Beruflich Dokumente
Kultur Dokumente
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 1
Agenda
Upgrading Software
High CPU
Stacking
Packet Forwarding
Multicasting
Access Control Lists
QoS
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 2
/overwrite option overwrites the software image in flash with the downloaded
image
/leave-old-sw option keeps the old software version after a download
/reload option reloads the system after downloading the image unless the
configuration has been changed and not been saved
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 3
After a version mismatch slave joins the stack it takes about one
minute before auto upgrade takes place
3750(config)# boot auto-copy-sw
3750(config)#Z
3750# show boot
BOOT path-list : flash:/c3750-i5k2-mz.121-19.EA1a.bin
Config file : flash:/config.text
Private Config file : flash:/private-config.text
Enable Break : no
Manual Boot : no
HELPER path-list :
Auto upgrade : yes
Agenda
Upgrading Software
High CPU
Stacking
Packet Forwarding
Access Control Lists
Multicasting
QoS
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 6
CPU Function
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 8
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 9
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 10
Agenda
Upgrading Software
High CPU
Stacking
Packet Forwarding
Access Control Lists
Multicasting
QoS
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 12
Each Link
Port ASIC Port ASIC Port ASIC
Is 16
Gbps
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 13
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 14
Configuration Considerations: M #1
There Is One Config for the Whole Stack
The Saved (Or Running) Config on the Master Will Be S #3
Used on All Switches; Slaves Maintain a Copy as Well
Replacing a Failed Switch: The Port Level Config Is Lost if S #2
a Different Model Switch Is Used; Global Stack Config Is
Still There Always
S #4
If a slave boots and the running and startup config in the
master differ, config for that slave may be lost (slave will M = Master Switch
get default port-level config)
S = Slave Switch
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 15
M #1 M #1 M #1
S #3 S #3 S #3
S #2 S #2 S #2
S #4
M #4 M #4
S #5
S #5 S #5
S #6
S #6 S #6
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 17
The above log occurred when switch 1 was reset (stack master) after switch 2
was assigned a higher stack priority; switch 2 then became the stack master
Reverse means the most current log message is at the top instead of the end
3750# remote command all debug platform stack-manager ssm
Switch : 2 : (Master) |
--------------------- Stack State Machine
Stack Manager Stack SM debugging is on
Switch : 1 :
------------
Stack Manager Stack SM debugging is on
3750#
1d01h: Entering stack_mgr_process_stack_message
1d01h: 007580: received msg Ready (10) for sw #01 slave
1d01h: Entering sm_ssm_compare_messages Switch Number 0 Old State 10 New State10
1d01h: stack_mgr : during state ready, got event 13(no_master_change) (ignored)
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 18
Forwarding
Blocked Link
Redundant Blocked
Uplink Link
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 19
Upgrading Software
High CPU
Stacking
Packet Forwarding
Access Control Lists
Multicasting
QoS
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 21
Show Interface
3550-1# show interface status
Port Name Status Vlan Duplex Speed Type
Fa0/1 Server-B1 notconnect 2 full 100 100BaseFX
Fa0/2 notconnect routed full 100 100BaseFX
Fa0/3 notconnect 1 half 100 100BaseFX
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 24
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 25
3750# session 1
3750-1# show platform pm group-masks
====================================================================
Etherchannel members and group masks table
Group #ports group frame-dist slot port mask interface index
--------------------------------------------------------------------
1 2 1 src-mac
2 1 5555 Gi2/0/1 0
1 1 AAAA Gi1/0/1 1
<output omited>
====================================================================
Etherchannel members info
group agport #ports members
--------------------------------------------------------------------
1 Po1 2 Gi1/0/1 Gi2/0/1
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 26
Catalyst 3550-24 and 3550-48 SDM Templates Catalyst 3550-12G and 3550-12T SDM Templates
Resource Default Access Route VLAN Resource Default Access Route VLAN
QoS ACE 1,000 1,000 512 1,000 QoS ACE 2,000 2,000 1,000 2,000
Security Security
1,000 2,000 512 1,000 2,000 4,000 1,000 2,000
ACE ACE
Unicast Unicast
5,000 1,000 5,000 8,000 6,000 2,000 6,000 12,000
MAC MAC
VLANs 1,000 1,000 1,000 1,000 VLANs 1,000 1,000 1,000 1,000
IGMP IGMP
1,000 2,000 1,000 1,000 6,000 8,000 6,000 6,000
Groups Groups
Unicast 8,000 2,000 16,000 Unicast 12,000 4,000 24,000
0 0
Routes * or 4,000 * or 1,000 * or 8,000 Routes * or 6,000 * or 2,000 * or 12,000
Multicast Multicast
1,000 2,000 1,000 0 6,000 8,000 6,000 0
Routes Routes
Routed Routed
Ports and 8 8 8 8 Ports and 16 16 16 16
SVIs SVIs
3750# show sdm prefer Works on the 2970 Also for Its L2 Features
The current template is "desktop default" template.
The selected template optimizes the resources in
the switch to support this level of features for Use these Commands to Help Verify Current # of Entries
8 routed interfaces and 1024 VLANs.
|
number of unicast mac addresses: 6K show mac address-table count
number of igmp groups + multicast routes: 1K show ip 1gmp snooping multicast count
show ip mroute count
number of unicast routes: 8K show ip route summary
number of directly connected hosts: 6K
number of indirect routes: 2K
number of policy based routing aces: 0 show access-lists
number of qos aces: 512 show access-lists
number of security aces: 1K show platform acl usage [port asic #]
LAYER 2 PACKET
FORWARDING
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 30
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 31
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 33
3750# session 1
3750-1# show platform mac-address-table mac-address 0006.52be.10c1 vlan 1
hmac: 01728E84 hash_q.flink: 00FDB98C hash_q.blink: 00FDB98C
key: 0638 age_q.flink: 00FE2694 age_q.blink: 00FE2694
mac_addr: 0006.52be.10c1 vlan_id: 0001 hmvid: 0001
cam_index : 00000036 mat_instance: 01B4DA10 owned_sw_num: 0001
mat_vlan_addr: 01B52108 mat_bg_addr: 00000000 bg_instance: 00000000
mad: 00000000(0 ) mad_ref_cnt: 0 flags: 01
si/di: 095/F002
3750-1# show platform tcam table local index 36 detail Some Output Omitted
localCamForwardingDescriptor Value Mask
------------------------------------------------------------------ Use sh platform vlan
mappedVlanId1: 1 3FF
macAddress: 0006.52BE.10C1 FFFF.FFFF.FFFF
mvid
globalPortNumber: 2 3FF
Value Is in Hex
3750-1# show platform pm if-numbers
interface gid gpn lpn port slot unit slun port-type lpn-idb gpn-idb
----------------------------------------------------------------------
Gi1/0/2 2 2 2 1/2 1 2 2 local Yes Yes gpn Is in Dec
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 35
IP PACKET FORWARDING
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 36
3550-2# show adjacency gigabitEthernet 0/12 detail 209.10.9.21 IP: 201.30.15.2 201.30.15.1
Protocol Interface Address
IP GigabitEthernet0/12 201.30.15.2(7)
Mac: 0090.2141.5427 0005.ddc5.8300
0 packets, 0 bytes
0090214154270005DDC583000800
ARP 03:49:45
Epoch: 0
3550-2# show interface gig 0/12
GigabitEthernet0/12 is up, line protocol is up (connected)
Hardware is Gigabit Ethernet, address is 0005.ddc5.8300 (bia 0005.ddc5.8300)
Internet address is 201.30.15.1/24
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 37
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 38
3550-2# show vlan internal usage The information at the bottom of the show forward
VLAN Usage command is used by 3550-2 to rewrite the packet
---- --------------------
1025 GigabitEthernet0/12
received on gig 0/10 in hardware and send it towards
the destination 209.10.9.21
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 39
Master Failover:
Stack switches continue to forward traffic using the stale FIB/Adj database
New master is elected, brings up its SVIs
New master sends gratuitous arps out on each L3 interface so that routing
peers learn the new router mac addresses for the 3750 stack (master owns
these)
New master starts building its routing/arp table, recalculates FIB/Adj, pushes it
down to slaves
After 5 minutes any routing entries that are still stale are flushed (should have
converged by now since new updates clear stale flags)
If a new slave had joined the stack during this, the existing FIB/Adj database
with stale entries would have been down loaded to it
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 40
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 43
3750# debug platform cpu-queues software-fwd-q (use caution when running debugs!)
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 44
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 45
Agenda
Upgrading Software
High CPU
Stacking
Packet Forwarding
Access Control Lists
Multicasting
QoS
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 46
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 49
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 50
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 51
interface gid gpn lpn port slot unit slun port-type lpn-idb gpn-idb
----------------------------------------------------------------------
Gi1/0/1 1 1 1 1/3 1 1 1 local Yes Yes
Gi1/0/2 2 2 2 1/2 1 2 2 local Yes Yes
Gi1/0/3 3 3 3 1/0 1 3 3 local Yes Yes
Gi1/0/4 4 4 4 1/1 1 4 4 local Yes Yes
Gi1/0/5 5 5 5 2/3 1 5 5 local Yes Yes
Gi1/0/6 6 6 6 2/2 1 6 6 local Yes Yes
Gi1/0/7 7 7 7 2/0 1 7 7 local Yes Yes
Gi1/0/8 8 8 8 2/1 1 8 8 local Yes Yes
Gi1/0/9 9 9 9 0/3 1 9 9 local Yes Yes
Gi1/0/10 10 10 10 0/2 1 10 10 local Yes Yes
Gi1/0/11 11 11 11 0/0 1 11 11 local Yes Yes
Gi1/0/12 12 12 12 0/1 1 12 12 local Yes Yes
3750# show platform tcam table acl index 49 detail <some output omitted>
l3CamInputAclDescriptor Value Mask
-----------------------------------------------------------------------------
l3Destination: AC.01.01.02 FF.FF.FF.FF
l3Source: AC.01.03.02 FF.FF.FF.FF
l4Destination: 50 FFFF
l4Source: 0 0
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 53
mask-> F8_FFFFFFFF_FFFFFFFF-FF_CC00FFFF_00000000
96 50_0A010122_0A010120-01_80000050_00000000 00040000 L3 Output
|
2970# show platform acl interface gig 0/2 2970# show interface gig 0/2 switchport
Input Label: 1 Switchport: Enabled
Output Label: 1 Access Mode VLAN: 1 (default)
Priority: normal
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 55
Agenda
Upgrading Software
High CPU
Stacking
Packet Forwarding
Access Control Lists
Multicasting
QoS
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 56
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 57
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 58
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 59
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 61
3550-
3550-2# show ip mroute (Use debug ip igmp to see the leave
(10.1.10.10, 239.10.10.10), 03:32:17/00:02:59, flags: T enter the multicast router 3550)
Incoming interface: GigabitEthernet0/12, RPF nbr 0.0.0.0
Outgoing interface list:
Vlan3,
Vlan3, Forward/Dense,
Forward/Dense, 00:00:07/00:00:00, H
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 62
3750# session 1
3750-1# show platform ip multicast hardware detail
mroute ATM SD DI RI hw-mdb stack flags
---------------------------------------------------------------------------------
(10.1.10.10, 239.10.10.10) 5E 9C 1AC7 23 1AC70023 0000 RHh
Ports(0): Gi2/0/2,
(*, 239.10.10.10) 5D 9B 1AC6 22 1AC60022 0000 RHh
Ports(7): Gi2/0/2,
Total entries in hw_list: 2
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 65
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 66
Agenda
Upgrading Software
High CPU
Stacking
Packet Forwarding
Access Control Lists
Multicasting
QoS
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 68
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 70
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 71
Trusted Interface: Identify Traffic via ACL Act on Policer Four Queues Per
Map Incoming L2 or L3 QoS and Ensure It Conforms Decision: Interface; WRR Queuing
Tag to Internal DSCP; If No to the Configured Rate with WRED (Gig Only) or
Tag Use Default CoS and Burst Mark Down Tail-Drop (Default) for
DSCP or Drop Congestion Control;
Untrusted Interface (Default): Done on an Aggregate or Out-of-Profile Optional Expedite
Use ACL (MAC or IP) to Individual Flow Basis; Up Queue
Identify and Class Traffic with to 128 Ingress Policers Set
an Internal DSCP or Trust Per Gig Interface, 8 Per Appropriate Up to 8 Individual or
Existing QoS Value and Map 10/100 Interface DSCP for In- Aggregate Egress
to Internal DSCP; If No ACL Profile Policers Per Gig or FE
Use Default CoS Physical Port or Per-Port Interface; Match on
Per-VLAN Basis (Ingress) DSCP Only
Done on a Per Interface Basis
QoS Is Disabled Globally by Default
Disable Flowcontrol on All Ports Before Enabling QoS
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 72
Taking the bigger of the 2 values above gives a minimum burst of 1518 bytes
The minimum sized burst value configurable on the 3550 however is 8000 bytes which can
hold about 5 MTU sized ethernet frames
For TCP traffic 1) above is changed to: 1518 bytes x (window size x2)
This is so that the policer does not take effect until TCP flow control kicks in; This calculation
sets the burst to twice the TCP window size
The Policing Rate does not include the 8 bytes of preamble and 1212 byte inter-
inter-frame gap (IFG)
per Ethernet frame. Because of this, the Policing Rate may seem incorrect when in reality it is
working correctly, particularly for smaller frame sizes. TCP windowing
windowing and Burst Size will also
effect the Policed Rate.
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 74
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 75
Traffic policed to DSCP 0 (1591728) is close to (2), DSCP 24 and 40 non-policed traffic
(576 + 8448 = 9024) is close to (1)
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 76
Q1 Q2 Q3 Q4
RR
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 78
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 79
3750# session 1 3750-1# show plat port-asic stats drop port 0 asic 1
3750-1# show plat port-asic stats enqueue port 0 asic 1 <output omitted>
<output omitted> RxQueue Drop Statistics
RxQueue Enqueue Statistics Queue 0
Queue 0 Weight 0 Frames: 0
Weight 0 Frames 0 Weight 1 Frames: 0
Weight 1 Frames 8 Weight 2 Frames: 0
Weight 2 Frames 0 1st Two Queues Queue 1
Queue 1 Are Internal Weight 0 Frames: 0
Weight 0 Frames 0 Weight 1 Frames: 0
Weight 1 Frames 0 System Queues Weight 2 Frames: 0
Weight 2 Frames 0 Queue 2
Queue 2 Weight 0 Frames: 0
Weight 0 Frames 1000 Weight 1 Frames: 0
Weight 1 Frames 3000 Q1 Weight 2 Frames: 0
Weight 2 Frames 39 Queue 3
Queue 3 Weight 0 Frames: 0
Weight 0 Frames 2000 Weight 1 Frames: 0
Weight 1 Frames 0 Q2 (Expedite) Weight 2 Frames: 0
Weight 2 Frames 0
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 81
3750# sho plat port-asic stats enqueue port 3 asic 2 3750# show plat port-asic stats drop port 3 asic 2
<output omitted> <output omitted>
Port 3 TxQueue Enqueue Statistics Port 3 TxQueue Drop Statistics
Queue 0 Queue 0
Weight 0 Frames 2000 Weight 0 Frames 0
Weight 1 Frames 0 Weight 1 Frames 0
Weight 2 Frames 0 Q1 (Expedite) Weight 2 Frames 0
Queue 1 Queue 1
Weight 0 Frames 1003 Weight 0 Frames 0
Weight 1 Frames 110 Weight 1 Frames 0
Weight 2 Frames 59
Q2 Weight 2 Frames 0
Queue 2 Queue 2
Weight 0 Frames 3000 Weight 0 Frames 0
Weight 1 Frames 0 Weight 1 Frames 0
Weight 2 Frames 0
Q3 Weight 2 Frames 0
Queue 3 Queue 3
Weight 0 Frames 0 Weight 0 Frames 0
Weight 1 Frames 0 Weight 1 Frames 0
Weight 2 Frames 0
Q4 Weight 2 Frames 0
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 84
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 85
RST-3507
9804_05_2004_c2 2004 Cisco Systems, Inc. All rights reserved. 86