Page 12 of 57
By Krzysztof Zaleski, CCIE #24081. This Booklet is available for free and can be freely distributed in a form as is. Selling is prohibited.
BRIDGING
T
RANSPARENT
IRB
I
NTEGRATED ROUTING AND BRIDGING MAKES IT POSSIBLE TO ROUTE A SPECIFIC PROTOCOL BETWEEN
ROUTED INTERFACES AND BRIDGE GROUPS
,
OR ROUTE A SPECIFIC PROTOCOL BETWEEN BRIDGE GROUPS
T
HE BRIDGE
-
GROUP VIRTUAL INTERFACE IS A NORMAL ROUTED INTERFACE THAT DOES NOT SUPPORT
BRIDGING
,
BUT DOES REPRESENT ITS CORRESPONDING BRIDGE GROUP TO THE ROUTED INTERFACE
P
ACKETS COMING FROM A ROUTED INTERFACE
,
BUT DESTINED FOR A HOST IN A BRIDGED
DOMAIN
,
ARE ROUTED TO
BVI
AND FORWARDED TO THE CORRESPONDING BRIDGED INTERFACE
.
A
LL ROUTABLE TRAFFIC RECEIVED ON A BRIDGED INTERFACE IS ROUTED
TO OTHER ROUTED INTERFACES AS IF IT IS COMING DIRECTLY FROM
BVI.
C
OMPLIES WITH THE
IEEE 802.1D
STANDARD
bridge <bridge-group> protocol ieee
(IF) bridge-group <bridge-group>
CRB
R
OUTE A GIVEN PROTOCOL AMONG ONE GROUP OF INTERFACES AND CONCURRENTLY
BRIDGE THAT PROTOCOL AMONG A SEPARATE GROUP OF INTERFACES
P
ROTOCOL MAY BE EITHER ROUTED OR BRIDGED ON A GIVEN INTERFACE
,
BUT NOT BOTH
bridge crb
W
HEN
CRB
IS ENABLED
,
YOU MUST CONFIGURE EXPLICIT
BRIDGE ROUTE COMMAND FOR ANY PROTOCOL THAT IS TO BE
ROUTED ON THE INTERFACES IN A BRIDGE GROUP
bridge irb
interface bvi <bridge-group>
bridge <bridge-group> route <protocol>
bridge <bridge-group> bridge <protocol>
bridge <bridge-group> address <mac-address> {forward | discard} [<intf>]
SPAN
SPAN
RSPAN
T
RANSMIT
(T
X
) SPAN –
CATCH FRAMES AFTER ALL MODIFICATION AND PROCESSING IS PERFORMED BY THE SWITCH
. I
N THE
CASE OF OUTPUT
ACL
S
,
IF THE
SPAN
SOURCE DROPS THE PACKET
,
THE
SPAN
DESTINATION WOULD ALSO DROP THE PACKET
R
ECEIVE
(R
X
) SPAN –
CATCH FRAMES BEFORE ANY MODIFICATION OR PROCESSING IS PERFORMED BY THE SWITCH
. D
ESTINATION
PORT STILL RECEIVES A COPY OF THE PACKET EVEN IF THE ACTUAL INCOMING PACKET IS DROPPED BY
ACL
OD
QOS
DROP
.
T
HE REFLECTOR PORT
(C
AT
3550
ONLY
)
LOOPS BACK UNTAGGED TRAFFIC TO THE SWITCH
. I
T IS INVISIBLE TO ALL
VLAN
S
T
HE TRAFFIC IS THEN PLACED ON THE
RSPAN VLAN
AND FLOODED TO ANY TRUNK PORTS THAT CARRY THE
RSPAN VLAN
Y
OU CANNOT USE
RSPAN
TO MONITOR
L
AYER
2
PROTOCOLS
(CDP, VTP, STP)
monitor session 1 source interface fastethernet0/1 [rx | tx | both]
monitor session 1 destination interface fastethernet0/8
monitor session 1 source vlan 5 rx
vlan <id>
remote-span (
ON SOURCE SWITCH ONLY
,
REMOTE SWITCH WILL LEARN THIS INFORMATION
)
Y
OU MUST CREATE THE
RSPAN VLAN
IN ALL SWITCHES THAT WILL PARTICIPATE IN
RSPAN (VTP
CAN BE USED
)
SW1: monitor session 1 destination remote vlan 901 reflector-port fastethernet0/1
SW2: monitor session 1 source remote vlan 901
SW2: monitor session 1 destination interface fastethernet0/5
Y
OU CAN MONITOR INCOMING TRAFFIC ON A SERIES OR RANGE OF PORTS AND
VLAN
S
.
Y
OU CANNOT MONITOR OUTGOING TRAFFIC ON MULTIPLE PORTS
. O
NLY
2 SPAN
SESSIONS PER SWITCH
.
monitor session <#> filter vlan <vlan-ids> (L
IMIT THE
SPAN
SOURCE TRAFFIC TO SPECIFIED
VLAN
S
)
N
O ACCESS PORT MUST BE CONFIGURED IN THE
RSPAN VLAN. I
T CANNOT BE
1
OR
1002-1005
SW1: monitor session 1 source interface fastethernet0/1 [rx | tx | both]
SW1: monitor session 1 source vlan 5 rx
MACRO
(IF) macro apply USER_PORT $vlanID 10
macro name USER_PORT
switchport mode access
switchport access vlan $vlanID
spanning-tree portfast
R
ANGE
define interface-range <name> <intf range>
interface range macro <name>
S
MARTPORT
A
FTER APPLYING MACRO TO INTERFACE OR TO GLOBAL
CONFIG
, macro description <name>
WILL BE ADDED
C
OMMON
P
ROTOCOL
T
YPES
802.1
Q
0
X
8100
ARP 0
X
0806
RARP 0
X
8035
IP 0
X
0800
IP
V
6 0
X
86DD
PPP
O
E 0
X
8863/0
X
8864
MPLS 0
X
8847/0
X
8848
IS-IS 0
X
8000
LACP 0
X
8809
802.1
X
0
X
888E
E
THERNET STARNDARDS
IEEE 802.2 LLC
IEEE 802.3
U
FE 100M
BPS
IEEE 802.3
Z
GE 1000M
BPS
O
PTICAL
IEEE 802.3
AB
GE 1000M
BPS
C
OPPER
IEEE 802.3
AE
10GE
bridge protocol A
route protocol A
bridge and route
protocol A
BVI
bridge <bridge-group> route <protocol>
35
X
0
F
EATURES
MAC
NOTIFICATION
(G) snmp-server enable traps mac-notification
mac address-table notification change [history-size <#>] [interval <sec>]
B
Y DEFAULT TRAPS ARE SENT EVERY
1
SEC
. H
ISTORY SIZE IS
1.
(IF) snmp trap mac-notification {added | removed}
F
LEX
L
INK
F
LEX
L
INKS ARE A PAIR OF A
L
AYER
2
INTERFACES WHERE ONE INTERFACE IS CONFIGURED TO ACT AS
A BACKUP TO THE OTHER
. U
SERS CAN DISABLE
STP
AND STILL RETAIN BASIC LINK REDUNDANCY
P
REEMPTION CAN BE ENABLED SO TRAFFIC GOES BACK TO PRIMARY LINK AFTER IT COMES BACK UP
T
HE
MAC
ADDRESS
-
TABLE MOVE UPDATE FEATURE ALLOWS THE SWITCH TO PROVIDE RAPID BIDIRECTIONAL
CONVERGENCE WHEN A PRIMARY LINK GOES DOWN AND THE STANDBY LINK BEGINS FORWARDING TRAFFIC
A
BACKUP LINK DOES NOT HAVE TO BE THE SAME TYPE
STP
IS AUTOMATICALY DISABLED ON
F
LEX
L
INK PORTS
(IF) switchport backup interface <intf>
(IF) switchport backup interface <intf> preemption mode [forced | bandwidth | off]
FORCED
–
ACTIVE ALWAYS PREEMPTS
;
BANDWIDTH
-
INTF WITH HIGHER
BW
ALWAYS ACTS AS ACTIVE
(IF) switchport backup interface <intf> preemption delay <sec> (
DEFAULT
35
SEC
)
(IF) switchport backup interface <intf> mmu primary vlan <vlan-id>
I
F NOT DEFINED
,
THE LOWEST
VLAN
IS USED FOR
MAC-
ADDRESS MOVE UPDATES
(G) mac address-table move update transmit
E
NABLE THE ACCESS SWITCH TO SEND
MAC
ADDRESS
-
TABLE MOVE UPDATES TO OTHER SWITCHES
(G) mac address-table move update receive
E
NABLE THE SWITCH TO GET AND PROCESS THE
MAC
ADDRESS
-
TABLE MOVE UPDATES
F
ALLBACK
BRIDGING
W
ITH FALLBACK BRIDGING
,
THE SWITCH BRIDGES TOGETHER TWO OR MORE
VLAN
S OR
ROUTED PORTS
,
ESSENTIALLY CONNECTING MULTIPLE
VLAN
S WITHIN ONE BRIDGE DOMAIN
F
ALLBACK BRIDGING DOES NOT ALLOW SPANNING TREES FROM
VLAN
S TO COLLAPSE
. E
ACH
VLAN
HAS OWN
SPT
INSTANCE
AND A SEPARATE
SPT,
CALLED
VLAN-
BRIDGE
SPT,
WHICH RUNS ON TOP OF THE BRIDGE GROUP TO PREVENT LOOPS
bridge <bridge-group> protocol vlan-bridge
(IF) bridge-group <bridge-group>
B
Y DEFAULT
,
SWITCH FORWARDS ANY FRAMES IT HAS DYNAMICALLY LEARNED
. B
UT
,
THE SWITCH ONLY FORWARD FRAMES
WHOSE
MAC
ADDRESSES ARE STATICALLY CONFIGURED
(
STATIC
MAC
FOR BRIDGE
,
NOT FOR MAC
-
ADDRESS
-
TABLE
!!!).
(G) mac address-table notification change
1) no bridge <group> acquire
2) bridge <group> address <mac> {forward | discard} [<interface>]