background image

Maintenance and Troubleshooting

123

Software Release 2.6.1
C613-02025-00 REV C

Using Trace Route for IP Traffic

You can use trace route to discover the route that packets pass between two 
systems running the IP protocol. Trace route sends an initial UDP packets with 
the Time To Live (TTL) field in the IP header set starting at 1. The TTL field is 
increased by one for every subsequent packet sent until the destination is 
reached. Each hop along the path between two systems responds with a TTL 
exceeded packet and from this the path is determined. 

To initiate a trace route, enter the command:

TRACE [[IPADDRESS=]

ipadd

] [MAXTTL=

number

] [MINTTL=

number

[NUMBER=

number

] [PORT=

port-number

] [SCREENOUTPUT={YES|NO}] 

[SOURCE=

ipadd

] [TIMEOUT=

number

] [TOS=

number

]

Any parameters not specified use the defaults configured with a previous 
invocation of the command:

SET TRACE [[IPADDRESS=]

ipadd

] [MAXTTL=

number

] [MINTTL=

number

[NUMBER=

number

] [PORT=

port-number

] [SCREENOUTPUT={YES|NO}] 

[SOURCE=

ipadd

] [TIMEOUT=

number

] [TOS=

number

]

As each response packet is received a message is displayed on the terminal 
device from which the command was entered and the details are recorded. To 
display the default configuration and summary information, enter the 
command:

SHOW TRACE

To halt a trace route that is in progress, enter the command:

STOP TRACE

For more information about trace route, see the 

Internet Protocol (IP)

 chapter in 

the 

Rapier Series Switch Software Reference.

Summary of Contents for Rapier i AT-RP16Fi/SC

Page 1: ...RAPIER SWITCH USER GUIDE Software Release 2 6 1...

Page 2: ...changes in specifications and other information contained in this document without prior written notice The information provided herein is subject to change without notice In no event shall Allied Te...

Page 3: ...14 Terminal Communication Parameters 14 Logging In 15 Assigning an IP Address 15 Setting Routes 16 Changing a Password 17 Choosing a Password 17 Using the Commands 18 Aliases 19 Getting Command Line H...

Page 4: ...ns 53 Loading Files 54 Setting LOADER Defaults 55 Example Load a Patch File Using HTTP 55 Uploading Files From the Switch 56 Example Upload a Configuration File Using TFTP 56 More information 57 Upgra...

Page 5: ...ing Information Protocol RIP 107 Novell IPX 107 AppleTalk 108 Resource Reservation Protocol RSVP 109 CHAPTER 7 Maintenance and Troubleshooting This Chapter 111 How the Switch Starts Up 112 How to Avoi...

Page 6: ......

Page 7: ...n if only to change the manager password to prevent unauthorised access To change the switching configuration and to take advantage of the advanced routing features you will need to enter detailed con...

Page 8: ...s Layer 3 features including IP IP multicasting IPX and Appletalk Chapter 7 Maintenance and Troubleshooting describes some of the commands you can use to monitor the switch and diagnose faults Where...

Page 9: ...t for Windows Information about other Allied Telesyn routing and switching products Online Technical Support For online support for your Rapier Series Switch see our online support page at http www al...

Page 10: ...omplete descriptions of these software features see the Rapier Series Switch Software Reference Software Features Rapier Layer 3 switches provide efficient and cost effective multiprotocol routing ter...

Page 11: ...streams TPAD support for fast credit card authorisation transactions A fully featured stateful inspection firewall IPsec compliant IP security services Integration with a Public Key Infrastructure PKI...

Page 12: ...ure Licences on page 20 Warning about FLASH memory Before you start to configure your switch note that it is possible to enter commands that can impact severely on your router s performance DO NOT cle...

Page 13: ...over which you will manage the switch This is necessary if you will access the switch using the GUI or Telnet see Assigning an IP Address on page 15 Set routes see Setting Routes on page 16 Change the...

Page 14: ...efault settings of the console port on the switch For instructions on how to configure HyperTerminal see the Rapier Switch Hardware Reference To start a terminal session connect to the switch in one o...

Page 15: ...o gain access to the command prompt When the switch is supplied it has a manager account with an initial password friend Enter your login name at the login prompt login manager Enter the password at t...

Page 16: ...and the Switching chapter in the Rapier Series Switch Software Reference For more information about IP addressing and routing see Chapter 6 Layer 3 in this document and the Internet Protocol IP chapt...

Page 17: ...tch Software Reference Choosing a Password All users including managers should take care in selecting passwords Tools exist that enable hackers to guess or test many combinations of login names and pa...

Page 18: ...regardless of the setting of the terminal To execute a command the cursor does not need to be at the end of the line The default editing mode is insert mode Characters are inserted at the cursor posit...

Page 19: ...topics access level USER or MANAGER and help text Both standard ASCII and Unicode character encodings are supported Alternate help files can be uploaded and stored in FLASH then activated using the co...

Page 20: ...tion is stored in the router s FLASH memory To enable or disable a special feature licence enter the commands ENABLE FEATURE feature PASSWORD password DISABLE FEATURE feature To list the current speci...

Page 21: ...servers establishing a connection to your switch including an example of configuring SSL for secure access the System Status page the first GUI page you see Using the GUI navigation and features an o...

Page 22: ...files are model specific with the model and version encoded in the file name Accessing the Switch via the GUI To use the GUI to configure the switch you use a web browser to open a connection to the...

Page 23: ...our side of the proxy server you will need to set the browser to bypass proxy entries for the IP address of the appropriate interface on the switch See Establishing a Connection to the Switch on page...

Page 24: ...es that follow take you through each possibility in detail Figure 2 A summary of the process for establishing a connection via the GUI Is the router already installed and configured in the LAN Determi...

Page 25: ...ight through Ethernet cable to connect an Ethernet card on the PC to any one of the switch ports see Figure 3 Figure 3 Connecting a PC directly to the switch You can browse to the switch through any V...

Page 26: ...ed operating system with a supported browser installed with JavaScript enabled See Browser and PC Setup on page 22 for more information You need to know the PC s subnet 2 Plug the switch into the LAN...

Page 27: ...your LAN If you need the switch s MAC address for this you can display it using the command SHOW SWITCH To set the interface to obtain its IP address by DHCP use the commands ADD IP INTERFACE VLAN1 IP...

Page 28: ...witch already has an IP address and the switch is already installed in a LAN 1 Find out the IP address of the switch s interface Ask your system administrator Alternatively access the CLI as described...

Page 29: ...ncluding passwords and email addresses can not be accessed by malicious parties This section details the required configuration For information about SSL refer to the Secure Sockets Layer SSL chapter...

Page 30: ...out contacting a CA for browsing to the GUI use the command CREATE PKI CERTIFICATE cer_name KEYPAIR 0 SERIALNUMBER 12345 SUBJECT cn 172 30 1 105 o my_company c us Using this command creates a certific...

Page 31: ...INTERFACE vlan1 IP 172 30 1 105 To add an IP route on this interface with a next hop of 172 30 1 254 use the command ADD IP ROUTE 0 0 0 0 INTERFACE vlan1 NEXT 172 30 1 254 For this example to succeed...

Page 32: ...f dynamic routes RIP multicasting and OSPF IPX Quality of Service and traffic filters Using Configuration Pages Most protocols are configured by creating or adding an entry an IP route a PIM interface...

Page 33: ...one person can configure a particular switch with the GUI at a time to avoid clashes between configurations Monitoring and diagnostics pages can be viewed by more than one user at a time Use the menu...

Page 34: ...acter strings or numbers especially for fields where there are few limits on the entries such as names See the online help for valid characters and field length select lists to select one option from...

Page 35: ...ct Apply Button An Apply button applies the configuration settings on the page or the section of the page The new settings will take effect immediately but are not automatically saved To save the sett...

Page 36: ...mation about Address Resolution Protocol ARP entries the IP route table information about the state of ping polling including counters the log messages that the switch automatically generates You can...

Page 37: ...nd process flow information The General Page Info displays when you click the Help button Click Page Element Info and roll your mouse over an element to see information about that element To freeze th...

Page 38: ...he support site at http www alliedtelesyn co nz Before you start ensure that the switch is running the most recent release and patch files The GUI is not part of the firmware release file but the most...

Page 39: ...om When the switch has loaded the file into its RAM it displays the message File transfer successfully completed It then writes the file to FLASH memory which takes approximately 30 seconds after the...

Page 40: ...f web pages as temporary files If you upgrade to a new GUI resource file or if you encounter problems in browsing to the GUI you may need to delete these files clear the cache To clear the cache in In...

Page 41: ...cannot access some pages Solution Delete your browser s temporary files see Deleting Temporary Files on page 40 and try again Check that you are trying to access the GUI from a supported operating sys...

Page 42: ...status Monitoring and that the link LED is lit see Traffic Flow on page 41 Time and NTP Diagnosis The switch s time is displayed on the Configuration System Time tab It will also be included in log pa...

Page 43: ...e Problem You have attempted to load a new release file onto the switch but the load has failed and you cannot access the switch through the GUI Solution 1 Access the switch s CLI see Connecting a Ter...

Page 44: ......

Page 45: ...ANAGER and SECURITY OFFICER By default the switch has one account manager defined with manager privilege and the default password friend The commands that a user can execute depends on the user s priv...

Page 46: ...are prompted to re enter the password The secure delay timer is by default 60 seconds If the password is not entered correctly the password prompt is repeated a set number of times If the correct pas...

Page 47: ...ecurity mode IP authentication Secure Shell see the Secure Shell chapter Rapier Series Switch Software Reference Encryption see the Compression and Encryption Services chapter Rapier Series Switch Sof...

Page 48: ...apier Series Switch Software Reference Table 5 Commands requiring SECURITY OFFICER privilege when the switch is operating in security mode Command Specific Parameters ACTIVATE IPSEC ACTIVATE SCR ADD F...

Page 49: ...BUG ENABLE PPP DEBUG ENABLE PPP TEMPLATE DEBUG ENABLE SA ENABLE SNMP ENABLE SSH ENABLE STAR MKTTRANSFER ENABLE USER LOAD MAIL MODIFY PURGE IPSEC PURGE PKI PURGE USER RENAME FILE RESET ENCO RESET IPSEC...

Page 50: ...connection is successful a login prompt from the remote switch is displayed Login using a login name that has been defined with MANAGER privilege such as the default MANAGER login name and enter the...

Page 51: ...onverts file names between DOS 16 3 format and DOS 8 3 format To reconcile file names the switch consults the translation table which is synchronised with file contents in memory For more information...

Page 52: ...ipts see the Scripting chapter in the Rapier Series Switch Software Reference For information about creating triggers see the Trigger Facility chapter in the Rapier Series Switch Software Reference Sa...

Page 53: ...form device filename ext where device specifies the physical memory device on which the file is stored FLASH If device is specified it must be separated from the rest of the file name by a colon devic...

Page 54: ...on about using Lightweight Directory Access Protocol LDAP to load PKI certificates or certificate revocation lists CRLs see the Operation chapter in the Rapier Series Switch Software Reference The rou...

Page 55: ...load To set LOADER defaults enter the command SET LOADER ATTRIBUTE CERT CRL CACERT DEFAULT BASEOBJECT dist name DEFAULT DELAY delay DEFAULT DESTFILE dest filename DESTINATION FLASH DEFAULT HTTPPROXY...

Page 56: ...s not specified with the upload command You can install Allied Telesyn s Trivial File Transfer Protocol Server AT TFTP Server on any PC or server running Windows This will provide a simple way to make...

Page 57: ...t rapier Make sure you download a patch or release file that matches your switch model A patch or release file for Rapier Series Switch has 86 as the first two digits of the filename Patch files have...

Page 58: ...patches as the temporary install and when the switch boots correctly to then set up the preferred install with the new release or patch To change the install information in the switch enter the comman...

Page 59: ...are on page 57 Load any patch files required and the help file for the release see Loading and Uploading Files on page 53 To load the release file using your LOADER default settings enter the command...

Page 60: ...om FLASH Example Upgrade to a new patch file Use this procedure to upgrade the software release currently running on the switch with a new patch This example assumes that the current release Software...

Page 61: ...in full screen text editor for editing script files stored on the switch file subsystem Using the text editor you can run script files manually or set script files to run automatically at switch resta...

Page 62: ...r the command ENABLE SNMP AUTHENTICATE_TRAP To enable the generation of link state traps for a specified interface enter the command ENABLE INTERFACE interface LINKTRAP where interface is the name of...

Page 63: ...more information on how to Use the logging facility to monitor network activity and to select and display the results see the Logging Facility chapter Use SNMP to manage the switch remotely see the Si...

Page 64: ......

Page 65: ...ection Port mirroring Support for SNMP management Enabling and Disabling Switch Ports An switch port that is enabled is available for packet reception and transmission Its administrative status in the...

Page 66: ...lticast rate limit DLF rate limit Learn limit Intrusion action Trap Current learned lock state 15 not locked Mirroring Tx to port 22 Is this port mirror port No Enabled flow control Pause Send tagged...

Page 67: ...one or a number from 1 to 256 Intrusion action The action taken on this port when a frame is received from an unknown MAC address when the port is locked One of None Discard Trap or Disable Current le...

Page 68: ...ate the highest possible common speed and duplex mode Table 8 on page 69 Setting the port to a fixed speed and duplex mode allows it to support equipment that cannot autonegotiate It is also possible...

Page 69: ...ch using the commands CREATE SWITCH TRUNK trunk PORT port list SELECT MACSRC MACDEST MACBOTH IPSRC IPDEST IPBOTH SPEED 10M 100M 1000M DESTROY SWITCH TRUNK trunk Port trunk groups can only be destroyed...

Page 70: ...ction criterion for the trunk group Each packet to be sent on the trunk group is checked using the selection criterion and a port in the trunk group chosen down which to send the packet If MACSRC is s...

Page 71: ...is specified then packet rate limiting for broadcast packets is turned off If any other value is specified the reception of broadcast packets will be limited to that number of packets per second See...

Page 72: ...hich belongs to no VLANs and therefore does not participate in any other switching Before the mirror port can be set it must be removed from all VLANs except the default VLAN The port cannot be part o...

Page 73: ...nt with an SNMP trap Discard the packet notify management with an SNMP trap and disable the port To enable port security on a port set the limit for learned MAC addresses to a value greater than zero...

Page 74: ...nto one broadcast domain irrespective of their physical position in the network Multiple VLANs can be used to group workstations servers and other network equipment connected to the switch according t...

Page 75: ...802 3ac and is four octets that can be inserted between the Source Address and the Type Length fields in the Ethernet packet Figure 14 on page 76 To accommodate the tag Standard 802 3ac also increased...

Page 76: ...frames on each port depending on whether or not the devices connected to the port are VLAN aware By assigning a port to two different VLANs to one as an untagged port and to another as a tagged port i...

Page 77: ...be associated with it on egress VLAN Membership using VLAN Tags Ports can belong to many VLANs as tagged ports Therefore when the VLAN tag is used to determine which VLAN a packet belongs to it is eas...

Page 78: ...switch must be configured to interconnect using untagged ports only A VLAN that spans several switches requires a port on each switch for the interconnection of the various parts of the VLAN If there...

Page 79: ...he ports belonging to the marketing VLAN and a second one that forwards traffic between the ports belonging to the training VLAN Devices in the marketing VLAN can only communicate with devices in the...

Page 80: ...tatic VLAN Ports tagged for some VLANs and left in the default VLAN as untagged ports will transmit broadcast traffic for the default VLAN If this is not required the unnecessary traffic in the switch...

Page 81: ...access another network Layer 3 Routing between Ports in a Protected VLAN can be prevented by adding a Layer 3 filter The Protected VLAN feature also allows all of the members of the Protected VLAN to...

Page 82: ...frame first arrives at a port the Ingress Rules for the port check the VLAN tagging in the frame to determine whether it will be discarded or forwarded to the Learning Process The first check depends...

Page 83: ...LTERING parameter enables or disables Ingress Filtering of frames admitted according to the ACCEPTABLE parameter on the specified ports Each port on the switch belongs to one or more VLANs If INFILTER...

Page 84: ...g the Forwarding Process then all switch ports in the VLAN will be flooded with the packet except the port on which the packet was received The default value of the ageing timer is 300 seconds 5 minut...

Page 85: ...ded over each port Entries in this Forwarding Database are created dynamically by the Learning Process A dynamic entry is automatically deleted from the Forwarding Database when its ageing timer expir...

Page 86: ...eleted from the Forwarding Database when its ageing timer expires Switch Filters Entry VLAN Destination Address Port Action Source 0 default 1 aa ab cd 00 00 01 1 Forward static 1 default 1 aa ab cd 0...

Page 87: ...the transmission of some frames over other frames on the basis of their user priority tagging The user priority field in an incoming frame with value 0 to 7 determines which of the eight priority leve...

Page 88: ...t Layer 3 by replacing the DSCP DiffServ Code Point or the TOS precedence value in the IP header s Type of Service TOS field Priority Level QOS egress queue 0 1 1 0 2 0 3 1 4 2 5 2 6 3 7 3 Table 14 Pa...

Page 89: ...ly recovering from a switch failure that would partition the extended LAN by reconfiguring the spanning tree to use redundant paths if available Spanning Tree Modes STP can run in STANDARD mode or RAP...

Page 90: ...erations are disabled on the port The port can still switch if its switch state is enabled LISTENING The port is enabled for receiving frames only LEARNING The port is enabled for receiving frames onl...

Page 91: ...panning Tree called default Multiple Spanning Trees can be created with each Spanning Tree encompassing multiple VLANs in networks switched exclusively by Rapier switches For more information about mu...

Page 92: ...used to control how fast a port changes its spanning state when moving towards the Forwarding state The value determines how long the port stays in each of the Listening and Learning states which pre...

Page 93: ...or instance by virtue of being more central in the physical topology of the network In these cases the STP PRIORITY parameters for at least one of the switches should be modified To change the STP pri...

Page 94: ...a Root Path Cost 0 Max Age 20 Hello Time 2 Forward Delay 15 Switch Max Age 20 Switch Hello Time 2 Switch Forward Delay 15 Transmission Limit 3 Name default Mode Standard RSTP Type n a VLAN members de...

Page 95: ...o be managed The range of values is between 0 and 65535 A lower number indicates a higher priority Designated Root The unique Bridge Identifier of the bridge assumed to be the root Standard Mode only...

Page 96: ...ree Algorithm uses the port priority when determining the root port for each switch The port with the lowest value is considered to have the highest priority The default value is 128 Each STP has its...

Page 97: ...e command SET STP stp name ALL PORT port list ALL PATHCOST 1 1000000 If the PATHCOST of a port has not been explicitly set by the user or the default values have been restored to the port then the def...

Page 98: ...d Bridge 32768 00 00 cd 05 19 28 Designated Port 8003 EdgePort No VLAN membership 1 Port 4 RSTP Port Role Disabled State Discarding Point To Point No Auto Port Priority 128 Port Identifier 8004 Pathco...

Page 99: ...ort Priority The priority of the port Used as part of the Port Identifier field In Standard mode it forms the upper 8 bits of the Port Identifier field In Rapid mode it forms the upper 4 bits of the P...

Page 100: ...ber of valid Configuration BPDUs received TCN BPDU The number of valid Topology Change Notification BPDUs received RST BPDU The number of valid Rapid Spanning Tree BPDUs received RAPID mode only Inval...

Page 101: ...to identify both the multicast groups and the host members For a VLAN aware devices this means multicast group membership is on a per VLAN basis If at least one port in the VLAN is a member of a mult...

Page 102: ...INTERFACE interface DLC 1 1024 DISABLE IP IGMP INTERFACE interface DLC 1 1024 The switch will snoop IGMP packets transiting the VLAN and only forward multicast packets to the ports which have seen a m...

Page 103: ...Member Query Interval Max Response Time inserted into Group Specific Queries sent in response to Leave Group messages and is also the amount of time between Group Specific Query messages Last Member Q...

Page 104: ...NAME name REPEAT YES NO ONCE FOREVER count TEST YES NO ON OFF The following sections list the events that may be specified for the EVENT parameter the parameters that may be specified as module specif...

Page 105: ...are of the form VLAN vlanname or VLANn where vlanname is the manager assigned name of the VLAN and n is the VLAN identifier VID For example to create a VLAN called admin with a VID of 11 and add port...

Page 106: ...se Mode are enabled with a special feature license To obtain a special feature license contact an Allied Telesyn authorised distributor or reseller The switch supports dynamic IP multicast routing pro...

Page 107: ...or reseller The switch s implementation of the Novell IPX protocol uses the term circuit to refer to a logical connection over an interface similar to an X 25 permanent virtual circuit PVC or a Frame...

Page 108: ...on page 109 use the command SHOW APPLE PORT IPX CIRCUIT information Name Circuit 1 Status enabled Interface vlan11 802 3 Network number c0e7230f Station number 0000cd000d26 Link state up Cost in Nove...

Page 109: ...o receive and process RSVP messages and accept reservation requests must be enabled To enable RSVP on the admin VLAN use the command ENABLE RSVP INTERFACE vlan11 To display information about the inter...

Page 110: ......

Page 111: ...o provide accurate support tailored to your situation see Getting the Most Out of Technical Support on page 117 restart the switch at any time with no configuration see Resetting Switch Defaults on pa...

Page 112: ...ld be able to at least proceed far enough to perform the load of the EPROM release and to start operating The install override option is designed to allow a mandatory switch boot from the EPROM releas...

Page 113: ...ch is connected to the network Some protocols are implemented in differently in some countries To ensure that the switch uses variants that will work in the country your switch is routing in enter the...

Page 114: ...me and if difficulties arise Configure Firewall The firewall facility is enabled with a special feature license To obtain a special feature license contact an Allied Telesyn authorised distributor or...

Page 115: ...ess Assign an IP address to the switch interface over which the software files are downloaded see Assigning an IP Address on page 15 5 Load software files onto switch Load the required software and pa...

Page 116: ...rk Terminator NT interface to the ISDN network at the local premises If this fails the NT may be faulty PING the Network Terminator NT interface to the ISDN network at the remote premises if known If...

Page 117: ...nose and solve your problem They may ask you to send the information to them by email Gather this information Your name organisation and contact details What is the make and model of your switch Enter...

Page 118: ...is a connection between the switch and another routing interface in the network Use the router s extended PING command over IPv4 IPv6 IPX and AppleTalk network protocols PING sends echo request packet...

Page 119: ...RIP on page 107 2 Try using Telnet to access the remote switch To Telnet from the local switch to the remote switch and from the remote switch to the local switch enter the command TELNET ipadd ipv6a...

Page 120: ...abled Refer to the documentation for the host TCP IP software for more information about configuring a gateway The host s TCP IP software should be configured to use the Head Office switch as its gate...

Page 121: ...ut from the SHOW PPP command see the Point to Point PPP chapter in the Rapier Series Switch Software Reference 2 Check IPX circuit configuration To check that the IPX circuits are correctly configured...

Page 122: ...the file server s internal network number If there is and it still does not work contact your authorised distributor or reseller for assistance Figure 32 Example output from the SHOW IPX SERVICES comm...

Page 123: ...ESS ipadd MAXTTL number MINTTL number NUMBER number PORT port number SCREENOUTPUT YES NO SOURCE ipadd TIMEOUT number TOS number Any parameters not specified use the defaults configured with a previous...

Reviews: