Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
Cisco Switching Black Book - Sean Odom, Hanson Nottingham.pdf
Скачиваний:
87
Добавлен:
24.05.2014
Размер:
2.89 Mб
Скачать

Port Single−Col

Multi−Coll Late−Coll

Excess−Col

Carri−Sen

Runts

Giants

———— ——————————

—————————— —————————

——————————

————————

——————— ——————

2/3

0

0

0

0

0

0

0

Last−Time−Cleared

—————————————

Fri Nov 24 2000, 21:53:38

Clearing MAC Addresses

The clear port security command is used to clear the MAC address from a list of secure addresses on a port. If the clear command is executed on a MAC address that is in use by an interface, the MAC address may be relearned by the switch and made secure again if dynamic port security is being used. Dynamic port security is when a switch is configured to allow only the first MAC address used on an interface to use the switch port. If another interface using another MAC address tries to use the switch port, the switch will automatically place the port in the disabled state. The light color on the switch will change from green to amber indicating the port is disabled. Cisco recommends that you disable port security before you clear any MAC addresses. Here is the command and its possible syntaxes, and an example of using the command:

clear port security mod_num/port_num {mac_addr|all} Coriolis5000> (enable) clear port security 3/10−20 all

All addresses cleared from secure address list for ports 3/10−20

Coriolis5000> (enable)

Configuring the Catalyst 5000 Supervisor Engine Module

To configure the basic configuration on a Catalyst 5000 Supervisor Engine Module, follow these steps:

1.Access the Cisco Catalyst 5000 through the console port located on the Supervisor Engine 3. The initial password is just pressing the Enter key, as shown here:

Cisco Systems Console

Enter password:

Console> enable

Enter password:

Console>(enable)

2. Configure the hostname:

Console>(enable) set prompt Catalyst5000>

Catalyst5000> (enable)

3.Configure a password for the switch. Press Enter for the old password if none has ever been configured:

Catalyst5000> (enable) set password

Enter old password:

Enter new password: coriolis1

Retype new password: coriolis1

Password changed.

131

4.Configure the password for Enable mode. Press Enter for the old password if none has ever been configured:

Catalyst5000> (enable) set enablepass

Enter old password:

Enter new password: coriolis2

Retype new password: coriolis2

Password changed.

Catalyst5000(enable)

5.Enter the IP address and the default gateway (router) for the switch on the Supervisor Engine module SC0:

Catalyst5000> (enable) set interface sc0 63.78.39.174 255.255.255.0 Interface sc0 IP address and netmask set.

Catalyst5000>(enable) set ip route default 38.68.127.254 Route added.

6.Enable trunking on interface 2/2 to complete your trunk link to the 1912EN switch and on interface 2/24 to the router for interVLAN routing:

Catalyst5000> (enable) set trunk 2/2 mode on isl Port(s) 2/2 trunk mode set to on.

Port(s) 2/2 trunk type set to isl.

2000 Nov 19 12:31:54 %DTP−5−TRUNKPORTON:Port 2/2

Catalyst5000> (enable) set trunk 2/24 mode on isl Port(s) 2/24 trunk mode set to on.

Port(s) 2/24 trunk type set to isl.

2000 Nov 19 12:32:46 %DTP−5−TRUNKPORTON:Port 2/24

7.Enable the switch to be a VTP client for the Coriolis VTP domain. Doing so will propagate the VLAN information from the 1912EN switch:

Catalyst5000> (enable) set vtp domain

?

Usage: set

vtp [domain <name>] [mode <mode>] [passwd <passwd>]

 

[pruning <enable|disable>]

[v2 <enable|disable>

(mode = client|server|transparent Use

passwd Ô0’ to clear vtp password)

Usage: set

vtp pruneeligible <vlans>

 

(vlans = 2..1000 An example of vlans is 2−10,1000)

Catalyst5000> (enable) set vtp domain

Coriolis mode client

VTP domain

Coriolis modified.

 

 

 

 

Related solution:

 

Found on page:

Testing the Supervisor Engine Hardware on a

494

Set/Clear Command−Based Switch

 

Setting the boot config−register on the Supervisor Engine Module

Here is an example of setting the boot config−register on the Supervisor Engine module. Let’s look at the command and the available syntaxes and then an example of using the command:

set boot config−register boot {rommon|bootflash|system} [module number]

Catalyst5000> (enable) set boot config−register boot rommon Configuration register is 0x0

ignore−config: disabled auto−config: non−recurring console baud: 9600

boot: the ROM monitor Catalyst5000> (enable)

132

Several other commands can be used to configure the Supervisor Engine. The following list shows some of them:

set boot config−register ignore−config enable—Sets the switch to ignore the contents of the configuration on NVRAM at startup

set boot config−register 0xvalue [module number]—Sets the configuration register value

set boot system flash device:[filename] [prepend] [module number]—Sets the system image to add to the BOOT environment variable

clear boot system flash device:[filename] [module number]—Clears a specific image from the

BOOT environment variable

clear boot system all [module number]—Clears the entire BOOT environment variable

show boot [module number]—Shows the current configuration register, BOOT environment variable, and configuration file (CONFIG_FILE) environment variable settings

Changing the Management VLAN on a Supervisor Engine

By default, the switch places all of its ports into what Cisco refers to as a native management VLAN. The native management VLAN is always configured for VLAN 1 on a Cisco switch. Cisco recommends adding another layer of security by changing the default management VLAN from VLAN 1, which is the default of all the ports on the module. To change the default VLAN from VLAN 1 to VLAN 3 on a Set/Clear command−based IOS, you use the set interface sc0 <VLAN number> command. Let’s look at the command and then examine the interface to see the changes:

Catalyst5002> (enable) set interface sc0 3

Interface sc0 vlan set.

Catalyst5002> (enable) show interfaces sc0: flags=63<UP,BROADCAST,RUNNING>

vlan 3 inet 38.187.127.11 netmask 255.255.255.0 broadcast 38.187.127.255

Catalyst5002> (enable)

Viewing the Supervisor Engine Configuration

Using the show version command, you can see the software version installed on the Supervisor Engine:

Catalyst5000> (enable) show version

WS−C5000 Software, Version McpSW: 5.5(2) NmpSW: 5.5(2)

Copyright (c) 1995−2000 by Cisco Systems

NMP S/W compiled on Jul 28 2000, 16:43:52

MCP S/W compiled on Jul 28 2000, 16:38:40

System Bootstrap Version: 3.1.2

Hardware Version: 2.0 Model: WS−C5000 Serial #: 011454261

Mod Port Model

Serial

# Versions

—————— ——————— ———————— ————————————————————

1

0

WS−X5530

011454261

Hw :

2.0

 

 

 

 

Fw :

3.1.2

 

 

 

 

Fw1:

4.2(1)

 

 

 

 

Sw :

5.5(2)

 

 

WS−F5521

011455134

Hw :

1.1

2

24

WS−X5225R 013405523

Hw :

3.1

133

 

 

 

 

Fw : 4.3(1)

 

 

 

 

 

 

Sw : 5.5(2)

 

 

 

DRAM

 

 

FLASH

 

NVRAM

 

Module Total

Used

Free

Total

Used Free

Total Used Free

—————— —————

————

—————

—————— ————— —————

————— ———— ————

1

32640K

20331K

12309K

8192K

5548K 2644K 512K

185K 327K

Uptime is 2 days, 19

hours, 3 minutes

 

 

 

Catalyst5000>

(enable)

 

 

 

 

You can also use the show module command, as shown in the following output:

Catalyst5000> (enable) show module

 

 

 

Mod

Slot Ports

Module−Type

Model

Sub

Status

——

———— —————

——————————————————

————————————

——

————————

1

1

0

Supervisor III

WS−X5530

yes

ok

2

2

24

10/100BaseTX Ethernet

WS−X5225R

no

ok

Mod

Module−Name

Serial−Num

 

 

 

————————————————— ——————————

1

00011454261

 

 

 

2

00013405523

 

 

 

Mod

MAC−Address(es)

Hw

Fw

Sw

——

——————————————————————————

————

——————

————

1

00−50−bd−a0−b0−00 to 00−50−bd−a0−b3−ff

2.0

3.1.2

5.5(2)

2

00−50−0f−b7−ff−50 to 00−50−0f−b7−ff−67

3.1

4.3(1)

5.5(2)

Mod

Sub−Type Sub−Model Sub−Serial Sub−Hw

 

 

 

—————————— ———————— —————————— ——————

1

NFFC

WS−F5521 0011455134 1.1

Catalyst5000> (enable)

Configuring the Cisco 2621 External Router for ISL Trunking

If you are going to use an external router for interVLAN routing, it helps to know how to configure it. Follow these steps to configure a 2621 for interVLAN routing:

1.Enter Interface Configuration mode for the Fast Ethernet 0/2 interface and force the port to use full duplex. Disable any IPs and use the no shutdown command:

Cisco2621(conf)# interface fastethernet 0/2

Cisco2621(conf−if)# no ip address

Cisco2621(conf−if)# no shutdown

Cisco2621(conf−if)# full−duplex

2.Create a subinterface for each VLAN and assign a description (optional), an IP address for the VLAN, an encapsulation type, and the VLAN number:

Cisco2621(conf−if)# interface fastethernet 0/2.2

Cisco2621(conf−if)# description vlan2

Cisco2621(conf−if)# ip address 63.78.39.2 255.255.255.0

Cisco2621(conf−if)# encapsulation isl 2

Cisco2621(conf−if)# interface fastethernet 0/2.3

Cisco2621(conf−if)# description vlan3

Cisco2621(conf−if)# ip address 63.78.39.3 255.255.255.0

Cisco2621(conf−if)# encapsulation isl 3

Tip Don’t forget to save your configuration. Use the show config command on each device to verify the configuration.

134

Соседние файлы в предмете Программирование