Clarifications and Updates

General Switch Traffic Security Guideline

Setting Fast-Leave and Forced Fast-Leave from the CLI. In earlier switch models, including the 5300xl switches, fast-leave and forced fast-leave options for a port were configured with a lengthy setmib command. The following commands now allow a port to be configured for fast-leave or forced fast-leave operation with a conventional CLI command instead of the setmib command. Note that these commands must be executed in a VLAN context.

Syntax: [no] ip igmp fastleave < port-list>

Enables IGMP fast-leaves on the specified ports in the selected VLAN. In the Config context, use the VLAN specifier, for example, vlan < vid > ip igmp fastleave < port-list>. The no form of the command disables IGMP fast-leave. (Default: Enabled)

[no] ip igmp forcedfastleave < port-list>

Forces IGMP Fast-Leaves on the specified ports in the selected VLAN, even if they are cascaded. (Default: Disabled)

To view a non-default IGMP forced fast-leave configuration on a VLAN, use the show running-configcommand. (The show running-configoutput does not include forced fast-leave if it is set to the default of 0.)

Note

In a future version of the 3400cl switch software, the show running-configcommand output will include any non-default fast-leave settings configured. However, this information is not included in the output for the M.08.53 software release.

IGMP Operating Notes.

On the Series 3400cl switches, the delayed group flush feature offers little additional benefit over the IGMP data-driven feature (which is enabled by default).

Forced fast-leave can be used when there are multiple devices attached to a port.

General Switch Traffic Security Guideline

Where the switch is running multiple security options, it implements network traffic security based on the OSI (Open Systems Interconnection model) precedence of the individual options, from the lowest to the highest. The following list shows the order in which the switch implements configured security features on traffic moving through a given port.

1.Disabled/Enabled physical port

2.MAC lockout (Applies to all ports on the switch.)

3.MAC lockdown

22