background image

Layer 2 Switching

91

Software Release 2.6.1
C613-02025-00 REV C

To specify whether the STP will operate in STANDARD mode or RAPID mode, 
use the command:

SET STP={

stp-name

|ALL} [MODE={STANDARD|RAPID}] [

other 

parameters

]

The default is STANDARD. If the mode is changed while the algorithm is 
running then the STP is re-initialised.

To display the STP state of the switch ports (Figure 21 on page 98), use the 
command:

SHOW STP[={stp-name|ALL}] PORT={port-list|ALL}

A Rapier switch in default LAN configuration has a 

default

 Spanning Tree 

enabled, spanning only a single default VLAN, to which all ports belong. The 
switches in the LAN run a distributed Spanning Tree Algorithm to create a 
single Spanning Tree. In a network of Rapier switches with VLANs configured, 
all VLANs belong by default to a default Spanning Tree called 

default

. Multiple 

Spanning Trees can be created with each Spanning Tree encompassing multiple 
VLANs (in networks switched exclusively by Rapier switches). 

For more information about multiple spanning trees, see the 

Switching

 chapter 

in the 

Rapier Switch Software Reference

.

Overlapping VLANs belonging to multiple Spanning 
Tree instances

The Rapier 

i

 Series switches support the situation where a port is contained in 

more than one Spanning Tree instance when the port is a member of more than 
one VLAN and those VLANs belong to different STPs (See Figure 19 on 
page 91). On the Rapier 

i

 Series switches only, the number of STPs that can be 

configured is 255.

Figure 19: Port membership of VLANs which belong to different spanning tree instances (on Rapier 

i

 Series 

switches only). 

STP A

STP B

VLAN 1

VLAN 2

VLAN 3

Port 1

Port 2

Port 3

Port 2 is a member of multiple Spanning Tree Instances (STP A and STP B) because it is a member of 
multiple VLANs (VLAN 2 and VLAN 3).

SWITCH12

Содержание Rapier i AT-RP16Fi/SC

Страница 1: ...RAPIER SWITCH USER GUIDE Software Release 2 6 1...

Страница 2: ...changes in specifications and other information contained in this document without prior written notice The information provided herein is subject to change without notice In no event shall Allied Te...

Страница 3: ...14 Terminal Communication Parameters 14 Logging In 15 Assigning an IP Address 15 Setting Routes 16 Changing a Password 17 Choosing a Password 17 Using the Commands 18 Aliases 19 Getting Command Line H...

Страница 4: ...ns 53 Loading Files 54 Setting LOADER Defaults 55 Example Load a Patch File Using HTTP 55 Uploading Files From the Switch 56 Example Upload a Configuration File Using TFTP 56 More information 57 Upgra...

Страница 5: ...ing Information Protocol RIP 107 Novell IPX 107 AppleTalk 108 Resource Reservation Protocol RSVP 109 CHAPTER 7 Maintenance and Troubleshooting This Chapter 111 How the Switch Starts Up 112 How to Avoi...

Страница 6: ......

Страница 7: ...n if only to change the manager password to prevent unauthorised access To change the switching configuration and to take advantage of the advanced routing features you will need to enter detailed con...

Страница 8: ...s Layer 3 features including IP IP multicasting IPX and Appletalk Chapter 7 Maintenance and Troubleshooting describes some of the commands you can use to monitor the switch and diagnose faults Where...

Страница 9: ...t for Windows Information about other Allied Telesyn routing and switching products Online Technical Support For online support for your Rapier Series Switch see our online support page at http www al...

Страница 10: ...omplete descriptions of these software features see the Rapier Series Switch Software Reference Software Features Rapier Layer 3 switches provide efficient and cost effective multiprotocol routing ter...

Страница 11: ...streams TPAD support for fast credit card authorisation transactions A fully featured stateful inspection firewall IPsec compliant IP security services Integration with a Public Key Infrastructure PKI...

Страница 12: ...ure Licences on page 20 Warning about FLASH memory Before you start to configure your switch note that it is possible to enter commands that can impact severely on your router s performance DO NOT cle...

Страница 13: ...over which you will manage the switch This is necessary if you will access the switch using the GUI or Telnet see Assigning an IP Address on page 15 Set routes see Setting Routes on page 16 Change the...

Страница 14: ...efault settings of the console port on the switch For instructions on how to configure HyperTerminal see the Rapier Switch Hardware Reference To start a terminal session connect to the switch in one o...

Страница 15: ...o gain access to the command prompt When the switch is supplied it has a manager account with an initial password friend Enter your login name at the login prompt login manager Enter the password at t...

Страница 16: ...and the Switching chapter in the Rapier Series Switch Software Reference For more information about IP addressing and routing see Chapter 6 Layer 3 in this document and the Internet Protocol IP chapt...

Страница 17: ...tch Software Reference Choosing a Password All users including managers should take care in selecting passwords Tools exist that enable hackers to guess or test many combinations of login names and pa...

Страница 18: ...regardless of the setting of the terminal To execute a command the cursor does not need to be at the end of the line The default editing mode is insert mode Characters are inserted at the cursor posit...

Страница 19: ...topics access level USER or MANAGER and help text Both standard ASCII and Unicode character encodings are supported Alternate help files can be uploaded and stored in FLASH then activated using the co...

Страница 20: ...tion is stored in the router s FLASH memory To enable or disable a special feature licence enter the commands ENABLE FEATURE feature PASSWORD password DISABLE FEATURE feature To list the current speci...

Страница 21: ...servers establishing a connection to your switch including an example of configuring SSL for secure access the System Status page the first GUI page you see Using the GUI navigation and features an o...

Страница 22: ...files are model specific with the model and version encoded in the file name Accessing the Switch via the GUI To use the GUI to configure the switch you use a web browser to open a connection to the...

Страница 23: ...our side of the proxy server you will need to set the browser to bypass proxy entries for the IP address of the appropriate interface on the switch See Establishing a Connection to the Switch on page...

Страница 24: ...es that follow take you through each possibility in detail Figure 2 A summary of the process for establishing a connection via the GUI Is the router already installed and configured in the LAN Determi...

Страница 25: ...ight through Ethernet cable to connect an Ethernet card on the PC to any one of the switch ports see Figure 3 Figure 3 Connecting a PC directly to the switch You can browse to the switch through any V...

Страница 26: ...ed operating system with a supported browser installed with JavaScript enabled See Browser and PC Setup on page 22 for more information You need to know the PC s subnet 2 Plug the switch into the LAN...

Страница 27: ...your LAN If you need the switch s MAC address for this you can display it using the command SHOW SWITCH To set the interface to obtain its IP address by DHCP use the commands ADD IP INTERFACE VLAN1 IP...

Страница 28: ...witch already has an IP address and the switch is already installed in a LAN 1 Find out the IP address of the switch s interface Ask your system administrator Alternatively access the CLI as described...

Страница 29: ...ncluding passwords and email addresses can not be accessed by malicious parties This section details the required configuration For information about SSL refer to the Secure Sockets Layer SSL chapter...

Страница 30: ...out contacting a CA for browsing to the GUI use the command CREATE PKI CERTIFICATE cer_name KEYPAIR 0 SERIALNUMBER 12345 SUBJECT cn 172 30 1 105 o my_company c us Using this command creates a certific...

Страница 31: ...INTERFACE vlan1 IP 172 30 1 105 To add an IP route on this interface with a next hop of 172 30 1 254 use the command ADD IP ROUTE 0 0 0 0 INTERFACE vlan1 NEXT 172 30 1 254 For this example to succeed...

Страница 32: ...f dynamic routes RIP multicasting and OSPF IPX Quality of Service and traffic filters Using Configuration Pages Most protocols are configured by creating or adding an entry an IP route a PIM interface...

Страница 33: ...one person can configure a particular switch with the GUI at a time to avoid clashes between configurations Monitoring and diagnostics pages can be viewed by more than one user at a time Use the menu...

Страница 34: ...acter strings or numbers especially for fields where there are few limits on the entries such as names See the online help for valid characters and field length select lists to select one option from...

Страница 35: ...ct Apply Button An Apply button applies the configuration settings on the page or the section of the page The new settings will take effect immediately but are not automatically saved To save the sett...

Страница 36: ...mation about Address Resolution Protocol ARP entries the IP route table information about the state of ping polling including counters the log messages that the switch automatically generates You can...

Страница 37: ...nd process flow information The General Page Info displays when you click the Help button Click Page Element Info and roll your mouse over an element to see information about that element To freeze th...

Страница 38: ...he support site at http www alliedtelesyn co nz Before you start ensure that the switch is running the most recent release and patch files The GUI is not part of the firmware release file but the most...

Страница 39: ...om When the switch has loaded the file into its RAM it displays the message File transfer successfully completed It then writes the file to FLASH memory which takes approximately 30 seconds after the...

Страница 40: ...f web pages as temporary files If you upgrade to a new GUI resource file or if you encounter problems in browsing to the GUI you may need to delete these files clear the cache To clear the cache in In...

Страница 41: ...cannot access some pages Solution Delete your browser s temporary files see Deleting Temporary Files on page 40 and try again Check that you are trying to access the GUI from a supported operating sys...

Страница 42: ...status Monitoring and that the link LED is lit see Traffic Flow on page 41 Time and NTP Diagnosis The switch s time is displayed on the Configuration System Time tab It will also be included in log pa...

Страница 43: ...e Problem You have attempted to load a new release file onto the switch but the load has failed and you cannot access the switch through the GUI Solution 1 Access the switch s CLI see Connecting a Ter...

Страница 44: ......

Страница 45: ...ANAGER and SECURITY OFFICER By default the switch has one account manager defined with manager privilege and the default password friend The commands that a user can execute depends on the user s priv...

Страница 46: ...are prompted to re enter the password The secure delay timer is by default 60 seconds If the password is not entered correctly the password prompt is repeated a set number of times If the correct pas...

Страница 47: ...ecurity mode IP authentication Secure Shell see the Secure Shell chapter Rapier Series Switch Software Reference Encryption see the Compression and Encryption Services chapter Rapier Series Switch Sof...

Страница 48: ...apier Series Switch Software Reference Table 5 Commands requiring SECURITY OFFICER privilege when the switch is operating in security mode Command Specific Parameters ACTIVATE IPSEC ACTIVATE SCR ADD F...

Страница 49: ...BUG ENABLE PPP DEBUG ENABLE PPP TEMPLATE DEBUG ENABLE SA ENABLE SNMP ENABLE SSH ENABLE STAR MKTTRANSFER ENABLE USER LOAD MAIL MODIFY PURGE IPSEC PURGE PKI PURGE USER RENAME FILE RESET ENCO RESET IPSEC...

Страница 50: ...connection is successful a login prompt from the remote switch is displayed Login using a login name that has been defined with MANAGER privilege such as the default MANAGER login name and enter the...

Страница 51: ...onverts file names between DOS 16 3 format and DOS 8 3 format To reconcile file names the switch consults the translation table which is synchronised with file contents in memory For more information...

Страница 52: ...ipts see the Scripting chapter in the Rapier Series Switch Software Reference For information about creating triggers see the Trigger Facility chapter in the Rapier Series Switch Software Reference Sa...

Страница 53: ...form device filename ext where device specifies the physical memory device on which the file is stored FLASH If device is specified it must be separated from the rest of the file name by a colon devic...

Страница 54: ...on about using Lightweight Directory Access Protocol LDAP to load PKI certificates or certificate revocation lists CRLs see the Operation chapter in the Rapier Series Switch Software Reference The rou...

Страница 55: ...load To set LOADER defaults enter the command SET LOADER ATTRIBUTE CERT CRL CACERT DEFAULT BASEOBJECT dist name DEFAULT DELAY delay DEFAULT DESTFILE dest filename DESTINATION FLASH DEFAULT HTTPPROXY...

Страница 56: ...s not specified with the upload command You can install Allied Telesyn s Trivial File Transfer Protocol Server AT TFTP Server on any PC or server running Windows This will provide a simple way to make...

Страница 57: ...t rapier Make sure you download a patch or release file that matches your switch model A patch or release file for Rapier Series Switch has 86 as the first two digits of the filename Patch files have...

Страница 58: ...patches as the temporary install and when the switch boots correctly to then set up the preferred install with the new release or patch To change the install information in the switch enter the comman...

Страница 59: ...are on page 57 Load any patch files required and the help file for the release see Loading and Uploading Files on page 53 To load the release file using your LOADER default settings enter the command...

Страница 60: ...om FLASH Example Upgrade to a new patch file Use this procedure to upgrade the software release currently running on the switch with a new patch This example assumes that the current release Software...

Страница 61: ...in full screen text editor for editing script files stored on the switch file subsystem Using the text editor you can run script files manually or set script files to run automatically at switch resta...

Страница 62: ...r the command ENABLE SNMP AUTHENTICATE_TRAP To enable the generation of link state traps for a specified interface enter the command ENABLE INTERFACE interface LINKTRAP where interface is the name of...

Страница 63: ...more information on how to Use the logging facility to monitor network activity and to select and display the results see the Logging Facility chapter Use SNMP to manage the switch remotely see the Si...

Страница 64: ......

Страница 65: ...ection Port mirroring Support for SNMP management Enabling and Disabling Switch Ports An switch port that is enabled is available for packet reception and transmission Its administrative status in the...

Страница 66: ...lticast rate limit DLF rate limit Learn limit Intrusion action Trap Current learned lock state 15 not locked Mirroring Tx to port 22 Is this port mirror port No Enabled flow control Pause Send tagged...

Страница 67: ...one or a number from 1 to 256 Intrusion action The action taken on this port when a frame is received from an unknown MAC address when the port is locked One of None Discard Trap or Disable Current le...

Страница 68: ...ate the highest possible common speed and duplex mode Table 8 on page 69 Setting the port to a fixed speed and duplex mode allows it to support equipment that cannot autonegotiate It is also possible...

Страница 69: ...ch using the commands CREATE SWITCH TRUNK trunk PORT port list SELECT MACSRC MACDEST MACBOTH IPSRC IPDEST IPBOTH SPEED 10M 100M 1000M DESTROY SWITCH TRUNK trunk Port trunk groups can only be destroyed...

Страница 70: ...ction criterion for the trunk group Each packet to be sent on the trunk group is checked using the selection criterion and a port in the trunk group chosen down which to send the packet If MACSRC is s...

Страница 71: ...is specified then packet rate limiting for broadcast packets is turned off If any other value is specified the reception of broadcast packets will be limited to that number of packets per second See...

Страница 72: ...hich belongs to no VLANs and therefore does not participate in any other switching Before the mirror port can be set it must be removed from all VLANs except the default VLAN The port cannot be part o...

Страница 73: ...nt with an SNMP trap Discard the packet notify management with an SNMP trap and disable the port To enable port security on a port set the limit for learned MAC addresses to a value greater than zero...

Страница 74: ...nto one broadcast domain irrespective of their physical position in the network Multiple VLANs can be used to group workstations servers and other network equipment connected to the switch according t...

Страница 75: ...802 3ac and is four octets that can be inserted between the Source Address and the Type Length fields in the Ethernet packet Figure 14 on page 76 To accommodate the tag Standard 802 3ac also increased...

Страница 76: ...frames on each port depending on whether or not the devices connected to the port are VLAN aware By assigning a port to two different VLANs to one as an untagged port and to another as a tagged port i...

Страница 77: ...be associated with it on egress VLAN Membership using VLAN Tags Ports can belong to many VLANs as tagged ports Therefore when the VLAN tag is used to determine which VLAN a packet belongs to it is eas...

Страница 78: ...switch must be configured to interconnect using untagged ports only A VLAN that spans several switches requires a port on each switch for the interconnection of the various parts of the VLAN If there...

Страница 79: ...he ports belonging to the marketing VLAN and a second one that forwards traffic between the ports belonging to the training VLAN Devices in the marketing VLAN can only communicate with devices in the...

Страница 80: ...tatic VLAN Ports tagged for some VLANs and left in the default VLAN as untagged ports will transmit broadcast traffic for the default VLAN If this is not required the unnecessary traffic in the switch...

Страница 81: ...access another network Layer 3 Routing between Ports in a Protected VLAN can be prevented by adding a Layer 3 filter The Protected VLAN feature also allows all of the members of the Protected VLAN to...

Страница 82: ...frame first arrives at a port the Ingress Rules for the port check the VLAN tagging in the frame to determine whether it will be discarded or forwarded to the Learning Process The first check depends...

Страница 83: ...LTERING parameter enables or disables Ingress Filtering of frames admitted according to the ACCEPTABLE parameter on the specified ports Each port on the switch belongs to one or more VLANs If INFILTER...

Страница 84: ...g the Forwarding Process then all switch ports in the VLAN will be flooded with the packet except the port on which the packet was received The default value of the ageing timer is 300 seconds 5 minut...

Страница 85: ...ded over each port Entries in this Forwarding Database are created dynamically by the Learning Process A dynamic entry is automatically deleted from the Forwarding Database when its ageing timer expir...

Страница 86: ...eleted from the Forwarding Database when its ageing timer expires Switch Filters Entry VLAN Destination Address Port Action Source 0 default 1 aa ab cd 00 00 01 1 Forward static 1 default 1 aa ab cd 0...

Страница 87: ...the transmission of some frames over other frames on the basis of their user priority tagging The user priority field in an incoming frame with value 0 to 7 determines which of the eight priority leve...

Страница 88: ...t Layer 3 by replacing the DSCP DiffServ Code Point or the TOS precedence value in the IP header s Type of Service TOS field Priority Level QOS egress queue 0 1 1 0 2 0 3 1 4 2 5 2 6 3 7 3 Table 14 Pa...

Страница 89: ...ly recovering from a switch failure that would partition the extended LAN by reconfiguring the spanning tree to use redundant paths if available Spanning Tree Modes STP can run in STANDARD mode or RAP...

Страница 90: ...erations are disabled on the port The port can still switch if its switch state is enabled LISTENING The port is enabled for receiving frames only LEARNING The port is enabled for receiving frames onl...

Страница 91: ...panning Tree called default Multiple Spanning Trees can be created with each Spanning Tree encompassing multiple VLANs in networks switched exclusively by Rapier switches For more information about mu...

Страница 92: ...used to control how fast a port changes its spanning state when moving towards the Forwarding state The value determines how long the port stays in each of the Listening and Learning states which pre...

Страница 93: ...or instance by virtue of being more central in the physical topology of the network In these cases the STP PRIORITY parameters for at least one of the switches should be modified To change the STP pri...

Страница 94: ...a Root Path Cost 0 Max Age 20 Hello Time 2 Forward Delay 15 Switch Max Age 20 Switch Hello Time 2 Switch Forward Delay 15 Transmission Limit 3 Name default Mode Standard RSTP Type n a VLAN members de...

Страница 95: ...o be managed The range of values is between 0 and 65535 A lower number indicates a higher priority Designated Root The unique Bridge Identifier of the bridge assumed to be the root Standard Mode only...

Страница 96: ...ree Algorithm uses the port priority when determining the root port for each switch The port with the lowest value is considered to have the highest priority The default value is 128 Each STP has its...

Страница 97: ...e command SET STP stp name ALL PORT port list ALL PATHCOST 1 1000000 If the PATHCOST of a port has not been explicitly set by the user or the default values have been restored to the port then the def...

Страница 98: ...d Bridge 32768 00 00 cd 05 19 28 Designated Port 8003 EdgePort No VLAN membership 1 Port 4 RSTP Port Role Disabled State Discarding Point To Point No Auto Port Priority 128 Port Identifier 8004 Pathco...

Страница 99: ...ort Priority The priority of the port Used as part of the Port Identifier field In Standard mode it forms the upper 8 bits of the Port Identifier field In Rapid mode it forms the upper 4 bits of the P...

Страница 100: ...ber of valid Configuration BPDUs received TCN BPDU The number of valid Topology Change Notification BPDUs received RST BPDU The number of valid Rapid Spanning Tree BPDUs received RAPID mode only Inval...

Страница 101: ...to identify both the multicast groups and the host members For a VLAN aware devices this means multicast group membership is on a per VLAN basis If at least one port in the VLAN is a member of a mult...

Страница 102: ...INTERFACE interface DLC 1 1024 DISABLE IP IGMP INTERFACE interface DLC 1 1024 The switch will snoop IGMP packets transiting the VLAN and only forward multicast packets to the ports which have seen a m...

Страница 103: ...Member Query Interval Max Response Time inserted into Group Specific Queries sent in response to Leave Group messages and is also the amount of time between Group Specific Query messages Last Member Q...

Страница 104: ...NAME name REPEAT YES NO ONCE FOREVER count TEST YES NO ON OFF The following sections list the events that may be specified for the EVENT parameter the parameters that may be specified as module specif...

Страница 105: ...are of the form VLAN vlanname or VLANn where vlanname is the manager assigned name of the VLAN and n is the VLAN identifier VID For example to create a VLAN called admin with a VID of 11 and add port...

Страница 106: ...se Mode are enabled with a special feature license To obtain a special feature license contact an Allied Telesyn authorised distributor or reseller The switch supports dynamic IP multicast routing pro...

Страница 107: ...or reseller The switch s implementation of the Novell IPX protocol uses the term circuit to refer to a logical connection over an interface similar to an X 25 permanent virtual circuit PVC or a Frame...

Страница 108: ...on page 109 use the command SHOW APPLE PORT IPX CIRCUIT information Name Circuit 1 Status enabled Interface vlan11 802 3 Network number c0e7230f Station number 0000cd000d26 Link state up Cost in Nove...

Страница 109: ...o receive and process RSVP messages and accept reservation requests must be enabled To enable RSVP on the admin VLAN use the command ENABLE RSVP INTERFACE vlan11 To display information about the inter...

Страница 110: ......

Страница 111: ...o provide accurate support tailored to your situation see Getting the Most Out of Technical Support on page 117 restart the switch at any time with no configuration see Resetting Switch Defaults on pa...

Страница 112: ...ld be able to at least proceed far enough to perform the load of the EPROM release and to start operating The install override option is designed to allow a mandatory switch boot from the EPROM releas...

Страница 113: ...ch is connected to the network Some protocols are implemented in differently in some countries To ensure that the switch uses variants that will work in the country your switch is routing in enter the...

Страница 114: ...me and if difficulties arise Configure Firewall The firewall facility is enabled with a special feature license To obtain a special feature license contact an Allied Telesyn authorised distributor or...

Страница 115: ...ess Assign an IP address to the switch interface over which the software files are downloaded see Assigning an IP Address on page 15 5 Load software files onto switch Load the required software and pa...

Страница 116: ...rk Terminator NT interface to the ISDN network at the local premises If this fails the NT may be faulty PING the Network Terminator NT interface to the ISDN network at the remote premises if known If...

Страница 117: ...nose and solve your problem They may ask you to send the information to them by email Gather this information Your name organisation and contact details What is the make and model of your switch Enter...

Страница 118: ...is a connection between the switch and another routing interface in the network Use the router s extended PING command over IPv4 IPv6 IPX and AppleTalk network protocols PING sends echo request packet...

Страница 119: ...RIP on page 107 2 Try using Telnet to access the remote switch To Telnet from the local switch to the remote switch and from the remote switch to the local switch enter the command TELNET ipadd ipv6a...

Страница 120: ...abled Refer to the documentation for the host TCP IP software for more information about configuring a gateway The host s TCP IP software should be configured to use the Head Office switch as its gate...

Страница 121: ...ut from the SHOW PPP command see the Point to Point PPP chapter in the Rapier Series Switch Software Reference 2 Check IPX circuit configuration To check that the IPX circuits are correctly configured...

Страница 122: ...the file server s internal network number If there is and it still does not work contact your authorised distributor or reseller for assistance Figure 32 Example output from the SHOW IPX SERVICES comm...

Страница 123: ...ESS ipadd MAXTTL number MINTTL number NUMBER number PORT port number SCREENOUTPUT YES NO SOURCE ipadd TIMEOUT number TOS number Any parameters not specified use the defaults configured with a previous...

Отзывы: