Dell Force10 S4810P Bedienungsanleitung

Stöbern Sie online oder laden Sie Bedienungsanleitung nach Allgemeine Dienstprogramm-Software Dell Force10 S4810P herunter. Dell Force10 S4810P Configuration manual Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 110
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen

Inhaltsverzeichnis

Seite 1 - 9.5(0.0)

Dell Configuration Guide for the S4810 System9.5(0.0)

Seite 2 - Notes, Cautions, and Warnings

Configuring Lossless Queues... 277Configuring the PF

Seite 3 - Contents

3. The authenticator decapsulates the EAP response from the EAPOL frame, encapsulates it in a RADIUS Access-Request frame and forwards the frame to th

Seite 4

13. Verify that the VLT LAG is running in both VLT peer units.EXEC mode or EXEC Privilege modeshow interfaces interfaceExample of Configuring VLTIn th

Seite 5

Configure the VLT links between VLT peer 1 and VLT peer 2 to the Top of Rack unit. In the following example, port Te 0/40 in VLT peer 1 is connected t

Seite 6

no ip address switchport no shutdowns60-1#s60-1#show interfaces port-channel 100 briefCodes: L - LACP Port-channel LAG Mode Status Uptime

Seite 7

Figure 132. eVLT Configuration ExampleeVLT Configuration Step ExamplesIn Domain 1, configure the VLT domain and VLTi on Peer 1.Domain_1_Peer1#configur

Seite 8

Domain_1_Peer2(conf-vlt-domain)# back-up destination 10.16.130.12Domain_1_Peer2(conf-vlt-domain)# system-mac mac-address 00:0a:00:0a:00:0aDomain_1_Pee

Seite 9

Configure eVLT on Peer 4.Domain_2_Peer4(conf)#interface port-channel 100Domain_2_Peer4(conf-if-po-100)# switchportDomain_2_Peer4(conf-if-po-100)# vlt-

Seite 10

Verifying a VLT ConfigurationTo monitor the operation or verify the configuration of a VLT domain, use any of the following show commands on the prima

Seite 11

Examples of the show vlt and show spanning-tree rstp CommandsThe following example shows the show vlt backup-link command.Dell_VLTpeer1# show vlt back

Seite 12

The following example shows the show vlt detail command.Dell_VLTpeer1# show vlt detailLocal LAG Id Peer LAG Id Local Status Peer Status Active VLANs--

Seite 13

Dell_VLTpeer2# show vlt statisticsVLT Statistics----------------HeartBeat Messages Sent: 994HeartBeat Messages Received: 978ICL Hello's Sent:

Seite 14

EAP over RADIUS802.1X uses RADIUS to shuttle EAP packets between the authenticator and the authentication server, as defined in RFC 3579.EAP messages

Seite 15

Configuring Virtual Link Trunking (VLT Peer 1)Enable VLT and create a VLT domain with a backup-link and interconnect trunk (VLTi).Dell_VLTpeer1(conf)#

Seite 16

Configure the backup link.Dell_VLTpeer2(conf)#interface ManagementEthernet 0/0Dell_VLTpeer2(conf-if-ma-0/0)#ip address 10.11.206.35/Dell_VLTpeer2(conf

Seite 17

Troubleshooting VLTTo help troubleshoot different VLT issues that may occur, use the following information.NOTE: For information on VLT Failure mode t

Seite 18

Description Behavior at Peer Up Behavior During Run TimeAction to Takethat the MAC address is the same on both units.Unit ID mismatchThe VLT peer does

Seite 19

Specifying VLT Nodes in a PVLANYou can configure VLT peer nodes in a private VLAN (PVLAN). VLT enables redundancy without the implementation of Spanni

Seite 20

not validated if you associate an ICL to a PVLAN. Similarly, if you dissociate an ICL from a PVLAN, although the PVLAN parity exists, ICL is removed f

Seite 21

PVLAN Operations When a VLT Peer is RestartedWhen the VLT peer node is rebooted, the VLAN membership of the VLTi link is preserved and when the peer n

Seite 22

VLT LAG Mode PVLAN Mode of VLT VLAN ICL VLAN MembershipMac SynchronizationPeer1 Peer2 Peer1 Peer2PromiscuousTrunk Primary Primary Yes NoTrunk Access P

Seite 23

VLT LAG Mode PVLAN Mode of VLT VLAN ICL VLAN MembershipMac SynchronizationPeer1 Peer2 Peer1 Peer2Access Access Secondary (Community)Secondary (Communi

Seite 24

4. Ensure that the port channel is active.INTERFACE PORT-CHANNEL modeno shutdown5. To configure the VLT interconnect, repeat Steps 1–4 on the VLT peer

Seite 25

Important Points to Remember• Dell Networking OS supports 802.1X with EAP-MD5, EAP-OTP, EAP-TLS, EAP-TTLS, PEAPv0, PEAPv1, and MS-CHAPv2 with PEAP.• A

Seite 26

5. Access INTERFACE VLAN mode for the VLAN to which you want to assign the PVLAN interfaces.CONFIGURATION modeinterface vlan vlan-id6. Enable the VLAN

Seite 27

proxy ARP. For example, consider a sample topology in which VLAN 100 is configured on two VLT nodes, node 1 and node 2. ICL link is not configured bet

Seite 28

VLT Nodes as Rendezvous Points for Multicast ResiliencyYou can configure virtual link trunking (VLT) peer nodes as rendezvous points (RPs) in a Protoc

Seite 29

without the implementation of Spanning Tree Protocol (STP), thereby providing a loop-free network with optimal bandwidth utilization.Peer routing for

Seite 30

When VLT has been configured and enabled on both VLT node1 and node2, any dynamically learned ND entry in VLT node1 should be synchronized instantaneo

Seite 31

Sample Configuration of IPv6 Peer Routing in a VLT DomainConsider a sample scenario as shown in the following figure in which two VLT nodes, Unit1 and

Seite 32

Neighbor Solicitation from VLT HostsConsider a case in which NS for VLT node1 IP reaches VLT node1 on VLT interface and NS for VLT node1 IP reaches VL

Seite 33

Consider a sample scenario in which NS for VLT node1 IP reaches VLT node1 on non-VLT interface and NS for VLT node1 IP reaches VLT node2 on non-VLT in

Seite 34

When VLT node receives traffic intended to non-VLT host, it routes the traffic over non-VLT interface. If the traffic intended to non-VLT host reaches

Seite 35 - About this Guide

61Virtual Routing and Forwarding (VRF)Virtual Routing and Forwarding (VRF) allows a physical router to partition itself into multiple Virtual Routers

Seite 36 - Configuration Fundamentals

Enabling 802.1XEnable 802.1X globally.Figure 10. 802.1X Enabled1. Enable 802.1X globally.CONFIGURATION modedot1x authentication2. Enter INTERFACE mode

Seite 37 - Navigating CLI Modes

Figure 133. VRF Network ExampleVRF Configuration NotesAlthough there is no restriction on the number of VLANs that can be assigned to a VRF instance,

Seite 38

A network device may have the ability to configure different virtual routers, where entries in the FIB that belong to one VRF cannot be accessed by an

Seite 39

Feature/Capability Support Status for Default VRF Support Status for Non-default VRFFRRP (if applicable) for VLANs Yes NoMulticast protocols (PIM-SM,

Seite 40 - The do Command

Feature/Capability Support Status for Default VRF Support Status for Non-default VRFBGP Yes NoACL Yes YesMulticast Yes NoNDP Yes NoRAD Yes NoIngress/E

Seite 41 - Undoing Commands

Task Command Syntax Command ModeCreate a non-default VRF instance by specifying a name and VRF ID number, and enter VRF configuration mode.ip vrf vrf-

Seite 42 - Entering and Editing Commands

Configuring VRRP on a VRF InstanceYou can configure the VRRP feature on interfaces that belong to a VRF instance.In a virtualized network that consist

Seite 43 - Command History

Figure 134. Setup OSPF and Static Routes1036Virtual Routing and Forwarding (VRF)

Seite 44

Figure 135. Setup VRF InterfacesThe following example relates to the configuration shown in Figure1 and Figure 2.Virtual Routing and Forwarding (VRF)1

Seite 45

Router 1ip vrf blue 1 ! ip vrf orange 2 ! ip vrf green 3 ! interface TenGigabitEthernet 3/0 no ip address switchport no shutdown ! interfa

Seite 46 - Getting Started

Router 2ip vrf blue 1!ip vrf orange 2!ip vrf green 3!interface TenGigabitEthernet 3/0 no ip address switchport no shutdown!interface GigabitE

Seite 47 - Pin Assignments

Examples of Verifying that 802.1X is Enabled Globally and on an InterfaceVerify that 802.1X is enabled globally and at the interface level using the s

Seite 48

The following shows the output of the show commands on Router 1.Router 1Dell#show ip vrfVRF-Name VRF-ID Interfaces default-vrf

Seite 49 - Accessing the System Remotely

O - OSPF, IA - OSPF inter area, N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2, E1 - OSPF external type 1,

Seite 51 - Configuration File Management

L2 - IS-IS level-2, IA - IS-IS inter area, * - candidate default, > - non-active route, + - summary routeGateway of last res

Seite 52

ip vrf forwarding VRF2 ip address 140.0.0.1/24ip route vrf VRF1 20.0.0.0/16 140.0.0.2 vrf VRF2ip route vrf VRF2 40.0.0.0/16 120.0.0.2 vrf VRF11044V

Seite 53 - Viewing Files

62Virtual Router Redundancy Protocol (VRRP)Virtual router redundancy protocol (VRRP) is supported on the S4810 platform.VRRP OverviewVRRP is designed

Seite 54 - View Configuration Files

Figure 136. Basic VRRP ConfigurationVRRP BenefitsWith VRRP configured on a network, end-station connectivity to the network is not subject to a single

Seite 55

decreases based on the dynamics of the network, the advertisement intervals may increase or decrease accordingly.CAUTION: Increasing the advertisement

Seite 56

• Create a virtual router for that interface with a VRID.INTERFACE modevrrp-group vridThe VRID range is from 1 to 255.NOTE: The interface must already

Seite 57 - Managing the File System

You can use the version both command in INTERFACE mode to migrate from VRRPv2 to VRRPv3. When you set the VRRP version to both, the switch sends only

Seite 58

To configure re-transmissions, use the following commands.• Configure the amount of time that the authenticator waits before re-transmitting an EAP Re

Seite 59 - Upgrading Dell Networking OS

belonging to either subnet 50.1.1.0/24 or subnet 60.1.1.0/24, but not from both subnets (though Dell Networking OS allows the same).• If the virtual I

Seite 60 - Using HTTP for File Transfers

The following example shows the same VRRP group (VRID 111) configured on multiple interfaces on different subnets.Dellshow vrrp------------------Gigab

Seite 61

Hold Down: 0 sec, Preempt: TRUE, AdvInt: 1 secAdv rcvd: 0, Bad pkts rcvd: 0, Adv sent: 2343, Gratuitous ARP sent: 5Virtual MAC address: 00:00:5e:00:0

Seite 62 - Management

Disabling PreemptThe preempt command is enabled by default. The command forces the system to change the MASTER router if another router with a higher

Seite 63

If you are configured for VRRP version 2, the timer values must be in multiples of whole seconds. For example, timer value of 3 seconds or 300 centise

Seite 64

default value of 10 (also known as cost). If the tracked interface’s state goes up, the VRRP group’s priority increases by 10.The lowered priority of

Seite 65 - Configuring Logging

show track• (Optional) Display the configuration and the UP or DOWN state of tracked interfaces and objects in VRRP groups, including the time since t

Seite 66 - Audit and Security Logs

GigabitEthernet 7/30, IPv6 VRID: 1, Version: 3, Net: fe80::201:e8ff:fe01:95ccVRF: 0 default-vrfState: Master, Priority: 100, Master: fe80::201:e8ff:fe

Seite 67 - Configuring Logging Format

This time is the gap between an interface coming up and being operational, and VRRP enabling.The seconds range is from 0 to 900.The default is 0.• Set

Seite 68

Figure 137. VRRP for IPv4 TopologyExamples of Configuring VRRP for IPv4 and IPv6The following example shows configuring VRRP for IPv4 Router 2.R2(conf

Seite 69

The bold lines show the new re-transmit interval, new quiet period, and new maximum re-transmissions.FTOS(conf-if-range-Te-0/0)#dot1x tx-period 90FTOS

Seite 70 - Disabling System Logging

priority 200 virtual-address 10.1.1.3 no shutdownR2(conf-if-gi-2/31)#endR2#show vrrp------------------GigabitEthernet 2/31, VRID: 99, Net: 10.

Seite 71

Figure 138. VRRP for an IPv6 ConfigurationNOTE: In a VRRP or VRRPv3 group, if two routers come up with the same priority and another router already ha

Seite 72 - Configuration

Although R2 and R3 have the same default, priority (100), R2 is elected master in the VRRPv3 group because the GigE 0/0 interface has a higher IPv6 ad

Seite 73

VRRP in a VRF ConfigurationThe following example shows how to enable VRRP operation in a VRF virtualized network for the following scenarios.• Multipl

Seite 74 - Synchronizing Log Messages

Figure 139. VRRP in a VRF: Non-VLAN ExampleExample of Configuring VRRP in a VRF on Switch-1 (Non-VLAN)Switch-1S1(conf)#ip vrf default-vrf 0!S1(conf)#i

Seite 75 - File Transfer Services

!S1(conf)#interface GigabitEthernet 12/3S1(conf-if-gi-12/3)#ip vrf forwarding VRF-3S1(conf-if-gi-12/3)#ip address 20.1.1.5/24S1(conf-if-gi-12/3)#vrrp-

Seite 76 - Enabling the FTP Server

VRRP in VRF: Switch-1 VLAN ConfigurationVRRP in VRF: Switch-2 VLAN ConfigurationSwitch-1S1(conf)#ip vrf VRF-1 1!S1(conf)#ip vrf VRF-2 2!S1(conf)#ip vr

Seite 77 - Terminal Lines

S2(conf-if-vl-100-vrid-101)#priority 255S2(conf-if-vl-100-vrid-101)#virtual-address 10.10.1.2S2(conf-if-vl-100)#no shutdown!S2(conf-if-gi-12/4)#interf

Seite 78

63S-Series Debugging and DiagnosticsThis chapter describes debugging and diagnostics for the S4810 platform.Offline DiagnosticsThe offline diagnostics

Seite 79

Running Offline DiagnosticsTo run offline diagnostics, use the following commands.For more information, refer to the examples following the steps.1. P

Seite 80 - Lock CONFIGURATION Mode

-----------------------------Dot1x Status: EnablePort Control: FORCE_AUTHORIZEDPort Auth Status: UNAUTHORIZEDRe-Authentication:

Seite 81

Please make sure that stacking/fanout not configured for Diagnostics execution.Also reboot/online command is necessary for normal operation after the

Seite 82

The following example shows the diag command (stack member).[output from master unit]Dell#diag stack-unit 2Warning - the stack unit will be pulled out

Seite 83

PRESENTTest 1.001 - Psu Power Good Test ... PASSTest 1 - Psu Power Good Test ...

Seite 84 - S4810MXL Switch

Table 76. Line Card Restart Causes and ReasonsCauses Displayed ReasonsRemote power cycle of the chassis push button resetreload soft resetreboot after

Seite 85 - Ethernet CFM

show hardware stack-unit {0-11} buffer unit {0-1} port {1-64 | all} buffer-info• View the forwarding plane statistics containing the packet buffer sta

Seite 86 - Maintenance Points

show hardware stack-unit {0-11} unit {0-1} table-dump {table name}Enabling Environmental MonitoringThe S4810 components use environmental monitoring h

Seite 87 - Maintenance End Points

2. Check air flow through the system. Ensure that the air ducts are clean and that all fans are working correctly.3. After the software has determined

Seite 88 - Enabling Ethernet CFM

OID String OID Name Description.1.3.6.1.4.1.6027.3.16.1.1.4 fpPacketBufferTable View the modular packet buffers details per stack unit and the mode of

Seite 89 - Create Maintenance Points

• Dynamic buffer — this pool is shared memory that is allocated as needed, up to a configured limit. Using dynamic buffers provides the benefit of sta

Seite 90

• Reduce the dedicated buffer on all queues/interfaces.• Increase the dynamic buffer on all interfaces.• Increase the cell pointers on a queue that yo

Seite 91 - Displaying the MP Databases

Port Control: FORCE_AUTHORIZEDPort Auth Status: UNAUTHORIZEDRe-Authentication: EnableUntagged VLAN id: NoneTx Period:

Seite 92 - Continuity Check Messages

%S50N:0 %DIFFSERV-2-DSA_DEVICE_BUFFER_UNAVAILABLE: Unable to allocate dedicated buffers for stack-unit 0, port pipe 0, egress port 25 due to unavailab

Seite 93 - Enabling Cross-Checking

6 3.00 2567 3.00 256The following example shows viewing the default buffer profile on a linecard.Dell#sho buffer-p

Seite 94 - Caching Link Trace

Sample Buffer Profile ConfigurationThe two general types of network environments are sustained data transfers and voice/data.Dell Networking recommend

Seite 95 - Enabling CFM SNMP Traps

Displaying Drop CountersTo display drop counters, use the following commands.• Identify which stack unit, port pipe, and port is experiencing internal

Seite 96

--- Egress FORWARD PROCESSOR Drops ---IPv4 L3UC Aged & Drops : 0TTL Threshold Drops : 0INVALID VLAN CNTR Drops : 0L2MC Drops

Seite 97

Example of Viewing Party Bus StatisticsDell#sh hardware stack-unit 2 cpu party-bus statisticsInput Statistics: 27550 packets, 2559298 bytes 0 droppe

Seite 98

GTPKT.ge0 : 973 +972GTBCA.ge0 : 1 +1GTBYT.ge0 : 71,531 +71,467RUC.cpu0 : 972 +971TDBGC6.cpu0 : 1,584 +1,

Seite 99

flash: 3104256 bytes total (2959872 bytes free)Dell#Example of a Mini Core Text FileVALID MAGIC-----------------PANIC STRING -----------------panic st

Seite 100

64Standards ComplianceThis chapter describes standards compliance for Dell Networking products.NOTE: Unless noted, when a standard cited here is liste

Seite 101 - Configuring 802.1X

MTU 9,252 bytesRFC and I-D ComplianceDell Networking OS supports the following standards. The standards are grouped by related protocol. The columns s

Seite 102 - Important Points to Remember

Guest VLAN: DisableGuest VLAN id: NONEAuth-Fail VLAN: DisableAuth-Fail VLAN id: NONEAuth-Fail Max-Attempts: NON

Seite 103 - Enabling 802.1X

General IPv4 ProtocolsThe following table lists the Dell Networking OS support per platform for general IPv4 protocols.Table 80. General IPv4 Protocol

Seite 104

General IPv6 ProtocolsThe following table lists the Dell Networking OS support per platform for general IPv6 protocols.Table 81. General IPv6 Protocol

Seite 105

RFC# Full Name S-Series/Z-Series2545 Use of BGP-4 Multiprotocol Extensions for IPv6 Inter-Domain Routing2796 BGP Route Reflection: An Alternative to F

Seite 106

Intermediate System to Intermediate System (IS-IS)The following table lists the Dell Networking OS support per platform for IS-IS protocol.Table 84. I

Seite 107 - Re-Authenticating a Port

MulticastThe following table lists the Dell Networking OS support per platform for Multicast protocol.Table 86. MulticastRFC# Full Name S-Series1112 H

Seite 108 - Configuring Timeouts

RFC# Full Name S4810 S4820T Z-SeriesManagement of TCP/IP-based internets1157 A Simple Network Management Protocol (SNMP)7.6.11212 Concise MIB Definiti

Seite 109 - Authentication

RFC# Full Name S4810 S4820T Z-SeriesDigital Hierarchy (SONET/SDH) Interface Type2570 Introduction and Applicability Statements for Internet Standard M

Seite 110

RFC# Full Name S4810 S4820T Z-SeriesradiusAuthClientMalformedAccessResponsesradiusAuthClientUnknownTypesradiusAuthClientPacketsDropped2698 A Two Rate

Seite 111 - Configuring a Guest VLAN

RFC# Full Name S4810 S4820T Z-SeriesNetwork Management Protocol (SNMP)3418 Management Information Base (MIB) for the Simple Network Management Protoco

Seite 112

RFC# Full Name S4810 S4820T Z-Seriesdraft-ietf-isis-wgmib- 16Management Information Base for Intermediate System to Intermediate System (IS-IS):isisSy

Seite 113 - ACLs to VLANs

Implementation Information...322Configure the

Seite 114

Figure 11. Dynamic VLAN Assignment1. Configure 8021.x globally (refer to Enabling 802.1X) along with relevant RADIUS server configurations (refer to t

Seite 115 - Configuring ACL VLAN Groups

RFC# Full Name S4810 S4820T Z-SeriessFlow.org sFlow Version 5 7.7.1sFlow.org sFlow Version 5 MIB 7.7.1FORCE10-BGP4-V2-MIBForce10 BGP MIB (draft-ietf-i

Seite 116

RFC# Full Name S4810 S4820T Z-SeriesFORCE10-SMI Force10 Structure of Management Information7.6.1FORCE10-SYSTEM-COMPONENT-MIBForce10 System Component M

Seite 117 - Viewing CAM Usage

If the supplicant fails authentication, the authenticator typically does not enable the port. In some cases this behavior is not appropriate. External

Seite 118

!interface TenGigabitEthernet 2/1 switchport dot1x authentication dot1x guest-vlan 200no shutdownDell(conf-if-Te-2/1)#Dell(conf-if-Te-2/1)#dot1x au

Seite 119

7Access Control List (ACL) VLAN Groups and Content Addressable Memory (CAM)This chapter describes the access control list (ACL) VLAN group and content

Seite 120 - Access Control Lists (ACLs)

for the ACL VLAN groups present on the system, an appropriate error message is displayed. The ACL manager application verifies the following parameter

Seite 121 - CAM Usage

• The maximum number of VLANs that you can configure as a member of ACL VLAN groups is limited to 512 on the S4180 switch if two slices are allocated.

Seite 122 - Test CAM Usage

4. Add VLAN member(s) to an ACL VLAN group.CONFIGURATION (conf-acl-vl-grp) modemember vlan {VLAN-range}5. Display all the ACL VLAN groups or display a

Seite 123 - ACL Optimization

4. View the number of flow processor (FP) blocks that is allocated for the different VLAN services.EXEC Privilege modeDell#show cam-usage switch Linec

Seite 124

The following sample output displays the CAM space utilization when Layer 2 and Layer 3 ACLs are configured:Dell#show cam-usage aclLinecard|Portpipe|

Seite 125

You can configure only two of these features at a time.• To allocate the number of FP blocks for VLAN open flow operations, use the cam-acl-vlan vlano

Seite 126 - Configure Route Map Filters

Using FIP Snooping...350FIP Sn

Seite 127 - Configuring Match Routes

8Access Control Lists (ACLs)This chapter describes access control lists (ACLs), prefix lists, and route-maps.• Access control lists (ACLs), Ingress IP

Seite 128 - Configuring Set Conditions

• Port/VLAN based IMPLICIT DENY Rules• VRF based PERMIT/DENY Rules• VRF based IMPLICIT DENY RulesNOTE: In order for the VRF ACLs to take effect, ACLs

Seite 129

• CAM OptimizationUser Configurable CAM AllocationUser configurable CAM allocations are supported on the S4810 platform.Allocate space for IPV6 ACLs b

Seite 130 - Continue Clause

Implementing ACLs on Dell Networking OSYou can assign one IP ACL per interface with Dell Networking OS. If you do not assign an IP ACL to an interface

Seite 131 - IP Fragment Handling

closer to 0) before rules with higher-order numbers so that packets are matched as you intended. By default, all ACL rules have an order of 255.Exampl

Seite 132 - Layer 4 ACL Rules Examples

To create a route map, use the following command.• Create a route map and assign it a unique name. The optional permit and deny keywords are the actio

Seite 133 - Configure a Standard IP ACL

The following example shows a route map with multiple instances. The show config command displays only the configuration of the current route map inst

Seite 134

Example of the match Command to Permit and Deny RoutesDell(conf)#route-map force permit 10Dell(config-route-map)#match tag 1000Dell(conf)#route-map fo

Seite 135 - Configure an Extended IP ACL

• Match next-hop routes specified in a prefix list (IPv6).CONFIG-ROUTE-MAP modematch ipv6 next-hop {access-list-name | prefix-list prefix-list-name}•

Seite 136

CONFIG-ROUTE-MAP modeset local-preference value• Specify a value for redistributed routes.CONFIG-ROUTE-MAP modeset metric {+ | - | metric-value}• Spec

Seite 137

Important Points to Remember... 378Configure GVRP.

Seite 138 - Applying an IP ACL

In the following example, the redistribute command calls the route map static ospf to redistribute only certain static routes into OSPF. According to

Seite 139 - Configure Ingress ACLs

Example of Using the continue Clause in a Route Map!route-map test permit 10match commu comm-list1set community 1:1 1:2 1:3set as-path prepend 1 2 3 4

Seite 140 - Configure Egress ACLs

Layer 4 ACL Rules ExamplesThe following examples show the ACL commands for Layer 4 packet filtering.Permit an ACL line with L3 information only, and t

Seite 141 - IP Prefix Lists

Configure a Standard IP ACLTo configure an ACL, use commands in IP ACCESS LIST mode and INTERFACE mode.For a complete list of all the commands related

Seite 142 - Implementation Information

If you are creating a standard ACL with only one or two filters, you can let Dell Networking OS assign a sequence number based on the order in which t

Seite 143 - Creating a Prefix List

To delete a filter, enter the show config command in IP ACCESS LIST mode and locate the sequence number of the filter you want to delete. Then use the

Seite 144 - Viewing Prefix Lists

Configure Filters, TCP PacketsTo create a filter for UDP packets with a specified sequence number, use the following commands.1. Create an extended IP

Seite 145

CONFIG-EXT-NACL mode{deny | permit} udp {source mask | any | host ip-address}} [count [byte]] [order] [fragments]When you use the log keyword, the CP

Seite 146 - ACL Resequencing

L2 ACL Behavior L3 ACL Behavior Decision on Targeted TrafficPermit Deny L3 ACL denies.Permit Permit L3 ACL permits.NOTE: If you configure an interface

Seite 147 - Table 7. ACL Resequencing

4. Apply rules to the new ACL.INTERFACE modeip access-list [standard | extended] nameTo view which IP ACL is applied to an interface, use the show con

Seite 148 - Route Maps

IGMP Snooping...398IGMP

Seite 149 - Logging of ACL Processes

Dell#configure terminalDell(conf)#ip access-list extended abcdDell(config-ext-nacl)#permit tcp any anyDell(config-ext-nacl)#deny icmp any anyDell(conf

Seite 150 - Configuring ACL Logging

Dell#configure terminalDell(conf)#interface te 0/0Dell(conf-if-te-0/0)#ip vrf forwarding blueDell(conf-if-te-0/0)#show config!interface TenGigabitEthe

Seite 151

A route prefix is an IP address pattern that matches on bits within the IP address. The format of a route prefix is A.B.C.D/X where A.B.C.D is a dotte

Seite 152

Creating a Prefix ListTo create a prefix list, use the following commands.1. Create a prefix list and assign it a unique name.You are in PREFIX LIST m

Seite 153

Creating a Prefix List Without a Sequence NumberTo create a filter without a specified sequence number, use the following commands.1. Create a prefix

Seite 154

ip prefix-list filter_in:count: 3, range entries: 3, sequences: 5 - 10 seq 5 deny 1.102.0.0/16 le 32 (hit count: 0) seq 6 deny 2.1.0.0/16 ge 23 (h

Seite 155 - How BFD Works

Applying a Filter to a Prefix List (OSPF)To apply a filter to routes in open shortest path first (OSPF), use the following commands.• Enter OSPF mode.

Seite 156 - BFD Packet Format

Table 7. ACL ResequencingRules ResquencingRules Before Resequencing: seq 5 permit any host 1.1.1.1seq 6 permit any host 1.1.1.2seq 7 permit any host 1

Seite 157

!ip access-list extended testremark 2 XYZremark 4 this remark corresponds to permit any host 1.1.1.1seq 4 permit ip any host 1.1.1.1remark 6 this rema

Seite 158 - BFD Three-Way Handshake

Logging of ACL ProcessesThis functionality is supported on the S4810 platform.To assist in the administration and management of traffic that traverses

Seite 160 - Configure BFD

packets in the ACL entry, and if the logging is deactivated in a specific interval because the threshold has exceeded, the count of packets that excee

Seite 161 - Enabling BFD Globally

NOTE: This example describes the configuration of ACL logging for standard IP access lists. You can enable the logging capability for standard and ext

Seite 162

are traversing through the ingress interfaces are examined, and appropriate ACLs can be applied in the ingress direction. By default, flow-based monit

Seite 163

monitor session 11 flow-based enable source GigabitEthernet 13/0 destination GigabitEthernet 13/1 direction bothThe

Seite 164 - Disabling and Re-Enabling BFD

Dell(conf)#interface gig 1/1Dell(conf-if-gi-1/1)#ip access-group testflow inDell(conf-if-gi-1/1)#show config!interface GigabitEthernet 1/1 ip address

Seite 165

9Bidirectional Forwarding Detection (BFD)Bidirectional forwarding detection (BFD) is supported only on the S4810 platform.BFD is a protocol that is us

Seite 166 - Configure BFD for OSPF

NOTE: A session state change from Up to Down is the only state change that triggers a link state change in the routing protocol client.BFD Packet Form

Seite 167

Field Descriptionsystem clears the poll bit and sets the final bit in its response. The poll and final bits are used during the handshake and in Deman

Seite 168 - Disabling BFD for OSPFv3

BFD SessionsBFD must be enabled on both sides of a link in order to establish a session.The two participating systems can assume either of two roles:A

Seite 169 - Configure BFD for OSPFv3

handshake. Now the discriminator values have been exchanged and the transmit intervals have been negotiated.4. The passive system receives the control

Seite 170 - Configure BFD for IS-IS

Enhanced Validation of Interface Ranges... 44823 Internet Protocol

Seite 171

receives a Down status notification from the remote system, the session state on the local system changes to Init.Figure 14. Session State ChangesImpo

Seite 172 - Disabling BFD for IS-IS

• Configure BFD for OSPFv3• Configure BFD for IS-IS• Configure BFD for BGP• Configure BFD for VRRP• Configuring Protocol Liveness• Troubleshooting BFD

Seite 173 - Configure BFD for BGP

Establishing a Session on Physical PortsTo establish a session, enable BFD at the interface level on both ends of the link, as shown in the following

Seite 174

Remote Addr: 2.2.2.2Remote MAC Addr: 00:01:e8:06:95:a2Int: GigabitEthernet 4/24State: UpConfigured parameters: TX: 100ms, RX: 100ms, Multiplier: 3Nei

Seite 175 - Disabling BFD for BGP

Number of messages from IFA about port state change: 0 Number of messages communicated b/w Manager and Agent: 7Disabling and Re-Enabling BFDBFD is

Seite 176 - Use BFD in a BGP Peer Group

Establishing Sessions for Static RoutesSessions are established for all neighbors that are the next hop of a static route.Figure 16. Establishing Sess

Seite 177

• Change parameters for all static route sessions.CONFIGURATION modeip route bfd interval milliseconds min_rx milliseconds multiplier value role [acti

Seite 178

Establishing Sessions with OSPF NeighborsBFD sessions can be established with all OSPF neighbors at once or sessions can be established with all neigh

Seite 179

INTERFACE modeip ospf bfd all-neighborsExample of Verifying Sessions with OSPF NeighborsTo view the established sessions, use the show bfd neighbors c

Seite 180 - Configure BFD for VRRP

To disable BFD sessions, use the following commands.• Disable BFD sessions with all OSPFv3 neighbors.ROUTER-OSPFv3 modeno bfd all-neighbors• Disable B

Seite 181

UDP Helper with No Configured Broadcast Addresses...468Troubleshooting UDP Helper...

Seite 182

To change parameters for all OSPF sessions or for OSPF sessions on a single interface, use the following commands.• Change parameters for OSPF session

Seite 183 - Troubleshooting BFD

Establishing Sessions with IS-IS NeighborsBFD sessions can be established for all IS-IS neighbors at once or sessions can be established for all neigh

Seite 184

The bold line shows that IS-IS BFD sessions are enabled.R2(conf-router_isis)#bfd all-neighborsR2(conf-router_isis)#do show bfd neighbors* - Active

Seite 185 - Autonomous Systems (AS)

INTERFACE moseisis bfd all-neighbors disableConfigure BFD for BGPBidirectional forwarding detection (BFD) for BGP is supported on the S4810 platform.I

Seite 186 - Figure 21. Internal BGP

Figure 19. Establishing Sessions with BGP NeighborsThe sample configuration shows alternative ways to establish a BFD session with a BGP neighbor:• By

Seite 187 - Sessions and Peers

typical response is to terminate the peering session for the routing protocol and reconverge by bypassing the failed neighboring router. A log message

Seite 188 - Route Reflectors

ROUTER BGP modeneighbor {ip-address | peer-group-name} bfd disable• Remove the disabled state of a BFD for BGP session with a specified neighbor.ROUTE

Seite 189 - BGP Attributes

Examples of the BFD show CommandsThe following example shows verifying a BGP configuration.R2# show running-config bgp!router bgp 2 neighbor 1.1.1.2

Seite 190 - Best Path Selection Criteria

Number of messages from IFA about port state change: 0Number of messages communicated b/w Manager and Agent: 5Session Discriminator: 10Neighbor Discri

Seite 191 - Best Path Selection Details

Down : 0Admin Down : 2The following example shows viewing BFD summary information.The bold line shows the message displayed when you e

Seite 192 - Local Preference

Default iSCSI Optimization Values...495iSCSI Optimizat

Seite 193

Connections established 1; dropped 0 Last reset neverLocal host: 2.2.2.3, Local port: 63805Foreign host: 2.2.2.2, Foreign port: 179E1200i_ExaScale#

Seite 194

Establishing Sessions with All VRRP NeighborsBFD sessions can be established for all VRRP neighbors at once, or a session can be established with a pa

Seite 195 - Next Hop

The bold line shows that VRRP BFD sessions are enabled.Dell(conf-if-gi-4/25)#vrrp bfd all-neighborsDell(conf-if-gi-4/25)#do show bfd neighbor* - A

Seite 196 - Multiprotocol BGP

Disabling BFD for VRRPIf you disable any or all VRRP sessions, the sessions are torn down.A final Admin Down control packet is sent to all neighbors a

Seite 197 - Four-Byte AS Numbers

Down for neighbor 2.2.2.2 on interface Gi 4/24 (diag: 0) 00:54:38 : Sent packet for session with neighbor 2.2.2.2 on Gi 4/24 TX packet dump:

Seite 198 - AS4 Number Representation

10Border Gateway Protocol IPv4 (BGPv4)Border gateway protocol IPv4 (BGPv4) version 4 (BGPv4) is supported on the S4810 platform.This chapter provides

Seite 199 - AS Number Migration

Figure 21. Internal BGPBGP version 4 (BGPv4) supports classless interdomain routing and aggregate routes and AS paths. BGP is a path vector protocol —

Seite 200

Figure 22. BGP Routers in Full MeshThe number of BGP speakers each BGP peer must maintain increases exponentially. Network management quickly becomes

Seite 201

Establish a SessionInformation exchange between peers is driven by events and timers. The focus in BGP is on the traffic routing policies.In order to

Seite 202 - BGP Configuration

Route reflection divides iBGP peers into two groups: client peers and nonclient peers. A route reflector and its client peers form a route reflection

Seite 203 - Enabling BGP

Configuring Shared LAG State Tracking...532Important Points about Sh

Seite 204

• Next HopNOTE: There are no hard coded limits on the number of attributes that are supported in the BGP. Taking into account other constraints such a

Seite 205

Figure 24. BGP Best Path SelectionBest Path Selection Details1. Prefer the path with the largest WEIGHT attribute.2. Prefer the path with the largest

Seite 206

c. Paths with no MED are treated as “worst” and assigned a MED of 4294967295.7. Prefer external (EBGP) to internal (IBGP) paths or confederation EBGP

Seite 207

and AS300. This is advertised to all routers within AS100, causing all BGP speakers to prefer the path through Router B.Figure 25. BGP Local Preferenc

Seite 208

Figure 26. Multi-Exit DiscriminatorsNOTE: Configuring the set metric-type internal command in a route-map advertises the IGP cost as MED to outbound E

Seite 209 - Configuring Peer Groups

*> 7.0.0.0/30 10.114.8.33 0 0 18508 ?*> 9.2.0.0/16 10.114.8.33 10 0 18508 701 iAS PathThe AS path is the list of

Seite 210

Multiprotocol BGPMultiprotocol extensions for BGP (MBGP) is defined in IETF RFC 2858. MBGP allows different types of address families to be distribute

Seite 211

internal configured, BGP advertises the metric configured in the redistribute command as MED.• If BGP peer outbound route-map has metric configured, a

Seite 212

Configure 4-byte AS numbers with the four-octet-support command.AS4 Number RepresentationDell Networking OS supports multiple representations of 4-byt

Seite 213 - Configuring Passive Peering

!router bgp 100bgp asnotation asdot+bgp four-octet-as-supportneighbor 172.30.1.250 local-as 65057<output truncated>Dell(conf-router_bgp)#do show

Seite 214

Notes, Cautions, and WarningsNOTE: A NOTE indicates important information that helps you make better use of your computer.CAUTION: A CAUTION indicates

Seite 215

Disabling and Undoing LLDP...567Enabling LLDP on Ma

Seite 216 - Enabling Graceful Restart

appear as if it still belongs to Router B’s old network (AS 200) as far as communicating with Router C is concerned.Figure 27. Before and After AS Num

Seite 217

3. Prepend "65001 65002" to as-path.Local-AS is prepended before the route-map to give an impression that update passed through a router in

Seite 218

• The f10BgpM2[Cfg]PeerReflectorClient field is populated based on the assumption that route-reflector clients are not in a full mesh if you enable BG

Seite 219

By default, Dell Networking OS compares the MED attribute on different paths from within the same AS (the bgp always-compare-med command is not enable

Seite 220

NOTE: Sample Configurations for enabling BGP routers are found at the end of this chapter.1. Assign an AS number and enter ROUTER BGP mode.CONFIGURATI

Seite 221 - Enabling Additional Paths

3. Enable the BGP neighbor.CONFIG-ROUTER-BGP modeneighbor {ip-address | peer-group-name} no shutdownExamples of the show ip bgp CommandsNOTE: When you

Seite 222

For the router’s identifier, Dell Networking OS uses the highest IP address of the Loopback interfaces configured. Because Loopback interfaces are vir

Seite 223

Connections established 0; dropped 0 Last reset never No active TCP connectionDell#The following example shows verifying the BGP configuration usi

Seite 224

bgp asnotation asplainNOTE: ASPLAIN is the default method Dell Networking OS uses and does not appear in the configuration display.• Enable ASDOT AS N

Seite 225

Configuring Peer GroupsTo configure multiple BGP neighbors at one time, create and populate a BGP peer group.An advantage of peer groups is that membe

Seite 226

Debugging MSDP... 600MSDP wi

Seite 227 - Changing MED Attributes

6. Add a neighbor as a remote AS.CONFIG-ROUTERBGP modeneighbor {ip-address | peer-group name} remote-as as-numberFormats: IP Address A.B.C.D• Peer-Gro

Seite 228

neighbor 10.14.8.60 remote-as 18505 neighbor 10.14.8.60 no shutdownDell(conf-router_bgp)#To enable a peer group, use the neighbor peer-group-name n

Seite 229 - Filtering BGP Routes

10.68.183.1 10.68.184.1 10.68.185.1Dell>Configuring BGP Fast Fall-OverBy default, a BGP session is governed by the hold time.BGP routers typica

Seite 230

fall-over enabledUpdate source set to Loopback 0Peer active in peer-group outbound optimizationFor address family: IPv4 UnicastBGP table version 52, n

Seite 231

You can constrain the number of passive sessions accepted by the neighbor. The limit keyword allows you to set the total number of sessions the neighb

Seite 232

Example of the Verifying that Local AS Numbering is DisabledThe first line in bold shows the actual AS number. The second two lines in bold show the l

Seite 233 - Aggregating Routes

R2(conf-router_bgp)#show conf!router bgp 65123 bgp router-id 192.168.10.2 network 10.10.21.0/24 network 10.10.32.0/24 network 100.10.92.0/24 netw

Seite 234 - Enabling Route Flap Dampening

• Defer best path selection for a certain amount of time. This helps optimize path selection and results in fewer updates being sent out.To enable gra

Seite 235

neighbor {ip-address | peer-group-name} graceful-restart [role receiver-only]• Set the maximum time to retain the restarting neighbor’s or peer-group’

Seite 236

Example of the show ip bgp paths CommandTo view all BGP path attributes in the BGP database, use the show ip bgp paths command in EXEC Privilege mode.

Seite 237 - Changing BGP Timers

Designated and Backup Designated Routers...637Link-State Advertisements (LSA

Seite 238

Regular Expression Definition[ ] (brackets) Matches any enclosed character and specifies a range of single characters.- (hyphen) Used within brackets

Seite 239 - Enabling MBGP Configurations

Redistributing RoutesIn addition to filtering routes, you can add routes from other routing instances or protocols to the BGP process. With the redist

Seite 240 - Debugging BGP

To allow multiple paths sent to peers, use the following commands.1. Allow the advertisement of multiple paths for the same address prefix without the

Seite 241 - Storing Last and Bad PDUs

To configure an IP community list, use these commands.1. Create a community list and enter COMMUNITY-LIST mode.CONFIGURATION modeip community-list com

Seite 242 - Capturing PDUs

Configuring an IP Extended Community ListTo configure an IP extended community list, use these commands.1. Create a extended community list and enter

Seite 243 - PDU Counters

Filtering Routes with Community ListsTo use an IP community list or IP extended community list to filter routes, you must apply a match community filt

Seite 244

To view the BGP configuration, use the show config command in CONFIGURATION ROUTER BGP mode.If you want to remove or add a specific COMMUNITY number f

Seite 245

Dell>show ip bgp communityBGP table version is 3762622, local router ID is 10.114.8.48Status codes: s suppressed, d damped, h history, * valid, >

Seite 246

CONFIG-ROUTER-BGP modebgp default local-preference value– value: the range is from 0 to 4294967295.The default is 100.To view the BGP configuration, u

Seite 247

set next-hop ip-addressChanging the WEIGHT AttributeTo change how the WEIGHT attribute is used, enter the first command. You can also use route maps t

Seite 248

Enable PIM-SM...687Conf

Seite 249

For inbound and outbound updates the order of preference is:• prefix lists (using the neighbor distribute-list command)• AS-PATH ACLs (using the neigh

Seite 250 - CAM Allocation

• If the prefix list contains no filters, all routes are permitted.• If none of the routes match any of the filters in the prefix list, the route is d

Seite 251

Filtering BGP Routes Using AS-PATH InformationTo filter routes based on AS-PATH information, use these commands.1. Create a AS-PATH ACL and assign it

Seite 252 - View CAM-ACL Settings

• Assign an ID to a router reflector cluster.CONFIG-ROUTER-BGP modebgp cluster-id cluster-idYou can have multiple clusters in an AS.• Configure the lo

Seite 253

Configuring BGP ConfederationsAnother way to organize routers within an AS and reduce the mesh for IBGP peers is to configure BGP confederations.As wi

Seite 254 - View CAM Usage

• history entry — an entry that stores information on a downed route• dampened path — a path that is no longer advertised• penalized path — a path tha

Seite 255 - Troubleshoot CAM Profiling

show ip bgp flap-statistics [ip-address [mask]] [filter-list as-path-name] [regexp regular-expression]– ip-address [mask]: enter the IP address and ma

Seite 256 - QoS CAM Region Limitation

Dampening enabled. 0 history paths, 0 dampened paths, 0 penalized pathsNeighbor AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd10.114.8

Seite 257 - Control Plane Policing (CoPP)

To reset a BGP connection using BGP soft reconfiguration, use the clear ip bgp command in EXEC Privilege mode at the system prompt.When you enable sof

Seite 258

Route Map ContinueThe BGP route map continue feature, continue [sequence-number], (in ROUTE-MAP mode) allows movement from one route-map entry to a sp

Seite 259

41 Per-VLAN Spanning Tree Plus (PVST+)... 722Protocol Overview...

Seite 260

• When exchanging updates with the peer, BGP sends and receives IPv4 multicast routes if the peer is marked as supporting that AFI/SAFI.• Exchange of

Seite 261

EXEC Privilege modedebug ip bgp [ip-address | peer-group peer-group-name] notifications [in | out]• View information about BGP updates and filter by p

Seite 262 - CoPP for OSPFv3 Packets

Capabilities advertised to neighbor for IPv4 Unicast : MULTIPROTO_EXT(1) ROUTE_REFRESH(2) CISCO_ROUTE_REFRESH(128)For address family: IPv4 UnicastB

Seite 263 - Increased CPU Queues for CoPP

00000000 00000000 00000000 00000000 0181a1e4 0181a25c 41af92c0 00000000 00000000 00000000 00000000 00000001 0181a1e4 0181a25c 41af9400 00000000

Seite 264 - NDP Packets

Sample ConfigurationsThe following example configurations show how to enable BGP and set up some peer groups. These examples are not comprehensive dir

Seite 265 - Configuring CoPP for OSPFv3

no shutdownR1(conf-if-lo-0)#int te 1/21R1(conf-if-te-1/21)#ip address 10.0.1.21/24R1(conf-if-te-1/21)#no shutdownR1(conf-if-te-1/21)#show config!inter

Seite 266 - Show Commands

R2(conf-router_bgp)#network 192.168.128.0/24R2(conf-router_bgp)#neighbor 192.168.128.1 remote 99R2(conf-router_bgp)#neighbor 192.168.128.1 no shutR2(c

Seite 267

R1(conf-router_bgp)# neighbor 192.168.128.3 peer-group BBBR1(conf-router_bgp)#R1(conf-router_bgp)#show config!router bgp 99network 192.168.128.0/24nei

Seite 268 - Data Center Bridging (DCB)

Minimum time between advertisement runs is 30 secondsMinimum time before advertisements start is 0 secondsExample of Enabling Peer Groups (Router 2)R2

Seite 269 - Priority-Based Flow Control

BGP-RIB over all using 207 bytes of memory2 BGP path attribute entrie(s) using 128 bytes of memory2 BGP AS-PATH entrie(s) using 90 bytes of memory2 ne

Seite 270

Guidelines for Configuring ECN for Classifying and Color-Marking Packets... 758Sample configuration to mark non-ecn packe

Seite 271

11Content Addressable Memory (CAM)Content addressable memory (CAM) is supported on the S4810 platform.CAM is a type of memory that stores information

Seite 272

CAM Allocation SettingOpenflow 0fedgovacl 0The following additional CAM allocation settings are supported on the S6000, S4810 or S4820T platforms only

Seite 273 - Enabling Data Center Bridging

Dell(conf)#1. Select a cam-acl action.CONFIGURATION modecam-acl [default | l2acl]NOTE: Selecting default resets the CAM entries to the default setting

Seite 274

Example of Viewing CAM-ACL SettingsDell(conf)#do show cam-acl-- Chassis Cam ACL --Current Settings(in block sizes) Next Boot(in block sizes)

Seite 275

L2PT : 0IpMacAcl : 0VmanQos : 0VmanDualQos : 0EcfmAcl : 0FcoeAcl : 0iscsiO

Seite 276

Example of the show cam-usage CommandDell#show cam-usageStackunit|Portpipe| CAM Partition | Total CAM | Used CAM |Available CAM========|=======

Seite 277 - Configuring Lossless Queues

QoS CAM Region LimitationTo store QoS service policies, the default CAM profile allocates a partition within the IPv4Flow region.If the QoS CAM space

Seite 278

12Control Plane Policing (CoPP)Control plane policing (CoPP) is supported on the S4810 platform.Control plane policing (CoPP) uses access control list

Seite 279

Figure 30. CoPP Implemented Versus CoPP Not ImplementedConfigure Control Plane PolicingThe S4810 can process a maximum of 4200 packets per second (PPS

Seite 280

CoPP policies are assigned on a per-protocol or a per-queue basis, and are assigned in CONTROL-PLANE mode to each port-pipe.CoPP policies are configur

Seite 281

Configuring an EdgePort...794Configurin

Seite 282

8. Assign the protocol based the service policy on the control plane. Enabling this command on a port-pipe automatically enables the ACL and QoS rules

Seite 283

The following example shows matching the QoS class map to the QoS policy.Dell(conf)#policy-map-input egressFP_rate_policy cpu-qosDell(conf-policy-map-

Seite 284 - ETS Operation with DCBx

The following example shows assigning the QoS policy to the queues.Dell(conf)#policy-map-input cpuq_rate_policy cpu-qosDell(conf-qos-policy-in)#servic

Seite 285

ports while traversing across units and finally on the master CMIC, they are queued on the same queues 0 – 7. In this case, the queue (4 – 7) taken by

Seite 286 - Configure a DCBx Operation

FP is installed for all Front panel ports.NDP PacketsNeighbor discovery protocol has 4 types of packets NS, NA, RA, RS. These packets need to be taken

Seite 287 - DCBx Port Roles

CPU QueueWeights Rate (pps) Protocol4 127 2000 IPC/IRC, VLT Control frames5 16 300 ARP Request, NS, RS, iSCSI OPT Snooping6 16 400 ICMP, ARP Reply, NT

Seite 288

To configure control-plane policing, perform the following:1. Create an IPv6 ACL for control-plane traffic policing for ospfv3.CONFIGURATION modeDell(

Seite 289 - Configuration Source Election

Q7 1100Dell#Example of Viewing Queue MappingTo view the queue mapping for each configured protocol, use the show ip protocol-queue-mapping

Seite 290

13Data Center Bridging (DCB)Data center bridging (DCB) is supported on the S4810 platform.NOTE: Ethernet Enhancements in Data Center BridgingThe follo

Seite 291 - Configuring DCBx

network that may drop packets in case of network congestion. IP networks rely on transport protocols (for example, TCP) for reliable data transmission

Seite 292

48 Service Provider Bridging...839VLAN Stacking...

Seite 293

The system supports loading two DCB_Config files:• FCoE converged traffic with priority 3.• iSCSI storage traffic with priority 4.In the Dell Networki

Seite 294

low-latency storage or server cluster traffic in a traffic class to receive more bandwidth and restrict best-effort LAN traffic assigned to a differen

Seite 295 - DCBx Error Messages

– No bandwidth limit or no ETS processing• Bandwidth allocated by the ETS algorithm is made available after strict-priority groups are serviced. Bandw

Seite 296

Data Center Bridging in a Traffic FlowThe following figure shows how DCB handles a traffic flow on an interface.Figure 32. DCB PFC and ETS Traffic Han

Seite 297

To enable DCB with PFC buffers on a switch, enter the following commands, save the configuration, and reboot the system to allow the changes to take e

Seite 298

dot1p Value in the Incoming FrameEgress Queue Assignment5 56 67 7Configuring Priority-Based Flow ControlPFC provides a flow control mechanism based on

Seite 299

3. Configure the CoS traffic to be stopped for the specified delay.DCB INPUT POLICY modepfc priority priority-rangeEnter the 802.1p values of the fram

Seite 300

To remove a DCB input policy, including the PFC configuration it contains, use the no dcb-input policy-name command in INTERFACE Configuration mode. T

Seite 301

Lossless traffic egresses out the no-drop queues. Ingress dot1p traffic from PFC-enabled interfaces is automatically mapped to the no-drop egress queu

Seite 302

Valid stack-unit IDs are 0 to 5.The only valid port-set ID (port-pipe number) is 0.Dell Networking OS Behavior: If you configure PFC on a 40GbE port,

Seite 303

50 Simple Network Management Protocol (SNMP)... 865Protocol Overview...

Seite 304

• You can only use a QoS DCB output policy in association with a priority group in a DCB output policy and cannot be applied to an interface as a norm

Seite 305

ETS-assigned bandwidth allocation and scheduling apply only to data queues, not to control queues.Dell Networking OS supports hierarchical scheduling

Seite 306

Creating an ETS Priority GroupAn ETS priority group specifies the range of 802.1p priority traffic to which a QoS output policy with ETS settings is a

Seite 307

The maximum number of priority groups supported in ETS output policies on an interface is equal to the number of data queues (4) on the port. The 802.

Seite 308

Dell Networking OS Behavior: Create a DCB output policy to associate a priority group with an ETS output policy with scheduling and bandwidth configur

Seite 309

Configuring Bandwidth Allocation for DCBx CINAfter you apply an ETS output policy to an interface, if the DCBx version used in your data center networ

Seite 310

dcb-policy input stack-unit {all | stack-unit-id} stack-ports all dcb-input-policy-nameEntering this command removes all DCB input policies applied to

Seite 311

DCBx OperationDCBx performs the following operations:• Discovers DCB configuration (such as PFC and ETS) in a peer device.• Detects DCB mis-configurat

Seite 312 - Applying a DCB Map on a Port

• If the received peer configuration is not compatible with the currently configured port configuration, the link with the DCBx peer port is disabled

Seite 313

NOTE: On a DCBx port, application priority TLV advertisements are handled as follows:• The application priority TLV is transmitted only if the priorit

Seite 314

Failover Roles... 893MAC Ad

Seite 315 - Pause and Resume of Traffic

A newly elected configuration source propagates configuration changes received from a peer to the other auto-configuration ports. Ports receiving auto

Seite 316 - Settings

DCBx ExampleThe following figure shows how to use DCBx.The external 40GbE ports on the base module (ports 33 and 37) of two switches are used for upli

Seite 317

1. Configure ToR- and FCF-facing interfaces as auto-upstream ports.2. Configure server-facing interfaces as auto-downstream ports.3. Configure a port

Seite 318

5. On manual ports only: Configure the PFC and ETS TLVs advertised to DCBx peers.PROTOCOL LLDP mode[no] advertise DCBx-tlv {ets-conf | ets-reco | pfc}

Seite 319 - Figure 35. DHCP packet Format

3. Configure the DCBx version used on all interfaces not already configured to exchange DCB information.PROTOCL LLDP mode[no] DCBx version {auto | cee

Seite 320

6. Configure the FCoE priority advertised for the FCoE protocol in Application Priority TLVs.PROTOCOL LLDP mode[no] fcoe priority-bits priority-bitmap

Seite 321

– fail: enables traces for DCBx failures.– mgmt: enables traces for DCBx management frames.– resource: enables traces for DCBx system resource frames.

Seite 322

Command Outputshow stack-unit {0-11 | all} stack ports all ets detailsDisplays the ETS configuration applied to ingress traffic on stack-links, includ

Seite 323

FCOE TLV Tx Status is disabled ISCSI TLV Tx Status is disabled Local FCOE PriorityMap is 0x8 Local ISCSI PriorityMap is 0x10 Remote FC

Seite 324 - Configuration Tasks

Fields DescriptionPort state for current operational PFC configuration:• Init: Local PFC configuration parameters were exchanged with peer.• Recommend

Seite 325 - Specifying a Default Gateway

Contents1 About this Guide...35Audience...

Seite 326 - Using DHCP Clear Commands

Enabling PortFast... 923Pre

Seite 327

Fields DescriptionPFC TLV Statistics: Pause Rx pkts Number of PFC pause frames receivedThe following example shows the show interface pfc statistics c

Seite 328

Oper status is initETS DCBx Oper status is DownState Machine Type is AsymmetricConf TLV Tx Status is enabledReco TLV Tx Status is enabled0 Input Conf

Seite 329

Traffic ClassPktsThe following example shows the show interface ets detail command.Dell(conf)# show interfaces tengigabitethernet 0/0 ets detailInterf

Seite 330

Traffic Class TLVPktsThe following table describes the show interface ets detail command fields.Table 15. show interface ets detail Command Descriptio

Seite 331 - Stacking

Field DescriptionConf TLV Tx Status Status of ETS Configuration TLV advertisements: enabled or disabled.ETS TLV Statistic: Input Conf TLV pkts Number

Seite 332 - DHCP Server

0 0,1,2,3,4,5,6,7 100% ETS1 - -2 - -3

Seite 333 - Configure Secure DHCP

Local DCBx Status----------------- DCBx Operational Version is 0 DCBx Max Version Supported is 0 Sequence Number: 1 Acknowledgment Number: 1 Prot

Seite 334

Field DescriptionLocal DCBx Status: Sequence Number Sequence number transmitted in Control TLVs.Local DCBx Status: Acknowledgment Number Acknowledgeme

Seite 335 - Clearing the Binding Table

Figure 34. PFC and ETS Applied to LAN, IPC, and SAN Priority TrafficQoS Traffic Classification: The service-class dynamic dot1p command has been used

Seite 336 - Dynamic ARP Inspection

dot1p Value in the Incoming FramePriority Group Assignment3 SAN4 IPC5 LAN6 LAN7 LANThe following describes the priority group-bandwidth assignment.Pri

Seite 337

Important Points to Remember... 950Configuring Upl

Seite 338 - Source Address Validation

Dell(conf-qos-policy-out)# exitDell(conf)# qos-policy-output ipc etsDell(conf-qos-policy-out)# bandwidth-percentage 5Dell(conf-qos-policy-out)# exitEx

Seite 339

In this example, the configured ETS bandwidth allocation and scheduler behavior is as follows:Unused bandwidth usage:Normally, if there is no traffic

Seite 340

Step Task Command Command Modepriority groups is made available and allocated according to the specified percentages. If a priority group does not use

Seite 341 - Equal Cost Multi-Path (ECMP)

Step Task Command Command Mode1Enter interface configuration mode on an Ethernet port.interface {tengigabitEthernet slot/port | fortygigabitEthernet s

Seite 342 - Link Bundle Monitoring

Configuring Lossless QueuesDCB also supports the manual configuration of lossless queues on an interface after you disable PFC mode in a DCB map and a

Seite 343 - Managing ECMP Group Paths

Priority-Based Flow Control Using Dynamic Buffer MethodPriority-based flow control using dynamic buffer spaces is supported on the S4810 platform.In a

Seite 344 - Creating an ECMP Group Bundle

The default behavior causes up to a maximum of 6.6 MB to be used for PFC-related traffic. The remaining approximate space of 1 MB can be used by lossy

Seite 345

The show dcb command has been enhanced to display the following additional buffer-related information: S4810-YU-MR-Dell (conf)#do show dcb dcb Status

Seite 346 - FCoE Transit

6. Assign the DCB policy to the DCB buffer threshold profile on stack ports.CONFIGURATION modeS4810-YU-MR-Dell(conf)# dcb-policy buffer-threshold stac

Seite 347 - Table 19. FIP Functions

14Dynamic Host Configuration Protocol (DHCP)Dynamic host configuration protocol (DHCP) is available on the S4810 platform.DHCP is an application layer

Seite 348

VLT Port Delayed Restoration... 984PIM-Sparse Mode Su

Seite 349

Option Number and DescriptionSubnet Mask Option 1Specifies the client’s subnet mask.Router Option 3Specifies the router IP addresses that may serve as

Seite 350 - Using FIP Snooping

Option Number and DescriptionIdentifiers a user-defined string used by the Relay Agent to forward DHCP client packets to a specific server.L2 DHCP Sno

Seite 351

Figure 36. Client and Server MessagingImplementation InformationThe following describes DHCP implementation.• Dell Networking implements DHCP based on

Seite 352 - Configure the FC-MAP Value

Configure the System to be a DHCP ServerConfiguring the system to be a DHCP server is supported only on the S4810 platform.A DHCP server is a network

Seite 353 - Configuring FIP Snooping

3. Specify the range of IP addresses from which the DHCP server may assign addresses.DHCP <POOL> modenetwork network/prefix-length• network: the

Seite 354

lease {days [hours] [minutes] | infinite}The default is 24 hours.Specifying a Default GatewayThe IP address of the default router should be on the sam

Seite 355

Creating Manual Binding EntriesAn address binding is a mapping between the IP address and the media access control (MAC) address of a client.The DHCP

Seite 356

Configure the System to be a Relay AgentThis feature is available on the S4810 platform.DHCP clients and servers request and offer configuration infor

Seite 357

Figure 37. Configuring a Relay AgentTo view the ip helper-address configuration for an interface, use the show ip interface command from EXEC privileg

Seite 358

ICMP redirects are not sentICMP unreachables are not sentConfigure the System to be a DHCP ClientA DHCP client is a network device that requests an IP

Seite 359

VRF Configuration...1033Load V

Seite 360

• Release the IP address dynamically acquired from a DHCP server from the interface.• Disable the DHCP client on the interface so it cannot acquire a

Seite 361

• To display statistics about DHCP client interfaces, use the show ip dhcp client statistics interface type slot/port command.• To clear DHCP client s

Seite 362 - Enabling FIPS Cryptography

Virtual Link Trunking (VLT)A DHCP client is not supported on VLT interfaces.VLAN and Port ChannelsDHCP client configuration and behavior are the same

Seite 363 - Generating Host-Keys

The received stacking configuration is always applied on the master stack unit.option #230 "unit-number:3#priority:2#stack-group:14"Configur

Seite 364 - Disabling FIPS Mode

ip dhcp relay information-option remote-idDHCP SnoopingDHCP snooping protects networks from spoofing. In the context of DHCP snooping, ports are eithe

Seite 365

3. Enable DHCP snooping on a VLAN.CONFIGURATION modeip dhcp snooping vlan nameAdding a Static Entry in the Binding TableTo add a static entry in the b

Seite 366 - Protocol Overview

Drop DHCP Packets on Snooped VLANs OnlyBinding table entries are deleted when a lease expires or the relay agent encounters a DHCPRELEASE.Line cards m

Seite 367 - Ring Status

MAC flooding An attacker can send fraudulent ARP messages to the gateway until the ARP cache is exhausted, after which, traffic from the gateway is br

Seite 368 - Important FRRP Concepts

To see how many valid and invalid ARP packets have been processed, use the show arp inspection statistics command.Dell#show arp inspection statisticsD

Seite 369

The DHCP binding table associates addresses the DHCP servers assign, with the port on which the requesting client is attached. When you enable IP sour

Seite 370 - FRRP Configuration

Display Stack Port Statistics...1085Display Stack M

Seite 371 - Configuring the Control VLAN

4. Enable IP+MAC SAV.INTERFACE modeip dhcp source-address-validation ipmacDell Networking OS creates an ACL entry for each IP+MAC address pair in the

Seite 372

15Equal Cost Multi-Path (ECMP)Equal cost multi-path (ECMP) is supported on the S4810 platform.ECMP for Flow-Based AffinityECMP for flow-based affinity

Seite 373

CONFIGURATION mode.ipv6 ecmp-deterministicConfiguring the Hash Algorithm SeedDeterministic ECMP sorts ECMPs in order even though RTM provides them in

Seite 374 - Viewing the FRRP Information

NOTE: An ecmp-group index is generated automatically for each unique ecmp-group when the user configures multipath routes to the same network. The sys

Seite 375 - Troubleshooting FRRP

Creating an ECMP Group BundleWithin each ECMP group, you can specify an interface.If you enable monitoring for the ECMP group, the utilization calcula

Seite 376

Dell(conf-ecmp-group-5)#show config!ecmp-group 5 interface tengigabitethernet 0/2 interface tengigabitethernet 0/3 link-bundle-monitor enableDell(c

Seite 377 - no disable

16FCoE TransitThe Fibre Channel over Ethernet (FCoE) Transit feature is supported on the S4810 switch on Ethernet interfaces. When you enable the swit

Seite 378

FIP provides functionality for discovering and logging into an FCF. After discovering and logging in, FIP allows FCoE traffic to be sent and received

Seite 379 - Configure GVRP

Figure 38. FIP Discovery and Login Between an ENode and an FCFFIP Snooping on Ethernet BridgesIn a converged Ethernet network, intermediate Ethernet b

Seite 380 - Configure GVRP Registration

FCoE-generated ACLsThese take precedence over user-configured ACLs. A user-configured ACL entry cannot deny FCoE and FIP snooping frames.The following

Seite 381 - Configure a GARP Timer

1About this GuideThis guide describes the protocols and features the Dell Networking Operating System (OS) supports and provides configuration instruc

Seite 382 - RPM Redundancy

The following sections describe how to configure the FIP snooping feature on a switch that functions as a FIP snooping bridge so that it can perform t

Seite 383 - High Availability (HA)

For VLAN membership, you must:• create the VLANs on the switch which handles FCoE traffic (use the interface vlan command).• configure each FIP snoopi

Seite 384

Enable FIP Snooping on VLANsYou can enable FIP snooping globally on a switch on all VLANs or on a specified VLAN.When you enable FIP snooping on VLANs

Seite 385 - Disabling Auto-Reboot

Table 20. Impact of Enabling FIP SnoopingImpact DescriptionMAC address learning MAC address learning is not performed on FIP and FCoE frames, which ar

Seite 386 - Hitless Behavior

3. Reload the switch to enable the configuration.EXEC Privilege mode.reloadAfter the switch is reloaded, DCB/DCBx is enabled.4. Enable the FCoE transi

Seite 387 - Software Resiliency

Command Outputshow fip-snooping statistics [interface vlan vlan-id| interface port-type port/slot | interface port-channel port-channel-number]Display

Seite 388 - Hot-Lock Behavior

Field DescriptionPort WWPN Worldwide port name of the CNA port.Port WWNN Worldwide node name of the CNA port.The following example shows the show fip-

Seite 389 - IGMP Protocol Overview

Field DescriptionFC-MAP FC-Map value advertised by the FCF.ENode Interface Slot/number of the interface connected to the ENode.FKA_ADV_PERIOD Period o

Seite 390 - Leaving a Multicast Group

Number of VN Port Session Timeouts :0Number of Session failures due to Hardware Config :0The following example shows the show fip-snoop

Seite 391 - IGMP Version 3

Field DescriptionNumber of Multicast Discovery Advertisements Number of FIP-snooped multicast discovery advertisements received on the interface.Numbe

Seite 392

2Configuration FundamentalsThe Dell Networking Operating System (OS) command line interface (CLI) is a text-based interface you can use to configure i

Seite 393 - Leaving and Staying in Groups

FCoE Transit Configuration ExampleThe following illustration shows an S4810 switch used as a FIP snooping bridge for FCoE traffic between an ENode (se

Seite 394 - Configure IGMP

Example of Enabling an FC-MAP Value on a VLANDell(conf-if-vl-10)# fip-snooping fc-map 0xOEFC01NOTE: Configuring an FC-MAP value is only required if yo

Seite 395 - Selecting an IGMP Version

17Enabling FIPS CryptographyFederal information processing standard (FIPS) cryptography is supported on the S4810 platform.This chapter describes how

Seite 396 - Adjusting Timers

Enabling FIPS ModeTo enable or disable FIPS mode, use the console port.Secure the host attached to the console port against unauthorized access. Any a

Seite 397

Monitoring FIPS Mode StatusTo view the status of the current FIPS mode (enabled/disabled), use the following commands.• Use either command to view the

Seite 398 - IGMP Snooping

• New 1024–bit RSA and RSA1 host key-pairs are created.To disable FIPS mode, use the following command.• To disable FIPS mode from a console port.CONF

Seite 399 - Disabling Multicast Flooding

18Force10 Resilient Ring Protocol (FRRP)Force10 resilient ring protocol (FRRP) is supported on the S4810 platform.FRRP provides fast network convergen

Seite 400

The Member VLAN is the VLAN used to transmit data as described earlier.The Control VLAN is used to perform the health checks on the ring. The Control

Seite 401 - Applications

Multiple FRRP RingsUp to 255 rings are allowed per system and multiple rings can be run on one system.More than the recommended number of rings may ca

Seite 402 - Protocol Separation

Concept ExplanationControl VLAN Each ring has a unique Control VLAN through which tagged ring health frames (RHF) are sent. Control VLANs are used onl

Seite 403

• EXEC mode is the default mode and has a privilege level of 1, which is the most restricted level. Only a limited selection of commands is available,

Seite 404

Concept ExplanationThere is no periodic transmission of TCRHFs. The TCRHFs are sent on triggered events of ring failure or ring restoration only.Imple

Seite 405

Configuring the Control VLANControl and member VLANS are configured normally for Layer 2. Their status as control or member is determined at the FRRP

Seite 406

3. Assign the Primary and Secondary ports and the control VLAN for the ports on the ring.CONFIG-FRRP mode.interface primary int slot/port secondary in

Seite 407

To create the Members VLANs for this FRRP group, use the following commands on all of the Transit switches in the ring.1. Create a VLAN with this ID n

Seite 408

5. Identify the Member VLANs for this FRRP group.CONFIG-FRRP mode.member-vlan vlan-id {range}VLAN-ID, Range: VLAN IDs for the ring’s Member VLANs.6. E

Seite 409

• Show the information for the identified FRRP group.EXEC or EXEC PRIVELEGED mode.show frrp ring-idRing ID: the range is from 1 to 255.• Show the stat

Seite 410

protocol frrp 101 interface primary GigabitEthernet 1/24secondary GigabitEthernet 1/34 control-vlan 101 member-vlan 201 mode master no disableExam

Seite 411 - Interfaces

mode transit no disableForce10 Resilient Ring Protocol (FRRP)377

Seite 412 - Interface Types

19GARP VLAN Registration Protocol (GVRP)GARP VLAN registration protocol (GVRP) is supported on the S4810 platform.Typical virtual local area network (

Seite 413

Configure GVRPTo begin, enable GVRP.To facilitate GVRP communications, enable GVRP globally on each switch. Then, GVRP configuration is per interface

Seite 414 - Physical Interfaces

CLI Command Mode Prompt Access CommandNOTE: Access all of the following modes from CONFIGURATION mode.AS-PATH ACLDell(config-as-path)# ip as-path acce

Seite 415 - Overview of Layer Modes

• Configure a GARP TimerEnabling GVRP GloballyTo configure GVRP globally, use the following command.• Enable GVRP for the entire switch.CONFIGURATION

Seite 416

not be unconfigured when it receives a Leave PDU. Therefore, the registration mode on that interface is FIXED.• Forbidden Mode — Disables the port to

Seite 417

LeaveAll Timer 5000Dell(conf)#Dell Networking OS displays this message if an attempt is made to configure an invalid GARP timer: Dell(conf)#garp time

Seite 418 - Management Interfaces

20High Availability (HA)High availability (HA) is supported on the S4810 platform.HA is a collection of features that preserves system continuity by m

Seite 419

RPM Slot ID: 0 RPM Redundancy Role: Primary RPM State: Active RPM SW Version: 7.6.1.0 Link to Peer: Up-- PEER RPM Status -----------------------

Seite 420 - VLAN Interfaces

Specifying an Auto-Failover LimitWhen a non-recoverable fatal error is detected, an automatic failover occurs.However, Dell Networking OS is configure

Seite 421 - Port Channel Interfaces

Unit Type : Member UnitStatus : not presentDell#conDell(conf)#stack-unit 1 provision S4810Dell(conf)#endDell#show

Seite 422 - Port Channel Implementation

Graceful RestartGraceful restart is supported on the S4810 platform.Graceful restart (also known as non-stop forwarding) is a protocol-based mechanism

Seite 423

• Crash Log — contains trace messages related to IPC and IRC timeouts and task crashes on line cards and is stored under the directory CRASH_LOG_DIR.F

Seite 424 - Creating a Port Channel

21Internet Group Management Protocol (IGMP)Internet group management protocol (IGMP) is supported on the S4810 platform.Multicast is premised on ident

Seite 425

CLI Command Mode Prompt Access CommandRAPID SPANNING TREEDell(config-rstp)# protocol spanning-tree rstpREDIRECTDell(conf-redirect-list)# ip redirect-l

Seite 426

Figure 42. IGMP Messages in IP PacketsJoin a Multicast GroupThere are two ways that a host may join a multicast group: it may respond to a general que

Seite 427

response, the querier removes the group from the list associated with forwarding port and stops forwarding traffic for that group to the subnet.IGMP V

Seite 428

Figure 44. IGMP Version 3–Capable Multicast Routers Address StructureJoining and Filtering Groups and SourcesThe following illustration shows how mult

Seite 429 - Changing the Hash Algorithm

Figure 45. Membership Reports: Joining and FilteringLeaving and Staying in GroupsThe following illustration shows how multicast routers track and refr

Seite 430

Figure 46. Membership Queries: Leaving and StayingConfigure IGMPConfiguring IGMP is a two-step process.1. Enable multicast routing using the ip multic

Seite 431 - Bulk Configuration

• Fast Convergence after MSTP Topology Changes• Designating a Multicast Router InterfaceViewing IGMP Enabled InterfacesInterfaces that are enabled wit

Seite 432 - Overlap Port Ranges

IGMP version is 3Dell(conf-if-gi-1/13)#Viewing IGMP GroupsTo view both learned and statically configured IGMP groups, use the following command.• Vi

Seite 433 - Define the Interface Range

INTERFACE modeip igmp query-interval• Adjust the maximum response time.INTERFACE modeip igmp query-max-resp-time• Adjust the last member query interva

Seite 434

Enabling IGMP Immediate-LeaveIf the querier does not receive a response to a group-specific or group-and-source query, it sends another (querier robus

Seite 435 - Maintenance Using TDR

• View the configuration.CONFIGURATION modeshow running-config• Disable snooping on a VLAN.INTERFACE VLAN modeno ip igmp snoopingRelated Configuration

Seite 436 - Link Dampening

Managing the File System... 57Enabling

Seite 437 - Enabling Link Dampening

CLI Command Mode Prompt Access CommandLLDP MANAGEMENT INTERFACEDell(conf-lldp-mgmtIf)#management-interface (LLDP Mode)LINEDell(config-line-console) or

Seite 438

• Configure the switch to only forward unregistered packets to ports on a VLAN that are connected to mrouter ports.CONFIGURATION modeno ip igmp snoopi

Seite 439

ip igmp snooping last-member-query-intervalFast Convergence after MSTP Topology ChangesThe following describes the fast convergence feature.When a por

Seite 440 - Enabling Pause Frames

routes. If SSH is specified as a management application, SSH links to and from an unknown destination uses the management default route.Protocol Separ

Seite 441 - Table 29. Layer 2 Overhead

can configure two default routes, one configured on the management port and the other on the front-end port.Two tables, namely, Egress Interface Selec

Seite 442 - Port-Pipes

When the feature is disabled using the no management egress-interface-selection command, the following operations are performed:• All management appli

Seite 443

the show management application pkt-drop-cntr command. This counter is cleared using clear management application pkt-drop-cntr command.• Packets whos

Seite 444 - Set Auto-Negotiation Options

traffic for such end-user-originated sessions destined to management port ip1 is handled using the EIS route lookup.Handling of Transit Traffic (Traff

Seite 445

This phenomenon occurs where traffic is transiting the switch. Traffic has not originated from the switch and is not terminating on the switch.• Drop

Seite 446

Protocol Behavior when EIS is Enabled Behavior when EIS is Disableddns EIS Behavior Default Behaviorftp EIS Behavior Default Behaviorntp EIS Behavior

Seite 447 - Dynamic Counters

Default Behavior: Route lookup is done in the default routing table and appropriate egress port is selected.Protocol Behavior when EIS is Enabled Beha

Seite 448

-- Stack Info --Unit UnitType Status ReqTyp CurTyp Version Ports-------------------------------------------------

Seite 449

Designating a Multicast Router InterfaceTo designate an interface as a multicast router interface, use the following command.Dell Networking OS also h

Seite 450 - Configuring IPSec

22InterfacesThis chapter describes interface types, both physical and logical, and how to configure them with Dell Networking Operating System (OS).•

Seite 451 - IPv4 Routing

Interface TypesThe following table describes different interface types.Interface Type Modes Possible Default Mode Requires Creation Default StatePhysi

Seite 452

Hardware is Force10Eth, address is 00:01:e8:05:f3:6a Current address is 00:01:e8:05:f3:6aPluggable media present, XFP type is 10GBASE-LR. Medium is

Seite 453 - Configuring Static Routes

interface GigabitEthernet 9/7 no ip address shutdown!interface GigabitEthernet 9/8 no ip address shutdown!interface GigabitEthernet 9/9 no ip add

Seite 454

Configuration Task List for Physical InterfacesBy default, all interfaces are operationally disabled and traffic does not pass through them.The follow

Seite 455

Example of a Basic Layer 2 Interface ConfigurationDell(conf-if)#show config!interface Port-channel 1 no ip address switchport no shutdownDell(conf-

Seite 456 - Messages

no ip address switchport no shutdownDell(conf-if)#ip address 10.10.1.1 /24% Error: Port is in Layer 2 mode Gi 1/2.Dell(conf-if)#To determine the c

Seite 457 - Resolution of Host Names

attacks on front-end ports. The following protocols support EIS: DNS, FTP, NTP, RADIUS, sFlow, SNMP, SSH, Syslog, TACACS, Telnet, and TFTP. This featu

Seite 458

CONFIGURATION modeinterface managementethernet interfaceThe slot range is 0.• Configure an IP address and mask on a Management interface.INTERFACE mod

Seite 459

no ip address no shutdownLayer 2 protocols are disabled by default. To enable Layer 2 protocols, use the no disable command. For example, in PROTOC

Seite 460 - Configuration Tasks for ARP

Destination Gateway Dist/Metric Last Change ----------- ------- ----------- -----------*S 0.0.0.0/

Seite 461 - Clearing ARP Cache

Loopback InterfacesA Loopback interface is a virtual interface in which the software emulates an interface. Packets routed to it are processed locally

Seite 462 - ARP Learning via ARP Request

Port Channel Definition and StandardsLink aggregation is defined by IEEE 802.3ad as a method of grouping multiple physical interfaces into a single lo

Seite 463 - Configuring ARP Retries

Dell Networking OS brings up 10/100/1000 interfaces that are set to auto negotiate so that their speed is identical to the speed of the first channel

Seite 464 - UDP Helper

Creating a Port ChannelYou can create up to 128 port channels with eight port members per group on the S4810 .To configure a port channel, use the fol

Seite 465 - Enabling UDP Helper

To add a physical interface to a port, use the following commands.1. Add the interface to a port channel.INTERFACE PORT-CHANNEL modechannel-member int

Seite 466

When more than one interface is added to a Layer 2-port channel, Dell Networking OS selects one of the active interfaces in the port channel to be the

Seite 467

Dell(conf-if-po-4)#int port 3Dell(conf-if-po-3)#channel tengi 0/8Dell(conf-if-po-3)#sho conf!interface Port-channel 3 no ip address channel-member T

Seite 468 - Troubleshooting UDP Helper

3. Verify the manually configured VLAN membership (show interfaces switchport interface command).EXEC modeDell(conf)# interface tengigabitethernet 0/1

Seite 469

assigned to one link. In packet-based hashing, a single flow can be distributed on the LAG and uses one link.Packet based hashing is used to load bala

Seite 470 - IPv6 Routing

Short-Cut Key CombinationActionCNTL-A Moves the cursor to the beginning of the command line.CNTL-B Moves the cursor back one character.CNTL-D Deletes

Seite 471 - IPv6 Headers

• Change the default (0) to another algorithm and apply it to ECMP, LAG hashing, or a particular line card.CONFIGURATION modehash-algorithm | [ecmp{cr

Seite 472 - IPv6 Header Fields

Bulk ConfigurationBulk configuration allows you to determine if interfaces are present for physical interfaces or configured for logical interfaces.In

Seite 473 - Extension Header Fields

Create a Multiple-RangeThe following is an example of multiple range.Example of the interface range Command (Multiple Ranges)Dell(conf)#interface rang

Seite 474 - Addressing

Add RangesThe following example shows how to use commas to add VLAN and port-channel interfaces to the range.Example of Adding VLAN and Port-Channel I

Seite 475 - Static and Dynamic Addressing

Monitoring and Maintaining InterfacesMonitor interface statistics with the monitor interface command. This command displays an ongoing list of the int

Seite 476

Output throttles: 0 0 pps 0m - Change mode c - Clear screenl - Page up a - Page downT - Increase r

Seite 477

NOTE: When you split a 40G port (such as fo 0/4) into four 10G ports, the 40G interface configuration is available in the startup configuration when y

Seite 478 - Path MTU Discovery

• improves network stability by penalizing misbehaving interfaces and redirecting traffic.• improves convergence times and stability throughout the ne

Seite 479 - IPv6 Neighbor Discovery

clear dampeningExample of the clear dampening CommandDell# clear dampening interface Gi 0/1Dell# show interfaces dampening GigabitEthernet0/0Interface

Seite 480

• Enable link bundle monitoring.ecmp-group• View all LAG link bundles being monitored.show running-config ecmp-groupUsing Ethernet Pause Frames for Fl

Seite 481

• show run | grep Ethernet returns a search result with instances containing a capitalized “Ethernet,” such as interface GigabitEthernet 0/0.• show ru

Seite 482

Threshold SettingsThreshold settings are supported on the S4810 platform.When the transmission pause is set (tx on), you can set three thresholds to d

Seite 483 - Configuration Tasks for IPv6

* Number of flow-control packet pointers: the range is from 1 to 2047 (default = 75).* Flow-control buffer threshold in KB: the range is from 1 to 201

Seite 484 - Assigning a Static IPv6 Route

For example, the VLAN contains tagged members with Link MTU of 1522 and IP MTU of 1500 and untagged members with Link MTU of 1518 and IP MTU of 1500.

Seite 485 - SNMP over IPv6

4. Access the port.CONFIGURATION modeinterface interface slot/port5. Set the local port speed.INTERFACE modespeed {10 | 100 | 1000 | auto}6. Optionall

Seite 486 - Showing an IPv6 Interface

interface GigabitEthernet 0/1no ip addressspeed 100duplex fullno shutdownSet Auto-Negotiation OptionsThe negotiation auto command provides a mode opti

Seite 487 - Showing IPv6 Routes

Examples of the show CommandsThe following example lists the possible show commands that have the configured keyword available:Dell#show interfaces co

Seite 488

Example of the rate-interval CommandThe bold lines shows the default value of 299 seconds, the change-rate interval of 100, and the new rate interval

Seite 489 - Clearing IPv6 Routes

Dynamic CountersBy default, counting is enabled for IPFLOW, IPACL, L2ACL, L2FIB.For the remaining applications, Dell Networking OS automatically turns

Seite 490

– (OPTIONAL) To clear statistics for all VRRP groups configured, enter the keyword vrrp. Enter a number from 1 to 255 as the vrid.– (OPTIONAL) To clea

Seite 491

23Internet Protocol Security (IPSec)Internet protocol security (IPSec) is available on the S4810 platform.IPSec is an end-to-end security scheme for p

Seite 492

NOTE: You can filter a single command output multiple times. The save option must be the last option entered. For example: Dell# command | grep regula

Seite 493

Configuring IPSec The following sample configuration shows how to configure FTP and telnet for IPSec.1. Define the transform set.CONFIGURATION modecry

Seite 494

24IPv4 RoutingIPv4 routing is supported on the S4810 platform.The Dell Networking Operating System (OS) supports various IP addressing features. This

Seite 495

• Assigning IP Addresses to an Interface (mandatory)• Configuring Static Routes (optional)• Configure Static Routes for the Management Interface (opti

Seite 496

interface GigabitEthernet 0/0 ip address 10.11.1.1/24 no shutdown!Dell(conf-if)#Dell(conf-if)#show conf!interface GigabitEthernet 0/0ip address 10.1

Seite 497

S 6.1.2.4/32 via 6.1.20.2, Te 5/0 1/0 00:02:30S 6.1.2.5/32 via 6.1.20.2, Te 5/0 1/0 00:02:30S 6.1.2.6/32 via 6.1.20.2, Te 5/

Seite 498

S 6.1.2.6/32 via 6.1.20.2, Te 5/0 1/0 00:02:30S 6.1.2.7/32 via 6.1.20.2, Te 5/0 1/0 00:02:30S 6.1.2.8/32 via 6.1.20.2, Te 5/0

Seite 499

Using the Configured Source IP Address in ICMP MessagesThis feature is supported on the S4810 platform.ICMP error or unreachable messages are now sent

Seite 500 - IS-IS Addressing

To configure the duration for which the device waits for the ACK packet to be sent from the requesting host to establish the TCP connection, perform t

Seite 501 - Multi-Topology IS-IS

CONFIGURATION modeip domain-lookup• Specify up to six name servers.CONFIGURATION modeip name-server ip-address [ip-address2 ... ip-address6]The order

Seite 502

Configuring DNS with TracerouteTo configure your switch to perform DNS with traceroute, use the following commands.• Enable dynamic resolution of host

Seite 503

3Getting StartedThis chapter describes how you start configuring your system.When you power up the chassis, the system performs a power-on self test (

Seite 504

corresponding IP address. This table is called the ARP Cache and dynamically learned addresses are removed after a defined period of time.For more inf

Seite 505 - Enabling IS-IS

--------------------------------------------------------------------------------Internet 10.1.2.4 17 08:00:20:b7:bd:32 Ma 1/0 - CPDell#E

Seite 506

• detect IP address conflicts• inform switches of their presence on a port so that packets can be forwarded• update the ARP table of other nodes on th

Seite 507

Figure 48. ARP Learning via ARP Request with ARP Learning via Gratuitous ARP EnabledWhether you enable or disable ARP learning via gratuitous ARP, the

Seite 508

ICMPFor diagnostics, the internet control message protocol (ICMP) provides routing information to end stations by choosing the best route (ICMP redire

Seite 509

2. Configure a broadcast address on interfaces that will receive UDP broadcast traffic. Refer to Configuring a Broadcast Address.Important Points to R

Seite 510 - Changing LSP Attributes

untagged GigabitEthernet 1/2no shutdownTo view the configured broadcast address for an interface, use show interfaces command.R1_E600(conf)#do show in

Seite 511 - Table 32. Metric Styles

Figure 49. UDP Helper with Broadcast-All AddressesUDP Helper with Subnet Broadcast AddressesWhen the destination IP address of an incoming packet matc

Seite 512 - Configuring the IS-IS Cost

UDP Helper with Configured Broadcast AddressesIncoming packets with a destination IP address matching the configured broadcast address of any interfac

Seite 513 - Changing the IS-Type

When using the IP helper and UDP helper on the same interface, use the debug ip dhcp command.Example Output from the debug ip dhcp CommandPacket 0.0.0

Seite 514 - Controlling Routing Updates

Accessing the Console PortTo access the console port, follow these steps:For the console port pinout, refer to Accessing the RJ-45 Console Port with a

Seite 515 - Applying IPv4 Routes

25IPv6 RoutingInternet protocol version 6 (IPv6) routing is supported on the S4810 platform.NOTE: The IPv6 basic commands are supported on all platfor

Seite 516 - Redistributing IPv4 Routes

NOTE: Dell Networking OS provides the flexibility to add prefixes on Router Advertisements (RA) to advertise responses to Router Solicitations (RS). B

Seite 517 - Redistributing IPv6 Routes

IPv6 Header FieldsThe 40 bytes of the IPv6 header are ordered, as shown in the following illustration.Figure 52. IPv6 Header FieldsVersion (4 bits)The

Seite 518

The following lists the Next Header field values.Value Description0 Hop-by-Hop option header4 IPv46 TCP8 Exterior Gateway Protocol (EGP)41 IPv643 Rout

Seite 519 - Debugging IS-IS

However, if the Destination Address is a Hop-by-Hop options header, the Extension header is examined by every forwarding router along the packet’s rou

Seite 520 - IS-IS Metric Styles

of double colons is supported in a single address. Any number of consecutive 0000 groups may be reduced to two colons, as long as there is only one do

Seite 521 - Configure Metric Values

Implementing IPv6 with Dell Networking OSDell Networking OS supports both IPv4 and IPv6 and both may be used simultaneously in your system.The followi

Seite 522

Feature and FunctionalityDell Networking OS Release IntroductionDocumentation and Chapter LocationS4810IS-IS for IPv6 8.3.10 Intermediate System to In

Seite 523

Feature and FunctionalityDell Networking OS Release IntroductionDocumentation and Chapter LocationS4810(outbound SSH) Layer 3 onlySecure Shell (SSH) s

Seite 524

Figure 53. Path MTU Discovery ProcessIPv6 Neighbor DiscoveryIPv6 neighbor discovery protocol (NDP) is supported on the S4810 platform.NDP is a top-lev

Seite 525

Entering CLI commands Using an SSH ConnectionYou can run CLI commands by entering any one of the following syntax to connect to a switch using the pre

Seite 526

Figure 54. NDP Router RedirectIPv6 Neighbor Discovery of MTU PacketsYou can set the MTU advertised through the RA packets to incoming routers, without

Seite 527

The DNS server address does not allow the following:• link local addresses• loopback addresses• prefix addresses• multicast addresses• invalid host ad

Seite 528 - Configuring LACP Commands

Displaying IPv6 RDNSS InformationTo display IPv6 interface information, including IPv6 RDNSS information, use the show ipv6 interface command in EXEC

Seite 529 - LACP Configuration Tasks

Secure Shell (SSH) Over an IPv6 TransportIPv6 secure shell (SSH) is supported on the S4810 platform.Dell Networking OS supports both inbound and outbo

Seite 530 - Setting the LACP Long Timeout

The total space allocated must equal 13.The ipv6acl range must be a factor of 2.• Show the current CAM settings.EXEC mode or EXEC Privilege modeshow c

Seite 531 - Shared LAG State Tracking

– prefix: IPv6 route prefix– type {slot/port}: interface type and slot/port– forwarding router: forwarding router’s address– tag: route tagEnter the k

Seite 532

• snmp-server community access-list-name ipv6• snmp-server group ipv6• snmp-server group access-list-name ipv6Showing IPv6 InformationAll of the follo

Seite 533

– For a VLAN interface, enter the keyword vlan then the VLAN ID.Example of the show ipv6 interface Command (S4810 )Dell#show ipv6 int man 1/0Managemen

Seite 534 - Configure a LAG on ALPHA

– To display information about an IPv6 Prefix lists, enter list and the prefix-list name.Examples of the show ipv6 route CommandsThe following example

Seite 535

– For a Gigabit Ethernet interface, enter the keyword GigabitEthernet then the slot/ port information.– For the Management interface on the RPM, enter

Seite 536

Default ConfigurationA version of Dell Networking OS is pre-loaded onto the chassis; however, the system is not configured when you power up for the f

Seite 537

26iSCSI OptimizationiSCSI optimization is supported on the S4810 platform.This chapter describes how to configure internet small computer system inter

Seite 538

• If you configure flow-control, iSCSI uses the current configuration. If you do not configure flow-control, iSCSI auto-configures flow control settin

Seite 539

Monitoring iSCSI Traffic FlowsThe switch snoops iSCSI session-establishment and termination packets by installing classifier rules that trap iSCSI pro

Seite 540

If more than 256 simultaneous sessions are logged continuously, the following message displays indicating the queue rate limit has been reached:%STKUN

Seite 541

Configuring Detection and Ports for Dell Compellent ArraysTo configure a port connected to a Dell Compellent storage array, use the following command.

Seite 542 - Manage the MAC Address Table

iSCSI optimization, which can turn on flow control again on reboot, use the no iscsi enable command and save the configuration.When you enable iSCSI o

Seite 543 - MAC Learning Limit

Parameter Default ValueiSCSI session monitoring Disabled. The CAM allocation for iSCSI is set to zero (0).iSCSI Optimization PrerequisitesThe followin

Seite 544

5. Reload the switch.EXEC Privilege modereloadAfter the switch is reloaded, DCB/ DCBx and iSCSI monitoring are enabled.6. (Optional) Configure the iSC

Seite 545

8. (Optional) Set the aging time for iSCSI session monitoring.CONFIGURATION mode[no] iscsi aging time time.The range is from 5 to 43,200 minutes.The d

Seite 546

Maximum number of connections is 256------------------------------------------------iSCSI Targets and TCP Ports:--------------------------------------

Seite 547 - NIC Teaming

Lock CONFIGURATION Mode... 80Viewing the Confi

Seite 548 - Configure Redundant Pairs

Configure the Management Port IP AddressTo access the system remotely, assign IP addresses to the management ports.1. Enter INTERFACE mode for the Man

Seite 549

27Intermediate System to Intermediate SystemIntermediate system to intermediate system (Is-IS) is supported on the S4810 platform.• IS-IS is supported

Seite 550

The NET length is variable, with a maximum of 20 bytes and a minimum of 8 bytes. It is composed of the following:• area address — within your routing

Seite 551 - Far-End Failure Detection

Transition ModeAll routers in the area or domain must use the same type of IPv6 support, either single-topology or multi-topology. A router operating

Seite 552 - FEFD State Changes

A new TLV (the Restart TLV) is introduced in the IIH PDUs, indicating that the router supports graceful restart.TimersThree timers are used to support

Seite 553 - Configuring FEFD

• Accepts external IPv6 information and advertises this information in the PDUs.The following table lists the default IS-IS values.Table 31. IS-IS Def

Seite 554 - Enabling FEFD on an Interface

Enabling IS-ISBy default, IS-IS is not enabled.The system supports one instance of IS-IS. To enable IS-IS globally, create an IS-IS routing process an

Seite 555 - Debugging FEFD

4. Enter an IPv4 Address.INTERFACE modeip address ip-address maskAssign an IP address and mask to the interface.The IP address must be on the same sub

Seite 556 - An RPM Failover

Generate wide metrics: noneAccept wide metrics: noneDell#To view IS-IS protocol statistics, use the show isis traffic command in EXEC Privilege

Seite 557 - 802.1AB (LLDP) Overview

3. Set the minimum interval between SPF calculations.ROUTER ISIS AF IPV6 modespf-interval [level-l | level-2 | interval] [initial_wait_interval [secon

Seite 558 - Optional TLVs

– retry-times: number of times an unacknowledged restart request is sent before the restarting router gives up the graceful restart engagement with th

Seite 559 - Table 38. Optional TLV Types

* 7 is for inputting a password that is already encrypted using a Type 7 hash. Obtaining the encrypted password from the configuration of another Dell

Seite 560 - TIA-1057 (LLDP-MED) Overview

Mode: Normal L1-State:NORMAL, L2-State: NORMAL L1: Send/Receive: RR:0/0, RA: 0/0, SA:0/0 T1 time left: 0, retry count left:0 L2: Send/Receive:

Seite 561

lsp-refresh-interval seconds– seconds: the range is from 1 to 65535.The default is 900 seconds.• Set the maximum time LSPs lifetime.ROUTER ISIS modema

Seite 562 - LLDP-MED Capabilities TLV

Metric Style Characteristics Cost Range Supported on IS-IS Interfacesnarrow transition Sends narrow (old) TLVs and accepts both narrow (old) and wide

Seite 563 - LLDP-MED Network Policies TLV

– default-metric: the range is from 0 to 63 if the metric-style is narrow, narrow-transition, or transition.The range is from 0 to 16777215 if the met

Seite 564

• Change the IS-type for the IS-IS process.ROUTER ISIS modeis-type {level-1 | level-1-2 | level-2}Example of the show isis database Command to View Le

Seite 565 - Configure LLDP

Distribute RoutesAnother method of controlling routing information is to filter the information through a prefix list.Prefix lists are applied to inco

Seite 566 - LLDP Compatibility

Applying IPv6 RoutesTo apply prefix lists to incoming or outgoing IPv6 routes, use the following commands.NOTE: These commands apply to IPv6 IS-IS onl

Seite 567 - Enabling LLDP

NOTE: These commands apply to IPv4 IS-IS only. To apply prefix lists to IPv6 routes, use ADDRESS-FAMILY IPV6 mode, shown later.• Include BGP, directly

Seite 568 - Advertising TLVs

– map-name: enter the name of a configured route map.• Include specific OSPF routes in IS-IS.ROUTER ISIS moderedistribute ospf process-id [level-1| le

Seite 569 - Figure 77. Configuring LLDP

Setting the Overload BitAnother use for the overload bit is to prevent other routers from using this router as an intermediate hop in their shortest p

Seite 570

Table 3. Forming a copy CommandLocation source-file-url Syntax destination-file-url SyntaxFor a remote file location:FTP servercopy ftp://username:pas

Seite 571 - Configuring LLDPDU Intervals

To view specific information, enter the following optional parameter:– interface: Enter the type of interface and slot/port information to view IS-IS

Seite 572 - Configuring a Time to Live

• narrow (supports only type, length, and value [TLV] up to 63)• wide (supports TLV up to 16777215)• transition (supports both narrow and wide and use

Seite 573 - Debugging LLDP

Beginning Metric Style Final Metric Style Resulting IS-IS Metric ValueNOTE: A truncated value is a value that is higher than 63, but set back to 63 be

Seite 574 - Relevant Management Objects

Table 34. Metric Value when the Metric Style Changes Multiple TimesBeginning Metric StyleNext Metric Style Resulting Metric ValueNext Metric Style Fin

Seite 575

Level-1 Metric Style Level-2 Metric Style Resulting Metric Valuewide transition narrow transition truncated valuewide transition transition truncated

Seite 576

Figure 57. IPv6 IS-IS Sample TopographyIS-IS Sample Configuration — Congruent TopologyIS-IS Sample Configuration — Multi-topologyIS-IS Sample Configur

Seite 577

router isisnet 34.0000.0000.AAAA.00!address-family ipv6 unicastmulti-topologyexit-address-familyDell (conf-router_isis)#Dell (conf-if-te-3/17)#show co

Seite 578

28Link Aggregation Control Protocol (LACP)Link aggregation control protocol (LACP) is supported on the S4810 platform.Introduction to Dynamic LAGs and

Seite 579

• There is a difference between the shutdown and no interface port-channel commands:– The shutdown command on LAG “xyz” disables the LAG and retains t

Seite 580 - NLB Unicast Mode Scenario

• Configure LACP mode.LACP mode[no] port-channel number mode [active | passive | off]– number: cannot statically contain any links.The default is LACP

Seite 581 - NLB Multicast Mode Scenario

EXEC Privilege modecopy running-config ftp:// username:password@{hostip | hostname}/filepath/ filename• Save the running-configuration to a TFTP serve

Seite 582 - Configuring a Switch for NLB

Configuring the LAG Interfaces as DynamicAfter creating a LAG, configure the dynamic LAG interfaces.To configure the dynamic LAG interfaces, use the f

Seite 583

Dell(conf-if-po-32)#switchportDell(conf-if-po-32)#lacp long-timeoutDell(conf-if-po-32)#endDell# show lacp 32Port-channel 32 admin up, oper up, mode la

Seite 584

Figure 58. Shared LAG State TrackingTo avoid packet loss, redirect traffic through the next lowest-cost link (R3 to R4). Dell Networking OS has the ab

Seite 585 - Anycast RP

As shown in the following illustration, LAGs 1 and 2 are members of a failover group. LAG 1 fails and LAG 2 is brought down after the failure. This ef

Seite 586

• If a LAG that is part of a failover group is deleted, the failover group is deleted.• If a LAG moves to the Down state due to this feature, its memb

Seite 587

ARP type: ARPA, ARP Timeout 04:00:00Last clearing of "show interface" counters 00:02:11Queueing strategy: fifoInput statistics: 132 pack

Seite 588

Figure 62. Inspecting Configuration of LAG 10 on ALPHA536Link Aggregation Control Protocol (LACP)

Seite 589 - Enable MSDP

Figure 63. Verifying LAG 10 Status on ALPHA Using the show lacp CommandSummary of the LAG Configuration on AlphaAlpha(conf-if-po-10)#int gig 2/31Alpha

Seite 590

interface GigabitEthernet 2/31no ip addressSummary of the LAG Configuration on BravoBravo(conf-if-gi-3/21)#int port-channel 10Bravo(conf-if-po-10)#no

Seite 591

Figure 64. Inspecting a LAG Port on BRAVO Using the show interface CommandLink Aggregation Control Protocol (LACP)539

Seite 592

9 -rw- 27674906 Jul 06 2007 00:20:24 FTOS-EF-4.7.4.302.bin10 -rw- 27674906 Jul 06 2007 19:54:52 boot-image-FILE11 drw- 8192 Jan 01 1980 00:18:28

Seite 593

Figure 65. Inspecting LAG 10 Using the show interfaces port-channel Command540Link Aggregation Control Protocol (LACP)

Seite 594

Figure 66. Inspecting the LAG Status Using the show lacp commandThe point-to-point protocol (PPP) is a connection-oriented protocol that enables layer

Seite 595

29Layer 2Layer 2 features are supported on the S4810 platform.Manage the MAC Address TableDell Networking OS provides the following management activit

Seite 596

The range is from 10 to 1000000.Configuring a Static MAC AddressA static entry is one that is not subject to aging. Enter static entries manually.To c

Seite 597

interface) before the system verifies that sufficient CAM space exists. If the CAM check fails, a message is displayed:%E90MH:5 %ACL_AGENT-2-ACL_AGENT

Seite 598

mac learning-limit mac-address-stickyUsing sticky MAC addresses allows you to associate a specific port with MAC addresses from trusted devices. If yo

Seite 599 - Clearing Peer Statistics

no ip address switchport mac learning-limit 1 dynamic no-station-move mac learning-limit station-move-violation log no shutdownLearning Limit Vi

Seite 600 - MSDP with Anycast RP

Recovering from Learning Limit and Station Move ViolationsAfter a learning-limit or station-move violation shuts down an interface, you must manually

Seite 601

When you use NIC teaming, consider that the server MAC address is originally learned on Port 0/1 of the switch (shown in the following) and Port 0/5 i

Seite 602 - Configuring Anycast RP

Apply all other configurations to each interface in the redundant pair such that their configurations are identical, so that transition to the backup

Seite 603

Two existing exec mode CLIs are enhanced to display and store the running configuration in the compressed mode.show running-config compressed and writ

Seite 604

LACP) port-channel interface as either the primary or backup link in a redundant pair with a physical interface.To ensure that existing network applic

Seite 605 - MSDP Sample Configurations

inactive: Vl 100:24:55: %RPM0-P:CP %IFMGR-5-OSTATE_UP: Changed interface state to up: Gi 3/4200:24:55: %RPM0-P:CP %IFMGR-5-ACTIVE: Changed Vlan interf

Seite 606

Figure 70. Configuring Far-End Failure DetectionThe report consists of several packets in SNAP format that are sent to the nearest known MAC address.I

Seite 607

4. If the FEFD enabled system is configured to use FEFD in Normal mode and neighboring echoes are not received after three intervals, (you can set eac

Seite 608

To report interval frequency and mode adjustments, use the following commands.1. Setup two or more connected interfaces for Layer 2 or Layer 3.INTERFA

Seite 609 - Spanning Tree Variations

To set up and activate two or more connected interfaces, use the following commands.1. Setup two or more connected interfaces for Layer 2 or Layer 3.I

Seite 610

Sender state -- Bi-directional Sender info -- Mgmt Mac(00:01:e8:14:89:25), Slot-Port(Gi 1/0) Peer info -- Mgmt Mac (00:01:e8:14:89:25), Slot-Po

Seite 611

30Link Layer Discovery Protocol (LLDP)The link layer discovery protocol (LLDP) is supported on the S4810 platform.802.1AB (LLDP) OverviewLLDP — define

Seite 612

Table 37. Type, Length, Value (TLV) TypesType TLV Description0 End of LLDPDU Marks the end of an LLDPDU.1 Chassis ID An administratively assigned name

Seite 613 - Modifying Global Parameters

Figure 73. Organizationally Specific TLVIEEE Organizationally Specific TLVsEight TLV types have been defined by the IEEE 802.1 and 802.3 working group

Seite 614

interface TenGigabitEthernet 0/4no ip addressshutdown!interface TenGigabitEthernet 0/10no ip addressshutdown!interface TenGigabitEthernet 0/34ip addre

Seite 615 - Configuring an EdgePort

Type TLV Description127 Protocol Identity Indicates the protocols that the port can process. Dell Networking OS does not currently support this TLV.IE

Seite 616

Regarding connected endpoint devices, LLDP-MED provides network connectivity devices with the ability to:• manage inventory• manage Power over Etherne

Seite 617 - MSTP Sample Configurations

Type SubType TLV DescriptionNone or all TLVs must be supported. Dell Networking OS does not currently support these TLVs.127 5 Inventory — Hardware Re

Seite 618

Figure 74. LLDP-MED Capabilities TLVTable 40. Dell Networking OS LLDP-MED CapabilitiesBit Position TLV Dell Networking OS Support0 LLDP-MED Capabiliti

Seite 619

NOTE: As shown in the following table, signaling is a series of control packets that are exchanged between an endpoint device and a network connectivi

Seite 620

Extended Power via MDI TLVThe extended power via MDI TLV enables advanced PoE management between LLDP-MED endpoints and network connectivity devices.A

Seite 621

Important Points to Remember• LLDP is enabled by default.• Dell Networking systems support up to eight neighbors per interface.• Dell Networking syste

Seite 622

Enabling LLDPLLDP is enabled by default. Enable and disable LLDP globally or per interface. If you enable LLDP globally, all UP interfaces send period

Seite 623 - Multicast Features

3. Enter the disable command.LLDP-MANAGEMENT-INTERFACE mode.To undo an LLDP management port configuration, precede the relevant command with the keywo

Seite 624

Figure 77. Configuring LLDPViewing the LLDP ConfigurationTo view the LLDP configuration, use the following command.• Display the LLDP configuration.CO

Seite 625 - Multicast Policies

!interface Vlan 100no ip addressno shutdown!interface Vlan 1000ip address 1.1.1.1/16no shutdownUncompressed config size – 52 lineswrite memory compres

Seite 626

Viewing Information Advertised by Adjacent LLDP AgentsTo view brief information about adjacent devices or to view all the information that neighbors a

Seite 627

Configuring LLDPDU IntervalsLLDPDUs are transmitted periodically; the default interval is 30 seconds.To configure LLDPDU intervals, use the following

Seite 628

• Return to the default setting.CONFIGURATION mode or INTERFACE modeno modeExample of Configuring a Single ModeR1(conf)#protocol lldpR1(conf-lldp)#sho

Seite 629

advertise dot1-tlv port-protocol-vlan-id port-vlan-id advertise dot3-tlv max-frame-size advertise management-tlv system-capabilities system-descri

Seite 630

Figure 78. The debug lldp detail Command — LLDPDU Packet DissectionRelevant Management ObjectsDell Networking OS supports all IEEE 802.1AB MIB objects

Seite 631

MIB Object CategoryLLDP Variable LLDP MIB Object DescriptionmsgTxInterval lldpMessageTxInterval Transmit Interval value.rxInfoTTL lldpRxInfoTTL Time t

Seite 632

Table 44. LLDP System MIB ObjectsTLV Type TLV Name TLV Variable System LLDP MIB Object1 Chassis ID chassis ID subtype Local lldpLocChassisIdSubtypeRem

Seite 633

TLV Type TLV Name TLV Variable System LLDP MIB Objectinterface numbering subtypeLocal lldpLocManAddrIfSubtypeRemote lldpRemManAddrIfSubtypeinterface n

Seite 634 - Area Types

Table 46. LLDP-MED System MIB ObjectsTLV Sub-Type TLV Name TLV Variable System LLDP-MED MIB Object1 LLDP-MED CapabilitiesLLDP-MED CapabilitiesLocallld

Seite 635 - Router Types

TLV Sub-Type TLV Name TLV Variable System LLDP-MED MIB Object3 Location Identifier Location Data FormatLocal lldpXMedLocLocationSubtypeRemote lldpXMed

Seite 636 - Area Border Router (ABR)

- - - network rw ftp: - - - network rw tftp: - - - network rw scp:You can cha

Seite 637 - Internal Router (IR)

31Microsoft Network Load BalancingThis functionality is supported on the S4810 platform.Network Load Balancing (NLB) is a clustering functionality tha

Seite 638 - LSA Throttling

• With NLB feature enabled, after learning the NLB ARP entry, all the subsequent traffic is flooded on all ports in VLAN1.With NLB, the data frame is

Seite 639 - Router Priority and Cost

flooded out of all member ports. Since all the servers in the cluster receive traffic, failover and balancing are preserved.Enable and Disable VLAN Fl

Seite 640 - OSPF with Dell Networking OS

32Multicast Source Discovery Protocol (MSDP)Multicast source discovery protocol (MSDP) is supported on the S4810 platform.Protocol OverviewMSDP is a L

Seite 641

Figure 79. Multicast Source Discovery Protocol (MSDP)RPs advertise each (S,G) in its domain in type, length, value (TLV) format. The total number of T

Seite 642 - OSPF ACK Packing

Anycast RPUsing MSDP, anycast RP provides load sharing and redundancy in PIM-SM networks. Anycast RP allows two or more rendezvous points (RPs) to sha

Seite 643

• Accept Source-Active Messages that Fail the RFP Check• Specifying Source-Active Messages• Limiting the Source-Active Cache• Preventing MSDP from Cac

Seite 644 - Enabling OSPFv2

Figure 82. Configuring OSPF and BGP for MSDPMulticast Source Discovery Protocol (MSDP)587

Seite 645 - Assigning a Router ID

Figure 83. Configuring PIM in Multiple Routing Domains588Multicast Source Discovery Protocol (MSDP)

Seite 646 - Enable OSPFv2 on Interfaces

Figure 84. Configuring MSDPEnable MSDPEnable MSDP by peering RPs in different administrative domains.1. Enable MSDP.CONFIGURATION modeip multicast-msd

Seite 647

For a particular target where VRF is enabled, the show output is similar to the following:Feature State------------------------------VRF enable

Seite 648 - Configuring Stub Areas

Examples of Configuring and Viewing MSDP R3_E600(conf)#ip multicast-msdp R3_E600(conf)#ip msdp peer 192.168.0.1 connect-source Loopback 0 R3_

Seite 649 - Enabling Passive Interfaces

Limiting the Source-Active CacheSet the upper limit of the number of active sources that the Dell Networking OS caches.The default active source limit

Seite 650 - Enabling Fast-Convergence

Figure 85. MSDP Default Peer, Scenario 1592Multicast Source Discovery Protocol (MSDP)

Seite 651

Figure 86. MSDP Default Peer, Scenario 2Multicast Source Discovery Protocol (MSDP)593

Seite 652

Figure 87. MSDP Default Peer, Scenario 3594Multicast Source Discovery Protocol (MSDP)

Seite 653

Figure 88. MSDP Default Peer, Scenario 4Specifying Source-Active MessagesTo specify messages, use the following command.• Specify the forwarding-peer

Seite 654

Dell(conf)#ip access-list standard fiftyDell(conf)#seq 5 permit host 200.0.0.50Dell#ip msdp sa-cacheMSDP Source-Active Cache - 3 entriesGroupAddr So

Seite 655 - Creating Filter Routes

Example of Verifying the System is not Caching Local SourcesWhen you apply this filter, the SA cache is not affected immediately. When sources that ar

Seite 656 - Applying Prefix Lists

R3_E600(conf)#do show ip msdp sa-cacheR3_E600(conf)#R3_E600(conf)#do show ip msdp peerPeer Addr: 192.168.0.1 Local Addr: 0.0.0.0(639) Connect Sourc

Seite 657 - Troubleshooting OSPFv2

Logging Changes in Peership StatesTo log changes in peership states, use the following command.• Log peership state changes.CONFIGURATION modeip msdp

Seite 658 - Basic OSPFv2 Router Topology

Forcibly Authorizing or Unauthorizing a Port...106Re-Authenticating a P

Seite 659 - OSPF Area 0 — Gl 3/1 and 3/2

1. Download Dell Networking OS software image file from the iSupport page to the local (FTP or TFTP) server. The published hash for that file is displ

Seite 660 - Enabling IPv6 Unicast Routing

Example of the clear ip msdp peer Command and Verifying Statistics are ClearedR3_E600(conf)#do show ip msdp peerPeer Addr: 192.168.0.1 Local Addr:

Seite 661

technique is less effective as traffic increases because preemptive load balancing requires prior knowledge of traffic distributions.• lack of scalabl

Seite 662 - Configuring Passive-Interface

Configuring Anycast RPTo configure anycast RP, use the following commands.1. In each routing domain that has multiple RPs serving a group, create a Lo

Seite 663 - Configuring a Default Route

CONFIGURATION modeip msdp originator-idExamples of R1, R2, and R3 Configuration for MSDP with Anycast RPThe following example shows an R1 configuratio

Seite 664 - Displaying Graceful Restart

no shutdown!interface Loopback 0 ip pim sparse-mode ip address 192.168.0.1/32 no shutdown!interface Loopback 1 ip address 192.168.0.22/32 no sh

Seite 665

neighbor 192.168.0.22 remote-as 100 neighbor 192.168.0.22 ebgp-multihop 255 neighbor 192.168.0.22 update-source Loopback 0 neighbor 192.168.0.22

Seite 666

interface GigabitEthernet 2/1 ip pim sparse-mode ip address 10.11.4.1/24 no shutdown!interface GigabitEthernet 2/11 ip pim sparse-mode ip address

Seite 667

redistribute connected redistribute bgp 200!router bgp 200 redistribute ospf 1 neighbor 192.168.0.2 remote-as 100 neighbor 192.168.0.2 ebgp-mult

Seite 668

33Multiple Spanning Tree Protocol (MSTP)Multiple spanning tree protocol (MSTP) is supported on the S4810 platform.Protocol OverviewMSTP — specified in

Seite 669

Spanning Tree VariationsThe Dell Networking OS supports four variations of spanning tree, as shown in the following table.Table 47. Spanning Tree Vari

Seite 670

• To copy a file from the internal FLASH, enter flash:// followed by the filename.• To copy the running configuration, enter the keyword running-confi

Seite 671

• Prevent Network Disruptions with BPDU Guard• Enabling SNMP Traps for Root Elections and Topology Changes• Configuring Spanning Trees as HitlessEnabl

Seite 672

mstiSpecify the keyword vlan then the VLANs that you want to participate in the MSTI.Examples of Configuring and Viewing MSTIThe following examples sh

Seite 673 - Troubleshooting OSPFv3

Influencing MSTP Root SelectionMSTP determines the root bridge, but you can assign one bridge a lower priority to increase the probability that it bec

Seite 674 - Viewing Summary Information

NOTE: Some non-Dell Networking OS equipment may implement a non-null default region name. SFTOS, for example, uses the Bridge ID, while others may use

Seite 675 - Policy-based Routing (PBR)

To change the MSTP parameters, use the following commands on the root bridge.1. Change the forward-delay parameter.PROTOCOL MSTP modeforward-delay sec

Seite 676

Modifying the Interface ParametersYou can adjust two interface parameters to increase or decrease the probability that a port becomes a forwarding por

Seite 677 - Networking OS

you implement only bpduguard, although the interface is placed in an Error Disabled state when receiving the BPDU, the physical interface remains up a

Seite 678

To view the enable status of this feature, use the show running-config spanning-tree mstp command from EXEC Privilege mode.MSTP Sample ConfigurationsT

Seite 679

!(Step 3)interface Vlan 100 no ip address tagged GigabitEthernet 1/21,31 no shutdown!interface Vlan 200 no ip address tagged GigabitEthernet 1/21

Seite 680 - PBR Exceptions (Permit)

Router 3 Running-ConfigurationThis example uses the following steps:1. Enable MSTP globally and set the region name and revision map MSTP instances to

Seite 681

4ManagementManagement is supported on the S4810 platform.This chapter describes the different protocols or services used to manage the Dell Networking

Seite 682 - Sample Configuration

(Step 2)interface 1/0/31 no shutdown spanning-tree port mode enable switchport protected 0exitinterface 1/0/32 no shutdown spanning-tree port mod

Seite 683 - Create the Redirect-List GOLD

– As shown in the following, the MSTP routers are located in the same region.– Does the debug log indicate that packets are coming from a “Different R

Seite 684 - View Redirect-List GOLD

The following example shows viewing the debug log of an unsuccessful MSTP configuration.4w0d4h : MSTP: Received BPDU on Gi 2/21 :ProtId: 0, Ver: 3, Bp

Seite 685 - PIM Sparse-Mode (PIM-SM)

34Multicast FeaturesMulticast features are supported on the S4810 platform.NOTE: Multicast is supported on secondary IP addresses on the S4810 platfor

Seite 686 - Send Multicast Traffic

Figure 92. Multicast with ECMPImplementation InformationBecause protocol control traffic in Dell Networking OS is redirected using the MAC address, an

Seite 687 - Enable PIM-SM

Protocol Ethernet AddressPIM-SM 01:00:5e:00:00:0d• The Dell Networking OS implementation of MTRACE is in accordance with IETF draft draft-fenner-trace

Seite 688 - Configuring S,G Expiry Timers

• If the limit is decreased after it is reached, Dell Networking OS does not clear the existing sessions. Entries are cleared after a timeout (you may

Seite 689

no access list limiting Receiver 1, so both IGMP reports are accepted, and two corresponding entries are created in the routing table.Figure 93. Preve

Seite 690

Location Description• no shutdown1/31• Interface GigabitEthernet 1/31• ip pim sparse-mode• ip address 10.11.13.1/24• no shutdown2/1• Interface Gigabit

Seite 691

Location Description• ip igmp access-group igmpjoinfilR2G2• no shutdownRate Limiting IGMP Join RequestsIf you expect a burst of IGMP Joins, protect th

Seite 692

Allowing Access to CONFIGURATION Mode CommandsTo allow access to CONFIGURATION mode, use the privilege exec level level configure command from CONFIGU

Seite 693 - Enabling PIM-SSM

Figure 94. Preventing a Source from Transmitting to a GroupTable 50. Preventing a Source from Transmitting to a Group — DescriptionLocation Descriptio

Seite 694

Location Description• no shutdown2/1• Interface GigabitEthernet 2/1• ip pim sparse-mode• ip address 10.11.1.1/24• no shutdown2/11• Interface GigabitEt

Seite 695

Preventing a PIM Router from Processing a JoinTo permit or deny PIM Join/Prune messages on an interface using an extended IP access list, use the foll

Seite 696 - Port Monitoring

35Open Shortest Path First (OSPFv2 and OSPFv3)Open shortest path first (OSPFv2 for IPv4) and OSPF version 3 (OSPF for IPv6) are supported on the S4810

Seite 697

Areas allow you to further organize your routers within in the AS. One or more areas are required within the AS. Areas are valuable in that they allow

Seite 698

The backbone is the only area with a default area number. All other areas can have their Area ID assigned in the configuration.In the previous example

Seite 699 - Configuring Port Monitoring

Figure 96. OSPF Routing ExamplesBackbone Router (BR)A backbone router (BR) is part of the OSPF Backbone, Area 0.This includes all ABRs. It can also in

Seite 700

An ABR can connect to many areas in an AS, and is considered a member of each area it connects to.Autonomous System Border Router (ASBR)The autonomous

Seite 701 - Remote Port Mirroring

available. An ABR floods the information for the router (for example, the ASBR where the Type 5 advertisement originated. The link-state ID for Type 4

Seite 702 - Remote Port Mirroring Example

Virtual LinksIn the case in which an area cannot be directly connected to Area 0, you must configure a virtual link between that area and Area 0.The t

Seite 703

• Allow access to a CONFIGURATION, INTERFACE, LINE, ROUTE-MAP, and/or ROUTER mode command.CONFIGURATION modeprivilege {configure |interface | line | r

Seite 704 - Restrictions

OSPF with Dell Networking OSDell Networking OS supports up to 10,000 OSPF routes for OSPFv2. Within that 10,000 routes, you can designate up to 8,000

Seite 705

period, neighbor OSPFv2 /v3 interfaces save the LSAs from the restarting OSPF interface. Helper neighbor routers continue to announce the restarting r

Seite 706

Multi-Process OSPFv2 (IPv4 only)Multi-process OSPF is supported on the S4810 platform with Dell Networking OS version 7.8.1.0 and later, and is suppor

Seite 707

Dell(conf-if-gi-2/2)#ip ospf dead-interval 80Dell(conf-if-gi-2/2)#In the following example, the dead interval is set at 4x the hello interval (shown i

Seite 708 - Configuration steps for ERPM

• Troubleshooting OSPFv21. Configure a physical interface. Assign an IP address, physical or Loopback, to the interface to enable Layer 3 routing.2. E

Seite 709

Assigning a Router IDIn CONFIGURATION ROUTER OSPF mode, assign the router ID.The router ID is not required to be the router’s IP address. However, Del

Seite 710

3. Return to CONFIGURATION mode to enable the OSPFv2 process globally.CONFIGURATION moderouter ospf process-id [vrf]The range is from 0 to 65535.After

Seite 711

In the example below, an IP address is assigned to an interface and an OSPFv2 area is defined that includes the IP address of a Layer 3 interface.The

Seite 712 - Private VLANs (PVLAN)

Example of Viewing OSPF Status on a Loopback InterfaceDell#show ip ospf 1 intGigabitEthernet 13/23 is up, line protocol is up Internet Address 10.168

Seite 713

Example of the show ip ospf database database-summary CommandTo view which LSAs are transmitted, use the show ip ospf database process-id database-sum

Seite 714 - Configuration Task List

aux Auxiliary lineconsole Primary terminal linevty Virtual terminalDell(conf)#line vty 0Dell(config-line-v

Seite 715 - Creating a Primary VLAN

Example of Viewing Passive InterfacesWhen you configure a passive interface, the show ip ospf process-id interface command adds the words passive inte

Seite 716 - Creating a Community VLAN

NOTE: A higher convergence level can result in occasional loss of OSPF adjacency. Generally, convergence level 1 meets most convergence requirements.

Seite 717 - Creating an Isolated VLAN

• Change the time interval between hello-packet transmission.CONFIG-INTERFACE modeip ospf hello-interval seconds– seconds: the range is from 1 to 6553

Seite 718

The bold lines in the example show the change on the interface. The change is reflected in the OSPF configuration.Dell(conf-if)#ip ospf cost 45Dell(co

Seite 719

Enabling OSPFv2 Graceful RestartGraceful restart is enabled for the global OSPF process.For more information, refer to Graceful Restart.The Dell Netwo

Seite 720

3. Configure the graceful restart role or roles that this OSPFv2 router performs.CONFIG-ROUTEROSPF- id modegraceful-restart role [helper-only | restar

Seite 721

seq sequence-number {deny |permit} ip-prefix [ge min-prefix-length] [le max-prefix-length]The optional parameters are:– ge min-prefix-length: is the m

Seite 722

network 10.1.2.32 0.0.0.255 area 2.2.2.2 network 10.1.3.24 0.0.0.255 area 3.3.3.3 distribute-list dilling inDell(conf-router_ospf)#Troubleshooting

Seite 723

• View debug messages.EXEC Privilege modedebug ip ospf process-id [event | packet | spf | database-timers rate-limit]To view debug messages for a spec

Seite 724 - Disabling PVST+

Figure 98. Basic Topology and CLI Commands for OSPFv2OSPF Area 0 — Gl 1/1 and 1/2router ospf 11111 network 10.0.11.0/24 area 0 network 10.0.12.0/24

Seite 725

• Disable logging to terminal lines.CONFIGURATION modeno logging monitor• Disable console logging.CONFIGURATION modeno logging consoleAudit and Securi

Seite 726

OSPF Area 0 — Gl 2/1 and 2/2router ospf 22222 network 192.168.100.0/24 area 0 network 10.2.21.0/24 area 0 network 10.2.22.0/24 area 0!interface Loo

Seite 727

Assigning IPv6 Addresses on an InterfaceTo assign IPv6 addresses to an interface, use the following commands.1. Assign an IPv6 address to the interfac

Seite 728

– number: the IPv4 address.The format is A.B.C.D.NOTE: Enter the router-id for an OSPFv3 router as an IPv4 IP address.• Disable OSPF.CONFIGURATION mod

Seite 729

To indicate that hello packets are not transmitted on that interface, when you configure a passive interface, the show ipv6 ospf interface command add

Seite 730 - PVST+ Sample Configurations

period command. The grace period is the time that the OSPFv3 neighbors continue to advertise the restarting router as though it is fully adjacent. Whe

Seite 731

• Display the Type-11 Grace LSAs sent and received on an OSPFv3 router (shown in the following example).EXEC Privilege modeshow ipv6 ospf database gra

Seite 732 - Quality of Service (QoS)

The following example shows the show ipv6 ospf database grace-lsa command.Dell#show ipv6 ospf database grace-lsa!Type-11 Grace LSA (Area 0)LS Age

Seite 733

between the two mechanisms is the extent of the coverage. ESP only protects IP header fields if they are encapsulated by ESP.You decide the set of IPs

Seite 734 - Port-Based QoS Configurations

– Configuring IPsec Authentication on an Interface– Configuring IPsec Encryption on an Interface– Configuring IPsec Authentication for an OSPFv3 Area–

Seite 735

NOTE: When you configure encryption using the ipv6 ospf encryption ipsec command, you enable both IPsec encryption and authentication. However, when y

Seite 736

When you enabled RBAC and extended logging:• Only the system administrator user role can execute this command.• The system administrator and system se

Seite 737 - Classify Traffic

If you have enabled IPSec encryption in an OSPFv3 area using the area encryption command, you cannot use the area authentication command in the area a

Seite 738 - Creating a Layer 3 Class Map

– area area-id: specifies the area for which OSPFv3 traffic is to be encrypted. For area-id, enter a number or an IPv6 prefix.– spi number: is the sec

Seite 739 - Creating a Layer 2 Class Map

Examples of the show crypto ipsec CommandsIn the first example, the keys are not encrypted (shown in bold). In the second and third examples, the keys

Seite 740

outbound ah sas spi : 500 (0x1f4) transform : ah-md5-hmac in use settings : {Transport, } replay detection support : N STATUS : ACTIVE

Seite 741 - Create a QoS Policy

• show ipv6 routesViewing Summary InformationTo get general route, configuration, links status, and debug information, use the following commands.• Vi

Seite 742 - Creating an Output QoS Policy

36Policy-based Routing (PBR)Policy-based Routing (PBR) allows a switch to make routing decisions based on policies applied to an interface.This chapte

Seite 743 - Allocating Bandwidth to Queue

To enable a PBR, you create a redirect list. Redirect lists are defined by rules, or routing policies. The following parameters can be defined in the

Seite 744 - Create Policy Maps

Implementing Policy-based Routing with Dell Networking OS• Non-contiguous bitmasks for PBR• Hot-Lock PBRNon-contiguous bitmasks for PBRNon-contiguous

Seite 745

The following example creates a redirect list by the name of “xyz.”Dell(conf)#ip redirect-list ?WORD Redirect-list name (max 16 chars) Dell(co

Seite 746

Dell(conf-redirect-list)#redirect 3.3.3.3 ?<0-255> An IP protocol number icmp

Seite 747 - DSCP Color Maps

The following describes the two log messages formats:• 0 – Displays syslog messages format as described in RFC 3164, The BSD syslog Protocol• 1 – Disp

Seite 748 - Creating a DSCP Color Map

PBR Exceptions (Permit)Use the command permit to create an exception to a redirect list. Exceptions are used when a forwarding decision should be base

Seite 749 - Displaying DSCP Color Maps

Applying a Redirect-list to an Interface Example:Dell(conf-if-te-2/0)#ip redirect-group xyz Dell(conf-if-te-2/0)#Applying a Redirect-list to an Interf

Seite 750 - Enabling QoS Rate Adjustment

NOTE: If, the redirect-list is applied to an interface, the output of show ip redirect-list redirect-list-name command displays reachability and ARP s

Seite 751

Create the Redirect-List GOLDEDGE_ROUTER(conf-if-Te-2/23)#ip redirect-list GOLDEDGE_ROUTER(conf-redirect-list)#description Route GOLD traffic to ISP_G

Seite 752 - Creating WRED Profiles

View Redirect-List GOLDEDGE_ROUTER#show ip redirect-listIP redirect-list GOLD: Defined as: seq 5 redirect 10.99.99.254 ip 192.168.1.0/24 any, Next-ho

Seite 753

37PIM Sparse-Mode (PIM-SM)Protocol-independent multicast sparse-mode (PIM-SM) is supported on the S4810 platform.PIM-SM is a multicast protocol that f

Seite 754

received becomes the outgoing interface associated with the (*,G) entry. This process constructs an RPT branch to the RP.3. If a host on the same subn

Seite 755

Important Point to RememberIf you use a Loopback interface with a /32 mask as the RP, you must enable PIM Sparse-mode on the interface.Configuring PIM

Seite 756

NOTE: You can influence the selection of the Rendezvous Point by enabling PIM-Sparse mode on a Loopback interface and assigning a low IP address.To di

Seite 757

To configure a global expiry time or to configure the expiry time for a particular (S,G) entry, use the following commands.1. Enable global expiry tim

Seite 758 - Marking Packets

Setting Up a Secure Connection to a Syslog ServerYou can use reverse tunneling with the port forwarding to securely connect to a syslog server.Pre-req

Seite 759

Configuring a Static Rendezvous PointThe rendezvous point (RP) is a PIM-enabled interface on a router that acts as the root a group-specific tree; eve

Seite 760

interface out of which it is sent and a DR priority value. The router with the greatest priority value is the DR. If the priority value is the same fo

Seite 761

38PIM Source-Specific Mode (PIM-SSM)PIM source-specific mode (PIM-SSM) is supported on the platform.PIM-SSM is a multicast protocol that forwards mult

Seite 762

Configure PIM-SMMConfiguring PIM-SSM is a two-step process.1. Configure PIM-SMM.2. Enable PIM-SSM for a range of addresses.Related Configuration Tasks

Seite 763

• When you remove the mapping configuration, Dell Networking OS removes the corresponding (S,G) states that it created and re-establishes the original

Seite 764

Interface Vlan 400Group 239.0.0.1Uptime 00:00:05Expires NeverRouter mode INCLUDELas

Seite 765

39Port MonitoringPort monitoring is supported on the S4810 platform.Mirroring is used for monitoring Ingress or Egress or both Ingress and Egress traf

Seite 766

2 Te 0/0 Te 0/2 both Port N/A N/ADell (conf-mon-sess-2)#do show running-config monitor session!monitor ses

Seite 767

0 Te 0/13 Gi 0/1 rx interface Port-based10 Te 0/14 Gi 0/2 rx interface Port-based20 Te 0/15 Gi 0/3

Seite 768

Configuring Port MonitoringTo configure port monitoring, use the following commands.1. Verify that the intended monitoring port has no configuration o

Seite 769

Configure Egress ACLs... 140Applying

Seite 770

3. Configure logging to a local host. locahost is “127.0.0.1” or “::1”.If you do not, the system displays an error when you attempt to enable role-ba

Seite 771 - Enabling RIP Globally

Note: Source as VLAN is achieved via Flow based mirroring. Please refer section Enabling Flow-Based Monitoring.In the following example, the host and

Seite 772 - Configure RIP on Interfaces

3. Apply the ACL to the monitored port.INTERFACE modeip access-group access-listExample of the flow-based enable CommandTo view an access-list that yo

Seite 773

Remote Port Mirroring ExampleRemote port mirroring uses the analyzers shown in the aggregation network in Site A.The VLAN traffic on monitored links f

Seite 774

• You can configure any switch in the network with source ports and destination ports, and allow it to function in an intermediate transport session f

Seite 775 - Summarize Routes

• By default, destination port sends the mirror traffic to the probe port by stripping off the rpm header. We can also configure the destination port

Seite 776 - Debugging RIP

R 100 Active T Fo 0/44R 300 Active T Fo 0/52Configuring the Sample Remot

Seite 777 - RIP Configuration Example

Dell(conf)#mac access-list standard mac_aclDell(config-std-macl)#permit 00:00:00:00:11:22 count monitorDell(config-std-macl)#exitDell(conf)#interface

Seite 778 - Core 2 RIP Output

Dell(conf-if-vl-20)#mode remote-port-mirroringDell(conf-if-vl-20)#tagged te 0/1Dell(conf-if-vl-20)#exitDell(conf)#interface vlan 30Dell(conf-if-vl-30)

Seite 779 - Core 3 RIP Output

5. Show the output for the LACP. Dell#show interfaces port-channel brief Codes: L - LACP Port-channel O - OpenFlow Controller Port-channel

Seite 780

4direction Specify rx, tx or both in case to monitor ingress/egress or both ingress and egress packets on the specified port..5erpm source-ip <id&g

Seite 781 - RIP Configuration Summary

• Disable console logging.CONFIGURATION modeno logging consoleSending System Messages to a Syslog ServerTo send system messages to a specified syslog

Seite 782

ERPM Behavior on a typical Dell Networking OS The Dell Networking OS is designed to support only the Encapsulation of the data received / transmitted

Seite 783 - Remote Monitoring (RMON)

39th byte in a given ERPM packet. The first 38/42 bytes of the header needs to be ignored/ chopped off.– Some tools support options to edit the captur

Seite 784 - Setting the rmon Alarm

40Private VLANs (PVLAN)The private VLAN (PVLAN) feature is supported on the S4810 platform.For syntax details about the commands described in this cha

Seite 785 - Configuring an RMON Event

– A primary VLAN has one or more secondary VLANs.– A primary VLAN and each of its secondary VLANs decrement the available number of VLAN IDs in the sw

Seite 786

INTERFACE VLAN mode[no] private-vlan mapping secondary-vlan vlan-list• Display type and status of PVLAN interfaces.EXEC mode or EXEC Privilege modesho

Seite 787

4. Select the PVLAN mode.INTERFACE modeswitchport mode private-vlan {host | promiscuous | trunk}• host (isolated or community VLAN port)• promiscuous

Seite 788

4. Map secondary VLANs to the selected primary VLAN.INTERFACE VLAN modeprivate-vlan mapping secondary-vlan vlan-listThe list of secondary VLANs can be

Seite 789

4. Add one or more host ports to the VLAN.INTERFACE VLAN modetagged interface or untagged interfaceYou can enter the interfaces singly or in range for

Seite 790

Dell(conf-vlan-100)# private-vlan mode isolatedDell(conf-vlan-100)# untagged Gi 2/2Private VLAN Configuration ExampleThe following example shows a pri

Seite 791

• The ports in isolated VLAN 4003 can only communicate with the promiscuous ports in the primary VLAN 4000.• All the ports in the secondary VLANs (bot

Seite 792

• Specify the minimum severity level for logging to a syslog server.CONFIGURATION modelogging trap level• Specify the minimum severity level for loggi

Seite 793

The following examples show the results of using this command without the command options on the C300 and S50V switches in the topology diagram previo

Seite 794

switchport mode private-vlan promiscuous no shutdown!interface GigabitEthernet 0/4 no ip address switchport switchport mode private-vlan host n

Seite 795

41Per-VLAN Spanning Tree Plus (PVST+)Per-VLAN spanning tree plus (PVST+) is supported on the S4810 platform.Protocol OverviewPVST+ is a variation of s

Seite 796

Table 51. Spanning Tree Variations Dell Networking OS SupportsDell Networking Term IEEE SpecificationSpanning Tree Protocol (STP) 802 .1dRapid Spannin

Seite 797

Enabling PVST+When you enable PVST+, Dell Networking OS instantiates STP on each active VLAN.1. Enter PVST context.PROTOCOL PVST modeprotocol spanning

Seite 798 - Security

Figure 103. Load Balancing with PVST+The bridge with the bridge value for bridge priority is elected root. Because all bridges use the default priorit

Seite 799

Root Identifier has priority 4096, Address 0001.e80d.b6d6Root Bridge hello time 2, max age 20, forward delay 15Bridge Identifier has priority 4096, Ad

Seite 800 - AAA Authentication

PROTOCOL PVST modevlan max-ageThe range is from 6 to 40.The default is 20 seconds.The values for global PVST+ parameters are given in the output of th

Seite 801

The range is from 0 to 240, in increments of 16.The default is 128.The values for interface PVST+ parameters are given in the output of the show spann

Seite 802 - Enabling AAA Authentication

PVST+ in Multi-Vendor NetworksSome non-Dell Networking systems which have hybrid ports participating in PVST+ transmit two kinds of BPDUs: an 802.1D B

Seite 803 - AAA Authorization

%TSM-6-SFM_DISCOVERY: Found SFM 6%TSM-6-SFM_DISCOVERY: Found SFM 7%TSM-6-SFM_SWITCHFAB_STATE: Switch Fabric: UP%TSM-6-SFM_DISCOVERY: Found SFM 8%TSM-6

Seite 804

Example of Viewing the Extend System ID in a PVST+ ConfigurationDell(conf-pvst)#do show spanning-tree pvst vlan 5 briefVLAN 5Executing IEEE compatible

Seite 805

no ip address tagged GigabitEthernet 2/12,32 no shutdown!interface Vlan 200 no ip address tagged GigabitEthernet 2/12,32 no shutdown!interface

Seite 806

42Quality of Service (QoS)Quality of service (QoS) is supported on the S4810 platform.Differentiated service is accomplished by classifying and queuin

Seite 807

Feature DirectionConfigure a Scheduler to Queue EgressSpecify WRED Drop Precedence EgressCreate Policy Maps Ingress + EgressCreate Input Policy Maps I

Seite 808

Figure 105. Dell Networking QoS ArchitectureImplementation InformationThe Dell Networking QoS implementation complies with IEEE 802.1p User Priority B

Seite 809 - RADIUS Authentication

Setting dot1p Priorities for Incoming TrafficDell Networking OS places traffic marked with a priority in a queue based on the following table.If you s

Seite 810

class dynamic dotp or trust dot1p. When priority-tagged frames ingress a tagged port, the frames are dropped because, for a tagged port, the default V

Seite 811

Policy-Based QoS ConfigurationsPolicy-based QoS configurations consist of the components shown in the following example.Figure 106. Constructing Polic

Seite 812 - Monitoring RADIUS

Creating a Layer 3 Class MapA Layer 3 class map differentiates ingress packets based on the DSCP value or IP precedence, and characteristics defined i

Seite 813

The following example matches IPv6 traffic with a DSCP value of 40.Dell(conf)# class-map match-all test Dell(conf-class-map)# match ipv6 dscp 40The fo

Seite 814 - TACACS+ Remote Authentication

– user (for user programs)– uucp (UNIX to UNIX copy protocol)Example of the show running-config logging CommandTo view nondefault settings, use the sh

Seite 815

numbers closer to 0) before rules with higher order numbers so that packets are matched as you intended.• Specify the order in which you want to apply

Seite 816 - Enabling SCP and SSH

-----------------------------------------------------------------------20416 1 18 IP 0x0 0 0 23.64.0.5/32 0.0.0.0/0 20 220417 1 18

Seite 817

Creating an Input QoS PolicyTo create an input QoS policy, use the following steps.1. Create a Layer 3 input QoS policy.CONFIGURATION modeqos-policy-i

Seite 818

Configuring Policy-Based Rate ShapingTo configure policy-based rate shaping, use the following command.• Configure rate shape egress traffic.QOS-POLIC

Seite 819

Create Policy MapsThere are two types of policy maps: input and output.Creating Input Policy MapsThere are two types of input policy-maps: Layer 3 and

Seite 820 - Secure Shell Authentication

Table 55. Default DSCP to Queue MappingDSCP/CP hex range (XXX)xxxDSCP Definition Traditional IP PrecedenceInternal Queue ID DSCP/CP decimal111XXX Netw

Seite 821

Mapping dot1p Values to Service QueuesAll traffic is by default mapped to the same queue, Queue 0.If you honor dot1p on ingress, you can create servic

Seite 822

Creating Output Policy MapsCreating output policy maps is supported on the S4810 platform.1. Create an output policy map.CONFIGURATION modepolicy-map-

Seite 823 - Troubleshooting SSH

• Displaying Color Maps• Display Color Map ConfigurationCreating a DSCP Color MapYou can create a DSCP color map to outline the differentiated service

Seite 824 - Table 62. VTY Access

Create the DSCP color map profile, bat-enclave-map, with a yellow drop precedence , and set the DSCP values to 9,10,11,13,15,16Dell(conf)# qos dscp-co

Seite 825

Enabling Timestamp on Syslog MessagesBy default, syslog messages do not include a time/date stamp stating when the error or message was created.To ena

Seite 826 - Role-Based Access Control

Display detailed information about a color policy for a specific interfaceDell# show qos dscp-color-policy detail te 0/10Interface TenGigabitEthernet

Seite 827

The range is from 1 to 3.Weighted Random Early DetectionWeighted random early detection (WRED) is supported on the S4810 platform.The WRED congestion

Seite 828

Default Profile Name Minimum Threshold Maximum Threshold Maximum Drop Ratewred_teng_g 467 4671 50wred_fortyg_y 467 4671 50wred_fortyg_g 467 4671 25Cre

Seite 829 - User Roles

wred_teng_y 467 4671 100wred_teng_g 467 4671 50wred_fortyg_y 467 4671 50wred_

Seite 830

• The estimated number of CAM entries the policy-map will consume.• Whether or not the policy-map can be applied.• The number of interfaces in a port-

Seite 831

are time-sensitive, such as video on demand (VoD) or voice over IP (VoIP) applications. In such cases, you can use ECN in conjunction with WRED to res

Seite 832

WRED/ECN configurations for the queues that belong to backplane ports are common to all the backplane ports and cannot be specified separately for eac

Seite 833

To configure the weight factor for WRED and ECN capabilities, global buffer pools for multiple queues, and associating a service class with ECN markin

Seite 834

Guidelines for Configuring ECN for Classifying and Color-Marking PacketsKeep the following points in mind while configuring the marking and mapping of

Seite 835

Applying this policy-map “ecn_0_pmap” will mark all the packets with ‘ecn == 0’ as yellow packets on queue0 (default queue).Classifying Incoming Packe

Seite 836 - Role Accounting

• Configure FTP Server Parameters (optional)• Configure FTP Client Parameters (optional)Enabling the FTP ServerTo enable the system as an FTP server,

Seite 837 - Displaying User Roles

Until Release 9.3(0.0), the software has the capability to qualify only on the 6-bit DSCP part of the ToS field in IPv4 Header. You can now accept and

Seite 838

This marking action to set the color of the packet is allowed only on the ‘match-any’ logical operator of the class-map.This marking-action can be con

Seite 839 - Service Provider Bridging

seq 15 permit any dscp 40 ecn 3!ip access-list standard dscp_50_non_ecn seq 5 permit any dscp 50 ecn 0!ip access-list standard dscp_40_non_ecn seq 5

Seite 840

Applying DSCP and VLAN Match Criteria on a Service QueueYou can configure Layer 3 class maps which contain both a Layer 3 Differentiated Services Code

Seite 841 - Configure VLAN Stacking

Classifying Incoming Packets Using ECN and Color-MarkingExplicit Congestion Notification (ECN) is a capability that enhances WRED by marking the packe

Seite 842

Until Release 9.3(0.0), the software has the capability to qualify only on the 6-bit DSCP part of the ToS field in IPv4 Header. You can now accept and

Seite 843 - Debugging VLAN Stacking

This marking action to set the color of the packet is allowed only on the ‘match-any’ logical operator of the class-map.This marking-action can be con

Seite 844 - VLAN Stacking

Sample configuration to mark non-ecn packets as “yellow” with Multiple traffic classConsider the example where there are no different traffic classes

Seite 845 - Building A

service-queue 2 class-map class_dscp_40 service-queue 3 class-map class_dscp_50Approach with explicit ECN match qualifiers for ECN packets:!ip access

Seite 846

43Routing Information Protocol (RIP)Routing information protocol (RIP) is supported on the S4810 platform.RIP is based on a distance-vector algorithm;

Seite 847

– For a Gigabit Ethernet interface, enter the keyword GigabitEthernet then the slot/port information.– For a loopback interface, enter the keyword loo

Seite 848 - Enabling Drop Eligibility

Implementation InformationDell Networking OS supports both versions of RIP and allows you to configure one version globally and the other version on i

Seite 849

Enabling RIP GloballyBy default, RIP is not enabled in Dell Networking OS.To enable RIP globally, use the following commands.1. Enter ROUTER RIP mode

Seite 850

192.162.2.0/24 [120/1] via 29.10.10.12, 00:01:21, Fa 0/0192.162.2.0/24 auto-summary192.161.1.0/24 [120/1] via 29.10.10.12, 00:00:27, Fa 0/019

Seite 851

distribute-list prefix-list-name in• Assign a configured prefix list to all outgoing RIP routes.ROUTER RIP modedistribute-list prefix-list-name outTo

Seite 852 - Layer 2 Protocol Tunneling

You can set one RIP version globally on the system using system. This command sets the RIP version for RIP traffic on the interfaces participating in

Seite 853

The following example of the show ip protocols command confirms that both versions are sent out that interface. This interface no longer sends and rec

Seite 854

The autosummary command requires no other configuration commands. To disable automatic route summarization, enter no autosummary in ROUTER RIP mode.NO

Seite 855 - Setting Rate-Limit BPDUs

Enable debugging of RIP.Example of the debug ip rip CommandThe following example shows the confirmation when you enable the debug function.Dell#debug

Seite 856 - Provider Backbone Bridging

Core 2 RIP OutputThe examples in the section show the core 2 RIP output.Examples of the show ip Commands to View Core 2 Information• To display Core 2

Seite 857 - Overview

The following example shows the show ip protocols command to show the RIP configuration activity on Core 2.Core2#show ip protocolsRouting Protocol is

Seite 858 - Enabling Extended sFlow

Example of an ACL that Permits Terminal AccessTo view the configuration, use the show config command in LINE mode.Dell(config-std-nacl)#show config!ip

Seite 859 - Displaying Show sFlow Global

Examples of the show ip Commands to View Learned RIP Routes on Core 3The following example shows the show ip rip database command to view the learned

Seite 860

GigabitEthernet 3/44 2 2 GigabitEthernet 3/43 2 2Routing for Networks: 10.11.20.0 10.11.30.0 192.168.2.0 192.168.1.0Rou

Seite 861 - Back-Off Mechanism

ip address 192.168.2.1/24 no shutdown!router ripversion 2network 10.11.20.0network 10.11.30.0network 192.168.1.0network 192.168.2.0782Routing Infor

Seite 862

44Remote Monitoring (RMON)Remote monitoring (RMON) is supported on the S4810 platform.RMON is an industry-standard implementation that monitors networ

Seite 863

long as the master RPM had been running long enough to sample all the data. NMS backs up all the long-term data collection and displays the failover d

Seite 864

The following example configures RMON alarm number 10. The alarm monitors the MIB variable 1.3.6.1.2.1.2.2.1.20.1 (ifEntry.ifOutErrors) once every 20

Seite 865 - SNMPv3 Compliance With FIPS

– controlEntry: specifies the RMON group of statistics using a value.– integer: a value from 1 to 65,535 that identifies the RMON Statistics Table. Th

Seite 866

45Rapid Spanning Tree Protocol (RSTP)Rapid spanning tree protocol (RSTP) is supported on the S4810 platform.Protocol OverviewRSTP is a Layer 2 protoco

Seite 867 - Set up SNMP

Important Points to Remember• RSTP is disabled by default.• Dell Networking OS supports only one Rapid Spanning Tree (RST) instance.• All interfaces i

Seite 868 - Creating a Community

3. Enable the interface.INTERFACE modeno shutdownExample of Verifying an Interface is in Layer 2 Mode and EnabledTo verify that an interface is in Lay

Seite 869 - Reading Managed Object Values

Example of Terminal Line AuthenticationIn the following example, VTY lines 0-2 use a single authentication method, line.Dell(conf)#aaa authentication

Seite 870 - Writing Managed Object Values

Figure 109. Rapid Spanning Tree Enabled GloballyTo view the interfaces participating in RSTP, use the show spanning-tree rstp command from EXEC privil

Seite 871

BPDU : sent 121, received 2The port is not in the Edge port modePort 379 (GigabitEthernet 2/3) is designated ForwardingPort path cost 20000, Port prio

Seite 872

Modifying Global ParametersYou can modify RSTP parameters.The root bridge sets the values for forward-delay, hello-time, and max-age and overwrites th

Seite 873

NOTE: With large configurations (especially those configurations with more ports) Dell Networking recommends increasing the hello-time.The range is fr

Seite 874

To view the current values for interface parameters, use the show spanning-tree rstp command from EXEC privilege mode.Enabling SNMP Traps for Root Ele

Seite 875

• If the interface to be shut down is a port channel, all the member ports are disabled in the hardware.• When you add a physical port to a port chann

Seite 876

The range is from 50 to 950 milliseconds.Example of Verifying Hello-Time IntervalDell(conf-rstp)#do show spanning-tree rstp briefExecuting IEEE compat

Seite 877 - Copying a Configuration File

46Software-Defined Networking (SDN)Dell Networking operating software supports Software-Defined Networking (SDN). For more information, refer to the S

Seite 878

47SecuritySecurity features are supported on the S4810 platform.This chapter describes several ways to provide security to the Dell Networking system.

Seite 879

– system: sends accounting information of any other AAA configuration.– exec: sends accounting information when a user has logged in to EXEC mode.– co

Seite 880

Local Preference... 192Multi-Exi

Seite 881 - Manage VLANs using SNMP

• Telnet to the peer RPM. You do not need to configure the management port on the peer RPM to be able to telnet to it.EXEC Privilege modetelnet-peer-r

Seite 882 - Assigning a VLAN Alias

CONFIG-LINE-VTY modeaccounting commands 15 com15accounting exec execAcctExample of Enabling AAA Accounting with a Named Method ListDell(config-line-vt

Seite 883

NOTE: In the release 9.4.(0.0), RADIUS and TACACS servers support VRF-awareness functionality. You can create RADIUS and TACACS groups and then map mu

Seite 884 - Managing Overload on Startup

3. Assign a method-list-name or the default list to the terminal line.LINE modelogin authentication {method-list-name | default}To view the configurat

Seite 885

The following example shows enabling authentication from the RADIUS server.Dell(config)# aaa authentication enable default radius tacacsRadius and TAC

Seite 886

Privilege levels 2 through 14 are not configured and you can customize them for different users and access.After you configure other privilege levels,

Seite 887 - Deriving Interface Indices

Configuring the Enable Password CommandTo configure Dell Networking OS, use the enable command to enter EXEC Privilege level 15. After entering the co

Seite 888 - Monitor Port-Channels

To assign commands and passwords to a custom privilege level, use the following commands. You must be in privilege level 15.1. Assign a user name and

Seite 889

Line 2: All other users are assigned a password to access privilege level 8.Line 3: The configure command is assigned to privilege level 8 because it

Seite 890

• Configure a custom privilege level for the terminal lines.LINE modeprivilege level level– level level: The range is from 0 to 15. Levels 0, 1, and 1

Seite 891

Transactions between the RADIUS server and the client are encrypted (the users’ passwords are not sent in plain text). RADIUS uses UDP as the transpor

Seite 892 - Stack Master Election

You can then send any user a message using the send command from EXEC Privilege mode. Alternatively, you can clear any line using the clear command fr

Seite 893 - Failover Roles

Configuration Task List for RADIUSTo authenticate users using RADIUS, you must specify at least one RADIUS server so that the system can communicate w

Seite 894

• Enable AAA login authentication for the specified RADIUS method list.LINE modelogin authentication {method-list-name | default}This procedure is man

Seite 895 - Supported Stacking Topologies

Setting Global Communication Parameters for all RADIUS Server HostsYou can configure global communication parameters (auth-port, key, retransmit, and

Seite 896

TACACS+Dell Networking OS supports terminal access controller access control system (TACACS+ client, including support for login authentication.Config

Seite 897

Example of a Failed AuthenticationTo view the configuration, use the show config in LINE mode or the show running-config tacacs+ command in EXEC Privi

Seite 898 - Create an S-Series Stack

Example of Specifying a TACACS+ Server HostDell(conf)#Dell(conf)#aaa authentication login tacacsmethod tacacs+Dell(conf)#aaa authentication exec tacac

Seite 899

Command AuthorizationThe AAA command authorization feature configures Dell Networking OS to send each configuration command to a TACACS server for aut

Seite 900 - Creating a New Stack

ip ssh server version {1|2}• Display SSH connection information.EXEC Privilege modeshow ip sshSpecifying an SSH VersionThe following example uses the

Seite 901

• ip ssh hostbased-authentication enable: enable host-based authentication for the SSHv2 server.• ip ssh key-size: configure the size of the server-ge

Seite 902

The following example configures the time-based rekey threshold for an SSH session to 30 minutes.Dell(conf)#ip ssh rekey time 30 The following example

Seite 903

5. To save the changes, use the saveenv command.uBoot modesaveenv6. Reload the system.uBoot modereset7. Copy startup-config.bak to the running config.

Seite 904

The default HMAC algorithms are the following:• hmac-md5• hmac-md5-96• hmac-sha1• hmac-sha1-96• hmac-sha2-256• hmac-sha2-256-96When FIPS is enabled, t

Seite 905 - Merge Two S-Series Stacks

• Using RSA Authentication of SSH• Configuring Host-Based SSH AuthenticationImportant Points to Remember• If you enable more than one method, the orde

Seite 906 - Split an S-Series Stack

5. Bind the public keys to RSA authentication.EXEC Privilege modeip ssh rsa-authentication my-authorized-keys flash://public_keyExample of Generating

Seite 907

admin@Unix_client# cat ssh_host_rsa_key.pubssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAIEA8K7jLZRVfjgHJzUOmXxuIbZx/AyWhVgJDQh39k8v3e8eQvLnHBIsqIL8jVy1QHhUeb7GaDl

Seite 908

TelnetTo use Telnet with SSH, first enable SSH, as previously described.By default, the Telnet daemon is enabled. If you want to disable the Telnet da

Seite 909

You can assign line authentication on a per-VTY basis; it is a simple password authentication, using an access-class as authorization.Configure local

Seite 910 - Verify a Stack Configuration

Dell(config-line-vty)#end(same applies for radius and line authentication)VTY MAC-SA Filter SupportDell Networking OS supports MAC access lists which

Seite 911

command to each role and as a result, it is easier and much more efficient to administer user rights. If a user’s role matches one of the allowed user

Seite 912

You must specify at least local authentication. For consistency, the best practice is to define the same authentication method list across all lines,

Seite 913

operator user role. This role does not have access to the commands that are available to the system security administrator for cryptography operations

Seite 914 - Recover from Stack Link Flaps

5. Reload the system.uBoot modereset6. Configure a new enable password.CONFIGURATION modeenable {secret | password}7. Save the running-config to the s

Seite 915

• If you inherit a user role, you cannot modify or delete the inheritance. If you want to change or remove the inheritance, delete the user role and c

Seite 916 - Storm Control

When you modify a command for a role, you specify the role, the mode, and whether you want to restrict access using the deleterole keyword or grant ac

Seite 917 - Spanning Tree Protocol (STP)

The following example shows that the secadmin role can now access Interface mode (highlighted in bold).Role Inheritance Modes

Seite 918

Adding and Deleting Users from a RoleTo create a user name that is authenticated based on a user role, use the username name password encryption-type

Seite 919

the same or greater than the privilege level of those commands. Users with defined roles can use commands provided their role is permitted to use thos

Seite 920

accounting commands role netadmin ucraaaline vty 3login authentication ucraaaauthorization exec ucraaaaccounting commands role netadmin ucraaaline vty

Seite 921

role is Force10-avpair= ”shell:role=<user-role>“ where user-role is a user defined or system-defined role.In the following example, you create a

Seite 922

Active accounted actions on tty2, User john Priv 1 Role netoperatorTask ID 1, EXEC Accounting record, 00:00:30 Elapsed,service=shellActive accounted a

Seite 923 - Enabling PortFast

Role access: secadmin,sysadminDell#show role mode configure interfaceRole access: netadmin, sysadminDell#show role mode configure lineRole access: net

Seite 924

48Service Provider BridgingService provider bridging is supported on the S4810 platform.VLAN StackingVirtual local area network (VLAN) stacking is sup

Seite 925

Restoring the Factory Default SettingsRestoring the factory-default settings deletes the existing NVRAM settings, startup configuration, and all confi

Seite 926 - Selecting STP Root

Figure 110. VLAN Stacking in a Service Provider NetworkImportant Points to Remember• Interfaces that are members of the Default VLAN and are configure

Seite 927 - STP Root Guard

Configure VLAN StackingConfiguring VLAN-Stacking is a three-step process.1. Creating Access and Trunk Ports2. Assign access and trunk ports to a VLAN

Seite 928 - Configuring Root Guard

interface GigabitEthernet 7/12 no ip address switchport vlan-stack trunk no shutdownEnable VLAN-Stacking for a VLANTo enable VLAN-Stacking for a V

Seite 929

To configure trunk ports, use the following commands.1. Configure a trunk port to carry untagged, single-tagged, and double-tagged traffic by making i

Seite 930 - STP Loop Guard

Example of Debugging a VLAN and its PortsThe port notations are as follows:• MT — stacked trunk• MU — stacked access port• T — 802.1Q trunk port• U —

Seite 931 - Configuring Loop Guard

untagged traffic and maps each to the appropriate VLAN, as shown by the packet originating from Building A.Therefore, a mismatched TPID results in the

Seite 932

Figure 112. Single and Double-Tag First-byte TPID Match846Service Provider Bridging

Seite 933 - System Time and Date

Figure 113. Single and Double-Tag TPID MismatchThe following table details the outcome of matched and mismatched TPIDs in a VLAN-stacking network with

Seite 934

Network PositionIncoming Packet TPIDSystem TPID Match Type Pre-Version 8.2.1.0Version 8.2.1.0+0x8100 single-tag matchswitch to VLAN switch to VLAN0x81

Seite 935 - Enabling NTP

• Make packets eligible for dropping based on their DEI value.CONFIGURATION modedei enableBy default, packets are colored green, and DEI is marked 0 o

Seite 936 - Disabling NTP on an Interface

5802.1ag802.1ag is available only on the S4810 platforms.Ethernet operations, administration, and maintenance (OAM) are a set of tools used to install

Seite 937

Example of Viewing DEI-Marking ConfigurationTo display the DEI-marking configuration, use the show interface dei-mark [interface slot/port | linecard

Seite 938

configuration, the queue selected by Dynamic Mode CoS takes precedence. However, rate policing for the queue is determined by QoS configuration. For e

Seite 939

Mapping C-Tag to S-Tag dot1p ValuesTo map C-Tag dot1p values to S-Tag dot1p values and mark the frames accordingly, use the following commands.1. Allo

Seite 940

Figure 115. VLAN Stacking without L2PTYou might need to transport control traffic transparently through the intermediate network to the other region.

Seite 941 - Set Daylight Saving Time

the intermediate network because only Dell Networking OS could recognize the significance of the destination MAC address and rewrite it to the origina

Seite 942

Enabling Layer 2 Protocol TunnelingTo enable Layer 2 protocol tunneling, use the following command.1. Verify that the system is running the default CA

Seite 943

4. Set a maximum rate at which the RPM processes BPDUs for L2PT.VLAN STACKING modeprotocol-tunnel rate-limitThe default is: no rate limiting.The range

Seite 944 - Tunneling

49sFlowConfiguring sFlow is supported on the S4810 platform.OverviewThe Dell Networking Operating System (OS) supports sFlow version 5.sFlow is a stan

Seite 945

Important Points to Remember• The Dell Networking OS implementation of the sFlow MIB supports sFlow configuration via snmpset.• Dell Networking recomm

Seite 946

0 UDP packets dropped165 sFlow samples collected69 sFlow samples dropped due to sub-samplingLinecard 1 Port set 0 H/W sampling rate 8192Gi 1/16: confi

Seite 947

In addition to providing end-to-end OAM in native Layer 2 Ethernet Service Provider/Metro networks, you can also use CFM to manage and troubleshoot an

Seite 948 - Feature Description

Dell#show sflowsFlow services are enabledGlobal default sampling rate: 32768Global default counter polling interval: 201 collectors configuredCollecto

Seite 949

Example of Viewing sFlow Configuration (Line Card)Dell#show sflow stack-unit 1stack-unit 1 Samples rcvd from h/w :165 Samples dropped for

Seite 950 - UFD and NIC Teaming

As a result of back-off, the actual sampling-rate of an interface may differ from its configured sampling rate. You can view the actual sampling-rate

Seite 951

0 UDP packets exported0 UDP packets dropped0 sFlow samples collected0 sFlow samples dropped due to sub-samplingImportant Points to Remember• To export

Seite 952

IP SA IP DA srcAS and srcPeerASdstAS and dstPeerASDescriptionwhere is source is reachable over ECMP.BGP BGP Exported Exported Extended gateway data is

Seite 953

50Simple Network Management Protocol (SNMP)Simple network management protocol (SNMP) is supported on the S4810 platform.NOTE: On Dell Networking route

Seite 954

Configuration mode. When the FIPS mode is enabled on the system, SNMPv3 operates in a FIPS-compliant manner, and only the FIPS-approved algorithm opti

Seite 955

Configuration Task List for SNMPConfiguring SNMP version 1 or version 2 requires a single step.NOTE: The configurations in this chapter use a UNIX env

Seite 956

Creating a CommunityFor SNMPv1 and SNMPv2, create a community to enable the community-based security in Dell Networking OS.The management station gene

Seite 957

snmp-server group group-name 3 noauth auth read name write name• Configure an SNMPv3 view.CONFIGURATION modesnmp-server view view-name oid-tree {inclu

Seite 958

Figure 3. Maintenance PointsMaintenance End PointsA maintenance end point (MEP) is a logical entity that marks the end point of a domain.There are two

Seite 959 - Upgrade Procedures

• Read the value of a single managed object.snmpget -v version -c community agent-ip {identifier.instance | descriptor.instance}• Read the value of th

Seite 960 - Virtual LANs (VLANs)

Configuring Contact and Location Information using SNMPYou may configure system contact and location information from the Dell Networking system or fr

Seite 961 - VLANs and Port Tagging

Subscribing to Managed Object Value Updates using SNMPBy default, the Dell Networking system displays some unsolicited SNMP messages (traps) upon cert

Seite 962

snmp coldstart SNMP_COLD_START: Agent Initialized - SNMP COLD_START. SNMP_WARM_START:Agent Initialized - SNMP WARM_START.s

Seite 963

envmon fan FAN_TRAY_BAD: Major alarm: fantray %d is missing or down FAN_TRAY_OK: Major alarm cleared: fan tray %d present FAN_BAD: Minor alarm: som

Seite 964

SNMP OID <oid> %RPM0-P:CP %SNMP-4-RMON_HC_RISING_THRESHOLD: STACKUNIT0 high-capacity rising threshold alarm from SNMP OID <oid>Copy C

Seite 965 - Moving Untagged Interfaces

MIB Object OID Object Values DescriptioncopySrcFileName is not required.copyDestFileType .1.3.6.1.4.1.6027.3.5.1.1.1.1.51 = Dell Networking OS file2 =

Seite 966 - Configuring Native VLANs

Copying a Configuration FileTo copy a configuration file, use the following commands.NOTE: In UNIX, enter the snmpset command for help using the follo

Seite 967

• Copy the running-config to the startup-config from the UNIX machine.snmpset -v 2c -c public force10system-ip-address copySrcFileType.index i 2 copyD

Seite 968 - VLT Proxy Gateway

Copying the Startup-Config Files to the Server via FTPTo copy the startup-config to the server via FTP from the UNIX machine, use the following comman

Seite 969

Implementation InformationBecause the S-Series has a single MAC address for all physical/LAG interfaces, only one MEP is allowed per MA (per VLAN or p

Seite 970

s filepath/filename copyDestFileType.index i 3 copyServerAddress.index a server-ip-address copyUserName.index s server-login-id copyUserPassword.index

Seite 971

Obtaining a Value for MIB ObjectsTo obtain a value for any of the MIB objects, use the following command.• Get a copy-config MIB object value.snmpset

Seite 972

Assigning a VLAN AliasWrite a character string to the dot1qVlanStaticName object to assign a name to a VLAN.Example of Assigning a VLAN Alias using SN

Seite 973

• Seven hex pairs represent a stack unit. Seven pairs accommodate the greatest number of ports available — 64 ports on the S4810 . On the S4810 , the

Seite 974

Example of Adding an Untagged Port to a VLAN using SNMPIn the following example, Port 0/2 is added as an untagged member of VLAN 10.>snmpset -v2c -

Seite 975

The following OIDs are configurable through the snmpset command.The node OID is 1.3.6.1.4.1.6027.3.18F10-ISIS-MIB::f10IsisSysOloadSetOverloadF10-ISIS-

Seite 976 - Enhanced VLT

Fetch Dynamic MAC Entries using SNMPDell Networking supports the RFC 1493 dot1d table for the default VLAN and the dot1q table for all other VLANs.NOT

Seite 977 - VLT Terminology

Example of Fetching MAC Addresses Learned on a Non-default VLAN Using SNMPIn the following example, GigabitEthernet 1/21 is moved to VLAN 1000, a non-

Seite 978

To display the interface number, use the following command.• Display the interface index number.EXEC Privilege modeshow interfaceExample of Deriving t

Seite 979 - Configuration Notes

Untagged 2)dot3aCommonAggFdbStatusSNMPv2-SMI::enterprises.6027.3.2.1.1.6.1.4.1107755009.1 = INTEGER: 1 << Status active, 2 – status inactiveExam

Seite 980

Creating a Maintenance DomainConnectivity fault management (CFM) divides a network into hierarchical maintenance domains, as shown in Maintenance Doma

Seite 981

• When you query an IPv4 icmpMsgStatsInPkts object in the ICMP table by using the snmpwalk command, the echo response output may not be displayed. To

Seite 982

51StackingStacking is supported on the S4810 platform.Stacking is supported on the S4810 platform with the Dell Networking Operating System (OS) versi

Seite 983 - VLT Bandwidth Monitoring

• LogsThe master switch maintains stack operation with minimal impact in the event of:• Switch failure• Inter-switch stacking link failure• Switch ins

Seite 984 - VLT Port Delayed Restoration

-----------------------------------------------------------------0 Member not present1 Management online S4810 S4810 4810-8-3-12-

Seite 985

Stack MAC : 00:01:e8:d5:ef:81-- Stack Info --Unit UnitType Status ReqTyp CurTyp Version Ports-------------------------------------------------

Seite 986 - VLT Routing

0 Standby online S4810S4810 7.8.1.0 521 Management online S4810S4810 7.8.1.0 522 Member online S4810S4810 7.8.1

Seite 987 - VLT Multicast Routing

High Availability on S-Series StacksS-Series stacks have master and standby management units analogous to Dell Networking route processor modules (RPM

Seite 988 - Configuring VLT Multicast

Management Access on S-Series StacksYou can access the stack via the console port or VTY line.• Console access — You may access the stack through the

Seite 989 - RSTP Configuration

– Stacking with 1G interfaces is not supported.• Stacking on the S4810 is accomplished through front-end user ports on the chassis.• All stack units m

Seite 990 - Configuring VLT

If the stack is running Dell Networking OS version 8.3.12.0 and the new unit is running an earlier software version, the new unit is put into a card p

Seite 991

Configuring BGP Route Reflectors...232Aggregating Routes...

Seite 992

These roles define the relationships between all devices so that each device can monitor the layers under its responsibility.Creating a Maintenance En

Seite 993 - Configuring a VLT Backup Link

3. Reload the switch.EXEC Privilege modereloadDell Networking OS automatically assigns a number to the new unit and adds it as member switch in the st

Seite 994

7. Reload the stack one unit at a time.EXEC Privilege modeshow system briefStart with the management unit, then the standby, then each of the members

Seite 995

Dell(conf)#Dell#02:39:18: %STKUNIT4-M:CP %SYS-5-CONFIG_I: Configured from consoleReload each unit in the stack. After the reload is complete, the four

Seite 996

Setting ports Te 0/0 Te 0/1 Te 0/2 Te 0/3 as stack group will make their interface configs obsolete aftera reload.[confirm yes/no]:yesS4810-1#show sys

Seite 997

4. Assign a stack group to each unit.CONFIGURATION modestack-unit id stack-group id5. Connect the new unit to the stack using stacking cables.Example

Seite 998

stack group configuration conflict occurs between the new unit and the provisioned stack unit, the configuration of the new unit takes precedence.1. A

Seite 999 - VLT Sample Configuration

• Dell Networking OS resets all the units in the losing stack; they all become stack members.• If there is no unit numbering conflict, the stack membe

Seite 1000 - Virtual Link Trunking (VLT)

Creating a Virtual Stack Unit on an S-Series StackUse virtual stack units to configure ports on the stack before adding a new unit.• Create a virtual

Seite 1001

Up Time : 57 min, 0 secDell Networking OS Version : 8-3-7-13Jumbo Capable : yesPOE Capable : noBurned In MAC : 00:01:e8:8a:df:e6No Of

Seite 1002

3 Management online S4810 S4810 8-3-12-13 644 Member not present5 Member not present6 Member not present7 Member

Seite 1003

Example of Viewing Configured MIPsDell#show ethernet cfm maintenance-points local mip-----------------------------------------------------------------

Seite 1004

redundancy force-failover stack-unitA new standby is elected. When the former stack master comes back online, it becomes a member unit.• Prevent the s

Seite 1005

Examples of Viewing the Status for Stacked SwitchesThe following example shows four switches stacked together with two 40G links in a ring topology.De

Seite 1006 - Verifying a VLT Configuration

1 0 up up 7200 up 72001 1 up up 7200 up 7440Speed in RPThe following example shows three switches stacked together

Seite 1007

1 Member online S4810 S4810 8-3-7-13 642 Member not present3 Standby online S4810 S4810 8-3-7-13 64The following examp

Seite 1008

Recover from Stack Link FlapsS-Series stack link integrity monitoring enables units to monitor their own stack ports and disable any stack port that f

Seite 1009

6 Member not present7 Member not present8 Member not present9 Member not present10 Member not present11 Member

Seite 1010

52Storm ControlStorm control is supported on the S4810 platform.The storm control feature allows you to control unknown-unicast and broadcast traffic

Seite 1011 - Access Switch)

53Spanning Tree Protocol (STP)The spanning tree protocol (STP) is supported on the S4810 platform.Protocol OverviewSTP is a Layer 2 protocol — specifi

Seite 1012 - Troubleshooting VLT

Important Points to Remember• STP is disabled by default.• The Dell Networking OS supports only one spanning tree instance (0). For multiple instances

Seite 1013

To configure and enable the interfaces for Layer 2, use the following command.1. If the interface has been assigned an IP address, remove it.INTERFACE

Seite 1014

The default is 100 minutes.The range is from 100 to 65535 minutes.Continuity Check MessagesContinuity check messages (CCM) are periodic hellos.Continu

Seite 1015

Figure 121. Spanning Tree Enabled GloballyTo enable STP globally, use the following commands.1. Enter PROTOCOL SPANNING TREE mode.CONFIGURATION modepr

Seite 1016

To view the spanning tree configuration and the interfaces that are participating in STP, use the show spanning-tree 0 command from EXEC privilege mod

Seite 1017

spanning-tree 0Modifying Global ParametersYou can modify the spanning tree parameters. The root bridge sets the values for forward-delay, hello-time,

Seite 1018

PROTOCOL SPANNING TREE modemax-age secondsThe range is from 6 to 40.The default is 20 seconds.To view the current values for global parameters, use th

Seite 1019

CAUTION: Enable PortFast only on links connecting to an end station. PortFast can cause loops if it is enabled on an interface connected to a network.

Seite 1020

• When you add a physical port to a port channel already in the Error Disable state, the new member port is also disabled in the hardware.• When you r

Seite 1021

• disables spanning tree on an interface• drops all BPDUs at the line card without generating a console messageExample of Blocked BPDUsDell(conf-if-gi

Seite 1022

Root Bridge hello time 2, max age 20, forward delay 15Dell#STP Root GuardSTP root guard is supported on the S4810 platform.Use the STP root guard fe

Seite 1023 - Working of IPv6 Peer Routing

Figure 123. STP Root Guard Prevents Bridging LoopsConfiguring Root GuardEnable STP root guard on a per-port or per-port-channel basis.Dell Networking

Seite 1024

• Enable root guard on a port or port-channel interface.INTERFACE mode or INTERFACE PORT-CHANNEL modespanning-tree {0 | mstp | rstp | pvst} rootguard–

Seite 1025

Enabling CCMTo enable CCM, use the following commands.1. Enable CCM.ECFM DOMAIN modeno ccm disableThe default is Disabled.2. Configure the transmit in

Seite 1026

STP Loop GuardSTP loop guard is supported only on the S4810 platform.The STP loop guard feature provides protection against Layer 2 forwarding loops (

Seite 1027

Figure 124. STP Loop Guard Prevents Forwarding LoopsConfiguring Loop GuardEnable STP loop guard on a per-port or per-port channel basis.Dell Networkin

Seite 1028

• You cannot enable root guard and loop guard at the same time on an STP port. For example, if you configure loop guard on a port on which root guard

Seite 1029 - VRF Overview

54System Time and DateSystem time and date settings and the network time protocol (NTP) are supported on the S4810 platform.You can set system times a

Seite 1030 - VRF Configuration Notes

Information included in the NTP message allows the client to determine the server time regarding local time and adjust the local clock accordingly. In

Seite 1031 - Table 74

Configure the Network Time ProtocolConfiguring NTP is a one-step process.• Enabling NTPRelated Configuration Tasks• Configuring NTP Broadcasts• Settin

Seite 1032

Example of Updating the System Clock Relative to NTPR5/R8(conf)#do show calendar06:31:02 UTC Mon Mar 13 1989R5/R8(conf)#ntp update-calendar 1R5/R8(con

Seite 1033 - VRF Configuration

– For a loopback interface, enter the keyword loopback then a number between 0 and 16383.– For a port channel interface, enter the keyword lag then a

Seite 1034 - View VRF Instance Information

4. Configure an NTP server.CONFIGURATION modentp server ip-address [key keyid] [prefer] [version number]Configure the IP address of a server and the f

Seite 1035 - Sample VRF Configuration

NOTE: • Leap Indicator (sys.leap, peer.leap, pkt.leap) — This is a two-bit code warning of an impending leap second to be inserted in the NTP time sca

Seite 1036

Sending Linktrace Messages and ResponsesLinktrace message and response (LTM, LTR), also called Layer 2 Traceroute, is an administratively sent multica

Seite 1037

Dell Networking OS Time and DateYou can set the time and date using the Dell Networking OS CLI.Configuration Task List The following is a configuratio

Seite 1038

– month: enter the name of one of the 12 months in English. You can enter the name of a day to change the order of the display to time day month year.

Seite 1039

– time-zone: enter the three-letter name for the time zone. This name displays in the show clock output.– start-month: enter the name of one of the 12

Seite 1040

– start-day: Enter the number of the day. The range is from 1 to 31. You can enter the name of a month to change the order of the display to time day

Seite 1041

55Tunneling Tunnel interfaces create a logical tunnel for IPv4 or IPv6 traffic. Tunneling supports RFC 2003, RFC 2473, and 4213.DSCP, hop-limits, flow

Seite 1042

ipv6 address 2::1/64tunnel destination 90.1.1.1tunnel source 60.1.1.1tunnel mode ipv6ip no shutdownThe following sample configuration shows a tunnel c

Seite 1043 - Route Leaking VRFs

Configuring a Tunnel InterfaceYou can configure the tunnel interface using the ip unnumbered and ipv6 unnumbered commands.To configure the tunnel inte

Seite 1044 - ip address 140.0.0.1/24

Configuring the tunnel source anylocalThe anylocal argument can be used in place of the ip address or interface, but only with multipoint receive-only

Seite 1045 - VRRP Overview

56Uplink Failure Detection (UFD)Uplink failure detection (UFD) is supported on the S4810 platform.Feature DescriptionUFD provides detection of the los

Seite 1046 - VRRP Implementation

Figure 126. Uplink Failure DetectionHow Uplink Failure Detection WorksUFD creates an association between upstream and downstream interfaces. The assoc

Seite 1047 - VRRP Configuration

• Set the amount of time a trace result is cached.ETHERNET CFM modetraceroute cache hold-time minutesThe default is 100 minutes.The range is from 10 t

Seite 1048

Figure 127. Uplink Failure Detection ExampleIf only one of the upstream interfaces in an uplink-state group goes down, a specified number of downstrea

Seite 1049 - Assign Virtual IP addresses

– An uplink-state group is considered to be operationally down if it has no upstream interfaces in the Link-Up state. No uplink-state tracking is perf

Seite 1050

Configuring Uplink Failure DetectionTo configure UFD, use the following commands.1. Create an uplink-state group and enable the tracking of upstream l

Seite 1051

4. (Optional) Enable auto-recovery so that UFD-disabled downstream ports in the uplink-state group come up when a disabled upstream port in the group

Seite 1052

Example of Syslog Messages Before and After Entering the clear ufd-disable uplink-state-group Command (S50)The following example message shows the Sys

Seite 1053 - Disabling Preempt

02:38:53: %RPM0-P:CP %IFMGR-5-OSTATE_UP: Changed interface state to up: Fo 13/3 02:38:53: %RPM0-P:CP %IFMGR-5-OSTATE_UP: Changed interface state to

Seite 1054 - Track an Interface or Object

Dell#show uplink-state-group detail(Up): Interface up (Dwn): Interface down (Dis): Interface disabledUplink State Group : 1 Status: Enabled, UpU

Seite 1055 - Tracking an Interface

The following example shows viewing the UFD configuration for the S50.Dell#show running-config uplink-state-group!no enableuplink state track 1downstr

Seite 1056

Dell(conf-uplink-state-group-3)#Dell(conf-uplink-state-group-3)#exitDell(conf)#exitDell#00:13:06: %STKUNIT0-M:CP %SYS-5-CONFIG_I: Configured from cons

Seite 1057

57Upgrade ProceduresTo find the upgrade procedures, go to the Dell Networking OS Release Notes for your system type to see all the requirements needed

Seite 1058 - Sample Configurations

Priority Defects Trap MessageMAC Status defect%ECFM-5-ECFM_MAC_STATUS_ALARM: MAC Status Defect detected by MEP 1 in Domain provider at Level 4 VLAN 30

Seite 1059

58Virtual LANs (VLANs)Virtual LANs (VLANs) are supported on the S4810 platform.VLANs are a logical broadcast domain or logical grouping of interfaces

Seite 1060

By default, VLAN 1 is the Default VLAN. To change that designation, use the default vlan-id command in CONFIGURATION mode. You cannot delete the Defau

Seite 1061

information is preserved as the frame moves through the network. The following example shows the structure of a frame with a tag header. The VLAN ID i

Seite 1062

• Configure a port-based VLAN (if the VLAN-ID is different from the Default VLAN ID) and enter INTERFACE VLAN mode.CONFIGURATION modeinterface vlan vl

Seite 1063 - VRRP in a VRF Configuration

The following example shows the steps to add a tagged interface (in this case, port channel 1) to VLAN 4. To view the interface’s status. Interface (p

Seite 1064

Moving Untagged InterfacesTo move untagged interfaces from the Default VLAN to another VLAN, use the following commands.1. Access INTERFACE VLAN mode

Seite 1065 - VLAN Scenario

T Gi 3/1 4 Active U Gi 3/2Dell#The only way to remove an interface from the Default VLAN is to place the interface in Default

Seite 1066

To configure a port so that it can be a member of an untagged and tagged VLANs, use the following commands.1. Remove any Layer 2 or Layer 3 configurat

Seite 1067

59VLT Proxy GatewayYou can configure a proxy gateway in VLT domains. A proxy gateway enables you to locally route the packets that are destined to a L

Seite 1068 - Offline Diagnostics

When the routing table across DCs is not symmetrical, there is a possibility of a routing miss by a DC that do not have the route for the L3 traffic.

Seite 1069 - Running Offline Diagnostics

Displaying Ethernet CFM StatisticsTo display Ethernet CFM statistics, use the following commands.• Display MEP CCM statistics.EXEC Privilege modeshow

Seite 1070

8. LLDP port channel interface can’t be changed to legacy lag when proxy gateway is enabled.9.“vlt-peer-mac transmit” is recommended only for square V

Seite 1071

• There are only a couple of MACs for each unit to be transmitted so that all current active MACs can definitely be carried on the newly defined TLV.•

Seite 1072 - Last Restart Reason (S4810 )

2. Trace route across VLT domains may show extra hops.3. IP route symmetry must be maintained across the VLT domains. Assume if the route to a destina

Seite 1073 - Hardware Watchdog Timer

8. Packet duplication – Assume exclude-vlan (say VLAN 10) is configured on C2/D2 for C1’s MAC. If packets for VLAN 10 with C1’s MAC get a hit at C2, t

Seite 1074

3. You can configure the remote MAC address of a VLT peer for a static proxy gateway and exclude a VLAN or a range of VLANs from proxy routing. This p

Seite 1075

60Virtual Link Trunking (VLT)Virtual link trunking (VLT) is supported on the S4810 platform.OverviewVLT allows physical links between two chassis to a

Seite 1076 - Table 77. SNMP Traps and OIDs

Figure 129. VLT on S4810 SwitchesVLT on Core SwitchesYou can also deploy VLT on core switches.Uplinks from servers to the access layer and from access

Seite 1077 - Buffer Tuning

Figure 130. Enhanced VLTVLT TerminologyThe following are key VLT terms.• Virtual link trunk (VLT) — The combined port channel between an attached devi

Seite 1078 - Deciding to Tune Buffers

Configure Virtual Link TrunkingVLT requires that you enable the feature and then configure the same VLT domain, backup link, and VLT interconnect on b

Seite 1079

• VLT Heartbeat is supported only on default VRFs.• In a scenario where one hundred hosts are connected to a Peer1 on a non-VLT domain and traffic flo

Seite 1080

6802.1X802.1X is supported on the S4810 platform.802.1X is a method of port security. A device connected to a port that is enabled with 802.1X is disa

Seite 1081

– The port channel must be in Default mode (not Switchport mode) to have VLTi recognize it.– The system automatically includes the required VLANs in V

Seite 1082 - Troubleshooting Packet Loss

– The chassis backup link does not carry control plane information or data traffic. Its use is restricted to health checks only.• Virtual link trunks

Seite 1083 - Displaying Drop Counters

• Software features supported on VLT physical ports– In a VLT domain, the following software features are supported on VLT physical ports: 802.1p, LLD

Seite 1084 - Dataplane Statistics

MAC address is selected as the Primary Peer. You can configure another peer as the Primary Peer using the VLT domain domain-id role priority priority-

Seite 1085 - Display Stack Member Counters

VLT and StackingYou cannot enable stacking on S4810 units with VLT.If you enable stacking on a unit on which you want to enable VLT, you must first re

Seite 1086 - Mini Core Dumps

PIM-Sparse Mode Support on VLTThe designated router functionality of the PIM Sparse-Mode multicast protocol is supported on VLT peer switches for mult

Seite 1087 - Enabling TCP Dumps

(DR) if they are incorrectly hashed. In addition to being first-hop or last -hop routers, the peer node can also act as an intermediate router.On a VL

Seite 1088 - Standards Compliance

local DA entries in TCAM. In case a VLT node is down, a timer that allows you to configure the amount of time needed for peer recovery provides resili

Seite 1089 - RFC and I-D Compliance

• VLT resiliency — After a VLT link or peer failure, if the traffic hashes to the VLT peer, the traffic continues to be routed using multicast until t

Seite 1090 - General IPv4 Protocols

Non-VLT ARP SyncSynchronization for non-ARP routing table entries is supported on the S4810 platform.ARP entries (including ND entries) learned on oth

Seite 1091 - Border Gateway Protocol (BGP)

Figure 7. EAP Frames Encapsulated in Ethernet and RADUISThe authentication process involves three devices:• The device attempting to access the networ

Seite 1092

Sample RSTP ConfigurationThe following is a sample of an RSTP configuration.Using the example shown in the Overview section as a sample VLT topology,

Seite 1093

Configuring a VLT InterconnectTo configure a VLT interconnect, follow these steps.1. Configure the port channel for the VLT interconnect on a VLT swit

Seite 1094 - Network Management

Enabling VLT and Creating a VLT DomainTo enable VLT and create a VLT domain, use the following steps.1. Enable VLT on a switch, then configure a VLT d

Seite 1095

Configuring a VLT Backup LinkTo configure a VLT backup link, use the following command.1. Specify the management interface to be used for the backup l

Seite 1096

Reconfiguring the Default VLT Settings (Optional) To reconfigure the default VLT settings, use the following commands.1. Enter VLT-domain configuratio

Seite 1097

Connecting a VLT Domain to an Attached Access Device (Switch or Server)To connect a VLT domain to an attached access device, use the following command

Seite 1098

Configuring a VLT VLAN Peer-Down (Optional)To configure a VLT VLAN peer-down, use the following commands.1. Enter VLT-domain configuration mode for a

Seite 1099

3. Enter VLT-domain configuration mode for a specified VLT domain.CONFIGURATION modevlt domain domain-idThe range of domain IDs is from 1 to 1000.4. E

Seite 1100

8. Configure enhanced VLT. Configure the port channel to be used for the VLT interconnect on a VLT switch and enter interface configuration mode.CONFI

Seite 1101 - MIB Location

VLT Sample ConfigurationTo review a sample VLT configuration setup, study these steps.1. Configure the VLT domain with the same ID in VLT peer 1 and V

Kommentare zu diesen Handbüchern

Keine Kommentare