Allied Telesis 2.6.1 manual Generic Vlan Registration Protocol Gvrp, Layer 2 Switching Process

Page 80

80

AT-8800 Series Switch User Guide

Generic VLAN Registration Protocol (GVRP)

The GARP application GVRP allows switches in a network to dynamically share VLAN membership information, to reduce the need for statically configuring all VLAN membership changes on all switches in a network. See the Generic Attribute Registration Protocol (GARP) chapter in the Rapier Switch Software Reference.

Layer 2 Switching Process

The Layer 2 switching process comprises related but separate processes. The Ingress Rules admit or discard frames based on their VLAN tagging. The Learning Process learns the MAC addresses and VLAN membership of frames admitted on each port. The Forwarding Process determines which ports the frames are forwarded to, and the Quality of Service priority with which they are transmitted. Finally, the Egress Rules determine for each frame whether VLAN tags are included in the Ethernet frames that are transmitted. These processes assume that each station on the extended LAN has a unique data link layer address, and that all data link layer frames have a header which includes the source (sender’s) MAC address and destination (recipient’s) MAC address.

The Ingress Rules

When a frame first arrives at a port, the Ingress Rules for the port check the VLAN tagging in the frame to determine whether it will be discarded or forwarded to the Learning Process.

The first check depends on whether the Acceptable Frame Types parameter is set to Admit All Frames or to Admit Only VLAN Tagged Frames. A port that transmits only VLAN tagged frames, regardless of which VLAN the port belongs to, will be automatically set to Admit Only VLAN Tagged Frames. The user cannot change this setting. Frames with a null numerical VLAN Identifier (VID) are VLAN-untagged frames, or frames with priority tagging only.

Every frame received by the switch must be associated with a VLAN. If a frame is admitted by the Acceptable Frame Types parameter, the second part of the Ingress Rules associates each untagged frame admitted with the VID of the VLAN for which the port is untagged.

Every port belongs to one or more VLANs, and therefore every incoming frame will have a VID to show which VLAN it belongs to. The final part of the Ingress Rules depends on whether Ingress Filtering is enabled for the port. If Ingress Filtering is disabled, all frames are passed on to the Learning Process, regardless of which VLAN they belong to. If Ingress Filtering is enabled, frames are admitted only if they have the VID of a VLAN to which the port belongs. If they have the VID of a VLAN to which the port does not belong, they are discarded.

Software Release 2.6.1 C613-02039-00 REV A

Image 80
Contents AT-8800 Series Switch Page Contents Operating the switch AT-8800 Series Switch User GuideMaintenance and Troubleshooting Page Chapter Introducing the AT-8800 Series SwitchWhy Read this User Guide? Where To Find More Information AT-8800 Series Switch Documentation SetIntroduction Features of the AT-8800 Series SwitchOnline Technical Support Management Features Software FeaturesSpecial Feature Licences Do if You Clear Flash Memory Completely on Getting Started with the Command Line Interface CLI This ChapterParameters for terminal communication Value Connecting a Terminal or PCTerminal Communication Parameters Enter the password at the password prompt Getting Started with the Command Line Interface CLILogging Assigning an IP AddressSetting Routes To change the IP address for an interface, enter the commandTo add a static route, enter the command Changing a PasswordChoosing a Password Using the Commands Not availableAliases Getting Command Line HelpTo display the current help file, enter the command Enabling Special Feature Licences Setting System ParametersGetting Started with the Graphical User Interface GUI Getting Started with the Graphical User Interface GUIWhat is the GUI? Accessing the Switch via the GUIBrowser and PC Setup Supported browsers and operating systemsHttp Proxy Servers Establishing a Connection to the Switch See Option 3 Connecting to an Installed Switch onSee Option 1 Configuring the Switch before Installation on See Option 2 Installing the Switch into the LAN onSee Http Proxy Servers on page 23 for more information Option 1 Configuring the Switch before InstallationUse this procedure if Option 2 Installing the Switch into the LAN Default username is managerAt the login prompt, enter the user name and password Plug the switch into the LANSee Secure Access on page 29 for more information Assign the vlan1 interface an IP addressOption 3 Connecting to an Installed Switch Find out the IP address of the switch’s interfaceSelect a PC If necessary, bypass the Http proxy serverSecure Access Create a Security Officer user accountTo create an RSA key pair, use the command Then enter the password for CIPHER, sbr4y3To enable system security, use the command System Status System StatusUsing the GUI Navigation and Features Configuration MenuUsing Configuration Pages Quality of Service and traffic filtersAn example of a configuration page with a selection table Editable Fields Management Menu Monitoring MenuContext Sensitive GUI Help Diagnostics MenuChanging the Password Configuring Multiple Devices Saving Configuration Entered with the GUICombining GUI and CLI Configuration To upgrade the GUI Then delete the GUI resource file, using the commandLoad the new file onto the switch Upgrading the GUIPoint your web browser at the switch’s IP address TroubleshootingInstall the new file as the preferred GUI Accessing the Switch via the GUI Deleting Temporary FilesTraffic Flow Solution SolutionsIP Addresses and Dhcp Time and NTPLoading Software Page Using Scripts on User Accounts and PrivilegesSnmp and MIBs on A Security Officer prompt looks likeLogin Operating the switch Normal Mode and Security ModeTo display the current operating mode, enter the command Specific Parameters Remote Management Storing Files in Flash MemoryUsing Scripts Example output from the Show File commandSaving the Switch’s Configuration Storing Multiple ScriptsFile extensions and file types Extension File type/function Loading and Uploading FilesFile Naming Conventions Loading Files SPASetting Loader Defaults Example Load a Patch File Using HttpTo load a patch file Configure the Loader Download the patch fileUploading Files From the Switch Example Upload a Configuration File Using TftpMore information To upload a log fileUpgrading Switch Software Load the new release file onto the switch Example Upgrade to a New Software Release UsingTo upgrade to a new software release Enter the licence password for the software release Make the release the default permanent releaseEnter licence information for the release Test the releaseCheck that the file is successfully loaded Example Upgrade to a new patch fileTo upgrade to a new patch file Using the Built-in Editor Snmp and MIBsWhere interface is the name of an interface, such as vlan11 For More About Operations and FacilitiesAT-8800 Series Switch User Guide Switch Ports Enabling and Disabling Switch PortsTo enable or disable a switch port, use the commands To display information about switch ports, use the commandSTP Autonegotiation of Port Speed and Duplex Mode Port Trunking Speed 10/100Show VLAN=ALL Layer 2 Switching Packet Storm ProtectionPort Mirroring Port security Example output from the Show Switch Port Intrusion command Virtual Local Area Networks VLANsVlan Tagging TpidFormat of user priority and Vlan data in an Ethernet frame Vlan Membership using Vlan Tags Member ports Vlan membership of example of a network using tagged portsVlan Membership of Untagged Packets Creating VLANs Vlans with untagged portsTo add tagged ports to a VLAN, use the command To destroy a VLAN, use the commandVlan Interaction with STPs and Trunk Groups Summary of Vlan tagging rulesProtected VLANs Ingress Rules Layer 2 Switching ProcessGeneric Vlan Registration Protocol Gvrp Learning Process Forwarding Process Layer 2 Filtering Example output from the Show Switch Filter command Quality of Service Egress RulesSpanning Tree Protocol STP Spanning Tree ModesRapid Spanning Tree port states State Meaning Spanning Tree and Rapid Spanning Tree Port StatesSpanning tree port states State Meaning Configuring STP SET STP=stpnameALL PRIORITY=0..65535 Example output from the Show STP command Do not occur Switch Max Age Parameter MeaningTo display STP port information, use the command 94AT-8800 Series Switch User Guide Example output from the Show STP Port commandTo show STP counters, use the command 96AT-8800 Series Switch User Guide ReceiveTransmit DiscardedInterfaces to Layer 3 Protocols Igmp SnoopingDisable Igmpsnooping Example output from the Show IP Igmp command Group ListTriggers EventDescription ParametersLayer Then use either of the following commands Displays the interfaces enabled for IP routing FigureInternet Protocol IP IP MulticastingLayer 103 Routing Information Protocol RIPNovell IPX Example output from the Show IPX Circuit command AppleTalkResource Reservation Protocol Rsvp Layer 105Page Maintenance and Troubleshooting How the Switch Starts Up Switch startup messagesHow to Avoid Problems Set system territoryWatch for software updates What to Do if You Clear Flash Memory Completely If you accidentally do this, you will need toGetting the Most Out of Technical Support What to Do if Passwords are LostWhat to Do if the PPP Link Disconnects Regularly Resetting Switch Defaults Checking Connections Using PingTo get debugging output, enter the command Maintenance and Troubleshooting 113Troubleshooting IP Configurations To set Ping defaults, enter the commandStop a Ping that is in progress, enter the command Telnet FailsTroubleshooting Dhcp IP Addresses Your switch is acting as a Dhcp clientYour switch is acting as a Dhcp server Maintenance and Troubleshooting 115Troubleshooting IPX Configurations To check that the PPP link is active, enter the commandLocal Workstations Can Not Access Remote Servers No Routes are Visible to the Remote RouterUsing Trace Route for IP Traffic Check route tablesTo halt a trace route that is in progress, enter the command