Introduction to catalyst vmps: This article introduces VMPS Technology in three modes: VLAN unspecified on the port and VLAN already specified on the port. How can I configure dynamic VLANs and VMPS for CATALYST 4500 series switches? This article takes cisco ios 12.2 (31) SGA as an example.
VMPS introduction:
The introduction of vlan of a Huawei switch and three VMPS modes. In the explanation of vlan of a Huawei switch, there are three VMPS modes (but User Registration Tool, namely URT, only supports open mode ). How to configure dynamic vlan and VMPS of a CATALYST 4500 series switch? This article takes cisco ios 12.2 (31) SGA as an example.
1. Introduction to
vlan_numConsole> (enable) show port [mod_num/port_num]6. Configure VLAN Trunks on Fast Ethernet and Gigabit Ethernet Ports:VLAN Trunk is used for interconnection between switches. You can set the Trunk on the Fast Ethernet and Gigabit Ethernet ports or on the Fast or Gigabit EtherChannel bundle, and use DTPDynamic Trunking Protocol as the Port of the tr unk) the protocol can also be used) for negotiation.VLAN Trunk has five modes and two kinds of encapsulation:Five modes: on, off, desirable, au
addresses in the LAN. FreeNAC can automatically discover various terminals in the network, provide support for 802.1x and Cisco VMPS port security modules, and also provide system patch package distribution and other functions. However, although FreeNAC provides support for non-Network-managed switches, the use of non-Network-managed switches will greatly compromise its NAC function. Therefore, if you want to use all of its NAC functions, it is best
small range of distribution layers.Configure the minority VLAN on a single access switch within a single distribution frame, instead of configuring VLAN for multiple departments on a single switch.
Two VLAN member modes are available:
· Static VLAN is also called Port-based VLAN ):-- Manually configure the switch port and assign it to a specific VLAN. The device that receives this port belongs to this VLAN.Sw1 # showcdpneighborsdetail
· Dynamic VLAN:You must first deploy a
TrafficVLANHow to operate: ·Each of the configuration on the switchVLANcan perform address learning, forwarding/filter and eliminate the loop mechanism, just like a separate physical bridge. VLANmay include several ports ·The switch forwards the data to the same port as the originatingVLANThe destination port implementationVLAN. ·usually a port only carries the one it belongs toVLANtraffic. VLANthe member mode:Static: The port assigned to the VLAN is configured statically (manually) by t
unchanged. It is just a simple ing, which depends on the database created by the network administrator. After the port allocated to dynamic v l a n is activated, the switch caches the source m a c Address of the initial frame. Then, the switch sends A request to an external server called vmps v l a n management policy server. The v m p s contains A text file, the file contains the m a c Address mapped to v l a n.
The switch downloads the file and ver
the switch port.
Dynamic VLAN: by setting the VMPSVLAN Membership Policy Server), it contains a ing table between MAC addresses and VLAN numbers. When the data frame arrives at the switch, the vswitch queries VMPS to obtain the vlan id of the corresponding MAC address.
2) ISL label: ISLInter-Switch Link) is a protocol for transmitting VLAN information and VLAN data streams between switches, between switches and routers, and between switches and serve
. Let's look at the dynamic VLAN. Dynamic VLAN formation is very simple. When the port determines which VLAN it belongs to, a dynamic VLAN is formed. However, this does not mean that the layer remains unchanged. It is just a simple ing, which depends on the database created by the network administrator.
After the port assigned to the dynamic VLAN is activated, the switch caches the source MAC address of the initial frame. Then, the switch sends a request to an external server called the VMPSVLAN
) # distribute-list access-list-number | name in [type number]
93. for out-of-band route updates, the most basic command format for configuring route updates is:R1 (config-router) # distribute-list access-list-number | name out [interface-name] routing-process | autonomous-system-number
94. set snmp Command Options:Set snmp community {read-only | ready-write | read-write-all} [community_string]
95. set snmp trap Command Format:Set snmp trap {enable | disable}[All | moudle | classis | bridge | re
update
For in-band route updates, the most basic command format for configuring route updates is:
R1 (config-router) # distribute-list access-list-number | name in [type number]
For out-of-band route updates, the most basic command format for configuring route updates is:
R1 (config-router) # distribute-list access-list-number | name out [interface-name] routing-process | autonomous-system-number
Router configuration-SNMP
Set snmp Command Options:
Set snmp community {read-only | ready-write | r
snooping binding table.
Ip arp inspection validate src-mac dst-mac ip detection valid client must meet the src-mac dst-mac ip no error
Ip arp inspection log-buffer entries 1024 inspection log Size
Ip arp inspection log-buffer logs 1024 interval 300 inspection log refresh time, interval is too small will occupy a lot of cpu time
!
!
!
Errdisable recovery cause udld
Errdisable recovery cause bpduguard
Errdisable recovery cause security-violation
Errdisable recovery cause channel-misconfig
Errdisa
at the switch, the vswitch queries VMPS to obtain the vlan id of the corresponding MAC address.2) ISL label: ISLInter-Switch Link) is a protocol for transmitting VLAN information and VLAN data streams between switches, between switches and routers, and between switches and servers, by configuring ISL encapsulation on the port directly connected to the vswitch, you can allocate and configure VLANs across the entire network.The international standard f
showvlanvlan number command to view a VLAN, such as showvlan2 and showvlan3. you can also use showvlan-membership, the change command mainly displays the static or dynamic VLAN of each port on the switch.
The above is the process of configuring a static VLAN for the switch. Let's look at the dynamic VLAN. Dynamic VLAN formation is very simple. When the port determines which VLAN it belongs to, a dynamic VLAN is formed. However, this does not mean that the layer remains unchanged. It is just a s
access-list-number | name out [interface-name] routing-process | autonomous-system-number
Set snmp Command Options: Set snmp community {read-only | ready-write | read-write-all} [community_string]
The format of the set snmp trap Command is as follows: Set snmp trap {enable | disable}[All | moudle | classis | bridge | repeater | auth | vtp | ippermit | vmps | config | entity | stpx]Set snmp trap rvcr_addr rcvr_community
Enable the SNMP chassis trap:Co
-violation enable timer to recover from your cure violation disable stateSecurity-violation enable timer to recover from 802.1x violation disable stateUdld enable timer to recover from udld error disable stateUnicast-flood enable timer to recover from unicast flood disable stateVmps enable timer to recover from vmps shutdown error disableAfter the preceding command is configured, IOS tries to restore the interface that is set to err-Disable after a pe
An instance of VLAN configuration for Cisco L3 switches and L2 SwitchesCisco VLAN implementation is usually port-centric. The port connected to the node determines the VLAN in which it resides. There are two ways to allocate a port to a VLAN: Static and Dynamic. The process of creating a static VLAN is to forcibly allocate the port to a VLAN. That is, we first create a VLAN on The VTP (VLAN Trunking Protocol) server, and then assign each port to the corresponding VLAN. This is the most common me
psecure-violation
errdisable recovery Cause Gbic-invalid
errdisable recovery Cause Dhcp-rate-limit
errdisable recovery Cause Unicast-flood
errdisable recovery Cause Vmps
errdisable recovery Cause arp-inspection
errdisable recovery interval 30
Spanning-tree Extend System-id
!
!
Interface GIGABITETHERNET2/1//restricted to the user of the port access, the switch can be
ip arp inspection limit rate 100
ARP Timeout 2
IP DHCP snooping limit ra
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.