1 pertemuan 9 switch configuration. discussion topics starting the switch configuring the switch 2

68
1 Pertemuan 9 Switch Configuration

Upload: spencer-sims

Post on 30-Dec-2015

237 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

1

Pertemuan 9 Switch Configuration

Page 2: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Discussion Topics

• Starting the Switch• Configuring the Switch

2

Page 3: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Starting the Switch

Switches:• are dedicated, specialized computers, which contain

a central processing unit (CPU), random access memory (RAM), and an operating system;

• have several ports that hosts can connect to;• have specialized ports for the purpose of

management; • can be managed and the configuration can be viewed

and changed through the console port ;• typically have no power switch to turn them on and off

- simply connect or disconnect from a power source;

Page 4: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Catalyst 2950 series Switches Features

• Fixed configuration symmetrical switches with all ports being FastEthernet or 10/100;

• Asymmetrical switches with two fixed fiber or copper Gigabit Ethernet ports;

• Asymmetrical switches with modular Gigabit Interface Converter (GBIC) slots

Page 5: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

LEDs

Light-emitting diodes (LEDs) • help monitor system activity and performance;• on the front of a switch:

- System LED - Remote Power Supply (RPS) LED - Port Mode LEDs - Port Status LEDs

Page 6: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

LEDs

System LED• shows whether the system is receiving power and functioning correctly;

RPS LED• indicates whether or not the remote power supply is in use;

Mode LEDs • indicate the current state of the Mode button;• are used to determine how the Port Status LEDs are interpreted;• to select or change the port mode, press the Mode button repeatedly until

the Mode LEDs indicate the desired mode.

Port Status LEDs• have different meanings, depending on the current value of the Mode

LED.

Page 7: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Switch Mode LED Indicators

Page 8: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Mode LED

Page 9: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Mode LED

Page 10: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Mode LED

Page 11: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Verifying Port LEDs During Switch POST

Power-On Self Test (POST)

• runs automatically to verify that the switch functions correctly;

• POST failure is considered to be a fatal error;

• should not expect a reliable operation of the switch if POST fails.

Page 12: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Verifying Port LEDs During Switch POST

Port Status LEDs during POST:turn amber - for about 30 seconds • the switch discovers the network topology and

searches for loops;turn green• the switch has established a link between the port

and a target, such as a computer;turn off• the switch has determined that nothing is plugged

into the port.

Page 13: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Console Connection

Page 14: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Console Connection

Page 15: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Console Connection

Shows information about the switch:

• details about POST status;

• data about the switch hardware.

Page 16: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Command-Line Interface (CLI)

Command-line interface (CLI) for Cisco switches:

• is very similar to the CLI for Cisco routers.

Page 17: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

“Help” command

Page 18: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

“help” command

“Help” commandWord help• to obtain a list of commands that begin with a particular

character sequence, enter those characters followed immediately by the question mark (?);

• do not enter a space before the question mark;• it completes a word. Command syntax help • to list keywords or arguments that are associated with a

particular command, enter one or more words associated with the command, followed by a space and then a question mark (?);

• provides applicable keywords or arguments based on a partial command.

Page 19: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Command Modes

• User EXEC

• Privileged EXEC

Page 20: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

User EXEC mode

User EXEC mode• default mode; • is recognized by its prompt, which ends in

a greater-than character (>);• available commands are limited:

- to change terminal settings;- to perform basic tests; - to display system information.

Page 21: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

“show” command

Show commands that are available in User EXEC mode

Page 22: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Privileged EXEC mode

Privileged EXEC mode• to enter enable command is used from User EXEC

mode;• is recognized by its prompt, which ends in a pound-sign

character (#);• the command set includes the configure command:

- allows other command modes to be accessed;• should be password protected to prevent unauthorized

use;• the password does not appear on the screen, and is case

sensitive.

Page 23: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Default Running Configuration

Default Running Configuration• when powered up for the first time, a switch has

default data in the running configuration file;• default hostname - Switch;• no passwords are set on the console or virtual

terminal (vty) lines;• the switch has no IP address (IP address for

management purposes is configured on the virtual interface VLAN 1)

Page 24: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Verifying the Catalyst Switch Default Configuration

• show running-config• show interface• show vlan• show flash• show version

Page 25: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Default Running Configuration

Page 26: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Default Port Settings

Default Running Configuration

• the switch ports or interfaces are set to auto mode;

• all switch ports are in VLAN 1;

• VLAN 1 is known as the default management VLAN.

Page 27: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Default Port Settings

Page 28: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Default Port Settings

Page 29: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Default Flash Directory Content

IOS image

file env_vars

sub-directory html

Page 30: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Default Flash Directory Content

Default Running Configuration• by default flash directory contains:

- IOS image;

- file env_vars;

- sub-directory html.

• flash directory does not contain:

- config.text – switch configuration file;

- vlan.dat - VLAN database file.

Page 31: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

IOS Version and Config. Register

show version command – used to verify:• IOS version; • configuration register settings.

Page 32: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Reset Switch Configuration

Page 33: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Reset Switch Configuration

Steps to overwrite any existing configuration:

• Remove the current VLAN information:

- delete the VLAN database file vlan.dat from the flash directory

• Erase the back up configuration file:

- delete file startup-config

• Restart the switch:

- use reload command.

Page 34: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Reset Switch Configuration

Page 35: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Hostname and Passwords Configuration

Page 36: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

IP address and Default Gateway Configuration

IP address Configuration:

• allows the switch to be accessible by Telnet and other TCP/IP applications

Page 37: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

VLAN1

Management VLAN:

• by default, VLAN 1 is the management VLAN;

• all internetworking devices should be in the management VLAN;

• allows a single management workstation to access, configure, and manage all the internetworking devices.

Page 38: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Port Speed and Duplex Settings Configuration

Page 39: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Port Speed and Duplex Settings Configuration

Fast Ethernet switch ports:

•by default set to auto-speed and auto-duplex (allows the interfaces to negotiate these settings);

•Network administrators can manually configure the interface speed and duplex values

Page 40: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

HTTP Service and Port Configuration

• Intelligent network devices can provide a web-based interface for configuration and management purposes;

• Once a switch is configured with an IP address and gateway, it can be accessed by a web-based interface;

HTTP services:• can be access by a web browser using:

- IP address;- port 80 - the default port for http.

• can be turned on or off, and the port address for the service can be chosen.

Page 41: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

HTTP Service and Port Configuration

Page 42: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Configuring the Catalyst Switch

Web Management Interface

Web Management Interface

Page 43: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

MAC Address Table

Switches

• examine the source address of frames that are received on the ports;

• learn the MAC addresses of PCs or workstations that are connected to their switch ports;

• record learned MAC addresses in a MAC address table.

Page 44: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Check Learned MAC Addresses

show mac-address-table command - Privileged EXEC mode

• examines the addresses that a switch has learned

Page 45: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

MAC Address Table

Switches: • dynamically learn and maintain thousands

of MAC addresses;• learned entries may be discarded from the

MAC address table (to preserve memory and for optimal operation) ;

• the MAC address entry is automatically discarded or aged out after 300 seconds (if no frames are seen with a previously learned address).

Page 46: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Check Learned MAC Addresses

Clear mac-address-table command - Privileged EXEC mode

• used to remove dynamically learned MAC addresses;

• used to remove static MAC address entries.

Page 47: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Managing the MAC Address Table

Page 48: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Static MAC Addresses

Static MAC address:

• permanently assigned to an interface;

Reasons for use a Static MAC address:

• will not be aged out automatically by the switch;

• a specific server or user workstation must be attached to the port and the MAC address is known;

• Security is enhanced.

Page 49: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Configuring Static MAC Addresses

Page 50: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Configuring Static MAC Addresses

Page 51: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Static MAC Addresses

To configure:

Switch(config)#mac-address-table static <mac-address

of host > interface FastEthernet <Ethernet number >

vlan <vlan name > To remove:

Switch(config)# no mac-address-table static <mac-

address of host > interface FastEthernet <Ethernet

number > vlan <vlan name >

Page 52: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Port Security

Port Security

• It is possible to limit the number of addresses that can be learned on an interface;

• the number of MAC addresses per port can be limited to 1;

• the first address dynamically learned by the switch becomes the secure address.

Page 53: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Port Security Configuration

Page 54: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Port Security

To configure port security :

Switch(config-if)#switchport port-security

To reverse port security:

Switch(config-if)# no switchport port-security

To verify port security status:

Switch(config)#show port security

Page 55: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Adding New Switch

Adding New Switch

Must be configured:

• Switch name;

• IP address for the switch in the management VLAN;

• a default gateway;

• Line passwords.

Page 56: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Adding New Switch

Page 57: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Moving a Switch

Host is moved:

• from one port or switch to another;

• configurations that can cause unexpected behavior should be removed;

• configuration that is required can then be added.

Page 58: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Add, Remove and Change MAC Addresses

Page 59: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Managing Switch Operation

• An administrator should document and maintain the operational configuration files for networking devices;

• The most recent running-configuration file should be backed up on a server or disk;

• The Cisco IOS Software should also be backed up to a local server. The Cisco IOS Software can then be reloaded to Flash memory if needed.

Page 60: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Managing Switch Operation

Page 61: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Enable Security

Page 62: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Passwords

Passwords

• must be set on the console and vty lines- for security and management purposes;

• must be set enable password;

• must be set enable secret password.

Page 63: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Password Recovery (2950)

1. Make sure that a PC is connected to the console port and a HyperTerminal window is open.

2. Turn the switch off. Turn it back on while holding down the “MODE” button on the front of the switch at the same time that the switch is powered on. Release the “MODE” button after the STAT LED goes out.

Page 64: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Password Recovery (2950)

3. Type flash_init

4. Type load_helper

5. Type dir flash:

6. rename flash:config.text flash:config.old

7. Type boot

8. N at the following prompt to start the Setup program.

Page 65: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Password Recovery (2950)

9. Type rename flash:config.old flash:config.text

10.copy flash:config.text system:running-config

Page 66: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Password Recovery (2950)

11.

Page 67: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Firmware and IOS Images

To upgrade the IOS, download a copy of the new image to a local server from the Cisco Connection Online (CCO) Software Center

Page 68: 1 Pertemuan 9 Switch Configuration. Discussion Topics Starting the Switch Configuring the Switch 2

Summary