Documentos de Académico
Documentos de Profesional
Documentos de Cultura
==================================
Trunk
VTP
VLAN
=====
STP
Etherchannel
SVI
Etherchannel L3
=====
Seguridad de Swtich
FHRP
DHCP
===================================
show mac address-table
show mac-address-table
show interface fa0/1 switchport
show interface trunk
===================================
Causas
=======
VLAN no este configurada
VLAN no este agregada al trunk
VLAN este bloqueada por STP
VLAN Actualizada por VTP
No existe un enlace troncal
Existir una VACL
Existir una Mac ACL
Seguridad de puerto
Negociación entre interfaces de switch
========================================
Comandos de consultas
show mac address-table
show mac-address-table
show interface fa0/1 switchport
show interface trunk
show vlan
show vtp status
show vtp pass
ipconfig
show ip int brief
show run int fa0/x
========================================
1.- Troubleshooting Trunks
Diferencias de encapsulación
- IEEE 802.1Q
- ISL (Inter-switch Link)
Auto
Desirable
Manual
int fa0/24
sw trunk enca dot
int fa0/24
sw trunk encap isl
default-gateway 192.168.x.1
802.1q
802.1q-n
=====================================
int fa0/24
sw mode trunk
sw nonegotiate
!
int fa0/24
sw mode trunk dynamic desirable (DTP)
=====================================
1.2 Modos incompatibles de Trunking
Acceso
Trunk
Dynamic Desirable
Dynamic Auto
==============================================
1.3 Diferencias en el nombre de dominio de VTP
========================================
1.4 Diferencias en la VLAN Nativa
========================================
cliente
server
transparente
off
===============================================
ipconfig
vlan 50
name SOPORTE
!
int fa0/3
sw mode acc
sw acc vlan 20
===================================
Troubleshooting de Spanning-tree y Etherchannel
===============================================
Spanning-tree
===================
Proceso de configuración
Nombre MST
Region MST
Instancia MST
Mapear VLAN instancia
Problemas
Problemas de Spanning-tree
%SW_MATM-4-MACFLAP_NOTIF
2. Tormentas broadcast
La tramas no tienen un TTL, las tramas broadcast esten siempre reenviandose por todos los
switches.
Consume BW
Retardo a la red
CPU
RAM
Storm-control
int fa0/5
storm-control broadcast level 1
3. Portfast
- Configurar en los edge port
- transicionar al estado forwarding inmediatamente.
- Suprime el estado Listening y Learning del STP.
int fa0/1
spann portf
!
====================================================
4. BPDU Guard
int f0/3
spanning-tree bpduguard enable
do sh int fa0/3
5. Root Guard
int fa0/4
spanning-tree portfast
spanning-tree guard root
6. BPDU Filter
7. Loop Guard
================================
2. Troubleshooting Etherchannel
Portchannel es una interfaz virtual que replica su configuración a los puertos físicos.
Amplifica la capacidad de BW
Se pueden agregar hasta 16 interfaces en un Po, pero solo 8 interfaces estaran activos.
Identica:
- Velocidad de puerto
- Modo Duplex
- Modo trunk
- VLAN nativa
- VLAN incluidas en el puerto
- Po L2 ó Po L3
LACP
Active/Passive
Active/Active
PAGP
auto/desirable
desirable/desirable
ON
on/off
2.3 Distribución inapropiada del algortimo de Etherchannel
src-mac
src-ip
dst-mac
dst-ip
mac-ip
SU
S: L2
U: Uso
Router-on-a-stick
Switch Virtual Interface
Puertos Ruteados
Etherchannel L3
Port-security
Spoof
Private VLAN
MAC ACL
Port ACL
VLAN ACL
HSRP
VRRP
GLBP
DHCP
=====
Troubleshooting
===================
Objetivos
============
- Tshoot Port- security
- Tshoot Dhcp Snooping
- Tshoot Dynamic ARP inspection
1. Tshoot Port-security
1.1 Port-sec este configurado pero no habilitado
1.2 MAC estática configurada incorrectamente
1.3 Maximo de MAC alcanzado
1.4 Violación de puerto
1.5 Port-sec no se guarden
================================================
int fa0/0
sw port-security -> Cuando no se agrega
sw port-sec max 1
sw port-sec violation shutdown
sw port-sec mac-address sticky
sw port-sec mac-address 0001.0002.0003
!
ASW1(config-if)#do sh port-sec int fa0/2
Port Security : Disabled
Port Status : Secure-down
Violation Mode : Restrict
Aging Time : 0 mins
Aging Type : Absolute
SecureStatic Address Aging : Disabled
Maximum MAC Addresses :2
Total MAC Addresses :0
Configured MAC Addresses : 0
Sticky MAC Addresses :1
Last Source Address:Vlan : 0040.0BC4.A853:10
Security Violation Count : 0
int fa0/2
sw port-sec mac 0001.0002.0003
ASW1#show port-security address
Secure Mac Address Table
-------------------------------------------------------------------------------
Vlan Mac Address Type Ports Remaining Age
(mins)
---- ----------- ---- ----- -------------
10 0001.0002.0003 SecureConfigured FastEthernet0/2 -
10 0040.0BC4.A853 SecureSticky FastEthernet0/2 -
int fa0/0
sw port-sec max 1 -> Por defecto es 1
PRS
#show errdisable
Port-sec
DAI
bpduguard
Ethcerchannel
dhcp
psecure-violation
wr
copy r s
============================
IP dhcp snooping
Dynamic ARP Inspection
IP Source Guard
MAC ACL
Port ACL
VACL
============================
2. HSRP AD para los host -> GW Virtual
int vlan 10
ip address 192.168.1.1 255.255.255.0
standby 10 ip 192.168.1.254
standby 10 preempt
standby 10 track fa0/0 decrement 50
standby 10 priority 110
standby 10 timers 1 3
Fallas
2.1 Dirección IP Virtual que no corresponda.
- Configurada en el PC
- Configurada en el grupo HSRP
int vlan 10
ip address 192.168.1.1 255.255.255.0
standby 20 ip 192.168.1.254
standby 10 preempt
standby 10 track fa0/0 decrement 50
standby 10 priority 110
standby 10 timers 1 3
int vlan 20
ip address 192.168.20.1 255.255.255.0
standby ip 192.168.1.254
R1
int vlan 10
ip address 192.168.1.1 255.255.255.0
R2
int vlan 10
ip address 192.168.1.2 255.255.255.0
Funcionamiento
=======================================
HSRP en modo balanceo de carga
HSRP en modo principal/Respaldo
- VRRP
- GLBP
=======================================================
3. Troubleshooting router-on-a-trunk
3. Troubleshooting router-on-a-stick
GW se configuran en un router
int gi0/0.10
encapsulation dot1q 10
ip add 192.168.10.1 255.255.255.0
!
SW
===
int fa0/24
desc LINK_RO1
sw trunk enc dot
sw mode tunk
sw none
sw trunk native vlan 99
sw trunk all vlan 10,20,30,40
int vlan 10
ip add 192.168.10.1 255.255.255.0
no shut
desc LAN_VLAN10
!
int fa0/1
no switchchport
ip add 10.232.0.1 255.255.255.0
src-mac
src-ip
dst-mac
dst-ip
src-dst mac
src-dst ip
DSW1(config)#port-channel load-balance ?
src-ac
dst-ip