Initial Switch Configuration
Assign Initial Management Information
23
Best Practice User Guide for the Catalyst 3850 and Catalyst 3650 Switch Series
Step 10
Following is the example for
show ip route vrf
command.
Configure a Management IP Address on an In-Band Interface
Step 11
Assign your management IP address to a VLAN interface that is used only for management, and not used
to carry other network traffic.
A VLAN interface is a Layer 3 endpoint on the subnet assigned to the corresponding VLAN.
Note
Do not use VLAN 1 as the management VLAN for security purposes.
The management VLAN is a separate VLAN for managing the switch and all other network devices in
the same subnet. You should assign an in-band IP address to a VLAN interface regardless of whether an
IP address is assigned to the out-of-band interface.
With in-band management, the IP address can be reached through the production network. For
management purposes, the in-band IP address can be used the same way as the out-of-band IP address.
There is no functional difference. However, the in-band IP address has more capabilities because this is
the source IP address for some of the auto-generated traffic that comes from the switch, for instance,
SNMP traps use the in-band IP address.
You can assign an IP address to your VLAN interface before you configure the VLAN on the switch.
The VLAN interface is not operational until the VLAN is created in hardware, and at least one physical
interface, which is a member of the VLAN, is in a forwarding state.
This example shows a VLAN created for management and indicates that the IP address is reachable.
C- IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static
o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
+ - replicated route, % - next hop override
Gateway of last resort is not set
192.168.128.5/16 is variably subnetted, 3 subnets, 2 masks
S 192.168.128.5/24 [1/0] via 192.168.128.1
C 192.168.128.5/24 is directly connected, GigabitEthernet0/0
L 192.168.128.2/32 is directly connected, GigabitEthernet0/0
ping vrf Mgmt-vrf 192.168.128.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.128.1, timeout is 2 seconds:
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/10 ms
odes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2