Part number First edition June
HP 10Gb Ethernet BL-c Switch
Legal notices
Contents
802.1x authentication process
Configuring Lacp
Configuring port-based traffic control
802.1x port states
Bridge priority Port priority Port path cost
Configuration guidelines
Adding a Vlan to a Spanning Tree Group Creating a Vlan
Edge port Link type
105
100
106
109
Internal versus external routing 134
131
141
155
167
Configuring the switch for tracking 177
173
175
Introduction
Accessing the switch
Accessing the switch
Additional references
Typeface or Meaning Example Symbol
Typographical conventions
Management Network
Connecting through Secure Shell
Connecting through the console port
Connecting through Telnet
Configuring an IP interface
Using the command line interfaces
Apply, verify, and save the configuration
Using the Browser-based Interface
Default configuration
Using Simple Network Management Protocol
For more details, see Configuring Snmp trap hosts
Snmp
Cfg/sys/ssnmp/snmpv3/usm x/auth md5sha
User configuration
CLI user equivalent
View based configurations
Configure a user with no authentication or password
Configuring Snmp trap hosts
CLI oper equivalent
SNMPv1 trap host
Sys/ssnmp/snmpv3/tparam x/uname
Accessing the switch Configure an entry in the notify table
SNMPv3 trap host configuration
SNMPv2 trap host configuration
Setting allowable source IP address ranges
Secure access to the switch
How Radius authentication works
Radius authentication and authorization
Configuring an IP address range for the management network
Apply and save the configuration
Configuring Radius on the switch CLI example
Click Submit
Configuring Radius on the switch BBI example
User accounts for Radius users
Radius authentication features
User account
Description and tasks performed
Accessing the switch User access levels
TACACS+ authentication
User name/access User service type Value
Radius attributes for user privileges
TACACS+ authentication features
How TACACS+ authentication works
Authorization
User access level TACACS+ level
Accounting
Configure custom privilege-level mapping optional
Configure the TACACS+ secret and second secret
Configuring TACACS+ authentication on the switch BBI example
Secure Shell and Secure Copy
Enabling or disabling SSH
Configuring SSH and SCP features CLI example
Enter the following command to log in to the switch
Using SSH and SCP client commands
Switch prompts you for the scpadmin password
For example
SSH and SCP encryption of management messages
Generating RSA host and server keys for SSH access
User account Description Password
User access control
SSH/SCP integration with Radius and TACACS+ authentication
Enable the user ID
Setting up user IDs
Define the user name and password
Ports and trunking
Ports on the switch
Ports and trunking
Port number Port alias
Built-in fault tolerance
Before you configure trunks
Ports and trunking Ethernet switch port names
Port trunk groups
Cfg/port x/cur
Trunk group configuration rules
Port trunking example
On Switch 2, configure trunk groups 4
Configuring trunk groups CLI example
On Switch 1, configure trunk groups 5
Configuring trunk groups BBI example
Click Submit
Page
Link Aggregation Control Protocol
Configurable Trunk Hash algorithm
Actor Switch Partner Switch
Page
Define the admin key on port
Configuring Lacp
Apply and verify the configuration
Save your new configuration changes
Port-based Network Access control
Port-based Network Access and traffic control
Extensible authentication protocol over LAN
Port-based Network Access and traffic control
EAPoL Message Exchange
802.1x authentication process
802.1x port states
Attribute Attribute Value
Supported Radius attributes
Port-based traffic control
EAPoL configuration guidelines
Configuring port-based traffic control
Overview
VLANs
VLANs and port Vlan ID numbers
Vlan numbers
Port configuration
Viewing and configuring PVIDs
Pvid numbers
Viewing VLANs
Vlan tagging
VLANs
VLANs
Vlan topologies and design considerations
VLANs and IP interfaces
Vlan configuration rules
Component Description
Multiple Vlans with tagging
VLANs Multiple VLANs with tagging
Configuring the example network
Configuring ports and VLANs on Switch 1 CLI example
# add Add port 18 to Vlan Current Ports for
Configuring ports and VLANs on Switch 2 CLI example
Configuring ports and VLANs on Switch 1 BBI example
VLANs Enable the port and enable Vlan tagging
Cfg/l2/fdb/static
FDB static entries
Trunking support for FDB static entries
Configuring a static FDB entry
Spanning Tree Protocol
Spanning Tree Protocol
Bridge Protocol Data Units
Determining the path for forwarding BPDUs
Spanning Tree Group configuration guidelines
Default Spanning Tree configuration
Creating a Vlan
Adding a Vlan to a Spanning Tree Group
Rules for Vlan tagged ports
Adding and removing ports from STGs
Switch element Belongs to
Why do we need Multiple Spanning Trees?
Multiple Spanning Trees
Assigning cost to ports and trunk groups
Two VLANs on separate instances of Spanning Tree Protocol
Vlan participation in Spanning Tree Groups
Configuring Switch 2 CLI example
Configuring Multiple Spanning Tree Groups
Configuring Switch 1 CLI example
Configuring Switch 1 BBI example
Page
Configuration guidelines
Configuring Port Fast Forwarding
Configuring Fast Uplink Convergence
Port Fast Forwarding
Rapid Spanning Tree Protocol
Rstp and Mstp
Port state changes
Rstp and Mstp
Port type and link type
Rstp configuration guidelines
Rstp configuration example
Configuring Rapid Spanning Tree Protocol BBI example
Multiple Spanning Tree Protocol
Rstp and Mstp Apply, verify, and save the configuration
Mstp region
Common Internal Spanning Tree
Mstp configuration example
Mstp configuration guidelines
Configuring Multiple Spanning Tree Protocol CLI example
Assign VLANs to Spanning Tree Groups
Configuring Multiple Spanning Tree Protocol BBI example
Click Submit
Page
Apply, verify, and save the configuration
Quality of Service
Quality of Service
Number Protocol Name
Using ACL filters
Summary of packet classifiers
Number
Quality of Service Well-known protocol types
Application
Well-krown TCP flag values
Precedence Group ACLs Precedence Level
Summary of ACL actions
Understanding ACL precedence
Using ACL Groups
Viewing ACL statistics
ACL Metering and Re-marking
Metering
Re-marking
Configure Access Control Lists CLI example
ACL configuration examples
Configure Access Control Lists and Groups BBI example
Click Submit
Page
Quality of Service Add the ACL to the port
Differentiated Services concepts
Using Dscp values to provide QoS
Per Hop Behavior
Drop Precedence Class
Service Level Default PHB 802.1p Priority
Using 802.1p priorities to provide QoS
QoS levels
Class selector priority classes
Page
Configure a port’s default 802.1 priority
802.1p configuration CLI example
802.1p configuration BBI example
Quality of Service Select a port 101
102
Quality of Service Set the 802.1p priority value
103
Page
Queuing and scheduling
IP routing benefits
Basic IP routing
Routing between IP subnets
Basic IP routing
Page
Page
Interface Devices IP Interface Address
Example of subnet routing
Subnet Devices IP Addresses
Enable, apply, and verify the configuration
Using VLANs to segregate broadcast domains
Devices IP Interface Switch Port
Add the switch ports to their respective VLANs 110
111
Dhcp relay agent
Dynamic Host Configuration Protocol
Dhcp relay agent configuration
Routing Information Protocol
Routing updates
Distance vector protocol
Stability
RIP Features
RIPv2 in RIPv1 compatibility mode
RIPv1
RIPv2
Authentication
Default
Multicast
Metric
Add VLANs for routing interfaces
RIP configuration example
Add IP interfaces to VLANs
Cfg/l3/frwd/on before you turn RIP on
Igmp Snooping
Igmp Snooping
FastLeave
IGMPv3
Igmp Filtering
Configuring the range
Configuring the action
Configuring Igmp Snooping CLI example
Igmp Snooping configuration example
Enable IGMPv3 Snooping optional
Static multicast router
Configuring a Static Mrouter CLI example
Configuring Igmp Filtering CLI example
Enable Igmp Filtering on the switch
Define an Igmp Filter
Configuring Igmp Snooping BBI example
Apply, verify, and save the configuration 124
Igmp Snooping Enable Igmp Snooping
Configuring Igmp Filtering BBI example
126
Igmp Snooping Define the Igmp Filter
Select Layer 3 Igmp Igmp Filters Add Filter
Page
Apply, verify, and save the configuration 128
Configure Static Mrouter Click the Configure context button
Configuring a Static Multicast Router BBI example
Apply, verify, and save the configuration Igmp Snooping 130
Types of Ospf areas
Ospf overview
Ospf area types
Types of Ospf routing devices
Shortest Path First Tree
Neighbors and adjacencies
Link-State Database
Internal versus external routing
Ospf implementation in HP 10GbE switch software
Configurable parameters
Area index set to an arbitrary value
Defining areas
Assigning the area index
Attaching an area to a network
Using the area ID to assign the Ospf area number
Interface cost
Summarizing routes
Default routes
Electing the designated router and backup
Router ID
Virtual links
Enable Ospf authentication for Area 2 on switch
Assign MD5 key ID to Ospf interfaces on switches 1, 2,
Configure MD5 key ID for Area 0 on switches 1, 2,
Enable Ospf MD5 authentication for Area 2 on switch
Assign MD5 key ID to Ospf virtual link on switches 2
Example 1 Simple Ospf domain CLI example
Ospf configuration examples
Ospf features not supported in this release
Example 1 Simple Ospf domain BBI example
Apply, verify, and save the configuration 143
Ospf
Click Submit
146
Configure the Ospf area
Click Submit Select Add Ospf Area
Ospf
148
Click Submit Select Add Ospf Interface
Apply, verify, and save the configuration 149
Define the backbone
Configuring Ospf for a virtual link on Switch a
Example 2 Virtual links
Configure the virtual link
Configuring Ospf for a virtual link on Switch B
Switch B in step
Attach the network interface to the transit area
Define the transit area
Example 3 Summarizing routes
Other Virtual Link Options
153
Verifying Ospf configuration
Remote monitoring
Remote monitoring
Rmon group 1-statistics
View Rmon statistics for the port
Configuring Rmon Statistics CLI example
Configuring Rmon Statistics BBI example
Remote monitoring Select a port 157
Rmon group 2-history
Remote monitoring Enable Rmon on the port
History MIB objects
Configure the Rmon History parameters
Apply, verify, and save the configuration 160
Configure Rmon History BBI example
Alarm MIB objects
Rmon group 3-alarms
Configure the Rmon Alarm parameters to track Icmp messages
Configure Rmon Alarms BBI example
Apply, verify, and save the configuration 163
164
Remote monitoring Apply, verify, and save the configuration
Configuring Rmon Events CLI example
Configure the Rmon Event parameters
Rmon group 9-events
Apply, verify, and save the configuration 166
Configuring Rmon Events BBI example
High availability
High availability
Uplink Failure Detection
Spanning Tree Protocol with UFD
Failure Detection Pair
Monitoring Uplink Failure Detection
Configuring Uplink Failure Detection
Configuring UFD on Switch 2 CLI example
Configuring UFD on Switch 1 CLI example
Turn UFD on
Create a trunk group of uplink ports 18-21 to monitor
Configuring Uplink Failure Detection BBI example
Apply, verify, and save the configuration 172
Vrrp components
Vrrp overview
Virtual router
Virtual router MAC address
Vrrp operation
Master and backup virtual router
Selecting the master Vrrp router
Virtual Interface Router
Active-Active redundancy
Failover methods
Parameter
HP 10GbE switch extensions to Vrrp
Tracking Vrrp router priority
Assigning Vrrp virtual router ID
Configuring the switch for tracking
Virtual router deployment considerations
Active-Active configuration
High availability configurations
Task 1 Configure Switch a
Configure ports
Turn on Vrrp and configure two Virtual Interface Routers
High availability Configure client and server interfaces
Turn off Spanning Tree Protocol globally
179
Task 2 Configure Switch B
Vrrp Virtual Router 1#
Task 1 Configure Switch a BBI example
Click Submit
183
184
Page
High availability Enable Vrrp processing
187
Click Submit Select Add Virtual Router
Click Submit
High availability 189
Apply, verify, and save the configuration 190
Port Mirroring
Troubleshooting tools
Troubleshooting tools
Enable Port Mirroring
Configuring Port Mirroring CLI example
View the current configuration
Select the ports that you want to mirror
Configuring Port Mirroring BBI example
Click Add Mirrored Port
Other network troubleshooting techniques
Page
197
Index
Index
198