Credits
Copyright notice:
Asia Pacific Headquarters
Americas Headquarters Cisco Systems (USA) Pte.
Cisco Systems, Inc.
Ltd.
San Jose, CA
Singapore
Europe Headquarters
Cisco Systems International BV
Amsterdam,
The Netherlands
Cisco has more than 200 offices worldwide. Addresses, phone numbers, and fax numbers are
listed on the Cisco website athttp://www.cisco.com/go/offices.
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates
in the U.S. and other countries. To view a list of Cisco trademarks, go to this
URL:http://www.cisco.com/c/en/us/about/legal/trademarks.html. Third-party trademarks that
are mentioned are the property of their respective owners. The use of the word partner does not
imply a partnership relationship between Cisco and any other company. (1110R)
DISCLAIMER WARRANTY: THIS CONTENT IS BEING PROVIDED “AS IS” AND AS
SUCH MAY INCLUDE TYPOGRAPHICAL, GRAPHICS, OR FORMATTING ERRORS.
CISCO MAKES AND YOU RECEIVE NO WARRANTIES IN CONNECTION WITH THE
CONTENT PROVIDED HEREUNDER, EXPRESS, IMPLIED, STATUTORY OR IN ANY
OTHER PROVISION OF THIS CONTENT OR COMMUNICATION BETWEEN CISCO
AND YOU. CISCO SPECIFICALLY DISCLAIMS ALL IMPLIED WARRANTIES,
INCLUDING WARRANTIES OF MERCHANTABILITY, NON-INFRINGEMENT AND
FITNESS FOR A PARTICULAR PURPOSE, OR ARISING FROM A COURSE OF
DEALING, USAGE OR TRADE PRACTICE. This learning product may contain early release
content, and while Cisco believes it to be accurate, it falls subject to the disclaimer above.
Copyright Date:
© 2020 Cisco Systems, Inc.
Course Welcome
Thank you for choosing Cisco as your technical learning provider. We recognize that
you have many options to choose from when working toward achieving your technical
and professional goals. Our objective is to help you meet those goals by providing highquality, collaborative learning experiences.
Before you begin, take a moment to review the primary components in this course, how
to access online support, and opportunities to provide feedback on the course.
Course outline: If you are attending a live, instructor-led training session, your
instructor may customize the course to meet the specific needs of the class. However,
you will find a basic outline of the material in the Course Introduction section.
Course content: You will find detailed information and instructions along with
supporting illustrations, self-check challenges to give you exam practice, and lab
activities to give you a real-world experience.
Glossary of terms: If you need to review or learn unfamiliar terms used in this course,
refer to the Glossary of Terms section.
Online support: Join the Cisco Learning Network community to participate in study
group discussions and get answers to questions as you prepare for your exam.
Your feedback: We encourage you to submit feedback so that we can continue to
improve course quality and offer the best learning products possible. Your input is
valuable to us, and we want to know how the course has helped with your job and exam
performance. There are two ways to submit feedback:
1. Course evaluation survey: If you attend a live, instructor-led training session, then
your instructor will provide a survey on the last day of class. After completing the
survey, you’ll receive a course completion certificate. Once you’ve had a chance to
practice what you’ve learned, you’ll receive a follow-up survey approximately two
months after completing the course.
2. Digital kit feedback: Use the Feedback button in the digital version of the course
materials to submit your comments.
We make regular updates to our content in response to your feedback, so please share
it with us.
Special thanks to our Cisco Authorized Learning Partners in making these materials
available.
Thank you again for choosing Cisco.
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
Lab Listing
Discovery Labs
Discovery 1: Get Started with Cisco CLI
Discovery 2: Observe How a Switch Operates
Discovery 3: Perform Basic Switch Configuration
Discovery 4: Inspect TCP/IP Applications
Discovery 5: Configure an Interface on a Cisco Router
Discovery 6: Configure and Verify Layer 2 Discovery Protocols
Discovery 7: Configure Default Gateway
Discovery 8: Explore Packet Forwarding
Discovery 9: Troubleshoot Switch Media and Port Issues
Discovery 10: Troubleshoot Port Duplex Issues
Discovery 11: Configure Basic IPv6 Connectivity
Discovery 12: Configure and Verify IPv4 Static Routes
Discovery 13: Configure IPv6 Static Routes
Discovery 14: Configure VLAN and Trunk
Discovery 15: Configure a Router on a Stick
Discovery 16: Configure and Verify Single-Area OSPF
Discovery 17: Configure and Verify EtherChannel
Discovery 18: Configure and Verify IPv4 ACLs
Discovery 19: Configure a Provider-Assigned IPv4 Address
Discovery 20: Configure Static NAT
Discovery 21: Configure Dynamic NAT and PAT
Discovery 22: Log into the WLC
Discovery 23: Monitor the WLC
Discovery 24: Configure a Dynamic (VLAN) Interface
Discovery 25: Configure a DHCP Scope
Discovery 26: Configure a WLAN
Discovery 27: Define a RADIUS Server
Discovery 28: Explore Management Options
Discovery 29: Explore the Cisco DNA Center
Discovery 30: Configure and Verify NTP
Discovery 31: Create the Cisco IOS Image Backup
Discovery 32: Upgrade Cisco IOS Image
Discovery 33: Configure WLAN Using WPA2 PSK Using the GUI
Discovery 34: Secure Console and Remote Access
Discovery 35: Enable and Limit Remote Access Connectivity
Discovery 36: Configure and Verify Port Security
Discovery 1: Get Started with Cisco CLI
Discovery 2: Observe How a Switch Operates
Discovery 3: Perform Basic Switch Configuration
Discovery 4: Inspect TCP/IP Applications
Discovery 5: Configure an Interface on a Cisco Router
Discovery 6: Configure and Verify Layer 2 Discovery Protocols
Discovery 7: Configure Default Gateway
Discovery 8: Explore Packet Forwarding
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
Discovery 9: Troubleshoot Switch Media and Port Issues
Discovery 10: Troubleshoot Port Duplex Issues
Discovery 11: Configure Basic IPv6 Connectivity
Discovery 12: Configure and Verify IPv4 Static Routes
Discovery 13: Configure IPv6 Static Routes
Discovery 14: Configure VLAN and Trunk
Discovery 15: Configure a Router on a Stick
Discovery 16: Configure and Verify Single-Area OSPF
Discovery 17: Configure and Verify EtherChannel
Discovery 18: Configure and Verify IPv4 ACLs
Discovery 19: Configure a Provider-Assigned IPv4 Address
Discovery 20: Configure Static NAT
Discovery 21: Configure Dynamic NAT and PAT
Discovery 22: Log into the WLC
Discovery 23: Monitor the WLC
Discovery 24: Configure a Dynamic (VLAN) Interface
Discovery 25: Configure a DHCP Scope
Discovery 26: Configure a WLAN
Discovery 27: Define a RADIUS Server
Discovery 28: Explore Management Options
Discovery 29: Explore the Cisco DNA Center
Discovery 30: Configure and Verify NTP
Discovery 31: Create the Cisco IOS Image Backup
Discovery 32: Upgrade Cisco IOS Image
Discovery 33: Configure WLAN Using WPA2 PSK Using the GUI
Discovery 34: Secure Console and Remote Access
Discovery 35: Enable and Limit Remote Access Connectivity
Discovery 36: Configure and Verify Port Security
Graded Labs
FASTLab 1: Implement the Initial Switch Configuration
FASTLab 2: Implement an Initial Router Configuration
FASTLab 3: Implement IPv4 Static Routing
FASTLab 4: Implement IPv6 Static Routing
FASTLab 5: Troubleshoot VLANs and Trunk
FASTLab 6: Implement Multiple VLANs and Basic Routing Between the VLANs
FASTLab 7: Improve Redundant Switched Topologies with EtherChannel
FASTLab 8: Implement Numbered and Named IPv4 ACLs
FASTLab 9: Implement PAT
FASTLab 10: Configure System Message Logging
FASTLab 11: Secure Device Administrative Access
FASTLab 12: Implement Device Hardening
Course Introduction
Overview
Implementing and Administering Cisco Solutions (CCNA) v 1.0 is a course that teaches
learners how to install, operate, configure, and verify a basic IPv4 and IPv6 network,
including configuring network components, such as switch, router, and Wireless LAN
Controller; managing network devices, and identifying basic security threats.
Skills and Knowledge
This subtopic lists the knowledge and skills that you should have before beginning this
course. It also includes recommended Cisco learning offerings that may help you meet
these prerequisites.
Knowledge and skills you should have before attending this course:
•
•
•
•
Basic computer literacy
Basic PC operating system navigation skills
Basic Internet usage skills
Basic IP address knowledge
Course Goal
This topic describes the course goal.
The goal of this course is to provide learners with the knowledge and skills that are
necessary to install, configure, and operate a small to medium-sized network.
Course Flow
The schedule reflects the recommended structure for this course. This structure allows
enough time for the instructor to present the course information and for you to work
through the lab activities. The exact timing of the subject materials and labs depends on
the pace of your specific class.
Day 1
•
•
•
•
•
Exploring the Functions of Networking
Introducing the Host-To-Host Communications Model
Operating Cisco IOS Software
Introducing LANs
Exploring the TCP/IP Link Layer
Day 2
•
•
•
•
•
Starting a Switch
Introducing the TCP/IP Internet Layer, IPv4 Addressing, and Subnets
Explaining the TCP/IP Transport Layer and Application Layer
Exploring the Functions of Routing
Configuring a Cisco Router
Day 3
•
•
•
•
•
Exploring the Packet Delivery Process
Troubleshooting a Simple Network
Introducing Basic IPv6
Configuring Static Routing
Implementing VLANs and Trunks
Day 4
•
•
•
•
•
Routing Between VLANs
Introducing OSPF
Improving Redundant Switched Topologies with EtherChannel
Explaining Basics of ACL
Enabling Internet Connectivity
Day 5
•
•
•
•
•
Explaining the Evolution of Intelligent Networks
Introducing System Monitoring
Managing Cisco Devices
Securing Administrative Access
Implementing Device Hardening
Day 6-8 Self-Study
•
•
•
Building Redundant Switched Topologies
Exploring Layer 3 Redundancy
Introducing WAN Technologies
•
•
•
•
•
Introducing QoS
Explaining Wireless Fundamentals
Introducing Architectures and Virtualization
Examining the Security Threat Landscape
Implementing Threat Defense Technologies
Cisco Training and Certifications
Cisco training and certification programs prepare students, network engineers, and
software developers for today’s most critical jobs. The industry needs talented
professionals with validated skill sets to power success in this changing technology
landscape. The latest programmable network infrastructure lets software developers
create new applications and experiences; IT professionals can implement automation
and DevOps workflows with intent-based networks. We’re ensuring that all learners can
access forefront training and certifications to meet the demands of the enterprise.
To learn more about how Cisco programs can help you remain marketable, job ready,
and poised for your next career goal, visithttp://www.cisco.com/c/en/us/trainingevents/training-certifications/overview.html.
Training Resources
You are encouraged to join the Cisco Learning Network—a dynamic learning
community for certified Cisco professionals, and those seeking certification, where you
can share questions, suggestions, and information about the Cisco training and
certifications program and other certification-related topics. To register,
visit https://learningnetwork.cisco.com.
The Cisco Learning Network also offers various resources for learning and interaction
with members of the Cisco certification community, including:
•
•
•
•
Certification communities: https://learningnetwork.cisco.com/s/communities
IT training videos and seminars: https://learningnetwork.cisco.com/s/all-media
Cisco Certifications: https://learningnetwork.cisco.com/s/certifications
Webinars and events: https://learningnetwork.cisco.com/s/event-list
Cisco Training Services and Cisco DevNet offer hands-on training, instructor-led, and
self-study:
•
•
Cisco Training Services product and solution
training: https://www.cisco.com/c/en/us/training-events/trainingcertifications/training/training-services/courses.html
Cisco DevNet programmability self-study and practice: https://developer.cisco.com/
Student Introductions
•
•
•
•
•
•
Your name
Your company
Job responsibilities
Skills and knowledge
Brief history
Objective
Exploring the Functions of Networking
Introduction
At the most basic level, a “network” is defined as a group of systems interconnected to
share resources. You can find examples of such systems and resources in a social
network to share work experience or personal events or a computer network to share
file storage, printer access, or internet connectivity.
A network connects computers, mobile phones, peripherals, and even IoT (Internet of
Things) devices. Switches, routers, and wireless access points (APs) are the essential
networking basics. Through them, devices connected to your network can communicate
with one another and with other networks, such as the Internet, which is a global system
of interconnected computer networks.
Networks carry data in many types of environments, including homes, small businesses,
and large enterprises. Large enterprise networks may have several locations that need
to communicate with each other. You can use a network in your home office to
communicate via the Internet to locate information, place orders for merchandise, and
send messages to friends. You can also have a small office that is set up with a network
that connects other computers and printers in the office. Similarly, you can work in a
large enterprise with many computers, printers, storage devices, and servers running
applications that are used to communicate, store, and process information from many
departments over large geographic areas.
A network of computers and other components that are located relatively close together
in a limited area is often referred to as a Local Area Network (LAN). Every LAN has
specific components, including hardware, interconnections, and software. Wide Area
Network (WAN) communication occurs between geographically separated areas and it’s
typically provided by different telecommunication providers using various technologies
using different media such as fiber, copper, cable, Asymmetric Digital Subscriber Line
(ADSL), or wireless links. In enterprise internetworks, WANs connect the main office,
branches, Small Office Home Office (SOHO), and mobile users.
As someone who is exploring the functions of networking, there are some important
skills that you will build upon:
•
•
•
Explain the functions, characteristics, and common components of a network.
Read a network diagram, including comparing and contrasting the logical and physical
topologies.
Describe the impact of user applications on the network.
What Is a Computer Network?
The term network is used in many different arenas. Examples of networks are social
networks, phone networks, television networks, neural networks, and, of course,
computer networks. A network is a system of connected elements that operate together.
A computer network connects personal computers (PCs), printers, servers, phones,
cameras, and other types of devices. A computer network connects devices in a way
allowing them to exchange data among each other, which facilitates information and
resource sharing. At home, computers allow family members to share files (such as
photos) and print documents on a network printer, televisions can play movies or other
media stored on your computers, and internet-enabled devices can connect to
webpages, applications and services anywhere in the world.
In the business environment you have a lot of business operations – marketing, sales,
and IT. You need to develop apps that allow information to be collected and processed.
Computer systems that collect and process the information need to communicate with
each other in order to share resources. You also need an infrastructure that supports
employees, who need to access these resources and interact with each other. A
network allows multiple devices such as laptops, mobile devices, servers, and shared
storage to exchange information with each other. There are various components,
connected to each other that are necessary for this communication to take place. This
infrastructure allows a business to run, lets customers to connect to the business (either
through salespeople or through an online store) and allows a business to sell its
products or services. To run normally, at the end of the day, a business and its
applications relies on networking technology.
A computer network can exist on its own, independent of other computer networks. It
can also connect to other networks. The internet is an example of many networks
interconnected together. It is global in its span and scope. To operate successfully,
interconnected networks follow standardized rules to communicate. These rules are
accepted and adhered to by each participating network.
The early internet connected only several mainframe computers with computer
terminals. The mainframe computers were large and their computing power was
considered enormous (albeit being the equivalent to today’s mobile phone). Terminals
were simple and inexpensive devices, which were used only to input data and display
the results. Teletype is an example of such a device. The range of devices that
connects to internet has expanded in last decades. The internet now connects not only
laptops, smartphones, and tablets but also game consoles, television sets, home
systems, medical monitors, home appliances, thunder detectors, environment sensors,
and many more things. The earlier concept of centralized computing resources is
revived today in the form of computing clouds.
"Mainframe Computer” by Pargon is licensed under CC BY 2.0
Computer network engineers are people who design, develop, and maintain highly
available network infrastructure to support the information technology activities of the
business. Network engineers interact with users of the network and provide support or
consultancy services about design and/or network optimization. Network engineers
typically have more knowledge and experience than network technicians, operators,
and administrators. A network engineer should update their knowledge of networking
constantly to keep up with new trends and practices.
Users who wish to connect their networks to the internet acquire access through a
service provider's access network. Service providers’ networks can use different
technologies from dial-up or broad-band telephony networks, such as ADSL network,
cable networks, mobile, radio, or fiber optic networks. A service provider network can
cover large geographical areas. Service provider networks also maintain connections
between themselves and other service providers to enable global coverage.
Computer networks can be classified in several ways, which can be combined to find
the most appropriate one for the implementation. Local and remote networks are
distinguished by the distance between the user and the computer networks the user is
accessing. Examples of networks categorized by their purpose would be data center
network and storage area network (SAN). Focusing on the technology used, you can
distinguish wireless or wired networks. Looking at the size of the network in terms of the
number of devices it has, there are small networks, usually with less than 10 devices,
medium to large networks consisting of tens to hundreds of devices, and very large,
global networks, such as the internet, which connects thousands of devices across the
world.
One of the most common categorizations looks at the geographical scope of the
network. Within it, there are local-area networks (LANs) that connect devices located
relatively close together in a limited area. Contrasting LANs, there are wide-area
networks (WANs), which cover broad geographic area and are managed by service
providers. An example of a LAN network is a university campus network that can span
several collocated buildings. An example of a WAN would be a telecommunication
provider’s network that interconnects multiple cities and states. This categorization also
includes metropolitan-area networks (MANs), which span a physical area larger than
LAN but smaller than WAN, for instance a city.
Medium-to-large enterprise networks can span multiple locations. Usually they have
a main office or Enterprise Campus, which holds most of the corporate resources,
and remote sites, such as branch offices or home offices of remote workers. A home
office usually has a small number of devices and is called Small Office/Home
Office (SOHO). SOHO networks mostly use the internet to connect to the main office. A
main office network, which is a LAN in terms of its geographical span, may consist of
several networks that occupy many floors or it may cover a campus that contains
several buildings. Many corporate environments require deployment of wireless
networks on a large scale and they use Wireless LAN Controllers (WLC) for centralizing
management of wireless deployments. Enterprise Campuses also typically include a
separate Data Center which is home to the computational power, storage, and
applications necessary to support an enterprise business. Enterprises are also
connected to the internet and internet connectivity is protected by a firewall. Branch
offices have their own LANs with their own resources, such as printers and servers, and
may store corporate information, but their operations largely depend on the main office,
hence the network connection with it. They connect to the main office by a WAN or
internet using routers as gateways.
Cisco Enterprise Architecture Model
Networks support the activities of many businesses and organizations and are required
to be secure, resilient and to allow growth. The design of a network requires
considerable technical knowledge. Network engineers commonly use validated network
architecture models to assist in the design and the implementation of the network.
Examples of validated models are Cisco three-tier hierarchical network architecture
model, spine-leaf model, and Cisco Enterprise Architecture model. These models
provide hierarchical structure to Enterprise networks, which is used to design the
network architecture in a form of layers (for example LAN Access, LAN Core), with each
layer providing different functionalities.
The words internet and web are very often used interchangeably, but they do not share
the same meaning. The internet is a global network that interconnects many networks
and therefore provides a world-wide communication infrastructure. The World Wide
Web describes one way to provide and access information over the internet using a web
browser. It is a service that relies on connections provided by the internet for its
function.
All the exchange of data within the internet follows the same well-defined rules, called
protocols, which are designed specifically for internet communication. These protocols
specify, among other things, the usage of hyperlinks and Uniform Resource Identifiers
(URIs). The internet is a base for many other data exchange services, such as e-mail or
file transfer. It is a common global infrastructure, composed of many computer networks
connected together that follow communication rules standardized for the internet. The
protocols and processes of the internet are defined by a set of documents called
Request for Comments (RFCs).
Components of a Network
A network can be as simple as two PCs that are connected by a wire or as complex as
several thousand devices that are connected through different types of media. The
elements that form a network can be roughly divided into 3
categories: devices, media, andservices. Devices are interconnected by media. Media
provides the channel over which the data travels from source to destination. Services
are software and processes that support common networking applications in use today.
Network Devices
Devices can be further divided into endpoints and intermediary devices:
•
•
Endpoints: End devices, which are most common to people, fall into the category of
endpoints. In the context of a network, end devices are called end-user devices, and
include PCs, laptops, tablets, mobile phones, game consoles, and television sets.
Endpoints are also file servers, printers, sensors, cameras, manufacturing robots, smart
home components, and so on. At the beginning of computer networking, all end devices
were physical hardware units. Today, many end devices are virtualized, meaning that
they do not exist as separate hardware units any more. In virtualization, one physical
device is used to emulate multiple end devices, for example all the hardware
components that one end device would require. The emulated computer system
operates as if it were a separate physical unit and has its own operating system and
other required software. In a way, it behaves like a tenant living inside a host physical
device, using its resources (processor power, memory, and network interface
capabilities) to perform its functions. Virtualization is commonly applied for servers to
optimize resource utilization, as server resources are often underutilized when they are
implemented as separate physical units.
Intermediary devices: These devices interconnect end devices or interconnect
networks. In doing so, they perform different functions, which include regenerating and
•
•
•
•
•
•
retransmitting signals, choosing the best paths between networks, classifying and
forwarding data according to priorities, filtering traffic to allow or deny it based on
security settings, and so on. As endpoints can be virtualized, so can intermediary
devices or even entire networks. The concept is the same as in the endpoint
virtualization—the virtualized element uses a subset of resources available at the
physical host system. Intermediary devices that are commonly found in enterprise
networks are:
Switches: These devices enable multiple endpoints such as PCs, file servers, printers,
sensors, cameras, and manufacturing robots to connect to the network. Switches are
used to allow devices to communicate on the same network. In general, a switch or
group of interconnected switches attempt to forward messages from the sender so it is
only received by the destination device. Usually, all the devices that connect to a single
switch or a group of interconnected switches belong to a common network and can
therefore communicate directly with each other. If an end device wants to communicate
with a device that is on a different network, then it requires "services" of a device that is
known as a router, which connects different networks together.
Routers: These devices connect networks and intelligently choose the best paths
between networks. Their main function is to route traffic from one network to another.
For example, you need a router to connect your office network to the internet. An
analogy that may help you understand the basic function of switches and routers is to
imagine a network as a neighborhood. A switch is the street which connects the houses,
and routers are the crossroads of those streets. The crossroads contain helpful
information such as road signs, to help you in finding a destination address. Sometimes,
you might need the destination after just one crossroad, but other times you might need
to cross several. The same is true in networking. Data sometimes "stops" at several
routers, before it is delivered to the final recipient. Certain switches combine
functionalities of routers and switches and they are called Layer 3 switches.
APs: These devices allow wireless devices to connect to a wired network. An AP
usually connects to a switch as a standalone device, but it also can be an integral
component of the router itself.
WLCs: These devices are used by network administrators or network operations
centers to facilitate management of many APs. The WLC automatically manages the
configuration of wireless APs.
Next-generation firewalls (NGFW): Firewalls are network security systems that
monitor and control the incoming and outgoing network traffic based on predetermined
security rules. A firewall typically establishes a barrier between a trusted, secure internal
network, and another outside network, such as the internet, that is assumed not to be
secure or trusted. The term next-generation firewall indicates a firewall that provides
additional features to accommodate the newest security requirements. An example of
such a feature is the ability to recognize user applications, for instance a game running
inside an application, such as a browser, that is connected to Facebook.
Intrusion Protection System (IPS): An IPS is a system that performs deep analysis of
network traffic, searching for signs that behavior is suspicious or malicious. If the IPS
detects such behavior, it can take protective action immediately. An IPS and a firewall
can work in conjunction to defend a network.
•
Management Services: A modern management service offers centralized
management that facilitates designing, provisioning, and applying policies across a
network. It includes features for discovery and management of network inventory,
management of software images, device configuration automation, network diagnostics,
and policy configuration. It provides end-to-end network visibility and uses network
insights to optimize the network. An example of such centralized management service is
Cisco DNA Center.
In user homes, you can often find one device that provides connectivity for wired
devices, provides connectivity for wireless devices, and provides access to the Internet.
You may be wondering which kind of device it is. It has characteristics of a switch in that
it provides physical ports to plug local devices, a router, as it enables users to access
other networks and the internet, and a WLAN AP, as it allows wireless devices to
connect to it. It is actually all three of these devices in a single package. This device is
often called a wireless router.
Another example of a network device is a file server, which is an end device. A file
server runs software that implements protocols that are standardized to support file
transfer from one device to another over a network. This service can be implemented by
either File Transfer Protocol (FTP) or Trivial File Transfer Protocol (TFTP). Having
an FTP or TFTP server in a network allows uploads and downloads of files over the
network. An FTP or TFTP server is often used to store back-up copies of files that are
important to network operation, such as operating system images and configuration
files. Having those files in one place makes file management and maintenance easier.
Media
Media are the physical elements that connect network devices. Media carry
electromagnetic signals that represent data. Depending on the medium,
electromagnetic signals can be guided, like in wires and fiber optic cables, or can be
propagated, like in wireless transmissions, such as are WiFi, mobile, and satellite.
Different media have different characteristics and the selection of the most appropriate
medium would depend on the circumstances, such as the environment in which the
media is used, distances that need to be covered, availability of financial resources, and
so on. For instance, for a filming crew working in a desert, a satellite connection (air
medium) might be the only available option.
Connecting of wired media to network devices is greatly eased by the use
of connectors. A connector is a plug, which is attached to each end of the cable. The
most common type of connector on a LAN is the plug that looks like an analog phone
connector. It is called a registered jack-45 (RJ-45) connector.
To be able to connect the media, which connects a device to a network, devices use
network interface cards (NICs). The media "plugs" directly into the NIC. NICs translate
the data that is created by the device into a format that can be transmitted over the
media. NICs used on LANs are also called LAN adapters. End devices used in LANs
usually come with several types of NICs installed, such as wireless NICs and Ethernet
NICs. NICs on a LAN are uniquely identified by a Media Access Control (MAC) address.
The MAC address is hard-coded or "burned in" by the NIC manufacturer. NICs that are
used to interface with WANs are called WAN interface cards (WICs) and they use serial
links to connect to a WAN network.
Network Services
Services in a network comprise software and processes that implement common
network applications, such as email and web, also including the less obvious processes,
implemented across the network, all of which generate data and determine how data is
moved through the network
Companies typically centralize business-critical data and applications into central
locations called Data Centers. These data centers can include routers, switches,
firewalls, storage systems, servers, and application delivery controllers. Similar to Data
Center centralization, computing resources can also be centralized off premises in the
form of a cloud. Clouds can be private, public, or hybrid, and aggregate the computing,
storage, network, and application resources in central locations. Cloud computing
resources are configurable and shared among many end users. The resources are
transparently available, regardless of the user point of entry (a personal computer at
home, an office computer at work, a smartphone or tablet, or a computer on a school
campus). Data stored by the user is available whenever the user is connected to the
cloud.
Characteristics of a Network
When you purchase a mobile phone or a PC, the specifications list tells you the
important characteristics of the device, just as specific characteristics of a network help
describe its performance and structure. When you understand what each characteristic
of a network means, you can better understand how the network is designed, how it
performs, and which aspects you may need to adjust to meet user expectations.
You can describe the qualities and features of a network by considering these
characteristics:
•
•
•
•
Topology: A network topology is the arrangement of its elements. Topologies give
insight into physical connections and data flows among devices. In a carefully designed
network, data flows are optimized and the network performs as desired.
Bitrate or Bandwidth: Bitrate is a measure of the data rate in bits per second of a
given link in the network. The unit of bitrate is bit per second (bps). This measure is
often referred to as bandwidth, or speed in device configurations, which is sometimes
thought of as speed. However, it is not about how fast 1 bit is transmitted over a link—
which is determined by the physical properties of the medium that propagates the
signal—it is about the number of bits transmitted in a second. Link bitrates commonly
encountered today are one and 10 Gigabits per second (1 or 10 billion bits per second).
100-Gbps links are not uncommon either.
Availability: Availability indicates how much time a network is accessible and
operational. Availability is expressed in terms of the percentage of time the network is
operational. This percentage is calculated as a ratio of the time in minutes that the
network is actually available and the total number of minutes over an agreed period,
multiplied by 100. In other words, availability is the ratio of uptime and total time,
expressed in percentage. To ensure high availability, networks should be designed to
limit the impact of failures and to allow quick recovery when a failure does occur. High
availability design usually incorporates redundancy. Redundant design includes extra
elements, which serve as back-ups to the primary elements and take over the
functionality if the primary element fails. Examples include redundant links, components,
and devices.
Reliability: Reliability indicates how well the network operates. It considers the ability of
a network to operate without failures and with the intended performance for a specified
time period. In other words, it tells you how much you can count on the network to
operate as you expect it to. For a network to be reliable, the reliability of all its
components should be considered. Highly reliable networks are highly available, but a
highly available network might not be highly reliable—its components might operate, but
at lower performance levels. A common measure of reliability is the mean time between
failures (MTBF), which is calculated as the ratio between the total time in service and
the number of failures, where not meeting the required performance level is considered
a failure. Choosing highly reliable redundant components in the network design
increases both availability and reliability.
For instance, let’s consider a networking device that reboots every hour. The reboot
takes 5 minutes, after which the device works as expected. The figure shows the
calculations of availability and reliability.
The availability percentage for the period of one day can be calculated as follows:
•
•
•
•
•
Scalability: Scalability indicates how easily the network can accommodate more users
and data transmission requirements, without affecting current network performance. If
you design and optimize a network only for the current requirements, it can be very
expensive and difficult to meet new needs when the network grows.
Security: Security tells you how well the network is defended from potential threats.
Both network infrastructure and the information that is transmitted over the network
should be secured. The subject of security is important, and defense techniques and
practices are constantly evolving. You should consider security whenever you take
actions that affect the network.
Quality of Service (QoS): QoS includes tools, mechanisms, and architectures, which
allow you to control how and when network resources are used by applications. QoS is
especially important for prioritizing traffic when the network is congested.
Cost: Cost indicates the general expense for the initial purchase of the network
components, and any costs associated with the installation and ongoing maintenance of
these components.
Virtualization: Traditionally, network services and functions have only been provided
via hardware. Network virtualization creates a software solution which emulates network
services and functions. Virtualization solves a lot of the networking challenges in today’s
networks, helping organizations centrally automate and provision the network from a
central management point.
These characteristics and attributes provide a means to compare various networking
solutions.
Physical vs. Logical Topologies
Each network has both a physical and a logical topology. The physical topology of a
network refers to the physical layout of the devices and cabling. The term node is
commonly used when discussing topology diagrams. For networking topology diagrams,
a node is a device.
Two networks might have the same physical topology, but distances between nodes,
physical interconnections, transmission rates, or signal types may be different. A
physical topology must be implemented using media that is appropriate for it. In wired
networks, recognizing the type of cabling used is important in describing the physical
topology. The figure represents some of the physical topologies that you may
encounter.
The following are the primary physical topology categories:
•
•
•
•
Bus: In a bus topology, every workstation is connected to a common transmission
medium, a single cable, which is called a backbone or bus. Therefore, each workstation
is directly connected to every other workstation in the network. In early bus topologies,
computers and other network devices were connected to a central coaxial cable via
connectors.
Ring: In a ring topology, computers and other network devices are cabled in succession
and the last device is connected to the first one to form a circle or ring. Each device is
connected to exactly two neighbors and has no direct connection to a third. When one
node sends data to another, the data passes through each node that lies between them
until it reaches the destination.
Star: The most common physical topology is a star topology. In this topology, there is a
central device to which all other network devices connect via point-to-point links. This
topology is also called the hub and spoke topology. There are no direct physical
connections among spoke devices. This topology includes star and extended star
topologies. In an extended star topology, one or more spoke devices is replaced by a
device that has its own spokes. In other words, it is composed of multiple star
topologies, whose central devices are connected between each other.
Mesh: In a mesh topology, a device can be connected to more than one other device.
For one node to reach others there are multiple paths available. Redundant links
increase reliability and self-healing. In a full mesh topology, every node is connected to
every other node. In partial mesh, certain nodes do not have connections to all other
nodes.
The logical topology is the path along which data travels from one point in the network
to another. The diagram depicts the logical topology between PC A and the Server. In
this example, data does not follow the shortest physical path, which would go through
two switches. The logical topology requires data to also travel through the router in
order for the two devices to communicate. The same could be true for all other end
devices. Logical topology would then be a star, where the router is a central device.
It is possible for the logical and physical topology of a network to be of the same type.
However, physical and logical topologies often differ. For example, an Ethernet hub is a
legacy device that functions as a central device to which other devices connect in a
physical star. The characteristic of a hub is that it "copies" every signal received on one
port to all other ports. So a signal sent from one node is received by all other nodes.
This behavior is typical of a bus topology. Because data flow has the characteristics of a
bus topology, it is a logical bus topology.
The logical topology is determined by the intermediary devices and the protocols
chosen to implement the network. The intermediary devices and network protocols both
determine how end devices access the media and how they exchange data.
A physical star topology in which a switch is the central device is by far the most
common in implementations of LANs today. When using a switch to interconnect the
devices, both the physical and the logical topologies are star topologies.
Interpreting a Network Diagram
Network diagrams are visual aids in understanding how a network is designed and how
it operates. In essence, they are maps of the network. They illustrate physical and
logical devices and their interconnections. Depending on the amount of information you
wish to present, you can have multiple diagrams for a network. Most common diagrams
are physical and logical diagrams. Other diagrams used in networking are sequence
diagrams, which illustrate the chronological exchange of messages between two or
more devices.
Both physical and logical diagrams use icons to represent devices and media. Usually,
there is additional information about devices, such as device names and models.
Physical diagrams focus on how physical interconnections are laid out and include
device interface labels (to indicate the physical ports to which media is connected) and
location identifiers (to indicate where devices can be found physically). Logical network
diagrams also include encircling symbols (ovals, circles, and rectangles), which indicate
how devices or cables are grouped. These symbols further include device and network
logical identifiers, such as addresses. These symbols also indicate which networking
processes are configured, such as routing protocols and provide their basic parameters.
In the example, you can see interface labels" S0/0/0," "Fa0/5," and "Gi0/1." The label is
composed of letters followed by numbers. Letters indicate the type of an interface. In
the example, "S" stands for Serial, "Fa" stands for Fast Ethernet, and "Gi" for Gigabit
Ethernet.
Devices can have multiple interfaces of the same type. The exact position of the
interface is indicated by the numbers that follow, which are subject to conventions. For
instance, the label S0/0/0 indicates serial port 0 (the last zero in the label), in the
interface card slot 0 (the second zero) in the module slot 0 (the first zero).
The name Fast Ethernet indicates an Ethernet link with the speed of 100 Mbps.
The diagram also includes the Internet protocol version 4 (IPv4) address of the entire
network given by 192.168.1.0/24. This number format indicates not only the network
address, which is 192.168.1.0 but also the network's prefix, a representation of its
subnet mask, which is /24. IPv4 addresses of individual devices are shown as ".1" and
".2." These numbers are only parts of the complete address, which is constructed by
combining the address of the entire network with the number shown. The resulting
address of the device in the diagram would be 192.168.1.1.
Impact of User Applications on the Network
The data traffic that is flowing in a network can be generated by end users or can be
control traffic. Users generate traffic by using applications. Control traffic can be
generated by intermediary devices or by activities related to operation, administration,
and management of the network. Today, users utilize many applications. The traffic
created by these applications differs in its characteristics. Usage of applications can
affect network performance and, in the same way, network performance can affect
applications. Usage translates to the user’s perception of the quality of the provided
service—in other words, a user experience that is good or bad. Recall that QoS is
implemented to prioritize network traffic and maximize the user experience.
User applications can be classified to better describe their traffic characteristics and
performance requirements. It is important to know what traffic is flowing in your network
and describe the traffic in technical terms. An example of traffic types found in today’s
network is given in the figure. This knowledge is used to optimize network design.
To classify applications, their traffic, and performance requirements are described in
terms of these characteristics:
•
•
•
•
•
•
Interactivity: Applications can be interactive or noninteractive. Interactivity presumes
that for a given request a response is expected for the normal functioning of the
application. For interactive applications, it is important to evaluate how sensitive they
are to delays—some might tolerate larger delays up to practical limits, but some might
not.
Real-time responsiveness: Real-time applications expect timely serving of data. They
are not necessarily interactive. An example of a real-time application is live football
match video streaming (live streaming) or video conferencing. Real-time applications
are sensitive to delay. Delay is sometimes used interchangeably with the term latency.
Latency refers to the total amount of time from the source sending data to the
destination receiving it. Latency accounts for propagation delay of signals through
media, time required for data processing on devices it crosses along the path, etc.
Because of the changing network conditions, latency might vary during data exchange:
some data might arrive with less latency then other. The variation in latency is called
jitter.
Amount of data generated: There are applications that produce low quantity of data,
such as voice applications. These applications do not require much bandwidth. Usually
they are referred to as bandwidth benign applications. On the other hand, video
streaming applications produce significant amount of traffic. This kind of application is
also termed bandwidth greedy.
Burstiness: Applications that always generate a consistent amount of data are referred
to as smooth or non-bursty applications. On the other hand, bursty applications at times
create small amount of data, but they can change behavior for shorter periods. An
example is web browsing. If you open a page in a browser that contains a lot of text, a
small amount of data is transferred. But if you start downloading a huge file, the amount
of data will increase during the download.
Drop sensitivity: Packet loss is losing packets along the data path, which can severely
degrade the application performance. Some real-time applications (such as Video On
Demand) are sensitive to the perceived packet loss when using the network resources.
You can say that such applications are drop sensitive.
Criticality to business: This aspect of an application is "subjective" in that it depends
on someone's estimate of how valuable and important the application is to a business.
For instance, an enterprise that relies on video surveillance to secure its premises might
consider video traffic as a top priority, while another enterprise might consider it totally
irrelevant.
One way that applications can be classified is as follows:
•
•
•
•
•
•
•
•
•
Batch applications: Applications such as FTP and TFTP are considered batch
applications. Both are used to send and receive files. Typically, a user selects a group
of files that need to be retrieved and then starts the transfer. Once the download starts,
no additional human interaction is required. The amount of available bandwidth
determines the speed at which the download occurs. While bandwidth is important for
batch applications, it is not critical. Even with low bandwidth, the download is completed
eventually. Their principal characteristics are:
Typically do not require direct human interaction.
Bandwidth important but not critical.
Examples: FTP, TFTP, inventory updates.
Interactive applications: Applications in which the user waits for a response to their
action are interactive. Think of online shopping applications, which are offered by many
retail businesses today. The interactive applications require human interaction and their
response times are more important than for batch applications. However, strict
response times or bandwidth guarantees might not be required, so if the appropriate
amount of bandwidth is not available, then the transaction may take longer, but it will
eventually complete. The main characteristics of the interactive applications are:
Typically support human-to-machine interaction.
Acceptable response times have different values depending on how important the
application is for the business.
Examples: database inquiry, stock-exchange transaction
Real-time applications, such as voice and video applications, may also involve human
interaction. Because of the amount of information that is transmitted, bandwidth is
critical. In addition, because these applications are time critical, a delay on the network
can cause a problem. Timely delivery of the data is crucial. It is also important that not
too much data is lost during transmission because real-time applications, unlike other
applications, do not retransmit lost data. Therefore, sufficient bandwidth is mandatory,
and the quality of the transmission must be ensured by implementing QoS. QoS is a
way of granting higher priority to certain types of data, such as Voice over IP (VoIP).
The main characteristics of the real-time applications are:
•
•
•
Typically support human-to-human interaction.
End-to-end latency is critical.
Examples: Voice applications, video conferencing, and live sports event online
streaming.
Applications may also be required to manage different types of communications. One
such application is the factory-automation application. Factory-automation applications
deal with plant process-related data, such as readings from sensors and alarms, which
require guaranteed delivery times and typically require feedback within a prescribed
response time. On the other hand, the same factory-automation application must also
handle certain device configurations and commercial data, which is not time-critical.
Introducing the Host-To-Host Communications
Model
Introduction
When a home user on a smart phone wants to send an email to a user in the Enterprise
office, the email application on one host sends an email to an email application on the
other host. It appears that once a send button has been pressed on one side, almost
immediately the message is received on the receiving side. But there is a series of
processes that happen in between, including using physical media on the end devices,
preparing an email to be sent through the network to the other side, and then also on
every device that connects devices and networks together. In order to logically describe
processes on individual hosts and make sure that both sides are compatible, we use
communication models which consist of different layers
Cisco Enterprise Architecture Model
In a communication model, a layer does not define a single protocol--it defines a data
communication function that may be performed by any number of protocols. Because
each layer defines a function, it can contain multiple protocols, each of which provides a
service suitable to the function of that layer.
Every protocol communicates with its peer. A peer is an implementation of the same
protocol in the equivalent layer on a remote computer. Peer-level communications are
standardized to ensure that successful communication take place.
Protocols and mechanisms are implemented in different devices, from hosts to network
devices in between. In the Cisco Enterprise Architecture model, the network
architecture, and the decision where to place different devices is often influenced by the
functions networking devices perform and protocols they run, so it is also important to
understand the functions of different layers from that perspective.
As a networking engineer, you need to understand the idea of the host-to-host
communications model, which includes important concepts:
•
•
•
•
Identification of layers and functions of Transmission Control Protocol/Internet Protocol
(TCP/IP) protocol suite, its layers, and functions
Comparison to Open Systems Interconnection (OSI) reference model because it is an
alternative to the TCP/IP protocol suite
How information is transmitted from the sender to the receiver across the network
Encapsulation and de-encapsulation processes on network and end devices
Host-To-Host Communications Overview
Communication can be described as successful sharing or exchanging of information. It
involves a source and a destination of information. Information is represented in some
form of messages. In computer networks, the sources of messages are end devices,
also called endpoints or hosts. The messages are created at the source, transferred
over the network, and delivered at the destination. For communication to be successful,
the message has to traverse one or more networks. A network interconnects large
number of devices, produced by different hardware and software manufacturers, over
many different transmission media, each one having its specifics. All these parameters
make the network very complex.
Communication models were created to organize internetworking complexity. Two
commonly used models today are International Organization for Standardization (ISO)
OSI and TCP/IP. Both provide a model of networking that describes internetworking
functions and a set of rules called protocols that set out requirements for
internetworking functions.
Both models present a network in terms of layers. Layers group networking tasks by the
functions that they perform in implementing a network. Each layer has a particular role.
In performing its functions, a layer deals with the layer above it and the layer below it,
which is called "vertical" communication. A layer at the source creates data that is
intended for the same layer on the destination device. This communication of two
corresponding layers is also termed "horizontal."
The second aspect of communication models is protocols. In the same way that
communication functions are grouped in layers, so are the protocols. People usually talk
about the protocols of certain layers, protocol architectures, or protocol suites. In fact,
TCP/IP is a protocol suite.
A networking protocol is a set of rules that describe one type of communication. All
devices participating in internetworking agree with these rules and it is this agreement
that makes communication successful. Protocols define rules used to implement
communication functions.
As defined by the ISO/International Electrotechnical Commission (IEC) 7498-1:1994
ISO standard, the word "open" in the OSI acronym indicates systems that are open for
the exchange of information using applicable standards. Open does not imply any
particular systems implementation, technology, or means of interconnection, but it refers
to the mutual recognition and support of the applicable standards.
While both ISO OSI and TCP/IP models define protocols, the protocols that are included
in TCP/IP are widely implemented in networking today. Nonetheless, as a general
model, ISO OSI aims at providing guidance for any type of computer system, and it is
used in comparing and contrasting different systems. Therefore, ISO OSI is called the
reference model.
Standards-based, layered models provide several benefits:
•
•
•
•
•
•
Make complexity manageable by breaking communication tasks into smaller, simpler
functional groups.
Define and specify communication tasks to provide the same basis for everyone to
develop their own solutions.
Facilitate modular engineering, allowing different types of network hardware and
software to communicate with one another.
Prevent changes in one layer from affecting the other layers.
Accelerate evolution, providing for effective updates and improvements to individual
components without affecting other components or having to rewrite the entire protocol.
Simplify teaching and learning.
Knowledge of layers and the networking functions that they describe assists in
troubleshooting network issues, making it possible to narrow the problem to a layer or a
set of layers.
Computer networks were initially concerned only with transfer of data, and the term data
referred to information in an electronic form that could be stored and processed by a
computer. Additionally, different data transfer protocols required completely different
network topologies, equipment and interconnections. IP, AppleTalk, Token Ring, and
Fiber Distributed Data Interface (FDDI) are examples of data transfer communications
protocols that required different hardware, topologies, and equipment to properly
operate. In addition to data transfer, other communication networks existed in parallel.
For example, telephone networks were built using separate equipment and
implemented a different set of protocols and standards. Over the years, computer
networking evolved such that IP became a common data communications standard and
the technology has been extended to also include other types of communication, such
as voice conversations, and video. Since only computer networking protocols and
standards are now used for voice, video and “pure” computer data, the networking was
termed converged networking.
The need to inter-connect devices is not exclusive to computer networks. Industrial
manufacturing companies used standards and protocols specifically designed to provide
automation and control over production process. The management and monitoring of
the manufacturing plant were traditionally the task of the Operational Technology (OT)
departments. Information Technology (IT) departments, which manage business
applications, and OT departments functioned independently. Today, thanks to the
industrial Internet of Things (IoT), manufacturers are collecting more data from the plant
floor than ever before. However, that data is only as valuable as the decisions it can
support. OT and IT departments collaborate to make the data meaningful and
accessible for use across the organization.
The result is another example of a converged network, called Factory Network, which
connects factory automation and control systems with IT systems using standardsbased networking. The Factory Network provides real-time access to mission-critical
data at the plant level, while sharing knowledge throughout the enterprise, helping
operations leaders make decisions that can contribute to safety and operational
effectiveness.
ISO OSI Reference Model
To address the issues with network interoperability, the ISO researched different
communication systems. As a result of this research, the ISO created the ISO OSI
model to serve as a framework on which a suite of protocols can be built. The vision
was that this set of protocols would be used to develop an international network that
would not depend on proprietary systems. In the computer industry, proprietary means
that one company or a small group of companies uses their own interpretation of tasks
and processes to implement networking. Usually, the interpretation is not shared with
others, so their solutions are not compatible, hence they do not communicate.
Meanwhile, the TCP/IP protocol suite was used in the first network implementations. It
quickly became a standard, meaning that it was the protocol suite implemented in
practice. Consequently, it was chosen over the OSI protocol suite and became the
standard in network implementations today.
ISO, the International Organization for Standardization, is an independent,
nongovernmental organization. It is the world's largest developer of voluntary
international standards. Those standards help businesses to increase productivity while
minimizing errors and waste.
The OSI reference model describes how data is transferred over a network. The model
addresses hardware and software equipment, and transmission.
The OSI model provides an extensive list of functions and services that can occur at
each layer. It also describes the interaction of each layer with the layers directly above
and below it. More importantly, the OSI model facilitates an understanding of how
information travels throughout the network. It provides vendors with a set of standards
that ensure compatibility and interoperability between the various types of network
technologies that companies produce around the world. The OSI model is also used for
computer network design, operation specifications, and troubleshooting.
Roughly, the model layers can be grouped into upper and lower layers. Layers 5 to 7, or
upper layers, are concerned with user interaction and the information that is
communicated, its presentation and how the communication proceeds. Layers 1 to 4,
the lower layers, are concerned with how this content is transferred over the network.
The OSI reference model separates network tasks into seven layers, which are named
and numbered. Here are the OSI model layers:
•
•
•
Layer 1: The physical layer defines electrical, mechanical, procedural, and functional
specifications for activating, maintaining, and deactivating the physical link between
devices. This layer deals with electromagnetic representation of bits of data and their
transmission. Physical layer specifications define line encoding, voltage levels, timing of
voltage changes, physical data rates, maximum transmission distances, physical
connectors, and other attributes. This layer is the only layer implemented solely in
hardware.
Layer 2: The data link layer defines how data is formatted for transmission and how
access to physical media is controlled. This layer typically includes error detection and
correction to ensure reliable data delivery. The data link layer involves network interface
controller to network interface controller (NIC-to-NIC) communication within the same
network or subnet. This layer uses a physical address sometimes called a MAC address
to identify hosts on the local network.
Layer 3: The network layer provides connectivity and path selection beyond the local
segment, all the way from the source to the final destination. The network layer uses
logical addressing to manage connectivity. In networking, the logical address is used to
identify the sender and the recipient. The postal system is another common system that
uses addressing to identify the sender and the recipient. Postal addresses follow the
format that includes name, street name and number, city, state, and country. Network
•
•
•
•
logical addresses have a different format than postal addresses; they are determined by
the network layer rules. Logical addressing ensures that a host has a unique address or
that it can be uniquely identified in terms of network communication.
Layer 4: The transport layer defines segmenting and reassembling of data belonging
to multiple individual communications, defines the flow control, and defines the
mechanisms for reliable transport, if required. The transport layer serves the upper
layers, which in turn interface with many user applications. To distinguish between
these application processes, the transport layer uses its own addressing. This
addressing is valid locally, within one host, unlike addressing at the network layer. The
transport services can be reliable or unreliable. The selection of the appropriate service
depends on application requirements. For instance, file transfer may be reliable, to
guarantee that the file arrives intact and whole. On the other hand, a missing pixel when
watching a video might go unnoticed. In networking, this is called an unreliable service.
Layer 5: The session layer establishes, manages, and terminates sessions between
two communicating hosts, to allow them to exchange data over a prolonged time period.
The session layer is mainly concerned with issues that application processes may
encounter and not with lower layer connectivity issues. The sessions, also called
dialogs, can determine whether to handle data in both directions simultaneously or only
handle data flow in one direction at a time. It also takes care of checkpoints and
recovery mechanisms. The session layer is explicitly implemented with applications that
use remote procedure calls.
Layer 6: The presentation layer ensures that data sent by the application layer of one
system is "readable" by the application layer of another system. It achieves that by
translating data into a standard format before transmission and converting that format
into a format known to the receiving application layer. It also provides special data
processing that must be done before transmission. It may compress and decompress
data to improve the throughput, and may encrypt and decrypt data to improve security.
Compression/decompression and encryption/decryption may also be done at lower
layers.
Layer 7: The application layer is the OSI layer that is closest to the user. It provides
services to user applications that want to use the network. Services include e-mail, file
transfer, and terminal emulation. An example of a user application is the web browser. It
does not reside at the application layer, but is using protocols that operate at the
application layer. Operating systems also use the application layer when performing
tasks triggered by actions that typically do not involve communication over the network.
Examples of such actions are opening a remotely located file with a text editor or
importing a remotely located file into spreadsheet. The application layer differs from
other layers in that it does not provide services to any other OSI layer.
TCP/IP Protocol Suite
The TCP/IP model represents a protocol suite. It is similar to the ISO OSI model in that
it uses layers to organize protocols and explain which functions they perform. TCP/IP
protocols are actively used in actual networks today.
The TCP/IP model defines and describes requirements for the implementation of host
systems. These include standard protocols that these systems should use. It does not
specify how to implement the protocol functions, but rather provides guidance for
vendors, implementors and users of what should be provided within the system.
The TCP/IP protocol suite has four layers and includes many protocols, although its
name stands for only two: TCP, which stands for the Transmission Control Protocol,
and IP, which stands for the Internet Protocol. The reason is that layers represented by
these two protocols carry out functions crucial to successful network communication.
Although this course refers to the TCP/IP protocol stack or protocol suite, it is common
in the industry to shorten this term to "IP stack."
Look at the four layers of the TCP/IP model:
•
•
Link layer: This layer is also known as the media access layer. It defines protocols
used to interface the directly connected network. Tasks of the protocols at this layer are
closely related to the characteristics of the physical medium and deal primarily with
physical network details. The link layer is also referred to as a network interface,
network access, or even data link layer. Because there are many different types of
physical networks, there are many link layer protocols. An example of the TCP/IP link
layer protocol is Ethernet. The link layer introduces physical addresses, sometimes
called hardware addresses or MAC addresses, to identify devices sharing a particular
physical network segment.
Internet layer: This layer routes data from the source to the destination, provides a
means to obtain information on how to reach other networks, and deals with reporting of
errors. The Internet layer provides logical addressing. Logical addressing ensures that a
•
•
host is uniquely identified. An Internet layer logical address, called IP address, is used
to identify a host. This address is valid globally and aims at uniquely identifying the host.
End devices, such as laptops, mobile phones, and servers, are configured with a logical
address, before they can connect to the network. IP protocols, namely IP version 4
(IPv4), and the newer version IP version 6 (IPv6), reside in this layer. This layer serves
the upper Transport layer and passes information to the Link layer.
Transport layer: Along with the Internet layer, this layer is the core of the TCP/IP
architecture. It is placed between so called "data mover" protocols of the Link and
Internet layers and software-oriented protocols of the Application layer. There are two
main protocols at this layer, TCP and User Datagram Protocol (UDP). These protocols
serve many application layer protocols. Transport services "prepare" application data for
transfer over the network, follow on the transfer process, and make sure that data from
different applications’ is not mixed. To distinguish between the applications, the
transport layer identifies each application with its own addressing. This addressing is
valid locally, within one host, unlike addressing at the Internet layer, which is valid
globally.
Application layer: The functions of this layer mainly deal with user interaction. It
supports user applications by providing protocols and services that let you actually use
the network. It also supports network application programming interfaces (APIs), that
allow programs to access the network services, regardless of the operating system that
they are running on. This layer accommodates protocols such as Hypertext Transfer
Protocol (HTTP), Secure HTTP (HTTPS), Domain Name System (DNS), File Transfer
Protocol (FTP), Simple Mail Transfer Protocol (SMTP), Secure Shell (SSH), and many
more. These protocols facilitate applications for web browsing, file transfer, names to IP
addresses resolution, sending of e-mails, remote access to devices, and many other
functions that network users perform.
Peer-To-Peer Communications
The term peer means the equal of a person or object. By analogy, peer-to-peer
communication means communication between equals. This concept is at the core of
layered modeling of a communication process. Although in performing its functions a
layer deals with layers directly above and below it, the data it creates is intended for the
corresponding layer at the receiving host. The concept is also called
the horizontal communication.
Except for the physical layer, functions of all layers are typically implemented in
software. Therefore, you hear about the logical communication of layers. Software
processes at different hosts are not communicating directly. Most probably, the hosts
are not even connected directly. Nevertheless, processes on one host manage to
accomplish logical communication with the corresponding processes on another host.
The term peer-to-peer (p2p) is often used in computing to indicate an application
architecture in which application tasks and workloads are equally distributed among
peers. Contrary to peer-to-peer are client-server architectures in which tasks and
workload are unequally divided.
Applications create data. The intended recipient of this data is the application at the
destination host, which can be distant. In order for application data to reach the
recipient, it first needs to reach the directly connected physical network. In the process,
the data is said to pass down the local protocol stack. First, an application protocol
takes user data and processes it. When processing by the application protocol is done,
it passes processed data down to the transport layer which does its processing. The
logic continues down the rest of the protocol stack until data is ready for the physical
transmission. The data processing that happens as data traverses the protocol stack
alters the initial data, which means that original application data is not the same as the
data represented in the electromagnetic signal transmitted. At the receiving side, the
process is reversed. The signals that arrive at the destination host are received from the
media by the Link layer, which serves data to the Internet layer. From there, data
is passed up the stack all the way to the receiving application. Here again, the data
received as the electromagnetic signal is different to the data that will be delivered to
the application. But the data that the application sees is the same data that the sending
application created.
Passing data up and down the stack is also referred to as vertical communication. For
the horizontal, peer-to-peer communication of layers to happen, it first requires vertical
down the stack and up the stack communication.
As data passes down or up the stack, the unit of data changes—and so does its name.
The generic term used for a data unit, regardless of where it is found in the stack, is a
Protocol Data Unit (PDU). Its name depends on where it exists in the protocol stack
Although there is no universal naming convention for PDUs, they are typically named as
follows:
•
•
•
Data: The general term for the PDU that is used at the Application layer
Segment: A Transport layer PDU
Packet: An Internet layer PDU
•
Frame: A Link layer PDU
To look into PDUs from peer-to-peer communication, you can use a packet analyzer,
such as Wireshark, which is a free and open-source packet analyzer. Packet analyzers
capture all the PDUs on a selected interface. They then examine their content, interpret
it and display it in text or using a graphical interface. Packet analyzers, sometimes also
called sniffers, are used for network troubleshooting, analysis, software and
communications protocol development, and education.
In the figure, you can see a screenshot of a Wireshark capture, which was started on a
local-area network (LAN) Ethernet interface. Wireshark organizes captured information
into three windows. The top window shows a table listing all captured frames. This
listing can be filtered to ease analysis. In the example, the filter is set to show only
frames that carry DNS protocol data. The second, middle window, the details pane,
shows the details of one frame selected from the list. Information is given first for the
lower layers. For each layer, the information includes data added by the protocol at that
layer. In the third window (not shown in the figure), the bytes pane displays information
selected in the details pane, as it was captured, in bytes.
In the figure, you can also see how Wireshark organizes analyzed information. In the
details pane, it displays data it finds in headers. It organizes header information by
layers, starting with the Link layer header and proceeding to the application layer. If you
look closely at the display of each header, you will see that information is organized into
meaningful groups—these groups are recognizable by the names, followed by a colon,
and a value, for example "Source: Cisco_29:ec:52 (04:fe:7f:29:ec:52)" or "Time to live:
127." These groupings correspond to how information is organized in the header.
Headers have fields and the names Wireshark uses correspond to header field names.
For instance, Source and Destination in Wireshark correspond to Source Address and
Destination Address fields of a header.
Encapsulation and De-Encapsulation
Information that is transmitted over a network must undergo a process of conversion at
the sending and receiving ends of the communication. The conversion process is known
as encapsulation and de-encapsulation of data. Both processes provide means for
implementation of the concept of horizontal communication where layer on the
transmitting side is communicating with the corresponding layer on the receiving side.
Have you ever opened a very large present and found a smaller box inside? And then
an even smaller box inside that one, until you got to the smallest box and, finally, to your
present? The process of encapsulation operates similarly in the TCP/IP model. The
Application layer receives the user data and adds to it its information in the form of a
header. It then sends it to the Transport layer. This process corresponds to putting a
present (user data) into the first box (a header), and adding some information on the
box (application layer data). The Transport layer also adds its own header before
sending the package to the Internet layer, placing the first box into the second box and
writing some transport-related information on it. This second box must be larger than
the first one to fit the content. This process continues at each layer. The Link layer adds
a trailer in addition to the header. The data is then sent across the physical media.
Encapsulation increases the size of the PDU. The added information is required for the
handling of the PDU and is calledoverhead to distinguish it from user data.
The figure represents the encapsulation process. It shows how data passes through the
layers down the stack. The data is encapsulated as follows:
1. The user data is sent from a user application to the Application layer, where the
Application layer protocol adds its header. The PDU is now called data.
2. The Transport layer adds the Transport layer header to the data. This header includes
its own information, indicating which Application layer protocol has sent the data. The
new data unit is now called a segment. The segment will be further treated by the
Internet layer, which is the next to process it.
3. The Internet layer encapsulates the received segment and adds its own header to the
data. The header and the previous data become a packet. The Internet layer adds the
information used to send the encapsulated data from the source of the message across
one or more networks to the final destination. The packet is then passed down to the
Link layer.
4. The Link layer adds its own header and also a trailer to form a frame. The trailer is
usually a data-dependent sequence, which is used for checking for transmission errors.
An example of such sequence is a Frame Check Sequence (FCS.) The receiver will use
it to detect errors. This layer also converts the frame to a physical signal and sends it
across the network using physical media.
At the destination, each layer looks at the information in the header added by its
counterpart layer at the source. Based on this information, each layer performs its
functions and removes the header before passing it up the stack. This process is
equivalent to unpacking a box. In networking, this process is called de-encapsulation.
The de-encapsulation process is like reading the address on a package to see if it is
addressed to you and then, if you are the recipient, opening the package and removing
the contents of the package.
The following is an example of how the destination device de-encapsulates a sequence
of bits:
1. The Link layer reads the whole frame and looks at both the frame header and the trailer
to check if the data has any errors. Typically, if an error is detected, the frame is
discarded, and other layers may ask for the data to be retransmitted. If the data has no
errors, the Link layer reads and interprets the information in the frame header. The
frame header contains information relevant for further processing, such as the type of
encapsulated protocol. If the frame header information indicates that the frame should
be passed to upper layers, the Link layer strips the frame header and trailer and then
passes the remaining data up to the Internet layer to the appropriate protocol.
2. The Internet layer examines the Internet header in the packet it received from the Link
layer. Based on the information it finds in the header it decides either to process the
packet at the same layer or to pass it up to the Transport layer. Before the Internet layer
passes the message to the appropriate protocol on the Transport layer, it first removes
the packet header.
3. The Transport layer examines the segment header of the received segment. The
information included in the segment header indicates which Application layer protocol
should receive the data. The Transport layer strips the segment header from the
segment and hands over data to the appropriate application layer protocol.
4. The Application layer protocol strips data header. It uses the information in the header
to process the data before passing it to the user application.
Not all devices process PDUs at all layers. For instance, a switch might only process a
PDU at the Link layer, meaning that it will “read” only frame information, that is
contained in the frame header and trailer. Based on the information found in the frame
header and trailer, the switch will either forward the frame unchanged out a specific
port, forward it out all ports except for the incoming port, or discard the frame if it detects
errors. Routers might look "deeper" into the PDU. A router de-encapsulates the frame
header and trailer and rely on the information contained in the packet header to make
their forwarding decisions. If router is filtering the packets, it may also look even deeper,
into the information contained in the segment header, before it decides on what to do
with the packet.
A host performs encapsulation as it sends data and performs de-encapsulation as it
receives it; and it can perform both functions simultaneously as part of multiple
communications it maintains.
In networking, you will often encounter usage of both OSI and TCP/IP model,
sometimes even interchangeably. You should be familiar with both, so you can
competently communicate with network engineers.
TCP/IP Stack vs OSI Reference Model
The OSI model and the TCP/IP stack were developed by different organizations at
approximately the same time. The purpose was to organize and communicate the
components that guide the transmission of data.
The speed at which the TCP/IP-based Internet was adopted and the rate at which it
expanded caused the OSI protocol suite development and acceptance to lag behind.
Although few of the protocols that were developed using the OSI specifications are in
widespread use today, the seven-layer OSI model has made major contributions to the
development of other protocols and products for all types of new networks.
The layers of the TCP/IP stack correspond to the layers of the OSI model:
•
•
•
•
The TCP/IP Link layer corresponds to the OSI physical and data link layers, and is
concerned primarily with interfacing with network hardware and accessing the
transmission media. Like Layer 2 of the OSI model, the Link layer of the TCP/IP model
is concerned with hardware addresses.
The TCP/IP Internet layer aligns with the network layer of the OSI model, and manages
the addressing of and routing between network devices.
The TCP/IP transport layer, like the OSI transport layer, provides the means for multiple
host applications to access the network layer in a best-effort mode or through a reliable
delivery mode.
The TCP/IP application layer supports applications that communicate with the lower
layers of the TCP/IP model and corresponds to the separate application, presentation,
and session layers of the OSI model.
Because the functions of each OSI layer are clearly defined, the OSI layers are used
even nowadays when referring to devices and protocols.
Take for example a “Layer 2 switch,” which is a LAN switch. The “Layer 2” is this case
refers to the OSI Layer 2, making it easy for people to know what is meant, as they
associate the OSI Layer 2 with a clearly defined set of functions.
Similarly, it is often said that IP is a “network layer protocol” or a “Layer 3 protocol” as
the TCP/IP’s Internet layer can be matched to the OSI network layer.
As a next example, look at the TCP/IP transport layer, which corresponds to the OSI
transport layer. The functions defined at both layers are the same, however, different
specific protocols are involved. Because of this, it is common to refer to the TCP and
UDP as “Layer 4 protocols” again using the OSI layer number.
Another example is the term “Layer 3 switch.” A switch was traditionally thought of as a
device that works on the Link layer level (Layer 2 of the OSI model). A Layer 3 switch is
also capable of providing Internet Layer (Layer 3 of the OSI model) services, which
were traditionally provided by routers.
It is very important to remember that the OSI model terminology and layer numbers are
often used rather than the TCP/IP model terminology and layer numbers when referring
to devices and protocols.
Operating Cisco IOS Software
Introduction
Just as a personal computer or a smart phone improves individual productivity, an
efficient internetwork improves the productivity of large groups of people, especially in
an enterprise environment. Both Enterprises and Small Office/Home Office (SOHO)
users represented in the Cisco Enterprise Architecture Model depend on a sophisticated
operating system (also implemented in software) to effectively connect users within the
enterprise and all over the world.
An internetwork's intelligence lies in its operating system. Network hardware inevitably
changes every few years with the introduction of new generations of processors,
switching, and memory components. But the internetwork's software is the unifying
thread that connects otherwise disparate networks and provides a scalable migration
path as needs evolve.
Just as enterprises invest in network operating systems that can evolve as new
hardware and applications are introduced, Cisco's Internetwork Operating System (IOS)
supports change and migration through integration in all evolving classes of network
platforms. This includes routers, switches, and other devices that have an impact on an
organization's internetwork. Cisco IOS is an operating system that implements and
controls the logic and functions of many Cisco devices and it enables companies to
build a single, integrated information systems infrastructure.
Cisco Enterprise Architecture Model
Operating such a multitasking software is part of your job as a networking engineer. It
all begins with using the command-line interface (CLI) as the primary user interface
which can be used for configuring, monitoring, and maintaining Cisco devices.
As a networking engineer, you will be able to operate Cisco IOS software and perform
various essential tasks, including:
•
•
•
Use CLI to enter commands.
Use the built-in help functionality and features in the CLI.
Navigate various modes in the Cisco IOS CLI and their hierarchical structure.
Cisco IOS Software Features and Functions
Like many common end devices (such as laptops, servers, and mobile phones),
network intermediary devices need an operating system to function. An operating
system is the software that manages hardware resources, for example, memory
allocation and input/output functions, and manages interaction among different
hardware components. Many Cisco devices run Cisco IOS Software. The operating
system software includes basic networking functions, but it may also include advanced
features, such as management and security services, quality of service (QoS) or call
processing features. Examples of devices that use Cisco IOS Software are routers,
local-area network (LAN) switches, small wireless access points (APs), and so on. The
main function of Cisco IOS Software is to provide network features and functions.
Cisco IOS Software delivers the following network features and functions:
•
•
•
•
•
•
Support for basic and advanced networking functions and protocols.
Connectivity for high-speed traffic transmission.
Security for access control and prevention of unauthorized network use.
CLI-based and/or graphical user interface (GUI)-based access enabling users to
execute configuration commands.
Scalability to allow adding hardware and software components.
Reliability to ensure dependable access to networked resources.
Networking devices run particular versions of the Cisco IOS Software. The IOS version
depends on the type of device being used and the required features. While all devices
come with a default IOS and feature set, it is possible to upgrade the IOS version and/or
feature set to obtain additional capabilities.
The portion of the operating system that interfaces with applications and the user is a
program known as a shell. Unlike common end-devices, Cisco network devices do not
have a keyboard, monitor, or mouse device to allow direct user interaction. However,
users can interact with the shell using their own computer and accessing a Command
Line Interface (CLI) or a graphical user interface (GUI). The figure illustrates the
examples of CLI-based and GUI-based access to shell.
When using a CLI, the user interacts directly with the system in a text-based
environment by entering commands on the keyboard at a command prompt. The
system executes the command, often providing textual output. The CLI requires very
little overhead to operate. But the user must have knowledge of the underlying structure
that controls the system.
GUIs may not always be able to provide all features that are available in the CLI. Some
tasks will require you to use the CLI, because they are not supported in the GUI.
Cisco IOS Software CLI Functions
One way that you can access the CLI is through a direct, cabled connection that is
called the console connection. To access the CLI directly using a console connection,
you must be physically present at the location of the device. Accessing a device CLI
through a console connection is also called out-of-band (OOB) access, emphasizing
that no network bandwidth is consumed in the process.
Another way to access the CLI is through the network using protocols that are designed
to provide remote access to the CLI, such as Secure Shell (SSH) and Telnet. SSH is a
secure method to remotely access the CLI. Telnet is an unsecure method of
establishing a CLI session. Unlike a console connection, SSH and Telnet connections
require an active networking service running on the device. Because these CLI
connections consume network bandwidth, they are also called in-band access.
Network-based access to the CLI lets you be somewhere other than the location of the
accessed device. Remote CLI access is convenient for the network engineers, but it is
subject to security risks that are inherently present in the networks that are used in
remote access.
Regardless of which connection method you use, access to the Cisco IOS CLI is
generally referred to as an executive or EXEC session. The features that you can
access via the CLI vary according to the version of Cisco IOS Software installed and the
type of device.
Some devices, such as routers, may also support a legacy auxiliary port that was used to
establish a CLI session remotely using a modem. Similar to a console connection, the
auxiliary (AUX) port is OOB and does not require networking services to be configured
or available.
The services that are provided by Cisco IOS Software are generally accessed using a
CLI. The CLI is a text-based interface that is similar to the old Microsoft operating
system that is called MS-DOS.
Once you access the shell, via the CLI or GUI, you can enter different commands.
Commands are used to configure, monitor, and manage the device and are executed by
the device operating system. While Cisco IOS Software provides core software that
extends across many products, the details of its operation and also the available
services may vary across different devices. Therefore, different devices will have
different commands available for execution.
The CLI is used to enter commands:
•
•
•
•
•
Operations vary on different internetworking devices.
Users type in or copy and paste entries in the console command modes.
Command modes have distinctive prompts.
Pressing Enter instructs the device to parse (translate) and execute the command.
The two primary EXEC modes are user mode and privileged mode.
Cisco IOS Software is designed as a modal operating system. The
term modal describes a system that has various modes of operation. Each mode has its
own set of commands, and command history, and is intended for usage for a specific
group of tasks. The CLI uses a hierarchical structure for the modes. This hierarchy
starts with the least specific command mode or higher-level mode, and proceeds with
more specific or lower-level command modes. A more specific command mode can be
entered from the less specific mode, which precedes it in the hierarchy.
To enter commands into the CLI, type in or copy and paste the entries within one of the
several console command modes. Each command mode is indicated with a distinctive
visual prompt. The term prompt is used because the system is prompting you to make
an entry. Pressing Enter instructs the device to parse and execute the command.
It is important to remember that the command is executed as soon as you enter it. If you
enter an incorrect command on a production router, it can negatively affect the network.
Each command mode has a name and a distinctive visual prompt, by which it can be
recognized. By default, every prompt begins with the device name. Following the device
name, the remainder of the prompt uses special characters and words to indicate the
mode. As you use commands and change operation mode, the prompt changes to
reflect the current context. To enter a command, you can either type them in or copy
and paste the entries. Once you are done, press Enter and the device will parse and
execute the command, if the command was entered correctly.
The example in the figure shows a CLI prompt switch>. The device in the example is
named switch, and the operating CLI mode is indicated by the greater-than sign (>).
As a security feature, to limit the commands that a user can view and execute, Cisco
IOS Software separates CLI sessions, into two primary access levels:
•
•
User EXEC: Allows a person to execute only a limited number of basic monitoring
commands.
Privileged EXEC: Allows a person to execute all device commands, for example, all
configuration and management commands. This level can be password-protected to
allow only authorized users to execute the privileged set of commands.
Cisco IOS Software Modes
Cisco IOS Software has various modes that are hierarchically structured. Highest in the
hierarchy is the user EXEC mode. It is followed by the privileged EXEC mode. From the
privileged EXEC mode, you can proceed to the Global Configuration Mode and from
there to more specific configuration modes such as Interface Configuration Mode and
Router Configuration Mode, as shown below.
Because these modes have a hierarchy, you can only access a lower-level mode from a
higher-level mode. For example, to access Global Configuration Mode, you must be in
the Privileged EXEC mode. Each mode is used to accomplish particular tasks and has a
specific set of commands that are available in this mode. Interface-specific configuration
commands are available only in the Interface Configuration Mode. To access interface
configuration commands, your full path through operation mode hierarchy would be:
User EXEC Mode > Privileged EXEC Mode > Global Configuration Mode > Interface
Configuration Mode. All commands that you enter and execute in Interface
Configuration Mode apply only to the device interface you chose to configure.
You can tell the operation mode that you are in, by looking at the prompt at the
beginning of the line. Normally when you connect to a device, you are allowed access to
the User EXEC Mode. In User EXEC mode you can change the console connection
settings, perform basic connectivity tests, and display system information, but you
cannot configure the device. To leave the User EXEC Mode (to close the console
connection), you can use either the logout, exit, or the quit commands.
To move between the modes, you must use pre-defined commands. The following table
offers an overview of basic IOS Software operation modes, commands or methods to
access and leave them, their prompt identifications, and a short description.
Mode
User EXEC
Mode
Privileged
EXEC Mode
Access Method
Begin a session with
your device.
While in user EXEC
mode, enter
theenable command.
While in privileged
Global
EXEC mode, enter
Configuration the configure
Mode
terminalcommand.
Prompt
Example
Exit Method
About This
Mode
Switch>
Enter logout, exit,
or quit.
Use this mode
to change
terminal
settings,
perform basic
connectivity
tests, or
display
system
information.
Switch#
Use this mode
to verify
commands
that you have
entered and to
enter
configuration
modes. Use a
password to
protect access
Enter disable or exit. to this mode.
To return to
Privileged EXEC
Mode,
enter exit or end, or
Switch(config)# press Ctrl-Z.
Use this mode
to configure
parameters
that apply to
the entire
device.
To return to the
Global
Configuration Mode,
type exit. Then to
return to the
Privileged EXEC
mode, press CtrlZor type exit or end.
Use this mode
to configure
parameters for
the device
interfaces.
While in global
configuration mode,
enter
the interface command
Interface
followed by interface
Configuration label of the interface
Switch(configMode
you wish to configure. if)#
You do not actually have to return to global configuration mode in order to move to a
different configuration mode. Rather, you can enter another configuration mode by
typing the appropriate command at any configuration mode prompt. (Note however, that
you will not be able to get any help for commands that are not actually valid at the
prompt.)
The figure shows two configuration examples, both performing the same task of
providing descriptions for Ethernet 0/0 and Ethernet 0/1 interfaces. In the configuration
on the left, the administrator started in the Global Configuration Mode and entered the
Interface Configuration Mode by typing the command interface Ethernet 0/0. Note how
the prompt changed from SW1(config)# to SW1(config-if)#. In the second line, the
administrator typed the description command. In the next line, the administrator typed
theinterface Ethernet 0/1 command; this command causes the switch to enter Interface
Configuration mode for the Ethernet 0/1 interface. Note that the prompt did not change
because the prompt does not indicate the specific interface. The last line applies
thedescription command to the Ethernet 0/1 interface. In the example on the right, the
same configuration is performed, by exiting and re-entering the Interface Configuration
Mode, as evident in the third and the fourth lines. Both are valid configurations and have
the same results.
Discovery 1: Get Started with Cisco CLI
Introduction
In this activity, you will learn about EXEC modes, CLI help, and the CLI error message.
You will also learn how to manage the Cisco IOS configuration and how to improve user
experience in the CLI.
Interacting with the device using the CLI is only one of the available options. The other
one is using a GUI, when the device's operating system provides one. GUIs may not
always provide all features available at the CLI. For these reasons, network devices are
typically accessed through a CLI. The CLI is less resource intensive and very stable
when compared to a GUI. However, to use the CLI, the user needs to have the
knowledge of the underlying structure that controls the system.
Topology
Job Aids
Device Information
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today.
Personal computers (PCs) in the virtual lab environment are simulated by routers, so you
should use Cisco IOS commands to configure them or verify the configuration.
Device Information Table
Device
Characteristic
Value
SW1
Ethernet0/0 description
Link to SW2
SW1
Ethernet0/1 description
Link to PC1
SW2
Ethernet0/0 description
Link to SW1
Device
Characteristic
Value
SW2
Ethernet0/1 description
Link to R1
SW2
Ethernet0/2 description
Link to PC2
R1
Ethernet0/0 description
Link to SW2
Task 1: Navigate Between EXEC Modes
This activity will guide you through the commands that enable you to navigate between
user EXEC and privileged EXEC operation modes of the Cisco IOS CLI. Also, it will
show you the commands that can assist you when using the CLI.
Activity
Step 1
Access the console of SW2. Press Enter.
The greater-than symbol (>) at the end of the prompt is an indication that you are
accessing the User EXEC Mode.
SW2>
Step 2
Use the question mark (?) to view the list of commands that are available in user EXEC.
When the display output pauses with the --More-- prompt, you can use the space bar to
display the next page of the output.
The available commands you see when entering ? are for this particular version of
Cisco IOS. Other versions may have some different commands.
SW2> ?
Exec commands:
access-enable Create a temporary Access-List entry
access-profile Apply user-profile to interface
clear Reset functions
connect Open a terminal connection
crypto Encryption related commands.
disable Turn off privileged commands
<... output omitted ...>
mtrace Trace reverse multicast path from destination to source
name-connection Name an existing network connection
--More-- <space bar>
pad Open a X.29 PAD connection
ping Send echo messages
<... output omitted ...>
where List active connections
x3 Set X.3 parameters on PAD
You have to press the space bar twice to scroll through the complete command list when
you are in the User EXEC operation mode. Have this information in mind because you
will soon contrast it to what you will be able to see in the Privileged EXEC Mode.
The commands are listed in alphabetical order. Note that the configure command is not
available under User EXEC Mode.
In the outputs, like in the previous one, many lines are omitted due to space
preservation. Omitted lines are indicated with the <... output omitted ...> string.
Step 3
As you just saw, when you are presented with the --More-- prompt, you can use
the space bar to scroll through the output page by page.
You can also use the Enter key to scroll forward just one line. You can also cancel the
remaining output. The method to cancel the remaining output depends on the device
and operating system version. Sometimes, you need to press Ctrl-C, and sometimes
you need to press Q. On SW2, you can press any key other than the space bar or
the Enter key. Give it a try.
SW2> ?
Exec commands:
access-enable Create a temporary Access-List entry
access-profile Apply user-profile to interface
clear Reset functions
connect Open a terminal connection
crypto Encryption related commands.
disable Turn off privileged commands
<... output omitted ...>
mtrace Trace reverse multicast path from destination to source
name-connection Name an existing network connection
--More-- <Enter>
pad Open a X.29 PAD connection
--More-- <Enter>
ping Send echo messages
--More-- <Ctrl-C>
SW2>
Entering EXEC Mode
As a security feature, Cisco IOS Software separates EXEC sessions into the following
two access levels:
•
•
User EXEC Mode allows you to execute only a limited number of basic monitoring
commands. When in EXEC mode, the prompt ends with the greater than or right angle
bracket (>) symbol. For example, when you are in EXEC mode on a device with the
hostname DTW_Switch, the prompt would be DTW_Switch>.
Privileged EXEC Mode allows you to execute all device commands, such as those that
you would use for configuration and management. It can be password-protected to
allow only authorized users to access the device. When you are in Privileged EXEC
Mode, the prompt ends with the octothorpe or pound sign (#). For example, when you
are in privileged EXEC mode on a device with the hostname DTW_Switch, the prompt
would look like DTW_Switch#. To change from the User EXEC Mode to the Privileged
EXEC Mode, enter the enable command at the hostname> prompt. To return to the
User EXEC Mode, enter the disable command at the hostname# prompt.
By default, no authentication is required to access the User EXEC Mode from the
console. You can enter the User EXEC mode by simply pressing the Enter key.
However, if access control (login authentication) is configured, you will be prompted to
enter a username and a password before you can continue to the User EXEC Mode. It
is a good practice to ensure that authentication is configured during initial configuration.
Entering the question mark (?) in the Privileged EXEC Mode reveals many more
command options compared to entering the question mark (?) command in the User
EXEC Mode. This feature is referred to as context-sensitive help.
User EXEC Mode Summary
•
•
•
•
User EXEC Mode provides a limited insight into device status and configuration.
Because the User EXEC Mode offers only a limited number of basic monitoring
commands, User EXEC Mode is sometimes referred to as view-only mode.
This mode does not allow reloading of the device.
Given its limited capabilities, this mode is useful for basic operations.
Privileged EXEC Mode Summary
•
•
•
•
•
•
Privileged EXEC mode provides a detailed examination of a device and enables
configuration and debugging.
Privileged EXEC mode provides critical commands, such as commands related to
configuration and management.
To change from the User EXEC Mode to the Privileged EXEC Mode, enter
the enable command at the hostname> prompt.
You can protect access to the Privileged EXEC Mode. If either the enable password or
enable secret is configured, the CLI will prompt you to enter the configured password
before allowing you to proceed.
When the correct password is entered, the device prompt changes to hostname#.
To return to the User EXEC Mode, enter the disable command at the hostname#
prompt.
Step 4
Use the enable command to access the Privileged EXEC Mode.
Passwords are not configured on any of the lab devices.
The last character in the prompt has changed to the octothorpe or pound sign (#). This
symbol indicates that you are in the Privileged EXEC Mode.
SW2> enable
SW2#
Step 5
Use the ? command again to display the list of commands that are available to you
under the Privileged EXEC Mode. Use thespace bar to scroll through the entire list of
the output.
SW2# ?
Exec commands:
access-enable Create a temporary Access-List entry
access-profile Apply user-profile to interface
access-template Create a temporary Access-List entry
archive manage archive files
beep Blocks Extensible Exchange Protocol commands
calendar Manage the hardware calendar
cd Change current directory
clear Reset functions
clock Manage the system clock
cns CNS agents
configure Enter configuration mode
connect Open a terminal connection
<... output omitted ...>
enable Turn on privileged commands
eou EAPoUDP
--More-- <Space bar>
erase Erase a filesystem
<... output omitted ...>
Under the Privileged EXEC Mode, you needed to press the space bar four times to get
through the entire list of commands. Under User EXEC Mode, you only needed to hit
the space bar twice.
Under the Privileged EXEC Mode, you can use the configure command. You cannot
proceed to the Global Configuration Mode from the User EXEC Mode directly; you
must traverse the Privileged EXEC Mode first.
Step 6
Use the disable command to return to the User EXEC Mode.
SW2# disable
SW2>
The last character in the system prompt is again the greater-than symbol (>).
EXEC Modes
In the following screen, which mode is represented by the Cisco IOS prompt?
user EXEC mode
privileged EXEC mode
global configuration mode
interface configuration mode
Task 2: Explore CLI Help
This session will guide you through using the question mark (?) command, which is
the command-listing feature of the Cisco IOS CLI. It will also demonstrate how you can
take advantage of the tab completion feature of the Cisco IOS CLI. The lab is prepared
with the devices that are represented in the topology, but for this task you will only use
the SW2. You will also examine CLI error messages.
Activity
Step 1
On SW2, use the enable command to access the Privileged EXEC Mode.
SW2> enable
SW2#
Step 2
Use the question mark (?) to display all commands that are available under the
Privileged EXEC Mode.
Use the space bar to scroll through the entire list of the output.
SW2# ?
Exec commands:
access-enable Create a temporary Access-List entry
access-profile Apply user-profile to interface
access-template Create a temporary Access-List entry
archive manage archive files
beep Blocks Extensible Exchange Protocol commands
calendar Manage the hardware calendar
cd Change current directory
clear Reset functions
clock Manage the system clock
cns CNS agents
configure Enter configuration mode
connect Open a terminal connection
<... output omitted ...>
enable Turn on privileged commands
eou EAPoUDP
--More-- <space bar>
<... output omitted ...>
The list is quite long. You have to use the space bar four times to get through the entire
list.
CLI Help
When you are getting to know a new program or interface, you usually take advantage
of the Help features that the program offers. Cisco IOS Software includes extensive
command-line help functions, including context-sensitive help. There are two basic
types of CLI help features that the Cisco IOS devices provide: context-sensitive help
and error message notification. Context-sensitive help offers assistance when you are
trying to determine the proper command and syntax. To access it, use the question
mark (?) command. For example, you know that the command you would like to use
starts with letters sh, but you are not sure what follows. Enter sh? and the CLI will list
all commands that start with sh and that are available in the current operation mode.
You can also use the context-sensitive help to figure out the complete syntax for a
command.
Another feature of the context-sensitive help is listing all available commands for the
current CLI mode. The listing can be used when you are unsure of the name of a
command, or you want to see if Cisco IOS Software supports a particular command in a
particular mode. To use context-sensitive help in this way, enter the question mark (?)
at any prompt.
The second type of CLI help feature is the error message notification. When you enter a
command in the CLI, before executing it, its syntax is checked. If the command syntax
is not correct, you will be notified of an error that reads, "Invalid input detected at '^'
marker." In addition to the text message, the caret symbol (^) will display under the
command you typed in, exactly below the place in the command at which the first error
is detected. Basically, Cisco IOS Software is saying, "I understood what you typed up to
this point."
You may also receive an error message about an ambiguous command. This type of
error occurs when you type in the abbreviated version of the command, but the
abbreviation matches multiple commands. In Cisco IOS Software, when you type
enough letters to match exactly one command, you may press the Enter key, without
completing the command. Because there is no other command that starts with these
letters, Cisco IOS Software will know exactly which command you had in mind and will
execute the command. For example, there are multiple commands that start with the
letter "c," but only one command that begins with "clo." If you pressEnter after entering
only c, you receive an "ambiguous command" error message. On the other hand, if you
enter clo and pressEnter, you do not receive a message that the command is
ambiguous because there is only the clock command that starts with "clo." Although,
you would receive an "Incomplete command" error message because clock does not
complete the command. The "Incomplete command" message indicates that you did not
enter all elements required by the command syntax and that Cisco IOS Software does
not have enough information to interpret what you were requesting.
This functionality may vary across Cisco IOS platforms.
The question mark is your friend when you are using the CLI. It is
impossible to remember the syntax for every Cisco IOS Software command,
so feel free to use this tool.
Type of CLI
Help
Description
Context-sensitive Provides a list of commands or the arguments that are associated with a
help
specific command.
Error notification Identifies problems with commands that you have entered so that you can
message
alter or correct them.
How to use context-sensitive help?
•
•
Command Words Help
To get help with command words, enter the sequence of characters that you know and
follow it immediately by a question mark. Make sure not to include any spaces before
the question mark. The Cisco IOS CLI displays a list of commands starting with the
characters that you entered. For example, enter s? to get a list of commands that start
with letter s.
•
•
Command Syntax Help
To get help with command syntax, enter a question mark after the command word or
words, where you would otherwise enter another keyword or an argument. Include a
space before the question mark. For example, enter show ? to get a list of the
command options and syntax for the show command. The Cisco IOS CLI displays a list
of available command options. <cr> characters might appear in the list. They stand for
carriage return and indicate that you should press Enter. You can access command
syntax help after any word or command option to help you complete the command.
Step 3
List only the commands that start with the letter "s" by entering s? at the line prompt.
SW2# s?
*s=show
sdlc send set setup
show slip spec-file ssh
start-chat systat
The output shows (look at the *s = show in the first line of the output) that there is an
exception to the normal command parsing rules. The CLI will interpret the letter "s" all
by itself as "show," although more than one command starts with letter "s." This feature
is specific to the device and the operating system version. While it will work on SW2 in
this lab, it may not work on all devices. Abbreviating "show" with the characters "sh" will
be useful on more Cisco IOS devices.
Step 4
Try out the Tab completion feature.
Like command abbreviation, Tab completion works as long as you have entered
enough characters to remove ambiguity. Type shand then press the Tab key. After
done, use backspace to erase the resulting command.
The CLI parser expands the unambiguous abbreviation into the full command.
SW2# sh<tab>
SW2# show
Step 5
You may find Tab completion helpful because it prevents you from repeating the
attempts to use commands that are ambiguously abbreviated. Tab completion is
especially useful when you write long commands using abbreviations.
If there are multiple matches for the abbreviation you enter, the Tab completion will not
work. If you are not sure why, you can always use the question mark assistance (?) to
determine why is your entry ambiguous. To try on your own, abbreviate
theconfigure command by entering the letters "con" and press the Tab key.
When you used the Tab to complete the command abbreviation "con," it did not work.
The command parser simply redisplayed "con." Using the question mark (?) at this point
shows that there are two commands that begin with "con." To be unambiguous, you
must use at least "conf" as your abbreviation for configure.
SW2# con<tab>
SW2# con?
configure connect
SW2# con
Step 6
You will not proceed to the Global Configuration Mode during this session. Use
the Backspace key to delete the "con" letters.
Step 7
You have just demonstrated that the question mark (?) and the Tab completion work for
commands.
The question mark (?) and the Tab completion are also helpful when you want to
display the arguments requested by the syntax. For example, if you wish to display all
arguments that you can or should use with the show command, use the question mark
(?) after the word show. Be careful to separate the question mark with a space.
SW2# show ?
aaa Show AAA values
access-expression List access expression
<... output omitted ...>
--More— <space bar>
<... output omitted ...>
There are many show commands available in the Cisco IOS CLI. To scroll through the
entire list, press the space bar nine times.
Step 8
As with commands, you can combine explicit characters followed by the question mark
to display a subset of the argument options.
For example, use show r? to display all show command options that start with the
letter "r."
SW2# show r?
radius region registry reload
resource rhosts rib rif
route-map route-tag running-config
Step 9
Experiment with command abbreviation and Tab completion until you feel comfortable
using them.
You can look at the example of abbreviating the command and using Tab to determine
the arguments for the show running-config command. Feel free to experiment
independently.
SW2# sh<tab>
SW2# show run<tab>
SW2# show running-config
Building configuration...
Current configuration : 885 bytes
!
version 15.1
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
service compress-config
<... output omitted ...>
You may also find Tab completion useful if you are working along with someone.
When you are the one typing in the commands, you might use abbreviated version and
the other person might not know the commands that you intended. But, if you decide to
use abbreviations with Tab completion, Cisco CLI will always display the entire
command verbiage, making it clear to everyone the commands that were used.
CLI Error Messages
The following is an overview of CLI error messages and their interpretations. If you
access the SW1 console and use the enablecommand to access the Privileged EXEC
Mode, you can try the following examples as you go along.
You did not enter enough characters.
SW1# c
% Ambiguous command:'c'
Required arguments or keywords were omitted at the end of the command.
SW1# clock set
% Incomplete command
SW1# clock set 19:50:00
% Incomplete command
The caret (^) indicates the first element in the command, that the CLI cannot interpret.
SW1# clock set 19:50:00 25 6
^
% Invalid input detected at "^" marker
Use the ? command to follow the correct syntax and set the system clock.
SW1# clock set 19:50:00 25 6 ?
% Unrecognized command
SW1# clock set 19:50:00 25 Jun
% Incomplete command.
SW1# clock set 19:50:00 25 Jun ?
<1993-2035> Year
SW1# clock set 19:50:00 25 Jun 2019 ?
SW1# clock set 19:50:00 25 Jun 2019
SW1#
*Jun 25 19:50:00.000: %SYS-6-CLOCKUPDATE: System clock has been updated from
04:33:42 PST Wed Oct 7 2015 to 19:50:00 PST Tue Jun 25 2019, configured from
console by console.
The three types of console error messages are:
•
•
•
Ambiguous command
Incomplete command
Incorrect command
Error Message
Meaning
How to Get Help
Repeat the entry, followed by the
question mark ?Make sure there are
no spaces.
% Ambiguous
command
You did not enter enough characters
for your device to uniquely
recognize the command.
% Incomplete
command
You did not enter all keywords or
values that are required by this
command.
Repeat the entry, followed by a space
and the question mark ?.
% Invalid input
detected at ‘^’
marker
You entered the command
incorrectly. The ^ marks the first
element with the error.
Enter the question mark ? to display
all commands or command options
that you can use.
The CLI displays possible keywords
that you can enter with the command.
You can use context-sensitive help to determine the syntax of a particular command.
For example, if the device clock needs to be set but you are not sure of
the clock command syntax, the context-sensitive help provides a means to check the
syntax.
Context-sensitive help supplies the entire command even if you enter just the first
characters of the command, such as cl?.
If you enter the command clock but an error message is displayed, indicating that the
command is incomplete, enter the ? command (preceded by a space) to determine
which arguments are required for the command. In the clock ? example, the help
output shows that the keyword set is required after clock.
If you now enter the command clock set but another error message appears, indicating
that the command is still incomplete, press the Up Arrow key to repeat the command
entry. Then add a space and enter the question mark (?) to display a list of arguments
that you can use for the command.
The example shows that, after the last command recall, the administrator used the ? to
reveal additional arguments, which involve entering the current time using the correct
format for day, month and year.
The example continues to illustrate how to set the device clock.
If after entering the current time you still see the Cisco IOS Software error message
indicating that the command that you have entered is incomplete, recall the command,
add a space, and enter the ? command to display a list of arguments that are available.
In this example, enter the day, month, and year using the correct format. Then
press Enter to execute the command.
Syntax checking uses the caret symbol (^) as an error-location indicator. It appears at
the point in the command string where the user has first entered an incorrect command,
keyword, or argument. The error-location indicator and interactive help system provide a
way to easily find and correct syntax errors. In the clock example, the caret symbol
indicates that the month was entered incorrectly as a number. The parser is expecting
the month to be spelled out.
Task 3: Manage Cisco IOS Configuration
Now you will examine the startup and running configurations of a Cisco IOS device. The
lab is prepared with the devices that are represented in the topology, but for this task
you will only use SW2. In the end, you will erase the configuration of SW2. Do not
worry, though. The lab system will be correctly configured the next time you initialize the
lab.
When you first access a device for the first time, the prompt includes the hostname that
is already configured on the device. You will modify the hostname configuration
parameter on the switch as you experiment with the startup and running configurations.
Activity
Step 1
On SW2, enter the Global Configuration Mode and change the hostname of the switch
to "Temp" and then return to the Privileged EXEC Mode. To change the device
hostname, use the hostname device-name command. Try using the Tab completion
with thehostname command and note the result. Exit the configuration mode by using
the end command.
Immediately after you change the hostname on the switch, the system prompt reflects
the new name.
SW2# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW2(config)# hostname Temp
Temp(config)# end
Temp#
By changing the hostname, you have modified the running configuration of the switch.
The startup configuration has not changed.
Running configuration and startup configurations are two different configurations of the
device. As their names indicate, the running configuration is the one that is currently
active on the device. Each configuration change that you make is immediately reflected
in the running configuration. The startup configuration is the configuration with which
the device starts when switched on.
Tab completion was available for the show commands, but not for
the hostname command. The hostname command takes as the argument a freeform
variable. In other words, what follows after the hostname word, can be almost anything.
There is no way for the Cisco IOS parser to guess what you wish this string to be.
Step 2
Examine what is configured in the running configuration, but use the include filter to
show only the lines that include the string "hostname." The filtering commands of the
CLI are introduced after you type in the command, by typing the pipe character |. The
pipe character separates the main command from filtering specification. The filtering
criteria is specified by choosing a filtering parameter and a filtering expression. The
filtering syntax will be described in more details later, and in this task, you will explore
the usage of the include filtering option. The include filtering parameter displays only
those lines of the output, that contain the specified filtering expression.
Insisting on the usage of the Tab completion and the question mark contextual help,
intends to remind you that these options are always available to you. They will not be
demonstrated any further in this task, but feel free to take advantage of them at any
time.
Temp# sh<tab>
Temp# show r?
radius region registry reload
resource rhosts rib rif
route-map route-tag running-config
Temp# show run<tab>
Temp# show running-config | inc<tab>
Temp# show running-config | include hostname
hostname Temp
Only one line in the running configuration includes the string "hostname" and it is
the hostname command that set the name of the device to "Temp."
Managing Cisco IOS Configuration
When a switch or a router starts, it looks for a configuration file in the Non-Volatile
Random Access Memory (NVRAM) of the device. NVRAM is the memory component in
the device hardware that retains stored information (for example, it is non-volatile) even
after the device is powered down. The configuration file that is stored in the NVRAM is
called the startup-config file. If there is no startup-config file in NVRAM, which is the
case when you buy new equipment, the router or switch enters the setup utility and
loads a default configuration. The setup utility also prompts you for specific
configuration information to create basic configuration for the device. You can also
interrupt the setup utility and start configuring the device manually, on your own.
Once the device has started, the system copies the startup configuration to randomaccess memory (RAM). The configuration file in RAM is called the running-config file.
As you make configuration changes, the system stores them in the running
configuration. It is important to understand that RAM does not retain stored information
when the device is powered off or rebooted. If a change is made to the running
configuration, it should be copied to the non-volatile memory, for it to be retained after a
reboot. One way you can do that is to use the copy running-config startupconfig command to store the changes in the startup-config file in the NVRAM.
In addition to NVRAM and RAM, Cisco devices have a Read Only Memory (ROM)
and flash memory. ROM is a form of permanent storage. This type of memory contains
microcode for basic functions to start and maintain the router. ROM is nonvolatile, so it
maintains the memory contents even when the power is turned off.
ROM contains:
•
•
•
The bootstrap code, which is used to bring up the router during initialization
Power-On Self Test (POST) microcode, which is used to test the basic functionality of
the router hardware and determine which components are present
ROM monitor includes a low-level operating system that is normally used for
manufacturing, testing, troubleshooting, and password recovery. In ROM monitor mode,
the router has no routing or IP capabilities.
Flash memory is similar to a hard drive in that the information that the system stores
there is retained even when the device is powered off. Cisco IOS Software is stored in
flash memory. Flash memory may also store backup configuration files and additional
device-related files.
To view the configuration files, use the show command, followed by the name of the file
that stores the configuration. For example, if you want to view the running configuration,
type show running-config. Remember, running-config is the name of the file that
stores the running configuration. For the device to retain the running configuration, store
it to NVRAM. You can replace the startup-config file that already resides in NVRAM with
the running configuration. Use the copy command, followed by the names of the source
and destination files. The complete command is copy running-config startup-config.
Review the table for additional commonly used Cisco IOS commands.
Common Cisco IOS Management
Command
Function
show
runningconfig
Displays the current running configuration. You can also use filters. For
example, you can use the show running-config interface
GigabitEthernet0/1 command to display only the interface GigabitEthernet0/1
running configuration.
show startupconfig
Displays the startup configuration stored in NVRAM.
configure
terminal
Enters the Global Configuration Mode, where you can interactively change the
configuration in RAM (the running-config), using console or remote terminal
access.
copy
runningconfig
startupconfig
Saves the running configuration to startup-config file in NVRAM.
copy startupconfig
runningconfig
Startup configuration from NVRAM is merged into the running configuration.
erase startupconfig
Deletes the saved startup-config file in NVRAM.
You can also use the copy command to copy configuration files and Cisco IOS
Software files from a switch or a router to other network locations, such as a server and
vice versa, using File Transfer Protocol (FTP), Secure Copy Protocol (SCP), Hypertext
Transfer Protocol (HTTP), Trivial File Transfer Protocol (TFTP), and other protocols. For
example, in the copy running-config tftp:command, the system copies the running
configuration in RAM to a TFTP server. To remember the copy command syntax, you
might find the mnemonic copy from to useful. To complete copying, you must supply
additional network information about the TFTP server—namely, its IP address or name.
You must also specify the name of the destination file to which you are copying. During
the copying process, a series of exclamation marks show the progress of the upload.
Copying configuration files from a switch or a router to a server is useful for backing up
the configuration files and for centralizing the file management.
Regardless of the size of the network, there should always be a backup copy of the
current running configuration accessible over the network.
Copying configuration files from an external server to the running configuration in RAM
or to the startup configuration file in NVRAM of the router or switch is useful for restoring
backups.
To create device configuration backup, you should copy the configuration files to
another device, such as a dedicated server.
When you copy a configuration into RAM, regardless of the source, the copied
configuration merges with the existing configuration in RAM. It does not overwrite it.
New parameters are added, and changes to existing parameters overwrite the old ones.
Configuration parameters in RAM for which there is no corresponding parameter in the
source file, remain unaffected.
Step 3
Now display the startup configuration filtered using the include filter, to show only the
lines that include the string "hostname."
When you make changes to the running configuration, it does not affect the startup
configuration. The startup configuration still has the hostname SW2.
Temp# show startup-config | include hostname
hostname SW2
Step 4
Use the reload command to reboot the switch. This action will cause the switch to lose
the running configuration and load the startup configuration at restart.
Answer No if asked to save the modified configuration. The goal is to demonstrate how
to return to the old configuration. If you save the modified configuration, the system will
overwrite the old startup configuration.
After the reload the hostname has returned to SW2, as you can see from the prompt.
Temp# reload
System configuration has been modified. Save? [yes/no]: no
Proceed with reload? [confirm] <Enter>
<... output omitted ...>
Press RETURN to get started! <Enter>
<... output omitted ...>
SW2>
To save the changes made to the running configuration, you have to copy the running
configuration over the startup configuration.
Step 5
Change the hostname one more time.
This time, set the hostname to "ThisWillStick."
On SW2, enter the following commands:
SW2> enable
SW2# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW2(config)# hostname ThisWillStick
ThisWillStick(config)# end
ThisWillStick#
Step 6
Copy the running configuration over the startup configuration.
On ThisWillStick, enter the following commands:
ThisWillStick# copy running-config startup-config
Destination filename [startup-config]? <Enter>
Building configuration...
Compressed configuration from 936 bytes to 641 bytes[OK]
ThisWillStick#
After this copy operation, the changed hostname is saved in the startup configuration
and will now "survive" the reload event.
Optionally, you can use the show startup-configuration command to verify that the
change is saved.
Step 7
Use the reload command again, and verify that the new hostname endures the reboot.
On ThisWillStick, enter the following commands:
ThisWillStick# reload
Proceed with reload? [confirm] <Enter>
<... output omitted ...>
Press RETURN to get started! <Enter>
<... output omitted ...>
ThisWillStick>
The hostname is, indeed, ThisWillStick.
Step 8
Now erase the startup configuration with the erase startup-config command. This
command cannot be shortened.
On ThisWillStick, enter the following commands:
ThisWillStick> enable
ThisWillStick# erase startup-config
Erasing the nvram filesystem will remove all configuration files! Continue?
[confirm] <Enter>
[OK]
Erase of nvram: complete
*Jun 25 00:40:12.990: %SYS-7-NV_BLOCK_INIT: Initialized the geometry of nvram
ThisWillStick#
Although the system erased the startup configuration, this action does not have an effect
on the running configuration. In fact (do not do this now), you could use the copy
running-config startup-config command to restore the startup configuration back to
what it was before the erase.
Step 9
Verify that the system actually erased the startup configuration using show startupconfig command.
On ThisWillStick, enter the following commands:
ThisWillStick# show startup-config
startup-config is not present
Step 10
Reload the switch.
After reload, the switch will attempt to read the startup configuration and find it missing.
This situation will essentially set the switch back to the factory default state. Do not
worry. When the lab is reinitialized, the lab system will appropriately set all device
configurations.
On ThisWillStick, enter the following commands:
ThisWillStick# reload
Proceed with reload? [confirm] <Enter>
<... output omitted ...>
Press RETURN to get started! <Enter>
Switch>
Step 11
Verify that the hostname parameter in the running configuration has the default value
(Switch).
On Switch, enter the following commands:
Switch> enable
Switch# show running-config | include hostname
hostname Switch
Switch#
Task 4: Improve User Experience in the CLI
In this session, you will practice using terminal history. Recalling recently entered
commands is useful, because it reduces typing. Once you recall a command, you can
simply press Enter to use the exact same command, or you can modify it. The lab is
prepared with the devices that are represented in the topology, but for this session you
will only use R1.
The prompt displays the hostname that is configured on the device. You will modify this
parameter of the router configuration as you experiment with the startup and running
configurations.
Activity
Step 1
On R1, use the enable command to access the Privileged EXEC Mode.
R1> enable
R1#
Step 2
Enter the sequence of commands that are shown below.
The sequence is rather arbitrary. It includes three EXEC Mode commands and two
Global Configuration Mode commands. Do not worry that the commands are new to
you. You are typing the sequence of the commands only to fill the terminal history.
•
•
•
•
•
•
show ip route (in Privileged EXEC Mode)
show clock (in Privileged EXEC Mode)
show ip interface brief (in Privileged EXEC Mode)
configure terminal (to go in Global Configuration Mode)
clock timezone EST 0 (in Global Configuration Mode)
no ip domain-lookup (in Global Configuration Mode)
On R1, enter the following commands:
R1# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
+ - replicated route, % - next hop override
Gateway of last resort is not set
10.0.0.0/8 is variably subnetted, 4 subnets, 2 masks
C 10.10.1.0/24 is directly connected, Ethernet0/0
L 10.10.1.1/32 is directly connected, Ethernet0/0
C 10.10.3.0/24 is directly connected, Loopback0
L 10.10.3.1/32 is directly connected, Loopback0
R1# show clock
*00:47:02.857 PST Tue Jun 25 2019
R1# show ip interface brief
Interface IP-Address OK? Method Status Protocol
Ethernet0/0 10.10.1.1 YES NVRAM up up
Ethernet0/1 unassigned YES NVRAM administratively down down
Ethernet0/2 unassigned YES NVRAM administratively down down
Ethernet0/3 unassigned YES NVRAM administratively down down
Serial1/0 unassigned YES NVRAM administratively down down
Serial1/1 unassigned YES NVRAM administratively down down
Serial1/2 unassigned YES NVRAM administratively down down
Serial1/3 unassigned YES NVRAM administratively down down
Loopback0 10.10.3.1 YES NVRAM up up
R1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
R1(config)# clock timezone EST 0
*Jun 25 08:48:41.931: %SYS-6-CLOCKUPDATE: System clock has been updated from
00:48:41 PST Tue Jun 25 2019 to 08:48:41 EST Tue Jun 25 2019, configured from
console by console.
R1(config)# no ip domain-lookup
The time and date that you see in your output is different than the output presented
here.
Improving User Experience in the CLI
The Cisco IOS CLI includes many features that make the configuration and verification
process easier and faster. These features include command-line editing keys, command
history, and filtering parameters.
Command-Line Editing Keys
Command-line editing keys are shortcuts and hot keys that the CLI provides. Use these
shortcuts and hot keys to move the cursor around on the command line for corrections
or changes. Use them also to make configuring, monitoring, and troubleshooting easier.
The table describes each of the shortcuts for command line editing and controlling
command entry.
CommandLine
Editing
Key
Sequence Description
Ctrl-A
Moves the cursor to the beginning of the command line
Ctrl-C
Aborts the current command and exits the configuration mode
CommandLine
Editing
Key
Sequence Description
Ctrl-E
Moves the cursor to the end of the command line
Esc-B
Moves the cursor back one word
Esc-F
Moves the cursor forward one word
Ctrl-B
Moves the cursor back one character
Ctrl-F
Moves the cursor forward one character
Ctrl-D
Deletes a single character at the cursor
Backspace
Removes one character to the left of the cursor
Ctrl-R
Redisplays the current command line
Ctrl-U
Erases a line
Ctrl-W
Erases a word to the left of the cursor
Ctrl-Z
Ends the configuration mode and returns to the EXEC prompt
Tab
Completes a partially entered command if enough characters have been entered to
make it unambiguous
Ctrl-Shift-6 Allows the user to interrupt a Cisco IOS process such as ping or traceroute
Ctrl-P or
Up Arrow
Recalls last (previous) commands
Ctrl-N or
Down
Arrow
Recalls more recent commands
CommandLine
Editing
Key
Sequence Description
The Esc key is not functional on all terminals.
Command History
The Cisco CLI provides a history or record of commands that users have entered. You
will find this feature, which is called the command history, particularly useful when
recalling long or complex commands or entries.
With the command history feature, you can complete the following tasks:
•
•
•
Display the contents of the command buffer: By default, command history is
enabled, and the system records the last 10 command lines in its history buffer.
Set the command history buffer size: To change the number of command lines that
the system will record during the current terminal session only, use the terminal
history command in user EXEC mode.
Recall previously entered commands that are stored in the history buffer: There is
one buffer for EXEC modes and another one for the configuration modes. To recall
commands in the history buffer, press Ctrl-P or the Up Arrow key. The command
output begins with the most recent command. Repeat the key sequence to recall
successively older commands.
To return to more recent commands in the history buffer (after recalling older
commands with Ctrl-P or the Up Arrow key), press Ctrl-N or the Down Arrow key.
Repeat the key sequence to recall successively more recent commands.
On most computers, there are additional select and copy functions available. Copy a
previous command string, then paste or insert it as the current command entry, and
press Enter.
When you use show commands such as show running-config, Cisco IOS Software
automatically pauses when displaying the output after a specified number of lines. The
process of displaying the output pauses, and Cisco IOS Software displays "--More--." It
then waits for user input to continue with the display process. You can press the
Spacebar key to display another set of subsequent lines or press Enter to display a
single line.
•
Set the number of lines on the current terminal screen: You can use the terminal
length command, followed by a number, to control the number of lines that the CLI
displays without pausing during the output. A value of zero prevents the router from
pausing between screens of output. By default, the value is set to 24.
Step 3
Now, while remaining in the configuration mode, use the Up Arrow and Down
Arrow keys to scroll through the terminal history buffer.
Note that you do not see the EXEC commands. There is a separate terminal history
buffer for the configuration and EXEC modes.
Step 4
Leave the configuration mode (use end, exit, or press Ctrl-Z) to return to the Privileged
EXEC Mode.
Step 5
Again, use the Up Arrow and Down Arrow keys to show that you can recall previous
commands.
Step 6
Recall the show ip route command and press the Enter key to resubmit it without any
edits.
It is a common exercise to revisit show commands. The show commands display
operational status and enable you to follow on the effect of the configuration changes
you make on the Cisco IOS device.
Step 7
Now type the following command, snow ip interface brief, purposely mistyping "show"
as "snow."
R1# snow ip interface brief
^
% Invalid input detected at '^' marker.
Everyone makes typographical errors. Managing typos is one of the best uses of the
terminal history and the command-line editing tools.
Step 8
Follow this sequence to quickly and easily correct the typographical error and resubmit
the corrected command:
a. Press the Up Arrow key once to retrieve the previous command.
b. Press Ctrl-A to move the cursor to the beginning of the line.
c. Press the Right Arrow twice to move the cursor to the right of the incorrect letter "n."
d. Press Backspace to erase the letter "n."
e. Press h to insert the correct letter "h."
f. Press Enter to resubmit the corrected command.
Step 9
Return to the Global Configuration Mode.
R1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
R1(config)#
As before, you will use commands that you are not familiar with to facilitate the
demonstration of the power of the terminal history buffer. Do not concern yourself with
commands themselves. Instead, focus on how beneficial the terminal history buffer can
be.
Step 10
Configure the description of interface Serial 1/0 to " Link to SP1" and enable the
interface by overriding the default shutdowncommand.
R1(config)# interface Serial 1/0
R1(config-if)# description Link to SP1
R1(config-if)# no shutdown
*Jun 25 08:51:13.776: %LINK-3-UPDOWN: Interface Serial1/0, changed state to
up
*Jun 25 08:51:14.780: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Serial1/0, changed state to up
R1(config-if)#
Step 11
Repeat a similar configuration for interface Serial 1/1.
The following process can make this task relatively easy:
a. Press the Up Arrow key three times to recall the interface command. Edit Serial 1/0
to be 1/1 and press the Enter key to resubmit the edited command.
b. Press the Up Arrow key three times to recall the description command. Edit SP1 to
be SP2 and press the Enter key to resubmit the edited command.
c. Press the Up Arrow key three times to recall the no shutdown command, and press
the Enter key to resubmit the command without any editing.
Note that the terminal history stores all recently entered commands, including the ones
that were entered with errors and were not executed.
The resulting sequence should look like the following example:
R1(config)# interface Serial 1/1
R1(config-if)# description Link to SP2
R1(config-if)# no shutdown
*Jun 25 09:02:22.638: %LINK-3-UPDOWN: Interface Serial1/1, changed state to
up
*Jun 25 09:02:23.642: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Serial1/1, changed state to up
R1(config-if)#
Step 12
Leave the configuration mode by using end, exit (two times), or pressing Ctrl-Z to
return to the privileged EXEC.
Optionally, you can save the running configuration to the startup configuration, but it is
not necessary in the automated lab environment.
Filtering Parameters
Another useful feature that improves the user experience in the CLI is the filtering
of show outputs. Using filtering, you can display only the parts of show outputs that you
are interested in. You can filter outputs by typing the pipe (|) character after
a showcommand, followed by a filtering parameter and a filtering expression. The table
describes filtering parameters that are available for output filtering. The filtering
expression is case-sensitive and must match exactly, for example it must not have extra
spaces.
Parameter Description
begin
Shows all output lines, starting with the line that matches the filtering expression
exclude
Excludes all output lines that match the filtering expression
include
Includes all output lines that match the filtering expression
section
Shows the entire section that starts with the filtering expression
Step 13
On the R1 router, use the begin and include options with the show runningconfig command and filtering expression interface.
You should see the following output when using the begin option:
R1# show running-config | begin interface
interface Loopback0
ip address 10.10.3.1 255.255.255.0
!
interface Ethernet0/0
description Link to SW2
ip address 10.10.1.1 255.255.255.0
!
interface Ethernet0/1
no ip address
shutdown
!
interface Ethernet0/2
no ip address
shutdown
!
interface Ethernet0/3
no ip address
shutdown
!
interface Serial1/0
description Link to SP1
no ip address
serial restart-delay 0
!
interface Serial1/1
description Link to SP2
no ip address
serial restart-delay 0
!
interface Serial1/2
no ip address
shutdown
serial restart-delay 0
!
interface Serial1/3
no ip address
shutdown
serial restart-delay 0
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
!
!
!
control-plane
!
!
!
!
!
!
!
line con 0
logging synchronous
line aux 0
line vty 0 4
login
transport input all
!
!
end
You should see the following output when using the include option:
R1# show running-config | include interface
interface Loopback0
interface Ethernet0/0
interface Ethernet0/1
interface Ethernet0/2
interface Ethernet0/3
interface Serial1/0
interface Serial1/1
interface Serial1/2
interface Serial1/3
Step 14
On the R1 router, use the section option with the show running-config command and
filtering expression interface.
You should see the following output when using the section option:
R1# show running-config | section interface
interface Loopback0
ip address 10.10.3.1 255.255.255.0
interface Ethernet0/0
description Link to SW2
ip address 10.10.1.1 255.255.255.0
interface Ethernet0/1
no ip address
shutdown
interface Ethernet0/2
no ip address
shutdown
interface Ethernet0/3
no ip address
shutdown
interface Serial1/0
description Link to SP1
no ip address
serial restart-delay 0
interface Serial1/1
description Link to SP2
no ip address
serial restart-delay 0
interface Serial1/2
no ip address
shutdown
serial restart-delay 0
interface Serial1/3
no ip address
shutdown
serial restart-delay 0
Step 15
On the R1 router, use the exclude option with the show running-config command and
filtering expression !.
You should see the following output when using the exclude option:
R1# show running-config | exclude !
Building configuration...
Current configuration : 1223 bytes
version 15.2
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
hostname R1
boot-start-marker
boot-end-marker
no aaa new-model
clock timezone EST 0 0
mmi polling-interval 60
no mmi auto-configure
no mmi pvc
mmi snmp-timeout 180
no ip domain lookup
ip cef
no ipv6 cef
multilink bundle-name authenticated
redundancy
interface Loopback0
ip address 10.10.3.1 255.255.255.0
interface Ethernet0/0
description Link to SW2
ip address 10.10.1.1 255.255.255.0
interface Ethernet0/1
no ip address
shutdown
interface Ethernet0/2
no ip address
shutdown
interface Ethernet0/3
no ip address
shutdown
interface Serial1/0
description Link to SP1
no ip address
serial restart-delay 0
interface Serial1/1
description Link to SP2
no ip address
serial restart-delay 0
interface Serial1/2
no ip address
shutdown
serial restart-delay 0
interface Serial1/3
no ip address
shutdown
serial restart-delay 0
ip forward-protocol nd
no ip http server
no ip http secure-server
control-plane
line con 0
logging synchronous
line aux 0
line vty 0 4
login
transport input all
end
Filtering Parameters
Introducing LANs
Introduction
A small home business or a small-office environment can use a small Local Area
Network (LAN) to connect two or more computers and to connect the computers to one
or more shared peripheral devices, such as printers. A large corporate office can use
multiple LANs to accommodate hundreds of computers and shared peripheral devices,
spanning many floors in an office complex.
The enterprise campus LAN is the portion of the infrastructure that provides network
access to end users and devices located at the same geographical location. It may span
several floors in a single building, or multiple buildings covering a larger geographical
area. The campus typically connects to a network core that provides access to other
parts of the network such as data centers, Wide Area Network (WAN), other campuses,
and the internet.
Cisco Enterprise Architecture Model
As a networking engineer, you will work with LAN switches, and for successful
completion of various tasks you first need to:
•
•
•
Explain what a LAN is and be able to identify LAN components.
Understand why you need switches.
List important switch features and characteristics.
Local Area Networks
The LAN emerged to serve the needs of high-speed interconnections between the
computer systems. While there have been many types of LAN transports, Ethernet
became the favorite of businesses starting in the early 1990s. Since its introduction,
Ethernet bandwidth has scaled from the original shared-media 10 Mbps to 400 Gbps in
Cisco Nexus 9000 Series Switches for the data center.
A LAN is a network of endpoints and other components that are located relatively close
together in a limited area.
LANs can vary widely in size. A LAN may consist of only two computers in a home
office or small business, or it may include hundreds of computers in a large corporate
office or multiple buildings. A LAN is typically a network completely within your own
premises (your organization's campus, or building, or office suite, or even your home).
Organization or individuals typically build and own the whole infrastructure, all the way
down to the physical cabling.
The defining characteristics of LANs, in contrast to WANs, include their typically higher
data transfer rates, smaller geographic area, and the lack of need for leased
telecommunication lines.
A WAN is a data communications network that provides access to other networks over
a large geographical area. WANs use facilities that an Internet service provider (ISP) or
carrier, such as a telephone or cable company, provides. The provider connects
locations of an organization to each other, to locations of other organizations, to
external services, and to remote users. WANs carry various traffic types such as voice,
data, and video.
LAN Components
On the first LANs, devices with Ethernet connectivity were mostly limited to personal
computers (PCs), file servers, print servers, and legacy devices such as hubs, and
bridges. Hubs and bridges were replaced by switches, and are no longer used.
Today, a typical small office will include routers, switches, access points, servers, IP
phones, mobile phones, PCs, and laptops.
Regardless of its size, a LAN requires these fundamental components for its operation:
•
•
•
•
•
•
•
Hosts: Hosts include any device that can send or receive data on the LAN. Sometimes
hosts are also called endpoints. Those two terms are used interchangeably throughout
the course.
Interconnections: Interconnections allow data to travel from one point to another in the
network. Interconnections include these components:
Network Interface Cards (NICs): NICs translate the data that is produced by the
device into a frame format that can be transmitted over the LAN. NICs connect a device
to the LAN over copper cable, fiber-optic cable, or wireless communication.
Network media: In traditional LANs, data was transmitted mostly over copper and fiberoptic cables. Modern LANs (even small home LANs) generally include a wireless LAN
(WLAN).
Network devices: Network devices, like switches and routers, are responsible for data
delivery between hosts.
Ethernet switches: Ethernet switches form the aggregation point for LANs. Ethernet
switches operate at Layer 2 of the Open Systems Interconnection (OSI) model and
provide intelligent distribution of frames within the LAN.
Routers: Routers, sometimes called gateways, provide a means to connect LAN
segments and provide connectivity to the internet. Routers operate at Layer 3 of the OSI
model.
•
Access points (APs): APs provide wireless connectivity to LAN devices. APs operate
at Layer 2 of the OSI model.
•
Protocols: Protocols are rules that govern how data is transmitted between
components of a network. Here are some commonly used LAN protocols:
Ethernet protocols (Institute of Electrical and Electronics Engineers [IEEE] 802.2 and
IEEE 802.3)
Internet Protocol (IP)
Transmission Control Protocol (TCP)
User Datagram Protocol (UDP)
Address Resolution Protocol (ARP) for IP version 4 (IPv4) and Neighbor Discovery
Protocol (NDP) for IP version 6 (IPv6)
Common Internet File System (CIFS)
Dynamic Host Configuration Protocol (DHCP)
•
•
•
•
•
•
•
Functions of a LAN
LANs provide network users with communication and resource-sharing functions:
•
•
•
Data and applications: When users are connected through a network, they can share
files and even software applications. This capability makes data more easily available
and promotes more-efficient collaboration on work projects.
Resources: The resources that can be shared include input devices, such as cameras,
and output devices, such as printers.
Communication path to other networks: If a resource is not available locally, the LAN
can provide connectivity via a gateway to remote resources, such as the internet.
Need for Switches
When you connect three or more devices, you need a dedicated network device to
enable communication between these hosts. Switches were introduced to LANs to
divide a network into segments.
A segment is a network connection that is made by a single unbroken network cable.
Ethernet cables and segments can span only a limited physical distance.
Historically, when network devices had few network segments, endpoints shared the
same media. Network segments that share the same media are known as collision
domains, because frames may collide with each other. A network collision occurs when
two or more devices, connected by a shared medium, try to communicate at the same
time. In a collision domain, only one device was able to transmit at the time, while other
devices had to wait before transmitting, to avoid collisions. The total bandwidth was
shared across all host devices on a shared media. Collisions also decrease network
efficiency, because host devices had to wait before re-transmitting data at another time.
Today, switches operating at the link layer divide a network into segments and reduce
the number of devices that share the total bandwidth. Each segment, then, results in a
new collision-free domain.
However, switches have additional functionality and can also be a solution for the
typical causes of network congestion.
The most common causes of network congestion are as follows:
•
•
•
Increasingly powerful computer and network technologies: central processing units
(CPUs), buses, and peripherals are consistently becoming faster and more powerful;
therefore, they can send more data at higher rates through the network.
Increasing volume of network traffic: Network traffic is now more common, as remote
resources are used and are even necessary to carry out basic work.
High-bandwidth applications: Software applications are becoming richer in their
functionality and are requiring more bandwidth to process. Applications such as desktop
publishing, engineering design, video on demand (VoD), e-learning, and streaming
video all require considerable processing power and speed. This richer functionality
puts a large burden on networks to manage the transmission of their files and requires
sharing of the applications among users.
As shown in the figure, each switch interface (also called a switch port) connects to a
single PC or server. Each switch port represents a segment. By default, a switch and all
interconnected switches belong to a single LAN.
Switches have these functions:
•
•
•
•
Operate at the link layer of the TCP/IP protocol suite
Selectively forward individual frames
Have many ports to segment a large LAN into many smaller segments
Have high speed and support various port speeds
The main purpose of a switch is to forward frames as fast and as efficiently as possible.
When a switch receives a frame on an input interface, it buffers that frame until the
switch performs the required processing and is ready to transmit the frame out an exit
interface. If switches did not have frame buffers, then the frames would be dropped
when the congestion occurs or the link becomes saturated.
Ethernet switches selectively forward individual frames from the source port to the
destination port.
Characteristics and Features of Switches
Switches have become a fundamental part of most networks. LAN switches have
special characteristics that make them effective in alleviating network congestion by
increasing effective network bandwidth.
Switches provide the following important functions, resulting in even greater benefits for
eliminating network congestion:
•
•
•
•
Dedicated communication between devices: This increases frame throughput.
Switches with one user device per port have microsegmented the network. In this type
of configuration, each user receives access to the full bandwidth and does not have to
contend with other users for available bandwidth. As a result, collisions do not occur.
Multiple simultaneous conversations: Multiple simultaneous conversations can occur
by forwarding-or switching-several packets at the same time, increasing network
capacity by the number of conversations that are supported. For example, when frames
are being forwarded between ports 1 and 2, another conversation can be happening
between ports 5 and 6. This multiplication is possible because of input/output (I/O)
buffers and fast internal transfer speeds between ports. A switch that can support all
possible combinations of frame transfers between all ports simultaneously is said to
offer wire-speed and nonblocking performance. Of course, this class of switch is
relatively expensive.
Full-duplex communication: After a connection is microsegmented, it has only two
devices (the switch and the host). It is now possible to configure the ports so they can
both receive and send data at the same time, which is called full-duplex communication.
For example, point-to-point 100-Mbps connections have 100 Mbps of transmission
capacity and 100 Mbps of receiving capacity, for an effective 200-Mbps capacity on a
single connection. The configuration between half-duplex and full-duplex is
automatically negotiated at the initial establishment of the link connection. Half-duplex
means that there is transmission of data in just one direction at a time.
Media-rate adaptation: A LAN switch that has ports with different media rates can
adapt to between rates, for example between 10, 100 and 1000 Mbps, 1 and 10 Gbps,
1, 10 and 25 Gbps, 40 Gbps and 100 Gbps. This adaptability allows bandwidth to be
matched as needed. Without this ability, it is not possible to have different media-rate
ports that are operating at the same time.
Switches connect LAN segments, determine the segment to which it will send the data,
and reduce network traffic. Some important characteristics of switches follow:
•
•
•
•
•
High port density: Switches have high port densities: 24-, 32- and 48-port switches
operate at speeds of 100 Mbps, 1 Gbps, 10 Gbps 25 Gbps, 40 Gbps and 100 Gbps.
Large enterprise switches may support hundreds of ports.
Large frame buffers: The ability to store more received frames before having to start
dropping them is useful, particularly when there may be congested ports connected to
servers or other heavily used parts of the network.
Port speed: Depending on the switch, it may be possible to support a range of
bandwidths. Ports of 100 Mbps, 1Gbps, and 10 Gbps are expected, but 40- or 100Gbps ports allow even more flexibility.
Fast internal switching: Having fast internal switching allows higher bandwidths: 100
Mbps, 1 Gbps, 10 Gbps, 25 Gbps, 40 Gbps and 100 Gbps.
Low per-port cost: Switches provide high port density at a lower cost. For this reason,
LAN switches can accommodate network designs that feature fewer users per segment.
This feature, therefore, increases the average available bandwidth per user.
Switches use application-specific integrated circuits (ASICs), which are fundamental to
how an Ethernet switch works. An ASIC is a silicon microchip designed for a specific
task (such as switching or routing packets), rather than being used for general-purpose
processing such as a CPU. A generic CPU is too slow for forwarding traffic in a switch.
While a general-purpose CPU may be fast at running a random application on a laptop
or server, manipulating and forwarding network traffic is a different matter. Traffic
handling requires constant lookups against large memory tables.
Exploring the TCP/IP Link Layer
Introduction
When users want to communicate either in Enterprise environment, at home, or
basically anywhere in the world, they need to have a way of being connected to the
network by some sort of physical media. This is where the Transmission Control
Protocol/Internet Protocol (TCP/IP) Link layer becomes vital. There are different ways of
being connected to the network, either using wired or wireless connectivity. In most
Enterprise environments and also at home, wireless communication is getting more and
more common for end users, but for the majority of other network devices, Ethernet is
the basis of all Enterprise communication.
The TCP/IP Link layer contains Ethernet and other protocols that computers use to
deliver data to the other computers and devices that are attached to the network. Unlike
higher level protocols, the Link layer protocols must understand the details of the
underlying physical network, such as the protocol data units structure, and the physical
address scheme that is used. Understanding the details and constraints of the physical
network ensures that these protocols can format the data correctly so that it can be
transmitted across the network. You should keep in mind how important the physical
characteristics of the transmission medium are. They include different cables,
connectors, use of pins, electrical currents, encoding, light modulation, and the rules for
how to activate and deactivate the use of the physical medium. These characteristics
are essential in building any kind of Enterprise or home network environment.
Cisco Enterprise Architecture Model
The design of TCP/IP hides the function of the Link layer from users - it focuses on
getting data across a specific type of physical network (such as Ethernet, and so on).
But as a networking engineer designing, building, and troubleshooting Enterprise
networks, you need to understand the essential ideas:
•
•
•
Distinguishing different Ethernet media options, including the most common connectors
and cable types.
Identifying the Ethernet frame structure, media access control (MAC) addresses and
their functions.
Mastering Ethernet switches operations and duplex options.
Ethernet LAN Connection Media
To connect a switch to a LAN, you must use some sort of media. The most common
LAN media is Ethernet. Ethernet is not just a type of cable or protocol. It is a network
standard published by the Institute of Electrical and Electronics Engineers (IEEE). So
you may hear various Ethernet terms, such as Ethernet protocols, Ethernet cables,
Ethernet ports, and Ethernet switches. IEEE 802.3 and Ethernet are often used
synonymously, although they have some differences. The term Ethernet is more
common and IEEE 802.3 is usually used when referring to a specific part of the
standard such as a particular frame format. Ethernet is basically a set of guidelines that
enable various network components to work together. These guidelines specify cabling
and signaling at the physical and data link layers of the OSI model. For example,
Ethernet standards recommend different types of cabling and specify maximum
segment lengths for each type.
The names of the standards (shown in the top row of the table below) specify the
transmission speed, the type of signaling, and the type of cabling. For example, in the
standard name 1000BASE-T denotes the following:
•
•
•
1000: Specifies a transmission speed of 1000 Megabits per second (Mbps) or 1 Gigabit
per second (Gbps)
BASE: Refers to baseband signaling (which means that only Ethernet signals are
carried on the medium)
T: Represents twisted-pair cabling.
Twisted-pair cabling is a type of wiring in which two conductors are twisted together for
the purposes of canceling electromagnetic interference (EMI) from external sources.
Ethernet Media Standards
Requirement
100BASETX
100BASE-FX
1000BASET
1000BASE-SX
1000BASELX
Media
TIA
Category 5
UTP two- 62.5/125-micron
pair
multimode fiber
TIA
Category 5,
5e
UTP four- 62.5/50-micron
pair
multimode fiber
9-micron
single-mode
fiber
Requirement
•
•
•
•
•
100BASETX
100BASE-FX
1000BASET
1000BASE-SX
Maximum
Segment
Length
100 m
(328 ft)
400 m
(1312.3 ft)
100 m
(328 ft)
275 m
(62.5 microns)
550 m
(50 microns)
Connector
ISO 8877
(RJ-45)
Duplex MIC ST
ISO 8877
(RJ-45)
Optical fiber
connector
1000BASELX
5–10 km
(1.86–6.2
miles)
Optical fiber
connector
The mechanical properties of Ethernet depend on the type of physical medium:
Coaxial (not used anymore)
Twisted pair copper
Fiber optics
Ethernet was originally based on the concept of computers communicating over a
shared coaxial cable.
Copper Media
Most Ethernet networks use unshielded twisted-pair (UTP) copper cabling for short and
medium-length distances because of its low cost, when compared to fiber-optic or
coaxial cable.
Unshielded Twisted-Pair Cable
Characteristic
Value
Speed and throughput
From 10 Mbps to 40 Gbps
Average cost per node
Least expensive
Characteristic
Value
Media and connector size
Small
Maximum cable length
100 m (30 m for 40 Gbps)
Ethernet over twisted-pair technologies uses twisted-pair cables for the physical layer of
an Ethernet computer network. Twisted-pair cabling is a type of wiring in which two
conductors—the forward and return conductors of a single circuit—are twisted together
for the purposes of canceling EMI from external sources (for example, electromagnetic
radiation from UTP cables and crosstalk between neighboring pairs).
A UTP cable is a four-pair wire. Each of the eight individual copper wires in a UTP cable
is covered by an insulating material. In addition, the wires in each pair are twisted
around each other. The advantage of a UTP cable is its ability to cancel interference
because the twisted-wire pairs limit signal degradation from EMI and radio frequency
interference (RFI). To further reduce crosstalk between the pairs in a UTP cable, the
number of twists in the wire pairs varies. Cables must follow precise specifications
regarding how many twists or braids are permitted per meter.
A UTP cable is used in various types of networks. When used as a networking medium,
a UTP cable has four pairs of either 22- or 24-gauge copper wire. A UTP cable that is
used as a networking medium has an impedance of 100 ohms, differentiating it from
other types of twisted-pair wiring such as what is used for telephone wiring. A UTP
cable has an external diameter of approximately 0.43 cm (0.17 inches), and its small
size can be advantageous during installation.
Several categories of UTP cable exist:
•
•
•
•
•
•
Category 5: Capable of transmitting data at speeds of up to 100 Mbps
Category 5e: Used in networks running at speeds of up to 1000 Mbps (1 Gbps)
Category 6: Comprises four pairs of 24-gauge copper wires, which can transmit data at
speeds of up to 10 Gbps
Category 6a: Used in networks running at speeds of up to 10 Gbps
Category 7: Used in networks running at speeds of up to 10 Gbps
Category 8: Used in networks running at speeds of up to 40 Gbps
RJ-45 Connector and Jack
UTP cables are used with RJ-45 connectors. The figure shows a UTP cable with an RJ45 connector and a jack.
The RJ-45 plug is the male component, which is crimped at the end of the cable. As you
look at the male connector from the front, as shown in the figure, the pin locations are
numbered from 8 on the left to 1 on the right.
The jack is the female component in a network device, wall, cubicle partition outlet, or
patch panel. As you look at the female connector from the front, as shown in the figure,
the pin locations are numbered from 1 on the left to 8 on the right.
Power over Ethernet
Power over Ethernet (PoE) describes systems which pass electric power along with
data on Ethernet cabling. This action allows a single Ethernet cable to provide both data
connection and electric power to devices such as wireless access points, Internet
Protocol (IP) cameras, and Voice over IP (VoIP) phones, by utilizing all four pairs in the
Category 5 cable or above.
Straight-Through or a Crossover UTP Cable?
When choosing a UTP cable, you must determine whether you need a straight-through
UTP cable or a crossover UTP cable. Straight-through cables are primarily used for
connecting electrically unlike devices, and crossover cables are used for connecting
electrically like devices. For example, the receive pin is the same on like devices, so it
needs to be crossed to the transmit pin.
To tell the difference in the two types of cabling, hold the ends of the cable next to each
other with the connector side of each end facing you. The cable is a straight-through
cable if each of the eight pins corresponds to the same pin on the opposite side, as
shown in the figure. The cable is a crossover cable if some of the wires on one end of
the cable are crossed to a different pin on the other side of the cable, as shown in the
figure.
The need for crossover cables is considered legacy, because most devices now use
straight-through cables and can internally cross-connect when a crossover is required.
When automatic medium-dependent interface crossover (auto-MDIX) is enabled on an
interface, the interface automatically detects the required cable connection type (straight
through or crossover) and configures the connection appropriately. With auto-MDIX
enabled, you can use either type of cable to connect to other devices, and the interface
automatically corrects for any incorrect cabling.
The following figure shows when to use straight-through and crossover cables.
Optical Fiber
An optical fiber is a flexible, transparent fiber that is made of very pure glass (silica) and
is not much larger than a human hair. It acts as a waveguide, or "light pipe," to transmit
light between the two ends of the fiber. Optical fibers are widely used in fiber-optic
communication, which permits transmission over longer distances and at higher
bandwidths (data rates) than other forms of communication. Fibers are used instead of
metal wires because signals travel along them with less loss and with immunity to EMI.
The two fundamental components that allow a fiber to confine light are the core and the
cladding. Most of the light travels from the beginning to the end inside the core. The
cladding around the core provides confinement. The diameters of the core and cladding
are shown in the figure, but the core diameter may vary for various fiber types. In this
case, the core diameter of 9 micrometers is very small. (The diameter of a human hair is
about 50 micrometers.) The outer diameter of the cladding is a standard size of 125
micrometers. Standardizing the size means that component manufacturers can make
connectors for all fiber-optic cables.
The third element in this picture is the buffer (coating), which has nothing to do with the
confinement of the light in the fiber. Its purpose is to protect the glass from scratches
and moisture. The fiber-optic cable can be easily scratched and broken, like a glass
pane. If the fiber is scratched, the scratch could propagate and break the fiber. Another
important role of the buffer is to keep the fiber dry.
Fiber Types
The most significant difference between multimode fiber (MMF) and single-mode fiber
(SMF) is in the ability of the fiber to send light over a long distance at high bit rates. In
general, MMF is used for shorter distances at a lower bit rate than SMF. For longdistance communications, SMF is preferred. There are many variations of fiber for both
MMF and SMF.
The most significant physical difference is in the size of the core. The glass in the two
fibers is the same, and the index of refraction (a way of measuring the speed of light in
a material) between the core and the cladding changes similarly. The diameter of the
fiber cladding is also the same. However, the core is a different size, which affects the
way that the light gets through the fiber. MMF supports multiple ways for the light from
one source to travel through the fiber— which is why it is called “multimode." Each path
can be thought of as a mode.
For SMF, the possible ways for light to get through the fiber have been reduced to
one—a "single mode." It is not exactly one, but it is a useful approximation.
MMF device uses light emitting diode (LED) as light source, which facilitates short
distance transmissions. On the other hand, SMF device uses laser to generate the
signal, which provides higher transmission rates covering longer distances.
The table summarizes MMF and SMF characteristics.
MMF and SMF Characteristics
MMF Characteristics
SMF Characteristics
LED transmitter is usually used
Laser transmitter is usually used
Lower bandwidth and speed
Higher bandwidth and speed
Shorter distances
Longer distances
Less expensive
More expensive
Fiber Connector Types
An optical fiber connector terminates the end of an optical fiber. Various optical fiber
connectors are available. The main differences among the types of connectors are
dimensions and methods of mechanical coupling. Generally, organizations standardize
on one type of connector, depending on the equipment that they commonly use, or they
standardize per type of fiber (one for MMF and one for SMF). There are about 70
connector types in use today.
The three types of connectors follow:
•
•
•
Threaded
Bayonet
Push-pull
Connectors are made of the following materials:
•
•
Metal
Plastic sleeve
Here is a list of the most common types of fiber connectors and their typical uses:
•
•
•
•
•
LC: Local connector (LC) is for enterprise equipment and is commonly used on small
form-factor pluggable (SFP) modules.
SC: Subscriber connector (SC) is for enterprise equipment.
ST: Straight tip (ST) is for patch panels (for their durability).
FC: Fiber-optic connector (FC) is for patch panels and is used by service providers.
MT-RJ: Mechanical Transfer Registered Jack (MT-RJ) connector is a two-fiber
connector (transmit and receive), has a form factor and is used for enterprise
equipment.
In data communications and telecommunications applications today, small form factor
(SFF) connectors (for example, LCs) are replacing the traditional connectors (for
example, SCs) mainly to pack more connectors on the faceplate and, as a result,
reduce system footprints.
SFP and SFP+ Transceivers
The SFP transceiver modules are hot-pluggable I/O devices that plug into module
sockets. The transceiver connects the electrical circuitry of the module with the optical
or copper network. In LAN networking devices SFP modules support Ethernet speeds
up to 1 Gbps. An optical SFP transceiver module with fiber-optic LC connector is shown
in the figure.
The SFP+ transceivers are an enhanced version of SFP transceivers. In LAN
networking devices SFP+ modules support 10 Gbps Ethernet. SFP and SFP+ modules
look the same.
SFP and SFP+ modules can be used in combination with LC or RJ45 connectors.
Different Cisco networking devices support different SFP and SFP+ modules. Different
SFP and SFP+ modules also support different types and length of fiber optic cables.
You should always check the device specifications and compatibility information.
Ethernet Frame Structure
Bits that are transmitted over an Ethernet LAN are organized into frames.
Field Length (Bytes)
8
6
Typical Ethernet
Frame Field
Destination MAC
Preamble Address
46–
1500
6
2
4
Source MAC
Address
Type Payload FCS
In Ethernet terminology, the container into which data is placed for transmission is
called a frame. The frame contains header information, trailer information, and the
actual data that is being transmitted.
There are several types of Ethernet frames, while Ethernet II frame is the most common
type, and is shown in the figure. This frame type is often used to send IP packets..
The table above shows the fields of an Ethernet II frame, which are:
•
•
•
•
•
•
Preamble: This field consists of 8 bytes of alternating 1s and 0s that are used to
synchronize the signals of the communicating computers.
Destination Address (DA): The DA field contains the MAC address of the network
interface card (NIC) on the local network to which the frame is being sent.
Source Address (SA): The SA field contains the MAC address of the NIC of the
sending computer.
Type: This field contains a code that identifies the network layer protocol.
Payload: This field contains the network layer data. If the data is shorter than the
minimum length of 46 bytes, a string of extraneous bits is used to pad the field. This
field is also known as “data and padding”.
FCS: The frame check sequence (FCS) field includes a checking mechanism to ensure
that the frame of data has been transmitted without corruption. The checking
mechanism that is being used is the cyclic redundancy check (CRC).
LAN Communication Types
The three major types of network communications are:
•
•
•
Unicast: Communication in which a frame is sent from one host and is addressed to
one specific destination. In a unicast transmission, there is only one sender and one
receiver. Unicast transmission is the predominant form of transmission on LANs and
within the Internet.
Broadcast: Communication in which a frame is sent from one address to all other
addresses. In this case, there is only one sender, but the information is sent to all the
connected receivers. Broadcast transmission is used for sending the same message to
all devices on the LAN.
Multicast: Communication in which information is sent to a specific group of devices or
clients. Unlike broadcast transmission, in multicast transmission, clients must be
members of a multicast group to receive the information.
MAC Addresses
A MAC address uniquely identifies a NIC interface of a device. It is used as a link layer
address for technologies like Ethernet, Wi-Fi, and Bluetooth for communication within a
network segment. The MAC address provides the means by which data is directed to
the proper destination device. The MAC address of a device is an address that is hardcoded into the NIC, so the MAC address is also referred to as the physical address or
burned-in address or Ethernet hardware address. The MAC address is expressed as
groups of hexadecimal digits that are organized in pairs or quads.
There are different display formats, including:
•
•
•
0000.0c43.2e08
00:00:0c:43:2e:08
00-00-0C-43-2E-08
Hexadecimal (often referred to as simply hex) is a numbering system with a base of 16.
This means that it uses 16 unique symbols as digits. The decimal system that you use on
a daily basis has a base of 10, which means that it is composed of 10 unique symbols, 0
through 9. The valid symbols in hexadecimal are 0,1, 2, 3, 4, 5, 6, 7, 8, 9, A, B, C, D, E,
and F. In decimal, A, B, C, D, E, and F equal 10, 11, 12, 13, 14, and 15, respectively.
Each hexadecimal digit is 4 bits long because it requires 4 bits in binary to count to 15.
Because a MAC address is composed of 12 hexadecimal digits, it is 48 bits long. The
letters A, B, C, D, E, and F can be either upper or lower case.
A MAC address is composed of 12 hexadecimal numbers, which means it has 48 bits.
There are two main components of a MAC. The first 24 bits constitute the
Organizationally Unique Identifier (OUI). The last 24 bits constitute the vendor-assigned,
end-station address.
•
•
•
•
24-bit OUI: The OUI identifies the manufacturer of the NIC. The IEEE regulates the
assignment of OUI numbers. Within the OUI, there are 2 bits that have meaning only
when used in the destination address field:
Broadcast or multicast bit: When the least significant bit in the first octet of the MAC
address is 1, it indicates to the receiving interface that the frame is destined for all
(broadcast) or a group of (multicast) end stations on the LAN segment. This bit is
referred to as the Individual/Group (I/G) address bit.
Locally administered address bit: The second least significant bit of the first octet of
the MAC address is referred as a universally or locally (U/L) administered address bit.
Normally, the combination of the OUI and a 24-bit station address is universally unique.
However, if the address is modified locally, this bit should be set to 1.
24-bit, vendor-assigned, end-station address: This portion uniquely identifies the
Ethernet hardware.
The MAC address identifies a specific computer interface on a LAN. Unlike other kinds
of addresses that are used in networks, the MAC address should not be changed
unless there is some specific need to do so.
Frame Switching
The switch builds and maintains a table, called the MAC address table, which matches
the destination MAC address with the port that is used to connect to a node. The MAC
address table is stored in the content-addressable memory (CAM), which enables very
fast lookups. Therefore, you might see a switch’s MAC address table referred to as a
CAM table.
For each incoming frame, the destination MAC address in the frame header is
compared to the list of addresses in the MAC address table. Switches then use MAC
addresses as they decide whether to filter, forward, or flood frames. When the
destination MAC address of a received unicast frame resides on the same switch port
as the source, the switch drops the frame, which is a behavior known as filtering.
Flooding means that the switch sends the incoming frame to all active ports, except the
port on which it received the frame.
The switch creates and maintains the MAC address table by using the source MAC
addresses of incoming frames and the port number through which the frame entered the
switch. In other words, a switch learns the network topology by analyzing the source
address of incoming frames from all attached networks.
The procedure below describes a specific example, when PC A sends a frame to PC B,
and the switch starts with an empty MAC address table.
Switching Frames Procedure
Step Action
1
The switch receives a frame from PC A on port 1.
2
The switch enters the source MAC address (of PC A) and the switch port that received
the frame into the MAC table.
3
The switch checks the table for the destination MAC address (of PC B). Because the
destination address is not known, the switch floods the frame to all the ports except the
port on which it received the frame. In this example, both PC B and PC C will receive the
frame.
4
The destination device with the matching MAC address (PC B) replies with a unicast
frame addressed to PC A.
5
The switch enters the source MAC address of PC B and the port number of the switch
port that received the frame into the MAC table. The destination address of the frame
(PC A) and its associated port is found in the MAC table.
6
The switch can now forward frames between the source and destination devices (PC A
and PC B) without flooding because it has entries in the MAC table that identify the
associated ports. Not having to send to other ports is called filtering.
The switch performs learning and forwarding actions (including in situations that differ
from the example explained above), such as:
•
•
•
Learning: When the switch receives the frame, it examines the source MAC address
and incoming port number. It performs one of the following actions depending whether
the MAC address is present in the MAC address table:
No: Adds the source MAC address and port number to the MAC address table and
starts the default 300 seconds aging timer for this MAC address.
Yes: Resets the default 300 seconds aging timer.
When the aging timer expires, the MAC address entry is removed from the MAC
address table.
•
•
•
•
Unicast frames forwarding: The switch examines the destination MAC address and if
it is unicast, performs one of the following actions depending whether the MAC address
is present in the MAC address table:
No: Forwards the frame out all ports except the incoming port (referred to as unknown
unicast).
Yes: Forwards the frame out of the port from which that MAC address was learned
previously.
Broadcast or multicast frames forwarding: The switch examines the destination
MAC address and if it is broadcast or multicast, forwards the frame out all ports except
the incoming port (unless using Internet Group Management Protocol (IGMP) with
multicast, in which case it will only send the frame to specific ports).
Discovery 2: Observe How a Switch Operates
Introduction
This discovery session will let you observe how a switch maintains its MAC address
table, which it uses to control the forwarding of frames. The lab is prepared with the
devices that are represented in the topology diagram with the IP addresses, as depicted
in the table. All devices are fully configured.
Topology
Job Aids
Device Information
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today.
Personal computers (PCs) in the virtual lab environment are simulated by routers, so you
should use Cisco IOS commands to configure them or verify the configuration.
Device Information Table
Device
Characteristic
Value
PC1
IPv4 address
10.10.1.10/24
PC1
Default gateway
10.10.1.1
PC2
IPv4 address
10.10.1.20/24
PC2
Default gateway
10.10.1.1
SW1
VLAN 1 IPv4 address
10.10.1.2/24
SW1
Default gateway
10.10.1.1
SW2
VLAN 1 IPv4 address
10.10.1.3/24
SW2
Default gateway
10.10.1.1
R1
Ethernet0/0 IPv4 address
10.10.1.1/24
R1
Loopback 0 IPv4 address
10.10.3.1/24
R1
Password
Cisco123
Task 1: Observe How a Switch Operates
Activity
Step 1
First, determine the MAC addresses of the Ethernet0/0 interface on PC1, PC2, and R1.
The show interface command displays the MAC address of the interface along with a
lot of other information. To reduce the amount of output, allowing you to focus on the
line that contains the MAC address, you can pipe the show interface output to include
a filter, as shown here.
One at a time, access the console connection to PC1, PC2, and R1 and execute
the show interface command.
PC1# show interface e0/0 | include address
Hardware is AmdP2, address is aabb.cc00.7600 (bia aabb.cc00.7600)
Internet address is 10.10.1.10/24
PC2# show interface e0/0 | include address
Hardware is AmdP2, address is aabb.cc00.7700 (bia aabb.cc00.7700)
Internet address is 10.10.1.20/24
R1# show interface e0/0 | include address
Hardware is AmdP2, address is aabb.cc00.7500 (bia aabb.cc00.7500)
Internet address is 10.10.1.1/24
In the emulated environment of the lab, the MAC addresses are similar to each other.
This similarity will make it easy to distinguish them as the steps of this discovery
progress.
MAC addresses in your output may be different.
Step 2
Access the console of SW2, and enter the show mac address-table command.
On SW2, enter the following command:
SW2# show mac address-table
Mac Address Table
------------------------------------------Vlan Mac Address Type Ports
---- ----------- -------- ----1 aabb.cc00.7500 DYNAMIC Et0/1
1 aabb.cc00.7700 DYNAMIC Et0/2
Total Mac Addresses for this criterion: 2
This output is consistent with the information from the Job Aid table. The MAC address
that is associated with PC2 is seen on interface Ethernet0/2, and the MAC address that
is associated with R1 is associated with interface Ethernet0/1.
PC2 and R1 are both directly connected to SW2 and forward frames very regularly. It is
expected that their addresses will remain in the MAC address table almost constantly.
You may also see the MAC address of PC1 in the table as well.
Step 3
In this step, be prepared to press Up Arrow to use the Cisco IOS command recall
feature to quickly repeat the show mac address-table command after clearing the
MAC address table. After clearing the MAC address table, you should find that the MAC
address for PC2 and R1 (which are directly connected to SW2) will repopulate
themselves quickly.
On SW2, type the clear mac address-table dynamic command to clear the MAC
address table and use command recall to repeatedly execute the show mac addresstable command until both addresses are populated. On SW2, enter the following
commands:
SW2# clear mac address-table dynamic
SW2# show mac address-table
Mac Address Table
-------------------------------------------
Vlan Mac Address Type Ports
---- ----------- -------- ----1 aabb.cc00.7500 DYNAMIC Et0/1
1 aabb.cc00.7700 DYNAMIC Et0/2
Total Mac Addresses for this criterion: 2
If you execute the show mac address-table command very quickly, it might happen
that the MAC address table will not be populated yet. In this case, execute the
command again, until the table is populated.
The directly connected systems will populate quickly as they send Ethernet frames to
the switch.
The MAC address of PC1, which is one hop away, is not in the table yet.
Step 4
Repeat a similar process on SW1. Clear the MAC address table and then observe the
population of the table.
The MAC address of PC1 should populate in just a few seconds. On SW1, enter the
following commands:
SW1# clear mac address-table dynamic
SW1# show mac address-table
Mac Address Table
------------------------------------------Vlan Mac Address Type Ports
---- ----------- -------- ----1 aabb.cc00.7600 DYNAMIC Et0/1
Total Mac Addresses for this criterion: 1
Step 5
Generate some traffic from PC1 to R1 and PC2. This traffic will have to travel across
both SW1 and SW2. Because the MAC address of PC1 is not known to SW2 and the
MAC addresses of R1 or PC2 are not known to SW1, there will be flooding of initial
Ethernet frames. The flooding will occur too quickly to recognize it in the lab. But the
final result should be that all three endpoints (PC1, PC2, and R1) appear in the MAC
address tables of both switches.
Access the console of PC1 and ping R1.
PC1# ping 10.10.1.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
Access the console of PC1 and ping PC2.
PC1# ping 10.10.1.20
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.20, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/2/5 ms
Step 6
Access the console of SW1 and execute the show mac address-table command.
Repeat the same on SW2.
On SW1, enter the following command:
SW1# show mac address-table
Mac Address Table
------------------------------------------Vlan Mac Address Type Ports
---- ----------- -------- ----1 aabb.cc00.7500 DYNAMIC Et0/0
1 aabb.cc00.7600 DYNAMIC Et0/1
1 aabb.cc00.7700 DYNAMIC Et0/0
Total Mac Addresses for this criterion: 3
On SW2, enter the following command.
SW2# show mac address-table
Mac Address Table
------------------------------------------Vlan Mac Address Type Ports
---- ----------- -------- ----1 aabb.cc00.7500 DYNAMIC Et0/1
1 aabb.cc00.7600 DYNAMIC Et0/0
1 aabb.cc00.7700 DYNAMIC Et0/2
Total Mac Addresses for this criterion: 3
In the MAC address table of SW1, the MAC addresses of PC2 and R1 are both
associated with the Ethernet0/0 interface. Interface Ethernet0/0 is the link to SW2. Any
Ethernet frames that are destined for either of these MAC addresses must be forwarded
to SW2 for delivery.
In the MAC address table of SW2, the MAC address of PC1 is associated with the
Ethernet0/0 interface. Interface Ethernet0/0 is the link to SW1. Any Ethernet frames that
are destined for this MAC address must be forwarded to SW1 for delivery.
Duplex Communication
The term duplex communication is used to describe a communications channel that can
carry signals in both directions, as opposed to a simplex channel, which carries a signal
in only one direction. There are two types of duplex settings that are used for
communications on an Ethernet network—full duplex and half duplex.
Half Duplex
Half-duplex communication relies on a unidirectional data flow, which means that data
can go only in one direction at a time. Sending and receiving data are not performed at
the same time. Half-duplex communication is similar to communication with walkietalkies or two-way radios, in which only one person can talk at a time. Because data can
flow in only one direction at a time, each device in a half-duplex system must constantly
wait its turn to transmit data. This constant waiting results in performance issues. As a
result, full-duplex communication has replaced half-duplex communication in more
current hardware. Half-duplex connections are typically seen in older hardware such as
hubs.
Characteristics of half-duplex operation:
•
•
•
Unidirectional data flow
Legacy connectivity
Collisions may be an issue
If a device transmits while another is also transmitting, a collision occurs. Therefore,
half-duplex communication implements Ethernet Carrier Sense Multiple Access with
Collision Detection (CSMA/CD) to help reduce the potential for collisions and to detect
them when they do occur. CSMA/CD allows a collision to be detected, which causes the
offending devices to stop transmitting. Each device retransmits after a random amount
of time has passed. Because the time at which each device retransmits is random, the
possibility that they again collide during retransmission is very small.
Full Duplex
Full-duplex communication is like telephone communication, in which each person can
talk, and hear what the other person says simultaneously. In a full-duplex
communication, the data flow is bidirectional, so data can be sent and received at the
same time. The bidirectional support enhances performance by reducing the wait time
between transmissions. Ethernet, Fast Ethernet, and Gigabit Ethernet NICs sold today
offer full-duplex capability. In full-duplex mode, the collision-detection circuit is disabled.
Frames that the two connected end nodes send cannot collide because the end nodes
use two separate circuits in the network cable.
Characteristics of full-duplex operation:
•
•
•
Point-to-point only
Attached to a dedicated switched port
Requires full-duplex support on both ends
Each full-duplex connection uses only one port. Full-duplex communications require a
direct connection between two nodes that both support full duplex. If one of the nodes is
a switch, the switch port to which the other node is connected must be configured to
operate in the full-duplex mode. The primary cause of duplex issues is mismatched
settings on two directly connected devices. For example, the switch is configured for full
duplex, and the attached PC is configured for half-duplex.
The duplex Command
The duplex command is used to specify the duplex mode of operation for switch ports.
The duplex command supports the following options:
•
•
•
The full option sets the full-duplex mode.
The half option sets the half-duplex mode.
The auto option sets autonegotiation of the duplex mode. With autonegotiation enabled,
the two ports communicate to decide the best mode of operation.
The figure shows an example of duplex and speed configurations on the Fast Ethernet
interfaces of two switches. To prevent mismatch issues, the settings on each interface
are configured to match the settings of the directly connected interfaces. For example,
Fa0/5 interface on SwitchX and Fa0/3 on SwitchY are configured to autonegotiate
speed and duplex settings with the connected PC. The Fa0/1 interface on SwitchX that
is connected to SwitchY is configured for full duplex and speed 100 Mbps, which is the
same as the configuration on Fa0/1 interface on SwitchY
For 100BASE-FX ports, the default option is full, and they cannot autonegotiate.
100BASE-FX ports operate only at 100 Mbps in full-duplex mode. For Fast Ethernet and
10/100/1000 ports, the default option is auto. The 10/100/1000 ports operate in either
half-duplex or full-duplex mode when their speed is set to 10 or 100 Mbps, but when
their speed is set to 1000 Mbps, they operate only in the full-duplex mode.
Autonegotiation can at times produce unpredictable results. By default, when
autonegotiation fails, a Cisco Catalyst switch sets the corresponding switch port to halfduplex mode. Autonegotiation failure occurs when an attached device does not support
autonegotiation. If the attached device is manually configured to also operate in the halfduplex mode, there is no problem. However, if the device is manually configured to
operate in the full-duplex mode, there is a duplex mismatch. A duplex mismatch causes
late collision errors at the end of the connection. To avoid this situation, manually set
the duplex parameters of the switch to match the attached device.
In the example above, the switch ports connected to the PCs are configured for
autonegotiation, since the PC's network card supports autonegotiation. The
interconnection ports between the switches have static configuration to avoid
autonegotiation failures if someone connects a device that only does 10 Mbps, or a hub.
You can use the show interfaces command in the privileged EXEC mode to verify the
duplex settings on a switch. This command displays statistics and statuses for all
interfaces or for the interface that you specify. The following example shows the duplex
and speed settings of a Fast Ethernet interface.
SwitchX# show interfaces FastEthernet0/5
FastEthernet0/5 is up, line protocol is up (connected)
Hardware is Fast Ethernet, address is 0022.91c4.0e01 (bia 0022.91c4.0e01)
MTU 1500 bytes, BW 100000 Kbit, DLY 100 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Full-duplex, 100Mb/s, media type is 10/100BaseTX
input flow-control is off, output flow-control is unsupported
<... output omitted ...>
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
7289 packets input, 927927 bytes, 0 no buffer
Received 184 broadcasts (1380 multicasts
0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 watchdog, 1380 multicast, 0 pause input
0 input packets with dribble condition detected
39965 packets output, 7985339 bytes, 0 underruns
0 output errors, 0 collisions, 1 interface resets
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier, 0 PAUSE output
0 output buffer failures, 0 output buffers swapped out
Starting a Switch
Introduction
In every Enterprise environment. switches are located in the heart of the network and
link together all the other equipment, so it’s very important that they are configured
correctly. It all begins with proper physical installation and then the basic configuration –
specifying the hostname, enabling the management interface, assigning an Internet
Protocol (IP) address, and configuring the default gateway and interface descriptions.
Once you have managed to configure one Cisco switch, it is relatively simple to
duplicate the process and configure more switches in a similar way. You can even copy
a standard configuration from one switch to another with only minor changes. But if
something goes wrong, it’s also important to recognize that there are issues. With
switches, you can recognize that from the light-emitting diode (LED) indicators.
Cisco Enterprise Architecture Model
As a network engineers it is important that you master the basic processes of starting a
switch:
•
•
•
•
•
Review the general requirements for a physical switch installation
Read switch LED indicators to recognize the status of a switch
Access a switch command-line interface (CLI).
Become familiar with CLI configuration commands.
Review the show commands, which enable you to verify the status of the switch.
Switch Installation
Before you physically install a Catalyst switch, you must have the correct power and
operating environment. When you have correctly connected the power cable, the switch
will turn on, if there is no on/off power button, which is the case on the Catalyst switch
shown in the figure.
This figure depicts an example of Cisco Catalyst switch, while the number and type of
ports and other connections on Cisco switches may vary.
Physical installation and startup of a Catalyst switch requires completion of these steps:
1. Before performing physical installation, verify the following:
o Switch power requirements
o Switch operating environment requirements (operational temperature and humidity)
2. Use the appropriate installation procedures for rack mounting, wall mounting, or table or
shelf mounting.
3. Before starting the switch, verify the network cables that provide connectivity to end
devices to the local-area network (LAN).
4. Attach the power cable plug to the power supply socket of the switch. The switch will
start. Some Catalyst switches do not have power buttons.
5. Observe the boot sequence:
o When the switch is on, power-on self test (POST) begins. During POST, the switch LED
indicators blink while a series of tests determines that the switch is functioning properly.
o The Cisco IOS Software output text is displayed on the console.
When all startup procedures are finished, the switch is ready to configure.
Connecting to a Console Port
Unlike a computer host, Cisco switches do not have a keyboard, monitor, or mouse
device to allow direct user interaction. Upon initial installation, you can configure the
switch from a personal computer (PC) that is connected directly through the console
port on the switch.
Cisco devices traditionally have an RJ-45 connector on their serial console port. On
newer Cisco network devices, a Universal Serial Bus (USB) serial console connection is
also supported. An appropriate console cable is typically included with the Cisco device.
Since modern computers and notebooks rarely include built-in serial ports, you may
also need an adapter.
On devices with two console ports, only one console port can be active at a time. When
a cable is plugged into the USB console port, the RJ-45 port becomes inactive. When the
USB cable is removed from the USB port, the RJ-45 port becomes active.
You need the following equipment to access a Cisco device through its console port:
•
•
•
•
•
•
•
The appropriate cable and adapters, depending on the console port you use and the
connectors on your PC (such as an RJ-45-to-DB-9 console cable, a USB-to-DB-9
adapter, a USB Type A-to-5-pin, mini-Type B, or USB-C to RJ-45 console cable).
PC or equivalent with a serial or USB port, an operating system device driver, and
terminal emulator software, such as HyperTerminal or Tera Term, configured with these
settings, as required by the switch or router:
Speed: 9600 bps
Data bits: 8
Parity: None
Stop bit: 1
Flow control: None
The console port can be located in various places on different switches.
When a console connection is established, you gain access to user EXEC mode by
default.
Switch LED Indicators
Typically, before turning on a device, you need to plug it in. However, some Cisco
switches do not have power switches, so when you plug them in, they power up
automatically. Because of this fact, you should make sure that the console cable is
connected and the terminal program running before you plug in the switch for the first
time. This preparation will allow you to monitor the boot process of the switch. As the
switch powers on, it begins POST, which is a series of tests that run automatically to
ensure that the switch functions properly. Ensuring the switch passes POST is the first
step of deploying a switch.
When you need to examine how a switch is working or to verify its status and to
troubleshoot any problems, you usually use commands from Cisco Internetwork
Operating System (IOS) CLI. However, the switch hardware includes several LEDs that
provide some status and troubleshooting information. Generally, when the Cisco switch
is functioning normally, the LEDs are lit in green, and if there is a malfunction, the LEDs
are lit in amber.
The following figure shows the front of a typical Cisco switch with six LEDs on the left,
one LED over each port, and a mode button.
LED Status
Letter
in
Figure Name
Description
A
SYST
Shows the overall system status.
B
RPS
Shows the status of the extra (redundant) power supply.
C
STAT
If on (green), each port LED represents the status of this port.
D
If on (green), each port LED represents the duplex of this port (on is fullDUPLX duplex; off means half-duplex).
E
If on (green), each port LED represents the speed of this port, as follows:
Off means 10 Mbps; Solid green means 100 Mbps; Flashing green means 1
SPEED Gbps.
F
PoE
Some switches have a PoE LED in the system status group of LEDs. If on
(green), each port LED indicates if the port is supplying PoE.
G
A button that cycles the meaning of the port LEDs (H) through four states
MODE (STAT, DUPLX, SPEED, PoE).
H
Port
Different meanings, depending on the port mode as toggled using the mode
button.
To help make sense of the LEDs, consider the example of the SYST LED for a moment.
This LED provides a quick overall status of the switch with three simple states on most
Cisco switches:
•
•
•
Off: The switch is not powered on.
On (green): The switch is powered on and operational. Cisco IOS Software has been
loaded.
On (amber): The switch POST process failed, and the Cisco IOS Software did not load.
So, just looking at the SYST LED on the switch tells you whether the switch is working
and, if it is not, whether this issue is due to the loss of power (the SYST LED is off) or
some kind of POST problem (the LED is amber).
Basic show Commands and Information
After you log into a Cisco switch, you can verify the switch software and hardware
status by using several commands that you execute from privileged EXEC mode. These
commands include the show interfaces, show version, and show runningconfigcommands. Here is a look at each of these commands in more detail.
Switch show interfaces Command
The show interfaces command displays the status and statistical information for the
network interfaces of the switch. The resulting output varies, depending on the network
for which a particular interface has been configured. You usually enter this command
with the options type and slot/number. The type option allows values such as
FastEthernet and GigabitEthernet. The slot/number option indicates the slot number
and the port number on the selected interface (for example, fa0/1).
SwitchX# show interfaces FastEthernet 0/1
FastEthernet0/1 is up, line protocol is up (connected)
Hardware is Fast Ethernet, address is 001e.147c.bd01 (bia 001e.147c.bd01)
MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Full-duplex, 100Mb/s, media type is 10/100BaseTX
input flow-control is off, output flow-control is unsupported
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:00, output 00:00:00, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 31000 bits/sec, 33 packets/sec
5 minute output rate 28000 bits/sec, 31 packets/sec
11369 packets input, 1326880 bytes, 0 no buffer
Received 317 broadcasts (317 multicasts)
0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 watchdog, 317 multicast, 0 pause input
0 input packets with dribble condition detected
21701 packets output, 2538278 bytes, 0 underruns
--More--
The table shows some of the fields in the example display that you will find useful for
verifying fundamental switch details:
Fundamental Switch Details
Output
Description
Indicates the status of the interface. The first part is the hardware status, and
the second part is the line protocol. The hardware status is the status of the
OSI physical layer, and the line protocol is the status of the OSI data link
FastEthernet0/1 layer; Together the two are the status of the TCP/IP link layer. In this
is up, line
example, the entire link layer is active and ready; In other words, the interface
protocol is up can send and receive frames. This state is referred to as “up/up.” Note that if
(connected)
the hardware is down, the line protocol will also be down.
Hardware is
Fast Ethernet,
address is
001e.147c.bd01 Indicates the Media Access Control (MAC) address of the interface.
Full-duplex,
100 Mbps
Shows the type and mode of connection. Other possibilities include halfduplex and 10 Mbps.
5-minute input
rate, 31,000 bps Reports interface traffic statistics for average input rate.
The show interfaces and show ip interface brief commands are used
frequently when you configure and monitor network devices. You will see
the show ip interface brief command in the upcoming Discovery lab.
Switch show version Command
You can use the show version Cisco IOS command in privileged EXEC mode to verify
the Cisco IOS software version and release numbers of the Cisco IOS Software that is
running on a Cisco switch.
SwitchX# show version
Cisco IOS Software, C2960 Software (C2960-LANBASEK9-M), Version
15.0(1)SE3, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2012 by Cisco Systems, Inc.
Compiled Wed 30-May-12 14:26 by prod_rel_team
ROM: Bootstrap program is C2960 boot loader
BOOTLDR: C2960 Boot Loader (C2960-HBOOT-M) Version 12.2(44)SE6, RELEASE
SOFTWARE (fc1)
SwitchX uptime is 15 hours, 30 minutes
System returned to ROM by power-on
System restarted at 15:06:49 UTC Tue Aug 21 2012
System image file is "flash:/c2960-lanbasek9-mz.150-1.SE3/c2960-lanbasek9mz.150-1.SE3.bin"
cisco WS-C2960-24TT-L (PowerPC405) processor (revision D0) with
65536K bytes of memory.
Processor board ID FOC1141Z8YW
Last reset from power-on
1 Virtual Ethernet interface
24 FastEthernet interfaces
2 Gigabit Ethernet interfaces
The password-recovery mechanism is enabled.
<... output omitted ...>
The following table describes some of the output fields of the show version command:
Output Fields from the show version Command
Output
Description
Identification of the software by name and version number
Cisco IOS
Software
version
Always specify the complete version number when reporting a possible
software problem. In this example, the switch is running Cisco IOS Release
15.0(1)SE3.
Current days and time since the system was last booted
Switch uptime In this example, the switch uptime is 15 hours and 30 minutes.
System image
file
System image name and file location (local or remote filesystem)
Switch
platform
Hardware platform information, including revision and amount of RAM
Processor
board ID
Device serial number
Switch show running-config Command
The show running-config command displays the current running (active) configuration
file of the switch. This command requires privileged EXEC mode access. This command
displays the IP version 4 (IPv4) address, subnet mask, and default gateway settings, if
they are configured:
SwitchX# show running-config
Building configuration...
Current configuration: 1750 bytes
!
! Last configuration change at 08:51:52 UTC Wed Aug 22 2012
! NVRAM config last updated at 06:26:14 UTC Wed Aug 22 2012
!
version 15.0
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname SwitchX
<... output omitted ...>
interface FastEthernet0/1
<... output omitted ...>
interface Vlan1
ip address 172.20.137.5 255.255.255.0
!
ip default-gateway 172.20.137.1
<... output omitted ...>
Discovery 3: Perform Basic Switch Configuration
Introduction
This activity will guide you through the initial configuration of a switch with Cisco IOS
Software. The lab is prepared with the devices that are represented in the topology
diagram, with the IPv4 addresses depicted in the table. Note that PC1, PC2, SW2, and
R1 are fully configured. In this discovery session, your task will be to provide an initial
configuration for SW1. During the session, you will configure and verify each of the
following settings on SW1:
•
•
•
•
Hostname
IPv4 address
IPv4 address of default gateway
Interface descriptions on the interfaces connecting to PC1 and SW2
You will also verify switch settings by using different show commands.
Topology
Job Aids
Device Information
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today.
Personal computers (PCs) in the virtual lab environment are simulated by routers, so you
should use Cisco IOS commands to configure them or verify the configuration.
Device Information Table
Device
Characteristic
Value
PC1
IPv4 address
10.10.1.10/24
PC1
Default gateway
10.10.1.1
PC2
IPv4 address
10.10.1.20/24
Device
Characteristic
Value
PC2
Default gateway
10.10.1.1
SW1
VLAN 1 IPv4 address
10.10.1.2/24
SW1
Default gateway
10.10.1.1
SW2
VLAN 1 IPv4 address
10.10.1.3/24
SW2
Default gateway
10.10.1.1
R1
Ethernet0/0 IPv4 address
10.10.1.1/24
R1
Loopback 0 IPv4 address
10.10.3.1/24
R1
Password
Cisco123
Task 1: Configure a Switch from the Command Line
Activity
Step 1
Access the console of SW1 and use the enable command to access the privileged
EXEC mode.
On SW1, enter the following command:
Switch> enable
Switch#
There is no password configured on the switch.
You can use unambiguous abbreviations for commands, such as en. You can also take
advantage of tab completion using something like en<tab>.
The change of the last character in the prompt from > to # is an indication that you have
successfully accessed privileged mode.
Step 2
Enter the global configuration mode using the configure terminal command.
On SW1, enter the following command:
Switch# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)#
The change in prompt to include (config) indicates that you are now in the global
configuration mode.
Step 3
Set the hostname of the switch to SW1 by using the hostname command.
On SW1, enter the following command:
Switch(config)# hostname SW1
SW1(config)#
The prompt reflects the hostname.
Step 4
In this topology, only VLAN 1 is in use. Set the IPv4 address that SW1 uses on VLAN 1
to 10.10.1.2 with the subnet mask 255.255.255.0. To do so, you will have to enter the
interface configuration mode and use the ip address command. You will also need to
enable the interface with the no shutdown command.
The VLAN 1 or Virtual Local Area Network (VLAN) 1 interface is assigned an IPv4
address. IP addresses are not required on the switch to forward Ethernet frames.
Assigning an IP address allows the network administrator to remotely access, log into
the switch over the network using SSH similar to logging into a server. This is a virtual
interface on the switch, not a physical interface.
A subnet mask is required to be configured when configuring the IPv4 address; it
indicates to the device which bits in the address represent the network, subnetwork, and
host fields.
On SW1, enter the following command:
SW1(config)# interface vlan 1
SW1(config-if)# ip address 10.10.1.2 255.255.255.0
SW1(config-if)# no shutdown
Again, the prompt changes as you move through the hierarchy of CLI modes. The
prompt includes config, indicating that you are in the global configuration mode. On the
other hand, config-if indicates that you are in the interface configuration mode.
Step 5
Next, set the SW1 default gateway to 10.10.1.1. You do this action from the global
configuration mode. Use the exit command to return to the global configuration mode,
then use the ip default-gateway command appropriately.
The default gateway on a switch is similar to the default gateway address on any enddevice. The default gateway is the address of a router to which the switch will send
packets when it is communicating with devices on other networks. In this example, the
default gateway is R1’s IPv4 address.
On SW1, enter the following command:
SW1(config-if)# exit
SW1(config)# ip default-gateway 10.10.1.1
Again, the prompt changes as you move through the hierarchy of CLI modes. The
prompt includes config, indicating that you are in the global configuration mode.
Step 6
Finish the configuration requirements by setting the descriptions on interfaces Ethernet
0/0 and Ethernet 0/1, which are links to SW2 and PC1, respectively.
The description command is available in the interface configuration mode.
On SW1, enter the following command:
SW1(config)# interface ethernet 0/0
SW1(config-if)# description Link to SW2
SW1(config-if)# interface ethernet 0/1
SW1(config-if)# description Link to PC1
You do not need to issue the exit command before going to other configuration modes,
as shown in this example.
Step 7
SW1 is now properly configured. Leave configuration mode and return to privileged
EXEC mode.
On SW1, enter the following command:
SW1(config-if)# end
SW1#
You can accomplish the same thing in several ways within Cisco IOS Software. Instead
of using the end command to go from interface configuration mode all the way back to
privileged EXEC, you could also have used the exit command twice or simply
pressed Ctrl-Z.
Task 2: Verify the Switch Initial Startup Status
Activity
This activity assumes that you have just finished configuration of the following settings
on SW1:
•
•
•
•
Hostname
IPv4 address
IPv4 address of default gateway
Interface descriptions on the interfaces connecting to PC1 and SW2
You will now verify these settings on SW1. Consult the topology diagram and
configuration specifications table for the complete connectivity and configuration details.
Note that PC1, PC2, SW2, and R1 were already fully configured. In this discovery task,
you will focus solely on SW1. But feel free to explore the other devices on your own.
Step 1
On SW1, verify the correct IPv4 address configuration on interface VLAN1. To verify
proper IPv4 configuration, you have several options. Often, these include directly
viewing the configuration, showing operational status, and verifying behavior. You will
utilize all three methodologies here.
One way that you can verify that the configuration is by simply viewing it with the show
running-config command. You can pare down the output of this command by piping it
to the include or section filter. But, because viewing the configuration of a particular
interface is a common exercise, you can specify an interface directly to the show
running-config command. Give the following a try on SW1.
SW1# show running-config interface vlan 1
Building configuration...
Current configuration : 59 bytes
!
interface Vlan1
ip address 10.10.1.2 255.255.255.0
end
The default settings are not displayed when using the show running-config command,
including the no shutdowncommand previously issued for the interface VLAN1.
Another way to verify the IPv4 address configuration is by viewing the status of
interfaces. Use the show ip interface briefcommand to see the status of interface
VLAN1. Verify that it is up and that the IPv4 address is correct.
SW1# show ip interface brief
Interface IP-Address OK? Method Status Protocol
<... output omitted ...>
Vlan1 10.10.1.2 YES manual up up
You might find that looking at the configuration or at system status is useful, but often
the most satisfying method is to verify the system behavior. If the interface has been
properly configured, you should be able to ping other IPv4 addresses on the local
subnet. Try to ping PC1, PC2, and R1.
SW1# ping 10.10.1.10
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.10, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/2/5 ms
SW1# ping 10.10.1.20
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.20, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
SW1# ping 10.10.1.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/202/1009 ms
The ping command will send five Internet Control Message Protocol (ICMP) echo
requests and wait for a reply after each request. A period (.) indicates a timeout on the
reply. An exclamation point (!) indicates that the reply was received.
It is common for a timeout to occur on the first echo request, but you may not see it. It
happens when the local system does not have an entry in its Address Resolution
Protocol (ARP) table for the remote system.
A ping can provide rudimentary performance indications. Timeouts are obviously bad,
but the command also displays response time statistics for the replies that were
received.
Step 2
Now verify that the default gateway is configured appropriately. Again, you have
multiple options.
View the running configuration, including only lines that include the string "default."
On SW1, enter the following command:
SW1# show running-config | include default
ip default-gateway 10.10.1.1
Besides looking at the configuration, you can verify the status. Use the show ip
route command to view the IP routing table of SW1.
SW1# show ip route
Default gateway is 10.10.1.1
Host Gateway Last Use Total Uses Interface
ICMP redirect cache is empty
Again, you can also verify system behavior. If your default gateway is properly set, you
should be able to ping IPv4 addresses on remote subnets. Try to ping address
10.10.3.1, which is on the other side of R1. SW1 will use its default gateway to get to
any address not on its local subnet.
SW1# ping 10.10.3.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.3.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/203/1012 m
Step 3
The last thing to verify is the description on the appropriate interfaces. You should have
configured descriptions on both Ethernet 0/0 and Ethernet 0/1. As usual, there are
multiple strategies that you can use for verification.
View the running configuration, but use the section filter to view sections that include the
"0/0" string. Repeat this action for the "0/1" string.
On SW1, enter the following command:
SW1# show running-config | section 0/0
interface Ethernet0/0
description Link to SW2
duplex auto
SW1# show running-config | section 0/1
interface Ethernet0/1
description Link to PC1
duplex auto
Verify the system status by using the show interface status command.
SW1# show interfaces status
Port Name Status Vlan Duplex Speed Type
Et0/0 Link to SW2 connected trunk auto auto unknown
Et0/1 Link to PC1 connected 1 auto auto unknown
<... output omitted ...>
Implement the Initial Switch Configuration
FASTLab 1: Implement the Initial Switch Configuration
Introduction
Read the requirements in the Scenario carefully and use the Configuration Tips to help
you do the required steps. If you need further assistance, refer to the Answer Key. Once
you have completed the configuration specified, answer the questions.
A law firm contracted CCS to install a switch that supports an administration desktop
AdminPC and a file server Fileserver.
The contract requires you to configure the following:
•
•
•
•
•
Hostname as "SW1" for the switch.
Enable interface VLAN 1 and configure the switch management IPv4 address on this
interface, with the correct subnet mask.
The default gateway for the switch SW1 should be 172.16.130.3.
The interface on the switch that is connected to AdminPC should be configured with
description—Link to AdminPC.
The interface on the switch that is connected to Fileserver should be configured with
description—Link to Fileserver.
You must complete the initial configuration of the switch to meet the requirements of the
contract.
The AdminPC has been preconfigured with IPv4 address 172.16.130.5 and subnet mask
255.255.255.0, and the Fileserver has been preconfigured with IPv4 address
172.16.130.6 and subnet mask 255.255.255.0.
Topology
Job Aid
If you shut down an interface on a real router or switch, the connected device will see it
as "down/down." Due to virtualization specifics, Cisco IOL (Cisco IOS Software on
Linux) behavior is slightly different. In the simulated lab environment, if you shut down
an interface on a router or switch, the connected device will see it as "up/up." In Cisco
IOL, the status of an interface can only be "up/up" or "administratively down/down."
Device Connections
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today.
Device Connections
Device
Interface
Connects to
Neighbor Interface
SW1
E0/1
R1
E0/0
SW1
E0/2
AdminPC
E0/0
SW1
E0/3
Fileserver
E0/0
IP Addressing
Device IP Address Information
Device
Interface
IPv4 Address
SW1
VLAN 1
172.16.130.10 255.255.255.0
Router
E0/0
172.16.130.3 255.255.255.0
AdminPC
E0/0
172.16.130.5 255.255.255.0
Fileserver
E0/0
172.16.130.6 255.255.255.0
The default gateway address is 172.16.130.3 for the SW1 switch, which is the IPv4
address on interface E0/0 on the Router.
Configuration Tips
•
•
To assign the hostname to the switch, enter the global configuration mode of the switch
and configure the hostname as SW1.
For remote management of a switch, an IP address must be assigned to a VLAN
interface on the switch. To assign an IPv4 address to the switch, configure IPv4 address
172.16.130.10 and subnet mask 255.255.255.0, as mentioned in the topology diagram
for interface VLAN 1, and enable interface VLAN 1. Don’t forget to enable the VLAN
interface.
•
•
•
Similar to any other host device, a switch must have a default gateway to reach the
devices that are not connected to the same subnet to forward the IP packets to the
destinations on the other networks. The default gateway is the address of the router
interface that is directly connected to the switch. The default gateway address must be
configured in the global configuration mode of the switch.
Identify the interface on the switch that is connected to the AdminPC, and configure the
interface with the "Link to AdminPC" description. To configure the description for an
interface, use the description command at the interface level.
Identify the interface on the switch that is connected to the file server and configure the
interface with the "Link to Fileserver" description. The contract requires that the link to
the file server must have a description: Link to Fileserver. To configure the description
for an interface, use the description command at the interface level.
Answer Key
You need to complete the following tasks:
•
•
Configure the hostname as "SW1" on the switch.
In order to assign the hostname to the switch, enter the global configuration mode of the
switch and configure the hostname as SW1.
Switch(config)# hostname SW1
•
•
Enable interface VLAN 1 and configure the switch management IPv4 address on this
interface, with the correct subnet mask.
For remote management of a switch, an IP address must be assigned to a VLAN
interface on the switch. To assign an IPv4 address to the switch, configure IPv4 address
172.16.130.10 and subnet mask 255.255.255.0, as mentioned in the topology diagram
for interface VLAN 1.
SW1(config)# interface vlan 1
SW1(config-if)# ip address 172.16.130.10 255.255.255.0
SW1(config-if)# no shutdown
•
•
Configure the default gateway for the switch SW1 to be 172.16.130.3.
Similar to any other host device, a switch must have a default gateway to reach the
devices that are not connected to the same segment in order to forward the IP packets
to the destinations on the other networks. The default gateway is the address of the
router interface that is directly connected to the switch. The default gateway address
must be configured in the global configuration mode of the switch
SW1(config)# ip default-gateway 172.16.130.3
•
•
Identify the interface on the switch that is connected to the AdminPC, and configure the
interface with the "Link to AdminPC" description.
The contract requires that the link to the AdminPC must have a description: Link to
AdminPC. Use the topology diagram to identify the port that the AdminPC is connected
to (Ethernet0/2). To configure the description for an interface, use
the description command at the interface level.
SW1(config)# interface e0/2
SW1(config-if)# description Link to AdminPC
•
•
Identify the interface on the switch that is connected to the file server and configure the
interface with the "Link to Fileserver" description.
The contract requires that the link to the file server must have a description: Link to
Fileserver. To configure the description for an interface, use the description command
at the interface level.
SW1(config)# interface e0/3
SW1(config-if)# description Link to Fileserver
Introducing the TCP/IP Internet Layer, IPv4
Addressing, and Subnets
Introduction
In every Local Area Network (LAN), Ethernet is used to exchange data locally. But if you
want to communicate between different LANs, for example, if a user in an Enterprise
Campus wants to communicate with a user at a Remote Site or globally, with a web
server for example, this exchange will cross many different physical networks and
devices. For communication to happen, you need an addressing system that uniquely
identifies every device globally and enables delivery of packets between them. The
delivery function is provided by the Transmission Control Protocol / Internet Protocol
(TCP/IP) Internet Layer, which provides services to exchange the data over the network
between identified end devices.
The most used protocol in the TCP/IP Internet layer is IP version 4 (IPv4), which uses
32-bit numbers. Remembering 32-bit IPv4 addresses would be cumbersome, so the
address is represented as a dotted decimal notation. As a networking engineer you will
need to be able to use simple math to convert between the binary and decimal world.
The IPv4 address, which identifies the device on the network, is typically accompanied
by a subnet mask, which defines the network.
Working as a network engineer, you will also manipulate the subnet mask to create
subnetworks for network segments of different sizes. This activity is called subnetting.
Subnetting allows you to create multiple logical networks that exist within a single larger
network, which is especially important in large Enterprise environments where you need
to logically organize your environment. And you can do this very efficiently – by using a
more advanced subnetting technique called variable-length subnet mask (VLSM).
Cisco Enterprise Architecture Model
As a network engineer, you will encounter different features of TCP/IP Internet layer in
every day work, which will include various details:
•
•
•
•
•
Describing IPv4, including IPv4 addressing and its general characteristics.
Mastering IPv4 address representation, its structure (network and the host portion of
addresses), and the IPv4 address fields.
Distinguishing address classes and the types of reserved IPv4 addresses, with focus on
relevant types (network address, broadcast address).
Demonstrate your knowledge of subnetting and VLSM.
Verify IPv4 settings on end host devices.
Internet Protocol
The IP component of Transmission Control Protocol (TCP) determines where packets of
data are routed, based on their destination addresses. IP has certain characteristics that
are related to how it manages this function.
IP uses packets to carry information through the network. A packet is a self-contained,
independent entity that contains data and sufficient information to be routed from the
source to the destination without reliance on previous packets.
IP has these characteristics:
•
•
•
•
•
•
•
•
IP operates at Layer 3 or the network layer of the Open Systems Interconnection (OSI)
reference model (network layer) and at the Internet layer of the TCP/IP stack.
IP is a connectionless protocol, in which a one-way packet is sent to the destination
without advance notification to the destination device. The destination device receives
the data and does not return any status information to the sending device.
Each packet is treated independently, which means that each packet can travel a
different way to the destination.
IP uses hierarchical addressing, in which the network identification (ID) is the equivalent
of a street, and the host ID is the equivalent of a house or an office building on that
street.
IP provides service on a best-effort basis and does not guarantee packet delivery. A
packet can be misdirected, duplicated, or lost on the way to its destination.
IP does not provide any special features that recover corrupted packets. Instead, the
end systems of the network provide these services.
IP operates independently of the medium that is carrying the data.
There are two types of IP addresses: IPv4 and IP version 6 (IPv6), the latter becoming
increasingly important in modern networks.
Example: Delivering a Letter Through a Postal Service
An analogy for IP services would be mail delivery by postal service. For example, you
live in San Francisco, and your mother lives in New York. You write three letters to your
mother. You seal each letter in a separate envelope, address each letter, and write your
return address in the upper left-hand corner of each envelope.
You deposit the three letters in the outgoing mail slot at your local post office. The
postal service makes its best attempt to deliver all three letters to your mother in New
York. However, the postal service will not guarantee that the letters will arrive at their
destination. It will not guarantee that all three letters will be processed by the same
carrier or take the same route. And it will not guarantee that the letters will arrive in the
order in which you mailed them.
Decimal and Binary Number Systems
Most people are accustomed to the decimal numbering system. The decimal (base 10)
system is the numbering system used in everyday mathematics. On the other hand, the
binary (base 2) system is the foundation of computer operations.
Network device addresses also use the binary system to define their location in the
network. IPv4 addresses are based on a dotted-decimal notation of a binary number:
four 8-bit fields (octets) converted from binary to decimal numbers, separated by dots.
An example of an IPv4 address written in a dotted-decimal notation is 192.168.10.22.
The binary equivalent of this number is 11000000.10101000.00001010.00010110. You
can use any number of bits for a binary number, but for IPv4 addresses you will always
use 8 bits when converting each of the decimal numbers to binary. You must have a
basic understanding of the mathematical properties of a binary system to understand
networking.
While the base number is important in any numbering system, it is the position of a digit
that confers value. In the decimal numbering system, the number 10 is represented by a
1 in the tens position and a 0 in the ones position. The number 100 is represented by a
1 in the hundreds position, a 0 in the tens position, and a 0 in the ones position. In the
decimal system, the digits are 0, 1, 2, 3, 4, 5, 6, 7, 8, and 9. When quantities higher than
9 are required, the decimal system begins with 10 and continues all the way to 99.
When quantities higher than 99 are required the decimal system begins again with 100,
and so on, with each column to the left raising the exponent by 1. All these tens,
hundreds, thousands and so on are all powers of 10.
For example, a decimal number 27398 represents the sum (2 x 10,000) + (7 x 1000) +
(3 x 100) + (9 x 10) + (8 x 1). If you write this with exponents the sum would look like: (2
x 104) + (7 x 103) + (3 x 102) + (9 x 101) + (8 x 100).
The binary system uses only the digits 0 and 1. Therefore, the first digit is 0, followed by
1. If a quantity higher than 1 is required, the binary system goes to 10, followed by 11.
The binary system continues with 100, 101, 110, 111, then 1000, and so on. The
following figure shows the binary equivalent of the decimal numbers 0 through 19.
Building a binary number follows the same logic as building a decimal number, with the
only difference that the base is 2 so the exponents represent the power of 2. If you take
the binary number 10011 for example, it represents a sum of (1 x 2 4) + (0 x 23) +(0 x 22)
+(1 x 21) +(1 x 20), which is equal to (1 x 16) + (0 x 8) + (0 x 4) + (1 x 2) + (1 x 1) = 19.
Binary-to-Decimal Conversion
Doing the conversion from binary into decimal is easy. Start by making a table with all of
the 2exponent values listed, for exponent values 0 through 7, as shown in the first row of
the following table. Add a row that lists the decimal value of each of these exponents, as
shown in the second row; these are the positional or place values (and are also called
placeholders). Next, write out the given bit sequence in the table, as shown in the third
row for the example binary number 10111001. Then, for each bit, multiply the place
value by the bit value, as shown in the fourth row. Notice that where the bit value is 0,
the answer is 0, and where the bit value is 1, the answer is the place value. Finally add
all of these values together; the result is the decimal value of the binary number. In this
example, the decimal value of the binary number 10111001 is 185.
BaseExponent
27
26
25
24
23
22
21
20
Place Value
128
64
32
16
8
4
2
1
Binary Number
1
0
1
1
1
0
0
1
Decimal Number (Total = 185)
128
0
32
16
8
0
0
1
10111001 = (128*1) + (64*0) + (32*1) + (16*1) + (8*1) + (4*0) + (2*0) + (1 *1)
10111001 = 128 + 0 + 32 + 16 + 8 + 0 + 0 + 1
10111001 = 185
The minimum value of an 8 bit binary number is 00000000, which in decimal equals to
0. The maximum value of an 8 bit binary number is 11111111, which in decimal equals
to 255. If you have a number that is larger than 255, it cannot be written with 8 bits.
Each of the decimal numbers an IPv4 address must be a number between 0 and 255.
Decimal-to-Binary Conversion
The process of converting a decimal number into binary can be simplified by using a
table. The table method utilizes elementary mathematics like addition and subtraction.
This process is simply and effective. With a bit of practice, you will learn it easily.
When converting from decimal into binary, the idea is to find the right sequence of bits
by marking placeholders as 1 or 0. All bits are represented, and each placeholder
marked with 1 adds its value to the converted number, while 0s are ignored. For
example, 255 is represented by marking all placeholders with 1, meaning that summing
up each placeholder value produces the decimal number: 128 + 64 + 32 + 16 + 8 + 4 +
2 + 1 = 255.
The process of converting a decimal number into binary is done by marking the closest
(lower) placeholder as 1, and subtracting the corresponding value from the decimal
number until there is no remainder. Any unused, or skipped, placeholders are marked
as 0. The binary representation of the decimal number is the 1 and 0 sequence that is
produced.
BaseExponent
27
26
25
24
23
22
21
20
Place Value
128
64
32
16
8
4
2
1
BaseExponent
27
26
25
24
23
22
21
20
Convert decimal
147 to binary
1
0
0
1
0
0
1
1
147 =
(27×1)+
(26×0)+ (25×0)+ (24×1)+ (23×0)+ (22×0)+ (21×1)+ (20×1)
147 =
(128×1)+
147 =
1+0+0+1+0+0+1+1
(16×1)+
(2×1)+
(1×1)
147 = 10010011
This figure illustrates the conversion of decimal number 147 to binary. Start by making a
table with all of the 2exponent values listed, for exponent values 0 through 7, as shown in
the first row of the table. Add a row that lists the decimal value of each of these
exponents, as shown in the second row; again these are the positional or place values
(and are also called placeholders). The binary number is put in the third row, as it is
determined. The following table describes the steps for converting the number 147 to a
binary number.
Procedure for Converting a Decimal Number to a Binary Number
Step Action
1.
Start by making a table with all of the 2exponent values listed, for exponent values 0
through 7, as shown in the first row of the table. Add a row that lists the decimal value of
each of these exponents, as shown in the second row; these are the place values.
2.
Looking at the table columns, what is the greatest power of 2 that is less than or equal to
147? 128 is less than or equal to 147, so place a 1 in the 27 = 128 column.
3.
Calculate how much is left over by subtracting 128 from 147. The result is 19.
4.
Now look for the next greatest power of 2 that is less than or equal to 19. The next place
value is 64, which is not less than or equal to 19, so place a 0 in that column.
5.
The next place value is 32, which again is not less than or equal to 19, so place a 0 in that
column as well.
Step Action
6.
The next place value is 16, which is less than or equal to 19. Place a 1 in that column.
Calculate how much is left over by subtracting 16 from 19. The result is 3.
7.
Now look for the next greatest power of 2 that is less than or equal to 3. The next place
value is 8, which is not less than or equal to 3, so place a 0 in that column.
8.
The next place value is 4, which is not less than or equal to 3, so place a 0 in that column
too.
9.
The next place value is 2, which is less than or equal to 3. Place a 1 in that column.
Calculate how much is left over by subtracting 2 from 3. The result is 1.
10.
Now look for the next greatest power of 2 that is less than or equal to 1. The next place
value (which is also the final place value) is 1, which is equal to 1, so place a 1 in the last
column.
11.
The binary equivalent of the decimal number 147 is 10010011.
You can also have a number that is smaller than 128, for example 35. 35 in decimal
converts to 00100011 in binary. Note that the first 2 bits of the binary number are zeros;
these zeros are known as leading zeros. Recall that IPv4 addresses are most often
written in the dotted-decimal notation, which consists of four sets of 8-bits (octets)
converted from binary to decimal numbers, separated by dots. For IPv4 addresses you
will always use 8 bits when converting each of the decimal numbers to binary. Some of
these binary numbers may have leading zeroes.
IPv4 Address Representation
Every device must be assigned a unique address to communicate on an IP network.
This includes hosts or endpoints (such as e personal computers (PCs), laptops,
printers, web servers, smartphones, and tablets), as well as intermediary devices (such
as routers and switches).
Physical street addresses are necessary to identify the locations of specific homes and
businesses so that mail can reach them efficiently. In the same way, logical IP
addresses are used to identify the location of specific devices on an IP network so that
data can reach those network locations. Every host that is connected to a network or
the internet has a unique IP address that identifies it. Structured addressing is crucial to
route packets efficiently. Learning how IP addresses are structured and how they
function in the operation of a network provides an understanding of how IP packets are
forwarded over networks using TCP/IP.
An IPv4 address is a 32-bit number, is hierarchical and consists of two parts:
•
•
The network address portion (network ID): Network ID is the portion of an IPv4
address that uniquely identifies the network in which the device with this IPv4 address
resides. The network ID is important because most hosts on a network can directly
communicate only with devices in the same network. If the hosts need to communicate
with devices that have interfaces assigned to some other network ID, there must be a
network device—a router or a multilayer switch—that can route data between the
networks.
The host address portion (host ID): Host ID is the portion of an IPv4 address that
uniquely identifies a device on a given IPv4 network. Host IDs are assigned to individual
devices, both hosts or endpoints, and intermediary devices.
There are two versions of IP that are in use: IPv4 and IPv6. IPv4 is the most common
and is currently used on the internet. It has been the mainstay protocol since the 1980s.
IPv6 was designed to solve the problem of global IPv4 address exhaustion. The adoption
of IPv6 was initially very slow, but is now reaching wider deployment.
Practical Example of an IPv4 Address
Recall that IPv4 addresses are most often written in the dotted-decimal notation, which
consists of four sets of 8-bits (octets) converted from binary to decimal numbers,
separated by dots. The following example shows an IPv4 address in decimal form
translated into its binary form, using the method described earlier.
IPv4 Header Fields
Before you can send an IP packet, there needs to be a format that all IP devices agree
on to route a packet from the source to the destination. All that information is contained
in the IP header. The IPv4 header is a container for values that are required to achieve
host-to-host communications. Some fields (such as the IP version) are static, and
others, such as Time to Live (TTL), are modified continually in transit.
The IPv4 header has several fields. First you will learn about these four fields:
•
•
Service type: Provides information on the desired quality of service
TTL: Limits the lifetime of a packet
The TTL value does not use time measurement units. It is a value between 1 and 255.
The packet source sets the value, and each router that receives the packet decrements the
value by 1. If the value remains above 0, the router forwards the packet. If the value
reaches 0, the packet is dropped. This mechanism keeps undeliverable packets from
traveling between networks for an indefinite amount of time.
•
•
Source address: Specifies the 32-bit binary value that represents the IPv4 address of
the sending endpoint
Destination address: Specifies the 32-bit binary value that represents the IPv4
address of the receiving endpoint
Other fields in the header include:
•
•
•
•
•
•
•
•
•
•
Version: Describes the version of IP
IHL: Internet Header Length (IHL) describes the length of the header
Total Length: Describes the length of a packet, including header and data
Identification: Used for unique fragment identification
Flag: Sets various control flags regarding fragmentation
Fragment Offset: Indicates where a specific fragment belongs
Protocol: Indicates the upper-layer protocol that is used in the data portion of an IPv4
packet. For example, a protocol value of 6 indicates this packet carries a TCP segment.
Header Checksum: Used for header error detection
Options: Includes optional parameters
Padding: Used to ensure that the header ends on a 32-bit boundary
IPv4 Address Classes
Nowadays, classless addressing is predominantly used. However, to fully understand
the concepts you will learn about here, you need to understand how the ever-changing
needs dictated the evolution of addressing solutions over time.
In the early days of the internet, the standard reserved first 8 bits of an IPv4 address for
the network part and the remaining 24 bits for the host part. 24 host bits offer
16,777,214 IPv4 host addresses. It soon became clear that such address allocation is
inefficient because most organizations require several smaller networks of smaller size
rather than one network with thousands of computers. Also, most organizations need
several networks of different sizes.
The first step to address this need was made in 1981 when the Internet Engineering
Task Force (IETF) released Request for Comment (RFC) 790 where the IPv4 address
classes were introduced for the first time. Here the Internet Assigned Numbers Authority
(IANA) determined IPv4 Class A, Class B, and Class C.
RFC is a formal document from the IETF communicating information about the internet
and defining internet standards.
Assigning IPv4 addresses to classes is known as classful addressing. Each IPv4
address is broken down into a network ID and a host ID. In addition, a bit or bit
sequence at the start of each address determines the class of the address.
IPv4 hosts only use Class A, B, and C IPv4 addresses for unicast (host-to-host)
communications. In 2002, RFC 3330 introduced also Class D and Class E defining
special-use IPv4 addresses. This RFC has been later obsoleted by another RFC defining
global and other specialized IPv4 address blocks. Still, Class D and Class E are included
here for completeness, but they are outside the scope of this discussion.
Class A
A Class A address block is designed to support extremely large networks with more
than 16 million host addresses. The Class A address uses only the first octet (8 bits) of
the 32-bit number to indicate the network address. The remaining 3 octets of the 32-bit
number are used for host addresses. The first bit of a Class A address is always a 0.
Because the first bit is a 0, the lowest number that can be represented is 00000000
(decimal 0), and the highest number that can be represented is 01111111 (decimal
127). However, these two network numbers, 0 and 127, are reserved and cannot be
used as network addresses. Therefore, any address that has a value between 1 and
126 in the first octet of the 32-bit number is a Class A address.
Class B
The Class B address space is designed to support the needs of moderate to large
networks with more than 65,000 hosts. The Class B address uses two of the four octets
(16 bits) to indicate the network address. The remaining two octets specify host
addresses. The first 2 bits of the first octet of a Class B address are always binary 10.
Starting the first octet with binary 10 ensures that the Class B space is separated from
the upper levels of the Class A space. The remaining 6 bits in the first octet may be
populated with either ones or zeros. Therefore, the lowest number that can be
represented with a Class B address is 10000000 (decimal 128), and the highest number
that can be represented is 10111111 (decimal 191). Any address that has a value in the
range of 128 to 191 in the first octet is a Class B address.
Class C
The Class C address space is the most commonly available address class. This
address space is intended to provide addresses for small networks with a maximum of
254 hosts. In a Class C address, the first three octets (24 bits) of the address identify
the network portion, with the remaining octet reserved for the host portion. A Class C
address begins with binary 110. Therefore, the lowest number that can be represented
is 11000000 (decimal 192), and the highest number that can be represented is
11011111 (decimal 223). If an address contains a number in the range of 192 to 223 in
the first octet, it is a Class C address.
Class D
Class D (multicast) IPv4 addresses are dedicated to multicast applications such as
streaming media. Multicasts are a special type of broadcast, in that only hosts that
request to participate in the multicast group will receive the traffic to the IPv4 address of
that group. Unlike IPv4 addresses in Classes A, B, and C, multicast addresses are
always the destination address and never the source. A Class D address begins with
binary 1110. Therefore, the lowest number that can be represented is 11100000
(decimal 224), and the highest number that can be represented is 11101111 (decimal
239). If an address contains a number in the range of 224 to 239 in the first octet, it is a
Class D address.
Class E
Class E (reserved) IPv4 addresses are reserved by the IANA as a block of experimental
addresses. Class E IPv4 addresses should never be assigned to IPv4 hosts. A Class E
address begins with binary 1111. Therefore, the lowest number that can be represented
is 11110000 (decimal 240), and the highest number that can be represented is
11111111 (decimal 255). If an address contains a number in the range of 240 to 255 in
the first octet, it is a Class E address.
The following table shows the IPv4 address range of the first octet (in decimal and
binary) for Class A, B, C, D, and E IPv4 addresses
Class A, B, and C First Octet Binary and Decimal Ranges
IPv4
Address
Class
First Octet Binary Range
First Octet Decimal Range
Class A
00000001 to 01111110
1–126
Class B
10000000 to 10111111
128–191
Class C
11000000 to 11011111
192–223
Class D
(Multicast)
11100000 to 11101111
224–239
Class E
(Reserved)
11110000 to 11111111
240–255
Class A addresses 127.0.0.0 to 127.255.255.255 cannot be used. This range is
reserved for loopback and diagnostic functions.
Subnet Masks
A subnet mask is a 32-bit number that describes which portion of an IPv4 address
refers to the network ID and which part refers to the host ID.
The subnet mask is configured on a device along with the IPv4 address.
If a subnet mask has a binary 1 in a bit position, the corresponding bit in the address is
part of the network ID. If a subnet mask has a binary 0 in a bit position, the
corresponding bit in the address is part of the host ID.
The figure represents an IPv4 address separated into a network and a host part. In the
example the network part ends on the octet boundary, which coincides with what you
learned about IPv4 address class boundaries. The address in the figure belongs to
class B, where the first two octets (16 bits) indicate the network part, and the remaining
two octets represent the host part. Therefore, you create the subnet mask by setting the
first 16 bits of the subnet mask to binary 1 and the last 16 bits of the subnet mask to
zero.
Notice the prefix /16; it is another way of expressing the subnet mask and it matches the
number of network bits that are set to binary 1 in the subnet mask.
Networks are not always assigned the same prefix. Depending on the number of hosts
on the network, the prefix that is assigned may be different. Having a different prefix
number changes the host range and broadcast address for each network.
Calculating the Network Address
An IPv4 address that has binary zeros in all the host bit positions is reserved for the
network address. The main purpose of the subnet mask is to identify the network
address of a host, which is crucial for routing purposes. Based on the network address,
the host can identify whether a packet's destination address is within the same network
or not.
Given an IPv4 address and a subnet mask, you can calculate the network address by
using the AND function between the binary representation of the IPv4 address and the
binary representation of the subnet mask.
The calculation is performed bit-by-bit following these rules:
•
•
•
•
0 AND 0 = 0
1 AND 0 = 0
0 AND 1 = 0
1 AND 1 = 1
The result of the AND operation is the network address of the network on which the
device resides; this is also called the network prefix. You can see that in the network
address, the network part is the same as it is in the original IPv4 address while the host
bits are all set to zero.
Usually you will use the decimal form of the network address, so you need to remember
the binary to decimal conversion. Look at the next figure to remember the conversion
process.
Subnets
A lot of networks nowadays still use a so called flat network design. A flat topology is an
OSI Layer 2 – switch-connected network where all devices see all the broadcasts in the
Layer 2 broadcast domain. In such a network, all devices can reach each other by
broadcast. Flat network design is easy to implement and manage, which could reduce
cost, maintenance, and administration.
However, such design also brings some concerns:
•
•
•
•
Security: Because the network is not segmented, you can not apply security policies
adapted to individual segments. If one device is compromised, it can quickly affect the
whole network.
Troubleshooting: Isolation of network faults is more challenging especially in bigger
flat networks, because there is no logical separation or hierarchy.
Address space utilization: In a large flat network you can end up with a lot of wasted
IP addresses. You cannot use addresses from this network anywhere else.
Scalability and speed: A flat network represents a single Layer 2 broadcast domain. If
there is a large amount of broadcast traffic this can impose a considerable pressure on
the available resources. A single broadcast domain typically should not include more
than a couple of hundred devices.
To tackle those challenges, network administrators can segment their networks,
especially large networks, by using subnetworks, or subnets. Although subnets were
initially designed for solving the shortage of IPv4 addresses, in today’s networks, they
are used to address administrative, organizational, security and scalability
considerations. If you break a bigger network into smaller subnetworks, you can create
a network of interconnected subnetworks.
Imagine a company that occupies a thirty-story building divided into departments. Such
company could prepare one large network to address all the IPv4 devices. But putting a
couple of hundred or even thousands of devices into one IPv4 network would make
such a network unusable, because of the broadcast traffic, security, and troubleshooting
issues. A better approach is to create a larger number of smaller networks, based for
example on department, functional or spatial separation. For example, think of the
company as group of networks, the departments being used as subnets, and the
devices in the departments as the individual host addresses belonging to these smaller
subnets. This process of creating smaller networks out of a bigger one is called
subnetting.
A subnet segments the hosts within the network. Without subnets, the network has a flat
topology. You use routers to separate networks by breaking the network into multiple
subnets or multiple OSI Layer 3 broadcast domains.
Recall that OSI Layer 2 is the data link layer and it is equivalent to part of the TCP/IP
link layer. OSI Layer 3 is the network layer and that it is equivalent to the TCP/IP
internet layer. A Layer 2 broadcast domain is a domain in which all devices see each
other’s Layer 2 broadcast frames while a Layer 3 broadcast domain is a domain in which
all devices see each other’s Layer 3 broadcast packets.
Segmenting your network using subnets brings several advantages:
•
•
•
•
•
Smaller networks are easier to manage and map to geographical or functional
requirements.
Better utilization of IP addressing space, because you can adapt subnets sizes.
Subnetting enables you to create multiple logical networks from a single network prefix.
Overall network traffic is reduced, which can improve performance.
You can more easily apply network security measures at the interconnections between
subnets than within a large single network.
In multiple-subnetwork environments, each subnetwork may be connected to the
internet by a single router. The figure shows one router connecting multiple
subnetworks to the internet. The details of the internal network environment and how
the network is divided into multiple subnetworks are inconsequential to other IP
networks.
As you already know, an IP address has two components: the network part and the host
part. In a flat network, all device IP addresses have the same network part. When the
network is broken into subnets, the IP addressing must be modified to accommodate
the required segmentation. The IP address of each device on a newly
created subnetwork has the same network part and the same subnet part. The subnet
part is borrowed from the host part of the address.
Implementing Subnetting: Borrowing Bits
Subnetting allows you to create multiple logical networks that exist within a single larger
network. When you are designing a network addressing scheme, you need to be able to
determine how many logical networks you will need and how many devices you will be
able to fit into these smaller networks.
To subnet a network address, you will borrow host bits and use them as subnet bits.
You will use the subnet mask to indicate how many host bits have been borrowed. Bits
must be borrowed consecutively, starting with the first host bit on the left. This approach
introduces classless networks.
To implement subnets, follow this procedure:
•
•
•
•
•
•
Determine the IP address for your network as assigned by the registry authority or
network administrator.
Based on your organizational and administrative structure, determine the number of
subnets that are required for the network. Be sure to plan for growth.
Based on the required number of subnets, determine the number of bits that you need
to borrow from the host bits.
Determine the binary and decimal value of the new subnet mask that results from
borrowing bits from the host ID.
Apply the subnet mask to the network IP address to determine the subnets and the
available host addresses. Also, determine the network and broadcast addresses for
each subnet.
Assign subnet addresses to all subnets. Assign host addresses to all devices that are
connected to each subnet.
Take a look at the following figure. The top table shows a standard Class C network
address that is not subnetted. The bottom table shows the same address after it is
subnetted by borrowing one host bit. Notice that the prefix length has changed from 24
to 25. The network IPv4 address itself is unchanged, although it is now considered a
subnetwork (subnet) and is one of two subnets that have been created. The subnet
mask has changed from 255.255.255.0 in decimal to 255.255.255.128, because the 128
bit is now turned on in the last octet.
Each time that a bit is borrowed, the number of subnet addresses increases, and the
number of host addresses that are available per subnet decreases. The algorithm that is
used to compute the number of subnets and hosts uses powers of two. Therefore,
borrowing one host bit enables you to create 21 = 2 subnets, borrowing 2 bits gives you
22 = 4 subnets, and so on.
You can use the following formula to calculate the number of subnets that are created by
borrowing a given number of host bits: Number of subnets = 2s (where s is the number
of bits that are borrowed)
As the following figure shows, you can also determine how many host addresses are
available per subnet when you borrow a given number of bits. Just like on a network,
there are two addresses that are not available to be used as host addresses on a
subnet; they are used for the address of the subnet itself (with all of the host bits set to
0) and the directed broadcast address on the subnet (with all of the host bits set to 1).
The figure shows that borrowing 1 bit for subnetting the address in the example leaves
7 bits for hosts.
You can use a formula to calculate the number of host addresses that are available when
a given number of host bits are borrowed:
Number of hosts = 2h – 2 (where h is the number of host bits that are remaining after bits
are borrowed)
The formula to determine the number of hosts for this example is 2 7– 2, which
calculates to 126 host addresses per subnet.
Here is another example, using the same network, in which five host bits are borrowed
for subnetting. In this example, 25 = 32 subnets are created, and only 23 – 2 = 6 host
addresses are available for each subnet. The new subnet mask is
11111111.11111111.11111111.11111000, which equates to 255.255.255.248 in
decimal.
The following figure shows the subnetting of a Class B network address. The top table
shows a network address with the default Class B subnet mask, 255.255.0.0. The
second table shows the same address after it is subnetted by borrowing six host bits.
Notice that the prefix length has changed from 16 to 22. The network IPv4 address itself
is unchanged, but the subnet mask has changed from 255.255.0.0 in decimal to
255.255.252.0.
The next figure shows the subnetting of a Class A network address. The top table
shows a network address with the default Class A subnet mask, 255.0.0.0. The bottom
table shows the same address after it is subnetted by borrowing 8 host bits. Notice that
the prefix length has changed from 8 to 16. The network IPv4 address itself is
unchanged, but the subnet mask has changed from 255.0.0.0 in decimal to 255.255.0.0.
Implementing Subnetting: Determining the
Addressing Scheme
If a network address is subnetted, the first subnet that is obtained after subnetting the
network address is called subnet zero, because all of the subnet bits are binary zero. To
determine each subsequent subnet address, increase the subnet address by the bit
value for the last bit that you borrowed.
In the following example, 8 bits are borrowed for subnetting the network address,
172.16.0.0/16. The first subnet address is 172.16.0.0/24; this is subnet zero. The last bit
that is borrowed is the bit with the value of 1 in the third octet, so the next subnet
address is 172.16.1.0/24.
The following figure shows the first six subnets and the last subnet that are created by
borrowing the 8 bits. There are a total of 28 = 256 subnets.
Notice that the address of a subnet has all of the host bits set to binary 0. This address
is one of the reserved addresses on a subnet. The other reserved address is the subnet
directed broadcast address, in which all of the host bits are set to binary 1. All of the
addresses in between the subnet address and the subnet broadcast address are valid
host addresses on that subnet. On these subnets there are 28 – 2 = 254 host addresses
per subnet.
Here are the host addresses and broadcast addresses for those subnets.
Host Addresses and Broadcast Addresses
Subnet Address
Host Address Range
Broadcast Address
172.16.0.0
172.16.0.1–172.16.0.254
172.16.0.255
172.16.1.0
172.16.1.1–172.16.1.254
172.16.1.255
172.16.2.0
172.16.2.1–172.16.2.254
172.16.2.255
172.16.3.0
172.16.3.1–172.16.3.254
172.16.3.255
172.16.4.0
172.16.4.1–172.16.4.254
172.16.4.255
172.16.5.0
172.16.5.1–172.16.5.254
172.16.5.255
Subnet Address
Host Address Range
Broadcast Address
...
...
...
172.16.255.0
172.16.255.1–172.16.255.254
172.16.255.255
In the following figure, Class B the 172.16.0.0/16 network address has been subnetted
by borrowing two host bits. The first subnet address is 172.16.0.0/18, the zero subnet.
The last bit that is borrowed is the bit with the value of 64, so the next subnet address is
172.16.64.0/18.
The following figure shows all the subnets that are created by borrowing the 2 bits. The
subnet 172.16.192.0/18 is the last subnet because 192 + 64 = 256, and the highest
possible value for any given octet is 255. However, if the subnet goes over the octet
boundary, then you have more subnets, as you will see in a couple of minutes as you
move on to the next example.
The following table shows the valid host addresses for each subnet that was created by
borrowing 2 bits. The table shows the valid host IPv4 address range for each
subnetwork. There are 22 = 4 subnets, and 214 – 2 = 16,382 host addresses per subnet.
Valid Host Addresses for Each Subnet Created by Borrowing 2 Bits
Subnet Address
Valid Host Address Range
Broadcast Address
172.16.0.0
172.16.0.1–172.16.63.254
172.16.63.255
172.16.64.0
172.16.64.1–172.16.127.254
172.16.127.255
172.16.128.0
172.16.128.1–172.16.191.254
172.16.191.255
172.16.192.0
172.16.192.1–172.16.255.254
172.16.255.255
Here is one more example of subnetting the same /16 network address, this time
borrowing 11 host bits for subnetting. The first subnet address is 172.16.0.0/27. The
second subnet address is 172.16.0.32/27, because the last borrowed bit has a value of
32. Notice that this time, the last borrowed bit is in the fourth octet. Therefore, the
increment of 32 (the value of the last borrowed bit) is first applied in the fourth octet.
Once all the possible subnet addresses in the fourth octet have been calculated in this
manner, you move back into the third octet since you have borrowed bits from the third
octet as well. You can use all the third octet values from 1 to 255 for your subnet
addresses as well.
The following table shows the first 10 subnet addresses and the last subnet address
(with the corresponding host addresses and broadcast addresses) that result from
subnetting Class B network 172.16.0.0 by borrowing 11 host bits. There are 211 = 2048
subnets, and 25 – 2 = 30 host addresses per subnet.
Subnet Address
Host Address Range
Broadcast Address
172.16.0.0
172.16.0.1–172.16.0.30
172.16.0.31
172.16.0.32
172.16.0.33–172.16.0.62
172.16.0.63
172.16.0.64
172.16.0.65–172.16.0.94
172.16.0.95
172.16.0.96
172.16.0.97–172.16.0.126
172.16.0.127
172.16.0.128
172.16.0.129–172.16.0.158
172.16.0.159
172.16.0.160
172.16.0.161–172.16.0.190
172.16.0.191
172.16.0.192
172.16.0.193–172.16.0.222
172.16.0.223
172.16.0.224
172.16.0.225–172.16.0.254
172.16.0.255
172.16.1.0
172.16.1.1–172.16.1.30
172.16.1.31
172.16.1.32
172.16.1.33–172.16.1.62
172.16.1.63
...
...
...
172.16.255.224
172.16.255.225–172.16.255.254
172.16.255.255
Benefits of VLSM and Implementing VLSM
When you are using subnetting, the same subnet mask is applied for all the subnets of
a given network. This way, each subnet has the same number of available host
addresses. You may need this approach sometimes, but most organizations require
several networks of various sizes rather than one network with thousands of devices.
So usually, having the same subnet mask for all subnets of a given network ends up
wasting address space, because each subnet has the same number of available host
addresses.
For example, in the following figure, Class B network 172.16.0.0 is subnetted by
borrowing 8 host bits and applying a 24-bit subnet mask, which allows for 256 subnets
with 254 host addresses each. In this example, many host addresses are wasted. Each
wide-area network (WAN) link needs only two host addresses, so 252 host addresses
are wasted on each WAN link. Many host addresses are also wasted on other subnets.
Variable-length subnet mask (VLSM) provides a solution.
VLSM allows you to use more than one subnet mask within a network to achieve more
efficient use of IP addresses. Instead of using the same subnet mask for all subnets,
you can use the most efficient subnet mask for each subnet. The most efficient subnet
mask for a subnet is the mask that provides an appropriate number of host addresses
for that individual subnet. For example, subnet 172.16.6.0 has only 19 hosts, so it does
not need the 254 host addresses that the 24-bit mask allows. A 27-bit mask would
provide 30 host addresses, which is much more appropriate for this subnet.
In the next figure, the 172.16.0.0/16 network is first divided into subnetworks using a 24bit subnet mask. However, one of the subnetworks in this range, 172.16.14.0/24, is
further divided into smaller subnetworks using a 27-bit mask to accommodate the
subnets that have 19 or 28 hosts. These smaller subnetworks range from
172.16.14.0/27 to 172.16.14.224/27. Then, one of these smaller subnets,
172.16.14.128/27, is further divided using a 30-bit mask, which creates subnets with
only two hosts to be used on the WAN links. The subnets with the 30-bit mask range
from 172.16.14.128/30 to 172.16.14.156/30.
In addition to providing a solution to the problem of wasted IP addresses, VLSM has
another important benefit: support for route summarization, which is also called route
aggregation. The hierarchical addressing design of VLSM enables easier
summarization of network addresses. Route summarization reduces the number of
routes in routing tables by representing a range of network subnets in a single summary
address. Smaller routing tables require less central processing unit (CPU) time for
routing lookups.
In the previous figure, the subnet 172.16.14.0/24 describes all the addresses that are
further subnets of 172.16.14.0, including those addresses from subnet 172.16.14.0/27
to subnet 172.16.14.128/30.
VLSM is an important technology in large routed networks. VLSM can be used in all
modern networks that run classless routing protocols such as Routing Information
Protocol version 2 (RIPv2), Open Shortest Path First (OSPF), and Enhanced Interior
Gateway Routing Protocol (EIGRP). However, VLSM could not be used on a network
using legacy classful protocols such as Routing Information Protocol version 1 (RIPv1)
and Interior Gateway Routing Protocol (IGRP). Those protocols are not capable of
carrying subnet mask information on their routing updates and are no longer used in
today’s networks.
Implementing VLSM
The network 172.16.0.0 has already been subnetted by applying a 20-bit subnet mask.
One of the resulting subnet addresses, 172.16.32.0/20, is used for the region of the
enterprise network that the following figure shows. This region needs to assign
addresses to multiple LANs. Each LAN must have 50 hosts. You can use VLSM to
further subnet the address 172.16.32.0/20 to give you more subnet addresses with
fewer hosts per subnet.
The next figure shows in binary the original subnetting of the 172.16.0.0/16 network to
/20 by borrowing 4 host bits, which provided 16 subnets with 4094 host addresses each.
The figure also shows how further subnetting with VLSM increases the number of
subnets and provides the desired number of host addresses per subnet. Borrowing an
additional 6 subnet bits results in an additional 26 = 64 subnets. This leaves 6 host bits,
resulting in 26 – 2 = 62 hosts on each of these subnets.
The next figure shows the subnet addresses and host addresses that are achieved by
using VLSM. The subnet for the region in this example, subnet 172.16.32.0/20, is
further subnetted by applying a 26-bit mask as the previous figure shows.
The following figure shows some of the new VLSM subnet addresses that are applied to
the regional network.
To calculate the subnet addresses for the WAN links, further subnet one of the unused
/26 subnets with a 30-bit subnet mask. For this example, subnet 172.16.33.0/26 will be
further subnetted. Borrowing an additional 4 subnet bits results in an additional 2 4 = 16
subnets. This leaves 2 host bits, resulting in 22– 2 = 2 hosts on each of these subnets.
The following figure shows all the new VLSM subnet addresses that are applied to the
regional network.
As seen in this example, where we used VLSM to further subnet the address
172.16.32.0/20 into smaller subnets of different sizes, the easiest way to assign the
subnets is to assign the subnets with the largest number of hosts first.
Private vs. Public IPv4 Addresses
As the internet began to grow exponentially in the 1990s, it became clear that if the
current growth trajectory continued, eventually there would not be enough IPv4
addresses for everyone who wanted one. Work began on a permanent solution, which
would become IPv6, but in the interim, several other solutions were developed. These
solutions included Network Address Translation (NAT), classless interdomain routing
(CIDR), private IPv4 addressing, and VLSM.
Public IPv4 Addresses
Hosts that are publicly accessible over the internet require public IP addresses. Internet
stability depends directly on the uniqueness of publicly used network addresses.
Therefore, a mechanism is needed to ensure that addresses are, in fact, unique. This
mechanism was originally managed by the InterNIC. The IANA succeeded the InterNIC.
The IANA carefully manages the remaining supply of IPv4 addresses to ensure that
duplication of publicly used addresses does not occur. Duplication would cause
instability in the internet and would compromise its ability to deliver packets to networks
using the duplicated addresses.
With few exceptions, businesses and home internet users receive their IP address
assignment from their local internet registry (LIR), which typically is their internet service
provider (ISP). These IP addresses are called provider-aggregatable (as opposed to
provider-independent addresses) because they are linked to the ISP. If you change
ISPs, you will need to readdress your internet-facing hosts.
The following table provides a summary of public IPv4 addresses.
IPv4 Address Class
Public IPv4 Address Range
A
•
•
1.0.0.0 to 9.255.255.255
11.0.0.0 to 126.255.255.255
B
•
•
128.0.0.0 to 172.15.255.255
172.32.0.0 to 191.255.255.255
C
•
•
192.0.0.0 to 192.167.255.255
192.169.0.0 to 223.255.255.255
LIRs obtain IP address pools from their regional internet registry (RIRs):
•
•
•
•
•
African Network Information Center (AfriNIC)
Asia Pacific Network Information Center (APNIC)
American Registry for Internet Numbers (ARIN)
Latin American and Caribbean Network Information Center (LACNIC)
Réseaux IP Européens Network Coordination Centre (RIPE NCC)
With the rapid growth of the internet, public IPv4 addresses began to run out. New
mechanisms such as NAT, CIDR, VLSM, and IPv6 were developed to help solve the
problem.
Private IPv4 Addresses
Internet hosts require a globally routable and unique IPv4 address, but private hosts
that are not connected to the internet can use any valid address, as long as it is unique
within the private network. However, because many private networks exist alongside
public networks, deploying random IPv4 addresses is strongly discouraged.
In February 1996, the Internet Engineering Task Force (IETF) published RFC 1918,
"Address Allocation for Private Internets," to both ease the accelerating depletion of
globally routable IPv4 addresses and provide companies an alternative to using
arbitrary IPv4 addresses. Three blocks of IPv4 addresses (one Class A network, 16
Class B networks, and 256 Class C networks) are designated for private, internal use.
Addresses in these ranges are not routed on the internet backbone. Internet routers are
configured to discard private addresses. In a private intranet, these private addresses
can be used instead of globally unique addresses. When a network that is using private
addresses must connect to the internet, private addresses must be translated to public
addresses. This translation process is called NAT. A router is often the network device
that performs NAT.
The following table provides a summary for private IPv4 addresses.
IPv4 Address Class
Private IPv4 Address Range
A
10.0.0.0/8
B
172.16.0.0/12
C
192.168.0.0/16
Reserved IPv4 Addresses
Certain IPv4 addresses are reserved and cannot be assigned to individual devices on a
network. Reserved IPv4 addresses include a network address, which is used to identify
the network itself, and a broadcast address, which is used for broadcasting packets to
all the devices on a network.
Network Address
The network address is a standard way to refer to a network. An IPv4 address that has
binary zeros in all the host bit positions is reserved for the network address.
For example, in a Class A network, 10.0.0.0 is the IPv4 address of the network
containing the host 10.1.2.3. All hosts in 10.0.0.0 will have the same network bits. The
IPv4 address 172.16.0.0 is a Class B network address, and 192.16.1.0 is a Class C
network address. A router uses the network IPv4 address when it searches its IPv4
routing table for the destination network location.
When networks are subnetted, the IPv4 address with binary zeros in all the host bit
positions is still reserved, for the address of the subnet. For example, 172.16.1.0/24 is
the address of a subnet.
Local Broadcast Address
If an IPv4 device wants to communicate with all the devices on the local network, it sets
the destination address to all ones (255.255.255.255) and transmits the packet. For
example, hosts that do not know their network number will use the 255.255.255.255
broadcast address to ask a server for the network address. The local broadcast is never
routed beyond the local network or subnet.
Directed Broadcast Address
The broadcast IPv4 address of a network is a special address for each network that
allows communication to all the hosts in that network. To send data to all the hosts in a
network, a host can send a single packet that is addressed to the broadcast address of
the network. The broadcast address uses the highest address in the network range,
which is the address in which all of the bits in the host portion are all ones. For network
10.0.0.0/8, with 8 network bits, the broadcast address would be 10.255.255.255. This
address is also referred to as the directed broadcast.
Assuming a hypothetical network in which every IPv4 host address was in use on the
10.0.0.0/8 network, a ping to 10.255.255.255 would receive a response from all
16,777,214 hosts.
For the network address 172.16.0.0/16, the last 16 bits make up the host field (or host
part of the address). The broadcast that would be sent out to all the devices on that
network would have a destination address of 172.16.255.255.
For the network address 192.168.11.0/24, the last 8 bits make up the host field (or host
part of the address). The broadcast that would be sent out to all the devices on that
network would have a destination address of 192.168.11.255.
For the subnet address 192.168.11.32/28, the last 4 bits are the host bits, so the
directed broadcast address would be 192.168.11.47.
The directed broadcast address can be routed over your company intranet and over the
internet. In the 1990s, a popular denial-of-service (DoS) attack referred to as a Smurf
used directed broadcasts to send so much traffic to an intended victim that they could
not send or receive any legitimate traffic. For this reason, Cisco IOS Software defaults to
disallowing directed broadcasts. This capability can be restored with the ip directedbroadcast command in the global configuration mode. It is a best practice to leave
directed broadcasts disabled unless you have a specific use case. Routers began using
the no ip directed-broadcast command as a platform default starting with Cisco IOS
Release 12.0.
Local Loopback Address
A local loopback address is used to let the system send a message to itself for testing.
The loopback address creates a shortcut method for TCP/IP applications and services
that run on the same device to communicate with one another. A typical local loopback
IPv4 address is 127.0.0.1. On a Microsoft Windows host, you can ping any IPv4
address in the 127.0.0.0/8 range to test the local TCP/IP stack. This is typically done to
make sure that the system’s network software and hardware is functioning properly.
Autoconfiguration IPv4 Addresses
When neither a statically nor a dynamically configured IPv4 address is found on startup,
those hosts supporting IPv4 link-local addresses (RFC 3927) will generate an address
in the 169.254.0.0/16 range. This address can be used only for local network
connectivity and operates with many caveats, one of which is that it will not be routed.
You will mostly see this address as a failure condition when a PC fails to obtain an
address via Dynamic Host Configuration Protocol (DHCP). This feature called
Automatic Private IP Addressing (APIPA) is implemented in Microsoft and Apple Mac
operating systems.
IPv4 Addresses for Documentation
Address blocks 198.51.100.0/24 and 203.0.113.0/24 are assigned for use in
documentation and example code. They are often used along with example.com or
example.net domain names in vendor and protocol documentation. As described in
RFC 5737, addresses within these blocks do not legitimately appear on the public
internet and can be used without any coordination with IANA or an internet registry.
All Zeros Address
The address 0.0.0.0 indicates the host in "this" network and is used only as a source
address. An example use case is the DHCP assignment process before the host has a
valid IPv4 address.
For more information about reserved IPv4 addresses, refer to RFC 5735.
Verifying IPv4 Address of a Host
All operating systems that are capable of TCP/IP communications include utilities for
configuring, managing, and monitoring the IPv4 networking configuration. Operating
systems such as Microsoft Windows, Apple Mac OS X, and most Linux variants include
both CLI and GUI tools.
Verifying IPv4 Address of a Host on Windows
On a PC running Microsoft Windows 10, in the Network and Sharing Center you can
view and set the IPv4 address that is associated with network adapter by
clicking Properties. In this example, the PC is manually configured with a static IPv4
address.
IP addresses can be either static or dynamic. At this point, all you need to know is that a
static IP address is a fixed IP address that is assigned manually to a device while a
dynamic IP address is assigned automatically and changes whenever a user reboots a
device.
Navigating to the TCP/IP network settings varies widely, depending on the operating
system that is installed.
Use the ipconfig command to display all current TCP/IP network configuration values
at the command line of a Windows computer.
For additional information about ipconfig and the command syntax, use your favorite
search engine and search for this string: microsoft technet dd197434
site:microsoft.com
Verifying the IPv4 Address of a Host on Apple Mac
Just like in Windows, you can use either GUI or CLI to configure or verify your IP
address settings on Apple Mac OS X. To use the GUI option, click the Apple logo in the
taskbar, choose System Preferences, and choose Network. A pop-up Window will
open, displaying your connections. Click the connection that you want to manage,
choose Advanced, and click the TCP/IP tab.
You can also acquire this information using a CLI. First you will need to open the
Terminal. You can do so in several ways, including using the Finder menu bar by
choosing Go > Utilities > Terminal. Then, use the ifconfig {interface name} command
to obtain the IPv4 address and other information.
Verifying the IPv4 Address of a Host on Linux
On most Linux operating systems, the ifconfig command is used to perform the same
tasks that ipconfig performs on Microsoft Windows operating systems.
On Linux systems, you can get the details of specific syntax for just about any
command using the man (manual) command. In the following example, man
ifconfig was entered.
Explaining the TCP/IP Transport Layer and
Application Layer
Introduction
Internet Protocol (IP) addressing is used to uniquely identify the devices globally. But to
provide a logical connection between the endpoints of a network and to provide
transport services from a host to a destination, you need a different set of functionalities,
which are provided by the Transmission Control Protocol / Internet Protocol (TCP/IP)
Transport Layer. Another important functionality is that the Transport layer provides the
interface between the Application layer that we use to communicate with through
various applications and the underlying Internet layer, and therefore hides the
complexity of the network from the applications.
The two most important protocols used at the Transport layer are the TCP and the User
Datagram Protocol (UDP). While the first one provides reliable, the second one only
provides best-effort communication. Application programmers can choose the service
that is the most appropriate for their specific applications. Both protocols support
establishment of multiple sessions from the end-host, which is important so that
different applications running on end-hosts can use the same IP address to
communicate with the network.
The Application layer provides functions for users or their programs, and it is highly
specific to the application being performed. It provides the services that user
applications use to communicate over the network, and it is the layer in which useraccess network processes reside. These processes encompass the ones that users
interact with directly, as well as other processes of which the users are not aware.
There are many Application layer protocols, and new protocols are constantly being
developed.
Cisco Enterprise Architecture Model
As a network engineer, you will often design, configure, and troubleshoot different
networks to be suitable for different Application layer protocols and you will need to,
among other characteristics, contrast reliable and unreliable transport services provided
by TCP and UDP.
TCP/IP Transport Layer Functions
The transport layer resides between the application and Internet layers of the TCP/IP
protocol stack. The TCP/IP Internet layer directs information to its destination, but it
cannot guarantee that the information will arrive in the correct order, free of errors, or
even that the information will arrive at all. The two most common transport layer
protocols of the TCP/IP protocol suite are TCP and UDP. Both protocols manage the
communication of multiple applications and provide communication services directly to
the application process on the host.
The basic service that the transport layer provides is tracking communication between
applications on the source and destination hosts. This service is called session
multiplexing, and it is performed by both UDP and TCP. A major difference between
TCP and UDP is that TCP can ensure that the data is delivered, while UDP does not
ensure delivery.
Review of Open Systems Interconnection (OSI) and TCP/IP reference models: The
transport layer of the TCP/IP protocol stack maps to the transport layer of the OSI
model. The protocols that operate at this layer are said to operate at Layer 4 of the OSI
model. If you hear someone use the term "Layer 4," they are referring to the transport
layer of the OSI model.
Multiple communications often occur at once; for instance, you may be searching the
web and using File Transfer Protocol (FTP) to transfer a file at the same time. The
transport layer tracks these communications and keeps them separate. This tracking is
provided by both UDP and TCP. To pass data to the proper applications, the transport
layer must identify the target application. If TCP is used, the transport layer has the
additional responsibilities of establishing end-to-end connections, segmenting data and
managing each piece, reassembling the segments into streams of application data,
managing flow control, and applying reliability mechanisms.
Session Multiplexing
Session multiplexing is the process by which an IP host is able to support multiple
sessions simultaneously and manage the individual traffic streams over a single link. A
session is created when a source machine needs to send data to a destination
machine. Most often, this process involves a reply, but a reply is not mandatory.
Session multiplexing service provided by the transport layer supports multiple TCP or
UDP sessions, and not just one TCP and one UDP session respectively over a single link
as indicated in the figure above.
Identifying the Applications
To pass data to the proper applications, the transport layer must identify the target
application. TCP/IP transport protocols use port numbers to accomplish this task. The
connection is established from a source port to a destination port. Each application
process that needs to access the network is assigned a port number that is unique in
that host. The destination port number is used in the transport layer header to indicate
which target application that piece of data is associated with. The source port is used by
the sending host to help keep track of existing data streams and new connections it
initiates. The source and destination port numbers are not usually the same.
Segmentation
TCP takes variably sized data chunks from the Application layer and prepares them for
transport onto the network. The application relies on TCP to ensure that each chunk is
broken up into smaller segments that will fit the maximum transmission unit (MTU) of
the underlying network layers. UDP does not provide segmentation services. UDP
instead expects the application process to perform any necessary segmentation and
supply it with data chunks that do not exceed the MTU of lower layers.
The MTU of the Ethernet protocol is 1500 bytes. Larger MTUs are possible, but 1500
bytes is the normal size.
Flow Control
If a sender transmits packets faster than the receiver can receive them, the receiver
drops some of the packets and requires them to be retransmitted. TCP is responsible
for detecting dropped packets and sending replacements. A high rate of retransmissions
introduces latency in the communication channel. To reduce the impact of
retransmission-related latency, flow control methods work to maximize the transfer rate
and minimize the required retransmissions.
Basic TCP flow control relies on acknowledgments that are generated by the receiver.
The sender sends some data while waiting for an acknowledgment from the receiver
before sending the next part. However, if the round-trip time (RTT) is significant, the
overall transmission rate may slow to an unacceptable level. To increase network
efficiency, a mechanism called windowing is combined with basic flow control.
Windowing allows a receiving computer to advertise how much data it is able to receive
before transmitting an acknowledgment to the sending computer.
Windowing enables avoidance of congestion in the network.
Connection-Oriented Transport Protocol
Within the transport layer, a connection-oriented protocol establishes a session
connection between two IP hosts and then maintains the connection during the entire
transmission. When the transmission is complete, the session is terminated. TCP
provides connection-oriented reliable transport for application data.
Reliability
TCP reliability has these three main objectives:
•
•
•
Detection and retransmission of dropped packets
Detection and remediation of duplicate or out-of-order data
Avoidance of congestion in the network
Reliable vs. Best-Effort Transport
The terms reliable and best effort are terms that describe two types of connections
between computers. TCP is a connection-oriented protocol that is designed to ensure
reliable transport, flow control, and guaranteed delivery of IP packets. For this reason, it
is labeled a "reliable" protocol. UDP is a connectionless protocol that relies on the
Application layer for sequencing and detection of dropped packets and is considered
"best effort." Each protocol has strengths that make them useful for particular
applications.
Reliable
Best-Effort
Protocol
TCP
UDP
Connection
Type
Connection-oriented
Connectionless
Sequencing
Yes
No
Email
•
File Transfer Protocol (FTP)
•
Web browsing
Downloading
•
Voice streaming
Dynamic Host Configuration Protocol
(DHCP)
Trivial File Transfer Protocol (TFTP)
Uses
•
•
•
•
Reliable (Connection-Oriented)
Some types of applications require a guarantee that packets arrive safely and in order.
Any missing packets could cause the data stream to be corrupted. Consider the
example of using your web browser to download an application. Every piece of that
application must be assembled on the receiver in the proper binary order, or it will not
execute. FTP is an application where the use of a connection-oriented protocol like TCP
is indicated.
TCP uses a three-way handshake when setting up a connection. You can think of it as
being similar to a phone call. The phone rings, the called party says "hello," and the
caller says "hello." Here are the actual steps:
1. The source of the connection sends a synchronization (SYN) segment to the destination
requesting a session. The SYN segment includes the Sequence Number (or SN).
2. The destination responds to the SYN with a synchronization-acknowledgment (SYNACK) and increments the initiator SN by 1.
3. If the source accepts the SYN-ACK, it sends an acknowledgment (ACK) segment to
complete the handshake.
Here are some common applications that use TCP:
•
•
•
•
•
Web browsers
Email
FTP
Network printing
Database transactions
To support reliability, a connection is established between the IP source and destination
to ensure that the application is ready to receive data. During the initial process of
connection establishment, information is exchanged about the capabilities of the
receiver, and starting parameters are negotiated. These parameters are then used for
tracking data transfer during the connection.
When the sending computer transmits data, it assigns a sequence number to each
packet. The receiver then responds with an acknowledgment number that is equal to
the next expected sequence number. This exchange of sequence and acknowledgment
numbers allows the protocol to recognize when data has been lost, or duplicated, or has
arrived out of order.
Best Effort (Connectionless)
Reliability (guaranteed delivery) is not always necessary, or even desirable. For
example, if one or two segments of a Voice over IP (VoIP) stream fail to arrive, it would
only create a momentary disruption in the stream. This disruption might appear as a
momentary distortion of the voice quality, but the user may not even notice. In real-time
applications, such as voice streaming, dropped packets can be tolerated as long as the
overall percentage of dropped packets is low.
Here are some common applications that use UDP:
•
•
•
Domain Name System (DNS)
Voice over IP (VoIP)
TFTP
UDP provides applications with best-effort delivery and does not need to maintain state
information about previously sent data. Also, UDP does not need to establish any
connection with the receiver and is termed connectionless. There are many situations in
which best-effort delivery is more desirable than reliable delivery. A connectionless
protocol is desirable for applications that require faster communication without
verification of receipt.
UDP is also better for transaction type services, such as DNS or DHCP. In transaction
type services, there is only a simple query and response. If the client does not receive a
response, it simply sends another query, which is more efficient and consumes less
resources than using TCP.
TCP vs. UDP Analogy
The postal service can be used as an analogy to illustrate the differences between
connection-oriented TCP and connectionless services that UDP provides.
Example: TCP—Sending Certified Mail
Imagine that you are a popular author in Seattle. Your editor in Indianapolis is very
anxious to publish your next novel and demands that you mail her each page as you
finish one. You print each page of the book as you write them and put each page in a
separate envelope. To ensure that your editor reassembles the book correctly, you put
a page number on each envelope (a sequence number). You address the envelope and
send the first one as certified mail. The postal service delivers it by any truck and any
route, but because it is certified, the carrier who delivers it must get a signature from
your editor and return a certificate of delivery to you.
Your contract with the publisher specifies that each page must be in a separate
envelope. But having to go to the post office to send each letter individually is too timeconsuming, so you send several envelopes together. The postal service again delivers
each envelope by any truck and any route. Your editor signs a separate receipt for each
envelope in the batch as she receives them. If one envelope is lost in transit, you will
not receive a certificate of delivery for that numbered envelope, and you will need to
resend that page. As your editor is receiving your envelopes, she uses the sequence
numbers to assemble the book in the proper order.
Like certified mail, TCP offers sequencing, acknowledgements, and retransmission.
Example: UDP—Sending Regular Mail
UDP services can be compared to using the postal service to pay your bills. You
address each bill payment to a specific company address, stamp the envelope, and
include your return address. The postal service guarantees its best effort to deliver each
payment. The postal service does not guarantee delivery, and it is not responsible for
telling you that delivery was successful or unsuccessful.
Like standard mail, UDP is a simple process that provides basic data-transfer services.
TCP Characteristics
Applications use the connection-oriented services of TCP to provide data reliability
between hosts. TCP includes several important features that provide reliable data
transmission.
TCP can be characterized as follows:
•
TCP operates at the transport layer of the TCP/IP stack (OSI Layer 4).
•
TCP provides application access to the Internet layer (OSI Layer 3, the network layer),
where application data is routed from the source IP host to the destination IP host.
•
TCP is connection-oriented and requires that network devices set up a connection to
exchange data. The end systems synchronize with one another to manage packet flows
and adapt to congestion in the network.
TCP provides error checking by including a checksum in the TCP segment to verify that
the TCP header information is not corrupt.
TCP establishes two connections between the source and destination. The pair of
connections operates in full-duplex mode, one in each direction. These connections are
often called a virtual circuit because, at the transport layer, the source and destination
have no knowledge of the network.
TCP segments are numbered and sequenced so that the destination can reorder
segments and determine if data is missing or arrives out of order.
Upon receipt of one or more TCP segments, the receiver returns an acknowledgment to
the sender to indicate that it received the segment. Acknowledgments form the basis of
reliability within the TCP session. When the source receives an acknowledgment, it
knows that the data has been successfully delivered. If the source does not receive an
acknowledgment within a predetermined period, it retransmits that data to the
destination. The source may also terminate the connection if it determines that the
receiver is no longer on the connection.
TCP provides mechanisms for flow control. Flow control assists the reliability of TCP
transmission by adjusting the effective rate of data flow between the two services in the
session.
•
•
•
•
•
Reliable data delivery services are critical for applications such as file transfers,
database services, transaction processing, and other applications in which delivery of
every packet must be guaranteed. TCP segments are sent by using IP packets. The
TCP header follows the IP header and supplies information that is specific to the TCP
protocol. Flow control, reliability, and other TCP characteristics are achieved by using
fields in the TCP header. Each field has a specific function.
The TCP header is a minimum of 20 bytes; the fields in the TCP header are as follows:
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
Source Port: Calling port number (16 bits)
Destination Port: Called port number (16 bits)
Sequence Number and Acknowledgment Number: Used for reliability and congestion
avoidance (32 bits each)
Header Length: Size of the TCP header (4 bits)
Reserved: For future use (3 bits)
Flags or control bits (9 bits)
Nonce Sum (NS): Enables the receiver to demonstrate to the sender that segments are
being acknowledged.
Congestion Window Reduced (CWR): Acknowledge that the congestion-indication
echoing was received
Explicit Congestion Notification Echo (ECE): Indication of congestion
Urgent (URG): This data should be prioritized over other data.
Acknowledgment (ACK): Used for acknowledgment
Push (PSH): Indicates that application data should be transmitted immediately and not
wait for the entire TCP segment.
Reset (RST): Indicates that the connection should be reset
Synchronize (SYN): Synchronize sequence numbers
Finish (FIN): Indicates there is no more data from sender
Window size: Window size value, used for flow control (16 bits)
Checksum: Calculated checksum from a constructed pseudo header (containing the
source address, destination address, and protocol from the IP header, TCP segment
length, and reserved bits) and the TCP segment (TCP header and payload) for errorchecking (16 bits)
•
•
•
Urgent Pointer: If the URG flag is set, this field is an offset from the sequence number
indicating the last urgent data byte (16 bits)
Options: The length of this field is determined by the data offset field (from 0 to 320
bits)
Data: upper-layer protocol (ULP) data (varies in size)
UDP Characteristics
Applications use the connectionless services of UDP to provide high-performance, lowoverhead data communications between hosts. UDP includes several features that
provide for low-latency data transmission.
UDP is a simple protocol that provides basic transport layer functions:
•
•
•
•
•
•
UDP operates at the transport layer of the TCP/IP stack (OSI Layer 4).
UDP provides applications with access to the Internet layer (OSI Layer 3, the network
layer), without the overhead of reliability mechanisms.
UDP is a connectionless protocol in which a one-way datagram is sent to a destination
without advance notification to the destination device.
UDP performs only limited error checking. A UDP datagram includes a checksum value,
which the receiving device can use to test the integrity of the data.
UDP provides service on a best-effort basis and does not guarantee data delivery,
because packets can be misdirected, duplicated, or lost on the way to their destination.
UDP does not provide any special features that recover lost or corrupted packets. UDP
relies on applications that are using its transport services to provide recovery.
•
Because of its low overhead, UDP is ideal for applications like DNS and Network Time
Protocol (NTP), where there is a simple request-and-response transaction.
The low overhead of UDP is evident when you review the UDP header length of only 64
bits (8 bytes). The UDP header length is significantly smaller compared with the TCP
minimum header length of 20 bytes.
The following list describes the field definitions in the UDP segment:
•
•
•
•
•
Source port: Calling port number (16 bits)
Destination port: Called port number (16 bits)
Length: Length of UDP header and UDP data (16 bits)
Checksum: Calculated checksum of the header and data fields (16 bits)
Data: ULP data (varies in size)
Application layer protocols that use UDP include DNS, Simple Network Management
Protocol (SNMP), DHCP, Routing Information Protocol (RIP), TFTP, Network File
System (NFS), online games, and voice streaming.
TCP/IP Application Layer
UDP and TCP use internal software ports to support multiple conversations between
various network devices. To differentiate the segments and datagrams for each
application, TCP and UDP both have header fields that uniquely identify these
applications. These unique identifiers are the port numbers.
The combination of an IP address and a port is strictly known as an endpoint and is
sometimes called a socket. A TCP connection is defined by two endpoints (sockets).
Some of the applications that TCP/IP supports include:
•
•
•
•
•
•
•
•
FTP (port 21, TCP): FTP is a reliable, connection-oriented service that uses TCP to
transfer files between systems that support FTP. FTP supports bidirectional binary and
ASCII file transfers. Besides using port 21 for exchange of control, FTP also uses one
additional port, 20 for data transmission.
SSH (port 22, TCP): Secure Shell (SSH) provides the capability to remotely access
other computers, servers, and networking devices. SSH enables a user to log in to a
remote host and execute commands. SSH messages are encrypted.
Telnet (port 23, TCP): Telnet is a predecessor to SSH. It sends messages in
unencrypted cleartext. As a security best practice, most organizations now use SSH for
remote communications.
HTTP (port 80, TCP): Hypertext Transfer Protocol (HTTP) defines how messages are
formatted and transmitted and which actions browsers and web servers can take in
response to various commands. It uses TCP.
HTTPS (port 443, TCP): Hypertext Transfer Protocol Secure (HTTPS) combines HTTP
with a security protocol (Secure Sockets Layer [SSL]/Transport Layer Security[TLS]).
DNS (port 53, TCP, and UDP): DNS is used to resolve Internet names to IP addresses.
DNS uses a distributed set of servers to resolve names that are associated with
numbered addresses. DNS uses TCP for zone transfer between DNS servers and UDP
for name queries.
TFTP (port 69, UDP): TFTP is a connectionless service. Routers and switches use
TFTP to transfer configuration files and Cisco IOS images and other files between
systems that support TFTP.
SNMP (port 161, UDP): SNMP facilitates the exchange of management information
between network devices. SNMP enables network administrators to manage network
performance, find and solve network problems, and plan for network growth.
Here, you have seen only some applications with their port numbers. Go to the Service
Name and Transport Protocol Port Number Registry for a complete list
at http://www.iana.org/assignments/service-names-port-numbers/service-names-portnumbers.xhtml.
Introducing HTTP
In a world that is driven by the Internet and ever-increasing amounts of data,
technologies that enable and standardize the way we exchange information are very
useful. Hyper Text Transfer Protocol (HTTP) and HTTP-based (Application
Programmable Interfaces) APIs form one of the foundations of the World Wide Web and
provide us with a way to communicate with remote systems.
HTTP is an Application layer protocol and is the foundation of communication for the
World Wide Web. It is based on a client-server computing model, where the client (e.g.
a web browser) and the server (e.g. a web server) use a request-response message
format to transfer information. HTTP presumes a reliable underlying transport layer
protocol, so TCP is commonly used, however, UDP can also be used in some cases.
By default, HTTP is a stateless (or connectionless) protocol, which means that it works
without the receiver retaining any client information and each request can be
understood in isolation, without the knowledge of any commands that came before it.
HTTP does have some mechanisms, namely HTTP headers, to make the protocol
behave as if it was stateful.
The information is media independent, which means that any type of data can be sent
by HTTP as long as both the client and the server know how to handle the data content.
HTTP is commonly used by Web browsers and servers to transfer the files that make up
web pages.
Although the HTTP specification allows for data to be transferred on port 80 using either
TCP or UDP, most implementations use TCP. A secure version of the protocol, HTTPS,
uses TCP port 443.
HTTP Request-Response Cycle
The data is exchanged via HTTP Requests and HTTP Responses, which are
specialized data formats, used for HTTP communication. A sequence of requests and
responses is called an HTTP Session and is initiated by a client by establishing a
connection to the server.
1. Client sends an HTTP request to the server.
2. Server receives the request.
3. Server processes the request.
4. Server returns an HTTP response.
5. Client receives the response (e.g. web page content).
An example of using a request-response cycle is web browsing. When a user is
browsing the web, a browser sends a HTTP request to get the Hyper Text Markup
Language (HTML) document that represents the page. The server responds to the
request and returns the HTTP response with a response code and the content of the
page, which is an HTML document. The clients’ browser parses this document,
displaying its content according to layout information and resources contained within the
page (usually images and videos) and sometimes processing additional requests
corresponding to execution scripts. The web browser presents all of this content to a
user as a complete Web page.
Domain Name System
The DNS provides an efficient way to convert human-readable names of IP end
systems into machine-readable IP addresses that are necessary for routing.
On TCP/IP networks, hosts are assigned their unique 32-bit IPv4 addresses in the
familiar dotted decimal notation so that they can send and receive messages over the
local network and the Internet. If there were no DNS, you would have to remember the
IPv4 address of every host that you would like to reach.
DNS uses a distributed database that is hosted on several servers, which are located
around the world, to resolve the names that are associated with IP addresses. The DNS
protocol defines an automated service that matches resource names with the required
numeric network address.
An easy way to observe DNS in action can be performed in a command window in
Microsoft Windows, Apple Mac OS X, or your favorite Linux distribution. When the
command window is open, enter nslookup www.google.com. This command queries
DNS to resolve the domain name into IP address. The result will appear below your
query.
You may receive a different IP address in your response than the example shows.
Your host sends a DNS query for the IP address of www.google.com. If your DNS
server has the answer cached, it returns the answer directly.
Explaining DHCP for IPv4
Managing a network can be very time-consuming. Network clients break, or are moved,
and new clients are purchased that need network connectivity. These tasks are all part
of the network administrator job. Depending on the number of IP hosts, manual
configuration of IPv4 addresses for every device on the network is virtually impossible.
DHCP can greatly decrease the workload of the network administrator. DHCP
automatically assigns an IPv4 address from an IPv4 address pool that the administrator
defines. However, DHCP is much more than just a mechanism that allocates IPv4
addresses. This service automates the assignment of IPv4 addresses, subnet masks,
gateways, and other required networking parameters.
DHCP is built on a client/server model. The DHCP server is allocated one or more
network addresses and sends configuration parameters to dynamically configured hosts
that request them. The term "client" refers to a host that is requesting initialization
parameters from a DHCP server. Most endpoint devices on today’s networks are DHCP
clients, including Cisco IP phones, desktop PCs, laptops, printers, and even Blu-Ray
players. Just about any device that you can configure to participate on a TCP/IP
network has the option of using DHCP to obtain its IPv4 configuration.
Depending on the actual DHCP server that is in use, there are three basic DHCP IPv4
address allocation mechanisms:
•
•
•
Dynamic allocation: Dynamic allocation of IPv4 addresses is the most common type of
address assignment. As devices boot and activate their Ethernet interfaces, the DHCP
client service triggers a DHCP Discover broadcast that includes the Media Access
Control (MAC) address of the DHCP client. If a DHCP server is listening on that IPv4
subnet, it responds with a DHCP Offer message. The DHCP Offer message offers an
unused IPv4 address from the address pool that is on the DHCP server. If the IPv4
address is acceptable, the DHCP client then sends a DHCP Request agreeing to the
offered address. The DHCP server then marks the IPv4 address as "in use" in its
database and sends a final DHCP ACK to the DHCP client. The DHCP server also
starts the countdown on a "lease timer." With a dynamic allocation, a DHCP client is
given its IPv4 configuration for a specified amount of time. When the lease time expires,
the DHCP server can reclaim the address, return it to the address pool, and lease it to
another host. DHCP clients can renew their address before it expires.
Automatic allocation: Automatic allocation of IPv4 addresses is very similar to
dynamic allocation, except that the lease time is set to never expire. This setting results
in the DHCP client always being associated with the same IPv4 address.
Static allocation: Static allocation is an alternative that is generally used for devices
such as servers and printers, where the device needs to keep the same IPv4 address
configuration permanently. A static entry is made in the DHCP database that maps the
MAC address to an IPv4 address.
The following figure illustrates how a DHCP server assigns an IPv4 address to a DHCP
client computer, while the table provides additional information for the exchanged
packets.
Source
Destination
Protocol Info
IPv4: 0.0.0.0
1. MAC: 78:ac:c0:52:e8:bd
IPv4: 255.255.255.255
MAC: ff:ff:ff:ff:ff:ff
DHCP
DHCP Discover
IPv4: 192.168.1.254
2. MAC: 00:1b:d5:9c:34:27
IPv4: 255.255.255.255
MAC: ff:ff:ff:ff:ff:ff
DHCP
DHCP Offer 192.168.1.10
IPv4: 0.0.0.0
3. MAC: 78:ac:c0:52:e8:bd
IPv4: 255.255.255.255
MAC: ff:ff:ff:ff:ff:ff
DHCP
DHCP Request
IPv4: 192.168.1.254
4. MAC: 00:1b:d5:9c:34:27
IPv4: 255.255.255.255
MAC: ff:ff:ff:ff:ff:ff
DHCP
DHCP ACK
The DHCP client and the DHCP server exchange the following packets:
1. DHCP Discover: The DHCP client boots up and sends this message on its local
physical subnet to the subnet's broadcast (destination IPv4 address of 255.255.255.255
and MAC address of ff:ff:ff:ff:ff:ff), with a source IPv4 address of 0.0.0.0 and its MAC
address.
2. DHCP Offer: The DHCP server responds and fills the yiaddr (your IPv4 address) field of
the message with the requested IPv4 address. The DHCP server sends the DHCP Offer
to the broadcast address, but includes the client's hardware address in the chaddr
(client hardware address) field of the offer, so the client knows that it is the intended
destination.
3. DHCP Request: The DHCP client may receive multiple DHCP Offer messages, but
chooses one and accepts only that DHCP server’s offer, implicitly declining all other
DHCP Offer messages. The client identifies the selected server by populating the
Server Identifier option field with the DHCP server's IPv4 address. The DHCP Request
is also a broadcast, so all DHCP servers that sent a DHCP Offer will receive it, and
each will know whether it was accepted or declined. Even though the client has been
offered an IPv4 address, it will send the DHCP Request message with a source IPv4
address of 0.0.0.0.
4. DHCP ACK: The DHCP server acknowledges the request and completes the
initialization process. DHCP ACK message has a source IPv4 address of the DHCP
server, and the destination address is once again a broadcast and contains all the
parameters that the client requested in the DHCP Request message. When the client
receives the DHCP ACK, it enters into the Bound state, and is now free to use the IPv4
address to communicate on the network.
Configuring a Router as an IPv4 DHCP Client
An Internet service provider (ISP) sometimes provides a static address for a router
interface that is connected to the Internet. In other cases, an address is provided using
DHCP. If the ISP uses DHCP to provide interface addressing, no manual address can
be configured. Instead, the router’s interface is configured to operate as a DHCP client.
Router(config)# interface GigabitEthernet0/0
Router(config-if)# ip address dhcp
The interface interface command on the router specifies an interface and enters the
interface configuration mode, while the ip address dhcp command enables the
interface to acquire an IPv4 address through DHCP.
If the router receives the optional default gateway DHCP parameter from the server, it
will inject the default route into its routing table, pointing to the default gateway IPv4
address.
To verify that router interface has acquired an IPv4 address through DHCP, you can
use the show ip interface brief command:
Router# show ip interface brief
Interface IP-Address OK? Method Status Protocol
GigabitEthernet0/0 192.168.1.10 YES DHCP up up
GigabitEthernet0/1 10.1.1.1 YES NVRAM up up
Configuring an IPv4 DHCP Relay
A DHCP relay agent is any host that forwards DHCP packets between clients and
servers. Relay agents are used to forward requests and replies between clients and
servers when they are not on the same subnet. DHCP requests are sent as broadcasts
and because routers block the broadcasts you need a relay functionality so that you can
reach the DHCP server.
Router(config)# interface GigabitEthernet0/1
Router(config-if)# ip helper-address 10.0.0.1
The ip helper-address address command should be issued on the interface where the
DHCP broadcasts are received.
To configure the DHCP relay agent to forward packets to a DHCP server, you should
enter the interface configuration mode using the interface interface command. Then,
use the ip helper-address address command to specify that the interface will forward
UDP broadcasts, including BOOTP and DHCP, to the specified server address.
These steps show how DHCP requests are processed when DHCP relay is used:
•
•
•
•
Step 1: A DHCP client broadcasts a DHCP request
Step 2: DHCP relay includes option 82 and sends the DHCP request as a unicast
packet to the DHCP server. Option 82 includes remote ID and circuit ID.
Step 3: The DHCP server responds to the DHCP relay
Step 4: The DHCP relay strips-off option 82 and sends the response to the DHCP client
To verify the DHCP relay configuration in this example, you can check whether the
client computers in the customer LAN have acquired IPv4 addresses from the DHCP
server.
You can use packet capture to examine the packets on the customer LAN to observe
the communication between the clients and DHCP relay agent. Furthermore, you can
examine the packets towards the service provider network to observe that the router
has forwarded the DHCP Discover message from the clients towards the DHCP server
using as source, the IPv4 address from router's interface GigabitEthernet0/1. You can
also observe that the DHCP server has sent the DHCP Offer, as a unicast packet, back
to the DHCP relay agent from which the DHCP Discover message came.
Configuring a Router as an IPv4 DHCP Server
The Cisco IOS DHCP server is a full DHCP server implementation that assigns and
manages IPv4 addresses from specified address pools within the device to DHCP
clients. The DHCP server can be configured to assign additional parameters such as
the IPv4 address of the DNS server and the default gateway. You can implement a
DHCP server on both Cisco IOS Routers and Cisco Catalyst switches.
To configure the DHCP server on a router, you should enter the DHCP pool
configuration mode using the ip dhcp pool namecommand. Then, assign the DHCP
parameters to the DHCP pool.
Router(config)# ip dhcp excluded-address 10.1.50.1 10.1.50.50
Router(config)# ip dhcp pool Customer
Router(dhcp-config)# network 10.1.50.0 /24
Router(dhcp-config)# default-router 10.1.50.1
Router(dhcp-config)# dns-server 10.1.50.1
Router(dhcp-config)# domain-name cisco.com
Router(dhcp-config)# lease 0 12
Router(dhcp-config)# exit
Use the following commands that are shown in the table to define the pool parameters.
Command
Description
network networknumber [mask |prefixlength]
Defines addresses in the DHCP pool. Optionally, defines a
subnet mask or prefix length to define the network part.
default-router address
Specifies the IP address of the default router for a DHCP client.
dns-server address
Specifies the IP address of a DNS server.
domain-name domain
Specifies the domain name for the DHCP client.
lease {days [hours]
[minutes] |infinite}
Specifies the duration of the lease. The default is a one-day lease.
You can also exclude the range of IPv4 addresses from the DHCP assignment, by
using the ip dhcp excluded-address ip-address [last-ip-address] command, which is
used in the global configuration mode.
In the configuration example above the IPv4 addresses are assigned from the address
pool 10.1.50.0/24 with a lease time of 12 hours. Additional parameters are the default
gateway, domain name, and DNS server Also IPv4 addresses from 10.1.50.1 to
10.1.50.50 are not assigned to the end devices.
To verify information about the configured DHCP address pools you can use show ip
dhcp pool command and to display the address binding information, which displays a
list of all IPv4 address-to-MAC bindings, you can use the show ip dhcp
bindingcommand.
IPv4 DHCP Settings on Windows Host
On a Windows computer, you can use different ipconfig command options to view and
refresh DHCP and DNS settings.
The following is the syntax for the ipconfig command:
ipconfig [/ all] [/ renew [adapter]] [/ release [adapter]] [/displaydns]
[/flushdns]
The following command options are commonly used:
•
•
•
•
•
•
/all This option displays the complete TCP/IP configuration for all adapters, including
DHCP and DNS configuration. Without this parameter, the ipconfig command displays
only the IP address, subnet mask, and default gateway values for each adapter.
Adapters can represent physical interfaces, such as installed network adapters, or
logical interfaces, such as dial-up connections.
/renew [adapter] This option renews DHCP configuration for all adapters (if an adapter
is not specified) or for a specific adapter if the adapter parameter is included. This
parameter is available only on computers with adapters that are configured to obtain an
IP address automatically. To specify an adapter name, enter the adapter name that
appears when you use ipconfig without parameters.
/release [adapter] This option sends a DHCPRELEASE message to the DHCP server
to release the current DHCP configuration and discard the IP address configuration for
either all adapters (if an adapter is not specified) or for a specific adapter if the adapter
parameter is included. This parameter disables TCP/IP for adapters that are configured
to obtain an IP address automatically. To specify an adapter name, enter the adapter
name that appears when you use ipconfig without parameters.
/displaydns This option displays the contents of the host DNS cache. When an IP host
makes a DNS query for a hostname, it caches the result to avoid unnecessary queries.
/flushdns This option deletes the host DNS cache. This option is useful if the IP
address that is associated with a hostname has changed, but the host is still caching
the old IP address.
/? This option displays help at the command prompt.
Discovery 4: Inspect TCP/IP Applications
Introduction
This discovery lab will help you explore TCP and UDP services that are enabled on a
router. You will see the particular ports numbers for each active service, and how clients
connect to the services using their own IPv4 addresses and their own port numbers.
The lab is prepared with the devices that are represented in the topology diagram with
the IPv4 addresses as depicted in the table.
Topology
Job Aids
Device Information
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today.
Personal computers (PCs) in the virtual lab environment are simulated by routers, so you
should use Cisco IOS commands to configure them or verify the configuration.
Device Information Table
Device
Characteristic
Value
PC1
IPv4 address
10.10.1.10/24
PC1
Default gateway
10.10.1.1
PC2
IPv4 address
10.10.1.20/24
PC2
Default gateway
10.10.1.1
SW1
VLAN 1 IPv4 address
10.10.1.2/24
SW1
Default gateway
10.10.1.1
SW2
VLAN 1 IPv4 address
10.10.1.3/24
SW2
Default gateway
10.10.1.1
R1
Ethernet0/0 IPv4 address
10.10.1.1/24
R1
Loopback 0 IPv4 address
10.10.3.1/24
R1
Password
Cisco123
Task 1: Inspect TCP/IP Applications
Activity
Step 1
R1 has been configured to run several TCP services, including Telnet, SSH, HTTP, and
HTTPS. It has also been configured to run an NTP service. How and why these
services may be configured on a router is beyond the scope of this discovery. For now,
verify the services that are running on R1 by viewing its open ports. Access the console
of R1 and execute the show control-plane host open-ports command.
There are several open TCP ports: 22 for SSH, 23 for Telnet, 80 for HTTP, and 443 for
HTTPS; as well as UDP port 123 for NTP.
R1# show control-plane host open-ports
Active Internet connections (servers and established)
Prot Local Address Foreign Address Service State
tcp *:22 *:0 SSH-Server LISTEN
tcp *:23 *:0 Telnet LISTEN
tcp *:80 *:0 HTTP CORE LISTEN
tcp *:80 *:0 HTTP CORE LISTEN
tcp *:443 *:0 HTTP CORE LISTEN
tcp *:443 *:0 HTTP CORE LISTEN
udp *:123 *:0 NTP LISTEN
These ports are in a listening state; that is, no foreign addresses are connected to them,
but they are ready for connections to ensue.
Both HTTP and HTTPS use TCP. In the output, you will see both as “HTTP CORE”
Service. To distinguish them, pay attention to the port numbers in the Local Address
column: HTTP uses port 80 while HTTPS uses port 443.
Step 2
Access the console of PC1 and use Telnet to connect to R1. The password for R1
is Cisco123.
In this lab environment, telnet is used for connection to R1. However, you should SSH
in production environment to remotely access and manage a device.
The prompt changes from PC1 to R1 because you are now connected to R1 via Telnet
from PC1.
PC1# telnet 10.10.1.1
Trying 10.10.1.1 ... Open
User Access Verification
Password: Cisco123
R1#
Step 3
Return to the console of R1 and review the open ports. You may want to use the Cisco
IOS command recall feature to re-enter the command.
There is an extra line in the output when compared with the last execution. It shows a
second line that is associated with TCP port 23. In this case, the foreign address is
populated. The IPv4 address is 10.10.1.10 (the address of PC1). The foreign port
number might not be the same as what is shown in the example because it is an
ephemeral port. An ephemeral port is allocated automatically for a short time from a
predefined range by the IPv4 stack software.
R1# show control-plane host open-ports
Active Internet connections (servers and established)
Prot Local Address Foreign Address Service State
tcp *:22 *:0 SSH-Server LISTEN
tcp *:23 *:0 Telnet LISTEN
tcp *:80 *:0 HTTP CORE LISTEN
tcp *:80 *:0 HTTP CORE LISTEN
tcp *:443 *:0 HTTP CORE LISTEN
tcp *:443 *:0 HTTP CORE LISTEN
tcp *:23 10.10.1.10:14044 Telnet ESTABLIS
udp *:123 *:0 NTP LISTEN
Step 4
Access the console of PC2 and use Telnet to connect to R1. The password for R1
is Cisco123.
The prompt changes from PC2 to R1 because you are now connected to R1 via Telnet
from PC2.
PC2# telnet 10.10.1.1
Trying 10.10.1.1 ... Open
User Access Verification
Password: Cisco123
R1#
Step 5
Return to the console of R1 and review the open ports. You may want to use the Cisco
IOS command recall feature to re-enter the command.
There is an extra line in the output that shows an additional connection to TCP port 23,
while the foreign address is populated with the IPv4 address of 10.10.1.20 (the address
of PC2). The foreign port number for this connection also might not be the same as
what is shown in the example because it will be an ephemeral port. The existing
connection from PC1 is retained.
R1# show control-plane host open-ports
Active Internet connections (servers and established)
Prot Local Address Foreign Address Service State
tcp *:22 *:0 SSH-Server LISTEN
tcp *:23 *:0 Telnet LISTEN
tcp *:80 *:0 HTTP CORE LISTEN
tcp *:80 *:0 HTTP CORE LISTEN
tcp *:443 *:0 HTTP CORE LISTEN
tcp *:443 *:0 HTTP CORE LISTEN
tcp *:23 10.10.1.20:15026 Telnet ESTABLIS
tcp *:23 10.10.1.10:14044 Telnet ESTABLIS
udp *:123 *:0 NTP LISTEN
Step 6
Return to the console of PC1 and use the exit command to disconnect the Telnet
session to R1.
The prompt returns to PC1 because you are no longer connected to R1.
R1# exit
[Connection to 10.10.1.1 closed by foreign host]
PC1#
Alternatively, you could have used the logout command to disconnect from R1.
Step 7
Return to the console of PC2 and use the exit command to disconnect the Telnet
session to R1.
The prompt returns to PC2 because you are no longer connected to R1.
R1# exit
[Connection to 10.10.1.1 closed by foreign host]
PC2#
Alternatively, you could have used the logout command to disconnect from R1.
Step 8
Return to the console of R1 and review the open ports again.
All ports are in a listening state.
R1# show control-plane host open-ports
Active Internet connections (servers and established)
Prot Local Address Foreign Address Service State
tcp *:22 *:0 SSH-Server LISTEN
tcp *:23 *:0 Telnet LISTEN
tcp *:80 *:0 HTTP CORE LISTEN
tcp *:80 *:0 HTTP CORE LISTEN
tcp *:443 *:0 HTTP CORE LISTEN
tcp *:443 *:0 HTTP CORE LISTEN
udp *:123 *:0 NTP LISTEN
Step 9
In the console of R1, disable the HTTP service using the no ip http server command in
global configuration mode. The web configuration service and related commands are
beyond the scope of this discovery, so for now, simply disable the HTTP service.
The TCP port 80 for HTTP is no longer opened.
R1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
R1(config)# no ip http server
R1(config)# exit
R1#
Step 10
In the console of R1, review the open ports again.
The TCP port 80 for HTTP is no longer shown in the output.
R1# show control-plane host open-ports
Active Internet connections (servers and established)
Prot Local Address Foreign Address Service State
tcp *:22 *:0 SSH-Server LISTEN
tcp *:23 *:0 Telnet LISTEN
tcp *:443 *:0 HTTP CORE LISTEN
tcp *:443 *:0 HTTP CORE LISTEN
udp *:123 *:0 NTP LISTEN
Exploring the Functions of Routing
Introduction
One of the intriguing aspects of Cisco routers, especially if you are new to routing, is
how the router chooses which route is the best among the routes presented by routing
protocols, manual configuration, and various other means. While route selection is
much simpler than you might imagine, you need to gain some knowledge about the way
Cisco routers work to understand it completely. Determining the best path involves the
evaluation of multiple paths to the same destination network and selecting the optimal
path to reach that network. This process is performed for every packet that goes
through a router.
A router is a networking device that forwards packets between different networks. A
router is typically positioned at the edge of a network and can provide connections to
other networks. In Enterprise Campus environments, you will typically find devices
providing routing in the center of the network or at the edge where they provide
connectivity to Wide Area Networks (WANs) or the internet. Routing functionality can
often be provided not only by routers but also by firewalls or Layer 3 switches. At home,
a router is typically part of an all-in-one device which also provides switching, wireless,
and security functions.
Cisco Enterprise Architecture Model
As a network engineer, you need to understand routing functionality that includes
different processes and ideas:
•
•
•
Role of a router and router components.
Routing table function and information in it.
The types of routes and how forwarding works in routers.
Role of a Router
A router is a networking device that forwards packets between different networks.
While switches exchange data frames between segments to enable communication
within a single network, routers are required to reach hosts that are not in the same
network. Routers enable internetwork communication by connecting interfaces in
multiple networks. For example, the router in the figure above has one interface
connected to the 192.168.1.0/24 network and another interface connected to the
192.168.2.0/24 network. The router uses a routing table to route traffic between the two
networks.
In the following figure, data frames travel between the various endpoints on local area
network (LAN) A. The switch enables the communication to all devices within the same
network, whose network Internet Protocol (IP) version 4 (IPv4) address is 10.18.0.0/16.
Likewise, the LAN B switch enables communication among the hosts on LAN B, whose
network IPv4 address is 10.22.0.0/16.
A host in LAN A cannot communicate with a host in LAN B without the router. Routers
enable communication between hosts that are not in the same local LAN. Routers are
able to do this function because they can be attached to multiple networks and have the
ability to route between them. In the figure, the router is attached to two networks,
10.18.0.0/16 and 10.22.0.0/16. Routers are essential components of large IP networks,
because they can accommodate growth across wide geographical areas.
This figure illustrates another important routing concept. Networks to which the router is
attached are called local or directly-connected networks. All other networks—networks
that a router is not directly attached to—are called remote networks.
The topology in the figure shows RouterX, which is directly attached to three networks
172.16.1.0/24, 172.16.2.0/24, and 192.168.100.0/24. To RouterX, all other networks,
i.e. 10.10.10.0/24, 10.10.20.0/24, and 10.10.30.0/24 are remote networks. To RouterY,
networks 10.10.10.0/24, 10.10.20.0/24 and 10.10.30/24 are directly connected
networks. RouterX and RouterY have a common directly-connected network
192.168.100.0/24.
Router Components
Cisco offers many different routers, which are suited for different networking
environments, such as enterprise LANs, service provider WANs, and so on. The various
models offer various features that are suitable for an array of different environments.
However, the core function of a router is to route packets, and for that reason, all
routers have many common components.
These components are as follows:
•
•
•
•
•
•
•
CPU: A central processing unit (CPU), or processor, is the chip that is installed on the
motherboard that carries out the instructions of a computer program. For example, it
processes all the information that is gathered from other routers or sent to other routers.
Motherboard: The motherboard is the central circuit board, which holds critical
electronic components of the system. The motherboard provides connections to other
peripherals and interfaces.
Memory: There are four primary types of memory:
RAM: Random-access memory (RAM) is memory on the motherboard that stores data
during CPU processing. It is a volatile type of memory in that its information is lost when
power is switched off. RAM provides temporary memory, including for the running
configuration of the router while the router is powered on.
NVRAM: Nonvolatile random-access memory (NVRAM) retains content when the router
is powered down. NVRAM stores the startup configuration file for most router platforms.
It also contains the software configuration register, which is used to determine which
Cisco IOS image is used when booting the router.
ROM: Read-only memory (ROM) is read-only memory on the motherboard. The content
of ROM is not lost when power is switched off. Data that is stored in ROM cannot be
modified, or it can be modified only slowly or with difficulty. ROM sometimes contains a
ROM monitor (ROMmon). ROM Monitor initializes the hardware and boots the Cisco
IOS software when you power on or reload a router. You can use the ROM monitor to
perform certain configuration tasks, such as recovering a lost password or downloading
software over the console port. ROM also includes bootloader software (bootstrap),
which helps the router boot when it cannot find a valid Cisco IOS image in the flash
memory. During normal startup, the ROM Monitor initializes the router, and then control
passes to the Cisco IOS software.
Flash: Flash memory is nonvolatile storage that can be electrically erased and
reprogrammed. Flash memory stores the Cisco IOS image. On some platforms, it can
also store configuration files or boot images.
•
•
•
Ports (also referred to as interfaces): Ports are used to connect routers to other
devices in the network. Routers can have these types of ports:
Management ports: Routers have a console port that can be used to attach to a
terminal that is used for management, configuration, and control. High-end routers may
also have a dedicated Ethernet port that can be used only for management. An IP
address can be assigned to the Ethernet port, and the router can be accessed from a
management subnet. The auxiliary (AUX) interface on a router is used for remote
management of the router. Typically, a modem is connected to the AUX interface for
dial-in access. From a security standpoint, enabling the option to connect remotely to a
network device carries with it the responsibility of vigilant device security.
Network ports: The router has many network ports, including various LAN or WAN
media ports, which may be copper or fiber cable. IP addresses are assigned to network
ports.
As an example, the following figure shows the ports on a Cisco integrated services
router (ISR) 4331 Router:
Router Functions
Routers have these two important functions:
•
Path determination: Routers use their routing tables to determine how to forward
packets. Each router must maintain its own local routing table, which contains a list of
all destinations that are known to the router, and information about how to reach those
destinations. When a router receives an incoming packet, it examines the destination IP
address in the packet and searches for the best match between the destination address
and the network addresses in the routing table. A matching entry may indicate that the
destination is directly connected to the router or that it can be reached via another
router. This router is called the next-hop router and is on the path to the final
destination. If there is no matching entry, the router sends the packet to the default
route. If there is no default route, the router drops the packet.
•
Packet forwarding: After a router determines the appropriate path for a packet, it
forwards the packet through a network interface toward the destination network.
Routers can have interfaces of different types. When forwarding a packet, routers
perform encapsulation following the OSI Layer 2 protocol implemented at the exit
interface. The figure shows the router A, which has two FastEthernet interfaces and one
serial interface. When the router A receives an Ethernet frame, it de-encapsulates it,
examines it, and determines the exit interface. If the router needs to forward the packet
out of the serial interface, the router will encapsulate the frame according to the Layer 2
protocol used on the serial link. The figure also shows a conceptual routing table that
lists destination networks known to the router along with its corresponding exit interface
or next-hop address. If there is an interface on the router that has an IPv4 address
within the destination network, the destination network is considered "directly
connected" to the router. For example, assume that the router A receives a packet on its
Serial0/0/0 interface that is destined for a host on network 10.1.1.0. Because the routing
table indicates that network 10.1.1.0 is directly connected, the router A forwards the
packet out of its FastEthernet 0/1 interface and the switches on the segment process
the packet to the host. If a destination network in the routing table is not directly
connected, the packet must reach the destination network via the next-hop router. For
example, assume that the router A receives a packet on its Serial0/0/0 interface and the
destination host address is on the 10.1.3.0 network. In this case, it must forward the
packet to the router B interface with the IPv4 address 10.1.2.2.
Routing Table
A routing table contains a list of all networks that are known to the router and
information about how to reach those networks. Each line or entry of the routing table
lists a destination network and the interface or next-hop address by which that
destination network can be reached.
A routing table may contain four types of entries:
•
•
•
•
Directly connected networks
Dynamic routes
Static routes
Default routes
Directly Connected Networks
All directly connected networks are added to the routing table automatically. A newly
deployed router, without any configured interfaces, has an empty routing table. The
directly connected routes are added after you assign a valid IP address to the router
interface, enable it with the no shutdown command, and when it receives a carrier
signal from another device (router, switch, end device, and so on). In other words, when
the interface status is up/up, the network of that interface is added to the routing table
as a directly connected network. If the hardware fails or is administratively shut down,
the entry for that network is removed from the routing table. The following figure shows
examples of routing table entries for directly connected networks. An active, properly
configured, directly connected interface actually creates two routing table entries. The
following figure displays the IPv4 routing table entries on R1 for the directly connected
network 10.1.1.0/24.
The entries contain the following information:
•
•
•
Route source: Identifies how the route was learned. Directly connected interfaces have
two route source codes. "C" identifies a directly connected network. "L" identifies the
local IPv4 address assigned to the router’s interface.
Destination network: For directly connected networks, the destination networks are
local to the router. The destination network address is indicated with network address
and subnet mask in the form of the prefix. Note that "L" entries, which identify the local
IPv4 address of the interface, have a prefix of /32.
Outgoing interface: Identifies the exit interface to use when forwarding packets to the
destination network.
Dynamic Routes
Dynamic routing protocols are used by routers to share information about the
reachability and status of remote networks. A dynamic routing protocol allows routers to
automatically learn about remote networks from other routers. These networks, and the
best path to each, are added to the routing table of the router, and identified as a
network learned by a specific dynamic routing protocol. Cisco routers can support a
variety of dynamic IPv4 and IPv6 routing protocols, such as Border Gateway Protocol
(BGP), Open Shortest Path First (OSPF), Enhanced Interior Gateway Routing Protocol
(EIGRP), Intermediate System-to-Intermediate System (IS-IS), Routing Information
Protocol (RIP), and so on. The routing information is updated when changes in the
network occur. Larger networks require dynamic routing because there are usually
many subnets and constant changes. These changes require updates to routing tables
across all routers in the network, to prevent connectivity loss. Dynamic routing protocols
ensure that the routing table is automatically updated to reflect changes in network. The
following figure displays an IPv4 routing table entry on R1 for the route to remote
network 172.16.1.0/24.
From the example entry, you can tell the following:
•
•
•
•
•
•
•
Route source: Identifies how the route was learned. "O" in the figure indicates that the
source of the entry was the OSPF dynamic routing protocol.
Destination network: Identifies the address of the remote network. The router knows
how to reach 172.16.1.0/24 network.
Administrative distance: Identifies the trustworthiness of the route source. Lower
values indicate preferred route source. OSPF has a default administrative distance
value of 110.
Metric: Identifies the value assigned to reach the remote network. Lower values
indicate preferred routes. This OSPF route has a metric of 2 for the destination network
172.16.1.0/24.
Next-hop: Identifies the IPv4 address of the next router to forward the packet to. The
IPv4 address of the next-hop is 192.168.10.2.
Route timestamp: Identifies how much time has passed since the route was learned.
The information in the example entry was learned 3 minutes and 23 seconds ago.
Outgoing interface: Identifies the exit interface to use to forward a packet toward the
final destination. The packets destined to the 172.16.1.0/24 network will be forwarded
out of the GigabitEthernet 0/1 interface.
Static Routes
Static routes are entries that you manually enter directly into the configuration of the
router. Static routes are not automatically updated and must be manually reconfigured if
the network topology changes. Static routes can be effective for small, simple networks
that do not change frequently. The benefits of using static routes include improved
security and resource efficiency. The main disadvantage of using static routes is the
lack of automatic reconfiguration if the network topology changes. There are two
common types of static routes in the routing table—static routes to a specific network
and the default static route.
From the example entry, you can tell the following:
•
•
•
•
•
Route source: Identifies how the route was learned. Static routes have a route source
code "S".
Destination network: The destination network address is indicated with network
address and subnet mask in the form of the prefix. The router knows how to reach
192.168.30.0/24 network.
Administrative distance: Identifies the trustworthiness of the route source. Lower
values indicate preferred route source. Static routes have a default administrative
distance value of 1.
Metric: Identifies the value assigned to reach the remote network. Static routes do not
calculate metric the same way as dynamic routes, metric is set. Default value for
administrative distance of a static route is 0.
Next-hop: Identifies the IPv4 address of the next router to forward the packet to. The
IPv4 address of the next-hop is 192.168.10.2.
Default Routes
A default route is an optional entry, which is used by the router if a packet does not
match any other, a more specific route in the routing table. A default route can be
dynamically learned or statically configured. There may be more than one source
providing the default route, but the selected default route is presented in the routing
table as Gateway of last resort.
From the example entry, you can tell the following:
•
•
•
•
•
Route source: Identifies how the route was learned. Default route is marked with an
asterisk (*). Depending on the source of a default route, asterisk is added to the route
source (S* in the example.)
Destination network: The destination network for default route is 0.0.0.0/0.
Administrative distance: Identifies the trustworthiness of the route source. Lower
values indicate preferred route source. Default route has the same administrative
distance as a source of a default route. In the example, the default route's source is a
static route, with a default administrative distance value of 1.
Metric: Identifies the value assigned to reach the remote network. The default route
inherits the metric value from the route source. In the example, since the default route is
statically configured, the metric is 0.
Next-hop: Identifies the IPv4 address of the next router to forward the packet to. The
IPv4 address of the next-hop for the default route in the example is 10.1.1.1.
IPv4 Routing Table Example
On a Cisco router, the show ip route command can be used to display the IPv4 routing
table of a router. The command output is used to verify that IPv4 networks and specific
interface addresses have been installed in the IPv4 routing table. The following output
displays the routing table of RouterA.
RouterA# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, + - replicated route
Gateway of last resort is 10.1.1.1 to network 0.0.0.0
C 10.1.1.0/24 is directly connected, GigabitEthernet0/0
L 10.1.1.2/32 is directly connected, GigabitEthernet0/0
R 172.16.0.0/16 [120/1] via 192.168.10.2, 00:01:08, GigabitEthernet0/1
O 172.16.1.0/24 [110/2] via 192.168.10.2, 00:03:23, GigabitEthernet0/1
D 192.168.20.0/24 [90/156160] via 10.1.1.1, 00:01:23, GigabitEthernet0/0
S 192.168.30.0/24 [1/0] via 192.168.10.2
C 192.168.10.0/24 is directly connected, GigabitEthernet0/1
L 192.168.10.1/32 is directly connected, GigabitEthernet0/1
S* 0.0.0.0/0 [1/0] via 10.1.1.1
The output shows that RouterA has received routes from multiple sources (static routes
and routing protocols), which would be uncommon in a production network. However,
this table is used here to demonstrate the various route sources. The first part of the
output explains the codes, presenting the letters and the associated sources of the
entries in the routing table.
The letters are:
•
•
•
•
•
•
•
C: Indicates directly connected networks; the first and seventh entries are directly
connected networks.
L: Indicates local interfaces within connected networks; the second and eighth entries
are local interfaces.
R: Indicates RIP; the third entry is RIP route.
O: Indicates OSPF; the fourth entry is an OSPF route.
D: Indicates EIGRP; the fifth entry is an EIGRP route. The letter D stands for Diffusing
Update Algorithm (DUAL), which is the update algorithm that EIGRP uses. The code
letter E was previously taken by the legacy exterior gateway protocol (EGP).
S: Indicates static routes; the sixth and ninth entries are static routes.
Asterisk (*): Indicates that this static route is a candidate for the default route.
Path Determination
Determining the best path involves the evaluation of multiple paths to the same
destination network and selecting the optimum path to reach that network. When you
statically configure a route, then you determine what is the best path to the network. But
when dynamic routing protocols are used, the best path is selected by a routing protocol
based on the quantitative value called metric. A metric is the quantitative value used to
measure how to get to a given network. A dynamic routing protocol’s best path to a
network is the path with the lowest metric.
Dynamic routing protocols typically use their own rules and metrics. The routing
algorithm calculates a metric for each path to the destination network. Metrics can be
based on either a single characteristic, such as bandwidth, or several characteristics of
a path, such as bandwidth, delay and reliability. Some routing protocols can base route
selection on multiple metrics, combining them into a single metric.
Review the example topology in the following figure.
Router R1 has multiple paths to LAN B network. One possible path is R1 > R2 > R3. An
alternative path is R1 > R3. If router R1 runs a routing protocol that uses "hop count" as
a metric, that protocol will count how many routers there are to the destination. R1
router would choose the path R1 > R3, because there is only 1 router on that path to the
LAN B. The example of a protocol that uses hop count as a metric is RIP.
OSPF and EIGRP routing protocols do not count routers, but both take into
consideration the bandwidth of the links on the path to the destination. In the example in
the figure, when bandwidth is considered, then R1 > R2 > R3 path along 1-Gbps links is
a better path than R1 > R3 with the bandwidth of 100 Mbps.
Each dynamic protocol offers its best path (its lowest metric route) to the routing table.
Administrative Distance
Routing tables can be populated from three types of sources: directly connected
networks, static routes, and routing protocols. The router must be able to evaluate the
routing information from all the sources and select the best route to each destination
network to install into the routing table.
It is possible for a router to be configured with multiple routing protocols and static
routes. If this occurs, the routing table may have more than one route source for the
same destination network. Cisco IOS Software uses what is known as the
administrative distance to determine the route to install into the IP routing table. The
administrative distance represents the "trustworthiness" of the route; the lower the
administrative distance, the more trustworthy the route source. For example, a static
route has a default administrative distance of 1, whereas an OSPF-learned route has a
default administrative distance of 110. Given separate routes to the same destination
with different administrative distances, the router chooses the route with the lowest
administrative distance.
Administrative distance is used as a tie breaker only when different sources offer the
information for the same destination network, i.e. the same network address and subnet
mask. For example, if both static and dynamic route sources offer information for
172.16.1.0/24 network, then the administrative distance will decide whether a static or
dynamic entry will be installed in the routing table. But, if the static route source offers
information for 172.16.0.0/16 and the dynamic route source offers information for
172.16.1.0/24, then these are considered different routes and there is no need for an
administrative distance to break a tie.
When a router has the choice of a static route and an OSPF route, the static route takes
precedence. Similarly, a directly connected route with an administrative distance of 0
takes precedence over a static route with an administrative distance of 1.
Each source type has a default administrative distance. The figure lists several routing
sources and their associated administrative distances. The values in the table are
default values, which can be changed.
Route Source
Default Administrative Distance
Connected
0
Static
1
EIGRP
90
OSPF
110
Keep in mind these takeaways regarding routing table sources:
•
•
•
Directly connected networks have an administrative distance of 0 and therefore preempt
all other entries for that destination network. Only a directly connected route can have
an administrative distance of 0 and the administrative distance of 0 cannot be modified
for directly connected networks.
Static routes have a default administrative distance of 1; therefore, if you configure a
static route, it will be included in the routing table unless there is a direct connection to
the destination network.
Each routing protocol has its own default administrative distance. The OSPF
administrative distance is 110, the administrative distance of EIGRP protocol is 90.
In the figure, the router has received two routing update messages—one from OSPF
and one from EIGRP. The metric that EIGRP uses has determined that the best path to
network 172.17.8.0/24 is via 192.168.5.2, but the metric that OSPF uses has
determined that the best path to 172.17.8.0/24 is via 192.168.3.1. Each routing protocol
uses a different metric to calculate the best path to a given destination, if it learns
multiple paths to the same destination.
The router has used the administrative distance feature to determine which route to
install in its routing table. Because the administrative distance for OSPF is 110 and the
administrative distance for EIGRP is 90, the router has chosen the EIGRP route and
adds only the EIGRP route to its routing table.
Route Selection in Cisco Routers
After installing route entries in the routing table, the routing table may contain entries
both for a destination network and for its subnets. For example, the routing table may
contain entry for 10.0.0.0/8, but also entries for subnets of that network, i.e.
10.10.0.0/16, 10.10.1.0/24, and 10.10.2.0/24.
When a router receives a packet, it looks at the routing table to determine how to
forward it to the final destination. The router always tries to find an exact match for the
destination IPv4 address included in the IPv4 header of the packet, but very rarely such
route exists in the routing table; therefore, the router looks for the best match.
Because each entry in a routing table may specify a subnetwork, a packet’s destination
address may match more than one routing table entry. For instance, a packet destined
to 10.10.2.3, would match entries 10.0.0.0/8, 10.10.0.0/16, and 10.10.2.0/24. Although
all three routes match the destination address, they do not match it in the same way.
The 10.10.2.3 destination IPv4 address matches 10.0.0.0/8 destination network only in
the first 8 bits. The 10.10.2.3 destination IPv4 address matches 10.10.0.0/16 destination
network only in the first 16 bits. Finally, the 10.10.2.3 destination IPv4 address matches
10.10.2.0/24 destination network in the first 24 bits. The routing table entry whose
leading address bits match the largest number of the packet destination address bits is
called the longest prefix match. In this example, 10.10.2.0/24 is the longest prefix
match.
The longest prefix match always wins among the routes that are installed in the routing
table, i.e. among entries that are already in the routing table.
Making a forwarding decision actually consists of three sets of processes: the routing
processes, the routing table, and the actual process that makes the forwarding decision
and switches packets.
Three processes are involved in building and maintaining the routing table in a Cisco
router:
•
•
•
Various routing processes, which actually run a routing protocol, such as RIP version 2
(RIPv2), EIGRP, IS-IS, and OSPF. The best route from a routing process has a
potential to be installed into the routing table. The routing protocol with the lowest
administrative distance always wins when installing routes into the routing table.
The routing table itself, which accepts information from the routing processes and also
replies to requests for information from the forwarding process.
The forwarding process, which requests information from the routing table to make a
packet forwarding decision.
Configuring a Cisco Router
Introduction
In a similar way as a switch, proper physical installation of a router is very important and
since there are many different models of routers, as a network engineer, you will have
to install and connect your router according to the model specifics, which are always
described in the installation documentation. After a router is physically set up, you will
typically need to connect to the router via a console interface and start configuring it.
You need to understand the initial configuration steps to properly configure the router,
however, the initial configuration of different models is typically similar. But before you
start with the initial configuration, it’s always a smart idea to check if the router hardware
is working properly. Then, you can start setting up interfaces that are connected to
different Internet Protocol (IP) networks and check their status. You can also check
what network devices the router can communicate with on the same link by using
different discovery protocols.
In Enterprise environments, routers and other devices performing routing are located in
different parts of the campus, while at home or smaller branches, they are typically
located close to the link to the telecommunication provider. In either case, you will need
to configure the interfaces according to some Enterprise or internet provider IP
addressing plan.
Cisco Enterprise Architecture Model
As a network engineer, it is critical that you master the set up of a router including:
•
•
•
Going through the initial steps to properly configure a router.
Configure and verify an interface on a router.
Configure and check the neighbors of your networking devices.
Initial Router Setup
Cisco provides several different types of router hardware, including some routers that
do only routing, while other routers offer additional functions. In fact, Cisco has a series
of integrated services routers (ISRs), with the name emphasizing the fact that many
functions are integrated into a single device.
The following figure shows a Cisco ISR with some of the more important features
highlighted.
Unlike a computer end device, Cisco routers do not have a keyboard, monitor, or mouse
device to allow direct user interaction. However, you can configure the router from a
personal computer (PC). At the initial installation, the PC has to be connected to the
router directly through the console port. To connect to the console port, you use a
console cable, which is also called a roll-over cable.
The console port can be an RJ-45 port or a USB port. A Cisco router might have only
one type or both types of console ports. When the console port on a device is an RJ-45
port, you require a console cable with an RJ-45 connector on one end. The other end
can be a serial DB-9 connector or a USB connector. Most of the modern computers
have USB ports and rarely include built-in serial ports. In case your console cable has a
serial connector, you will need a serial-to-USB adapter and operating system driver
(USB-to-RS-232-compatible serial port adapter) to establish connectivity.
When the console port is a USB port, you need a suitable USB cable (for example, a
USB Type A-to-5-pin mini Type B) and operating system device driver to establish
connectivity.
Your PC also needs a serial port and the communications software, such as Tera Term
or putty, configured with the following settings:
•
•
•
•
•
Speed: 9600 bps
Data bits: 8
Parity: None
Stop bit: 1
Flow control: None
On routers with two console ports, only one console port can be active at a time. When a
cable is plugged into the USB console port, the RJ-45 port becomes inactive. When the
USB cable is removed from the USB port, the RJ-45 port becomes active.
The startup of a Cisco router requires verifying the physical installation, powering up the
router, and viewing the Cisco IOS Software output on the console.
The router completes these tasks to start router operations:
1. Runs the power-on self-test (POST) to test the hardware. During POST, the router
executes diagnostics to verify the basic operation of the central processing unit (CPU),
memory, and interface circuitry.
2. Finds and loads the Cisco IOS Software that the router uses for its operating system.
3. Finds and loads the configuration file, if one exists. The configuration file contains
statements about router-specific attributes, protocol functions, and interface addresses.
Before you start the router, verify the power and cooling requirements, cabling, and
console connection. Then, push the power switch to "On" and observe both the boot
sequence and the Cisco IOS Software output on the console.
After a router completes POST and loads a Cisco IOS Software image, it looks for a
device configuration file in its nonvolatile random-access memory (NVRAM), known as
the startup-config. If the router does not find one, it executes a question-driven, initial
configuration routine that is called "setup." Setup is a prompt-driven program that allows
minimal device configuration. If the router has a startup configuration file in NVRAM, the
user EXEC mode prompt appears.
A router without an existing configuration enters the system configuration dialog.
....System Configuration Dialog....
Continue with configuration dialog? [yes/no]:
A configured router with an existing configuration displays a user EXEC mode prompt.
RouterX con0 is now available
Press RETURN to get started.
RouterX>
If there is a username and/or password configured, you will instead get a prompt to enter
credentials.
The setup mode is not intended for entering complex protocol features in the router but
rather for bringing up a minimal configuration. You do not have to use the setup mode;
you can use other configuration modes to configure the router.
The primary purpose of the setup mode is to rapidly bring up a minimal-feature
configuration for any router that cannot find its configuration from some other source. In
addition to being able to run the setup mode when the router boots, you may also
initiate it by entering the setup privileged EXEC mode command.
To skip the system configuration dialog and configure the router manually, answer the
first question in the system configuration dialog with no, or press Ctrl-C.
Router# setup
....System Configuration Dialog....
Continue with configuration dialog? [yes/no]: no
To verify the router status, use the show version command:
R1# show version
Cisco IOS Software, Linux Software (I86BI_LINUX-ADVENTERPRISEK9-M), Version
15.2(4)M3, DEVELOPMENT TEST SOFTWARE
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2013 by Cisco Systems, Inc.
Compiled Tue 26-Feb-13 19:06 by prod_rel_team
ROM: Bootstrap program is Linux
R1 uptime is 0 minutes
System returned to ROM by reload at 0
System restarted at 03:00:23 CET Wed May 7 2019
System image file is "unix:/iou_root/images/IOL/i86bi_linux-adventerprisek9ms.152-4.M3"
<... output omitted ...>
To verify the running configuration of the router, use the show runningconfig command:
R1# show running-config
Building configuration...
Current configuration : 2919 bytes
!
! No configuration change since last restart
version 15.2
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R1
<... output omitted ...>
Configuring Router Interfaces
One of the main functions of a router is to forward packets from one network device to
another. For the router to perform this task, you must define the characteristics of the
interfaces through which the router receives and forwards the packets.
There are generally two types of physical interfaces that are used for forwarding
packets on Cisco routers: Ethernet interfaces and serial interfaces.
•
•
Ethernet interfaces: The term Ethernet interface refers to any type of Ethernet
interface. For example, some Cisco routers have an Ethernet interface that is capable of
only 10 Mbps, so to configure this type of interface, you would use the interface
Ethernetinterface-identifier configuration command. However, other routers have
interfaces that are capable of operating up to 100 Mbps. These interfaces are referred
to as Fast Ethernet ports. You use the interface FastEthernet interfaceidentifier command to configure these types of ports. Similarly, the interfaces that are
capable of Gigabit Ethernet speeds are referenced with the interface
GigabitEthernet interface-identifier command. The interfaces that are capable of
operating up to 10 Gbps, 25 Gbps, 40 Gbps, and 100 Gpbs Ethernet speed are
referenced with the interface TenGigabitEthernet interfaceidentifier, interface TwentyFiveGigEinterfaceidentifier, interface FortyGigabitEthernet interface-identifier,
and interface HundredGigE interface-identifiercommands respectively.
Serial interfaces: Serial interfaces are the second major type of physical interfaces on
Cisco routers. To support point-to-point leased lines and Frame Relay access-link
standards, Cisco routers use serial interfaces. You can then choose which data link
layer protocol to use, such as High-Level Data Link Control (HDLC) or Point-to-Point
Protocol (PPP) for leased lines or Frame Relay for Frame Relay connections, and
configure the router to use the correct data link layer protocol. Use the interface
serial interface-identifier command when configuring these types of interfaces.
Routers use interface-identifiers to distinguish between interfaces of the same type.
Depending on the model of the router, the interface-identifier may be:
•
•
•
An interface number, for example interface ethernet 1
A slot/interface number, for example interface fastethernet 0/1
A module/slot/interface number, for example interface serial 1/0/1
It is appropriate to mention the loopback interface here. A loopback interface is a virtual
interface that resides on a router. It is not connected to any other device. Loopback
interfaces are very useful because they will never go "down," unless the entire router
goes down or the interface is manually disabled. This helps in managing routers because
there will always be at least one active interface on the routers—the loopback interface.
To create a loopback interface, all you need to do is enter the configuration mode for the
interface. Optionally, you may add an IP version 4 (IPv4) address.
Router(config)# interface loopback 0
Router(config-if)# ip address 10.0.0.1 255.255.255.255
An IPv4 address with a mask of 255.255.255.255 (prefix /32, all bits set to binary 1) is
called the host IPv4 address. The host IPv4 address indicates that only one IPv4
address is used in the subnet and is often used to address loopback interfaces.
You can configure the loopback address with something less than a /32. The routing
table will see that as a directly connected network, but the interface address will be
given a /32.
The router interface characteristics include, but are not limited to, interface description,
the IP address of the interface, the data link encapsulation method, the media type, the
bandwidth, and the clock rate. You can enable many features on a per-interface basis.
When you first configure an interface, except in the setup mode, you must
administratively enable the interface before the router can use it to transmit and receive
packets. Use the no shutdown command to enable the interface.
You may want to disable an interface to perform hardware maintenance on a specific
interface or a segment of a network. You may also want to disable an interface if a
problem exists on a specific segment of the network, and you must isolate this segment
from the rest of the network. The shutdown command disables, or administratively
turns off an interface. To re-enable the interface, use theno shutdown command.
To enable an interface:
RouterX# configure terminal
RouterX(config)# interface GigabitEthernet 0/0
RouterX(config-if)# no shutdown
%LINK-3-UPDOWN: Interface GigabitEthernet0/0, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0,
changed state to up
To disable an interface:
RouterX# configure terminal
RouterX(config)# interface Serial 0/0/0
RouterX(config-if)# shutdown
%LINK-5-CHANGED: Interface Serial0/0/0, changed state to administratively
down
%LINEPROTO-5-UPDOWN: Line protocol on Interface Serial0/0/0, changed state
to down
Configuring IPv4 Addresses on Router Interfaces
When you are sending mail via the postal service, you need street addresses to identify
the locations of specific homes and companies so that mail can reach those real-world
locations. In the same way, each interface on a Cisco router must have its own IP
address to uniquely identify it on the network. If no IP address is configured, even if the
interface is in the "up/up" state, the router will not attempt to send and receive IP
packets on the interface. To attain proper operation, for every interface that a router
should use for forwarding IPv4 packets, the router needs an IPv4 address.
The configuration of an IPv4 address on an interface is relatively simple. To configure
the address and mask, simply use the ip address ip-address mask interface
subcommand. The following example shows the configuration of an IPv4 address on the
serial interface of a router.
RouterX# configure terminal
RouterX(config)# interface Serial 0/0/0
RouterX(config-if)# ip address 172.18.0.1 255.255.0.0
RouterX(config-if)# no shutdown
The specific steps to configure an interface on a Cisco router are as follows:
Although the use of 172.18.0.0/16 network is technically correct, it in fact represents a
huge waste of IP Addresses, since it allows for 65534 hosts and on serial point-to-point
links we have only two hosts.
So, a better IP Address/Mask would be 172.18.0.1/30 on Router X and 172.18.0.2/30 on
router Y.
Configuration of an IPv4 Address on the Serial Interface of a Router
Step Action
Results and Notes
1
Enter the global configuration mode using
the configure terminal command:
Router# configure terminal
Displays a new prompt:
Router(config)#
2
Identify the specific interface that requires an IPv4
address by using theinterface type interfaceidentifier command:
Router(config)# interface Serial 0/0/0
Displays a new prompt; for
example:
Router(config-if)#
3
Set the IPv4 address and subnet mask for the interface
by using the ip address ip-address mask command:
Router(config-if)# ip address 172.18.0.1 255.255.0.0
Configures the IPv4 address and
subnet mask for the selected
interface
4
Enable the interface to change the state from
"administratively down" to "up" by using the no
shutdown command:
Router(config-if)# no shutdown
Enables the current interface
Checking Interface Configuration and Status
When you have completed the router interface configuration, you can verify the
configuration by using various show commands.
You can view information about interfaces by using several commands:
•
•
•
•
•
show ip interface brief: A brief list of interfaces and their IPv4 addresses.
show protocols type interface-identifier: Brief details about a particular interface.
show interfaces: Details about all the interfaces (for example, packets that are flowing
in and out of the interface).
Optionally, you can include the interface type and slot/interface number on many
commands:
show interfaces type interface-identifier: Details for a specific interface.
When you configure an IP address on an interface, the router automatically calculates
the subnet and installs it in the routing table as a connected route. This will result in two
lines added for that newly configured interface, one with the letter "C" (the connected
route) and another with the letter "L" (the local interface IPv4 address). Note that "L"
entries, which identify the IPv4 address of the interface, have a subnet mask of /32.
The following examples show sample outputs from the presented commands.
RouterY# show ip interface brief
Interface IP-Address OK? Method Status Protocol
FastEthernet0/0 10.1.1.1 YES manual up up
FastEthernet0/1 unassigned YES unset administratively down down
Serial0/0/0 unassigned YES unset administratively down down
Serial0/0/1 unassigned YES unset up up
Serial0/1/0 unassigned YES unset up up
Serial0/1/1 unassigned YES unset administratively down down
The following table shows the output fields and their meanings.
Output
Field
Description
Interface
Type of specific interface
IP Address
IPv4 address that is assigned to the interface
OK?
"Yes" means that the IPv4 address is valid; "No" means that the IPv4 address is
not valid
Method
Describes how the IPv4 address was obtained or configured.
Status
Indicates the physical layer status of the interface.
Output
Field
Description
Protocol
Indicates the data link layer status of the interface.
R2# show protocols Ethernet 0/0
Ethernet0/0 is up, line protocol is up
Internet address is 10.10.2.1/24
RouterX# show interfaces
GigabitEthernet0/0 is up, line protocol is up
Hardware is CN Gigabit Ethernet, address is f866.f231.7250 (bia
f866.f231.7250)
Description: Link to ISP
Internet address is 192.168.2.1/24
MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Full Duplex, 100Mbps, media type is RJ45
output flow-control is unsupported, input flow-control is unsupported
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:53, output 00:00:09, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
<... output omitted ...>
The table shows some of the output fields for a Gigabit Ethernet interface and their
meanings in this example.
Output
Description
GigabitEthernet...is
{up | down |
administratively
down}
Line protocol is
{up | down}
Indicates whether the interface hardware is currently active, down, or if an
administrator has taken it down. Please refer to the Troubleshooting Status
Codes table for explanation of all the combinations of these two statuses.
Hardware
Displays the hardware type and Media Access Control (MAC) address.
Description
Displays the configured interface description.
Output
Description
Internet address
Displays the IPv4 address followed by the prefix length (subnet mask).
MTU
Displays the maximum transmission unit (MTU) of the interface.
BW
Shows the bandwidth of the interface in kilobits per second. The
bandwidth parameter is used to compute routing protocol metrics and
other calculations.
DLY
Shows the delay of the interface in microseconds. This parameter is used
to compute routing protocol metrics and other calculations.
Rely
Displays the reliability of the interface as a fraction of 255 (255/255 is
100% reliability). This parameter is used to compute routing protocol
metrics and other calculations.
Load
Displays the load on the interface as a fraction of 255 (255/255 is
completely saturated). This parameter is used to compute routing protocol
metrics and other calculations.
Encapsulation
Shows the encapsulation method that is used on the interface.
5-minute input
rate,
5-minute output
rate
Shows the average number of bits and packets that the interface
transmitted per second in the last 5 minutes.
By truncating the words, you can significantly shorten the commands that
refer to router interfaces. For example, you can use show int Fa0/0 instead
of show interfaces FastEthernet0/0.
Each of the command outputs shown in the previous examples lists two interface status
codes. For a router to use an interface, the two interface status codes on the interface
must be in the up state. The first status code refers to whether the physical layer (Layer
1) is working, and the second status code mainly (but not always) refers to whether the
data link layer (Layer 2) protocol is working.
Four combinations of settings exist for the status codes when troubleshooting a
network. The following table lists the four combinations, along with an explanation of the
typical reasons why an interface would be in this state. As you review the list, note that
if the hardware status (the first status code) is not "up," the second will always be
"down," because the data link layer functions cannot work if the physical layer has a
problem.
Troubleshooting Status Codes with Four Combinations of Settings
Hardware and
Line Protocol
Status
Typical Reasons
administratively
down, down
The interface has a shutdown command that is configured on it.
down, down
The interface has a no shutdown command that is configured, but the
physical layer has a problem. For example, no cable has been attached to the
interface, or with Ethernet, the switch interface on the other end of the cable
is shut down, or the switch is powered off.
up, down
Almost always refers to data link layer problems, most often configuration
problems. For example, serial links have this combination when one router is
configured to use one protocol, and the other defaults to use another.
up, up
All is well, and the interface is functioning.
Discovery 5: Configure an Interface on a Cisco Router
Introduction
This discovery lab will guide you through the configuration of an interface on a Cisco
IOS router. The lab is prepared with the devices that are represented in the topology
diagram and in the connectivity table. In general, the devices are fully configured. An
exception is the Ethernet0/0 interface on R1. You will configure that interface now.
Topology
Job Aid
Device Information
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today.
Personal computers (PCs) in the virtual lab environment are simulated by routers, so you
should use Cisco IOS commands to configure them or verify the configuration.
Device Information Table
Device
Characteristic
Value
R1
Ethernet0/0 description
Not configured
R1
Ethernet0/0 IPv4 address
Not configured
R1
Loopback 0 IPv4 address
10.10.3.1/24
Device
Characteristic
Value
PC1
IPv4 address
10.10.1.10/24
PC1
Default gateway
10.10.1.1
PC2
IPv4 address
10.10.1.20/24
PC2
Default gateway
10.10.1.1
SW1
VLAN 1 IPv4 address
10.10.1.2/24
SW1
Default gateway
10.10.1.1
SW2
VLAN 1 IPv4 address
10.10.1.3/24
SW2
Default gateway
10.10.1.1
Task 1: Configure an IPv4 Address on the Router Interfaces
Activity
Step 1
Access the console of R1 and enter the global configuration mode.
On R1, enter the following command:
R1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
R1(config)#
Step 2
Enter the interface configuration mode for Ethernet0/0, configure 10.10.1.1/24 as its
IPv4 address, add an interface description, and then enable the interface.
On R1, enter the following commands:
R1(config)# interface Ethernet 0/0
R1(config-if)# ip address 10.10.1.1 255.255.255.0
R1(config-if)# description Link to SW2
R1(config-if)# no shutdown
Step 3
Examine the IPv4 routing table on R1. You should see the IPv4 address (L—local) and
IPv4 subnet (C—connected) that you have just configured on the Ethernet0/0 interface.
When you need to apply a privilege mode command from the configuration mode then
an easy way of doing it is to add the “do” keyword before your actual command to save
your time from going back and forth between the different modes.
On R1, enter the following commands:
R1(config-if)# do show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
+ - replicated route, % - next hop override
Gateway of last resort is not set
10.0.0.0/8 is variably subnetted, 4 subnets, 2 masks
C 10.10.1.0/24 is directly connected, Ethernet0/0
L 10.10.1.1/32 is directly connected, Ethernet0/0
C 10.10.3.0/24 is directly connected, Loopback0
L 10.10.3.1/32 is directly connected, Loopback0
In the routing table, the local (L) 10.10.1.1/32 IPv4 address identifies the IPv4 address
used on the Ethernet0/0 interface. The connected (C) 10.10.1.0/24 network identifies
the network where the Ethernet0/0 interface belongs.
Note that there is another pair of C and L entries in the routing table. These are related
to the router loopback interface that is pre-configured on the router.
Step 4
Use the do command to execute an EXEC mode ping command. Attempt to ping PC1
(10.10.1.10). The attempt should succeed.
On R1, enter the following command:
R1(config-if)# do ping 10.10.1.10
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.10, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
R1(config-if)#
It is common for the first one or two ICMP echo requests to time out. It is usually due to
delays that are associated with updating the ARP cache with the MAC address of the
local peer.
Step 5
Leave the global configuration mode.
On R1, enter the following command:
R1(config-if)# end
R1#
Task 2: Verify Interface Configuration and Status
Activity
Step 1
On R1, verify that the running configuration for the Ethernet0/0 interface is correct.
On R1, enter the following command:
R1# show running-config interface Ethernet 0/0
Building configuration...
Current configuration : 90 bytes
!
interface Ethernet0/0
description Link to SW2
ip address 10.10.1.1 255.255.255.0
end
Router interfaces are “shutdown” by default. If you were to use the show runningconfig interface interface-id command before enabling the interface, you would see the
"shutdown" keyword displayed for the interface. However, when you enable the
interface by applying the no shutdown command, you will not see "no shutdown"
keyword when using the show running-configcommand, as in the example.
Commands for some settings are not shown in the output of the show runningconfig command after you enter them. Certain settings, such as interface administrative
status, are considered default and they do not appear in theshow runningconfig output, unless they are changed.
Step 2
On R1, display a brief summary of the IP information and the statuses of all interfaces.
On R1, enter the following command:
R1# show ip interface brief
Interface IP-Address OK? Method Status Protocol
Ethernet0/0 10.10.1.1 YES manual up up
Ethernet0/1 unassigned YES NVRAM administratively down down
Ethernet0/2 unassigned YES NVRAM administratively down down
Ethernet0/3 unassigned YES NVRAM administratively down down
Serial1/0 unassigned YES NVRAM administratively down down
Serial1/1 unassigned YES NVRAM administratively down down
Serial1/2 unassigned YES NVRAM administratively down down
Serial1/3 unassigned YES NVRAM administratively down down
Loopback0 10.10.3.1 YES NVRAM up up
The Ethernet0/0 interface is configured with the correct IPv4 address. Both the status
and the protocol are "up".
Step 3
On the R1 router, display the status and statistics of the Ethernet0/0 interface.
On R1, enter the following command:
R1# show interfaces Ethernet 0/0
Ethernet0/0 is up, line protocol is up
Hardware is AmdP2, address is aabb.cc00.1800 (bia aabb.cc00.1800)
Description: Link to SW2
Internet address is 10.10.1.1/24
MTU 1500 bytes, BW 10000 Kbit/sec, DLY 1000 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:00, output 00:00:06, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
1116 packets input, 71557 bytes, 0 no buffer
Received 947 broadcasts (0 IP multicasts)
0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 input packets with dribble condition detected
218 packets output, 23872 bytes, 0 underruns
0 output errors, 0 collisions, 2 interface resets
3 unknown protocol drops
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier
0 output buffer failures, 0 output buffers swapped out
From the output, you can see that both the status and the protocol for Ethernet0/0
interface are "up". The interface description is "Link to SW2." 10.10.1.1 is the IPv4
address applied on the interface.
The MAC address on your interface may be different than that shown in the example
output.
Exploring Connected Devices
Most network devices, by definition, do not work in isolation. A Cisco device frequently
has other Cisco devices as neighbors on the network. If you are able to obtain
information about those other devices, it can help you with any network design
decisions, troubleshooting, and completing equipment changes.
If you do not have any documentation about the network topology or if the existing
documentation is not up-to-date, you may find yourself in a position of needing to
discover the neighboring devices of a router. You can sometimes do this procedure
manually by inspecting the physical wiring if the devices are installed next to each other.
If you are not local to the devices, or when neighboring devices are in other buildings or
cities, you must use a different method.
One possibility is to use a dynamic discovery protocol that gathers information about
directly connected devices. Cisco devices support Cisco Discovery Protocol, which
provides information about directly connected Cisco devices and their functions and
capabilities.
Cisco Discovery Protocol is a Cisco proprietary protocol that discovers basic information
about neighboring Cisco devices without needing to know the passwords for the
neighboring devices. To discover information, routers and switches send Cisco
Discovery Protocol messages out each of their interfaces. Devices that support Cisco
Discovery Protocol learn information about other devices by listening for the
advertisements that these devices send.
From a troubleshooting perspective, you can use Cisco Discovery Protocol to confirm or
fix the information that a network diagram shows, or even discover the devices and
interfaces that a network uses. Confirming that the network is actually cabled to match
the network diagram is a good step to take before trying to predict the normal flow of
data in a network.
On media that support multicasts at the data link layer, Cisco Discovery Protocol uses
multicast frames; on other media, Cisco Discovery Protocol sends a copy of the Cisco
Discovery Protocol update to any known data link addresses. So, any Cisco Discovery
Protocol-supporting device that shares a physical medium with another Cisco Discovery
Protocol-supporting device can learn about the other device. It is common for network
administrators to disable Cisco Discovery Protocol for security reasons.
Another dynamic discovery protocol is Link Layer Discovery Protocol (LLDP), which is a
standardized, vendor-independent discovery protocol that discovers neighboring
devices from different vendors. The Institute of Electrical and Electronics Engineers
(IEEE) standardized this protocol as the 802.1AB standard. LLDP performs functions
that are similar to Cisco Discovery Protocol.
Information Obtained with Cisco Discovery Protocol
The figure displays an example of how Cisco Discovery Protocol exchanges information
with its directly connected neighbors. You can display the results of this information
exchange on a console that is connected to a network device that is configured to run
Cisco Discovery Protocol on its interfaces.
Information provided by the Cisco Discovery Protocol about each neighboring device:
•
•
•
•
•
Device identifiers: For example, the configured host name of the device
Address list: Up to one network layer address for each protocol that is supported
Port identifier: The identifier of the local port (on the receiving device) and the
connected remote port (on the sending device)
Capabilities list: Supported features—for example, the device acting as a source-route
bridge and also as a router
Platform: The hardware platform of the device—for example, Cisco 4000 Series
Routers
Notice that the upper router in the figure is not connected directly to switch A (the switch
that the administrator is connected to). To obtain Cisco Discovery Protocol information
about this upper router from switch A console, the administrator could use Telnet or
SSH to connect to a switch that is connected directly to this router.
Using Cisco Discovery Protocol
You can enable or disable Cisco Discovery Protocol on a router as a whole (global) or
on a port-by-port (interface) basis. You can also view Cisco Discovery Protocol
information with the show cdp command. This command has several keywords that
enable access to different types of information and different levels of detail. The
following example shows the different show cdp options.
RouterA# show cdp ?
entry Information for specific neighbor entry
interface CDP interface status and configuration
neighbors CDP neighbor entries
traffic CDP statistics
The Cisco Discovery Protocol is enabled by default on most interfaces (except for some
legacy interfaces), but you can disable this functionality at the device and interface
level.
To prevent other Cisco Discovery Protocol-capable devices from accessing information
about a specific device, use the no cdp run global configuration command. To disable
Cisco Discovery Protocol on an interface, use the no cdp enable command. To enable
Cisco Discovery Protocol on an interface, use the cdp enable interface configuration
command.
RouterA(config)# no cdp run
! Disable CDP Globally
RouterA(config)# interface serial0/0/0
RouterA(config-if)# no cdp enable
! Disable CDP on just this interface
The show cdp neighbors command displays information about Cisco Discovery
Protocol neighbors. The following example shows the Cisco Discovery Protocol output
for Router A.
RouterA# show cdp neighbors
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
S - Switch, H - Host, I - IGMP, r - Repeater
Device ID Local Intrfce Holdtme Capability Platform Port ID
SwitchA fa0/0 122 S I WS-C2960 fa0/2
RouterB s0/0/0 177 R S I 2811 s0/0/1
For each Cisco Discovery Protocol neighbor following information is displayed:
•
•
•
•
•
•
Device ID
Local interface—the interface on this device that is connected to the neighbor
Holdtime value, in seconds
Device capability code
Hardware platform
Port ID—the interface on the neighboring device that is connected to this device
The holdtime value indicates how long (in seconds) the receiving device should hold the
Cisco Discovery Protocol information before discarding it.
Cisco Discovery Protocol information is sent periodically; the holdtime counts down and
if it reaches zero, the information is discarded.
The format of the show cdp neighbors output varies among different types of devices,
but the available information is generally consistent across devices.
You can use the show cdp neighbors command on a Cisco Catalyst switch to display
the Cisco Discovery Protocol updates that the switch receives on the local interfaces.
Note that on a switch, the local interface is referred to as the local port.
If you add the detail argument to the show cdp neighbors command, the resulting
output includes additional information, such as the network layer addresses of
neighboring devices. The output from the show cdp neighbors detail command is
identical to the one that the show cdp entry * command produces.
RouterA# show cdp neighbors detail
Device ID: RouterB
Entry address(es):
IP address: 10.1.1.2
Platform: Cisco 2811, Capabilities: Router Switch IGMP
Interface: Serial0/0/0, Port ID (outgoing port): Serial0/0/1
Holdtime : 155 sec
Version :
Cisco IOS Software, 2800 Software (C2800NM-ADVIPSERVICESK9-M), Version
12.4(12), RELEASE
SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2006 by Cisco Systems, Inc.
Compiled Fri 17-Nov-06 12:02 by prod_rel_team
Note Cisco Discovery Protocol is limited to gathering information about the directly
connected Cisco neighbors. Other tools, such as Telnet and SSH, are available for
gathering information about remote devices that are not directly connected.
Configure and Verify LLDP
To permit the discovery of non-Cisco devices, Cisco devices also support LLDP, which
is a vendor-neutral device discovery protocol that is defined by IEEE 802.1AB standard.
LLDP allows network devices to advertise information about themselves to other
devices on the network. This protocol runs over the data link layer, which allows two
systems that are running different network layer protocols to learn about each other.
LLDP is a protocol that transmits information about the capabilities and the status of a
device and its interfaces. LLDP devices use the protocol to solicit information only from
other LLDP devices.
LLDP supports a set of attributes that it uses to discover other devices. These attributes
contain type, length, value (TLV) descriptions. TLVs are blocks of information
embedded in LLDP advertisements which give details about optional information
elements such as: IP address, Device ID, and Platform. LLDP devices can use TLVs to
send and receive information to other devices on the network. Using this protocol,
devices can advertise details such as configuration information, device capabilities, and
device identity.
Some of the TLVs that are advertised by LLDP:
•
•
Management address: the IP address used to access the device for management
(configuring and verifying the device)
System capabilities: different hardware and software specifications of the device
•
System name: the host name that was configured on that device
LLDP has these configuration guidelines and limitations:
•
•
•
•
Must be enabled on the device before you can enable or disable it on any interface
Is supported only on physical interfaces
Can discover up to one device per port
Can discover Linux servers
To enable or disable LLDP globally, use the following command:
R1(config)# [no] lldp run
To enable or disable LLDP on an interface, use the following commands:
R1(config-if)# [no] lldp transmit
R1(config-if)# [no] lldp receive
To display information about neighbors, use the following command:
R1# show lldp neighbors
After you globally enable LLDP, it is enabled for transmit and receive on all supported
interfaces by default. The lldp transmitcommand enables the transmission of LLDP
packets on an interface. The lldp receive command enables the reception of LLDP
packets on an interface.
The show lldp neighbors command displays information about neighbors, including
device ID, interface type and number, holdtime settings, capabilities, and port ID.
R1# show lldp neighbors
Capability codes:
(R) Router, (B) Bridge, (T) Telephone, (C) DOCSIS Cable Device
(W) WLAN Access Point, (P) Repeater, (S) Station, (O) Other
Device ID Local Intf Hold-time Capability Port ID
DSW2 Et0/2 120 R Et0/2
DSW1 Et0/1 120 R Et0/2
Total entries displayed: 2
The output in the example tells you, that router R1 has two neighbors, DSW1 and
DSW2. Both devices have routing functionality. The interfaces to reach them through
are Ethernet0/1 and Etherne0/2. This output contains information only about the
neighbors that support LLDP and have it configured to exchange information.
Discovery 6: Configure and Verify Layer 2 Discovery
Protocols
Introduction
During this activity, you will use Cisco Discovery Protocol and LLDP to map the
connectivity within an unfamiliar network. There are four devices in the topology, and
you have access to their console ports, but you do not know how they are connected.
Using Cisco Discovery Protocol and LLDP commands, you will determine the actual
topology.
Topology
Job Aid
There are no Job Aids for this lab exercise because the objective of the lab is to map
the connectivity within an unfamiliar network.
Task 1: Discover Neighbors Using Cisco Discovery Protocol
Activity
Step 1
Before accessing the console of switch SW1, wait 60 seconds for Cisco Discovery
Protocol to populate its database. On SW1, use the show cdp neighbors command to
determine the devices to which SW1 is connected. Note that the Cisco Discovery
Protocol table shows both the local port on SW1 and the port on the remote device to
which SW1 is connected.
On SW1, enter this command:
SW1# show cdp neighbors
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone,
D - Remote, C - CVTA, M - Two-port Mac Relay
Device ID Local Intrfce Holdtme Capability Platform Port ID
SW2 Eth 0/0 153 S I Linux Uni Eth 0/0
The Device ID column in the output indicates the remote device connected to SW1,
which is switch SW2. The Local Intrfce column indicates the local port (Ethernet0/0) on
SW1. The Port ID column indicates the remote port (Ethernet0/0) on SW2 used for
connecting to SW1.
Step 2
Execute the show cdp neighbors command again, but this time, use
the detail keyword. What is the IPv4 address of SW2?
On SW1, enter this command:
SW1# show cdp neighbors detail
------------------------Device ID: SW2
Entry address(es):
IP address: 10.10.1.3
Platform: Linux Unix, Capabilities: Switch IGMP
Interface: Ethernet0/0, Port ID (outgoing port): Ethernet0/0
Holdtime : 147 sec
Version :
Cisco IOS Software, Solaris Software (I86BI_LINUXL2-ADVENTERPRISEK9-M),
Experimental Version 15.1(20130919:231344) [dstivers-sept19-2013pm-team_track
107]
Copyright (c) 1986-2013 by Cisco Systems, Inc.
Compiled Thu 19-Sep-13 22:38 by dstivers
advertisement version: 2
VTP Management Domain: ''
Duplex: half
Management address(es):
IP address: 10.10.1.3
The IPv4 address of SW2 switch is 10.10.1.3.
If you do not see all of the details of the SW2 neighbor (including its IPv4 address), wait
a few minutes and try again.
Step 3
Continue the topology inspection from SW2. You know that SW1 is one of the neighbors
of SW2. What are the other neighbors of SW2?
On SW2, enter these commands:
SW2# show cdp neighbors
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone,
D - Remote, C - CVTA, M - Two-port Mac Relay
Device ID Local Intrfce Holdtme Capability Platform Port ID
SW1 Eth 0/0 130 S I Linux Uni Eth 0/0
R1 Eth 0/1 153 R Linux Uni Eth 0/0
SW2# show cdp neighbors detail
------------------------Device ID: SW1
Entry address(es):
IP address: 10.10.1.2
Platform: Linux Unix, Capabilities: Switch IGMP
Interface: Ethernet0/0, Port ID (outgoing port): Ethernet0/0
Holdtime : 124 sec
Version :
Cisco IOS Software, Solaris Software (I86BI_LINUXL2-ADVENTERPRISEK9-M),
Experimental Version 15.1(20130919:231344) [dstivers-sept19-2013pm-team_track
107]
Copyright (c) 1986-2013 by Cisco Systems, Inc.
Compiled Thu 19-Sep-13 22:38 by dstivers
advertisement version: 2
VTP Management Domain: ''
Duplex: half
Management address(es):
IP address: 10.10.1.2
------------------------Device ID: R1
Entry address(es):
IP address: 10.10.1.1
Platform: Linux Unix, Capabilities: Router
Interface: Ethernet0/1, Port ID (outgoing port): Ethernet0/0
Holdtime : 147 sec
Version :
Cisco IOS Software, Linux Software (I86BI_LINUX-ADVENTERPRISEK9-M), Version
15.2(4)M3, DEVELOPMENT TEST SOFTWARE
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2013 by Cisco Systems, Inc.
Compiled Tue 26-Feb-13 19:06 by prod_rel_team
advertisement version: 2
Duplex: half
Management address(es):
Based on the output, SW2 has two neighboring devices, SW1 and router R1. The IPv4
address of SW1 is 10.10.1.2, and the IPv4 address of R1 is 10.10.1.1.
Step 4
Continue the topology inspection from R1. What are the other neighbors of R1?
On R1, enter these commands:
R1# show cdp neighbors
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone,
D - Remote, C - CVTA, M - Two-port Mac Relay
Device ID Local Intrfce Holdtme Capability Platform Port ID
SW2 Eth 0/0 164 S I Linux Uni Eth 0/1
R2 Eth 0/1 173 R Linux Uni Eth 0/0
R1# show cdp neighbors detail
------------------------Device ID: SW2
Entry address(es):
IP address: 10.10.1.3
Platform: Linux Unix, Capabilities: Switch IGMP
Interface: Ethernet0/0, Port ID (outgoing port): Ethernet0/1
Holdtime : 161 sec
Version :
Cisco IOS Software, Solaris Software (I86BI_LINUXL2-ADVENTERPRISEK9-M),
Experimental Version 15.1(20130919:231344) [dstivers-sept19-2013pm-team_track
107]
Copyright (c) 1986-2013 by Cisco Systems, Inc.
Compiled Thu 19-Sep-13 22:38 by dstivers
advertisement version: 2
VTP Management Domain: ''
Native VLAN: 1
Duplex: half
------------------------Device ID: R2
Entry address(es):
IP address: 192.168.3.2
Platform: Linux Unix, Capabilities: Router
Interface: Ethernet0/1, Port ID (outgoing port): Ethernet0/0
Holdtime : 170 sec
Version :
Cisco IOS Software, Linux Software (I86BI_LINUX-ADVENTERPRISEK9-M), Version
15.2(4)M3, DEVELOPMENT TEST SOFTWARE
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2013 by Cisco Systems, Inc.
Compiled Tue 26-Feb-13 19:06 by prod_rel_team
advertisement version: 2
Duplex: half
The output shows that R1 has connections to SW2 and router R2, connected to local
interfaces Ethernet0/0 and Ethernet0/1, respectively. SW2 has 10.10.1.3 IPv4 address.
The IPv4 address of R2 is 192.168.3.2.
Step 5
Continue the topology inspection from R2.
On R2, enter these commands:
R2# show cdp neighbors
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone,
D - Remote, C - CVTA, M - Two-port Mac Relay
Device ID Local Intrfce Holdtme Capability Platform Port ID
R1 Eth 0/0 176 R Linux Uni Eth 0/1
R2# show cdp neighbors detail
------------------------Device ID: R1
Entry address(es):
IP address: 192.168.3.1
Platform: Linux Unix, Capabilities: Router
Interface: Ethernet0/0, Port ID (outgoing port): Ethernet0/1
Holdtime : 174 sec
Version :
Cisco IOS Software, Linux Software (I86BI_LINUX-ADVENTERPRISEK9-M), Version
15.2(4)M3, DEVELOPMENT TEST SOFTWARE
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2013 by Cisco Systems, Inc.
Compiled Tue 26-Feb-13 19:06 by prod_rel_team
advertisement version: 2
Duplex: half
R2 has no additional neighbors, so the only neighboring device is R1. The 192.168.3.1
IPv4 address is used on R1 Ethernet0/1 interface.
Task 2: Discover Neighbors Using Link Layer Discovery Protocol
Activity
Step 1
Before configuring LLDP, disable Cisco Discovery Protocol on all devices (SW1, SW2,
R1, and R2).
On SW1, enter these commands:
SW1# configure terminal
SW1(config)# no cdp run
On SW2, enter these commands:
SW2# configure terminal
SW2(config)# no cdp run
On R1, enter these commands:
R1# configure terminal
R1(config)# no cdp run
On R2, enter these commands:
R2# configure terminal
R2(config)# no cdp run
Step 2
On the SW1, SW2, R1, and R2 globally enable LLDP and exit to the Privileged EXEC
mode.
On SW1, enter these commands:
SW1(config)# lldp run
SW1(config)# exit
On SW2, enter these commands:
SW2(config)# lldp run
SW2(config)# exit
On R1, enter these commands:
R1(config)# lldp run
R1(config)# exit
On R2, enter these commands:
R2(config)# lldp run
R2(config)# exit
Step 3
On SW1, execute the show lldp neighbors command.
On SW1, enter this command:
SW1# show lldp neighbor
SW1# show lldp neighbor
Capability codes:
(R) Router, (B) Bridge, (T) Telephone, (C) DOCSIS Cable Device
(W) WLAN Access Point, (P) Repeater, (S) Station, (O) Other
Device ID Local Intf Hold-time Capability Port ID
SW2 Et0/0 120 Et0/0
Total entries displayed: 1
Note that the LLDP table shows the name of the remote device, as well as both the
local port on SW1 and the remote port on the remote device that are connected to each
other. The output is very similar to the output produced by the Cisco Discovery Protocol.
The Device ID column indicates the remote device connected to SW1, which is switch
SW2. The Local Intf column indicates the local port (Ethernet0/0) used for connecting to
the remote port (Ethernet0/0) on SW2 identified by the Port ID column.
In the virtual lab environment, when you run the LLDP on a switch, it can discover
neighbor routers and switches. But LLDP enabled router will discover only neighbor
routers.
Step 4
Execute the show lldp neighbors command again, but this time, use
the detail keyword. What is the IPv4 address of SW2?
On SW1, enter this command:
SW1# show lldp neighbors detail
-----------------------------------------------Chassis id: aabb.cc00.3b00
Port id: Et0/0
Port Description: Ethernet0/0
System Name: SW2
System Description:
Cisco IOS Software, Solaris Software (I86BI_LINUXL2-ADVENTERPRISEK9-M),
Experimental Version 15.1(20130919:231344) [dstivers-sept19-2013pm-team_track
107]
Copyright (c) 1986-2013 by Cisco Systems, Inc.
Compiled Thu 19-Sep-13 22:38 by dstivers
Time remaining: 108 seconds
System Capabilities: B,R
Enabled Capabilities - not advertised
Management Addresses:
IP: 10.10.1.3
Auto Negotiation - not supported
Physical media capabilities - not advertised
Media Attachment Unit type - not advertised
Vlan ID: - not advertised
The output is similar to the output from the Cisco Discovery Protocol and the IPv4
address of SW2 switch is 10.10.1.3.
The output of both show cdp neighbors and show lldp neighbors commands is very
similar and provide the same information, with exception of the Platform column
(provides information about the platform used on the remote device) which is only
available in the output of the show cdp neighbors command.
It is recommended that you continue the topology inspection using LLDP on the other
devices as well, to verify that you get the same results as you got from the previous
Cisco Discovery Protocol inspection.
Implement an Initial Router Configuration
FASTLab 2: Implement an Initial Router Configuration
Scenario
Read the requirements in the Scenario carefully and use the Configuration Tips to help
you do the required steps. If you need further assistance, refer to the Answer Key. Once
you have completed the configuration specified, answer the questions.
A law firm contracted CCS to connect their existing network to the internet. The router
that will be used for this implementation has arrived on site. However, the service
provider has yet to provide the physical connection to the internet. The law firm has
requested CCS to complete the router installation part of the implementation process. A
previous network engineer has completed the physical installation. You must complete
the router configuration.
The contract for this implementation requires you to complete the following tasks:
•
•
•
Configure the hostname of the router as "Branch."
Configure the router interface that is connected to the switch with a description of "Link
to SW1."
Assign correct IPv4 address and subnet mask to interface Ethernet0/0 on the Branch
router. Ensure that you can ping the IPv4 address of switch SW1 to verify the
•
•
connectivity. In case connectivity test fails, make sure that you used the no
shutdown command on the interface.
Assign correct IPv4 address to the Loopback 0 interface on the Branch router.
Configure the interface on SW1 that is connected to the router with the description “Link
to Branch”.
The router may take 2 to 5 minutes to boot before you can access it. If the router comes
up with the initial system configuration dialog prompt, type: no to skip it.
Topology
Job Aid
If you shut down an interface on a real router or switch, the connected device will see it
as "down/down." Because of virtualization specifics, Cisco IOL (Cisco IOS Software on
Linux) behavior is slightly different. If you shut down an interface on a router or switch,
the connected device will see it as "up/up." In Cisco IOL, the status of an interface can
only be "up/up" or "administratively down/down." Also, in the virtual lab environment,
all interfaces are Ethernet interfaces and not FastEthernet or GigabitEthernet interfaces,
which you are likely to encounter in networks today.
Device Information
Device Interface IPv4 Address
Connected Connected Device Connected Device
Device
Interface
IPv4 Address
SW1
VLAN 1 172.16.130.10/24 VLAN 1
—
—
SW1
E0/1
VLAN 1
Branch
E0/0
172.16.130.3/24
SW1
E0/2
VLAN 1
AdminPC
E0/0
172.16.130.5/24
172.16.2.2/32
—
—
—
Branch Lo0
Configuration Tips
The router may take 2 to 5 minutes to boot before you can access it. If the router comes
up with the initial system configuration dialog prompt, type: no to skip it.
•
•
•
•
•
•
•
To configure the hostname on a router, enter the global configuration mode and enter
the hostname hostname command.
To configure an interface, you must enter the interface configuration mode. From the
global configuration mode, enter theinterface interface command.
To configure a description for an interface, use the description command at the
interface level.
To assign an IPv4 address to an interface, use the ip address ip address subnet
mask interface configuration mode command.
To test the connectivity between devices, use the ping command. Use
the source keyword to if you wish to specify the interface of the router to use as a
source interface for the probes. The command syntax is as follows: ping ip
address source interface.
Enable an interface using the no shutdown command.
You can check which switch port is connected to the router by using the Topology
Diagram or you can use Cisco Discovery Protocol.
Answer Key
You need to complete the following tasks:
•
•
Configure the hostname of the router as "Branch."
In order to assign the hostname of the router (identified as Branch in the lab), you may
need to wait until the router has finished initializing and press Enter to get the Setup
mode prompt, "Would you like to enter the initial configuration dialog? [yes/no]: ".
Answer "no" to not enter setup mode. Enter router global configuration mode and
configure the hostname as Branch.
--- System Configuration Dialog --Would you like to enter the initial configuration dialog? [yes/no]: n
Router# configure terminal
Router(config)# hostname Branch
Branch(config)#
•
•
Configure the router interface that is connected to the switch with a description of "Link
to SW1."
The contract requires that the link to the switch has a description of "Link to SW1." In
order to configure a description for an interface, use the description command at the
interface level.
Branch(config)#interface Ethernet0/0
Branch(config-if)#description Link to SW1
•
•
Assign correct IPv4 address and subnet mask to interface Ethernet0/0 on the Branch
router. Ensure that you can ping the IPv4 address of switch SW1 to verify the
connectivity. In case connectivity test fails, make sure that you used the no
shutdown command on the interface.
In order to enable IPv4 connectivity between the E0/0 interface of the router and
AdminPC (172.16.130.5), configure the E0/0 interface with the IPv4 address
172.16.130.3 and subnet mask 255.255.255.0, and enable the interface by configuring
the no shutdown command.
Branch(config)#interface Ethernet0/0
Branch(config-if)#ip address 172.16.130.3 255.255.255.0
Branch(config-if)#no shutdown
•
You can use the show ip interface brief or show ip interface e0/0 commands to verify
the status and IPv4 address that is configured for the Ethernet 0/0 interface on the
Branch router.
Branch# show ip interface ethernet 0/0
Ethernet 0/0 is up, line protocol is up,
Internet address is 172.16.130.3/24
•
Verify that the Branch router can ping the IPv4 address of SW1 (172.16.130.10).
Branch# ping 172.16.130.10
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.130.10, timeout is 2 seconds:
Packet sent with a source address of 172.16.130.3
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
Branch#
•
•
Assign correct IPv4 address to the Loopback 0 interface on the Branch router.
The contract requires the loopback interface to have an IPv4 address of 172.16.2.2/32.
In order to configure the IPv4 address on an interface, use the following command:
Branch(config)# interface Loopback0
Branch(config-if)# ip address 172.16.2.2 255.255.255.255
•
To verify the status you can use show ip interface brief, show ip interface loopback
0, or show interface loopback 0commands. To verify the connectivity you can use the
ping command between AdminPC and the Loopback 0 interface that is configured on
the Branch router.
Branch# show ip interface loopback 0
Loopback0 is up, line protocol is up
Internet Address is 172.16.2.2/32
Branch# ping 172.16.130.5 source loopback0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.130.5, timeout is 2 seconds:
Packet sent with a source address of 172.16.2.2
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
Branch#
•
•
Configure the interface on SW1 that is connected to the router with the description “Link
to Branch”.
The contract requires that the link to the branch has a description of "Link to Branch." In
order to configure a description for an interface, use the description command at the
interface level.
SW1(config)#interface Ethernet0/1
SW1(config-if)#description Link to Branch
•
Check the configuration of that specific port.
SW1# show running-configuration interface e0/1
Building configuration...
Current configuration : 70 bytes
!
interface Ethernet0/1
description Link to Branch
duplex auto
end
SW1#
Exploring the Packet Delivery Process
Introduction
Any device connected to either an Enterprise Campus, Branch, or home network uses
an Internet Protocol (IP) address that identifies the device on the network, and a subnet
mask that describes which portion of the address refers to the network ID and which
part refers to the host ID. Having this information, a device is “smart” enough to know if
the devices it wants to communicate with can be reached directly, which means they
are on the same network. In this case, the device can rely on a switch to deliver the
frames to the receiver. But the sender might still not know the physical address of such
device, therefore, a protocol that is able to map IP addresses to physical addresses of a
receiver is required.
If the two hosts are on different subnets, then the sending host must send the data to its
default gateway, which will forward the data to the destination. The default gateway,
which is a router, allows devices on one subnet to communicate with devices in other
subnets.
Host-to-host packet delivery either in the same network or in different networks contains
a variety of processes, and as a networking engineer you need to feel confident about
them. This knowledge is especially important when troubleshooting, where different
components are crucial in diagnosing issues in packet delivery.
Cisco Enterprise Architecture Model
The packet delivery process includes:
•
•
The role of the Layer 2 address and Layer 3 address.
The role of Address Resolution Protocol (ARP).
Layer 2 Addressing
Here you will observe where Open Systems Interconnection (OSI) Layer 2
(corresponding to the Transmission Control Protocol / Internet Protocol [TCP/IP] Link
layer) addresses fit into the host-to-host packet delivery process.
The characteristics of Layer 2 Ethernet local-area networks (LANs) are:
•
•
•
Uses Media Access Control (MAC) addresses.
Identifies end devices in the LAN.
Enables the packet to be carried by the local media across each segment.
Layer 2 defines how data is formatted for transmission and how access to the physical
media is controlled. Layer 2 devices provide an interface with the physical media. Some
common examples are network interface cards (NICs) installed in a host.
Device-to-device communications require Layer 2 addresses, also known as physical
addresses. For example, Ethernet physical addresses or MAC addresses are
embedded in Ethernet NIC in end devices, such as hosts.
Although MAC addresses are unique, physical addresses are not hierarchical. They are
associated with a particular device, regardless of its location or to which network it is
connected. These Layer 2 addresses have no meaning outside the local network media.
They are used to locate the end devices in the local physical network on the data link
layer.
An Ethernet MAC address is a two-part, 48-bit binary value that is expressed as 12
hexadecimal digits. The address formats might appear like 00-05-9A-3C-78-00,
00:05:9A:3C:78:00, or 0005.9A3C.7800.
All devices that are connected to an Ethernet LAN have MAC-addressed interfaces. The
NIC uses the MAC address in received frames to determine if a message should be
passed to the upper layers for processing. The MAC address is permanently encoded
into a read-only memory (ROM) chip on an NIC. The MAC address is made up of the
Organizationally Unique Identifier (OUI) and the vendor assignment number.
Switches also have MAC addresses, but a device only sends a frame to these
addresses when communicating with the switch, for example for management.
Otherwise, frames are addressed for other devices and the switch forwards the frames
to those devices.
The figure shows the Layer 2 (L2) addresses on two personal computers (PCs) and a
router. Note that the router has different MAC addresses on each interface.
Layer 3 Addressing
You will now examine where OSI Layer 3 (corresponding to the TCP/IP Internet layer)
devices and addressing fit into the host-to-host communications model.
Layer 3 provides connectivity and path selection between two host systems that may be
located on geographically separated networks. At the boundary of each local network,
an intermediary network device, usually a router, de-encapsulates the frame to read the
destination address that is contained in the header of the packet (the Layer 3 protocol
data unit [PDU]). Routers use the network identifier portion of this address to determine
which path to use to reach the destination host. Once the path is determined, the router
encapsulates the packet in a new frame and sends it toward the destination end device.
Layer 3 addresses must include identifiers that enable intermediary network devices to
locate the networks that different hosts belong to. In the TCP/IP protocol suite, every IP
host address contains information about the network where the host is located.
Intermediary devices that connect networks are routers. The role of the router is to
select paths and direct packets toward a destination. This process is known as routing.
A router uses a list of paths that is located in a routing table to determine where to send
data.
Routing Table
192.168.3.0/24
Interface Gi0/0
192.168.4.0/24
Interface Gi0/1
Layer 3 addresses are assigned to end devices such as hosts and to network devices
that provide Layer 3 functions. The router has its own Layer 3 address on each
interface. Each network device that provides a Layer 3 function maintains a routing
table.
As seen in the example, the two router interfaces belong to different networks. The left
interface and the directly connected PC belong to the 192.168.3.0/24 network, while the
right interface and the directly connected PC belong to the 192.168.4.0/24 network. For
devices in different IP networks, a Layer 3 device is needed to route traffic between
them.
Default Gateways
A source host is able to communicate directly (without a router) with a destination host
only if the two hosts are on the same subnet. If the two hosts are on different subnets,
the sending host must send the data to its default gateway, which will forward the data
to the destination. The default gateway is an address on a router (or Layer 3 switch)
connected to the same subnet that the source host is on.
Therefore, before a host can send a packet to its destination, it must first determine if
the destination address is on its local subnet or not. It uses the subnet mask in this
determination. The subnet mask describes which portion of an IPv4 address refers to
the network or subnet and which part refers to the host.
The source host first does an AND operation between its own IPv4 address and subnet
mask to arrive at its local subnet address. To determine if the destination address is on
the same subnet, the source host then does an AND operation between the destination
IPv4 address and the source’s subnet mask. This is because it doesn’t know the subnet
mask of the destination address, and if the devices are on the same subnet they must
have the same mask. If the resulting subnet address is the same, then it knows the
source and destination are on the same subnet. Otherwise, they are on different
subnets.
For example, IPv4 host 10.10.1.241/24 is on the 10.10.1.0/24 subnet. If the host that it
wants to communicate with is 10.10.1.175, it knows that this IPv4 host is also on the
local 10.10.1.0/24 subnet.
If the source and destination devices are on the same subnet, then the source can
deliver the packet directly. If they are on different subnets, then the packet must be
forwarded to the default gateway, which will forward it to its destination. The default
gateway address must have the same network and subnet portion as the local host
address; in other words, the default gateway must be on the same subnet as the local
host.
Host are configured with the address of their default gateway. On a Windows computer,
the Internet Protocol (TCP/IP) Propertiestools are used to enter the default gateway
IP address if you need to set the network parameters manually. These parameters may
also be learned automatically.
Address Resolution Protocol
When a device sends a packet to a destination, it encapsulates the packet into a frame.
The packet contains IPv4 addresses, and the frame contains MAC addresses.
Therefore, there must be a way to map an IPv4 address to a MAC address. For
example, if you enter the ping 10.1.1.3 command, the MAC address of 10.1.1.3 must
be included in the destination MAC address field of the frame that is sent. To determine
the MAC address of the device with an IPv4 address 10.1.1.3, a process is performed
by a Layer 2 protocol called ARP.
ARP provides two essential services:
•
•
Address resolution: Mapping IPv4 addresses to MAC addresses on a network
Caching: Locally storing MAC addresses that are learned via ARP
The term address resolution in ARP refers to the process of binding or mapping the
IPv4 address of a remote device to its MAC address. ARP sends a broadcast message
to all devices on the local network. This message includes its own IPv4 address and the
destination IPv4 address. The message is asking the device on which the destination
IPv4 address resides to respond with its MAC address. The address resolution
procedure is completed when the originator receives the reply frame, which contains the
required MAC address, and updates its table containing all the current bindings.
The Layer 2 broadcast address is FF:FF:FF:FF:FF:FF.
Using ARP to Resolve the MAC of a Local IPv4 Address
Because ARP is a Layer 2 protocol, its scope is limited to the local LAN. If the source
and destination devices are on the same subnet, then the source can use ARP to
determine the destination’s MAC address.
For example, IPv4 host 10.10.1.241/24 is on the 10.10.1.0/24 subnet. If the host that it
wants to communicate with is 10.10.1.175, it knows that this IPv4 host is also on the
local 10.10.1.0/24 subnet, and it can use ARP to determine its MAC address directly.
The following output shows the Wireshark analysis of the ARP messages. In the first
example you can see an ARP request sent as a broadcast to find out the MAC address
of IPv4 host 10.10.1.175. In the second ARP message you can see the ARP reply
including the MAC address of the host which is 00:bc:22:a8:e0:a0
Source Destination Prot Info
00:bc:22:52:e8:bd Broadcast ARP Who has 10.10.1.175? Tell 10.10.1.241
Source Destination Prot Info
00:bc:22:a8:e0:a0 00:bc:22:52:e8:bd ARP 10.10.1.175 is at 00:bc:22:a8:e0:a0
Using ARP to Resolve the MAC of a Remote IPv4 Address
If the source and destination devices are not on the same subnet, then the source uses
ARP to determine the default gateway’s MAC address.
For example, when the source host 10.10.1.241 wants to communicate with the
destination host 10.10.2.55, it compares this IPv4 address against its subnet mask and
discovers that the host is on a different IPv4 subnet (10.10.2.0/24). When a host wants
to send data to a device that is on another network or subnet, it encapsulates the packet
in a frame addressed to its default gateway. So, the destination MAC address in the
frame needs to be the MAC address of the default gateway. In this situation, the source
must send an ARP request to find the MAC address of the default gateway. In the
example, host 10.10.1.241 sends a broadcast with an ARP Request for the MAC
address of 10.10.1.1.
The following output shows the Wireshark analysis of ARP messages. In the first
example you can see an ARP request sent as a broadcast to find out the MAC address
of IPv4 host 10.10.1.1. In the second ARP message you can see the ARP reply
showing that the MAC address of the default gateway is 00:25:b5:9c:34:27.
Source Destination Prot Info
00:bc:22:52:e8:bd Broadcast ARP Who has 10.10.1.1? Tell 10.10.1.241
Source Destination Prot Info
00:25:b5:9c:34:27 00:bc:22:52:e8:bd ARP 10.10.1.1 is at 00:25:b5:9c:34:27
Understanding the ARP Cache
Each IPv4 device on a network segment maintains a table in memory—the ARP table or
ARP cache. The purpose of this table is to cache recent IPv4 addresses to MAC
address bindings. When a host wants to transmit data to another host on the same
subnet, it searches the ARP table to see if there is an entry. If there is an entry, the host
uses it. If there is no entry, the IPv4 host sends an ARP broadcast requesting
resolution.
By caching recent bindings, ARP broadcasts can be avoided for any mappings in the
cache. Without the ARP cache, each IPv4 host would have to send an ARP broadcast
each time it wanted to communicate with another IPv4 host.
Each entry, or row, of the ARP table has a pair of values—an IPv4 address and a MAC
address. The relationship between the two values is a map, which simply means that
you can locate an IPv4 address in the table and discover the corresponding MAC
address. The ARP table caches the mapping for the devices on the local LAN, including
the default gateway.
The device creates and maintains the ARP table dynamically, adding and changing
address relationships as they are used on the local host. The entries in an ARP table
expire after a while; the default expiry time for Cisco devices is 4 hours. Other operating
systems (Windows, Mac OS) might have a different value – Windows OS for example
uses a random value between 15 - 45 seconds. This timeout ensures that the table
does not contain information for systems that may be switched off or that have been
moved. When the local host wants to transmit data again, the entry in the ARP table is
regenerated through the ARP process.
If no device responds to the ARP request, then the original packet is dropped, because
a frame to put the packet in cannot be created without the destination MAC address.
On a Microsoft Windows PC, the arp -a command displays the current ARP table for all
interfaces on the PC.
To limit the output of the arp command to a single interface, use the arp -a N ip_address command.
To display the ARP table on a Cisco IOS router, use the show ip arp or show
arp EXEC command; the output is the same.
Branch# show ip arp
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.1.1.1 5 001b.d59c.3427 ARPA GigabitEthernet0/0
Internet 10.1.1.241 4 00BC.2252.e8bd ARPA GigabitEthernet0/0
Branch# show arp
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.1.1.1 5 001b.d59c.3427 ARPA GigabitEthernet0/0
Internet 10.1.1.241 4 00BC.2252.e8bd ARPA GigabitEthernet0/0
The proper syntax to display the ARP table is show ip arp [ip-address] [host-name]
[mac-address] [interface type number].
Syntax Description
Parameter
Description
ip-address
(Optional) Displays ARP entries matching this IPv4 address
host-name
(Optional) Hostname
mac-address
(Optional) 48-bit MAC address
Parameter
Description
interface type
number
(Optional) Displays ARP entries that are learned via this interface type
and number
Discovery 7: Configure Default Gateway
Introduction
This activity will help you explore how ARP maps IPv4 addresses to MAC addresses
and how default gateways allow access to hosts on remote subnets. The lab is
prepared with the devices that are represented in the topology diagram with the IPv4
addresses as depicted in the table. Note that PC2, PC3, SW1, and R1 are fully
configured.
Topology
Job Aids
Device Information
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today.
Personal computers (PCs) in the virtual lab environment are simulated by routers, so you
should use Cisco IOS commands to configure them or verify the configuration.
Device Inform
tion Table
Device
Characteristic
Value
PC1
IPv4 address
10.10.1.10/24
PC1
Default gateway
Not configured
PC2
IPv4 address
10.10.1.20/24
PC2
Default gateway
10.10.1.1
PC3
IPv4 address
192.168.3.2/24
PC3
Default gateway
192.168.3.1
SW1
VLAN 1 IPv4 address
10.10.1.2/24
SW1
Default gateway
10.10.1.1
SW1
Ethernet0/0 description
Link to PC1
SW1
Ethernet0/1 description
Link to R1
SW1
Ethernet0/2 description
Link to PC2
R1
Ethernet0/0 description
Link to SW1
R1
Ethernet0/0 IPv4 address
10.10.1.1/24
R1
Ethernet0/1 IPv4 address
192.168.3.1/24
R1
Loopback 0 IPv4
10.10.3.1/24
Task 1: Configure Default Gateway
Activity
Step 1
Verify that PC1 does not have a default route in its routing table.
On PC1, enter the following command:
PC1# show ip route
Default gateway is not set
Host Gateway Last Use Total Uses Interface
ICMP redirect cache is empty
Step 2
All devices in the network that have IPv4 addresses maintain an ARP cache. Via the
ARP process, devices learn the MAC address of other hosts on their local subnet with
which they need to communicate. Access the console of PC1 and execute theshow
arp command.
PC1 should have an entry for itself (10.10.1.10).
PC1# show arp
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.10.1.10 - aabb.cc00.2200 ARPA Ethernet0/0
If there was activity within the discovery before executing the show arp command, you
may find that there are other entries in the table.
The command show arp does not work on PCs. It is used here because the actual
device that is used to simulate a PC is a router. The command on a Windows/Mac/Linux
system would be arp –a.
MAC addresses in your output may be different.
Step 3
To initiate communication between PC1 and other devices on the subnet, which will
initiate the ARP process to learn the appropriate MAC addresses, use
the ping command. Ping PC2 (10.10.1.20), R1 (10.10.1.1), and SW1 (10.10.1.2).
Sometimes, the first ping times out because of the delay that the ARP process caused.
PC1# ping 10.10.1.20
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.20, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
PC1# ping 10.10.1.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/201/1003 ms
PC1# ping 10.10.1.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/203/1004 ms
Step 4
Examine the ARP cache on PC1 again.
The ARP cache is now populated with all four hosts that have IPv4 addresses on the
10.10.1.0/24 subnet.
PC1# show arp
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.10.1.1 2 aabb.cc00.2100 ARPA Ethernet0/0
Internet 10.10.1.2 0 aabb.cc80.2a00 ARPA Ethernet0/0
Internet 10.10.1.10 - aabb.cc00.2200 ARPA Ethernet0/0
Internet 10.10.1.20 2 aabb.cc00.2800 ARPA Ethernet0/0
Step 5
From PC1, ping 192.168.3.2, which is a PC on a different subnet.
From PC1, ping PC3:
PC1# ping 192.168.3.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.3.2, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
View the ARP cache on PC1.
PC1# show arp
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.10.1.1 1 aabb.cc00.2100 ARPA Ethernet0/0
Internet 10.10.1.2 0 aabb.cc80.2a00 ARPA Ethernet0/0
Internet 10.10.1.10 - aabb.cc00.2200 ARPA Ethernet0/0
Internet 10.10.1.20 1 aabb.cc00.2800 ARPA Ethernet0/0
Internet 192.168.3.2 0 aabb.cc00.2100 ARPA Ethernet0/0
There is an ARP cache entry for 192.168.3.2. The MAC addresses for 192.168.3.2 and
10.10.1.1 are identical. This behavior is the result of the Proxy ARP feature, which is
enabled on Cisco IOS routers by default. PC1 does not have a default gateway that is
configured, so it attempts to use ARP for all addresses. R1 saw the ARP request for a
remote address that was available in its routing table, and sent an ARP reply with its
own MAC address. PC1 can then forward traffic that is destined to 192.168.3.2 to the
R1 MAC address, and R1 will forward as necessary. While proxy ARP can be helpful as
a last resort, properly configuring a default gateway is a better practice.
Step 6
Configure R1 as the default gateway for PC1.
On PC1, enter the following command:
PC1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
PC1(config)# ip default-gateway 10.10.1.1
PC1(config)# end
PC1#
Verify the routing table on PC1 again:
PC1# show ip route
Default gateway is 10.10.1.1
Host Gateway Last Use Total Uses Interface
ICMP redirect cache is empty
Default gateway, along with the IPv4 address and the subnet mask, is one of the main
configuration parameters for the end-device. The default gateway is used when there is
a need to communicate with the devices outside the local subnet. The sending device
examines the destination address to determine the destination network ID. It then
compares this destination subnet ID with its own subnet ID. If subnet IDs are different,
the sending device forwards the packet to the default gateway for further routing. The
default gateway is an IPv4 address of a router interface that is connected to the local
subnet. In other words, a default gateway always belongs to the same subnet as the
end-device.
The main advantage of proxy ARP is that it can be added to a single router on a network
and does not disturb the routing tables of the other routers on the network. Proxy ARP
must be used on the network where IPv4 hosts are not configured with a default gateway
or do not have any routing intelligence. The use of proxy ARP is not recommended in
today's networks, because it can be a significant security issue. Therefore, Proxy ARP
should be disabled on all interfaces unless in a rare situation where you need it.
Step 7
Remove the entry for 192.168.3.2 from the ARP cache of PC1 using the clear ip arp
192.168.3.2 command, and verify that the entry has been removed using the show
arp command.
On PC1, enter the following commands:
PC1# clear ip arp 192.168.3.2
PC1# show arp
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.10.1.1 6 aabb.cc00.2100 ARPA Ethernet0/0
Internet 10.10.1.2 6 aabb.cc80.2a00 ARPA Ethernet0/0
Internet 10.10.1.10 - aabb.cc00.2200 ARPA Ethernet0/0
Internet 10.10.1.20 6 aabb.cc00.2800 ARPA Ethernet0/0
Step 8
Ping 192.168.3.2 again.
On PC1, enter the following commands:
PC1# ping 192.168.3.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.3.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
You can verify that there is no entry for 192.168.3.2 in the ARP cache of PC1.
PC1# show arp
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.10.1.1 8 aabb.cc00.2100 ARPA Ethernet0/0
Internet 10.10.1.2 8 aabb.cc80.2a00 ARPA Ethernet0/0
Internet 10.10.1.10 - aabb.cc00.2200 ARPA Ethernet0/0
Internet 10.10.1.20 8 aabb.cc00.2800 ARPA Ethernet0/0
For all addresses outside of the 10.10.1.0/24 subnet, PC1 will now use the destination
MAC address of 10.10.1.1 (R1, its default gateway). R1 will then forward the packet
appropriately because of its routing table.
Host-To-Host Packet Delivery
Host-to-host packet delivery consists of an interesting series of processes. In this
multipart example, you will discover what happens "behind the scenes" when an IPv4
host communicates with another IPv4 host, firstly when a router is used and secondly
when a switch is responsible for host-to-host packet delivery process.
Host-To-Host Packet Delivery (Step 1 of 14)
In this example, the host 192.168.3.1 needs to send arbitrary application data to the
host 192.168.4.2, which is located on another subnet. The application does not need a
reliable connection, so it uses User Datagram Protocol (UDP). Because it is not
necessary to set up a session, the application can start sending data, using the UDP
port numbers to establish the session and deliver the segment to the right application.
Host-To-Host Packet Delivery (Step 2 of 14)
UDP prepends a UDP header (UDP HDR) and passes the segment to the IPv4 layer
(Layer 3) with an instruction to send the segment to 192.168.4.2. IPv4 encapsulates the
segment in a Layer 3 packet, setting the source address (SRC IP) of the packet to
192.168.3.1, while the destination address (DST IP) is set to 192.168.4.2.
Host-To-Host Packet Delivery (Step 3 of 14)
When Host A analyzes the destination address, it finds that the destination address is
on a different network. The host forwards any packet that is not destined for the local
IPv4 network in a frame addressed to the default gateway. The default gateway is the
address of the local router, which must be configured on hosts (PCs, servers, and so
on). IPv4 passes the Layer 3 packet to Layer 2 with instructions to forward it to the
default gateway. Host A must place the packet in its “parking lot” (on hold) until it has
the MAC address of the default gateway.
Host-to-Host Packet Delivery (Step 4 of 14)
To deliver the packet, the host needs the Layer 2 information of the next-hop device.
The ARP table in the host does not have an entry and must resolve the Layer 2 address
(MAC address) of the default gateway. The default gateway is the next hop for the
packet. The packet waits while the host resolves the Layer 2 information.
Host-To-Host Packet Delivery (Step 5 of 14)
Because the host does not know the default gateway’s Layer 2 address, the host uses
the standard ARP process to obtain the mapping. The host sends a broadcast ARP
request looking for the MAC address of its default gateway.
Host-To-Host Packet Delivery (Step 6 of 14)
The host has previously been configured with 192.168.3.2 as the default gateway. The
host 192.168.3.1 sends out the ARP request, and the router receives it. The ARP
request contains information about the Host A. Notice that the first thing the router does
is add this information to its own ARP table.
Host-To-Host Packet Delivery (Step 7 of 14)
The router processes the ARP request like any other host would, and sends the ARP
reply with its own information, directly to the host’s MAC address.
Host-to-Host Packet Delivery (Step 8 of 14)
The host receives an ARP reply to its ARP request and enters the information in its local
ARP table.
Host-To-Host Packet Delivery (Step 9 of 14)
Now the Layer 2 frame with the application data can be sent to the default gateway. The
pending frame is sent with the local host IPv4 address and MAC address as the source.
However, the destination IPv4 address is that of the remote host, but the destination
MAC address is that of the default gateway.
Host-To-Host Packet Delivery (Step 10 of 14)
When the router receives the frame, it recognizes its MAC address and processes the
frame. At Layer 3, the router sees that the destination IPv4 address is not its address. A
host Layer 3 device would discard the frame. However, because this device is a router,
it passes all IPv4 packets that are not for the router itself to the routing process. The
routing process determines where to send the packet.
Host-To-Host Packet Delivery (Step 11 of 14)
Destination
Next Hop
Interface
192.168.3.0/24
Connected
Gi0/0
192.168.4.0/24
Connected
Gi0/1
The routing process checks for the longest prefix match of the destination IPv4 address
in its routing table. In this example, the destination network is directly connected.
Therefore, the routing process can pass the packet directly to Layer 2 for the
appropriate interface.
Host-To-Host Packet Delivery (Step 12 of 14)
Assuming that the router does not have the mapping to 192.168.4.2, Layer 2 uses the
ARP process to obtain the mapping for the IPv4 address and the MAC address. The
router asks for the Layer 2 information in the same way as the hosts. An ARP request
for the destination MAC address is sent to the link.
The destination host receives and processes the ARP request.
Host-To-Host Packet Delivery (Step 13 of 14)
The destination host receives the frame that contains the ARP request and passes the
request to the ARP process. The ARP process takes the information about the router
from the ARP request and places the information in its local ARP table. The ARP
process generates the ARP reply and sends it back to the router.
The router receives the ARP reply, populates its local ARP table, and starts the packetforwarding process.
Host-To-Host Packet Delivery (Step 14 of 14)
The frame is forwarded to the destination. Note that the router changes Layer 2 address
in frames as needed, but it will not change the Layer 3 address in packets.
Role of a Switch in Packet Delivery (Step 1 of 4)
Typically, your network will have switches between hosts and routers. In this multipart
example, you will see what happens on a switch when a host communicates with a
router.
Remember that a switch does not change the frame in any way. When a switch
receives the frame, it forwards it out the proper port according to the MAC address
table.
An application on host A wishes to send data to a remote network. Before an IP packet
can be forwarded to the default gateway, its MAC address needs to be obtained. ARP
on Host A creates an ARP request and sends it out, as a broadcast frame. Before the
ARP request reaches other devices on a network, the switch receives it.
When the switch receives the frame, it needs to forward it out on the proper port.
However, in this example, the source MAC address is not in the MAC address table of
the switch. The switch can learn the port mapping for the source host from the source
MAC address in the frame, so the switch adds the information to the table
(0800:0222:2222 = port FastEthernet0/1).
Role of a Switch in Packet Delivery (Step 2 of 4)
Because the destination address of the frame is a broadcast, the switch has to flood the
frame out to all the ports, except the one it came in.
Role of a Switch in Packet Delivery (Step 3 of 4)
The router replies to the ARP request and sends an ARP reply packet back to the
sender as a unicast frame.
The switch learns the port mapping for the router’s MAC address from the source MAC
address in the frame. The switch adds it to the MAC address table (0800:0333:2222 =
port FastEthernet0/3)
Role of a Switch in Packet Delivery (Step 4 of 4)
The destination address of the frame (Host A) is found in the MAC address table, so the
switch can forward the frame out on port FastEthernet0/1. If the destination address
was not found in the MAC address table, the switch would need to flood out the frame
on all ports, except the one it came in on.
All frames pass through the switch unchanged. The switch builds its MAC address table
based on the source address of received frames, and it sends all unicast frames directly
to the destination host based on the destination MAC address and port that are stored
in the MAC address table.
Discovery 8: Explore Packet Forwarding
Introduction
This activity will guide you through the exploration of packet forwarding. The lab is
prepared with the devices as represented in the topology diagram. The devices are fully
configured, including static routing on the routers. MAC addresses in your outputs may
be different from the MAC addresses displayed in the outputs in this activity..
Topology
Job Aids
Device Information
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today. In
the virtual lab environment, personal computers (PCs) and the server (SRV) are
simulated by routers, so you should use Cisco IOS commands to configure them or
verify the configuration.
Device Information Table
Device
Characteristic
Value
PC1
IPv4 address
10.10.1.10/24
Device
Characteristic
Value
PC1
Default gateway
10.10.1.1
PC2
IPv4 address
10.10.2.20/24
PC2
Default gateway
10.10.2.1
SRV1
IPv4 address
10.10.3.30/24
SRV1
Default gateway
10.10.3.1
SW1
VLAN 1 IPv4 address
10.10.1.4/24
SW1
Default gateway
10.10.1.1
SW1
Ethernet0/0 description
Link to R1
SW1
Ethernet0/1 description
Link to PC1
SW2
VLAN 1 IPv4 address
10.10.2.4/24
SW2
Default gateway
10.10.2.1
SW2
Ethernet0/0 description
Link to R2
SW2
Ethernet0/1 Description
Link to PC2
SW3
VLAN 1 IPv4 address
10.10.3.4/24
SW3
Default gateway
10.10.3.1
SW3
Ethernet0/0 description
Link to R3
SW3
Ethernet0/1 description
Link to SRV1
R1
Ethernet0/0 description
Link to SW1
Device
Characteristic
Value
R1
Ethernet0/0 IPv4 address
10.10.1.1/24
R1
Ethernet0/1 description
Link to R3
R1
Ethernet0/1 IPv4 address
10.1.1.2/30
R1
Ethernet0/2 description
Link to R2
R1
Ethernet0/2 IPv4 address
10.1.1.10/30
R2
Ethernet0/0 description
Link to SW2
R2
Ethernet0/0 IPv4 address
10.10.2.1/24
R2
Ethernet0/2 description
Link to R1
R2
Ethernet0/2 IPv4 address
10.1.1.9/30
R2
Ethernet0/3 description
Link to R3
R2
Ethernet0/3 IPv4 address
10.1.1.6/30
R3
Ethernet0/0 description
Link to SW3
R3
Ethernet0/0 IPv4 address
10.10.3.1/24
R3
Ethernet0/1 description
Link to R1
R3
Ethernet0/1 IPv4 address
10.1.1.1/30
R3
Ethernet0/3 description
Link to R2
R3
Ethernet0/3 IPv4 address
10.1.1.5/30
Task 1: Explore Packet Forwarding
Activity
Step 1
Observe the topology diagram. This activity will focus on the forwarding of packets from
PC1 to SRV1.
The devices in the path between these two hosts are SW1, R1, R3, and SW3.
Step 2
Access the console of PC1, and verify connectivity to SRV1 using
the ping and traceroute commands.
PC1# ping 10.10.3.30
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.3.30, timeout is 2 seconds:
.!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
PC1# traceroute 10.10.3.30
Type escape sequence to abort.
Tracing the route to 10.10.3.30
VRF info: (vrf in name/id, vrf out name/id)
1 10.10.1.1 1 msec 0 msec 0 msec
2 10.1.1.1 1 msec 0 msec 1 msec
3 10.10.3.30 0 msec * 1 msec
The traceroute output shows 10.10.1.1 and 10.1.1.1 being in the forwarding path to
SRV1. These addresses belong to Ethernet0/0 on R1 and Ethernet0/1 on R3. The
interfaces Ethernet0/1 on R1 and Ethernet0/0 on R3 are also involved in the forwarding
process, as are the switches SW1 and SW3.
Step 3
One at a time, access the consoles of PC1, R1, R3, and SRV1, and use the show
interfaces command to inventory the IPv4 addresses and MAC addresses on the
interfaces that are involved in the forwarding process.
The information that you need is in the output of the show interfaces command, but to
focus explicitly on the data that you are interested in, it would be useful to send the
output through the include filter and only display lines that contain the string address.
PC1# show interfaces Ethernet0/0
Ethernet0/0 is up, line protocol is up
Hardware is AmdP2, address is aabb.cc00.0400 (bia aabb.cc00.0400)
Internet address is 10.10.1.10/24
MTU 1500 bytes, BW 10000 Kbit/sec, DLY 1000 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:01, output 00:00:07, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
1470 packets input, 93664 bytes, 0 no buffer
Received 1229 broadcasts (0 IP multicasts)
0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 input packets with dribble condition detected
311 packets output, 34770 bytes, 0 underruns
0 output errors, 0 collisions, 1 interface resets
2 unknown protocol drops
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier
0 output buffer failures, 0 output buffers swapped out
This example illustrated the full command syntax of the show interfaces command.
The examples that follow will utilize command abbreviation.
Note that the string that is passed to the include filter cannot be abbreviated, per se.
That is, Cisco IOS Software cannot determine that when you use the string add that you
intend for it to be an abbreviation of address. But the only appearance of the
string addin the command output is as a substring of address; therefore, it would be an
acceptable string to use for this purpose.
R1# show interface e0/0 | include address
Hardware is AmdP2, address is aabb.cc00.0100 (bia aabb.cc00.0100)
Internet address is 10.10.1.1/24
R1# show interface e0/1 | include address
Hardware is AmdP2, address is aabb.cc00.0110 (bia aabb.cc00.0110)
Internet address is 10.1.1.2/30
R3# show interface e0/0 | include address
Hardware is AmdP2, address is aabb.cc00.0300 (bia aabb.cc00.0300)
Internet address is 10.10.3.1/24
R3# show interface e0/1 | include address
Hardware is AmdP2, address is aabb.cc00.0310 (bia aabb.cc00.0310)
Internet address is 10.1.1.1/30
SRV1# show interface e0/0 | include address
Hardware is AmdP2, address is aabb.cc00.0600 (bia aabb.cc00.0600)
Internet address is 10.10.3.30/24
MAC addresses may be different than shown in the example.
Step 4
The output of the show interfaces commands can be compiled for reference into a
table.
The table would appear as follows:
MAC addresses may be different than shown in the example.
Device
Interface
MAC Address
IPv4 Address
PC1
Ethernet0/0
aabb.cc00.0400
10.10.1.10
R1
Ethernet0/0
aabb.cc00.0100
10.10.1.1
R1
Ethernet0/1
aabb.cc00.0110
10.1.1.2
R3
Ethernet0/0
aabb.cc00.0300
10.10.3.1
R3
Ethernet0/1
aabb.cc00.0310
10.1.1.1
SRV1
Ethernet0/0
aabb.cc00.0600
10.10.3.30
Step 5
When PC1 generates an IPv4 packet for SRV1, it will encapsulate the data with an IPv4
header specifying 10.10.3.30 as the destination IPv4 address and 10.10.1.10 as the
source IPv4 address. It will then encapsulate the IPv4 packet with an Ethernet header
specifying the Ethernet0/0 MAC address in R1 (aabb.cc00.0100 in this example) as the
destination MAC address and its own MAC address (aabb.cc00.0400 in this example)
as the source. PC1 obtains the MAC address of R1 from its ARP cache. Access the
console of PC1 and display its ARP cache.
The entry for 10.10.1.1 was populated in the ARP table when you performed
the ping operation at the beginning of this discovery.
PC1# show ip arp
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.10.1.1 45 aabb.cc00.0100 ARPA Ethernet0/0
Internet 10.10.1.10 - aabb.cc00.0400 ARPA Ethernet0/0
MAC addresses may be different than shown in the example.
Step 6
Execute the following sequence of commands to observe the behavior of the ARP
process. Execute the debug arp command to enable debugging of ARP packets, and
use the show commands to provide visibility into the process. Shut down the
Ethernet0/0 interface of PC1 to clear the ARP cache entries that are associated with the
interface. Next, re-enable the interface and initiate connectivity; both actions will
stimulate ARP activity. The informational notes that are imbedded in the directions
further explain the operations.
On PC1, enable debugging of ARP packets:
PC1# debug arp
ARP packet debugging is on
Be very careful when using debug commands in production environments. Depending
on the circumstances, they can have a catastrophic effect on router performance. Until
you have experience with debug commands, it is best to consult a senior engineer
within your organization on their use.
PC1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
PC1(config)# interface Ethernet 0/0
PC1(config-if)# do show ip arp
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.10.1.1 51 aabb.cc00.0100 ARPA Ethernet0/0
Internet 10.10.1.10 - aabb.cc00.0400 ARPA Ethernet0/0
The do command allows access to EXEC mode commands from within the
configuration mode. The show ip arp command verifies that the two entries are still in
the ARP cache.
PC1(config-if)# shutdown
PC1(config-if)#
*Oct 9 12:40:03.589: %LINK-5-CHANGED: Interface Ethernet0/0, changed state to
administratively down
*Oct 9 12:40:04.589: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Ethernet0/0, changed state to down
PC1(config-if)# do show ip arp
PC1(config-if)#
This time, there is no output from the show ip arp command. The ARP cache on PC1 is
currently empty. The entries that are associated with Ethernet0/0 were cleared when the
interface was shut down.
PC1(config-if)# no shutdown
PC1(config-if)#
*Oct 9 12:41:24.437: IP ARP: sent rep src 10.10.1.10 aabb.cc00.0400,
dst 10.10.1.10 ffff.ffff.ffff Ethernet0/0
*Oct 9 12:41:24.437: IP ARP: sent rep src 10.10.1.10 aabb.cc00.0400,
dst 10.10.1.10 ffff.ffff.ffff Ethernet0/0
The two preceding messages are debug messages. Note that they are both ARP "rep"
frames, which are reply frames. The destination IPv4 address is 10.10.1.10. PC1 is
sending this ARP broadcast asking any host that has the IPv4 address 10.10.1.10,
which is its own address, to respond back with an ARP reply. Cisco IOS Software sends
this ARP broadcast automatically when interfaces are brought online. It is an attempt to
recognize when there are duplicate IPv4 addresses on the network. If any responses
are received, system logging (syslog) messages would be generated to alert the
network administrator that there are duplicate addresses. No replies were received,
which is normal.
*Oct 9 12:41:26.434: %LINK-3-UPDOWN: Interface Ethernet0/0, changed state to
up
*Oct 9 12:41:27.434: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Ethernet0/0, changed state to up
These two messages are the normal syslog messages, which are generated when
interfaces change their state. Exit configuration mode.
PC1(config-if)# end
PC1#
You just left configuration mode. The rest of this exploration will be completed from
privileged EXEC. First ping SRV1 from PC1.
PC1# ping 10.10.3.30
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.3.30, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
For this ping operation from PC1 to SRV1 to complete, PC1 must forward the packets in
a frame to R1, for R1 to forward to R3. PC1 needs to know the MAC address of R1 to
forward the packets to R1.
*Oct 9 12:41:27.434: IP ARP: creating incomplete entry for IP address:
10.10.1.1 interface Ethernet0/0
This debug message indicates that PC1 recognizes that it needs the MAC address for
10.10.1.1 (R1, its default gateway). PC1 creates an entry in its ARP cache and starts
the ARP process.
*Oct 9 12:41:27.434: IP ARP: sent req src 10.10.1.10 aabb.cc00.0400,
dst 10.10.1.1 0000.0000.0000 Ethernet0/0
This debug message indicates that PC1 sent an ARP request specifying 10.10.1.1 as
the destination; the 0000.0000.0000 field in the request is a place holder because PC1
does not know the MAC address (which is why it is sending the ARP request). This ARP
request is broadcast to all hosts within the broadcast domain (we don’t see the
broadcast in the debug output). PC1 is requesting any system with the IPv4 address
10.10.1.1 to respond with an ARP reply.
*Oct 9 12:41:27.435: IP ARP: rcvd rep src 10.10.1.1 aabb.cc00.0100, dst
10.10.1.10 Ethernet0/0
This debug message indicates that PC1 received an ARP reply from 10.10.1.1,
indicating that its MAC address is aabb.cc00.0100.
Step 7
View the ARP cache on PC1, which is a result of the exchange of ARP packets that you
just witnessed.
The ARP cache of PC1 now has an entry that is mapping the IPv4 address of R1 to the
MAC address of R1. It also has ARP entry of its own address.
PC1# show ip arp
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.10.1.1 8 aabb.cc00.0100 ARPA Ethernet0/0
Internet 10.10.1.10 - aabb.cc00.0400 ARPA Ethernet0/0
Step 8
The close inspection of the ARP process is complete. Turn off the debug operations by
using undebug all command.
Debug can be turned off on a per classification basis. That is, you could have
used undebug arp to turn off the debug process that you started with the debug
arp command.
PC1# undebug all
All possible debugging has been turned off
A common abbreviation that is used for undebug all is u all.
The lab environment does not support capturing packets on the interface links, but the
preceding results support the following extrapolation, which describes how a packet is
forwarded from PC1 to SRV1:
•
•
•
•
•
•
•
•
•
The IPv4 header remains constant across the entire path; the IPv4 header will specify
10.10.3.30 as the destination IPv4 address and 10.10.1.10 as the source IPv4 address.
A unique Layer 2 header is used to traverse each network segment.
PC1 and R1 learn the MAC addresses of each other via ARP.
R1 and R3 learn the MAC addresses of each other via ARP.
SRV1 and R3 learn the MAC addresses of each other via ARP.
PC1 will encapsulate the IPv4 packet with an Ethernet header that specifies
aabb.cc00.0100 (R1 Ethernet0/0) as the destination MAC address and aabb.cc00.0400
(PC1) as the source MAC address.
PC1 will send this packet out its Ethernet0/0 interface, and R1 will receive it on its
Ethernet0/0 interface.
R1 will strip the Ethernet header and replace it with another Ethernet header that
specifies aabb.cc00.0310 (R3 Ethernet 0/1) as the destination MAC address and
aabb.cc00.0110 (R1 Ethernet0/1) as the source MAC address. R1 will send this out of
its Ethernet 0/1 interface, and R3 will receive it on its Ethernet 0/1 interface.
R3 will strip the Ethernet header and replace it with another Ethernet header that
specifies aabb.cc00.0600 (SRV1) as the destination MAC address and aabb.cc00.0300
as the source MAC address. This source MAC address is the MAC address of the
Ethernet 0/0 interface.
•
R3 will send this frame out its Ethernet0/0 interface, and SRV1 will receive it on its
Ethernet0/0 interface.
Step 9
The previous steps did not depict how SW1 supports the forwarding of frames of
between PC1 and R1 and how SW3 supports the forwarding of frames between R3 and
SRV1. Switches learn which ports connect to devices with which MAC addresses based
on examination of the source MAC address on incoming frames. When they know which
ports lead to which MAC addresses, they can forward frames out of those ports based
on the destination MAC address in frames. Access the console of SW1 and view its
MAC address table.
The MAC address of PC1 is associated with SW1 port Ethernet0/1 and the MAC
address of R1 is associated with SW1 port Ethernet0/0.
SW1# show mac address-table
Mac Address Table
------------------------------------------Vlan Mac Address Type Ports
---- ----------- -------- -----
1 aabb.cc00.0100 DYNAMIC Et0/0
1 aabb.cc00.0400 DYNAMIC Et0/1
Total Mac Addresses for this criterion: 2
Step 10
Clear the MAC address table on SW1 using the clear mac address-table
dynamic command, and display it again to verify that it is empty.
The example shows an empty MAC address table, but when you attempt this step, you
may see that the entries have already repopulated. If so, simply repeat the last two
commands as quickly as possible (use the Up Arrow key for command recall) until you
see the empty MAC address table.
SW1# clear mac address-table dynamic
SW1# show mac address-table
Mac Address Table
------------------------------------------Vlan Mac Address Type Ports
---- ----------- -------- -----
Step 11
Wait at least 10 seconds after viewing the empty MAC address table before continuing.
Display the MAC address table one more time.
The MAC address table has again been repopulated with the MAC addresses of PC1
and R1.
SW1# show mac address-table
Mac Address Table
------------------------------------------Vlan Mac Address Type Ports
---- ----------- -------- ----1 aabb.cc00.0100 DYNAMIC Et0/0
1 aabb.cc00.0400 DYNAMIC Et0/1
Total Mac Addresses for this criterion: 2
Step 12
How did the table get repopulated? When the switch receives a frame of any kind, it
examines the source MAC address to determine if it needs to add it to the MAC address
table. By default, with Cisco IOS Software, Ethernet interfaces send frames to their own
MAC address every 10 seconds as a keepalive mechanism. Verify this setting by
accessing the console of PC1 and use the show interface command to view the status
of Ethernet0/0.
The keepalive value is set to 10 seconds. Also, make note of the number of packets
output from the interface.
PC1# show interface e0/0
Ethernet0/0 is up, line protocol is up
Hardware is AmdP2, address is aabb.cc00.0400 (bia aabb.cc00.0400)
Internet address is 10.10.1.10/24
MTU 1500 bytes, BW 10000 Kbit/sec, DLY 1000 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:00, output 00:00:09, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
3583 packets input, 225244 bytes, 0 no buffer
Received 3014 broadcasts (0 IP multicasts)
0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 input packets with dribble condition detected
708 packets output, 76818 bytes, 0 underruns
0 output errors, 0 collisions, 2 interface resets
2 unknown protocol drops
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier
0 output buffer failures, 0 output buffers swapped out
Step 13
Wait 10 seconds and repeat the show interface command. Verify that the number of
packets output has increased by at least 1.
You now have some experience with the forwarding of packets between IPv4 hosts,
including the ARP process and the use of MAC addresses on Ethernet networks. You
also investigated how switches populate and use the MAC address tables. Feel free to
continue exploring independently within the lab environment.
PC1# show interface e0/0
Ethernet0/0 is up, line protocol is up
Hardware is AmdP2, address is aabb.cc00.0400 (bia aabb.cc00.0400)
Internet address is 10.10.1.10/24
MTU 1500 bytes, BW 10000 Kbit/sec, DLY 1000 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:00, output 00:00:00, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
3624 packets input, 227780 bytes, 0 no buffer
Received 3048 broadcasts (0 IP multicasts)
0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 input packets with dribble condition detected
716 packets output, 77591 bytes, 0 underruns
0 output errors, 0 collisions, 2 interface resets
2 unknown protocol drops
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier
0 output buffer failures, 0 output buffers swapped out
Troubleshooting a Simple Network
Introduction
Smooth operation and high availability of the network are crucial to organizations.
Unplanned downtime can quickly lead to loss of productivity and, therefore, financial
loss. Recent studies have shown that 75% of total operating expenses are due to
monitoring and troubleshooting tasks.
Remember that most issues affecting a network are encountered during the original
implementation. If a network is correctly installed, it should continue to operate without
problems. However, this circumstance is only true in theory. Cabling becomes
damaged, configurations change, and new devices are connected, which may require
configuration changes. Ongoing maintenance is necessary. Therefore, diagnosing and
resolving problems is an essential skill that network engineers use as a part of their
many different job tasks.
There are no specific recipes for troubleshooting. A particular problem can be
diagnosed and sometimes even solved in many different ways. However, by employing
a structured approach to the troubleshooting process, you can greatly reduce the
average amount of time that it takes to diagnose and solve a problem.
Cisco Enterprise Architecture Model
Troubleshooting can be a very time-consuming process. By using the tools built into the
Cisco Internetwork Operating System (IOS) Software and on different end-device
operating systems, you can shorten the time to diagnose and resolve problems. There
are many technologies and protocols that you can leverage in combination with
specialized tools and applications to support troubleshooting and maintenance
processes.
Troubleshooting Methods
A troubleshooting method is a guiding principle that determines how you move through
the phases of the troubleshooting process.
All troubleshooting processes include the elements of gathering and analyzing
information, eliminating possible causes, and formulating and testing hypotheses.
However, the time one spends on each of these phases, and how one moves from
phase to phase, can be significantly different from person to person. It is a key
differentiator between novice and expert troubleshooters.
In a typical troubleshooting process, for a complex problem, you would continually move
between the different processes: gather some information, analyze it, eliminate some
possibilities, gather more information, analyze again, formulate a hypothesis, test it,
reject it, eliminate some more possibilities, gather more information, and so on.
If you do not use a structured approach but move between the phases randomly, you
might eventually find the solution, but the process will be very inefficient. In addition, if
your approach has no structure, it is practically impossible to hand it over to someone
else without losing all progress that was made up to this point. You may also need to
stop and resume your own troubleshooting process.
A structured approach to troubleshooting (no matter what the exact method is) will yield
more predictable results in the end and will make it easier to pick up the process where
you left off in a later stage or to hand it over to someone else.
Quickly formulating a first hypothesis that is based on common problem causes and
corresponding solutions can be very effective in the short run.
A troubleshooting method that is commonly deployed by both experienced and
inexperienced troubleshooters is the "shoot-from-the-hip" method, where, after a very
short period of gathering information, the troubleshooter quickly makes a change to see
if it solves the problem. This action might seem like random troubleshooting, but usually
the guiding principle for this method is knowing common symptoms and their
corresponding causes.
Look at the following example: A user reports a local-area network (LAN) performance
problem to you. In 90 percent of similar problems in the past in this environment, the
problem was caused by a duplex mismatch, and the solution was to configure the
switch port for 100-Megabits per second (Mbps) full duplex. An obvious thing to do is to
quickly verify the duplex setting of the switch port to which the user connects and if not
correct, to change it to 100-Mbps full duplex to see if this action fixes the problem.
When it works, this method can be very effective because very little time is spent on
gathering data, analyzing, and eliminating possible causes. However, the downside is
that if it does not work, you have not come any closer to a possible solution.
Experienced troubleshooters can use this method effectively, and it can also be a useful
tool for an inexperienced troubleshooter. However, the main factor in using this method
effectively is knowing when to stop and then switch to a more methodical approach.
A structured troubleshooting method is a guideline that helps you move through the
different phases of the troubleshooting process. The key to all structured
troubleshooting methods is the elimination of the causes of the issue.
By systematically eliminating possible problem causes, you can reduce the scope of the
problem until you manage to isolate and solve the problem. If it turns out that you lack
the knowledge or experience to solve the problem yourself, you can hand it over as a
better-defined problem. So, even if you do not manage to solve the problem, you will
increase the chances that someone else can find the cause of the problem and resolve
it quickly and efficiently.
Several different, structured, troubleshooting approaches exist, and the approach to use
may be chosen depending on the problem.
The following troubleshooting methods are the most common:
•
Top-down method: Work from the application layer in the Open Systems
Interconnection (OSI) model down to the physical layer. The top-down method uses the
OSI model as a guiding principle. One of the most important characteristics of the OSI
model is that each layer depends on the underlying layers for its operation. This
structure implies that if you find a layer to be operational, you can safely assume that all
underlying layers are fully operational as well. For example, if you are researching the
problem of a user who cannot browse a particular website and you find that you can
establish a Transmission Control Protocol (TCP) connection on port 80 from this host to
the server and get a response from the server, you can typically draw the conclusion
that the transport layer and all layers below must be fully functional between the client
and the server. It is most likely a client or server problem and not a network problem. Be
aware that, in the example above, it is reasonable to conclude that Layers 1 through 4
must be fully operational, but this idea is not definitively proved. For example,
unfragmented packets might be routed correctly, while fragmented packets are
dropped. The TCP connection to port 80 might not uncover such a problem. Therefore,
the goal of this method is to find the highest OSI layer that is still working. All devices
•
•
and processes that work on that layer or on the layers below it are then eliminated from
the scope of your problem. It might be clear that this method is most effective if the
problem is on one of the higher OSI layers. The top-down method is one of the most
straightforward troubleshooting methods, because problems reported by users are
typically defined as application layer problems, so starting the troubleshooting process
at that layer is the obvious thing to do. A drawback or impediment to this method is that
you need to access the application layer software on the machine of the client to initiate
the troubleshooting process. If the software is installed only on few machines, it might
be hard to test it properly.
Bottom-up method: Work from the physical layer in the OSI model up to the
application layer. The bottom-up approach also uses the OSI model as the guiding
principle, but this time you start on the physical layer and work your way up to the
application layer. By verifying layer by layer that the network is operating correctly, you
steadily eliminate more potential problem causes and narrow the scope of the potential
problems. For example, if you are researching the problem of a user who cannot
browse a particular website, you would first verify physical connectivity. You would log
in to the switch and verify the port status. After each test or verification step, you would
move up through the layers of the OSI model. A benefit of this method is that all the
initial troubleshooting takes place on the network, so access to clients, servers, or
applications is not necessary until later in the troubleshooting process. Also, the
thoroughness and steady progress of this method will give you a relatively high
probability of eventual success or, at the very least, a decent reduction of the problem
scope. A disadvantage of this method is that, in large networks, it can be a very timeconsuming process, because a lot of effort will be spent on gathering and analyzing
data. Therefore, the best use of this method is to first reduce the problem scope by
using a different strategy and then switching to this method for clearly bounded parts of
the network topology.
Divide-and-conquer method: Start in the middle of the OSI layers (usually the network
layer) and then go up or down, depending on the results. If it is not clear whether the
top-down or the bottom-up approach would be most effective, it can be helpful to start in
the middle (typically the network layer) and run an end-to-end test, such as a ping. If the
ping succeeds, you can assume that all lower layers are good, and you can start
bottom-up troubleshooting, from the network layer. Alternatively, if the test fails, you can
start a top-down troubleshooting process, from the network layer. Whether the result of
the initial test is positive or negative, this method usually results in a faster elimination of
potential problems than what you would achieve by implementing a full top-down or
bottom-up approach, which makes the divide-and-conquer method a very effective
strategy.
•
•
•
Follow-the-path method: Determine the path that packets follow through the network
from the source to the destination and track the packets along the path. Tracing the
path of packets through the network eliminates irrelevant links and devices from the
troubleshooting process. The objective of a troubleshooting method is to isolate the
problem by eliminating potential problem areas from the scope of the troubleshooting
process. By analyzing and verifying the path that packets and frames take through the
network as they travel from the source to the destination, you can reduce the scope of
your troubleshooting to just those links and devices that are actually in the forwarding
path.
Swap components method: Move components physically and observe if the problem
moves with the components or not. A common way to at least isolate the problem is to
start swapping the components like cables, switches, switch ports, or network interface
cards (NICs) on the personal computer (PC) to confirm that the problem moves with the
specific component. This method allows you to isolate the problem, even if the
information that you can gather is minimal, just by executing simple tests in a
methodical way. Even if you do not solve the problem, you have scoped it to a single
element, and further troubleshooting can now be focused on that element. The
drawbacks of this method are as follows:
You are isolating the problem to only a limited set of physical elements and you are not
gaining any real insight into what is happening, because you are gathering only very
limited, indirect information.
•
This method assumes that the problem is with a single component. If the problem is
with a particular combination of elements, you might not be able to isolate the problem
correctly. Be sure to document everything that you change.
•
Perform comparison method: Compare devices or processes of the network that are
operating correctly to devices or processes that are not operating as expected. Gather
clues by spotting significant differences. By comparing configurations, software
versions, hardware or other device properties, links, or processes between working and
nonworking situations and then seeing differences between them, you might be able to
resolve the problem by changing the nonoperational situation to be consistent with the
working situation. The biggest disadvantage of this method is that it can lead to a
working situation, but not to an understanding of the root cause of the problem.
Sometimes, you cannot even be sure if you have implemented a real solution or only a
workaround. Here is an example. You are troubleshooting a connectivity problem with a
branch office router. You have managed to narrow down the problem to some issue
with the default routing, but you cannot seem to find the cause. You notice that this
router is an older type that was phased out in most of the other branch offices. You
have one of the newer types of routers in the trunk of your car, because you plan to
install that in another branch office next week. You decide to copy the configuration of
the existing branch router to the newer router and replace it. Now everything starts to
work as expected. So what do you do? Do you consider the problem fixed? What was
the root cause? What should you do with the old and new routers now? As you can see,
this method has several drawbacks, but it is still a useful technique because you can
use it even when you lack the background to troubleshoot based on knowledge of the
technology. The effectiveness of this method depends on how easy it is to compare the
working and the nonworking devices, situations, or processes. Having a good baseline
of what constitutes normal behavior on the network makes it easier to notice abnormal
behavior. Also, the use of consistent configuration templates makes it easier to see the
significant differences between functioning and malfunctioning devices. Therefore, the
effectiveness of this method depends on the quality of the overall network maintenance
process.
Troubleshooting Tools
Network administrators spend a lot of time troubleshooting the network. Tools that are
used for troubleshooting are capable of generating outputs with a lot of information. In
the process of troubleshooting, one challenge is to know how and what to look for in an
output command—because you want to check only for specific information that is
relevant to the case. You can focus on specific information with Cisco IOS
troubleshooting tools, and Microsoft Windows tools, if appropriate for your network.
Logging
During operation, network devices generate messages about different events. These
messages are sent to an operating system process. This process is responsible for
sending these messages to various destinations, as directed by the device
configuration. Logging messages are also sent to the console by default. Even if the
global logging process is disabled, logging messages are nevertheless sent to the
console. You can decide about the severity level of the logged messages and their
destination.
You can verify logging settings on networking devices by using a show
logging command.
R1# show logging
Syslog logging: enabled (0 messages dropped, 0 messages rate-limited, 0
flushes, 0 overruns, xml disabled, filtering disabled)
No Active Message Discriminator.
No Inactive Message Discriminator.
Console logging: level debugging, 15 messages logged, xml disabled,
filtering disabled
Monitor logging: disabled
Buffer logging: level debugging, 15 messages logged, xml disabled,
filtering disabled
Exception Logging: size (4096 bytes)
Count and timestamp logging messages: disabled
Persistent logging: disabled
Trap logging: level informational, 20 message lines logged
Logging Source-Interface: VRF Name:
Log Buffer (4096 bytes):
*Dec 18 12:38:49.804: %SYS-5-RESTART: System restarted -*Dec 18 12:38:51.528: %LINK-3-UPDOWN: Interface Ethernet0/0, changed state to
up
*Dec 18 12:38:51.541: %LINK-3-UPDOWN: Interface Ethernet0/1, changed state to
up
*Dec 18 12:38:51.545: %LINK-3-UPDOWN: Interface Ethernet0/2, changed state to
up
*Dec 18 12:38:52.534: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Ethernet0/0, changed state to up
*Dec 18 12:38:52.547: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Ethernet0/1, changed state to up
*Dec 18 14:40:34.071: %SYS-5-CONFIG_I: Configured from console by console
*Dec 18 14:44:01.979: %AMDP2_FE-6-EXCESSCOLL: Ethernet0/1 TDR=0, TRC=0
*Dec 18 14:53:13.704: %AMDP2_FE-6-EXCESSCOLL: Ethernet0/1 TDR=0, TRC=0
R1#
From the output of the command, you can chronologically see the events that have
triggered logging messages.
The logging messages may be sent to the console, the monitor, and the memory buffer,
which has a size of 4096 bytes. There are eight levels of severity of logging messages.
Levels are numbered from 0 to 7, from most severe to debugging messages, namely:
emergency, alert, critical, error, warning, notification, informational, and debugging.
Timestamps show the time when each event occurred. By default, system logging is on
and the default severity level is debugging, which means that all messages are logged.
In the output above you can see that the system was restarted once. After the restart,
the interfaces and the line protocols changed the state to "up." This message was
logged as a notification message—level 5.
Cisco IOS doesn't send log messages to a terminal session over IP (Telnet or Secure
Shell protocol [SSH] connections) by default. In the output this is shown by logging to
the monitor setting, which is set to off (disabled). If you need to enable logging to
terminal sessions, you need to use the terminal monitor command. After using
the terminal monitor command, monitor logging enablement can be verified by a show
logging command:
R1# show logging
Syslog logging: enabled (0 messages dropped, 0 messages rate-limited, 0
flushes, 0 overruns, xml disabled, filtering disabled)
No Active Message Discriminator.
No Inactive Message Discriminator.
Console logging: level debugging, 15 messages logged, xml disabled,
filtering disabled
Monitor logging: level debugging, 15 messages logged, xml disabled,
filtering disabled
Buffer logging: level debugging, 15 messages logged, xml disabled,
filtering disabled
Exception Logging: size (4096 bytes)
Count and timestamp logging messages: disabled
<--- output omitted --->
Logging to the monitor (all TTY lines) shows "disabled" or, if enabled, the severity level
limit, number of messages logged, and whether XML formatting or filtering is enabled.
Internet Control Message Protocol
Internet Control Message Protocol (ICMP) is a supporting protocol in the TCP/IP
protocol suite. It is used by network devices, including routers, to send error messages
and operational information indicating, for example, that a requested service is not
available or that a host or router could not be reached. ICMP differs from transport
protocols such as TCP and User Datagram Protocol (UDP) in that it is not typically used
to exchange data between systems, nor is it regularly employed by end-user network
applications (except for some diagnostic tools, such as ping and traceroute).
ICMP messages are typically used for diagnostic or control purposes or generated in
response to errors in IP operations. ICMP errors are directed to the source IP address
of the originating packet. For example, every device (such as an intermediate router)
forwarding an IP version 4 (IPv4) datagram first decrements the time-to-live (TTL) field
in the IPv4 header by one. If the resulting TTL is 0, the packet is discarded and an
ICMP time exceeded in transit message is sent to the packet’s source address.
Many commonly used network utilities are based on ICMP messages.
The traceroute command (or tracert Microsoft Windows command) can be
implemented by transmitting packets with specially set IPv4 TTL header fields, and
looking for ICMP time exceeded in transit and Destination unreachable messages
generated in response. The related ping utility is implemented using the ICMP echo
request and echo reply messages.
ICMP uses the basic support of IP as if it were a higher-level protocol; however, ICMP is
actually integral to IP. Although ICMP messages are contained within standard IP
packets, ICMP messages are usually processed as a special case, distinguished from
normal IP processing. Often, it is necessary to inspect the contents of the ICMP
message and deliver the appropriate error message to the application responsible for
transmission of the IP packet that prompted the sending of the ICMP message.
ICMP is a network layer protocol. There is no TCP or UDP port number associated with
ICMP packets as these numbers are associated with the transport layer above.
Verification of End-To-End IPv4 Connectivity
You can use several verification tools to verify end-to-end IPv4 connectivity:
•
•
•
•
•
ping: A successful ping to an IPv4 address means that the endpoints have basic IPv4
connectivity between them.
traceroute (or Microsoft Windows tracert): The results of traceroute to an IPv4 address
can help you determine how far along the path data can successfully reach.
Telnet or SSH: Used to test the transport layer connectivity for any TCP port over IPv4.
show ip arp or show arp (or Microsoft Windows arp -a): Used to display the mapping
of IPv4 addresses to media access control (MAC) addresses to verify connected
devices.
show ip interface brief (or Microsoft Windows ipconfig /all): Used to display the IPv4
address configuration of the interfaces.
Using ping
The ping command is a very common method for troubleshooting the accessibility of
devices. It uses a series of ICMP Echo messages to determine these parameters:
•
•
•
Whether a remote host is active or inactive
The round-trip time (RTT) in communicating with the host
Packet loss
The ping command first sends an echo request packet to an address, then waits for a
reply. The ping is successful only if the echo request gets to the destination, and the
destination is able to send an echo reply to the source within a predetermined time
called a timeout. The default value of this timeout is two seconds on Cisco devices.
The ICMP header starts after the IPv4 header, since the ICMP messages are
encapsulated in IPv4 packets. The first 4 bytes of the ICMP header are fixed in the
following format:
•
•
•
First byte specifies the ICMP type.
Second byte specifies the code, which depends on the ICMP type.
Third and the fourth bytes are used for the checksum of the ICMP header.
The remaining part of the header depends on the ICMP message type. The ICMP
control messages are identified by the value in the type field. The code field gives
additional context information for the message.
The table below lists commonly used ICMP-type values during troubleshooting.
ICMP
Type Meaning and Code Values
0
Echo-reply
3
Destination unreachable code 0 = net unreachable 1 = host unreachable 2 = protocol
unreachable 3 = port unreachable 4 = fragmentation needed and DF set 5 = source
route failed
4
Source-quench
5
Redirect code 0 = redirect datagrams for the network 1 = redirect datagrams for the
host 2 = redirect datagrams for the type of service and network 3 = redirect datagrams
for the type of service and host
6
Alternate-address
8
Echo
ICMP
Type Meaning and Code Values
9
Router-advertisement
10
Router-solicitation
11
Time-exceeded code 0 = time to live exceeded in transit 1 = fragment reassembly time
exceeded
The table below lists the possible output characters from the Cisco IOS ping command:
Character
Description
!
Each exclamation point indicates receipt of a reply.
.
Each period indicates the device timed out while waiting for a reply.
U
A destination unreachable error protocol data unit (PDU) was received.
Q
Source quench (destination too busy).
M
Could not fragment.
?
Unknown packet type.
&
Packet lifetime exceeded.
For example, after sending ICMP echo requests, if an ICMP echo reply packet is
received within the default, 2-second (configurable) timeout, an exclamation point (!) is
output, meaning that the reply was received before the timeout expired. A period (.) is
output if the reply was not received before the timeout expired.
The device also outputs the min/avg/max RTT in milliseconds.
When pinging, processing delays can be significant because the router considers that
responding to a ping is a low-priority task.
Test the end-to-end connectivity:
R1# ping 10.10.50.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.50.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 4/6/16 ms
R1# ping 10.10.50.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.50.2, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
Ping with the source from the address of a specific interface:
R1# ping 10.10.50.2 source ethernet 0/0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.50.2, timeout is 2 seconds:
Packet sent with a source address of 10.10.10.2
.....
Success rate is 0 percent (0/5)
When a normal ping command is sent from a device, the source address of the ping is
the IPv4 address of the interface that the packet uses to exit the device. The source
address can be changed to the address of any interface on the device.
You can also perform an extended ping, and adjust parameters such as the source
IPv4 address, as follows:
R1# ping
Protocol [ip]:
Target IP address: 10.10.1.2
Repeat count [5]: 1
Datagram size [100]:
Timeout in seconds [2]:
Extended commands [n]: y
Source address or interface: 10.10.1.1
Type of service [0]:
Set DF bit in IP header? [no]:
Validate reply data? [no]:
Data pattern [0xABCD]:
Loose, Strict, Record, Timestamp, Verbose[none]:
Sweep range of sizes [n]:
Type escape sequence to abort.
Sending 1, 100-byte ICMP Echos to 10.10.1.2, timeout is 2 seconds:
Packet sent with a source address of 10.10.1.1
!
Success rate is 100 percent (1/1), round-trip min/avg/max = 1/1/1 ms
If ping fails or returns an unusual RTT, you can use the traceroute command to help
narrow down the problem. You can also vary the size of the ICMP echo payload to test
problems that are related to the MTU.
On a Microsoft Windows device, by default four packets are sent; information displayed
is similar to the Cisco IOS output, as shown in the example:
C:\> ping 172.16.10.2
Pinging 172.16.10.2 with 32 bytes of data:
Reply from 172.16.10.2: bytes=32 time<1ms TTL=128
Reply from 172.16.10.2: bytes=32 time<1ms TTL=128
Reply from 172.16.10.2: bytes=32 time<1ms TTL=128
Reply from 172.16.10.2: bytes=32 time<1ms TTL=128
Ping statistics for 172.16.10.2:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Using traceroute (Cisco IOS) or tracert (Microsoft Windows)
Traceroute is used to test the path that packets take through the network. It sends out
either an ICMP echo request (Microsoft Windows) or UDP (most implementations)
messages, with gradually increasing IPv4 TTL values to probe the path by which a
packet traverses the network. The first packet with the TTL set to 1 will be discarded by
the first hop router, which will send an ICMP “time exceeded” message sourced from its
IPv4 address. The device that initiated the traceroute therefore knows the address of
the first hop router. When the TTL is set to 2, the packets will arrive at the second
router, which will respond with an ICMP "time exceeded" message from its IPv4
address. This process continues until the message reaches its final destination; the
destination device will return either an ICMP echo reply (Windows) or an ICMP port
unreachable, indicating that the request or message has reached its destination.
Cisco traceroute works by sending a sequence of three packets for each TTL value,
with different destination UDP ports, which allows it to report routers that have multiple,
equal-cost paths to the destination. For example, the first three packets with TTL 1 use
UDP ports 33434 (first packet), 33435 (second packet), and 33436 (third packet). The
next three UDP datagrams are sent with a TTL of 2 to destination ports 33437, 33438,
and 33439.
R1# traceroute 10.10.50.2
Type escape sequence to abort.
Tracing the route to 10.10.50.2
VRF info: (vrf in name/id, vrf out name/id)
1 10.10.10.2 0 msec 0 msec 1 msec
2 10.10.20.2 0 msec 1 msec 0 msec
3 172.16.0.2 1 msec 0 msec 0 msec
4 10.10.80.2 0 msec 1 msec 0 msec
5 10.10.40.2 1 msec 1 msec 0 msec
6 *
10.10.50.2 1 msec 1 msec
Use the extended traceroute command to test connectivity from a specified source:
R1# traceroute 10.10.50.2 source Loopback0
<... output omitted ...>
The table below lists the characters that can appear in the Cisco
IOS traceroute command output.
Character Description
nn msec
For each node, the round-trip time in milliseconds for the specified number of
probes
*
The probe timed out
A
Administratively prohibited (for example, by an access control list [ACL])
Q
Source quench (destination too busy)
I
User interrupted test
U
Port unreachable
H
Host unreachable
N
Network unreachable
P
Protocol Unreachable
T
Timeout
?
Unknown packet type
The tracert command is a Windows implementation of traceroute (and will not work on
Cisco devices).
Using Telnet and SSH
One way to obtain information about a remote network device is to connect to it using
either the Telnet or SSH applications. Telnet and SSH are virtual terminal protocols that
are part of the TCP/IP suite. The protocols allow connections and remote console
sessions from one network device to one or more remote devices.
When you use Telnet to connect to a remote device, the default port number is used.
The default port for Telnet is 23. You can use a different port number, from 1 to 65,535,
to test if a remote device is listening to the port.
Although Telnet can be used as a troubleshooting tool to check transport layer
functionality, it should not be used in a production environment to administer network
devices. Nowadays SSH is used, as it is a secure access method.
To log on to a host that supports Telnet, use the telnet EXEC command:
RouterA# telnet host
(where host is an IP address or hostname of a remote system)
Test the transport layer using the telnet command.
R1# telnet 10.10.50.2 80
Trying 10.10.50.2, 80 ... Open
^C
HTTP/1.1 400 Bad Request
Date: Wed, 12 Feb 2014 10:00:32 GMT
Server: cisco-IOS
Accept-Ranges: none
400 Bad Request
[Connection to 10.10.50.2 closed by foreign host]
The telnet command in the output tests if Hypertext Transfer Protocol (HTTP), which
listens on TCP port 80, is open. Since we get Open response, we can assume that
remote device is reachable and it listens to TCP port 80. On a Cisco router to exit the
established connection you must enter a control+C (^C) hotkey as shown in the output.
The Hotkey that closes the connection on a Cisco device is "ctrl+shift+6 and x."
To start an encrypted session with a remote networking device, use the ssh EXEC
command:
RouterA # ssh ip address
Verify ARP table
Devices use ARP to perform IPv4 address resolution for IPv4 to MAC address mapping.
The show ip arp or (show arp) command displays the ARP table on a Cisco router.
Branch# show ip arp
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.1.1.1 5 001b.d59c.3427 ARPA GigabitEthernet0/0
Internet 10.1.1.241 4 00BC.2252.e8bd ARPA GigabitEthernet0/0
The arp -a command displays IPv4-to-MAC-address mappings on a Windows Host.
C:\Windows\system32> arp -a
Interface: 10.1.10.100 --- 0xd
Internet Address Physical Address Type
10.1.10.1 54-75-d0-8e-9a-d8 dynamic
224.0.0.22 01-00-5e-00-00-16 static
224.0.0.252 01-00-5e-00-00-fc static
255.255.255.255 ff-ff-ff-ff-ff-ff static
Verify IPv4 address information
Commands ipconfig and ipconfig /all (Microsoft Windows) are a command-line utilities
that are available on all versions of Microsoft Windows starting with Windows NT. This
utility allows you to get the IPv4 address information of a Windows computer.
Theipconfig /all option displays the IP address, subnet mask, and gateway for all
physical and virtual network adapters. It also displays Domain Name Service (DNS) and
Microsoft Windows Internet Name Service (Microsoft WINS) settings for each adapter.
For a brief overview of interface IPv4 addressing and status information on a Cisco
device, use the show ip interface briefcommand
Troubleshooting Common Switch Media Issues
Switches operate at multiple layers of the OSI model. At Layer 1 of the OSI model,
switches provide an interface to the physical media. At Layer 2 of the OSI model, they
provide switching of frames based on MAC addresses. Therefore, switch problems are
generally seen as Layer 1 and Layer 2 issues. Layer 3 issues, concerning IP
connectivity to the switch for management purposes, could also occur.
In laying out the troubleshooting methodology, some people start at Layer 1 and start
looking at potential media issues like damage to wiring or interference by
electromagnetic sources. The category of UTP wiring will be critical. Cables of lower
category will have more sensitivity to the certain sources of electromagnetic interference
(EMI) such as air-conditioning systems. Category 5 will have better enclosures and
plastic around the wiring to protect it from such sources. Poor cable management could,
for example, put a strain on Registered Jack-45 (RJ-45) connectors causing some
cables to break.
Physical security could also be a cause of media issues. If you allow people to connect
hubs to your switches or connect unwanted sources of traffic to the switch, then traffic
patterns may change, which is not necessarily related to media or physical layer, but
collisions could increase if you install the hub and connect it to your switch. This
problem is related to physical connectivity and so it could be categorized as a physical
layer or media issue.
When new equipment is connected to a switch and the connection operates in the halfduplex mode, or a duplex mismatch occurs, this could lead to an excessive number of
collisions (this is layer 2 issue).
A collision occurs when a transmitting Ethernet station detects another signal while
transmitting a frame. A late collision is a special type of collision. If a collision occurs
after the first 512 bits (64 octets or bytes) of data are transmitted by the transmitting
station, then a late collision is said to have occurred. Most importantly, late collisions are
not resent by the network interface card; in other words, they are not resent by Ethernet,
unlike collisions occurring before the first 64 octets or bytes. It is left for the upper layers
of the protocol stack to determine that there was loss of data and retransmit.
Late collisions should never occur in a properly designed Ethernet network. Possible
causes are usually incorrect cabling or a noncompliant number of hubs in the network;
perhaps a bad network interface card could also cause late collisions. If they happen,
they are typically detected using protocol analyzers and verifying cabling distances and
physical layer requirements and limitations of Ethernet.
A symptom of excessive noise could be number of cyclic redundancy check (CRC)
errors, or rather changes in the number of CRC errors not related to collisions; in other
words, if the number of collisions is constant, consistent, and does not change or have
peaks, then CRC errors could be caused by excessive noise and not related to actual
collisions.
When this issue happens, cable inspection is probably the first step. You can use the
multitude of cable testers and tools available for that purpose. Poor design in using
perhaps something other than Category 5 cabling for Fast Ethernet and 100-Mbps
networks could be the cause, and cable testing plus documentation could tell you the
way to fix this problem.
If the rate of collisions exceeds the baseline for your network, then there are other types
of solutions to the problem. There are several guidelines in terms of what that baseline
should be, including that the number of collisions compared to the total number of
output packets should be less than 0.1 percent.
If collisions are a problem, the cause could be a defective or ill behaving device, for
example, a network interface card sending excessive garbage into the network. This
situation typically happens when there are circuitry or logic failures or even physical
failures on the device. This condition is typically known as jabbering and relates to
network interface cards and other devices continuously sending random or garbage
data into the network. A time domain reflectometer (TDR) could be used to find
unterminated Ethernet cabling, which could be reflecting signals back into the network
and causing collisions.
Fiber media issues have these possible sources:
•
•
•
Microbend and macrobend losses:
Bending the fiber in too small of a radius causes light to escape.
Light strikes the core or cladding at less than the critical angle.
Total internal reflection no longer occurs, and light leaks out.
•
•
Splice losses
Dirty connectors
•
There are several ways in which light can be lost from the fiber. Some are due to
manufacturing problems (for example, microbends, macrobends, and splicing fibers that
do not have their cores centered), while others are physics problems (back reflections
or refractions) because light reflects whenever it encounters a change in the index of
refraction, which defines how much the path of light is bent or refracted when entering a
media. The index of refraction is calculated by dividing the speed of light in a vacuum by
the speed of light in another medium, in this case optical fiber.
Macrobends typically occur during fiber installation.
One cause of light leaking out at a macrobend is that part of the traveling wave, which is
called the evanescent wave, travels inside the cladding. Around the bend, part of the
evanescent wave would have to travel faster than the speed of light in the material,
which is not possible, so this light instead radiates out of the fiber.
Bend losses can be minimized by designing a larger index difference between the core
and the cladding. Core and the cladding have different refractive indexes. The refractive
index of the core is always greater than the index of the cladding. Another approach is
to operate at the shortest possible wavelength and perform good installations.
Splices are a way to connect two fibers by fusing their ends. The best way to align the
fiber core is by using the outside diameter of the fiber as a guide. If the core is at the
center of the fiber, a good splice can be achieved. If the core is off center, then it is
impossible to create a good splice. You would have to cut the fiber further upstream and
test again.
Another possibility is that the fibers to be spliced could have dirt on their ends. Dirt can
cause many problems, particularly if the dirt intercepts some or all the light from the
core. The core for single-mode fiber (SMF) is only 9 micrometers. Splicing fiber is a
highly specialized skill in which trained technicians use fusion splicing equipment to
connect two fiber runs.
Any contamination in the fiber connection can cause failure of the component or failure
of the whole system. Even microscopic dust particles can cause a variety of problems
for optical connections. A particle that partially or completely blocks the core generates
strong back reflections, which can cause instability in the laser system. Dust particles
trapped between two fiber faces can scratch the glass surfaces. Even if a particle is only
situated on the cladding or the edge of the endface, it can cause an air gap or
misalignment between the fiber cores which significantly degrades the optical signal. In
addition to dust, other types of contamination, like oil, water, powdery coatings, must
also be cleaned off the endface. These contaminants can be more difficult to remove
than dust particles and can also cause damage to equipment if not removed.
When you clean fiber components, always complete the steps in the procedures
carefully. The goal is to eliminate any dust or contamination and to provide a clean
environment for the fiber-optic connection. Remember that inspection, cleaning and reinspection are critical steps which must be done before you make any fiber-optic
connection. The most important warning, when cleaning optical connectors is to always
turn off any laser sources before you inspect fiber connectors, optical components, or
bulkheads.
Troubleshooting Media Issues Workflow
You can use the show interfaces command to diagnose media issues.
To troubleshoot media issues when you have no connection or a bad connection
between a switch and another device, follow this process:
1. Use the show interfaces command to check the interface status. If the interface is not
operational, check the cable and connectors for damage.
2. Use the show interfaces command to check for excessive noise. If there is excessive
noise, you will see increased error counters in the output of the command. Then first
find and remove the source of the noise, if possible. Verify that the cable does not
exceed the maximum cable length and check the type of cable that is used. For copper
cable, it is recommended that you use at least Category 5.
3. Use the show interfaces command to check for excessive collisions. If there are
collisions or late collisions, verify the duplex settings on both ends of the connection.
Troubleshooting Common Switch Port Issues
Port issues will most likely have visible symptoms, such as users being unable to
connect to the network. These problems are sometimes related to faulty media and
equipment, such as NICs, but more often port issues are related to duplex and speed
settings.
Most common port issues are related to duplex and speed issues:
•
Duplex-related issues result from a mismatch in duplex settings:
•
Speed-related issues result from a mismatch in speed settings:
A common issue with speed and duplex occurs when the duplex settings are
mismatched between two switches, between a switch and a router, or between a switch
and a workstation or server. This mismatch can occur when you manually hard-code the
speed and duplex or from autonegotiation issues between the two devices.
Duplex and Speed-Related Issues
A duplex mismatch is a situation in which the switch operates at full duplex and the
connected device operates at half duplex. The result of a duplex mismatch is extremely
slow performance, intermittent connectivity, and loss of connection. Other possible
causes of data-link errors at full duplex are bad cables, a faulty switch port, or NIC
software or hardware issues.
Here are examples of duplex-related issues:
•
•
•
One end is set to full duplex, and the other is set to half duplex, resulting in a mismatch.
One end is set to full duplex, and the other is set to autonegotiation:
If autonegotiation fails and this end reverts to half duplex, it results in a mismatch.
•
•
One end is set to half duplex, and the other is set to autonegotiation:
If autonegotiation fails, this end reverts to half duplex.
Both ends are set to half duplex, and there is no mismatch.
•
•
•
•
•
•
•
Autonegotiation is set on both ends:
One end fails to full duplex, and the other end fails to half duplex.
For example, a Gigabit Ethernet interface defaults to full duplex, while a 10/100 defaults
to half duplex.
Autonegotiation is set on both ends:
Autonegotiation fails on both ends, and they both revert to half duplex.
Both ends are set to half duplex, and there is no mismatch.
Here are examples of speed-related issues:
•
•
•
•
•
•
One end is set to one speed, and the other is set to another speed, resulting in a
mismatch.
One end is set to a higher speed, and autonegotiation is enabled on the other end:
If autonegotiation fails, the switch senses what the other end is using and reverts to the
optimal speed.
Autonegotiation is set on both ends:
Autonegotiation fails on both ends, and they revert to their lowest speed.
Both ends are set at the lowest speed, and there is no mismatch.
The Institute of Electrical and Electronics Engineers (IEEE) 802.3ab Gigabit Ethernet
standard mandates the use of autonegotiation for speed and duplex. Although
autonegotiation is not mandatory for other speeds, practically all Fast Ethernet NICs
also use autonegotiation by default. The use of autonegotiation for speed and duplex is
the current recommended practice for ports that are connected to noncritical endpoints.
However, if duplex negotiation fails for some reason, you might have to set the speed
and duplex manually on both ends. Typically, this would mean setting the duplex mode
to full duplex on both ends of the connection. You should manually set the speed and
duplex on links between networking devices and ports that are connected to critical
endpoints, such as servers.
The table summarizes possible settings of speed and duplex for a connection between
a switch port and an end-device NIC. The table gives just a general idea about speed
and duplex misconfiguration combinations.
Speed and Duplex Settings for End-Device NIC and Switch Connections
Resulting
end
Configuration Configuration device
Resulting
on end device on Switch
NIC
Switch
NIC (Speed, (Speed,
(Speed,
(Speed,
Duplex)
Duplex)
Duplex) Duplex) Comments
1000
Mbps,
full
duplex
Assuming that the maximum
capability of a Cisco Catalyst switch
and NIC is 1000 Mbps, full duplex.
AUTO
1000
Mbps,
full
duplex
1000
Mbps,
full
duplex
A link is established, but the switch
does not see any autonegotiation
information from the NIC. Because
Cisco Catalyst switches support only a
full-duplex operation with 1000 Mbps,
they default to full duplex. This
change happens only when operating
at 1000 Mbps.
AUTO
1000 Mbps,
full duplex
1000
Mbps,
full
duplex
1000
Mbps,
full
duplex
Assuming that the maximum
capability of a NIC is 1000 Mbps, full
duplex.
1000 Mbps,
full duplex
1000 Mbps,
full duplex
1000
Mbps,
1000
Mbps,
AUTO
1000 Mbps,
full duplex
AUTO
1000
Mbps,
full
duplex
Correct manual configuration.
Resulting
end
Configuration Configuration device
Resulting
on end device on Switch
NIC
Switch
NIC (Speed, (Speed,
(Speed,
(Speed,
Duplex)
Duplex)
Duplex) Duplex) Comments
full
duplex
full
duplex
100 Mbps,
full duplex
1000 Mbps,
full duplex
No link
No link
Neither side establishes a link due to a
speed mismatch.
100 Mbps,
full duplex
AUTO
(default 100
Mbps half
duplex)
100
Mbps,
full
duplex
100
Mbps,
half
duplex
A duplex mismatch can result in
performance issues, intermittent
connectivity, and loss of
communication.
100 Mbps,
full duplex
100
Mbps,
half
duplex
100
Mbps,
full
duplex
A duplex mismatch can result in
performance issues, intermittent
connectivity, and loss of
communication.
100 Mbps,
full duplex
100
Mbps,
full
duplex
100
Mbps,
full
duplex
Correct manual configuration.
100
Mbps,
half
duplex
A link is established, but the switch
does not see any autonegotiation
information from the NIC and defaults
to half duplex when operating at
10/100 Mbps.
AUTO
(default 100
Mbps half
duplex)
100 Mbps,
full duplex
AUTO
100
Mbps,
half
duplex
10 Mbps, half
duplex
AUTO
10 Mbps, 10 Mbps, A link is established, but the switch
half
half
does not see Fast Link Pulse (FLP). It
duplex
duplex
defaults to 10 Mbps, half duplex.
10 Mbps, half
duplex
100 Mbps,
half duplex
100 Mbps,
half duplex
No link
No link
Neither side establishes a link due to a
speed mismatch.
Resulting
end
Configuration Configuration device
Resulting
on end device on Switch
NIC
Switch
NIC (Speed, (Speed,
(Speed,
(Speed,
Duplex)
Duplex)
Duplex) Duplex) Comments
AUTO
100 Mbps,
half duplex
100
Mbps,
half
duplex
100
Mbps,
half
duplex
A link is established, but the NIC does
not see any autonegotiation
information. It defaults to 100 Mbps,
half duplex.
AUTO
10 Mbps, half
duplex
10 Mbps, 10 Mbps, A link is established, but the NIC does
half
half
not see FLP. It defaults to 10 Mbps,
duplex
duplex
half duplex.
Troubleshooting Process for Duplex and Speed-Related Issues
A common cause of performance problems in Ethernet-based networks is a duplex or
speed mismatch between two ends of a link:
•
•
•
•
•
Duplex configuration guidelines:
Point-to-point Ethernet links should always run in the full-duplex mode. Half duplex is
not common anymore—you can encounter it if hubs are used.
Autonegotiation of speed and duplex is recommended on ports that are connected to
noncritical endpoints.
Manually set the speed and duplex on links between networking devices and ports
connected to critical end points.
Verify duplex and speed settings on an interface.
To troubleshoot switch duplex and speed issues when you have no connection or a bad
connection between a switch and another device, use this general process:
•
•
Use the show interfaces command to check whether there is a speed mismatch
between the switch and a device on the other side (switch, router, server, and so on). If
there is a speed mismatch, set the speed on both sides to the same value.
Use the show interfaces command to check whether there is a duplex mismatch
between the switch and a device on the other side. It is recommended that you use full
duplex if both sides support it.
The example shows the show interfaces command output. The example highlights
duplex and speed settings for the FastEthernet0/1 interface. Based on the output of
the show interfaces command, you can find, diagnose, and correct the duplex or
speed mismatch between the switch and the device on the other side.
SW1# show interfaces FastEthernet0/1
FastEthernet0/1 is up, line protocol is up (connected)
Hardware is Fast Ethernet, address is 0017.0e6c.8e81 (bia 0017.0e6c.8e81)
<... output omitted ...>
Full-duplex, 100Mb/s, media type is 10/100BaseTX
<... output omitted ...>
If the mismatch occurs between two Cisco devices with Cisco Discovery Protocol
enabled, you will see Cisco Discovery Protocol error messages on the console or in the
logging buffer of both devices. Cisco Discovery Protocol is useful for detecting errors
and for gathering port and system statistics on connected Cisco devices. Whenever
there is a duplex mismatch (in this example, on the FastEthernet0/1 interface), the
consoles of Cisco switches display these error messages:
%CDP-4-DUPLEX_MISMATCH: duplex mismatch discovered on FastEthernet0/1 (not
half duplex)
Use the duplex mode command to configure duplex operation on an interface. The
following are available duplex modes:
•
•
•
full: Specifies full-duplex operation.
half: Specifies half-duplex operation.
auto: Specifies the autonegotiation capability. The interface automatically operates at
half or full duplex, depending on environmental factors such as the type of media and
the transmission speeds for the peer routers, hubs, and switches that are used in the
network configuration.
Troubleshooting Physical Connectivity Issue
Often troubleshooting processes involve a component of hardware troubleshooting.
There are three main categories of issues that could be the cause of a failure on the
network: hardware failures, software failures (bugs), and configuration errors. A fourth
category might be performance problems, but performance problems are a symptom,
and not the cause of a problem.
After you have used the ping and traceroute utilities to determine that a network
connectivity problem exists and where it exists, check to see if there are physical
connectivity issues before you get involved in more complex troubleshooting. You could
spend hours troubleshooting a situation only to find that a network cable is loose or
malfunctioning.
The interfaces that the traffic passes through are a component that is always worth
verifying when you are troubleshooting performance-related issues and you suspect the
hardware to be at fault. The interfaces are usually one of the first things that you would
verify while tracing the path between devices.
If you have physical access to devices that you suspect are causing network problems,
you can save troubleshooting time by looking at the port light emitting diodes (LEDs).
The port LEDs show the link status and can indicate an error condition. If a link light for
a port is not on, make sure that both ends of the cable are plugged into the correct
ports.
When troubleshooting small form-factor pluggable (SFP) and SFP+ modules, always
check if you are using SFP or SFP+ transceivers in the switch ports. You should also
check that the same wavelength is used; a transceiver using 1310nm laser will not
communicate with an 850nm transceiver. You need to verify what kind of the optical
cable, single-mode fiber (SMF) or Multi mode fiber (MMF), the SFP module supports
and that you are using the correct one. You should always refer to the documentation
(typically installation guide) for a specific networking device to check the specific
supported cables and modules.
The output of the show interfaces command lists important statistics that should be
checked. The first line of the output from this command tells you whether an interface is
up or down.
To verify the interface status, use the show interfaces command.
Branch# show interfaces GigabitEthernet0/1
GigabitEthernet0/1 is up, line protocol is up
<... output omitted ...>
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
<... output omitted ...>
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 output errors, 0 collisions, 1 interface resets
0 unknown protocol drops
The output of the show interfaces command also displays the following important
statistics:
•
Input queue drops: Input queue drops (and the related ignored and throttle counters)
signify the fact that at some point more traffic was delivered to the device than it could
process. This situation does not necessarily indicate a problem because it could be
normal during traffic peaks. However, it could be an indication that the central
processing unit (CPU) cannot process packets in time. So if this number is consistently
•
•
•
high, you should try to determine at which moments these counters are increasing and
how this increase relates to the CPU usage.
Output queue drops: Output queue drops indicate that packets were dropped due to a
congestion on the interface. Seeing output drops is normal at any point where the
aggregate input traffic is higher than the output traffic. During traffic peaks, the packets
are dropped if traffic is delivered to the interface faster than the interface can send it out.
However, although this setting is considered normal behavior, it leads to packet drops
and queuing delays, so applications that are sensitive to packet drops and queuing
delays, such as Voice over IP (VoIP), might suffer from performance issues. Consistent
output drops might indicate that you need to implement an advanced queuing
mechanism to provide good quality of service (QoS) to each application.
Input errors: Input errors indicate errors that are experienced during the reception of
the frame, such as CRC errors. High numbers of CRC errors could indicate cabling
problems, interface hardware problems, or in an Ethernet-based network, duplex
mismatches.
Output errors: Output errors indicate errors, such as collisions, during the transmission
of a frame. In most Ethernet-based networks, full-duplex transmission is the norm and
half duplex transmission is the exception. In full-duplex transmission, operation
collisions cannot occur. Therefore, collisions, especially late collisions, often indicate
duplex mismatches.
Discovery 9: Troubleshoot Switch Media and Port
Issues
Introduction
In this activity, you will use troubleshooting guidelines to isolate and correct switch
media issues. You will follow troubleshooting guidelines to determine the source of
connectivity problems between a computer and a switch and between a router and a
switch and fix them.
John calls you about an issue that he is experiencing while using computer PC2. He
says that PC2 has no network connectivity, and he insists that somebody unplugged his
computer from the switch. The senior engineers are out. You are the only one who can
solve this problem right now. You only have access to the SW1 and SW2 switches.
Troubleshoot connectivity between PC2 and SW1.
Topology
Job Aids
Device Information
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today.
Personal computers (PCs) in the virtual lab environment are simulated by routers, so you
should use Cisco IOS commands to configure them or verify the configuration.
Device Information Table
Device
Characteristic
Value
PC1
IPv4 address
10.10.1.10/24
PC1
Default gateway
10.10.1.1
PC2
IPv4 address
10.10.1.20/24
PC2
Default gateway
10.10.1.1
SW1
VLAN 1 IPv4 address
10.10.1.2/24
SW1
Default gateway
10.10.1.1
SW2
VLAN 1 IPv4 address
10.10.1.3/24
SW2
Default gateway
10.10.1.1
R1
Ethernet0/0 IPv4 address
10.10.1.1/24
R1
Loopback 0 IPv4 address
10.10.3.1/24
R1
Password
Cisco123
Task 1: Troubleshoot Port Issues
Activity
Step 1
From SW1, determine if you can ping PC2.
SW1# ping 10.10.1.20
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.20, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
When you issue a ping from SW1 to PC2, your success rate is 0 percent, so there is no
Layer 3 connectivity between these two devices.
Step 2
Verify the status of interface Ethernet0/2 on SW2 using the show interfaces
Ethernet0/2 command. Interface Ethernet0/2 connects to PC2.
SW2# show interfaces Ethernet0/2
Ethernet0/2 is administratively down, line protocol is down (disabled)
Hardware is AmdP2, address is aabb.cc00.0520 (bia aabb.cc00.0520)
Description: Link to PC2
MTU 1500 bytes, BW 10000 Kbit/sec, DLY 1000 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Auto-duplex, Auto-speed, media type is unknown
<... output omitted ...>
The output of the show interfaces Ethernet0/2 command tells you that the interface
toward PC2 is administratively down, which indicates that the administrator has disabled
the interface.
Step 3
Fix the issue so that John can continue his work. Do not forget to verify Layer 3
connectivity between PC2 and SW1.
Enter the interface configuration mode for Ethernet0/2 and enable the interface with
the no shutdown command.
SW2# configure terminal
SW2(config)# interface Ethernet 0/2
SW2(config-if)# no shutdown
SW2(config-if)# end
Wait for 30 seconds and verify interface status and test Layer 3 connectivity between
PC2 and SW1 by issuing the ping command from SW1. It should be successful.
SW2# show interfaces Ethernet0/2
Ethernet0/2 is up, line protocol is up (connected)
Hardware is AmdP2, address is aabb.cc00.0520 (bia aabb.cc00.0520)
Description: Link to PC2
MTU 1500 bytes, BW 10000 Kbit/sec, DLY 1000 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Full-duplex, Auto-speed, media type is 100BaseTX
<... output omitted ...>
SW1# ping 10.10.1.20
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.20, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
Step 4
Save the configuration of SW2.
It is important to save the configuration of SW2 because the no shutdown command
would disappear if the switch is restarted. John would again be cut off from the network.
SW2# copy running-config startup-config
Destination filename [startup-config]? <Enter>
Building configuration...
Compressed configuration from 985 bytes to 686 bytes[OK]
If you shut down an interface on a real switch or router, the connected device will see it
as "down/down." Due to virtualization specifics, Cisco IOL (Cisco IOS Software on
Linux) behavior is slightly different. If you shut down an interface on a router or switch,
the connected device will see it as "up/up." In Cisco IOL, the status of an interface can
only be "up/up" or "administratively down/down."
Discovery 10: Troubleshoot Port Duplex Issues
Introduction
In this activity, you will interact with a recording of a lab, made on actual devices, rather
than with the actual devices. In this activity, when entering a command, the entire
command must be entered exactly as stated, including matching the case and spaces;
shortcuts and tab completion are not supported. In GUIs, you will only be able to use the
menu items required for the activity, you will not be able to use other menu items.
Your colleague informs you that SW2 is showing messages about a duplex mismatch
and that they are unable to prevent the messages. The senior engineers went out for
lunch and you need to resolve this issue on your own.
Topology
Job Aids
Device Information
Device Information Table
Device
Characteristic
Value
PC1
IPv4 address
10.10.1.10/24
Device
Characteristic
Value
PC2
IPv4 address
10.10.1.20/24
SW1
VLAN 1 IPv4 address
10.10.1.2/24
SW1
FastEthernet0/0 description
Link to SW2
SW1
FastEthernet0/2 description
Link to PC1
SW2
VLAN 1 IPv4 address
10.10.1.3/24
SW2
FastEthernet0/0 description
Link to SW1
SW2
FastEthernet0/2 description
Link to PC2
SW2
FastEthernet0/13 description
Link to R1
R1
FastEthernet0/0 description
Link to SW2
R1
FastEthernet0/0 IPv4 address
10.10.1.1/24
Task 1: Troubleshoot Port Duplex Issues
Activity
Step 1
On SW2, verify that you have console logging enabled. Use the show
logging command.
From the output, you can see that logging is enabled.
SW2# show logging
Syslog logging: enabled (0 messages dropped, 0 messages rate-limited, 0
flushes, 0 overruns, xml disabled, filtering disabled)
No Active Message Discriminator.
No Inactive Message Discriminator.
Console logging: level debugging, 15 messages logged, xml disabled,
filtering disabled
Monitor logging: level debugging, 0 messages logged, xml disabled,
filtering disabled
Buffer logging: level debugging, 15 messages logged, xml disabled,
filtering disabled
Exception Logging: size (4096 bytes)
Count and timestamp logging messages: disabled
Persistent logging: disabled
Trap logging: level informational, 18 message lines logged
Logging Source-Interface: VRF Name:
<... output omitted ...>
Step 2
Press the Enter key or the Next button to get more information.
Because you have console logging enabled, the switch is reporting its status. As a
result, your colleague is seeing the duplex mismatch message.
The duplex mismatch message appears.
%CDP-4-DUPLEX_MISMATCH: duplex mismatch discovered on FastEthernet0/13 (not
full duplex), with R1 FastEthernet0/0 (full duplex).
SW2#
In a real environment, you would use the Space key to get more information. However,
this is a simulation, so a part of the output has been omitted.
Step 3
Use the show interfaces FastEthernet0/13 command to identify the duplex setting on
the interface.
SW2# show interfaces FastEthernet0/13
FastEthernet0/13 is up, line protocol is up (connected)
Hardware is Fast Ethernet, address is 000b.5fe5.81cd (bia 000b.5fe5.81cd)
MTU 1500 bytes, BW 100000 Kbit, DLY 100 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Half-duplex, Auto-speed, media type is 100BaseTX
input flow-control is unsupported output flow-control is unsupported
ARP type: ARPA, ARP Timeout 04:00:00
<… output omitted …>
SW2#
You can see that half duplex is set on the FastEthernet0/13 interface.
Step 4
Use the show ip interface brief | include 0/13 command to verify that the interface is
functional.
SW2# show ip interface brief | include 0/13
FastEthernet0/13 unassigned YES unset up up
The output shows that the FastEthernet0/13 interface is in an "up/up" state. This status
means that, although the duplex settings are mismatched on the link, it is still functional.
The drawback is that the connection is not efficient. With a half-duplex operation, the
device cannot send and receive data at the same time.
Step 5
Now you need to fix the issue that you identified. You need to enter the configuration
mode and set the FastEthernet 0/13 interface duplex setting to "full" using the duplex
full command.
On SW2, enter the following commands:
SW2# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW2(config)# interface FastEthernet 0/13
SW2(config-if)# duplex full
Step 6
Do not forget to save the changes that you made.
Save your changes by copying the running configuration to the startup configuration.
Usually, you would execute the copy running-config startup-config command from
the privileged mode. But by adding the do command in front of it, you can also execute
it from the interface configuration mode where you are currently in.
SW2(config-if)# do copy running-config startup-config
Destination filename [startup-config]? <Enter>
Building configuration...
[OK]
Troubleshooting Common Problems Associated with
IPv4 Addressing
Troubleshooting IPv4 addressing is an important skill and will prove valuable when
resolving several network issues. For example, assume that a host cannot
communicate to a server that is on a remote network.
Recommended troubleshooting steps that you should perform from the host:
1. Verify the host IPv4 address and subnet mask.
2. Ping the loopback address.
3. Ping the IPv4 address of the local interface.
4. Ping the default gateway.
5. Ping the remote server.
The following examples assume you are on a Windows host.
Verify the Host IPv4 Address and Subnet Mask
Access the command prompt and use ipconfig command to display all current TCP/IP
network configuration parameters. If theMedia State of your adapter indicates that
media is disconnected (like in an example of Wireless LAN adapter below), then you
should troubleshoot the adapter or check the cable (for wired interfaces).
C:\> ipconfig
Windows IP Configuration
Ethernet adapter Ethernet:
Connection-specific DNS Suffix . :
Link-local IPv6 Address . . . . . : fe80::bc2e:95ce:a622:5c7a%18
IPv4 Address. . . . . . . . . . . : 172.16.10.2
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 172.16.10.1
Wireless LAN adapter Wi-Fi:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Ping the Loopback Address
Access the command prompt and ping 127.0.0.1. This address is the diagnostic or
loopback address. If you get a successful ping, your IPv4 stack is considered to be
initialized. If it fails, you have an IPv4 stack failure, and you need to reinstall TCP/IP on
the host.
C:\> ping 127.0.0.1
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Ping statistics for 127.0.0.1:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Ping the IPv4 Address of the Local Interface
From the command prompt, ping the IPv4 address of the local host. If the ping is
successful, your network interface card (NIC) is functioning. If it fails, there is a problem
with the NIC. If the ping is successful, it does not mean that a cable is plugged into the
NIC, but only that the IPv4 protocol stack on the host can communicate to the NIC (via
the LAN driver).
C:\> ping 172.16.10.2
Pinging 172.16.10.2 with 32 bytes of data:
Reply from 172.16.10.2: bytes=32 time<1ms TTL=128
Reply from 172.16.10.2: bytes=32 time<1ms TTL=128
Reply from 172.16.10.2: bytes=32 time<1ms TTL=128
Reply from 172.16.10.2: bytes=32 time<1ms TTL=128
Ping statistics for 172.16.10.2:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Ping the Default Gateway
From the command prompt, ping the default gateway (router). If the ping works, it
means that the NIC is plugged into the network and can communicate on the local
network. If it fails, you have a local physical network problem that could be anywhere
from the NIC to the router.
C:\> ping 172.16.10.1
Pinging 172.16.10.1 with 32 bytes of data:
Reply from 172.16.10.1: bytes=32 time<1ms TTL=128
Reply from 172.16.10.1: bytes=32 time<1ms TTL=128
Reply from 172.16.10.1: bytes=32 time<1ms TTL=128
Reply from 172.16.10.1: bytes=32 time<1ms TTL=128
Ping statistics for 172.16.10.1:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Ping the Remote Server
If the previous steps are successful, try to ping the remote server. If the ping is
successful, then you know that you have IPv4 connectivity between the local host and
the remote server. You also know that the remote physical network is working.
C:\> ping 172.16.20.2
Pinging 172.16.20.2 with 32 bytes of data:
Reply from 172.16.20.2: bytes=32 time<1ms TTL=128
Reply from 172.16.20.2: bytes=32 time<1ms TTL=128
Reply from 172.16.20.2: bytes=32 time<1ms TTL=128
Reply from 172.16.20.2: bytes=32 time<1ms TTL=128
Ping statistics for 172.16.20.2:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
If the ping to the remote server fails, then you may have some type of remote physical
network problem. Verify and correct this by going to the server and performing the same
steps as you just did from the host.
Check the Default Gateway
If the previous steps are unsuccessful, there may be an incorrect default gateway
configuration on either the host or the server, or there may be a routing issue.
You can use the traceroute utility to test the path that packets take through the network,
to ensure that they are going through the router.
To verify the host setting for the default gateway use the appropriate CLI command or
check the settings in the GUI. A useful command in Windows beside ipconfig is route
print. In the example, the user host has a correct default gateway setting.
C:\> route print
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 172.16.10.1 172.16.10.2 35
<--- output omitted --->
One of the possible problem causes is also a wrong setting of a default gateway on the
server. Depending on the host operating system, you will need to use the proper CLI
command or check the settings in the GUI. The server should have a default gateway of
172.16.20.1.
Next, you should check the IPv4 addresses and subnet masks of the interfaces, and the
routing table, on the default gateway router. You should connect to the router and check
the status of interfaces using the show ip interface brief command. To confirm the
IPv4 addresses and subnet masks, use the show running-config command. To check
the routing table, use the show ip routecommand and confirm that all the networks are
listed in the routing table.
Introducing Basic IPv6
Introduction
As the global internet continues to grow, its overall architecture needs to evolve to
accommodate the new technologies that support the increasing numbers of users,
applications, appliances, and services. This evolution also includes Enterprise networks
and communication providers, which provide services to home users. Internet protocol
(IP) version 6 (IPv6) was proposed when it became clear that the 32-bit addressing
scheme of Internet Protocol version 4 (IPv4) cannot keep up with the demands of
internet growth. IPv6 quadruples the number of network address bits from 32 bits (in
IPv4) to 128 bits. This means that the address pool for IPv6 is around 340 undecillion,
or 340 trillion trillion trillion, which is an unimaginably large number.
The larger IPv6 address space allows networks to scale and provide global reachability.
The simplified IPv6 packet header format handles packets more efficiently. The IPv6
network is designed to embrace encryption and favor targeted multicast over often
problematic broadcast communication.
IPv6 as a protocol has been known for a while, but enterprises are beginning to
understand the ways in which it can help them achieve their goals, improve efficiency
and gain functionality.
Cisco Enterprise Architecture Model
As a network engineer, you will need to get familiar with IPv6 including:
•
•
Describing IPv6 features and advantages and comparing them to IPv4.
Configuring basic IPv6 addressing and testing IPv6 connectivity in the network.
IPv4 Address Exhaustion Workarounds
IPv4 provides approximately 4 billion unique addresses. Although 4 billion is a lot of
addresses, it is not enough to keep up with the growth of the internet.
To extend the lifetime and usefulness of IPv4 and to circumvent the address shortage,
several mechanisms were created:
•
•
•
•
Classless interdomain routing (CIDR)
Variable-length subnet masking (VLSM)
Network Address Translation (NAT)
Private IPv4 addresses space (Request for Comments [RFC] 1918)
Over the years, hardware support has been added to devices to support IPv4
enhancements through ASICs ( Application Specific Integrated Circuits ), offloading the
processing from the equipment CPU to network hardware. This allows more
simultaneous transmission and higher bandwidth utilization.
To allocate IPv4 addresses efficiently, CIDR was developed. CIDR allows the address
space to be divided into smaller blocks, varying in size depending on the number of
hosts needed in individual blocks. These blocks are no longer associated with predefined IPv4 addresses classes, such as class A, B, and C. Instead, the allocation
includes a subnet mask or prefix length which defines the size of the block.
VLSMs allow more efficient use of IPv4 addresses, specifically on small segments, such
as point-to-point serial links. VLSM usage was recommended in RFC 1817. CIDR and
VLSM support was a prerequisite for Internet service providers (ISPs) to improve
scalability of the routing on the internet.
NAT introduced a model in which a device that is facing outward to the internet has a
globally routable IPv4 address, while the internal network is configured with private RFC
1918 addresses. These private addresses can never be routed outside the site, as they
can be identical in many different enterprise networks. In this way, even large
enterprises with thousands of systems can hide behind a few routable public networks.
Dynamic Host Configuration Protocol (DHCP) is used extensively in IPv4 networks, to
dynamically allocate addresses, which are typically from private IPv4 addresses space
(RFC 1918) that are then translated to public addresses using NAT.
One of the arguments against deploying IPv6 is that NAT will solve the problems of
limited address space in IPv4. The use of NAT merely delays the exhaustion of the IPv4
address space. Many large organizations and ISPs are moving to IPv6 because they
are running out of IPv4 private addresses, for example, as Internet of Things (IoT)
devices are added to their networks.
Negative implications of using NAT, some of which are identified in RFC 2775 and RFC
2993 include:
•
NAT breaks the end-to-end model of IP, in which only the endpoints, not the
intermediary devices, should process the packets.
•
•
•
NAT inhibits end-to-end network security. To protect the integrity of the IP header by
some cryptographic functions, the IP header cannot be changed between the origin of
the packet (to protect the integrity of the header) and the final destination (to check the
integrity of the received packet). Any translation of parts of a header on the path will
break the integrity check.
When applications are not NAT-friendly, which means that, for a specific application,
more than just the port and address mapping are necessary to forward the packet
through the NAT device, NAT has to embed complete knowledge of the applications to
perform correctly. This fact is especially true for dynamically allocated ports, embedded
IP addresses in application protocols, security associations, and so on. Therefore, the
NAT device needs to be upgraded each time that a new non-NAT-friendly application is
deployed (for example, peer-to-peer).
When different networks use the same private address space and they have to merge
or connect, an address space collision occurs. Hosts that are different but have the
same address cannot communicate with each other. There are NAT techniques
available to help with this issue, but they increase NAT complications.
IPv6 Features
Although VLSM, NAT, and other workarounds (for avoiding the transition to IPv6) are
available, networks with internet connectivity must begin the transition to IPv6 as soon
as possible. For IPv4 networks that provide goods and services to internet users, it is
especially important because the transition by the internet community is already under
way. New networks may be unable to acquire IPv4 addresses, and networks that are
running IPv6 exclusively will not be able to communicate with IPv4-only networks unless
you configure an intermediary gateway or another transition mechanism. IPv6 and IPv4
are completely separate protocols, and IPv6 is not backward-compatible with IPv4. As
the internet evolves, organizations must adopt IPv6 to support future business
continuity, growth, and global expansion. Furthermore, some ISPs and Regional
Internet Registries (RIRs) are administratively out of IPv4 address which means that
their supply of IPv4 addresses is now limited and organizations have to migrate to and
support IPv6 networks.
IPv4
32 bits
192.168.201.113
4,294,467,295 IPv4 Addresses
IPv6
128 bits
2001:0db8:2c80:dd02:0029:ec7a:002b:ea73
340,282,366,920,938,463,463,374,607,431,768,211,456 IPv6 Addresses
IPv6 includes several features that make it attractive for building global-scale, highly
effective networks:
•
•
•
•
•
•
•
•
•
•
Larger address space: The expanded address space includes several IP addressing
enhancements:
It provides improved global reachability and flexibility.
A better aggregation of IP prefixes is announced in the routing tables. The aggregation
of routing prefixes limits the number of routing table entries, which creates efficient and
scalable routing tables.
Multihoming increases the reliability of the internet connection of an IP network. With
IPv6, a host can have multiple IP addresses over one physical upstream link. For
example, a host can connect to several ISPs.
Autoconfiguration is available.
There are more "plug-and-play" options for more devices.
Simplified mechanisms are available for address renumbering and modification.
Simpler header: Streamlined fixed header structures make the processing of IPv6
packets faster and more efficient for intermediate routers within the network. This fact is
especially true when large numbers of packets are routed in the core of the IPv6
internet.
Security and mobility: Features that were not part of the original IPv4 specification,
such as security and mobility, are now built into IPv6. IP Security (IPsec) is available in
IPv6, allowing the IPv6 networks to be secure. Mobility enables mobile network devices
to move around in networks without breaks in established network connections.
Transition richness: IPv6 also includes a rich set of tools to aid in transitioning
networks from IPv4, to allow an easy, nondisruptive transition over time to IPv6dominant networks. An example is dual stacking, in which devices run both IPv4 and
IPv6.
IPv6 Addresses and Address Types
IPv6 addresses consist of 128 bits and are represented as a series of eight 16-bit
hexadecimal fields that are separated by colons. Although upper and lower case are
permitted, it is best practice to use lower case for IPv6 representation:
Address representation:
•
•
Format is x:x:x:x:x:x:x:x, where x is a 16-bit hexadecimal field:
Example: 2001:0db8:010f:0001:0000:0000:0000:0acd
•
•
Leading zeros in a field can be omitted:
Example: 2001:db8:10f:1:0:0:0:acd
•
•
Successive fields of 0 are represented as "::" but only once in an address:
Example: 2001:db8:10f:1::acd
The a, b, c, d, e, and f in hexadecimal fields can be either uppercase or lowercase, but it
is best practice to use lower case for IPv6 representation.
Although Cisco IOS accepts both lowercase and uppercase representation of an IPv6
address, RFC 5952 recommends that IPv6 addresses be represented in lowercase, to
ensure compatibility with case-sensitive applications.
Here are two ways to shorten the writing of IPv6 addresses:
•
•
The leading zeros in a field can be omitted, so 010f can be written as 10f. A field that
contains all zeros (0000) can be written as 0.
Successive fields of zeros can be represented as a double colon (::) but only once in an
address. An address parser can identify the number of missing zeros by separating the
two parts and filling in zeros until the 128 bits are completed. However, if two double
colons are placed in the address, there is no way to identify the size of each block of
zeros. Therefore, only one double colon is possible in a valid IPv6 address.
The use of the double-colon technique makes many addresses very small; for example,
ff01:0:0:0:0:0:0:1 becomes ff01::1. The all zeros address are written as a double colon;
this type of address representation is known as the unspecified address.
IPv6 Address Types
IPv6 supports three basic types of addresses. Each address type has specific rules
regarding its construction and use. These types of addresses are:
•
•
•
Unicast: Unicast addresses are used in a one-to-one context.
Multicast: A multicast address identifies a group of interfaces. Traffic that is sent to a
multicast address is sent to multiple destinations at the same time. An interface may
belong to any number of multicast groups.
Anycast: An IPv6 anycast address is assigned to an interface on more than one node.
When a packet is sent to an anycast address, it is routed to the nearest interface that
has this address. The nearest interface is found according to the measure of metric of
the particular routing protocol that is running. All nodes that share the same address
should behave the same way so that the service is offered similarly, regardless of the
node that services the request.
IPv6 does not support broadcast addresses in the way that they are used in IPv4.
Instead, specific multicast addresses (such as the all-nodes multicast address) are
used.
IPv6 unicast addresses are assigned to each node (interface). Their uses are discussed
in RFC 4291. The unicast addresses are listed below.
An IPv6 address prefix, in the format ipv6-prefix/prefix-length, can be used to represent
bitwise contiguous blocks of the entire address space. The prefix length is a decimal
value that indicates how many of the high-order contiguous bits of the address compose
the prefix. An IPv6 address network prefix is represented in the same way as the
network prefix (as in 10.1.1.0/24) in IPv4. For example, 2001:db8:8086:6502::/32 is a
valid IPv6 prefix.
Address
Value
Global
Unicast
Assigned by Internet Assigned Numbers Authority (IANA) and used
on public networks. They are equivalent to IPv4 global (public)
2000::/3 addresses. ISPs summarize these to provide scalability on the internet.
Link-local
An automatically configured IPv6 address on an interface, the scope is
fe80::/10 only on the physical link, and is required.
UniqueLocal
fc00::/7
Description
Unique local unicast addresses are analogous to private IPv4 addresses
in that they are used for local communications. The scope is entire site
or organization.
Address
Value
Description
Address
Value
Description
::1
Like the 127.0.0.1 address in IPv4, 0:0:0:0:0:0:0:1, or ::1, is used for
local testing functions. Unlike IPv4, which dedicates a complete A
class block of addresses for local testing, IPv6 uses only one.
Unspecified ::
0.0.0.0 in IPv4 means "unknown" address. In IPv6, this address is
represented by 0:0:0:0:0:0:0:0 or ::, and it is typically used in the
source address field of the packet when an interface does not have an
address and is trying to acquire one dynamically.
Loopback
IPv6 Address Scopes and Prefixes
To fully understand IPv6 addressing, it is important to have a solid understanding of
IPv6 scopes and prefixes. An IPv6 address scope specifies the region of the network in
which the address is valid. For example, the link-local address has a scope that is called
"link-local," which means that it is valid and should be used on a directly attached
network (link). Scopes can apply to both unicast and multicast addresses. There are
several different scopes or regions: the link scope, site scope, organization scope, and
global network scope.
Addresses in the link scope are called link-local addresses, and routers will not forward
these addresses to other links or networks. Addresses that are valid within a single site
are called site-local addresses. Addresses intended to span multiple sites belonging to
one organization are called organization-local addresses, and addresses in the global
network scope are called global unicast addresses.
Multiple IPv6 Addresses on an Interface
As with IPv4, IPv6 addresses are assigned to interfaces; however, unlike IPv4, an IPv6
interface is expected to have multiple addresses. The IPv6 addresses that are assigned
to an interface can be any of the basic types: unicast, multicast, or anycast.
IPv6 Unicast Addresses
An IPv6 unicast address generally uses 64 bits for the network ID and 64 bits for the
interface ID. The network ID is administratively assigned, and the interface ID can be
configured manually or autoconfigured.
When you use the Stateless Address AutoConfiguration (SLAAC) IPv6 address
assignment method, a 64-bit interface ID is required.
Use of EUI-64 Format Interface ID in IPv6 Addresses
The interface ID in an IPv6 address is analogous to the host portion of an IPv4 address;
it uniquely identifies an interface on a link. A 64-bit interface ID is not required but is
highly recommended. However, a 64-bit interface ID is required when an IPv6 address
is autoconfigured. One way to guarantee that the interface ID is unique is to base it on
the Media Access Control (MAC) address of the interface.
The Extended Universal Identifier 64-bit format (EUI-64) defines the method to create
an interface identifier from an IEEE 48-bit MAC address. Since the EUI-64 format is
based on unique MAC addresses, using this format, a device can automatically assign
itself a unique 64-bit IPv6 interface ID, without the need for manual configuration or
DHCP. The following figure illustrates this process:
The EUI-64 format interface ID is derived from the 48-bit MAC address by inserting the
hexadecimal number fffe between the upper 3 bytes (OUI field) and the lower 3 vendor
assigned bytes of the MAC address. Then, the seventh bit of the first octet is inverted.
(In a MAC address, this bit indicates the scope and has a value of 0 for global scope
and 1 for local scope; it will be 0 for globally unique MAC addresses. In the EUI-64
format, the meaning of this bit is opposite, so the bit is inverted.)
IPv6 Global Unicast Address
Both IPv4 and IPv6 addresses are generally assigned in a hierarchical manner. Users
are assigned IP addresses by ISPs. ISPs obtain allocations of IP addresses from a local
Internet registry (LIR) or National Internet Registry (NIR), or from their appropriate RIR.
The RIR in turn obtains IP addresses from The Internet Corporation for Assigned
Names and Numbers (ICANN), the operator for IANA.
RFC 4291 specifies the 2000::/3 prefix to be the global unicast address space that the
IANA may allocate to the RIRs. A global unicast address (GUA) is an IPv6 address that
is created from the global unicast prefix. The structure of global unicast addresses
enables the aggregation of routing prefixes, which limits the number of routing table
entries in the global routing table. Global unicast addresses that are used on links are
aggregated upward through organizations and eventually to the ISPs.
The figure shows how address space can be allocated to the RIR and ISP. These
values are minimum allocations, which means that an RIR will get a /23 or shorter, an
ISP will get a /32 or shorter, and a site will get a /48 or shorter. A shorter prefix length
allows more available address space. For example, a site could get a /40 instead of a
/48, giving it more addresses if it can justify it to its ISP. The figure shows a provider
aggregatable model where the end customer obtains its IPv6 address from the ISP. The
end customer can also choose a provider-independent address space by going straight
to the RIR. In this case, it is not uncommon for an end customer to be able to justify a
/32 prefix. The example in the figure uses common and recommended size of the
network with 64 bits used as interface ID.
Global unicast addresses are routable and reachable across the internet. They are
intended for widespread generic use. A global unicast address is structured
hierarchically to allow address aggregation. In the 2000::/3 prefix, the /3 prefix length
states that only the first 3 bits are significant in matching the prefix 2000. The first 3 bits
of the first hexadecimal value, 2, are 001. The fourth bit is insignificant and can be either
a 0 or a 1. Therefore, the first hex digit is either 2 (0010) or 3 (0011). The remaining 12
bits in the hextet (16-bit segment) can be a 0 or a 1. This results in a range of global
unicast addresses of 2000::/3 through 3fff::/3.
A global routing prefix is assigned to a service provider by IANA. The fixed first three
bits plus the following 45 bits identify the organization´s site within the public domain.
A subnet ID can be used by an individual organization to create its own local addressing
hierarchy and to identify subnets. A subnet ID is similar to a subnet in IPv4, except that
an organization with an IPv6 subnet ID can support many more individual subnets (the
actual number depends on the global routing prefix). An organization with a 16-bit IPv6
subnet ID can support up to 65,535 individual subnets.
The interface ID has the same meaning for all unicast addresses. It is used to identify
the interfaces that are on a link and that must be unique to the link. The interface ID is
64 bits long and, depending on the device operating system, can be created by using
the EUI-64 format or by using a randomly generated number. An example of a global
unicast address is 2001:0db8:bbbb:cccc:0987:65ff:fe01:2345.
IPv6 Link-Local Unicast Address
Link-local addresses (LLAs): have a smaller scope than site-local addresses—they refer
only to a particular physical link (physical network). The concept of the link-local scope
is not new to IPv6. RFC 3927 defined 169.254.x.x block as link-local for IPv4. These
addresses have a smaller scope than site-local addresses—they refer only to a
particular physical link (physical network). Routers do not forward packets using linklocal addresses, not even within the organization; they are only for local communication
on a particular physical network segment.
A link-local address is an IPv6 unicast address that is automatically configured on any
interface. This address is the first IPv6 address that will be enabled on the interface. A
device does not have to have any other address but must have a link-local address. A
link-local address consists of the link-local prefix fe80::/10 (1111 1110 10) and the
interface identifier that can be modified in EUI-64 format or randomly generated value
depending on operating system installed on networking device.
It is a common practice to statically configure link-local addresses on the router
interfaces, to make troubleshooting easier. Nodes on a local link can use link-local
addresses to communicate; the nodes do not need globally unique addresses to
communicate.
Link-local addresses are used for link communications such as automatic address
configuration, neighbor discovery, and router discovery. Many IPv6 routing protocols
also use link-local addresses. For static routing, the address of the next-hop device
should be specified using the link-local address of the device; for dynamic routing, all
IPv6 routing protocols must exchange the link-local addresses of neighboring devices.
An example of a link-local unicast address is fe80:0000:0000:0000:0987:65ff:
fe01:2345, which would generally be represented in shorthand notation as
fe80::987:65ff:fe01:2345.
Note The prefix fe80::/10 for link-local addresses includes addresses beginning with
fe80 through febf. In common practice though, link-local addresses typically begin with
fe80.
IPv6 Unique Local Unicast Address
Unique local unicast addresses are analogous to private IPv4 addresses in that they are
used for local communications, intersite virtual private networks (VPNs), and so on,
except for one important difference – these addresses are not intended to be translated
to a global unicast address. They are not routable on the internet without IPv6 NAT, but
they are routable inside a limited area, such as a site. They may also be routed between
a limited set of sites. A unique local unicast address has these characteristics:
•
•
•
•
•
•
It has a globally unique prefix—it has a high probability of uniqueness.
It has a well-known prefix to enable easy filtering at site boundaries.
It allows combining or privately interconnecting sites without creating any address
conflicts or requiring a renumbering of interfaces that use these prefixes.
It is ISP-independent and can be used for communications inside a site without having
any permanent or intermittent internet connectivity.
If it is accidentally leaked outside of a site via routing or the Domain Name System
(DNS), there is no conflict with any other addresses.
Applications may treat unique local addresses like global scoped addresses.
In unique local unicast addresses, global IDs are defined by the administrator of the
local domain. Subnet IDs are also defined by the administrator of the local domain.
Subnet IDs are typically defined using a hierarchical addressing plan, allowing routes to
be summarized and, therefore, reducing the size of routing updates and routing tables.
An example of a unique local unicast address is
fc00:aaaa:bbbb:cccc:0987:65ff:fe01:2345.
Loopback Addresses
Just as with IPv4, a provision has been made for a special loopback IPv6 address for
testing. Packets that are sent to this address "loop back" to the sending device.
However, in IPv6, there is just one address, not a whole block, for this function. The
loopback address is 0:0:0:0:0:0:0:1, which is normally expressed as "::1."
Unspecified Addresses
In IPv4, an IPv4 address containing all zeroes has a special meaning—it refers to the
host itself and is used as a source address to indicate the absence of an address. In
IPv6, this concept has been formalized, and the all-zeros address is named the
unspecified address. It is typically used in the source field of a packet sent by a device
requesting to have its IPv6 address configured. You can apply address compression to
this address. Because the address is all zeroes, the address is simply expressed by two
colons (::).
IPv6 Multicast Addresses
The following figure illustrates the format of an IPv6 multicast address. An IPv6
multicast address defines a group of devices known as a multicast group. IPv6 multicast
addresses use the prefix ff00::/8, which is equivalent to the IPv4 multicast address
224.0.0.0/4. A packet sent to a multicast group always has a unicast source address. A
multicast address can never be the source address. Unlike IPv4, there is no broadcast
address in IPv6. Instead, IPv6 uses multicast, including an all-IPv6 devices well-known
multicast address and a solicited-node multicast address.
The first 8 bits are ff, followed by 4 bits allocated for flags and a 4-bit Scope field. The
Scope field defines the range to which routers can forward the multicast packet. The
next 112 bits represent the group ID.
The first three flags bits are 0 (reserved), R (rendezvous point), and P (network prefix)
are beyond the scope of this course. The fourth flag, the least significant bit (LSB), or
rightmost bit, is the transient flag (T flag). The T flag denotes the two types of multicast
addresses:
•
•
Permanent (0): These addresses, known as predefined multicast addresses, are
assigned by IANA and include both well-known and solicited multicast.
Nonpermanent (1): These are "transient" or "dynamically" assigned multicast
addresses. They are assigned by multicast applications.
The scope bits define the scope of the multicast group. For example, a scope value 1
means interface-local scope or node-local scope, which spans only a single interface on
a node. It is used for loopback transmission of multicast. Link-local scope is defined with
the value 2. It spans the topology area of a single link. Admin-local scope is not
automatically defined from the physical topology or another non-multicast related
configuration and should be defined by administrator. Admin-local scope is the smallest
administratively defined multicast scope. A site-local scope spans a single site, whereas
organization-local scope spans several sites in one organization.
The following table shows a few examples of well-known IPv6 multicast addresses that
have different scopes:
IPv6 Multicast
Address
Description
Scope
ff01::1
All nodes address
Node-local
scope
ff01::2
All routers address
Node-local
scope
ff02::1
All nodes address
Link-local
scope
ff02::2
All routers address
Link-local
scope
ff02::5
Open Shortest Path First (OSPF) routers
Link-local
scope
ff02::6
OSPF designated routers
Link-local
scope
ff02::9
Routing Information Protocol (RIP) routers
Link-local
scope
ff02::A
Enhanced Interior Gateway Routing Protocol (EIGRP) Link-local
routers
scope
ff05::2
All routers address
Site-local
scope
ff05::1:3
All Dynamic Host Configuration Protocol (DHCP)
servers
Site-local
scope
IPv6 Anycast Addresses
An IPv6 anycast address is an address that can be assigned to more than one interface
(typically on different devices). In other words, multiple devices can have the same
anycast address. A packet sent to an anycast address is routed to the "nearest"
interface having that address, according to the router’s routing table.
Anycast addresses are available for both IPv4 and IPv6, initially defined in RFC
1546, Host Anycasting Service. Anycast was meant to be used for services such as
DNS and Hypertext Transfer Protocol (HTTP) but was never really implemented as
designed.
Anycast addresses are syntactically indistinguishable from unicast addresses, because
anycast addresses are allocated from the unicast address space. Assigning a unicast
address to more than one interface makes a unicast address an anycast address. The
nodes to which the anycast address is assigned must be explicitly configured to
recognize that the address is an anycast address.
There are some reserved anycast address formats such as the subnet-router anycast
address defined in RFC 4291 and RFC 2526. Such anycast address has the following
format:
The subnet-router anycast address has a prefix that is followed by a series of zeros (as
the interface ID). For example, if the prefix for the subnet is 2001:db8:10f:1::/64 then the
subnet router anycast address for that subnet is 2001:db8:10f:1::. If you send a packet
to the subnet-router anycast address, it will be delivered to one router, which has an
interface in that subnet. All routers must have subnet-router anycast addresses for the
subnets that are configured on their interfaces.
Reserved Addresses
The Internet Engineering Task Force (IETF) reserved a portion of the IPv6 address
space for various uses, both present and future. Reserved addresses represent 1/256th
of the total IPv6 address space. The lowest address within each subnet prefix (the
interface identifier set to all zeroes) is reserved as the subnet-router anycast address.
The 128 highest addresses within each /64 subnet prefix are reserved for use as
anycast addresses.
Comparison of IPv4 and IPv6 Headers
The IPv6 header differs significantly from the IPv4 header in several ways.
The figure illustrates the IPv4 header format:
The IPv4 header contains 12 fields. Following these fields is an Options field of variable
length that the figure shows in yellow and a padding field that is followed by the data
portion that is usually the transport layer segment. The basic IPv4 header has a size of
20 octets. The Options field increases the size of the IPv4 header.
Of the 12 IPv4 header fields, 6 are removed in IPv6; these fields are shown in green in
the figure. The main reasons for removing these fields in IPv6 are as follows:
•
•
•
The Internet Header Length field (shown as HD Len in the figure) was removed
because it is no longer required. Unlike the variable-length IPv4 header, the IPv6
header is fixed at 40 octets.
Fragmentation is processed differently in IPv6 and does not need the related fields in
the basic IPv4 header. In IPv6, routers no longer process fragmentation. IPv6 hosts are
responsible for path maximum transmission unit (MTU) discovery. If the host needs to
send data that exceeds the MTU, the host is responsible for fragmentation (this process
is recommended but not required). The related Flags field option appears in the
Fragmentation Extension Header in IPv6. This header is attached only to a packet that
is fragmented.
The Header Checksum field at the IP layer was removed because most data link layer
technologies already perform checksum and error control. This change forces formerly
optional upper-layer checksums (such as User Datagram Protocol [UDP]) to become
mandatory.
The Options field is not present in IPv6. In IPv6, a chain of extension headers
processes any additional services. Examples of extension headers include
Fragmentation, Authentication Header, and Encapsulating Security Payload (ESP).
Most other fields were either unchanged or changed only slightly.
This figure illustrates the IPv6 header format:
The IPv6 header has 40 octets, instead of 20 octets as in IPv4. The IPv6 header has
fewer fields, and the header is aligned on 64-bit boundaries to enable fast processing by
current and next-generation processors. The Source and Destination address fields are
four times larger than in IPv4.
The IPv6 header contains eight fields:
1. Version: This 4-bit field contains the number 6, instead of the number 4 as in IPv4.
2. Traffic Class: This 8-bit field is similar to the type of service (ToS) field in IPv4. The
source node uses this field to mark the priority of outbound packets.
3. Flow Label: This new field has a length of 20 bits and is used to mark individual traffic
flows with unique values. Routers are expected to apply an identical quality of service
(QoS) treatment to each packet in a flow.
4. Payload Length: This field is like the Total Length field for IPv4, but because the IPv6
base header is a fixed size, this field describes the length of the payload only, not of the
entire packet.
5. Next Header: The value of this field determines the type of information that follows the
basic IPv6 header.
6. Hop Limit: This field specifies the maximum number of hops that an IPv6 packet can
take. Initial hop limit value is set by operating system (64 or 128 is common, but up to
the operating system). The hop limit field is decremented by each IPv6 router along the
path to the destination. An IPv6 packet is dropped when hop limit field reaches 0. The
hop limit is designed to prevent packets from circulating forever if there is a routing
error. In normal routing, this limit should never be reached.
7. Source Address: This field of 16 octets, or 128 bits, identifies the source of the packet.
8. Destination Address: This field of 16 octets, or 128 bits, identifies the destination of
the packet.
The extension headers, if there are any, follow these eight fields. The number of
extension headers is not fixed, so the total length of the extension header chain is
variable.
For further exploration of IPv6 header fields and their functions, see RFC 8200, Internet
Protocol, Version 6 (IPv6) Specification.
Connecting IPv6 and IPv4 Networks
Devices running different protocols - IPv4 and IPv6 - cannot communicate unless some
translation mechanism is implemented.
Three main options are available for transitioning to IPv6 from the existing IPv4 network
infrastructure: dual-stack network, tunneling, and translation. It is important to note
though that the IPv4 and IPv6 devices cannot communicate with each other unless
translation is configured.
In a dual-stack network, both IPv4 and IPv6 are fully deployed across the infrastructure,
so that configuration and routing protocols handle both IPv4 and IPv6 addressing and
adjacencies separately.
Using the tunneling option, organizations build an overlay network that tunnels one
protocol over the other by encapsulating IPv6 packets within IPv4 packets over the IPv4
network, and IPv4 packets within IPv6 packets over the IPv6 network.
Translation facilitates communication between IPv6-only and IPv4-only hosts and
networks by performing IP header and address translation between the two address
families.
Internet Control Message Protocol Version 6
Internet Control Message Protocol Version 6 (ICMPv6) provides the same diagnostic
services as Internet Control Message Protocol Version 4 (ICMPv4), and it extends the
functionality for some specific IPv6 functions that did not exist in IPv4.
ICMPv6 enables nodes to perform diagnostic tests and report problems. Like ICMPv4,
ICMPv6 implements two kinds of messages—error messages (such as Destination
Unreachable, Packet Too Big, or Time Exceeded) and informational messages (such as
Echo Request and Echo Reply).
ICMPv6 Type Field Descriptions
ICMPv6 Type Field
Description
1
Destination Unreachable
128
Echo Request
129
Echo Reply
133
Router Solicitation
134
Router Advertisement
135
Neighbor Solicitation
136
Neighbor Advertisement
The ICMPv6 packet is identified as 58 in the Next Header field. Inside the ICMPv6
packet, the Type field identifies the type of ICMP message. The Code field further
details the specifics of this type of message. The Data field contains information that is
sent to the receiver for diagnostics or information purposes.
ICMPv6 is used on-link for router solicitation and advertisement, for neighbor solicitation
and advertisement, and for the redirection of nodes to the best gateway.
Neighbor solicitation messages are sent on the local link when a node wants to
determine the data link layer address of another node on the same local link. After
receiving the neighbor solicitation message, the destination node replies by sending a
neighbor advertisement message which includes the data link layer address of the node
sending the neighbor advertisement message. Hosts send router Solicitation messages
to locate the routers on the local link and routers respond with router advertisements
which enable autoconfiguration of the hosts.
Neighbor Discovery
Neighbor discovery uses ICMPv6 neighbor solicitation and neighbor advertisement
messages. The figure depicts the neighbor discovery process, where host A wants to
communicate with host B using IPv6. Since it does not know the data link layer address
(MAC address) of host B, it sends a neighbor solicitation message, and host B replies
with a neighbor advertisement message.
Neighbor discovery is a process that enables these functions:
•
•
•
•
Determining the data link layer address of a neighbor on the same link, like Address
Resolution Protocol (ARP) does in IPv4
Finding neighbor routers on a link
Keeping track of neighbors
Querying for duplicate addresses
The neighbor discovery process uses solicited-node multicast addresses.
Solicited-Node Multicast Address
The solicited-node address is a multicast address which has a link-local scope. All
nodes must join the solicited-node multicast group that corresponds to each of its
unicast and anycast addresses. The solicited-node address is composed of the
ff02:0:0:0:0:1:ff/104 prefix, which is concatenated with the right-most 24 bits of the
corresponding unicast or anycast address.
The source node creates a solicited-node multicast address using the right-most 24 bits
of the IPv6 address of the destination node, and sends a Neighbor Solicitation message
to this multicast address. The corresponding node responds with its data link layer
address in a Neighbor Advertisement message.
Multicast Mapping over Ethernet
A packet destined to a solicited-node multicast address is put in a frame destined to an
associated multicast MAC address.
If an IPv6 address is known, then the associated IPv6 solicited-node multicast address
is known. The example in the figure gives the IPv6 address
2001:db8:1001:f:2c0:10ff:fe17:fc0f. The associated solicited-node multicast address is
ff02::1:ff17:fc0f.
If an IPv6 solicited-node multicast address is known, then the associated MAC address
is known, formed by concatenating the last 32 bits of the IPv6 solicited node multicast
address to 33:33
As the figure shows, the IPv6 solicited-node multicast address is ff02::1:ff17:fc0f. The
associated Ethernet MAC address is 33.33.ff.17.fc.0f.
You must understand that the resulting MAC address is a virtual MAC address: It is not
burned into any Ethernet card. Depending on the IPv6 unicast address, which
determines the IPv6 solicited-node multicast address, any Ethernet card may be
instructed to listen to any of the 224 possible virtual MAC addresses that begin with
33.33.ff. In IPv6, Ethernet cards often listen to multiple virtual multicast MAC addresses
and their own burned-in unicast MAC addresses.
A solicited node multicast is more efficient than an Ethernet broadcast used by IPv4
ARP. With ARP all nodes receive and must therefore process the broadcast requests.
By using IPv6 solicited-node multicast addresses fewer devices receive the request and
therefore fewer frames need to be passed to an upper layer to make the determination
whether they are intended for that specific host.
IPv6 Address Allocation
Interface identifiers in IPv6 addresses are used to identify interfaces on a link. They can
also be thought of as the "host portion" of an IPv6 address. Interface identifiers need to
be unique on a specific link. Interface IDs are typically 64 bits and can be configured in
multiple ways.
There are several ways to assign an IPv6 address to a device:
•
Static assignment using a manual interface ID: One way to statically assign an IPv6
address to a device is to manually assign both the prefix (network) and interface ID
(host) portions of the IPv6 address. To configure an IPv6 address on a Cisco router
interface and enable IPv6 processing on that interface, use the ipv6 address ipv6address/prefix-length command in the interface configuration mode. The following
example shows how to statically configure a global unicast address and a link-local
address on a router's interface.
Router(config)# interface Ethernet0/0
Router(config-if)# ipv6 address 2001:db8:2222:7272::72/64
Router(config-if)# ipv6 address fe80::1 link-local
•
Static assignment using an EUI-64 interface ID: Another way to statically assign an
IPv6 address is to configure the prefix (network) portion of the IPv6 address and derive
the interface ID (host) portion from the MAC address of the device, which is known as
the EUI-64 interface ID.
To configure an IPv6 address for an interface and enable IPv6 processing on the
interface using an EUI-64 interface ID in the low order 64 bits of the address (host), use
the ipv6 address ipv6-prefix/prefix-length eui-64 command in the interface
configuration mode. The following example shows how to statically assign IPv6 address
on a router's interface using an EUI-64 interface ID.
Router(config)# interface Ethernet0/0
Router(config-if)# ipv6 address 2001:0db8:0:1::/64 eui-64
Static assignment, using an EUI-64 interface ID, is used in Cisco IOS Software but not
in all operating systems. For example, Windows operating systems take advantage of
some additional privacy extensions that were defined in RFC 4941, allowing IPv6
address interface identifier to be generated randomly.
•
•
•
Stateless Address Autoconfiguration (SLAAC): As the name implies,
autoconfiguration is a mechanism that automatically configures the IPv6 address of a
node. SLAAC means that the client picks their own address based on the prefix being
advertised on their connected interface. As defined in RFC 4862, the autoconfiguration
process includes generating a link-local address, generating global addresses through
SLAAC, and the duplicate address detection procedure to verify the uniqueness of the
addresses on a link. Some clients may choose to use EUI-64 or a randomized value for
the Interface ID. SLAAC uses neighbor discovery mechanisms to find routers and
dynamically assign IPv6 addresses based on the prefix advertised by the routers. The
autoconfiguration mechanism was introduced to enable plug-and-play networking of
devices to help reduce administration overhead.
Stateful DHCPv6: DHCP for IPv6 enables DHCP servers to pass configuration
parameters, such as IPv6 network addresses, to IPv6 nodes. It offers the capability of
automatic allocation of reusable network addresses and additional configuration
flexibility. Stateful DHCP means that the DHCP server is responsible for assigning the
IPv6 address to the client. The DHCP server keeps a record of all clients and the IPv6
address assigned to them.
Stateless DHCPv6: Stateless DHCP works in combination with SLAAC. The device
gets its IPv6 address and default gateway using SLAAC. The device then sends a query
to a DHCPv6 server for other information such as domain-names, DNS servers and
other client relevant information. This is termed stateless DHCPv6 because the server
does not track IPv6 address bindings per client.
IPv6 supports DNS record types that are supported in the DNS name-to-address and
address-to-name lookup processes. The DNS record types support IPv6 addresses.
IPv6 also supports the reverse mapping of IPv6 addresses to DNS names. The
Dynamic DNS support for Cisco IOS Software feature enables Cisco IOS software
devices to perform Dynamic Domain Name System (DDNS) updates to ensure that an
IPv6 host DNS name is correctly associated with its IPv6 address.
Router Advertisements
Routers periodically send router advertisements on all their configured interfaces. The
router sends a router advertisement to the all-nodes multicast address, ff02::1, to all
IPv6 nodes in the same link.
This figure depicts the router advertisements send by the router.
Router advertisement packet:
•
•
•
•
ICMP type: 134
Source: Router link-local address
Destination: ff02::1 (all-nodes multicast address)
Data: Options, prefix, lifetime, autoconfiguration flag
The default gateway is received by the hosts only through router advertisement; the
concept of DHCP in IPv6 has changed from IPv4, and the DHCP server no longer
supplies the default gateway
Here are examples for the information that the message might contain:
•
•
•
•
•
•
Prefixes that can be used on the link: This information enables stateless
autoconfiguration of the hosts. These prefixes must be /64 for stateless
autoconfiguration.
Lifetime of the prefixes: The default valid lifetime is 30 days, and the default preferred
lifetime is 7 days.
Flags: Flags indicate the kind of autoconfiguration that the hosts can perform. Unlike
IPv4, the router advertisement message suggests to the host how to obtain its
addressing dynamically. There are three options:
SLAAC
SLAAC and stateless DHCPv6
Stateful DHCPv6
•
•
Default preference field: Provides coarse preference metric (low, medium, or high) for
default devices. For example, two devices on a link may provide equivalent but not
equal-cost routing, and the policy may dictate that one of the devices is preferred.
Other types of information for hosts: This information can include the default MTU
and hop count.
By sending prefixes, router advertisements allow host autoconfiguration. You can
configure other advertisement timing and other parameters on routers.
Router Solicitation
A router sends router advertisements every 200 seconds or immediately after a router
solicitation. Router solicitations ask routers that are connected to the local link to send
an immediate router advertisement so that the host can receive the autoconfiguration
information without waiting for the next scheduled router advertisement.
The router solicitation message is defined as follows:
•
•
•
The ICMP type is 133.
The source address is usually the unspecified address (the reason for an unspecified
address is because the router advertisement is not sent back as a unicast but as an allnodes multicast, so the source address of the router solicitation is not important.) The
source address can also be the link-local address of the device.
The destination address is the all-routers multicast address (ff02::2) with the link-local
scope.
When a router sends an answer to a router solicitation, the destination address of the
router advertisement is the all-nodes multicast (ff02::1). The router could be configured
to send solicited router advertisements as a unicast.
A host should send a router solicitation only at the host boot time and only three times.
This practice avoids flooding of router solicitation packets if there is no router on the
local network.
Configuring Stateless Autoconfiguration
The ipv6 address autoconfig command enables stateless autoconfiguration on routers
on an interface-by-interface basis.
RouterB(config-if)# ipv6 address autoconfig [default]
Command
Description
ipv6 address
autoconfig[default]
Configures stateless autoconfiguration on the interface. If you add
the default keyword, the router will install a default route.
Discovery 11: Configure Basic IPv6 Connectivity
Introduction
In this discovery lab, you will explore the configuration of IPv6 in a small network that
contains three routers and three end hosts. Study the topology diagram and Device
Information Table to understand the network connectivity and addressing. All systems
currently are configured with IPv4 addresses and Routing Information Protocol (RIP)
routing. During migration, IPv4 and IPv6 are commonly implemented in parallel with
dual stacks on IPv6-capable systems. You will leave the IPv4 configuration in place
during this exercise. Initially, IPv6 is also fully configured on R2 and PC2. This discovery
lab will guide you through configuring IPv6 on the rest of the network devices.
First, you will configure static IPv6 addresses on R1 and R3. Note that, for simplicity, all
static IPv6 addresses in the topology differ in only four hexadecimal fields (an IPv6
address has 32 hexadecimal fields, including leading zeros and successive fields of
zeros). The first 14 hexadecimal fields are same and are 2001:0db8:0000:00. The
following 2 fields completes the 64-bit prefix and represents the network (01, 02, 03, 04,
05, or 06) within the topology. The next 14 hexadecimal fields are all 00. The final 2
fields specify the host on the network; in this example, the byte is either 01 or 02.
After configuring the IPv6 addresses on R1 and R3, you will configure PC1 and SRV1
for IPv6 stateless autoconfiguration. Then, you will verify the connectivity between PC1
and R1 and between SRV1 and R3.
Servers usually have manually configured IPv6 addresses, but for lab purposes you are
going to use autoconfiguration. Similarly, routers should have manually configured linklocal addresses, but in the lab activity you are going to use automatic address
configuration.
Topology
Job Aid
Device Information
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today.
Personal computers (PCs) in the virtual lab environment are simulated by routers, so you
should use Cisco IOS commands to configure them or verify the configuration.
Device Information Table
Device
Characteristic
Value
PC1
IPv6 address
2001:db8:0:1::/64 Auto
PC2
IPv6 address
2001:db8:0:2::/64 Auto
SRV1
IPv6 address
2001:db8:0:3::/64 Auto
R1
Ethernet0/0 IPv6 address
2001:db8:0:1::1/64
R1
Serial1/1 IPv6 address
2001:db8:0:4::1/64
R1
Serial1/2 IPv6 address
2001:db8:0:5::1/64
R2
Ethernet0/0 IPv6 address
2001:db8:0:2::1/64
R2
Serial1/2 IPv6 address
2001:db8:0:5::2/64
R2
Serial1/3 IPv6 address
2001:db8:0:6::1/64
R3
Ethernet0/0 IPv6 address
2001:db8:0:3::1/64
R3
Serial1/1 IPv6 address
2001:db8:0:4::2/64
R3
Serial1/3 IPv6 address
2001:db8:0:6::2/64
Task 1: Configure IPv6 Addresses
Activity
Step 1
On R1, enable IPv6 routing.
By default, routing for IPv6 is not enabled on a Cisco router. To enable IPv6 routing, use
the ipv6 unicast-routing command in global configuration mode. If IPv6 routing is not
enabled, the router still plays a role of IPv6 host, once it has an IPv6 address.
The ipv6 unicast-routing command is required for forwarding and configuring routing
protocol, but not required to configure IPv6 addresses on interfaces.
On R1, enter the following commands:
R1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
R1(config)# ipv6 unicast-routing
You can use abbreviated commands during configuration. For example, you can
use conf t for configure terminal. If there is any confusion, you can attempt tab
completion to expand the full command syntax. For example, conf <tab> t <tab> would
expand toconfigure terminal.
Step 2
On R1, configure the IPv6 address 2001:db8:0:5::1/64 on the Serial1/2 interface.
On R1, enter the following commands:
R1(config)# interface Serial1/2
R1(config-if)# ipv6 address 2001:db8:0:5::1/64
Step 3
R2 is fully IPv6-configured, and Serial1/2 is the link to R1. If you have correctly
configured the address of R1, you should be able to ping the R2 IPv6 address
(2001:db8:0:5::2). Enter the do command to execute an EXEC mode ping to verify the
connectivity from R1 to R2.
On R1, enter the following command:
R1(config-if)# do ping 2001:db8:0:5::2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:5::2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 6/8/9 ms
Step 4
Configure the R1 IPv6 addresses on Ethernet0/0 (2001:db8:0:1::1/64) and Serial1/1
(2001:db8:0:4::1/64). Remember to take advantage of the Cisco IOS command recall.
The IPv6 addresses in the topology are very similar. Currently, there are no configured
IPv6 peers on Ethernet0/0 or Serial1/1, so you cannot use the ping command for
verification. Leave the configuration mode when the addressing is complete.
On R1, enter the following commands:
R1(config-if)# interface Ethernet0/0
R1(config-if)# ipv6 address 2001:db8:0:1::1/64
R1(config-if)# interface Serial1/1
R1(config-if)# ipv6 address 2001:db8:0:4::1/64
R1(config-if)# end
R1#
Step 5
On R1, display the full IPv6 information that is associated with Ethernet0/0 using
the show ipv6 interface command. It is similar to the show ip interface command,
except that it is IPv6-specific.
On R1, enter the following command:
R1# show ipv6 interface Ethernet0/0
Ethernet0/0 is up, line protocol is up
IPv6 is enabled, link-local address is FE80::A8BB:CCFF:FE00:100
No Virtual link-local address(es):
Description: Link to SW1
Global unicast address(es):
2001:DB8:0:1::1, subnet is 2001:DB8:0:1::/64
Joined group address(es):
FF02::1
FF02::2
FF02::1:FF00:1
FF02::1:FF00:100
MTU is 1500 bytes
ICMP error messages limited to one every 100 milliseconds
ICMP redirects are enabled
ICMP unreachables are sent
ND DAD is enabled, number of DAD attempts: 1
ND reachable time is 30000 milliseconds (using 30000)
ND advertised reachable time is 0 (unspecified)
ND advertised retransmit interval is 0 (unspecified)
ND router advertisements are sent every 200 seconds
ND router advertisements live for 1800 seconds
ND advertised default router preference is Medium
Hosts use stateless autoconfig for addresses.
The output displays both the global unicast address and the link-local address.
IPv6 automatically joins several required multicast groups. All addresses starting with
FF are IPv6 multicast addresses. The third hexadecimal digit "0" means it is a
permanent or well-known multicast address. The fourth hexadecimal digit indicates this
multicast address has link-local scope and is not to be routed.
ff02::1 is all node address to reach out all IPv6 nodes in the same link, ff02::2 is used to
reach all IPv6 routers on the same link, while ff02::1:FF00:1 is IPv6 solicited-node
multicast group for the global unicast address 2001:db8:0:1::1 and ff02::1:ff00:100 for
the link-local address fe80::a8bb:ccff:fe00:100.
The solicited-node address is composed of the ff02:0:0:0:0:1:ff/104 prefix, which is
concatenated with the right-most 24 bits of the corresponding unicast or anycast address.
IPv6 neighbor discovery is automatically enabled when the interface has an IPv6
address. R1 will send neighbor discovery router advertisements containing the global
unicast prefix on Ethernet0/0 when the ipv6 unicast-routing command is configured.
The hosts on this network can use these advertisements for stateless autoconfiguration.
Step 6
On R3, enable IPv6 routing.
On R3, enter the following commands:
R3# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
R3(config)# ipv6 unicast-routing
Step 7
Configure the R3 IPv6 address (2001:db8:0:4::2/64) on Serial1/1, then verify that you
can ping R1 (2001:db8:0:4::1) from R3.
On R3, enter the following commands:
R3(config)# interface Serial1/1
R3(config-if)# ipv6 address 2001:db8:0:4::2/64
R3(config-if)# do ping 2001:db8:0:4::1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:4::1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 8/8/9 ms
Step 8
Configure the R3 IPv6 address (2001:db8:0:6::2/64) on Serial1/3, then verify that you
can ping R2 (2001:db8:0:6::1) from R3. Remember to take advantage of the Cisco IOS
command recall feature.
On R3, enter the following commands:
R3(config-if)# interface Serial1/3
R3(config-if)# ipv6 address 2001:db8:0:6::2/64
R3(config-if)# do ping 2001:db8:0:6::1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:6::1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 8/8/9 ms
Step 9
Configure the R3 IPv6 address (2001:db8:0:3::1/64) on Ethernet0/0. There are currently
no IPv6 peers on Ethernet0/0, so you cannot use the ping command for verification.
Leave the configuration mode when you are done configuring Ethernet0/0.
On R3, enter the following commands:
R3(config-if)# interface Ethernet 0/0
R3(config-if)# ipv6 address 2001:db8:0:3::1/64
R3(config-if)# end
R3#
Step 10
On R3, display the Ethernet0/0 MAC address using the show interfaces command.
The output can be run through the includefilter using address as the filter string to
reduce the amount of command output.
On R3, enter the following command:
R3# show interfaces Ethernet0/0 | include address
Hardware is AmdP2, address is aabb.cc00.0300 (bia aabb.cc00.0300)
Internet address is 10.10.3.1/24
The MAC address in your output may differ.
Step 11
On R3, use the show ipv6 interface brief command to display the IPv6 addresses that
are assigned to the R3 interfaces. It is similar to the show ip interface brief command,
except that it is IPv6-specific.
On R3, enter the following command:
R3# show ipv6 interface brief
Ethernet0/0 [up/up]
FE80::A8BB:CCFF:FE00:300
2001:DB8:0:3::1
Ethernet0/1 [administratively down/down]
unassigned
Ethernet0/2 [administratively down/down]
unassigned
Ethernet0/3 [administratively down/down]
unassigned
Serial1/0 [administratively down/down]
unassigned
Serial1/1 [up/up]
FE80::A8BB:CCFF:FE00:300
2001:DB8:0:4::2
Serial1/2 [administratively down/down]
unassigned
Serial1/3 [up/up]
FE80::A8BB:CCFF:FE00:300
2001:DB8:0:6::2
There are two IPv6 addresses on each of the three configured interfaces. There is a
link-local address that was statelessly autoconfigured. There is also the global unicast
address that you configured.
To statelessly autoconfigure link-local address, Cisco IOS Software uses the EUI-64
interface ID with the fe80::/10 prefix. The IPv6 EUI-64 format address is obtained
through the 48-bit MAC address. The MAC address is first separated into two 24-bits,
with one being OUI (Organizationally Unique Identifier) and the other being NIC specific.
Then the 16-bit 0xFFFE is then inserted between these two 24-bits for the 64-bit EUI
address. Next, the seventh bit from the left, or the universal/local (U/L) bit, needs to be
inverted. So, aa:bb:cc:00:03:00 becomes a8bb:ccff:fe00:300.
The serial interfaces, being point-to-point links, do not use MAC addresses. IPv6
"borrows" the MAC address from an Ethernet interface to compute the link-local
address for serial interfaces. The result is that R3 is using the same link-local address
on multiple interfaces. This situation is acceptable because the link-local address only
needs to be unique on the “link”, meaning data link.
Task 2: Configure IPv6 Stateless Autoconfiguration
Activity
Step 1
With R3 sending neighbor discovery router advertisements on its Ethernet0/0 interface,
SRV1 can use stateless autoconfiguration for IPv6. On SRV1, display its MAC address.
On SRV1, enter the following command:
SRV1# show interfaces Ethernet0/0 | include address
Hardware is AmdP2, address is aabb.cc00.0e00 (bia aabb.cc00.0e00)
Internet address is 10.10.3.30/24
You can see the MAC address; you will see how it is used with the EUI-64 process to
generate the SRV1 IPv6 address with stateless autoconfiguration.
The MAC address in your output may be different.
Step 2
On SRV1, configure Ethernet0/0 to use stateless autoconfiguration for the IPv6 address
assignment and for the IPv6 default route assignment.
PCs (for example, Windows) are typically enabled for SLAAC by default.
Microsoft Windows operating systems do not use EUI-64 by default. They use a
randomly generated Interface ID for privacy reasons. The MAC address has no
influence on this.
On SRV1, enter the following commands:
SRV1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SRV1(config)# interface Ethernet0/0
SRV1(config-if)# ipv6 address autoconfig default
SRV1(config-if)# end
SRV1#
Step 3
On SRV1, display the IPv6 addresses that are assigned to Ethernet0/0.
On SRV1, enter the following command:
SRV1# show ipv6 interface brief Ethernet0/0
Ethernet0/0 [up/up]
FE80::A8BB:CCFF:FE00:E00
2001:DB8:0:3:A8BB:CCFF:FE00:E00
There are two addresses: the link-local address using the standard fe80::/10 prefix, and
the global unicast address using the 2001:db8:0:3::/64 prefix that SRV1 received from
the R3 router advertisement. Both use the EUI-64 standard to incorporate the
Ethernet0/0 MAC address into the IPv6 address.
Step 4
Display the IPv6 routing table on SRV1.
On SRV1, enter the following command:
SRV1# show ipv6 route
IPv6 Routing Table - default - 4 entries
Codes: C - Connected, L - Local, S - Static, U - Per-user Static route
B - BGP, HA - Home Agent, MR - Mobile Router, R - RIP
H - NHRP, I1 - ISIS L1, I2 - ISIS L2, IA - ISIS interarea
IS - ISIS summary, D - EIGRP, EX - EIGRP external, NM - NEMO
ND - ND Default, NDp - ND Prefix, DCE - Destination, NDr - Redirect
O - OSPF Intra, OI - OSPF Inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2
ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2, l - LISP
ND ::/0 [2/0]
via FE80::A8BB:CCFF:FE00:300, Ethernet0/0
NDp 2001:DB8:0:3::/64 [2/0]
via Ethernet0/0, directly connected
L 2001:DB8:0:3:A8BB:CCFF:FE00:E00/128 [0/0]
via Ethernet0/0, receive
L FF00::/8 [0/0]
via Null0, receive
The default route (to prefix ::/0) is pointing to the R3 link-local address, as you saw
earlier, that was created by a default option in the ipv6 address autoconfig command.
The ND code indicates that this default route was learned as part of the neighbor
discovery (ND) process.
The NDp entry describes the prefix that has been learned by R3 router advertisement
message.
Step 5
At this point, SRV1 should be able to ping the R3 global unicast addresses on
Ethernet0/0 (2001:db8:0:3::1), on Serial1/1 (2001:db8:0:4::2), and Serial1/3
(2001:db8:0:6::2). Confirm this connectivity using the ping command. Again, be sure to
take advantage of the Cisco IOS command recall feature.
On SRV1, enter the following commands:
SRV1# ping 2001:db8:0:3::1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:3::1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/4/20 ms
SRV1# ping 2001:db8:0:4::2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:4::2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
SRV1# ping 2001:db8:0:6::2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:6::2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
Step 6
However, you cannot ping addresses on R1 or R2. Attempt to ping the R1 Serial1/1
interface (2001:db8:0:4::1).
On SRV1, enter the following command:
SRV1# ping 2001:db8:0:4::1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:4::1, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
Because R3 is directly connected to the 2001:db8:0:4::/64 subnet, it can successfully
send the probe to R1. The ping fails because R1 does not have a route back to the
2001:db8:0:3/64 network where SRV1 is connected.
Step 7
On PC1, configure Ethernet0/0 to use stateless autoconfiguration and the default route
assignment.
On PC1, enter the following commands:
PC1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
PC1(config)# interface Ethernet0/0
PC1(config-if)# ipv6 address autoconfig default
PC1(config-if)# end
PC1#
Step 8
On PC1, display the IPv6 addresses that are assigned to Ethernet0/0.
On PC1, enter the following command:
PC1# show ipv6 interface brief e0/0
Ethernet0/0 [up/up]
FE80::A8BB:CCFF:FE00:C00
2001:DB8:0:1:A8BB:CCFF:FE00:C00
Step 9
Display the IPv6 routing table on PC1 to verify that it has an IPv6 default route.
On PC1, enter the following command:
PC1# show ipv6 route
IPv6 Routing Table - default - 4 entries
Codes: C - Connected, L - Local, S - Static, U - Per-user Static route
B - BGP, HA - Home Agent, MR - Mobile Router, R - RIP
H - NHRP, I1 - ISIS L1, I2 - ISIS L2, IA - ISIS interarea
IS - ISIS summary, D - EIGRP, EX - EIGRP external, NM - NEMO
ND - ND Default, NDp - ND Prefix, DCE - Destination, NDr - Redirect
O - OSPF Intra, OI - OSPF Inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2
ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2, l - LISP
ND ::/0 [2/0]
via FE80::A8BB:CCFF:FE00:100, Ethernet0/0
NDp 2001:DB8:0:1::/64 [2/0]
via Ethernet0/0, directly connected
L 2001:DB8:0:1:A8BB:CCFF:FE00:C00/128 [0/0]
via Ethernet0/0, receive
L FF00::/8 [0/0]
via Null0, receive
fe80::a8bb:ccff:fe00:100 is the Ethernet0/0 link-local address on R1 in this example.
Your display may be different because the MAC address used to create the address may
be different.
Step 10
From PC1, verify that you can ping the R1 Ethernet0/0 (2001:db8:0:1::1), Serial1/1
(2001:db8:0:4::1), and Serial1/2 (2001:db8:0:5::1) interfaces.
On PC1, enter the following commands:
PC1# ping 2001:db8:0:1::1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:1::1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/3/15 ms
PC1# ping 2001:db8:0:4::1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:4::1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
PC1# ping 2001:db8:0:5::1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:5::1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
Verification of End-To-End IPv6 Connectivity
You can use several verification tools to verify end-to-end IP version 6 (IPv6)
connectivity:
•
•
•
ping: A successful ping means that the device endpoints are able to communicate. This
result does not mean that there are no problems, it simply proves that the basic IPv6
connectivity is working.
traceroute: The results of traceroute can help you determine how far along the path
data can successfully travel. Knowing at what point the data fails can help you
determine the location of the issue. Cisco devices use UDP protocol when
running traceroute. The Windows operating system uses ICMP when running the
similar command tracert.
Telnet: Used to test the transport layer connectivity for any TCP port over IPv6.
In the following scenario, PC1 wants to access applications on the server. The figure
shows the desirable path.
You can use the ping utility to test end-to-end IPv6 connectivity by providing the IPv6
address as the destination address. The utility recognizes the IPv6 address when one is
provided and uses IPv6 as a protocol to test connectivity.
Use the ping utility on the Windows PC to test IPv6 connectivity:
C:\Windows\system32> ping 2001:db8:100::100
Pinging 2001:db8:100::100 with 32 bytes of data:
Reply from 2001:db8:100::100: time=19ms
Reply from 2001:db8:100::100: time=1ms
Reply from 2001:db8:100::100: time=1ms
Reply from 2001:db8:100::100: time=1ms
Ping statistics for 2001:db8:100::100:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 1ms, Maximum = 19ms, Average = 5ms
You can also use the ping utility on the router to test IPv6 connectivity:
Branch# ping 2001:db8:100::100
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:db8:100::100, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 0/0/4 ms
Traceroute is a utility that allows observation of the path between two hosts and
supports IPv6. Use the traceroute Cisco IOS command or tracert Windows command,
followed by the IPv6 destination address, to observe the path between two hosts. The
trace generates a list of IPv6 hops that are successfully reached along the path. This list
provides important verification and troubleshooting information.
The tracert utility on the Windows PC allows you to observe the IPv6 path:
C:\Windows\system32> tracert 2001:db8:100::100
Tracing route to 2001:db8:100::100 over a maximum of 30 hops
1 1 ms 1 ms <1 ms 2001:db8:101::1
2 10 ms 1 ms 1 ms 2001:db8:102::2
3 10 ms 1 ms 1 ms 2001:db8:100::100
Trace complete.
You can also use the traceroute utility on the router to observe the IPv6 path:
Branch# traceroute 2001:db8:100::100
Type escape sequence to abort.
Tracing the route to 2001:db8:100::100
1 2001:db8:102::2 0 msec 0 msec 0 msec
2 2001:db8:100::100 0 msec 0 msec 0 msec
Similar to IPv4, you can use Telnet to test end-to-end transport layer connectivity over
IPv6 using the telnet command from a PC, router, or a switch. When you provide the
IPv6 destination address, the protocol stack determines that the IPv6 protocol has to be
used. If you omit the port number, the client will connect to port 23. You can specify a
specific port number on the client and connect to any TCP port that you want to test.
Although telnet can be used as a troubleshooting tool to check transport layer
functionality, it should not be used in a production environment to administer network
devices. Nowadays a secure access method is used for that purpose using Secure
Shell protocol (SSH).
You can use the telnet command to test the transport layer connectivity for any TCP
port over IPv6.
•
Use Telnet to connect to the standard Telnet TCP port from a Windows PC.
C:\Windows\system32> telnet 2001:db8:100::100
Server~
•
Use Telnet to connect to the TCP port 80, which tests the availability of the HTTP
service.
C:\Windows\system32> telnet 2001:db8:100::100 80
HTTP/1.1 400 Bad Request
Date: Wed, 26 Sep 2019 07:27:10 GMT
Server: Server
Accept-Ranges: none
400 Bad Request
Connection to host lost.
In the example, you can see two connections from a PC to the Server. The first one
connects to port 23 and tests Telnet over IPv6. The second connects to port 80 and
tests Hypertext Transfer Protocol (HTTP) over IPv6.
The telnet command in the output tests if HTTP, which listens on TCP port 80, is open.
The telnet command can also be used from a Cisco router. In this case, to exit the
established connection you must enter a control+C hotkey. The hotkey that closes the
connection on a Cisco device is "ctrl+shift+6 and x."
When troubleshooting end-to-end connectivity, it is useful to verify mappings between
destination IP addresses and MAC addresses on individual segments. In IPv4, ARP
provides this functionality. In IPv6, the Neighbor Discovery process and ICMPv6 replace
the ARP functionality. The neighbor discovery table caches IPv6 addresses and their
resolved MAC addresses. As shown in the figure, the netsh interface ipv6 show
neighbors Windows command lists all devices that are currently in the IPv6 neighbor
discovery table cache. The information that is displayed for each device includes the
IPv6 address, physical (MAC) address, and the neighbor cache state, similar to an ARP
table in IPv4. By examining the neighbor discovery table, you can verify that the
destination IPv6 addresses map to the correct Ethernet addresses
Neighbor discovery table on a PC:
C:\Windows\system32> netsh interface ipv6 show neighbors
Interface 13: LAB
Internet Address Physical Address Type
------------------------------------ ----------------- --------fe80::9c5a:e957:a865:bde9 00-0c-29-36-fd-f7 Stale
fe80::fa66:f2ff:fe31:7250 f8-66-f2-31-72-50 Reachable (Router)
ff02::2 33-33-00-00-00-02 Permanent
ff02::16 33-33-00-00-00-16 Permanent
ff02::1:2 33-33-00-01-00-02 Permanent
ff02::1:ff05:f9fb 33-33-ff-05-f9-fb Permanent
ff02::1:ff31:7250 33-33-ff-31-72-50 Permanent
ff02::1:ff65:bde9 33-33-ff-65-bd-e9 Permanent
ff02::1:ff67:bae4 33-33-ff-67-ba-e4 Permanent
Neighbor discovery table on a router:
Branch# show ipv6 neighbors
IPv6 Address Age Link-layer Addr State Interface
FE80::21E:7AFF:FE79:7A81 8 001e.7a79.7a81 STALE Gi0/1
2001:DB8:101:1:A083:AEE4:E7C5:2CCA 46 000c.2936.fdf7 STALE Gi0/0
2001:DB8:209:165::2 0 001e.7a79.7a81 REACH Gi0/1
2001:DB8:101:1:C31:CD87:7505:F9FB 0 000c.2952.51fd REACH Gi0/0
The figure also shows an example of the neighbor discovery table on the Cisco IOS
router, using the show ipv6 neighborscommand. The table includes the IPv6 address
of the neighbor, age in minutes, the MAC address, the state and the interface through
which the neighbor is reachable. The states are explained in the table:
State
Description
Address resolution is being performed on the entry. The source has sent a
INCMP
neighbor solicitation message to the solicited-node multicast address of the
(Incomplete) target, but it has not received the corresponding neighbor advertisement message.
The source has received positive confirmation within the last ReachableTime
milliseconds that the forward path to the neighbor was functioning correctly,
REACH
since the packets have been recently received. While in the REACH state, the
(Reachable) device takes no special action because it is sending packets.
STALE
More than ReachableTime milliseconds have elapsed since the device received
the last positive confirmation that the forward path was functioning properly.
While in the STALE state, the device takes no action until a packet is sent.
STALE state is the normal state of the neighbor.
DELAY
More than ReachableTime milliseconds have elapsed since the device received
the last positive confirmation that the forward path was functioning properly. A
packet was sent within the last DELAY_FIRST_PROBE_TIME seconds. If the
device receives no reachability confirmation within
DELAY_FIRST_PROBE_TIME seconds of entering the DELAY state, send a
neighbor solicitation message and change the state to PROBE.
PROBE
The device actively seeks a reachability confirmation by resending neighbor
solicitation messages in RetransTimer milliseconds until a reachability
confirmation is received.
You can use other commands to verify that IPv6 is configured correctly on Cisco
routers:
•
•
Verify that IPv6 routing has been enabled on the router. In the show runningconfig command output look for the ipv6 unicast-routing command.
Verify that the interfaces have been configured with the correct IPv6 addresses. You
can use the show ipv6 interface command to display the statuses and configurations
for all IPv6 interfaces.
Configuring Static Routing
Introduction
Routers preserve knowledge of the network topology and forward packets based on
destinations, choosing the best path across the topology. This knowledge of the
topology and changes in the topology can be maintained statically or dynamically. In
large, Enterprise Campus environments, you would typically use one of the available
routing protocols that calculate route information using dynamic routing algorithms.
Static routes, which define explicit paths between two routers, cannot be automatically
updated. You must manually reconfigure static routes when network changes occur.
Therefore, you should use static routes in environments where network traffic is
predictable and where the network design is simple. For example, in branches, smaller
remote sites, Small Office Home Office (SOHO), or in stub networks – networks with
only one exit.
You should not use static routes in large, constantly changing networks because static
routes cannot react to network changes fast enough. Most networks use dynamic routes
to communicate between routers but might have one or two static routes configured for
special cases. Static routes are also useful for specifying a gateway of last resort (a
default router).
Cisco Enterprise Architecture Model
As a network engineer, you will encounter various challenges concerning static routes:
•
•
•
Explaining the difference between static and dynamic routing.
Configuring and verifying both static and default static routes.
Fixing problems with any of the static or static default routes configured on the routers.
Routing Operation
Routing is the process of selecting a path to forward data that originated from one
network and is destined for a different network. Routers gather and maintain routing
information to enable the transmission and receipt of such data packets.
Conceptually, routing information takes the form of entries in a routing table, with one
entry for each identified route. You can manually configure the entries in the routing
table, or the router can use a routing protocol to create and maintain the routing table
dynamically to accommodate network changes when they occur.
A router must perform these actions to route data:
•
•
•
•
•
Identify the destination of the packet: Determine the destination network address of
the packet that needs to be routed by using the subnet mask.
Identify the sources of routing information: Determine from which sources a router
can learn paths to network destinations.
Identify routes: Determine sources from which a router can learn paths to network
destinations.
Select routes: Select the best path to the intended destination.
Maintain and verify routing information: Update known routes and the selected route
according to network conditions.
The routing information that a router learns is offered to the routing table. The router
relies on this table to tell it which interfaces to use when forwarding packets. The figure
shows that the router on the left uses interface Serial0/0/0 to get to the 172.16.1.0/24
subnet.
If the destination network is directly connected—that is, if there is an interface on the
router that belongs to that network—the router already knows which interface to use
when forwarding packets. If destination networks are not directly attached, the router
must learn which route to use when forwarding packets.
The destination information can be learned in two ways:
•
•
You can enter destination network information manually, also known as a static route.
Routers can learn destination network information dynamically through a routing
protocol process that is running on the router.
Static and Dynamic Routing Comparison
There are two ways that a router can learn where to forward packets to destination
networks that are not directly connected.
•
•
Static routing: The router learns routes when an administrator manually configures the
static route. The administrator must manually update this static route entry whenever an
internetwork topology change requires an update. Static routes are user-defined routes
that specify the outgoing interface on the router when packets should be sent to a
specific destination. These administrator-defined routes allow a very precise control
over the routing behavior of the Internet Protocol (IP) internetwork.
Dynamic routing: The router dynamically learns routes after an administrator
configures a routing protocol that determines routes to remote networks. Unlike the
situation with static routes, after the network administrator enables dynamic routing, the
routing process automatically updates the routing table whenever the device receives
new topology information. The router learns and maintains routes to the remote
destinations by exchanging routing updates with other routers in the internetwork.
Here are the characteristics of static and dynamic routes:
•
•
•
•
•
•
•
•
Static routes:
A network administrator manually enters static routes into the router.
A network topology change requires a manual update to the route.
Routing behavior can be precisely controlled.
Dynamic routes:
A network routing protocol automatically adjusts dynamic routes when the topology or
traffic changes.
Routers learn and maintain routes to the remote destinations by exchanging routing
updates.
Routers discover new networks or other changes in the topology by sharing routing
table information.
When to Use Static Routing
Static routes are best suited for small networks, such as local-area networks (LANs),
where routes rarely change. If routes change, you need to manually update your routes
to reflect the new data transmission paths.
In these situations use static routes:
•
•
•
In a small network that requires only simple routing.
In a hub-and-spoke network topology.
When you want to create a quick ad hoc route.
•
Common use is a default static route.
In these situations do not use static routes:
•
•
In a large network.
When the network is expected to scale.
Some of the advantages of using static routes include:
•
•
•
Conserving router resources: Static routing does not consume network bandwidth
and the central processing unit (CPU) resources of the router. When you use a routing
protocol, the traffic between routers adds some overhead as the routers exchange
routing updates about remote networks. Depending on the size of the network, a router
requires some CPU cycles to compute the best way to remote networks.
Simple to configure in a small network: Static routes are commonly used in small
networks that have few routers. Many small networks are designed as stub networks (a
network that is accessed by a single link); for these types of networks, static routes are
the most appropriate solution. Also, most of these networks are designed in a hub-andspoke topology, where you can use default routes for branches that are pointing to the
hub router, which is the gateway to other networks.
Security: Sometimes, you may want to define static routes to control the data
transmission paths that are used by your data. This option may be useful in highly
secure environments.
Here are some disadvantages of using static routes:
•
•
•
Scalability: Static routing might be appropriate for networks that have fewer than four
or five routers. Dynamic routing is more appropriate for large networks to reduce the
probability of errors in a routing configuration. If planned, designed and implemented
correctly, the network can be expanded very easily to meet future demands. Using
dynamic instead of static routing helps the expansion process of the network and does
not require significant redesign of the existing network infrastructure from scratch.
Accuracy: If your network changes and you do not update the static routes, your router
does not have accurate knowledge of your network. Not having accurate knowledge of
your network can result in lost or delayed data transmissions.
High maintenance: When the number of routers increases, the number of static routes
also increases. In large networks, adding even one router with only one new network
means that in addition to configuring the newly added router with static routes to other
networks, you must configure all existing routers in the network with static routes to the
new network.
IPv4 Static Route Configuration
Static routes are commonly used when you are routing from a network to a stub
network. Static routes can also be useful for specifying a "gateway of last resort" to
which all packets with an unknown destination address are sent.
Configure unidirectional static routes to and from a stub network to allow communication
to occur.
When configuring a static route, follow these steps as illustrated in the example in the
figure for router A:
•
•
•
Specify an IPv4 destination network (172.16.1.0 255.255.255.0).
Use the IPv4 address of the next-hop router (172.16.2.1).
Or, use the outbound interface of the local router (Serial0/0/0).
Note Using egress interfaces in the static routes declare that the static networks are
“directly connected” to the egress interfaces and it works fine and without issues only on
point-to-point links, such as serial interfaces running High-level Data Link Control
(HDLC) or Point-to-Point (PPP). On the other hand, when the egress interface used in
the static route is a multi-access interface such as Ethernet (or a serial interface running
Frame Relay or Asynchronous Transfer Mode (ATM)), the solution will likely be
complicated and possibly disastrous. It is highly recommended to configure static routes
using only next hop IPv4 address. Static routes defined using only egress interfaces
might cause uncertainty or unpredictable behavior in the network and shouldn’t be used
unless absolutely necessary.
Static route pointing to the next-hop IPv4 address:
RouterA(config)# ip route 172.16.1.0 255.255.255.0 172.16.2.1
In the figure, router A is configured with a static route to reach the 172.16.1.0/24 subnet
via the next hop IPv4 address 172.16.2.1 using the ip route command.
Alternatively, you can configure the static route by pointing to the exit interface instead
of using the next-hop IPv4 address.
RouterA(config)# ip route 172.16.1.0 255.255.255.0 serial0/0/0
The table lists the ip route command parameters for this example.
Command
Parameters
Description
ip route
Identifies the static route
172.16.1.0
Destination network in the static route
255.255.255.0
Indicates the subnet mask of the destination network; there are 8 bits of
subnetting in effect
172.16.2.1
IPv4 address of the next-hop router in the path to the destination
Serial 0/0/0
Identifies the interface that will be used to reach the next-hop router
In the figure, you would also need to configure router B with a static or default route to
reach the networks behind router A via the serial interface of router B.
A static route is configured for connectivity to remote networks that are not directly
connected to your router. For end-to-end connectivity, you must configure a static route
in both directions.
A host route is a static route for a single host. A host route has a subnet mask of
255.255.255.255.
A floating static route is a static route with administrative distance greater than 1. By
default, static routes have a very low administrative distance of 1, which means that
your router will prefer a static route over any routes that were learned through a
dynamic routing protocol. If you want to use a static route as a backup route (so called
floating static route), you will have to change its administrative distance.
To change administrative distance of a static route add the admin distance parameter to
the command. For example, to change the administrative distance to 10, add number
10 at the end of the ip route configuration.
RouterA(config)# ip route 172.16.1.0 255.255.255.0 172.16.2.1 10
Default Routes
Use a default route when the route from a source to a destination is not known or when
it is not feasible for the router to maintain many routes in its routing table.
A default static route is a route that matches the destination address of all packets that
don’t match any other more specific routes in the routing table. Default static routes are
used in these instances:
•
•
When no other routes in the routing table match the destination IP address of the
packet, or when a more specific match does not exist. A common use for a default static
route is to connect the edge router of a company to an Internet service provider (ISP)
network.
When a router has only one other router to which it is connected. This condition is
known as a stub router.
The syntax for a default static route is like the one that is used for any other static route,
except that the network address is 0.0.0.0 and the subnet mask is 0.0.0.0.
RouterB(config)# ip route 0.0.0.0 0.0.0.0 172.16.2.2
Or
RouterB(config)# ip route 0.0.0.0 0.0.0.0 serial0/0/1
The 0.0.0.0 network address and 0.0.0.0 subnet mask are called a quad-zero route.
In the figure, router B is configured to forward to router A all packets for which there is
no route for the destination network in the router B routing table.
This table lists the ip route command parameters for this example.
Command
Parameters
Description
ip route
Identifies the static route
0.0.0.0
Matches all destination addresses that do not match any other route in the
routing table
0.0.0.0
Matches all subnet masks
172.16.2.2
IPv4 address of the next-hop router to be used as the default for packet
forwarding
Verifying Static and Default Route Configuration
Most routing tables contain a combination of directly connected routes, static routes,
and dynamic routes. However, the routing table must first contain the directly connected
networks that are used to access the remote networks before any static or dynamic
routing can be used.
Verifying Static Route Configuration
RouterA# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
<... output omitted ...>
Gateway of last resort is not set
10.0.0.0/24 is subnetted, 1 subnets
C 10.0.0.0 is directly connected, FastEthernet0/0
172.16.0.0/24 is subnetted, 2 subnets
S 172.16.1.0/24 [1/0] via 172.16.2.1
C 172.16.2.0/24 is directly connected, Serial0/0/0
L 172.16.2.2/32 is directly connected, Serial0/0/0
To verify static routes in the routing table, examine the routing table with the show ip
route command:
•
•
The static route includes the network address, subnet mask (in prefix form), and IPv4
address of the next-hop router or exit interface.
The static route is denoted with the code "S" in the routing table.
Routing tables must contain directly connected networks that are used to connect
remote networks before static or dynamic routing can be used. This means that a route
will not appear in the routing table of the router if the exit interface used for that specific
route is disabled (administratively down) or does not have an IP address assigned. The
interface state needs to be up/up.
A static route includes the network address and prefix of the remote network, along with
the IPv4 address of the next-hop router or exit interface. Static routes are denoted with
the code "S" in the routing table, as shown in the figure.
If you configure a static route to use an egress interface instead of a next-hop IPv4
address, the routing table entry is changed accordingly.
For example, if this default route pointing to the exit interface (Serial0/0/1) is configured
on router B:
RouterB(config)# ip route 0.0.0.0 0.0.0.0 Serial0/0/1
The corresponding routing table entry of the static route in the routing table of router B
is:
RouterB# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
+ - replicated route, % - next hop override
Gateway of last resort is 0.0.0.0 to network 0.0.0.0
S* 0.0.0.0/0 is directly connected, Serial0/0/1
172.16.0.0/16 is variably subnetted, 4 subnets, 2 masks
C 172.16.1.0/24 is directly connected, FastEthernet0/0
L 172.16.1.1/32 is directly connected, FastEthernet0/0
C 172.16.2.0/24 is directly connected, Serial0/0/1
L 172.16.2.1/32 is directly connected, Serial0/0/1
Note that the entry in the routing table no longer refers to the next-hop IPv4 address but
refers directly to the exit interface. This exit interface is the same one to which the static
route was resolved when it used the next-hop IPv4 address. Now that the routing table
process has a match for a packet and this static route, it is able to resolve the route to
an exit interface in a single lookup.
The static route displays the route as directly connected. It is important to understand
that this does not mean that this route is a directly connected network or a directly
connected route. This route is still a static route with the “S” code.
Verifying Default Route Configuration
To verify the default route configuration, examine the routing table on router B:
RouterB# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
+ - replicated route, % - next hop override
Gateway of last resort is 172.16.2.2 to network 0.0.0.0
S* 0.0.0.0/0 [1/0] via 172.16.2.2
172.16.0.0/16 is variably subnetted, 4 subnets, 2 masks
C 172.16.1.0/24 is directly connected, FastEthernet0/0
L 172.16.1.1/32 is directly connected, FastEthernet0/0
C 172.16.2.0/24 is directly connected, Serial0/0/1
L 172.16.2.1/32 is directly connected, Serial0/0/1
The example in the figure shows the router B routing table after configuration of the
default route.
The asterisk (*) indicates that the route is a candidate default route.
Discovery 12: Configure and Verify IPv4 Static Routes
Introduction
In this activity, you will explore IPv4 routing, focusing on static routing. You will
configure and verify static routes and observe the packet-forwarding behavior that is
associated with various routing configurations, including the use of a statically defined
default route.
The lab is prepared with the devices as represented in the topology diagram and
connectivity table. All devices have their basic configurations in place, including
hostnames and IPv4 addresses. Default gateways are defined on PC1, PC2, and
SRV1, but no other routing has been configured.
Topology
Job Aid
Device Information
Device Information Table
Device
Characteristic
Value
PC1
IPv4 address
10.10.1.10/24
PC1
Default gateway
10.10.1.1
PC2
IPv4 address
10.10.2.20/24
Device
Characteristic
Value
PC2
Default gateway
10.10.2.1
SRV1
IPv4 address
10.10.3.30/24
SRV1
Default gateway
10.10.3.1
SW1
VLAN 1 IPv4 address
10.10.1.4/24
SW1
Default gateway
10.10.1.1
SW1
Ethernet0/0 description
Link to R1
SW1
Ethernet0/1 description
Link to PC1
SW2
VLAN 1 IPv4 address
10.10.2.4/24
SW2
Default gateway
10.10.2.1
SW2
Ethernet0/0 description
Link to R2
SW2
Ethernet0/1 description
Link to PC2
SW3
VLAN 1 IPv4 address
10.10.3.4/24
SW3
Default gateway
10.10.3.1
SW3
Ethernet0/0 description
Link to R3
SW3
Ethernet0/1 description
Link to SRV1
R1
Ethernet0/0 description
Link to SW1
R1
Ethernet0/0 IPv4 address
10.10.1.1/24
R1
Serial1/1 description
Link to R3
Device
Characteristic
Value
R1
Serial1/1 IPv4 address
10.1.1.2/30
R1
Serial1/2 description
Link to R2
R1
Serial1/2 IPv4 address
10.1.1.10/30
R2
Ethernet0/0 description
Link to SW2
R2
Ethernet0/0 IPv4 address
10.10.2.1/24
R2
Serial1/2 description
Link to R1
R2
Serial1/2 IPv4 address
10.1.1.9/30
R2
Serial1/3 description
Link to R3
R2
Serial1/3 IPv4 address
10.1.1.6/30
R3
Ethernet0/0 description
Link to SW3
R3
Ethernet0/0 IPv4 address
10.10.3.1/24
R3
Serial1/1 description
Link to R1
R3
Serial1/1 IPv4 address
10.1.1.1/30
R3
Serial1/3 description
Link to R2
R3
Serial1/3 IPv4 address
10.1.1.5/30
The personal computers (PCs) and SRV in the virtual lab environment are simulated by
routers, so you should use Cisco IOS commands to configure them or make
verifications.
Task 1: Verify Device Reachability
Activity
Step 1
Before getting into the configuration of static routes, observe the connectivity when
routing is not yet configured on any of the routers. To do that, from PC1 ping SW1 and
R1 Ethernet0/0.
On PC1, enter the following commands:
PC1# ping 10.10.1.4
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.4, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
PC1# ping 10.10.1.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.1, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/2 ms
Be sure to take advantage of the Cisco IOS command recall feature when entering
similar commands. Use the Up Arrow key to scroll through the command history, and
use the Right and Left Arrow and Backspace keys to edit commands that are similar
to what you need to enter.
Study the topology diagram whenever it is helpful to clarify the physical layout of the lab.
You expected to be able to ping these addresses. They are on the same subnet as
PC1, so routing is not required. The Address Resolution Protocol (ARP) protocol
resolves the Media Access Control (MAC) address of the peer, and communication
ensues at Layer 2.
Step 2
PCs, and IPv4 end hosts in general, normally have routing tables. They usually consist
of a single entry—a default route to their default gateway. View the routing table on PC1
to verify that R1 is its default gateway.
On PC1, enter the following command:
PC1# show ip route
Default gateway is 10.10.1.1
Host Gateway Last Use Total Uses Interface
ICMP redirect cache is empty
The default gateway for PC1 is the 10.10.1.1 IPv4 address. This IPv4 address is applied
on Ethernet0/0 interface on R1 connecting to SW1.
Step 3
From PC1, ping the IPv4 addresses of the remote Serial1/1 and Serial1/2 interfaces of
R1.
On PC1, enter these commands:
PC1# ping 10.1.1.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.1.1.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/201/1002 ms
PC1# ping 10.1.1.10
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.1.1.10, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
The pings were successful without any routes configured on R1. PC1 was
preconfigured to send all remote traffic to R1, and R1 has all the respective subnets
(including the subnet of PC1) in its routing table as directly connected networks.
Step 4
Try to ping the R2 Serial1/2 interface, which is a point-to-point neighbor to the Serial1/2
interface of R1, from PC1.
On PC1, enter this command:
PC1# ping 10.1.1.9
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.1.1.9, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
This ping attempt fails. Interestingly, the Internet Control Message Protocol (ICMP) echo
requests actually do make it to R2. PC1 is configured to use R1 as its default gateway,
and R1 has 10.1.1.0/30 as a directly connected network in its routing table. So, the
forwarding to R2 will function. The problem is that R2 does not have a route back to
10.10.1.0/24 (the network PC1 belongs to) and, as a result, cannot forward the replies
to R1. Therefore, R2 drops the ICMP packet.
Task 2: Configure and Verify Static Routes
Activity
Step 1
It is now time to configure some static routes. On R1, configure routes to 10.10.2.0/24
and 10.10.3.0/24 networks through R2 and R3 as the next-hop, respectively.
On R1, enter these commands:
R1# configure terminal
R1(config)# ip route 10.10.2.0 255.255.255.0 10.1.1.9
R1(config)# ip route 10.10.3.0 255.255.255.0 10.1.1.1
R1(config)# end
R1#
Step 2
On R2, configure routes to 10.10.1.0/24 and 10.10.3.0/24 networks through R1 and R3
as the next-hop, respectively.
On R2, enter these commands:
R2# configure terminal
R2(config)# ip route 10.10.1.0 255.255.255.0 10.1.1.10
R2(config)# ip route 10.10.3.0 255.255.255.0 10.1.1.5
R2(config)# end
R2#
Step 3
Study the topology diagram and consider the static routes that you just configured.
Should PC1 be able to ping PC2? How about SRV1? And how about 10.1.1.6 or
10.1.1.5 (IPv4 addresses in the subnet between R2 and R3)? Explore the current
connectivity from PC1 to PC2, R2 and SRV1.
On PC1, enter the following command:
PC1# ping 10.10.2.20
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.2.20, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
PC1 can ping PC2. This fact implies bidirectional connectivity. The forwarding ICMP
echoes from PC1 to PC2 were successful, and the forwarding of ICMP echo replies
from PC2 to PC1 was successful as well. The first miss (.) in the output is normal
behavior, since ARP response time is longer than the timeout for ICMP echo replies.
Without knowing destination MAC address, ICMP echo request cannot be successful.
On PC1 ping SRV1:
PC1# ping 10.10.3.30
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.3.30, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
This ping attempt was not successful. With the current route configuration, the ICMP
echoes will actually reach SRV1. R1 has a route to 10.10.3.0/24 network using R3, and
R3 has an interface that is directly connected to 10.10.3.0/24 network. However, the
ICMP echo replies that SRV1 generated will be sent to R3 (the default gateway of
SRV1), but R3 does not have a route back to reach 10.10.1.0/24 network of PC1.
Therefore, R3 drops the echo replies.
The period (.) characters in the ping output indicate timeouts on the reply.
On PC1 ping R2 Serial1/3:
PC1# ping 10.1.1.6
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.1.1.6, timeout is 2 seconds:
U.U.U
Success rate is 0 percent (0/5)
This ping attempt fails for a different reason. The subnet 10.1.1.4/30 is the point-to-point
link between R2 and R3. R1 does not have a route to that subnet. Therefore, it must
drop the packets that are destined for that subnet.
The "U" characters in the ping output indicate that a router in the forwarding path
returned ICMP Unreachable messages to PC1.
Step 4
Study the topology diagram. There are six subnets. Each router has direct connectivity
to three of those subnets with the remaining three subnets being remote to the router.
For full connectivity, each router must have a route defined for each of the three remote
subnets. Configure the third static route on both R1 and R2, and configure all three
routes on R3.
On R1, enter these commands:
R1# configure terminal
R1(config)# ip route 10.1.1.4 255.255.255.252 10.1.1.9
R1(config)# end
R1#
On R1 and R2, if your login session has not timed out, command recall will still function
when you enter configuration mode, providing access to the previously entered route
commands. But, be careful. The routes have different subnet masks, so
you mustchange them along with the IPv4 addresses. Note, that from R1 perspective
there are two paths to reach the 10.1.1.4/30 subnet. Therefore, the next-hop can be
either R2 (10.1.1.9) or R3 (10.1.1.1).
On R2, enter these commands:
R2# configure terminal
R2(config)# ip route 10.1.1.0 255.255.255.252 10.1.1.10
R2(config)# end
R2#
The next-hop (10.1.1.10) that is specified in the static route is the Serial1/2 interface on
R1. The 10.1.1.5 IPv4 address applied on Serial1/3 interface on R3 would have been an
equivalent option for the next-hop. The choice to use R1 as the next-hop was arbitrary.
On R3, enter these commands:
R3# configure terminal
R3(config)# ip route 10.10.1.0 255.255.255.0 10.1.1.2
R3(config)# ip route 10.10.2.0 255.255.255.0 10.1.1.6
R3(config)# ip route 10.1.1.8 255.255.255.252 10.1.1.2
R3(config)# end
R3#
The next-hop (10.1.1.2) that is specified in the static route to 10.1.1.8/30 (network
between R1 and R2) is the Serial1/1 interface on R1. The 10.1.1.6 IPv4 address applied
on Serial1/3 interface on R2 would have been an equivalent option for the next-hop.
The choice to use R1 as the next-hop was arbitrary.
Step 5
Now it is appropriate to verify the routing tables on all three routers, R1, R2 and R3.
Each router should have a route for each of the three remote subnets in the routing
table.
On R1, enter these commands:
R1# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
+ - replicated route, % - next hop override
Gateway of last resort is not set
10.0.0.0/8 is variably subnetted, 9 subnets, 3 masks
C 10.1.1.0/30 is directly connected, Serial1/1
L 10.1.1.2/32 is directly connected, Serial1/1
S 10.1.1.4/30 [1/0] via 10.1.1.9
C 10.1.1.8/30 is directly connected, Serial1/2
L 10.1.1.10/32 is directly connected, Serial1/2
C 10.10.1.0/24 is directly connected, Ethernet0/0
L 10.10.1.1/32 is directly connected, Ethernet0/0
S 10.10.2.0/24 [1/0] via 10.1.1.9
S 10.10.3.0/24 [1/0] via 10.1.1.1
R1# show running-config | include route
ip route 10.1.1.4 255.255.255.252 10.1.1.9
ip route 10.10.2.0 255.255.255.0 10.1.1.9
ip route 10.10.3.0 255.255.255.0 10.1.1.1
The manually configured static routes on R1 for each of the three remote subnets are
now available in the routing table.
If you perform the same steps on R2 and R3, you should get similar results, with
appropriate routes configured.
Step 6
At this point, all three routers have routes (either directly connected or statically defined)
to all six subnets. Full connectivity should be available now. On PC1, verify that IPv4
addresses from the different subnets are reachable by issuing the ping command.
On PC1, enter these commands:
PC1# ping 10.10.2.20
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.2.20, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
PC1# ping 10.10.3.30
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.3.30, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
PC1# ping 10.1.1.6
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.1.1.6, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/2 ms
PC1# ping 10.1.1.5
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.1.1.5, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/2 ms
All pings executed on PC1 were successful, indicating that R1 uses the correct static
routes to remote subnets in the routing table.
Task 3: Demonstrate Static Route Drawbacks
Activity
Step 1
The ping command is used to verify whether there is connectivity between two devices.
Additionally, you can use the traceroutecommand to verify the paths that the packet
takes between the devices.
On PC1, trace the route to PC2:
PC1# traceroute 10.10.2.20
Type escape sequence to abort.
Tracing the route to 10.10.2.20
VRF info: (vrf in name/id, vrf out name/id)
1 10.10.1.1 1 msec 1 msec 1 msec
2 10.1.1.9 1 msec 0 msec 1 msec
3 10.10.2.20 2 msec * 2 msec
The path from PC1 to PC2 goes through R1 and R2.
On PC1 trace the route to SRV1:
PC1# traceroute 10.10.3.30
Type escape sequence to abort.
Tracing the route to 10.10.3.30
VRF info: (vrf in name/id, vrf out name/id)
1 10.10.1.1 1 msec 1 msec 1 msec
2 10.1.1.1 1 msec 0 msec 0 msec
3 10.10.3.30 1 msec * 1 msec
The path from PC1 to SRV1 goes through R1 and R3.
It is normal for the middle attempt to the final destination to time out with the traceroute
command. The reason for this behavior is because Cisco routers rate limit ICMP Port
Unreachable Massages. When a traceroute is started, the router sends out a sequence
of UDP datagrams to an invalid port address at the destination host. Three datagrams
are sent, each with TTL value set to 1. As soon as the datagrams hit the first router,
they expire and the router responds with an ICMP Time Exceeded Message. For every
additional datagram sent, the TTL values increments by 1. When the destination host is
reached, it replies with ICMP Port Unreachable Messages, because the datagrams are
trying to access an invalid port.
At this point, one of the limitations of static routes should be apparent. They do not
scale well. In the lab, there are only six subnets and three routers, with no path being
longer than two hops. In this simple environment, nine static routes were required for full
connectivity. As the network complexity grows, the number of required static routes
grows very fast and quickly becomes unwieldy.
In the next series of steps, you will experience another limitation of static routes. The
static routes do not provide redundancy. You will introduce an interface fault into the
network.
Step 2
On R3, disable the interface Serial1/1, which connects R3 to R1.
On R3, enter these commands:
R3# configure terminal
R3(config)# interface Serial 1/1
R3(config-if)# shutdown
R3(config-if)# end
R3#
*Oct 15 07:04:28.078: %SYS-5-CONFIG_I: Configured from console by console
R3#
*Oct 15 07:04:29.292: %LINK-5-CHANGED: Interface Serial1/1, changed state to
administratively down
*Oct 15 07:04:30.296: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Serial1/1, changed state to down
The syslog messages indicate that the state of the Serial1/1 interface changed to
“down”.
Step 3
Shutting down Serial1/1 interface on R3 will have effects on R1 and R3. Access the
console of R1 and verify that a syslog message is displayed, indicating that the interface
Serial1/1 has changed its status to "down." In the lab environment, this status change
may take a minute to propagate.
On R1, observe the syslog messages:
R1#
*Oct 15 07:04:57.975: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Serial1/1, changed state to down
Step 4
View the interface status and routing table on R1.
On R1, enter this command:
R1# show ip interface brief
Interface IP-Address OK? Method Status Protocol
Ethernet0/0 10.10.1.1 YES NVRAM up up
Ethernet0/1 unassigned YES NVRAM administratively down down
Ethernet0/2 unassigned YES NVRAM administratively down down
Ethernet0/3 unassigned YES NVRAM administratively down down
Serial1/0 unassigned YES NVRAM administratively down down
Serial1/1 10.1.1.2 YES NVRAM up down
Serial1/2 10.1.1.10 YES NVRAM up up
Serial1/3 unassigned YES NVRAM administratively down down
The protocol status of Serial1/1 interface is "down."
On R1 enter this command:
R1# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
+ - replicated route, % - next hop override
Gateway of last resort is not set
10.0.0.0/8 is variably subnetted, 6 subnets, 3 masks
S 10.1.1.4/30 [1/0] via 10.1.1.9
C 10.1.1.8/30 is directly connected, Serial1/2
L 10.1.1.10/32 is directly connected, Serial1/2
C 10.10.1.0/24 is directly connected, Ethernet0/0
L 10.10.1.1/32 is directly connected, Ethernet0/0
S 10.10.2.0/24 [1/0] via 10.1.1.9
There are only two static routes in the routing table. With Serial1/1 interface being
down, there is no path to 10.1.1.1 IPv4 address on the 10.1.1.0/30 subnet. Therefore,
the route to 10.10.3.0/24 that uses the 10.1.1.1 IPv4 address as the next hop is invalid
and has been removed from the routing table.
Note that the ip route command for this static route still exists in the configuration.
Step 5
Explore the connectivity from the perspective of PC1. Access the console of PC1 and
attempt a ping and a traceroute to 10.10.3.30 IPv4 address that belongs to SRV1.
On PC1, enter this command:
PC1# ping 10.10.3.30
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.3.30, timeout is 2 seconds:
U.U.U
Success rate is 0 percent (0/5)
The ping is not successful. The "U" characters indicate that a router in the path (in this
case, R1) is sending an ICMP unreachable message back to PC1.
PC1# traceroute 10.10.3.30
Type escape sequence to abort.
Tracing the route to 10.10.3.30
VRF info: (vrf in name/id, vrf out name/id)
1 10.10.1.1 1 msec 1 msec 0 msec
2 10.10.1.1 !H * !H
The path gets to R1 (10.10.1.1), but then gets stuck.
Step 6
Repair the interface fault by returning to R3 and enabling Serial1/1.
On R3, enter these commands:
R3# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
R3(config)# interface Serial 1/1
R3(config-if)# no shutdown
R3(config-if)# end
R3#
*Oct 15 07:13:12.022: %LINK-3-UPDOWN: Interface Serial1/1, changed state to
up
R3#
*Oct 15 07:13:12.747: %SYS-5-CONFIG_I: Configured from console by console
*Oct 15 07:13:13.027: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Serial1/1, changed state to up
The syslog messages indicate that the state of the Serial1/1 interface changed to “up”.
Step 7
Return to the console of R1 and verify that the display of the syslog message is
indicating that Serial1/1 interface has changed back to the "up" state.
On R1, observe the syslog messages:
R1#
*Oct 15 07:13:18.148: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Serial1/1, changed state to up
A syslog message indicates that the state of the Serial1/1 interface is “up”.
Step 8
The real proof comes by verifying end-to-end connectivity. Return to the console of PC1
and execute a ping command and atraceroute command to SRV1.
On PC1, enter these commands:
PC1# ping 10.10.3.30
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.3.30, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 10/10/11 ms
PC1# traceroute 10.10.3.30
Type escape sequence to abort.
Tracing the route to 10.10.3.30
VRF info: (vrf in name/id, vrf out name/id)
1 10.10.1.1 1 msec 1 msec 1 msec
2 10.1.1.1 10 msec 10 msec 9 msec
3 10.10.3.30 11 msec * 9 msec
Because there is direct connectivity between R1 and R3, the ping from PC1 to SRV1 is
successful again and the path is through R1 and R3.
Task 4: Configure and Verify the Backup Static Route
Activity
What has been demonstrated so far in this activity covers the typical usage of static
routes. The next series of steps will show an unconventional use of static routes. This
task should be considered an academic exercise; it is only feasible because of the
simplicity of the lab environment. Add more routers or subnets into the mix, and this
methodology would quickly become unwieldy.
Administrative distance is a property that is used to distinguish the trustworthiness of
different routing protocols. Cisco IOS routers prefer routes with a lower administrative
distance. By default, static routes have an administrative distance of 1, which all but
guarantees that they will be used in the routing table.
It is optional to specify a different administrative distance on static routes. In this next
series of steps, you will define a set of backup (floating) static routes with an
administrative distance of 2. The only way that these routes will end up in the routing
table is if one of the routes with an administrative distance of 1 becomes unavailable.
You will also verify the behavior when an interface fails in the new configuration.
Step 1
Access the console of R1 and add three additional static routes. The new routes will
specify the same remote destination networks as in the existing static routes, but they
will also specify a next hop on the alternate peer router and use an administrative
distance of 2.
On R1, enter the following commands:
R1# configure terminal
R1(config)# ip route 10.10.2.0 255.255.255.0 10.1.1.1 2
R1(config)# ip route 10.10.3.0 255.255.255.0 10.1.1.9 2
R1(config)# ip route 10.1.1.4 255.255.255.252 10.1.1.1 2
R1(config)# end
R1#
The last parameter in the command represents the administrative distance for the static
route. All three static routes will have administrative distance of 2, which is worse than
previously configured static routes to the same destination networks using the default
administrative distance of 1.
Step 2
Verify that now there are six static routes in the configuration, two for each of the remote
networks. The second route to each remote network specifies an alternate next hop and
an administrative distance of 2.
On R1, enter the following command:
R1# show running-config | include route
ip route 10.1.1.4 255.255.255.252 10.1.1.9
ip route 10.1.1.4 255.255.255.252 10.1.1.1 2
ip route 10.10.2.0 255.255.255.0 10.1.1.9
ip route 10.10.2.0 255.255.255.0 10.1.1.1 2
ip route 10.10.3.0 255.255.255.0 10.1.1.1
ip route 10.10.3.0 255.255.255.0 10.1.1.9 2
Now, R1 has two static routes per remote network, one with administrative distance of 1
that will serve as a primary route and other with administrative distance of 2 serving as
a backup when the primary route fails.
Step 3
Verify that only three of the static routes appear in the routing table. Only the routes that
have the default administrative distance of 1 are selected for the routing table.
On R1, enter this command:
R1# show ip route static
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
+ - replicated route, % - next hop override
Gateway of last resort is not set
10.0.0.0/8 is variably subnetted, 9 subnets, 3 masks
S 10.1.1.4/30 [1/0] via 10.1.1.9
S 10.10.2.0/24 [1/0] via 10.1.1.9
S 10.10.3.0/24 [1/0] via 10.1.1.1
The values that you see within the brackets are [Administrative Distance / Metric].
These three routes all have an administrative distance of 1. The metric is used by
routing protocols to measure paths; it is always 0 for static routes.
Step 4
Repeat the respective configuration of static routes on R2 and R3.
On R2, enter these commands:
R2# configure terminal
R2(config)# ip route 10.10.1.0 255.255.255.0 10.1.1.5 2
R2(config)# ip route 10.10.3.0 255.255.255.0 10.1.1.10 2
R2(config)# ip route 10.1.1.0 255.255.255.252 10.1.1.5 2
R2(config)# end
R2#
On R3, enter these commands:
R3# configure terminal
R3(config)# ip route 10.10.1.0 255.255.255.0 10.1.1.6 2
R3(config)# ip route 10.10.2.0 255.255.255.0 10.1.1.2 2
R3(config)# ip route 10.1.1.8 255.255.255.252 10.1.1.6 2
R3(config)# end
R3#
Step 5
Repeat the fault experiment that was performed earlier in the discovery by disabling the
Serial1/1 interface on R3.
On R3, enter these commands:
R3# configure terminal
R3(config)# interface Serial 1/1
R3(config-if)# shutdown
R3(config-if)# end
R3#
*Oct 15 07:29:34.297: %SYS-5-CONFIG_I: Configured from console by console
*Oct 15 07:29:35.080: %LINK-5-CHANGED: Interface Serial1/1, changed state to
administratively down
R3#
*Oct 15 07:29:36.084: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Serial1/1, changed state to down
The syslog messages indicate that the state of the Serial1/1 interface changed to
“down”.
Step 6
Access the console of R1 to verify that the display of the syslog message indicates that
the Serial1/1 interface of R1 has "changed state to down."
On R1, observe the syslog messages:
R1#
*Oct 15 07:29:58.519: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Serial1/1, changed state to down
The syslog messages indicate that the state of the Serial1/1 interface changed to
“down”.
Step 7
View the routing table on R1.
On R1, enter this command:
R1# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
+ - replicated route, % - next hop override
Gateway of last resort is not set
10.0.0.0/8 is variably subnetted, 7 subnets, 3 masks
S 10.1.1.4/30 [1/0] via 10.1.1.9
C 10.1.1.8/30 is directly connected, Serial1/2
L 10.1.1.10/32 is directly connected, Serial1/2
C 10.10.1.0/24 is directly connected, Ethernet0/0
L 10.10.1.1/32 is directly connected, Ethernet0/0
S 10.10.2.0/24 [1/0] via 10.1.1.9
S 10.10.3.0/24 [2/0] via 10.1.1.9
There is a route to 10.10.3.0/24 network. The route through R2 (10.1.1.9) with an
administrative distance of 2 replaced the route through R3 (10.1.1.1) with an
administrative distance of 1 when the connection to the 10.1.1.0/30 network was lost.
Step 8
Access the console of PC1 and verify connectivity between PC1 and SRV1, using
the ping and traceroute commands.
On PC1, enter these commands:
PC1# ping 10.10.3.30
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.3.30, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 17/17/18 ms
PC1# traceroute 10.10.3.30
Type escape sequence to abort.
Tracing the route to 10.10.3.30
VRF info: (vrf in name/id, vrf out name/id)
1 10.10.1.1 1 msec 0 msec 1 msec
2 10.1.1.9 9 msec 9 msec 9 msec
3 10.1.1.5 17 msec 18 msec 17 msec
4 10.10.3.30 15 msec * 18 msec
The connectivity between PC1 and SRV1 still remains, even with the loss of the link
between R1 and R3. However, the path is now longer and traverses R1, R2, and R3.
Step 9
Return to R3 to repair the interface fault.
On R3, enter these commands:
R3# configure terminal
R3(config)# interface Serial 1/1
R3(config-if)# no shutdown
R3(config-if)# end
R3#
*Oct 15 07:34:30.570: %SYS-5-CONFIG_I: Configured from console by console
R3#
*Oct 15 07:34:30.968: %LINK-3-UPDOWN: Interface Serial1/1, changed state to
up
*Oct 15 07:34:31.972: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Serial1/1, changed state to up
The syslog messages indicate that the state of the Serial1/1 interface changed to “up”.
Step 10
Access the console of R1 and verify the display of the syslog message indicating that its
interface Serial1/1 returns to an "up" state.
On R1, observe the syslog messages:
R1#
*Oct 15 07:34:38.628: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Serial1/1, changed state to up
The syslog messages indicate that the state of the Serial1/1 interface changed to “up”.
Step 11
View the routing table on R1.
On R1, enter this command:
R1# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
+ - replicated route, % - next hop override
Gateway of last resort is not set
10.0.0.0/8 is variably subnetted, 9 subnets, 3 masks
C 10.1.1.0/30 is directly connected, Serial1/1
L 10.1.1.2/32 is directly connected, Serial1/1
S 10.1.1.4/30 [1/0] via 10.1.1.9
C 10.1.1.8/30 is directly connected, Serial1/2
L 10.1.1.10/32 is directly connected, Serial1/2
C 10.10.1.0/24 is directly connected, Ethernet0/0
L 10.10.1.1/32 is directly connected, Ethernet0/0
S 10.10.2.0/24 [1/0] via 10.1.1.9
S 10.10.3.0/24 [1/0] via 10.1.1.1
The original route to 10.10.3.0/24 network using R3 as the next hop and with an
administrative distance of 1 has returned to the routing table.
Task 5: Configure and Verify the Default Route
Activity
A default route is a route to the network 0.0.0.0 with the subnet mask 0.0.0.0. Default
routes can be defined statically. Default routes are most commonly used when there is
a hierarchy in the network—for example, to get from a branch office network to the
headquarters network (and the rest of the world), or to get from the corporate network to
the internet.
The lab environment is not hierarchical; in fact, it is perfectly symmetrical. So, the use of
a default route on R1, R2, or R3 is not very practical. But, even so, it can be
enlightening to explore the behavior of a default route within the lab environment.
Step 1
Access R1 and remove all the static routes that are configured. Unfortunately, removing
those routes is a tedious operation. Be sure to make good use of the Cisco IOS
command history feature to ease the burden.
On R1, enter these commands:
R1# configure terminal
R1(config)# no ip route 10.1.1.4 255.255.255.252 10.1.1.9
R1(config)# no ip route 10.1.1.4 255.255.255.252 10.1.1.1 2
R1(config)# no ip route 10.10.2.0 255.255.255.0 10.1.1.9
R1(config)# no ip route 10.10.2.0 255.255.255.0 10.1.1.1 2
R1(config)# no ip route 10.10.3.0 255.255.255.0 10.1.1.1
R1(config)# no ip route 10.10.3.0 255.255.255.0 10.1.1.9 2
R1(config)# end
R1#
Step 2
Verify that there are no route commands left in the configuration and that only local and
connected routes appear in the routing table.
On R1, enter these commands:
R1# show running-config | include route
R1# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
+ - replicated route, % - next hop override
Gateway of last resort is not set
10.0.0.0/8 is variably subnetted, 6 subnets, 3 masks
C 10.1.1.0/30 is directly connected, Serial1/1
L 10.1.1.2/32 is directly connected, Serial1/1
C 10.1.1.8/30 is directly connected, Serial1/2
L 10.1.1.10/32 is directly connected, Serial1/2
C 10.10.1.0/24 is directly connected, Ethernet0/0
L 10.10.1.1/32 is directly connected, Ethernet0/0
As you notice, the output from both “show” commands verifies that there are no static
routes left on R1.
Step 3
Configure a default route on R1 using 10.1.1.1 (Serial1/1 on R3) as the next-hop.
On R1, enter these commands:
R1# configure terminal
R1(config)# ip route 0.0.0.0 0.0.0.0 10.1.1.1
R1(config)# end
R1#
Step 4
Verify that this route is the only route in the running configuration and that there is a
default route in the routing table.
On R1, enter these commands:
R1# show running-config | include route
ip route 0.0.0.0 0.0.0.0 10.1.1.1
R1# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
+ - replicated route, % - next hop override
Gateway of last resort is 10.1.1.1 to network 0.0.0.0
S* 0.0.0.0/0 [1/0] via 10.1.1.1
10.0.0.0/8 is variably subnetted, 6 subnets, 3 masks
C 10.1.1.0/30 is directly connected, Serial1/1
L 10.1.1.2/32 is directly connected, Serial1/1
C 10.1.1.8/30 is directly connected, Serial1/2
L 10.1.1.10/32 is directly connected, Serial1/2
C 10.10.1.0/24 is directly connected, Ethernet0/0
L 10.10.1.1/32 is directly connected, Ethernet0/0
The output indicates that there is only one static default route in the routing table of R1
pointing to 10.1.1.1 (Serial1/1 on R3) as next-hop.
Step 5
Verify the connectivity between PC1 and other IPv4 addresses in the network by using
the ping command.
On PC1, enter these commands:
PC1# ping 10.10.3.30
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.3.30, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 10/10/10 ms
PC1# ping 10.10.2.20
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.2.20, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 12/13/15 ms
PC1# ping 10.1.1.9
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.1.1.9, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 8/9/10 ms
Replacing specific static routes in the configuration of R1 with a default route to R3,
does provide connectivity throughout the network, as long as there are no failed
interfaces.
Step 6
Examine the path from PC1 to PC2 using the traceroute command.
On PC1, enter this command:
PC1# traceroute 10.10.2.20
Type escape sequence to abort.
Tracing the route to 10.10.2.20
VRF info: (vrf in name/id, vrf out name/id)
1 10.10.1.1 1 msec 0 msec 1 msec
2 10.1.1.1 9 msec 5 msec 9 msec
3 10.1.1.6 13 msec 13 msec 13 msec
4 10.10.2.20 14 msec * 15 msec
R1 is the first hop in the path. R1 no longer has an explicit and efficient static route to
10.10.2.0/24 network, therefore it uses its default route and forwards this traffic to R3.
R3 has a static route to the 10.10.2.0/24 network via R2. Therefore, the path from PC1
to PC2 goes through R1, R3, and then R2.
Step 7
Examine the path from PC1 to 10.1.1.9 (Serial1/2 on R2) using
the traceroute command.
On PC1, enter this command:
PC1# traceroute 10.1.1.9
Type escape sequence to abort.
Tracing the route to 10.1.1.9
VRF info: (vrf in name/id, vrf out name/id)
1 10.10.1.1 0 msec 0 msec 0 msec
2 10.1.1.9 11 msec * 9 msec
R1 did not need to use its default route to reach 10.1.1.9. R1 has a directly connected
route to 10.1.1.8/30 network in its routing table. This specific route is preferred over the
default route and is used in this case.
Step 8
You have examined connectivity and the path from PC1 to PC2. Now, access the
console of PC2, and examine connectivity and the path from PC2 to PC1 using
the ping and traceroute commands.
On PC2, enter this command:
PC2# ping 10.10.1.10
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.10, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 12/13/14 ms
The explicit static routes to 10.10.1.0/24 network that are defined on R2 and R3 will
sustain connectivity to that subnet within the lab.
On PC2, enter this command:
PC2# traceroute 10.10.1.10
Type escape sequence to abort.
Tracing the route to 10.10.1.10
VRF info: (vrf in name/id, vrf out name/id)
1 10.10.2.1 1 msec 0 msec 0 msec
2 10.1.1.10 13 msec 14 msec 13 msec
3 10.10.1.10 15 msec * 13 msec
R2 is the first hop in this path, and R2 has an explicit and optimized static route to
10.10.1.0/24 network that uses R1 as the next hop. Therefore, the path from PC2 to
PC1 traverses R2 and then R1. In this case, R3 is not involved.
Contrast to this situation, the path that was previously displayed for PC1 to PC2. That
path required the default route on R1. The path traversed R1, R3, and then R2.
When the path from Host A to Host B is not simply the reverse of the path that is taken
from Host B to Host A, it is called asymmetric routing. Asymmetric routing is generally
an undesirable behavior.
At this point, you have experimented extensively with static routes. You have configured
typical static routes and redundant static routes and a default static route. In each case,
you have seen how to verify the status of the configuration and the routing table. You
have also examined the packet-forwarding behavior in each case, including scenarios
where there is an interface fault in place. Feel free to continue to independently explore
the configuration and function of static routes in the lab environment.
Configuring IPv6 Static Routes
Routing for IP version 6 (IPv6) is not enabled by default on Cisco routers. Therefore,
you need to enable IPv6 routing by using theipv6 unicast-routing command in global
configuration mode before you start configuring IPv6 static routes; the ipv6 unicastrouting command is required for forwarding and configuring routing protocol, but not
required to configure IPv6 addresses on interfaces.
There is an IPv6-specific requirement per RFC 2461 that a router must be able to
determine the link-local address of each of its neighboring routers to ensure that the
target address of a redirect message identifies the neighbor router by its link-local
address. This requirement means that using a global unicast address as a next-hop
address with IPv6 routing is not recommended.
Configuring a static route for IPv6 is almost the same as it is in IPv4. In IPv4, the nexthop IPv4 address or the exit interface can be specified in the static route configuration,
although using a next-hop is highly recommended, and using an exit interface alone
should be avoided. The same approach applies in IPv6, but the next-hop IPv6 address
in IPv6 can either be a link-local address or a global address; if a link-local address is
used then the exit interface must also be specified.
Static routes are used in IPv6 in the same situations as they are used in IPv4. They can
point to specific networks or hosts, or default static routes can be used for identifying a
"gateway of last resort". In addition, when redundancy to specific networks is required,
you can configure a backup route (floating static route) with higher administrative
distance than the primary route.
The proceeding example shows how to configure an IPv6 static route using different
methods (link-local or a global address):
Router# configure terminal
Router(config)# ipv6 unicast-routing
Router(config)# ipv6 route 2001:0db8:beef::/32 fa1/0 fe80::2
Router(config)# ipv6 route 2001:0db8:beef::/32 2001:0db8:feed::1
The first static route uses a link-local next hop address, specified with the fe80 prefix.
Whenever using a link-local address as the next hop you must also use an exit interface
because this link-local address could be used on any interface. The second static route
points to the next hop global IPv6 address 2001:0db8:feed::1.
In an IPv6 address the alphanumeric characters used in hexadecimal format are case
insensitive; therefore, uppercase and lowercase characters are equivalent. Although
Cisco IOS accepts both lowercase and uppercase representation of an IPv6 address, RFC
5952 recommends that IPv6 addresses be represented in lowercase, to ensure
compatibility with case-sensitive applications.
IPv6 Static Route Configuration Example
Consider the next example to understand IPv6 static route configuration.
In this example, an IPv6 static network route is configured on the HQ router, pointing to
the Branch router in order to reach the Branch router’s LAN. An IPv6 default route is
configured on the Branch router, pointing to the HQ router in order to reach all other
networks:
HQ(config)# ipv6 route 2001:db8:a01::/48 2001:db8:d1a5:c900::1
Branch(config)# ipv6 route ::/0 2001:db8:d1a5:c900::2
The table shows IPv6 static and default route commands:
Configuring an IPv6 Static Route
Command and Variable
Description
ipv6 route ipv6-network/ipv6mask[outgoing_interface] ipv6-nexthop
Configures an IPv6 static route. When the next hop is
a link-local address, the outgoing interface must be
specified.
ipv6 route ::/0 [outgoinginterface] ipv6-next-hop
Configures a default IPv6 route. When the next hop is
a link-local address, the outgoing interface must be
specified.
Verifying IPv6 Static Route Configuration
Use the show ipv6 route static command to verify only the IPv6 static route
configuration in the routing table.
Verify the static IPv6 route on the HQ router:
HQ# show ipv6 route static
IPv6 Routing Table - default - 4 entries
Codes: C - Connected, L - Local, S - Static, U - Per-user Static route
B - BGP, R - RIP, I1 - ISIS L1, I2 - ISIS L2
IA - ISIS interarea, IS - ISIS summary, D - EIGRP, EX - EIGRP external
ND - Neighbor Discovery, l - LISP
O - OSPF Intra, OI - OSPF Inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2
ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2
S 2001:db8:a01::/48 [1/0]
via 2001:db8:d1a5:c900::1
Verify the IPv6 static route on the Branch router:
Branch# show ipv6 route static
IPv6 Routing Table - default - 4 entries
Codes: C - Connected, L - Local, S - Static, U - Per-user Static route
B - BGP, R - RIP, I1 - ISIS L1, I2 - ISIS L2
IA - ISIS interarea, IS - ISIS summary, D - EIGRP, EX - EIGRP external
ND - Neighbor Discovery, l - LISP
O - OSPF Intra, OI - OSPF Inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2
ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2
S ::/0 [1/0]
via 2001:db8:d1a5:c900::2
Alternatively, you can verify the static IPv6 route using the show ipv6 static command.
For example, here is the static route on the HQ router:
HQ# show ipv6 static
IPv6 Static routes Table - default
Codes: * - installed in RIB, u/m - Unicast/Multicast only
U - Per-user Static route
N - ND Static route
M - MIP Static route
P - DHCP-PD Static route
R - RHI Static route
* 2001:db8:a01::/48 via 2001:db8:d1a5:c900::1, distance 1
The table shows IPv6 static route verification commands:
IPv6 Static Route Verification
Command and Variable
Description
show ipv6 static [ipv6-address | ipv6prefix/prefix-length][interface interface-type
interface-number] [recursive] [detail]
or
show ipv6 route static
Displays the current contents of the IPv6
routing table. These examples show two
different ways of displaying IPv6 static routes.
You can also verify that the default IPv6 route on the Branch router is working by
issuing the ping command to the server:
Branch# ping 2001:db8:ac10:100::64
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:AC10:100::64, timeout is 2
seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 0/0/0 ms
Discovery 13: Configure IPv6 Static Routes
Introduction
In this activity, you will configure IPv6 static routing between R1 and R3 and verify
connectivity between end devices in the network. Router R2 has static IPv6 routes preconfigured. Study the topology diagram and address table to understand the network
connectivity and addressing. All systems are currently configured with IPv4 addresses
and IPv6 addresses. You will define a default route and a floating route on the R1
router.
Topology
Job Aids
Device Information
In the virtual lab environment, personal computers (PCs) and the server (SRV) are
simulated as routers, so you should use Cisco IOS commands to configure them or make
verifications.
Device Information Table
Device
Characteristic
Value
PC1
IPv6 address
2001:db8:0:1::100/64
PC2
IPv6 address
2001:db8:0:2::100/64
SRV1
IPv6 address
2001:db8:0:3::100/64
R1
Ethernet0/0 IPv6 address
2001:db8:0:1::1/64
R1
Serial1/1 IPv6 address
2001:db8:0:4::1/64
R1
Serial1/2 IPv6 address
2001:db8:0:5::1/64
R2
Ethernet0/0 IPv6 address
2001:db8:0:2::1/64
R2
Serial1/2 IPv6 address
2001:db8:0:5::2/64
R2
Serial1/3 IPv6 address
2001:db8:0:6::1/64
Device
Characteristic
Value
R3
Ethernet0/0 IPv6 address
2001:db8:0:3::1/64
R3
Serial1/1 IPv6 address
2001:db8:0:4::2/64
R3
Serial1/3 IPv6 address
2001:db8:0:6::2/64
Task 1: Configure IPv6 Static Routes
Activity
Step 1
SRV1 is configured for remote access using Telnet. However, user at PC1 cannot
establish the Telnet connection. From PC1, try accessing the SRV1 server using Telnet.
On PC1, enter these commands:
PC1# telnet 2001:db8:0:3::100
Trying 2001:db8:0:3::100 ...
% Connection timed out; remote host not responding
The Telnet connection to SRV1 cannot be established, because the remote host is not
responding.
Step 2
Telnet connectivity test failed. Check IPv6 connectivity from PC1 to SRV1 and PC2.
Both checks should fail.
On PC1, enter these commands:
PC1# ping 2001:db8:0:3::100
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:3::100, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
PC1# ping 2001:db8:0:2::100
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:2::100, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
Both pings are failing. In the lab network there is no full IPv6 connectivity.
Step 3
The IPv6 connectivity checks fail because routers R1 and R3 do not have routing preconfigured. Examine the IPv6 routing table on each router to explore the IPv6 routing
information that the routers have in their routing table.
On R1, enter the following command:
R1# show ipv6 route
IPv6 Routing Table - default - 7 entries
<--- output omitted --->
C 2001:DB8:0:1::/64 [0/0]
via Ethernet0/0, directly connected
L 2001:DB8:0:1::1/128 [0/0]
via Ethernet0/0, receive
C 2001:DB8:0:4::/64 [0/0]
via Serial1/1, directly connected
L 2001:DB8:0:4::1/128 [0/0]
via Serial1/1, receive
C 2001:DB8:0:5::/64 [0/0]
via Serial1/2, directly connected
L 2001:DB8:0:5::1/128 [0/0]
via Serial1/2, receive
L FF00::/8 [0/0]
via Null0, receive
The output shows, that R1 has information about directly-connected networks only.
Router R1 does not have information about neither SRV1 LAN (2001:db8:0:3::/64) nor
PC2 LAN (2001:db8:0:2::/64).
The sources of the routing table entries are identified by a code at the beginning of the
entry, which indicates how the route was learned. The 2001:db8:0:1::/64 network is
identified with a "C" code, which identifies the directly connected network on the
Ethernet0/0 interface. The 2001:db8:0:1::1/128 IPv6 address is identified with a "L"
code, which identifies the address assigned to Ethernet0/0 interface, belonging the
2001:db8:0:1::/64 network. These entries are added to the routing table automatically,
when router interface is configured, enabled and active.
On R2, enter the following command:
R2# show ipv6 route
IPv6 Routing Table - default - 9 entries
<--- output omitted --->
S ::/0 [1/0]
via 2001:DB8:0:6::2
S 2001:DB8:0:1::/64 [1/0]
via 2001:DB8:0:5::1
C 2001:DB8:0:2::/64 [0/0]
via Ethernet0/0, directly connected
L 2001:DB8:0:2::1/128 [0/0]
via Ethernet0/0, receive
C 2001:DB8:0:5::/64 [0/0]
via Serial1/2, directly connected
L 2001:DB8:0:5::2/128 [0/0]
via Serial1/2, receive
C 2001:DB8:0:6::/64 [0/0]
via Serial1/3, directly connected
L 2001:DB8:0:6::1/128 [0/0]
via Serial1/3, receive
L FF00::/8 [0/0]
via Null0, receive
The output shows that, besides information about directly-connected networks, R2 has
two static entries. The first static entry is an IPv6 default route, indicated by ::/0. The
default route points to the R3 router as the next hop (2001:db8:0:6::2). The second
static entry is for PC1 LAN (2001:db8:0:1::/64), which is available via R1 router (nexthop IPv6 2001:db8:0:5::1.)
On R3, enter the following command:
R3# show ipv6 route
IPv6 Routing Table - default - 7 entries
<--- output omitted --->
C 2001:DB8:0:3::/64 [0/0]
via Ethernet0/0, directly connected
L 2001:DB8:0:3::1/128 [0/0]
via Ethernet0/0, receive
C 2001:DB8:0:4::/64 [0/0]
via Serial1/1, directly connected
L 2001:DB8:0:4::2/128 [0/0]
via Serial1/1, receive
C 2001:DB8:0:6::/64 [0/0]
via Serial1/3, directly connected
L 2001:DB8:0:6::2/128 [0/0]
via Serial1/3, receive
L FF00::/8 [0/0]
via Null0, receive
Based on the output, you see that R3 router knows of its directly-connected networks
only. It has no information about PC1 and PC2 LANs (2001:db8:0:1::/64 and
2001:db8:0:2::/64).
The routing tables content reveals that routing information must be added to R1 and R3
routers. On R1, you need add two static routes, a default IPv6 route and a static IPv6
route to PC2 LAN, which will take care of routing packets from PC1 towards the SRV1
server. To provide the path for the response packets, from SRV1 to PC1, on R3 you
need to add a static IPv6 route towards PC1 LAN. To provide full connectivity, you also
need to add a static IPv6 route to PC2 LAN.
You must ensure that the IPv6 routing function is enabled on the router. Otherwise, you
would be able to type in the IPv6 routes, but the router will not perform IPv6 routing. By
default, IPv6 routing is not enabled. You must enable IPv6 routing on both R1 and R3.
Step 4
Enable IPv6 routing on R1 and R3 using the ipv6 unicast-routing command.
On R1, enter the following commands:
R1# configure terminal
R1(config)# ipv6 unicast-routing
R1(config)#
On R3, enter the following commands:
R3# configure terminal
R3(config)# ipv6 unicast-routing
R3(config)#
Step 5
Add a default IPv6 route on R1, specifying R3 router as the next-hop.
On R1, enter the following command:
R1(config)# ipv6 route ::/0 2001:db8:0:4::2
The default IPv6 route is denoted ::/0. Its IPv4 equivalent is 0.0.0.0/0 quad zero network
id. The next hop IPv6 address is the address of the R3 Serial 1/1 interface.
Step 6
On R1 router, add a static IPv6 route to 2001:db8:0:2::/64 network.
On R1, enter the following command:
R1(config)# ipv6 route 2001:db8:0:2::/64 2001:db8:0:5::2
The next-hop IPv6 address belong to Serial 1/2 interface of R2.
Step 7
Without leaving the Global Configuration mode, verify that both routes are added to R1
IPv6 routing table. Use the do keyword in front of the show command.
On R1, enter the following command:
R1(config)# do show ipv6 route
IPv6 Routing Table - default - 9 entries
<--- output omitted --->
S ::/0 [1/0]
via 2001:DB8:0:4::2
C 2001:DB8:0:1::/64 [0/0]
via Ethernet0/0, directly connected
L 2001:DB8:0:1::1/128 [0/0]
via Ethernet0/0, receive
S 2001:DB8:0:2::/64 [1/0]
via 2001:DB8:0:5::2
C 2001:DB8:0:4::/64 [0/0]
via Serial1/1, directly connected
L 2001:DB8:0:4::1/128 [0/0]
via Serial1/1, receive
C 2001:DB8:0:5::/64 [0/0]
via Serial1/2, directly connected
L 2001:DB8:0:5::1/128 [0/0]
via Serial1/2, receive
L FF00::/8 [0/0]
via Null0, receive
Both routes that you entered are included in the IPv6 routing table. Because of the
longest-prefix matching used in routing, packets destined to PC2 LAN will be forwarded
via R2 router. Packets destined to other networks will be routed according to the default
route entry, via R3 router.
Note that the routes in IPv6 routing table are sorted from the lowest to the highest
number. The same is true of IPv4 routing table.
Step 8
Since R2 router is pre-configured, adding a static route to PC2 LAN on R1 now ensures
the connectivity in both directions. From PC1, verify the connectivity between PC1 and
PC2.
On PC1, enter this command:
PC1# ping 2001:db8:0:2::100
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:3::100, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 8/15/43 ms
Step 9
Configuring routes on R1 ensured connectivity in one direction, from PC1 to SRV1. To
ensure connectivity in both directions for all devices, on R3, add static routes to PC1
LAN and PC2 LAN.
On R3, enter the following command:
R3(config)# ipv6 route 2001:db8:0:1::/64 2001:db8:0:4::1
R3(config)# ipv6 route 2001:db8:0:2::/64 2001:db8:0:6::1
Step 10
Without leaving the Global Configuration mode, verify that both IPv6 static routes are
added to R3 IPv6 routing table. Use the dokeyword in front of the show command.
On R3, enter the following command:
R3(config)# do show ipv6 route static
IPv6 Routing Table - default - 9 entries
Codes: C - Connected, L - Local, S - Static, U - Per-user Static route
B - BGP, HA - Home Agent, MR - Mobile Router, R - RIP
H - NHRP, I1 - ISIS L1, I2 - ISIS L2, IA - ISIS interarea
IS - ISIS summary, D - EIGRP, EX - EIGRP external, NM - NEMO
ND - ND Default, NDp - ND Prefix, DCE - Destination, NDr - Redirect
O - OSPF Intra, OI - OSPF Inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2
ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2, l - LISP
S 2001:DB8:0:1::/64 [1/0]
via 2001:DB8:0:4::1
S 2001:DB8:0:2::/64 [1/0]
via 2001:DB8:0:6::1
Both routes that you entered are included in the IPv6 routing table. You can also see
the default administrative distance of the static route, which is 1.
Step 11
Verify IPv6 connectivity between PC1 and SRV1, by
using ping and traceroute commands.
On PC1, enter the following command:
PC1# ping 2001:db8:0:3::100
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:3::100, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 8/15/43 ms
PC1# traceroute 2001:db8:0:3::100
Type escape sequence to abort.
Tracing the route to 2001:DB8:0:3::100
1 2001:DB8:0:1::1 0 msec 1 msec 0 msec
2 2001:DB8:0:4::2 9 msec 9 msec 8 msec
3 2001:DB8:0:3::100 9 msec 9 msec 9 msec
The successful ping test verifies that there is connectivity between PC1 and SRV1.
The traceroute command confirms the connectivity and adds information about the
path that IPv6 packets are taking from PC1 to SRV1. Based on the IPv6 addresses
shown in the output, you can see that the packets follow the PC1 > R1 > R3 > SRV1
path.
Step 12
The network topology shows that there is an alternative path to SRV1: PC1 > R1 > R2 >
R3 > SRV1. It can serve as a backup-path in case of the link failure between R1 and
R3. To ensure this backup path is immediately available, configure a floating static
default route to SRV1 network via R2. Use administrative distance 200. Exit to the
Privileged EXEC mode.
On R1, enter the following commands:
R1(config)# ipv6 route ::/0 2001:db8:0:5::2 200
R1(config)# end
By explicitly specifying the administrative distance, you are changing the default
"thrustworthiness" of the static route. Setting the administrative distance to 200 makes it
unlikely that this route will be installed in the routing table. The maximum value you can
set is 254. This is why the route is called floating. It's administrative distance floats high
above other administrative distance values, making it difficult for the route to "land" in
the routing table. The route will get installed only when all sources with lesser
administrative distance become unavailable.
Step 13
Verify that the floating route is not in the IPv6 routing table.
On R1, enter the following command:
R1# show ipv6 route static
IPv6 Routing Table - default - 9 entries
<--- output omitted --->
S ::/0 [1/0]
via 2001:DB8:0:4::2
S 2001:DB8:0:2::/64 [1/0]
via 2001:DB8:0:5::2
The IPv6 default route is the same one you configured at the beginning of the lab, using
R3 as the next hop.
Step 14
To ensure bidirectional connectivity in cases of R1-R3 link failure, you have to add a
floating route on R3 router also. The current IPv6 static route to PC1 LAN
(2001:db8:0:1::/64) uses R1 router as the next hop. In case of the link failure, the route
is going to be removed from the routing table. Configure an alternative floating IPv6
static route to PC1 LAN, using R2 as the next hop. Use administrative distance of 200.
On R3, enter the following command:
R3(config)# ipv6 route 2001:db8:0:1::/64 2001:db8:0:6::1 200
Step 15
To make sure that the floating route will be installed in the IPv6 routing table, simulate a
R1-R3 link failure by manually disabling the Serial 1/1 interface on R1.
On R1, enter the following command:
R1# configure terminal
R1(config)# interface Serial 1/1
R1(config-if)# shutdown
R1(config-if)#
*May 30 19:31:33.124: %LINK-5-CHANGED: Interface Serial1/1, changed state to
administratively down
*May 30 19:31:34.129: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Serial1/1, changed state to down
R1(config-if)#
Step 16
Wait until you see the message on R3 that the link has gone down. Examine the routing
tables on R1 and R3, and verify that the floating IPv6 routes are installed.
On R1, enter the following command:
R1(config-if)# do show ipv6 route static
IPv6 Routing Table - default - 7 entries
<--- output omitted --->
S ::/0 [200/0]
via 2001:DB8:0:5::2
S 2001:DB8:0:2::/64 [1/0]
via 2001:DB8:0:5::2
R3(config)# do show ipv6 route static
IPv6 Routing Table - default - 7 entries
<--- output omitted --->
S 2001:DB8:0:1::/64 [200/0]
via 2001:DB8:0:6::1
S 2001:DB8:0:2::/64 [1/0]
via 2001:DB8:0:6::1
The output shows backup IPv6 default route installed in the routing table on R1 and the
backup static IPv6 route to 2001:db8:0:1::/64 network installed on R3. Both entries are
showing the floating route administrative distance that you set to 200. Note that you had
to add floating static entries on all routers that would be affected by the change in the
network. The lab network is small, and the related configuration work is not excessive.
But in a larger network, 'dynamic' responsiveness to network conditions is hard to
achieve using static routes. Dynamic routing protocols are better choice in larger
networks.
Step 17
Verify that there is connectivity between PC1 and SRV1, by using Telnet to connect to
SRV1. Authenticate with username admin and password Cisco123. Once the Telnet
connection establishes, use the exit command to terminate the connection.
On PC1, enter the following command:
PC1# telnet 2001:db8:0:3::100
Trying 2001:db8:0:3::100 ... Open
User Access Verification
Username: admin
Password: Cisco123
SRV1> exit
[Connection to 2001:DB8:0:3::100 closed by foreign host]
PC1#
Successful telnet connection indicates that there is IPv6 connectivity from PC1 to SRV1.
Step 18
Verify that the path packets are taking form PC1 to SRV1.
On PC1, enter the following command:
PC1# traceroute 2001:db8:0:3::100
Type escape sequence to abort.
Tracing the route to 2001:DB8:0:3::100
1 2001:DB8:0:1::1 0 msec 1 msec 0 msec
2 2001:DB8:0:5::2 9 msec 9 msec 8 msec
3 2001:DB8:0:6::2 9 msec 9 msec 9 msec
4 2001:DB8:0:3::100 9 msec 9 msec 9 msec
Packets are now taking the PC1 > R1 > R2 > R3 > SRV1 path.
Step 19
Enable the Serial 1/1 interface on R1 to conclude the lab.
On R1, enter the following command:
R1(config-if)# no shutdown
R1(config-if)#
*May 30 19:37:07.028: %LINK-3-UPDOWN: Interface Serial1/1, changed state to
up
*May 30 19:37:08.033: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Serial1/1, changed state to up
Implement IPv4 Static Routing
FASTLab 3: Implement IPv4 Static Routing
Introduction
Read the requirements in the Scenario carefully and use the Configuration Tips to help
you do the required steps. If you need further assistance, refer to the Answer Key. Once
you have completed the configuration specified, answer the questions.
The customer informed the CCS company that the Internet Service Provider has
provided the internet connection. You are asked to complete the implementation of the
internet connection on the Branch router. The Ethernet 0/1 interface on the Branch
router will be used for connecting the customer network to the Internet Service Provider.
On the other hand, the customer has not yet decided the routing protocol that needs to
be implemented for the network. Therefore, you must implement static routing as an
interim solution.
Besides the implementation of internet connection, the customer is also adding a new
router as part of a future expansion project. The new router is designated as "R1" and is
connected to the Branch router. The new router will be connected to a switch and a
server, but these components are still under the procurement process and are not
delivered yet.
The contract for this implementation requires from you to complete the following tasks:
•
•
•
•
•
•
•
Configure the new router with a hostname “R1”.
Configure interface Ethernet0/0 on R1 with correct IPv4 address. Also, enable the
interface.
Configure Loopback0 interface on R1 with correct IPv4 address.
Configure interface Ethernet0/2 on Branch router with correct IPv4 address. Ensure that
you can ping the Ethernet0/0 interface on router R1.
Enable interface Ethernet0/1 on the Branch router and configure it with IPv4 address
209.165.200.226/27, which is provided by the ISP.
Apply a default route on R1, which sends the traffic to the Branch router. Verify the
validity of the default route by pinging the addresses of AdminPC, and the Fileserver,
from the R1 router.
Configure the default route on Branch router with a next- hop address (gateway) of
209.165.200.225. Ensure that you can ping the 209.165.201.1 internet test IPv4
address.
You must be able to ping from the Branch router to all other IPv4 addresses that are
configured in the network and the internet test address (209.165.201.1). You should get
successful ping responses from the Branch router to the internet, because the Branch
router uses a public IPv4 address (209.165.200.226).
The router R1 may take 2 to 5 minutes to boot before you can access it. If the router
comes up with the initial system configuration dialog prompt, type no to skip it.
Topology
Job Aid
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today.
Device Information
Device
Interface
IPv4 Address
Remote
Interface
IPv4 Address
Branch
E0/0
172.16.130.3/24
SW1
E0/1
VLAN 1
Branch
E0/1
209.165.200.226/27
Internet
E0/0
209.165.200.225/27
Branch
E0/2
172.16.160.3/24
R1
E0/0
172.16.160.1/24
Branch
Lo 0
172.16.2.2/32
—
—
—
R1
E0/0
172.16.160.1/24
Branch
E0/2
172.16.160.3/24
R1
Lo 0
172.16.1.1/32
—
—
—
AdminPC
E0/0
172.16.130.5/24
SW1
E0/2
—
Fileserver
E0/0
172.16.130.6/24
SW1
E0/3
—
Device
Interface
IPv4 Address
Remote
Interface
IPv4 Address
Internet
Lo 0
209.165.201.1/32
—
—
—
Internet
E0/0
209.165.200.225/27
Branch
E0/1
209.165.200.226/27
Configuration Tips
The router R1 may take 2 to 5 minutes to boot before you can access it. If the router
comes up with the initial system configuration dialog prompt, type no to skip it.
•
•
•
•
•
•
Configure a hostname on the R1 router, by using the hostname global configuration
command.
Network interfaces need to be administratively enabled from "shutdown" using the no
shutdown command. Loopback interfaces are enabled by default.
Configure the correct IPv4 address on the interfaces, by using the ip
address interface configuration command.
Apply a default route on the R1 router, specifying the Branch router as the default
gateway. To apply a default route, use the ip route 0.0.0.0 0.0.0.0 ip address of next
hop neighbor command. Verify the validity of the default route by using
the ping command from the R1 router to the AdminPC and Fileserver.
Apply a default route on the Branch router with the specified next hop address using the
command listed above. Perform the verification by pinging the internet test IPv4
address.
If the next hop in an ip route command is not available, the route will not appear in the
routing table.
Answer Key
You need to complete the following tasks:
•
•
Configure the new router with a hostname “R1”.
Enter global configuration mode, and use the following command to configure a
hostname as "R1" on the R1 router.
Router(config)# hostname R1
R1(config)#
•
•
Configure interface Ethernet0/0 on R1 with correct IPv4 address. Also, enable the
interface.
Begin the interface E0/0 configuration on R1 by issuing the no shutdown command to
enable it.
R1(config)# interface e0/0
R1(config-if)# no shutdown
•
Use the following command to assign the IPv4 address 172.16.160.1/24 along with the
subnet mask.
R1(config-if)# ip address 172.16.160.1 255.255.255.0
•
•
Configure Loopback0 interface on R1 with correct IPv4 address.
Use the following commands to assign the IPv4 address 172.16.1.1/32 along with the
subnet mask to Loopback 0 on R1:
R1(config)# interface loopback 0
R1(config-if)# ip address 172.16.1.1 255.255.255.255
•
•
Configure interface Ethernet0/2 on Branch router with correct IPv4 address. Ensure that
you can ping the Ethernet0/0 interface on router R1.
Issue the no shutdown command on interface E0/2 on the Branch router to enable it.
Branch(config)# interface e0/2
Branch(config-if)# no shutdown
•
Use the following commands to assign the IPv4 address 172.16.160.3/24 along with the
subnet mask to interface E0/2.
Branch(config-if)# ip address 172.16.160.3 255.255.255.0
•
Use the following command on the Branch router
Branch(config-if)# do ping 172.16.160.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.160.1, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
Branch(config-if)#
•
•
Enable interface Ethernet0/1 on the Branch router and configure it with IPv4 address
209.165.200.226/27, which is provided by the ISP.
Issue the no shutdown command on interface E0/1 on the Branch router to enable it.
Branch(config)# interface e0/1
Branch(config-if)# no shutdown
•
Use the following command to assign the IPv4 address 209.165.200.226/27 to the
interface.
Branch(config-if)# ip address 209.165.200.226 255.255.255.224
•
•
Apply a default route on the R1 router, specifying the Branch router as the default
gateway. Verify the validity of the default route by pinging the addresses of AdminPC,
and the Fileserver, from the R1 router.
Use the following command on R1:
R1(config)# ip route 0.0.0.0 0.0.0.0 172.16.160.3
•
Check connectivity from R1 to the AdminPC:
R1# ping 172.16.130.5
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.130.5, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
•
Check connectivity from R1 to the FileServer
R1# ping 172.16.130.6
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.130.6, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
•
•
Configure the default route on Branch router with a next-hop address (gateway) of
209.165.200.225. Ensure that you can ping the 209.165.201.1 internet test IPv4
address from the Branch router.
Use the following command on Branch:
Branch(config)# ip route 0.0.0.0 0.0.0.0 209.165.200.225
•
Verify the default route on the Branch router by checking that the Branch router can
ping the Internet test IPv4 address.
Branch# ping 209.165.201.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 209.165.201.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
If the command output does not show the desired result, it indicates that the default
route that is configured on the Branch router is not correct.
Implement IPv6 Static Routing
FASTLab 4: Implement IPv6 Static Routing
Scenario
Read the requirements in the Scenario carefully and use the Configuration Tips to help
you do the required steps. If you need further assistance, refer to the Answer Key. Once
you have completed the configuration specified, answer the questions.
You are piloting the IPv6 implementation. The ISP has provided you with the following
IPv6 addresses for testing; you need to ensure that these addresses are reachable from
your network:
•
•
•
2001:db8:0:1a::1/64
2001:db8:0:1b::1/64
2001:db8:0:1c::1/64
You need to complete these tasks to enable IPv6 routing in the network:
•
•
•
Configure a default route on R1, using the IPv6 global address to establish connectivity
with the Internet router. Do not use the autoconfiguration method on R1.
Configure R4 to receive an IPv6 address and a default route from R1 using stateless
autoconfiguration method.
Configure a default route on R3 that points to R1. In default route configuration, include
an exit interface and use a link-local address for the next-hop address.
•
IPv6 configurations are already configured on the other devices. However, you need to
investigate any incomplete configurations or misconfigurations. Also, ensure that the
connectivity from all devices exists to the test IPv6 addresses that are provided by the
ISP.
The Router R1 may take 2 to 3 minutes to boot up and become accessible.
Topology
Job Aid
If you shut down an interface on a real router or switch, the connected device will see it
as "down/down." Because of virtualization specifics, Cisco IOL (Cisco IOS Software on
Linux) behavior is slightly different. If you shut down an interface on a router or switch,
the connected device will see it as "up/up." In Cisco IOL, the status of an interface can
only be "up/up" or "administratively down/down." Also, in the virtual lab environment,
all interfaces are Ethernet interfaces and not FastEthernet or GigabitEthernet interfaces,
which you are likely to encounter in networks today.
Device Information
Device
Interface
IPv6 Address
Remote
Interface
IPv6 Address
R1
Ethernet0/0
2001:db8:0:4::1/64
SW1
Ethernet0/0
VLAN 1
R1
Ethernet0/1
2001:db8:0:6::2/64
Internet
Ethernet0/0
2001:db8:0:6::1/64
R1
Ethernet0/2
2001:db8:0:3::1/64
R4
Ethernet0/0
Autoconfig
Device
Interface
IPv6 Address
Remote
Interface
IPv6 Address
R2
Ethernet0/0
2001:db8:0:4::2/64
SW1
Ethernet0/1
VLAN 1
R2
Ethernet0/1
2001:db8:0:5::1/64
PC1
Ethernet0/0
Autoconfig
R3
Ethernet0/0
2001:db8:0:4::3/64
SW1
Ethernet0/2
VLAN 1
Internet
Loopback 1
2001:db8:0:1a::1/64
—
—
—
Internet
Loopback 2
2001:db8:0:1b::1/64
—
—
—
Internet
Loopback 3
2001:db8:0:1c::1/64
—
—
—
Configuration Tips
The Router R1 may take 2 to 3 minutes to boot up and become accessible.
•
•
•
•
•
Configure a default route on R1 that points to the Internet router. In the default route
configuration command ipv6 route ipv6 address, use a global IPv6 address for the
next-hop address.
Configure R4 to receive an IPv6 address and a default route from R1 through the
stateless autoconfiguration method. Use the ipv6 address autoconfig
default command to receive the IPv6 address and default route from the IPv6-enabled
neighbor router. Remember that you need to enter the interface configuration mode to
perform this command. Verify that connectivity exists to the ISP-provided IPv6
addresses using the ping command.
Configure a default route on R3 that points to R1. In the default route configuration
command, include an exit interface and use a link-local address for the next-hop
address. You can use the show ipv6 interface brief command on R1 to identify the
link-local address of the next-hop interface.
Use the ipv6 route ::/0 <exit interface> <IPv6 next hop address> command with the
correct exit interface and next-hop global IPv6 address to configure the default route.
Using the show running-config and show ipv6 route commands, check the static
route configuration on R2 and the static route configuration on R1 for traffic from the
Internet router to PC1. Check if the correct next-hop IPv6 address are configured.
Observe that the static routes that are configured on R1 and R2 have an incorrect IPv6
global address configured for the next-hop address; fix these issues.
Answer Key
You need to complete the following tasks:
•
Configure a default route on R1, using the IPv6 global address to establish connectivity
with the Internet router. Do not use the autoconfiguration method on R1.
•
Use the following command to accomplish this task:
R1(config)# ipv6 route ::/0 2001:db8:0:6::1
•
•
Configure R4 to receive an IPv6 address and a default route from R1 through the
stateless autoconfiguration method.
Use the following command to accomplish this task:
R4(config)# interface e0/0
R4(config-if)# ipv6 address autoconfig default
•
•
Configure a default route on R3 that points to R1. In default route configuration, include
an exit interface and use a link-local address for the next-hop address.
Use the show ipv6 interface brief command on R1 to identify the link-local address of
the next-hop interface:
R1# show ipv6 int brief
Ethernet0/0 [up/up]
FE80::A8BB:CCFF:FE00:100
2001:DB8:0:4::1
Ethernet0/1 [up/up]
FE80::A8BB:CCFF:FE00:110
2001:DB8:0:6::2
Ethernet0/2 [up/up]
FE80::A8BB:CCFF:FE00:120
2001:DB8:0:3::1
Ethernet0/3 [administratively down/down]
unassigned
NVI0 [up/up]
unassigned
•
Use the following command to configure a default route on R3:
R3(config)# ipv6 route ::/0 e0/0 FE80::A8BB:CCFF:FE00:100
•
•
IPv6 configurations are already configured on the other devices. However, you need to
investigate any incomplete configurations or misconfigurations. Also, ensure that the
connectivity from all devices exists to the test IPv6 addresses that are provided by the
ISP.
Examine the configuration on R2. Observe that the static route that is configured on R2
has an incorrect IPv6 global address configured for the next-hop address.
R2# show running-config | include ipv6 route
ipv6 route 2001:DB8:0:1A::/64 2001:DB8:0:4::3
ipv6 route 2001:DB8:0:1B::/64 2001:DB8:0:4::3
ipv6 route 2001:DB8:0:1C::/64 2001:DB8:0:4::3
!
The output of the show run command shows that the static route next-hop IPv6 global
address is pointing to R3 instead of the next-hop global IPv6 address of R1.
•
Use the following configuration commands to fix the static route configuration on R2:
R2(config)# no ipv6 route 2001:DB8:0:1A::/64 2001:DB8:0:4::3
R2(config)# no ipv6 route 2001:DB8:0:1B::/64 2001:DB8:0:4::3
R2(config)# no ipv6 route 2001:DB8:0:1C::/64 2001:DB8:0:4::3
R2(config)# ipv6 route 2001:DB8:0:1A::/64 2001:DB8:0:4::1
R2(config)# ipv6 route 2001:DB8:0:1B::/64 2001:DB8:0:4::1
R2(config)# ipv6 route 2001:DB8:0:1C::/64 2001:DB8:0:4::1
•
Examine the configuration on R1. Observe that the static route that is configured on R1
for the reverse traffic flow to IPv6 address 2001:DB8:0:5::/64 from the ISP-provided
IPv6 address has an incorrect IPv6 global address configured for the next-hop address.
R1# show running-config | include ipv6 route
ipv6 route 2001:DB8:0:5::/64 2001:DB8:0:6::1
ipv6 route ::/0 2001:DB8:0:6::1
•
The static route has the next-hop IPv6 global address is pointing to the Internet router
instead of the next-hop IPv6 global address of R2. Use the following configuration
commands to fix the static route configuration on R1.
R1(config)# no ipv6 route 2001:DB8:0:5::/64 2001:DB8:0:6::1
R1(config)# ipv6 route 2001:DB8:0:5::/64 2001:DB8:0:4::2
•
Use the show ipv6 route static and show running-config commands to verify that the
static route configurations are correct. Ping from PC1 to the ISP-provided IPv6
addresses such as 2001:db8:0:1a::1, 2001:db8:0:1b::1, and 2001:db8:0:1c::1 to verify
connectivity.
R2# show running-config
Building configuration...
Current configuration : 1201 bytes
<output omitted>
!
ipv6 route 2001:DB8:0:1A::/64 2001:DB8:0:4::1
ipv6 route 2001:DB8:0:1B::/64 2001:DB8:0:4::1
ipv6 route 2001:DB8:0:1C::/64 2001:DB8:0:4::1
!
!
R2# show ipv6 route static
IPv6 Routing Table - default - 8 entries
Codes: C - Connected, L - Local, S - Static, U - Per-user Static route
B - BGP, HA - Home Agent, MR - Mobile Router, R - RIP
H - NHRP, I1 - ISIS L1, I2 - ISIS L2, IA - ISIS interarea
IS - ISIS summary, D - EIGRP, EX - EIGRP external, NM - NEMO
ND - ND Default, NDp - ND Prefix, DCE - Destination, NDr - Redirect
O - OSPF Intra, OI - OSPF Inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2
ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2, l - LISP
S 2001:DB8:0:1A::/64 [1/0]
via 2001:DB8:0:4::1
S 2001:DB8:0:1B::/64 [1/0]
via 2001:DB8:0:4::1
S 2001:DB8:0:1C::/64 [1/0]
via 2001:DB8:0:4::1
R2#
R1# show run | incl ipv6 route
ipv6 route 2001:DB8:0:5::/64 2001:DB8:0:4::2
ipv6 route ::/0 2001:DB8:0:6::1
R1# show ipv6 route static
IPv6 Routing Table - default - 9 entries
Codes: C - Connected, L - Local, S - Static, U - Per-user Static route
B - BGP, HA - Home Agent, MR - Mobile Router, R - RIP
H - NHRP, I1 - ISIS L1, I2 - ISIS L2, IA - ISIS interarea
IS - ISIS summary, D - EIGRP, EX - EIGRP external, NM - NEMO
ND - ND Default, NDp - ND Prefix, DCE - Destination, NDr - Redirect
O - OSPF Intra, OI - OSPF Inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2
ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2, l - LISP
S ::/0 [1/0]
via 2001:DB8:0:6::1
S 2001:DB8:0:5::/64 [1/0]
via 2001:DB8:0:4::2
PC1# ping 2001:db8:0:1a::1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:1A::1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 4/7/19 ms
PC1# ping 2001:db8:0:1b::1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:1B::1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
PC1# ping 2001:db8:0:1c::1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:0:1C::1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
PC1#
Implementing VLANs and Trunks
Introduction
If an Enterprise Campus network is poorly designed where it has a large number of
devices in the same Local Area Network (LAN) segment, the poor design will typically
affect performance of the network because of a large broadcast and failure domain,
limited security control, and so on. A router could be used to solve the issue, because it
blocks broadcasts, but routers are typically slower, expensive, and often do not fit the
design of an Enterprise Campus network.
A commonly used solution is usage of virtual local area networks (VLANs), which
segment a network on per ports basis and can span over multiple switches. This allows
you to logically segment a switched network on an organizational basis, by functions,
project teams, or applications rather than on a physical or geographical basis. For
example, all workstations and servers used by a particular workgroup team can be
connected to the same VLAN, regardless of their physical connections to the network or
the fact that they might be intermingled with other teams. Reconfiguration of the network
can be done through software rather than by physically unplugging and moving devices
or wires.
In Enterprise environments, switches often use links that carry data from multiple
VLANs and allow VLANs to be extended across an entire network. These links are
called trunks.
Cisco Enterprise Architecture Model
As a networking engineer, you need to gain skills in the area of VLANs, such as:
•
•
•
Identifying the common issues in a poorly designed local network.
Familiarizing yourself with the operation of VLANs.
Implementing correct steps to implement and verify VLANs and trunks.
•
VLAN Introduction
•
To understand VLANs, you need a solid understanding of LANs. A LAN is a
group of devices that share a common broadcast domain. When a device on the
LAN sends broadcast messages, the switch floods the broadcast messages (as
well as unknown unicast) to all ports except the incoming port. Hence, all other
devices on the LAN receive them. You can think of a LAN and a broadcast
domain as being basically the same thing. Without VLANs, a switch considers all
its interfaces to be in the same broadcast domain. In other words, all connected
devices are in the same LAN. With VLANs, a switch can put some interfaces into
one broadcast domain and some into another. The individual broadcast domains
that are created by the switch are called VLANs. A VLAN is a group of devices
on one or more LANs that are configured to communicate as if they were
attached to the same wire, when in fact they are located on a number of different
LAN segments.
•
•
A VLAN allows a network administrator to create logical groups of network
devices. These devices act like they are in their own independent network, even
if they share a common infrastructure with other VLANs. Each VLAN is a
separate Layer 2 broadcast domain, which is usually mapped to a unique
Internet Protocol (IP) subnet (Layer 3 broadcast domain). A VLAN can exist on a
single switch or span multiple switches. VLANs can include devices in a single
building or multiple-building infrastructures, as illustrated in the figure.
•
•
•
•
•
Within the switched internetwork, VLANs provide segmentation and
organizational flexibility. You can design a VLAN structure that lets you group
devices that are segmented logically by functions, project teams, and
applications without regard to the physical location of the users. VLANs allow you
to implement access and security policies for particular groups of users. If a
switch port is operating as an access port, it can be assigned to only one VLAN,
which adds a layer of security. Multiple ports can be assigned to each VLAN.
Ports in the same VLAN share broadcasts. Ports in different VLANs do not share
broadcasts. Containing broadcasts within a VLAN improves the overall
performance of the network.
If you want to carry traffic for multiple VLANs across multiple switches, you need
a trunk to connect each pair of switches. VLANs can also connect across WANs.
It is important to know that traffic cannot pass directly to another VLAN (between
broadcast domains) within the switch or between two switches. To interconnect
two different VLANs, you must use routers or Layer 3 switches. The process of
forwarding network traffic from one VLAN to another VLAN using a router is
called inter-VLAN routing. Routers perform inter-VLAN routing by either having a
separate router interface for each VLAN, or by using a trunk to carry traffic for all
VLANs. The devices on the VLANs send traffic through the router to reach other
VLANs.
Usually, subnet numbers are chosen to reflect which VLANs they are associated
with. The figure shows that VLAN 2 uses subnet 10.0.2.0/24, VLAN 3 uses
10.0.3.0/24, and VLAN 4 uses 10.0.4.0/24. In this example, the third octet clearly
identifies the VLAN that the device belongs to. The VLAN design must take into
consideration the implementation of a hierarchical, network-addressing scheme.
Cisco Catalyst Series Switches have a factory default configuration in which
various default VLANs are preconfigured to support various media and protocol
types. The default Ethernet VLAN is VLAN 1, which contains all ports by default.
If you want to communicate with the Cisco Catalyst switch for management
purposes from a remote client that is on a different VLAN, which means it is on a
different subnet, then the switch must have an IP address and default-gateway
configured. This IP address must be in the management VLAN, which is by
default VLAN 1.
Creating a VLAN
On Cisco Catalyst Series Switches, you can use the vlan global configuration command
to create a VLAN and enter the VLAN configuration mode. Use the no form of this
command to delete the VLAN. The example shows how to add VLAN 2 to the VLAN
database and how to name it "Sales."
Add VLAN 2 and name it "Sales":
SwitchX# configure terminal
SwitchX(config)# vlan 2
SwitchX(config-vlan)# name Sales
The following table lists the VLAN ranges on Cisco Catalyst switches:
Command
and
Variable
Description
vlan vlanid
Enter a new VLAN ID (VID) to create a VLAN, or enter an existing VLAN ID to
modify that VLAN. Do not enter leading zeros. You can enter a single VID, a
series of VIDs that are separated by commas, or a range of VIDs that are separated
by hyphens.
(Optional) Specifies the VLAN name, which is an American Standard Code for
namevlan- Information Interchange (ASCII) string from 1 to 32 characters that must be
name
unique within the administrative domain.
To add a VLAN to the VLAN database, use the vlan global configuration command by
entering a VID.
The following table lists the VLAN ranges on Cisco Catalyst switches:
Range
VLANs Type
Usage
0, 4095 Reserved For system use only. You cannot use these VLANs.
1
Normal
The Cisco default VLAN on a switch. You can use this VLAN, but cannot
delete it. All interfaces belong to this VLAN, by default.
Range
VLANs Type
Usage
2–1001 Normal
Used for Ethernet VLANs.
1002–
1005
Normal
For legacy reasons, these VLANs are used for Token Ring and Fiber
Distributed Data Interface (FDDI) VLANs. You cannot delete VLANs
1002-1005.
1006–
4094
Extended Used for Ethernet VLANs.
VLANs 1 and 1002–1005 are automatically created by the switch, while the others have
to be created manually.
VLAN Trunking Protocol (VTP) is a Cisco proprietary Layer 2 messaging protocol that
maintains VLAN configuration consistency by managing the addition, deletion, and
renaming of VLANs on a network-wide basis. It reduces administration overhead in a
switched network. The switch supports VLANs in VTP client, server, and transparent
modes.
The configurations of VLAN IDs 1 to 1005 are always saved in the VLAN database
(vlan.dat file), which is stored in flash memory. If the VTP mode is transparent, they are
also stored in the switch running configuration file, and you can save the configuration in
the startup configuration file.
In VTP versions 1 and 2, the switch must be in VTP transparent mode when you create
extended VLANs (VIDs 1006 to 4094). These VLANs are not stored in the VLAN
database, but because VTP mode is transparent, they are stored in the switch running
(and if saved in startup) configuration file. However, extended-range VLANs created in
VTP version 3 are stored in the VLAN database, and can be propagated by VTP. Thus,
VTP version 3 supports extended VLANs creation and modification in server and
transparent modes.
To create an Ethernet VLAN, you must specify at least a VLAN number. If you do not
enter a name for the VLAN, the default is to append the VLAN number to
the vlan command. For example, VLAN0004 would be the default name for VLAN 4 if
you don't specify a name.
Assigning a Port to a VLAN
The end device connected to the switch has no knowledge of a configured VLAN on the
switch. The configuration is only performed on the switch port. The end device has an
IP address and subnet mask that associates it with a subnet. This subnet then maps to
the VLAN that is configured on the switch port to which the end device is connected.
The commands that define the VLAN port membership mode and characteristics are the
following:
Command
and
Variable Membership Mode
VLAN Membership Characteristics
switchport
mode
access
Static-access
A static-access port can belong to one VLAN and is
manually assigned to that VLAN.
Trunk (Institute of
switchport Electrical and
mode
Electronics Engineers
trunk
[IEEE] 802.1Q)
A trunk port is a member of all VLANs by default,
including extended-range VLANs, but membership can
be limited by configuring the allowed-VLAN list.
switchport
voice
vlanvlanid
Voice VLAN
A voice VLAN port is an access port attached to a Cisco
IP Phone, configured to use one VLAN for voice traffic
and another VLAN for data traffic from a device attached
to the phone.
In some other documentation, static-access ports may be referred to as untagged
ports, while the trunk ports may be referred to as tagged ports. Therefore, these
two terms may be used interchangeably.
Assigning a Port to a Data VLAN
When you connect a host to a switch port, you should associate the port with a VLAN in
accordance with the network design and the subnet that it belongs to. To associate a
device with a VLAN, assign the switch port to which the device connects to a single
VLAN. The switch port, therefore, becomes an access port.
After creating a VLAN, you can manually assign a port or many ports to this VLAN. A
port can belong to only one data VLAN at a time.
VLAN 1 is the factory default VLAN. If you do not assign a VLAN to an access port,
VLAN 1 is assigned automatically.
The following example shows how you can assign the previously created VLAN 2 to the
FastEthernet0/3 interface.
SwitchX# configure terminal
SwitchX(config)# interface FastEthernet 0/3
SwitchX(config-if)# switchport mode access
SwitchX(config-if)# switchport access vlan 2
On some switches you must create the VLAN before assigning it to a port, or else no
traffic will flow.
The table lists the commands to use when assigning a port to a VLAN.
Command and
Variable
Description
interface interface
Enters the interface configuration mode.
switchport mode
access
Sets the interface to access mode.
switchport access
vlanvlan_number
Assigns the single VLAN to the interface. To reset the VLAN to the
default VLAN, use the no form of this command.
The following example shows how you use the interface range global configuration
command to enable FastEthernet interfaces 0/1 to 0/3 and assign them to VLAN 2:
SwitchX# configure terminal
SwitchX# interface range FastEthernet0/1 - 3
SwitchX(config-if-range)# no shutdown
SwitchX(config-if-range)#
*Oct 6 08:24:35: %LINK-3-UPDOWN: Interface FastEthernet0/1, changed state to
up
*Oct 6 08:24:35: %LINK-3-UPDOWN: Interface FastEthernet0/2, changed state to
up
*Oct 6 08:24:35: %LINK-3-UPDOWN: Interface FastEthernet0/3, changed state to
up
*Oct 6 08:24:36: %LINEPROTO-5-UPDOWN: Line protocol on Interface
FastEthernet0/2, changed state to up
*Oct 6 08:24:36: %LINEPROTO-5-UPDOWN: Line protocol on Interface
FastEthernet0/3, changed state to up
*Oct 6 08:24:36: %LINEPROTO-5-UPDOWN: Line protocol on Interface
FastEthernet0/1, changed state to up
SwitchX(config-if-range)# switchport mode access
SwitchX(config-if-range)# switchport access vlan 2
The following example shows how you use the default interface global configuration
command to set the interface to factory defaults:
SwitchX(config)# default interface FastEthernet0/2
Interface FastEthernet0/2 set to default configuration
The table lists the commands to use when configuring a range of interfaces, as well as
to set the interface to factory defaults.
Command and
Variable
Description
interface
range interfaces
Enables you to configure multiple ports at the same time.
default
interface interface
Removes all settings from an interface, including VLAN association and
membership mode.
Assigning a Port to a Voice VLAN
Usually, IP phones are placed next to a computer in the working environment. They use
Ethernet and require the same network cables as computers. Hence, you can use two
separate connections, from the computer and the IP phone to the network.
Alternatively, you can connect the computer to an Ethernet port on the IP phone, and
then the connection from the IP phone to the network carries the traffic from both the
computer and the IP phone. This is enabled on some Cisco Catalyst switches with a
unique feature that is called voice VLAN; it lets you overlay a voice topology onto a data
network. You can segment phones into separate logical networks, even though the data
and voice infrastructure are physically the same.
With the IP phones in their own VLANs, network administrators can more easily identify
and troubleshoot network problems. Also, network administrators have the ability to
prioritize voice traffic over data traffic.
The voice VLAN feature allows voice traffic from the attached IP phone and data traffic
from an end-station to be transmitted on different VLANs.
You create a voice VLAN in the same way as you create data VLAN, using
the vlan global configuration command. The following example shows how to create
VLAN 3 and how to assign this VLAN as a voice VLAN to the FastEthernet0/2 interface.
Add VLAN 3 and name it "telephony":
SW1# configure terminal
SW1(config)# vlan 3
SW1(config-vlan)# name telephony
Assign interface FastEthernet0/2 to voice VLAN 3:
SW1# configure terminal
SW1(config)# interface FastEthernet0/2
SW1(config-if)# switchport mode access
SW1(config-if)# switchport voice vlan 3
When an IP phone is connected to a switch port, this port should have a voice VLAN
associated with it. This process is done by assigning a single voice VLAN to the switch
port to which the phone is connected.
Command
Description
switchport
mode access
Sets the interface to access mode.
switchport voice Set the voice VLAN to an interface. This action will instruct the Cisco IP
vlanvlan-id
phone to forward all voice traffic through the specified VLAN.
You can configure a data and voice VLAN on the same interface, as shown in this
example:
SW1# configure terminal
SW1(config)# vlan 2
SW1(config-vlan)# name data
SW1(config-vlan)# exit
SW1(config)# interface FastEthernet0/2
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 2
SW1(config-if)# switchport voice vlan 3
Verifying VLANs
After you configure a VLAN, you should validate the parameters for that VLAN.
Use the show vlan command to display information on all configured VLANs. The
command displays configured VLANs, their names, and the ports on the switch that are
assigned to each VLAN. You can observe in the output all information about the VLANs.
To display information on all configured VLANs:
SW1# show vlan
VLAN Name Status Ports
---- -------------------------------- --------- -----------------------------1 default active Fa0/1, Fa0/3, Fa0/4, Fa0/5, Fa0/6, Fa0/7
2 data active Fa0/2
3 telephony active Fa0/2
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ----1 enet 100001 1500 - - - - - 0 0
2 enet 100002 1500 - - - - - 0 0
3 enet 100003 1500 - - - - - 0 0
1002 fddi 101002 1500 - - - - - 0 0
1003 tr 101003 1500 - - - - - 0 0
1004 fdnet 101004 1500 - - - ieee - 0 0
1005 trnet 101005 1500 - - - ibm - 0 0
Remote SPAN VLANs
-----------------------------------------------------------------------------
Primary Secondary Type Ports
------- --------- ----------------- -----------------------------------------
The example shows that VLAN 2 (data) and VLAN 3 (telephony) are created on the
switch. Both are active and are assigned to the FastEthernet0/2. All other interfaces are
assigned to the default VLAN—VLAN 1. Trunk ports that are connected to another
device do not appear in the output of the show vlan command.
Use the show vlan id vlan_number or show vlan name vlan-name command to
display information about a particular VLAN. The example shows the output of
the show vlan command for the "data" VLAN, which is VLAN 2.
SW1# show vlan id 2
VLAN Name Status Ports
---- -------------------- ------- ---------------------
2 data active Fa0/2
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ---- ------- ----- ------ ------ -------- --- --------- ------ -----2 enet 100002 1500 - - - - - 0 0
<... output omitted ...>
On the other hand, you can use the show vlan brief command, which displays one line
for each VLAN with the VLAN name, status, and its ports. Connected trunk ports also
do not appear in the output of the show vlan brief command.
SW1# show vlan brief
VLAN Name Status Ports
---- -------------------------------- --------- -----------------------------1 default active Fa0/1, Fa0/3, Fa0/4, Fa0/5, Fa0/6, Fa0/7
2 data active Fa0/2
3 telephony active Fa0/2
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
Dynamic Trunking Protocol (DTP) is used by Cisco switches to automatically negotiate
whether an interface used for interconnection between two switches should be put into
access or trunk mode. When the interface is in trunk mode, DTP also negotiates trunk
encapsulation.
The DTP individual modes are:
•
•
dynamic auto: the interface will form a trunk only if it receives DTP messages to do so
from the other side switch. An interface configured in dynamic auto mode does not
generate DTP messages and only listens for incoming DTP messages.
dynamic desirable: the interface will negotiate the mode automatically, and will actively
try to convert the link to a trunk link. An interface configured in dynamic desirable mode
generates DTP messages and listens for incoming DTP messages. If the port on the
other side switch interface is capable to form a trunk, a trunk link will be formed.
Interfaces on some switches are by default set to dynamic desirable and on other
switches they are by default set to dynamic auto.
The individual combinations of interface settings on the switches lead to following
results:
Interface mode on one side
Interface mode on other
side
Resulting operational
mode
dynamic auto
dynamic auto
access
dynamic auto
dynamic desirable
trunk
dynamic desirable
dynamic desirable
trunk
dynamic auto or dynamic
desirable
trunk
trunk
dynamic auto or dynamic
desirable
access
access
The best practice is to disable the autonegotiation and not use the dynamic
auto and dynamic desirable switch port modes. Instead, the best practice is to manually
configure the port mode as trunk on both sides. If you do not want the switch to
negotiate at all, use the switchport nonegotiate command (necessary only for trunk
ports, as the static access ports do not send DTP packets automatically.)
To verify the VLAN configuration of an interface, as well as the administrative and
operational mode, use show interfaces interface-id switchport command.
SW1# show interfaces FastEthernet0/2 switchport
Name: Fa0/2
Switchport: Enabled
Administrative Mode: dynamic desirable
Operational Mode: static access
Administrative Trunking Encapsulation: negotiate
Operational Trunking Encapsulation: native
Negotiation of Trunking: On
Access Mode VLAN: 2 (data)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Voice VLAN: 3 (telephony)
<... output omitted ...>
You can also use the show mac address-table command to verify which Media
Access Control (MAC) addresses belong to which port and VLAN. You can also see the
MAC addresses that have been learned on a particular VLAN with the show mac
address-table vlan vlan-id command.
Switch# show mac address-table
Mac Address Table
------------------------------------------Vlan Mac Address Type Ports
---- ----------- -------- ----1 aabb.cc00.2f00 DYNAMIC Fa0/0
1 aabb.cc00.3100 DYNAMIC Fa0/1
2 aabb.cc00.3000 DYNAMIC Fa0/2
If the MAC address has not yet been learned on a particular VLAN and port, then you
will see no entry in the MAC address table. Also remember, that if the MAC address
remains inactive for a specified number of seconds, it is removed from the MAC address
table. The default aging time is 300 seconds.
Each port on a switch belongs to a VLAN. If the VLAN to which the port belongs is
deleted, the port becomes inactive. Also, a port becomes inactive if it is assigned to a
non-existent VLAN. All inactive ports are unable to communicate with the rest of the
network.
As shown in the following example, you can use the show
interface interface switchport command to check whether the port is inactive. If the
port is inactive, it will not be functional until you create the missing VLAN using
the vlan vlan_id command or until you assign the port to a valid VLAN.
Switch# show interfaces Ethernet0/1 switchport
Name: Et0/1
Switchport: Enabled
Administrative Mode: static access
Operational Mode: static access
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: native
Negotiation of Trunking: Off
Access Mode VLAN: 10 (Inactive)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
Trunking with 802.1Q
Without trunking, running many VLANs between switches would require the same
number of interconnecting links.
If every port belongs to one VLAN and you have several VLANs that are configured on
switches, then interconnecting them requires one physical cable per VLAN. When the
number of VLANs increases, the number of required interconnecting links also
increases. Ports are then used for inter-switch connectivity instead of attaching end
devices.
Instead, you can use one connection configured as a trunk:
•
•
•
•
Combining many VLANs on the same port is called trunking.
A trunk allows the transport of frames from different VLANs.
Each frame has a tag that specifies the VLAN that it belongs to.
The receiving device forwards the frames to the corresponding VLAN based on the tag
information.
A trunk is a point-to-point link between two network devices, such as a server, router
and a switch. Ethernet trunks carry the traffic of multiple VLANs over a single link and
allow you to extend the VLANs across an entire network. A trunk does not belong to a
specific VLAN. Rather, it is a conduit for VLANs between devices. By default, on a
Cisco Catalyst switch, all configured VLANs are carried over a trunk interface.
A trunk could also be used between a network device and a server or another device that
is equipped with an appropriate trunk capable network interface card (NIC).
VLAN Tagging
If your network includes VLANs that span multiple interconnected switches, the
switches must use VLAN trunking on the connections between them. Switches use a
process called VLAN tagging in which the sending switch adds another header to the
frame before sending it over the trunk. This extra header is called a tag and includes a
VLAN ID (VID) field so that the sending switch can list the VLAN ID and the receiving
switch can identify the VLAN that each frame belongs to, as illustrated in the figure.
Trunking allows switches to pass frames from multiple VLANs over a single physical
connection. For example, the figure shows Switch 1 receiving a broadcast frame on the
Fa0/1 interface, which is a member of VLAN 1. In a broadcast, the frame must be
forwarded to all ports in VLAN 1. Because there are ports on Switch 2 that are members
of the VLAN 1 switch, the frame must be forwarded to Switch 2. Before forwarding the
frame, Switch 1 adds a header that identifies the frame as belonging to VLAN 1. This
header tells Switch 2 that the frame should be forwarded to the VLAN 1 ports. Switch 2
removes the header and then forwards the frame for all ports that are part of VLAN 1.
As another example, the device on the Switch 1 Fa0/5 interface sends a broadcast.
Switch 1 sends the broadcast out of port Fa0/6 (because this port is in VLAN 2) and out
Fa0/23 (because it is a trunk, meaning that it supports multiple VLANs). Switch 1 adds a
trunking header to the frame, listing a VLAN ID of 2. Switch 2 strips off the trunking
header, and because the frame is part of VLAN 2, Switch 2 knows to forward the frame
out of only ports Fa0/5 and Fa0/6 and not ports Fa0/1 and Fa0/2.
IEEE 802.1Q
Cisco Catalyst switches support the IEEE 802.1Q trunking protocol.
When a switch puts an Ethernet frame on a trunk, it needs to add a VLAN tag with
information about the VLAN to which the frame belongs. The switch does so by using
the 802.1Q encapsulation header. IEEE 802.1Q uses an internal tagging mechanism
that inserts an extra 4-byte tag field into the original Ethernet frame between the Source
Address and Type or Length fields. As a result, the frame still has the original source
and destination MAC addresses. Also, because the original header has been expanded,
802.1Q encapsulation forces a recalculation of the original frame check sequence
(FCS) field in the Ethernet trailer, because the FCS is based on the content of the entire
frame. It is the responsibility of the receiving Ethernet switch to look at the 4-byte tag
field and determine where to deliver the frame.
The figure shows the 802.1Q header and framing of the revised Ethernet header.
Here are tag fields:
•
•
•
•
Type or tag protocol identifier is set to a value of 0x8100 to identify the frame as an
IEEE 802.1Q-tagged frame.
Priority indicates the frame priority level that can be used for the prioritization of traffic.
Canonical Format Identifier (CFI) is a 1-bit identifier that enables Token Ring frames
to be carried across Ethernet links
VLAN ID uniquely identifies the VLAN to which the frame belongs.
On an 802.1Q trunk port, there is one VLAN, called the native VLAN, which is untagged.
By default, the native VLAN is VLAN 1, which means that the switch does not insert an
extra 802.1Q tag inside an Ethernet frame. When the switch on the receiving side
receives the Ethernet frame that does not have an 802.1Q tag, it knows that the frame
belongs to the native VLAN. All other VLANs are tagged with a VID. IEEE 802.Q
specifies that native VLANs are backward compatible with legacy LAN scenarios, where
untagged traffic is common.
Both switches must be configured with the same native VLAN or errors will occur, and
untagged traffic will go to the wrong VLAN on the receiving switch. By default it is the
VLAN 1.
Configuring an 802.1Q Trunk
The following example shows the configuration of interface Ethernet0/0 as a trunk. Use
the switchport mode interface configuration command to set an Ethernet port to trunk
mode. The example also shows reconfiguration of the native VLAN. VLAN 99 is
configured as the native VLAN; therefore, traffic from VLAN 99 is sent untagged. You
must ensure that the switch on the other end of the trunk link is configured the same
way.
If you do not explicitly configure the VLANs that traverse the trunk, all VLANs will be
allowed to cross the link. Use the switchport mode trunk allowed
vlan vlan_list command to allow only certain VLANs on the trunk link. In the example,
only VLANs 10, 20, 30, and 99 are allowed on a trunk link. If you need to add or remove
allowed VLANs, use the switchport trunk allowed
vlan {add |remove} vlan_list command.
SwitchX# configure terminal
SwitchX(config)# interface Ethernet 0/0
SwitchX(config-if)# switchport mode trunk
SwitchX(config-if)# switchport trunk native vlan 99
SwitchX(config-if)# switchport trunk allowed vlan 10,20,30,99
Use the no form of those commands to reset the trunk port to the default state.
The table lists commands to use when creating a trunk port:
Command and
Variable
Description
interface interface Enters the interface configuration mode.
switchport mode
trunk
Sets the interface type to trunking.
Command and
Variable
Description
switchport trunk Sets the native VLAN on the trunk to the specified VLAN number. Traffic
native
from this VLAN is sent untagged. You must ensure that the switch on the
vlan vlan_number other end of the trunk link is configured the same way.
switchport trunk Sets allowed VLANs on a trunk link. vlan_list is a sequence of VLAN
allowed
numbers, separated with commas. The vlan_list cannot have spaces after
vlan vlan_list
commas.
switchport trunk
allowed vlan
Adds specified VLANs to the existing list of allowed VLANs on a trunk
addvlan_list
link. The vlan_list cannot have spaces after commas.
switchport trunk
allowed vlan
Removes specified VLANs from the existing list of allowed VLANs on a
removevlan_list
trunk link. The vlan_list cannot have spaces after commas.
Be extremely careful when adding a new VLAN to the list of allowed
VLANs on a trunk port. It is a common mistake to use the switchport
trunk allowed vlan vlan-number command. This command will overwrite
the existing list of allowed VLANs, and it will replace it with the single
VLAN you have just specified. Therefore, it is necessary to use
the switchport trunk allowed vlan add vlan-number command.
The following example shows you how to verify the configuration of a trunked interface,
using the show interfaces interface-idswitchport command.
Display VLAN information for an interface.
SwitchX# show interfaces Ethernet0/0 switchport
Name: Et0/0
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: dot1q
Negotiation of Trunking: On
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 99 (VLAN0099)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
<... output omitted ...>
Trunking VLANs Enabled: 10,20,30,99
<... output omitted ...>
In the example, you can see that the interface Ethernet 0/0 operates as a trunk port,
and has the VLAN 99 as the native VLAN. It only allows VLANs 10, 20, 30, and 99 to
traverse through the link.
To verify, which ports are configured as trunks on a switch, you can use the show
interfaces trunk command.
Switch# show interfaces trunk
Port Mode Encapsulation Status Native vlan
Et0/0 on 802.1q trunking 99
Port Vlans allowed on trunk
Et0/0 10,20,30,99
Port Vlans allowed and active in management domain
Et0/0 10,20,30,99
<... output omitted ...>
You can also use the show interfaces status command to quickly verify which port is a
trunk, and which port belongs to a certain VLAN.
SwitchX# show interfaces status
Port Name Status Vlan Duplex Speed Type
Et0/0 connected trunk auto auto unknown
Et0/1 connected 2 auto auto unknown
Et0/2 connected 1 auto auto unknown
Et0/3 connected 1 auto auto unknown
Unlike access ports, when a port is configured as trunk port, it will not be seen under
the show vlan [brief] command. Notice that, in this example, interface Ethernet 0/0 is
missing.
SwitchX# SwitchX# show vlan brief
VLAN Name Status Ports
---- -------------------------------- --------- -----------------------------1 default active Et0/2, Et0/3
2 SALES active Et0/1
10 VLAN0010 active
20 VLAN0020 active
30 VLAN0030 active
99 VLAN0099 active
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
Discovery 14: Configure VLAN and Trunk
Introduction
This lab exercise will guide you through several aspects of VLAN operations, including
the management of VLANs, and using trunks to carry multiple VLANs across a single
physical link. The devices are configured as pictured in the topology diagram. Currently,
all devices have IP version 4 (IPv4) addresses in the 10.10.1.0/24 subnet. Only the
default VLAN, VLAN 1, exists initially. You will start by migrating this configuration to
one that uses two VLANs.
Topology
Job Aid
Device Information
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today.
Personal computers (PCs) in the virtual lab environment are simulated by routers, so you
should use Cisco IOS commands to configure them or verify the configuration.
Device Information Table
Device
Characteristic
Value
PC1
IPv4 address
10.10.1.10/24
PC2
IPv4 address
10.10.1.20/24
Device
Characteristic
Value
PC3
IPv4 address
10.10.1.30/24
PC4
IPv4 address
10.10.1.40/24
SW1
VLAN 1 IPv4 Address
10.10.1.4/24
SW1
Ethernet0/0 description
Link to SW2
SW1
Ethernet1/0 description
Link to PC1
SW1
Ethernet1/1 description
Link to PC2
SW2
VLAN 1 IPv4 address
10.10.1.5/24
SW2
Ethernet0/0 description
Link to SW1
SW2
Ethernet1/0 description
Link to PC3
SW2
Ethernet1/1 description
Link to PC4
Device Information Table (Changes)
Device
Characteristic
Value
PC2
VLAN
2
PC2
IPv4 address
10.10.2.20/24
PC4
VLAN
2
PC4
IPv4 address
10.10.2.40/24
Task 1: Configure VLAN and Trunk
Activity
Step 1
Start by demonstrating that there is full connectivity between the devices in VLAN 1 on
the 10.10.1.0/24 subnet. Access the console of PC1 and ping the IPv4 addresses of the
other devices.
Enter the following commands on PC1:
PC1# ping 10.10.1.20
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.20, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
PC1# ping 10.10.1.30
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.30, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
PC1# ping 10.10.1.40
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.40, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
PC1# ping 10.10.1.4
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.4, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
PC1# ping 10.10.1.5
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.5, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
Step 2
Now access the console of PC2 and change its IPv4 address to 10.10.2.20 on the
10.10.2.0/24 subnet.
You can use abbreviated commands during configuration. For example, you can
use conf t for configure terminal. If there is any confusion, you can attempt tab
completion to expand the full command syntax. For example, conf tab t tab would
expand toconfigure terminal.
Enter the following commands to PC2:
PC2# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
PC2(config)# interface Ethernet0/0
PC2(config-if)# ip address 10.10.2.20 255.255.255.0
PC2(config-if)# end
PC2#
At this point, PC2 is still in VLAN 1, so it is in the same broadcast domain as all the
other hosts. But its IPv4 address is configured for a different IPv4 subnet. Therefore,
PC2 will not attempt Address Resolution Protocol (ARP) resolution for hosts on the
10.10.1.0/24 subnet. It must use a gateway to reach the 10.10.1.0/24 subnet; however,
this gateway does not even exist. PC2 is currently isolated by the IP configuration.
Step 3
Access the console of PC4 and reconfigure its IP address to be 10.10.2.40 on the
10.10.2.0/24 subnet.
Enter the following commands to the PC4:
PC4# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
PC4(config)# interface Ethernet0/0
PC4(config-if)# ip address 10.10.2.40 255.255.255.0
PC4(config-if)# end
PC4#
Now, both PC2 and PC4 are configured for the 10.10.2.0/24 subnet, while the rest of
the hosts are configured for the 10.10.1.0/24 subnet. They are all in the same broadcast
domain (VLAN 1), but they are isolated by the IP configuration.
PC2 and PC4 are seeing ARP requests (broadcasts) from PC1 and PC3 even though they
are on a different subnet and have no reason to have to process these ARP requests.
Step 4
Verify that PC4 can communicate with PC2 because they are both configured for the
10.10.2.0/24 subnet. Attempt to ping 10.10.2.20. The ping should succeed.
Enter the following commands to PC4:
PC4# ping 10.10.2.20
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.2.20, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
Step 5
Access the console of SW1 and verify that the only Ethernet VLAN is the default VLAN,
VLAN 1.
Enter the following command to the SW1 switch:
SW1# show vlan
VLAN Name Status Ports
---- -------------------------------- --------- ------------------------------
1 default active Et0/1, Et0/2, Et0/3, Et1/0
Et1/1, Et1/2, Et1/3
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ -----
1 enet 100001 1500 - - - - - 0 0
1002 fddi 101002 1500 - - - - - 0 0
1003 tr 101003 1500 - - - - - 0 0
1004 fdnet 101004 1500 - - - ieee - 0 0
1005 trnet 101005 1500 - - - ibm - 0 0
Primary Secondary Type Ports
------- --------- ----------------- -----------------------------------------
Besides VLAN 1, which is the default Ethernet VLAN, there are four other VLANs that
exist by default. VLANs 1002 to 1005 exist to support the legacy Token Ring and FDDI
technology. They are very rarely used in networks today.
Step 6
Create VLAN 2 and assign "Engineering" as its name.
Enter the following commands to the SW1 switch:
SW1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW1(config)# vlan 2
SW1(config-vlan)# name Engineering
SW1(config-vlan)# end
SW1#
Step 7
Verify that the VLAN has been created and is active.
Enter the following command to the SW1 switch:
SW1#show vlan brief
VLAN Name Status Ports
---- -------------------------------- --------- -----------------------------1 default active Et0/1, Et0/2, Et0/3, Et1/0
Et1/1, Et1/2, Et1/3
2 Engineering active
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
You can compare the output of the show vlan brief command to the output of
the show vlan command that was used previously. With the brief argument, the
characteristics that are only appropriate to Token Ring and FDDI networks (such as
parent and ring number) are hidden from the display.
Although VLAN 2 is active, no active ports appear to be using VLAN 2.
Step 8
Look closer at the status of VLAN 2. Display information about it by specifying its VLAN
ID in the show vlan id vlan-id command.
Enter the following command to the SW1 switch:
SW1# show vlan id 2
VLAN Name Status Ports
---- -------------------------------- --------- ------------------------------
2 Engineering active Et0/0
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ -----
2 enet 100002 1500 - - - - - 0 0
Primary Secondary Type Ports
------- --------- ----------------- -----------------------------------------
When you show all VLANs, only the access mode ports are displayed. When you show
a particular VLAN, the trunk ports that carry the VLAN are also displayed. Ethernet0/0 is
the trunk port connecting SW1 and SW2.
Step 9
In the lab environment, the default trunking encapsulation method on the SW1 and SW2
is Inter-Switch Link (ISL), which is an older Cisco proprietary trunking protocol. IEEE
802.1Q is much more common in networks today, and some switch models no longer
support ISL. Thus, before verifying the switch port status of the Ethernet0/0 interface on
SW1, explicitly configure this interface to IEEE 802.1Q trunk using the switchport
trunk encapsulation dot1q command.
Enter the following commands to the SW1 switch:
SW1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW1(config)# interface Ethernet0/0
SW1(config-if)# switchport trunk encapsulation dot1q
SW1(config-if)# end
SW1#
Step 10
You must configure SW2 to be synchronized with the configuration that you just
performed on SW1. Access the console of SW2 and configure Ethernet0/0 explicitly as
the 802.1Q trunk.
Enter the following commands to the SW2 switch:
SW2# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW2(config)# interface Ethernet0/0
SW2(config-if)# switchport trunk encapsulation dot1q
SW2(config-if)# end
SW2#
Step 11
Access the SW1 console and view the switch port status of the Ethernet0/0 interface.
Enter the following command to the SW1 switch:
SW1# show interface Ethernet0/0 switchport
Name: Et0/0
Switchport: Enabled
Administrative Mode: dynamic desirable
Operational Mode: trunk
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: dot1q
Negotiation of Trunking: On
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
Administrative private-vlan host-association: none
Administrative private-vlan mapping: none
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk Native VLAN tagging: enabled
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk associations: none
Administrative private-vlan trunk mappings: none
Operational private-vlan: none
Trunking VLANs Enabled: ALL
Pruning VLANs Enabled: 2-1001
Capture Mode Disabled
Capture VLANs Allowed: ALL
Appliance trust: none
The default administrative trunking mode on the Ethernet 0/0 switch port on SW1 is
"dynamic desirable." Since the other side was able to receive the DTP messages sent
from this port, a trunk link was formed between the two switches. Both administrative
and operational trunking encapsulations are the 802.1Q trunk. Optionally, you may
repeat this verification on SW2.
Step 12
While the trunking status was automatically negotiated between the switches, the best
practice is to explicitly configure the trunking status on switch ports. Also, it is best
practice to assign a native VLAN to 802.1Q trunks that is not used by any endpoint
hosts on the network. Begin this explicit configuration by defining VLAN 256 and
assigning it the "NoHosts" name.
Enter the following commands to the SW1 switch:
SW1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW1(config)# vlan 256
SW1(config-vlan)# name NoHosts
SW1(config-vlan)# exit
SW1(config)#
While it makes no difference to the switch which IPv4 subnet you implement on which
VLAN, for ease of network management, it is common to use the value of the third octet
of the IPv4 network as the VLAN ID, when possible. For example, you would pair VLAN
2 with 10.10.2.0/24, pair VLAN 3 with 10.10.3.0/24, etc.
The number 256 is not a valid IPv4 address octet. The X.Y.256.Z addresses are invalid
IPv4 addresses. Therefore, 256 can be an effective VID to use for a VLAN that
intentionally services no hosts and is used for the native VLAN on 802.1Q trunks.
VLANs do not have to follow the same naming convention on all switches, but they
should for ease of management.
Step 13
Now, explicitly configure Ethernet0/0 as a trunk using VLAN 256 as the native VLAN.
Enter the following commands to the SW1 switch:
SW1(config)# interface Ethernet0/0
SW1(config-if)# switchport trunk native vlan 256
SW1(config-if)# switchport mode trunk
SW1(config-if)# end
SW1#
Before changing the native VLAN on SW2, you will see on the SW1 console the %CDP4-NATIVE_VLAN_MISMATCH message every 60 seconds.
*Feb 2 12:34:09.712: %CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch
discovered on Ethernet0/0 (256), with SW2 Ethernet0/0 (1).
Step 14
You must configure SW2 to be synchronized with the configuration that you just
performed on SW1. Access the console of SW2, configure VLAN 2 and VLAN 256, and
configure Ethernet0/0 explicitly as trunk with VLAN 256 as the native VLAN.
Enter the following commands to the SW2 switch:
SW2# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW2(config)# vlan 2
SW2(config-vlan)# name Engineering
SW2(config-vlan)# vlan 256
SW2(config-vlan)# name NoHosts
SW2(config-vlan)# exit
SW2(config)# interface Ethernet0/0
SW2(config-if)# switchport trunk native vlan 256
SW2(config-if)# switchport mode trunk
SW2(config-if)# end
SW2#
Step 15
Verify the trunk status of Ethernet0/0 on SW2.
Enter the following commands to the SW2 switch:
SW2# show interface Ethernet0/0 switchport
Name: Et0/0
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: dot1q
Negotiation of Trunking: On
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 256 (NoHosts)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
Administrative private-vlan host-association: none
Administrative private-vlan mapping: none
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk Native VLAN tagging: enabled
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk associations: none
Administrative private-vlan trunk mappings: none
Operational private-vlan: none
Trunking VLANs Enabled: ALL
Pruning VLANs Enabled: 2-1001
Capture Mode Disabled
Capture VLANs Allowed: ALL
Appliance trust: none
Both administrative and operational modes are the 802.1Q trunk. The trunking native
VLAN is 256. Optionally, you may repeat this verification on SW1.
Step 16
VLAN 2 is now ready on both switches, and the trunk link is configured between the two
switches. On SW2, explicitly define the PC4 switch port as an access port that is
assigned to VLAN 2.
Enter the following commands to the SW2 switch:
SW2# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW2(config)# interface Ethernet1/1
SW2(config-if)# switchport access vlan 2
SW2(config-if)# switchport mode access
SW2(config-if)# end
SW2#
Step 17
Verify the status of the Ethernet1/1 switch port configuration.
Enter the following command to the SW2 switch:
SW2# show interface Ethernet1/1 switchport
Name: Et1/1
Switchport: Enabled
Administrative Mode: static access
Operational Mode: static access
Administrative Trunking Encapsulation: negotiate
Operational Trunking Encapsulation: native
Negotiation of Trunking: Off
Access Mode VLAN: 2 (Engineering)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
Administrative private-vlan host-association: none
Administrative private-vlan mapping: none
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk Native VLAN tagging: enabled
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk associations: none
Administrative private-vlan trunk mappings: none
Operational private-vlan: none
Trunking VLANs Enabled: ALL
Pruning VLANs Enabled: 2-1001
Capture Mode Disabled
Capture VLANs Allowed: ALL
Appliance trust: none
Step 18
On SW2, verify the interface status of the trunk link (Ethernet0/0) and the ports that are
supporting PC3 and PC4.
Enter the following command to the SW2 switch:
SW2# show interface status
Port Name Status Vlan Duplex Speed Type
Et0/0 Link to SW1 connected trunk auto auto unknown
Et0/1 connected 1 auto auto unknown
Et0/2 connected 1 auto auto unknown
Et0/3 connected 1 auto auto unknown
Et1/0 Link to PC3 connected 1 auto auto unknown
Et1/1 Link to PC4 connected 2 auto auto unknown
Et1/2 connected 1 auto auto unknown
Et1/3 connected 1 auto auto unknown
Step 19
On SW1, verify the interface status of the trunk link (Ethernet0/0) and the ports that are
supporting PC1 and PC2.
Enter the following command to the SW1 switch:
SW1# show interface status
Port Name Status Vlan Duplex Speed Type
Et0/0 Link to SW2 connected trunk auto auto unknown
Et0/1 connected 1 auto auto unknown
Et0/2 connected 1 auto auto unknown
Et0/3 connected 1 auto auto unknown
Et1/0 Link to PC1 connected 1 auto auto unknown
Et1/1 Link to PC2 connected 1 auto auto unknown
Et1/2 connected 1 auto auto unknown
Et1/3 connected 1 auto auto unknown
Step 20
Notice that PC4 and PC2 are on different VLANs, so although they are configured for
the same IPv4 subnet, they should no longer be able to communicate. Verify this status
by attempting to ping 10.10.2.20 from PC4. This ping should fail.
Enter the following command to PC4:
PC4# ping 10.10.2.20
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.2.20, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
Step 21
Access the SW1 console. Configure the switch port connected to PC2 (Ethernet1/1) to
be an access port that is assigned to VLAN 2.
Enter the following commands to the SW1 switch:
SW1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW1(config)# interface Ethernet1/1
SW1(config-if)# switchport access vlan 2
SW1(config-if)# switchport mode access
SW1(config-if)# end
SW1#
Step 22
Verify the switch port status of Ethernet1/1.
Enter the following command to the SW1 switch:
SW1# show interface Ethernet1/1 switchport
Name: Et1/1
Switchport: Enabled
Administrative Mode: static access
Operational Mode: static access
Administrative Trunking Encapsulation: negotiate
Operational Trunking Encapsulation: native
Negotiation of Trunking: Off
Access Mode VLAN: 2 (Engineering)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
Administrative private-vlan host-association: none
Administrative private-vlan mapping: none
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk Native VLAN tagging: enabled
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk associations: none
Administrative private-vlan trunk mappings: none
Operational private-vlan: none
Trunking VLANs Enabled: ALL
Pruning VLANs Enabled: 2-1001
Capture Mode Disabled
Capture VLANs Allowed: ALL
Appliance trust: none
Step 23
Verify the interface of the SW1 trunk ports and the links to the PCs.
Enter the following command to the SW1 switch:
SW1# show interface status
Port Name Status Vlan Duplex Speed Type
Et0/0 Link to SW2 connected trunk auto auto unknown
Et0/1 connected 1 auto auto unknown
Et0/2 connected 1 auto auto unknown
Et0/3 connected 1 auto auto unknown
Et1/0 Link to PC1 connected 1 auto auto unknown
Et1/1 Link to PC2 connected 2 auto auto unknown
Et1/2 connected 1 auto auto unknown
Et1/3 connected 1 auto auto unknown
Step 24
PC2 and PC4 are now both configured for the 10.10.2.0/24 subnet and are in the same
broadcast domain (VLAN 2). Access the PC4 console and verify that it can once again
ping PC2.
Enter the following command to PC4:
PC4# ping 10.10.2.20
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.2.20, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
Step 25
At this point, there is no routing configured. PC2 and PC4 are isolated from the other
hosts that are in VLAN 1. Demonstrate that PC4 cannot ping PC1.
Enter the following command to PC4:
PC4# ping 10.10.1.10
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.10, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
VLAN Design Considerations
VLANs create boundaries that can isolate endpoints or traffic, so you should design a
multi-VLAN topology thoughtfully. The general question that you should ask yourself is
the following: "Who is talking to whom, and what are they trying to get done?" Here are
some considerations that you need to take into account before implementing VLANs:
•
•
•
•
The maximum number of VLANs is switch-dependent.
VLAN 1 is the factory-default Ethernet VLAN.
Keep management traffic in a separate VLAN.
Change the native VLAN to something other than VLAN 1.
Typically, access layer Cisco switches support up to 64, 256, or 1024 VLANs. The
maximum number of VLANs is switch-dependent.
Cisco switches have a factory-default configuration in which default VLANs are
preconfigured to support various media and protocol types. The default Ethernet VLAN
is VLAN 1. For security reasons, a good practice is to configure all the ports on all
switches to be associated with VLANs other than VLAN 1. Also, all unused switch ports
should be assigned to black hole VLAN and set to be administratively down. A black
hole VLAN is a term for a VLAN which is associated with a subnet that has no route, or
no default-gateway to other networks within your organization, or to the internet. Hence,
you can mitigate the security associated with the default VLAN 1.
In this example, a black hole VLAN is created and unused ports are placed into that
VLAN. Also, unused switch ports are shut down to prevent unauthorized access to the
network.
SW1# configure terminal
SW1(config)# vlan 900
SW1(config-vlan)# name BLACKHOLE
SW1(config-vlan)# interface range Ethernet0/16-24
SW1(config-if-range)# switchport mode access
SW1(config-if-range)# switchport access vlan 900
SW1(config-if-range)# shutdown
If you did not use the shutdown command in the above configuration, then if someone
plugs a device into an unused port, the port will come up, but the device will be placed
into a VLAN that does not have access to anything. Thus, you can successfully mitigate
some network attacks.
A good security practice is to separate management and user data traffic because you
do not want users to be able to establish Secure Shell (SSH) sessions to the switch.
The management VLAN by default is VLAN 1, and it should be changed to a different
VLAN. If you want to communicate with a Cisco switch remotely for management
purposes, the switch must have an IP address and a default-gateway configured, and
they must be in the management VLAN. In this case, users who are not in the
management VLAN cannot access the switch, unless they were routed into the
management VLAN.
When configuring a trunk port, consider the following:
•
•
•
Make sure that the native VLAN for an 802.1Q trunk is the same on both ends of the
trunk port.
Only allow specific VLANs to traverse through the trunk port.
DTP manages trunk negotiations between Cisco switches.
Make sure that the native VLAN for an IEEE 802.1Q trunk is the same on both ends of
the trunk link. If the configuration is different on the two switches, the traffic will be
forwarded in the wrong VLAN. If IEEE 802.1Q trunk configuration is not the same on
both ends, Cisco IOS Software will report error messages. Note that native VLAN
frames are untagged.
SW1#
*Mar 31 06:22:46.631: %CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch
discovered on Ethernet0/0(999), with SW2 Ethernet0/0 (99).
Another good security practice is to change the native VLAN to something other than
VLAN 1 because all control traffic is sent on VLAN 1. The native VLAN should be
changed to be a VLAN that is not used for any other traffic. By default, the native VLAN
is not tagged, but it is recommended to tag the native VLAN. The example below shows
how to change the native VLAN and tag it.
SW1# configure terminal
SW1(config-vlan)# interface Ethernet0/0
SW1(config-if-range)# switchport mode trunk
SW1(config-if-range)# switchport trunk native vlan 90
SW1(config-if-range)# switchport trunk native vlan tag
Switches from other vendors do not support DTP. As discussed, DTP is used by Cisco
switches to automatically negotiate whether an interface between two switches will be
put into access or trunk mode.
Troubleshoot VLANs and Trunk
FASTLab 5: Troubleshoot VLANs and Trunk
Scenario
Read the requirements in the Scenario carefully and use the Configuration Tips to help
you do the required steps. If you need further assistance, refer to the Answer Key. Once
you have completed the configuration specified, answer the questions.
The IT department of an airline company has asked you to help their new junior
engineer named Marcus. Marcus has just set up a Proof of Concept (PoC) lab to better
understand switching. He has set up a VLAN scheme where PCs are in two VLANs,
while servers are in a different VLAN. These devices are spread across two switches
SW1 and SW2, which have a trunk connection between them. Marcus has not set up
the equipment properly, so it is up to you to troubleshoot the lab network and show him
that the VLANs and trunks are working properly.
•
Ensure that the VLAN names have been configured correctly on the two switches SW1
and SW2, using the following VLAN name information:
VLAN Name
65
Users1
13
Users2
80
Servers
VLAN names on different switches do not have to be the same, since the VIDs
uniquely identify the VLAN in different switches. However, it is best practice to make
them the same for easier management and troubleshooting.
•
•
Ensure that the interfaces on SW1 and SW2 that are connected to PCs and Servers are
configured correctly and are enabled.
Isolate and troubleshoot the issues that are related to the trunking between SW1 and
SW2.
Topology
Job Aid
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today.
Device Information
Device
Interface
IPv4 Address
Remote
Interface
VLAN
PC1
E0/0
192.168.65.1/24
SW1
E0/1
65
PC2
E0/0
192.168.65.2/24
SW2
E0/1
65
PC3
E0/0
192.168.13.1/24
SW1
E0/0
13
Server1
E0/0
192.168.80.1/24
SW1
E0/2
80
Server2
E0/0
192.168.80.2/24
SW2
E0/2
80
SW1
E0/3
Trunk
SW2
E0/3
—
VLAN Name Information
VLAN
Name
65
Users1
VLAN
Name
13
Users2
80
Servers
Configuration Tips
•
•
•
•
•
•
•
Use the show vlan command to see the VLANs configured. It will show the ports in
each VLAN along with the VLAN names.
On SW1, VLAN 65 is "User," but it is supposed to be "Users1."
On SW1 and SW2, the VLAN for "Users2" is not named. Name VLAN 13 correctly.
The port on SW2 connecting to PC2 is configured to place traffic to the wrong VLAN.
Enable the port on SW1 that is connected to Server1.
Verify the trunking configuration between SW1 and SW2. The port is set as an access
port. Remove the configuration that is related to making the port an access port and
apply the configuration making it a trunk unconditionally. Trunk links will not come up
when the trunk ports do not have a matching configuration.
Use the ping command to check connectivity between devices in the same VLAN.
The ping command will not work between devices in different VLANs.
Answer Key
You need to complete the following tasks:
•
•
Ensure that the VLAN names have been configured correctly on the two switches SW1
and SW2:
Inspect the VLAN table on SW1 and SW2.
SW1# show vlan brief
VLAN Name Status Ports
---- -------------------------------- --------- -----------------------------1 default active
13 VLAN0013 active Et0/0, Et0/3
65 User active Et0/1
80 Servers active Et0/2
•
VLAN 65 is "User," but it is supposed to be "Users1." Make the correction to the name
of VLAN 65.
SW1(config)# vlan 65
SW1(config-vlan)# name Users1
SW1(config-vlan)# exit
•
The VLAN for "Users2" is not named. Remedy this by naming VLAN 13 correctly.
SW1(config)# vlan 13
SW1(config-vlan)# name Users2
SW1(config-vlan)# exit
•
Inspect the VLAN table on SW2. The VLAN entries should match. Correct the name for
VLAN 13 here as well.
SW2# show vlan brief
VLAN Name Status Ports
---- -------------------------------- --------- -----------------------------1 default active Et0/0
13 VLAN0013 active
65 Users active
80 Servers active Et0/1, Et0/2
SW2(config)# vlan 13
SW2(config-vlan)# name Users2
SW2(config-vlan)# exit
•
•
Ensure that the interfaces on SW1 and SW2 that are connected to PCs and Servers are
configured correctly and are enabled.
Check the VLAN assignment of the port that is connected to PC1 on SW1.
SW1# show vlan brief
VLAN Name Status Ports
---- -------------------------------- --------- -----------------------------1 default active
13 Users2 active Et0/0, Et0/3
65 Users1 active Et0/1
80 Servers active Et0/2
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
SW1#
The port on SW1 that is connected to PC1 is correctly configured to tag the appropriate
VLAN tag.
•
Check the VLAN assignment of the port that is connected to PC2 on SW2.
SW2# show vlan brief
VLAN Name Status Ports
---- -------------------------------- --------- -----------------------------1 default active Et0/0
13 Users2 active
65 Users1 active
80 Servers active Et0/1, Et0/2
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
SW2#
The port on SW2 connecting to PC2 is configured to encapsulate traffic to the wrong
VLAN.
•
Correct the VLAN assignment configuration on the port on SW2.
SW2(config)# interface E0/1
SW2(config-if)# switchport access vlan 65
•
Check the VLAN assignment of the port that is connected to Server1 on SW1.
SW1# show run interface E0/2
interface Ethernet E0/2
switchport access vlan 80
switchport mode access
shutdown
duplex auto
end
The port is configured with VLAN parameters correctly, but it is administratively
disabled.
•
Enable the port on SW1 that is connected to Server1.
SW1(config)# interface E0/2
SW1(config-if)# no shutdown
•
Check the VLAN assignment of the port that is connected to Server2 on SW2.
SW2# show run interface E0/2
switchport access vlan 80
switchport mode access
duplex auto
end
The port on SW2 that is connected to Server2 is correctly configured with the correct
VLAN encapsulating parameters.
•
Check the VLAN assignment of the port that is connected to PC3 on SW1.
SW1# show run interface E0/0
switchport access vlan 13
switchport mode access
duplex auto
end
The port on SW1 that is connected to PC3 is correctly configured with the correct
VLAN-encapsulating parameters.
•
•
Isolate and troubleshoot the issues that are related to the trunking between SW1 and
SW2.
Inspect the E0/3 port on SW1 that is one end of the trunk.
SW1# show run interface E0/3
interface Ethernet0/3
switchport access vlan 13
switchport trunk encapsulation dot1q
switchport mode access
duplex auto
end
The port is set as an access port.
•
Remove the configuration that is related to making the port an access port and apply
the configuration making it a trunk unconditionally.
SW1(config)# interface E0/3
SW1(config-if)# no switchport access vlan 13
SW1(config-if)# no switchport mode access
SW1(config-if)# switchport mode trunk
•
Now inspect E0/3 on SW2 that is the other end of the trunk.
SW2# show run interface E0/3
interface Ethernet0/3
switchport trunk encapsulation dot1q
switchport mode trunk
duplex auto
end
•
Confirm the trunk status on both switches.
SW1# show interface trunk
Port Mode Encapsulation Status Native vlan
Et0/3 on 802.1q trunking 1
Port Vlans allowed on trunk
Et0/3 1-4094
Port Vlans allowed and active in management domain
Et0/3 1,13,65,80
Port Vlans in spanning tree forwarding state and not pruned
Et0/3 1,13,65,80
SW1#
SW2# show interface trunk
Port Mode Encapsulation Status Native vlan
Et0/3 on 802.1q trunking 1
Port Vlans allowed on trunk
Et0/3 1-4094
Port Vlans allowed and active in management domain
Et0/3 1,13,65,80
Port Vlans in spanning tree forwarding state and not pruned
Et0/3 1,13,65,80
•
Check connectivity between devices on the same VLAN. PC1 should be able to ping
PC2. Server1 should also be able to ping Server2.
Server1# ping 192.168.80.2
Sending 5, 100-byte ICMP Echo Packets to 192.168.80.2, timeout is 2 seconds
!!!!!
Success rate is 100 percent (5/5)
PC1# ping 192.168.65.2
Sending 5, 100-byte ICMP Echo Packets to 192.168.65.2, timeout is 2
seconds
!!!!!
Success rate is 100 percent (5/5)
•
PC1 and PC2 should not be able to ping Server1 and Server2 and vice versa.
Server1# ping 192.168.65.1
Sending 5, 100-byte ICMP Echo Packets to 192.168.80.2, timeout is 2 seconds
.....
Success rate is 0 percent (0/5)
PC2# ping 192.168.80.2
Sending 5, 100-byte ICMP Echo Packets to 192.168.65.2, timeout is 2 seconds
.....
Success rate is 0 percent (0/5)
Routing Between VLANs
Introduction
Enterprises typically have several departments, which are separated into different virtual
local-area networks (VLANs). VLANs are used to logically separate switch ports.
Essentially, each VLAN behaves like a separate physical switch with its own Layer 2
broadcast domain, which means broadcast frames are only switched among the ports
within the same VLAN. This behavior is important in Enterprise environments, because
the Campus network can be organized based on departments, functions, projects, or
applications. Each VLAN is also mapped to its own subnet and Layer 3 broadcast
domain.
Users and devices in different departments need to communicate as well, which means
that devices in different VLANs should be able to communicate with each other. You
can permit these devices to communicate by using a solution that is called inter-VLAN
routing. There are different options of achieving that goal depending on what kind of
network devices you use for this task.
Cisco Enterprise Architecture Model
As a network engineer, you need to enable routing between the VLANs, which means
that you need to gain skills in:
•
•
•
Understanding inter-VLAN routing cases.
Describing different inter-VLAN routing solutions.
Demonstrating basic configuration examples for some solutions.
Purpose of Inter-VLAN Routing
Each VLAN is a unique Layer 2 broadcast domain. Devices on separate VLANs are, by
default, not able to communicate. Each VLAN is usually assigned to a different Internet
Protocol (IP) subnet, which is a Layer 3 broadcast domain. You can permit these
devices to communicate by using a solution that is called inter-VLAN routing. InterVLAN communication occurs between subnets via a Layer 3 device.
VLANs have these characteristics:
•
•
•
•
A VLAN creates a separate Layer 2 broadcast domain.
Traffic cannot be switched between VLANs.
Each VLAN is mapped to a separate IP subnet.
Routing is necessary to forward traffic between VLANs.
VLANs perform network partitioning and traffic separation at Layer 2 and are usually
associated with unique IP subnets on the network, as illustrated in the figure for IP
version 4 (IPv4) subnets. This subnet configuration facilitates the routing process in a
multi-VLAN environment. Inter-VLAN communication cannot occur without a Layer 3
device. Layer 3 switches or routers perform inter-VLAN routing by either having a
separate router interface for each VLAN, or by using a trunk to carry traffic for all
VLANs. The devices on the VLANs send traffic through the router to reach other
VLANs.
Options for Inter-VLAN Routing
Inter-VLAN routing is a process of forwarding network traffic from one VLAN to another
VLAN using a Layer 3 device.
Option 1: Router with a Separate Interface in Each VLAN
Traditional inter-VLAN routing requires multiple physical interfaces on both the router
and the switch. VLANs are associated with unique IP subnets on the network. This
subnet configuration facilitates the routing process in a multi-VLAN environment. When
you use a router to facilitate inter-VLAN routing, the router interfaces are connected to
switch interfaces that are in separate VLANs. Devices on these VLANs send traffic
through the router to reach other VLANs. However, when you use a separate interface
for each VLAN on a router, you can quickly run out of interfaces. This solution is not
very scalable.
Option 2: Router on a Stick
Not all inter-VLAN routing configurations require multiple physical interfaces. Some
router software permits configuring router interfaces as trunk links. Trunk links open up
new possibilities for inter-VLAN routing. A router on a stick is a type of router
configuration in which a single physical interface routes traffic among multiple VLANs on
a network.
The figure shows a router that is attached to a switch. The router interface is configured
to operate as a trunk link and is connected to a switch port that is configured as a trunk.
The router performs inter-VLAN routing by accepting VLAN-tagged traffic on the trunk
interface coming from the adjacent switch and internally routing between the VLANs
using subinterfaces. Subinterfaces are multiple virtual interfaces that are associated
with one physical interface. To perform inter-VLAN routing functions, the router must
know how to reach all VLANs that are being interconnected; there must be a separate
logical connection on the router for each VLAN. VLAN trunking (such as Institute of
Electrical and Electronics Engineers [IEEE] 802.1Q) must be enabled on these
connections.
These subinterfaces are configured in software. Each is independently configured with
its own IP addresses and VLAN assignment. The router routes packets incoming from
one subinterface and then sends the data on another subinterface by putting it in a
VLAN-tagged frame and sending it back out the same physical interface. Devices on the
VLANs have their default gateway set to the appropriate router IP address; in this figure,
the devices in VLAN 10 will have default gateway set to 10.1.10.1, and the devices in
VLAN 20 will have default gateway set to 10.1.20.1.
Router Trunk Link Configuration Example
The following example shows how you can configure a router on a stick, by configuring
subinterfaces and trunking on the router:
Configuring subinterfaces and trunking on the router
Router(config)# interface GigabitEthernet 0/0.10
Router(config-subif)# encapsulation dot1q 10
Router(config-subif)# ip address 10.1.10.1 255.255.255.0
Router(config-subif)# interface GigabitEthernet 0/0.20
Router(config-subif)# encapsulation dot1q 20
Router(config-subif)# ip address 10.1.20.1 255.255.255.0
The commands used on the router are as follows:
Command and Variable
Description
interface interface |
subinterface
Enters interface or subinterface configuration mode
encapsulation
dot1q vlan_number
Defines the encapsulation format as IEEE 802.1Q and specifies
the VLAN identifier
ip address ip_address
network_mask
Assigns an IPv4 address and network mask to an interface
In the figure, the GigabitEthernet0/0 interface is divided into two subinterfaces—
GigabitEthernet0/0.10 and GigabitEthernet0/0.20. Each subinterface represents the
router in each of the VLANs for which it routes.
In the example, the encapsulation dot1q 20 command enables 802.1Q encapsulation
trunking on the GigabitEthernet0/0.20 subinterface. The value 20 represents the VLAN
number (or VLAN identifier), therefore associating 802.1Q-tagged traffic from this VLAN
with the subinterface.
Each 802.1Q-tagged VLAN on the trunk link requires a subinterface with 802.1Q
encapsulation trunking that is enabled in this manner. The subinterface number does
not have to be the same as the dot1q VLAN number. However, management and
troubleshooting are easier when the two numbers are the same.
In this example, devices in different VLANs use the subinterfaces of the router as
default gateways to access the devices that are connected to the other VLANs.
On the switch, assign ports to specific VLANs and configure the port toward the router
as a trunk. The trunk link will carry traffic from different VLANs, and the router will route
between these VLANs.
On the switch, assign ports to specific VLANs and configure the port toward the router
as a trunk
Switch(config)# interface FastEthernet 0/13
Switch(config-if)# switchport mode trunk
Switch(config-if)# interface FastEthernet 0/1
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 10
Switch(config-if)# interface FastEthernet 0/3
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 20
The commands used on the switch are as follows:
Command and
Variable
Description
interface interface Enters interface configuration mode.
switchport mode
trunk
Sets the interface to trunk mode.
switchport mode
access
Sets the interface to access mode.
Sets the access VLAN when the interface is in the access mode. To reset
switchport
the access-mode VLAN to the appropriate default VLAN for the switch,
accessvlan_number use the no form of this command.
Verify VLAN Subinterfaces
To verify the router configuration, use the show commands to display the VLANs and IP
routing information for each VLAN to verify that the routing table includes the subnets of
all VLANs.
Verify the VLAN subinterfaces, using the show vlans command.
Router# show vlans
<... output omitted ....>
Virtual LAN ID: 10 (IEEE 802.1Q Encapsulation)
vLAN Trunk Interface: GigabitEthernet0/0.10
Protocols Configured: Address: Received: Transmitted:
IP 10.1.10.1 11 18
<... output omitted ...>
Virtual LAN ID: 20 (IEEE 802.1Q Encapsulation)
vLAN Trunk Interface: GigabitEthernet0/0.20
Protocols Configured: Address: Received: Transmitted:
IP 10.1.20.1 11 8
<... output omitted ...>
The sample output shows two VLAN subinterfaces—GigabitEthernet0/0.10 and
GigabitEthernet0/0.20.
Verify the IPv4 routing table for the VLAN subinterfaces, using the show ip
route command.
Router# show ip route
<--- output omitted --->
Gateway of last resort is not set 10.0.0.0/8 is variably subnetted, 8
subnets, 2 masks
C 10.1.1.0/24 is directly connected, Ethernet0/0
L 10.1.10.1/32 is directly connected, GigabitEthernet0/0.10
C 10.1.10.0/24 is directly connected, GigabitEthernet0/0.10
L 10.1.20.1/32 is directly connected, GigabitEthernet0/0.20
C 10.1.20.0/24 is directly connected, GigabitEthernet0/0.20
The show ip route command displays the state of the routing table. The sample output
shows two subinterfaces. The GigabitEthernet0/0.10 and GigabitEthernet0/0.20 VLAN
subinterfaces are directly connected to the router.
Option 3: Layer 3 Switch
Some switches can perform Layer 3 functions, replacing the need for dedicated routers
to perform basic routing on a network. Layer 3 switches are capable of performing interVLAN routing. Traditionally, a switch makes forwarding decisions by looking at the
Layer 2 header, whereas a router makes forwarding decisions by looking at the Layer 3
header. A Layer 3 switch combines the functionality of a switch and a router in one
device. It switches traffic when the source and destination are in the same VLAN and
routes traffic when the source and destination are in different VLANs (that is, on
different IP subnets). To enable a Layer 3 switch to perform routing functions, you must
properly configure VLAN interfaces on the switch; these are called switch virtual
interfaces (SVIs). You must use the IP addresses that match the subnet that the VLAN
is associated with on the network. The Layer 3 switch must also have IP routing
enabled. Devices on the VLANs have their default gateway set to the appropriate Layer
3 switch IP address.
Layer 3 switching is more scalable than router on a stick because the latter can pass
only so much traffic through the trunk link. In general, a Layer 3 switch is primarily a
Layer 2 device that has been upgraded to have some routing capabilities. A router is a
Layer 3 device that can perform some switching functions. Layer 3 switches do not have
WAN interfaces, while routers do. Typically, routers also support more advanced Layer
3 features (for example, Network Address Translation, encryption, and tunneling) than
Layer 3 switches.
However, the line between switches and routers becomes hazier every day. Some
Layer 2 switches support limited Layer 3 functionality, such as static routing on SVIs, so
you can configure static routes, but routing protocols are not supported.
Following is an example configuration on the Layer 3 switch with personal computers
(PCs) that are connected to VLAN 10 and VLAN 20. PCs in VLAN 10 will have default
gateway 10.1.10.1, and PCs in VLAN 20 will have default gateway 10.1.20.1. The Layer
3 switch will perform routing between VLAN 10 and VLAN 20.
ip routing
!
interface Vlan10
ip address 10.1.10.1 255.255.255.0
no shutdown
!
interface Vlan20
ip address 10.1.20.1 255.255.255.0
no shutdown
Discovery 15: Configure a Router on a Stick
Introduction
This lab exercise will guide you through routing between VLANs. The devices are
configured as shown in the topology diagram. Currently, devices have IPv4 addresses
in the 10.10.1.0/24 or 10.10.2.0/24 subnets. You will start by migrating this configuration
to one that uses two VLANs and two physical interfaces on R1 to route between them.
You will then continue the migration to implement three VLANs and the use of trunking
on R1 to allow one physical interface to have a logical presence on multiple VLANs. In
the end, the switches will maintain their IP presence on VLAN 1, PC2 and PC4 will be
on VLAN 2, and PC1 and PC3 will move to VLAN 3. R1 will be the default gateway for
all hosts, and it will route between the VLANs. The SW1-SW2 link is configured as a
trunk, and R1 E0/0 already has IPv4 address.
Topology
Job Aids
Device Information
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today.
Personal computers (PCs) in the virtual lab environment are simulated by routers, so you
should use Cisco IOS commands to configure them or verify the configuration.
Device Information Table
Device
Characteristic
Value
R1
Ethernet0/0 IPv4 address
10.10.1.1/24
Device
Characteristic
Value
R1
Ethernet0/1 IPv4 address
N/A
R1
Loopback0 IPv4 address
10.10.99.1/24
PC1
IPv4 address
10.10.1.10/24
PC1
IPv4 default gateway
10.10.1.1
PC2
VLAN
2
PC2
IPv4 address
10.10.2.20/24
PC3
IPv4 address
10.10.1.30/24
PC3
IPv4 default gateway
10.10.1.1
PC4
VLAN
2
PC4
IPv4 address
10.10.2.40/24
SW1
VLAN 1 IPv4 address
10.10.1.4/24
SW1
IPv4 default gateway
10.10.1.1
SW2
VLAN 1 IPv4 address
10.10.1.5/24
SW2
IPv4 default gateway
10.10.1.1
Device Information Table (Changes)
Device
Characteristic
Value
R1
Ethernet0/1.2 IPv4 address
10.10.2.1/24 VLAN 2
R1
Ethernet0/1.3 IPv4 address
10.10.3.1/24 VLAN 3
PC1
VLAN
3
Device
Characteristic
Value
PC1
IPv4 address
10.10.3.10/24
PC1
IPv4 default gateway
10.10.3.1
PC2
IPv4 default gateway
10.10.2.1
PC3
VLAN
3
PC3
IPv4 address
10.10.3.30/24
PC3
IPv4 default gateway
10.10.3.1
PC4
IPv4 default gateway
10.10.2.1
Task 1: Include a Router Interface in a VLAN
Activity
Step 1
One way to implement routing between VLANs is to connect physical interfaces on
routers to switch access ports that are assigned to the appropriate VLANs. R1 already
has its Ethernet0/0 interface connected to a VLAN 1 access port (Ethernet0/1) on SW1.
In the following series of steps, you will configure a second physical connection from R1
to an access port on the switch that is in VLAN 2. Access the console of SW1 and verify
the current interface status.
Enter the following command to the SW1 switch:
SW1# show interfaces status
Port Name Status Vlan Duplex Speed Type
Et0/0 Trunk to SW2 connected trunk auto auto unknown
Et0/1 Link to R1 VLAN 1 connected 1 auto auto unknown
Et0/2 Link to R1 VLAN 2 connected 1 auto auto unknown
Et0/3 connected 1 auto auto unknown
Et1/0 Link to PC1 connected 1 auto auto unknown
Et1/1 Link to PC2 connected 2 auto auto unknown
Et1/2 connected 1 auto auto unknown
Et1/3 connected 1 auto auto unknown
R1 Ethernet0/1 is connected to SW1 Ethernet0/2. Ethernet0/2 is currently in VLAN 1.
This means that router R1 has two interfaces connected to ports that have access
VLAN set to 1. In other words, router R1 is only part of VLAN 1. Also note that Ethernet
0/0, which is connected to SW2, is a trunk, and Ethernet 1/1, which is connected to
PC2, is in VLAN 2.
Step 2
Configure SW1 Ethernet0/2 to be an access port that is assigned to VLAN 2.
Enter the following commands to the SW1 switch:
SW1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW1(config)# interface Ethernet 0/2
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 2
SW1(config-if)# end
SW1#
By assigning SW1 port E0/2 to VLAN 2, you have included the router R1 in VLAN 2. It
can now act as the default gateway for both VLANs.
Step 3
Access the R1 console, configure its Ethernet0/1 interface with IPv4 address
10.10.2.1/24, and enable the interface.
Enter the following commands to the R1 router:
R1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
R1(config)# interface Ethernet 0/1
R1(config-if)# ip address 10.10.2.1 255.255.255.0
R1(config-if)# no shutdown
R1(config-if)# end
R1#
*Oct 30 07:57:23.805: %LINK-3-UPDOWN: Interface Ethernet0/1, changed state to
up
*Oct 30 07:57:24.810: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Ethernet0/1, changed state to up
Step 4
R1 can now act as a gateway for VLAN 2. Before you configure R1 as the default
gateway for PC4, verify that PC4 belongs to the same VLAN 2. According to the
topology diagram, PC4 is connected to SW2 Ethernet 1/1 interface. Examine the VLAN
information summary on SW2 to verify interface VLAN assignment.
On SW2, enter the following command:
SW2# show vlan brief
VLAN Name Status Ports
---- -------------------------------- --------- -----------------------------1 default active Et0/1, Et0/2, Et0/3, Et1/0
Et1/2, Et1/3
2 Engineering active Et1/1
256 NoHosts active
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
The output shows that Ethernet1/1 access VLAN is set to 2. Alternatively, because
Cisco Discovery Protocol is enabled, you can use the show cdp neighbors
detail command on PC4 to view SW2 information.
PC4# show cdp neighbors detail
------------------------Device ID: SW2
Entry address(es):
IP address: 10.10.1.5
Platform: Linux Unix, Capabilities: Switch IGMP
Interface: Ethernet0/0, Port ID (outgoing port): Ethernet1/1
Holdtime : 158 sec
Version :
Cisco IOS Software, Solaris Software (I86BI_LINUXL2-ADVENTERPRISEK9-M),
Experimental Version 15.1(20130919:231344) [dstivers-sept19-2013pm-team_track
107]
Copyright (c) 1986-2013 by Cisco Systems, Inc.
Compiled Thu 19-Sep-13 22:38 by dstivers
advertisement version: 2
VTP Management Domain: ''
Native VLAN: 2
Duplex: half
Step 5
On PC4, configure router R1’s VLAN 2 IPv4 address 10.10.2.1 as the default gateway
and exit to the privileged EXEC mode.
On PC4, enter the following command:
PC4# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
PC4(config)# ip default-gateway 10.10.2.1
PC4(config)# end
PC4#
The default gateway IPv4 address and the host IPv4 address must belong to the same
subnet.
Step 6
Verify that PC4 can now reach hosts on VLAN 1 by pinging PC1 (10.10.1.10).
Enter the following command to PC4:
PC4# ping 10.10.1.10
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.10, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
Refer to the topology diagram to understand the physical path from PC4 to PC1. The
VLAN 2 path starts at PC4 and proceeds to SW2. Then, it crosses the trunk link to SW1
and continues up to the R1 Ethernet0/1 interface. R1 performs the route forwarding to
VLAN 1. It sends the packet out of its Ethernet0/0 interface back to SW1 on VLAN 1,
and then SW1 delivers the packet to PC1.
Step 7
According to the topology diagram, PC2 is also in VLAN 2. Before you configure the
default gateway on PC2, verify that it belongs to VLAN 2. All devices have Cisco
Discovery Protocol enabled. Use the information obtained by the Cisco Discovery
Protocol to verify VLAN configuration.
On PC2, enter the following command:
PC2# show cdp neighbors detail
------------------------Device ID: SW1
Entry address(es):
IP address: 10.10.1.4
Platform: Linux Unix, Capabilities: Switch IGMP
Interface: Ethernet0/0, Port ID (outgoing port): Ethernet1/1
Holdtime : 149 sec
Version :
Cisco IOS Software, Solaris Software (I86BI_LINUXL2-ADVENTERPRISEK9-M),
Experimental Version 15.1(20130919:231344) [dstivers-sept19-2013pm-team_track
107]
Copyright (c) 1986-2013 by Cisco Systems, Inc.
Compiled Thu 19-Sep-13 22:38 by dstivers
advertisement version: 2
VTP Management Domain: ''
Native VLAN: 2
Duplex: half
PC2 is already configured in VLAN 2.
Step 8
Configure the default gateway on PC2.
On PC2, enter the following command:
PC2# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
PC2(config)# ip default-gateway 10.10.2.1
PC2(config)# end
PC2#
Step 9
Verify that PC2, which is connected to VLAN 2 on SW1, can reach hosts that are
connected to VLAN 1 on SW2. Ping PC3 (10.10.1.30). The attempt should succeed.
Enter the following command to PC2:
PC2# ping 10.10.1.30
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.30, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
There is connectivity between PC2 and PC3. Consulting the topology diagram, trace the
path between PC2 and PC3. Remember that a device with the routing function must be
in the path, since PC2 and PC3 are not in the same subnets and VLANs.
At this point, successful routing exists between two VLANs using two physical interfaces
on R1.
Task 2: Configure a Router with a Trunk Link
Activity
In the next series of steps, you will add a third VLAN. You will leave the switch
management IPv4 addresses in VLAN 1, but all PCs will be distributed between VLAN 2
and VLAN 3. There are not enough physical interfaces available on R1 to connect to all
the three VLANs individually. Therefore, you need to configure one of the router R1
physical interfaces, Ethernet 0/1, as a trunk to allow it to have a logical connection to
multiple VLANs.
In this lab, only VLAN 2 and VLAN 3 will be configured on the router’s trunk interface
Ethernet 0/1. The Ethernet 0/0 interface will remain in VLAN 1. In a real environment,
you would configure all required VLANs to the trunk.
Step 1
Start by accessing the SW1 console and creating VLAN 3, assigning it the name
"Marketing," and then return to the Global Configuration mode.
On SW1, enter the following commands:
SW1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW1(config)# vlan 3
SW1(config-vlan)# name Marketing
SW1(config-vlan)# exit
Step 2
Configure the port connecting to PC1 as an access interface, and assign it to VLAN 3.
On SW1, enter the following command:
SW1(config)# interface Ethernet 1/0
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 3
SW1(config-if)# end
SW1#
Step 3
Verify the configuration of VLAN 3 on SW1.
On SW1, enter the following command:
SW1# show vlan id 3
VLAN Name Status Ports
---- -------------------------------- --------- ------------------------------
3 Marketing active Et0/0, Et1/0
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ----3 enet 100003 1500 - - - - - 0 0
Primary Secondary Type Ports
------- --------- ----------------- -----------------------------------------
The output shows two ports are in VLAN 3. Ethernet 1/0 is the access interface that you
just configured. Ethernet 0/0 is the trunk interface towards SW2, which was preconfigured for the lab. VLAN 3 is allowed on the trunk.
Step 4
Access the console of PC1 and configure its IPv4 address and default gateway. Both
addresses must belong to the same subnet, the subnet allocated for VLAN 3, which is
10.10.3.0/24. For PC1, use the IPv4 address 10.10.3.10/24. For the default gateway,
use the IPv4 address 10.10.3.1/24.
On PC1, enter the following commands:
PC1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
PC1(config)# interface Ethernet 0/0
PC1(config-if)# ip address 10.10.3.10 255.255.255.0
PC1(config-if)# exit
PC1(config)# ip default-gateway 10.10.3.1
PC1(config)# end
PC1#
Step 5
Access the console of SW2 and create VLAN 3, as you did on SW1. Assign the port
connecting PC3 as an access interface, and assign it to VLAN 3.
On SW2, enter the following commands:
SW2# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW2(config)# vlan 3
SW2(config-vlan)# name Marketing
SW2(config-vlan)# exit
SW2(config)# interface Ethernet 1/0
SW2(config-if)# switchport mode access
SW2(config-if)# switchport access vlan 3
SW2(config-if)# end
SW2#
Step 6
Verify the status of the Ethernet1/0 interface on SW2.
On SW2, enter the following command:
SW2# show interfaces Ethernet1/0 status
Port Name Status Vlan Duplex Speed Type
Et1/0 Link to PC3 connected 3 auto auto unknown
The output shows that Ethernet 1/0 interface is in VLAN 3.
Step 7
Verify the configuration of VLAN 3 on SW2.
On SW2, enter the following command:
SW2# show vlan id 3
VLAN Name Status Ports
---- -------------------------------- --------- ------------------------------
3 Marketing active Et0/0, Et1/0
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ----3 enet 100003 1500 - - - - - 0 0
Primary Secondary Type Ports
------- --------- ----------------- -----------------------------------------
The output shows two ports are in VLAN 3. Ethernet 1/0 is the access interface that you
just configured. Ethernet 0/0 is the trunk interface towards SW1, which was preconfigured for the lab. VLAN 3 is allowed on the trunk.
Step 8
Access the console of PC3 and configure its IPv4 address and default gateway. Both
addresses must belong to the same subnet, the subnet that is allocated for VLAN 3. For
PC3 use the IPv4 address 10.10.3.30/24.
On PC3, enter the following command:
PC3# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
PC3(config)# interface Ethernet 0/0
PC3(config-if)# ip address 10.10.3.30 255.255.255.0
PC3(config-if)# exit
PC3(config)# ip default-gateway 10.10.3.1
PC3(config)# end
PC3#
Note that although you configured the PC1 and PC3 with the default gateway, you have
not yet configured 10.10.3.1/24 IPv4 address on the router.
Step 9
PC3 and PC1 are now correctly configured. The switch ports that they are connected to
are assigned to VLAN 3. Verify that there is connectivity between them.
On PC3, enter the following command:
PC3# ping 10.10.3.10
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.3.10, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
Step 10
Use the R1 Ethernet0/1 to SW1 Ethernet0/2 connection as a trunk for VLANs 2 and 3.
To prepare for the trunk port configuration on R1, you must configure SW1 Ethernet0/2
as a trunk port. Only two VLANs will be configured on the interface. Configure
Ethernet0/2 on SW1 as a trunk with native VLAN 256 and 802.1Q encapsulation; VLAN
256 is already configured on SW1.
Only two VLANs will be configured on a single interface.
On SW1, enter the following commands:
SW1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW1(config)# interface Ethernet 0/2
SW1(config-if)# switchport trunk encapsulation dot1q
SW1(config-if)# switchport trunk native vlan 256
SW1(config-if)# switchport trunk allowed vlan 2,3
SW1(config-if)# switchport mode trunk
SW1(config-if)# end
SW1#
*Oct 30 09:55:41.399: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Ethernet0/2, changed state to down
*Oct 30 09:55:44.049: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Ethernet0/2, changed state to up
Note that if you do not allow specific VLANs on the trunk, the default configuration
allows all VLANs.
Step 11
Now, configure Ethernet 0/1 interface on R1 so that it connects to both VLAN 2 and
VLAN 3. First, remove the IPv4 address that is currently configured on R1 Ethernet 0/1
physical interface.
On R1, enter the following commands:
R1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
R1(config)# interface Ethernet0/1
R1(config-if)# no ip address
Step 12
To accommodate two VLANs and their two subnets, create two logical subinterfaces,
one for each VLAN, of the Ethernet 0/1 interface. First, create the logical Ethernet0/1.2
subinterface, assign it to VLAN 2, and configure it with the appropriate IPv4 address
that is given in the Device Information table.
On R1, enter the following commands:
R1(config-if)# interface Ethernet 0/1.2
R1(config-subif)# encapsulation dot1q 2
R1(config-subif)# ip address 10.10.2.1 255.255.255.0
In this example, the subinterface number (.2), the VLAN ID (2), and the third octet of the
IPv4 address (2) are all consistent with each other. This practice is common, but it is not
a technical requirement.
Step 13
Create the logical Ethernet0/1.3 subinterface, assign it to VLAN 3, and configure it with
the appropriate IPv4 address. Leave the configuration mode when you are done.
On R1, enter the following commands:
R1(config-subif)# interface Ethernet 0/1.3
R1(config-subif)# encapsulation dot1q 3
R1(config-subif)# ip address 10.10.3.1 255.255.255.0
R1(config-subif)# end
R1#
Step 14
If everything was configured successfully, R1 should have connectivity to devices in
both VLAN 2 and VLAN 3. Verify this connectivity from the router to all PCs. All
verifications should be successful.
On R1, enter the following commands:
R1# ping 10.10.3.10
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.3.10, timeout is 2 seconds:
..!!!
Success rate is 60 percent (3/5), round-trip min/avg/max = 1/1/1 ms
R1# ping 10.10.2.20
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.2.20, timeout is 2 seconds:
..!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
R1# ping 10.10.3.30
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.3.30, timeout is 2 seconds:
.!!!!
Success rate is 60 percent (3/5), round-trip min/avg/max = 1/1/1 ms
R1# ping 10.10.2.40
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.2.40, timeout is 2 seconds:
.!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
Step 15
Verify that the PCs can also reach each other. From PC1 verify connectivity to PC2.
On PC1, enter the following command:
PC1# ping 10.10.2.20
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.2.20, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
Step 16
Verify that R1 is in the path between PC1 and PC2 using the traceroute command.
On PC1, enter the following command:
PC1# traceroute 10.10.2.20
Type escape sequence to abort.
Tracing the route to 10.10.2.20
VRF info: (vrf in name/id, vrf out name/id)
1 10.10.3.1 0 msec 0 msec 0 msec
2 10.10.2.20 0 msec * 1 msec
Step 17
Also verify that PC1 can still reach the switch management IPv4 addresses that remain
in VLAN 1. Ping 10.10.1.4 and 10.10.1.5. Both attempts should succeed.
On PC1, enter the following command:
PC1# ping 10.10.1.4
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.4, timeout is 2 seconds:
!!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
PC1# ping 10.10.1.5
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.5, timeout is 2 seconds:
!!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms
Implement Multiple VLANs and Basic Routing
Between the VLANs
FASTLab 6: Implement Multiple VLANs and Basic Routing
Between the VLANs
Scenario
Read the requirements in the Scenario carefully and use the Configuration Tips to help
you do the required steps. If you need further assistance, refer to the Answer Key. Once
you have completed the configuration specified, answer the questions.
You have been working on a proof of concept (PoC) lab with Marcus, who works for the
airline company that is your customer. So far, you have only been testing VLANs and
trunks on the PoC lab. Now, Marcus wants to implement inter-VLAN routing using the
router-on-a-stick method. Router R1 is added for that purpose. Switches do not have
VLANs or trunks configured.
You need to perform these tasks:
•
•
•
•
Implement the VLAN assignments on switches SW1 and SW2 as per topology and Job
Aid.
Configure an IEEE 802.1Q trunk between switches SW1 and SW2.
Configure an IEEE 802.1Q trunk between switch SW1 and router R1. Use the interface
labeling and IPv4 addresses provided in the Job Aid.
Verify that there is connectivity among the servers and PCs in the lab. Verify that router
R1 is included in the path of the communication between devices from different VLANs.
Topology
Job Aids
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today.
Personal computers (PCs) in the virtual lab environment are simulated by routers, so you
should use Cisco IOS commands to configure them or verify the configuration.
Device Information
Device
Interface
IPv4 Address
Remote
Interface
VLAN
R1
E0/0.65
192.168.65.254/24
SW1
E0/0
Trunk
R1
E0/0.80
192.168.80.254/24
SW1
E0/0
Trunk
PC1
E0/0
192.168.65.1/24
SW1
E0/1
65
Device
Interface
IPv4 Address
Remote
Interface
VLAN
Server1
E0/0
192.168.80.1/24
SW1
E0/2
80
PC2
E0/0
192.168.65.2/24
SW2
E0/1
65
Server2
E0/0
192.168.80.2/24
SW2
E0/2
80
SW1
E0/3
Trunk
SW2
E0/3
Trunk
VLAN Name Information
VLAN
Name
65
Users
80
Servers
Configuration Tips
•
•
•
•
•
Ensure that both switches have the same VLAN numbers and names, so that traffic
from one switch can connect through the trunk to ports on the other switch.
On switches, use the switchport trunk encapsulation dot1q command to specify the
type of trunk encapsulation before configuring a port as a trunk.
Use the encapsulation dot1q vlan vlan-id command to configure router subinterfaces
to use 802.1Q encapsulation.
Ensure that the router R1 subinterfaces are configured with appropriate IPv4 addresses
and corresponding VLANs.
Use ping and traceroute commands to verify the connectivity.
Answer Key
You need to complete the following tasks:
•
•
Implement the VLAN assignments on switches SW1 and SW2 as per topology and Job
Aid.
Use the configuration commands that are shown below to add the VLANs on switch
SW1.
SW1(config)# vlan 65
SW1(config-vlan)# name Users
SW1(config-vlan)# vlan 80
SW1(config-vlan)# name Servers
SW1(config-vlan)# exit
•
Use the configuration commands that are shown below to add the VLANs on switch
SW2.
SW2(config)# vlan 65
SW2(config-vlan)# name Users
SW2(config-vlan)# vlan 80
SW2(config-vlan)# name Servers
SW2(config-vlan)# exit
•
Use the configuration commands that are shown below to configure the VLAN
assignment of the port connected to PC1.
SW1(config)# interface E0/1
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 65
•
Use the configuration commands that are shown below to configure the VLAN
assignment of the port connected to PC2.
SW2(config)# interface E0/1
SW2(config-if)# switchport mode access
SW2(config-if)# switchport access vlan 65
•
Use the configuration commands that are shown below to configure the VLAN
assignment of the port connected to Server 1.
SW1(config)# interface E0/2
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 80
•
Use the configuration commands that are shown below to configure the VLAN
assignment of the port connected to Server 2.
SW2(config)# interface E0/2
SW2(config-if)# switchport mode access
SW2(config-if)# switchport access vlan 80
•
•
Configure an IEEE 802.1Q trunk between switches SW1 and SW2.
Use the commands that are shown below to implement the trunk configuration on
interface E0/3 of switch SW1.
SW1(config)# interface E0/3
SW1(config-if)# switchport trunk encapsulation dot1q
SW1(config-if)# switchport mode trunk
•
Use the commands that are shown below to implement trunk configuration on interface
E0/3 of switch SW2.
SW2(config)# interface E0/3
SW2(config-if)# switchport trunk encapsulation dot1q
SW2(config-if)# switchport mode trunk
•
•
Configure an IEEE 802.1Q trunk between switch SW1 and router R1. Use the interface
labeling and IPv4 addresses provided in the Job Aid.
Use the commands that are shown below to implement trunk configuration on interface
E0/0 of switch SW1.
SW1(config)# interface E0/0
SW1(config-if)# switchport trunk encapsulation dot1q
SW1(config-if)# switchport mode trunk
•
Use the commands that are shown below to configure the subinterface on router R1 for
VLAN 65 and use 802.1Q trunk encapsulation.
R1(config)# interface 0/0.65
R1(config-subif)# encapsulation dot1q 65
R1(config-subif)# ip address 192.168.65.254 255.255.255.0
R1(config-subif)#
•
Use the commands that are shown below to configure the subinterface on router R1 for
VLAN 80 and use 802.1Q trunk encapsulation.
R1(config)# interface e0/0.80
R1(config-subif)# encapsulation dot1q 80
R1(config-subif)# ip address 192.168.80.254 255.255.255.0
•
•
Verify that there is connectivity among the servers and PCs in the lab. Verify that router
R1 is included in the path of the communication between devices from different VLANs.
Verify that the status of the trunk between switches SW1 and SW2 is up and working.
SW1# show interface trunk
Port Mode Encapsulation Status Native vlan
Et0/3 on 802.1q trunking 1
Port Vlans allowed on trunk
Et0/3 1-4094
Port Vlans allowed and active in management domain
Et0/3 1,65,80
Port Vlans in spanning tree forwarding state and not pruned
Et0/3 1
SW2# show interface trunk
Port Mode Encapsulation Status Native vlan
Et0/3 on 802.1q trunking 1
Port Vlans allowed on trunk
Et0/3 1-4094
Port Vlans allowed and active in management domain
Et0/3 1,65,80
Port Vlans in spanning tree forwarding state and not pruned
Et0/3 1
•
Verify connectivity between devices on the same VLAN on different switches.
Server1# ping 192.168.80.2
Sending 5, 100-byte ICMP Echo Packets to 192.168.80.2, timeout is 2 seconds
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
PC1# ping 192.168.65.2
Sending 5, 100-byte ICMP Echo Packets to 192.168.65.2, timeout is 2 seconds
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
•
Verify that the router-on-a-stick configuration is working by checking connectivity
between devices on the different VLANs. Verify using the show running-configuration
interface command and ping responses from devices on the different VLANs.
R1# show running-config interface e0/0.65
Building configuration...
Current configuration : 97 bytes
!
interface Ethernet0/0.65
encapsulation dot1q 65
ip address 192.168.65.254 255.255.255.0
end
R1# show running-config interface e0/0.80
Building configuration...
Current configuration : 97 bytes
!
interface Ethernet0/0.80
encapsulation dot1q 80
ip address 192.168.80.254 255.255.255.0
end
Server1# ping 192.168.65.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.65.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/2 ms
Server1#
PC1# ping 192.168.80.2
Sending 5, 100-byte ICMP Echo Packets to 192.168.80.2, timeout is 2
seconds
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
•
Check the connectivity between the server VLAN and the router VLAN.
Introducing OSPF
Introduction
In larger networks encompassing many buildings with endpoints, branches, and remote
sites, all implementing different Virtual Local Area Networks (VLANs), efficient routing is
crucial for network performance. But in such a large environment, changes are frequent
as new networks emerge, paths change, or different configuration or interface issues
occur. Thus, the network has to be able to quickly and automatically adapt to changes.
Relying on static routing could result in waiting for a long time as the network
administrators implement the necessary configuration changes. This is where the role of
routing protocols becomes crucial.
The objective of routing protocols is to exchange network reachability information
between routers and dynamically adapt to network changes. These protocols use
routing algorithms to determine the optimal path between different segments in the
network, and update routing tables with the best paths. Dynamic routing protocols play
an important role in enterprise networks. There are several different protocols available,
with each having its advantages and limitations. Convergence time, support for
summarization, and the ability to scale, affect the choice of suitable routing protocols. It
is best practice that you use one routing protocol throughout the enterprise, if possible.
In the enterprise campus, the routing protocol must support high-availability
requirements and provide very fast convergence. One of the most common Internet
Protocol (IP) routing protocols in such environments is Open Shortest Path First
(OSPF), an open standard protocol that works as an interior gateway protocol (IGP) at
the corporate office and at all the branches. Despite its relatively simple configuration in
small and medium networks, OSPF implementation and troubleshooting in large-scale
networks may represent a real challenge, therefore a good understanding of basic
OSPF concepts is vital.
Cisco Enterprise Architecture Model
As a networking engineer, you will encounter routing protocols when designing,
configuring, and troubleshooting networks. If the protocol used is OSPF, you will need
knowledge of various aspects of OSPF, such as:
•
•
•
•
A solid understanding of OSPF functions
Familiarity with OSPF packet types, and the link-state database (LSDB)
The process of OSPF neighbor establishment
Configuring and verifying basic OSPF implementation
Dynamic Routing Protocols
A routing protocol is a set of processes, algorithms, and messages that are used to
exchange routing information. Routing information is used to populate the routing table
with the best paths to destinations in the network. As routers learn of changes to
network reachability, this information is dynamically passed onto other routers.
A dynamic routing protocol has these purposes:
•
•
•
•
Discovering remote networks
Maintaining up-to-date routing information
Choosing the best path to destination networks
Finding a new best path if the current path is no longer available
All routing protocols have the same purpose: to learn about remote networks and to
quickly adapt whenever there is a change in the topology. The method that a routing
protocol uses to accomplish this purpose depends upon the algorithm that it uses and
the operational characteristics of the protocol. The operations of a dynamic routing
protocol vary, depending on the type of routing protocol, and on the routing protocol
itself.
Although routing protocols provide routers with up-to-date routing tables, they put
additional demands on the memory and processing power of the router. First, the
exchange of route information adds overhead that consumes network bandwidth. Even
though this is almost never an issue in the networks today, in rare cases this overhead
might be a problem, particularly where low-bandwidth links are used between routers.
Second, after the router receives the route information, protocols such as Enhanced
Interior Gateway Routing Protocol (EIGRP) and OSPF process it extensively to offer
information to the routing table. So, the routers that use these protocols must have
sufficient processing capacity to implement the algorithms of the protocol and to perform
timely packet routing and forwarding.
An autonomous system (AS), otherwise known as a routing domain, is a collection of
routers under a common administration, such as an internal company network or an
Internet service provider (ISP) network. Because the internet is based on the AS
concept, the following two types of routing protocols are required:
•
•
IGP: An IGP routing protocol is used to exchange routing information within an AS.
EIGRP, Intermediate System-to-Intermediate System (IS-IS), OSPF, and the legacy
routing protocol, Routing Information Protocol (RIP) are examples of IGPs for IP version
4 (IPv4).
EGP: An Exterior Gateway Protocol (EGP) routing protocol is used to route between
autonomous systems. Border Gateway Protocol (BGP) is the EGP used today for IPv4.
Within an AS, most IGP routing can be classified as distance vector or link-state routing:
•
•
Distance vector: The distance vector routing approach determines the direction
(vector) and distance (such as router hops) to any link in the internetwork. Some
distance vector protocols periodically send complete routing tables to all connected
neighbors. In large networks, these routing updates can become very large, causing
significant traffic on the links. The only information that a router knows about a remote
network is the distance or metric to reach this network and the path or interface to use
to get there. Distance vector routing protocols do not have an actual map of the network
topology. RIP is an example of a distance vector routing protocol while EIGRP is an
advanced distance vector routing protocol that provides additional functionality.
Link state: The link-state approach, which uses the shortest path first (SPF) algorithm,
creates an abstract of the exact topology of the entire internetwork, or at least of the
partition in which the router is situated. A link-state routing protocol is like having a
complete map of the network topology. A link-state router uses the link-state information
to create a topology map and to select the best path to all destination networks in the
topology. The OSPF and IS-IS protocols are examples of link-state routing protocols.
Routing protocols can also be classified as classful or classless:
•
Classless routing protocol: RIP version 2 (RIPv2), EIGRP, OSPF, IS-IS and BGP are
classless routing protocols and can be considered second-generation protocols
because they are designed to address the limitations of classful routing protocols. A
classless routing protocol is a protocol that advertises subnet mask information in the
routing updates for the networks advertised to neighbors. As a result, this feature
enables the protocols to support discontiguous networks (where subnets of the same
major network are separated by a different major network) and Variable Length Subnet
Masking (VLSM). This allows the routers to exchange routing information for subnets
(such as 10.1.1.0/24) as well as for major networks (for example, 10.0.0.0/8). In the
following figure, when routers R1 and R3 send routing advertisements to router R2, they
include the subnet mask in the updates (10.1.1.0/24 and 10.2.2.0/24), so R2 learns
about those specific subnets.
•
Classful routing protocol: Classful routing protocols such as RIP version 1 (RIPv1)
and Interior Gateway Routing Protocol (IGRP) are legacy protocols and not used today.
They do not advertise the subnet mask information within the routing updates.
Therefore, only one subnet mask can be used within a major network; thus VLSM and
discontiguous networks are not supported.
The concept of route summarization plays a really important role when using dynamic
routing protocols, because it optimizes the number of routing updates exchanged
between the routers in the routing domain. The purpose of route summarization is to
aggregate multiple routes into one route advertisement. For example, if Router A knows
about all of the subnets 10.1.0.0/24, 10.1.1.0/24, 10.1.2.0/24 and so on all the way up to
10.1.255.0/24, then instead of sending all of these routes to its neighbors, you could
configure it to send the summary route 10.1.0.0/16. In this case, Router A is telling its
neighbors that it knows how to get to all networks that have the same first 16 bits as
10.1.0.0, in other words that start with “10.1”.
All classless routing protocols support manual route summarization. Some of these
protocols have autosummarization at the major network boundary, to the classful
network address, on by default. For example, assume Router A has autosummarization
on and it knows about all of the subnets 10.1.0.0/24, 10.1.1.0/24, 10.1.2.0/24 and so on
all the way up to 10.1.255.0/24. In this case Router A would automatically send the
10.0.0.0/8 route to any of its neighbors that are in another major network.
This automatic summarization of a classless routing protocol like EIGRP can be a
problem if your subnets are discontiguous, meaning the 10.1.x.x subnets are separated
from the 10.2.x.x subnets by a different classful network such as 172.16.0.0. To stop
this from happening, automatic route summarization must be disabled with the no autosummary command under EIGRP. The subnets could then be manually summarized
with the /16 mask. Remember, the automatic summarization would not even occur if all
subnets are in the 10.0.0.0 network.
OSPF does not know the concept of autosummarization; hence, you must manually
summarize the routes that should be advertised to neighbor routers, otherwise all
subnets will be sent separately and may result in large routing tables in the receiving
routers. As of IOS release 15, EIGRP does not have autosummarization on by default;
in older IOS versions autosummarization was on by default. EIGRP’s
autosummarization feature can be disabled by using the no auto-summary command.
Classful routing protocols do not support manual route summarization and perform only
autosummarization.
Path Selection
The router determines the best path to the destination network by evaluating multiple
available paths and choosing the optimal one to reach that network. If you want to
control the choice of the best path to the network, you need to statically configure a
route. When the router uses dynamic routing protocols it chooses the best path by
evaluating a value called metric, which quantifies the path to the destination network.
(You will sometimes see the metric referred to as distance.) A dynamic routing
protocol’s best path to a network is the path with the lowest metric. Dynamic routing
protocols use their own rules and metrics. Each dynamic protocol offers its best path (its
lowest metric route) to the routing table.
In an enterprise network, it is not uncommon to encounter multiple dynamic routing
protocols and static routes configured. If this occurs, the routing table may have more
than one route source (a connected route, a static route, and a dynamic route) for the
same destination network. Cisco IOS Software uses the administrative distance to
determine the route to install into the IP routing table. The administrative distance
represents the "trustworthiness" of the source of the route; the lower the administrative
distance, the more trustworthy the route source. For example, a static route has a
default administrative distance of 1, whereas an OSPF-learned route has a default
administrative distance of 110. Given separate routes to the same destination with
different administrative distances, the router chooses the route with the lowest
administrative distance. Administrative distance is used as a tie breaker only when
different sources offer the information for the same destination network, i.e. the same
network address and subnet mask.
The administrative distance is an integer from 0 to 255. A routing protocol with a lower
administrative distance is considered more trustworthy than one with a higher
administrative distance.
In the figure, the router has received two routing update messages—one from OSPF
and one from EIGRP. The metric that EIGRP uses has determined that the best path to
network 172.17.8.0/24 is via 192.168.5.2, but the metric that OSPF uses has
determined that the best path to 172.17.8.0/24 is via 192.168.3.1. Each routing protocol
uses a different metric to calculate the best path to a given destination, if it learns
multiple paths to the same destination.
The router has used the administrative distance feature to determine which route to
install in its routing table. Because the administrative distance for OSPF is 110 and the
administrative distance for EIGRP is 90, the router has chosen the EIGRP route and
adds only the EIGRP route to its routing table.
The default administrative distances can be tuned for each routing protocol.
The table shows the default administrative distance for selected routing information
sources.
Route Source
Default Administrative Distance
Connected interface (and static routes via interface)
0
Static route (via next hop address)
1
External Border Gateway Protocol (EBGP)
20
EIGRP
90
OSPF
110
IS-IS
115
RIP
120
External EIGRP
170
Internal Border Gateway Protocol (IBGP)
200
Unreachable
255 (will not be used to pass traffic)
Link-State Routing Protocol Overview
As mentioned, the two basic types of routing protocols are distance vector and link
state. OSPF is an example of a link-state routing protocol.
Although most routing protocols belong to these two types, the Cisco proprietary EIGRP
routing protocol is an exception and is considered as an advanced distance vector
protocol. The reason for that is, because it contains some properties of distance vector
and some properties of link state protocols. Despite the fact that it is based on the
architecture of the distance vector protocols, some of the implemented link state
features play a key role in the protocol behavior. For example, EIGRP uses Hello
packets to discover neighbors, multiple parameters are included in the metric (value)
calculation for the routes, it uses incremental updates, and so on.
Link-state routing protocols such as OSPF have several advantages when compared to
traditional distance vector routing protocols:
•
•
•
•
•
Link-state protocols are more scalable.
Each router has a full map of the topology.
Updates are sent when a topology change occurs and are reflooded periodically.
Link-state protocols respond quickly to topology changes.
More information is communicated between the routers.
When a failure occurs in a network, routing protocols should detect the failure as soon
as possible and find another path across the network. Link-state protocols support fast
convergence with support for scalability and multivendor environments, so they are the
usual type of IGP that is found in large network environments. (As noted, EIGRP can
also be used in large networks, and one of the benefits it offers is the fast convergence
time).
The link-state protocols consist of the following key features:
•
•
•
•
•
They are scalable: Link-state protocols use a hierarchical design and can scale to very
large networks, if properly designed.
Each router has a full map of the topology: Because each router contains full
information about the routers and links in a network, each router is able to
independently select a loop-free and efficient pathway, which is based on cost, to reach
every neighbor in the network.
Updates are sent when a topology change occurs and are reflooded
periodically: Link-state protocols send updates of a topology change by using triggered
updates. Also, updates are sent periodically—by default every 30 minutes.
They respond quickly to topology changes: Link-state protocols establish neighbor
relationships with the adjacent routers. The failure of a neighbor is detected quickly, and
this failure is communicated by using triggered updates to all routers in the network.
This immediate reporting generally leads to fast convergence times.
More information is communicated between routers: Routers that run a link-state
protocol have a common view on the network. Each router has full information about
other routers and links between them, including the metric on each link.
Link-State Routing Protocol Data Structures
A router that runs a link-state routing protocol must first establish a neighbor adjacency
with its neighboring routers. A router achieves this neighbor adjacency by exchanging
hello packets with the neighboring routers. After neighbor adjacency is established, the
neighbor is put into the neighbor database.
In the example, router A recognizes routers B and D as neighbors.
After a neighbor relationship is established between routers, the routers synchronize
their LSDBs (also known as topology databases or topology tables) by reliably
exchanging link-state advertisements (LSAs). An LSA describes a router and the
networks that are connected to the router. LSAs are stored in the LSDB. By exchanging
all LSAs, routers learn the complete topology of the network. Each router will have the
same topology database within an area, which is a logical collection of OSPF networks,
routers, and links that have the same area identification within the autonomous system.
After the topology database is built, each router applies the SPF algorithm to the LSDB
in that area. The SPF algorithm uses the Dijkstra algorithm to calculate the best (also
called the shortest) path to each destination.
The best paths to destinations are then offered to the routing table. The routing table
includes a destination network and the next-hop IP address. In the example, the routing
table on router A states that a packet should be sent to router D to reach network X.
Introducing OSPF
OSPF is a link-state routing protocol. You can think of a link as an interface on a router.
The state of the link is a description of that interface and of its relationship to its
neighboring routers. A description of the interface would include, for example, the IP
address of the interface, the subnet mask, the type of network to which it is connected,
the routers that are connected to that network, and so on. The collection of all these link
states forms a LSDB. All routers in the same area share the same LSDB. Routers in
other OSPF areas will have different LSDBs.
OSPF was developed based on an open standard and is supported by several router
manufacturers. OSPF is widely used as an IGP, especially in large network
environments. OSPF was developed as a replacement for the distance vector routing
protocol RIP. The major advantages of OSPF over RIP are its fast convergence and its
ability to scale to much larger networks. The OSPF for IPv4 networks is OSPF version 2
(OSPFv2).
With OSPF, an AS can be logically subdivided into multiple areas.
OSPF uses a two-layer network hierarchy that has two primary elements:
•
•
AS: An AS consists of a collection of networks under a common administration that
share a common routing strategy. An AS, which is sometimes called a domain, can be
logically subdivided into multiple areas.
Area: An area is a grouping of contiguous networks. Areas are logical subdivisions of
the AS.
Within each AS, a contiguous area 0 (backbone area) must be defined. In the multiarea
design, all other nonbackbone areas are connected to the backbone area.
A multiarea design is more effective because the network is segmented to limit the
propagation of LSAs inside an area. It is especially useful for large networks.
In a multiarea topology, there are some special commonly used OSPF terms, based on
the OSPF router roles. Routers that are only in Area 0 are known as backbone routers.
Routers that are only in nonbackbone (normal) areas are known as internal routers;
they have all interfaces in one area only. An area border router (ABR) connects Area 0
to the nonbackbone areas. ABRs contain LSDB information for each area, make route
calculations for each area, and advertise routing information between areas. An AS
boundary router (ASBR) is a router that has at least one of its interfaces connected to
an OSPF area and at least one of its interfaces connected to an external non-OSPF
domain, such as EIGRP routing domain.
The optimal number of routers per area varies based on factors such as network stability,
but the general recommendation is to have no more than 50 routers per single area.
In a single area OSPF, whenever there is a change in a topology, new LSAs are
created and sent throughout the area. All routers change their LSDB when they receive
the new LSA, and the SPF algorithm is run again on the updated LSDB to verify new
paths to destinations within the area.
The OSPF dynamic routing protocol does the following:
•
•
•
•
Creates a neighbor relationship by exchanging hello packets
Propagates LSAs rather than routing table updates:
Link: Router interface
State: Description of an interface and its relationship to neighboring routers
•
•
•
Floods LSAs to all OSPF routers in the area, not just to the directly connected routers
Pieces together all the LSAs that OSPF routers generate to create the OSPF LSDB
Uses the SPF algorithm to calculate the shortest path to each destination and places it
in the routing table
A router sends LSA packets immediately to advertise its state when there are state
changes. Moreover, the router resends (floods) its own LSAs every 30 minutes by
default as a periodic update. The information about the attached interfaces, the metrics
that are used, and other variables are included in OSPF LSAs. As OSPF routers
accumulate link-state information, they use the SPF algorithm to calculate the shortest
path to each network.
Essentially, an LSDB is an overall map of the networks in relation to the routers. It
contains the collection of LSAs that all routers in the same area have sent. Because the
routers within the same area share the same information, they have identical topological
databases.
Establishing OSPF Neighbor Adjacencies
Neighbor OSPF routers must recognize each other on the network before they can
share information because OSPF routing depends on the status of the link between two
routers. The Hello protocol completes this process. OSPF routers send hello packets on
all OSPF-enabled interfaces to determine if there are any neighbors on those links.
The Hello protocol establishes and maintains neighbor relationships by ensuring
bidirectional (two-way) communication between neighbors.
•
•
•
OSPF routers first establish neighbor adjacencies.
Hello packets are periodically sent to the all OSPF routers IPv4 address 224.0.0.5.
Routers must agree on certain information (*) inside the hello packet before adjacency
can be established.
An OSPF neighbor relationship, or adjacency, is formed between two routers if they
both agree on the area ID, hello and dead intervals, authentication, and stub area flag.
Of course, the routers must also be on the same IPv4 subnet. Bidirectional
communication occurs when a router recognizes itself in the neighbors list in the hello
packet that it receives from a neighbor.
Each interface that participates in OSPF uses the all OSPF routers multicast address
224.0.0.5 to periodically send hello packets. A hello packet contains the following
information:
•
•
•
•
•
•
•
•
Router ID: The router ID is a 32-bit number that uniquely identifies the router; it must be
unique on each router in the network. The router ID is, by default, the highest IPv4
address on a loopback interface, if there is one configured. If a loopback interface with
an IPv4 address is not configured, the router ID is the highest IPv4 address on any
active interface. You can also manually configure the router ID by using the routerid command. Even though using a loopback IPv4 address is better approach than using
a physical IPv4 address for a router ID, it is highly recommended to manually set the
router ID. In this way, the router ID is stable and will not change, for example if an
interface goes down.
Hello and dead intervals: The hello interval specifies the frequency in seconds at
which a router sends hello packets to its OSPF neighbors. The default hello interval on
broadcast and point-to-point links is 10 seconds. The dead interval is the time in
seconds that a router waits to hear from a neighbor before declaring the neighboring
router out of service. By default, the dead interval is four times the hello interval. These
timers must be the same on neighboring routers; otherwise, an adjacency will not be
established.
Neighbors: The Neighbors field lists the adjacent routers from which the router has
received a hello packet. Bidirectional communication occurs when the router recognizes
itself in the Neighbors field of the hello packet from the neighbor.
Area ID: To communicate, two routers must share a common segment and their
interfaces must belong to the same OSPF area on this segment. The neighbors must
also be on the same subnet (with the same subnet mask). These routers in the same
area will all have the same LSDB information for that area.
Router priority: The router priority is an 8-bit number. OSPF uses the priority to select
a designated router (DR) and backup designated router (BDR). In certain types of
networks, OSPF elects DRs and BDRs. The DR acts as a central exchange point to
reduce traffic between routers.
DR and BDR IPv4 addresses: These addresses are the IPv4 addresses of the DR and
BDR for the specific network, if they are known.
Authentication data: If router authentication is enabled, two routers must exchange the
same authentication data. Authentication is not required, but if it is enabled, all peer
routers must have the same key configured.
Stub area flag: A stub area is a special area. Designating a stub area is a technique
that reduces routing updates by replacing them with a default route. Two routers have to
agree on the stub area flag in the hello packets to become neighbors.
OSPF routers do establish a neighbor relationship over point-to-point links:
•
•
•
Commonly a serial interface running either Point-to-Point Protocol (PPP) or High-Level
Data Link Control (HDLC)
May also be a point-to-point subinterface running Frame Relay or ATM
Does not require DR or BDR election
A point-to-point network joins a single pair of routers. A serial line that is configured with
a data link layer protocol such as PPP or HDLC is an example of a point-to-point
network. On these types of networks, the router dynamically detects its neighboring
routers by multicasting its hello packets to all OSPF routers, using the 224.0.0.5
address. On point-to-point networks, neighboring routers become adjacent whenever
they can communicate directly. No DR or BDR election is performed; there can be only
two routers on a point-to-point link, so there is no need for a DR or BDR. The default
OSPF hello and dead timers on point-to-point links are 10 seconds and 40 seconds,
respectively.
OSPF Neighbor States
When routers that run OSPF are initialized, an exchange process occurs, with the Hello
protocol as the first procedure.
OSPF routers go through different OSPF states:
The figure illustrates the exchange process that happens when routers appear on the
network:
1. A router interface is enabled on the network. The OSPF process is in a down state
because the router has not yet exchanged information with any other router. The router
begins by sending a hello packet out the OSPF-enabled interface, although it does not
know the identity of any other routers.
2. All directly connected routers that are running OSPF receive the hello packet from the
first router and add the router to their lists of neighbors. After adding the router to the
list, other routers are in the initial state (INIT state).
3. Each router that received the hello packet sends a unicast reply hello packet to the first
router with its corresponding information. The Neighbors field in the hello packet lists all
neighboring routers, including the first router.
4. When the first router receives the hello packets from the neighboring routers containing
its own router ID inside the list of neighbors, it adds the neighboring routers to its own
neighbor relationship database. After recognizing itself in the neighbor list, the first
router goes into two-way state with those neighbors. At this point, all routers that have
each other in their lists of neighbors have established a bidirectional (two way)
communication. When routers are in two-way state, they must decide whether to
proceed in building an adjacency or staying in the current state.
If the link type is a multiaccess broadcast network (for example, an Ethernet local area
network [LAN]), a DR and BDR must first be selected. The DR acts as a central
exchange point for routing information to reduce the amount of routing information that
the routers have to exchange. The DR and BDR are selected after routers are in the
two-way state. Note that the DR and BDR is per LAN, not per area. The router with the
highest priority becomes the DR, and the router with the second highest priority
becomes the BDR. If there is a tie, the router with the highest router ID becomes the
DR, and the router with the second highest router ID becomes the BDR. Among the
routers on a LAN that are not elected as the DR or BDR, the exchange process stops at
this point, and the routers remain in the two-way state. Routers then communicate only
with the DR (or BDR) by using the OSPF DR multicast IPv4 address 224.0.0.6. The DR
uses the 224.0.0.5 multicast IPv4 address to communicate with all other non-DR
routers. On point-to-point links, there is no DR/BDR election, because only two routers
can be connected on a single point-to-point segment, and there is no need for using DR
or BDR.
After the DR and BDR are selected, the routers are considered to be in the exstart
state. The routers are then ready to discover the link-state information about the
internetwork and create their LSDBs. The exchange protocol is used to discover the
network routes, and it brings all the routers from the exchange state to a full state of
communication with the DR and BDR.
As shown in the figure, the exchange protocol continues as follows:
1. In the exstart state a Master/Slave relationship is created between each router and its
adjacent DR and BDR. The router with the higher router ID acts as the master during
the exchange process. The Master/Slave election dictates which router will start the
exchange of routing information. This step is not shown in the figure.
2. The Master/Slave routers exchange one or more database description (DBD) packets,
containing a summary of their LSDB. The routers are in the exchange state.
3. A router compares the DBD that it received with the LSAs that it has. If the DBD has a
more up-to-date link-state entry, the router sends a link-state request (LSR) to the other
router. When routers start sending LSRs, they are in the loading state.
4. The router sends a link state update (LSU), containing the entries requested in the LSR.
This is acknowledged with a link state acknowledgment (LSAck). When all LSRs have
been satisfied for a given router, the adjacent routers are considered synchronized and
are in the full state.
All states except two-way and full are transitory, and routers should not remain in these
states for extended periods of time.
SPF Algorithm
A metric is an indication of the overhead that is required to send packets across a
certain interface. OSPF uses cost as a metric. A smaller cost indicates a better path
than a higher cost. By default on Cisco devices, the cost of an interface is inversely
proportional to the bandwidth of this interface, so a higher bandwidth indicates a lower
cost. For example, there is more overhead, a higher cost, and more time delays that are
involved in crossing a 10-Mbps Ethernet line than in crossing a 100-Mbps Ethernet line.
On Cisco devices, the formula used to calculate OSPF cost is cost = reference
bandwidth / interface bandwidth (in bits per second).
The default reference bandwidth is 108, which is 100,000,000, or the equivalent of the
bandwidth of Fast Ethernet. Therefore, the default cost of a 10-Mbps Ethernet link will
be 108 / 107 = 10, and the cost of a 100-Mbps link will be 108 / 108 = 1. The problem
arises with links that are faster than 100 Mbps. Because the OSPF cost has to be an
integer, all links that are faster than Fast Ethernet will have an OSPF cost of 1.
There are three approaches you can take to influence the cost to be more realistic,
especially on high-speed links:
•
•
Reference bandwidth: You can set the reference bandwidth on the router globally to
provide granular link costs.
To adjust the reference bandwidth for a link, use the ospf auto-cost referencebandwidth reference-bandwidth command that is configured in the OSPF routing
process configuration mode.
•
•
Interface cost: You can choose to use arbitrary cost numbers on every interface.
To override the cost that is calculated for an interface for the OSPF routing process, use
the ip ospf cost cost interface configuration command.
•
Interface bandwidth: You can configure the bandwidth kilobits-per-second command
on an interface to override the default bandwidth.
Whether you choose the reference bandwidth method, interface cost method, or interface
bandwidth method for adjusting OSPF link costs, it is imperative that you consistently
configure adjustments on every router in the OSPF network. Inconsistent application of
OSPF link costs can lead to suboptimal path selection.
The cost to reach a distant network from a router is the cumulative cost of all links on
the path from the router to the network. In the example, the cost from R1 to the
destination network via R3 is 40 (20 + 10 + 10), and the cost via R2 is 30 (10 + 10 +
10). The path via R2 is better because it has a lower cost.
The figure represents the R1 view of the network, where R1 is the root and calculates
the pathways by assuming this view.
Each router has its own view of the topology, even though all the routers build the
shortest path trees by using the same LSDB.
Each router places itself as the root of a tree and then runs the SPF algorithm. The path
calculation is based on the cumulative cost that is required to reach that destination.
LSAs are flooded throughout the area by using a reliable algorithm, which ensures that
all the routers in an area have the same LSDB (topological database). Because of the
flooding process, R1 has learned the link-state information for each router in its area.
Each router uses the information in its topological database to calculate a shortest path
tree, with itself as the root. The router then uses this tree to determine the best routes,
which are offered to the routing table to route network traffic.
R1 SPF Tree
Destination
Shortest Path
Cost
R2 LAN
R1 to R2
14
R3 LAN
R1 to R3
22
R4 LAN
R1 to R2 to R4
30
For R1, the best path to each LAN and its cost are shown in the table. Note that in
terms of number of hops (routers) to reach the destination, the shortest path might not
necessarily be the best one, because the selection of the best route is based on the
lowest total cost value from the available paths. Each router has its own view of the
topology, even though the routers build shortest path trees by using the same LSDB.
Building a Link-State Database
When two routers discover each other and establish adjacency by using hello packets,
they use the exchange protocol to exchange information about the LSAs.
OSPF uses five types of routing protocol packets, from which four types of OSPF
packets are involved in building the LSDB.
Packet
Type Name Description
1
Hello
The hello packet discovers and maintains neighbors.
2
DBD
The DBD packets describe the summary of the LSDB and contain the LSA
headers that help routers build the LSDB.
3
LSR
After DBD packets are exchanged, each router checks the LSA headers against
its own database. If it does not have current information for any LSA, it
generates an LSR packet and sends it to its neighbor to request updated LSAs.
4
LSU
The LSU packets contain the requested LSAs that should be updated. This
packet is often used in flooding.
5
LSAck packets help to ensure a reliable transmission of OSPF packets. Each
LSAck DBD, LSR and LSU is explicitly acknowledged.
As shown in the table, the exchange protocol operates as follows:
1. The routers exchange one or more DBD packets. A DBD includes information about the
LSA entry header that appears in the LSDB of the router. Each LSA entry header
includes information about the link-state type, the address of the advertising router, the
cost of the link, and the sequence number. The router uses the sequence number to
determine the "newness" of the received link-state information.
2. When the router receives the DBD, it acknowledges the receipt of the DBD that is using
the LSAck packet.
3. The routers compare the information that they receive with the information that they
have. If the received DBD has a more up-to-date link-state entry, the router sends an
LSR to the other router to request the updated link-state entry.
4. The other router responds with complete information about the requested entry in an
LSU packet.
5. When the router receives an LSU, it adds the new link-state entries to its LSDB and it
sends an LSAck.
Discovery 16: Configure and Verify Single-Area OSPF
Introduction
This activity will guide you through the configuration and verification of OSPF for IPv4
on a Cisco IOS router. The lab is prepared with the devices that are represented in the
topology diagram and the connectivity table. All devices have their basic configurations
in place, including hostnames and IPv4 addresses. R2 and R3 are also configured with
OSPF. You will configure OSPF on R1 and verify the results.
Topology
Job Aids
The initial configuration is as follows:
•
•
•
•
All devices have their basic configurations in place, including hostnames and IPv4
addresses.
OSPF is preconfigured on R2 and R3:
Process ID number 1 is used.
Both routers announce a loopback interface network.
Device Information
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today.
Device Details
Device
Interface
IPv4 Address
Neighbor
R1
Ethernet0/0
10.0.1.1/24
R2
R1
Ethernet0/1
10.1.1.1/24
R3
R1
Loopback0
10.10.11.1/24
—
R2
Ethernet0/0
10.0.1.2/24
R1
R2
Ethernet0/2
10.2.1.2/24
R3
Device
Interface
IPv4 Address
Neighbor
R2
Loopback0
10.10.12.1/24
—
R3
Ethernet0/1
10.1.1.3/24
R1
R3
Ethernet0/2
10.2.1.3/24
R2
R3
Loopback0
10.10.13.1/24
—
Command List
The table defines the commands that you use to configure OSPF.
Command and
Variable
Description
router
ospfprocess-id
Enters the OSPF routing configuration mode. The network administrator
chooses the process ID, which is a number between 1 and 65,535. The
process ID is locally significant, which means that it does not have to match
other OSPF routers to establish adjacencies with those neighbors.
network ipaddress
wildcardmaskarea areaid
Uses a combination of the network address and wildcard mask and serves as
the criteria to match when identifying the interfaces that can send and receive
OSPF packets. The network address along with the wildcard mask, identifies
which networks OSPF will run on, which in turn indicates which networks
will be advertised in OSPF.
The area ID identifies the OSPF area to which the network belongs. When all
the routers are within the same OSPF area, the network commands must be
configured with the same area ID on all routers. There must be an Area 0. In
a single-area OSPF environment, the area is always 0.
ip ospfprocessidarea area-id
Enables OSPF explicitly on the selected interface. This interface
configuration mode command is an alternative to the network command.
Task 1: Configure and Verify Single-Area OSPF
The router ospf command uses a process identifier as an argument. The process ID is
a unique, arbitrary number that you select to identify the routing process. The process
ID is locally significant and does not need to match the OSPF process ID on other
OSPF routers. However, best practice suggests that the process ID should be the same
on all routers in the same routing domain.
The network command identifies which IPv4 networks on the router are part of the
OSPF network. For each network, you must also identify the OSPF area to which the
networks belong. The network that is identified in the network command does not tell
the router which network to advertise; instead, it indicates the interfaces on which OSPF
will be enabled. Then, the network configured on these interfaces will be advertised into
OSPF.
As with subnet mask and an IPv4 address, a wildcard mask is a string of 32 binary
digits. However, a wildcard mask is used by a device to determine which bits of the
address to examine for a match. A wildcard mask is not used on its own. It is used in
conjunction with an IPv4 address. The matching rule consists of a reference IPv4
address and a wildcard mask that applies to it. When a wildcard mask is applied to the
reference IPv4 address, the result is the matching pattern of binary digits. For a match
to occur, the IPv4 address from the packet header must match the resulting pattern.
The wildcard mask bits are used as follows:
•
Where wildcard mask bit is 0: the value found at the same position in the reference IPv4
address must be matched.
Where wildcard mask bit is 1: the value found at the same position in the reference IPv4
address can be ignored.
•
In order to route traffic toward external networks or toward the internet, the router must
either know all the destination networks or have a default route. You can statically
configure a default route, but it can also be learned dynamically via OSPF. The router
that announces the default route needs to be configured with the default-information
originatecommand in the router configuration (config-router) mode. You can also add
the always keyword at the end of the command (default-information originate always)
so that the router will always advertise the default route, regardless of whether its
routing table has a default route.
Activity
Complete the following steps:
Step 1
Verify the OSPF configuration on router R2 using the show running-config command.
On R2, enter the following command:
R2# show running-config | section ospf
router ospf 1
router-id 2.2.2.2
network 10.0.1.0 0.0.0.255 area 0
network 10.2.1.0 0.0.0.255 area 0
network 10.10.12.0 0.0.0.255 area 0
You should see that OSPF with the process ID 1 is preconfigured to run on interfaces
whose IPv4 address matches the network statements:
•
•
Ethernet0/0 (10.0.1.1 matches 10.0.1.0 0.0.0.255 because the first 3 octets match)
Ethernet0/2 (10.2.1.2 matches 10.2.1.0 0.0.0.255 because the first 3 octets match)
•
Loopback0 (10.10.12.1 matches 10.10.12.0 0.0.0.255 because the first 3 octets
match)
If you refer to the Job Aids, you can quickly see that the configured OSPF networks are
associated with each of the active interfaces on R2. All networks, meaning all active
interfaces on the router, belong to the same area—Area 0.
At this point, note that the router is configured with the router ID 2.2.2.2.
Step 2
Another way to verify the OSPF configuration is by using the show ip
protocols command. This command will display the status of the configured dynamic
routing protocols on a router. Verify the OSPF configuration on router R3.
On R3, enter the following command:
R3# show ip protocols
*** IP Routing is NSF aware ***
Routing Protocol is "ospf 1"
Outgoing update filter list for all interfaces is not set
Incoming update filter list for all interfaces is not set
Router ID 3.3.3.3
Number of areas in this router is 1. 1 normal 0 stub 0 nssa
Maximum path: 4
Routing for Networks:
10.1.1.0 0.0.0.255 area 0
10.2.1.0 0.0.0.255 area 0
10.10.13.0 0.0.0.255 area 0
Routing Information Sources:
Gateway Distance Last Update
2.2.2.2 110 17:04:48
Distance: (default is 110)
You should see that only the OSPF routing protocol is configured on R3. OSPF uses
the process ID 1 and is preconfigured to run on interfaces whose IPv4 address matches
the network statements:
•
•
•
Ethernet0/1 (10.1.1.3)
Ethernet0/2 (10.2.1.3)
Loopback0 (10.10.13.1)
If you refer to the Job Aids, you can quickly see that OSPF on R3 is enabled on all
enabled interfaces. All networks, or all interfaces on the router, belong to the same
area—Area 0.
The router is preconfigured with the router ID 3.3.3.3.
Router ID
If an OSPF router is not configured with an OSPF router-id command and no loopback
interfaces with IPv4 addresses are configured, then the OSPF router ID will be the
highest IPv4 address on any of its active interfaces. The interface does not need to be
enabled for OSPF, meaning that it does not need to be included in one of the
OSPF network commands. However, the interface must be active—it must be in the
"up" state.
The router ID looks like an IPv4 address, but it is not routable and therefore not included
in the routing table, unless the OSPF routing process chooses an interface (physical or
loopback) that is appropriately defined by a network command orip ospf processid area area-id interface command.
Step 3
On R1, you should configure OSPF process ID 1. Configure the router ID to 1.1.1.1.
Include all the networks that are associated with each of the three active interfaces for
R1 in Area 0.
On R1, enter the following commands:
R1# configure terminal
R1(config)# router ospf 1
R1(config-router)# router-id 1.1.1.1
R1(config-router)# network 10.0.1.0 0.0.0.255 area 0
R1(config-router)# network 10.1.1.0 0.0.0.255 area 0
R1(config-router)# network 10.10.11.0 0.0.0.255 area 0
R1(config-router)# end
During configuration, a syslog message indicates that new adjacencies have been
initiated with two neighbors, R2 and R3. The OSPF neighbor state is “FULL”, which
means that they have synchronized to each other and share the same LSDB
knowledge. Note that R2 and R3 are represented by the preconfigured router IDs,
2.2.2.2 and 3.3.3.3, respectively.
*Oct 13 07:24:35.278: %OSPF-5-ADJCHG: Process 1, Nbr 2.2.2.2 on Ethernet0/0
from LOADING to FULL, Loading Done
*Oct 13 07:24:46.037: %OSPF-5-ADJCHG: Process 1, Nbr 3.3.3.3 on Ethernet0/1
from LOADING to FULL, Loading Done.
Verify Single-Area OSPF
You can use several commands to verify the configuration of single-area OSPF:
•
Router# show ip ospf interface brief
The show ip ospf interface brief command verifies the interfaces that are enabled for
OSPF. It is useful to determine if yournetwork statements are correctly configured.
•
Router# show ip ospf interface interface-id
The show ip ospf interface interface-id command verifies all OSPF-related
configuration on an interface.
•
Router# show ip protocols
The show ip protocols command provides a summary of the configured routing
protocol information. You can see the protocols that are enabled and the networks that
these protocols are routing for. You can also see on which interfaces the routing
protocols were enabled explicitly.
•
Router# show ip ospf neighbor
The show ip ospf neighbor command displays the OSPF neighbor information on a
per-interface basis.
•
Router# show ip route
The show ip route command displays the routes that are known to the router and how
they are learned. This command is one of the best ways to determine connectivity
between the local router and the rest of the internetwork.
Step 4
Display the interfaces on R1 that are participating in OSPF.
On R1, enter the following command:
R1# show ip ospf interface brief
Interface PID Area IP Address/Mask Cost State Nbrs F/C
Lo0 1 0 10.10.11.1/24 1 P2P 0/0
Et0/1 1 0 10.1.1.1/24 10 BDR 1/1
Et0/0 1 0 10.0.1.1/24 10 BDR 1/1
Ethernet0/0, Ethernet0/1, and Loopback0 are participating in OSPF in Area 0, under
process ID 1 and belong to Area 0. The cost on Ethernet0/0 and Ethernet0/1 interfaces
is 10, because they both are Ethernet interfaces, while the Loopback0 interface has a
cost of 1. By default, the cost on loopback interfaces is set to 1.
Hello and dead intervals
The hello interval specifies the frequency in seconds at which a router sends hello
packets. The default hello interval on multiaccess networks is 10 seconds. The dead
interval is the time in seconds that a router waits to hear from a neighbor before
declaring the neighboring router out of service. By default, the dead interval is four times
the hello interval. These timers must be the same on neighboring routers; otherwise, an
adjacency will not be established.
Step 5
Display detailed information about the interfaces on R1 that are participating in OSPF.
On R1, enter the following command:
R1# show ip ospf interface
Loopback0 is up, line protocol is up
Internet Address 10.10.11.1/24, Area 0, Attached via Network Statement
Process ID 1, Router ID 1.1.1.1, Network Type POINT_TO_POINT, Cost: 1
Topology-MTID Cost Disabled Shutdown Topology Name
0 1 no no Base
Transmit Delay is 1 sec, State POINT_TO_POINT
Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5
oob-resync timeout 40
<--- output omitted --->
Ethernet0/1 is up, line protocol is up
Internet Address 10.1.1.1/24, Area 0, Attached via Network Statement
Process ID 1, Router ID 1.1.1.1, Network Type BROADCAST, Cost: 10
Topology-MTID Cost Disabled Shutdown Topology Name
0 10 no no Base
Transmit Delay is 1 sec, State BDR, Priority 1
<--- output omitted --->
Ethernet0/0 is up, line protocol is up
Internet Address 10.0.1.1/24, Area 0, Attached via Network Statement
Process ID 1, Router ID 1.1.1.1, Network Type BROADCAST, Cost: 10
Topology-MTID Cost Disabled Shutdown Topology Name
0 10 no no Base
Transmit Delay is 1 sec, State BDR, Priority 1
Designated Router (ID) 2.2.2.2, Interface address 10.0.1.2
Backup Designated router (ID) 1.1.1.1, Interface address 10.0.1.1
<--- output omitted --->
The output of this command provides many details about all interfaces on the router that
participate in OSPF. Ethernet0/0, Ethernet0/1, and Loopback 0 interfaces are all active
(status and line protocol is “up”) and belong to OSPF area 0. They share the same
information about the process ID and router ID, which is 1 and 1.1.1.1, respectively. The
cost for the loopback 0 interface is 1, while the cost for each Ethernet interface is 10.
The output of this command also provides information about OSPF timers. On these
interfaces the hello interval has a default value of 10 seconds and the dead interval also
has a default value of 40 seconds.
Step 6
Verify the OSPF configuration on R1.
On R1, enter the following command:
R1# show ip protocols
*** IP Routing is NSF aware ***
Routing Protocol is "ospf 1"
Outgoing update filter list for all interfaces is not set
Incoming update filter list for all interfaces is not set
Router ID 1.1.1.1
Number of areas in this router is 1. 1 normal 0 stub 0 nssa
Maximum path: 4
Routing for Networks:
10.0.1.0 0.0.0.255 area 0
10.1.1.0 0.0.0.255 area 0
10.10.11.0 0.0.0.255 area 0
Routing Information Sources:
Gateway Distance Last Update
2.2.2.2 110 00:02:46
3.3.3.3 110 00:02:36
Distance: (default is 110)
You should see only OSPF configuration, because OSPF is the only routing protocol
that is running on R1. The router ID is 1.1.1.1. OSPF uses process ID 1 and is
configured to run on the interfaces whose IPv4 address matches the network
statements:
•
•
•
Ethernet0/0 (10.0.1.1)
Ethernet0/1 (10.1.1.1)
Loopback0 (10.10.11.1)
All three interfaces participate in the same OSPF area 0.
In addition to all that information, the show ip protocols command also provides
information about the OSPF neighbors, which are identified in the Gateway column.
2.2.2.2 and 3.3.3.3 are the router IDs of R2 and R3, respectively.
Step 7
Display the list of the OSPF neighbors for R1.
On R1, enter the following command:
R1# show ip ospf neighbor
Neighbor ID Pri State Dead Time Address Interface
3.3.3.3 1 FULL/DR 00:00:38 10.1.1.3 Ethernet0/1
2.2.2.2 1 FULL/DR 00:00:34 10.0.1.2 Ethernet0/0
R1 has two neighbors:
•
•
3.3.3.3 (router ID of R3), which can be reached via the Ethernet0/1 interface. The
10.1.1.3 IPv4 address is used on the R3 interface to which R1 directly connects.
2.2.2.2 (router ID of R2), which can be reached via the Ethernet0/0 interface. The
10.0.1.2 IPv4 address is used on the R2 interface to which R1 directly connects.
Notice that the neighbor state is "FULL/DR," indicating that the OSPF adjacency is
established and both of the neighbors are DR routers on the link with R1. Instead of DR,
you could also see a BDR state, indicating that the router is BDR, or DROTHER.
DROTHER would indicate that the router is neither the DR nor the BDR. A router could
be DROTHER either because other routers are DR and BDR (on a LAN with more than
two routers) or because the router has its priority set to 0 and therefore it cannot
become the DR or BDR.
Step 8
On R2, display the list of the OSPF neighbors to verify that the neighbor state of R1 is
BDR.
On R2, enter the following command:
R2# show ip ospf neighbor
Neighbor ID Pri State Dead Time Address Interface
3.3.3.3 1 FULL/DR 00:00:38 10.2.1.3 Ethernet0/2
1.1.1.1 1 FULL/BDR 00:00:39 10.0.1.1 Ethernet0/0
Notice that the neighbor state for R1 (router ID 1.1.1.1) is "FULL/BDR," indicating that
the OSPF adjacency is established and R1 is the BDR router on the link with R2.
You can also use the same show ip ospf neighbor command on R3 to verify that R1 is
BDR router on the link with R3.
Step 9
Display the routing table on R1.
On R1, enter the following command:
R1# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
+ - replicated route, % - next hop override
Gateway of last resort is not set
10.0.0.0/8 is variably subnetted, 9 subnets, 2 masks
C 10.0.1.0/24 is directly connected, Ethernet0/0
L 10.0.1.1/32 is directly connected, Ethernet0/0
C 10.1.1.0/24 is directly connected, Ethernet0/1
L 10.1.1.1/32 is directly connected, Ethernet0/1
O 10.2.1.0/24 [110/20] via 10.1.1.3, 00:04:50, Ethernet0/1
[110/20] via 10.0.1.2, 00:05:00, Ethernet0/0
C 10.10.11.0/24 is directly connected, Loopback0
L 10.10.11.1/32 is directly connected, Loopback0
O 10.10.12.0/24 [110/11] via 10.0.1.2, 00:05:00, Ethernet0/0
O 10.10.13.0/24 [110/11] via 10.1.1.3, 00:04:50, Ethernet0/1
The routes that the router has learned via OSPF are tagged with an "O."
In the lab environment, the loopback IPv4 addresses using /24 prefix on the routers are
advertised as /24 networks by OSPF. However, when using the same configuration on
real routers, the loopback IPv4 addresses using /24 prefix will be advertised as /32
networks by OSPF, because by default loopbacks are always advertised as /32s by
OSPF.
R1 has learned the following networks:
•
•
•
The network between R2 and R3, which has two equal cost paths—via the
Ethernet0/0 and Ethernet0/1 interfaces. For both routes to 10.2.1.0/24 network, the
parameters in the square brackets are same. The first parameter has value of 110
and identifies the administrative distance for OSPF, while the second parameter has
value of 20 and identifies the total cost of the path. Because both paths are equally
good (they have the same cost), they are both included in the routing table and used
by R1 when sending traffic to 10.2.1.0/24 network. R1 will send packets on either
path; this is called load-balancing.
The network of the loopback interface on R2; best path is via Ethernet0/0
The network of the loopback interface on R3; best path is via Ethernet0/1
Step 10
R1 has two paths to the 10.2.1.0/24 network, because both paths have equal costs.
Influence the interface cost on R1, so that only the path via Ethernet0/0 will be chosen
as the best one. Use 1 as the cost parameter.
First, verify the costs of the Ethernet0/0 and Ethernet0/1 interfaces.
R1# show ip ospf interface brief
Interface PID Area IP Address/Mask Cost State Nbrs F/C
Lo0 1 0 10.10.11.1/24 1 LOOP 0/0
Et0/1 1 0 10.1.1.1/24 10 BDR 1/1
Et0/0 1 0 10.0.1.1/24 10 BDR 1/1
Both interfaces have the same cost—10. If you want the path via Ethernet0/0 to be
chosen, you have to change its cost to a lower value.
R1# configure terminal
R1(config)# interface Ethernet0/0
R1(config-if)# ip ospf cost 1
R1(config-if)# end
Alternatively, you could also change the cost of Ethernet0/1 to a higher value.
Step 11
Again, display the routing table of R1. Verify that there is only one path, the path via
Ethernet0/0, to reach the 10.2.1.0/24 network.
On R1, enter the following command:
R1# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
+ - replicated route, % - next hop override
Gateway of last resort is not set
10.0.0.0/8 is variably subnetted, 9 subnets, 2 masks
C 10.0.1.0/24 is directly connected, Ethernet0/0
L 10.0.1.1/32 is directly connected, Ethernet0/0
C 10.1.1.0/24 is directly connected, Ethernet0/1
L 10.1.1.1/32 is directly connected, Ethernet0/1
O 10.2.1.0/24 [110/11] via 10.0.1.2, 00:00:02, Ethernet0/0
C 10.10.11.0/24 is directly connected, Loopback0
L 10.10.11.1/32 is directly connected, Loopback0
O 10.10.12.0/24 [110/2] via 10.0.1.2, 00:00:02, Ethernet0/0
O 10.10.13.0/24 [110/11] via 10.1.1.3, 00:06:44, Ethernet0/1
The total cost to reach the 10.2.1.0/24 network is 11, which is the sum of the costs on
all the links to reach the network (including the cost of the links that R2 needs to reach
this network).
•
•
R1 can reach this network via R2. The cost of the link for R1 to reach R2 is 1 (the
cost that you configured).
The cost of the link for R2 to reach the 10.2.1.0/24 network is 10.
Passive Interfaces in OSPF
A passive interface in OSPF suppresses inbound and outbound OSPF hello packets on
the interface.
•
To configure a specific interface as passive for the OSPF routing protocol:
Router(config-router)# passive-interface interface
•
To configure all interfaces, except the specified ones, as passive for the OSPF routing
protocol:
Router(config-router)# passive-interface default
Router(config-router)# no passive-interface interface
With OSPF running on a network, the passive-interface command stops both outgoing
and incoming routing updates because the effect of the command causes the router to
stop sending and receiving hello packets over an interface. For this reason, the routers
will not become neighbors. Use the passive interface configuration only on the
interfaces where you do not expect the router to form any OSPF neighbor adjacency,
for example on a connection to an end device.
You can configure either a specific interface as passive, or you can turn on a passive
interface setting as the default, changing all interfaces to passive for OSPF, and then
make active for OSPF the interfaces that should not be configured as passive with
the no passive-interface configuration command.
Step 12
On R1, set all interfaces as passive, except the interface that connects to R3. The
easiest way is to use the passive-interface default command.
On R1, enter the following commands:
R1# configure terminal
R1(config)# router ospf 1
R1(config-router)# passive-interface default
*Oct 13 11:30:01.326: %OSPF-5-ADJCHG: Process 1, Nbr 2.2.2.2 on
Ethernet0/0 from FULL to DOWN, Neighbor Down: Interface down or detached
*Oct 13 11:30:01.326: %OSPF-5-ADJCHG: Process 1, Nbr 3.3.3.3 on
Ethernet0/1 from FULL to DOWN, Neighbor Down: Interface down or detached
R1(config-router)# no passive-interface Ethernet0/1
*Oct 13 11:31:07.174: %OSPF-5-ADJCHG: Process 1, Nbr 3.3.3.3 on
Ethernet0/1 from LOADING to FULL, Loading Done
R1(config-router)# end
Note that during configuration, a syslog message indicates that existing adjacencies
have been terminated. After you specify that Ethernet0/1 should not be configured as
passive, the new adjacency is initiated with R3.
Step 13
Display the list of the OSPF neighbors on R1.
On R1, enter the following command:
R1# show ip ospf neighbor
Neighbor ID Pri State Dead Time Address Interface
3.3.3.3 1 FULL/DR 00:00:31 10.1.1.3 Ethernet0/1
Because only Ethernet0/1 has been excluded from the passive interface configuration,
R1 has formed an adjacency with R3 only.
Step 14
Display the routing table on R1 and verify the OSPF routes after the configuration
changes.
On R1, enter the following command:
R1# show ip route
<--- output omitted --->
Gateway of last resort is not set
10.0.0.0/8 is variably subnetted, 9 subnets, 2 masks
C 10.0.1.0/24 is directly connected, Ethernet0/0
L 10.0.1.1/32 is directly connected, Ethernet0/0
C 10.1.1.0/24 is directly connected, Ethernet0/1
L 10.1.1.1/32 is directly connected, Ethernet0/1
O 10.2.1.0/24 [110/20] via 10.1.1.3, 00:08:27, Ethernet0/1
C 10.10.11.0/24 is directly connected, Loopback0
L 10.10.11.1/32 is directly connected, Loopback0
O 10.10.12.0/24 [110/21] via 10.1.1.3, 00:08:27, Ethernet0/1
O 10.10.13.0/24 [110/11] via 10.1.1.3, 00:08:27, Ethernet0/1
The routes that the router has learned via OSPF are tagged with an "O." Even though
all interfaces except Ethernet0/1 are passive for OSPF, R1 still learns the same three
networks and uses them in the routing table. This means that R1 will only use the
Ethernet0/1 as the exit interface when it sends traffic to 10.2.1.0/24, 10.10.12.0/24 and
10.10.13.0/24 networks.
Routing for IPv6
There are different routing protocols available for and Internet Protocol version 6 (IPv6)
because routing for IPv6 is needed just as it is for IPv4.
The same rules apply for routers using IPv6 as they do for IPv4. Routers can learn
where to forward packets to destination networks that are not directly connected by
performing static or dynamic routing. Because static routing is best suited for small
networks where changes rarely happen, dynamic routing is recommended in medium or
large networks.
To support IPv6, all the IPv4 routing protocols had to go through varying degrees of
changes, with the most obvious being that each had to be changed to support longer
addresses and prefixes.
IPv6 Routing Protocols and Their RFCs
Routing Protocol
Full Name
RFC
RIPng
RIP next generation
2080
OSPFv3
OSPF version 3
2740
MP-BGP4
Multiprotocol BGP-4
2545/4760
EIGRP for IPv6
EIGRP for IPv6
Proprietary
As with IPv4, most IPv6 routing protocols are IGPs, with BGP still being the only EGP of
note. All these IGPs and BGP were updated to support IPv6. The table lists the routing
protocols and their new RFCs.
Each of these routing protocols had to be changed to support IPv6. The actual
messages that are used to send and receive routing information have changed, using
IPv6 headers instead of IPv4 headers, and using IPv6 addresses in those headers. For
example, RIP next generation (RIPng) sends routing updates to the IPv6 destination
multicast address ff02::9 instead of to the former RIPv2 IPv4 224.0.0.9 address. Also,
the routing protocols typically advertise their link-local IPv6 address as the next hop in a
route.
The routing protocols still retain many of the same internal features. For example,
RIPng is based on RIPv2 and is still a distance vector protocol, with the hop count as
the metric and 15 hops as the highest valid hop count (16 is infinity). OSPF version 3
(OSPFv3), which was created specifically to support IPv6 (and also supports IPv4), is
still a link-state protocol, with the cost as the metric but with many internals, including
LSA types, changed. OSPFv3 uses multicast addresses, including the all OSPF routers
IPv6 address ff02::5, and the OSPF DR IPv6 address ff02::6. As a result, OSPFv2 is not
compatible with OSPFv3. However, the core operational concepts remain the same.
You can also use and configure IPv6 static routing in the same way that you would with
IPv4.
Building Redundant Switched Topologies
Introduction
The content in this section is self-study material and will not be delivered in class by
your instructor.
In any kind of Enterprise environment, one of the most important aspects of network
design is providing redundancy. A network should never rely on one device to be a
single point of failure, because that can affectively cause the loss of digital
communication within and even outside the Enterprise.
Therefore, it is crucial to build a redundant topology, including implementing additional
switches and redundant links between them. Although a redundant topology in a
switched network has its benefits, it can also cause problems, such as Open System
Interconnect (OSI) Layer 2 loops. To avoid Layer 2 loops in a switched topology,
Spanning Tree Protocol (STP) is used as a Layer 2 loop prevention mechanism while
still providing network link redundancy. Thus, you should never disable STP in Layer 2
environments.
A limitation of the traditional STP is the convergence delay after a topology change, so
the use of Rapid STP (RSTP) is recommended. Although RSTP is backwardscompatible with STP, the two protocols are different in many ways. In order to take the
full advantage of RSTP, all switches in a spanning tree topology must run the rapid
version of the protocol.
Cisco Enterprise Architecture Model
As a networking engineer working with Cisco Catalyst switches, you should be familiar
with STP and all its more optimized variants, such as Cisco’s Per VLAN Spanning Tree
Plus (PVST+), and get a firm grip on physical redundancy and STP concepts, such as:
•
•
•
Issues in Redundant Topologies
STP and RSTP protocols operation
Implementation of STP stability mechanism
Physical Redundancy in a LAN
Enterprise voice and data networks are designed with physical component redundancy
to eliminate the possibility of any single point of failure causing a loss of function for an
entire switched network. Building a reliable switched network requires additional
switches and redundant physical links. However, redundant Layer 2 switch topologies
require planning and configuration to operate without introducing Layer 2 loops.
Physical loops may occur in the network as part of a design strategy for redundancy in a
switched network. Adding additional switches to local-area networks (LANs) can add the
benefit of redundancy. Connecting two switches to the same network segments ensures
continuous operation if there are problems with one of the segments. Redundancy can
ensure the constant availability of the network. However, when adding redundant
physical links and additional switches, a physical loop is created and by spanning a
single VLAN between connected switches a Layer 2 loop is created also.
Layer 2 LAN protocols, such as Ethernet, lack a mechanism for recognizing and
eliminating endless looping of frames, as illustrated in the figure. Some Layer 3
protocols implement a Time to Live (TTL) or hop limit mechanism that limits the number
of times that a Layer 3 networking device can retransmit a packet or limit how many
Layer 3 devices a packet can traverse. Lacking such a mechanism, Layer 2 devices
would continue to retransmit looping traffic indefinitely.
Layer 2 loops affect performance in a switched LAN. A loop-avoidance mechanism
solves these problems and STP was developed for that purpose.
Issues in Redundant Topologies
In the absence of a protocol to monitor link forwarding states, a redundant switch
topology is vulnerable to these conditions:
•
Continuous frame duplication: Without some loop-avoidance process, each switch
floods broadcast, multicast, and unknown unicast frames endlessly. Switches flood
broadcast frames to all ports except the port on which the frame was received. The
frames then duplicate and travel endlessly around the loop in all directions. The result of
continuous broadcast frame duplication is called abroadcast storm.
•
•
Multiple frame transmission: Multiple copies of unicast frames may be delivered to
destination stations. Many protocols expect to receive only a single copy of each
transmission. Multiple copies of the same frame can cause unrecoverable errors.
Media Access Control (MAC) database instability: Instability in the content of the
MAC address table results from the fact that different ports of the switch receive copies
of the same frame. Data forwarding can be impaired when the switch consumes the
resources that are coping with instability in the MAC address table.
For example, in the topology that is shown in the figure no Layer 2 loop prevention
mechanism is implemented. Suppose that host A sends a frame to host B. Host A
resides on network segment A, and host B resides on network segment B. Assume that
none of the switches have learned the address of host B.
Host A transmits the frame destined for host B on segment A.
Switch W receives the frame that is destined for host B, learns the MAC address of host
A on segment A, and floods it out to switches X and Y.
Switch X and switch Y both receive the frame from host A (via switch W) and correctly
learn that host A is on segment 1 for switch X and on segment 2 for switch Y. Switch X
and switch Y then forward the frame to switch Z. Switch Z receives two copies of the
frame from host A: one copy through switch X on segment 3 and one copy through
switch Y on segment 4.
Assume that the first copy of the frame from switch X arrives first. Switch Z learns that
host A resides on segment 3. Because switch Z does not know where host B is
connected, it forwards the frame to all its ports (except the incoming port on segment 3)
and therefore to host B and also to switch Y.
When the second copy of the frame from switch Y arrives at switch Z on segment 4,
switch Z updates its table to indicate that host A resides on segment 4. Switch Z then
forwards the frame to host B and switch X.
In this example where no loop prevention mechanism exists the result is that host B has
received multiple copies of the frame, which can cause problems with the receiving
application directly on the host B.
Switches X and Y now change their internal tables to indicate that host A is on segment
3 for switch X and on segment 4 for switch Y. The copies of the initial frame from host A
being received on different segments of the switches results in MAC database
instability.
Furthermore, if the initial frame from host A was a broadcast frame, then all switches
forward the frames endlessly. Switches flood broadcast frames to all ports except the
port on which the frame was received. The frames then duplicate and travel endlessly
around the loop in all directions. They eventually would use all available network
bandwidth and block transmission of other packets on both segments. This situation
results in a broadcast storm.
Spanning Tree Operation
The solution to prevent Layer 2 loops is STP. STP enables the use of physical path
redundancy while preventing the undesirable effects of active Layer 2 loops in the
network. By default, STP is turned on in Cisco Catalyst switches.
There are several varieties of STP. All variants of STP provide Layer 2 loop prevention
by managing the physical paths to given network segments. The original STP is an
Institute of Electrical and Electronics Engineers (IEEE) committee standard, which is
defined as 802.1D and was created for a bridged network using Ethernet bridges.
Ethernet bridges are obsolete and replaced with Ethernet switches so the devices
running any variant of STP nowadays are switches. Note, however, that STP
terminology includesbridge even though it is being run on switches.
STP behaves in the following way:
•
•
•
STP uses bridge protocol data units (BPDUs) for communication between switches.
STP forces certain ports into a blocked state so that they do not listen to, forward, or
flood data frames. The overall effect is that only one path to each network segment is
active at any time.
If there is a connectivity problem with any active network segment, STP activates a
previously inactive path, if one exists (changing the blocked port to the forwarding
state).
To prevent Layer 2 loops in a network, STP uses a reference point called root bridge.
The root bridge is the logical center of the spanning tree topology. All paths that are not
needed to reach the root bridge from anywhere in the network are placed in STP
blocking mode.
The root bridge is chosen with an election. In the original STP, each switch has a
unique 64-bit bridge ID (BID) that consists of the 16-bit bridge priority and 48-bit MAC
address as shown in the figure. The bridge priority is a number between 0 and 65535
and the default on Cisco switches is 32768.
In evolved variants of STP, like Cisco PVST+, RSTP or Multiple Spanning Tree Protocol
(MSTP), the original bridge priority field in the BID is changed to include an Extended
System ID field as shown in the figure. This field carries information such as VLAN ID or
instance number required for the evolved variants of STP to operate. The bridge priority
field in this case is 4 bits and the Extended System ID field is 12 bits. In command
outputs you will either see this combination written as a 16-bit field, or as two
components: a 16-bit bridge priority where the lower 12 bits are binary 0, and a 12-bit
Extended System ID. In the latter case, the bridge priority is a number between 0 and
65535 in increments of 4096, and the default on Cisco switches is 32768.
The following are the steps of the spanning tree algorithm:
1. All interfaces on all switches in the spanning tree topology start in blocked mode.
2. The switches elect a root bridge. The root bridge is selected based on the lowest BID (in
all STP variants). If all switches in the network have the same bridge priority, the switch
with the lowest MAC address becomes the root bridge. You can only have one root
bridge per network in an original STP and one root bridge per VLAN in Cisco PVST+.
By default, if a switch that is elected as a root bridge fails, the switch with the next
lowest BID becomes the new root bridge. Cisco enables the configuration of a primary
and secondary root bridge. If a primary root bridge failure occurs, the configured
secondary becomes the new root bridge.
3. Each nonroot switch determines a root port. The root port is the port with the best path
to the root bridge. The root path cost value is used in this calculation; it is the cumulative
STP cost of all links to the root bridge. The root port is the port with the lowest root path
cost to the root bridge.
4. On each segment a designated port is selected. This is again calculated based on the
lowest root path cost. The designated port on a segment is on the switch with the lowest
root path cost. On root bridges, all switch ports are designated ports. Each network
segment will have one designated port.
5. The root ports and designated ports transition to the forwarding state, and any other
ports (called non-designated ports) stay in the blocking state.
The STP path cost depends on the speed of the link. The first table shows the default
STP link costs. The second table shows the summary of the STP port roles.
STP Path Costs
Data Rate
STP Cost (802.1D-1998)
STP Cost (802.1D-2004)
4 Mbps
250
5,000,000
10 Mbps
100
2,000,000
16 Mbps
62
1,250,000
100 Mbps
19
200,000
1 Gbps
4
20,000
2 Gbps
3
10,000
10 Gbps
2
2000
STP Port Roles
Port Role
Description
Root port
This port exists on non-root bridges. It is the switch port with the best path to
the root bridge. Root ports forward traffic toward the root bridge and populate
the MAC address table for network segments attached to that port. Only one
root port is allowed per switch or per VLAN in Cisco PVST+.
Designated
port
This port exists on root and non-root bridges. For root bridges, all switch ports
are designated ports. For non-root bridges, a designated port is the switch port
that will receive and forward frames toward the root bridge as needed. Only
one designated port is allowed per segment. If multiple switches exist on the
same segment, an election process determines the designated port, and the
corresponding switch port begins forwarding frames for the segment.
Designated ports populate the MAC address table for the network segment
attached to that port.
Port Role
Description
The nondesignated port is a switch port that it is blocking data frames and is
Nondesignated not populating the MAC address table with the source addresses of frames that
port
are seen on that segment.
Disabled port
The disabled port is a switch port that is shut down.
Spanning Tree Operation Example
The first step in the spanning tree algorithm is the election of a root bridge. Initially, all
switches assume that they are the root. They start transmitting BPDUs with the Root ID
field containing the same value as the bridge ID field. Thus, each switch essentially
claims that it is the root bridge on the network.
When the switches start receiving BPDUs from the other switches, each switch
compares the root ID in the received BPDUs against the value that it currently has
recorded as the root ID. If the received value is lower than the recorded value (which
was originally the BID of that switch), the switch replaces the recorded value with the
received value and starts transmitting this value in the Root ID field in its own BPDUs.
Eventually, all switches learn and record the BID of the switch that has the lowest BID.
The switches all transmit this BID in the Root ID field of their BPDUs.
In the example, Switch B becomes the root bridge because it has the lowest BID.
Switch A and switch B have the same priority, but switch B has a lower MAC address
value.
When a switch recognizes that it is not the root (because it is receiving BPDUs that
have a root ID value that is lower than its own BID), it marks the port on which it is
receiving those BPDUs as its root port.
A switch could receive BPDUs on multiple ports. In this case, the switch elects the port
that has the lowest-cost path to the root as its root port. If two ports have an equal path
cost to the root, the switch looks at the BID values in the received BPDUs to make a
decision (where the lowest BID is considered best, similar to root bridge election). If the
root path cost and the BID in both BPDUs are the same because both ports are
connected to the same upstream switch, the switch looks at the Port ID field in the
received BPDUs and selects its root port based on the lowest value in that field.
By default, the cost that is associated with each port is related to its speed (the higher
the interface bandwidth, the lower the cost), but the cost can be manually changed.
Switches A, C, and D mark the ports that are directly connected to switch B (which is
the root bridge) as the root port. These directly connected ports on switches A, C, and D
have the lowest cost to the root bridge.
After electing the root bridge and root ports, the switches determine which switch will
have the designated port for each Ethernet segment; the switch with the designated port
is called the designated bridge for the segment. This process is similar to the root bridge
and root port elections. Each switch that is connected to a segment sends BPDUs out of
the port that is connected to that segment, claiming to be the designated bridge for that
segment. At this point, it considers its port to be a designated port.
When a switch starts receiving BPDUs from other switches on that segment, it
compares the received values of the root path cost, BID, and port ID fields (in that
order) against the values in the BPDUs that it is sending out its own port. The switch
stops transmitting BPDUs on the port and marks it as a nondesignated port if the other
switch has lower values.
In the example, all ports on the root bridge (switch B) are designated ports. The ports on
switch A that are connecting to switch C and switch D become designated ports,
because switch A has the lower root path cost.
To prevent Layer 2 loops while STP executes its algorithm, all ports start out in the
blocking state. When STP marks a port as either a root port or a designated port, the
algorithm starts to transition this port to the forwarding state and all nondesignated ports
remain in the blocking state.
The original and rapid versions of STP both execute the same algorithm in the decisionmaking process. However, in the transition of a port from the blocking (or discarding, in
rapid spanning tree terms) to the forwarding state, there is a big difference between
those two spanning tree versions. Classic 802.1D would simply take 30 seconds to
transition the port to forwarding. The rapid spanning tree algorithm can use additional
mechanisms to transition the port to forwarding in less than a second.
Although the order of the steps that are listed in the diagrams suggests that STP goes
through them in a coordinated, sequential manner, that is not actually the case. If you
look back at the description of each step in the process, you see that each switch is
going through these steps in parallel. Also, each switch might adapt its selection of root
bridge, root ports, and designated ports as it receives new BPDUs. As the BPDUs are
propagated through the network, all switches eventually have a consistent view of the
topology of the network. When this stable state is reached, BPDUs are transmitted only
by designated ports. However, all blocking ports are continuously listening for BPDUs
that are sent every 2 seconds. If a blocking port stops receiving BPDUs, it will begin
transition to the forwarding state.
There are two loops in the sample topology, meaning that two ports should be in the
blocking state to break both loops. The port on Switch C that is not directly connected to
Switch B (root bridge) is blocked, because it is a nondesignated port. The port on
Switch D that is not directly connected to Switch B (root bridge) is also blocked,
because it is a nondesignated port.
Types of Spanning Tree Protocols
The STP is a network protocol that ensures a loop-free topology.
Several varieties of spanning tree protocols exist:
•
STP (IEEE 802.1D) is the legacy standard that provides a loop-free topology in a
network with redundant links. STP creates a Common Spanning Tree (CST) that
assumes one spanning tree instance for the entire bridged network, regardless of the
number of VLANs.
•
•
•
•
PVST+ is a Cisco enhancement of STP that provides a separate 802.1D spanning tree
instance for each VLAN that is configured in the network.
MSTP, or IEEE 802.1s, is an IEEE standard that is inspired by the earlier Cisco
proprietary Multi-Instance STP (MISTP) implementation. MSTP maps multiple VLANs
into the same spanning tree instance.
RSTP, or IEEE 802.1w, is an evolution of STP that provides faster convergence of STP.
It redefines port roles and enhances BPDU exchanges.
Rapid PVST+ is a Cisco enhancement of RSTP that uses PVST+. Rapid PVST+
provides a separate instance of 802.1w per VLAN.
When Cisco documentation and this course refer to implementing RSTP, they are
referring to the Cisco RSTP implementation—Rapid PVST+.
Comparison of Spanning Tree Protocols
The following are the characteristics of various spanning tree protocols:
•
•
Protocol
Standard Resources Needed
Convergence
Number of Trees
STP
802.1D
Low
Slow
One
PVST+
Cisco
High
Slow
One for every VLAN
RSTP
802.1w
Medium
Fast
One
Rapid PVST+
Cisco
Very high
Fast
One for every VLAN
MSTP
802.1s
Medium or high
Fast
One for multiple VLANs
STP assumes one 802.1D spanning tree instance for the entire bridged network,
regardless of the number of VLANs. Because only one instance exists, the central
processing unit (CPU) and memory requirements for this version are lower than for the
other protocols. However, because of only one instance, there is only one root bridge
and one tree. Traffic for all VLANs flows over the same path, which can lead to
suboptimal traffic flows. Because of the limitations of 802.1D, this version is slow to
converge.
PVST+ is a Cisco enhancement of STP that provides a separate 802.1D spanning tree
instance for each VLAN that is configured in the network. The separate instance
supports features like PortFast, UplinkFast, BackboneFast, BPDU guard, BPDU filter,
root guard, and loop guard to enhance security. Creating an instance for each VLAN
increases the CPU and memory requirements but allows for per-VLAN root bridges. The
use of PVST+ gives the administrator the ability to load balance traffic per VLAN. For
example, the root bridge for VLAN 10 could be switch A and the root bridge for VLAN 20
could be switch B. Convergence of this version is similar to the convergence of 802.1D.
However, convergence is per-VLAN.
•
•
•
RSTP, or IEEE 802.1w, is an evolution of STP that provides faster STP convergence.
This version addresses many convergence issues, but because it still provides a single
instance of STP, it does not address the suboptimal traffic flow issues. To support that
faster convergence, the CPU usage and memory requirements of this version are
slightly higher than the requirements of original STP but lower than requirements of
PVST+.
Rapid PVST+ is a Cisco enhancement of RSTP that uses PVST+. It provides a
separate instance of 802.1w per VLAN. This version addresses both the convergence
issues and the suboptimal traffic flow issues. However, this version has the largest CPU
and memory requirements.
MSTP is an IEEE standard that is inspired by the earlier Cisco proprietary MISTP
implementation. To reduce the number of required STP instances, MSTP enables
mapping of multiple VLANs into the same spanning tree instance with common root
bridge. The Cisco implementation of MSTP provides up to 16 instances of RSTP
(802.1w) and combines many VLANs with the same physical and logical topology into a
common RSTP instance. Each instance supports PortFast, BPDU guard, BPDU filter,
root guard, and loop guard security enhancements. The CPU and memory requirements
of this version are lower than the requirements of Rapid PVST+ but are higher than
requirements of RSTP.
Default Spanning Tree Configuration
The default spanning tree configuration for Cisco Catalyst switches is:
•
•
•
PVST+
Enabled on all ports in VLAN 1
Slower convergence after topology change than with RSTP
The default spanning tree mode for Cisco Catalyst switches is PVST+, which is enabled
on all ports. PVST+ has much slower convergence after a topology change than the
Rapid PVST but requires less CPU and memory resources to compute the shortest path
tree upon topology changes.
PortFast and BPDU Guard
Two features that enhance STP are PortFast and BPDU guard. To fully appreciate the
benefits of these features, review the STP initialization process that a switch port
transitions through when it is enabled.
Because STP is responsible for maintaining a loop-free topology, precautions are
required each time that you enable a switch port. If the port is connected to another
switch, BPDUs are exchanged every two seconds to ensure that a loop is not
introduced into the topology. In STP and PVST+, a port goes through these stages
when it is enabled:
1. Blocking: For up to 20 seconds, the port remains in the blocking state.
2. Listening: For 15 seconds, the port listens to BPDUs that it received and listens for
new topology information. The switch processes received BPDUs and determines if any
better BPDU was received that would cause the port to transition back to the blocking
state. If no better BPDU was received, the port transitions into a learning state. In the
listening state, the port does not populate the MAC address table with the addresses it
learns and it does not forward any frames.
3. Learning: For up to 15 seconds, the port updates the MAC address forwarding table,
but it does not begin forwarding.
4. Forwarding: Once the switch port is certain it will not form a loop by forwarding frames,
it enters the forwarding state. It still monitors for topology changes that could require it
to transition back to the blocking state to prevent a loop.
If a switch port connects to another switch, the STP initialization cycle must transition
from state to state to ensure a loop-free topology.
However, for access devices such as personal computers (PCs), laptops, servers, and
printers, the delays that incurred with STP initialization can cause problems such as
Dynamic Host Configuration Protocol (DHCP) timeouts. Cisco designed the PortFast
and BPDU guard features as enhancements to STP to reduce the time that is required
for an access device to enter the forwarding state.
STP is designed to prevent loops. Because there can be no loop on a port that is
connected directly to a host or server, the full function of STP is not needed for that port.
PortFast is a Cisco enhancement to STP that allows a switchport to begin forwarding
much faster than a switchport in normal STP mode.
When the PortFast feature is enabled on a switch port that is configured as an access
port, that port bypasses the typical STP listening and learning states. This feature
allows the port to transition from the blocking to the forwarding state immediately. You
can use PortFast on access ports that are connected to a single workstation or to a
server to allow those devices to connect to the network immediately rather than waiting
for spanning tree to converge.
In a valid PortFast configuration, no BPDUs should be received, because access and
Layer 3 devices do not generate BPDUs. If a port receives a BPDU, that would indicate
that another bridge or switch is connected to the port. This event could happen if a user
plugged a switch on their desk into the port where the user PC was previously plugged
into.
For example, assume that users decide they want more bandwidth. Since there are two
network access connections in their office, they decide to use both of them. To use
them both, they unplug their individual PCs from the network switches and plug it into
their own switch. They then plug the new switch into both of the network access ports. If
PortFast is enabled on both ports of the network switch, this action could cause a loop
and bring the network to a halt.
To avoid such situation when using PortFast, the BPDU guard enhancement is the
solution. It allows network designers to enforce the STP domain diameter and keep the
active topology predictable. The devices behind the ports that have STP PortFast and
BPDU guard enabled are not able to influence the STP topology thus preventing the
users to connect additional switches and violating STP diameter. At the reception of
BPDUs, the BPDU guard operation effectively disables the port that has PortFast
configured, by transitioning the port into errdisable state. A message also appears on
the switch console. For example, the following message might appear:
2000 May 12 15:13:32 %SPANTREE-2-RX_PORTFAST:Received BPDU on PortFast enable
port. Disabling 2/1
2000 May 12 15:13:32 %PAGP-5-PORTFROMSTP:Port 2/1 left bridge port 2/1
Because the purpose of PortFast is to minimize the time that ports must wait for
spanning tree to converge, you should use it only on ports that no other switch is
connected to, like access ports for connecting user equipment and servers or on trunk
ports when connecting to a router in a router on a stick configuration. If you enable
PortFast on a port that is connecting to another switch, you risk creating a spanning tree
loop, or with the BPDU guard feature enabled the port will transition in errdisable.
Rapid Spanning Tree Protocol
A limitation of a traditional STP is the convergence delay after a topology change and
this is why the use of RSTP is recommended. RSTP is an IEEE standard that redefines
STP port roles, states, and BPDUs. It greatly improves the recalculation of the spanning
tree, and thus the convergence time, when the Layer 2 topology changes, including
when links come up and for indirect link failures.
Note the following regarding IEEE 802.1w RSTP:
•
•
•
•
•
802.1D STP was designed for an era of networks that were more tolerant of 50-second
delays in redundancy.
There are many proprietary mechanisms in place to enhance the performance and
convergence of STP; however, not all vendors or all switches have these mechanisms.
The 802.1w RSTP allows the network to converge faster than 802.1D.
Because RSTP is a standards-based protocol, it operates across multiple vendor
platforms
RSTP is backwards compatible with 802.1D.
The immediate hindrance of STP is convergence. Depending on the type of failure, it
takes anywhere from 30 to 50 seconds to converge after a network change. RSTP
helps with convergence issues that plague traditional STP. Cisco proprietary Rapid
PVST+ is based on the 802.1w standard in the same way that PVST+ is based on
802.1D. The operation of Rapid PVST+ is simply a separate instance of 802.1w for
each VLAN.
RSTP is proactive and therefore negates the need for the 802.1D delay timers. RSTP
supersedes 802.1D while remaining backward compatible. Much of the 802.1D
terminology and most parameters remain unchanged. In addition, RSTP is capable of
reverting to 802.1D to interoperate with traditional switches on a per-port basis, and
negotiate port states on a peer switch basis, using a proposal and agreement process.
Numerous differences exist between RSTP and STP, including that RSTP requires a
full-duplex point-to-point connection between adjacent switches.
RSTP Port Roles
With RSTP, port roles are slightly different than with STP.
RSTP defines the following port roles.
•
•
•
•
•
Root: The root port is the switch port on every nonroot bridge that is the best path to the
root bridge. There can be only one root port on each switch. The root port is considered
part of the active topology. It forwards, sends, and receives BPDUs.
Designated: In the active topology, a designated port is the switch port that will receive
and forward frames toward the root bridge as needed. There can be only one
designated port per segment.
Alternate: The alternate port is a switch port that offers an alternate path toward the
root bridge. It assumes a discarding state in an active topology. The alternate port
makes a transition to a designated port if the current designated port fails.
Backup: The backup port is an additional switch port on the designated switch with a
redundant link to the shared segment for which the switch is designated. The backup
port is in the discarding state in active topology. The backup port moves to the
forwarding state if there is a failure on the designated port for the segment.
Disabled: A disabled port has no role within the operation of spanning tree.
There is a difference between STP and RSTP port roles. Instead of the STP
nondesignated port role, there are now alternate and backup port roles. These
additional port roles allow RSTP to define a standby switch port before a failure or
topology change.
You will probably not see a backup port role in practice. It is used only when switches
are connected to a shared segment. To build shared segments, you need hubs, which are
obsolete.
Comparison of RSTP and STP Port States
STP Port Role
STP Port State
Root port
Forwarding
Designated port
Forwarding
Nondesignated port
Blocking
Disabled
—
In transition
Listening
Learning
RSTP Port Role
RSTP Port State
Root port
Forwarding
Designated port
Forwarding
Alternative or backup port
Discarding
Disabled
Discarding
In transition
Learning
The RSTP port states correspond to the three basic operations of a switch port:
discarding, learning, and forwarding. There is no listening state as there was with STP.
The listening and blocking STP states are replaced with the discarding state.
In a stable topology, RSTP ensures that every root port and designated port transit to
forwarding, while all alternate ports and backup ports are always in the discarding state.
The characteristics of RSTP port states are as follows:
Port state
Description
This state is seen in both a stable active topology and during topology
synchronization and changes. The discarding state prevents the forwarding of data
Discarding frames, thus “breaking” the continuity of a Layer 2 loop.
Learning
This state is seen in both a stable active topology and during topology
synchronization and changes. The learning state accepts data frames to populate
the MAC table to limit flooding of unknown unicast frames.
This state is seen only in stable active topologies. The forwarding switch ports
determine the topology. Following a topology change, or during synchronization,
Forwarding the forwarding of data frames occurs only after a proposal-and-agreement process.
A port will accept and process BPDU frames in all port states.
In RSTP the PortFast feature is known as an edge port concept. All ports directly
connected to end stations cannot create bridging loops in the network. Therefore, the
edge port directly transitions to the forwarding state, and skips the listening and learning
stages. Unlike PortFast, an edge port that receives a BPDU immediately loses its edge
port status and becomes a normal spanning-tree port.
Improving Redundant Switched Topologies
with EtherChannel
Introduction
The increasing deployment of higher-speed switched Ethernet to the desktop can be
attributed to the proliferation of bandwidth-intensive intranet applications. Any-to-any
communications of new intranet applications such as video to the desktop, interactive
messaging, Voice over Internet Protocol (VoIP), and collaborative applications are
increasing the need for scalable bandwidth within the core and at the edge of campus
networks.
Additional bandwidth is required at the access to the network, where end-devices
generate larger amounts of traffic, at the links that carry traffic aggregated from multiple
end-devices (uplinks), and at the links that carry application traffic, for example at the
links to the Data Center. When additional bandwidth is needed, the speed of these links
can be increased, but only to a certain point. As the speed increases on the links, this
solution finds its limitation where the fastest possible port is no longer fast enough to
aggregate the traffic coming from all the devices.
A second option is to multiply the numbers of physical links between both switches to
increase the overall speed of the switch-to-switch communication. But if there are
simply just multiple links between the two devices, the Spanning Tree Protocol (STP) is
going to block all except one link in order to avoid loops in the network.
A solution lies in a technology called EtherChannel. EtherChannel is a technology that
allows you to circumvent these issues by creating logical links made up of several
physical links.
Cisco Enterprise Architecture Model
As a network engineer, you will work with EtherChannel in Enterprise environments, so
you should be aware of various concepts:
•
•
•
The need for EtherChannel technology.
Different options for creating EtherChannels.
Configuration steps for EtherChannel implementation.
EtherChannel Overview
The proliferation of bandwidth-intensive applications such as video and interactive
messaging created a necessity for links with greater bandwidth. Additional bandwidth is
required both at the access to the network, where end-devices generate larger amounts
of traffic, and at the links that carry traffic aggregated from multiple end-devices, for
instance at the uplinks.
You can increase link bandwidth by choosing links of higher bitrate, but higher bitrate
links are more expensive. This solution cannot scale indefinitely and, at some point,
even a port with the greatest possible bandwidth might no longer suffice.
Another way to increase link bandwidth is by using more than one link between devices.
Aggregating multiple physical links increases the available bandwidth between two
devices. Aggregating multiple physical links also adds resiliency against link failure, by
providing link redundancy.
In a local-area network (LAN) environment, you can create logical aggregated Ethernet
links. Both Layer 2 and Layer 3 interfaces can be aggregated.
Aggregation can also be implemented on the network on Layer 1. An example of
aggregation at the physical layer is combining frequency bands in wireless
communications.
EtherChannel is a technology that enables link aggregation. In the industry, you will
often encounter terms such as port channel and Ethernet port channel. When using
these terms in an Ethernet LAN environment, EtherChannel, and Ethernet port channel
technology mean the same.
Many other terms are used to name the aggregation concept. Some of them are linkbundling, network interface card (NIC) bonding, NIC teaming, network bonding, and
channel bonding.
EtherChannel enables packets to be sent over several physical interfaces as if over a
single interface. EtherChannel logically bonds several physical connections into one
logical connection. The process offers redundancy and load balancing, while
maintaining the combined throughput of physical links.
Without EtherChannel technology, most control plane protocols such as Layer 2 STP or
Layer 3 routing protocols will treat multiple links as individual links. In the case of STP,
multiple links between the same two devices are treated as loops and, to avoid loops,
STP makes sure that only one link remains operational. Although the additional links
add resiliency, because of the STP, the available bandwidth between the two devices is
not increased.
EtherChannel bundles individual links into a channel group to create a single logical
interface called a port channel that provides the aggregate bandwidth of several
physical links. Each link can be in only one port channel. All the links in a port channel
must be compatible. Among other requirements, they must use the same speed and
operate in full-duplex mode.
The EtherChannel technology was originally developed by Cisco as a means of
increasing speed between switches by grouping several FastEthernet or Gigabit
Ethernet ports into one logical link, called an EtherChannel link, as shown in the
following figure. Since the multiple physical links are bundled into a single
EtherChannel, STP no longer sees them as separate physical links. Instead it sees a
single EtherChannel link. As a result, STP does not consider a single link to be a loop
and puts the port channel interface (containing all ports) in the forwarding state.
Therefore, the combined bandwidth of bundled physical links is available to the logical
link.
Some devices other than switches also support link aggregation. You can create an
EtherChannel link between two switches or between an EtherChannel-enabled server
and a switch. EtherChannel always creates one-to-one logical links. You cannot send
traffic to two different switches through the same EtherChannel logical link. One
EtherChannel logical link always connects only two devices.
For an EtherChannel logical link to form, all ports on both devices must be correctly
configured. On both sides, ports that are part of the logical link all belong to a logical
port channel interface. You can group from two to eight physical ports (or more on some
platforms) into a port channel logical interface, but you cannot mix port types within a
single EtherChannel. For example, you could group four FastEthernet ports into one
logical Ethernet link, but you could not group two FastEthernet ports and two
GigabitEthernet ports into one logical Ethernet link.
You can also configure multiple EtherChannel links between two devices, as shown in
the figure above. However, when several logical EtherChannel links exist between two
switches, STP detects loops. To avoid loops, STP will make only one logical link
operational. When STP blocks the redundant links, it blocks one entire EtherChannel,
thus blocking all the ports belonging to that EtherChannel link.
The advantages of the EtherChannel link aggregation are:
•
EtherChannel creates an aggregation that is seen as one logical link. Where there is
only one EtherChannel link, all physical links in the EtherChannel are active because
STP sees only one (logical) link. The bandwidth of physical links is combined to provide
increased bandwidth over the logical link.
•
•
•
Because EtherChannel relies on the existing switch ports, you do not need to upgrade
the ports to faster and more expensive ones to obtain more bandwidth. Most
configuration tasks can be performed on the EtherChannel logical interface instead of
on each individual port, which ensures configuration consistency throughout the links.
Load balancing is possible across the physical links that are part of the same
EtherChannel.
EtherChannel improves resiliency against link failure, as it provides link redundancy.
The loss of a physical link within an EtherChannel does not create a change in the
topology, and there will not be a spanning-tree recalculation. As long as at least one
physical link is active, the EtherChannel is functional, even if its overall throughput
decreases.
EtherChannel Configuration Options
As a Cisco proprietary technology, EtherChannel was initially implemented using Cisco
proprietary Port Aggregation Protocol (PAgP). Since the link aggregation concept has
become widely adopted within the industry, to avoid interoperability issues, the
aggregation control protocol was first standardized in the form of the Institute of
Electrical and Electronics Engineers (IEEE) 802.3ad standard or Link Aggregation
Control Protocol (LACP). LACP is currently defined in IEEE 802.1AX. Because LACP is
an IEEE standard, you can use it to facilitate EtherChannel in multivendor
environments.
To implement aggregated logical links, you can choose to configure them statically or to
configure a dynamic aggregation protocol to automatically create them. Static
configuration is simpler, but more error prone. Link aggregation protocols define a
dynamic negotiation procedure between adjoining switches. Using dynamic protocols
provides a more efficient use of the aggregated logical link.
With LACP, you can control link aggregation (for example the maximum number of
bundled ports allowed). LACP is also superior to static port channels with its automatic
failover, where traffic from a failed link within EtherChannel is sent over remaining
working links in the EtherChannel.
LACP controls the bundling of physical interfaces to form a single logical interface.
When you configure LACP, LACP packets are sent between LACP enabled ports to
negotiate the forming of a channel. When LACP identifies matched Ethernet links, it
groups the matching links into a logical EtherChannel link.
The individual links must match on several parameters:
•
•
•
Interface types cannot be mixed, for instance FastEthernet or Gigabit Ethernet cannot
be bundled into a single EtherChannel.
Speed and duplex settings must be the same on all the participating links.
Switchport mode and virtual local-area network (VLAN) information must match. Access
ports must be assigned to the same VLAN. Trunk ports must have the same allowed
range of VLANs. The native VLAN must be the same on all the participating links.
The best practice is to ensure that interfaces have consistent settings, before you
enable LACP protocol on them. It is important to remember that interfaces on both sides
must be consistently configured.
The LACP protocol defines two modes:
•
•
LACP active: This LACP mode places a port in an active negotiating state. In this state,
the port initiates negotiations with other ports by sending LACP packets.
LACP passive: This LACP mode places a port in a passive negotiating state. In this
state, the port responds to the LACP packets that it receives, but it does not initiate
LACP packet negotiation. The passive mode is useful when you do not know whether
the remote system supports LACP.
When you configure the desired LACP mode on an interface, you automatically enable
the LACP protocol on that interface.
Manual static configuration places the interface in an EtherChannel manually, without
any negotiation. No negotiation between the two switches means that there is no
checking to make sure that all the ports have consistent settings. There are no link
management mechanisms either.
With static configuration, you define a mode for a port. There is only one static mode,
the on mode. When static on mode is configured, the interface does not negotiate—it
does not exchange any control packets. It immediately becomes part of the aggregated
logical link, even if the port on the other side is disabled. With the on mode, the
EtherChannel configuration is unconditional. If the port is not configured with the static
on mode, then it is not meant to be included in the aggregated link.
For the EtherChannel link to form, modes on both sides of the individual links must be
compatible. The table shows which modes result in aggregation and which do not.
Channel Mode
Passive
Active
On
Passive
—
OK
—
Active
OK
OK
—
On
—
—
OK
As you can see from the table, if you configure one side to be in passive mode, it will
behave passively, waiting for the other side to initiate the EtherChannel negotiation. If
the other side is also set to passive, the negotiation never starts and the EtherChannel
does not form. If you disable all modes by using the no version of the command or if no
mode is configured, then the interface is placed in the off mode and EtherChannel is
disabled.
For the LACP enabled link to be included in the EtherChannel, at least one of the ports
must be configured with the active mode.
The on mode manually places the interface in an EtherChannel, without any
negotiation. It works only if the other side is also set to on. If the other side is set to
negotiate parameters through LACP, no EtherChannel will form, because the side that
is set to on mode will not negotiate.
Note that once an EtherChannel is formed, whether by static configuration or dynamic
negotiation, if a link within the EtherChannel fails, the EtherChannel will still be
functional, as long as at least one physical link is active. The overall throughput would of
course decrease in this situation.
An advantage of configuring dynamic protocols to establish EtherChannel is protection
from misconfigurations. LACP can ensure that the configuration at both ends fulfill the
link aggregation requirements, before establishing an EtherChannel link. If you
accidentally misconfigure a port, or if you accidentally make a mistake in cabling, for
instance, by plugging a cable in a trunk port on one side, and in an access port on the
other side, LACP will not allow an EtherChannel link to form. With static link
aggregation, a cabling or configuration mistake could go undetected and cause
undesirable network behavior.
Because EtherChannel uses several links to transport packets through the physical
infrastructure, the packets will be distributed between the physical links through load
balancing. Load balancing takes place between links that are part of the same
EtherChannel. Depending on the hardware platform, one or more load-balancing
methods can be implemented. These methods include source media access control
(MAC) address to destination MAC address load balancing, or source internet protocol
(IP) address to destination IP address load balancing, across the physical links. Some
methods can include source and destination port numbers also.
The goal of load balancing is not only to utilize all available links, but also to ensure that
packets with the same header information will be forwarded on the same physical link to
prevent unordered packet delivery. Load-balancing is performed in the hardware and is
enabled by default.
After you configure an EtherChannel, any configuration changes applied to the portchannel interface apply to all the physical ports assigned to the port-channel interface.
Configuration changes applied to the physical port affect only the port where you apply
the configuration, so it is best not to change the configuration of a physical port once it
is part of an EtherChannel. To change the parameters of all ports in an EtherChannel,
apply configuration commands to the port-channel interface, for example, spanning-tree
commands or commands to configure a Layer 2 EtherChannel as a trunk.
Layer 2 and Layer 3 EtherChannel
Interfaces can be bundled into two types of EtherChannels, depending on the type of
interfaces you are attempting to join to the port-channel:
•
•
Layer 2 EtherChannel bundles access or trunk ports between switches or other devices
(for example, servers).
Layer 3 EtherChannel bundles routed ports between switches or routers.
Both Layer 2 and Layer 3 EtherChannels are common in an enterprise network. Layer 3
EtherChannel links are implemented within the LAN, mostly between Layer 3 switches,
or between a Layer 3 switch and a router. Enterprises also implement Layer 3
EtherChannel on the links connecting to the WAN service provider, where the
aggregated link is established between the enterprise edge router and the service
provider’s router.
In the figure, you see an example of the enterprise LAN topology. Layer 2 and Layer 3
switches are connected using EtherChannel links, which consist of pairs of ports.
Aggregated links that exist between SW1 and the Access switch, and SW2 and the
Access switch, are Layer 2 EtherChannel links. Aggregated links between the SW1 and
SW2 switches, and between the SW1 switch and router R1, are Layer 3 EtherChannel
links.
When an aggregated link is a Layer 3 link, the IP addresses are assigned to the logical
port-channel interfaces on both sides of the link, and not to the member interfaces. A
port-channel for a Layer 3 aggregated link is a routed interface and it can have subinterfaces, just like other non-aggregated routed interfaces. It can also be enabled for
routing protocols.
The configuration options are the same for both types of EtherChannel links – you can
choose to configure an aggregation protocol (LACP) or you can manually configure the
link. Whatever the aggregation method you choose, ports you are aggregating must be
of the same type, such as routed ports, and they must have the same attributes.
WAN service providers sometimes implement Layer 1 devices in the connection from
the customer’s router to the service provider router. Examples of these devices are
media converters and multiplexers. This intermediary Layer 1 equipment might block
LACP protocol messages. To ensure link aggregation, you should opt for static manual
Layer 3 EtherChannel configuration.
Some older router platforms do not support dynamic aggregation protocols. On these
platforms, you must configure EtherChannel manually.
In the default Layer 3 switch configuration, the routing function is disabled, and all ports
are switched, Layer 2 ports. Switched ports can be converted to routed ports. Routed
ports behave like ports found on router platforms. Routed ports do not run Layer 2
management protocols, like STP, Dynamic Trunking Protocol (DTP), and others.
Routed ports are not members of any VLANs manually configured on the switch. A
routed port on a switch represents a boundary between different Layer 2 domains.
Routed ports do not run STP, so ports don’t need to wait for STP calculations.
For successful establishment of a Layer 3 EtherChannel link, physical ports on each
side of the aggregated link must be configured as routed ports. They also must have
matching port attributes, such as bandwidth and duplex mode.
In addition, the logical port-channel interface must be a routed interface. A Layer 3
EtherChannel will become active only when both the aggregated interface and its
constituent physical interfaces are routed interfaces.
The figure illustrates the difference between Layer 2 and Layer 3 EtherChannel. In the
figure, there are three aggregated links, represented by logical interfaces port-channel
20, port-channel 21 and port-channel 22.
Port-channel 20 is an access Layer 2 logical interface for the aggregated link that
bundles physical ports GigabitEthernet 1/1 and GigabitEthernet 1/2. Note that both
GigabitEthernet 1/1 and GigabitEthernet 1/2 have the same Layer 2 attributes: they are
both access ports and they both belong to VLAN 1.
Similarly, port-channel 21 is a trunk Layer 2 logical interface for the aggregated link that
bundles GigabitEthernet 2/1 and GigabitEthernet 2/2 physical interfaces. Both
GigabitEthernet 2/1 and GigabitEthernet 2/2 are configured as trunks and allow the
same VLANs: VLAN 1 and VLAN 2.
VLAN 1 and VLAN 2 have corresponding Switch Virtual Interfaces (SVIs) configured.
These SVIs provide Layer 3 IP connectivity to their corresponding VLANs. Although
related to those SVIs, both EtherChannels that are represented by port-channel 20 and
port-channel 21 are still Layer 2 aggregated links, for example, they run Layer 2
management protocols.
Port-channel 22 is a routed logical interface for the aggregated link that bundles
physical ports GigabitEthernet 1/3 and GigabitEthernet 1/4. Both GigabitEthernet 1/3
and GigabitEthernet 1/4 are configured as routed ports. The figure also shows an
unaggregated routed port GigabitEthernet 2/3.
Configuring and Verifying EtherChannel
Configuring EtherChannel
EtherChannel bundles individual links into a single logical interface called a port
channel. There are slight differences in configuration of Layer 2 EtherChannel and
Layer 3 EtherChannel. For both types of EtherChannels, you configure interface
bundling on physical interfaces. Once interfaces are bundled, you configure aggregated
link parameters on the logical port channel interface.
Requirements and restrictions include:
•
•
•
•
•
•
•
All Ethernet interfaces must support EtherChannel.
The same configuration options must be supported on both devices connected with the
aggregated link. You should verify which configuration options are available on devices.
Some router platforms support only manual configuration.
You can typically group from two to eight physical ports, but some platforms allow more
ports to be included. Verify the maximum allowed number of ports that you can bundle.
The interface mode, switched or routed, should be the same for aggregated interface
and for member interfaces.
You cannot mix port types within a single EtherChannel. For example, you could group
four FastEthernet ports into one logical Ethernet link, but you could not group two
FastEthernet ports and two GigabitEthernet ports into one logical Ethernet link. There is
no requirement that the interfaces should be physically contiguous, or on the same
module.
All ports on both devices must be correctly configured. The individual links must match
on several parameters:
Speed and duplex settings must be the same on all the participating links.
•
•
•
Interface mode must match: you cannot aggregate switched and routed ports in the
same EtherChannel.
Switchport mode must match: all interfaces in the EtherChannel bundle must be
assigned to the same VLAN or be configured as a trunk.
VLAN information must match: access ports must be assigned to the same VLAN.
Trunk ports must have the same allowed range of VLANs. The native VLAN must be the
same on all the participating links.
You should ensure that interfaces have consistent settings before you bundle them. If
you later have to change these settings, configure them on the corresponding portchannel interface.
After you configure the port channel interface, any configuration that you apply to the
port channel interface affects member interfaces as well. The opposite does not apply
and will cause interface incompatibility and link suspension from the EtherChannel.
It is recommended that you configure LACP protocol to establish EtherChannel links, if
the platform you are working on supports it. LACP can prevent misconfiguration issues
by ensuring that configurations at both ends of the aggregated link fulfill the link
aggregation requirements.
To ensure configuration consistency of the physical interfaces, you can utilize
the interface range command. The syntax of the command requires that you enter the
interface type, followed by identifiers of the first and the last interface in the range.
The example in the figure shows how the interface range command is used to
configure four GigabitEthernet interfaces of SW1. The range is specified by providing
interface type (GigabitEthernet), and identifiers of the first interface and the last
interface (0/1–4). The command in the example specifies four interfaces, the first being
GigabitEthernet 0/1, and the last being GigabitEthernet 0/4. Once you specify the range,
all the configuration commands that follow apply to all the interfaces included in the
range. Using theinterface range command, you easily ensure that all the interfaces
have the same configuration. A similar configuration must be applied on the SW2 switch
also.
Once you successfully bundle the ports, you can ensure consistent configuration by
applying it to the port-channel interface.
When configuring EtherChannel, a good practice is to start by shutting down the
interfaces to be aggregated, so that incomplete configuration will not start to create
activity on the link.
After shutting down the member interfaces, proceed by using the channel-group
command to specify the port-channel identifier, also called channel group number, and
the method for establishing the aggregated link.
The command syntax is channel-group channel-group-number mode { on } | { active |
passive }.
•
•
•
•
•
The channel-group command assigns the interface to the port channel interface and
automatically creates the port channel interface. The channel-group-number specifies
the identifier of the port channel interface for the aggregated link.
With the mode keyword, the channel-group command also specifies the method for
link aggregation. The keywords specifying the link aggregation method have the
following meanings:
on: Forces the port to aggregate without LACP. In the on mode, an EtherChannel is
established only when a port group in the on mode is connected to another port group in
the on mode.
active: Enables LACP only if a LACP device is detected at the other end of the link. The
active mode places the port into an active negotiating state in which the port starts
negotiations with other port by sending LACP packets.
passive: Enables LACP on the port and places it into a passive negotiating state in
which the port responds to LACP packets that it receives, but does not start LACP
packet negotiation
The example configuration in the previous figure bundles GigabitEthernet0/1,
GigabitEthernet0/2, GigabitEthernet0/3, and GigabitEthernet0/4 into a Layer 2
EtherChannel link represented by the logical interface port-channel 1. Layer 2 settings
of the EtherChannel interface, trunking, and VLANs allowed on the trunk, are configured
on the logical port channel interface.
The following list summarizes the steps used to configure Layer 2 EtherChannel:
1. Use interface range command to configure interface attributes for interfaces that are
being aggregated [optional].
2. Shut down interfaces that will be aggregated, using the shutdown command.
3. Bundle the interfaces using channel-group command by specifying the port channel
identifier and aggregation method:
• Choose on for manual unconditional aggregation
• Choose active or passive to enable LACP
4. Configure the port-channel interface.
5. Enable interfaces that were previously shut down.
The channel-group identifier does not need to match on both sides of the port channel.
However, it is a good practice to do so because it makes it easier to manage the
configuration.
To configure Layer 2 EtherChannel, you do not need to change the default settings for
the interface modes. On switches, physical interfaces and port-channel interfaces are
Layer 2 ports, or switched ports, by default.
When configuring Layer 3 EtherChannel on a Layer 3 switch, there are several specifics
that you normally do not encounter with Layer 2 EtherChannels.
First, you should ensure that the interfaces that you are aggregating are all routed
interfaces—and that applies to both the port channel interface and to member
interfaces. When configuring Layer 3 EtherChannels, it is recommended that you first
manually create the port channel logical interface, and convert it to the routed interface.
To create the port channel logical interface, use the interface port-channel portchannel-identifier global configuration mode command. By default, port channel
interface is a Layer 2 interface. Therefore, use the no switchport command to make it
a routed interface. The no switchport command deletes any configuration specific to
Layer 2 on the interface.
In the next step, you configure the port channel interface with an IP version 4 (IPv4)
address using the ip address command. Note that the IPv4 address is assigned to the
logical port channel interface, and not to any of the member physical interfaces. If a
member interface already has an IPv4 address assigned, and you wish to assign the
same IPv4 address to the port channel interface, you must first delete the IPv4 address
from the member interface before configuring it on the port channel interface.
Finally, you should configure member interface bundling. For successful bundling to a
Layer 3 EtherChannel, all member interfaces must be routed interfaces. Use the no
switchport command to make the interfaces routed interfaces.
The command used to bundle member interfaces is the same as for the Layer 2
EtherChannels. Use the channel-group command to specify the port channel identifier
and the method of aggregation. The port channel identifier that you choose for the
logical interface must match the number you use with the channel-group command
when configuring member interfaces.
Use LACP where the platforms allow it. If the platform does not support aggregation
protocols, you have to configure static aggregation. Beware that, with static
configuration, misconfigurations on devices are not going to be detected automatically.
The following is an example of Layer 3 EtherChannel configuration.
The example in the figure shows the configuration of a Layer 3 EtherChannel link
between two Layer 3 switches. The configuration example is given only for the SW1
switch. A similar configuration must be applied on the SW2 switch also.
The first line of the configuration creates a logical port channel interface with the
identifier 3. When the port channel interface does not exist, it is created using interface
port-channel command. The port channel interface is configured as a routed interface
using theno switchport command. Once the port channel interface is a routed
interface, you can configure Layer 3 parameters, such as the IPv4 address. The IPv4
address assigned to the port-channel 3 interface on SW 1 is 172.16.3.10/24.
To configure member interface bundling, the example uses the interface
range command. All member interfaces are converted to routed interfaces using the no
switchport command. Interface bundling is specified with the channelgroup command. The channel-group identifier is 3, which matches the identifier of the
previously created port channel interface. The aggregation method is set to on, which
means that the interfaces are bundled manually. For the Layer 3 EtherChannel to be
fully operational, the configuration on SW2 switch must specify the same aggregation
method. The port channel identifier does not need to match between SW1 and SW2
switches, but it is best practice that they do match.
The following list summarizes the steps used to configure Layer 3 EtherChannel:
1. Create a logical port channel interface using interface port-channel command.
2. Turn the logical port channel interface into routed interface, using the no
switchport command.
3. Assign IPv4 address to the port channel interface.
4. Use the interface range command to configure member interfaces:
o Convert member interfaces into routed ports using the no switchport command
o Bundle the interfaces using the channel-group command by specifying the logical
interface identifier and aggregation method: choose on for manual unconditional
aggregation, or choose active or passive to enable LACP.
Verifying EtherChannel Configuration
You can use several commands to verify an EtherChannel configuration. Using
verification commands, you can make sure that EtherChannel link is operational, at
which layer it is operating, whether all its member interfaces are active, which
aggregation method is configured, and so on.
The following commands are available for EtherChannel verification in Cisco IOS
Software:
•
The show interface port-channel command displays the general status of the logical
port channel interface that represents the aggregated link. In the example, the interface
port-channel 1 is operational.
SW1# show interface Port-channel1
Port-channel1 is up, line protocol is up (connected)
Hardware is EtherChannel, address is 000f.34f9.9182 (bia 000f.34f9.9182)
MTU 1500 bytes, BW 200000 Kbit, DLY 100 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
<... output omitted ...>
•
The show etherchannel summary command displays one line of information per port
channel and is particularly useful when several port channel interfaces are configured
on the same device. The output of the command provides, among other, information on
port channel interface status, method used for link aggregation, member interfaces, and
their status. In the example output, the switch has one EtherChannel configured; group
1 uses LACP. The interface bundle consists of the FastEthernet0/1 and FastEthernet0/2
interfaces; the letter P indicates that these ports are bundled. You can see that the
aggregated link is a Layer 2 EtherChannel, and that it is in use. The letters SU indicate
that the interface is a Layer 2 interface: The letter S stands for Layer 2 and the letter U
stands for in use.
SW2# show etherchannel summary
Flags: D - down P - bundled in port-channel
I - stand-alone s - suspended
H - Hot-standby (LACP only)
R - Layer3 S - Layer2
U - in use f - failed to allocate aggregator
M - not in use, minimum links not met
u - unsuitable for bundling
w - waiting to be aggregated
d - default port
Number of channel-groups in use: 1
Number of aggregators: 1
Group Port-channel Protocol Ports
------+-------------+-----------+---------------------------------------1 Po1(SU) LACP Fa0/1(P) Fa0/2(P)
•
The show etherchannel port-channel command displays information about the
specific port channel interface. In the output, theGroup: field indicates the port channel
identifier, which is 1 in the example. The protocol used to bundle the ports is indicated in
theProtocol: output field, and it is LACP in the example. Member interfaces are
indicated in the table called Ports in the Port-channel:and, in this example, the members
are two physical interfaces FastEthernet0/1 and FastEthernet0/2. The EC
state indicates whether the member interface is operational, for instance, whether it
actively participates in the EtherChannel. The example output shows that both member
interfaces are active.
Switch# show etherchannel Port-channel
Channel-group listing:
----------------------
Group: 1
---------Port-channels in the group:
--------------------------Port-channel: Po1 (Primary Aggregator)
-----------Age of the Port-channel = 4d:01h:29m:00s
<... output omitted ...>
Protocol = LACP
<... output omitted ...>
Ports in the Port-channel:
Index Load Port EC state No of bits
------+------+------+------------------+----------0 00 Fa0/1 Active 4
1 00 Fa0/2 Active 4
Time since last port bundled: 0d:00h:00m:18s Fa0/2
Time since last port Un-bundled: 0d:00h:00m:32s Fa0/2
Load does not actually indicate the load over an interface. It is a hexadecimal value that
indicates which interface will be chosen for a specific flow of traffic.
•
The show etherchannel summary command displays a summary of EtherChannel
information. In the following example, you see summarized information about the Layer
3 EtherChannel links on an SW1 switch.
SW1# show etherchannel summary
Flags: D - down P - bundled in port-channel
I - stand-alone s - suspended
H - Hot-standby (LACP only)
R - Layer3 S - Layer2
U - in use f - failed to allocate aggregator
M - not in use, minimum links not met
u - unsuitable for bundling
w - waiting to be aggregated
d - default port
Number of channel-groups in use: 1
Number of aggregators: 1
Group Port-channel Protocol Ports
------+-------------+-----------+---------------------------------------------1 Po5(RU) - Gi0/1(P) Gi0/2(P)
The one-line summary shows the "RU" indication next to the Po5 interface label. The
“R” tells you that port-channel 5 represents a Layer 3 EtherChannel. The member
interfaces GigabitEthernet 0/1 and GigabitEthernet 0/2, are indeed bundled, because
the "P" flag, standing for “bundled in port-channel” is next to each of them. Note that this
command will not give you information about the IPv4 address configured, which you
can obtain using the show ip interface port-channel 5 command
GigabitEthernet 0/1 and GigabitEthernet 0/2 will now behave as one virtual Layer 3
physical interface. For instance, if you issue theshow ip route command, routes will be
seen as being accessible through PortChannel 5 and not either GigabitEthernet 0/1 or
GigabitEthernet 0/2, as illustrated in the following example output:
SW1# show ip route
< output omitted >
172.16.0.0/24 is subnetted, 2 subnets
C 172.16.1.0 is directly connected, Loopback0
O 172.16.2.0 [110/2] via 192.168.1.2, 00:02:37, Port-channel5
C 192.168.1.0/24 is directly connected, Port-channel5
Discovery 17: Configure and Verify EtherChannel
Introduction
The purpose of this activity is to provide you with some experience of working with
EtherChannel. The live virtual lab is prepared with the switches represented in the
topology diagram and the connectivity table. All devices have their basic configurations
in place, including hostnames and IPv4 addresses. Note that all the links between the
switches use pairs of connections. You will see that this fact does not lead to doubling
of the bandwidth by default. You will configure EtherChannel on some of the links,
examine how link aggregation affects STP topology for one of the VLANs, and verify the
EtherChannel configuration.
Topology
Job Aids
The configuration is as follows:
•
All devices have their basic configurations in place, including hostnames and IP
addresses.
Device Information
In the virtual lab environment, all interfaces are Ethernet interfaces and not FastEthernet
or GigabitEthernet interfaces, which you are likely to encounter in networks today.
Personal computers (PCs) and servers (SVRs) in the virtual lab environment are
simulated by routers, so you should use Cisco IOS commands to configure them or
verify the configuration.
Device Details
Device
Interface
Neighbor
Additional Information
SW1
Ethernet 1/0
PC1
access port, VLAN 10
SW1
Ethernet 0/0
SW4
trunk port, native VLAN - 99
SW1
Ethernet 0/1
SW4
trunk port, native VLAN - 99
SW1
Ethernet 0/2
SW3
trunk port, native VLAN - 99
SW1
Ethernet 0/3
SW3
trunk port, native VLAN - 99
PC1
Ethernet0/0
SW1
IPv4 address: 10.10.10.5/24
SW2
Ethernet 1/0
PC2
access port, VLAN 20
SW2
Ethernet 0/0
SW3
trunk port, native VLAN - 99
SW2
Ethernet 0/1
SW3
trunk port, native VLAN - 99
SW2
Ethernet 0/2
SW4
trunk port, native VLAN - 99
SW2
Ethernet 0/3
SW3
trunk port, native VLAN - 99
PC2
Ethernet0/0
SW2
IPv4 address: 10.10.20.5/24
SW3
Ethernet 1/0
SRV1
access port, VLAN 10
SW3
Ethernet 0/0
SW2
trunk port, native VLAN - 99
SW3
Ethernet0/1
SW2
trunk port, native VLAN - 99
SW3
Ethernet 0/2
SW1
trunk port, native VLAN - 99
SW3
Ethernet 0/3
SW1
trunk port, native VLAN - 99
SW3
Ethernet 1/2
SW4
trunk port, native VLAN - 99
Device
Interface
Neighbor
Additional Information
SW3
Ethernet 1/3
SW4
trunk port, native VLAN - 99
SRV1
Ethernet0/0
SW3
IPv4 address: 10.10.10.10/24
SW4
Ethernet1/0
SRV2
access port, VLAN 20
SW4
Ethernet 0/0
SW1
trunk port, native VLAN - 99
SW4
Ethernet 0/1
SW1
trunk port, native VLAN - 99
SW4
Ethernet 0/2
SW2
trunk port, native VLAN - 99
SW4
Ethernet 0/3
SW2
trunk port, native VLAN - 99
SW4
Ethernet 1/2
SW3
trunk port, native VLAN - 99
SW4
Ethernet 1/3
SW3
trunk port, native VLAN - 99
SVR2
Ethernet0/0
SW4
10.10.20.20/24
Device Cabling Details
Switch
Port
Switch
Port
SW1
Ethernet0/0
SW4
Ethernet0/0
SW1
Ethernet0/1
SW4
Ethernet0/1
SW1
Ethernet0/2
SW3
Ethernet0/2
SW1
Ethernet0/3
SW3
Ethernet0/3
SW2
Ethernet0/0
SW3
Ethernet0/0
SW2
Ethernet0/1
SW3
Ethernet0/1
SW2
Ethernet0/2
SW4
Ethernet0/2
Switch
Port
Switch
Port
SW2
Ethernet0/3
SW4
Ethernet0/3
SW3
Ethernet1/2
SW4
Ethernet1/2
SW3
Ethernet1/3
SW4
Ethernet1/3
Task 1: Configure and Verify EtherChannel
Activity
Complete the following steps:
Step 1
Start by accessing the console of SW1 and displaying the interface status summary on
SW1.
On SW1, enter the following command:
SW1# show interfaces status
Port Name Status Vlan Duplex Speed Type
Et0/0 Link to SW4 connected trunk auto auto unknown
Et0/1 Link to SW4 connected trunk auto auto unknown
Et0/2 Link to SW3 connected trunk auto auto unknown
Et0/3 Link to SW3 connected trunk auto auto unknown
Et1/0 Link to PC1 connected 10 auto auto unknown
Et1/1 disabled 1 auto auto unknown
Et1/2 disabled 1 auto auto unknown
Et1/3 disabled 1 auto auto unknown
Ethernet0/2 and Ethernet 0/3, which are connected to SW3 are trunk interfaces.
Trunking is configured with the native VLAN set to VLAN 99.
Ethernet1/0 is an access interface, assigned to VLAN 10.
Ethernet 0/0 and Ethernet 0/1 are also trunk interfaces. They are connected to SW4
switch, and configured with the native VLAN set to VLAN 99.
Interfaces Ethernet 1/1, Ethernet 1/2, and Ethernet 1/3 are not in use and are disabled.
Step 2
Examine the topology. Switches are interconnected with multiple trunk connections.
There are many physical loops in the topology. To understand what the topology is,
after the STP performs its processing, you need to examine the STP information on the
switches. You need to establish what the resulting topology is for each VLAN after STP
calculations. To begin, display the spanning tree information for VLAN 10 on SW1. To
view STP information, use the show spanning-tree command. To view STP
information for a specific VLAN, use the show spanning-tree vlan vlan-id command
with the appropriate VLAN identifier. Display the spanning tree information for VLAN 10
on the other switches to complete your understanding of the VLAN 10 topology. Then
examine the STP configuration for VLANs 20 and 1, to determine the STP topology for
these VLANs.
On SW1, enter the following command:
SW1# show spanning-tree vlan 10
VLAN0010
Spanning tree enabled protocol ieee
Root ID Priority 24586
Address aabb.cc00.0d00
Cost 100
Port 3 (Ethernet0/2)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Bridge ID Priority 32778 (priority 32768 sys-id-ext 10)
Address aabb.cc00.0b00
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Aging Time 300 sec
Interface Role Sts Cost Prio.Nbr Type
------------------- ---- --- --------- -------- ------------------------------Et0/0 Altn BLK 100 128.1 Shr
Et0/1 Altn BLK 100 128.2 Shr
Et0/2 Root FWD 100 128.3 Shr
Et0/3 Altn BLK 100 128.4 Shr
Et1/0 Desg FWD 100 128.5 Shr
The MAC addresses might differ in your output.
The output you are seeing displays STP-related information for VLAN 10. The
VLAN0010 ‘title’ indicates that you are seeing STP information only for VLAN 10, which
is named VLAN0010.
The first part of the output provides two blocks of similar information; the first block
gives information about the root switch, and the second block gives information about
the switch you are administering. The STP information for the root switch provides the
STP priority and MAC address, the STP cost to the root switch, root port identifier (on
your switch), and the STP timers. When the switch you are administering is the root
switch, in place of the cost and port identifier, you will see the phrase This bridge is the
root. As you can see from the output, SW1 is not the root switch.
The second block of information provides STP priority and MAC address, STP timers,
and aging time for the switch you are administering.
The second part of the output is the table showing interface STP information, in
particular STP role, STP status, STP cost, STP interface priority, and STP type, for all
interfaces that are part of the VLAN that you specified in the command.
Both Eternet0/2 and 0/3 connect to SW3, but only Ethernet0/2 is forwarding traffic. The
STP is blocking Ethernet0/3 to prevent a loop. Only half of the potential bandwidth in
this pair of links is in use. Ethernet 0/0 and Ethernet 0/1 interfaces are both in the
blocking state. They are not forwarding traffic. All interfaces have STP cost of 100.
To determine the resulting STP topology for VLAN 10, you need to examine the STP
information on other switches also.
To identify the root switch in the topology, follow the direction in which the Root port is
facing. In this case, the Root port is Etherent0/2 facing toward SW3. On SW3, enter
the show spanning-tree vlan 10 command.
SW3# show spanning-tree vlan 10
VLAN0010
Spanning tree enabled protocol ieee
Root ID Priority 24586
Address aabb.cc01.2100
This bridge is the root
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Bridge ID Priority 24586 (priority 24576 sys-id-ext 10)
Address aabb.cc01.2100
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Aging Time 300 sec
Interface Role Sts Cost Prio.Nbr Type
------------------- ---- --- --------- -------- ------------------------------Et0/0 Desg FWD 100 128.1 Shr
Et0/1 Desg FWD 100 128.2 Shr
Et0/2 Desg FWD 100 128.3 Shr
Et0/3 Desg FWD 100 128.4 Shr
Et1/0 Desg FWD 100 128.5 Shr
Et1/2 Desg FWD 100 128.7 Shr
Et1/3 Desg FWD 100 128.8 Shr
Notice the previously mentioned This bridge is the root message—you have
discovered the root switch. Also notice that none of the interfaces have the Root role,
they are all designated ports, which is another indicator that you have discovered the
root switch.
After you examine STP information for VLAN 10 on all the switches, the resulting
topology should look like the one in the following figure.
Also, examine the STP configuration for other VLANs and determine the STP topology
for VLAN 20 and VLAN 1. For your reference, these two STP topologies are also shown
below.
Step 3
To better utilize the links between the SW1 and SW3 switches, you will aggregate them
into a Layer 2 EtherChannel link. Start the configuration by shutting down interfaces
Ethernet0/2 and Ethernet0/3 on the SW1 switch. Disable both interfaces at the same
time.
On SW1, enter the following commands:
SW1# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW1(config)# interface range Ethernet0/2 - 3
SW1(config-if-range)# shutdown
*Dec 28 09:09:31.692: %LINK-5-CHANGED: Interface Ethernet0/2, changed state
to administratively down
*Dec 28 09:09:31.693: %LINK-5-CHANGED: Interface Ethernet0/3, changed state
to administratively down
*Dec 28 09:09:32.693: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Ethernet0/2, changed state to down
*Dec 28 09:09:32.694: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Ethernet0/3, changed state to down
Having interfaces disabled while you are configuring them ensures that the incomplete
configuration will not create activity on the link.
Step 4
Shut down interfaces Ethernet0/2 and Ethernet0/3 on switch SW3.
On SW3, enter the following commands:
SW3# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW3(config)# interface range Ethernet0/2 - 3
SW3(config-if-range)# shutdown
*Dec 28 09:10:17.356: %LINK-5-CHANGED: Interface Ethernet0/2, changed state
to administratively down
*Dec 28 09:10:17.356: %LINK-5-CHANGED: Interface Ethernet0/3, changed state
to administratively down
SW3(config-if-range)#
*Dec 28 09:10:18.360: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Ethernet0/2, changed state to down
*Dec 28 09:10:18.360: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Ethernet0/3, changed state to down
Step 5
On SW1, bundle Ethernet0/2 and Ethernet 0/3 interfaces to the logical interface portchannel 1. The aggregation should be negotiated by the LACP protocol.
On SW1, enter the following commands:
SW1(config-if-range)# channel-group 1 mode active
Creating a port-channel interface Port-channel 1
SW1(config-if-range)#
Step 6
On SW3, bundle Ethernet0/2 and Ethernet 0/3 to logical interface port channel 1 using
the LACP protocol active mode.
On SW3, enter the following commands:
SW3(config-if-range)# channel-group 1 mode active
Creating a port-channel interface Port-channel 1
SW3(config-if-range)#
Note that you have configured both sides of the links to be in the LACP active state,
which means to actively negotiate link aggregation. For successful aggregation, it would
be enough to have only one side operating in the LACP active mode; the other could be
configured to be in passive mode.
Step 7
Ethernet 0/2 and Ethernet 0/3 interfaces on both switches have a matching
configuration regarding the following: speed and duplex attributes, switchport mode set
to trunk, native VLAN, and all allowed VLANs on the trunk. Thus, the pre-conditions for
successful establishment of the EtherChannel link are fulfilled. You can enable
interfaces Ethernet0/2 and Ethernet0/3 on switch SW1.
On SW1, enter the following commands:
SW1(config-if-range)# no shutdown
Step 8
Enable interfaces Ethernet0/2 and Ethernet0/3 on switch SW3.
On SW3, enter the following commands:
SW3(config-if-range)# no shutdown
*Dec 28 09:13:11.268: %LINK-3-UPDOWN: Interface Ethernet0/2, changed state to
up
*Dec 28 09:13:11.268: %LINK-3-UPDOWN: Interface Ethernet0/3, changed state to
up
*Dec 28 09:13:12.272: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Ethernet0/2, changed state to up
*Dec 28 09:13:12.272: %LINEPROTO-5-UPDOWN: Line protocol on Interface
Ethernet0/3, changed state to up
SW3(config-if-range)#
*Dec 28 09:13:18.543: %LINEPROTO-5-UPDOWN: Line protocol on Interface Port-
channel1, changed state to up
Line protocol for physical interfaces Ethernet 0/2 and Ethernet 0/3 changes state to up.
Logical interface port channel 1 also transitions to the up state.
Step 9
Add the description EChannel to SW3 to port channel 1 interface on SW1 switch.
On SW1, enter the following commands:
SW1(config-if-range)# exit
SW1(config)# interface port-channel 1
SW1(config-if)# description EChannel to SW3
SW1(config-if)# end
SW1#
Step 10
Add the description EChannel to SW1 to port channel 1 interface on SW3 switch.
On SW3, enter the following commands:
SW3(config-if-range)# exit
SW3(config-if)# interface port-channel 1
SW3(config-if)# description EChannel to SW1
SW3(config-if)# end
SW3#
Step 11
Display the interface status summary on SW1.
On SW1, enter the following command:
SW1# show interfaces status
Port Name Status Vlan Duplex Speed Type
Et0/0 Link to SW4 connected trunk auto auto unknown
Et0/1 Link to SW4 connected trunk auto auto unknown
Et0/2 Link to SW3 connected trunk auto auto unknown
Et0/3 Link to SW3 connected trunk auto auto unknown
Et1/0 Link to PC1 connected 10 auto auto unknown
Et1/1 disabled 1 auto auto unknown
Et1/2 disabled 1 auto auto unknown
Et1/3 disabled 1 auto auto unknown
Po1 EChannel to SW3 connected trunk auto auto
Ethernet0/2 and 0/3 information is still present in the output, like when you first
displayed interface statuses. In addition, now Po1 is also listed. The port channel is up
on SW1.
Step 12
Display the interface status summary on SW3.
On SW3, enter the following command:
SW3# show interfaces status
Port Name Status Vlan Duplex Speed Type
Et0/0 Link to SW2 connected trunk auto auto unknown
Et0/1 Link to SW2 connected trunk auto auto unknown
Et0/2 Link to SW1 connected trunk auto auto unknown
Et0/3 Link to SW1 connected trunk auto auto unknown
Et1/0 Link to SRV1 connected 10 auto auto unknown
Et1/1 disabled 1 auto auto unknown
Et1/2 Link to SW4 connected trunk auto auto unknown
Et1/3 Link to SW4 connected trunk auto auto unknown
Po1 EChannel to SW1 connected trunk auto auto
Port Po1 is listed in the output, along with all other SW3 interfaces. The port channel is
up on SW3.
Step 13
To analyze whether and how the bundling of ports affected the STP topology, display
the spanning tree information for VLAN 10 on SW1 again. You should notice changes
compared to what you were seeing before the links were aggregated.
On SW1, enter the following command:
SW1# show spanning-tree vlan 10
VLAN0010
Spanning tree enabled protocol ieee
Root ID Priority 24586
Address aabb.cc00.0800
Cost 56
Port 65 (Port-channel1)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Bridge ID Priority 32778 (priority 32768 sys-id-ext 10)
Address aabb.cc00.0500
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Aging Time 15 sec
Interface Role Sts Cost Prio.Nbr Type
------------------- ---- --- --------- -------- ------------------------------Et0/0 Desg FWD 100 128.1 Shr
Et0/1 Desg FWD 100 128.2 Shr
Et1/0 Desg FWD 100 128.5 Shr
Po1 Root FWD 56 128.65 Shr
If you display spanning tree information quickly enough, you may find interfaces
Ethernet0/0 and 0/1 in listening or learning state. If so, repeat the command until all
interfaces are in the forwarding state. The cost of the port channel is 56, which is much
lower than the cost of 100, assigned to individual interfaces.
The MAC addresses might differ in your output.
Ethernet0/2 and 0/3 are no longer visible to the spanning tree. Instead, they have been
replaced by the logical port channel 1 interface. The port channel is in the forwarding
state. The forwarding state implies that the port channel is forwarding on all member
interfaces. The cost of the port channel is 56, which is much lower than the cost of 100,
assigned to individual interfaces. The following figure shows the STP topology for VLAN
10, after the link aggregation.
The Ethernet0/0 and Ethernet 0/1 are not in the blocking state any more. They are now
forwarding. These interfaces connect to SW4. Since the path from SW1 back to the root
(SW3) now costs less due to the port channel establishment, its ports have been
selected as the designated ports for these two links. However, the ports on SW4 side of
the links are now in the blocking state, which you can verify by issuing the show
spanning-tree vlan 10 command on SW4:
SW4# show spanning-tree vlan 10
VLAN0010
Spanning tree enabled protocol ieee
Root ID Priority 24586
Address aabb.cc01.2100
Cost 100
Port 7 (Ethernet1/2)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Bridge ID Priority 28682 (priority 28672 sys-id-ext 10)
Address aabb.cc01.2200
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Aging Time 300 sec
Interface Role Sts Cost Prio.Nbr Type
------------------- ---- --- --------- -------- -------------------------------
Et0/0 Altn BLK 100 128.1 Shr
Et0/1 Altn BLK 100 128.2 Shr
Et0/2 Desg FWD 100 128.3 Shr
Et0/3 Desg FWD 100 128.4 Shr
Et1/2 Root FWD 100 128.7 Shr
Et1/3 Altn BLK 100 128.8 Shr
Note that aggregating links does not affect STP root switch selection. The root selection
is based on the switch STP priority and its MAC address.
Step 14
Now that you have successfully configured link aggregation, verify the configuration by
displaying the interface information of the port channel 1 interface on SW1.
On SW1, enter the following command:
SW1# show interfaces Port-channel 1
Port-channel1 is up, line protocol is up (connected)
Hardware is Ethernet, address is aabb.cc00.0530 (bia aabb.cc00.0530)
Description: EChannel to SW3
MTU 1500 bytes, BW 20000 Kbit/sec, DLY 1000 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Auto-duplex, Auto-speed, media type is unknown
input flow-control is off, output flow-control is unsupported
Members in this channel: Et0/2 Et0/3
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:00, output never, output hang never
Last clearing of "show interface" counters never
Input queue: 0/2000/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
2041 packets input, 162930 bytes, 0 no buffer
Received 1858 broadcasts (0 multicasts)
0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 input packets with dribble condition detected
2069 packets output, 158394 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 unknown protocol drops
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier
0 output buffer failures, 0 output buffers swapped out
From the output, you can determine that the port channel 1 bundles Ethernet0/2 and
Ethernet 0/3 interfaces, and that the logical bandwidth of the aggregated link is 20 Mbps
(20000 Kbit/s), twice the bandwidth of the individual interfaces.
Step 15
To view aggregation details, such as aggregation method and how long the aggregated
link has been up, display the detailed EtherChannel information on SW1.
On SW1, enter the following command:
SW1# show etherchannel port-channel
Channel-group listing:
---------------------Group: 1
---------Port-channels in the group:
--------------------------Port-channel: Po1 (Primary Aggregator)
-----------Age of the Port-channel = 0d:01h:11m:56s
Logical slot/port = 16/0 Number of ports = 2
HotStandBy port = null
Port state = Port-channel Ag-Inuse
Protocol = LACP
Port security = Disabled
Ports in the Port-channel:
Index Load Port EC state No of bits
------+------+------+------------------+----------0 00 Et0/2 Active 0
0 00 Et0/3 Active 0
Time since last port bundled: 0d:01h:11m:39s Et0/2
From the output, you can determine that the number of ports in this port channel is two.
The members are the Ethernet0/2 and Ethernet0/3 interfaces. The protocol that was
used to build the bundle is LACP.
Step 16
View summarized information about the aggregated EtherChannel links on the SW1
switch.
On SW1, enter the following command:
SW1# show etherchannel summary
Flags: D - down P - bundled in port-channel
I - stand-alone s - suspended
H - Hot-standby (LACP only)
R - Layer3 S - Layer2
U - in use f - failed to allocate aggregator
M - not in use, minimum links not met
u - unsuitable for bundling
w - waiting to be aggregated
d - default port
Number of channel-groups in use: 1
Number of aggregators: 1
Group Port-channel Protocol Ports
------+-------------+-----------+----------------------------------------------
1 Po1(SU) LACP Et0/2(P) Et0/3(P)
The EtherChannel information is shown in one line, and includes EtherChannel type,
status of the port channel interface and its member interfaces, and aggregation method.
From the output, you can determine that the Layer 2 port channel 1 is operational
(indicated by SU flags), that it has two member interfaces that are both active in the
aggregated link (indicated by the P flag), and that aggregation was performed using
LACP.
You have successfully configured and verified Layer 2 EtherChannel between the SW1
and SW3 switches.
Improve Redundant Switched Topologies with
EtherChannel
FASTLab 7: Improve Redundant Switched Topologies with
EtherChannel
Scenario
Read the requirements in the Scenario carefully and use the Configuration Tips to help
you do the required steps. If you need further assistance, refer to the Answer Key. Once
you have completed the configuration specified, answer the questions.
Ana is testing the EtherChannel configuration for a new LAN implementation. She has
completed the physical set-up and IPv4 addressing. She has also created the VLANs.
She needs your help with configuring an EtherChannel to bundle the Ethernet interfaces
(E0/0, E0/1, E0/2, and E0/3) connecting the two switches. The switches are intended to
operate with devices of other vendors, therefore, Ana chooses to implement only
standardized protocols. PC1 and PC2 are in VLAN 11.
Here are the requirements for the lab:
•
You need to group the existing four links into a single channel group using port channel
identifier 12. Switch SW1 needs to initiate the EtherChannel while switch SW2 should
only respond to it.
•
•
You need to make sure that the port channel trunk encapsulation is dot1q and then
enable trunking on the port channel.
Once you have completed the configuration, perform a connectivity check between PC1
and PC2 using ping ping. The ping test should be successful.
Topology
Job Aid
If you shut down an interface on a real router or switch, the connected device will see it
as "down/down." Due to virtualization specifics, Cisco IOL (Cisco IOS Software on
Linux) behavior is slightly different. If you shut down an interface on a router or switch,
the connected device will see it as "up/up." In Cisco IOL, the status of an interface can
only be "up/up" or "administratively down/down." Also, in the virtual lab environment,
all interfaces are Ethernet interfaces and not FastEthernet or GigabitEthernet interfaces,
which you are likely to encounter in networks today.
Device Information
Device
Remote Device Connection
SW1 (Ethernet 0/0)
SW2 (Ethernet 0/0)
SW1 (Ethernet 0/1)
SW2 (Ethernet 0/1)
SW1 (Ethernet 0/2)
SW2 (Ethernet 0/2)
SW1 (Ethernet 0/3)
SW2 (Ethernet 0/3)
SW1 (Ethernet 1/0)
PC1 (10.10.11.11)
SW2 (Ethernet 1/0)
PC2 (10.10.11.12)
Configuration Tips
Use the interface range command to configure multiple interfaces at the same time.
Use the channel-group command to bundle interfaces and to specify the aggregation
method.
After the aggregated link is established, configure trunking parameters on the portchannel, by first using the interface port-channelcommand.
Answer Key
•
You need to group the existing four links into a single channel group using port channel
identifier 12. Switch SW1 needs to initiate the EtherChannel while switch SW2 should
only respond to it.
First disable the interfaces on each switch and then configure the port channel:
SW1>enable
SW1#configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW1(config)#
SW1(config)# interface range ethernet 0/0-3
SW1(config-if-range)# shutdown
SW1(config-if-range)# channel-group 12 mode active
Creating a port-channel interface Port-channel 12
SW1(config-if-range)#
SW2> enable
SW2# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
SW2(config)#
SW2(config)# interface range ethernet 0/0-3
SW2(config-if-range)# shutdown
SW2(config-if-range)# channel-group 12 mode passive
Creating a port-channel interface Port-channel 12
SW2(config-if-range)#
•
You need to make sure that the port channel trunk encapsulation is dot1q and then
enable trunking on the port channel.
First configure the port-channel on each switch:
SW1(config)# interface port-channel 12
SW1(config-if)# switchport trunk encapsulation dot1q
SW1(config-if)# switchport mode trunk
SW1(config-if-range)# exit
SW2(config)# interface port-channel 12
SW2(config-if)# switchport trunk encapsulation dot1q
SW2(config-if)# switchport mode trunk
SW2(config-if-range)# exit
After the port-channel is configured on both switches, then enable the interfaces on both
switches (if you enable one side before the other side is configured, you will get errors
and the EtherChannel will not come up). Note that you may get error messages as you
enable each switch; wait a few seconds for the port channel to come up fully before you
verify your configuration.
SW1(config)# interface range Ethernet0/0-3
SW1(config-if-range)# no shutdown
SW2(config)# interface range Ethernet0/0-3
SW2(config-if-range)# no shutdown
•
Once you have completed the configuration, perform a connectivity check between PC1
and PC2 using ping. The test should be successful.
PC1> enable
PC1# ping 10.10.11.12
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.11.12, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/2 ms
PC1#
PC2> enable
PC2# ping 10.10.11.11
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.11.11, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/2 ms
PC2>
•
Execute the show interfaces trunk command on SW1 to verify the configuration.
SW1#show interfaces trunk
Port Mode Encapsulation Status Native vlan
Po12 on 802.1q trunking 1
Port Vlans allowed on trunk
Po12 1-4094
Port Vlans allowed and active in management domain
Po12 1-4094
Port Vlans in spanning tree forwarding state and not pruned
Po12 1-4094
SW1#
Execute the show etherchannel summary command on SW2 to verify the
configuration.
SW2#show etherchannel summary
Flags: D - down P - bundled in port-channel
I - stand-alone s - suspended
H - Hot-standby (LACP only)
R - Layer3 S - Layer2
U - in use f - failed to allocate aggregator
M - not in use, minimum links not met
u - unsuitable for bundling
w - waiting to be aggregated
d - default port
Number of channel-groups in use: 1
Number of aggregators: 1
Group Port-channel Protocol Ports
------+-------------+-----------+---------------------------------------------12 Po12(SU) LACP Et0/0(P) Et0/1(P) Et0/2(P)
Et0/3(P)
SW2#
Exploring Layer 3 Redundancy
Introduction
The content in this section is self-study material and will not be delivered in class by
your instructor.
End devices are typically configured with a single default gateway Internet Protocol (IP)
address that does not change when the network topology changes. If the router whose
IP address is configured as the default gateway fails, the local device is unable to send
packets off the local network segment, so it effectively gets disconnected from the rest
of the network. Even if a redundant router exists that could serve as a default gateway
for that segment, there is no dynamic method to help the devices in the segment
determine the address of a new default gateway.
A solution lies in creating a type of router redundancy, where a set of routers work
together to present the illusion of a single router to the hosts on the Local Area Network
(LAN). By sharing an IP address and a Media Access Control (MAC) address, two or
more routers can act as a single “virtual” router. The redundancy protocol provides the
mechanism for determining which router should take the active role in forwarding traffic
and determining when that role must be taken over by a standby router. The transition
from one forwarding router to another is transparent to the end devices. Even though
the example is explained on routers, in modern networks, the devices performing this
function would typically be Layer 3 switches.
Cisco Enterprise Architecture Model
As a networking engineer, you will need to be familiar with Layer 3 redundancy,
including the basic concepts:
•
•
The need for default gateway redundancy.
The default gateway redundancy protocol options.
•
Need for Default Gateway Redundancy
•
When routers have different paths to specific destinations (through redundant
next-hop routers) and the primary path becomes unavailable, the routing protocol
between the routers will dynamically converge, providing a connection through
the secondary path.
Hosts that run routing protocols can react in the same manner when the primary
path towards different subnets fails, since they do not depend on a default
gateway configuration. For example, you can have a Microsoft Windows server
with the LAN routing feature that can communicate with two different routers to
establish connectivity to remote subnets. If the primary router fails, the server will
use the information from the routing protocol to switch to the secondary path.
However, most client computers, servers, printers, and so on do not support
dynamic routing protocols and whenever they need to communicate with a host
that is located in a different subnet, they must relay packets through the default
gateway. Therefore, the availability of this gateway is extremely important.
For example, a company that has dual redundant routers that connect users to
the internet may experience a problem when the primary router goes down.
Without an extra protocol, none of the devices on the company's network can
access the internet because of the primary router failure. Even though the
secondary router is operational, the devices may not be configured to access a
secondary router when the primary router goes down. Hence, an extra feature is
needed that can provide default gateway redundancy to the clients.
The following figure illustrates a topology with redundant routers that provide
routing functions in the specific segment. When the host determines that a
destination IP version 4 (IPv4) network is not on its local subnet, it forwards the
packet to the default gateway. Most IPv4 hosts do not run a dynamic routing
protocol to build a list of reachable networks. Instead, they rely on a manually
configured or dynamically learned default gateway to route all packets. Typically,
IPv4 hosts are configured to request addressing information, including the default
gateway, from a Dynamic Host Configuration Protocol (DHCP) server.
•
•
•
•
•
•
•
Redundant equipment alone does not guarantee failover. In this example, both
Router A and Router B are responsible for routing packets for the 10.1.10.0/24
subnet. Because the routers are deployed as a redundant pair, if Router A
becomes unavailable, the interior gateway protocol (IGP) can quickly and
dynamically converge and determine that Router B will now transfer the packets
that would otherwise have gone through Router A. Because the end device does
not run a routing protocol, it will not receive the dynamic routing information.
The end device is configured with a single default gateway IPv4 address, which
does not dynamically update when the network topology changes. If the default
gateway fails, the local device is unable to send packets out of the local network
segment. As a result, the host is isolated from the rest of the network. Even if a
redundant router that could serve as a default gateway for that segment exists,
there is no dynamic method by which these devices can determine the address
of a new default gateway.
Though the example is illustrated on routers, it is equally valid on Layer 3 switches.
Understanding FHRP
Since most IP hosts have a single default gateway IP address, which does not change
when the network topology changes, an extra feature on routers is needed that can
provide Layer 3 gateway redundancy to the hosts. First Hop Redundancy Protocols
(FHRPs) are a group of protocols with similar functionality that enable a set of routers or
Layer 3 switches to present an illusion of a "virtual" router. The virtual router is assigned
a virtual IP address and virtual MAC address, which is shared by two routers. This is the
base prerequisite to achieve gateway redundancy to hosts that cannot detect a change
in the network.
The following figure represents a generic FHRP scenario with a set of routers working
together to present the illusion of a single router to the hosts on the LAN. By sharing an
IP (Layer 3) address and a MAC (Layer 2) address, two or more routers can act as a
single "virtual" router.
Hosts that are on the local subnet should have the IP address of the virtual router as
their default gateway. When an IPv4 host needs to communicate to another IPv4 host
on a different subnet, it will use Address Resolution Protocol (ARP) to resolve the MAC
address of the default gateway. The ARP resolution returns the MAC address of the
virtual router. The host then encapsulates the packets inside frames sent to the MAC
address of the virtual router; these packets are then routed to their destination by any
active router that is part of that virtual router group. The standby router takes over if the
active router fails. Therefore, the virtual router as a concept has an active (forwarding)
router and standby router.
You use an FHRP to coordinate two or more routers as the devices that are responsible
for processing the packets that are sent to the virtual router. The host devices send
traffic to the address of the virtual router. The actual (physical) router that forwards this
traffic is transparent to the end stations.
The redundancy protocol provides the mechanism for determining which router should
take the active role in forwarding traffic and determining when a standby router should
take over that role. When the forwarding router fails, the standby router detects the
change and a failover occurs. Hence, the standby router becomes active and starts
forwarding traffic destined for the shared IP address and MAC address. The transition
from one forwarding router to another is transparent to the end devices.
A common feature of FHRP is to provide a default gateway failover that is transparent to
hosts. Cisco routers and switches typically support the use of three FHRPs:
1. Hot Standby Router Protocol (HSRP): HSRP is an FHRP that Cisco designed to
create a redundancy framework between network routers or Layer 3 switches to
achieve default gateway failover capabilities. Only one router per subnet forwards
traffic. HSRP is defined in Request for Comments (RFC) 2281.
2. Virtual Router Redundancy Protocol (VRRP): VRRP is an open FHRP standard that
offers the ability to add more than two routers for additional redundancy. Only one
router per subnet forwards traffic. VRRP is defined in RFC 5798.
3. Gateway Load Balancing Protocol (GLBP): GLBP is an FHRP that Cisco designed to
allow multiple active forwarders to load-balance outgoing traffic on a per host basis
rather than a per subnet basis like HSRP.
The routers communicate FHRP information between each other through hello
messages, which also represent a keepalive mechanism. This figure illustrates the
FHRP failover process.
When the forwarding router or the link, where FHRP is configured, fails, these steps
take place:
1. The standby router stops seeing hello messages from the forwarding router.
2. The standby router assumes the role of the forwarding router.
3. Because the new forwarding router assumes both the IP and MAC addresses of the
virtual router, the end stations see no disruption in service.
Understanding HSRP
HSRP is an FHRP that facilitates transparent failover of the first-hop IP device (default
gateway). When you use HSRP, you configure the host with the HSRP virtual IP
address as its default gateway, instead of using the IP address of the router.
HSRP Overview
HSRP defines a standby group of routers, while one router is designated as the active
router, as depicted in this figure.
HSRP provides gateway redundancy by sharing IP and MAC addresses between
redundant gateways. The protocol consists of virtual IP and MAC addresses that the
two routers that belong to the same HSRP group share between each other.
Hosts on the IP subnet that are protected by HSRP have their default gateway
configured with the HSRP group virtual IP address.
When IPv4 hosts use ARP to resolve the MAC address of the default gateway IPv4
address, the active HSRP router responds with the shared virtual MAC address. The
packets that are received on the virtual IPv4 address are forwarded to the active router.
The HSRP active and the standby router perform the following functions:
•
•
•
•
•
•
•
•
•
•
Active router:
Responds to default gateway ARP requests with the virtual router MAC address
Assumes active forwarding of packets for the virtual router
Sends hello messages between the active and standby routers
Knows the virtual router IPv4 address
Standby router:
Sends hello messages
Listens for periodic hello messages
Assumes active forwarding of packets if it does not hear from active router
Sends Gratuitous ARP message when standby becomes active
HSRP routers send hello messages that reach all HSRP routers. The active router
sources hello packets from its configured IPv4 address and the shared virtual MAC
address. The standby router sources hellos from its configured IPv4 address and its
burned-in MAC address (BIA). Hence, the HSRP routers can identify who is the active
and who is the standby router.
The following table summarizes the HSRP terminology.
HSRP Terminology
Term
Definition
Active router
The router that is currently forwarding packets for the virtual router
Standby router The primary backup router
Standby group The set of routers participating in HSRP that jointly emulate a virtual router
The function of the HSRP standby router is to monitor the operational status of the
HSRP group and to quickly assume the packet-forwarding responsibility if the active
router becomes inoperable. When the primary HSRP router comes back online, it will
not regain the active role by default. To transfer the active role to the primary router, you
have to configure pre-emption.
The standby preempt command enables the HSRP router with the highest priority to
immediately become the active router. Priority is determined first by the configured
priority value, and then by the IPv4 address. In each case, a higher value is of greater
priority. Pre-emption is recommended because you want your network to have
deterministic behavior.
HSRP for IPv4 has two versions: Version 1 and Version 2. The default HSRP version is
1. Because the two versions are not compatible, you must use the same version on
your HSRP enabled routers.
The shared virtual MAC address is generated by combining a specific MAC address
range and the HSRP group number. HSRP Version 1 uses a MAC address in the form
0000.0C07.ACXX and HSRP Version 2 uses a MAC address in the form
0000.0C9F.FXXX, where XX or XXX stand for the group number. For example, the
virtual MAC address for a HSRP Version 2 virtual router in group 10 would be
0000.0C9F.F00A. The A in 00A is the hexadecimal value for 10.
In addition, routers with HSRP Version 1 send hello packets to the multicast address of
224.0.0.2 (reserved multicast address used to communicate to all routers) on User
Datagram Protocol (UDP) port 1985, while HSRP Version 2 uses the 224.0.0.102
multicast address on UDP port 1985.
HSRP Advanced Features
Besides the default behavior, you can configure some other HSRP features to increase
your network availability and performance:
•
•
Load balancing: Routers can simultaneously provide redundant backup and perform
load sharing across various subnets and virtual local-area networks (VLANs).
Interface tracking: When a tracked interface becomes unavailable, the HSRP tracking
feature ensures that a router with the unavailable interface will relinquish the active
router role.
The following figure illustrates a topology with multiple VLANs that can benefit from the
HSRP load-balancing feature.
The two Layer 3 switches have HSRP enabled in two separate VLANs. For each VLAN,
HSRP allocates a standby group, a virtual IPv4 address, and a virtual MAC address.
The active router for each HSRP group is on a different Layer 3 switch. Thus, the hosts
in different VLANs use a different Layer 3 switch, which enables load sharing across
various subnets and VLANs.
The active router in HSRP is elected based on the HSRP priority, which is 100 by
default and is configurable per HSRP group. In the case of an equal priority, the router
with the highest IPv4 address for the respective group is elected as an active router.
The HSRP interface tracking feature decreases the priority of the router by a configured
value, when a tracked interface becomes unavailable. In this situation, the priority of a
standby group router may become higher and it will take the role of active router.
Therefore, a router with the unavailable interface will relinquish the active router role.
The following topology has two redundant routers that connect a host to the internet.
The routers have HSRP enabled on the interfaces that are facing the host network
(interface fa0/0 on each router.)
The primary router (Router 1) is configured with priority 110, while the secondary router
(Router 2) has a default priority of 100. Router 1 is also configured with the HSRP
interface tracking option for the interface Fa0/1, which is connected to the internet. If
this interface becomes unavailable, the Router 1 HSRP priority is configured to
decrease by 20, which will relinquish the active router role to Router 2, which will have a
higher priority during this incident. When interface Fa0/1 on Router 1 comes back
online, the router will revert to the configured priority and will become the active router.
These changes will happen only if you have enabled pre-emption.
HSRP is a Cisco proprietary protocol and VRRP is a standard protocol. VRRP is similar
to HSRP, both in operation and configuration, and the differences between HSRP and
VRRP are very slight. The VRRP master is analogous to the HSRP active gateway,
while the VRRP backup is analogous to the HSRP standby gateway. Other VRRP
differences from HSRP include that it allows you to use the actual IP address of one of
the VRRP group members as a virtual IP address, and that it uses a different multicast
address for communication between peers.
Introducing WAN Technologies
Introduction
The content in this section is self-study material and will not be delivered in class by
your instructor.
When users in Enterprise networks need access to remote sites, or a Branch needs to
connect to the Enterprise campus, or when remote users need to access the Enterprise
local area network (LAN), a Wide Area Network (WAN) is needed. As the name
suggests, WANs cover large geographical areas. WANs are operated by companies
such as telephone or cable companies, service providers, or satellite companies. They
build large networks that span entire cities or regions and lease the right to use their
networks to their customers.
Many WAN technologies exist today and new technologies, such as 4G and 5G Mobile
networks, are constantly emerging. An increasingly common option for enterprises is
also to use the global internet infrastructure for WAN connectivity.
One of the most important aspects of interconnecting Enterprise sites and users is
security. In order to secure traffic in transit over the service provider networks or
internet, Virtual Private Networks (VPNs) are deployed. There are multiple options for
VPNs and sometimes Enterprises need to combine multiple different services in the
network, depending on the availability of services and business needs.
Cisco Enterprise Architecture Model
As a network engineer, you should keep up on possible WAN connectivity options and
other WAN details by acquiring:
•
•
Knowledge of WAN devices and cabling.
Awareness of WAN protocols and topology options.
•
Familiarity with VPN options.
Introduction to WAN Technologies
A WAN is a data communications network that operates beyond the geographic scope
of a LAN. To implement a WAN, enterprises use the facilities of service providers or
carriers, such as a telephone or cable company. The provider interconnects enterprises
own locations, and connects it to locations of other enterprises, to external services, and
to remote users. WANs carry various traffic types such as voice, data, and video.
WANs have these three major characteristics:
•
•
•
WANs generally connect devices that are separated by a broader geographic area than
a LAN can serve.
WANs use the services of carriers such as telephone companies, cable companies,
satellite systems, and network providers.
WANs use connections of various types to provide access to bandwidth over large
geographic areas.
WAN operations focus primarily on the physical layer (Open Systems Interconnection
[OSI] Layer 1) and the data link layer (OSI Layer 2). WAN access standards typically
describe both physical layer delivery methods and data link layer requirements. The
data link layer requirements include physical addressing, flow control, and
encapsulation.
WAN access standards are defined and managed by several recognized authorities,
among them are Telecommunications Industry Association and the Electronic Industries
Alliance (TIA/EIA), International Organization for Standardization (ISO), and Institute of
Electrical and Electronics Engineers (IEEE)
LAN technologies provide high-speed and cost efficiency for the transmission of data in
organizations, but only in relatively small geographic areas. Businesses require
communication with distant sites, provided by a WAN, for several reasons, including the
following:
•
•
•
•
People and processes in the enterprise’s regional and branch offices exchange and
share data.
Enterprises often share information with other organizations across large distances.
Employees who travel or work from remote sites frequently need to access information
that resides on their corporate networks, i.e. they need access to centrally located
applications and services.
Applications and services used by employees can be hosted in the cloud.
WANs may provide high bandwidth, over long-distance, across complex physical
networks, often with performance guarantees. WANs are very different to LANs:
maintenance costs increase with longer-distances, to guarantee performance the
network should recover from faults very quickly, the signal quality and bit error rates
must be kept under control, and bandwidth should be carefully managed. Therefore,
many technologies and standards were developed specifically to meet WAN
requirements.
For many enterprises, it is not feasible to build their own infrastructure to connect
computers across a country or around the world, in the same way they would do for a
LAN. Therefore, they use the existing WAN technologies and resources, to fulfill this
need. Nevertheless, the cost of the network and its related services is a significant
expense. Increasingly, the internet is being used as an inexpensive alternative to an
enterprise WAN for some applications.
When a WAN service provider receives data from a client site, it must forward the data
to the remote site for final delivery to the recipient. Sometimes, the remote site may be
connected to the same service provider as the originating site, but it is not always the
case. If providers are not the same, the originating provider must pass the data to the
destination provider, through provider interconnections.
WAN service providers use several different technologies to connect their subscribers.
The connection type that is used may not be the same as the one service provider
employs inside its own network or the one it uses to connect to other service providers.
Service provider networks are complex. They are mostly built of high-bandwidth fiberoptic media, using Dense Wavelength Division Multiplexing (DWDM), the
Synchronous Optical Networking (SONET) in North America, and Synchronous Digital
Hierarchy (SDH) in the rest of the world. These standards define how to transfer data
over optical fiber over great distances.
WAN Devices and Demarcation Point
Several types of devices are specific to WAN environments, including modems, and
certain types of routers and switches. The following are descriptions of WAN devices
and terms used in discussing WANs. Some of the devices were used in the past with
legacy WAN connectivity options.
Modems are devices that modulate and demodulate analog carriers to encode and
retrieve digital information. A modem interprets digital and analog signals, enabling data
to be transmitted over voice-grade telephone lines. At the source, digital signals are
converted to a form that is suitable for transmission over analog communication
facilities. At the destination, these analog signals are returned to their digital form. Pure
analog circuits are not encountered often today. Modems still do modulate multiple
carriers and implement coding schemes, which are digital. Nonetheless, the word
modem is still in use, by convention, for devices that work on lines that were not
primarily intended for data service, such as phone lines of various types and cable TV
lines. The terms transceiver or converter or media converter are used for fiber lines.
Modems are part of the equipment installed at the customer location, although it is not
necessary that they are owned and managed by the customer (for example, the
enterprise). In the figure, a Digital Subscriber Line (DSL) modem (which is used in
broadband environments based on DSL technology) connects to a router with an
Ethernet cable and connects to the service provider network with a telephone cable. A
modem can also be implemented as a router module.
Optical fiber converters are used where a fiber-optic link terminates to convert optical
signals into electrical signals and vice versa. You can also implement the converter as a
router or switch module.
A router provides internetworking and WAN access interface ports that are used to
connect to the service provider network. These interfaces may be serial connections or
other WAN interfaces. With some types of WAN interfaces, you need an external device
such as a CSU/DSU or modem (analog, cable, or DSL) to connect the router to the local
point of presence (POP) of the service provider.
A core router or multilayer switch resides within the middle or backbone of the WAN,
rather than at its periphery. To fulfil this role, a router or multilayer switch must be able
to support multiple telecommunications interfaces of the highest speed in use in the
WAN core. It must also be able to forward Internet Protocol (IP) packets at wire speed
on all these interfaces. The router or multilayer switch must support the routing
protocols that are being used in the core.
Wireless routers are used when you are using the wireless medium for WAN
connectivity. You can also use an access point instead of a wireless router.
Router with cellular connectivity features are used when connecting to a WAN via a
cellular/mobile broadband access network. Routers with cellular connectivity features
include an interface which supports cellular communication standards and protocols.
Interfaces for cellular communication can be factory installed, or they can embed a
module that provides cellular connectivity. A router can be moved between locations. It
can also operate while in motion (in trucks, buses, cars, trains). Enterprise grade routers
that support cellular connectivity also include diagnostic and management functions,
enable multiple cellular connections to one or more service providers, support Quality of
Service (QoS), etc.
DTE/DCE and CSU/DSU: data terminating equipment (DTE) and data communications
equipment (DCE) are terms that were used in the context of WAN connectivity options
that are mostly considered legacy today. The two terms name two separate devices.
The DTE device is either a source or a destination for digital data. Specifically, these
devices include PCs, servers, and routers. In the figure, a router in either office would
be considered a DTE. DCE devices convert the data received from the sending DTE
into a form acceptable to the WAN service provider. The purpose is to convert a signal
from a form used for local transmission to a form used for long distance transmission.
Converted signals travel across provider’s network to the remote DCE device, which
connects the receiving DTE. You could say that a DCE translates data from LAN to
WAN "language." To simplify, the data path over a WAN would be DTE > DCE > DCE >
DTE.
DCEs deal with both analog and digital data representations. When dealing only with
digitized data, a DCE is a CSU/DSU. In other words, when you connect a digital device
to a digital line, you use CSU/DSU. It connects two different types of digital signals.
When connecting a digital device to an analog circuit (such as phone line), the DCE is a
modem.
In the figure below, the router, a digital device, connects to a line, which is digital, via
the CSU/DSU unit. The CSU/DSU connects to the service provider infrastructure using
a telephone or coaxial cable, and it connects to the router with a serial cable. The DSU
converts the telephone line frames into frames that can be interpreted on the LAN and
vice versa. It also provides a clocking signal on the serial line. If a CSU/DSU is
implemented as a module within a router, a serial cable is not necessary.
Nowadays, CSU and DSU are two components within one piece of hardware. The DSU
manages the interface with the DTE. In serial communication, where clocking is
required, the DSU plays the role of the DCE and provides clocking. The DSU converts
DTE serial communications to frames which the CSU can understand and vice versa, it
converts the carrier’s signal into frames that can be interpreted on the LAN. The CSU
deals with the provider’s part of the network. It connects to the provider’s
communication circuit and places the frames from the DSU onto it and from it to the
DSU. The CSU ensures connection integrity through error correction and line
monitoring.
WAN Interface Cards (WICs) in a router may contain an integrated CSU/DSU.
The preceding list is not exhaustive and other devices may be required, depending on the
WAN access technology chosen.
The demarcation point is a marking which separates a customer’s WAN equipment from
the service provider’s equipment. The customer side of the demarcation point
accommodates the Customer Premises Equipment (CPE).
CPE are typically devices inside the wiring closet located on the subscriber’s premises.
CPE either belongs to the subscriber or is leased from the service provider. CPE is
connected to the closest point in the service provider’s network (an edge router or an
exchange/central office). This link is called the local loop or last mile. This point where
the subscriber connects to the service providers network is called a POP. Examples of
CPE devices are modems, routers, optical converters, and so on. A copper or fiber
cable connects the CPE to the nearest exchange or central office of the service
provider.
The provider’s side of demarcation point includes links that connect to the service
provider equipment, i.e. the local loop or last mile.
Physically, the demarcation point can be a cabling junction box, located on the
customer premises, that connects the CPE wiring to the local loop. It is usually placed
for easy access by a technician.
The demarcation point is the place where the responsibility for the connection changes
from the user to the service provider. When problems arise, it is necessary to determine
whether the user or the service provider is responsible for troubleshooting or repair.
The exact demarcation point is different from country to country.
WAN Topology Options
A physical topology describes the physical arrangement of network devices that allows
for data to move from a source to a destination network, while the logical topology
represents how data actually flows. When considering WAN topologies, you think about
logical topologies. The logical topologies below are the enterprise’s view of its data
flows through the service provider’s network. A physical topology might show all the
various service provider devices that are switching the data flows inside the cloud.
The four basic logical topologies in a WAN design are shown in the figure.
Point-to-point topology: This topology establishes a circuit (a logical connection)
between exactly two sites. It is also called a Layer 2 service as it creates a connection,
via which it seems that both sites are on the same physical segment. It is considered
transparent to the enterprise network as if there was a direct physical link between two
endpoints. The link capacity is dedicated to the customer. Typically, a point-to-point
topology is offered in the form of leased lines. This solution does not scale well and can
be costly.
Hub-and-spoke topology: This topology features a central router or multilayer switch,
acting as the hub, which is connected to all other remote devices, the spokes. All
communication among the spoke networks traverses the hub. The advantages of a hub-
and-spoke design are that it is a simple network that requires few circuits, it has
simplified management, and has minimized tariff costs. However, the disadvantages are
significant:
•
•
•
The central router (hub) represents a single point of failure.
The central router limits the overall performance for access to centralized resources.
The central router is a single pipe that manages all traffic that is intended either for the
centralized resources or for the other regional routers.
There may be suboptimal traffic flows, as traffic between spokes must go through the
hub.
With only one hub node, the topology is also called single-homed. Providing an extra
hub node provides for redundancy and the topology is referred to as dual-homed huband-spoke.
Meshed topologies are the ones in which there are many redundant interconnections
between the nodes. There are two types of meshed topologies, full mesh and partial
mesh:
•
•
Full mesh topology: In this topology, each remote node on the periphery of a given
service provider network has a direct logical connection, also called a circuit, to every
other remote node. Any site can communicate directly with any other site. The key
rationale for creating a full mesh environment is to provide a high level of redundancy. A
disadvantage of a full mesh topology is that it can be complex to configure and maintain
the large number of circuits required, and therefore it does not scale well.
Partial mesh topology: In this topology, almost, but not all remote nodes are interconnected. It reduces the number of sites that have direct connections to all other
nodes. Partial meshes are highly flexible topologies that can take various very different
configurations. Some nodes are organized in a full mesh scheme, but others are only
connected to one or two in the network. A partial mesh topology is commonly found in
peripheral networks connected to a full meshed backbone. This topology is often used
in "regionalized" enterprise networks. Among all its locations, an enterprise chooses
several to act as regional centers. These centers serve a selected area and implement
a hub-and-spoke topology within them, where they are the hub. This process creates
multiple hub-and-spoke topologies in an enterprise network. Hubs themselves are
connected in a full mesh topology. This set-up lowers the number of required circuits,
provides redundancy, and ensures performance. The cost of a partial mesh topology is
higher than hub-and-spoke but less than full mesh.
Large networks usually deploy a combination of these topologies—for example, a
partial mesh in the network core, redundant hub-and-spoke for larger branches, and
simple hub-and-spoke for noncritical remote locations.
Network downtime can be very expensive in terms of decreased productivity and
potential loss of revenue. Take, for example, a company that sells products on-line. Not
being able to access the warehouse records might significantly decrease company’s
income. To increase network availability, many organizations deploy a dual-carrier WAN
design to increase redundancy and path diversity. Dual-carrier WAN means that the
enterprise has connections to two different carriers (service providers).
Aspects of the WAN service are determined by a legal agreement between the
enterprise and the service provider. These agreements define technical, administrative,
and financial aspects of the service. Technical details are commonly included inService
Level Agreements (SLAs) and they describe aspects of the service, such as quality,
availability, reliability, and so on.
Single-carrier WANs are simpler and easier to support and manage. However, network
outages can be detrimental.
Dual-carrier WANs provide better path diversity with better fault isolation between
providers. They offer enhanced network redundancy, load balancing, distributed
computing or processing, and the ability to implement backup service provider
connections. The disadvantage of dual-carrier topologies is that they are more
expensive to implement than single-carrier topologies, because they require additional
networking hardware. They are also more difficult to implement because they require
additional, and more complex, configurations. The cost of downtime to your organization
usually exceeds the additional cost of the second provider and the complexity of
managing redundancy.
WAN Connectivity Options
Before physically connecting to a service provider network, an enterprise needs to
choose the type of WAN service or connectivity that it requires.
WAN networks have undergone many technological changes. When the internet was
first developed, it was built on the existing telecom infrastructure, which was intended
for telephony voice traffic. The telephony network, known under the term Public
Switched Telephone Network (PSTN), was constructed over the period of a hundred
years. Its reach was global and reached very remote areas. Most of the subscriber
telephone links, i.e. local loops or last mile, installed copper cabling. The international
traffic and traffic within service providers networks was using the fiber optic cabling and
satellite systems. The first WAN connectivity options and technologies leveraged the
existing physical infrastructure, since installing cables for the new WAN infrastructure
represents most of the cost in developing a new WAN network. The proliferation of the
internet and internet related business activities economically justified the investment into
new WAN infrastructure. During the late 1990s, many telecommunication companies
invested into building an optical fiber global network. Today, the optical fiber network
has largely replaced the copper-based network, and it extends to many user homes, i.e.
it replaces the traditional copper cabling also on the local loop.
When discussing WANs, it can be useful to distinguish its geographical elements, as
WAN technologies vary in these different geographical elements. A WAN network
consist of:
•
•
•
The local-loop/last-mile network, which represents end user connections to the service
providers. Local-loop connections terminate at service provider's access nodes, which
are the first points that aggregate traffic from multiple end users. A local loop can
connect only one subscriber with a service provider access node – such as fiber pointto-point telephone lines, or it can connect a number of subscribers with a service
provider access node – such as coaxial cable TV systems. The local loop is the
smallest geographical WAN element. The local loop was traditionally built using copper
cabling, but is currently being replaced with optical fiber.
Backhaul networks, which connect multiple access nodes of the service provider’s
network. Service provider backhaul networks can span over smaller areas, such as
municipalities, or larger areas, such as countries and regions. Backhaul networks are
also connected to internet service providers and to the backbone network. Backhaul
networks can be implemented using optical fiber, or using microwave links. Local loops
together with backhaul networks are sometimes called access networks. Examples of
access networks are the telephone network, cable TV network, and cellular network.
These example access networks provide both access to the internet, and access to
another communication service, such as telephony, or TV.
The backbone network, or backbone, interconnects service provider’s networks.
Backbone networks are large, high-capacity networks with a very large geographic
span, owned and managed by governments, universities and commercial entities.
Backbone networks are connected among themselves to create a redundant network.
Other service providers can connect to the backbone directly or through another service
provider. Backbone network service providers are also called Tier-1 providers.
Backbone networks are built mainly using optical fiber.
One of the first Internet backbone networks was NSFNET, which was built in 1987. It
was funded by the National Science Foundation (NSF) and it used the combination of
optical fiber and copper cable links to interconnect higher education communities.
Overview of WAN Connectivity Options
There are many options for implementing WAN solutions. These options differ in
technology, bandwidth, and cost.
The diagram in the figure gives an overview of available WAN connectivity options,
taking into consideration also the traditional, now mostly legacy connection options, that
were built to leverage the telephone network.
Both the traditional, and current and emerging WAN connectivity options can be broadly
classified into:
•
•
•
•
Dedicated communication links, which provide permanent dedicated connections
using point-to-point links with various capacities that are limited only by the underlying
physical facilities and the willingness of enterprises to pay for these dedicated lines. A
point-to-point link provides a pre-established WAN communications path from the
customer premises through the provider network to a remote destination. They are
simple to implement and provide high quality and permanent dedicated capacity. They
are generally costly and have fixed capacity, which makes them inflexible.
Switched communication links can be either circuit-switched or packet-switched. It is
important to differentiate between the two switching models:
Circuit-switched communication: Circuit switching establishes a dedicated virtual
connection, called a circuit, between a sender and a receiver. The connection through
the network of the service provider is established dynamically, before communication
can start, using signaling which varies for different technologies. During transmission, all
communication takes the same path. The fixed capacity allocated to the circuit is
available for the duration of the connection, regardless of whether there is information to
transmit or not. Computer network traffic can be bursty in nature. Because the
subscriber has sole use of the fixed capacity allocation, switched circuits are generally
not suited for data communication. Examples of circuit-switched communication links
are PSTN analog dialup and Integrated Services Digital Network (ISDN).
Packet-switched communication: Using circuit switching does not make efficient use of
the allocated fixed bandwidth due to the data flow fluctuations. In contrast to circuit
switching, packet switching segments data into packets that are routed over a shared
network. Packet-switching networks do not require a dedicated circuit to be established,
and they allow many pairs of nodes to communicate over the same channel. Packet-
switched communication links include Ethernet WAN (MetroEthernet), Multiprotocol
Label Switching (MPLS), legacy Frame Relay, and legacy Asynchronous Transfer Mode
(ATM).
•
Internet-based communication links: Instead of using a separate WAN infrastructure,
enterprises today commonly take advantage of the global internet infrastructure for
WAN connectivity. Previously, the internet was not a viable option for a WAN
connection due to many security risks and lack of SLA, i.e. the lack of adequate
performance guarantees. Nowadays, with the development of VPN technologies, the
internet has become one of the most common connection types that is cheap and
secure. Internet WAN connection links include various broadband access technologies,
such as fiber, DSL, cable, and broadband wireless. They are usually combined with
VPN technologies to provide security. Other access options are cellular (or mobile)
networks and satellite systems.
Each of the WAN technologies provides advantages and disadvantages for the
customer. When choosing an appropriate WAN connection, consider whether to use the
internet based public connections or connections implemented within non-public service
providers networks. Internet based connections are readily available, flexible, and a
cheaper option that can be made secure using technologies, such as VPNs.
Connections within a service provider’s network guarantee security and performance.
Another element to consider when deciding about WAN connections, is the number of
nodes you need to interconnect. Also, consider the traffic requirements and QoS for
each of the required connections. If traffic is sensitive to delays, such as is voice or
video, private dedicated or switched connections might be better. One of the factors that
will limit your choices is what connection options are locally available. In remote areas,
you might have only satellite access at your disposal. Since WAN costs can be
significant, your operating budget will also influence your choice.
Software defined WAN (SD-WAN) is a new concept in WAN. SD-WAN uses a
different approach from legacy WAN networking when it comes to WAN device
communication and WAN device management. In a legacy network all routers are
independently configured. A small change on a network may require manual
reconfiguration of hundreds of routers. In SD-WAN, all changes are centrally managed
and require only a few clicks to deploy. SD-WAN is an industry response to a trend of
more and more users accessing enterprise resources from more locations. At the same
time, the resources, such as applications and services, are hosted by more and more
clouds. Different user locations have different WAN connectivity options available. For
an enterprise, managing a large number of WAN connections can become inefficient.
SD-WAN provides a software layer to control and manage available WAN connections
and provide users with the best connection for the applications/services they require. It
also provides security features.
Traditional WAN Connectivity Options
WAN technologies that emerged at the beginning of the data communications era were
developed so they could leverage the existing global telephone network. Nowadays,
most of them are considered legacy. However, even today, you might still encounter
situations in which these legacy connectivity options might be the only ones available.
The figure illustrates legacy WAN connectivity options.
Leased lines are an example of legacy dedicated communication links, which have
existed since the early 1950s, and for this reason, are referred to by different names
such as leased circuits, serial link, serial line, or point-to-point link. The term leased line
refers to the fact that the organization pays a monthly lease fee to a service provider to
use the line. Leased lines are available in different capacities and are generally priced
based on the bandwidth required and the distance between the two connected points.
In North America, service providers use the T-carrier system to define the digital
transmission capability of a serial copper media link, while Europe uses the E-carrier
system. For instance, a T1 link supports 1.544 Mbps, an E1 link supports 2.048 Mbps, a
T3 link supports 43.7 Mbps, and an E3 link supports 34.368 Mbps. The copper cable
physical infrastructure has largely been replaced by an optical fiber network.
Transmission rates in optical fiber networks are given in terms of Optical Carrier (OC)
transmission rates, which define the digital transmitting capacity of a fiber optic network.
Communications across a serial connection is a method of data transmissions in which
the bits are transmitted sequentially over a single channel.
The two types of legacy circuit-switched WAN technologies are the PSTN analog dialup
connection and ISDN connections. Both connections utilize the copper cabling at the
local loop, to connect the equipment in the subscriber premises to the Central Office,
which acts as the access node of the service provider network.
•
In the dial-up connections, binary computer data is transported through the voice
telephone network using a device called modem. The physical characteristics of the
cabling and its connection to the PSTN limit the rate of the signal to less than 56 kbps.
The legacy dial-up WAN connection is a solution for remote areas with limited WAN
access options.
•
ISDN technology enables the local loop of a PSTN to carry digital signals, resulting in
higher capacity switched connections. The capacity ranges from 64 kbps to 2.048
Mbps.
The examples of legacy packet switched networks are Frame Relay and ATM.
•
•
Frame Relay is a Layer 2 technology which defines virtual circuits (VCs). Each VC
represents a logical end-to-end link mapped over the physical service provider’s Frame
Relay WAN. An enterprise can use a single router interface to connect to multiple sites
using different VCs. VCs are used to carry both voice and data traffic between a source
and a destination. Each frame carries the identification of the VC it should be
transferred over. This identification is called a Data-Link Connection Identifier (DLCI).
VCs are configurable, offering flexibility in defining WAN connections.
ATM technology is built on a cell-based architecture rather than on a frame-based
architecture. ATM cells are always a fixed length of 53 bytes. Small, fixed-length cells
are well-suited for carrying voice and video traffic because this traffic is intolerant of
delay. Video and voice traffic do not have to wait for larger data packets to be
transmitted. The 53-byte ATM cell is less efficient than the bigger frames and packets. A
typical ATM line needs almost 20 percent greater bandwidth than Frame Relay to carry
the same volume of network layer data. ATM was designed to be extremely scalable
and to support link speeds of T1/E1 to optical fiber network speeds of 622 Mbps and
faster. ATM also defines VCs and also allows multiple VCs on a single interface to the
WAN network.
Current and Emerging WAN Connectivity Options
WAN technologies and approaches are constantly evolving. Some technologies that
were once commonplace, like dial-up, ISDN and Frame Relay, are rarely seen today.
The following figure depicts WAN technologies that you are likely to encounter today.
MPLS
Service providers build networks by using different underlying technologies, the most
popular being MPLS. MPLS is an Internet Engineering Task Force (IETF) standard that
defines a packet label-based switching technique, which was originally devised to
perform fast switching in the core of IP networks. This technique helped carriers and
large enterprises scale their networks as increasingly large routing tables become more
complex to manage. Service providers began implementing MPLS in 2001 as a way to
allow enterprises to create end-to-end circuits across any type of transport medium
using any available WAN technology.
MPLS is an architecture that combines the advantages of Layer 3 routing with the
benefits of Layer 2 switching.
The multiprotocol in the name means that the technology is able to carry any protocol
as payload data. Payloads may be IP version 4 (IPv4) and IP version 6 (IPv6) packets,
Ethernet, or DSL, and so on. This means that different sites can connect to the
provider’s network using different access technologies.
When a packet enters an MPLS network, the first MPLS router adds a short fixed-length
label to each packet, placed between a packet's data link layer header and its IP
header. The label is removed by the egress router, when the packet leaves the MPLS
network. The label is added by a provider edge (PE) router when the packet enters the
MPLS network and is removed by a PE router when leaving the MPLS network. This
process is transparent to the customer.
MPLS routers are also called label switched routers (LSRs). Based on its location in the
network, a router can be a customer edge router (CE router), a provider edge router (PE
router), or an internal provider router (P router). To forward a packet, routers use the
label to determine the packet's next hop.
MPLS is a connection-oriented protocol. For a packet to be forwarded, a path must be
defined beforehand. A label-switched path (LSP) is constructed by defining a sequence
of labels that must be processed from the network entry to the network exit point. Using
dedicated protocols, routers exchange information about what labels to use for each
flow.
Since packets sent between the same endpoints might belong to different MPLS flows,
they might flow through different paths in the network.
MPLS labels can be added one on top of another. This feature of MPLS is called label
stacking. Therefore, a protocol data unit (PDU) may carry multiple labels. The top label
is always processed first, making it possible to combine labels in many different ways.
Label stacking allows the possibility to create many paths, which can have different
processing characteristics, which in turn means that MPLS can accommodate a great
variety of customer requirements.
MPLS provides several services. The most common ones are QoS support, traffic
engineering, quick recovery from failures, and VPNs.
Ethernet over WAN
Ethernet was originally developed to be a LAN access technology. At that time, it was
not suitable as a WAN access technology because the maximum cable length
supported was only up to a kilometer. Over the years the Ethernet physical layer media
and coding schemes constantly changed, while the Ethernet frame has remained the
same, enabling a consistent link layer and upper layer interface. Ethernet has therefore
become a reasonable WAN access option.
Service providers now offer Ethernet WAN services using fiber optic cabling. The
Ethernet WAN service can go by many names, including Metropolitan Ethernet (Metro
Ethernet), Ethernet over MPLS (EoMPLS), and Virtual Private LAN Service (VPLS).
With Ethernet WAN, all sites look as if they are connected to the same Ethernet switch
inside the service provider network. Therefore, all sites are on a single multi-access
network and each site can communicate directly with all others on the WAN. As
Ethernet operates at layer 2 of the OSI model, you can use your own IP addressing
space for routing purposes. You can also extend your internal LAN QoS policies across
the service provider network.
Ethernet as the WAN connectivity protocol can be deployed in several ways:
•
•
•
Pure Ethernet connectivity, i.e. end-to-end Ethernet connectivity without transformations
to other WAN technologies, has a geographic span determined by the physical layer
limitations. Therefore, the service is limited to specific geographic regions and is more
adequate for Metropolitan Area Network (MAN) implementations, hence the name
Metro Ethernet. Pure Ethernet-based deployments are cheaper but less reliable and
scalable. They can handle hundreds of remote sites.
Ethernet over SDH/ SONET deployments are useful when there is an existing
SDH/SONET infrastructure already in place. SDH/SONET are two versions of the
protocol designed for, and used within, the service provider network infrastructure.
Ethernet frames must undergo reframing in order to be transferred over a SDH/SONET
network. Also, the bitrate hierarchy of the SDH/SONET network must be followed, which
limits bandwidth flexibility.
MPLS based deployments are a service provider solution that uses an MPLS network to
provide virtual private Layer 2 WAN connectivity for customers. MPLS based Ethernet
WANs can connect a very large number (thousands) of locations, and are reliable and
scalable.
Benefits of Ethernet WAN include:
•
•
•
Reduced expenses and administration – Ethernet WAN provides a switched, highbandwidth Layer 2 network capable of managing data, voice, and video all on the same
infrastructure. These characteristics increase bandwidth and eliminate expensive
conversions to other WAN technologies. The technology enables businesses to
inexpensively connect numerous sites, in a metropolitan area, to each other and to the
internet. An all-Ethernet infrastructure simplifies the network management process,
because every device uses the same protocol to communicate.
Easy integration with existing networks – Ethernet WAN connects easily to existing
Ethernet LANs, reducing installation costs and time.
Enhanced business productivity – Ethernet WAN enables businesses to continue to use
IP-based business applications already developed, and to utilize the accumulated
knowledge, i.e. to reuse the investment made in software and training.
Broadband Internet Access
Broadband connectivity options could be classified into wired and wireless. Wired
connections use some sort of cabling, such as fiber or copper wires. These wired
connections tend to be permanent, i.e. permanently enabled, dedicated, and mostly
offer consistent bandwidth. On the other hand, given the nature of wireless
communications, wireless connectivity solutions do not offer the same consistency of
bandwidth, error rate and latency as wired connections. This is due to factors such as
location (distance from radio towers, multi-path propagation, radio interference from
other sources, etc.), weather, and bandwidth usage (local loop is usually shared among
multiple users). In addition, these factors can vary over time. In order to deliver highly
reliable and consistent performance, an understanding of the radio propagation and
conditions at each installation is needed. Examples of wired broadband connectivity are
DSL, cable TV connections, and optical fiber networks. Examples of wireless broadband
are cellular 3G/4G/5G or satellite internet services.
Broadband solutions are inexpensive when compared to other WAN connectivity
options. However, they do not allow customer to control latency or QoS. In terms of
broadband throughput, there are usually several options from which to choose.
Wired Broadband Internet Access
DSL technology is an always-on connection technology that uses existing twisted-pair
telephone lines to transport high-bandwidth data, and provides IP services to
subscribers. Service providers deploy DSL connections in the local loop/last mile. The
connection is set up between a pair of modems on either end of a copper wire that
extends between the customer premises equipment (CPE) and the DSL access
multiplexer (DSLAM). A DSLAM is the device located at the Central Office (CO) of the
provider, which concentrates connections from multiple DSL subscribers. The DSLAM
combines individual DSL connections from users into one high-capacity link to an ISP,
and, therefore, to the internet. DSL is a broadband technology of choice for many
remote workers.
There are many DSL varieties, differing in available bitrates, and underlying data link
and physical layer characteristics. Different DSL flavors are: Asymmetric DSL (ADSL)
with different upload and download bitrates, ADSL2+ with higher data rates, longer
reach, and improvements for packet transmission; High-Data-Rate DSL (HDSL); ISDN
based DSL with the longest DSL reach of all DSL technologies; Symmetric DSL (SDSL)
that allows symmetric bandwidth on the upstream and downstream and offers multiple
rates, Very High-Data-Rate DLS (VDSL), etc. All these variations are encompassed
under the term xDSL, which denotes any of the DSL technologies.
Generally, a subscriber cannot choose to connect to an enterprise network directly, but
must first connect to an ISP, and then an IP connection is made through the internet to
the enterprise. Security risks are incurred in this process, but can be mitigated with
security measures.
Another wired broadband access option is cable access. Accessing the internet through
cable utilizes the cable network, which was primarily developed for TV signal
distribution, and is known as the cable TV system. At the physical layer, the coaxial
cable was the primary medium used to build cable TV systems. It carries radio
frequency (RF) signals. Most cable operators are deploying hybrid fiber-coaxial
networks. Internet service is provided by the Internet Service Provider (ISP) associated
with the cable service provider.
To enable the transmission of data over the cable system and to add high-speed data
transfer to an existing cable TV system, the Data over Cable Service Interface
Specification (DOCSIS) international standard defines the communications
requirements and operation support interface requirements.
Two types of equipment are required to send signals upstream and downstream on a
cable system:
•
•
Cable Modem (CM) on the subscriber end
Cable Modem Termination System (CMTS) at the headend of the cable operator
The topology in the figure displays a sample cable WAN connection. A headend CMTS
communicates with CMs located in subscriber homes. The headend is actually a router
with databases for providing internet services to cable subscribers. When deploying
hybrid fiber-coaxial (HFC) networks, service providers enable high-speed transmission
of data to cable modems located in residential areas. Using optical fiber, the headend is
connected to a node that also connects to coaxial cables, called feeder cables, which
connect multiple subscribers. The node performs optical-to-RF signal conversion.
Wireless Broadband Internet Access
Wireless technology uses RF spectrum to send and receive data. One limitation of
wireless access was the need to be within the local transmission range (typically less
than 150 feet/46 m) of a wireless router or a wireless modem that has a wired
connection to the internet. However, developments in broadband wireless technology
are increasing the reach of wireless connections and now include WANs.
The following technologies enable wireless broadband access:
•
Municipal Wi-Fi: Many municipal governments, often working with service providers,
are deploying wireless networks. Some of these networks provide high-speed internet
access at no cost or for substantially less than the price of other broadband services.
Other cities reserve their Wi-Fi networks for official use, providing police, fire fighters,
and city workers remote access to the internet and municipal networks. To connect to a
municipal Wi-Fi, a subscriber typically needs a wireless modem, which provides a
stronger radio and directional antenna than conventional wireless adapters. Most
•
•
•
•
•
service providers provide the necessary equipment for free or for a fee, much like they
do with DSL or cable modems.
Cellular/Mobile broadband refers to wireless internet access delivered through mobile
phone towers to computers, mobile phones, and other digital devices. Devices use a
small radio antenna to communicate with a larger antenna at the phone tower, via radio
waves. Organizations leverage cellular networks for a variety of use cases, such as for
metering devices (sensors, vehicle diagnostics), temporary sites (sports/fair/conference
access), and to connect smaller and remote business sites. Three common term
0
You can add this document to your study collection(s)
Sign in Available only to authorized usersYou can add this document to your saved list
Sign in Available only to authorized users(For complaints, use another form )