Beruflich Dokumente
Kultur Dokumente
Testing performed by
Mikheil Kartvelishvili
UGT
Lab equipment:
Hostname
SW1
SW2
SW3
R1
R2
R3
Hardware Platform
Cisco Catalyst 3750
Extreme Networks X670-48x
Extreme Networks X440-24p
Cisco 1841
Juniper ACX1100
Juniper ACX1100
Software Version
12.2(44)SE5
12.6.2.10
15.1.0.20
12.4(15)T5
12.3X54-D15.3
12.3X54-D15.3
Features Tested:
1.
2.
3.
4.
5.
6.
7.
Rapid PVST+
MST (802.1s)
STP Security
Link Aggregation (LACP)
DHCP Snooping / IP Source-guard
IP Routing / OSPF
First-Hop Redundancy / VRRP
1|Page
1. Rapid PVST+
1.1 TOPOLOGY
R1
Cisco 1841
.1 Fa0/0
VLAN 10,20,30
Fa1/0/1
SW1
Gi1/0/1
Gi1/0/2
VLAN 10,20,30
VLAN 10,20,30
SW3
Extreme Summit X440
Port 1
Port 1
Port 2
SW2
Extreme Summit X670
Port 2
VLAN 10,20,30
Port 3
Port 3
VLAN 10,20,30
GE0/0/0
.2
R2
ACX1100
VLAN 10,20,30
.3
GE0/0/0
R3
ACX1100
1.2 CONFIGURATION
SW1
spanning-tree
spanning-tree
spanning-tree
spanning-tree
!
vlan 10
name LAN1
!
vlan 20
mode rapid-pvst
etherchannel guard misconfig
extend system-id
vlan 20 priority 4096
2|Page
name LAN2
!
vlan 23
!
vlan 30
name LAN3
!
!
interface GigabitEthernet1/0/1
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface GigabitEthernet1/0/2
switchport trunk encapsulation dot1q
switchport mode trunk
!
!
end
SW2
configure vlan default delete ports all
configure vr VR-Default delete ports 1-48
configure vr VR-Default add ports 1-48
create vlan "LAN10"
configure vlan LAN10 tag 10
create vlan "LAN20"
configure vlan LAN20 tag 20
create vlan "LAN30"
configure vlan LAN30 tag 30
configure vlan Default add ports 1-48 untagged
configure vlan LAN10 add ports 1-2 tagged
configure vlan LAN20 add ports 1-2 tagged
configure vlan LAN30 add ports 1-2 tagged
create stpd LAN10
configure stpd LAN10 mode dot1w
configure stpd LAN10 priority 4096
configure stpd LAN10 default-encapsulation pvst-plus
create stpd LAN20
configure stpd LAN20 mode dot1w
configure stpd LAN20 default-encapsulation pvst-plus
create stpd LAN30
configure stpd LAN30 mode dot1w
configure stpd LAN30 default-encapsulation pvst-plus
configure stpd s0 delete vlan default ports all
disable stpd s0 auto-bind vlan default
enable stpd s0 auto-bind vlan Default
configure stpd LAN10 add vlan LAN10 ports 1 pvst-plus
configure stpd LAN20 add vlan LAN20 ports 1 pvst-plus
configure stpd LAN30 add vlan LAN30 ports 1 pvst-plus
configure stpd LAN10 add vlan LAN10 ports 2 pvst-plus
3|Page
SW3
configure vlan default delete ports all
configure vr VR-Default delete ports 1-24
configure vr VR-Default add ports 1-24
create vlan "LAN10"
configure vlan LAN10 tag 10
create vlan "LAN20"
configure vlan LAN20 tag 20
create vlan "LAN30"
configure vlan LAN30 tag 30
configure vlan Default add ports 1 untagged
configure vlan LAN10 add ports 1-2 tagged
configure vlan LAN20 add ports 1-2 tagged
configure vlan LAN30 add ports 1-2 tagged
create stpd LAN10
configure stpd LAN10 mode dot1w
configure stpd LAN10 default-encapsulation pvst-plus
create stpd LAN20
configure stpd LAN20 mode dot1w
configure stpd LAN20 default-encapsulation pvst-plus
create stpd LAN30
configure stpd LAN30 mode dot1w
configure stpd LAN30 priority 4096
configure stpd LAN30 default-encapsulation pvst-plus
configure stpd s0 delete vlan default ports all
disable stpd s0 auto-bind vlan default
enable stpd s0 auto-bind vlan Default
configure stpd LAN10 add vlan LAN10 ports 1 pvst-plus
configure stpd LAN20 add vlan LAN20 ports 1 pvst-plus
configure stpd LAN30 add vlan LAN30 ports 1 pvst-plus
configure stpd LAN10 add vlan LAN10 ports 2 pvst-plus
configure stpd LAN20 add vlan LAN20 ports 2 pvst-plus
configure stpd LAN30 add vlan LAN30 ports 2 pvst-plus
configure stpd LAN10 tag 10
enable stpd LAN10
configure stpd LAN20 tag 20
enable stpd LAN20
configure stpd LAN30 tag 30
enable stpd LAN30
4|Page
1.3 VERIFICATION
SW1#sho spanning-tree vlan 10
VLAN0010
Spanning tree enabled protocol rstp
Root ID Priority 4096
Address 0004.966d.5c18
Cost
4
Port
2 (GigabitEthernet1/0/2)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Bridge ID Priority 32778 (priority 32768 sys-id-ext 10)
Address 001d.45d0.4080
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Aging Time 300 sec
Interface
Role Sts Cost Prio.Nbr Type
------------------- ---- --- --------- -------- -------------------------------Gi1/0/1
Desg FWD 4
128.1 P2p
Gi1/0/2
Root FWD 4
128.2 P2p
Address 0004.966d.558b
Cost
4
Port
1 (GigabitEthernet1/0/1)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Bridge ID Priority 32798 (priority 32768 sys-id-ext 30)
Address 001d.45d0.4080
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Aging Time 300 sec
Interface
Role Sts Cost Prio.Nbr Type
------------------- ---- --- --------- -------- -------------------------------Gi1/0/1
Root FWD 4
128.1 P2p
Gi1/0/2
Desg FWD 4
128.2 P2p
=============================
SW2.73 # sho stpd LAN10
Stpd: LAN10
Stp: ENABLED
Number of Ports: 2
Rapid Root Failover: Disabled
Operational Mode: 802.1W
Default Binding Mode: PVST+
802.1Q Tag: 10
Ports: 1,2
Participating Vlans: LAN10
Auto-bind Vlans: (none)
Bridge Priority: 4096
BridgeID:
10:00:00:04:96:6d:5c:18
Designated root:
10:00:00:04:96:6d:5c:18
RootPathCost: 0
Root Port: ---MaxAge: 20s
HelloTime: 2s
ForwardDelay: 15s
CfgBrMaxAge: 20s
CfgBrHelloTime: 2s CfgBrForwardDelay: 15s
Topology Change Time: 35s
Hold time: 1s
Topology Change Detected: FALSE
Topology Change: FALSE
Number of Topology Changes: 4
Time Since Last Topology Change: 1686s
SW2.74 # sho stpd LAN20
Stpd: LAN20
Stp: ENABLED
Number of Ports: 2
Rapid Root Failover: Disabled
Operational Mode: 802.1W
Default Binding Mode: PVST+
802.1Q Tag: 20
Ports: 1,2
Participating Vlans: LAN20
Auto-bind Vlans: (none)
Bridge Priority: 32768
BridgeID:
80:00:00:04:96:6d:5c:18
Designated root:
10:14:00:1d:45:d0:40:80
RootPathCost: 20000 Root Port: 1
6|Page
MaxAge: 20s
HelloTime: 2s
ForwardDelay: 15s
CfgBrMaxAge: 20s
CfgBrHelloTime: 2s CfgBrForwardDelay: 15s
Topology Change Time: 35s
Hold time: 1s
Topology Change Detected: FALSE
Topology Change: FALSE
Number of Topology Changes: 2
Time Since Last Topology Change: 1664s
SW2.75 # sho stpd LAN30
Stpd: LAN30
Stp: ENABLED
Number of Ports: 2
Rapid Root Failover: Disabled
Operational Mode: 802.1W
Default Binding Mode: PVST+
802.1Q Tag: 30
Ports: 1,2
Participating Vlans: LAN30
Auto-bind Vlans: (none)
Bridge Priority: 32768
BridgeID:
80:00:00:04:96:6d:5c:18
Designated root:
10:00:00:04:96:6d:55:8b
RootPathCost: 20000 Root Port: 2
MaxAge: 20s
HelloTime: 2s
ForwardDelay: 15s
CfgBrMaxAge: 20s
CfgBrHelloTime: 2s CfgBrForwardDelay: 15s
Topology Change Time: 35s
Hold time: 1s
Topology Change Detected: FALSE
Topology Change: FALSE
Number of Topology Changes: 1
Time Since Last Topology Change: 1718s
===========================================
SW3.13 # sho stp LAN10
Stpd: LAN10
Stp: ENABLED
Number of Ports: 2
Rapid Root Failover: Disabled
Operational Mode: 802.1W
Default Binding Mode: PVST+
802.1Q Tag: 10
Ports: 1,2
Participating Vlans: LAN10
Auto-bind Vlans: (none)
Bridge Priority: 32768
BridgeID:
80:00:00:04:96:6d:55:8b
Designated root:
10:00:00:04:96:6d:5c:18
RootPathCost: 20000 Root Port: 2
MaxAge: 20s
HelloTime: 2s
ForwardDelay: 15s
CfgBrMaxAge: 20s
CfgBrHelloTime: 2s CfgBrForwardDelay: 15s
Topology Change Time: 35s
Hold time: 1s
Topology Change Detected: FALSE
Topology Change: FALSE
Number of Topology Changes: 3
Time Since Last Topology Change: 2005s
SW3.14 # sho stp LAN20
7|Page
Stpd: LAN20
Stp: ENABLED
Number of Ports: 2
Rapid Root Failover: Disabled
Operational Mode: 802.1W
Default Binding Mode: PVST+
802.1Q Tag: 20
Ports: 1,2
Participating Vlans: LAN20
Auto-bind Vlans: (none)
Bridge Priority: 32768
BridgeID:
80:00:00:04:96:6d:55:8b
Designated root:
10:14:00:1d:45:d0:40:80
RootPathCost: 20000 Root Port: 1
MaxAge: 20s
HelloTime: 2s
ForwardDelay: 15s
CfgBrMaxAge: 20s
CfgBrHelloTime: 2s CfgBrForwardDelay: 15s
Topology Change Time: 35s
Hold time: 1s
Topology Change Detected: FALSE
Topology Change: FALSE
Number of Topology Changes: 9
Time Since Last Topology Change: 1954s
SW3.15 # sho stp LAN30
Stpd: LAN30
Stp: ENABLED
Number of Ports: 2
Rapid Root Failover: Disabled
Operational Mode: 802.1W
Default Binding Mode: PVST+
802.1Q Tag: 30
Ports: 1,2
Participating Vlans: LAN30
Auto-bind Vlans: (none)
Bridge Priority: 4096
BridgeID:
10:00:00:04:96:6d:55:8b
Designated root:
10:00:00:04:96:6d:55:8b
RootPathCost: 0
Root Port: ---MaxAge: 20s
HelloTime: 2s
ForwardDelay: 15s
CfgBrMaxAge: 20s
CfgBrHelloTime: 2s CfgBrForwardDelay: 15s
Topology Change Time: 35s
Hold time: 1s
Topology Change Detected: FALSE
Topology Change: FALSE
Number of Topology Changes: 7
Time Since Last Topology Change: 1968s
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!.!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Success rate is 99 percent (1392/1393), round-trip min/avg/max = 1/8/16 ms
SW1(config)#int gi1/0/2
SW1(config-if)#shut
SW1(config-if)#
mikho@R3# run ping 192.168.10.1 rapid count 10000
PING 192.168.10.1 (192.168.10.1): 56 data bytes
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!.!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
...!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
9|Page
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!^C
--- 192.168.10.1 ping statistics --3384 packets transmitted, 3379 packets received, 0% packet loss
round-trip min/avg/max/stddev = 0.820/9.510/16.475/2.055 ms
[edit interfaces]
mikho@R3#
10 | P a g e
2. MST (802.1s)
2.1 TOPOLOGY
R1
Cisco 1841
.1 Fa0/0
VLAN 10,20,30
Fa1/0/1
SW1
Gi1/0/1
Gi1/0/2
VLAN 10,20,30
VLAN 10,20,30
SW3
Extreme Summit X440
Port 1
Port 1
Port 2
SW2
Extreme Summit X670
Port 2
VLAN 10,20,30
Port 3
Port 3
VLAN 10,20,30
GE0/0/0
.2
R2
ACX1100
VLAN 10,20,30
.3
GE0/0/0
R3
ACX1100
2.2 CONFIGURATION
SW1
spanning-tree mode mst
spanning-tree etherchannel guard misconfig
spanning-tree extend system-id
!
spanning-tree mst configuration
name TEST
revision 1
instance 1 vlan 10, 20
instance 2 vlan 30
!
spanning-tree mst 1 priority 4096
!
11 | P a g e
ascending
dot1q
dot1q
dot1q
SW2
configure vlan default delete ports all
create vlan "LAN10"
configure vlan LAN10 tag 10
create vlan "LAN20"
configure vlan LAN20 tag 20
create vlan "LAN30"
configure vlan LAN30 tag 30
configure vlan Default add ports 1-48 untagged
configure vlan LAN10 add ports 1-3 tagged
configure vlan LAN20 add ports 1-3 tagged
configure vlan LAN30 add ports 1-3 tagged
configure mstp region TEST
configure mstp revision 1
configure stpd s0 delete vlan default ports all
disable stpd s0 auto-bind vlan default
configure stpd s0 mode mstp cist
create stpd INST1
configure stpd INST1 mode mstp msti 1
12 | P a g e
2
ports
ports
ports
ports
ports
ports
1
1
1
2
2
2
dot1d
dot1d
dot1d
dot1d
dot1d
dot1d
SW3
configure vlan default delete ports all
configure vlan default delete ports 3-24
create vlan "LAN10"
configure vlan LAN10 tag 10
create vlan "LAN20"
configure vlan LAN20 tag 20
create vlan "LAN30"
configure vlan LAN30 tag 30
configure vlan Default add ports 1-2 untagged
configure vlan LAN10 add ports 1-2, 23-24 tagged
configure vlan LAN20 add ports 1-2, 23-24 tagged
configure vlan LAN30 add ports 1-2, 23-24 tagged
configure mstp region TEST
configure mstp revision 1
configure stpd s0 delete vlan default ports all
disable stpd s0 auto-bind vlan default
configure stpd s0 mode mstp cist
create stpd INST1
configure stpd INST1 mode mstp msti 1
create stpd INST2
configure stpd INST2 mode mstp msti 2
configure stpd INST2 priority 4096
configure stpd INST1 add vlan LAN10 ports 1 dot1d
configure stpd INST1 add vlan LAN20 ports 1 dot1d
configure stpd INST2 add vlan LAN30 ports 1 dot1d
configure stpd INST1 add vlan LAN10 ports 2 dot1d
configure stpd INST1 add vlan LAN20 ports 2 dot1d
configure stpd INST2 add vlan LAN30 ports 2 dot1d
enable stpd s0
enable stpd INST1
enable stpd INST2
13 | P a g e
2.3 VERIFICATION
SW1#sho spanning-tree mst 1
##### MST1 vlans mapped: 10,20
Bridge
address 001d.45d0.4080 priority
Root
this switch for MST1
Interface
Role Sts Cost Prio.Nbr Type
---------------- ---- --- --------- -------- -------------------------------Gi1/0/1
Desg FWD 20000 128.1 P2p
Gi1/0/2
Desg FWD 20000 128.2 P2p
Fa1/0/1
Desg FWD 200000 128.3 P2p Edge
SW1#sho spanning-tree mst 2
##### MST2 vlans mapped: 30
Bridge
address 001d.45d0.4080 priority 32770 (32768 sysid 2)
Root
address 0004.966d.558b priority 4098 (4096 sysid 2)
port Gi1/0/1
cost
20000 rem hops 19
Interface
Role Sts Cost Prio.Nbr Type
---------------- ---- --- --------- -------- -------------------------------Gi1/0/1
Root FWD 20000 128.1 P2p
Gi1/0/2
Altn BLK 20000 128.2 P2p
Fa1/0/1
Desg FWD 200000 128.3 P2p Edge
RemainHopCount: 20 CfgMaxHopCount: 20
Topology Change Time: 35s
Hold time: 1s
Topology Change Detected: FALSE
Topology Change: FALSE
Number of Topology Changes: 11
Time Since Last Topology Change: 1085s
SW3.2 # sho stp INST2
Stpd: INST2
Stp: ENABLED
Number of Ports: 2
Rapid Root Failover: Disabled
Operational Mode: MSTP
Default Binding Mode: 802.1D
MSTI Instance: MSTI 2
802.1Q Tag: (none)
Ports: 1,2
Participating Vlans: LAN30
Auto-bind Vlans: (none)
Bridge Priority: 4096
BridgeID:
80:00:00:04:96:6d:55:8b
Designated root:
80:00:00:04:96:6d:55:8b
CIST Root:
80:00:00:04:96:6d:55:8b
CIST Regional Root: 80:00:00:04:96:6d:55:8b
MSTI Regional Root: 80:00:00:04:96:6d:55:8b
External RootPathCost: 0
Internal RootPathCost: 0
Root Port: ---Master Port: ---MaxAge: 20s
HelloTime: 2s
ForwardDelay: 15s
CfgBrMaxAge: 20s
CfgBrHelloTime: 2s CfgBrForwardDelay: 15s
RemainHopCount: 20 CfgMaxHopCount: 20
Topology Change Time: 35s
Hold time: 1s
Topology Change Detected: FALSE
Topology Change: FALSE
Number of Topology Changes: 37
Time Since Last Topology Change: 1089s
SW1(config)#int gi1/0/1
SW1(config-if)#shut
SW1(config-if)#
*Apr 27 01:43:46.546: %LINK-5-CHANGED: Interface GigabitEthernet1/0/1, changed state to
administratively down
*Apr 27 01:43:46.554: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/1,
changed state to down
SW1(config-if)#
17 | P a g e
3. STP Security
3.1 TOPOLOGY
< Same as section[2] >
3.2 CONFIGURATION
3.2.1 BPDU Guard/Loop Guard
configure stpd s0 ports link-type edge 1 edge-safeguard enable bpdu-restrict
3.3.2 Root Guard
configure stpd INST1 ports restricted-role enable 1
3.3 VERIFICATION
3.3.1 BPDU Guard/Loop Guard
* SW2.17 # sho log
02/16/2015 20:24:44.22 <Info:vlan.msgs.portLinkStateDown> Port 1 link down - Local fault
02/16/2015 20:24:44.12 <Info:vlan.dbg.info> Toggling AdminState on Port 1
02/16/2015 20:24:44.12 <Warn:STP.DsblPortBrdgDtect> BPDU Restrict Port (1) has received a bpdu and
will be shutdown
* SW2.20 # sho port 1 no-refresh
Port Summary
Port Display
VLAN Name
Port Link Speed Duplex
# String
(or # VLANs)
State State Actual Actual
==================================================================
1
(0004)
R D
==================================================================
Port State: D-Disabled, E-Enabled
Link State: A-Active, R-Ready, NP-Port not present, L-Loopback,
D-ELSM enabled but not up
d-Ethernet OAM enabled but not up
* SW2.18 # enable ports 1
* SW2.19 # sho port 1 no-refresh
Port Summary
Port Display
VLAN Name
Port Link Speed Duplex
# String
(or # VLANs)
State State Actual Actual
==================================================================
1
(0004)
E A 1000 FULL
==================================================================
Port State: D-Disabled, E-Enabled
Link State: A-Active, R-Ready, NP-Port not present, L-Loopback,
D-ELSM enabled but not up
d-Ethernet OAM enabled but not up
18 | P a g e
3.3.2 Role-restricted
Note: This feature is similar to Cisco Root-guard, but is a bit different: in case of superior BPDU
received on protected port it is not disabled, and violating BPDU is simply ignored leaving port in
forwarding state and avoiding it to assume root role.
Stp: ENABLED
Number of Ports: 2
80:00:00:04:96:6d:5c:18
Designated root:
CIST Root:
80:00:00:04:96:6d:55:8b
80:00:00:04:96:6d:55:8b
80:00:00:04:96:6d:55:8b
80:00:00:04:96:6d:55:8b
External RootPathCost: 0
Root Port: 2
MaxAge: 20s
HelloTime: 2s
CfgBrMaxAge: 20s
RemainHopCount: 19
ForwardDelay: 15s
CfgBrHelloTime: 2s
CfgBrForwardDelay: 15s
CfgMaxHopCount: 20
Hold time: 1s
Topology Change: FALSE
19 | P a g e
Stp: ENABLED
Number of Ports: 2
80:00:00:04:96:6d:5c:18
Designated root:
CIST Root:
10:00:00:1d:45:d0:40:80
80:00:00:04:96:6d:55:8b
80:00:00:04:96:6d:55:8b
10:00:00:1d:45:d0:40:80
External RootPathCost: 0
Root Port: 1
MaxAge: 20s
HelloTime: 2s
CfgBrMaxAge: 20s
RemainHopCount: 19
ForwardDelay: 15s
CfgBrHelloTime: 2s
CfgBrForwardDelay: 15s
CfgMaxHopCount: 20
Hold time: 1s
Topology Change: TRUE
Gi1/0/1
VLAN 10,20,30
SW3
Extreme Summit X440
Port 23
VLAN 10,20,30
Port 1
Port 1
Port 2
Port 3
Port 4
Port 24
VLAN 10,20,30
GE0/0/0 .2 GE0/0/1
R2
ACX1100
Gi1/0/2
SW2
Extreme Summit X670
Port 3
VLAN 10,20,30
.3
GE0/0/0
R3
ACX1100
4.2 CONFIGURATION
SW2
enable sharing 2 grouping 2, 4 algorithm address-based L3_L4 lacp
SW3
enable sharing 2 grouping 2-3 algorithm address-based L2 lacp
enable sharing 23 grouping 23-24 algorithm address-based L3_L4 lacp
configure sharing 23 lacp timeout short
21 | P a g e
R2
chassis {
aggregated-devices {
ethernet {
device-count 1;
}
}
}
interfaces {
ge-0/0/0 {
gigether-options {
802.3ad ae0;
}
}
ge-0/0/1 {
gigether-options {
802.3ad ae0;
}
}
ae0 {
vlan-tagging;
aggregated-ether-options {
lacp {
active;
}
}
unit 10 {
vlan-id 10;
family inet {
address 192.168.10.2/24;
}
}
unit 20 {
vlan-id 20;
family inet {
address 192.168.20.2/24;
}
}
unit 30 {
vlan-id 30;
family inet {
address 192.168.30.2/24;
}
}
}
}
22 | P a g e
4.3 VERIFICATION
* SW2.22 # show sharing
Load Sharing Monitor
Config Current Agg
Ld Share Ld Share Agg Link Link Up
Master Master Control Algorithm Group Mbr State Transitions
==============================================================================
2 2
LACP L3_L4
2
Y A
3
L3_L4
4
Y A
2
==============================================================================
Link State: A-Active, D-Disabled, R-Ready, NP-Port not present, L-Loopback
Load Sharing Algorithm: (L2) Layer 2 address based, (L3) Layer 3 address based
(L3_L4) Layer 3 address and Layer 4 port based
(custom) User-selected address-based configuration
Custom Algorithm Configuration: ipv4 L3-and-L4, xor
Number of load sharing trunks: 1
SW3.1 # show sharing
Load Sharing Monitor
Config Current Agg
Ld Share Ld Share Agg Link Link Up
Master Master Control Algorithm Group Mbr State Transitions
==============================================================================
2 2
LACP L2
2
Y A
10
L2
3
Y A
1
23 23
LACP L3_L4
23
Y A
8
L3_L4
24
Y A
8
==============================================================================
Link State: A-Active, D-Disabled, R-Ready, NP-Port not present, L-Loopback
Load Sharing Algorithm: (L2) Layer 2 address based, (L3) Layer 3 address based
(L3_L4) Layer 3 address and Layer 4 port based
Number of load sharing trunks: 2
mikho@R2# run show lacp interfaces
Aggregated interface: ae0
LACP state:
Role Exp Def Dist Col Syn Aggr Timeout Activity
ge-0/0/0
Actor No No Yes Yes Yes Yes Fast Active
ge-0/0/0 Partner No No Yes Yes Yes Yes Fast Active
ge-0/0/1
Actor No No Yes Yes Yes Yes Fast Active
ge-0/0/1 Partner No No Yes Yes Yes Yes Fast Active
LACP protocol:
Receive State Transmit State
Mux State
ge-0/0/0
Current Fast periodic Collecting distributing
ge-0/0/1
Current Fast periodic Collecting distributing
[ R2 Set up as FTP server ]
[edit interfaces]
mikho@R3# ...kernel-ppc-12.3X51-D10.5 ftp://mikho:cisco123@192.168.10.2/
ftp://mikho:cisco123@192.168.10.2/jkernel-ppc- 18% of 66 MB 142 kBps 06m24s^C
23 | P a g e
24 | P a g e
R1
Cisco 1841
DHCP Server
.1 Fa0/0
VLAN 10,20,30
Fa1/0/1
SW1
Gi1/0/2
Gi1/0/1
VLAN 10,20,30
VLAN 10,20,30
SW3
Extreme Summit X440
Port 23
Port 1
Port 1
Port 2
Port 3
Port 4
Port 24
VLAN 10,20,30
GE0/0/0 .2 GE0/0/1
SW2
Extreme Summit X670
Port 3
VLAN 10,20,30
R2
ACX1100
R3
ACX1100
5.2 CONFIGURATION
SW2
enable ip-security dhcp-snooping vlan LAN20 port 1 violation-action drop-packet
enable ip-security dhcp-snooping vlan LAN20 port 3 violation-action drop-packet
enable ip-security dhcp-snooping vlan LAN20 port 2 violation-action drop-packet
configure trusted-ports 1-2 trust-for dhcp-server
enable ip-security source-ip-lockdown ports 3
25 | P a g e
SW3
enable ip-security dhcp-snooping vlan LAN20 port 1 violation-action drop-packet
enable ip-security dhcp-snooping vlan LAN20 port 2 violation-action drop-packet
enable ip-security dhcp-snooping vlan LAN20 port 23 violation-action drop-packet
block-port permanent
configure trusted-servers vlan LAN20 add server 192.168.20.1 trust-for dhcp-server
R1
ip dhcp pool TEST
network 192.168.20.0 255.255.255.0
default-router 192.168.20.1
domain-name ugt.ge
R2
system {
services {
ftp;
dhcp-local-server {
pool-match-order {
ip-address-first;
}
group GROUP1 {
interface ae0.20;
}
}
}
}
access {
address-assignment {
26 | P a g e
pool TEST {
family inet {
network 192.168.20.0/24;
}
}
}
}
R3
interfaces {
ge-0/0/0 {
unit 20 {
vlan-id 20;
family inet {
dhcp-client;
}
}
}
}
5.3 VERIFICATION
* SW2.1 # show ip-security dhcp-snooping entries LAN20
-----------------------------------------------------------------Vlan: LAN20
-----------------------------------------------------------------Lease Time Server Client
IP Addr
MAC Addr
(hh:mm:ss) Port Port
----------------------- ------ -----192.168.20.9 28:8a:1c:74:9a:80 24:00:00 1
3
Total number of entries : 1
* SW2.2 # show ip-security source-ip-lockdown
Ports
Locked IP Address
3
192.168.20.9
mikho@R3# run show interfaces terse | except down
27 | P a g e
Interface
ge-0/0/0
ge-0/0/0.10
[edit interfaces]
mikho@R3# delete ge-0/0/0.20 family inet dhcp-client
[edit interfaces]
mikho@R3# set ge-0/0/0.20 family inet address 192.168.20.10/24
[edit interfaces]
mikho@R3# commit
commit complete
[edit interfaces]
mikho@R3# run ping 192.168.20.1
PING 192.168.20.1 (192.168.20.1): 56 data bytes
^C
--- 192.168.20.1 ping statistics --4 packets transmitted, 0 packets received, 100% packet loss
[edit interfaces]
mikho@R3# delete ge-0/0/0.20 family inet address 192.168.20.10/24
ge-0/0/0.20 family inet dhcp-client
[edit interfaces]
mikho@R3# set ge-0/0/0.20 family inet dhcp-client
[edit interfaces]
28 | P a g e
mikho@R3# commit
commit complete
[edit interfaces]
29 | P a g e
6. IP Routing / OSPF
6.1 TOPOLOGY
VLAN20
OSPF Area 20 Stub
192.168.20.0/24
R1
VLAN10
OSPF Area 0
192.168.10.0/24
SW2
R2
6.2 CONFIGURATION
R1
router ospf 1
router-id 1.1.1.1
log-adjacency-changes
area 20 stub
interface Loopback0
ip address 10.1.1.1 255.255.255.255
ip ospf 1 area 20
interface FastEthernet0/0.10
shutdown
interface FastEthernet0/0.20
ip ospf 1 area 20
interface FastEthernet0/0.30
shutdown
R2
routing-options {
router-id 3.3.3.3;
}
protocols {
ospf {
area 0.0.0.0 {
interface ae0.10;
interface lo0.0;
}
}
}
SW2
configure vlan LAN10 ipaddress 192.168.10.12 255.255.255.0
enable ipforwarding vlan LAN10
configure vlan LAN20 ipaddress 192.168.20.12 255.255.255.0
30 | P a g e
6.3 VERIFICATION
[edit protocols ospf]
mikho@R2# run show ospf interface
Interface
State Area
DR ID
ae0.10
DR 0.0.0.0
3.3.3.3
lo0.0
DR 0.0.0.0
3.3.3.3
BDR ID
0.0.0.0
0.0.0.0
Nbrs
1
0
Fa0/0.20 1 20
192.168.20.1/24 1
R1#sho ip ospf neighbor
DR 1/1
33 | P a g e
8.8.8.8
8.8.8.8
VRRP ID 1
VIP 192.168.20.1
R1
.11
SW2
.12
VLAN20
192.168.20.0/24
.2
R2
7.2 CONFIGURATION
SW2
create vlan "LOOPBACK"
enable loopback-mode vlan LOOPBACK
configure vlan LOOPBACK ipaddress 8.8.8.8 255.255.255.255
34 | P a g e
R1
interface Loopback100
ip address 8.8.8.8 255.255.255.255
!
interface FastEthernet0/0.20
vrrp 1 ip 192.168.20.1
vrrp 1 priority 120
vrrp 1 authentication CISCO
end
7.3 VERIFICATION
R1#sho vrrp all
FastEthernet0/0.20 - Group 1
State is Master
Virtual IP address is 192.168.20.1
Virtual MAC address is 0000.5e00.0101
Advertisement interval is 1.000 sec
Preemption enabled
Priority is 120
Authentication text "CISCO"
Master Router is 192.168.20.11 (local), priority is 120
Master Advertisement interval is 1.000 sec
Master Down interval is 3.531 sec
R1(config)#int fa0/0
35 | P a g e
R1(config-if)#shut
R1(config-if)#
*Feb 24 12:05:29.436: %VRRP-6-STATECHANGE: Fa0/0.20 Grp 1 state Master -> Init
*Feb 24 12:05:31.436: %LINK-5-CHANGED: Interface FastEthernet0/0, changed state to administratively
down
*Feb 24 12:05:32.436: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed
state to down
36 | P a g e