Table of Contents Table of Contents Table of Contents Table of Contents p p p p age 1.0 IP-Address and Secondary Addresses configuration ..........4 1.1 IP-Static-routing..................... 4 1.2 IP-Loopback Interface.................... 4 1.3 IP-OSPF-routing ....................5 1.4 IP-RIPv1,v2-routing....................6 1.5 DHCP server, static / dynamic-pool ............... 7 1.6 DHCP/Bootp relay argent / ip-helper..............
Page 3
9.0r1 VPN IPSEC site-to-site tunnel via pre-shared key ..........31 9.0r2 VPN IPSEC site-to-site tunnel via pre-shared key ..........32 9.1 VPN IPSEC site-to-site tunnel certification PKI............33 9.1.1 Certification control / certificates / CRLS / CA identity ........35 9.3 VPN PPTP User termination .................
1.0 IP-Address and Secondary Addresses configuration XSR-1805#show running-config Version 4.0.0.0, Built Mar 26 2003, 19:47:17 hostname XSR-1805 interface FastEthernet1 description "LAN-Interface1" ip address 10.10.10.1 255.255.255.0 ip address 40.40.40.1 255.255.255.0 secondary no shutdown interface FastEthernet2 description "LAN-Interface2" ip address 20.20.20.1 255.255.255.0 ip address 50.50.50.1 255.255.255.0 secondary no shutdown XSR-1805#...
1.3 IP-OSPF-routing XSR-1805#show running-config Version 4.0.0.0, Built Mar 26 2003, 19:47:17 hostname XSR-1805 interface FastEthernet1 description "LAN-Interface1" ip address 10.10.10.1 255.255.255.0 ip address 40.40.40.1 255.255.255.0 secondary no shutdown interface FastEthernet2 description "LAN-Interface2" ip address 20.20.20.1 255.255.255.0 ip address 50.50.50.1 255.255.255.0 secondary no shutdown interface Loopback0 ip address 192.168.222.1 255.255.255.255...
1.4 IP-RIPv1,v2-routing XSR-1805#show running-config Version 4.0.0.0, Built Mar 26 2003, 19:47:17 hostname XSR-1805 interface FastEthernet1 description "LAN-Interface1" ip address 10.10.10.1 255.255.255.0 ip address 40.40.40.1 255.255.255.0 secondary no shutdown interface FastEthernet2 description "LAN-Interface2" ip address 20.20.20.1 255.255.255.0 ip address 50.50.50.1 255.255.255.0 secondary no shutdown interface Loopback0 ip address 192.168.222.1 255.255.255.255...
1.7 SNTP Simple Network Time Protocol XSR-1805#show running-config Version 4.0.0.0, Built Mar 26 2003, 19:47:17 hostname XSR-1805 sntp-client server 51.51.51.88 interface FastEthernet1 description "LAN-Interface1" ip address 10.10.10.1 255.255.255.0 ip address 40.40.40.1 255.255.255.0 secondary ip dhcp server no shutdown interface FastEthernet2 description "LAN-Interface2"...
3.0 Access control list incoming outgoing 3.1 Access control list 1-99 (standard) 3.2 Access control list 100-199 (extended) XSR-1805#show running-config Version 4.0.0.0, Built Mar 26 2003, 19:47:17 hostname XSR-1805 access-list 2 permit 20.20.20.0 0.0.0.255 access-list 110 deny ip 10.10.10.100 0.0.0.0 any access-list 110 deny ip 10.10.10.111 0.0.0.0 any access-list 110 permit ip any any interface FastEthernet1...
3.3 Access control list moving online editing XSR-1805#show running-config Version 4.0.0.0, Built Mar 26 2003, 19:47:17 hostname XSR-1805 access-list 110 deny ip 10.10.10.100 0.0.0.0 any access-list 110 deny ip 10.10.10.111 0.0.0.0 any access-list 110 permit ip any any interface FastEthernet1 description "LAN-Interface1"...
5.0 Dialer Interface XSR-1805#show running-config Version 4.0.0.0, Built Mar 26 2003, 19:47:17 hostname XSR-1805 interface bri 1/0 isdn switch-type basic-net3 no shutdown dialer pool-member 1 priority 0 access-list 110 permit ip any any interface FastEthernet1 description "LAN-Interface1" ip address 10.10.10.1 255.255.255.0 no shutdown interface Dialer0 dialer pool 1...
5.2 PAP for authentication PPP XSR-1805#show running-config Version 4.0.0.0, Built Mar 26 2003, 19:47:17 hostname XSR-1805 username remote privilege 0 "password is not displayed" interface bri 1/0 isdn switch-type basic-net3 no shutdown dialer pool-member 1 priority 0 access-list 110 permit ip any any interface FastEthernet1 description "LAN-Interface1"...
5.3 CHAP for authentication PPP XSR-1805#show running-config Version 4.0.0.0, Built Mar 26 2003, 19:47:17 hostname XSR-1805 username remote privilege 0 cleartext iamRemote interface bri 1/0 isdn switch-type basic-net3 no shutdown dialer pool-member 1 priority 0 access-list 110 permit ip any any interface FastEthernet1 description "LAN-Interface1"...
5.5.2 Dialer Int. PRI to BRI with D-channel-callback remote1-site remote1#show running-config Version 6.0.0.9, Built Dec 12 2003, 14:56:30 hostname remote1 username central privilege 0 password cleartext xsr interface bri 0/2/0 isdn switch-type basic-net3 no shutdown dialer pool-member 1 priority 0 access-list 102 permit ip any any interface FastEthernet 1...
5.5.3 Dialer Int. PRI to BRI with D-channel-callback remote2-site remote1#show running-config Version 6.0.0.9, Built Dec 12 2003, 14:56:30 hostname remote2 username central privilege 0 password cleartext xsr interface bri 0/1/0 isdn switch-type basic-net3 no shutdown dialer pool-member 1 priority 10 access-list 130 permit ip any any interface FastEthernet 1...
6.0 ISDN config for BRIx/x 6.1 ISDN switch type changing XSR-1805#show running-config Version 4.0.0.0, Built Mar 26 2003, 19:47:17 hostname XSR-1805 interface bri 1/0 isdn switch-type basic-net3 no shutdown dialer pool-member 1 priority 0 access-list 110 permit ip any any interface FastEthernet1 description "LAN-Interface1"...
6.2 ISDN callback XSR-1805#show running-config Version 4.0.0.0, Built Mar 26 2003, 19:47:17 hostname XSR-1805 interface bri 1/0 isdn switch-type basic-net3 no shutdown dialer pool-member 1 priority 0 access-list 110 permit ip any any interface FastEthernet1 description "LAN-Interface1" ip address 10.10.10.1 255.255.255.0 no shutdown interface Dialer0 dialer pool 1...
7.0 PPPoE on Fast Ethernet interfaces 7.1 IP-address negotiation for PPPoE XSR-1805#show running-config Version 4.0.0.0, Built Mar 26 2003, 19:47:17 hostname XSR-1805 interface FastEthernet1 ip address 10.10.10.1 255.255.255.0 no shutdown interface FastEthernet2 description "LAN-Interface2-4-PPPoE" no shutdown interface FastEthernet2.1 encapsulate ppp ip address negotiated ip mtu 1492 ip nat source assigned overload...
8.1 SSH / Telnet SSH and Telnet are enabled by default SSH and Telnet are enabled by default SSH and Telnet are enabled by default SSH and Telnet are enabled by default XSR-1805#show running-config Version 4.0.0.0, Built Mar 26 2003, 19:47:17 hostname XSR-1805 ip ssh server disable ip telnet server disable...
9.1 VPN IPSEC site-to-site tunnel certification PKI XSR-1805_1#show running-config Version 4.0.0.0, Built Mar 26 2003, 19:47:17 hostname XSR-1805_1 crypto isakmp proposal prop-map1 authentication rsa-sig group 5 lifetime 10800 access-list 101 permit ip 10.10.10.0 0.0.0.255 any crypto isakmp peer 20.20.20.1 255.255.255.255 proposal prop-map1 config-mode gateway crypto ipsec transform-set VPN-3des esp-3des esp-sha-hmac...
Page 34
Issue Certificate via SCEP protocol to XSR Issue Certificate via SCEP protocol to XSR from Issue Certificate via SCEP protocol to XSR Issue Certificate via SCEP protocol to XSR from from from Win n n n dows dows dows dows 2000 2000 2000 CA 2000...
9.3 VPN PPTP User termination XSR-1805#show running-config Version 4.0.0.0, Built Mar 26 2003, 19:47:17 hostname XSR-1805 interface FastEthernet1 ip address 134.141.130.12 255.255.255.0 no shutdown interface FastEthernet2 ip address 192.168.1.1 255.255.255.0 ip nat source assigned overload no shutdown interface Vpn1 multi-point ip address 192.168.2.1 255.255.255.0 ip local pool VPN 192.168.2.0 255.255.255.0 aaa group DEFAULT...
9.5r1 GRE native site-to-site tunnel Router-1 XSR-1805_1#show running-config Version 6.0.0.0, Built Sep 14 2003, 11:09:28 hostname XSR-1805_1 access-list 101 permit gre any any access-list 101 deny any any interface FastEthernet 1 description "LAN-Interface1" ip address 10.10.10.1 255.255.255.0 no shutdown interface FastEthernet 2 description "LAN-Interface2"...
9.5r2 GRE native site-to-site tunnel Router-2 XSR-1805_2#show running-config Version 6.0.0.0, Built Sep 14 2003, 11:09:28 hostname XSR-1805_2 access-list 101 permit gre any any access-list 101 deny any any interface FastEthernet 1 description "LAN-Interface1" ip address 80.80.80.1 255.255.255.0 no shutdown interface FastEthernet 2 description "LAN-Interface2"...
10.1 DIFFSERV DSCP field addressing XSR-1805#show running-config Version 4.0.0.0, Built Mar 26 2003, 19:47:17 hostname XSR-1805 class-map DSCP_EF match access-group 2 match ip dscp EF policy-map DSCP_EF class DSCP_EF priority high 12000 access-list 2 permit 10.10.10.0 0.0.0.255 interface FastEthernet1 description "LAN-Interface1" ip address 10.10.10.1 255.255.255.0 no shutdown interface FastEthernet2...
12.1 Vlan configuration 802.1q tagged routing XSR-1805#show running-config Version 6.0.0.0, Built Sep 14 2003, 11:09:28 hostname XSR-1805 interface FastEthernet 1 description "UnTagged-Native-Interface" ip address 11.11.11.1 255.255.255.0 no ip proxy-arp no shutdown interface FastEthernet 1.10 description "vlan 10 tagged" vlan 10 ip address 10.10.10.1 255.255.255.0 no ip proxy-arp no shutdown...
Important commands for using the XSR platform: A1.1 show version - Software, Bootrom, RAM, Flash, System Uptime XSR-1805#show version Enterasys Networks Operating Software Copyright 2002 by Enterasys Networks Inc. Hardware: Processor board ID: 9002854-02 REV0A Serial Number: 361903091537210L Processor: IBM PowerPC 405GP Rev. D at 200MHz...
A1.3 show interface - IP address, speed, duplex, statistics, errors XSR-1805#show interface FastEthernet1 is Admin Up Description: LAN-Interface1 Internet address is 10.10.10.1, subnet mask is 255.255.255.0 The name of this device is Eth1. The physical link is currently up. The device is in polling mode, and is active. The last driver error is '(null)'.
C1.4 show tunnels / GRE via IPSEC XSR-1805_2#show tunnels Tunnel MIB: Creation Time Proto Username Peer IP Packets In/Out 40000001 12/02/2003, 16:14 GRE 20.20.20.1 0000003528/0000002552 XSR-1805_2# C1.5 show interface vpn / GRE via IPSEC XSR-1805_2#show interface vpn Vpn1 is Admin Up Internet address is 192.168.1.2, subnet mask is 255.255.255.0 Multicast redirect to 192.168.1.1 is enabled.
D1.4 show interface atm 1/0 XSR1805-ADSL #show interface atm 1/0 ********** ATM Interface Stats ********** ATM 1/0 is Admin Up / Oper Up Description: "ADSL-connection" The name of this device is adsl. Administrative State is ENABLED Operational State is UP. The upstream data rate is 192 kbit/sec.
D1.5 show interface atm 1/0.1 XSR1805-ADSL #show interface atm 1/0.1 ********** ATM Sub-Interface Stats ********** ATM 1/0.1 is Admin Up / Oper Up Internet address is 212.184.161.76, subnet mask is 255.255.255.255 State: OPENED IPCP State: OPENED PPPoE is Oper Up The logical link is currently Up The Name of the Access Concentrator is ERX1400 The Session Id is 0x0054...
D1.6 show ppp interface atm 1/0.1 XSR1805-ADSL#show ppp interface atm 1/0.1 ********** PPP Stats ********** ATM 1/0.1: PPP is Admin Up / Oper Up Current State: OPENED IPCP Current State: OPENED LCP STATS Total Rcv Pck: Total Rcv Control Pck: Total Rcv Data Pck: Total Rcv Pck Discarded: Total Tx Pck:...
Page 55
Getting Help Getting Help Getting Help Getting Help For additional support related to the XSR, contact Enterasys Networks using one of the following methods: World Wide Web World Wide Web World Wide Web World Wide Web http://www.enterasys.com http://www.enterasys.com http://www.enterasys.com http://www.enterasys.com...