 3
1) AOS L3 Training
- Static Routing
- RIP
- OSPF
2)

Alcatel-Lucent - Enterprise Solutions Division 53

All Rights Reserved Alcatel-Lucent 2007

LAB L3

vlan 60
10.10.60.
1/24
Workgroup
vlan 10
10.10.10.
1/24
vlan 10
10.10.10.
2/24

Backbone
#1

Area
0.0.0.0

vlan 30
10.10.30.
1/24

1) Backbone#1 Backbone#2 Link aggregation

vlan 20
10.10.20.
1
/24

Bandwidth .
vlan 20
10.10.20.
2/24

Linkagg
2 port

LAB

2) OSPF Network .
3) OSPF Area Backbone Area .

vlan 30
10.10.30.
2/24

Backbone
#2

4) Local Network Redistribution .


5) OSPF Interface / Neighbor .
5) Routing table .

vlan 40
10.10.40.
1/24

vlan 50
10.10.50.
1/24

LAB - 2
Alcatel-Lucent - Enterprise Solutions Division 54

All Rights Reserved Alcatel-Lucent 2007

Session 4
Enterprise Business Group
NIBU

Agenda

Session 4
1) AOS Security Training
- Switch Service Port
- Access Control List
- QoS
- Network Security
. AVLAN
. Access Guardian
. Binding Rule
- AQM
2) Operation & Trouble Shooting

Alcatel-Lucent - Enterprise Solutions Division 56

All Rights Reserved Alcatel-Lucent 2007

Part 1 : Service Port

Switch IP Service
1. IP Service

-> show ip service

- Switch Service port open


Name
Port Status

----------------------+-------+--------- aaa authentication deny
ftp
21 disabled

ssh
22 disabled

telnet
23 enabled
- Application Service port disable udp-relay
67 enabled

http
80 disabled
network-time
123 enabled
snmp
161
enabled
2. IP Service Disable
avlan-telnet
259 enabled
avlan-http
260
enabled
-> no ip service ssh
avlan-secure-http
261 enabled
secure-http
443 disabled
3. IP Service Enable
avlan-http-proxy
262 enabled
-> ip service ssh

Alcatel-Lucent - Enterprise Solutions Division 57

All Rights Reserved Alcatel-Lucent 2007

Part 2 : Access Control List


- ACL rule, action condition .
qos apply .
- qos config qos flush qos apply

Layer2 ACL
policy condition toMAC3 destination mac 00:00:00:00:00:03
policy action deny disposition drop
policy rule r1 condition toMAC3 action deny
qos apply

Layer3 ACL
policy condition fromIP1toIP3 source ip 10.0.0.100 destination ip 192.0.0.0 mask 255.0.0.0
policy action deny disposition deny
policy rule r1 condition fromIP1toIP3 action deny
qos apply

Layer4 ACL
policy service t445 destination tcp port 445
policy service t135 destination tcp port 135
policy service group tcp_group t445 t135
policy condition c1 service group tcp_group
policy action deny disposition deny
policy rule r1 condition c1 action deny
qos apply

Alcatel-Lucent - Enterprise Solutions Division 58

All Rights Reserved Alcatel-Lucent 2007

Part 2 : Access Control List

UserPorts Group Policy


- IP address spoofing
- Uplink & Rouing
- policy port group UserPorts 1/1-12
-> show ip traffic
Datagrams received
------------------------+-----------Total

9260274

IP header error

Destination IP error

:
:
Fragment failed

Fragments generated
Event

Source

0
Total

Last 1 seconds

---------------------------+-----------------------spoof

1/2

2538258

Alcatel-Lucent - Enterprise Solutions Division 59

1223

last mac 00:10:a4:97:d0:e8

All Rights Reserved Alcatel-Lucent 2007

Part 2 : Access Control List

ICMP Drop Rules


policy condition ping10 source vlan 10 ip protocol 1
policy action drop disposition drop
policy rule noping10 condition ping10 action drop
qos apply

Alcatel-Lucent - Enterprise Solutions Division 60

All Rights Reserved Alcatel-Lucent 2007

Part 2 : Access Control List

Switch Access Control Sample


- IP 10.10.10.100 IP Switch TCP 23,21,80
policy service t1 protocol 6 destination tcp port 23
policy service t2 protocol 6 destination tcp port 21
policy service t3 protocol 6 destination tcp port 80
policy service group g_1 t1 t2 t3
policy condition drop destination network group Switch service group g_1
policy condition ok_c1 source ip 10.10.10.100 destination network group Switch service group g_1
policy action accept disposition accept
policy action deny disposition deny
policy rule r1 precedence 100 condition ok_c1 action accept
policy rule drop condition drop action deny
qos apply

Alcatel-Lucent - Enterprise Solutions Division 61

All Rights Reserved Alcatel-Lucent 2007

Part 3 : QoS

ACL Condition, Action, Rule .

QoS Policies

Classification on L1/L2/L3/L4 (IPV6 support in future release)


Enqueuing in one of the 8 COS queues

Actions

Drop frames
Change queuing priority
Update TOS/Diffserv and/or 802.1P priority tags
802.1p/TOS/Diffserv marking
802.1p/TOS/Diffserv mapping
Per COS max bandwidth (64K bps)
Statistics (# of packets, # of bytes)
Ingress policing / Egress shaping
Multi-actions support

Alcatel-Lucent - Enterprise Solutions Division 62

All Rights Reserved Alcatel-Lucent 2007

Part 3 : QoS

QoS Sample
policy condition c_ip source ip 10.0.0.1
policy action a_ip tos 6
policy rule r_ip condition c_ip action a_ip
qos port 5/1 trusted
qos apply

Alcatel-Lucent - Enterprise Solutions Division 63

All Rights Reserved Alcatel-Lucent 2007

Part 4 : Network Security - AVLAN

Authentication VLAN
- Authentication Sever Network
.
- Group Mobility
Vlan Network .

- Network
- User Based Network Access Control
- Protocol -Telnet, HTTP, AV Client S/W
- -Windows 98/NT/ME/2000/XP
-
. Authentication Client (Client PC)
. Authentication Agent (Network Device)
. Authentication Server (LDAP/Radius server)
- Switch PC Network
-

Alcatel-Lucent - Enterprise Solutions Division 64

All Rights Reserved Alcatel-Lucent 2007

Part 4 : Network Security - AVLAN

AVLAN Sample Config


-

.
-> vlan 99 : Vlan
-> vlan 99 router ip 192.168.11.1 : Vlan 99 IP
-> VLAN 99 RADIUS server
-> vlan 2 : authentication VLAN
-> vlan 2 router ip 192.168.12.1 : Vlan 2 IP
-> vlan port mobile slot/port : Avlan port mobile port enable
-> vlan port slot/port authenticate enable : Avlan port Authenticated port

enable

-> vlan 2 authentication enable : Vlan 2 authenticated Vlan enable


-> aaa radius-server "rserver" host 200.5.1.100 key 43b85916020505fe retransmit 4 timeout 2
auth-port 1812 acct-port 1813 : Switch Radius server
-> aaa authentication vlan single-mode rad1 : Single mode Avlan
-> aaa accounting vlan rad1 : Accounting
-> Vlan 2 Network

Alcatel-Lucent - Enterprise Solutions Division 65

All Rights Reserved Alcatel-Lucent 2007

Part 4 : Network Security Access


Guardian

Access Guardian ?
- 802.1x Network
- 802.1x , Mac , Web
- Supplicant Non-supplicant user

Alcatel-Lucent - Enterprise Solutions Division 66

All Rights Reserved Alcatel-Lucent 2007

Part 4 : Network Security Access


Guardian

Access Guardian Sample Config


- mobile port & 802.1x enable
vlan port mobile 1/1
vlan port 1/1 802.1x enable
- 802.1x & Mac
aaa radius-server "rserver" host 192.168.1.111 key secret retransmit 4 timeout 2 auth-port 1812 acct-port 1813
aaa authentication 802.1x rserver
aaa authentication mac rserver
aaa accounting 802.1x rserver
- Device Authentication policy
802.1x 1/1 direction both port-control auto quiet-period 60 tx-period 30 supp-timeout 30 server-timeout 30 max-req 2
re-authperiod 3600 reauthentication
802.1x 1/1 supp-polling retry 2
802.1x 1/1 supplicant policy authentication pass group-mobility block fail block
802.1x 1/1 non-supplicant policy authentication pass group-mobility block fail block

Alcatel-Lucent - Enterprise Solutions Division 67

All Rights Reserved Alcatel-Lucent 2007

Part 4 : Network Security Binding


Rule

Binding Rule

- Network Rule Network .


- Rule : PORT-PROTOCOL, MAC-PORT-PROTOCOL, MAC-PORT,
- G.M .
- .
- MAC-port-IP Address
-> vlan 255 binding mac-ip-port 00:00:da:59:0c:12 21.0.0.10 2/3
-> vlan 255 no binding mac-ip-port 00:00:da:59:0c:12
- MAC-port
-> vlan 1500 binding mac-port 00:02:9a:3e:f1:06 6/10
-> vlan 1500 no binding mac-port 00:02:9a:3e:f1:06
- port-protocol
-> vlan 1503 binding port-protocol 3/1 ip-snap
-> vlan 1503 no binding port-protocol 3/1 ip-snap

Alcatel-Lucent - Enterprise Solutions Division 68

All Rights Reserved Alcatel-Lucent 2007

Part 5 : AQM
AQM ?

- (IPS, IDS, F/W)



- : IDP, Omnivista & Quarantine Manager, Alcatel-lucent Switch
- Omnivista Quarantine Manager

AQM Flow

Quarantine Engine
!!!

NMS
(OmniVista)

Attack detected !!!, you can:


PC Port Shut down
ACL
PC MAC quarantine
vlan

11

A-VLAN(80.1X)
A-VLAN(80.1X)



PC
PC
Virus
Virus



(e.g.
(e.g. port
port scan)
scan)

22

IDP
IDP







Source
Source

(MAC
(MAC
IP)

33

IDP
IDP
Step#2
Step#2

OmniVista
OmniVista

AQE

AQE

44





AQM
AQM






,,


IDP
IDP










Shut
Shut down
down






ACL
ACL


PC
PC



PC
PC
quarantine VLAN

55

Alcatel-Lucent - Enterprise Solutions Division 69

All Rights Reserved Alcatel-Lucent 2007

Agenda

Session 4
1) AOS Security Training
- Switch
- Access Control List
- QoS
2) Operation & Troubleshooting
- T.S Guide
- T.S Guide
- T.S Guide
- T.S Guide

Alcatel-Lucent - Enterprise Solutions Division 70

All Rights Reserved Alcatel-Lucent 2007

T.S Guide

OS9800 CMM Module LED


- LED
- OK1 : Hardware ( )
- OK2 : Software ( )
- CONTROL : Prim-CMM , Secon-CMM
- FABRIC : Fabric
- TEMP : 0-40C , 40-45C , 45C
.
- FAN : Fan tray
- PSU : power
- LINK : EMP port Link/Activity

Alcatel-Lucent - Enterprise Solutions Division 71

All Rights Reserved Alcatel-Lucent 2007

T.S Guide

OS9800 NI Module LED


- LED
- OK1 : Hardware ( )
. H/W
Check Check Pass
- OK2 : Software ( )
. CMM S/W loading S/W loading

Alcatel-Lucent - Enterprise Solutions Division 72

All Rights Reserved Alcatel-Lucent 2007

T.S Guide

OS6850 LED
- LED
- OK : H/W
- PRI : PRI-CMM
- PWR : Power Supply
- BPS : Backup Power

Alcatel-Lucent - Enterprise Solutions Division 73

All Rights Reserved Alcatel-Lucent 2007

T.S Guide

OS9800 CMM OK1 LED (OS6850 OK LED)


- OS9000 OS6850

[Miniboot]-> Booting
- Directory Certified Directory Image Miniboot
- cd working Working Directory ls Image file
setNextRunningVersion 2 Working Directory Boot .
[Miniboot]->
[Miniboot]->
[Miniboot]->
[Miniboot]->
[Miniboot]->
[Miniboot]->
[Miniboot]->

cd working
ls
cd ..
cd certified
ls
setNextRunningVersion 2
reboot

Alcatel-Lucent - Enterprise Solutions Division 74

All Rights Reserved Alcatel-Lucent 2007

T.S Guide

OS9000 Booting U-boot booting Hit any key to stop autoboot: 0 message

- message jumper U-booot mode booting
CMM Detected
Loading boot.params...
Boot command line disabled.
- CMM Flash memory j5011 jumper 1-2

Alcatel-Lucent - Enterprise Solutions Division 75

All Rights Reserved Alcatel-Lucent 2007

T.S Guide

OS9800 CMM OK1 LED (OS6850 OK LED) Certified: [Kernel] mode


[miniboot]->

AOS
- Zmodem AOS
1) Switch Console reload
2) Booting Hit any key to stop autoboot: 0 message Enter U-boot mode
- jumper mode
3) U-boot printenv
4) Zmodem 9600 115200
=> setenv baudrate 115200
## Switch baudrate to 115200 bps and press ENTER ...
- console 115200
5) miniboot mode bootflags 0x1000
=> setenv bootflags 0x1000
6)
=> printenv

Alcatel-Lucent - Enterprise Solutions Division 76

All Rights Reserved Alcatel-Lucent 2007

T.S Guide
7)
=> saveenv
8) miniboot boot mode
=> run miniboot
9) miniboot mode certified directory
[Miniboot]->
[Miniboot]->cd "certified
10) sysStartZmodem Zmodem
[Miniboot]->sysStartZmodem
Upload directory: /flash/certified
rz ready to receive file, please start upload (or send 5 CTRL-X's to abort).
- Zmodem S/W AOS image

Alcatel-Lucent - Enterprise Solutions Division 77

All Rights Reserved Alcatel-Lucent 2007

T.S Guide
-

Console

Starting zmodem transfer. Press Ctrl+C to cancel.


Transferring Jadvrout.img...
100% 1396 KB 10 KB/s 00:02:10
2 Errors
Transferring Jbase.img...
100% 12523 KB 10 KB/s 00:19:22
2 Errors
Transferring Jdiag.img...
100% 2852 KB 10 KB/s 00:04:25
2 Errors
Transferring Jdni.img...
100% 2497 KB 10 KB/s 00:03:51
2 Errors
Transferring Jeni.img...
100% 4196 KB 10 KB/s 00:06:28
2 Errors
Transferring Jos.img...
100% 1871 KB 10 KB/s 00:02:53
2 Errors
Transferring Jrelease.img...
100%
3 KB 3 KB/s 00:00:01
2 Errors
Transferring Jsecu.img...
100% 378 KB 10 KB/s 00:00:37
2 Errors
**B0800000000022d
ZMODEM file transfer successful,
Hit <RETURN> to exit...
value = 0 = 0x0
11) Zmodem reboot
- Certified Directory image load Certified
[Miniboot]->reboot

Alcatel-Lucent - Enterprise Solutions Division 78

All Rights Reserved Alcatel-Lucent 2007

T.S Guide
12) Booting Hit any key to stop autoboot: 0 Enter U-boot mode booting
CMM Detected
Loading boot.params...
Boot Configuration Jumper Set
Hit any key to stop autoboot: 0
13) bootflags baudrate Default
=> setenv bootflags 0x0
=> setenv baudrate 9600
## Switch baudrate to 9600 bps and press ENTER ...
- Baudrate Console
14) Booting show running-directory Running configuration CERTIFIED
15) copy certified working certified image working copy Running configuration
WORKING
16)
-> write memory
-> copy working certified copy working certified flash-synchro

Alcatel-Lucent - Enterprise Solutions Division 79

All Rights Reserved Alcatel-Lucent 2007

T.S Guide

Read-Write Backup

Password Clear
1) backup
2) cd network network
3) ls userTable
4) rm userTable_name
4) reload working no rollback-timeout
5) (admin/switch )
6) ( )

Alcatel-Lucent - Enterprise Solutions Division 80

All Rights Reserved Alcatel-Lucent 2007

T.S Guide

Read-Write Backup

Password Clear
1) Switch Console reload
2) Hit any key to stop autoboot: 0 Enter
3) ==> prompt u-boot booting
4) fatls ide :1,0 /flash file
=> fatls ide :1,0
FileSize ATTR
Filename
---------- ---- --------------------------------------0 DIR certified
317 00 boot.params
0 DIR working
11 00 boot.slot.cfg
1985 00 boot.cfg.1.err
64239 00 swlog1.log
0 DIR network
64000 00 swlog2.log
0 DIR switch

Alcatel-Lucent - Enterprise Solutions Division 81

All Rights Reserved Alcatel-Lucent 2007

T.S Guide
4) fatls ide :1,0 /network /flash/network directory
- usertable file
=> fatls ide :1,0 /network
FileSize ATTR
Filename
---------- ---- --------------------------------------0 DIR .
0 DIR ..
23040 00 usertable4
33 00 policy.cfg
404 00 ssh_host_dsa_key
361 00 ssh_host_dsa_key.pub
12 00 lockoutsetting
5) fatdelete ide :1,0 /network/usertable4 usertable file
- usertable4 usertable file
=> fatdelete ide :1,0 /network/usertable4
Error (no IRQ) dev 0 blk 2097216: status 0x51
Error (no IRQ) dev 0 blk 2097216: status 0x51
Error (no IRQ) dev 0 blk 2097216: status 0x51
Error (no IRQ) dev 0 blk 2097216: status 0x51
Invalid FAT value 0x00000000
Deleted /network/usertable4

Alcatel-Lucent - Enterprise Solutions Division 82

All Rights Reserved Alcatel-Lucent 2007

T.S Guide
6) fatls ide :1,0 /network usertable file
=> fatls ide :1,0 /network
FileSize ATTR
Filename
---------- ---- --------------------------------------0 DIR .
0 DIR ..
33 00 policy.cfg
404 00 ssh_host_dsa_key
361 00 ssh_host_dsa_key.pub
12 00 lockoutsetting
7) run miniboot reboot
=> run miniboot
## Booting image at ff900000 ...
Image Name: miniboot-6.1.3.601.R01
Image Type: PowerPC VxWorks Kernel Image (gzip compressed)
Data Size: 781716 Bytes = 763.4 kB
Load Address: 00005000
Entry Point: 00005000
Verifying Checksum ... OK
8) Booting admin/switch default login
login : admin
password : switch

Alcatel-Lucent - Enterprise Solutions Division 83

All Rights Reserved Alcatel-Lucent 2007

T.S Guide
9) show user default
- admin password password
10) snmp community name
- snmp
user password-size min 6
aaa authentication snmp "local"
snmp security no security
snmp community map mode enable
user "cobalt" read-write all password "public" no auth
snmp community map "public" user "cobalt" on
snmp station 221.148.52.11 162 "cobalt" v3 enable
snmp trap absorption enable
snmp trap to webview enable
11)
-> write memory
-> copy working certified

Alcatel-Lucent - Enterprise Solutions Division 84

copy working certified flash-synchro

All Rights Reserved Alcatel-Lucent 2007

T.S Guide Switch Check

Switch
1) Switch H/W .
- show module, show cmm, show fan, show power
- Switch LED ( LED )
2) Switch S/W .
- show system : switch uptime, code version
- ls /flash dump file (PMD, Error)
- show running-directory CMM Running configuration
working
- show health, show health [slot#], show health all cpu Switch health
.
3) show log swlog log .
4) show configuration snapshot config .
5) Layer Layer .
- show interfaces slot/port port inbound/outbound packet
broadcast, unicast, multicast .
- show interfaces status Interface autonego/duplex .
- show interfaces counters errors Interface error .
6) STP .
- show vlan port/show spantree port blocking port
- show spantree [num] topology change, topology age .

Alcatel-Lucent - Enterprise Solutions Division 85

All Rights Reserved Alcatel-Lucent 2007

T.S Guide Switch Check


7) Routing table .
- Static routing : routing path
- RIP : rip version, rip router table
- OSPF : DR, BDR , Neighbor, LSDB .
Switch Packet Debug(Part 19 ) Hello packet .
8) S/W Up/downgrade .
- working directory Up/downgrade
working certified .
9) Virus

Alcatel-Lucent - Enterprise Solutions Division 86

All Rights Reserved Alcatel-Lucent 2007

T.S Guide Switch Packet Debug


1) Switch packet debug packet .
10 packet Capture .
/flash test.txt file .
-> debug ip packet board all output file test.txt start timeout 10 ( CMM & NI)
-> debug ip packet board ni 1 output file test.txt start timeout 10 (NI 1 module)
2) ftp test.txt file PC .
sample 445 port .
8 R 8/20 (00508bad0d9a)->(00d0959e66d4) IP 203.232.212.2->218.176.37.227 TCP 3577,445
8 S 8/49 00d0959e66d4->00d095816c3c IP 203.232.212.2->218.176.37.227 TCP 3577,445
8 R 8/20 (00508bad0d9a)->(00d0959e66d4) IP 203.232.212.2->218.181.193.22 TCP 3578,445
8 S 8/49 00d0959e66d4->00d095816c3c IP 203.232.212.2->218.181.193.22 TCP 3578,445
8 R 8/20 (00508bad0d9a)->(00d0959e66d4) IP 203.232.212.2->218.230.206.226 TCP 3582,445
8 S 8/49 00d0959e66d4->00d095816c3c IP 203.232.212.2->218.230.206.226 TCP 3582,445
8 R 8/20 (00508bad0d9a)->(00d0959e66d4) IP 203.232.212.2->218.54.65.199 TCP 3579,445
8 S 8/49 00d0959e66d4->00d095816c3c IP 203.232.212.2->218.54.65.199 TCP 3579,445

Alcatel-Lucent - Enterprise Solutions Division 87

All Rights Reserved Alcatel-Lucent 2007

T.S Guide


1. Log
- show log swlog console or Telnet
- /flash swlog1.log & swlog2.log binary ftp PC
- CMM Secon-CMM log .
(Second-CMM file Pri-CMM .
Pri-CMM FTP get )
. 6600,7000,8800
rcp /flash/swlog1.log /flash/swlog1.sec
rcp /flash/swlog2.log /flash/swlog2.sec
. 6850, 9000
rcp "cmm-b:/flash/swlog1.log" "/flash/swlog1.cmmB"
rcp "cmm-b:/flash/swlog2.log" "/flash/swlog2.cmmB"

Alcatel-Lucent - Enterprise Solutions Division 88

All Rights Reserved Alcatel-Lucent 2007

T.S Guide
- Primary-CMM Secon-CMM swlog
. Console Telnet Switch Primary CMM
. telnet 127.2.66.1 login ID/PW Secon-CMM login
. Show log swlog log exit
2. tech_support log files
- /flash tech-support file binary ftp PC
show tech-support
show tech-support layer2
show tech-support layer3
show tech-support layer3 "RIP, PIMSM, OSPF, MROUTE, IPX, DVMRP or BGP"
- RIP, PIMSM, OSPF, MROUTE, IPX, DVMRP or BGP
show tech-support layer3 protocol
3. Configuration File
-

/flash/working "boot.cfg" file binary ftp PC

4. 2. Dump file
-

ls dump file binary ftp PC

Alcatel-Lucent - Enterprise Solutions Division 89

All Rights Reserved Alcatel-Lucent 2007

T.S Guide
5. Console or Telnet Capture
ls -r
show log swlog
show log pmd pmd-file-name ( PMD file )
show configuration status
show microcode loaded
show microcode working
show microcode certified
show system
show hardware info
show running-directory
show configuration snapshot
rls /flash (6600 stack rls 2 /flash)
rls /working
rls /certified

Alcatel-Lucent - Enterprise Solutions Division 90

All Rights Reserved Alcatel-Lucent 2007

www.alcatel-lucent.com

Das könnte Ihnen auch gefallen