Notice Notice Cabletron Systems reserves the right to make changes in specifications and other information contained in this document without prior notice. The reader should in all cases consult Cabletron Systems to determine whether any such changes have been made.
Page 4
Notice VCCI Notice This is a Class A product based on the standard of the Voluntary Control Council for Interference by Information Technology Equipment (VCCI). If this equipment is used in a domestic environment, radio disturbance may arise. When such trouble occurs, the user may be required to take corrective actions. DOC Notice This digital apparatus does not exceed the Class A limits for radio noise emissions from digital apparatus set out in the Radio Interference Regulations of the Canadian Department of Communications.
Notice DECLARATION OF CONFORMITY ADDENDUM Application of Council Directive(s): 89/336/EEC 73/23/EEC Manufacturer’s Name: Cabletron Systems, Inc. Manufacturer’s Address: 35 Industrial Way PO Box 5005 Rochester, NH 03867 European Representative Name: Mr. J. Solari European Representative Address: Cabletron Systems Limited Nexus House, Newbury...
Configure the SSR CLI ....................30 Configure SNMP Services .....................31 Configure DNS ........................31 Monitoring Configuration ....................31 Chapter 2: Bridging Configuration Guide ..........33 Bridging Overview.........................33 Spanning Tree (IEEE 802.1d) ..................33 Bridging Modes (Flow-Based and Address-Based) ...........34 VLAN Overview ........................34 SmartSwitch Router User Reference Manual...
Page 8
Configure ARP Cache Entries ................48 Configure Proxy ARP..................... 48 Configure DNS Parameters ..................49 Configure IP Services (ICMP) ..................49 Configure IP Helper....................... 49 Configure Direct Broadcast ..................50 Monitor IP Parameters......................50 Configuration Examples....................... 51 SmartSwitch Router User Reference Manual...
Page 9
Notes on Using the AS Path Prepend Feature.............78 BGP Configuration Examples ....................78 BGP Peering Session Example ..................78 IBGP Configuration Example..................81 IBGP Routing Group Example................81 IBGP Internal Group Example................84 EBGP Multihop Configuration Example..............87 Community Attribute Example ..................90 SmartSwitch Router User Reference Manual...
Page 10
Export Policies ......................121 Creating an Export Destination.................. 123 Creating an Export Source ..................123 Import Policies......................123 Creating an Import Source..................124 Creating a Route Filter ....................124 Creating an Aggregate Route ..................124 SmartSwitch Router User Reference Manual...
Page 11
Chapter 9: IPX Routing Configuration Guide........151 IPX Routing Overview ......................151 RIP (Routing Information Protocol) ................151 SAP (Service Advertising Protocol) ................152 Configuring IPX RIP & SAP ....................153 IPX RIP..........................153 IPX SAP ..........................153 Creating IPX Interfaces ....................153 SmartSwitch Router User Reference Manual...
Page 12
Implicit Deny Rule ....................... 172 Applying ACLs to Interfaces..................173 Applying ACLs to Services..................174 ACL Logging ........................ 174 Maintaining ACLs Offline Using TFTP or RCP............175 Maintaining ACLs Using the ACL Editor ..............176 SmartSwitch Router User Reference Manual...
Page 13
Removing the Control Module ...................192 Installing the Control Module..................193 Hot Swapping a Switching Fabric Module (SSR 8600 only)..........193 Chapter 14: VRRP Configuration Guide..........195 VRRP Overview ........................195 Configuring VRRP .......................195 Basic VRRP Configuration...................196 Configuration of Router R1 ..................196 SmartSwitch Router User Reference Manual...
Page 14
Setting the Backup Priority.................. 204 Setting the Advertisement Interval ..............204 Setting Pre-empt Mode ..................204 Setting an Authentication Key ................205 Monitoring VRRP ........................ 205 ip-redundancy trace..................... 205 ip-redundancy show....................206 VRRP Configuration Notes....................206 SmartSwitch Router User Reference Manual...
Who Should Read This Manual? Read this manual if you are a network administrator responsible for configuring and monitoring the SSR. SmartSwitch Router User Reference Manual...
Chapter 13 on page 189 Configure VRRP Chapter 14 on page 195 Related Documentation The Cabletron Systems documentation set includes the following items. Refer to these other documents to learn more about your product. For Information About See the Installing and setting up the SSR...
Layer-3 (routing) and Layer-4 (application) switching. The hardware provides wire-speed performance regardless of the performance monitoring, filtering, and Quality of Service (QoS) features enabled by the software. You do not need to accept performance compromises to run QoS or access control lists (ACLs). SmartSwitch Router User Reference Manual...
Page 18
Layer-2 prioritization (802.1p) • Layer-3 source-destination flows • Layer-4 source-destination flows • Layer-4 application flows RMON • RMONv1/v2 for each port Management • SNMP • CoreWatch Element Manager (GUI) • Emacs-like Command Line Interface (CLI) SmartSwitch Router User Reference Manual...
Table 2. Common CLI key commands Key Sequence Command Ctrl+A Move cursor to beginning of line Ctrl+B Move cursor back one character Ctrl+D Delete character Ctrl+E Move cursor to end of line SmartSwitch Router User Reference Manual...
SmartSwitch Router’s configuration is changed accordingly. However, the changes are not written to the Startup configuration file in the Control Module’s boot flash and therefore are not reinstated after a reboot. SmartSwitch Router User Reference Manual...
Enable mode provides more facilities than User mode. You can display critical features within Enable mode including router configuration, access control lists and SNMP statistics. To enter Enable mode, enter the enable command, then supply the password when prompted. SmartSwitch Router User Reference Manual...
Page 23
- Show SNMP related parameters. statistics - Show or clear SSR statistics - Show STP status system - Show system-wide parameters tacacs - Show TACACS related parameters traceroute - Traceroute utility vlan - Show VLAN-related parameters SmartSwitch Router User Reference Manual...
- Configure Open Shortest Path Protocol (OSPF) port - Configure Port parameters - Configure Quality of Service parameters - Configure Routing Information Protocol (RIP) snmp - Configure SNMP related parameters. - Configure STP parameters system - Configure system-wide parameters SmartSwitch Router User Reference Manual...
(PROM) mode. You should then reboot the SSR at the boot PROM to restart the system. If the system fails to reboot successfully, please call Cabletron Systems Technical Support to resolve the problem. To reboot the SSR from the ROM monitor mode, enter the following command.
Here is an example: ctron-ssr-1# system show version Software Information Software Version : 1.0 Copyright : Copyright (c) 1996-1998 Cabletron Systems, Inc. Image Information : Version 1.0, built on Fri Mar 20 19:28:49 1998 Image Boot Location: file:/pc-flash/boot/ssr8/ SmartSwitch Router User Reference Manual...
The SSR boots using the boot PROM software installed on the Control Module’s internal memory. To upgrade the boot PROM software and boot using the upgraded image, use the following procedure. Display the current boot settings by entering the system show version command: SmartSwitch Router User Reference Manual...
Here is an example: ctron-ssr-1# system show version Software Information Software Version : 1.0 Copyright : Copyright (c) 1996-1998 Cabletron Systems, Inc. Image Information : Version 1.0.B.13, built on Wed Mar 25 22:49:07 1998 Image Boot Location: file:/pc-flash/boot/ssr8/ Boot Prom Version : prom-1.0...
The SSR contains numerous system facilities for system management. You can perform configuration management tasks on the SSR including: • Setting the SSR name • Setting the SSR date and time • Configuring the CLI • Configuring SNMP services SmartSwitch Router User Reference Manual...
You can customize the CLI display format to a desired line length or row count. To configure the CLI terminal display, enter the following command in Enable mode: Configure the CLI terminal display. <num> cli set terminal rows columns <num> SmartSwitch Router User Reference Manual...
Display history buffer. cli show history Show terminal settings. cli show terminal Show all accesses to the SNMP agent. snmp show access Show all SNMP information. snmp show all Show chassis ID. snmp show chassis-id SmartSwitch Router User Reference Manual...
Page 32
SSR. Show the default terminal settings (number of system show terminal rows, number of columns, and baud rate. Show SSR uptime. system show uptime Show the software version running on the system show version SSR. SmartSwitch Router User Reference Manual...
Spanning Tree (IEEE 802.1d) Spanning tree (IEEE 802.1d) allows bridges to dynamically discover a subset of the topology that is loop-free. In addition, the loop-free tree that is discovered contains paths to every LAN segment. SmartSwitch Router User Reference Manual...
VLAN to which it belongs. This reduces the broadcast traffic on a network by an appreciable factor. The type of VLAN depends upon one criterion: how a received frame is classified as belonging to a particular VLAN. VLANs can be categorized into the following types: • Port based SmartSwitch Router User Reference Manual...
To do this, the switch must look into the network layer header of the incoming frame. This type of VLAN behaves similar to a router by segregating different subnets into different broadcast domains. SmartSwitch Router User Reference Manual...
The SSR can also be used purely as a router, i.e., each physical port of the SSR is a separate routing interface. Packets received at any interface are routed and not bridged. In this case, no VLAN configuration is required. Note that VLANs are still created implicitly by SmartSwitch Router User Reference Manual...
VLAN to which they belong. Untagged frames are classified as belonging to a particular VLAN based on the protocol of the frame and the VLAN configured on the receiving port for that protocol. SmartSwitch Router User Reference Manual...
For example, the following illustration shows an SSR with traffic being sent from port A to port B, port B to port A, port B to port C, and port A to port C. SmartSwitch Router User Reference Manual...
The SSR supports only one spanning tree process per SSR. By default, spanning tree is disabled on the SSR. To enable spanning tree on the SSR, you perform the following task on the ports where you want spanning tree enabled. SmartSwitch Router User Reference Manual...
You can set a priority for an interface. When two bridges tie for position as the root bridge, you configure an interface priority to break the tie. The bridge with the lowest interface value is elected. SmartSwitch Router User Reference Manual...
To change the default interval setting, enter the following command in Configure mode: Set the default of the forward delay <num> stp set bridging forward-delay interval. SmartSwitch Router User Reference Manual...
VLAN id per trunk between two SSRs. These VLAN ids extend the VLAN broadcast domain to more than one SSR. To configure a VLAN trunk, perform the following command in the Configure mode. Configure 802.1Q VLAN trunks. <port-type> <port-list> vlan make SmartSwitch Router User Reference Manual...
The SSR provides display of bridging statistics and configurations contained in the SSR. To display bridging information, enter the following commands in Enable mode. Show IP routing table. ip show routes Show all MAC addresses currently l2-tables show all-macs in the l2 tables. SmartSwitch Router User Reference Manual...
You can associate all the ports containing the clients and servers to an IP VLAN called ‘BLUE’. First, create an IP VLAN named ‘BLUE’ ssr(config)# vlan create BLUE ip Next, assign ports to the ‘BLUE’ VLAN. ssr(config)# vlan add ports et.1.(1-8), gi.1.(1-2) to BLUE SmartSwitch Router User Reference Manual...
UDP are responsible for ensuring successful data transfer by employing error handling, retransmission and sequencing techniques. TCP and UDP also specify “ports,” which identify the application which is using TCP/UDP. For example, a web server would typically use TCP/UDP port 80, which specifies HTTP-type traffic. SmartSwitch Router User Reference Manual...
Distance Vector Multicast Routing Protocol (DVMRP) RFC 1075 • Internet Group Management Protocol (IGMP) as described in RFC 2236 The SSR also supports the latest DVMRP Version 3.0 draft specification, which includes mtrace, Generation ID and Pruning/Grafting. SmartSwitch Router User Reference Manual...
The SmartSwitch Router supports two encapsulation types for IP. You can configure encapsulation type on a per-interface basis. • Ethernet II: The standard ARPA Ethernet Version 2.0 encapsulation, which uses a 16- bit protocol type code (the default encapsulation method) SmartSwitch Router User Reference Manual...
ARP reply packet containing the SSR MAC address. Proxy ARP is enabled by default on the SSR. To disable proxy ARP, enter the following command in Configure mode: Disable Proxy ARP on <InterfaceName> ip disable-proxy-arp interface |all an interface. SmartSwitch Router User Reference Manual...
By default, if no UDP port number is specified, the SSR will forward UDP broadcast packets for the following six services: • BOOTP/DHCP (port 67 and 68) • DNS (port 37) • NetBIOS Name Server (port 137) SmartSwitch Router User Reference Manual...
Show IP interface configuration interface show ip Show all TCP/UDP connections ip show connections [no-lookup] and services. <interface-name> Show configuration of IP interfaces. ip show interfaces [ Show IP routing table information. ip show routes SmartSwitch Router User Reference Manual...
You can also assign an IP or IPX interface directly to a physical port. For example, to assign an IP interface ‘RED’ to physical port et.3.4, perform the following: ssr(config)# interface create ip RED address-netmask 10.50.0.0/255.255.0.0 port et.3.4 SmartSwitch Router User Reference Manual...
Page 52
Chapter 3: IP Routing Configuration Guide SmartSwitch Router User Reference Manual...
By default, RIP is disabled on the SSR and on each of the attached interfaces. To configure RIP on the SSR, follow these steps: Start the RIP process by entering the rip start command. Use the rip add interface command to inform RIP about the attached interfaces. SmartSwitch Router User Reference Manual...
RIP Parameter Default Value Version number RIP v1 Check-zero for RIP reserved parameters Enabled Whether RIP packets should be broadcast Choose Preference for RIP routes Metric for incoming routes Metric for outgoing routes SmartSwitch Router User Reference Manual...
Configure RIP Route Preference You can set the preference of routes learned from RIP. To configure RIP route preference, enter the following command in Configure mode. Set the preference of routes learned from RIP. <num> rip set preference SmartSwitch Router User Reference Manual...
Show detailed information of all request rip trace request receive received by the router. Show detailed information of all response rip trace response receive received by the router. SmartSwitch Router User Reference Manual...
OSPF. OSPF routes can be redistributed into RIP or BGP • Interface Parameters: Parameters that can be configured include interface output cost, retransmission interval, interface transmit delay, router priority, router dead and hello intervals, and authentication key SmartSwitch Router User Reference Manual...
Create virtual links, if necessary. Enable OSPF OSPF is disabled by default on the SSR. To enable or disable OSPF, enter one of the following commands in Configure mode. Enable OSPF. ospf start Disable OSPF. ospf stop SmartSwitch Router User Reference Manual...
<name-or-IPaddr> ospf set interface |all hello packets on an OSPF interface. <num> hello-interval Configure the retransmission interval <name-or-IPaddr> ospf set interface |all between link state advertisements for <num> retransmit-interval adjacencies belonging to an OSPF interface. SmartSwitch Router User Reference Manual...
To create areas and assign interfaces, enter the following commands in the Configure mode. Create an OSPF area. <area-num> ospf create area |backbone Add an interface to an OSPF area. <name-or-IPaddr> ospf add interface <area-addr> [to-area |backbone] [type broadcast|non-broadcast] SmartSwitch Router User Reference Manual...
To connect an area via a transit area to the backbone • To create a redundant backbone connection via another area Each Area Border Router must be configured with the same virtual link. Note that virtual links cannot be configured through a stub area. SmartSwitch Router User Reference Manual...
Advertisements (LSAs). LSAs are limited to initial advertisements and any subsequent changes. Periodic LSAs over NBMA circuits are suppressed. To configure OSPF over WAN circuits, enter the following command in Configure mode: Configure OSPF over a WAN <hostname-or-IPaddr> ospf add nbma-neighbor circuit. <name-or-IPaddr> to-interface [eligible] SmartSwitch Router User Reference Manual...
Show information about OSPF export ospf show export-policies policies. Shows routes redistributed into OSPF. ospf show exported-routes Show all OSPF global parameters. ospf show globals Show information about OSPF import ospf show import-policies policies. SmartSwitch Router User Reference Manual...
We would like to redistribute these RIP routes as OSPF type-2 routes, and associate the tag 100 with them. Router R1 would also like to redistribute its static routes as type 2 OSPF routes. The interface routes would redistributed as type 1 OSPF routes. SmartSwitch Router User Reference Manual...
Page 68
Create the Export-Policy for redistributing all interface, RIP and static routes into OSPF. ip-router policy export destination ospfExpDstType1 source directExpSrc network all ip-router policy export destination ospfExpDstType2 source statExpSrc network all ip-router policy export destination ospfExpDstType2t100 source ripExpSrc network all SmartSwitch Router User Reference Manual...
Page 69
SmartSwitch Router User Reference Manual...
Page 70
Figure 1. Exporting to OSPF 140.1.5/24 140.1.1.2/24 A r e a 140.1.0.0 140.1.4/24 A r e a B a c k b o n e 150.20.3.1/16 140.1.1.1/24 130.1.1.1/16 140.1.3.1/24 140.1.2.1/24 190.1.1.1/16 130.1.1.3/16 150.20.3.2/16 120.190.1.1/16 A r e a 150.20.0.0 120.190.1.2/16 202.1.2.2/16 160.1.5.2/24 160.1.5.2/24...
AS topologies. BGP also provides the ability to create and enforce policies at the AS level, such as selectively determining which AS routes are to be accepted or what routes are to be advertised to BGP peers. SmartSwitch Router User Reference Manual...
Setting the autonomous system number • Setting the router ID • Creating a BGP peer group • Adding a BGP peer host • Starting BGP • Using AS path regular expressions • Using AS path prepend SmartSwitch Router User Reference Manual...
A BGP peer group is a group of neighbor routers that have the same update policies. To configure a BGP peer group, enter the following command in Configure mode: Configure a BGP peer group bgp create peer-group <number-or-string> type external|internal|igp|routing [autonomous-system <number>] [proto any|rip|ospf|static] [interface <interface-name-or-ipaddr> |all] SmartSwitch Router User Reference Manual...
Page 74
<name-or-IPaddr> | all Interfaces whose routes are carried via the IGP for which third-party next hops may be used instead. Use only for type Routing group. Specify the interface or all for all interfaces. SmartSwitch Router User Reference Manual...
An AS-path operator is one of the following: aspath_term {m,n} A regular expression followed by {m,n} (where m and n are both non-negative integers and m <= n) means at least m and at most n repetitions. SmartSwitch Router User Reference Manual...
# insert two instances of the AS when advertising the route to this peer bgp set peer-host 194.178.244.33 group nlnet as-count 2 # insert three instances of the AS when advertising the route to this # peer bgp set peer-host 194.109.86.5 group webnet as-count 3 SmartSwitch Router User Reference Manual...
The router process used for a specific BGP peering session is known as a BGP speaker. A single router can have several BGP speakers. Successful BGP peering depends on the establishment of a neighbor relationship between BGP speakers. The first step in creating SmartSwitch Router User Reference Manual...
Page 79
BGP peer and the TCP connection is closed. Figure 2 illustrates a sample BGP peering session. AS-1 AS-2 SSR1 SSR2 10.0.0.1/16 10.0.0.2/16 Legend: Physical Link Peering Relationship Figure 2. Sample BGP Peering Session SmartSwitch Router User Reference Manual...
Page 80
The CLI configuration for router SSR2 is as follows: interface create ip et.1.1 address-netmask 10.0.0.2/16 port et.1.1 ip-router global set autonomous-system 2 ip-router global set router-id 10.0.0.2 bgp create peer-group pg2w1 type external autonomous-system 1 bgp add peer-host 10.0.0.1 group pg2w1 bgp start SmartSwitch Router User Reference Manual...
This implementation comes closest to the IBGP implementation of other router vendors. You should use the IBGP Routing group as the mechanism to configure the SSR for IBGP. If the peers are directly connected, then IBGP using group-type Internal can also be used. SmartSwitch Router User Reference Manual...
Page 82
BGP configuration that uses the Routing group type. AS-64801 10.12.1.1/30 10.12.1.6/30 Cisco lo0 172.23.1.25/30 OSPF 10.12.1.5/30 10.12.1.2/30 SSR4 SSR1 IBGP 172.23.1.10/30 172.23.1.5/30 lo0 172.23.1.26/30 SSR6 172.23.1.6/30 172.23.1.9/30 Figure 3. Sample IBGP Configuration (Routing Group Type) SmartSwitch Router User Reference Manual...
Page 83
172.23.1.25 group ibgp1 # Set our local address. This line is necessary because we want CISCO to # peer with our loopback bgp set peer-group ibgp1 local-address 172.23.1.26 # Start BGP bgp start SmartSwitch Router User Reference Manual...
The IBGP Internal group expects all peers to be directly attached to a shared subnet so that, like external peers, the next hops received in BGP advertisements may be used directly for forwarding. All Internal group peers should be L2 adjacent. SmartSwitch Router User Reference Manual...
Page 85
The CLI configuration for router SSR1 is as follows: ip-router global set autonomous-system 1 bgp create peer-group int-ibgp-1 type internal autonomous-system 1 bgp add peer-host 16.122.128.2 group int-ibgp-1 bgp add peer-host 16.122.128.8 group int-ibgp-1 bgp add peer-host 16.122.128.9 group int-ibgp-1 SmartSwitch Router User Reference Manual...
Page 86
The gated.conf file for router SSR2 is as follows: autonomoussystem 1 ; routerid 16.122.128.2 ; bgp yes { traceoptions aspath detail packets detail open detail update ; group type internal peeras 1 peer 16.122.128.1 peer 16.122.128.8 peer 16.122.128.9 SmartSwitch Router User Reference Manual...
Such neighbors are logically, but not physically connected. For example, BGP can be run between external neighbors across non-BGP routers. Some additional configuration is required to indicate that the external peers are not physically attached. SmartSwitch Router User Reference Manual...
Page 88
! Specify the gateway option, which indicates EBGP multihop. Set the ! gateway option to the address of the router that has a route to the ! peer. bgp set peer-host 18.122.128.2 gateway 16.122.128.3 group ebgp_multihop SmartSwitch Router User Reference Manual...
Page 89
18.122.0.0 masklen 16 gateway 17.122.128.4 The CLI configuration for router SSR3 is as follows: interface create ip to-yago3 address-netmask 17.122.128.4/16 port et.4.2 interface create ip to-yago2 address-netmask 18.122.128.4/16 port et.4.4 ip add route 16.122.0.0/16 gateway 17.122.128.3 SmartSwitch Router User Reference Manual...
Figure 5 shows a BGP configuration where the specific community attribute is used. Figure 6 shows a BGP configuration where the well-known community attribute is used. SmartSwitch Router User Reference Manual...
Page 92
For this reason, it is generally desirable to order import clauses from most to least specific. An import clause without an optional- attributes-list option will match any update with any (or no) communities. SmartSwitch Router User Reference Manual...
Page 93
901color1 network all preference 160 ip-router policy import source 901color2 network all preference 155 ip-router policy import source 901color3 network all preference 160 ip-router policy import source 901color4 network all preference 155 SmartSwitch Router User Reference Manual...
Page 94
In an Export Statement: The optional-attributes-list option of the ip-router policy create bgp-export-destination command may be used to send the BGP community attribute. Any communities specified with the optional-attributes-list option are sent in addition to any received in the route or specified with the group. SmartSwitch Router User Reference Manual...
Page 95
899to900dest source 899toanydir network all ip-router policy export destination 899to902dest source 899toanydir network all Any communities specified with the optional-attributes-list option are sent in addition to any received with the route or associated with a BGP export destination. SmartSwitch Router User Reference Manual...
Page 96
Well-known-community none This is not actually a community, but rather a keyword that specifies that a received BGP update is only to be matched if no communities are present. It has no effect when originating communities. SmartSwitch Router User Reference Manual...
Local_Pref values that are greater than 254. When operating a mixed network of this type, you should make sure that all routers are restricted to sending Local_Pref values in the range metric to 254. SmartSwitch Router User Reference Manual...
BGP speakers within the same AS. The MED attribute is never propagated to other BGP speakers in neighboring autonomous systems. Figure 8 shows a sample BGP configuration where the MED attribute has been used. SmartSwitch Router User Reference Manual...
Page 100
# Set the MED to be announced to peer group pg752to751 bgp set peer-group pg752to751 metric-out 20 Router SSR6 has the following CLI configuration: bgp create peer-group pg752to751 type external autonomous-system 64751 bgp add peer-host 10.200.12.15 group pg752to751 bgp set peer-group pg752to751 metric-out 10 SmartSwitch Router User Reference Manual...
# Create an aggregate route for 212.19.192.0/19 with all its subnets as # contributing routes ip-router policy summarize route 212.19.192.0/19 ip-router policy redistribute from-proto aggregate to-proto bgp target- as 64901 network 212.19.192.0/19 ip-router policy redistribute from-proto direct to-proto bgp target-as 64901 network all restrict SmartSwitch Router User Reference Manual...
All peers of the route reflector that are not part of the cluster are non-clients. The SSR supports client peers as well as non-client peers of a route reflector. SmartSwitch Router User Reference Manual...
Page 103
SSR11 is the route reflector for the second cluster. Router SSR10 has router SSR9 as a client peer and router SSR11 as a non-client peer. The following line in router SSR10’s configuration file causes it to be a route reflector. bgp set peer-group SSR9 reflector-client SmartSwitch Router User Reference Manual...
To accomplish this, routers SSR10 and SSR11 have the following line in their configuration files: ip-router policy redistribute from-proto bgp source-as 64901 to- proto bgp target-as 64901 • If the cluster ID is changed, all BGP sessions with reflector clients will be dropped and restarted. SmartSwitch Router User Reference Manual...
The SSR also provides the ability to create advanced and simple routing policies. Simple routing policies provide a quick route redistribution between various routing protocols (RIP and OSPF). Advanced routing policies provide more control over route redistribution. SmartSwitch Router User Reference Manual...
RIP routes rip set preference Point-to-point interface Routes to interfaces that are ip-router global set interface down-preference down Aggregate/generate routes aggr-gen OSPF AS external routes ospf set ase-defaults preference BGP routes bgp set preference SmartSwitch Router User Reference Manual...
Due to the nature of OSPF, only the importation of ASE routes may be controlled. OSPF intra-and inter-area routes are always imported into the routing table with a preference of 10. If a tag is specified with the import policy, routes with the specified tag will only be imported. SmartSwitch Router User Reference Manual...
The metric, type, tag, and AS-Path are a few examples of attributes associated with the exported routes. Export-Source This component specifies the source of the exported routes. It can also specify the metric to be associated with the routes exported from this source. SmartSwitch Router User Reference Manual...
The action taken when no match is found is dependent on the context. For instance, a route that does match any of the route-filters associated with the specified import or export policies is rejected. SmartSwitch Router User Reference Manual...
It is used, for example, at an autonomous system border to generate a route to a network to be advertised via BGP given the presence of one or more subnets of that network learned via OSPF. The routing process does not perform any aggregation unless explicitly requested. SmartSwitch Router User Reference Manual...
Tag associated with a route. Both OSPF and RIP version 2 currently support tags. All other protocols have a tag of zero. In some cases, a combination of the associated attributes can be specified to identify the routes contributing to an aggregate. SmartSwitch Router User Reference Manual...
In addition, a sequence number is maintained to prevent the replay of older packets. This method provides a much stronger assurance that routing data originated from a router with a valid authentication key. SmartSwitch Router User Reference Manual...
Export Policies. The general syntax of the redistribute command is as follows: ip-router policy redistribute from-proto <protocol> to-proto <protocol> [network <ipAddr- mask> [exact|refines|between <low-high>]] [metric <number>|restrict] [source-as <number>] [target-as <number>] SmartSwitch Router User Reference Manual...
To redistribute direct routes, enter one of the following commands in Configure mode: To redistribute direct routes ip-router policy redistribute from-proto direct to-proto rip network all into RIP. To redistribute direct routes ip-router policy redistribute from-proto direct to-proto ospf network all into OSPF. SmartSwitch Router User Reference Manual...
The aggregate parameter causes an aggregate route with the specified IP address and subnet mask to be redistributed. Note: The aggregate route must first be created using the aggr-gen command. This command creates a specified aggregate route for routes that match the aggregate. SmartSwitch Router User Reference Manual...
135.3.2.0/24 gateway 130.1.1.3 ip add route 135.3.3.0/24 gateway 130.1.1.3 !+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ! Configure default routes to the other subnets reachable through R2. !+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ip add route 202.1.0.0/16 gateway 120.190.1.2 ip add route 160.1.5.0/24 gateway 120.190.1.2 SmartSwitch Router User Reference Manual...
Example 2: Redistribution into OSPF For all examples given in this section, refer to the configurations shown in Figure 12 on page 131. The following configuration commands for router R1: • Determine the IP address for each interface SmartSwitch Router User Reference Manual...
OSPF, we have not specified this parameter. Export all RIP, Interface & Static Routes to OSPF Note: Also export interface, static, RIP, OSPF, and OSPF-ASE routes into RIP. SmartSwitch Router User Reference Manual...
Path are a few examples of attributes associated with the exported routes. • Export Sources - This component specifies the source of the exported routes. It can also specify the metric to be associated with the routes exported from this source. The SmartSwitch Router User Reference Manual...
Page 122
The <filter-id>, if specified, is the identifer of the route-filter associated with this export- policy. If there is more than one route-filter for any export-destination and export-source combination, then the ip-router policy export destination <exp-dest-id> source <exp-src-id> command should be repeated for each <filter-id>. SmartSwitch Router User Reference Manual...
It you do not have complex filter requirements, then use the second method. After you create one or more building blocks, they are tied together by the iprouter policy import command. SmartSwitch Router User Reference Manual...
Route aggregation is a method of generating a more general route, given the presence of a specific route. The routing process does not perform any aggregation unless explicitly requested. Aggregate-routes can be constructed from one or more of the following building blocks: SmartSwitch Router User Reference Manual...
Page 125
The <filter-id> is the identifer of the route-filter associated with this aggregate. If there is more than one route-filter for any aggregate-destination and aggregate-source combination, then the ip-router policy aggr-gen destination <aggr-dest-id> source <aggr- src-id> command should be repeated for each <filter-id>. SmartSwitch Router User Reference Manual...
RIP does not support the use of preference to choose between routes of the same protocol. That is left to the protocol metrics. For all examples in this section, refer to the configuration shown in Figure 11 on page 127. SmartSwitch Router User Reference Manual...
Page 127
Chapter 7: Routing Policy Configuration Guide RIP V2 The following configuration commands for router R1 • Determine the IP address for each interface. • Specify the static routes configured on the router. • Determine its RIP configuration. SmartSwitch Router User Reference Manual...
Router R1 has several RIP peers. Router R41 has an interface on the network 10.51.0.0. By default, router R41 advertises network 10.51.0.0/16 in its RIP updates. Router R1 would like to import all routes except the 10.51.0.0/16 route from its peer R41. SmartSwitch Router User Reference Manual...
Due to the nature of OSPF, only the importation of ASE routes may be controlled. OSPF intra-and inter-area routes are always imported into the SSR routing table with a preference of 10. If a tag is specified, the import clause will only apply to routes with the specified tag. SmartSwitch Router User Reference Manual...
Page 130
That is done by the OSPF costs. Routes that are rejected by policy are stored in the table with a negative preference. For all examples in this section, refer to the configuration shown in Figure 12 on page 131. SmartSwitch Router User Reference Manual...
Page 131
Figure 12: Exporting to OSPF 140.1.5/24 140.1.1.2/24 A r e a 140.1.0.0 140.1.4/24 A r e a B a c k b o n e 150.20.3.1/16 140.1.1.1/24 130.1.1.1/16 140.1.3.1/24 140.1.2.1/24 190.1.1.1/16 130.1.1.3/16 150.20.3.2/16 120.190.1.1/16 A r e a 150.20.0.0 120.190.1.2/16 202.1.2.2/16 160.1.5.2/24 160.1.5.2/24...
100 Create the Import-Policy importing all OSPF ASE routes with a tag of 100 except the default ASE route. ip-router policy import source ospfImpSrct100 network all ip-router policy import source ospfImpSrct100 network default restrict SmartSwitch Router User Reference Manual...
170.1.1.1/16 port et.1.7 !++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ! Configure a default route through 170.1.1.7 !++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ip add route default gateway 170.1.1.7 !+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ! Configure default routes to the 135.3.0.0 subnets reachable through ! R3. SmartSwitch Router User Reference Manual...
Since we would also like to export/redistribute RIP and direct routes into RIP, we would also create export-sources for those protocols. Create a RIP export source since we would like to export RIP routes. ip-router policy create rip-export-source ripExpSrc SmartSwitch Router User Reference Manual...
140.1.1.0/24 and 140.1.2.0/24 networks to router R3. RIP Version 1 does not carry any information about subnet masks in its packets. Thus it would not be possible to announce the subnets (140.1.1.0/24 and 140.1.2.0/24) into RIP Version 1 without aggregating them. SmartSwitch Router User Reference Manual...
Page 137
Create a RIP export source since we would like to export RIP routes. ip-router policy create rip-export-source ripExpSrc Create a Direct export source since we would like to export Direct routes. ip-router policy create direct-export-source directExpSrc SmartSwitch Router User Reference Manual...
For all examples in this section, refer to the configuration shown in Figure 12 on page 131. The following configuration commands for router R1: • Determine the IP address for each interface • Specify the static routes configured on the router • Determine its OSPF configuration SmartSwitch Router User Reference Manual...
OSPF as type 2 OSPF-ASE routes. ip-router policy create ospf-export-destination ospfExpDstType2 type 2 metric 4 Create a Static export source since we would like to export static routes. ip-router policy create static-export-source statExpSrc SmartSwitch Router User Reference Manual...
Create a OSPF export destination for type-2 routes. ip-router policy create ospf-export-destination ospfExpDstType2 type 2 metric 4 Create a OSPF export destination for type-2 routes with a tag of 100. ip-router policy create ospf-export-destination ospfExpDstType2t100 type 2 tag 100 metric 4 SmartSwitch Router User Reference Manual...
(VLANs) can be configured with the same IP interface on the SSR, IGMP keeps track of multicast host members on a per-port basis. Ports belonging to an IP VLAN without any IGMP membership will not be forwarded any multicast traffic. SmartSwitch Router User Reference Manual...
Tunnel traffic is not optimized on a per-port basis, and it goes to all ports on an interface, even though IGMP keeps per-port membership information. This is done to minimize CPU overload for tunneled traffic. SmartSwitch Router User Reference Manual...
You can configure the SSR with a wait time for IGMP Host Membership responses which is different from the default. The wait time you set then applies to all ports on the SSR. The default response time is 10 seconds. SmartSwitch Router User Reference Manual...
DVMRP on interfaces and then setting DVMRP parameters on the interfaces on which DVMRP is disabled. • Defining DVMRP tunnels, which IP uses to send multicast traffic between two end points. Starting and Stopping DVMRP DVMRP is disabled by default on the SSR. SmartSwitch Router User Reference Manual...
You can configure the DVMRP routing metric associated with a set of destinations for DVMRP reports. The default metric is 1. To configure the DVMRP routing metric, enter the following command in Configure mode: Configure the DVMRP routing dvmrp set interface <ip-addr> metric <number> metric. SmartSwitch Router User Reference Manual...
Internet). You can configure a DVMRP tunnel on a router if the other end is running DVMRP. The SSR then sends and receives multicast packets over the tunnel. Tunnels are CPU-intensive; they are not switched directly through the SSR’s multitasking ASICs. SmartSwitch Router User Reference Manual...
Show all IGMP timers. igmp show timers Show information about multicasts l2-tables show igmp-mcast-registration registered by IGMP. Show IGMP status on a VLAN. l2-tables show vlan-igmp-status Show all multicast Source, Group mulitcast show cache entries. SmartSwitch Router User Reference Manual...
IPX routers use RIP to create and dynamically maintain a database of internetwork routing information. RIP allows a router to exchange routing information with a neighboring router. As a router becomes aware of any change in the internetwork layout, SmartSwitch Router User Reference Manual...
Router’s request for the names and addresses of either all or certain type of servers • Response to workstation or router’s request • Periodic broadcast to make sure all other routers are aware of the internetwork configuration • Perform broadcasting whenever they detect a change in the internetwork configurations SmartSwitch Router User Reference Manual...
The IPX address is a 12-byte number divided into three parts. The first part is the 4-byte (8-character) IPX external network number. The second part is the 6-byte (12-character) node number. The third part is the 2-byte (4-character) socket number. SmartSwitch Router User Reference Manual...
802.3 SNAP: SNAP IEEE 802.3 encapsulation, in which the type code becomes the frame length for the IEEE 802.2 LLC encapsulation (destination and source Service Access Points, and a control byte) • 802.3: 802.3 encapsulation method used within Novell IPX environments SmartSwitch Router User Reference Manual...
IPX. However, you can add static RIP routes to RIP routing table to explicitly specify a route. To add a static RIP route, enter the following command in Configure mode: Add a static RIP route. <networkaddr> ipx add route <nextrouter or network node> <metric> <ticks> SmartSwitch Router User Reference Manual...
Once an IPX access control list has been created, you must apply the access control list to an IPX interface. To apply an IPX access control list, enter the following command in Configure mode: Apply an IPX access control list. l <name> <Interface Name> apply interface input|output [logging [on|off]] SmartSwitch Router User Reference Manual...
Once an IPX GNS access control list has been created, you must apply the access control list to an IPX interface. To apply an IPX GNS access control list, enter the following command in Configure mode: Apply an IPX GNS access control list. <name> apply interface <InterfaceName> output [logging [on|off]] SmartSwitch Router User Reference Manual...
Show IPX RIP/SAP table summary ipx show tables summary Configuration Examples This example performs the following configuration: • Creates IPX interfaces • Adds static RIP routes • Adds static SAP entries7.pdf.zip • Adds a RIP access list SmartSwitch Router User Reference Manual...
Page 159
!IPX type 20 access list acl 300 deny ipxtype20 !IPX type 20 inbound filter to interface ipx2 acl 300 apply interface ipx2 input !GNS Access List acl 300 deny ipxgns A.01:03:05:07:02:03 0004 FILESERVER2 acl 200 apply interface ipx2 output SmartSwitch Router User Reference Manual...
Perform access control to services provided on the SSR, for example, Telnet server and HTTP server. Note: Currently, Source Filtering is available on Cabletron Systems WAN cards, however application must take place on the entire WAN card. SmartSwitch Router User Reference Manual...
TACACS server responds to the SSR TACACS client to provide authentication. You can configure up to five TACACS server targets on the SSR. A timeout is set to tell the SSR how long to wait for a response from TACACS servers. SmartSwitch Router User Reference Manual...
TACACS Plus server reply. Determine the SSR action if no tacacs-plus set last-resort password|succeed server responds. Enable TACACS Plus. tacacs-plus enable Monitor TACACS Plus You can monitor TACACS Plus configuration and statistics within the SSR. SmartSwitch Router User Reference Manual...
A secure filter shuts down access to the SSR based on MAC addresses. All packets received by a port are dropped. When combined with static entries, however, these filters can be used to drop all received traffic but allow some frames to go through. SmartSwitch Router User Reference Manual...
To configure Layer-2 port address lock filters, enter the following commands in Configure mode: Configure a port address lock filter. filters add port-address-lock name <name> <MACaddr> source-mac vlan <VLAN-num> <port-list> in-port-list SmartSwitch Router User Reference Manual...
MAC address to go through • Combine a destination secure port with a destination static entry to drop all received traffic but allow any frame destined to specific destination MAC address go through SmartSwitch Router User Reference Manual...
Static Entries Example Source static entry: The consultant is only allowed to access the engineering file servers on port et.1.2. filters add static-entry name consultant source-mac 001122:334455 vlan 1 in-port-list et.1.1 out-port-list et.1.2 restriction allow SmartSwitch Router User Reference Manual...
To allow ONLY the engineering manager access to the engineering servers, you must "punch" a hole through the secure-port wall. A "source static-entry" overrides a "source secure port". filters add static-entry name eng-mgr source-mac 080060:123456 vlan 1 in-port-list et.1.1 out-port-list et.1.2 restriction allow SmartSwitch Router User Reference Manual...
TCP can use socket port numbers while IPX can use a network node address to define a rule. For IP, TCP and UDP ACLs, the following fields can be specified: • Source IP address • Destination IP address • Source port number • Destination port number SmartSwitch Router User Reference Manual...
Nor is there precedence attached to each field. The router simply goes down the list, one rule at a time until there is a match. Consequently, rules that are more specific (i.e. with more details) should always be listed SmartSwitch Router User Reference Manual...
With the implicit deny rule, this ACL actually has three rules: acl 101 permit ip 1.2.3.4/24 any any any acl 101 permit ip 4.3.2.1/24 any nntp any acl 101 deny any any any any any SmartSwitch Router User Reference Manual...
However, this restriction does not prevent you from specifying many rules in an ACL. You just have to put all of these rules into one ACL and apply it to an interface. SmartSwitch Router User Reference Manual...
This can get worse if the console is connected at a low baud rate, for example, 1200 baud. Furthermore, if a Syslog server is configured then a Syslog packet must also be sent to the Syslog server, SmartSwitch Router User Reference Manual...
If the administrator needs to re-order or modify the ACL rules, one must make the changes in the acl.changes file on the remote host, download the changes and make them effective again. SmartSwitch Router User Reference Manual...
Defining an IP ACL To define an IP ACL, perform the following in the Configure mode: Define an IP ACL. <name> permit|deny ip|tcp|udp|icmp|igmp <srcaddr/mask> |any <dstaddr/mask> |any Note: Additional fields depend on the protocol type you select. SmartSwitch Router User Reference Manual...
Show all ACLs. acl show all Show a specific ACL. <Name> acl show aclname | all Show an ACL on a specific interface. <Name> acl show interface Show ACLs on all IP interfaces. acl show interface all-ip SmartSwitch Router User Reference Manual...
Page 178
Chapter 10: Security Configuration Guide Show ACLs on all IPX interfaces. acl show interface all-ipx Show static entry filters. acl show service SmartSwitch Router User Reference Manual...
For Layer-2 traffic, you can define a flow based on the MAC packet headers. • The MAC fields are source MAC address, destination MAC address and VLAN IDs. A list of incoming ports can also be specified SmartSwitch Router User Reference Manual...
– distributes priority throughput among the four priorities (control, high, medium, and low) based on percentages. The SSR can use only one queuing policy at a time. The policy is used on the entire SSR. The default queuing policy is strict priority. SmartSwitch Router User Reference Manual...
Configuring IPX QoS Policies To configure an IPX QoS policy, perform the following tasks: Identify the Layer-3 or 4 flow and set the IPX QoS policy. Specify the precedence for the fields within an IPX flow. SmartSwitch Router User Reference Manual...
SSR. To allocate bandwidth for each SSR queue, enter the following command in Configure mode: <percentage> Allocate bandwidth for a qos set weighted-fair control <percentage> <percentage> high medium weighted-fair queuing policy. <percentage> SmartSwitch Router User Reference Manual...
To display QoS information, enter the following command in Enable mode: Show all IP QoS flows qos show ip Show all IPX QoS flows. qos show ipx Show all Layer-2 QoS flows. qos show l2 all-destination all-flow <port-list> <vlanID> ports vlan source-mac <MACaddr> <MACaddr> dest-mac SmartSwitch Router User Reference Manual...
RMON/RMON2 and can be displayed by using the statistics show command in the CLI. In addition to the monitoring commands listed, you can find more monitoring commands listed in each chapter of the SmartSwitch Router User Reference Manual. To access statistics on the SSR, enter the following commands in Enable mode: Show DVMRP routes.
Page 186
Show RMON statistics. statistics show rmon Show traffic summary statistics. statistics show summary-stats Show TCP statistics. statistics show tcp Show UDP statistics. statistics show udp Show TACACS server statistics. tacacs show stats Show all VLANs. vlan list SmartSwitch Router User Reference Manual...
<port list> port Note: Port Mirroring is available for WAN ports, however, you cannot configure Port Mirroring on a port-by-port basis. (You can only configure Port Mirroring for the entire WAN card). SmartSwitch Router User Reference Manual...
Hot Swapping Line Cards The procedure for hot swapping a line card consists of deactivating the line card, removing it from its slot in the SSR chassis, and installing a new line card in the slot. SmartSwitch Router User Reference Manual...
For example, to reactivate a line card in slot 7, enter the following command in Enable mode: ctron-ssr-1# system hotswap in slot 7 Removing the Line Card To remove a line card from the SSR: Make sure the Offline LED on the line card is lit. SmartSwitch Router User Reference Manual...
If you have a secondary control module installed on the SSR, you can hot swap it with another Control Module or line card. Note: You can only hot swap an inactive Control Module. You should never remove the active Control Module from the SSR. Doing so will crash the system. SmartSwitch Router User Reference Manual...
Make sure that none of the LEDs on the Control Module are lit. Loosen the captive screws on each side of the Control Module. Carefully remove the Control Module from its slot in the SSR chassis. SmartSwitch Router User Reference Manual...
SSR, and insert another Switching Fabric Module in the slot. Note: You cannot deactivate the Switching Fabric Module with the system hotswap command. To deactivate the Switching Fabric Module: Press the Hot Swap button on the Switching Fabric Module you want to deactivate. SmartSwitch Router User Reference Manual...
Page 194
Make sure the circuit card (and not the metal plate) is between the card guides. Check both the upper and lower tracks. Tighten the captive screws on each side of the Switching Fabric Module to secure it to the chassis. SmartSwitch Router User Reference Manual...
Configuring VRRP This section presents three sample VRRP configurations: • A basic VRRP configuration with one virtual router • A symmetrical VRRP configuration with two virtual routers • A multi-backup VRRP configuration with three virtual routers SmartSwitch Router User Reference Manual...
Line 1 adds IP address 10.0.0.1/16 to interface test, making Router R1 the owner of this IP address. Line 2 creates virtual router on interface test. Line 3 associates IP address VRID=1 10.0.0.1/16 with virtual router . Line 4 starts VRRP on interface test. VRID=1 SmartSwitch Router User Reference Manual...
This configuration allows you to load-balance traffic coming from the hosts on the 10.0.0.0/16 subnet and provides a redundant path to either virtual router. Note: This is the recommended configuration on a network using VRRP. SmartSwitch Router User Reference Manual...
7: ip-redundancy start vrrp 2 interface test Router R1 is the owner of IP address 10.0.0.1/16. Line 4 associates this IP address with virtual router , so Router R1 is the Master for virtual router VRID=1 VRID=1 SmartSwitch Router User Reference Manual...
In a VRRP configuration where more than one router is backing up a Master, you can specify which Backup router takes over when the Master goes down by setting the priority for the Backup routers. SmartSwitch Router User Reference Manual...
Page 200
Router R3 is the secondary Backup for virtual routers . It would VRID=1 VRID=2 become a Master router only if both Routers R1 and R2 should fail. In such a case, Router R3 would become the Master for all three virtual routers. SmartSwitch Router User Reference Manual...
200. If no other routers in the VRRP VRID=2 VRID=3 configuration have a higher priority, Router R1 will take over as Master for virtual routers , should Router R2 or R3 go down. VRID=2 VRID=3 SmartSwitch Router User Reference Manual...
The following table shows the priorities for each virtual router configured on Router R2. Virtual Router Default Priority Configured Priority – IP address=10.0.0.1/16 200 (see line 8) VRID=1 – IP address=10.0.0.2/16 255 (address owner) 255 (address owner) VRID=2 – IP address=10.0.0.3/16 100 (see line 9) VRID=3 SmartSwitch Router User Reference Manual...
Since 100 is the default priority, lines 8 and 9, which set the priority to 100, are actually unnecessary. They are included for illustration purposes only. Additional Configuration This section covers settings you can modify in a VRRP configuration, including backup priority, advertisement interval, pre-empt mode, and authentication key. SmartSwitch Router User Reference Manual...
<interface> preempt-mode disabled virtual router. Note: If the IP address owner is available, then it will always take over as the Master, regardless of whether pre-empt mode is on or off. SmartSwitch Router User Reference Manual...
Backup to Master. (Enabled by default.) Display a message when a ip-redundancy trace vrrp packet-errors enabled VRRP packet error is detected. (Enabled by default.) Enable all VRRP tracing. ip-redundancy trace vrrp all enabled SmartSwitch Router User Reference Manual...
• If a Master router is manually rebooted, or if its interface is manually brought down, it will send a special keep-alive advertisement that lets the Backup routers that a new Master is needed immediately. SmartSwitch Router User Reference Manual...
Page 207
SNMP requests directed at the virtual router's IP address. Not responding allows network management to notice that the original Master router (i.e., the IP address owner) is down. SmartSwitch Router User Reference Manual...
Need help?
Do you have a question about the SmartSwitch Router and is the answer not in the manual?
Questions and answers