Omada Pro S5500-24GP4F - Network switch TP-LINK - Free user manual and instructions

Find the device manual for free Omada Pro S5500-24GP4F TP-LINK in PDF.

TP-LINK Omada Pro S5500-24GP4F - Network switch
📄 999 pages English EN Download 💬 AI Question 10 questions ⚙️ Specs
Notice TP-LINK Omada Pro S5500-24GP4F - page 46
Pick your language and provide your email: we'll send you a specifically translated version.
Product Type 24-Port Gigabit Stackable L3 Managed PoE+ Switch
Ports 24 x Gigabit RJ45 (PoE+), 4 x 10G SFP+ Slots
PoE Budget 370W total, up to 30W per port (PoE+)
Stacking Up to 4 units in a stack
Switching Capacity 128 Gbps
Forwarding Rate 95.23 Mpps
Dimensions (W x D x H) 440 x 220 x 44 mm (19-inch rackmount)
Weight 4.5 kg
Power Supply Internal AC 100-240V, 50/60Hz
Layer 3 Features Static routing, RIP, OSPF, BGP, VRRP, multicast routing
VLAN Support 802.1Q VLAN, MAC VLAN, Protocol VLAN, Private VLAN, Voice VLAN
QoS 802.1p/DSCP priority, rate limiting, storm control, WRED
Security 802.1X, ACL, IP-MAC binding, ARP detection, DHCP snooping, DoS defend
Management Web GUI, CLI (Telnet/SSH/Console), SNMP v1/v2c/v3, RMON, NETCONF
Cooling 2 built-in fans with speed control
Operating Temperature 0°C to 50°C
Storage Temperature -40°C to 70°C
Operating Humidity 10% to 90% non-condensing
MTBF > 100,000 hours

Frequently Asked Questions - Omada Pro S5500-24GP4F TP-LINK

How do I access the switch for the first time?
By default, the switch has IP address 192.168.0.1. Connect your PC to a port and open a web browser to that IP. Use username admin and password admin. For CLI, use a console cable or Telnet/SSH.
Can this switch provide power to connected devices?
Yes, the S5500-24GP4F supports PoE+ (IEEE 802.3at/af) on all 24 Gigabit ports, with a total power budget of 370W and up to 30W per port.
How many switches can be stacked?
Up to 4 units can be stacked together using the SFP+ ports (requires stacking cables or modules). The stack appears as a single logical switch.
What layer 3 routing protocols are supported?
The switch supports static routing, RIP/RIPng, OSPF/OSPFv3, BGP, VRRP, and multicast routing (PIM-DM/SM).
How do I enable PoE on a port?
Go to SYSTEM > PoE in the web GUI. Select the port, enable PoE, and optionally set priority or power limit. Click Apply and save the configuration.
Can I manage the switch from the cloud?
Yes, the switch can be managed by the Omada SDN Controller (cloud or on-premise). Enable Controller Settings under System and configure the controller IP or use cloud discovery.
What security features are included?
The switch offers 802.1X port authentication, ACLs (MAC/IP/Combined), IP-MAC binding, ARP detection, DHCP snooping, DoS defend, and port security.
How do I update the firmware?
Download the latest firmware from TP-Link's website. In the GUI, go to SYSTEM > System Tools > Firmware Upgrade. Upload the file and follow the prompts. Do not power off during upgrade.
What is the difference between standalone and controller mode?
In standalone mode, the switch is configured individually via its own web/CLI interface. In controller mode, it is managed centrally by the Omada SDN Controller, suitable for large-scale networks with multiple devices.
Does the switch support jumbo frames?
Yes, it supports jumbo frames up to 9K bytes. Enable it globally under SYSTEM > System Info > System Summary and click Settings for Jumbo Frame.

User questions about Omada Pro S5500-24GP4F TP-LINK

0 question about this device. Answer the ones you know or ask your own.

Ask a new question about this device

Your email remains private: it is only used to notify you if someone answers your question.

No questions yet. Be the first to ask one.

Download the instructions for your Network switch in PDF format for free! Find your manual Omada Pro S5500-24GP4F - TP-LINK and take your electronic device back in hand. On this page are published all the documents necessary for the use of your device. Omada Pro S5500-24GP4F by TP-LINK.

USER MANUAL Omada Pro S5500-24GP4F TP-LINK

Accessing the Switch

Determine the Management Method 4

Web Interface Access....5

Login....5

Save the Configuration File....6

Disable the Web Server 7

Configure the Switch's IP Address and Default Gateway 8

Command Line Interface Access 10

Console Login (only for switch with console port)....10

SSH Login....12

Telnet Login....16

Disable SSH login 17

Disable Telnet login....18

Copy running-config startup-config....18

Change the Switch's IP Address and Default Gateway....19

Managing System

System 21

Overview....21

Supported Features....21

System Info Configurations 23

Using the GUI 23

Viewing the System Summary....23

Configuring the Device Description....27

Configuring the System Time 27

Configuring the Daylight Saving Time....28

Configuring LED (Only for Certain Devices)....29

Using the CLI 30

Viewing the System Summary....30

Configuring the Device Description....31

Configuring the System Time 32

Configuring the Daylight Saving Time....35

Configuring LED (Only for Certain Devices) 37

User Management Configurations.... 38

Using the GUI 38

Creating Accounts 38

Configuring Enable Password....39

Using the CLI 40

Creating Accounts 40

Configuring Enable Password....41

System Tools Configurations 44

Using the GUI 44

Configuring the Boot File....44

Restoring the Configuration of the Switch 46

Backing up the Configuration File....47

Upgrading the Firmware....47

Loading Patch....48

Activating Patch....48

Running Patch....49

Deactivating Patch....49

Uninstalling Running Patch....49

Deleting Patch 49

Viewing Patch Info....50

Configuring DHCP Auto Install (Only for Certain Devices) 50

Rebooting the switch....52

Resetting the Switch....53

Using the CLI....54

Configuring the Boot File....54

Restoring the Configuration of the Switch 55

Backing up the Configuration File....55

Upgrading the Firmware....56

Loading Patch....56

Activating Patch....57

Running Patch....57

Deactivating Patch....58

Uninstalling Running Patch....58

Deleting Patch 58

Viewing Patch Info....58

Upgrading the MCU-Firmware....59

Configuring DHCP Auto Install (Only for Certain Devices) 59

Creating Checkpoint File 60

Viewing Checkpoint File....61

Rolling Back Configuration....61

Rebooting the Switch 62

Reseting the Switch....63

EEE Configuration....64

Using the CLI....64

PoE Configurations (Only for Certain Devices) 66

Using the GUI 67

Configuring the PoE Parameters Manually....67

Configuring the PoE Parameters Using the Profile....70

Configuring the PoE Auto Recovery Parameters Manually....73

Using the CLI....75

Configuring the PoE Parameters Manually....75

Configuring the PoE Parameters Using the Profile....77

Management Port Configurations (Only for Certain Devices) 80

Using the CLI....80

Power Supply Configurations (Only for Certain Devices)....82

Using the CLI 82

Configuring the Power Backup Mode....82

SDM Template Configuration....83

Using the GUI 83

Using the CLI....84

Time Range Configuration....86

Using the GUI 86

Adding Time Range Entries....86

Configuring Holiday 88

Using the CLI....89

Adding Time Range Entries 89

Configuring Holiday 90

Controller Settings (Only for Certain Devices) 92

Using the GUI 92

Enabling Cloud-Based Controller Management....92

Configuring Controller Inform URL....93

Using the CLI....93

Enabling Cloud-Based Controller Management....93

Configuring Controller Inform URL....93

File System Configurations....95

Using the CLI....95

Configuring the File System....95

FTP, SFTP and SCP Configurations....97

Overview....97

Using the CLI....97

Using the FTP....97

Using the SFTP/SFTPv6....98

Using the SCP....98

Example for PoE Configurations....100

Network Requirements....100

Configuring Scheme....100

Using the GUI....100

Using the CLI....103

Appendix: Default Parameters....105

Managing Physical Interfaces

Physical Interface 109

Overview....109

Supported Features....109

Basic Parameters Configurations....110

Using the GUI 110

Using the CLI 111

Port Isolation Configurations....114

Using the GUI 114

Using the CLI....115

Loopback Detection Configuration....117

Using the GUI 117

Using the CLI....119

Configuration Examples....121

Example for Port Isolation....121

Network Requirements....121

Configuration Scheme....121

Using the GUI....121

Using the CLI 123

Example for Loopback Detection....124

Network Requirements......124

Configuration Scheme....124

Using the GUI....125

Using the CLI 126

Appendix: Default Parameters....127

Configuring Stack (Only for Certain Devices)

Overview 129

Stack Concepts....130

Stack Operation Procedure 132

Stack Topology....134

Stack Operation Procedure....136

Using the GUI 136

Viewing the Stack Information....136

Configuring the Provision Info 137

Configuring the Provisioned Member 138

Configuring the Stack Member 139

Configuring the Stack Port Group....140

Using the CLI 142

Configuring Stack System Name....142

Entering Stack Port Group View....143

Configuring Stack Port....143

Viewing Current Stack Port Group Info....144

Configuring Stack Device Priority....144

Modifying Stack Unit ID....145

Configuring Provision Entries....145

Configuring Stack Virtual MAC....146

Viewing MAC-delay Switching Time 146

Viewing Stack Port Info....147

Viewing Device Info....147

Viewing Stack Neighbor....147

Appendix: Default Parameters....148

Configuring DDM (Only for Certain Devices)

Overview 150

DDM Configuration....151

Using the GUI 151

Configuring DDM Globally....151

Configuring the Threshold....152

Viewing DDM Status....156

Using the CLI 156

Configuring DDM Globally....156

Configuring DDM Shutdown....157

Configuring the Threshold....158

Viewing DDM Configuration....164

Viewing DDM Status....165

Appendix: Default Parameters....166

Configuring LAG

LAG....169

Overview....169

Supported Features....169

LAG Configuration....170

Using the GUI 171

Configuring Load-balancing Algorithm....171

Configuring Static LAG or LACP....172

Using the CLI 174

Configuring Load-balancing Algorithm....174

Configuring Static LAG or LACP....176

Configuration Examples....180

Example for Static LAG 180

Network Requirements....180

Configuration Scheme....180

Using the GUI....180

Using the CLI 181

Example for LACP 182

Network Requirements....182

Configuration Scheme....182

Using the GUI....183

Using the CLI 184

Appendix: Default Parameters....187

Managing MAC Address Table

MAC Address Table 189

Overview....189

Supported Features....189

MAC Address Configurations....191

Using the GUI 191

Adding Static MAC Address Entries 191

Modifying the Aging Time of Dynamic Address Entries....193

Adding MAC Filtering Address Entries....193

Viewing Address Table Entries....194

Using the CLI 194

Adding Static MAC Address Entries 194

Modifying the Aging Time of Dynamic Address Entries....196

Adding MAC Filtering Address Entries....196

Security Configurations 198

Using the GUI 199

Configuring MAC Notification Traps 199

Limiting the Number of MAC Addresses Learned in VLANs....200

Using the CLI 202

Configuring MAC Notification Traps 202

Limiting the Number of MAC Addresses in VLANs 204

Example for Security Configurations....206

Network Requirements....206

Configuration Scheme 206

Using the GUI 207

Using the CLI 208

Appendix: Default Parameters....209

Configuring 802.1Q VLAN

Overview 211

802.1Q VLAN Configuration 212

Using the GUI 212

Configuring the VLAN....212

Configing Port Parameters for 802.1Q VLAN 213

Using the CLI 214

Creating a VLAN 214

Adding the Port to the Specified VLAN 215

Configuring the Port 216

Configuration Example 218

Network Requirements....218

Configuration Scheme 218

Network Topology....219

Using the GUI 219

Using the CLI 222

Appendix: Default Parameters ......224

Configuring MAC VLAN

Overview 226

MAC VLAN Configuration....227

Using the GUI 227

Configuring 802.1Q VLAN 227

Binding the MAC Address to the VLAN....227

Enabling MAC VLAN for the Port....228

Using the CLI 229

Configuring 802.1Q VLAN 229

Binding the MAC Address to the VLAN....229

Enabling MAC VLAN for the Port....230

Configuration Example 231

Network Requirements....231

Configuration Scheme 231

Using the GUI 232

Using the CLI 235

Appendix: Default Parameters....238

Configuring Protocol VLAN

Overview 240

Protocol VLAN Configuration....241

Using the GUI 241

Configuring 802.1Q VLAN 241

Creating Protocol Template 242

Configuring Protocol VLAN....243

Using the CLI 244

Configuring 802.1Q VLAN 244

Creating a Protocol Template....244

Configuring Protocol VLAN....245

Configuration Example 248

Network Requirements....248

Configuration Scheme 248

Using the GUI 249

Using the CLI 254

Appendix: Default Parameters....258

Configuring VLAN-VPN (Only for Certain Devices)

VLAN-VPN 260

Overview....260

Supported Features....261

Basic VLAN-VPN Configuration 262

Using the GUI 262

Configuring 802.1Q VLAN 262

Configuring Basic VLAN-VPN 263

Using the CLI 264

Configuring 802.1Q VLAN 264

Configuring Basic VLAN-VPN 264

Flexible VLAN-VPN Configuration....267

Using the GUI 267

Using the CLI....268

Configuration Examples....270

Example for Basic VLAN VPN 270

Network Requirements....270

Configuration Scheme....270

Using the GUI....271

Using the CLI 276

Example for Flexible VLAN VPN 280

Network Requirements....280

Configuration Scheme....280

Using the GUI....281

Using the CLI 288

Appendix: Default Parameters....291

Configuring GVRP

Overview 293

GVRP Configuration....294

Using the GUI 295

Using the CLI 296

Configuration Example 299

Network Requirements....299

Configuration Scheme 299

Using the GUI 300

Using the CLI....304

Appendix: Default Parameters....308

Configuring Private VLAN (Only for Certain Devices)

Overview 310

Private VLAN Configurations 312

Using the GUI 312

Using the CLI 313

Creating Private VLAN....313

Configuring the Up-link Port 315

Configuring the Down-link Port 317

Configuration Example 319

Network Requirements 319

Configuration Scheme 319

Network Topology 319

Using the GUI 320

Using the CLI 324

Appendix: Default Parameters 328

Configuring Multicast

Layer 2 Multicast 330

Overview 330

Supported Features 332

IGMP Snooping Configuration 334

Using the GUI 334

Configuring IGMP Snooping Globally 334

Configuring IGMP Snooping for VLANs 335

Configuring IGMP Snooping for Ports....338

Configuring Hosts to Statically Join a Group....339

Configuring IGMP Accounting and Authentication Features....340

Using the CLI 341

Configuring IGMP Snooping Globally 341

Configuring IGMP Snooping for VLANs....342

Configuring IGMP Snooping for Ports....347

Configuring Hosts to Statically Join a Group 348

Configuring IGMP Accounting and Authentication Features....349

MLD Snooping Configuration....353

Using the GUI 353

Configuring MLD Snooping Globally 353

Configuring MLD Snooping for VLANs....354

Configuring MLD Snooping for Ports 357

Configuring Hosts to Statically Join a Group....357

Using the CLI 358

Configuring MLD Snooping Globally 358

Configuring MLD Snooping for VLANs....359

Configuring MLD Snooping for Ports 364

Configuring Hosts to Statically Join a Group....365

MVR Configuration 367

Using the GUI 367

Configuring 802.1Q VLANs....367

Configuring MVR Globally 368

Adding Multicast Groups to MVR....369

Configuring MVR for the Port....370

(Optional) Adding Ports to MVR Groups Statically 371

Using the CLI 372

Configuring 802.1Q VLANs....372

Configuring MVR Globally....372

Configuring MVR for the Ports 374

Multicast Filtering Configuration....377

Using the GUI 377

Creating the Multicast Profile....377

Configure Multicast Filtering for Ports 379

Using the CLI 380

Creating the Multicast Profile....380

Binding the Profile to Ports....383

Viewing Multicast Snooping Information....387

Using the GUI 387

Viewing IPv4 Multicast Table....387

Viewing IPv4 Multicast Statistics on Each Port 388 Viewing IPv6 Multicast Table....389 Viewing IPv6 Multicast Statistics on Each Port 390

Using the CLI 391

Viewing IPv4 Multicast Snooping Information....391 Viewing IPv6 Multicast Snooping Configurations....392

PIM Configuration....393

Using the GUI 393

Configuring Multicast Routing Globally 393 Viewing Mroute Information....394 Configuring PIM DM Interface 395 Viewing PIM DM Neighbor 396 Configuring PIM SM Interface 396 Viewing PIM SM Neighbor 397 Configuring BSR 398 Configuring RP 400 Viewing Group to RP Mapping Information 401 Viewing RP Information 402 Configuring PIM SSM 402 Viewing PIM SM Packet Statistics 403 Configuring Static Mroute 404

Using the CLI 405

Configuring IP Multicast-routing Globally....405 Configuring IP PIM Globally 405 Configuring IP PIM On Specified Interface 406 Configuring Candidate BSR on Specified Interface 407 Configuring Candidate RP on Specified Interface....407 Configuring Static RP 408 Configuring BSR Domain Border....409 Configuring PIM-SSM 410 Configuring DR Priority....410 Configuring IP PIM Hello-Interval....411 Configuring IP PIM Join-prune-interval 412 Viewing IP Multicast Info 413 Viewing IP Mroute 413 Viewing IP PIM Interface Info 414 Viewing IP PIM Neighbor Info 414 Viewing IP PIM Statistic 415

Viewing Candidate BSR and Candidate RP 415

Viewing RP 416

Viewing Hash Result of Specified Multicast Group 416

Configuring Static Multicast-routing Entries....417

Viewing IP Mroute Static Info 418

Layer 3 IGMP Configuration....419

Using the GUI 419

Configuring IGMP Globally....419

Configuring IGMP on the Interface....419

Viewing Interface State....420

Viewing Multicast Group Information....422

Using the CLI 423

Configuring IP IGMP Globally....423

Configuring IP IGMP On Ports....424

Configuration Examples....429

Example for Configuring Basic IGMP Snooping....429

Network Requirements....429

Configuration Scheme....429

Using the GUI....430

Using the CLI 432

Example for Configuring MVR 434

Network Requirements....434

Network Topology....434

Configuration Scheme....435

Using the GUI....435

Using the CLI 438

Example for Configuring Unknown Multicast and Fast Leave....441

Network Requirement....441

Configuration Scheme....442

Using the GUI....442

Using the CLI 444

Example for Configuring Multicast Filtering....445

Network Requirements....445

Configuration Scheme....445

Network Topology....445

Using the GUI....446

Using the CLI 450

Appendix: Default Parameters ....453

Default Parameters for IGMP Snooping 453

Default Parameters for MLD Snooping....454

Default Parameters for MVR....455

Default Parameters for Multicast Filtering....455

Default Parameters for PIM....455

Default Parameters for Static Multicast-Routing....456

Default Parameters for Layer 3 IGMP....456

Configuring Spanning Tree

Spanning Tree 458

Overview 458

Basic Concepts 458

STP/RSTP Concepts 458

MSTP Concepts 462

STP Security 463

STP/RSTP Configurations 466

Using the GUI 466

Configuring STP/RSTP Parameters on Ports....466

Configuring STP/RSTP Globally....468

Verifying the STP/RSTP Configurations....470

Using the CLI 472

Configuring STP/RSTP Parameters on Ports....472

Configuring Global STP/RSTP Parameters 474

Enabling STP/RSTP Globally....475

MSTP Configurations 478

Using the GUI 478

Configuring Parameters on Ports in CIST 478

Configuring the MSTP Region 481

Configuring MSTP Globally....485

Verifying the MSTP Configurations ....487

Using the CLI 488

Configuring Parameters on Ports in CIST 488

Configuring the MSTP Region

Configuring Global MSTP Parameters

Enabling Spanning Tree Globally

STP Security Configurations

Using the GUI

Using the CLI

Configuring the STP Security

Configuration Example for MSTP

Network Requirements

Configuration Scheme

Using the GUI

Using the CLI

Appendix: Default Parameters

Configuring LLDP

LLDP

Overview

Supported Features

LLDP Configurations

Using the GUI

Configuring LLDP Globally

Configuring LLDP For the Port

Using the CLI

Global Config

Port Config

LLDP-MED Configurations

Using the GUI

Configuring LLDP Globally

Configuring LLDP-MED Globally

Configuring LLDP-MED for Ports

Using the CLI

Global Config....531

Port Config....532

Viewing LLDP Settings....535

Using GUI....535

Viewing LLDP Device Info 535

Viewing LLDP Statistics 539

Using CLI 540

Viewing LLDP-MED Settings....541

Using GUI....541

Using CLI 544

Configuration Example 545

Configuration Example for LLDP....545

Network Requirements....545

Network Topology....545

Configuration Scheme....545

Using the GUI....545

Using CLI....546

Example for LLDP-MED 552

Network Requirements....552

Configuration Scheme....552

Using the GUI....552

Using CLI....555

Appendix: Default Parameters....558

Configuring L2PT (Only for Certain Devices)

Overview 560

L2PT Configuration....562

Using the GUI 562

Using the CLI 563

Configuration Example 567

Network Requirements....567

Configuration Scheme 567

Using the GUI 567

Using the CLI 568

Appendix: Default Parameters....570

Configuring PPPoE ID Insertion (Only for Certain Devices)

Overview 572

PPPoE ID Insertion Configuration....573

Using the GUI 573

Using the CLI....574

Appendix: Default Parameters....577

Configuring Layer 3 Interfaces

Overview 579

Layer 3 Interface Configurations....580

Using the GUI 580

Creating an Layer 3 Interface....580

Configuring IPv4 Parameters of the Interface 582

Configuring IPv6 Parameters of the Interface 583

Viewing Detail Information of the Interface 586

Using the CLI 587

Creating a Layer 3 Interface....587

Configuring IPv4 Parameters of the Interface 589

Configuring IPv6 Parameters of the Interface 590

Configuration Example 593

Network Requirement....593

Configuration Scheme 593

Using the GUI 593

Using the CLI....594

Appendix: Default Parameters....596

Configuring Routing

Overview 598

IPv4 Static Routing Configuration....599

Using the GUI 599

Using the CLI....600

IPv6 Static Routing Configuration....601

Using the GUI....601

Using the CLI....601

Viewing Routing Table 603

Using the GUI 603

Viewing IPv4 Routing Table....603

Viewing IPv6 Routing Table....604

Using the CLI....604

Viewing IPv4 Routing Table....604

Viewing IPv6 Routing Table....605

RIP Configurations....606

Using the GUI 606

Configuring RIP Globally....606

Configuring Network....607

Configuring Interface 608

Configuring Route Redistribution....609

Using the CLI....610

Enabling RIP Function....610

Enabling RIP Function for Specific Network Segment....610

Configuring RIP Message Version....611

Configuring RIP Timer....612

Configuring Management Distance 613

Enabling Auto-summary Function....613

Setting Default Metric....614

Configuring RIP Redirection....615

Enabling ECMP Function....616

Introducing Default Route 616

Configuring RIP Neighbor....617

Configuring Passive-Interface....618

Configuring Authentication Mode....619

Configuring Authentication String....619

Configuring Authentication Key-chain....620

Configuring Receive Version....621

Configuring Send Version....622

Configuring Split Horizon....623

Enabling RIPv2 Packet Broadcast....624

Viewing RIP Routing Table 624

Viewing RIP Status....625

Clearing IP RIP 626

RIPng Configurations 627

Using the CLI 627

Enabling RIPng Function....627

Enabling RIP Function on Specific Port....627

Configuring RIPng Timer 628

Setting Default Metric....629

Configuring RIPng Redirection....630

Enabling ECMP Function....631

Introducing Default Route 631

Configuring Passive-Interface....632

Configuring Split Horizon....633

Viewing RIPng Routing Table....634

Viewing RIPng Status....634

Clearing IPv6 RIP 635

OSPF Configurations....636

Using the GUI 636

Configuring OSPF Process 636

Configuring OSPF 637

Configuring Network 639

Configuring Interface 640

Configuring Area....642

Configuring Area Aggregation....643

Configuring Virtual Link....644

Configuring Route Redistribution....646

Viewing Neighbor Table 647

Using the CLI 649

Configuring Router OSPF 649

Configuring Router ID 649

Configuring Network 650

Configuring Max-Paths....651

Configuring ASBR 652

Configuring Default-Metric....653

Configuring Default-Information Originate....654

Configuring Auto-Cost....655

Configuring OSPF Administrative Distance....656

Configuring Computing Delay and Interval 657

Configuring RFC 1583 658

Defining Stub Area 659

Defining NSSA Area 660

Configuring Area Default-Cost 661

Configuring Summary Route 662

Configuring Area Authentication ....664

Configuring Virtual-Link 664

Configuring Virtual-Link Authentication 665

Configuring Area Virtual-Link Simple Authentication Key 666

Configuring Area Virtual-Link Message-Digest-Key 667

Configuring Opaque LSA Support 668

Configuring OSPF GR 669

Configuring Graceful Restart Period 670

Configuring GR Helper 670

Configuring Planned-only Restart 671

Configuring Strict LSA Checking 672

Configuring Interface Cost 673

Configuring IP OSPF Retransmit-Interval....673

Configuring IP OSPF Transmit-Delay 674

Configuring IP OSPF Priority....675

Configuring IP OSPF Hello-Interval....676

Configuring IP OSPF Dead-Interval 677

Configuring IP OSPF Authentication....677

Configuring IP OSPF Authentication-Key 678

Configuring IP OSPF Message-Digest-Key....679

Configuring IP OSPF Network Type....680

Ignoring MTU Check....681

Preventing OSPF Packets....682

Resetting OSPF Process....683

Viewing OSPF Global Information....683

Viewing OSPF LSDB....683

Viewing OSPF Interface....684

Viewing OSPF Neighbor....684

Viewing OSPF ABR/ASBR Routing Table....684

Viewing OSPF Routing Table....685

Viewing OSPF GR Helper Status 685

OSPFv3 Configurations....686

Using the CLI....686

Enabling OSPFv3 Routing 686

Configuring Router ID 686

Configuring Max-Paths....687

Configuring ASBR 688

Configuring Default-Information Originate....689

Configuring Auto-Cost....690

Configuring OSPFv3 Administrative Distance....690

Configuring OSPFv3 Distance....691

Configuring Computing Delay and Interval 692

Configuring OSPFv3 LSA Reception Interval....693

Defining Stub Area 693

Defining NSSA Area 694

Configuring Summary Route 695

Assigning Interfaces 696

Configuring Interface Cost 697

Configuring IPv6 OSPF Retransmit-Interval....698

Configuring IPv6 OSPF Transmit-Delay....699

Configuring IPv6 OSPF Priority 700

Configuring IPv6 OSPF Hello-Interval....701

Configuring IPv6 OSPF Dead-Interval....701

Configuring IPv6 OSPF Network Type 702

Ignoring MTU Check....703

Preventing OSPFv3 Packets....704

Reseting OSPFv3 Process 705

Viewing OSPFv3 Global Information 705

Viewing OSPFv3 LSDB 705

Viewing OSPFv3 Interface 705

Viewing OSPFv3 Neighbor 706

Viewing OSPFv3 ABR/ASBR Routing Table 706

Viewing OSPFv3 Routing Table 706

BFD Configurations....707

Using the CLI....707

Creating BFD-template....707

Configuring Detect-multiplier....708

Configuring Receive Interval 709

Configuring Transmit Interval 709

Disabling BFD Session Detection....710

Enabling Passive Mode....711

Enabling OSPF BFD 711

Binding BFD Template to OSPF-enabled Interface 712

Enabling OSPFv3 BFD 713

Binding BFD Template to OSPFv3-enabled Interface 714

Configuring BFD on IS-IS-enabled Port 715

Viewing BFD Counters 716

Viewing BFD Info 717

BGP Configurations....718

Using the CLI 718

Enabling BGP Globally 718

Creating Aggregate Route....719

Configuring BGP Management Distance....720

Configuring Load-balancing Path....720

Configuring BGP Network 721

Enabling Route Redistribution 722

Configuring Timers....722

Allowing MED Comparison....723

Configuring Route from Confederation Neighbors in Best Path Selection 724

Ignoring AS Path Information in Best Path Selection 725

Configuring Multipath in Best Path Selection 725

Enabling Router ID Comparison in Best Path Selection....726

Allowing MED Comparison between BGP Confederations in Best Path Selection....727

Configuring MED Missing-as-worst 728

Configuring Client-to-client Reflection 728

Configuring Cluster ID 729

Configuring Confederation ID 730

Configuring Confederation Peers 730

Configuring Route Dampening 731

Activating IPv4 Unicast 732

Configuring Local Preference 733

Configuring Deterministic-med 734

Configuring Enforce-first-as 734

Configuring Fast-external-failover 735

Configuring Network import-check 736

Setting Router ID 736

Activating Address Family 737

Configuring Advertisement-interval 738

Configuring Neighbor Allowas-in 739

Configuring Attribute-unchanged 740

Announcing Dynamic Capability 740

Sending Default Route 741

Configuring Neighbor Description

Disabling Connect Check

Configuring Distribute List

Disabling Capability Negotiation

Configuring EBGP Multihop

Configuring Local-AS

Configuring Maximum-prefix

Configuring Next-hop-self

Configuring Override-capability

Disabling OPEN Message Sending

Configuring Neighbor Password

Configuring Peer-group

Configuring BGP Port

Configuring Remote AS

Removing Private AS

Configuring Route-reflector-client 753

Disabling Neighbor Manually 754

Configuring Soft-reconfiguration Inbound 755

Configuring Strict-capability-match 756

Configuring Neighbor Timers 756

Configuring Neighbor Timers Connect 757

Configuring Neighbor Max Hops 758

Configuring Update-source 759

Configuring Default Weight 759

Viewing BGP Routing Table....760

Viewing BGP Attribute....760

Viewing IP BGP CIDR only....761

Viewing IP BGP Dampening Flap-statistics....761

Viewing IP BGP Dampening Dampened-paths 761

Viewing IP BGP Dampening Parameters 761

Viewing BGP Neighbor Information 762

Viewing Advertised-routes....762

Viewing Dampened Routes from Neighbors....762

Viewing Neighbor Flapping Route 762

Viewing Neighbor Prefix-counts....763

Viewing Routes from Neighbors....763

Viewing Routes Learned from Neighbors 763

Viewing Next Hop....763

Viewing BGP Path 763

Viewing Specific Network Information....764

Viewing BGP Neighbor Summary....764

Resetting Specific BGP Neighbor....764

Resetting All BGP Neighbors....765

Resetting BGP Route Dampening 765

IS-IS Configurations....766

Using the CLI....766

Enabling IS-IS Globally 766

Enabling Level-1 Authentication....767

Enabling Level-2 Authentication....767

Enabling Host Name....768

Configuring Area Type 769

Configuring Log Adjacency Change....770

Configuring LSP Generate Interval....771

Configuring LSP Max Length....771

Configuring LSP Refresh Interval....772

Configuring LSP Lifetime....773

Configuring Metric Style 773

Configuring Network Entity Title....774

Enabling Purge Originator 775

Configuring ATT....776

Configuring Overload Bit....776

Configuring Prefix Priority....777

Clearing IS-IS Neighbor....778

Redistributing Route....779

Setting Route Distance....780

Enabling IS-IS on the Interface....781

Enabling BFD 781

Configuring IS-IS Type....782

Configuring CSNP Interval 783

Configuring Hello Interval 784

Configuring Hello Multiplier....785

Configuring Metric....786

Configuring Network Type 787

Making IS-IS Silent 787

Enabling IS-IS Authentication 788

Configuring Priority

Configuring Three-way Handshake

Viewing IS-IS Database

Viewing IS-IS Host Name

Viewing IS-IS Neighbor

Viewing IS-IS Routing Info

Viewing IS-IS Summary

Viewing IS-IS Interface

URPF Configurations

Using the CLI

Enabling URPF

Configuring URPF Filter Mode

Tunnel Configurations

Using the CLI

Creating Tunnel Interface

Specifying Tunnel Mode 798

Specifying Tunnel Source....798

Specifying Tunnel Destination....799

Configuring TTL 800

Specify Interface IP Address....801

Disabling Tunnel Encapsulation....801

Configuring IPv4 Tunnel Route....802

Configuring IPv6 Tunnel Route....803

Viewing Tunnel Interface 803

Example for Static Routing....805

Network Requirements....805

Configuration Scheme 805

Using the GUI 805

Using the CLI 807

Configuring DHCP Service

DHCP 811

Overview....811

Supported Features....811

DHCP Server Configuration....816

Using the GUI 816

Enabling DHCP Server 816

Configuring DHCP Server Pool 818

Configuring Manual Binding....819

Using the CLI 820

Enabling DHCP Server 820

Configuring DHCP Server Pool 823

Configuring Manual Binding....826

DHCP Relay Configuration 829

Using the GUI 829

Enabling DHCP Relay and Configuring Option 82....829

Configuring DHCP Interface Relay....831

Configuring DHCP VLAN Relay 831

Using the CLI 833

Enabling DHCP Relay 833

(Optional) Configuring Option 82....834

Configuring DHCP Interface Relay 836

Configuring DHCP VLAN Relay 837

DHCPV6 Relay Configuration....840

Using the CLI 840

Enabling DHCPV6 Relay....840

Adding DHCPV6 Server Address 841

Enabling Option 18\37 Support....841

Specifying Custom Remote ID 842

Viewing DHCPV6 Relay Info....843

Viewing DHCPV6 Relay Counters....843

DHCP L2 Relay Configuration 844

Using the GUI 844

Enabling DHCP L2 Relay 844

Configuring Option 82 for Ports 845

Using the CLI 846

Enabling DHCP L2 Relay 846

Configuring Option 82 for Ports 847

DHCPV6 L2 Relay Configuration....850

Using the CLI 850

Enabling DHCPV6 L2 Relay Globally 850

Enabling DHCPV6 L2 Relay of VLAN 850

Enabling Option 18\37 Support....851

Specifying Custom Remote ID 852

Viewing DHCPV6 L2 Relay Info 853

Configuration Examples....854

Example for DHCP Server 854

Network Requirements 854

Configuration Scheme....854

Using the GUI....854

Using the CLI 856

Example for DHCP Interface Relay 856

Network Requirements 856

Configuration Scheme....857

Using the GUI....858

Using the CLI 863

Example for DHCP VLAN Relay 866

Network Requirements 866

Configuration Scheme....866

Using the GUI....867

Using the CLI 870

Example for Option 82 in DHCP Relay....872

Network Requirements....872

Configuration Scheme....873

Configuring the DHCP Relay Switch....874

Configuring the DHCP Server 876

Example for DHCP L2 Relay 878

Network Requirements......878

Configuration Scheme....878

Configuring the DHCP Relay Switch....879

Configuring the DHCP Server 882

Appendix: Default Parameters....884

Configuring ARP

Overview 888

Supported Features......888

ARP Configurations....890

Using the GUI 890

Viewing the ARP Entries 890

Adding Static ARP Entries Manually....891

Configuring Gratuitous ARP 891

Configuring Proxy ARP....892

Configuring Local Proxy ARP 893

Using the CLI 894

Configuring the ARP Entry 894

Configuring the Gratuitous ARP 896

Configuring Proxy ARP 899

Appendix: Default Parameters....901

Configuring VRRP (Only for Certain Devices)

Overview 903

VRRP Configuration 904

Using the GUI 904

Using the CLI....912

Configuring VRRP on Specified Ports....912

Appendix: Default Parameters....917

Configuring QoS

QoS....919

Overview....919

Supported Features....919

Class of Service Configuration....921

Using the GUI 922

Configuring Port Priority....922

Configuring 802.1p Priority....924

Configuring DSCP Priority....927

Specifying the Scheduler Settings 930

Using CLI 933

Configuring Port Priority....933

Configuring 802.1p Priority....935

Configuring DSCP Priority....938

Specifying the Scheduler Settings....944

QoS for VLAN Configuration 948

Using the CLI 948

Configuring Local Priority 948

Configuring 802.1P Priority....949

Configuring DSCP Priority....949

WRED Configuration....951

Using the CLI 951

Configuring Drop Template....951

Binding Drop Template....952

Viewing WRED Template Info....952

Viewing WRED Template Binding Info....953

Bandwidth Control Configuration....954

Using the GUI 954

Configuring Rate Limit....954

Configuring Storm Control 955

Using the CLI 956

Configuring Rate Limit....956

Configuring Storm Control 958

OUI-Based VLAN Configuration....961

Using the CLI 961

Configuring OUI-Based VLAN Entries....961

Enabling OUI-Based VLAN on Interface....962

Viewing OUI-Based VLAN Configuration....962

Voice VLAN Configuration 964

Using the GUI 964

Configuring OUI Addresses 964

Configuring Voice VLAN Globally 966

Adding Ports to Voice VLAN 966

Using the CLI 967

Auto VoIP Configuration 970

Using the GUI 970

Using the CLI 971

Configuration Examples....975

Example for Class of Service 975

Network Requirements......975

Configuration Scheme....975

Using the GUI....976

Using the CLI 978

Example for Voice VLAN 980

Network Requirements....980

Configuration Scheme....981

Using the GUI....981

Using the CLI 985

Example for Auto VoIP 988

Network Requirements....988

Configuration Scheme....989

Using the GUI....989

Using the CLI 993

Appendix: Default Parameters....999

Configuring Access Security

Access Security 1004

Overview....1004

Supported Features....1004

Access Security Configurations....1005

Using the GUI 1005

Configuring the Access Control Feature....1005

Configuring the HTTP Function 1008

Configuring the HTTPS Function....1009

Configing the SSH Feature 1012

Configuring the Telnet Function....1013

Configuring the Serial Port Parameters....1014

Using the CLI 1014

Configuring the Access Control Feature....1014

Configuring the HTTP Function 1016

Configuring the HTTPS Function....1018

Configuring the SSH Feature 1021

Configuring the Telnet Function....1023

Configuring the Serial Port Parameters....1023

Appendix: Default Parameters....1025

Configuring AAA

Overview 1029

AAA Configuration....1030

Using the GUI 1031

Adding Servers....1031

Configuring Server Groups....1033

Configuring the Method List....1034

Configuring the AAA Application List....1036

Configuring Login Account and Enable Password 1036

Using the CLI....1037

Adding Servers....1037

Creating RADSEC Template....1040

Downloading CA Certificate....1040

Downloading Client Certificate....1041

Downloading Client-key....1042

Creating RADIUS Server 1042

Viewing RADIUS Server Info 1043

Creating Load-balancing Algorithm....1044

Configuring Load-balancing Batch....1044

Configuring Dead Count 1045

Configuring Dead Cycle....1046

Configuring Dead Interval....1046

Configuring Dead Time....1047

Configuring Maximum Unresponsive Interval....1047

Configuring Testuser 1048

Configuring Detect-server....1049

Configuring Server Groups....1049

Configuring the Method List....1051

Configuring the AAA Application List....1052

Configuring Login Account and Enable Password 1056

Configuration Example 1059

Network Requirements....1059

Configuration Scheme 1059

Using the GUI 1060

Using the CLI....1062

Appendix: Default Parameters....1065

Configuring 802.1x

Overview 1068

802.1x Configuration....1069

Using the GUI 1069

Configuring the RADIUS Server....1069

Configuring 802.1x Globally....1072

Configuring 802.1x on Ports....1073

View the Authenticator State 1075

Using the CLI....1076

Configuring the RADIUS Server....1076

Configuring 802.1x Globally....1078

Configuring 802.1x on Ports....1080

Viewing Authenticator State....1082

Configuration Example 1084

Network Requirements....1084

Configuration Scheme 1084

Network Topology....1084

Using the GUI 1085

Using the CLI....1087

Appendix: Default Parameters....1090

Configuring Port Security

Overview 1092

Port Security Configuration 1093

Using the GUI 1093

Using the CLI....1094

Configuring Port Security....1094

Configuring Sticky MAC Manually....1096

Configuring Sticky MAC Save-time....1096

Appendix: Default Parameters....1098

Configuring MACsec

(Only for Certain Devices)

Overview 1100

MACsec Configurations....1101

Using the CLI....1101

Configuring MACsec Policy Template....1101

Applying MACsec Policy....1102

Configuring MACsec Cipher_suite 1102

Configuring Confidentiality-offset....1103

Configuring Packet Encryption....1104

Configuring MKA Negotiation....1105

Configuring MKA Priority 1106

Configuring MKA PSK....1106

Configuring MKA Timer 1107

Enabling Replay-protection....1108

Configuring Validation-mode 1109

Appendix: Default Parameters....1111

Configuring ACL

Overview 1113

ACL Configuration....1114

Using the GUI 1114

Configuring Time Range 1114

Creating an ACL....1114

Configuring ACL Rules....1115

Configuring MAC ACL Rule....1115

Configuring IP ACL Rule....1120

Configuring Combined ACL Rule....1124

Configuring the IPv6 ACL Rule....1129

Configuring the Packet Content ACL Rule....1133

Configuring ACL Binding....1138

Using the CLI 1139

Configuring Time Range 1139

Configuring ACL 1139

Configuring Policy....1149

Redirecting Route 1151

Configuring ACL Binding....1152

Viewing ACL Counting 1153

Configuration Example for ACL....1154

Configuration Example for MAC ACL....1154

Network Requirements....1154

Configuration Scheme....1154

Using the GUI....1155

Using the CLI 1161

Configuration Example for IP ACL....1162

Network Requirements....1162

Configuration Scheme....1163

Using the GUI....1163

Using the CLI 1169

Configuration Example for Combined ACL....1171

Network Requirements....1171

Configuration Scheme....1171

Using the GUI....1172

Using the CLI 1177

Appendix: Default Parameters....1179

Configuring IPv4 IMPB

IPv4 IMPB 1182

Overview....1182

Supported Features....1182

IP-MAC Binding Configuration....1183

Using the GUI 1183

Binding Entries Manually....1183

Binding Entries via ARP Scanning....1184

Binding Entries via DHCP Snooping....1186

Viewing the Binding Entries....1188

Using the CLI....1189

Binding Entries Manually....1189

Binding Entries via DHCP Snooping....1191

Viewing Binding Entries 1192

ARP Detection Configuration....1193

Using the GUI 1193

Adding IP-MAC Binding Entries 1193

Enabling ARP Detection....1193

Configuring ARP Detection on Ports 1194

Viewing ARP Statistics....1195

Using the CLI....1196

Adding IP-MAC Binding Entries 1196

Enabling ARP Detection....1196

Configuring ARP Detection on Ports 1197

Viewing ARP Statistics....1199

IPv4 Source Guard Configuration....1200

Using the GUI 1200

Adding IP-MAC Binding Entries 1200

Configuring IPv4 Source Guard....1200

Using the CLI 1201

Adding IP-MAC Binding Entries 1201

Configuring IPv4 Source Guard 1201

Configuration Examples....1203

Example for ARP Detection 1203

Network Requirements....1203

Configuration Scheme....1203

Using the GUI....1204

Using the CLI 1206

Example for IP Source Guard....1208

Network Requirements....1208

Configuration Scheme....1208

Using the GUI....1208

Using the CLI 1210

Appendix: Default Parameters....1211

Configuring IPv6 IMPB

IPv6 IMPB 1214

Overview....1214

Supported Features....1214

IPv6-MAC Binding Configuration....1216

Using the GUI 1216

Binding Entries Manually 1216

Binding Entries via ND Snooping....1217

Binding Entries via DHCPv6 Snooping....1219

Viewing the Binding Entries....1220

Using the CLI 1221

Binding Entries Manually 1221

Binding Entries via ND Snooping....1223

Binding Entries via DHCPv6 Snooping....1224

Viewing Binding Entries 1225

ND Detection Configuration 1226

Using the GUI 1226

Adding IPv6-MAC Binding Entries....1226

Enabling ND Detection....1226

Configuring ND Detection on Ports....1227

Viewing ND Statistics....1227

Using the CLI 1228

Adding IPv6-MAC Binding Entries....1228

Enabling ND Detection....1228

Configuring ND Detection on Ports....1229

Viewing ND Statistics....1230

IPv6 Source Guard Configuration....1231

Using the GUI 1231

Adding IPv6-MAC Binding Entries....1231

Configuring IPv6 Source Guard 1231

Using the CLI 1232

Adding IPv6-MAC Binding Entries....1232

Configuring IPv6 Source Guard 1232

Configuration Examples....1234

Example for ND Detection....1234

Network Requirements....1234

Configuration Scheme....1234

Using the GUI....1235

Using the CLI 1237

Example for IPv6 Source Guard 1238

Network Requirements....1238

Configuration Scheme....1239

Using the GUI....1239

Using the CLI 1240

Appendix: Default Parameters....1242

Configuring DHCP Filter

DHCP Filter 1245

Overview....1245

Supported Features....1245

DHCPv4 Filter Configuration....1247

Using the GUI 1247

Configuring the Basic DHCPv4 Filter Parameters....1247

Configuring Legal DHCPv4 Servers 1248

Using the CLI 1249

Configuring the Basic DHCPv4 Filter Parameters....1249

Configuring Legal DHCPv4 Servers....1251

DHCPv6 Filter Configuration 1253

Using the GUI 1253

Configuring the Basic DHCPv6 Filter Parameters....1253

Configuring Legal DHCPv6 Servers 1254

Using the CLI 1255

Configuring the Basic DHCPv6 Filter Parameters....1255

Configuring Legal DHCPv6 Servers 1256

Configuration Examples....1258

Example for DHCPv4 Filter 1258

Network Requirements....1258

Configuration Scheme....1258

Using the GUI....1259

Using the CLI 1260

Example for DHCPv6 Filter 1261

Network Requirements....1261

Configuration Scheme....1262

Using the GUI....1262

Using the CLI 1263

Appendix: Default Parameters....1265

Configuring DoS Defend

Overview 1267

DoS Defend Configuration....1268

Using the GUI 1268

Using the CLI 1269

Appendix: Default Parameters....1272

Monitoring the System

Overview 1274

Monitoring the CPU 1275

Using the GUI 1275

Using the CLI 1275

Monitoring the Memory 1277

Using the GUI 1277

Using the CLI 1277

Monitoring Traffic

Traffic Monitor 1280

Using the GUI 1280

Using the CLI 1284

Appendix: Default Parameters....1285

Mirroring Traffic

Using the GUI 1287

Using the CLI 1289

Configuration Examples....1291

Network Requirements....1291

Configuration Scheme 1291

Using the GUI 1291

Using the CLI 1292

Appendix: Default Parameters....1294

Configuring sFlow (Only for Certain Devices)

Overview 1296

sFlow Configuration....1297

Using the GUI 1297

Configuring the sFlow Agent....1297

Configuring the sFlow Collector 1298

Configuring the sFlow Sampler 1298

Using the CLI 1300

Configuration Example 1303

Network Requirements....1303

Configuration Scheme 1303

Using the GUI 1303

Using the CLI 1304

Appendix: Default Parameters....1307

Configuring OAM (Only for Certain Devices)

Ethernet OAM....1309

Overview....1309

Supported Features....1310

Ethernet OAM Configurations....1313

Using the GUI 1313

Enabling OAM and Configuring OAM Mode 1313

Configuring Link Monitoring....1314

Configuring RFI....1316

Configuring Remote Loopback....1317

Viewing OAM Status....1318

Using the CLI 1320

Enabling OAM and Configuring OAM Mode 1320

Configuring Link Monitoring....1321

Configuring Remote Failure Indication....1327

Configuring Remote Loopback....1328

Verifying OAM Connection....1329

Viewing OAM Statistics 1332

Using the GUI 1332

Viewing OAMPDUs....1332

Viewing Event Logs....1334

Using the CLI 1335

Viewing OAMPDUs....1335

Viewing Event Logs....1337

Configuration Example 1339

Network Requirements....1339

Configuration Scheme....1339

Using the GUI....1339

Using the CLI 1343

Appendix: Default Parameters....1347

Configuring DLDP

Overview 1349

DLDP Configuration....1350

Using the GUI 1350

Using the CLI 1352

Appendix: Default Parameters....1354

Configuring SNMP & RMON

SNMP 1356

Overview....1356

Basic Concepts 1356

SNMP Configurations....1360

Using the GUI 1360

Enabling SNMP 1360

Creating an SNMP View....1361

Creating SNMP Communities (For SNMP v1/v2c) 1362

Creating an SNMP Group (For SNMP v3)....1363

Creating SNMP Users (For SNMP v3)....1364

Using the CLI 1365

Enabling SNMP 1365

Creating an SNMP View....1367

Creating SNMP Communities (For SNMP v1/v2c) 1368

Creating an SNMP Group (For SNMPv3)....1369

Creating SNMP Users (For SNMPv3)....1371

Notification Configurations....1373

Using the GUI 1373

Configuring the Information of NMS Hosts....1373

Enabling SNMP Traps....1375

Using the CLI....1378

Configuring the NMS Host....1378

Enabling SNMP Traps....1380

RMON 1388

RMON Configurations 1389

Using the GUI 1389

Configuring the Statistics Group....1389

Configuring History Group 1390

Configuring Event Group 1391

Configuring Alarm Group 1392

Using the CLI 1394

Configuring Statistics....1394

Configuring History....1396

Configuring Event 1397

Configuring Alarm....1398

Configuration Example 1401

Network Requirements....1401

Configuration Scheme 1402

Using the GUI 1402

Using the CLI 1407

Appendix: Default Parameters....1413

Configuring NETCONF

(Only for Certain Devices)

Overview 1418

NETCONF Configurations....1419

Using the CLI 1419

Enabling NETCONF SSH Connection....1419

Diagnosing the Device & Network

Diagnosing the Device....1421

Using the GUI 1421

Using the CLI....1422

Diagnosing the Network....1423

Using the GUI 1423

Troubleshooting with Ping Testing....1423

Troubleshooting with Tracert Testing....1424

Using the CLI 1425

Configuring the Ping Test....1425

Configuring the Tracert Test....1426

Appendix: Default Parameters....1427

Configuring System Logs

Overview 1429

System Logs Configurations....1430

Using the GUI 1431

Configuring the Local Logs....1431

Configuring the Remote Logs....1431

Backing up the Logs 1432

Viewing the Log Table....1433

Using the CLI 1433

Configuring the Local Logs....1433

Configuring the Remote Logs....1435

Configuration Example 1437

Network Requirements....1437

Configuration Scheme 1437

Using the GUI 1437

Using the CLI 1438

Appendix: Default Parameters....1439

About This Guide

This User Guide provides information for managing Managed Switches. Please read this guide carefully before operation.

Intended Readers

This Guide is intended for network managers familiar with IT concepts and network terminologies.

Conventions

When using this guide, notice that features available in Managed Switches may vary by model and software version. Availability of Managed Switches may also vary by region or ISP. All images, steps, and descriptions in this guide are only examples and may not reflect your actual experience.

Some models featured in this guide may be unavailable in your country or region. For local sales information, visit https://www.tp-link.com.

The information in this document is subject to change without notice. Every effort has been made in the preparation of this document to ensure accuracy of the contents, but all statements, information, and recommendations in this document do not constitute the warranty of any kind, express or implied. Users must take full responsibility for their application of any products.

In this Guide, the following conventions are used:

PoE budget calculations are based on laboratory testing. Actual PoE power budget is not guaranteed and will vary as a result of client limitations and environmental factors.

The symbol 📋 stands for Note. Notes contain suggestions or references that help you make better use of your device.

For GUI:

Menu Name > Submenu Name > Tab page indicates the menu structure. System > System Info > System Summary means the System Summary page under the System Info menu option that is located under the System menu.

Bold font indicates a button, a toolbar icon, menu or menu item.

For CLI:

Bold Font An unalterable keyword.

For example: show logging

Normal Font A constant (several options are enumerated and only one can be selected).For example: no bandwidth {all | ingress | egress}
{} Items in braces {} are required.
[] Items in square brackets [] are optional.
| Alternative items are grouped in braces and separated by vertical bars |.For example: speed {10 | 100 | 1000}
Italic Font A variable (an actual value must be assigned).For example: bridge aging-time aging-time

Common combination:

{[ ][ ][ ]} A least one item in the square brackets must be selected.

For example: bandwidth {[ingress ingress-rate] [egress egress-rate]}

This command can be used on three occasions:

bandwidth ingress ingress-rate is used to restrict ingress bandwidth.

bandwidth egress egress-rate is used to restrict egress bandwidth.

bandwidth ingress ingress-rate egress egress-rate is used to restrict ingress and egress bandwidth.

More Information

■ The latest software and documentations can be found at Download Center at https://www.tp-link.com/support/download/?type=smb. ■ The Installation Guide (IG) can be found where you find this guide or inside the package of the switch. ■ The authentication information can be found where you find this guide. ■ Specifications can be found on the product page at https://www.tp-link.com. ■ To ask questions, find answers, and communicate with TP-Link users or engineers, please visit https://community.tp-link.com/business to join TP-Link Community. - Our Technical Support contact information can be found at the Contact Technical Support page at https://www.tp-link.com/support/?type=smb.

Part 1

Accessing the Switch

CHAPTERS

  1. Determine the Management Method
  2. Web Interface Access
  3. Command Line Interface Access

1 Determine the Management Method

Before building your network, choose a proper method to manage your switch based on your actual network situation. The switch supports two configuration options: Standalone Mode or Controller Mode.

TP-LINK Omada Pro S5500-24GP4F - Determine the Management Method - 1

Note:

Controller Mode is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If Controller Mode is available, there is SYSTEM > Controller Settings in the menu structure.

■ Controller Mode

If you want to configure and manage a large-scale network centrally, which consists of mass devices such as access points, switches, and gateways, Controller Mode is recommended. In Controller Mode, the switch can be centrally configured and monitored via Omada SDN Controller.

To prepare the switch for Omada Pro SDN Controller Management, refer to Controller Settings (Only for Certain Devices). For detailed instructions about the network topology in such situations and how to use Omada Pro SDN Controller, refer to the User Guide of Omada Pro SDN Controller. The guide can be found on the download center of our official website: https://www.tp-link.com/support/download/?type=smb

■ Standalone Mode

If you have a relatively small-sized network and only one or just a small number of devices need to be managed, Standalone Mode is recommended. In Standalone Mode, the switch can be singly configured and monitored via the GUI (Graphical User Interface, also called web interface in this text) or via the CLI (Command Line Interface). There are equivalent functions in the web interface and the command line interface, while web configuration is easier and more visual than the CLI configuration. You can choose the method according to their available applications and preference.

This User Guide introduces how to configure and monitor the switch in Standalone Mode.

TP-LINK Omada Pro S5500-24GP4F - ■ Standalone Mode - 1

Note:

  • The GUI and CLI is inaccessible while the switch is managed by a controller. To turn the switch back to Standalone Mode and access its GUI and CLI, you can forget the switch on the controller or reset the switch. • The first time you log in, change the password to better protect your network and devices.

2 Web Interface Access

You can access the switch's web interface through web-based authentication. The switch uses two built-in web servers, HTTP server and HTTPS server, for user authentication.

Alternatively, you can access the switch's web interface through the Management Port. The Management Port is a dedicated Ethernet port for out-of-band management of the device. Traffic on this port is segregated from operational network traffic on the switch ports and cannot be switched or routed to the operational network. The Management Port is located next to the Console port and can connect to 10Mbps, 100Mbps, or 1000Mbps devices. It requires an assigned IP address for device management.

The following example shows how to log in via the HTTP server.

2.1 Login

To manage your switch through a web browser on the host PC:

1) Make sure that the route between the host PC and the switch is available. 2) Launch a web browser. Supported web browsers include, but are not limited to, the following types:

■ IE 8.0, 9.0, 10.0, 11.0 ■ Firefox 26.0, 27.0 ■ Chrome 32.0, 33.0

3) Enter the switch's IP address in the web browser's address bar. The switch's default IP address is 192.168.0.1.

Figure 2-1 Enter the Switch's IP Address in the BrowserTP-LINK Omada Pro S5500-24GP4F - Login - 1

192.168.0.1

4) Enter the username and password (both admin by default) in the pop-up login window.

Figure 2-2 Login AuthenticationUsername: admin Password: ...... Remember Me Log In

TP-LINK Omada Pro S5500-24GP4F - Login - 3

Note:

• The first time you log in, change the password to better protect your network and devices. - With Allow Data Collection enabled, the device will report the device name, device ID, MAC address, hardware ID, device model, hardware version, and software version to the cloud. The information is only used to help us understand the device activation status to provide you with better services. If you do not want the device to report the information, you can disable the feature at any time.

5) The typical web interface is shown below. You can view the switch's running status and configure the switch on this interface.

Figure 2-3 Web InterfaceSYSTEM L2 FEATURES L3 FEATURES QOS SECURITY MAINTENANCE Save Log Out Port Status UNIT1 1 3 5 7 9 11 13 15 17 19 21 23 2 4 6 8 10 12 14 16 18 20 22 24 25 26 27 28 System Info UNIT1 System Description: Omada Pro 24-Port Gigabit Stackable L3 Managed PoE+ Switch with 4 10G Slots Device Name: S6500-24GP4…

2.2 Save the Configuration File

The switch's configuration files fall into two types: the running configuration file and the start-up configuration file.

After you perform configurations on the sub-interfaces and click Apply, the modifications will be saved in the running configuration file. The configurations will be lost when the switch reboots.

If you need to keep the configurations after the switch reboots, please click Save on the main interface to save the configurations in the start-up configuration file.

Figure 2-4 Save the ConfigurationSYSTEM L2 FEATURES L3 FEATURES QoS SECURITY MAINTENANCE Save Log Out Port Status UNIT1 1 3 5 7 9 11 13 15 17 19 21 23 2 4 6 8 10 12 14 16 18 20 22 24 25 26 27 28 System Info UNIT1 System Description Device Name: Device Location: Contact Information Hardware Version: Save the configuration file? No Y…

2.3 Disable the Web Server

You can shut down the HTTP server and HTTPS server to block any access to the web interface.

Go to SECURITY > Access Security > HTTP Config, disable the HTTP server and click Apply.

Figure 2-5 Shut Down HTTP ServerGlobal Config HTTP: Enable Port: 80 (1-65535) Apply

Go to SECURITY > Access Security > HTTPS Config, disable the HTTPS server and click Apply.

Figure 2-6 Disable the HTTPS ServerGlobal Config HTTPS: Enable Protocol Version: TLS Version 1.2 Port: 443 (1-65535) Apply

2.4 Configure the Switch's IP Address and Default Gateway

If you want to access the switch via a specified port (hereafter referred to as the access port), you can configure the port as a routed port and specify its IP address, or configure the IP address of the VLAN which the access port belongs to.

■ Change the IP Address

By default, all the ports belong to VLAN 1 with the VLAN interface IP 192.168.0.1.

The following example shows how to change the switch's default access IP address 192.168.0.1.

1) Go to L3 FEATURES > Interface. The default access IP address in VLAN 1 is in the Interface List. Click Edit IPv4 to modify VLAN1's IP address.

Figure 2-7 Change VLAN1's IP AddressRouting Config IPv4 Routing: ✓ Enable IPv6 Routing: □ Enable Apply Interface Config + Add - Delete □ Interface ID IP Address Mode IP Address Subnet Mask Interface Name Status Operation □ VLAN1 DHCP 192.168.0.1 255.255.255.0 Up Edit IPv4 Detail Edit IPv6 Total: 1

2) Choose the IP Address Mode as Static. Enter the new access address in the IP Address field and click Apply. Make sure that the route between the host PC and the switch's new IP address is available.

Figure 2-8 Specify the IP AddressModify IPv4 Interface Interface ID: VLAN1 Admin Status: Enable Interface Name: (Optional. 1-16 characters) IP Address Mode: None Static DHCP BOOTP IP Address: 192.168.0.100 (Format: 192.168.0.1) Subnet Mask: 255.255.255.0 (Format: 255.255.255.0) Apply

3) Enter the new IP address in the web browser to access the switch.

4) Click to save the settings.

■ Configure the Default Gateway

The following example shows how to configure the switch's gateway. By default, the switch has no default gateway.

1) Go to page L3 FEATURES > Static Routing > IPv4 Static Routing Config. Click Add to load the following page and configure the parameters related to the switch's gateway. Then click Create.

Figure 2-9 Configure the Default GatewayIPv4 Static Routing Destination: 0.0.0.0 (Format: 10.10.10.0) Subnet Mask: 0.0.0.0 (Format: 255.255.255.0) Next Hop: 192.168.0.100 (Format: 192.168.0.2) Distance: 1 (Optional. range: 1-255) Cancel Create

Destination: Specify the destination IPv4 address of the packets.

Subnet Mask: Specify the subnet mask of the destination IPv4 address.

Next Hop Specify the IPv4 gateway address to which the packet should be sent next.

Distance Specify the administrative distance. The distance is the trust rating of a routing entry. A higher value means a lower trust rating. Among routes to the same destination, the route with the lowest distance value will be recorded in the routing table.

Metric Displays the metric to reach the destination IP address.

Interface Name Displays the name of the gateway interface.

2) Click Save the settings. 3) Check the routing table to verify the default gateway you configured. The entry marked in red box displays the valid default gateway.

Figure 2-10 View the Default Gateway

IPv4 Routing Information Summary
Refresh
ProtocolDestination NetworkNext HopDistanceMetricInterface Name
Static0.0.0.0/24192.168.0.10010VLAN1
Connected192.168.0.0/24192.168.0.10001VLAN1
Total: 2

3 Command Line Interface Access

Users can access the switch's command line interface through the console port or management port (only for switch with console port or management port), Telnet or SSH connection, and manage the switch with the command lines.

Console connection requires the host PC connecting to the switch's console port directly, while Telnet and SSH connection support both local and remote access.

The following table shows the typical applications used in the CLI access.

Table 3-1 Method list

Method Using Port Typical Applications
Console Console port (connected directly)Hyper Terminal
Telnet RJ-45 port CMD
SSH RJ-45 port Putty

3.1 Console Login (only for switch with console port)

Follow these steps to log in to the switch via the Console port:

1) Connect the PC or terminal to the Console port on the switch with the serial cable. 2) Start the terminal emulation program (such as the Hyper Terminal) on the PC and configure the terminal emulation program as follows:

■ Baud Rate: 38400bps ■ Data Bits: 8 ■ Parity: None ■ Stop Bits: 1 ■ Flow Control: None

3) Type the User name and Password in the Hyper Terminal window. The default value for both of them is admin. Press Enter in the main window and Switch> will appear, which

indicates that you have successfully logged in to the switch and you can use the CLI now.

Figure 3-1 CLI Main WindowUser: admin Password: Switch>

TP-LINK Omada Pro S5500-24GP4F - Console Login (only for switch with console port) - 2

Note:

The first time you log in, change the password to better protect your network and devices.

4) Enter enable to enter the User EXEC Mode to further configure the switch.

Figure 3-2 User EXEC ModeUser admin Password: Switch>enable Switch#

TP-LINK Omada Pro S5500-24GP4F - Note: - 2

Note:

In Windows XP, go to Start > All Programs > Accessories > Communications > Hyper Terminal to open the Hyper Terminal and configure the above settings to log in to the switch.

3.2 SSH Login

SSH login (enabled by default for L3 switches) supports the following two modes: Password Authentication Mode and Key Authentication Mode. You can choose one according to your needs:

■ Password Authentication Mode: Username and password are required, which are both admin by default. ■ Key Authentication Mode (Recommended): A public key for the switch and a private key for the client software (PuTTY) are required. You can generate the public key and the private key through the PuTTY Key Generator.

Before logging in via SSH, follow the steps below to enable SSH on the terminal emulation program:

Figure 3-3 Enable SSHS6500-24GP4XF>enable S6500-24GP4XF#config S6500-24GP4XF(config)#ip ssh server

Password Authentication Mode

1) Open PuTTY and go to the Session page. Enter the IP address of the switch in the Host Name field and keep the default value 22 in the Port field; select SSH as the Connection type. Click Open.

Figure 3-4 Configurations in PuTTYPuTTY Configuration Category: Session Logging Terminal Keyboard Bell Features Window Appearance Behaviour Translation Selection Colours Connection Data Proxy Telnet Rlogin SSH Serial Basic options for your PuTTY session Specify the destination you want to connect to Host Name (or IP address) Port 19…

2) Enter the login username and password to log in to the switch, and you can continue to configure the switch.

Figure 3-5 Log In to the Switchlogin as: admin Further authentication required Authenticating with public key "rsa-key-20150122" SG500-24GP4XF

TP-LINK Omada Pro S5500-24GP4F - Password Authentication Mode - 3

Note:

The first time you log in, change the password to better protect your network and devices.

Key Authentication Mode

1) Open the PuTTY Key Generator. In the Parameters section, select the key type and enter the key length. In the Actions section, click Generate to generate a public/private key pair. In the following figure, an SSH-2 RSA key pair is generated, and the length of each key is 1024 bits.

Figure 3-6 Generate a Public/Private Key PairPuTTY Key Generator File Key Conversions Help Key No key. Actions Generate a public/private key pair Generate a key Generate Load an existing private key file Load Save the generated key Save public key Save private key Parameters Type of key to generate: SSH-1 (RSA) SSH-2 RSA SSH-2 DSA Key type Num…

TP-LINK Omada Pro S5500-24GP4F - Key Authentication Mode - 2

Note:

• The key length should be between 512 and 3072 bits. - You can accelerate the key generation process by moving the mouse quickly and randomly in the Key section.

2) After the keys are successfully generated, click Save public key to save the public key to a TFTP server; click Save private key to save the private key to the host PC.

Figure 3-7 Save the Generated KeysPuTTY Key Generator File Key Conversions Help Key Public key for pasting into OpenSSH authorized_keys file: ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAAQEAg4R3LBYbN7SDbFjn3MuoHr4LHF7Jv8WNBCf 7xoJzrlwndlbpC7Dlxd8m0zlJo6SR +sUVK8EaTWROqOpfBroxhu7QPLIBM40cMzOmDCZk3bhfg6g0rVf0MmSmGNoEYtiD qhXLbFU3rDxTjn5nlUCrvG0o…

3) On Hyper Terminal, download the public key file from the TFTP server to the switch as shown in the following figure:

Figure 3-8 Download the Public Key to the SwitchTelnet 192.168.0.1 ***************** User Access Login ***************** User:admin Password: #2005-01-27 08:06:01.[User]/S/login the CLI by admin on uty0 (192.168.0.200). Switch>enable Switch#configure Switch(config)#ip ssh download v2 public ip-address 192.168.0.100 Start to download SSH key file.…

TP-LINK Omada Pro S5500-24GP4F - Note: - 3

Note:

  • The key type should accord with the type of the key file. In the above CLI, v1 corresponds to SSH-1 (RSA), and v2 corresponds to SSH-2 RSA and SSH-2 DSA. • The key downloading process cannot be interrupted.

4) After the public key is downloaded, open PuTTY and go to the Session page. Enter the IP address of the switch and select SSH as the Connection type (keep the default value in the Port field).

Figure 3-9 Configure the Host Name and Connection TypePuTTY Configuration Category: Session Logging Terminal Keyboard Bell Features Window Appearance Behaviour Translation Selection Colours Connection Data Proxy Telnet Rlogin SSH Serial Basic options for your PuTTY session Specify the destination you want to connect to Host Name (or IP address) Port 19…

5) Go to Connection > SSH > Auth. Click Browse to download the private key file to PuTTY. Click Open to start the connection and negotiation.

Figure 3-10 Download the Private Key to PuTTYPuTTY Configuration Category: Session Logging Terminal Keyboard Bell Features Window Appearance Behaviour Translation Selection Colours Connection Data Proxy Telnet Rlogin SSH Kex Auth TTY X11 About Options controlling SSH authentication Bypass authentication entirely (SSH-2 only) Authentication met…

6) After negotiation is completed, enter the username to log in. If you can log in without entering the password, the key authentication completed successfully.

Figure 3-11 Log In to the SwitchLogin as: admin Further authentication required Authenciating with public key "rsa-key-20150122" S6500-24GP4XF

TP-LINK Omada Pro S5500-24GP4F - Note: - 4

Note:

The first time you log in, change the password to better protect your network and devices.

3.3 Telnet Login

The switch supports Login Local Mode for authentication by default.

Before logging in via Telnet, enable Telnet on the terminal emulation program via SSH or serial cable.

Login Local Mode: Username and password are required, which are both admin by default.

The following steps show how to manage the switch via the Login Local Mode:

1) Make sure the switch and the PC are in the same LAN (Local Area Network). Click Start and type in cmd in the Search bar and press Enter.

Figure 3-12 Open the CMD Windowcmd Shut down

2) Type in telnet 192.168.0.1 in the CMD window and press Enter.

Figure 3-13 Log In to the SwitchMicrosoft Windows [Version 10.0.19045.2965] (c) Microsoft Corporation. All rights reserved. C:\Users\admin>telnet 192.168.0.1_

3) Type in the login username and password (both admin by default). Press Enter and you will enter User EXEC Mode.

Figure 3-14 Enter User EXEC Mode***************** User Access Login ***************** User:admin Password: S6500-24GP4XF_

TP-LINK Omada Pro S5500-24GP4F - Telnet Login - 4

Note:

The first time you log in, change the password to better protect your network and devices.

4) Type in enable command and you will enter Privileged EXEC Mode. By default no password is needed. Later you can set a password for users who want to access the Privileged EXEC Mode.

Figure 3-15 Enter Privileged EXEC Mode***************** User Access Login ****************** User:admin Password: S6500-24GP4XF>enable S6500-24GP4XF#_

Now you can manage your switch with CLI commands through Telnet connection.

3.4 Disable SSH login

You can shut down the SSH server to block any SSH access to the CLI interface.

■ Using the GUI:

Go to SECURITY > Access Security > SSH Config, disable the SSH server and click Apply.

Figure 3-16 Shut down SSH serverGlobal Config SSH: Enable Protocol V1: Enable Protocol V2: Enable Idle Timeout: 120 seconds (1-120) Maximum Connections: 5 (1-5) Port: 22 (1-65535) Apply

■ Using the CLI:

Switch#configure

Switch(config)#no ip ssh server

3.5 Disable Telnet login

You can shut down the Telnet function to block any Telnet access to the CLI interface.

■ Using the GUI:

Go to SECURITY > Access Security > Telnet Config, disable the Telnet function and click Apply.

Figure 3-17 Disable Telnet loginTelnet Config Telnet: Enable Port: 23 (1-65535) Apply

■ Using the CLI:

Switch#configure

Switch(config)#telnet disable

3.6 Copy running-config startup-config

The switch's configuration files fall into two types: the running configuration file and the start-up configuration file.

After you enter each command line, the modifications will be saved in the running configuration file. The configurations will be lost when the switch reboots.

If you need to keep the configurations after the switch reboots, please use the command copy running-config startup-config to save the configurations in the start-up configuration file.

Switch(config)#end

Switch#copy running-config startup-config

3.7 Change the Switch's IP Address and Default Gateway

If you want to access the switch via a specified port (hereafter referred to as the access port), you can configure the port as a routed port and specify its IP address, or configure the IP address of the VLAN which the access port belongs to.

■ Change the IP Address

By default, all the ports belong to VLAN 1 with the VLAN interface IP 192.168.0.1/24. In the following example, we will show how to replace the switch's default access IP address 192.168.0.1/24 with 192.168.0.10/24.

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#ip address 192.168.0.10 255.255.255.0

The connection will be interrupted and you should telnet to the switch's new IP address 192.168.0.10.

C:\Users\Administrator>telnet 192.168.0.10

User:admin

Password:tplink

Switch>enable

Switch#copy running-config startup-config

■ Configure the Default Gateway

In the following example, we will show how to configure the switch's gateway as 192.168.0.100. By default, the switch has no default gateway.

Switch#configure

Switch(config)#ip route 0.0.0.0 0.0.0.0 192.168.0.100 1

Switch(config)#end

Switch#copy running-config startup-config

Part 2

Managing System

CHAPTERS

  1. System
  2. System Info Configurations
  3. User Management Configurations
  4. System Tools Configurations
  5. EEE Configuration
  6. PoE Configurations (Only for Certain Devices) 7 Management Port Configurations (Only for Certain Devices)
  7. Power Supply Configurations
  8. SDM Template Configurations
  9. Time Range Configurations
  10. Controller Settings (Only for Certain Devices)
  11. File System Configurations (Only for Certain Devices)
  12. FTP, SFTP and SCP Configurations (Only for Certain Devices)
  13. Example for PoE Configurations
  14. Appendix: Default Parameters

1 System

1.1 Overview

In System part, you can view the system information and configure the system parameters and features of the switch.

1.2 Supported Features

System Info

You can view the switch's port status and system information, and configure the device description, system time, daylight saving time and LED status.

User Management

You can manage the user accounts for login to the switch. There are multiple user types which have different access levels, and you can create different user accounts according to your need.

System Tools

You can configure the boot file of the switch, backup and restore the configurations, update the firmware, reset the switch, and reboot the switch.

EEE

EEE (Energy Efficient Ethernet) is used to reduce the power consumption of the switch during periods of low data transmission. You can simply enable this feature on ports to allow power reduction.

PoE

TP-LINK Omada Pro S5500-24GP4F - PoE - 1

Note:

PoE configuration is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If PoE configuration is available, there is SYSTEM > PoE in the menu structure.

Power over Ethernet (PoE) is a remote power supply function. With this function, the switch can supply power in addition to data to connected devices over twisted-pair cables.

Some devices such as IP phones, access points (APs) and cameras may be located far away from the AC power source in actual use. PoE can provide power for these devices without requiring to deploy power cables. This allows a single cable to provide both data connection and electric power to devices.

IEEE 802.3af and 802.3at are both PoE standards. The standard process of PoE power supply contains powered-device discovery, power administration, disconnect detection and optional power-device power classification.

PSE

Power sourcing equipment (PSE) is a device that provides power for PDs on the Ethernet, for example, the PoE switch. PSE can detect the PDs and determine the device power requirements.

PD

Powered device (PD) is a device receiving power from the PSE, for example, IP phones and access points. According to whether PDs comply with IEEE standard, they can be classified into standard PDs and non-standard PDs. Only standard PDs can be powered via TP-Link PoE switches.

Stack

TP-LINK Omada Pro S5500-24GP4F - Stack - 1

Note:

This feature is only supported on stackable switches.

With stackable design, the switches can be stacked into one stack topology for higher reliability, larger bandwidth, and simpler networking. To build the stack topology, you need to prepare 2-4 switches and enough SFP+/SFP28 modules/cables.

SDM Template

SDM (Switch Database Management) Template is used to distribute system resources to different applications such as ACL and ARP Detection. The switch provides three templates with different resource allocations. You can view the details of the three templates and choose one according to your needs.

Time Range

With this feature, you can configure a time range. You can use the time range when you configure other features like ACL.

Controller Settings

TP-LINK Omada Pro S5500-24GP4F - Controller Settings - 1

Note:

Controller Settings is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If Controller Settings is available, there is SYSTEM > Controller Settings in the menu structure.

With this feature, you can configure your switch to be discovered by Omada SDN Controller on this page, then it can be managed centrally via Omada SDN Controller.

2 System Info Configurations

With system information configurations, you can:

■ View the System Summary ■ Configure the Device Description ■ Configure the System Time ■ Configure the Daylight Saving Time ■ Configure LED (Only for Certain Devices)

2.1 Using the GUI

2.1.1 Viewing the System Summary

Choose the menu SYSTEM > System Info > System Summary to load the System Summary page. You can view the port status and system information of the switch.

Viewing the Port Status

In the Port Status section, you can view the status and bandwidth utilization of each port.

Figure 2-1 Viewing the System SummaryPort Status UNIT1 1 3 5 7 9 11 13 15 17 19 21 23 2 4 6 8 10 12 14 16 18 20 22 24 25 26 27 28

The following table introduces the meaning of each port status:

Port Status Indication
Indicates the Ethernet port is not connected to a device.
Indicates the Ethernet port is transmitting and receiving data at the highest speed.
Indicates the Ethernet port is transmitting and receiving data, but not at the highest speed.
Indicates the SFP port is not connected to a device.
Indicates the SFP port is transmitting and receiving data at the highest speed.

TP-LINK Omada Pro S5500-24GP4F - Viewing the Port Status - 2

Indicates the SFP port is transmitting and receiving data, but not at the highest speed.

You can move your cursor to a port to view the detailed information of the port.

Figure 2-2 Port InformationPort: 1/0/4 Type: Auto RJ45 Speed: 1000M, Full Duplex Status: Link Up

Port Information Indication

Port Displays the port number.

Type Displays the type of the port.

Speed Displays the maximum transmission rate and duplex mode of the port.

Status Displays the connection status of the port.

You can click a port to view the bandwidth utilization on this port.

Figure 2-3 Bandwidth UtilizationBandwidth Utilization (Port:1/0/1) | Port | Bandwidth Utilization (%) | |---|---| | 1 | 100 | | 2 | 50 | | 3 | 40 | | 4 | 30 | | 5 | 20 | | 6 | 10 | | 7 | 5 | | 8 | 5 | | 9 | 5 | | 10 | 5 | | 11 | 5 | | 12 | 5 | | 13 | 5 | | 14 | 5 | | 15 | 5 | | 16 | 5 | | 17 | 5 | | 18 | 5 | | 19 | 5 | | 20 | 5 |…

RX Displays the bandwidth utilization of receiving packets on this port.

TX Displays the bandwidth utilization of sending packets on this port.

Viewing the System Information

In the System Info section, you can view the system information of the switch.

Figure 2-4 System Information

System Info
UNIT1
System Description:Omada Pro 24-Port Gigabit Stackable L3 Managed PoE+ Switch with 4 10G Slots
Device Name:S6500-24GP4XF
Device Location:Hong Kong
Contact Information:www.tp-link.com
Hardware Version:S6500-24GP4XF 1.0
Firmware Version:1.0.0 Build 20240531 Rel.63051
Boot Loader Version:1.0.0 Build 20230821 Rel.74148
MAC Address:00-0A-EB-00-13-31
System Time:2006-01-02 02:29:12
Running Time:0 day - 18 hour - 29 min - 13 sec
Serial Number
Jumbo Frame:DisabledSettings
SNTP:DisabledSettings
IGMP Snooping:DisabledSettings
SNMP:EnabledSettings
Spanning Tree:DisabledSettings
DHCP Relay:DisabledSettings
802.1X:DisabledSettings
HTTP Server:EnabledSettings
Telnet:EnabledSettings
SSH:DisabledSettings
System DescriptionDisplays the system description of the switch.
Device NameDisplays the name of the switch. You can edit it on the Device Description page.
Device LocationDisplays the location of the switch. You can edit it on the Device Description page.
Contact InformationDisplays the contact information of the switch. You can edit it on the Device Description page
Hardware VersionDisplays the hardware version of the switch.
Firmware VersionDisplays the firmware version of the switch.
Boot Loader VersionDisplays the boot loader version of the switch.
MAC Address Displays the MAC address of the switch.
System Time Displays the system time of the switch.
Running Time Displays the running time of the switch.
Serial Number Displays the serial number of the switch.
Jumbo FrameDisplays whether Jumbo Frame is enabled. You can click Settings to jump to the Jumbo Frame configuration page.
SNTPDisplays whether the switch gets system time from NTP Server. You can click Settings to jump to the System Time configuration page.
IGMP SnoopingDisplays whether IGMP Snooping is enabled. You can click Settings to jump to the IGMP Snooping configuration page.
SNMPDisplays whether SNMP is enabled. You can click Settings to jump to the SNMP configuration page.
Spanning TreeDisplays whether Spanning Tree is enabled. You can click Settings to jump to the Spanning Tree configuration page.
DHCP RelayDisplays whether DHCP Relay is enabled. You can click Settings to jump to the DHCP Relay configuration page.
802.1xDisplays whether 802.1x is enabled. You can click Settings to jump to the 802.1x configuration page.
HTTP ServerDisplays whether HTTP server is enabled. You can click Settings to jump to the HTTP configuration page.
TelnetDisplays whether Telnet is enabled. You can click Settings to jump to the Telnet configuration page.
SSHDisplays whether SSH is enabled. You can click Settings to jump to the SSH configuration page.

2.1.2 Configuring the Device Description

Choose the menu SYSTEM > System Info > Device Description to load the following page.

Figure 2-5 Configuring the Device DescriptionDevice Description Device Name: S6500-24GP4XF (1-128 characters) Device Location: Hong Kong (1-128 characters) System Contact: www.tp-link.com (1-128 characters) Apply

1) In the Device Description section, configure the following parameters.

Device Name Specify a name for the switch.

Device Location Enter the location of the switch.

System Contact Enter the contact information.

2) Click Apply.

2.1.3 Configuring the System Time

Choose the menu SYSTEM > System Info > System Time to load the following page.

Figure 2-6 Configuring the System TimeTime Info Current System Time: Tuesday, August 20, 2024 11:53:20 Current Time Source: PC's Clock Time Config Configure Manually Get Time from NTP Server Synchronize with PC's Clock Time Zone: (GMT+08:00) Beijing, Urumqi, Hong Kong, Taipei Primary NTP Server: 139.78.100.163 (Format: 192.168.0.1 or 20…

In the Time Info section, you can view the current time information of the switch.

Current System TimeDisplays the current date and time of the switch.
Current Time SourceDisplays the current time source of the switch.

In the Time Config section, there are three methods to configure the system time: Manual, Get Time from NTP Server and Synchronize with PC's Clock. Follow these steps to configure the system time:

1) Choose one method to set the system time and specify the related parameters.

Manual Set the system time manually.
Date: Specify the date of the system.
Time: Specify the time of the system.
Get Time from NTP ServerGet the system time from an NTP server. Make sure the NTP server is accessible on your network. If the NTP server is on the internet, connect the switch to the internet first.Time Zone: Select your local time zone.Primary Server: Enter the IP Address of the primary NTP server.Secondary Server: Enter the IP Address of the secondary NTP server. Once the primary NTP server is down, the switch can get the system time from the secondary NTP server.Update Rate: Specify the interval the switch fetching time from NTP server, which ranges from 1 to 24 hours.
Synchronize with PC's ClockSynchronize the system time of the switch with PC's clock.

2) Click Apply.

2.1.4 Configuring the Daylight Saving Time

Choose the menu SYSTEM > System Info > Daylight Saving Time to load the following page.

Figure 2-7 Configuring the Daylight Saving TimeDST Config DST: Enable Mode: Predefined Mode Recurring Mode Date Mode Predefined Profile: USA Apply

Follow these steps to configure Daylight Saving Time:

1) In the DST Config section, enable the Daylight Saving Time function. 2) Choose one method to set the Daylight Saving Time and specify the related parameters.

Predefined ModeIf you select Predefined Mode, choose a predefined DST schedule for the switch.USA: Select the Daylight Saving Time of the USA. It is from 2:00 a.m. on the Second Sunday in March to 2:00 a.m. on the First Sunday in November.Australia: Select the Daylight Saving Time of Australia. It is from 2:00 a.m. on the First Sunday in October to 3:00 a.m. on the First Sunday in April.Europe: Select the Daylight Saving Time of Europe. It is from 1:00 a.m. on the Last Sunday in March to 1:00 a.m. on the Last Sunday in October.New Zealand: Select the Daylight Saving Time of New Zealand. It is from 2:00 a.m. on the Last Sunday in September to 3:00 a.m. on the First Sunday in April.
Recurring ModeIf you select Recurring Mode, specify a cycle time range for the Daylight Saving Time of the switch. This configuration will be used every year.Offset: Specify the time to set the clock forward by.Start Time: Specify the start time of Daylight Saving Time. The interval between start time and end time should be more than 1 day and less than 1 year(365 days).End Time: Specify the end time of Daylight Saving Time. The interval between start time and end time should be more than 1 day and less than 1 year (365 days).
Date ModeIf you select Date Mode, specify an absolute time range for the Daylight Saving Time of the switch. This configuration will be used only one time.Offset: Specify the time to set the clock forward by.Start Time: Specify the start time of Daylight Saving Time. The interval between start time and end time should be more than 1 day and less than 1 year(365 days).End Time: Specify the end time of Daylight Saving Time. The interval between start time and end time should be more than 1 day and less than 1 year (365 days).

3) Click Apply.

2.1.5 Configuring LED (Only for Certain Devices)

TP-LINK Omada Pro S5500-24GP4F - Configuring LED (Only for Certain Devices) - 1

Note:

Configuring LED is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If configuring LED is available, there is SYSTEM > LED On/Off in the menu structure.

Choose the menu System > LED On/Off to load the following page. Choose the LED status and click Apply.

Figure 2-8 Configuring LED On/OffLED On/Off Config LED: On Off Apply

2.2 Using the CLI

2.2.1 Viewing the System Summary

On privileged EXEC mode or any other configuration mode, you can use the following commands to view the system information of the switch:

show interface status [fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port ]

View status of the interface.

port: Enter the number of the Ethernet port.

show system-info

View the system information including System Description, Device Name, Device Location, System Contact, Hardware Version, Firmware Version, System Time, Run Time and so on.

The following example shows how to view the interface status and the system information of the switch.

Switch#show interface status

PortStatusSpeedDuplexFlowCtrlActive-MediumDescription
Gi1/0/1LinkDownN/AN/AN/ACopper
Gi1/0/2LinkDownN/AN/AN/ACopper
Gi1/0/3LinkUp1000MFullDisableCopper
...

Switch#show system-info

System Description - Omada Pro 24-Port Gigabit Stackable L3 Managed PoE+ Switch with 4 10G Slots

Device Name - S6500-24GP4XF

Device Location - Hong Kong

Contact Information - www.tp-link.com

Hardware Version - S6500-24GP4XF 1.0

Software Version - 1.0.0 Build 20231105 Rel.68404

Bootloader Version - 1.0.0 Build 20230821 Rel.74148

MAC Address - 5C-E9-31-43-31-FA

Serial Number - 2238481000146

System Time - 2023-12-01 11:19:40

Running Time - 0 day - 0 hour - 3 min - 43 sec

Device Info

Unit 1

Unit State - Provisioned

Hardware Version - S6500-24GP4XF

Unit 2

Unit State - Ready

Hardware Version - S6500-24GP4XF 1.0

Firmware Version - 1.0.0 Build 20231105 Rel.68404

Bootloader Version - 1.0.0 Build 20230821 Rel.74148

Serial Number - 2238481000146

Running Time - 0 day - 0 hour - 3 min - 43 sec

Power Supply Module - Operational

Redundant Power Supply - Support

2.2.2 Configuring the Device Description

Follow these steps to configure the device description:

Step 1 configure

Enter global configuration mode.

Step 2 hostname [ hostname ]

Specify the system name of the switch.

hostname: Enter the device name. The length of the name ranges from 1 to 32 characters. By default, it is the model name of the switch.

Step 3 location [ location ]

Specify the system location of the switch.

location: Enter the device location. It should consist of no more than 32 characters. By default, it is "Hong Kong".

Step 4 contact-info [ contact-info ]

Specify the system contact Information.

contact-info: Enter the contact information. It should consist of no more than 32 characters. By default, it is "www.tp-link.com".

Step 5 show system-info

Verify the system information including system Description, Device Name, Device Location, System Contact, Hardware Version, Firmware Version, System Time, Run Time and so on.

Step 6 end

Return to privileged EXEC mode.

Step 7 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the device name as Switch_A, set the location as BEIJING and set the contact information as https://www.tp-link.com.

Switch#configure

Switch(config)#hostname Switch

Switch(config)#location HongKong

Switch(config)#contact-info https://www.tp-link.com

Switch(config)#show system-info

System Description - Omada 48-Port Gigabit Stackable L3 Managed Switch with 6 10G Slots

Device Name - Switch

Device Location - HongKong

Contact Information - www.tp-link.com

...

Switch(config)#end

Switch#copy running-config startup-config

2.2.3 Configuring the System Time

Follow these steps to configure the system time:

TP-LINK Omada Pro S5500-24GP4F - Configuring the System Time - 1

Note:

The mode of Synchronize with PC's Clock does not support CLI command.

Step 1 configure

Enter global configuration mode.

Step 2 Use the following command to set the system time manually:

system-time manual time

Configure the system time manually.

time: Specify the date and time manually in the format of MM/DD/YYYY-HH:MM:SS. The valid value of the year ranges from 2000 to 2037.

Use the following command to set the system time by getting time from the NTP server. Ensure the NTP server is accessible. If the NTP server is on the internet, connect the switch to the internet first.

system-time ntp { timezone } { ntp-server } { backup-ntp-server } { fetching-rate }

timezone: Enter your local time-zone, which ranges from UTC-12:00 to UTC+13:00.

The detailed information of each time-zone are displayed as follows:

UTC-12:00 — TimeZone for International Date Line West.

UTC-11:00 — TimeZone for Coordinated Universal Time-11.

UTC-10:00 —— TimeZone for Hawaii.

UTC-09:00 —— TimeZone for Alaska.

UTC-08:00 — TimeZone for Pacific Time (US Canada).

UTC-07:00 — TimeZone for Mountain Time (US Canada).

UTC-06:00 — TimeZone for Central Time (US Canada).

UTC-05:00 — TimeZone for Eastern Time (US Canada).

UTC-04:30 — TimeZone for Caracas.

UTC-04:00 — TimeZone for Atlantic Time (Canada).

UTC-03:30 — TimeZone for Newfoundland.

UTC-03:00 — TimeZone for Buenos Aires, Salvador, Brasilia.

UTC-02:00 — TimeZone for Mid-Atlantic.

UTC-01:00 — TimeZone for Azores, Cape Verde Is.

UTC — TimeZone for Dublin, Edinburgh, Lisbon, London.

UTC+01:00 — TimeZone for Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna.

UTC+02:00 — TimeZone for Cairo, Athens, Bucharest, Amman, Beirut, Jerusalem.

UTC+03:00 — TimeZone for Kuwait, Riyadh, Baghdad.

UTC+03:30 — TimeZone for Tehran.

UTC+04:00 — TimeZone for Moscow, St.Petersburg, Volgograd, Tbilisi, Port Louis.

UTC+04:30 — TimeZone for Kabul.

UTC+05:00 — TimeZone for Islamabad, Karachi, Tashkent.

UTC+05:30 — TimeZone for Chennai, Kolkata, Mumbai, New Delhi.

UTC+05:45 — TimeZone for Kathmandu.

UTC+06:00 — TimeZone for Dhaka, Astana, Ekaterinburg.

UTC+06:30 — TimeZone for Yangon (Rangoon).

UTC+07:00 — TimeZone for Novosibirsk, Bangkok, Hanoi, Jakarta.

UTC+08:00 — TimeZone for Beijing, Chongqing, Hong Kong, Urumqi, Singapore.

UTC+09:00 — TimeZone for Seoul, Irkutsk, Osaka, Sapporo, Tokyo.

UTC+09:30 — TimeZone for Darwin, Adelaide.

UTC+10:00 — TimeZone for Canberra, Melbourne, Sydney, Brisbane.

UTC+11:00 — TimeZone for Solomon Is., New Caledonia, Vladivostok.

UTC+12:00 — TimeZone for Fiji, Magadan, Auckland, Wellington.

UTC+13:00 — TimeZone for Nuku'alofa, Samoa.

ntp-server: Specify the IP address of the primary NTP server.

backup-ntp-server: Specify the IP address of the backup NTP server.

fetching-rate: Specify the interval for fetching time from the NTP server.

Step 3 Use the following command to verify the system time information.

show system-time

Verify the system time information.

Use the following command to verify the NTP mode configuration information.

show system-time ntp

Verify the system time information of NTP mode.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the system time by Get Time from NTP Server and set the time zone as UTC+08:00, set the NTP server as 133.100.9.2, set the backup NTP server as 139.78.100.163 and set the update rate as 11.

Switch#configure

Switch(config)#system-time ntp UTC+08:00 133.100.9.2 139.78.100.163 11

Switch(config)#show system-time ntp

Backup NTP server: 139.78.100.163

Last successful NTP server: 133.100.9.2

Update Rate: 11 hour(s)

Switch(config)#end

Switch#copy running-config startup-config

2.2.4 Configuring the Daylight Saving Time

Follow these steps to configure the Daylight Saving Time:

Step 1 configure

Enter global configuration mode.

Step 2 Use the following command to select a predefined Daylight Saving Time configuration:

system-time dst predefined [USA | Australia | Europe | New-Zealand]

Specify the Daylight Saving Time using a predefined schedule.

USA | Australia | Europe | New-Zealand: Select one mode of Daylight Saving Time.

USA: 02:00 a.m. on the Second Sunday in March \~ 02:00 a.m. on the First Sunday in November.

Australia: 02:00 a.m. on the First Sunday in October ~ 03:00 a.m. on the First Sunday in April.

Europe: 01:00 a.m. on the Last Sunday in March ~ 01:00 a.m. on the Last Sunday in October.

New Zealand: 02:00 a.m. on the Last Sunday in September ~ 03:00 a.m. on the First Sunday in April.

Use the following command to set the Daylight Saving Time in recurring mode:

system-time dst recurring {sweek}{sday}{smonth}{stime}{eweek}{eday}{emonth}{etime}[offset]

Specify the Daylight Saving Time in recurring mode.

sweek: Enter the start week of Daylight Saving Time. There are 5 values showing as follows: first, second, third, fourth, last.

sday: Enter the start day of Daylight Saving Time. There are 7 values showing as follows: Sun, Mon, Tue, Wed, Thu, Fri, Sat.

smonth: Enter the start month of Daylight Saving Time. There are 12 values showing as follows: Jan, Feb, Mar, Apr, May, Jun, Jul, Aug, Sep, Oct, Nov, Dec.

stime: Enter the start time of Daylight Saving Time, in the format of HH:MM.

eweek: Enter the end week of Daylight Saving Time. There are 5 values showing as follows: first, second, third, fourth, last.

eday: Enter the end day of Daylight Saving Time. There are 7 values showing as follows: Sun, Mon, Tue, Wed, Thu, Fri, Sat.

emonth: Enter the end month of Daylight Saving Time. There are 12 values showing as follows: Jan, Feb, Mar, Apr, May, Jun, Jul, Aug, Sep, Oct, Nov, Dec.

etime: Enter the end time of Daylight Saving Time, in the format of HH:MM.

offset: Enter the offset of Daylight Saving Time. The default value is 60.

Use the following command to set the Daylight Saving Time in date mode:

system-time dst date {smonth } {sday } {stime } {syear } {emonth } {eday } {etime } {eyear } [ offset]

Specify the Daylight Saving Time in Date mode.

smonth: Enter the start month of Daylight Saving Time. There are 12 values showing as follows: Jan, Feb, Mar, Apr, May, Jun, Jul, Aug, Sep, Oct, Nov, Dec.

sday: Enter the start day of Daylight Saving Time, which ranges from 1 to 31.

stime: Enter the start time of Daylight Saving Time, in the format of HH:MM.

syear: Enter the start year of Daylight Saving Time.

emonth: Enter the end month of Daylight Saving Time. There are 12 values showing as follows: Jan, Feb, Mar, Apr, May, Jun, Jul, Aug, Sep, Oct, Nov, Dec.

eday: Enter the end day of Daylight Saving Time, which ranges from 1 to 31.

etime: Enter the end time of Daylight Saving Time, in the format of HH:MM.

eyear: Enter the end year of Daylight Saving Time.

offset: Enter the offset of Daylight Saving Time. The default value is 60.

Step 3: show system-time dst

Verify the DST information of the switch.

Step 4: end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the Daylight Saving Time by Date Mode. Set the start time as 01:00 August 1st, 2017, set the end time as 01:00 September 1st, 2017 and set the offset as 50.

Switch#configure

Switch(config)#system-time dst date Aug 1 01:00 2017 Sep 1 01:00 2017 50

Switch(config)#show system-time dst

DST starts at 01:00:00 on Aug 1 2017

DST ends at 01:00:00 on Sep 1 2017

DST offset is 50 minutes

DST configuration is one-off

Switch(config)#end

Switch#copy running-config startup-config

2.2.5 Configuring LED (Only for Certain Devices)

TP-LINK Omada Pro S5500-24GP4F - Configuring LED (Only for Certain Devices) - 1

Note:

LED configuration is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If LED configuration is available, there is SYSTEM > LED On/Off in the menu structure.

Follow these steps to configure the LED status:

Step 1 configure

Enter global configuration mode.

Step 2 led {on | off}

Configure the LED status. By default, the LEDs are on.

on | off: Turn on or turn off the LEDs.

3 User Management Configurations

You can create and manage accounts with different access levels to prevent settings from being changed by unauthorized individuals.

3.1 Using the GUI

There are four types of user accounts with different access levels: Admin, Operator, Power User and User.

■ There is a default Admin account which cannot be deleted. The default username and password of this account are both admin. You can also create more Admin accounts. If you create Operator, Power User or User accounts, you need go to the AAA section to create an Enable Password. If needed, these types of users can use the Enable Password to change their access level to Admin.

3.1.1 Creating Accounts

Choose the menu SYSTEM > User Management > User Config to load the following page.

Figure 3-1 User Config PageUser Config User ID Username Access Level Operation 1 admin Admin Total: 1

By default, there is a default Admin account in the table. You can click to edit this Admin account but you cannot delete it.

You can create new user accounts. Click and the following window will pop up.

Figure 3-2 Adding AccountUser Username: (1-16 characters) Access Level: User Password (6-31 characters) Confirm Password: (6-31 characters) Cancel Create

Follow these steps to create a new user account.

1) Configure the following parameters:

Username: Specify a username for the account. It should contain 16 characters at most, and be composed of digits, English letters and underscores only.

Access Level: Select the access level. There are four options provided:

Admin: Admins are able to view and modify all function settings.

Operator: Operators are able to view and modify most function settings.

Power User: Power Users are able to view and modify limited function settings.

User: Users are able only to view function settings without the permission to modify them.

Password: Specify a password for the account.

Confirm

Password

Retype the password.

2) Click Create.

3.1.2 Configuring Enable Password

Choose the menu SECURITY > AAA > Global Config to load the following page.

Figure 3-3 Configure Enable PasswordEnable Admin Enable Admin: ○ Clear Password ● Set Password Password: (1-31 characters) Apply

Follow these steps to configure Enable Password:

1) Select Set Password and specify the enable password in the Password field. It should be a string with 31 characters at most, which can contain only English letters (case-sensitive), digits and 17 kinds of special characters. The special characters are !\$%'()*,-./[]_{I}.

2) Click Apply.

Tips:

The logged-in users can enter the Enable Password on this page to get the administrative privileges.

3.2 Using the CLI

There are four types of user accounts with different access levels: Admin, Operator, Power User and User.

■ There is a default Admin account which cannot be deleted. The default username and password of this account are both admin. You can also create more Admin accounts. If you create Operator, Power User or User accounts, you need go to the AAA section to create an Enable Password. If needed, these types of users can use the Enable Password to change their access level to Admin.

3.2.1 Creating Accounts

Follow these steps to create an account:

Step 1 configure

Enter global configuration mode.

Step 2 Use the following command to create an account unencrypted or symmetric encrypted.

user name name { privilege admin | operator | power_user | user } password { [0] password | 7 encrypted-password }

name: Enter a user name for users' login. It contains 16 characters at most, composed of digits, English letters and symbols. No spaces, question marks and double quotation marks are allowed.

admin | operator | power_user | user: Specify the access level for the user. Admin can edit, modify and view all the settings of different functions. Operator can edit, modify and view mostly the settings of different functions. Power User can edit, modify and view some of the settings of different functions. User can only view the settings without the right to edit and modify.

0: Specify the encryption type. 0 indicates that the password you entered is unencrypted, and the password is saved to the configuration file unencrypted. By default, the encryption type is 0.

password: Enter a password for users' login. It contains 6–31 alphanumeric characters (case-sensitive) and symbols. No spaces are allowed.

7: Specify the encryption type. 7 indicates that the password you entered is symmetric encrypted, and the password is saved to the configuration file symmetric encrypted.

encrypted-password: Enter a symmetric encrypted password with fixed length, which you can copy from another switch's configuration file. After the encrypted password is configured, you should use the corresponding unencrypted password to reenter this mode.

Use the following command to create an account MD5 encrypted.

user name name { privilege admin | operator | power_user | user } secret { [0] password | 5 encrypted-password }

Create an account whose access level is Admin.

name: Enter a user name for users' login. It contains 16 characters at most, composed of digits, English letters and symbols. No spaces, question marks and double quotation marks are allowed.

admin | operator | power_user | user: Specify the access level for the user. Admin can edit, modify and view all the settings of different functions. Operator can edit, modify and view mostly the settings of different functions. Power User can edit, modify and view some of the settings of different functions. User can only view the settings without the right to edit and modify.

0: Specify the encryption type. 0 indicates that the password you entered is unencrypted, but the password is saved to the configuration file MD5 encrypted. By default, the encryption type is 0.

password: Enter a password for users' login. It contains 6–31 alphanumeric characters (case-sensitive) and symbols. No spaces are allowed.

5: Specify the encryption type. 5 indicates that the password you entered is MD5 encrypted, and the password is saved to the configuration file MD5 encrypted.

encrypted-password: Enter a MD5 encrypted password with fixed length, which you can copy from another switch's configuration file.

Step 3 show user account-list

Verify the information of the current users.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

3.2.2 Configuring Enable Password

Follow these steps to create an account of other type:

Step 1 configure

Enter global configuration mode.

Step 2 Use the following command to create an enable password unencrypted or symmetric encrypted.

enable admin password { [0]password | 7 encrypted-password }

Create an Enable Password. It can change the users' access level to Admin. By default, it is empty.

0: Specify the encryption type. 0 indicates that the password you entered is unencrypted, and the password is saved to the configuration file unencrypted. By default, the encryption type is 0.

password: Enter an enable password. It is a string with 31 characters at most, which can contain only English letters (case-sensitive), digits and 17 kinds of special characters. The special characters are !\$%'()*,-./[]_{}.

7: Specify the encryption type. 7 indicates that the password you entered is symmetric encrypted, and the password is saved to the configuration file symmetric encrypted.

encrypted-password: Enter a symmetric encrypted password with fixed length, which you can copy from another switch's configuration file. After the encrypted password is configured, you should use the corresponding unencrypted password to reenter this mode.

Use the following command to create an enable password unencrypted or MD5 encrypted.

enable admin secret { [0] password | 5 encrypted-password }

Create an Enable Password. It can change the users' access level to Admin. By default, it is empty.

0: Specify the encryption type. 0 indicates that the password you entered is unencrypted, but the password is saved to the configuration file MD5 encrypted. By default, the encryption type is 0.

password: Enter an enable password. It is a string with 31 characters at most, which can contain only English letters (case-sensitive), digits and 17 kinds of special characters. The special characters are !\$%'()*,-./[]_{}.

5: Specify the encryption type. 5 indicates that the password you entered is MD5 encrypted, and the password is saved to the configuration file MD5 encrypted.

encrypted-password: Enter a MD5 encrypted password with fixed length, which you can copy from another switch's configuration file. After the encrypted password is configured, you should use the corresponding unencrypted password to reenter this mode.

Step 3 show user account-list

Verify the information of the current users.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

Tips:

The logged-in users can enter the enable-admin command and the Enable Password to get the administrative privileges.

The following example shows how to create a user with the access level of Operator, set the username as user1 and password as 123, and set the enable password as abc123.

Switch#config

Switch(config)#user name user1 privilege operator password 123

Switch(config)#enable admin password abc123

Switch(config)#show user account-list

IndexUser-NameUser-Type
------------
1user1Operator
2adminAdmin

Switch(config)#end

Switch#copy running-config startup-config

4 System Tools Configurations

With System Tools, you can:

■ Configure the boot file ■ Restore the configuration of the switch ■ Back up the configuration file ■ Upgrade the firmware ■ Configure the Hot Patch ■ Configure DHCP Auto Install ■ Reboot the switch ■ Reset the switch

4.1 Using the GUI

4.1.1 Configuring the Boot File

Choose the menu SYSTEM > System Tools > Boot Config to load the following page.

Figure 4-1 Configuring the Boot File

Boot Config

UnitCurrent Startup ImageNext Startup ImageBackup ImageCurrent Startup ConfigNext Startup ConfigBackup Config
1image1.binimage1.binimage2.binconfig1.cfgconfig1.cfgconfig2.cfg
Total: 1

Restore

Image Table

UNIT1
Current Startup Image
Image Name:image1.bin
Software Version:1.0.0
Flash Version:1.3.0
Next Startup Image
Image Name:image1.bin
Software Version:1.0.0
Flash Version:1.3.0
Backup Image
Image Name:image2.bin
Software Version:1.0.0
Flash Version:1.3.0

Follow these steps to configure the boot file:

1) In the Boot Config section, select one or more units and configure the relevant parameters.

Unit Displays the number of the unit.
Current Startup ImageDisplays the current startup image.
Next Startup ImageSelect the next startup image. When the switch is powered on, it will try to start up with the next startup image. The next startup and backup image should not be the same.
Backup ImageSelect the backup image. When the switch fails to start up with the next startup image, it will try to start up with the backup image. The next startup and backup image should not be the same.
Current Startup ConfigDisplays the current startup configuration.
Next Startup ConfigSpecify the next startup configuration. When the switch is powered on, it will try to start up with the next startup configuration. The next startup configuration and backup configuration should not be the same.
Backup ConfigSpecify the backup configuration. When the switch fails to start up with the next startup configuration, it will try to start up with the backup configuration. The next startup and backup configuration should not be the same.

2) Click Apply.

In the Image Table, you can view the information of the current startup image, next startup image and backup image. Click your desired image type and the following information will be displayed:

Image Name Displays the name of the image.

Software Version

Displays the software version of the image.

Flash Version Displays the flash version of the image.

4.1.2 Restoring the Configuration of the Switch

Choose the menu SYSTEM > System Tools > Restore Config to load the following page.

Figure 4-2 Restoring the Configuration of the SwitchRestore Config Restore the configurations using a saved configuration file. Target Unit: All Unit Configuration File: Browse □ Reboot the switch to validate the configuration after the restore is complete. Import

Follow these steps to restore the current configuration of the switch:

1) In the Restore Config section, select the unit to be restored. 2) Click Browse and select the desired configuration file to be imported. 3) Choose whether to reboot the switch after restoring is completed. Only after the switch is rebooted will the imported configuration take effect. 4) Click Import to import the configuration file.

TP-LINK Omada Pro S5500-24GP4F - Restoring the Configuration of the Switch - 2

Note:

It will take some time to restore the configuration. Please wait without any operation.

4.1.3 Backing up the Configuration File

Choose the menu SYSTEM > System Tools > Backup Config to load the following page.

Figure 4-3 Backing up the Configuration FileBackup Config Back up the current startup configuration file. Target Unit: All Unit Export

In the Backup Config section, select one unit and click Export to export the configuration file.

TP-LINK Omada Pro S5500-24GP4F - Backing up the Configuration File - 2

Note:

It will take some time to export the configuration. Please wait without any operation.

4.1.4 Upgrading the Firmware

Choose the menu SYSTEM > System Tools > Firmware Upgrade to load the following page.

Figure 4-4 Upgrading the FirmwareFirmware Upgrade You can upgrade the firmware of the switch using the new upgrade file. Firmware Version: 1.0.0 Build 20230628 Rel.306 Hardware Version: S5500-24GP4XF 1.0 Image Name: Backup Image Firmware File: Browse □ Reboot the switch using the backup image after upgrading is completed. Upgrade

You can view the current firmware information on this page:

Firmware Version: Displays the current firmware version of the system.

Hardware Version: Displays the current hardware version of the system.

Image Name

Displays the image to upgrade. The operation will only affect the image displayed here.

Follow these steps to upgrade the firmware of the switch:

1) Click Browse and select the proper firmware upgrade file. 2) Choose whether to reboot the switch after upgrading is completed. Only after the switch is rebooted will the new firmware take effect.

3) Click Upgrade to upgrade the system.

TP-LINK Omada Pro S5500-24GP4F - 3) Click Upgrade to upgrade the system. - 1

Note:

• It is recommended to back up the configurations before upgrading. - Select the appropriate upgrade software version that matches your hardware. • To avoid damage, DO NOT turn off the device while upgrading.

4.1.5 Loading Patch

Follow these steps to load the patch file from the TFTP server into the system's patch area:

Step 1: patch load flash | usbflash1 | usbflash2 | ip-address

ipaddr filename filename

Load a patch file from a TFTP server into the patch area of the system. The patch is in the deactivated state and has not taken effect.

flash: Load patch from flash.

usbflash1: Load patch from USB1.

usbflash2: Load patch from USB2.

ipaddr: IP address of the TFTP server.

filename: Name of the patch file.

The following example shows how to load the patch file patch.bin from the TFTP server with IP address 192.168.0.146 to the system patch area:

Switch#patch load ip-address 192.168.0.146 filename patch.bin

4.1.6 Activating Patch

Follow these steps to temporarily run the deactivated patch loaded into the system patch area:

Step 1 patch active

Temporarily run a deactivated patch loaded into the system patch area. When a deactivated patch is temporarily run, the patch is activated and takes effect. When the device is restarted, the patch that was activated before the restart will be deactivated. Users can perform the following three operations on the activated patch:

patch run: Change the patch status to running.

patch deactive: Change the patch status to deactivated.

patch delete: Invalidate the patch and delete it from the patch area.

The following example shows how to activate all deactivated patches loaded into the system patch area:

Switch#patch active

4.1.7 Running Patch

Follow these steps to permanently run an activated patch:

Step 1 patch run

Permanently run an activated patch. When an activated patch is permanently run, the patch is in the running state. When the device is restarted, the patch that was in the running state before the restart will remain in the running state and take effect. Users can perform the following two operations on the running patch:

patch uninstall: Return the patch from the running state to the activated state.

patch delete: Invalidate the patch and delete it from the patch area.

The following example shows how to permanently run an activated patch:

Switch#patch run

4.1.8 Deactivating Patch

Follow these steps to deactivate an activated patch:

Step 1 patch deactive

Deactivate an activated patch

The following example shows how to deactivate an activated patch:

Switch#patch deactive

4.1.9 Uninstalling Running Patch

Follow these steps to uninstall a running patch and activate it:

Step 1 patch uninstall

Uninstall a running patch and activate it.

The following example shows how to uninstall a running patch and activate it:

Switch#patch uninstall

4.1.10 Deleting Patch

Follow these steps to delete a patch in the deactivated, activated, or running state, invalidating the patch and deleting the patch file from the system patch area:

Step 1 patch delete

Delete a patch in the deactivated, activated, or running state, invalidating the patch and deleting the patch file from the system patch area.

The following example shows how to delete a patch:

Switch#patch delete

4.1.11 Viewing Patch Info

Follow these steps to view the patch information of the current system:

Step 1: Show patch information.

View the patch information of the current system.

The following example shows how to view the patch information of the current system:

Switch#show patch information

4.1.12 Configuring DHCP Auto Install (Only for Certain Devices)

TP-LINK Omada Pro S5500-24GP4F - Configuring DHCP Auto Install (Only for Certain Devices) - 1

Note:

DHCP Auto Install is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If DHCP Auto Install is available, there is SYSTEM > System Tools > DHCP Auto Install in the menu structure.

This feature is used to download configuration files and images from the TFTP server automatically. It requires a TFTP server and a DHCP server that supports option 67, 125, and 150 on your network. When Auto Install function starts, the switch tries to get configuration file name, image file path, and TFTP server IP address from the DHCP server, and then downloads the new image and configuration file from the TFTP server.

The downloaded configuration file can be saved as a startup configuration file and the downloaded image will update the backup image of the switch.

Choose the menu SYSTEM > System Tools > DHCP Auto Install to load the following page.

Figure 4-5 Configuring DHCP Auto InstallDHCP Auto Install DHCP Auto Install: Enable Auto Install Persistent Mode: Enable Auto Save Mode: Enable Auto Reboot Mode: Enable Auto Install Retry Count: 1 (1-3) Auto Install State: Stopped Apply

Configure the following parameters and click Apply:

DHCP Auto Install Enable or disable DHCP Auto Install.
Auto InstallPersistent ModeEnable or disable Auto Install Persistent Mode. With this mode enabled, the switch will start Auto Install progress once the switch has rebooted.
Auto Save ModeEnable or disable Auto Save Mode. With this mode enabled, the downloaded configuration file will be saved as the startup configuration file. The downloaded configuration will be effective after the next reboot.
Auto Reboot ModeEnable or disable Auto Reboot Mode. With this mode enabled, the switch will reboot automatically once the auto install process is complete.
Auto Install Retry CountSpecify how many times the switch can try to get the configuration file or image file from the TFTP server in one cycle. If the number of tries has reached this limit, the switch will wait for 10 minutes before trying to get the files again. This process will be repeated until the switch succeeds in getting either the image file or configuration file, or until you stop Auto Install manually.

Auto Install State: Displays the status of the Auto Install process.

For configuration example and detailed instructions, refer to FAQ.

TP-LINK Omada Pro S5500-24GP4F - For configuration example and detailed instructions, refer to FAQ. - 1

Note:

• If Auto Install fails to get the configuration file, this procedure will be retried every 10 minutes. - If DHCP Auto Install is enabled and there is no layer 3 interface whose IP address mode is DHCP, the switch will choose a layer 3 interface and change its IP address mode to DHCP.

4.1.13 Rebooting the switch

There are two methods to reboot the switch: manually reboot the switch and configure reboot schedule to automatically reboot the switch.

Manually Rebooting the Switch

Choose the menu SYSTEM > System Tools > System Reboot > System Reboot to load the following page.

Figure 4-6 Manually Rebooting the SwitchSystem Reboot Target Unit: All Unit Save the current configuration before reboot Reboot

Follow these steps to reboot the switch:

1) In the System Reboot section, select the desired unit. 2) Choose whether to save the current configuration before reboot. 3) Click Reboot.

TP-LINK Omada Pro S5500-24GP4F - Manually Rebooting the Switch - 2

Note:

• To avoid damage, DO NOT turn off the device while rebooting.

Configuring Reboot Schedule

Choose the menu SYSTEM > System Tools > System Reboot > Reboot Schedule to load the following page.

Figure 4-7 Configuring the Reboot ScheduleReboot Schedule Config Reboot Schedule Enable Time Interval: 360 minutes (1-43200) Special Time: Month Day Year Time (HH:MM) January 1 2000 Save the current configuration before reboot Apply

Follow these steps to configure the reboot schedule:

1) Enable Reboot Schedule, and select one time schedule for the switch to reboot.

Time IntervalSpecify the time interval when the switch will be rebooted. The switch will reboot after this period. Valid values are from 1 to 43200 minutes.To make this schedule recur, you need to clickSave to save current configuration or enable the optionSave the current configuration before reboot.
Special Time Specify the date and time for the switch to reboot.Month/Day/Year: Specify the date for the switch to reboot.Time (HH:MM): Specify the time for the switch to reboot, in the format of HH:MM.
Save the current configuration before rebootSelect whether the configuration of the switch will be saved before reboot.

2) Choose whether to save the current configuration before the reboot. 3) Click Apply.

Tips:

To delete the reboot schedule configurations, you can click Delete and the configurations will be empty.

4.1.14 Resetting the Switch

Choose the menu SYSTEM > System Tools > System Reset to load the following page.

Figure 4-8 Resetting the SwitchSystem Reset Target Unit: All Units Maintain the IP Address Reset

Follow these steps to reset the switch:

1) In the System Reset section, select the desired unit. 2) Choose whether to maintain the IP address of selected unit when resetting. 3) Click Reset.

After reset, all configurations of the switch will be reset to the factory defaults.

TP-LINK Omada Pro S5500-24GP4F - Resetting the Switch - 2

Note:

  • System Reset will restore the system to the factory defaults and your current settings will be lost. • To maintain the IP address of the selected unit when resetting, enable Maintain the IP Address.

4.2 Using the CLI

4.2.1 Configuring the Boot File

Follow these steps to configure the boot file:

Step 1configure
Enter global configuration mode.
Step 2boot application filename {image1|image2}{startup|backup}Specify the configuration of the boot file. By default, image1.bin is the startup image and image2.bin is the backup image.image1|image2: Select the image file to be configured.startup|backup: Select the property of the image file.
Step 3boot config filename {config1|config2}{startup|backup}Specify the configuration of the boot file. By default, config1.cfg is the startup configuration file and config2.cfg is the backup configuration file.config1|config2: Select the configuration file to be configured.startup|backup: Specify the property of the configuration file.
Step 4show bootVerify the boot configuration of the system.
Step 5endReturn to privileged EXEC mode.
Step 6copy running-config startup-configSave the settings in the configuration file.

The following example shows how to set the next startup image as image1, the backup image as image2, the next startup configuration file as config1 and the backup configuration file as config2.

Switch#configure

Switch(config)#boot application filename image1 startup

Switch(config)#boot application filename image2 backup

Switch(config)#boot config filename config1 startup

Switch(config)#boot config filename config2 backup

Switch(config)#show boot

Boot config:

Current Startup Image - image2.bin

Next Startup Image - image1.bin

Backup Image - image2.bin

Current Startup Config - config2.cfg

Next Startup Config - config1.cfg

Backup Config - config2.cfg

Switch(config)#end

Switch#copy running-config startup-config

4.2.2 Restoring the Configuration of the Switch

Follow these steps to restore the configuration of the switch:

Step 1 enable

Enter privileged mode.

Step 2 copy tftp startup-config ip-address

ip-addr filename name

Download the configuration file to the switch from TFTP server.

ip-addr: Specify the IP address of the TFTP server. Both IPv4 and IPv6 addresses are supported.

name: Specify the name of the configuration file to be downloaded.

TP-LINK Omada Pro S5500-24GP4F - Restoring the Configuration of the Switch - 1

Note:

It will take some time to restore the configuration. Please wait without any operation.

The following example shows how to restore the configuration file named file1 from the TFTP server with IP address 192.168.0.100.

Switch>enable

Switch#copy tftp startup-config ip-address 192.168.0.100 filename file1

Start to load user config file...

Operation OK! Now rebooting system...

4.2.3 Backing up the Configuration File

Follow these steps to back up the current configuration of the switch in a file:

Step 1 enable

Enter privileged mode.

Step 2 copy startup-config tftp ip-address ip-addr filename name

Back up the configuration file to TFTP server.

ip-addr: Specify the IP address of the TFTP server. Both IPv4 and IPv6 addresses are supported.

name: Specify the name of the configuration file to be saved.

The following example shows how to backup the configuration file named file2 to TFTP server with IP address 192.168.0.100.

Switch>enable

Switch#copy startup-config tftp ip-address 192.168.0.100 filename file2

Start to backup user config file...

Backup user config file OK.

4.2.4 Upgrading the Firmware

Follow these steps to upgrade the firmware:

Step 1 enable

Enter privileged mode.

Step 2 firmware upgrade tftp ip-address ip-addr filename name

Upgrade the switch's backup image via TFTP server. To boot up with the new firmware, you need to choose to reboot the switch with the backup image.

ip-addr: Specify the IP address of the TFTP server. Both IPv4 and IPv6 addresses are supported.

name: Specify the name of the desired firmware file.

Step 3 Enter Y to continue and then enter Y to reboot the switch with the backup image.

The following example shows how to upgrade the firmware using the configuration file named file3.bin. The TFTP server is 190.168.0.100.

Switch>enable

Switch#firmware upgrade tftp ip-address 192.168.0.100 filename file3.bin

It will only upgrade the backup image. Continue? (Y/N):Y

Operation OK!

Reboot with the backup image? (Y/N): Y

4.2.5 Loading Patch

Follow these steps to load the patch file from the TFTP server into the system's patch area:

Step 1: patch load ip-address

ipaddr filename filename

Load a patch file from a TFTP server into the patch area of the system. The patch is in the deactivated state and has not taken effect.

ipaddr: IP address of the TFTP server.

filename: Name of the patch file.

The following example shows how to load the patch file patch.bin from the TFTP server with IP address 192.168.0.146 to the system patch area:

Switch#patch load ip-address 192.168.0.146 filename patch.bin

4.2.6 Activating Patch

Follow these steps to temporarily run the deactivated patch loaded into the system patch area:

Step 1: patch active

Temporarily run a deactivated patch loaded into the system patch area. When a deactivated patch is temporarily run, the patch is activated and takes effect. When the device is restarted, the patch that was activated before the restart will be deactivated. Users can perform the following three operations on the activated patch:

patch run: Change the patch status to running.

patch deactive: Change the patch status to deactivated.

patch delete: Invalidate the patch and delete it from the patch area.

The following example shows how to activate all deactivated patches loaded into the system patch area:

Switch#patch active

4.2.7 Running Patch

Follow these steps to permanently run an activated patch:

Step 1 patch run

Permanently run an activated patch. When an activated patch is permanently run, the patch is in the running state. When the device is restarted, the patch that was in the running state before the restart will remain in the running state and take effect. Users can perform the following two operations on the running patch:

patch uninstall: Return the patch from the running state to the activated state.

patch delete: Invalidate the patch and delete it from the patch area.

The following example shows how to permanently run an activated patch:

Switch#patch run

4.2.8 Deactivating Patch

Follow these steps to deactivate an activated patch:

Step 1 patch deactive

Deactivate an activated patch

The following example shows how to deactivate an activated patch:

Switch#patch deactive

4.2.9 Uninstalling Running Patch

Follow these steps to uninstall a running patch and activate it:

Step 1 patch uninstall

Uninstall a running patch and activate it.

The following example shows how to uninstall a running patch and activate it:

Switch#patch uninstall

4.2.10 Deleting Patch

Follow these steps to delete a patch in the deactivated, activated, or running state, invalidating the patch and deleting the patch file from the system patch area:

Step 1 patch delete

Delete a patch in the deactivated, activated, or running state, invalidating the patch and deleting the patch file from the system patch area.

The following example shows how to delete a patch:

Switch#patch delete

4.2.11 Viewing Patch Info

Follow these steps to view the patch information of the current system:

Step 1 show patch information

View the patch information of the current system.

The following example shows how to view the patch information of the current system:

Switch#show patch information

4.2.12 Upgrading the MCU-Firmware

Follow these steps to upgrade the MCU-firmware:

Step 1 enable

Enter privileged mode.

Step 2 mcu-firmware unit

unit id type mcu-type upgrade

Upgrade the switch's MCU-firmware online.

unit id: Stack unit ID, ranging from 1 to 4.

mcu-type: MCU device type, which can be pse, crps, fan, monitor.

Step 3 mcu-firmware type

mcu-type version

View the MCU version information.

mcu-type: MCU device type, which can be pse, crps, fan, monitor.

4.2.13 Configuring DHCP Auto Install (Only for Certain Devices)

TP-LINK Omada Pro S5500-24GP4F - Configuring DHCP Auto Install (Only for Certain Devices) - 1

Note:

DHCP Auto Install is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If DHCP Auto Install is available, there is SYSTEM > System Tools > DHCP Auto Install in the menu structure.

This feature is used to download configuration files and images from the TFTP server automatically. It requires a TFTP server and a DHCP server that supports option 67, 125 and 150 on your network. When Auto Install function starts, the switch tries to get configuration file name, image file path and TFTP server IP address from the DHCP server, and then downloads the new image and configuration file form the TFTP server.

Follow these steps to configure the DHCP Auto Install.

Step 1 configure

Enter global configuration mode.

Step 2 boot autoinstall persistent-mode

Enable the auto install persistent mode. After saving configuration, the switch will start the Auto Install function automatically during next reboot process.

Step 3 boot autoinstall auto-save

Enable the auto save mode and the switch will save the configuration file downloaded as startup configuration file automatically.

Step 4 boot autoinstall auto-reboot

Enable the auto reboot mode and the switch will reboot automatically after the auto install process is completed successfully.

Step 5 boot autoinstall retry-count count

Specify the auto install retry count which ranges from 1 to 3. The default value is 1.

Step 6 boot autoinstall start

Start the Auto Install process and the switch will download the configuration file and the backup image automatically.

Step 7 end

Return to privileged EXEC mode.

Step 8 copy running-config startup-config

Save the settings in the configuration file.

TP-LINK Omada Pro S5500-24GP4F - Step 8 copy running-config startup-config - 1

Note:

• If Auto Install fails to get the configuration file, this procedure will be retried every 10 minutes. - If DHCP Auto Install is enabled and there is no layer 3 interface whose IP address mode is DHCP, the switch will choose a layer 3 interface and change its IP address mode to DHCP.

The following example shows how to configure the Auto Install function.

Switch#configure

Switch(config)#boot autoinstall persistent-mode

Switch(config)#boot autoinstall auto-save

Switch(config)#boot autoinstall auto-reboot

Switch(config)#boot autoinstall retry-count 2

Switch(config)#show boot autoinstall

Auto Install Mode......Stop

Auto Install Persistent Mode......Enabled

Auto Save Mode......Enabled

Auto Reboot Mode......Enabled

Auto Install Retry Count......2

Auto Install State......Stopped

4.2.14 Creating Checkpoint File

Follow these steps to create a checkpoint file:

Step 1 checkpoint file

fileName

no checkpoint file fileName

Create a checkpoint file. When creating a checkpoint file, it snapshots the current configuration. When deleting a checkpoint file, specify the filename for deletion. Note that after performing a device reset operation, all checkpoint files will be cleared. To delete a checkpoint file, please use the no checkpoint file command.

fileName: Checkpoint file name, in the format of letters, numbers, underscores, hyphens and dots, and the length is limited to 1 to 32 characters. For example: hello_2024-01.cfg

The following example shows how to create a checkpoint file named "hello2024" for the current configuration:

Switch#checkpoint file hello2024

4.2.15 Viewing Checkpoint File

Follow these steps to view the checkpoint files:

Step 1 show checkpoint

show checkpoint file fileName

View the names of all existing checkpoint files, or view all configuration information in a specific checkpoint file.

fileName: Checkpoint file name, in the format of letters, numbers, underscores, hyphens and dots, and the length is limited to 1 to 32 characters. fileName must be the name of an existing file in the show checkpoint command execution result.

The following example shows how to view the configuration information in the checkpoint file named "hello2024":

Switch#show checkpoint file hello2024

4.2.16 Rolling Back Configuration

Follow these steps to roll back the configuration of the switch to the configuration in an existing checkpoint file:

Step 1 rollback running-config file

fileName

Roll back the configuration of the switch to the configuration in an existing checkpoint file.

fileName: Checkpoint file name, in the format of letters, numbers, underscores, hyphens and dots, and the length is limited to 1 to 32 characters. fileName must be the name of an existing file in the show checkpoint command execution result.

The following example shows how to roll back the configuration of the switch to the configuration in the checkpoint file named "hello2024":

Switch#rollback running-config file hello2024

4.2.17 Rebooting the Switch

Manually Rebooting the Switch

Follow these steps to reboot the switch:

Step 1 enable

Enter privileged mode.

Step 2 reboot

Reboot the switch.

Configuring Reboot Schedule

Follow these steps to configure the reboot schedule:

Step 1 configure

Enter global configuration mode.

Step 2 Use the following command to set the interval of reboot:

reboot-schedule in interval [ save_before_reboot ]

(Optional) Specify the reboot schedule.

interval: Specify a period of time. The switch will reboot after this period. The valid values are from 1 to 43200 minutes.

save_before_reboot: Save the configuration file before the switch reboots. To make this schedule recur, you can add this part to the command.

Use the following command to set the special time of reboot:

reboot-schedule at time [date] [save_before_reboot]

(Optional) Specify the reboot schedule.

time: Specify the time for the switch to reboot, in the format of HH:MM.

date: Specify the date for the switch to reboot, in the format of DD/MM/YYYY. The date should be within 30 days.

save_before_reboot: Save the configuration file before the switch reboots.

If no date is specified, the switch will reboot according to the time you have set. If the time you set is later than the time that this command is executed, the switch will reboot later the same day; otherwise the switch will reboot the next day.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the switch to reboot at 12:00 on 15/08/2017.

Switch#configure

Switch(config)#reboot-schedule at 12:00 15/08/2017 save_before_reboot

Reboot system at 15/08/2017 12:00. Continue? (Y/N): Y

Reboot Schedule Settings

Reboot schedule at 2017-08-15 12:00 (in 25582 minutes)

Save before reboot: Yes

Switch(config)#end

Switch#copy running-config startup-config

4.2.18 Resetting the Switch

Follow these steps to reset the switch:

Step 1 enable

Enter privileged mode.

Step 2 reset [except-ip]

Reset the switch, and all configurations of the switch will be reset to the factory defaults.

except-ip: To maintain the IP address when resetting the switch, add this part to the command.

Follow these steps to disable the reset function of console port or reset button:

Step 1 configure

Enter global configuration mode.

Step 2 service reset-disable

Disable the reset function of console port or reset button. By default, the reset function is enabled.

Note: use the no service reset-disable command to enable the reset function of console port.

5 EEE Configuration

Choose the menu SYSTEM > EEE to load the following page.

Figure 5-1 Configuring EEETP-LINK Omada Pro S5500-24GP4F - EEE Configuration - 1

Follow these steps to configure EEE:

1) In the EEE Config section, select one or more ports to be configured. 2) Enable or disable EEE on the selected port(s). 3) Click Apply.

5.1 Using the CLI

Follow these steps to configure EEE:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list } Enter interface configuration mode.

Step 3 eee

Enable EEE on the port.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the EEE feature on port 1/0/1.

Switch#config

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#eee

Switch(config-if)#show interface eee

Port EEE status

Gi1/0/1 Enable

Gi1/0/2 Disable

...

Switch(config-if)#end

Switch#copy running-config startup-config

6 PoE Configurations (Only for Certain Devices)

TP-LINK Omada Pro S5500-24GP4F - PoE Configurations (Only for Certain Devices) - 1

Note:

PoE configuration is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If PoE configuration is available, there is SYSTEM > PoE in the menu structure.

With the PoE feature, you can:

■ Configure the PoE parameters manually ■ Configure the PoE parameters using the profile ■ Configure the PoE Auto Recovery parameters manually

You can configure the PoE parameters one by one via configuring the PoE parameters manually. You can also set a profile with the desired parameters and bind the profile to the corresponding ports to quickly configure the PoE parameters. PoE Auto Recovery uses ping packets to detect the link status between PoE ports and connected PoE powered devices (PDs). The switch pings the IP addresses of PDs constantly. If a PD loses connection, the switch will reboot it automatically.

6.1 Using the GUI

6.1.1 Configuring the PoE Parameters Manually

Choose the menu SYSTEM > PoE > PoE Config to load the following page.

Figure 6-1 Configuring PoE Parameters Manually

PoE Config
UnitSystem Power Limit (W)System Power Consumption (W)System Power Remain (W)Operation
Unit10.00.00.0
Total: 1
Port Config
UNIT1
☐ PortPoE StatusPoE PriorityPower LimitPower Limit Value (0.1-30.0 W)Time RangePoE ProfilePower (W)Curre
☐ 1/0/1EnabledLowClass430No LimitNone0
☐ 1/0/2EnabledLowClass430No LimitNone0
☐ 1/0/3EnabledLowClass430No LimitNone0
☐ 1/0/4EnabledLowClass430No LimitNone0
☐ 1/0/5EnabledLowClass430No LimitNone0
☐ 1/0/6EnabledLowClass430No LimitNone0
☐ 1/0/7EnabledLowClass430No LimitNone0
☐ 1/0/8EnabledLowClass430No LimitNone0
☐ 1/0/9EnabledLowClass430No LimitNone0
☐ 1/0/1 nEnabledLowClass430No LimitNone0

Follow these steps to configure the basic PoE parameters:

1) In the PoE Config section, you can view the current PoE parameters.

System Power Limit (W)Specify the maximum power the PoE switch can supply.
System Power Consumption (W)Displays the real-time system power consumption of the PoE switch.
System Power Remain (W)Displays the real-time power remained for the connected devices.

In addition, you can click and configure the System Power Limit. Click Apply.

Figure 6-2 Configuring System Power LimitPoE Config Unit: 1 System Power Limit: 800.0 W (1-800) Cancel Save

Unit Displays the unit ID.

System Power Limit Specify the maximum power the PoE switch can supply.

2) In the Port Config section, select the port you want to configure and specify the parameters. Click Apply.

PoE Status Enable or disable the PoE function for the corresponding port. The port can supply power to the PD when its status is enable.
PoE PrioritySelect the priority level for the corresponding port. When the power required exceeds the system power limit, the switch will power off PDs on low-priority ports to ensure stable running of other PDs.
Power Limit Specify the maximum power the port can supply. The following options are provided:Auto: The switch will allocate a value as the maximum power that the port can supply automatically.Class1: The maximum power that the port can supply is 4 W.Class2: The maximum power that the port can supply is 7 W.Class3: The maximum power that the port can supply is 15.4 W.Class4: The maximum power that the port can supply is 30 W.Class5: The maximum power that the port can supply is 45W.Class6: The maximum power that the port can supply is 60W.Manual: Enter a value manually.
Power Limit Value (0.1–30.0 W)If you selectManualas Power Limit mode, specify a maximum power supply value in this field.If you selectClass1toClass4as Power Limit mode, you can view the maximum power supply value in this field.
Time RangeSelect a time range. The port will supply power only during the time range. For how to create a time range, refer toTime Range Configuration.
PoE ProfileA quick configuration method for the corresponding ports. Select a profile to use its preset configurations. You will be unable to modify the PoE status, PoE priority or power limit manually. For how to create a profile, refer to Configuring the PoE Parameters Using the Profile.
Power (W) Displays the real-time power supply of the port.
Current (mA) Displays the real-time current of the port.
Voltage (V) Displays the real-time voltage of the port.
PD Class Displays the class the connected PD belongs to.
Power Status Displays the real-time power status of the port.

6.1.2 Configuring the PoE Parameters Using the Profile

■ Creating a PoE Profile

Choose the menu SYSTEM > PoE > PoE Profile and click + Add to load the following page.

Figure 6-3 Creating a PoE ProfilePoE Profile Config Profile Name: (1-16 characters) PoE Status: Enable Disable PoE Priority: Low Power Limit: Auto Cancel Create

Follow these steps to create a PoE profile:

1) In the PoE Profile Config section, specify the desired configurations of the profile.

Profile Name Specify a name for the PoE profile.
PoE Status Specify the PoE status for the PoE profile.
PoE PrioritySpecify the priority level for the PoE profile. The following options are provided:High, Middle and Low. When the supply power exceeds the system power limit, the switch will power off PDs on low-priority ports to ensure stable running of other PDs.
Power Limit Specify the maximum power the port can supply. The following options are provided:Auto: The switch will allocate a value as the maximum power that the port can supply automatically.Class1: The maximum power that the port can supply is 4W.Class2: The maximum power that the port can supply is 7 W.Class3: The maximum power that the port can supply is 15.4 W.Class4: The maximum power that the port can supply is 30 W.Class5: The maximum power that the port can supply is 45 W.Class6: The maximum power that the port can supply is 60 W.Manual: Enter a value manually.

2) Click Create.

■ Binding the Profile to the Corresponding Ports

Choose the menu SYSTEM > PoE > PoE Config to load the following page.

Figure 6-4 Binding the Profile to the Corresponding Ports

PoE Config
UnitSystem Power Limit (W)System Power Consumption (W)System Power Remain (W)Operation
Unit10.00.00.0
Total: 1
Port Config
UNIT1
☐ PortPoE StatusPoE PriorityPower LimitPower Limit Value (0.1-30.0 W)Time RangePoE ProfilePower (W)Curre
☐ 1/0/1EnabledLowClass430No LimitNone0
☐ 1/0/2EnabledLowClass430No LimitNone0
☐ 1/0/3EnabledLowClass430No LimitNone0
☐ 1/0/4EnabledLowClass430No LimitNone0
☐ 1/0/5EnabledLowClass430No LimitNone0
☐ 1/0/6EnabledLowClass430No LimitNone0
☐ 1/0/7EnabledLowClass430No LimitNone0
☐ 1/0/8EnabledLowClass430No LimitNone0
☐ 1/0/9EnabledLowClass430No LimitNone0
☐ 1/0/1 nEnabledLowClass430No LimitNone0

Follow these steps to bind the profile to the corresponding ports:

1) In the PoE Config section, you can view the current PoE parameters.

System Power Limit (W)Specify the maximum power the PoE switch can supply.
System Power Consumption (W)Displays the real-time system power consumption of the PoE switch.
System Power Remain (W)Displays the real-time power remained for the connected devices.

In addition, you can click and configure the System Power Limit. Click Apply.

Figure 6-5 Configuring System Power LimitPoE Config Unit: 1 System Power Limit: 800.0 W (1-800) Cancel Save

Unit Displays the unit number.

System Power Limit Specify the maximum power the PoE switch can supply.

2) In the Port Config section, select one or more ports and configure the following two parameters: Time Range and PoE Profile. Click Apply and the PoE parameters of the selected PoE Profile, such as PoE Status and PoE Priority, will be displayed in the table.

PoE Status Enable or disable the PoE function for the corresponding port. The port can supply power to the PD when its status is enable.
PoE PrioritySelect the priority level for the corresponding port. When the power required exceeds the system power limit, the switch will power off PDs on low-priority ports to ensure stable running of other PDs.
Power Limit Specify the maximum power the port can supply. The following options are provided:Auto: The switch will allocate a value as the maximum power that the port can supply automatically.Class1: The maximum power that the port can supply is 4W.Class2: The maximum power that the port can supply is 7 W.Class3: The maximum power that the port can supply is 15.4 W.Class4: The maximum power that the port can supply is 30 W.Class5: The maximum power that the port can supply is 45 W.Class6: The maximum power that the port can supply is 60 W.Manual: Enter a value manually.
PowerLimit Value(0.1–30.0 W)If you selectManualas Power Limit mode, specify a maximum power supply value in this field.If you selectClass1toClass4as Power Limit mode, you can view the maximum power supply value in this field.
Time RangeSelect a time range. The port will supply power only during the time range. For how to create a time range, refer to Time Range Configuration.
PoE ProfileA quick configuration method for the corresponding ports. Select a profile to use its preset configurations. You will be unable to modify the PoE status, PoE priority or power limit manually.
Power (W) Displays the real-time power supply of the port.
Current (mA) Displays the real-time current of the port.
Voltage (V) Displays the real-time voltage of the port.
PD Class Displays the class the connected PD belongs to.
Power Status Displays the real-time power status of the port.

6.1.3 Configuring the PoE Auto Recovery Parameters Manually

Choose the menu SYSTEM > PoE > PoE Auto Recovery Config to load the following page.

Figure 6-6 Enabling PoE Auto RecoveryGlobal Config PoE Auto Recovery: ☐ Enable Notes: Some problems may occur in case of specified usage scenarios or improper configurations. 1. Before upgrading the connected PoE powered device (PD), disable PoE Auto Recovery on the corresponding port to avoid PD's damage. 2. Ping IP Address should be…

Follow these steps to configure the basic PoE Auto Recovery parameters:

1) In the Global Config section, you can enable the PoE Auto Recovery function globally. 2) In the Port Config section, click + Add to load the following page.

Figure 6-7 Configuring PoE Auto RecoveryPoE Auto Recovery Config Port: 1 3 5 7 9 11 13 15 17 19 21 23 2 4 6 8 10 12 14 16 18 20 22 24 Selected Unselected Not Available PoE Auto Recovery: Enable Ping IP Address: Startup Delay: 60 (30-600) Interval: 60 (10-120) Failure Threshold: 5 (1-10) Break Time: 15 (3-120) Cancel Create

Here you can view, add, edit and delete the PoE Auto Recovery entries.

Auto RefreshWhen enabled, the switch refreshes the data every 5 seconds so you can get the real-time ping statistics.
Port Display which port this entry takes effect on.
Ping IP Address Display the IP address of the PD connected to the port.Make sure the IP address configured here is the same as that of the PD connected to the corresponding port. Otherwise, the switch will continually reboot the PD.
Startup DelayDisplay the time that the switch will wait before starting to ping the IP address, which is to reserve time for the connected PD's rebooting. It ranges from 30 to 600 seconds.
IntervalDisplay the interval between two consecutive ping packets. It ranges from 10 to 120 seconds.
Failure ThresholdDisplay the threshold that the switch consecutively fails to receive the responses from the PD on the port. Once the failures reach the threshold, the switch will reboot the device. It ranges from 1 to 10.
Break TimeDisplay the time that the switch powers off the PD after the connection failures it detected have reached Failure Threshold. It ranges from 3 to 120 seconds.
Failures Display the number of PD's reboots. It will be reset after reaching 9,999 or when the switch is rebooted.
Total PingsDisplay the total number of ping packets that the switch sends to the connected PD. It will be reset after reaching 9,999 or when the switch is rebooted.
Status Display the status of PoE Auto Recovery on the port. To make it enabled, enable PoE Auto Recovery both globally and on the port.
Operation Here you can edit or delete the desired entry.

6.2 Using the CLI

6.2.1 Configuring the PoE Parameters Manually

Follow these steps to configure the basic PoE parameters:

Step 1configureEnter global configuration mode.
Step 2power inline consumption power-limitSpecify the maximum power the PoE switch can supply globally.power-limit: Specify the maximum power the PoE switch can supply.
Step 3(Optional) power inline unit unit id consumption power-limitSpecify the maximum power a stack unit can supply globally.unit id: Stack unit IDpower-limit: Specify the maximum power the PoE switch can supply.
Step 4interface { fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list }Enter Interface Configuration mode.port: Specify the Ethernet port number, for example 1/0/1.port-list: Specify the list of Ethernet ports, for example 1/0/1-3, 1/0/5.
Step 5power inline supply { enable | disable }Specify the PoE status for the corresponding port.enable | disable: Enable or disable the PoE function. By default, it is enable.

Step 6 power inline priority { low | middle | high }

Specify the PoE priority for the corresponding port.

low | middle | high: Select the priority level for the corresponding port. When the supply power exceeds the system power limit, the switch will power off PDs on low-priority ports to ensure stable running of other PDs. The default setting is low.

Step 7 power inline consumption { power-limit | auto | class1 | class2 | class3 | class4 }

Specify the maximum power the corresponding port can supply.

power-limit | auto | class1 | class2 | class3 | class4: Select or enter the maximum power the corresponding port can supply. The following options are provided: Auto represents that the switch will allocate the maximum power that the port can supply automatically. Class1 represents 4 W, Class2 represents 7W, Class3 represents 15.4 W and Class4 represents 30 W, or you can enter a value manually. The value ranges from 1 to 300. It is in the unit of 0.1 watt. For instance, if you want to configure the maximum power as 5 W, you should enter 50. By default, it is Class4.

Step 8 power inline time-range name

Specify a time range for the port. Then the port will supply power only during the time range. For how to create a time range, refer to Time Range Configuration.

name: Specify the name of the time range.

Step 9 show power inline

Verify the global PoE information of the system.

Step 10 show power inline configuration interface [fastEthernet { port | port-list } | gigabitEthernet { port | port-list } | ten-gigabitEthernet { port | port-list }]

Verify the PoE configuration of the corresponding port.

port: Specify the Ethernet port number, for example 1/0/1.

port-list: Specify the list of Ethernet ports, in the format of 1/0/1-3, 1/0/5.

Step 11: show power inline information interface [fastEthernet { port | port-list } | gigabitEthernet { port | port-list } | ten-gigabitEthernet { port | port-list }]

Verify the real-time PoE status of the corresponding port.

port: Specify the Ethernet port number, for example 1/0/1.

port-list: Specify the list of Ethernet ports, in the format of 1/0/1-3, 1/0/5.

Step 12: end

Return to privileged EXEC mode.

Step 13: copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the system power limit as 160 W. Set the priority as middle and set the power limit as class3 for the port 1/0/5.

Switch#configure

Switch(config)#power inline consumption 160

Switch(config)#interface gigabitEthernet 1/0/5

Switch(config-if)#power inline supply enable

Switch(config-if)#power inline priority middle

Switch(config-if)#power inline consumption class3

Switch(config-if)#show power inline

System Power Limit: 160.0w

System Power Consumption: 0.0w

System Power Remain: 160.0w

Switch(config-if)#show power inline configuration interface gigabitEthernet 1/0/5

Interface PoE-Status PoE-Prio Power-Limit(w) Time-Range PoE-Profile

Gi1/0/5 Enable Middle Class3 No Limit None

Switch(config-if)#show power inline information interface gigabitEthernet 1/0/5

Interface Power(w) Current(mA) Voltage(v) PD-Class Power-Status

Gi1/0/5 1.3 26 53.5 Class 2 ON

Switch(config-if)#end

Switch#copy running-config startup-config

6.2.2 Configuring the PoE Parameters Using the Profile

Follow these steps to configure the PoE profile:

Step 1 configure

Enter global configuration mode.

Step 2 power inline consumption power-limit

Specify the maximum power the PoE switch can supply globally.

power-limit: Specify the maximum power the PoE switch can supply.

Step 3 power profile name [supply { enable | disable } [priority { low | middle | high } [consumption { power-limit | auto | class1 | class2 | class3 | class4}]]]

Create a PoE profile for the switch. In a profile, the PoE status, PoE priority and power limit are configured. You can bind a profile to the corresponding port to quickly configure the PoE function.

name: Specify a name for the PoE profile. It ranges from 1 to 16 characters. If the name contains spaces, enclose the name in double quotes.

enable | disable: Specify the PoE status for the profile. By default, it is enable.

low | middle | high: Select the priority level for the profile. When the supply power exceeds the system power limit, the switch will power off PDs on low-priority ports to ensure stable running of other PDs.

power-limit | auto | class1 | class2 | class3 | class4: Select or enter the maximum power the corresponding port can supply. The following options are provided: Auto represents that the switch will assign a value of maximum power automatically. Class1 represents 4W, Class2 represents 7W, Class3 represents 15.4W and Class4 represents 30W or you can enter a value manually. The value ranges from 1 to 300. It is in the unit of 0.1 watt. For instance, if you want to configure the maximum power as 5W, you should enter 50.

Step 4 interface { fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list }

Enter Interface Configuration mode.

port: Specify the Ethernet port number, for example 1/0/1.

port-list: Specify the list of Ethernet ports, for example 1/0/1-3, 1/0/5.

Step 5 power inline profile name

Bind a PoE profile to the desired port. If one profile is selected, you will not be able to modify PoE status, PoE priority or power limit manually.

name: Specify the name of the PoE profile. If the name contains spaces, enclose the name in double quotes.

Step 6 power inline time-range name

Specify a time range for the port. Then the port will supply power only during the time range. For how to create a time range, refer to Time Range Configuration.

name: Specify the name of the time range.

Step 7 show power profile

Verify the defined PoE profile.

Step 8 show power inline configuration interface [fastEthernet { port | port-list } | gigabitEthernet { port | port-list } | ten-gigabitEthernet { port | port-list }]

Verify the PoE configuration of the corresponding port.

port: Specify the Ethernet port number, for example 1/0/1.

port-list: Specify the list of Ethernet ports, in the format of 1/0/1-3, 1/0/5.

Step 9 show power inline information interface [ fastEthernet { port | port-list } | gigabitEthernet { port | port-list } | ten-gigabitEthernet { port | port-list } ]Verify the real-time PoE status of the corresponding port.port: Specify the Ethernet port number, for example 1/0/1.port-list: Specify the list of Ethernet ports, in the format of 1/0/1-3, 1/0/5.

Step 10 end

Return to privileged EXEC mode.

Step 11: copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to create a profile named profile1 and bind the profile to port 1/0/6.

Switch#configure

Switch(config)#power profile profile1 supply enable priority middle consumption class2

Switch(config)#show power profile

IndexNameStatusPriorityPower-Limit(w)
--------------------
1profile1EnableMiddleClass2

Switch(config)#interface gigabitEthernet 1/0/6

Switch(config-if)#power inline profile profile1

Switch(config-if)#show power inline configuration interface gigabitEthernet 1/0/6

InterfacePoE-StatusPoE-PrioPower-Limit(w)Time-RangePoE-Profile
Gi1/0/6EnableMiddleClass2No Limitprofile1

Switch(config-if)#end

Switch#copy running-config startup-config

7 Management Port Configurations (Only for Certain Devices)

7.1 Using the CLI

7.1 Using the CLI

Follow these steps to configure the Management Port:

Step 1 configure

Enter global configuration mode.

Step 2 management-port protocol {dhcp|none}

Enable/Disable the IPv4 DHCP function on the management port.

dhcp: Enable the DHCP function.

none: Disable the DHCP function.

Step 3 management-port ip {ip-addr}{mask}

Configure the IPv4 address of the management port. To delete the address, use the no management-port ip command.

ip_addr: IPv4 address.

mask: IP mask.

Step 4 management-port ipv6 enable

Enable the management-port ipv6 function. To disable the function, use the no management-port ipv6 enable command.

Step 5 management-port ipv6 address {ipv6-addr} [eui64]

Configure the IPv6 address of the management port. To delete the address, use the no management-port ipv6 address command.

ipv6_addr: IPv6 address, you need to specify the prefix length.

eui64: Create the address in eui64 mode.

Step 6 show management-port

View the configuration information of the management port.

Step 7 end

Return to privileged EXEC mode.

Step 8 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the management port.

Switch#configure

Switch(config)#management-port protocol none

Switch(config)#management-port ip 192.168.10.1 255.255.255.0

Switch(config)#management-port ipv6 enable

Switch(config)#management-port ipv6 address 2001::1/64

Switch(config)#management-port ipv6 address 2001::1/64 eui64

Switch(config)#show management-port

Interface Status...... Down

IP Address.... 192.168.10.1

Subnet Mask.... 255.255.255.0

Default Gateway.... 0.0.0.0

IPv6 Administrative Mode...... Enabled

IPv6 Prefix is.... 2001::1/64

Configured IPv4 Protocol...... None

Configured IPv6 Protocol...... None

IPv6 AutoConfig Mode...... Disabled

Burned In MAC Address.... 5c:e9:31:43:31:7b

Switch(config)#end

Switch#copy running-config startup-config

8

Power Supply Configurations (Only for Certain Devices)

8.1 Using the CLI

8.1.1 Configuring the Power Backup Mode

Follow these steps to configure the power backup mode:

Step 1 configure

Enter global configuration mode.

Step 2 power backup unit

{unit id} {power} mode {mode}

Configure the power backup mode.

unit id: Stack unit ID, ranging from 1-4.

power: power supply module number.

mode: Power backup mode.

Step 3 show power

View the power details.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure pwr1 of unit 1 as the backup power.

Switch#configure

Switch(config)#power backup unit 1 pwr1 mode enable

switch(config)#show power

Switch(config)#end

Switch#copy running-config startup-config

9

SDM Template Configuration

9.1 Using the GUI

Choose the menu SYSTEM > SDM Template to load the following page.

Figure 9-1 Configuring SDM TemplateSDM Template Config Current Template: default Next Template: default Select Next Template: default Apply SDM Template Table SDM Template IP ACL Rules MAC ACL Rules Combined ACL Rules IPv6 ACL Rules IPv4 Source Guard Entries IPv6 Source Guard Entries default 300 300 300 0 299 0 enterpriseV4 0 300 500…

In SDM Template Config section, select one template and click Apply. The setting will be effective after the switch is rebooted.

Current Template Displays the template currently in effect.

Next Template Displays the template that will take effect after reboot.

Select Next Template: Select the template that will take effect after reboot. You can check the details of the template in the template table.

Default: It is the default setting. This template gives balance to the IP ACL rules, MAC ACL rules, and ARP detection entries.

EnterpriseV4: This template maximizes system resources for IP ACL rules and MAC ACL rules.

EnterpriseV6: This template allocates resources to IPv6 ACL rules.

You can view the details of each template in the SDM Template Table section.

SDM Template: Displays the name of the template.

IP ACL Rules: Displays the number of IP ACL Rules including layer 3 ACL rules and layer 4 ACL rules.

MAC ACL Rules Displays the number of layer 2 ACL rules.
Combined ACL RulesDisplays the number of Combined ACL rules.
IPv6 ACL Rules Displays the number of IPv6 ACL rules.
IPv4 Source Guard EntriesDisplays the number of IPv4 Source Guard entries.
IPv6 Source Guard EntriesDisplays the number of IPv6 Source Guard entries.

9.2 Using the CLI

Follow these steps to configure the SDM template:

Step 1configure
Enter global configuration mode.
Step 2show sdm prefer { used | default | enterpriseV4 | enterpriseV6 }View the template table. It will help you determine which template is suitable for your network.used: Displays the resource allocation of the current template.default: Displays the resource allocation of the default template.enterpriseV4: Displays the resource allocation of the enterpriseV4 template.enterpriseV6: Displays the resource allocation of the enterpriseV6 template.
Step 3sdmprefer { default | enterpriseV4 | enterpriseV6 }Select the template that will be effective after the switch is rebooted.default: Select the template of default. It gives balance to the IP ACL rules, MAC ACL rules and ARP detection entries.enterpriseV4: Select the template of enterpriseV4. It maximizes system resources for IP ACL rules and MAC ACL rules.enterpriseV6: Select the template of enterpriseV4. It allocates resources to IPv6 ACL rules.
Step 4endReturn to privileged EXEC mode.
Step 5copy running-config startup-configSave the settings in the configuration file.

The following example shows how to set the SDM template as enterpriseV4.

Switch#config

Switch(config)#show sdm prefer enterpriseV4

"enterpriseV4" template:

number of IP ACL Rules : 0

number of MAC ACL Rules : 300

number of Combined ACL Rules : 500

number of IPV6 ACL Rules : 0

number of IPV4 Source Guard Entries : 499

number of IPV6 Source Guard Entries : 0

number of Packet Content ACL Rules : 0

Switch to "enterpriseV4" template.

Changes to the running SDM preferences have been stored, but cannot take effect until reboot the switch.

Switch(config)#end

Switch#copy running-config startup-config

10 Time Range Configuration

Time ranges can be referenced by other functions like PoE or ACL rules, which can decide the effective time period of the functions. To complete Time Range configuration, follow these steps:

1) Add time range entries. 2) Configure Holiday time range.

10.1 Using the GUI

10.1.1 Adding Time Range Entries

Choose the menu SYSTEM > Time Range > Time Range Config and click + Add to load the following page.

Figure 10-1 Configuring Time RangeTime-Range Config Name: (1-16 characters) Holiday: Exclude Include Period Time Config Index Date Day Time Operation No entries in this table. Total: 0 Discard Create

Follow these steps to add time range entries:

1) In the Time-Range Config section, specify a name for the entry and select the Holiday mode.

Name: Specify a name for the entry.

Holiday: Select to include or exclude the holiday in the time range.

Exclude: The time range will not take effect on holidays.

Include: The time range will still take effect on holidays.

To configure Holiday, refer to Configuring Holiday.

2) In the Period Time Config section, click and the following window will pop up.

Figure 10-2 Adding Period TimePeriod Time Config Date From Month: January ▼ Day: 1 ▼ Year: 2000 ▼ To Month: January ▼ Day: 1 ▼ Year: 2000 ▼ Time From: (Format: HH:MM) To: (Format: HH:MM) Day of Week Mon Tue Wed Thu Fri Sat Sun Cancel Create

Configure the following parameters and click Create:

Date: Specify the start date and end date for this time range.

Time: Specify the start time and end time each day for this time range.

Day of Week: Select the days of the week for this time range.

3) Similarly, you can add more entries of period time according to your needs. The final period time is the sum of all the periods in the table. Click Create.

Figure 10-3 View Configuration ResultTime-Range Config Name: worktime (1-16 characters) Holiday: Exclude Include Period Time Config Index Date Day Time Operation 0 January 1, 2023 - January 1, 2024 Mon,Tue,Wed,Thu,Fri 08:00 - 20:00 Total: 0 Discard Create

10.1.2 Configuring Holiday

Choose the menu SYSTEM > Time Range > Holiday Config and click + Add to load the following page.

Figure 10-1 Configuring HolidayHoliday Config Holiday Name: (1-16 characters) Start Date Month Day January 01 End Date Month Day January 01 Cancel Create

Configure the following parameters and click Create to add a Holiday entry.

Holiday Name: Specify a name for the entry.

Start Date: Specify the start date of the Holiday time range.

End Date: Specify the end date of the Holiday time range.

Similarly, you can add more Holiday entries. The final Holiday time range is the sum of all the entries.

10.2 Using the CLI

10.2.1 Adding Time Range Entries

Follow these steps to add time range entries:

Step 1: configure

Enter global configuration mode.

Step 2 time-range

name

Create a time-range entry.

name: Specify a name for the entry.

Step 3 holiday { exclude | include }

Include or exclude the holiday in the time range.

exclude: The time range will not take effect on holiday.

include: The time range will not be affected by holiday.

To configure Holiday, refer to Configuring Holiday.

Step 4 absolute from

start-date to end-date

Specify the start date and end date of this time range.

start-date: Specify the start date in the format MM/DD/YYYY.

end-date: Specify the end date in the format MM/DD/YYYY.

Step 5 periodic start

start-time end end-time day-of-the-week week-day

Specify days of a week as the period of this time range.

start-time: Specify the start time of a day in the format HH:MM.

end-time: Specify the end time of a day in the format HH:MM.

week-day: Specify the days of week in the format of 1-3, 7. The numbers 1-7 respectively represent Monday, Tuesday, Wednesday, Thursday, Friday, Saturday and Sunday.

Step 6 show time-range

View the configuration of Time Range.

Step 7 end

Return to privileged EXEC mode.

Step 8 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to create a time range entry and set the name as time1, holiday mode as exclude, absolute time as 10/01/2017 to 10/31/2017 and periodic time as 8:00 to 20:00 on every Monday and Tuesday:

Switch#config

Switch(config)#time-range time1

Switch(config-time-range)#holiday exclude

Switch(config-time-range)#absolute from 12/01/2023 to 12/31/2023

Switch(config-time-range)#periodic start 08:00 end 20:00 day-of-the-week 1,2

Switch(config-time-range)#show time-range

Time-range entry: 12 (Inactive)

Time-range entry: time1 (Inactive)

holiday: exclude

number of time slice: 1

01 - 12/01/2023 to 12/31/2023

- 08:00 to 20:00 on 1,2

Switch(config-time-range)#end

Switch#copy running-config startup-config

10.2.2 Configuring Holiday

Follow these steps to configure Holiday time range:

Step 1 configure

Enter global configuration mode.

Step 2 holiday name start-date end-date

Create a holiday entry.

name: Specify a name for the entry.

start-date: Specify the start date in the format MM/DD.

end-date: Specify the end date in the format MM/DD.

Step 3 show holiday

View the configuration of Holiday.

Step 4 end

Return to privileged EXEC mode.

Step 8 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to create a holiday entry and set the entry name as holiday1 and set start date and end date as 07/01 and 09/01:

Switch#config

Switch(config)#holiday holiday1 start-date 07/01 end-date 09/01

Switch(config)#show holiday

Index Holiday Name Start-End

1 holiday1 07.01-09.01

Switch(config)#end

Switch#copy running-config startup-config

11 Controller Settings (Only for Certain Devices)

TP-LINK Omada Pro S5500-24GP4F - Controller Settings (Only for Certain Devices) - 1

Note:

Controller Settings is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If Controller Settings is available, there is SYSTEM > Controller Settings in the menu structure.

This feature prepares the switch for Omada SDN Controller Management in either of the following scenarios:

If you are using Omada Cloud-Based Controller, enable Cloud-Based Controller Management on this page, then you can further add your devices to your Omada Cloud-Based Controller. If your switch and Omada SDN Controller are located on the same subnet, the controller can discover and manage the switch without any controller settings. Otherwise, you need to inform the switch of the controller's URL/IP address.

11.1 Using the GUI

11.1.1 Enabling Cloud-Based Controller Management

Choose the menu SYSTEM > Controller Settings to load the following page. In the Cloud-Based Controller Management section, enable Cloud-Based Controller Management and click Apply. After you add the switch to your Omada Cloud-Based Controller, you can check the connection status on this page.

Figure 11-1 Enabling Cloud-Based Controller ManagementCloud-Based Controller Management Connection Status: Disabled Cloud-Based Controller Management: Enable Notes: To enjoy centralized management on Omada Cloud-Based Controller, enable Cloud-Based Controller Management and add the device to the controller via its serial number. You can disable this fe…

11.1.2 Configuring Controller Inform URL

Choose the menu SYSTEM > Controller Settings to load the following page. In the Cloud-Based Controller Management section, check Enable and accept the Terms of Use and the Privacy Policy. In the Controller Inform URL section, inform the switch of the controller's URL/IP address, and click Apply.

Figure 11-1 Configuring Controller Inform URLCloud-Based Controller Management Connection Status: Disabled Cloud-Based Controller Management: ✓ Enable ✓ I accept the Terms of Use and confirm that I have fully read and understood the Privacy Policy Notes: To enjoy centralized management on Omada Cloud-Based Controller, enable Cloud-Based Contro…

11.2 Using the CLI

11.2.1 Enabling Cloud-Based Controller Management

Follow these steps to enable cloud-based controller management:

Step 1 configure

Enter global configuration mode.

Step 2 controller cloud-based

Enable cloud-based controller management.

Step 3 show controller

View the controller settings and status.

11.2.2 Configuring Controller Inform URL

Follow these steps to configure controller inform URL:

Step 1 configure

Enter global configuration mode.

Step 2 controller inform-url [ controller-url | controller-ip ]

Inform the switch of the controller's URL/IP address.

Step 3: show controller

View the controller settings and status.

The following example shows how to inform the switch of the controller whose IP address is 192.168.1.1:

Switch#config

Switch(config)#controller inform-url 192.168.1.1

Switch(config)#show controller

Cloud-Based Controller Management : Disabled

Connection Status : Disabled

Cloud-Based Privacy Policy : Disabled

Inform URL/IP Address :

192.168.1.1?dPort=29810&mPort=0&omadaclid=c21f969b5f03d33d43e04f8f136e7682

12 File System Configurations

12.1 Using the CLI

12.1.1 Configuring the File System

Follow these instructions to configure the file system:

Funtion 1copy{flash|usbflash1|usbflash2}{filename}{destination}Copy the specified file.flash|usbflash1|usbflash2: The flash type of the source file.filename: File name.destination: Copied file path.
Funtion 2cd{filename|flash|usbflash1|usbflash2}[filename]Change the current file path.filename|flash|usbflash1|usbflash2: The path that needs to be switched. If you enter filename, the file will be found in the current path by default.filename: Specify the file in the corresponding flash.
Funtion 3dir[flash|usbflash1|usbflash2][filename]List files and subdirectories contained in the specified working directory.flash|usbflash1|usbflash2: Specify path.filename: Specify the file in the corresponding flash.
Funtion 4pwdDisplay the absolute path name of the current working directory.
Funtion 5rename{srcFilename}{dstFilename}Rename a file.srcFilename: Source file name.dstFilename: Renamed file name.

Function 6

delete {filename|flash|usbflash1|usbflash2} [filename]

Delete a file.

filename|flash|usbflash1|usbflash2: The file that needs to be deleted. If you enter filename, the file will be found in the current working path by default.

filename: Specify the file in the corresponding flash.

13 FTP, SFTP and SCP Configurations

13.1 Overview

SSH provides secure services for network terminal access in a traditionally insecure network environment by authenticating the server to the client and encrypting data bidirectionally. Through the SFTP method, clients can securely connect to an SSH server for secure file transfers.

13.2 Using the CLI

13.2.1 Using the FTP

Follow these steps to use the FTP (File Transfer Protocol):

Step 1 ftp

Enter the FTP view

Step 2 open [ipv6] {hostlp}

Connect to FTP server.

ipv6: Specify the FTP server type as IPv6.

hostlp: FTP server IP.

Step 3 put {srcFilename} {dstFilename}

Upload files to FTP server.

srcFilename: Source file name.

dstFilename: Renamed file name.

Step 4 get {srcFilename} {dstFilename}

Download files from FTP server.

srcFilename: Source file name.

dstFilename: Renamed file name.

Step 5 close

Close current FTP connection.

The following example shows how to use the FTP:

Switch#configure

Switch(config)#ftp

Switch(ftp)#open 192.168.0.146

Switch(ftp)#open 192.168.0.146

Switch(ftp)#put src.c dst.c

Switch(ftp)#get src.c dst.c

Switch(ftp)#close

13.2.2 Using the SFTP/SFTPv6

Follow these steps to use the SFTP (Secure File Transfer Protocol):

Step 1 sftp {open} {hostIp} {username}

Connect to SFTP server.

open: Establish a connection to the server.

hostIp: The destination IP address of the connection (IPv4/IPv6).

username: Username for connection. Maximum length is 63 characters and can include numbers, English letters, and some special characters: '-@:/.]()'. '-' cannot be used as the starting character.

Step 2 sftp {get | put} {srcFileName} {dstFileName}

Connect to SFTP server.

get | put: Download/Upload files from/to SFTP server

srcFilename: The file name to be downloaded from the server/uploaded to the server, with a maximum length of 63 characters, which can include numbers, English letters, and some special characters: '-@:/.]()'.

dstFilename: The file name downloaded to the local computer/uploaded to the server, with a maximum length of 63 characters and can include numbers, English letters, and some special characters: '-@:/.].()'.

The following example shows how to use the SFTP:

Switch#sftp open 192.168.0.10 admin

Switch#sftp get test1.txt test2.txt

13.2.3 Using the SCP

Follow these steps to use the SCP (Secure Copy):

Step 1 scp {get | put} {username} {serverIp} {srcFileName} {dstFileName}
Connect to SFTP server.
get | put: Download/Upload files from/to SFTP server
username: SCP server IP
serverIp: SCP server IP.
srcFilename: Source file name.
dstFilename: Destination file name. 

The following example shows how to use the SFTP:

Switch#scp get admin 1.1.1.1 test1.txt test2.txt

14 Example for PoE Configurations

14.1 Network Requirements

The network topology of a company is shown as below. Camera1 and Camera2 work for the security of the company and cannot be power off all the time. AP1 and AP2 provide the internet service and only work in the office time.

Figure 14-1 Network Topologygraph TD A["Switch A"] -->|Gi1/0/1| B["Camera1"] A -->|Gi1/0/2 Gi1/0/3| C["Camera2"] A -->|Gi1/0/4| D["Camera3"] B --> E["AP1 AP2"] C --> F["AP2"] D --> G["AP3 AP2"]

14.2 Configuring Scheme

To implement this requirement, you can set a PoE time-range as the office time, for example, from 08:30 to 18:00 on work days. Then apply the settings to port 1/0/3 and 1/0/4. Port 1/0/1 and port 1/0/2 need to supply power all the time, so the time range configurations can be left as the default settings here.

14.3 Using the GUI

The configurations of port 1/0/4 are similar to the configurations of port 1/0/3. Here we take port 1/0/3 as an example.

1) Choose the menu SYSTEM > Time Range > Time Range Create and click + Add to load the following page.

Figure 14-2 Creating Time RangeTime-Range Config Name: (1-16 characters) Holiday: Exclude Include Period Time Config Add Delete ID Date Day Time Operation No entries in this table. Total: 0 Discard Create

2) Click + Add and the following window will pop up. Set Date, Time, and Day of Week as shown in the following figure. Click Create.

Figure 14-3 Creating a Periodic TimePeriod Time Config Date From Month: January Day: 1 Year: 2017 To Month: January Day: 1 Year: 2018 Time From: 08:30 (Format: HH:MM) To: 18:00 (Format: HH:MM) Day of Week ✓ Mon ✓ Tue ✓ Wed ✓ Thu ✓ Fri □ Sat □ Sun Cancel Create

3) Specify a name for the time range. Click Create.

Figure 14-4 Configuring Time RangeTime-Range Config Name: OfficeTime (1-16 characters) Holiday: Exclude Include Period Time Config ID Date Day Time Operation 0 January 1, 2017 - January 1, 2018 Mon.Tue.Wed.Thu.Fri 08:30 - 18:00 Total: 0 Discard Create

4) Choose the menu SYSTEM > PoE > PoE Config to load the following page. Select port 1/0/3 and set the Time Range as OfficeTime. Click Apply.

Figure 14-5 Configure the PortPoE Config Unit System Power Limit (W) System Power Consumption (W) System Power Remain (W) Operation Unit1 192.0 0.0 192.0 Total: 1 Port Config UNIT1 □ Port PoE Status PoE Priority Power Limit Power Limit Value (0.1-30.0 W) Time Range PoE Profile Power (W) Curr OfficeTime □ 1 Enabled Low Class4 30…

5) Click Save to save the settings.

14.4 Using the CLI

The configurations of Port1/0/4 are similar to the configuration of port 1/0/3. Here we take port 1/0/3 as an example.

1) Create a time-range.

Switch_A#config

Switch_A(config)#time-range office-time

Switch_A(config-time-range)#holiday exclude

Switch_A(config-time-range)#absolute from 01/01/2023 to 01/01/2024

Switch_A(config-time-range)#periodic start 08:30 end 18:00 day-of-the-week 1-5

Switch_A(config-time-range)#exit

2) Enable the PoE function on the port 1/0/3. Specify the basic parameters for the port 1/0/3 and bind the time-range office-time to the port.

Switch_A(config)#interface gigabitEthernet 1/0/3

Switch_A(config-if)#power inline supply enable

Switch_A(config-if)#power inline time-range office-time

Switch_A(config-if)#end

Switch_A#copy running-config startup-config

Verify the Configuration

Verify the configuration of the time-range:

Switch_A#show time-range

Time-range entry: office-time (Active)

holiday: exclude

number of time slice: 1

01 - 01/01/2023 to 01/01/2024

- 08:00 to 18:00 on 1,2,3,4,5

Verify the configuration of the PoE basic parameters:

Switch_A#show power inline configuration interface gigabitEthernet 1/0/3

InterfacePoE-StatusPoE-PrioPower-Limit(w)Time-RangePoE-Profile
Gi1/0/3EnableLowClass4office-timeNone

15 Appendix: Default Parameters

Default settings of System Info are listed in the following tables.

Table 15-1 Default Settings of Device Description Configuration

Parameter Default Setting
Device Name The model nameof the switch
Device Location Hong Kong
System Contact www.tp-link.com

Table 15-2 Default Settings of System Time Configuration

Parameter Default Setting
Time Source Manual

Table 15-3 Default Settings of Daylight Saving Time Configuration

Parameter Default Setting
DST status Disabled

Default settings of User Management are listed in the following table.

Table 15-4 Default Settings of User Configuration

Parameter Default Setting
User Name admin
Password admin
Access Level Admin

Default settings of System Tools are listed in the following table.

Table 15-5 Default Settings of Boot Configuration

Parameter Default Setting
Current Startup Image image1.bin
Next Startup Image image1.bin
Backup Image image2.bin
Current Startup Config config1.cfg
Next Startup Config config1.cfg
Backup Config config2.cfg

The default settings of EEE are listed in the following table.

Table 15-6 Default Settings of EEE Configuration

Parameter Default Setting
Status Disabled

(Only for certain devices) The default settings of PoE are listed in the following table.

Table 15-7 Default Settings of PoE Configuration

Parameter Default Setting
PoE Config
System Power Limit (Refer to the actual web interface)
Port Config
PoE Status Enabled
PoE Priority Low
Power Limit (0.1w-30.0w) Class 4
Time Range No Limit
PoE Profile None
Profile Config
Profile Name None
PoE Status Enabled
PoE Priority Low
Power Limit Auto

The default settings of SDM Template are listed in the following table.

Table 15-8 Default Settings of SDM Template Configuration

Parameter Default Setting
Current Template IDDefault
Next Template ID Default

The default settings of Time Range are listed in the following table.

Table 15-9 Default Settings of Time Range Configuration

Parameter Default Setting
Holiday Include

Part 3

Managing Physical Interfaces

CHAPTERS

  1. Physical Interface
  2. Basic Parameters Configurations
  3. Port Isolation Configurations
  4. Loopback Detection Configuration
  5. Configuration Examples
  6. Configuring Management Port
  7. Configuring RSPAN Monitoring
  8. Appendix: Default Parameters

1 Physical Interface

1.1 Overview

Interfaces are used to exchange data and interact with interfaces of other network devices. Interfaces are classified into physical interfaces and layer 3 interfaces.

■ Physical interfaces are the ports on the switch panel. They forward packets based on MAC address table. ■ Layer 3 interfaces are used to forward IPv4 and IPv6 packets using static or dynamic routing protocols. You can use Layer 3 interfaces for IP routing and inter-VLAN routing.

This chapter introduces the configurations for physical interfaces.

1.2 Supported Features

The switch supports the following features about physical interfaces:

Basic Parameters

You can configure port status, speed mode, duplex mode, flow control and other basic parameters for ports.

Port Isolation

You can use this feature to restrict a specific port to sending packets to only the ports in a configured forwarding port list.

Loopback Detection

This function allows the switch to detect loops that occur on a specific port. When a loop is detected on a port, the switch will display an alert on the management interface and block the corresponding port according to your configurations.

2 Basic Parameters Configurations

2.1 Using the GUI

Choose the menu L2 FEATURES > Switching > Port > Port Config to load the following page.

Figure 2-1 Configuring Basic ParametersPort Config Jumbo: 1518 bytes (1518-9216) Apply UNIT1 LAGS Port Type Description Status Speed Duplex Flow Control LAG 1/0/1 Copper Enabled Auto Auto Disabled -- 1/0/2 Copper Enabled Auto Auto Disabled -- 1/0/3 Copper Enabled Auto Auto Disabled -- 1/0/4 Copper Enabled Auto Auto Disabled -- 1/0/5 Copp…

Follow these steps to configure basic parameters for the ports:

1) Configure the MTU size of jumbo frames for all the ports, then click Apply.

Jumbo Configure the size of jumbo frames. By default, it is 1518 bytes.

Generally, the MTU (Maximum Transmission Unit) size of a normal frame is 1518 bytes. If you want the switch to support transmission of frames with an MTU size greater than 1518 bytes, you can configure the MTU size manually here.

2) Select one or more ports to configure the basic parameters. Then click Apply.

UNIT/LAGSClick the UNIT number to configure physical ports. Click LAGS to configure LAGs.
TypeDisplays the medium type of the port. Copper indicates an Ethernet port, and Fiber indicates an SFP port.
Description (Optional) Enter a description for the port.
Status With this option enabled, the port forwards packets normally. Otherwise, the port cannot work. By default, it is enabled.
SpeedChoose the speed mode of the port. You can select 'Auto', or manually specify the speed mode. 'Auto' means the speed will be automatically determined by auto-negotiation. The device connected to the port should be in the same speed and duplex mode as the port.
DuplexChoose the duplex mode of the port. There are three options: Half, Full and Auto. The default setting is Auto. Half: The port can send and receive packets, but only one-way at a time. Full: The port can send and receive packets simultaneously. Auto: The port automatically negotiates duplex mode with the peer device.
Flow ControlWith this option enabled, when a device gets overloaded it will send a PAUSE frame to notify the peer device to stop sending data for a specified period of time, thus avoiding the packet loss caused by congestion.
LAG Displays the LAG that the port belongs to.

TP-LINK Omada Pro S5500-24GP4F - Using the GUI - 2

Note:

If the port is a member port of an LAG, it will follow the port configuration of the LAG and not its own.

2.2 Using the CLI

Follow these steps to set basic parameters for the ports.

Step 1 configure Enter global configuration mode.

Step 2 jumbo-size sizeChange the MTU (Maximum Transmission Unit) size to support jumbo frames. The default MTU size for frames received and sent on all ports is 1518 bytes. To transmit jumbo frames, you can manually configure MTU size of frames up to 9216 bytes.size: Configure the MTU size of jumbo frames. The value ranges from 1518 to 9216bytes.
Step 3 interface {vlan vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list |}Enter interface configuration mode.

Step 4 Configure basic parameters for the port:

description string

Give a port description for identification.

string: Content of a port description, ranging from 1 to 16 characters.

shutdown

no shutdown

Use shutdown to disable the port, and use no shutdown to enable the port. When the status is enabled, the port can forward packets normally, otherwise it will discard the received packets. By default, all ports are enabled.

speed { 10 | 100 | 1000 | 10000 | auto }

Set the appropriate speed mode for the port.

10 | 100 | 1000 | 10000 | auto: Speed mode of the port. The options are subject to your actual product. The device connected to the port should be in the same speed and duplex mode with the port. When auto is selected, the speed mode will be determined by auto-negotiation.

duplex { auto | full | half }

Set the appropriate duplex mode for the port.

auto | full | half: Duplex mode of the port. The device connected to the port should be in the same speed and duplex mode with the port. When auto is selected, the duplex mode will be determined by auto-negotiation.

flow-control

Enable the switch to synchronize the data transmission speed with the peer device, avoiding the packet loss caused by congestion. By default, it is disabled.

Step 5 show interface configuration [fastEthernet

port | gigabitEthernet port || ten-

gigabitEthernet port | port-channel port-channel-id ]

Verify the configuration of the port or LAG.

Step 6 end

Return to privileged EXEC mode.

Step 7 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to implement the basic configurations of port1/0/1, including setting a description for the port, configuring the jumbo frame, making the port automatically negotiate speed and duplex with the neighboring port, and enabling the flow-control:

Switch#configure

Switch#jumbo-size 9216

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#no shutdown

Switch(config-if)#description router connection

Switch(config-if)#speed auto

Switch(config-if)#duplex auto

Switch(config-if)#flow-control

Switch(config-if)#show interface configuration gigabitEthernet 1/0/1

Port State Speed Duplex FlowCtrl Description

Gi1/0/1 Enable Auto Auto Enable router connection

Switch(config-if)#show jumbo-size

Global jumbo size : 9216

Switch(config-if)#end

Switch#copy running-config startup-config

3 Port Isolation Configurations

3.1 Using the GUI

Port isolation is used to restrict a specific port to sending packets to only the ports in a configured forwarding port list.

Choose the menu L2 FEATURES > Switching > Port > Port Isolation to load the following page.

Figure 3-1 Port Isolation List

The above page displays the port isolation list. Click to configure Port Isolation on the following page.

Figure 3-2 Port IsolationPort Isolation Config | Port | Select All | Selected | Unselected | Not Available | | :--- | :--- | :--- | :--- | :--- | | Port | UNIT1 | 1 | 3 | 5 | | Port | UNIT1 | 2 | 4 | 6 | | Port | UNIT1 | 2 | 4 | 6 | | Port | UNIT1 | 9 | 10 | 12 | | Port | UNIT1 | 11 | 12 | 14 | | Port | UNIT1 | 13 | 14 | 16…

Follow these steps to configure Port Isolation:

1) In the Port section, select one or multiple ports to be isolated. 2) In the Forwarding Port List section, select the forwarding ports or LAGs which the isolated ports can only communicate with. It is multi-optional. 3) Click Apply.

TP-LINK Omada Pro S5500-24GP4F - Using the GUI - 2

Note:

If the port is a member port of an LAG, it will follow the port configuration of the LAG and not its own.

3.2 Using the CLI

Follow these steps to configure Port Isolation:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list |

Specify the port to be isolated and enter interface configuration mode.

Step 3 port isolation { [fa-forward-list fa-forward-list] [gi-forward-list gi-forward-list] [te-forward-list te-forward-list] [po-forward-list po-forward-list] }

Add ports or LAGs to the forwarding port list of the isolated port. This is multi-optional. fa-forward-list / gi-forward-list / te-forward-list: Specify the forwarding Ethernet ports. po-forward-list: Specify the forwarding LAGs.

Step 4 show port isolation interface { fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel }

Verify the Port Isolation configuration of the specified port.

Step 5 end

Return to privileged EXEC mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to add ports 1/0/1-3 and LAG 4 to the forwarding list of port 1/0/5:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/5

Switch(config-if)#port isolation gi-forward-list 1/0/1-3 po-forward-list 4

Switch(config-if)#show port isolation interface gigabitEthernet 1/0/5

Port LAG Forward-List

Gi1/0/5 N/A Gi1/0/1-3, Po4

Switch(config-if)#end

Switch#copy running-config startup-config

4 Loopback Detection Configuration

4.1 Using the GUI

To avoid broadcast storm, we recommend that you enable storm control before loopback detection is enabled. For detailed introductions about storm control, refer to Configuring QoS.

Choose the menu L2 FEATURES > Switching > Port > Loopback Detection to load the following page.

Figure 4-1 Configuring Loopback DetectionLoopback Detection Loopback Detection Status: Enable Detection Interval: 30 seconds (1-1000) Auto-recovery Time: 90 seconds (2-100,000) Web Refresh Status: Enable Web Refresh Interval: 6 seconds (3-100) Apply Port Config UNIT1 LAGS Recovery Port Status Operation Mode Recovery Mode Loop Status Block…

Follow these steps to configure loopback detection:

1) In the Loopback Detection section, enable loopback detection and configure the global parameters. Then click Apply.

Loopback

Enable or disable the loopback detection function globally.

Detection Status

Detection IntervalSpecify the interval between successive sent loopback detection packets.The valid value ranges from 1 to 1000 and the default value is 30.
Auto-recovery TimeSet the auto-recovery time globally. The blocked port in Auto Recovery mode will automatically be recovered to normal status after the auto-recovery Time expires. The value ranges from 2 to 100,000 in seconds, and the default value is 90.
Web Refresh StatusEnable or disable web refresh status. With this option enabled, the web page will automatically be refreshed regularly according to the web refresh interval. By default, it is disabled.
Web Refresh IntervalIf you have enabled web refresh status, set the refresh interval in seconds between 3 and 100. The default value is 6.

2) In the Port Config section, select one or more ports to configure the loopback detection parameters. Then click Apply.

Status Enable or disable loopback detection for the port.
Operation Mode Specify the operation to be taken when a loop is detected.
Alert: The Loop Status will display if there is a loop detected on the corresponding port. It is the default setting.
Port Based: The switch will display an alert and block the corresponding port when a loop is detected.
VLAN-Based: The switch will display an alert and block the corresponding VLAN when a loop is detected.
Recovery ModeIf you select Port Based or VLAN-Based as the operation mode, you also need to configure the recovery mode for the blocked port:
Auto: The blocked port will automatically recover to normal status after the auto-recovery time. It is the default setting.
Manual: You need to manually release the blocked port. Click the Recovery button to release the selected port.

3) (Optional) View the loopback detection information.

Loop Status Displays whether a loop is detected on the port.
Block Status Displays whether the port is blocked.
Block VLAN Displays whether the VLAN is blocked.
LAG Displays the LAG that the port belongs to.

4.2 Using the CLI

Follow these steps to configure loopback detection:

Step 1 configure

Enter global configuration mode.

Step 2 loopback-detection

Enable the loopback detection feature globally. By default, it is disabled.

Step 3 loopback-detection interval

interval-time

Set the interval of sending loopback detection packets which is used to detect the loops in the network.

interval-time: The interval of sending loopback detection packets. The valid values are from 1 to 1000 seconds. By default, the value is 30 seconds.

Step 4 loopback-detection recovery-time

recovery-time

Set the auto-recovery time, after which the blocked port in Auto Recovery mode can automatically be recovered to normal status.

recovery-time: Specify the detection interval, ranging from 2 to 100,000 seconds. The default value is 90.

Step 5 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port}

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list |

Enter interface configuration mode.

Step 6 loopback-detection

Enable loopback detection for the port. By default, it is disabled.

Step 7

loopback-detection config process-mode { alert | port-based | vlan-based } recovery-mode { auto | manual }

Set the process mode when a loopback is detected on the port. There are three modes:

alert: The switch will only display alerts when a loopback is detected. It is the default setting.

port-based: In addition to displaying alerts, the switch will block the port on which the loop is detected.

vlan-based: In addition to displaying alerts, the switch will block the VLAN of the port in which the loop is detected.

Set the recovery mode for the blocked port. There are two modes:

auto: After the recovery time expires, the blocked port will automatically recover to normal status and restart to detect loops in the network.

manual: The blocked port can only be released manually. You can use the command 'loopback-detection recover' to recover the blocked port to normal status.

Step 9 show loopback-detection global

Verify the global configuration of Loopback Detection.

Step 10 show loopback-detection interface { fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel}Verify the Loopback Detection configuration of the specified port.

Step 11 end

Return to privileged EXEC mode.

Step 12 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable loopback detection globally (keep the default parameters):

Switch#configure

Switch(config)#loopback-detection

Switch(config)#show loopback-detection global

Loopback detection global status : enable

Loopback detection interval : 30s

Loopback detection recovery time : 3 intervals

Switch(config-if)#end

Switch#copy running-config startup-config

The following example shows how to enable loopback detection of port 1/0/3 and set the process mode as alert and recovery mode as auto:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/3

Switch(config-if)#loopback-detection

Switch(config-if)#loopback-detection config process-mode alert recovery-mode auto

Switch(config-if)#show loopback-detection interface gigabitEthernet 1/0/3

PortEnableProcess ModeRecovery ModeLoopbackBlockLAG
----------------------------
Gi1/0/3enablealertautoN/AN/AN/A

Switch(config-if)#end

Switch#copy running-config startup-config

5 Configuration Examples

5.1 Example for Port Isolation

5.1.1 Network Requirements

As shown below, three hosts and a server are connected to the switch and all belong to VLAN 10. Without changing the VLAN configuration, Host A is not allowed to communicate with the other hosts except the server, even if the MAC address or IP address of Host A is changed.

Figure 5-1 Network Topologygraph TD Switch["Switch"] -->|Gi1/0/1| HostA["Host A"] Switch -->|Gi1/0/2| HostB["Host B"] Switch -->|Gi1/0/3| HostC["Host C Server"] Switch -->|Gi1/0/4| HostD["Host D"] HostA --> VLAN10["VLAN 10"] HostB --> VLAN10 HostC --> VLAN10 HostD --> VLAN10

5.1.2 Configuration Scheme

You can configure port isolation to implement the requirement. Set port 1/0/4 as the only forwarding port for port 1/0/1, thus forbidding Host A to forward packets to the other hosts.

Since communications are bidirectional, if you want Host A and the server to communicate normally, you also need to add port 1/0/1 as the forwarding port for port 1/0/4.

Demonstrated with S6500-24GP4XF, the following sections provide configuration procedure in two ways: using the GUI and using the CLI.

5.1.3 Using the GUI

1) Choose the menu L2 FEATURES > Switching > Port > Port Isolation to load the following page. It displays the port isolation list.

Figure 5-2 Port Isolation List

Port Isolation Config
UNIT1
PortLAG Forwarding Port List
1/0/1- 1/0/1-48,1/0/49-54
1/0/2- 1/0/1-48,1/0/49-54
1/0/3- 1/0/1-48,1/0/49-54
1/0/4- 1/0/1-48,1/0/49-54
1/0/5- 1/0/1-48,1/0/49-54
1/0/6- 1/0/1-48,1/0/49-54
1/0/7- 1/0/1-48,1/0/49-54
1/0/8- 1/0/1-48,1/0/49-54
1/0/9- 1/0/1-48,1/0/49-54
1/0/10- 1/0/1-48,1/0/49-54
Total: 54

2) Click Edit on the above page to load the following page. Select port 1/0/1 as the port to be isolated, and select port 1/0/4 as the forwarding port. Click Apply.

Figure 5-3 Port Isolation ConfigurationPort Isolation Config Port UNIT1 LAGS Select All 41 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 42 44 46 48 50 52 54 Selected Unselected Not Available Forwarding Port List UNIT1 LAGS Select All 41 43 45 47 49 51 53 2 4 6 8 10 12 14 16…

3) Select port 1/0/4 as the port to be isolated, and select port 1/0/1 as the forwarding port. Click Apply.

Figure 5-4 Port Isolation ConfigurationPort Isolation Config Port UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 49 51 53 42 44 46 48 50 52 54 Selected Unselected Not Available Forwarding Port List UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 2…

4) Click Save the settings.

5.1.4 Using the CLI

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#port isolation gi-forward-list 1/0/4

Switch(config-if)#exit

Switch(config)#interface gigabitEthernet 1/0/4

Switch(config-if)#port isolation gi-forward-list 1/0/1

Switch(config-if)#end

Switch#copy running-config startup-config

Verify the Configuration

Switch#show port isolation interface

Port LAG Forward-List

Gi1/0/1N/AGi1/0/4
Gi1/0/2N/AGi1/0/1-48,Te1/0/49-54,Gi2/0/1-48,Te2/0/49-54
Gi1/0/3N/AGi1/0/1-48,Te1/0/49-54,Gi2/0/1-48,Te2/0/49-54
Gi1/0/4N/AGi1/0/1
Gi1/0/5N/AGi1/0/1-48,Te1/0/49-54,Gi2/0/1-48,Te2/0/49-54
...

5.2 Example for Loopback Detection

5.2.1 Network Requirements

As shown below, Switch A is a convergence-layer switch connecting to several access-layer switches. Loops can be easily caused in case of misoperation on the access-layer switches. If there is a loop on an access-layer switch, broadcast storms will occur on Switch A or even in the entire network, creating excessive traffic and degrading the network performance.

To reduce the impacts of broadcast storms, users need to detect loops in the network via Switch A and timely block the port on which a loop is detected.

Figure 5-5 Network Topologygraph TD A["Switch A"] -->|Gi1/0/1| B["Access-layer Switches"] A -->|Gi1/0/2| C["Access-layer Switches"] A -->|Gi1/0/3| D["Management Host"] C --> E["Loop"] D --> E

5.2.2 Configuration Scheme

Enable loopback detection on ports 1/0/1-3 and configure SNMP to receive the trap notifications. For detailed instructions about SNMP, refer to Configuring SNMP & RMON. Here we introduce how to configure loopback detection and monitor the detection result on the management interface of the switch.

Demonstrated with S6500-24GP4XF, the following sections provide configuration procedure in two ways: using the GUI and using the CLI.

5.2.3 Using the GUI

1) Choose the menu L2 FEATURES > Switching > Port > Loopback Detection to load the configuration page. 2) In the Loopback Detection section, enable loopback detection and web refresh globally. Keep the other parameters as default values and click Apply.

Figure 5-6 Global ConfigurationLoopback Detection Loopback Detection Status: ✓ Enable Detection Interval: 20 seconds (1-1000) Auto-recovery Time: 90 seconds (2-100,000) Web Refresh Status: ✓ Enable Web Refresh Interval: 6 seconds (3-100) Apply

3) In the Port Config section, enable ports 1/0/1-3, select the operation mode as Port-Based so that the port will be blocked when a loop is detected, and keep the recovery mode as Auto so that the port will automatically be recovered to normal status after the auto-recovery time. Click Apply.

Figure 5-7 Port ConfigurationPort Config UNIT1 LAGS Recovery Port Status Operation Mode Recovery Mode Loop Status Block Status Block VLAN LAG Enable Port Based Auto ✓ 1/0/1 Enabled Port Based Auto -- -- -- -- ✓ 1/0/2 Enabled Port Based Auto -- -- -- -- ✓ 1/0/3 Enabled Port Based Auto -- -- -- -- □ 1/0/4 Disabled Alert Auto -- -…

4) Monitor the detection result on the above page. The Loop status and Block status are displayed on the right side of ports.

5.2.4 Using the CLI

1) Enable loopback detection globally and configure the detection interval and recovery time.

Switch#configure

Switch(config)#loopback-detection

Switch(config)#loopback-detection interval 30

Switch(config)#loopback-detection recovery-time 3

2) Enable loopback detection on ports 1/0/1-3 and set the process mode and recovery mode.

Switch(config)#interface range gigabitEthernet 1/0/1-3

Switch(config-if-range)#loopback-detection

Switch(config-if-range)#loopback-detection config process-mode port-based recovery-mode auto

Switch(config-if-range)#end

Switch#copy running-config startup-config

Verify the Configuration

Verify the global configuration:

Switch#show loopback-detection global

Loopback detection global status : enable

Loopback detection interval: 30 s

Loopback detection recovery time : 90 s

Verify the loopback detection configuration on ports:

Switch#show loopback-detection interface

PortEnableProcess ModeRecovery ModeLoopbackBlockLAG
----------------------------
Gi1/0/1enableport-basedautoN/AN/AN/A
Gi1/0/2enableport-basedautoN/AN/AN/A
Gi1/0/3enableport-basedautoN/AN/AN/A

6

Appendix: Default Parameters

Default settings of Switching are listed in the following tables.

Table 6-1 Configurations for Ports

Parameter Default Setting
Port Config
Jumbo 1518 bytes
TypeCopper (For RJ45 Ports)Fiber (For SFP/SFP+/SFP28/QSFP28 Ports)
Status Enabled
SpeedAuto(For RJ45 Ports)1000M (For SFP Ports)10G(For SFP+ Ports)25G(For SFP28 Ports)100G(For QSFP28 Ports)
DuplexAuto (For RJ45 Ports)Full (For SFP/SFP+/SFP28/QSFP28 Ports)
Flow Control Disabled
Loopback Detection
Loopback Detection Status Disabled
Detection Interval 30 seconds
Auto-recovery Time 90 seconds
Web Refresh Status Disabled
Web Refresh Interval 6 seconds
Port Status Disabled
Operation mode Alert
Recovery modeAuto

Part 4

Configuring Stack

(Only for Certain Devices)

CHAPTERS

  1. Overview
  2. Stack Concepts
  3. Stack Operation Procedure
  4. Stack Topology
  5. Stack Configuration
  6. Appendix: Default Parameters

1 Overview

Stack is a device virtualization technology that connects two or more switches supporting stack features via cables through their stack ports, which logically virtualize them into one device as a whole to forward data in the network in Layer 2 and Layer 3 protocols. Through this feature, switches can be stacked to improve reliability, expand port numbers, increase bandwidth, simplify networking, and etc.

In a stack system, the switches can be categorized mainly into two roles: Master Switch and Member Switch. The master switch manages and controls devices in the whole stack system while the member switch only forwards data as a standby device of the master switch.

As the following figure shows, the switches are connected to form a stack which works as a unified system that enables multiple devices to collaborate under the management of the master switch as a whole.

Figure 1-1 Network Topology of a Stack Systemgraph TD A["Router"] --> B["Switch"] A --> C["Switch"] B --> D["Router"] B --> E["Member Switch"] C --> F["Router"] C --> G["Member Switch"] D --> H["Stack"] E --> H F --> H G --> H

2 Stack Concepts

Concepts related with Stack will be introduced in this chapter to enable Stack establishment and configuration.

Stack Role

Every single device is called a stack member once they form a stack system. Each stack member processes service packets and plays a role, either master or member, in the stack system according to the function they perform:

  • Master: The master switch manages the entire stack system, and there is only one master switch in one stack system.
  • Member: The member switch forwards data under the management of the master switch. If the master switch fails, a new master will be selected from the member switches to succeed the previous master.

Unit ID

When the stack is running, Unit ID is used to identify and manage stack members. Every member has its own unique unit ID in a stack system. To ensure uniqueness, it is recommended to prepare a unit number assignment scheme before establishing the stack and then manually configure it on each member device. When the stack is running, if you want to change the unit ID manually, only the unit numbers that have not been occupied by other member devices are available for you to choose from.

Priority

As an attribute of stack members, Priority can decide the role of the stack member during master election. The higher the priority value, the more likely the member will be elected as the master. We recommend manually assigning the highest priority value to the switch you prefer to be the stack master before stack establishment.

Stack Events

- Attach: This refers to the circumstance where two independent stacks are joined into one due to stack link establishment. Once attach happens, the previous masters compete to be the new master. The stack members of the defeated stack will join the winner stack to form a new stack. The master will assign Unit IDs to the newly joined members and compare their configuration files. Members with configuration files different from the master will download the master's configuration files and reconfigure.

- Detach: This refers to the circumstance where a stack is separated into two or more stacks because of stack link failures. When this occurs, each newly established stack elects its own new master and uses the MAC address of the master as its stack MAC address. However, stack separation may cause routing and forwarding problems on the network since the separated stacks continue operating with the previous IP address by default, resulting in IP addresses being reused in the same LAN.

3 Stack Operation Procedure

Stack involves four stages: Connecting the stack members, Topology collection, Master election, and Stack management and maintenance.

1. Configuring the Stack Port Groups and Connecting the Stack Members

To establish a stack, first configure the stack port groups (one port can also be called a stack port group) of the switches to be stacked one by one via the GUI. Then, physically connect the stack port groups of the member devices with cables to form a stack topology (will be introduced in Chapter 4).

2. Topology Collection

Each member in the stack collects and builds the topology of the whole stack by exchanging stack discovery packets with its neighbors. Initially, each member keeps a local record of the known topology information. After a period of time of broadcasting and updating information, all stack members can collect the complete topology information (known as topology convergence). Then the switch enters the master election stage.

3. Master Election

The stack will enter the master election stage after all members obtain the topology information. There is always one master in a stack system while the other devices are members. The stack role of the stack members is determined during master election.

Master election is held each time the topology changes, for example, when stack attach or detach occurs, or when the stack or the current master is reset.

The master is elected based on the following rules and in the order listed:

  1. The switch that is currently the stack master.
  2. The switch with the highest priority value.
  3. The switch with the lowest MAC address.

4. Stack Management and Maintenance

  • Stack Management: After the stack is established, all the stack members are integrated into a virtual device in the network. You can log in to the stack system through any member device to configure it and manage it via the master. Stack management can be implemented on the Stack Info and Stack Config pages. However, we highly recommend that you prepare the configuration planning with a clear set of roles and functions for each member device before configuring the stack.
  • Stack Maintenance: It enables the stack system to monitor the joining and leaving of member devices as well as the new topology to maintain the current topology.

When the stack is operating normally, packets are transmitted constantly between stack members. Once the switch finds out that the link status changes, it will recollect system topology and update the topology database to ensure the normal operation of the stack.

The events that will change the link status of the stack port and affect the system topology include: certain stack member failures, member leaving, new member's coming, link failure or failure recovery, etc.

When the master switch fails, the stack system elects a new master from the remaining members to succeed the previous master.

4 Stack Topology

With the stack feature, switches can be stacked into one topology for higher reliability, larger bandwidth, and simpler networking.

And according to different using scenarios, there are generally three stack topology structures. Please build the proper topology according to your needs:

Chain Topology

Compared with the other two structures, Chain Topology is relatively simple without requiring cable connection between the first and last unit (see Figure 2-1). It is suitable for long-distance stacking, but its reliability is not ideal.

Figure 4-1 Chain Topologygraph TD A["Switch"] --> B["Switch"] B --> C["Switch"] C --> D["Switch"]

Ring Topology

Compared with Chain Topology, Ring Topology has higher reliability. The ring topology automatically turns into a chain topology when one of its connections fails, enabling the entire stack system to continue working. As the ring topology requires cable connection between the first and last unit, it's not suitable for long-distance stacking.

Figure 4-2 Ring Topologygraph TD A["Switch"] --> B["Switch"] B --> C["Switch"] C --> D["Switch"] D --> E["Switch"]

Star Topology

Star topology connects the switches to a central master switch, therefore, it can significantly increase the data forwarding rate between member switches while providing unified management.

Figure 4-3 Star Topologygraph TD A["Switch"] --> B["Switch"] B --> C["Switch"] C --> D["Switch"] D --> E["Switch"]

TP-LINK Omada Pro S5500-24GP4F - Star Topology - 2

Note:

Before stacking, make sure that the firmware versions of the switches to be stacked are compatible; otherwise, the stack may fail due to versions with large gaps

5 Stack Operation Procedure

5.1 Using the GUI

5.1.1 Viewing the Stack Information

Choose the menu SYSTEM > Stack > Stack Info to load the following page.

Figure 5-1 Stack Info

Stack Info
Stack Topology:Solo
Stack MAC:00-0a-ab-00-13-31
Stack Member Info
Unit IDNew Unit IDRoleMAC AddressPriorityStack VersionDevice TypeState
11Master00-0a-ab-00-13 -3151.0.0S6500-24GP4X FReady
Stack Port Info
UNIT1
Stack PortStack Port GroupStatusNeighbor
1/0/250Ethernetnone
1/0/260Ethernetnone
1/0/270Ethernetnone
1/0/280Ethernetnone

You can view the stack information on this page.

TP-LINK Omada Pro S5500-24GP4F - Viewing the Stack Information - 1

Note:

The "Version" in "Stack Member Info" refers to the version number of the Stack.

Stack Info

Stack Topology Displays the type of the stack topology.
Stack MACDisplays the MAC address of the stack system.It is the MAC address of the master in the stack.

Stack Member Info

Unit ID Displays the current Unit of the switch in the stack.
New Unit ID Displays the new Unit ID for the switch.

Role: Displays the role of the switch in the stack.

MAC Address: Displays the MAC address of the switch in the stack.

Priority: Displays the priority of the switch in the stack.

State: Displays the state of the switch in the stack.

- Ready: The stack generation is completed.

- Processing: The stack generation is in process.

Stack Port Config

Stack Port Displays the stack port number.

Stack Port Group Displays the stack port group number.

Status Displays the status of the port.

- Down: No device is connected to the port.

- OK: The stack is running normally on the port.

- Authentication Fail: The peer device is not computable.

- Ethernet: The port works as an Ethernet port.

Neighbor Displays the connected neighbor UNIT number.

5.1.2 Configuring the Provision Info

Choose the menu SYSTEM > Stack > Stack Config to load the following page.

Figure 5-2 Provision Info ConfigProvision Info Unit ID: Device Type: S6500-48G6XF Apply

Follow these steps to configure Provision Info:

1) Choose the Unit ID of the provisioned switch. 2) Choose the Device Type of the provisioned switch. 3) Click Apply.

Provision Info

You can provision (to supply a configuration to) a new switch before it joins the switch stack. You can configure the Unit ID and device type in advance for the new switch. The switch that will be added to the stack and that receives this configuration is called a provisioned member.

Unit ID: Specify the Unit ID of the provisioned switch.

Device Type:

Specify the device type of the provisioned switch, which needs to be identical to that of the devices in the current stack system.

5.1.3 Configuring the Provisioned Member

After the Provision Info Config succeeded, you can view and delete the provisioned member on the same page.

Figure 5-3 Provisioned Member TableProvisioned Member Unit ID Device Type State 2 S6500-48G6XF Provisioned Total: 1

Follow these steps to delete a provisioned member.

1) Choose and click the provisioned member to be deleted.

2) Click Delete.

Figure 5-4 Deleting Provisioned MemberProvisioned Member Unit ID Device Type State 2 S6500-48G6XF Provisioned Total: 1 1 entry selected.

Provisioned Member

You can view or remove the provisioned switches of the stack in this section.

Unit ID: Displays the Unit ID of the provisioned switch.

Device Type: Displays the device type of the provisioned switch.

State Displays the state of the provisioned switch.

5.1.4 Configuring the Stack Member

On the same page, you can view and configure the stack member info.

Figure 5-5 Stack Member TableStack Member Config Unit ID New Unit ID Role MAC Address Priority State 1 1 Master 00-0a-eb-00-13-31 5 Ready Total: 1

Follow these steps to configure Stack Member info:

1) Choose the stack member to be configured. 2) Select the New Unit ID for the chosen stack member if it is to be changed. 3) Select the Priority for the chosen stack member if it is to be changed. 4) Click Apply.

Figure 5-6 Modifying Unit ID and PriorityStack Member Config Unit ID New Unit ID Role MAC Address Priority State ✓ ✓ ✓ ✓ ✓ ✓ 1 1 Master 00-0a-eb-00-13-31 5 Ready Total: 1 1 entry selected. Cancel Apply

Stack Member Config

You can config the Unit ID and priority of the switches in the stack.

Unit ID Displays the current Unit of the switch in the stack.

New Unit ID Configure a new Unit ID for the switch.

Role Displays the role of the switch in the stack.

MAC Address Displays the MAC address of the switch in the stack.

Priority Displays the priority of the switch in the stack.

Displays the state of the switch in the stack.

State

- Ready: The stack generation is completed.

- Processing: The stack generation is in process.

TP-LINK Omada Pro S5500-24GP4F - Stack Member Config - 1

Note:

If you change the New Unit ID of the stack member, the new setting will not take effect until rebooting the switch.

5.1.5 Configuring the Stack Port Group

On the same page, configure the Stack Port Groups of the units to be stacked.

Figure 5-7 Stack Port TableStack Port Group Config UNIT1 □ Stack Port Stack Port Group Status □ 1/0/25 -- Ethernet □ 1/0/26 -- Ethernet □ 1/0/27 -- Ethernet □ 1/0/28 -- Ethernet Total: 4

Follow these steps to configure Stack Port Group of UNIT 1 (here two units are used as an example of stack):

1) Choose the ports of UNIT1 to be configured. 2) Select the Stack Port Group NO. for the chosen ports. 3) Click Apply.

Figure 5-8 Configuring Stack Port Group of UNIT 1Stack Port Group Config UNIT1 Stack Port Stack Port Group Status ✓ 1/0/25 None Ethernet ✓ 1/0/26 None Ethernet □ 1/0/27 1 Ethernet □ 1/0/28 2 Ethernet 3 Total: 4 4 Cancel Apply 5 6 Notes:

After the configuration succeeded, the stack port table will show the current Stack Port Group NO. for the chosen ports.

Figure 5-9 Stack Port Table Showing the Stack Port Group NO.

Stack Port Group Config
UNIT1
Stack PortStack Port GroupStatus
1/0/251Down
1/0/261Down
1/0/27---Ethernet
1/0/28---Ethernet
Total: 4

Then, log out the GUI of UNIT 1 and log in the GUI of UNIT 2, repeat the steps to configure Stack Port Group of UNIT 2:

1) Choose the ports of UNIT2 to be configured (here the Table shows UNIT 1 as the stack system hasn't formed). 2) Select the Stack Port Group NO. for the chosen ports. 3) Click Apply.

Figure 5-10 Configuring Stack Port Group of UNIT 2Stack Port Group Config UNIT1 UNIT2 □ Stack Port Stack Port Group Status ✓ 1/0/49 Down ✓ 1/0/50 None Down □ 1/0/51 1 Ethernet □ 1/0/52 2 Ethernet □ 1/0/53 3 Ethernet □ 1/0/54 4 Ethernet Total: 6 --- Ethernet 2 entries selected. Cancel Apply

After the two switches are physically connected through the stack port groups, the status will change to "OK" for both UNITs. And the State in Stack Member Config will change to "ready", which means the stack generation is completed.

Figure 5-11 The "OK" Status of the Port Group

Stack Port Group Config
UNIT1UNIT2
Stack PortStack Port GroupStatus
1/0/491OK
1/0/501OK
1/0/51--Ethernet
1/0/52--Ethernet
1/0/53--Ethernet
1/0/54--Ethernet
Total: 6

Figure 5-12 The "Ready" Status of the Stack MemberTP-LINK Omada Pro S5500-24GP4F - Configuring the Stack Port Group - 4

Stack Port Config

You can configure the stack ports in the stack.

Stack Port Displays the stack port number.

Stack Port Group Displays the stack port group number.

Displays the status of the port. - Down: No device is connected to the port. Status - OK: The stack is running normally on the port. - Authentication Fail: The peer device is not computable. - Ethernet: The port works as an Ethernet port.

5.2 Using the CLI

5.2.1 Configuring Stack System Name

Follow these steps to configure the name of the stack system:

Step 1 configure

Enter global configuration mode.

Step 2 switch stack-name name

Specify the name of the stack system.

name: Specify the name of the stack system.

The following example shows how to specify the name of the stack system.

Switch#configure

Switch(config)#switch stack-name "test"

5.2.2 Entering Stack Port Group View

Follow these steps to access the viewing page of a specified stack port group configuration of the specified device:

Step 1 configure

Enter global configuration mode.

Step 2 switch unitid stack-group groupid

Enter the viewing page of a specified stack port group of the specified device.

unitid: Device ID in the stack system.

groupid: ID of the stack port group.

The following example shows how to enter the viewing page of a stack port group 1 on switch 1.

Switch#configure

switch(config)# switch 1 stack-group 1

5.2.3 Configuring Stack Port

Follow these steps to enable the stack function for a specified slot:

Step 1 configure

Enter global configuration mode.

Step 2 switch 2 stack-group 1

Enter stack group mode.

Step 3 switch(stack-group)# [no] interface port

Enable/disable the stack function for a specified port, and add the port to the stack group.

port: Add the port to the stack group.

The following example shows how to configure 1/0/28 as a stack port and join stack-group 1 of unit 2.

Switch#configure

switch(config)# switch 2 stack-group 1

switch(stack-group)# interface 1/0/28

5.2.4 Viewing Current Stack Port Group Info

Follow these steps to view the information of the current stack port group:

Step 1 configure

Enter global configuration mode.

Step 2 switch 2 stack-group 1

Enter stack group mode.

Step 2 switch(stack-group)# group-info

View the specified stack port group configuration of the specified device

group info: Displays the information of the stack group.

The following example shows how to view the information of the stack port group 1 on switch 2.

Switch#configure

switch(config)# switch 2 stack-group 1

switch(stack-group)# group-info

5.2.5 Configuring Stack Device Priority

Follow these steps to configure the stack priority of the device with specified unit ID:

Step 1 configure

Enter global configuration mode.

Step 2 switch

unitid priority priority

Configure the stack priority of the device with specified unit ID.

unitid: Device ID in the stack system, ranging from 1 to 12.

priority: Stack priority. The higher the priority, the more likely the device is to become the master device. The value ranges from 1 to 255.

The following example shows how to configure the stack priority of unit 1 as 5.

Switch#configure

switch(config)#switch 1 priority 5

5.2.6 Modifying Stack Unit ID

Follow these steps to modify the stack unit ID of a specified device:

Step 1 configure

Enter global configuration mode.

Step 2 switch

unitid renumber new-unitid

Modify the stack unit ID of a specified device, which will take effect after rebooting.

unitid: Device ID in the stack system, ranging from 1 to 12.

new-unitid: New device ID to be configured, ranging from 1 to 12.

The following example shows how to renumber the stack unit ID of unit 1 as 2.

Switch#configure

Switch(config)#switch 1 renumber 2

TP-LINK Omada Pro S5500-24GP4F - Switch(config)#switch 1 renumber 2 - 1

Note:

Changing the Unit number may result in a configuration change for that unit. The interface configuration associated with the old unit number will remain as a provisioned configuration. Do you want to continue?[Y/N] y

Changing Unit Number 1 to Unit Number 2. New Unit Number will be effective after next reboot.

5.2.7 Configuring Provision Entries

Follow these steps to configure provision entries:

Step 1 configure

Enter global configuration mode.

Step 2 switch

unitid provision device-type

Create a provisioned entry specifying unit ID and device-type. After creation, you can use other configuration commands to configure the unit. The configuration will take effect after the stack is connected. To delete the entry, use the no switch unitid provision device-type command.

unitid: Device ID in the stack system, ranging from 1 to 12.

device-type: Device type. The provision device needs to be of the same type as the connected device.

The following example shows how to configure provision entries.

Switch#configure

switch(config)#switch 1 provision 3

5.2.8 Configuring Stack Virtual MAC

Follow these steps to enable the virtual MAC feature.

Step 1 configure

Enter global configuration mode.

Step 2 switch mac-delay {

delay-time | immediately }

Enable or disable the virtual MAC feature. To disable this feature, please use the parameter "immediately".

delay-time: The delay time for virtual MAC switching (in minutes), ranging from 0-60 minutes. 0 indicates never switching the stack MAC. The default value is 10 minutes. If the original master switch in the stacking system temporarily leaves and returns within the switching time, the stack MAC address will not change. However, if the master switch does not return to the stacking system within the switching time, the stacking system will use the MAC address of the current master switch as the new MAC address.

immediately: When the stacking system changes, the stacking system MAC changes immediately, that is, the virtual MAC feature is not enabled.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the virtual MAC switching time to 5 minutes:

Switch#configure

Switch(config)#switch mac-delay 5

Switch(config)#end

Switch#copy running-config startup-config

5.2.9 Viewing MAC-delay Switching Time

Follow these steps to view the MAC-delay switching time of the current stacking system.

Step 1 configure

Enter global configuration mode.

Step 2 switch mac-delay show

Display the MAC-delay switching time of the current stacking system.

The following example shows how to view the MAC-delay switching time of the current stacking system:

Switch#configure

Switch(config)#switch mac-delay show

5.2.10 Viewing Stack Port Info

Follow these steps to view the stack port information of all members of the stack group:

Step 1 show switch stack-ports

View the stack port information of all members of the stack group.

The following example shows how to view the stack port information of all members of the stack group:

Switch#show switch stack-ports

5.2.11 Viewing Device Info

Follow these steps to view the information of all devices in the stack system:

Step 1 show switch unit-id

View information of all devices in the stack system.

unitid: Device ID in the stack system, ranging from 1 to 12

Note: Use this command to view the current stack system's topology type and MAC address, the unitID of existing or pre-configured members in the current stack system, new unitIDs to be configured, member switch MAC addresses, priorities, stack versions, device types, stack statuses, and configuration statuses:

Ready: Stack has been completed.

Processing: Stack is currently being processed.

Provisioned: Device is in pre-configuration mode.

Loading: Device is currently undergoing configuration.

Complete: Device configuration has completed.

All member switches' configuration information can only be viewed on the master switch, while through member switches can only the configuration status of their own be viewed.

The following example shows how to view the information of member switch 2.

Switch#show switch 2

5.2.12 Viewing Stack Neighbor

Follow these steps to view the group ID of the stack port and the unit ID of its neighboring member device in the current stack system:

Step 1 show switch neighbors

View the group ID of the stack port and the unit ID of its neighboring member device in the current stack system

The following example shows how to view the unit ID of the current stack system.

Switch#show switch neighbors

6

Appendix: Default Parameters

Default settings of Stack are listed in the following tables.

Table 6-1 Default Settings of Stack

Parameter Default Setting
Stack Member Config
Priority 5
Stack Port Group Config
Stack Port Group None

Part 5

Configuring DDM

(Only for Certain Devices)

CHAPTERS

  1. Overview
  2. DDM Configuration
  3. Appendix: Default Parameters

1 Overview

TP-LINK Omada Pro S5500-24GP4F - Overview - 1

Note:

DDM is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If DDM is available, there is L2 FEATURES > Switching > DDM in the menu structure.

The DDM (Digital Diagnostic Monitoring) function is used to monitor and manage the SFP modules inserted into the SFP ports. With this function, the user can configure multiple thresholds for the SFP module. The SFP port can be automatically shut down when the switch detects the operating parameter of the module exceeds the threshold. The monitored parameters include: Temperature, Voltage, Bias Current, Tx Power and Rx Power.

2 DDM Configuration

To complete DDM configuration, follow these steps:

1) Enable DDM function on the SFP port and configure the shutdown condition. 2) Configure the threshold for Warning or Alarm.

2.1 Using the GUI

2.1.1 Configuring DDM Globally

Choose the menu L2 FEATURES > Switching > DDM > DDM Config and select the desired SFP port to load the following page.

Figure 2-1 Configure DDM Globally

DDM Status
PortTemperature (℃)Voltage (V)Bias Current (mA)TX Power (mW)RX Power (mW)Transmit FaultLoss of SignalData Ready
1/0/25--------
1/0/26--------
1/0/27--------
1/0/28--------

Follow these steps to configure the DDM parameters on SFP ports:

1) In the Port Config section, select one or multiple SFP ports to configure DDM parameters.

DDM Status: Enable or disable DDM function.

Shutdown: Specify whether to shut down the port when the operating parameter exceeds the Alarm or Warning threshold.

None: The port will never be shut down regardless if the threshold ranges are exceeded or not. This is the default setting.

Alarm: The port will be shut down when the configured alarm threshold range is exceeded.

Warning: The port will be shut down when the configured warning threshold range is exceeded.

LAG: Displays the LAG that the port belongs to.

2) Click Apply.

2.1.2 Configuring the Threshold

TP-LINK Omada Pro S5500-24GP4F - Configuring the Threshold - 1

Note:

The value of threshold parameters should conform to the following rule: High Alarm ≥ High Warning ≥ Low Warning ≥ Low Alarm.

Choose the menu L2 FEATURES > Switching > DDM > Threshold Config to load the following page.

■ Configuring the Temperature Threshold

Figure 2-2 Configure Temperature Threshold

Temperature
PortHigh Alarm (-128-127.996 °C)Low Alarm (-128-127.996 °C)High Warning (-128-127.996 °C)Low Warning (-128-127.996 °C)LAG
1/0/25-----
1/0/26-----
1/0/27-----
1/0/28-----
Total: 4

Follow these steps to configure DDM's temperature threshold:

1) In the Temperature table, select one or more SFP ports to configure temperature threshold of the SFP ports.

High AlarmSpecify the highest threshold for the alarm. When the operating parameter rises above this value, action associated with the alarm will be taken. The valid values are from -128 to 127.996.
Low AlarmSpecify the lowest threshold for the alarm. When the operating parameter falls below this value, action associated with the alarm will be taken. The valid values are from -128 to 127.996.
High WarningSpecify the highest threshold for the warning. When the operating parameter rises above this value, action associated with the warning will be taken. The valid values are from -128 to 127.996.
Low WarningSpecify the lowest threshold for the warning. When the operating parameter falls below this value, action associated with the warning will be taken. The valid values are from -128 to 127.996.

LAG Displays the LAG that the port belongs to.

2) Click Apply.

■ Configuring the Voltage Threshold

Figure 2-3 Configure Voltage Threshold

Voltage
PortHigh Alarm(0-6.5535 V)Low Alarm(0-6.5535 V)High Warning(0-6.5535 V)Low Warning(0-6.5535 V)LAG
1/0/25
1/0/26
1/0/27
1/0/28
Total: 4

Follow these steps to configure DDM's voltage threshold:

1) In the Voltage table, select one or more SFP ports to configure voltage threshold on the SFP ports.

High AlarmSpecify the highest threshold for the alarm. When the operating parameter rises above this value, action associated with the alarm will be taken. The valid values are from 0 to 6.5535.
Low AlarmSpecify the lowest threshold for the alarm. When the operating parameter falls below this value, action associated with the alarm will be taken. The valid values are from 0 to 6.5535.
High WarningSpecify the highest threshold for the warning. When the operating parameter rises above this value, action associated with the warning will be taken. The valid values are from 0 to 6.5535.
Low WarningSpecify the lowest threshold for the warning. When the operating parameter falls below this value, action associated with the warning will be taken. The valid values are from 0 to 6.5535.

LAG Displays the LAG that the port belongs to.

2) Click Apply.

■ Configuring the Bias Current Threshold

Figure 2-4 Configure Bias Current Threshold

Bias Current
PortHigh Alarm(0-131 mA)Low Alarm(0-131 mA)High Warning(0-131 mA)Low Warning(0-131 mA)LAG
1/0/25
1/0/26
1/0/27
1/0/28
Total: 4

Follow these steps to configure DDM's bias current threshold:

1) In the Bias Current table, select one or more SFP ports to configure bias current threshold on the SFP ports.

High AlarmSpecify the highest threshold for the alarm. When the operating parameter rises above this value, action associated with the alarm will be taken. The valid values are from 0 to 131.
Low AlarmSpecify the lowest threshold for the alarm. When the operating parameter falls below this value, action associated with the alarm will be taken. The valid values are from 0 to 131.
High WarningSpecify the highest threshold for the warning. When the operating parameter rises above this value, action associated with the warning will be taken. The valid values are from 0 to 131.
Low WarningSpecify the lowest threshold for the warning. When the operating parameter falls below this value, action associated with the warning will be taken. The valid values are from 0 to 131.

LAG Displays the LAG that the port belongs to.

2) Click Apply.

■ Configuring the Tx Power Threshold

Figure 2-5 Configure Tx Power Threshold

TX Power
PortHigh Alarm(0-6.5535 mW)Low Alarm(0-6.5535 mW)High Warning(0-6.5535 mW)Low Warning(0-6.5535 mW)LAG
1/0/25----------
1/0/26----------
1/0/27----------
1/0/28----------
Total: 4

Follow these steps to configure DDM's Tx power threshold:

1) In the TX Power table, select one or more SFP ports to configure Tx power threshold on the SFP ports.

High AlarmSpecify the highest threshold for the alarm. When the operating parameter rises above this value, action associated with the alarm will be taken. The valid values are from 0 to 6.5535.
Low AlarmSpecify the lowest threshold for the alarm. When the operating parameter falls below this value, action associated with the alarm will be taken. The valid values are from 0 to 6.5535.
High WarningSpecify the highest threshold for the warning. When the operating parameter rises above this value, action associated with the warning will be taken. The valid values are from 0 to 6.5535.
Low WarningSpecify the lowest threshold for the warning. When the operating parameter falls below this value, action associated with the warning will be taken. The valid values are from 0 to 6.5535.
LAG Displays the LAG that the port belongs to.

2) Click Apply.

■ Configuring the Rx Power Threshold

Figure 2-6 Configure Rx Power Threshold

RX Power
PortHigh Alarm(0-6.5535 mW)Low Alarm(0-6.5535 mW)High Warning(0-6.5535 mW)Low Warning(0-6.5535 mW)LAG
1/0/25----------
1/0/26----------
1/0/27----------
1/0/28----------
Total: 4

Follow these steps to configure DDM's Rx power threshold:

1) In the RX Power table, select one or more SFP ports to configure the Rx power threshold on the SFP ports.

High AlarmSpecify the highest threshold for the alarm. When the operating parameter rises above this value, action associated with the alarm will be taken. The valid values are from 0 to 6.5535.
Low AlarmSpecify the lowest threshold for the alarm. When the operating parameter falls below this value, action associated with the alarm will be taken. The valid values are from 0 to 6.5535.
High WarningSpecify the highest threshold for the warning. When the operating parameter rises above this value, action associated with the warning will be taken. The valid values are from 0 to 6.5535.
Low WarningSpecify the lowest threshold for the warning. When the operating parameter falls below this value, action associated with the warning will be taken. The valid values are from 0 to 6.5535.

LAG Displays the LAG that the port belongs to.

2) Click Apply.

2.1.3 Viewing DDM Status

Choose the menu L2 FEATURES > Switching > DDM > DDM Status to load the following page.

Figure 2-7 View DDM Status

DDM Status
PortTemperature (°C)Voltage (V)Bias Current (mA)TX Power (mW)RX Power (mW)Transmit FaultLoss of SignalData Ready
1/0/25----------------
1/0/26----------------
1/0/27----------------
1/0/28----------------
Total: 4

In the DDM Status table, view the current operating parameters for the SFP modules inserted into the SFP ports.

Temperature Displays the current temperature of the SFP module inserted into a specific port.

Voltage Displays the current voltage of the SFP module inserted into a specific port.

Bias Current Displays the current bias current of the SFP module inserted into a specific port.

Tx Power Displays the current Tx power of the SFP module inserted into a specific port.

Rx Power Displays the current Rx power of the SFP module inserted into a specific port.

Transmit Fault Reports remote SFP module signal loss. The values are True, False and No Signal.

Loss of Signal Reports local SFP module signal loss. The values are True and False.

Data Ready Indicates whether the SFP module is operational. The values are True and False.

2.2 Using the CLI

2.2.1 Configuring DDM Globally

Follow these steps to enable DDM on specified SFP ports:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet

port | range fastEthernet port-list | gigabitEthernet port | range

gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list }

Enter interface configuration mode.

Step 3 ddm state enable

Enable DDM on this SFP port.

Step 4 show ddm configuration state

Display the DDM state of the SFP ports.

Step 5 end

Return to Privileged EXEC Mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable DDM status on SFP port 1/0/25:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/25

Switch(config-if)#ddm state enable

Switch(config-if)#show ddm configuration state

Port DDM Status Shutdown

Gi1/0/25 Enable None

...

Switch(config-if)#end

Switch#copy running-config startup-config

2.2.2 Configuring DDM Shutdown

Follow these steps to configure settings for shutting down SFP ports when the alarm threshold or warning threshold is exceeded:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet

port | range fastEthernet port-list | gigabitEthernet port | range

gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list }

Enter interface configuration mode.

Step 3 ddm shutdown { none | warning | alarm }

none: The port will not be shut down if the alarm threshold or warning threshold is exceeded.

warning: Shut down the port when the warning threshold is exceeded.

alarm: Shut down the port when the alarm threshold is exceeded.

Step 4 show ddm configuration state

Display the DDM state of the SFP ports.

Step 5 end

Return to Privileged EXEC Mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set SFP port 1/0/25 to shut down when the warning threshold is exceeded.

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/25

Switch(config-if)#ddm shutdown warning

Switch(config-if)#show ddm configuration state

DDM Status Shutdown

Gi1/0/25 Enable Warning

...

Switch(config-if)#end

Switch#copy running-config startup-config

2.2.3 Configuring the Threshold

■ Configuring Temperature Threshold

Follow these steps to configure the threshold of the DDM temperature on the specified SFP port.

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet

port | range fastEthernet port-list | gigabitEthernet port | range

gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list }

Enter interface configuration mode.

Step 3ddm temperature_threshold { high_alarm | high_warning | low_alarm | low_warning } valuehigh_alarm: Specify the high threshold for the alarm. When the operating parameter rises above this value, action associated with the alarm will be taken.high_warning: Specify the high threshold for the warning. When the operating parameter rises above this value, action associated with the warning will be taken.low_alarm: Specify the low threshold for the alarm. When the operating parameter falls below this value, action associated with the alarm will be taken.low_warning: Specify the low threshold for the warning. When the operating parameter falls below this value, action associated with the warning will be taken.value: Enter the threshold value in Celsius. The valid values are from -128 to 127.996.
Step 4show ddm configuration temperatureDisplay the DDM temperature threshold on the SFP ports.
Step 5endReturn to Privileged EXEC Mode.
Step 6copy running-config startup-configSave the settings in the configuration file.

The following example shows how to set SFP port 1/0/27's high alarm temperature threshold as 110 Celsius.

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/27

Switch(config-if)#ddm temperature_threshold high_alarm 110

Switch(config-if)#show ddm configuration temperature

Temperature Threshold(Celsius):

High Alarm Low Alarm High Warning Low Warning

Gi1/0/27 110.000000 -- -- --

...

Switch(config-if)#end

Switch#copy running-config startup-config

■ Configuring Voltage Threshold

Follow these steps to configure the threshold of the DDM voltage on the specified SFP port.

Step 1 configure Enter global configuration mode.

Step 2 interface { fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list }Enter interface configuration mode.
Step 3ddm voltage_threshold { high_alarm | high_warning | low_alarm | low_warning } valuehigh_alarm: Specify the high threshold for the alarm. When the operating parameter rises above this value, action associated with the alarm will be taken.high_warning: Specify the high threshold for the warning. When the operating parameter rises above this value, action associated with the warning will be taken.low_alarm: Specify the low threshold for the alarm. When the operating parameter falls below this value, action associated with the alarm will be taken.low_warning: Specify the low threshold for the warning. When the operating parameter falls below this value, action associated with the warning will be taken.value: Enter the threshold value in V. The valid values are from 0 to 6.5535.

Step 4 show ddm configuration voltage

Display the DDM voltage threshold of the SFP ports.

Step 5 endReturn to Privileged EXEC Mode.
Step 6 copy running-config startup-configSave the settings in the configuration file.

The following example shows how to set SFP port 1/0/27's high alarm threshold voltage as 5 V.

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/27

Switch(config-if)#ddm vlotage_threshold high_alarm 5

Switch(config-if)#show ddm configuration voltage

Voltage Threshold(V):

High Alarm Low Alarm High Warning Low Warning

Gi1/0/27

5.000000

--

--

--

...

Switch(config-if)#end

Switch#copy running-config startup-config

■ Configuring Bias Current Threshold

Follow these steps to configure the threshold of the DDM bias current on the specified SFP port.

Step 1 configure Enter global configuration mode.

Step 2 interface { fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list }Enter interface configuration mode.
Step 3ddm bias_current_threshold { high_alarm | high_warning | low_alarm | low_warning } valuehigh_alarm: Specify the high threshold for the alarm. When the operating parameter rises above this value, action associated with the alarm will be taken.high_warning: Specify the high threshold for the warning. When the operating parameter rises above this value, action associated with the warning will be taken.low_alarm: Specify the low threshold for the alarm. When the operating parameter falls below this value, action associated with the alarm will be taken.low_warning: Specify the low threshold for the warning. When the operating parameter falls below this value, action associated with the warning will be taken.value: Enter the threshold value in mA. The valid values are from 0 to 131.

Step 4 show ddm configuration bias_current Display the DDM bias current threshold of the SFP ports. Step 5 end Return to Privileged EXEC Mode. Step 6 copy running-config startup-config Save the settings in the configuration file.

The following example shows how to set SFP port 1/0/27's high alarm threshold bias current as 120 mA.

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/17

Switch(config-if)#ddm vlotage_threshold high_alarm 120

Switch(config-if)#show ddm configuration bias_current

Voltage Threshold(V):

High Alarm Low Alarm High Warning Low Warning

Gi1/0/27

120.000000

--

--

--

...

Switch(config-if)#end

Switch#copy running-config startup-config

Configuring Rx Power Threshold

Follow these steps to configure the threshold of the DDM Rx power on the specified SFP port.

Step 1 configure Enter global configuration mode.

Step 2 interface { fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list }Enter interface configuration mode.
Step 3ddm rx_power_threshold { high_alarm | high_warning | low_alarm | low_warning } valuehigh_alarm: Specify the high threshold for the alarm. When the operating parameter rises above this value, action associated with the alarm will be taken.high_warning: Specify the high threshold for the warning. When the operating parameter rises above this value, action associated with the warning will be taken.low_alarm: Specify the low threshold for the alarm. When the operating parameter falls below this value, action associated with the alarm will be taken.low_warning: Specify the low threshold for the warning. When the operating parameter falls below this value, action associated with the warning will be taken.value: Enter the threshold value in mW. The valid values are from 0 to 6.5535.

Step 4 show ddm configuration rx_power Display the DDM rx power threshold on the SFP ports. Step 5 end Return to Privileged EXEC Mode. Step 6 copy running-config startup-config Save the settings in the configuration file.

The following example shows how to set SFP port 1/0/27's high alarm threshold Rx power as 6 mW.

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/27

Switch(config-if)#ddm rx_power_threshold high_alarm 6

Switch(config-if)#show ddm configuration rx_power

Rx Power Threshold(mW) :

High Alarm Low Alarm High Warning Low Warning

Gi1/0/27

6.000000

--

--

--

...

Switch(config-if)#end

Switch#copy running-config startup-config

■ Configuring Tx Power Threshold

Follow these steps to configure the threshold of the DDM Tx power on the specified SFP port.

Step 1 configure Enter global configuration mode.

Step 2 interface { fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list }Enter interface configuration mode.
Step 3ddm tx_power_threshold { high_alarm | high_warning | low_alarm | low_warning } valuehigh_alarm: Specify the high threshold for the alarm. When the operating parameter rises above this value, action associated with the alarm will be taken.high_warning: Specify the high threshold for the warning. When the operating parameter rises above this value, action associated with the warning will be taken.low_alarm: Specify the low threshold for the alarm. When the operating parameter falls below this value, action associated with the alarm will be taken.low_warning: Specify the low threshold for the warning. When the operating parameter falls below this value, action associated with the warning will be taken.value: Enter the threshold value in mW. The valid values are from 0 to 6.5535.

Step 4 show ddm configuration tx_power Display the DDM tx power threshold on the SFP ports. Step 5 end Return to Privileged EXEC Mode. Step 6 copy running-config startup-config Save the settings in the configuration file.

The following example shows how to set SFP port 1/0/27's high alarm threshold Tx power as 6 mW.

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/27

Switch(config-if)#ddm tx_power_threshold high_alarm 6

Switch(config-if)#show ddm configuration tx_power

Tx Power Threshold(mW) :

High Alarm Low Alarm High Warning Low Warning

Gi1/0/27 6.000000 -- -- --

...

Switch(config-if)#end

Switch#copy running-config startup-config

2.2.4 Viewing DDM Configuration

Follow these steps to view the DDM configuration.

Step 1 configure Enter global configuration mode.

Step 2show ddm configuration { state | temperature | voltage | bias_current | tx_power | rx_power}state: Displays the DDM configuration state.temperature: Displays the threshold of the DDM temperature value.voltage: Displays the threshold of the DDM voltage value.bias_current: Displays the threshold of the DDM bias current value.tx_power: Displays the threshold of the DDM Tx Power value.rx_power: Displays the threshold of the DDM Rx Power value.

Step 3 end Return to Privileged EXEC Mode. Step 4 copy running-config startup-config Save the settings in the configuration file.

The following example shows how to view SFP ports' Rx power threshold.

Switch#configure

Switch(config)#show ddm configuration rx_power

Rx Power Threshold(mW) :

High Alarm Low Alarm High Warning Low Warning

Gi1/0/27 6.000000 -- -- --

Gi1/0/28 -- -- -- --

Switch(config)#end

2.2.5 Viewing DDM Status

Follow these steps to view the DDM status, which is the digital diagnostic monitoring status of SFP modules inserted into the switch's SFP ports.

Step 1 configure

Enter global configuration mode.

Step 2 show ddm status

Displays all the monitoring status of SFP modules.

Step 3 end

Return to Privileged EXEC Mode.

The following example shows how to view SFP ports' DDM status.

Switch#configure

Switch(config)#show ddm status

Temperature(C)Rx Power(mW)Voltage(V)Data ReadyBias Current(mA)Rx LosTx Power(mW)Tx Fault
Gi1/0/27--------
--------
Gi1/0/28--------
--------

Switch(config)#end

3 Appendix: Default Parameters

Default settings of DDM are listed in the following table.

Table 3-1 Default Settings of DDM

Parameter Default Setting
DDM Status Enabled. All the SFP ports are being monitored.
ShutdownNone. The port will not be shut down even if the alarm or warning threshold is exceeded.

Part 6

Configuring LAG

CHAPTERS

  1. LAG
  2. LAG Configuration
  3. Configuration Examples
  4. Appendix: Default Parameters

1 LAG

1.1 Overview

LAG (Link Aggregation Group) is to combine multiple physical ports together to make a single logical channel, which can greatly extend bandwidth. The bandwidth of the LAG is the sum of the bandwidth of its member ports.

1.2 Supported Features

You can configure LAG in two ways: static LAG and LACP (Link Aggregation Control Protocol).

Static LAG

The member ports are manually added to the LAG.

LACP

LACP (Link Aggregation Control Protocol) enables dynamic link aggregation and disaggregation by exchanging LACP packets with its peer (directly connected device that also implements LACP). The switch can dynamically combine ports with similar configurations to create a single logical channel with greater bandwidth and flexible load balancing.

2 LAG Configuration

To complete LAG configuration, follow these steps:

1) Configure the global load-balancing algorithm. 2) Configure Static LAG or LACP.

Configuration Guidelines

■ Ensure that both ends of the aggregation link work in the same LAG mode. For example, if the local end works in LACP mode, the peer end should also be set as LACP mode. ■ Ensure that devices on both ends of the aggregation link use the same number of physical ports with the same speed, duplex, jumbo and flow control mode.

■ A port cannot be added to more than one LAG at the same time. ■ LACP does not support half-duplex links.

■ One static LAG supports up to eight member ports. All the member ports share the bandwidth evenly. If an active link fails, the other active links share the bandwidth evenly.

■ One LACP LAG supports multiple member ports, but at most eight of them can work simultaneously, and the other member ports are backups. Using LACP protocol, the switches negotiate parameters and determine the working ports. When a working port fails, the backup port with the highest priority will replace the faulty port and start to forward data.

For the functions like IGMP Snooping, 802.1Q VLAN, MAC VLAN, Protocol VLAN, VLAN-VPN, GVRP, Voice VLAN, STP, QoS, DHCP Snooping and Flow Control, the member port of an LAG follows the configuration of the LAG but not its own. The configurations of the port can take effect only after it leaves the LAG.

■ The port enabled with Port Security, Port Mirror, MAC Notification or 802.1X cannot be added to an LAG, and the member port of an LAG cannot be enabled with these functions.

2.1 Using the GUI

2.1.1 Configuring Load-balancing Algorithm

Choose the menu L2 FEATURES > Switching > LAG > LAG Table to load the following page.

Figure 2-1 Global ConfigGlobal Config Hash Algorithm: SRC MAC+DST MAC LAG Table Apply Delete Group ID Description Members Operation No entries in this table. Total: 0

In the Global Config section, select the load-balancing algorithm (Hash Algorithm), then click Apply.

Hash Algorithm

Select the Hash Algorithm, based on which the switch can choose the port to forward packets. In this way, different data flows are forwarded on different physical links to implement load balancing. There are six options:

SRC MAC: The computation is based on the source MAC addresses of the packets.

DST MAC: The computation is based on the destination MAC addresses of the packets.

SRC MAC+DST MAC: The computation is based on the source and destination MAC addresses of the packets.

SRC IP: The computation is based on the source IP addresses of the packets.

DST IP: The computation is based on the destination IP addresses of the packets.

SRC IP+DST IP: The computation is based on the source and destination IP addresses of the packets.

Tips:

  • Load-balancing algorithm is effective only for outgoing traffic. If the data stream is not well shared by each link, you can change the algorithm of the outgoing interface. ■ Please properly choose the load-balancing algorithm to avoid data stream transferring only on one physical link. For example, Switch A receives packets from several hosts and forwards them to the Server with the fixed MAC address, you can set the algorithm

as "SRC MAC" to allow Switch A to determine the forwarding port based on the source MAC addresses of the received packets.

Figure 2-2 Hash Algorithm Configurationgraph LR A["Computer 1"] --> B["Switch A"] C["Computer 2"] --> B D["Server"] --> B B <--> E["Switch A Switch B"]

Hosts Server

2.1.2 Configuring Static LAG or LACP

For one port, you can choose only one LAG mode: Static LAG or LACP. And make sure both ends of a link use the same LAG mode.

■ Configuring Static LAG

Choose the menu L2 FEATURES > Switching > LAG > Static LAG to load the following page.

Figure 2-3 Static LAGLAG Config Group ID: Description: Port: (Format: 1/0/1, input or choose below) UNIT1 1 3 5 7 9 11 13 15 17 19 21 23 25 27 2 4 6 8 10 12 14 16 18 20 22 24 26 28 Selected Unselected Not Available Apply

Follow these steps to configure the static LAG:

1) Select a LAG for configuration.

Group ID: Select a LAG for static LAG configuration.

Description: Displays the type of the LAG.

Port: Enter the port number or simply click the port to choose the member ports of the LAG.

2) Select the member ports for the LAG. This is multi-optional. 3) Click Apply.

TP-LINK Omada Pro S5500-24GP4F - ■ Configuring Static LAG - 2

Note:

Clearing all member ports will delete the LAG.

- Configuring LACP

Choose the menu L2 FEATURES > Switching > LAG > LACP to load the following page.

Figure 2-4 LACP ConfigGlobal Config System Priority: 32768 (0-65535) Apply LACP Config UNIT1 Port Status Group ID Port Priority Mode LAG 1/0/1 Disabled 0 32768 Passive --- 1/0/2 Disabled 0 32768 Passive --- 1/0/3 Disabled 0 32768 Passive --- 1/0/4 Disabled 0 32768 Passive --- 1/0/5 Disabled 0 32768 Passive --- 1/0/6 Disa…

Follow these steps to configure LACP:

1) Specify the system priority of the switch and click Apply.

System Priority

Specify the system priority for the switch. A smaller value means a higher priority. When exchanging information between switches, the switch with higher priority determines the link aggregation a port belongs to, and the system with lower priority adds the proper ports to the link aggregation according to the selection of its peer.

2) Select the member port to be added to the LAG and configure the related parameters, then click Apply.

Port Select one or more ports to configure.

Status Enable or disable the LACP function of the port. By default, it is disabled.

Group ID Specify the group ID of the LAG.

Note that the value cannot be the same as the group number of other static LAGs.

The valid value of the group ID is determined by the maximum number of LAG supported by your switch. For example, if your switch supports up to 14 LAGs, the valid value is from 1 to 14.

Specify the Port Priority. A smaller value means a higher port priority. The value ranges from 0 to 65535, and the default value is 32768.

In an LAG, only eight ports can work simultaneously, the ports with higher priorities will be selected as the working port to forward data, and the other ports are backup ports. If two ports have the same priority value, the port with the smaller port number has the higher priority.

Mode Select the LACP mode for the port.

In LACP, the switch uses LACPDU (Link Aggregation Control Protocol Data Unit) to compare the LACP parameters with the peer end's. In this way, the two ends select working ports and form the aggregation link. The LACP mode determines whether the port will take the initiative to send the LACPDU at the beginning of the LACP process. There are two modes:

Passive: The port will not send LACPDU before receiving the LACPDU from the peer end.

Active: The port will take the initiative to send LACPDU.

LAG Displays the LAG that the port belongs to.

2.2 Using the CLI

2.2.1 Configuring Load-balancing Algorithm

Follow these steps to configure the load-balancing algorithm:

Step 1 configure

Enter global configuration mode.

Step 2port-channel load-balance {src-mac | dst-mac | src-dst-mac | src-ip | dst-ip | src-dst-ip}Select the Hash Algorithm. The switch will choose the ports to transfer the packets based on the Hash Algorithm. In this way, different data flows are forwarded on different physical links to implement load balancing.src-mac: The computation is based on the source MAC addresses of the packets.dst-mac: The computation is based on the destination MAC addresses of the packets.src-dst-mac: The computation is based on the source and destination MAC addresses of the packets.src-ip: The computation is based on the source IP addresses of the packets.dst-ip: The computation is based on the destination IP addresses of the packets.src-dst-ip: The computation is based on the source and destination IP addresses of the packets.

Step 3 show etherchannel load-balance

Verify the configuration of load-balancing algorithm.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the global load-balancing mode as src-dst-mac:

Switch#configure

Switch(config)#port-channel load-balance src-dst-mac

Switch(config)#show etherchannel load-balance

EtherChannel Load-Balancing Configuration:

src-dst-mac

EtherChannel Load-Balancing Addresses Used Per-Protocol:

Non-IP: Source XOR Destination MAC address

IPv4: Source XOR Destination MAC address

IPv6: Source XOR Destination MAC address

Switch(config)#end

Switch#copy running-config startup-config

2.2.2 Configuring Static LAG or LACP

You can choose only one LAG mode for a port: Static LAG or LACP. And make sure both ends of a link use the same LAG mode.

■ Configuring Static LAG

Follow these steps to configure static LAG:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list ]

Enter interface configuration mode.

Step 3 channel-group

num mode on

Add the port to a static LAG.

num: The group ID of the LAG.

Step 4 show etherchannel

num summary

Verify the configuration of the static LAG.

num: The group ID of the LAG.

Step 5 end

Return to privileged EXEC mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to add ports1/0/5-8 to LAG 2 and set the mode as static LAG:

Switch#configure

Switch(config)#interface range gigabitEthernet 1/0/5-8

Switch(config-if-range)#channel-group 2 mode on

Switch(config-if-range)#show etherchannel 2 summary

Flags: D - down

P - bundled in port-channel

U - in use

I - stand-alone

H - hot-standby (LACP only)

s - suspended

R - layer3

S - layer2

f - failed to allocate aggregator

u - unsuitable for bundling

w - waiting to be aggregated

d - default port

GroupPort-channelProtocolPorts
----------------
2Po2(S)-Gi1/0/5(D) Gi1/0/6(D) Gi1/0/7(D) Gi1/0/8(D)

Switch(config-if-range)#end

Switch#copy running-config startup-config

- Configuring LACP

Follow these steps to configure LACP:

Step 1 configure

Enter global configuration mode.

Step 2 lacp system-priority pri

Specify the system priority for the switch.

To keep active ports consistent at both ends, you can set the priority of one device to be higher than that of the other device. The device with higher priority will determine its active ports, and the other device can select its active ports according to the selection result of the device with higher priority. If the two ends have the same system priority value, the end with a smaller MAC address has the higher priority.

pri: System priority. The valid values are from 0 to 65535, and the default value is 32768. A smaller value means a higher device priority.

Step 3 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list ]

Enter interface configuration mode.

Step 4 channel-group num mode {active | passive}

Add the port to an LAG and set the mode as LACP.

num: The group ID of the LAG.

mode: LAG mode. Here you need to select LACP mode: active or passive.

In LACP, the switch uses LACPDU (Link Aggregation Control Protocol Data Unit) to negotiate the parameters with the peer end. In this way, the two ends select active ports and form the aggregation link. The LACP mode determines whether the port will take the initiative to send the LACPDU.

passive: The port will not send LACPDU before receiving the LACPDU from the peer end.

active: The port will take the initiative to send LACPDU.

Step 5 lacp port-priority pri

Specify the Port Priority. The port with higher priority in an LAG will be selected as the working port. If two ports have the same priority value, the port with a smaller port number has the higher priority.

pri: Port priority. The valid values are from 0 to 65535, and the default value is 32768. A smaller value means a higher port priority.

Step 6 show lacp sys-id

Verify the global system priority.

Step 7 show lacp internal

Verify the LACP configuration of the local switch.

Step 8 end

Return to privileged EXEC mode.

Step 9 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to specify the system priority of the switch as 2:

Switch#configure

Switch(config)#lacp system-priority 2

Switch(config)#show lacp sys-id

2,000a.eb13.2397

Switch(config)#end

Switch#copy running-config startup-config

The following example shows how to add ports 1/0/1-4 to LAG 6, set the mode as LACP, and select the LACPDU sending mode as active:

Switch#configure

Switch(config)#interface range gigabitEthernet 1/0/1-4

Switch(config-if-range)#channel-group 6 mode active

Switch(config-if-range)#show lacp internal

Flags: S - Device is requesting Slow LACPDUs

F - Device is requesting Fast LACPDUs

A - Device is in active mode

P - Device is in passive mode

Channel group 6

PortFlagsStateLACP Port PriorityAdmin KeyOper KeyPort NumberPort State
Gi1/0/1SAUp327680x60x4b10x10x7d
Gi1/0/2SADown327680x600x20x45
Gi1/0/3SADown327680x600x30x45

Gi1/0/4 SA Down 32768 0x6 0 0x4 0x45

Switch(config-if-range)#end

Switch#copy running-config startup-config

3 Configuration Examples

3.1 Example for Static LAG

3.1.1 Network Requirements

As shown below, hosts and servers are connected to switch A and switch B, and heavy traffic is transmitted between the two switches. To achieve high speed and reliability of data transmission, users need to improve the bandwidth and redundancy of the link between the two switches.

Figure 3-1 Network Topologygraph LR A["Hosts"] --> B["Switch A Switch B"] B --> C["Servers"] B -->|Gi1/0/8| B B -->|Gi1/0/1| B

3.1.2 Configuration Scheme

LAG function can bundle multiple physical ports into one logical interface to increase bandwidth and improve reliability. In this case we can configure static LAG to meet the requirement.

The overview of the configuration is as follows:

1) Considering there are multiple devices on each end, configure the load-balancing algorithm as 'SRC MAC+DST MAC'.

2) Add ports 1/0/1-8 to a static LAG.

Demonstrated with S6500-24GP4XF, the following sections provide configuration procedure in two ways: using the GUI and using the CLI.

3.1.3 Using the GUI

The configurations of switch A and switch B are similar. The following introductions take switch A as an example.

1) Choose the menu L2 FEATURES > Switching > LAG > LAG Table to load the following page. Select the hash algorithm as 'SRC MAC+DST MAC'.

Figure 3-2 Global ConfigurationGlobal Config Hash Algorithm: SRC MAC+DST MAC Apply

2) Choose the menu L2 FEATURES > Switching > LAG > Static LAG to load the following page. Select LAG 1 and add ports 1/0/1-8 to LAG 1.

Figure 3-3 System Priority ConfigurationLAG Config Group ID: LAG1 Description: -- Port: 1/0/1-8 (Format: 1/0/1, input or choose below) UNIT1 1 3 5 7 2 4 6 8 37 39 41 43 45 47 49 51 53 38 40 42 44 46 48 50 52 54 Selected Unselected Not Available Apply

3) Click Save the settings.

3.1.4 Using the CLI

The configurations of switch A and switch B are similar. The following introductions take switch A as an example.

1) Configure the load-balancing algorithm as "src-dst-mac".

Switch#configure

Switch(config)#port-channel load-balance src-dst-mac

2) Add ports 1/0/1-8 to static LAG 1.

Switch(config)#interface range gigabitEthernet 1/0/1-8

Switch(config-if-range)#channel-group 1 mode on

Switch(config-if)#end

Switch#copy running-config startup-config

Verify the Configuration

Switch#show etherchannel 1 summary

Flags: D - downP - bundled in port-channelU - in use
I - stand-aloneH - hot-standby(LACP only)s - suspended
R - layer3S - layer2f - failed to allocate aggregator
u - unsuitable for bundlingw - waiting to be aggregatedd - default port
GroupPort-channelProtocolPorts
----------------
1Po2(S)-Gi1/0/1(D)Gi1/0/2(D)Gi1/0/3(D)
Gi1/0/5(D)Gi1/0/6(D)Gi1/0/7(D)

3.2 Example for LACP

3.2.1 Network Requirements

As shown below, hosts and servers are connected to Switch A and Switch B, and heavy traffic is transmitted between the two switches. To achieve high speed and reliability of data transmission, users need to improve the bandwidth and redundancy of the link between the two switches.

3.2.2 Configuration Scheme

LAG function can bundle multiple physical ports into one logical interface to increase bandwidth and improve reliability. In this case, we take LACP as an example.

As shown below, you can bundle up to eight physical ports into one logical aggregation group to transmit data between the two switches, and respectively connect the ports of the groups. In addition, another two redundant links can be set as the backup. To avoid traffic bottleneck between the servers and Switch B, you also need to configure LAG on them to increase link bandwidth. Here we mainly introduce the LAG configuration between the two switches.

Figure 3-1 Network Topologygraph LR A["Hosts"] -->|Gi1/0/1 Gi1/0/1| B["Switch A Switch B"] B -->|Gi1/0/10 Gi1/0/10| C["Servers"]

The overview of the configuration is as follows:

1) Considering there are multiple devices on each end, configure the load-balancing algorithm as 'SRC MAC+DST MAC'.

2) Specify the system priority for the switches. Here we choose Switch A as the dominate device and specify a higher system priority for it. 3) Add ports 1/0/1-10 to the LAG and set the mode as LACP. 4) Specify a lower port priority for ports 1/0/9-10 to set them as the backup ports. When any of ports 1/0/1-8 is down, the backup ports will automatically be enabled to transmit data.

Demonstrated with S6500-24GP4XF, the following sections provide configuration procedure in two ways: using the GUI and using the CLI.

3.2.3 Using the GUI

The configurations of Switch A and Switch B are similar. The following introductions take Switch A as an example.

1) Choose the menu L2 FEATURES > Switching > LAG > LAG Table to load the following page. Select the hash algorithm as 'SRC MAC+DST MAC'.

Figure 3-2 Global ConfigurationGlobal Config Hash Algorithm: SRC MAC+DST MAC Apply

2) Choose the menu L2 FEATURES > Switching > LAG > LACP Config to load the following page. In the Global Config section, specify the system priority of Switch A as 0 and click Apply. Remember to ensure that the system priority value of Switch B is bigger than 0.

Figure 3-3 System Priority ConfigurationGlobal Config System Priority: 0 (0-65535) Apply

3) In the LACP Config section, select ports 1/0/1-10, and respectively set the status, group ID, port priority and mode for each port as follows.

Figure 3-4 LACP ConfigurationLACP Config UNIT1 Port Status Group ID Port Priority Mode LAG Enable 1 0 Active ✓ 1/0/1 Enabled 1 0 Active --- ✓ 1/0/2 Enabled 1 0 Active --- ✓ 1/0/3 Enabled 1 0 Active --- ✓ 1/0/4 Enabled 1 0 Active --- ✓ 1/0/5 Enabled 1 0 Active --- ✓ 1/0/6 Enabled 1 0 Active --- ✓ 1/0/7 Enabled 1 0 Active --- ✓ 1…

4) Click Save the settings.

3.2.4 Using the CLI

The configurations of Switch A and Switch B are similar. The following introductions take Switch A as an example.

1) Configure the load-balancing algorithm as "src-dst-mac".

Switch#configure

Switch(config)#port-channel load-balance src-dst-mac

2) Specify the system priority of Switch A as 0. Remember to ensure that the system priority value of Switch B is bigger than 0.

Switch(config)#lacp system-priority 0

3) Add ports 1/0/1-8 to LAG 1 and set the mode as LACP. Then specify the port priority as 0 to make them active.

Switch(config)#interface range gigabitEthernet 1/0/1-8

Switch(config-if-range)#channel-group 1 mode active

Switch(config-if-range)#lacp port-priority 0

Switch(config-if-range)#exit

4) Add port 1/0/9 to LAG 1 and set the mode as LACP. Then specify the port priority as 1 to set it as a backup port. When any of the active ports is down, this port will be preferentially selected to work as an active port.

Switch(config)#interface gigabitEthernet 1/0/9

Switch(config-if)#channel-group 1 mode active

Switch(config-if)#lacp port-priority 1

Switch(config-if)#exit

5) Add port 1/0/10 to LAG 1 and set the mode as LACP. Then specify the port priority as 2 to set it as a backup port. The priority of this port is lower than port 1/0/9.

Switch(config)#interface gigabitEthernet 1/0/10

Switch(config-if)#channel-group 1 mode active

Switch(config-if)#lacp port-priority 2

Switch(config-if)#end

Switch#copy running-config startup-config

Verify the Configuration

Verify the system priority:

Switch#show lacp sys-id

0,000a.eb13.2397

Verify the LACP configuration:

Switch#show lacp internal

Flags: S - Device is requesting Slow LACPDUs

F - Device is requesting Fast LACPDUs

A - Device is in active mode

P - Device is in passive mode

Channel group 1

PortFlagsStateLACPPort PriorityAdmin KeyOper KeyPort NumberPort State
Gi1/0/1SADown00x100x10x45
Gi1/0/2SADown00x100x20x45
Gi1/0/3SADown00x100x30x45
Gi1/0/4SADown00x100x40x45
Gi1/0/5SADown00x100x50x45
Gi1/0/6SADown00x100x60x45
Gi1/0/7SADown00x100x70x45
Gi1/0/8 SADown00x100x80x45
Gi1/0/9 SADown10x100x90x45
Gi1/0/10 SADown20x100xa0x45

4 Appendix: Default Parameters

Default settings of Switching are listed in the following tables.

Table 4-1 Default Settings of LAG

Parameter Default Setting
LAG Table
Hash Algorithm SRC IP+DST IP
LACP Config
System Priority 32768
Admin Key 0
Port Priority 32768
Mode Passive
Status Disabled

Part 7

Managing MAC Address Table

CHAPTERS

  1. MAC Address Table
  2. MAC Address Configurations
  3. Security Configurations
  4. Example for Security Configurations
  5. Appendix: Default Parameters

1 MAC Address Table

1.1 Overview

Address Table displays all the MAC address entries recorded by the switch, which is the basis for the switch to perform Layer 2 packet forwarding. You can view all the information of the Address Table here.

Table 1-1 The MAC Address Table

MAC Address VLAN ID Port Type Aging Status
00:00:00:00:00:01 1 1 Dynamic Aging
00:00:00:00:00:02 1 2 Static No-Aging
...

1.2 Supported Features

The address table of the switch contains dynamic addresses, static addresses and filtering addresses. For devices which support security configurations, you can configure notification traps and limit the number of MAC addresses in a VLAN for traffic safety.

Address Configurations

■ Dynamic address

Dynamic addresses are addresses learned by the switch automatically, and the switch regularly ages out those that are not in use. That is, the switch removes the MAC address entries related to a network device if no packet is received from the device within the aging time. And you can specify the aging time if needed.

■ Static address

Static addresses are manually added to the address table and do not age. For some relatively fixed connection, for example, frequently visited server, you can manually set the MAC address of the server as a static entry to enhance the forwarding efficiency of the switch.

■ Filtering address

The filtering address entry is used to block the undesired packets from being forwarded. The filtering address can be added or removed manually and does not age.

Security Configurations

TP-LINK Omada Pro S5500-24GP4F - Security Configurations - 1

Note:

Security Configurations are only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If Security Configurations are available, there are L2 FEATURES > Switching > MAC Address > MAC Notifications and L2 FEATURES > Switching > MAC Address > MAC VLAN Security in the menu structure.

■ Configuring MAC Notification Traps

You can configure traps and SNMP (Simple Network Management Protocol) to monitor and receive notifications of the usage of the MAC address table and the MAC address change activity. For example, you can configure the switch to send notifications when a new MAC address is learned, so the administrator knows a new users accesses the network.

■ Limiting the Number of MAC Addresses in VLANs

You can configure VLAN Security to limit the number of MAC addresses that can be learned in specified VLANs. The switch will not learn addresses when the number of learned addresses has reached the limit, preventing the address table from being used up by broadcasting packets of MAC address attacks.

MAC Address Configurations

With MAC address table, you can:

■ Add static MAC address entries ■ Change the MAC address aging time ■ Add filtering address entries ■ View address table entries

2.1 Using the GUI

2.1.1 Adding Static MAC Address Entries

You can add static MAC address entries by manually specifying the desired MAC address or binding dynamic MAC address entries.

■ Adding MAC Addresses Manually

Choose the menu L2 FEATURES > Switching > MAC Address > Static Address and click + Add to load the following page.

Figure 2-1 Adding MAC Addresses ManuallyStatic Address MAC Address: (Format: 00-00-00-00-00-01) VLAN ID: (1-4094) Port: (Format: 1/0/1, input or choose below) UNIT 1 1 3 5 7 9 11 13 15 17 19 21 23 25 27 2 4 6 8 10 12 14 16 18 20 22 24 26 28 Selected Unselected Not Available Cancel Create

Follow these steps to add a static MAC address entry:

1) Enter the MAC address, VLAN ID and select a port to bind them together as an address entry.

MAC Address Enter the MAC address included in the static entry.

VLAN ID Enter the VLAN ID included in the static entry.

Port Select the corresponding port included in the static entry. The port must belong to the specified VLAN.

After you have added the static MAC address, if the corresponding port number of the MAC address is not correct, or the connected port (or the device) has been changed, the switch cannot forward the packets correctly. Please reset the static address entry appropriately.

Type Displays the type of the MAC address entry.

Aging Status Displays the aging status of the MAC address entry.

2) Click Create.

■ Binding Dynamic Address Entries

If some dynamic address entries are frequently used, you can bind these entries as static entries.

Choose the menu L2 FEATURES > Switching > MAC Address > Dynamic Address to load the following page.

Figure 2-2 Binding Dynamic MAC Address EntriesAging Config Auto Aging: ✓ Enable Aging Time: 300 seconds (10-630) Apply Dynamic Address Table UNIT1 □ MAC Address VLAN ID Port Type Aging Status □ 40-ED-00-22-30-40 1 1/0/1 Dynamic Aging Total: 1 Showing 1-1 of 1 records Items per page: 100 ▼

Follow these steps to bind dynamic MAC address entries:

1) In the Dynamic Address Table section, Select your desired MAC address entries. 2) Click Bind, and then the selected entries will become static MAC address entries.

TP-LINK Omada Pro S5500-24GP4F - Adding Static MAC Address Entries - 3

Note:

  • In the same VLAN, once an address is configured as a static address, it cannot be set as a filtering address, and vice versa. • Multicast or broadcast addresses cannot be set as static addresses.
  • Ports in LAGs (Link Aggregation Group) are not supported for static address configuration.

2.1.2 Modifying the Aging Time of Dynamic Address Entries

Choose the menu L2 FEATURES > Switching > MAC Address > Dynamic Address to load the following page.

Figure 2-3 Modifying the Aging Time of Dynamic Address EntriesAging Config Auto Aging: ✓ Enable Aging Time: 300 seconds (10-630) Apply

Follow these steps to modify the aging time of dynamic address entries:

1) In the Aging Config section, enable Auto Aging, and enter your desired length of time.

Auto Aging: Enable or disable auto aging for the dynamic MAC address entries.

Aging Time

Specify the aging time for the dynamic MAC address entry. It is the duration that a dynamic entry remains in the MAC address table after the entry is used or updated. The valid values are from 10 to 630 seconds, and the default value is 300.

2) Click Apply.

2.1.3 Adding MAC Filtering Address Entries

Choose the menu L2 FEATURES > Switching > MAC Address > Filtering Address and click + Add to load the following page.

Figure 2-4 Adding MAC Filtering Address EntriesFiltering Address MAC Address: (Format: 00-00-00-00-00-01) VLAN ID: (1-4094) Cancel Create

Follow these steps to add MAC filtering address entries:

1) Enter the MAC Address and VLAN ID.

MAC Address: Enter the MAC address included in the filtering address entry.

VLAN ID: Enter the VLAN ID included in the filtering address entry.

2) Click Create.

TP-LINK Omada Pro S5500-24GP4F - Adding MAC Filtering Address Entries - 2

Note:

  • In the same VLAN, once an address is configured as a filtering address, it cannot be set as a static address, and vice versa. • Multicast or broadcast addresses cannot be set as filtering addresses.

2.1.4 Viewing Address Table Entries

You can view entries in the MAC address table to check your former operations and address information.

Choose the menu L2 FEATURES > Switching > MAC Address > Address Table and click

TP-LINK Omada Pro S5500-24GP4F - Viewing Address Table Entries - 1

Search to load the following page.

Figure 2-5 Viewing Address Table EntriesAddress Table MAC Address VLAN ID Type Dynamic Static Filter Port (Format: 00-00-00-00-00-01) (1-4094) Clear Search MAC Address VLAN ID Port Type Aging Status 40-ED-00-22-30-40 1 1/0/1 Dynamic Aging Total: 1

2.2 Using the CLI

2.2.1 Adding Static MAC Address Entries

Follow these steps to add static MAC address entries:

Step 1 configure

Enter global configuration mode.

Step 2 mac address-table static mac-addr vid vid interface {fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port }

Bind the MAC address, VLAN, and port together to add a static address to the VLAN.

mac-addr: Enter the MAC address, and packets with this destination address received in the specified VLAN are forwarded to the specified port. The format is xx:xx:xx:xx:xx:xx, for example, 00:00:00:00:00:01.

vid: Specify an existing VLAN in which packets with the specific MAC address are received.

port: Specify a port to which packets with the specific MAC address are forwarded. The port must belong to the specified VLAN.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

TP-LINK Omada Pro S5500-24GP4F - Step 4 copy running-config startup-config - 1

Note:

  • In the same VLAN, once an address is configured as a static address, it cannot be set as a filtering address, and vice versa. • Multicast or broadcast addresses cannot be set as static addresses.
  • Ports in LAGs (Link Aggregation Group) are not supported for static address configuration.

The following example shows how to add a static MAC address entry with MAC address 00:02:58:4f:6c:23, VLAN 10 and port 1. When a packet is received in VLAN 10 with this address as its destination, the packet will be forwarded only to port 1/0/1.

Switch#configure

Switch(config)# mac address-table static 00:02:58:4f:6c:23 vid 10 interface gigabitEthernet 1/0/1

Switch(config)#show mac address-table static

MAC Address Table

MACVLANPortTypeAging
00:02:58:4f:6c:2310Gi1/0/1config staticno-aging

Total MAC Addresses for this criterion: 1

Switch(config)#end

Switch#copy running-config startup-config

2.2.2 Modifying the Aging Time of Dynamic Address Entries

Follow these steps to modify the aging time of dynamic address entries:

Step 1 configure

Enter global configuration mode.

Step 2 mac address-table aging-time

aging-time

Set your desired length of address aging time for dynamic address entries.

aging-time: Set the length of time that a dynamic entry remains in the MAC address table after the entry is used or updated. The valid values are from 10 to 630. Value 0 means the Auto Aging function is disabled. The default value is 300 and we recommend you keep the default value if you are unsure.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to modify the aging time to 500 seconds. A dynamic entry remains in the MAC address table for 500 seconds after the entry is used or updated.

Switch#configure

Switch(config)# mac address-table aging-time 500

Switch(config)#show mac address-table aging-time

Aging time is 500 sec.

Switch(config)#end

Switch#copy running-config startup-config

2.2.3 Adding MAC Filtering Address Entries

Follow these steps to add MAC filtering address entries:

Step 1 configure

Enter global configuration mode.

Add the filtering address to the VLAN.

mac-addr: Specify a MAC address to be used by the switch to filter the received packets. The switch will drop packets of which the source address or destination address is the specified MAC address. The format is xx:xx:xx:xx:xx:xx, for example, 00:00:00:00:00:01.

vid: Specify an existing VLAN in which packets with the specific MAC address will be dropped.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

TP-LINK Omada Pro S5500-24GP4F - Step 1 configure - 1

Note:

  • In the same VLAN, once an address is configured as a filtering address, it cannot be set as a static address, and vice versa. Multicast or broadcast addresses cannot be set as filtering addresses.

The following example shows how to add the MAC filtering address 00:1e:4b:04:01:5d to VLAN 10. Then the switch will drop the packet that is received in VLAN 10 with this address as its source or destination.

Switch#configure

Switch(config)# mac address-table filtering 00:1e:4b:04:01:5d vid 10

Switch(config)#show mac address-table filtering

MAC Address Table

MACVLANPortTypeAging
-------------------
00:1e:4b:04:01:5d10filterno-aging

Total MAC Addresses for this criterion: 1

Switch(config)#end

Switch#copy running-config startup-config

3 Security Configurations

TP-LINK Omada Pro S5500-24GP4F - Security Configurations - 1

Note:

Security Configurations are only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If Security Configurations are available, there are L2 FEATURES > Switching > MAC Address > MAC Notifications and L2 FEATURES > Switching > MAC Address > MAC VLAN Security in the menu structure.

With security configurations of the MAC address table, you can:

Configure MAC notification traps. Limit the number of MAC addresses in VLANs.

3.1 Using the GUI

3.1.1 Configuring MAC Notification Traps

Choose the menu L2 FEATURES > Switching > MAC Address > MAC Notification to load the following page.

Figure 3-1 Configuring MAC Notification TrapsMAC Notification Global Config Global Status: Enable Table Full Notification: Enable Notification Interval: 1 seconds (1-1000) Apply MAC Notification Port Config UNIT1 Port Learned Mode Change New MAC Learned Gi1/0/1 Disabled Disabled Gi1/0/2 Disabled Disabled Gi1/0/3 Disabled Disabled Gi1/0/4 Disab…

Follow these steps to configure MAC notification traps:

1) In the MAC Notification Global Config section, enable this feature, configure the relevant options, and click Apply.

Global Status Enable or disable the MAC notification feature globally.
Table Full NotificationEnable or disable Table Full Notification. With this option enabled, a notification will be generated and sent to the management host when the MAC address table is full.
Notification IntervalSpecify the time value of Notification Interval. Notification Interval is the interval at which the New MAC Learned notifications are continuously sent.

2) In the MAC Notification Port Config section, select one or more ports to configure the notification status. Click Apply.

Learned Mode ChangeEnable or disable Learned Mode Change. With this option enabled, when the learned mode of the specified port is changed, a notification will be generated and sent to the management host.
New MAC LearnedEnable or disable New MAC Learned. With this option enabled, when the specified port learns a new MAC address, a notification will be generated and sent to the management host.

3) Configure SNMP and set a management host. For detailed SNMP configurations, please refer to Configuring SNMP & RMON.

3.1.2 Limiting the Number of MAC Addresses Learned in VLANs

■ For Certain Devices

Choose the menu L2 FEATURES > Switching > MAC Address > MAC VLAN Security to load the following page.

Figure 3-2 Configuring the MAC VLAN Security Mode

MAC VLAN Security Config

MAC VLAN Security Mode:

TP-LINK Omada Pro S5500-24GP4F - ■ For Certain Devices - 1

Drop

TP-LINK Omada Pro S5500-24GP4F - ■ For Certain Devices - 2

Forward

Apply

MAC VLAN Security Table

TP-LINK Omada Pro S5500-24GP4F - ■ For Certain Devices - 3

Add

TP-LINK Omada Pro S5500-24GP4F - ■ For Certain Devices - 4

Delete

VLAN IDMax Learned NumberCurrent Learned NumberOperation
No entries in this table.
Total: 0

Follow these steps to limit the number of MAC addresses in VLANs:

1) In the MAC VLAN Security Config section, select the security mode for all VLANs.

Drop: Packets with new source MAC addresses in the VLAN will be dropped when the maximum number of MAC addresses is exceeded.

Forward: Packets of new source MAC addresses will be forwarded but the addresses will not be learned when the maximum number of MAC addresses is exceeded.

2) In the MAC VLAN Security Table section, click Add to load the following page. Enter the VLAN ID and the Max Learned Number to limit the number of MAC addresses that can be learned in the specified VLAN.

Figure 3-3 Limiting the Number of MAC Addresses in VLANsVLAN Security Config VLAN ID: (1-4094) Max Learned Number: (0-16383) Cancel Create

VLAN ID: Specify an existing VLAN in which you want to limit the number of MAC addresses.

Max Learned Number:

Set the maximum number of MAC addresses in the specific VLAN. It ranges from 0 to 16383.

You can control the available address table space by setting maximum learned MAC number for VLANs. However, an improper maximum number can cause unnecessary floods in the network or a waste of address table space. Therefore, before you set the number limit, please be sure you are familiar with the network topology and the switch system configuration.

3) Click Create.

■ For Certain Devices

Choose the menu L2 FEATURES > Switching > MAC Address > MAC VLAN Security and click Add to load the following page.

Figure 3-4 Limiting the Number of MAC Addresses in VLANsVLAN Security Config VLAN ID: (1-4094) Max Learned Number: (0-16383) Mode: Drop Cancel Create

Follow these steps to limit the number of MAC addresses in VLANs:

1) Enter the VLAN ID to limit the number of MAC addresses that can be learned in the specified VLAN.

VLAN ID Specify an existing VLAN in which you want to limit the number of MAC addresses.

2) Enter your desired value in Max Learned Number to set a threshold.

Max Learned NumberSet the maximum number of MAC addresses in the specific VLAN. It ranges from 0 to 16383.You can control the available address table space by setting maximum learned MAC number for VLANs. However, an improper maximum number can cause unnecessary floods in the network or a waste of address table space. Therefore, before you set the number limit, please be sure you are familiar with the network topology and the switch system configuration.

3) Choose the mode that the switch adopts when the maximum number of MAC addresses in the specified VLAN is exceeded.

Drop Packets with new source MAC addresses in the VLAN will be dropped when the maximum number of MAC addresses in the specified VLAN is exceeded.

Forward Packets of new source MAC addresses will be forwarded but the addresses will not be learned when the maximum number of MAC addresses in the specified VLAN is exceeded.

4) Click Create.

3.2 Using the CLI

3.2.1 Configuring MAC Notification Traps

Follow these steps to configure MAC notification traps:

Step 1configureEnter global configuration mode.
Step 2mac address-table notification global-status {enable | disable}Enable MAC Notification globally.enable | disable: Enable or disable MAC Notification globally.
Step 3mac address-table notification table-full-status [enable | disable](Optional) Enable Table Full Notification.enable | disable: With Table Full Notification enabled, when address table is full, a notification will be generated and sent to the management host.
Step 4mac address-table notification interval timeSpecify the time value of Notification Interval. Notification Interval is the interval at which the New MAC Learned notifications are continuously sent.time: Specify the Notification Interval in seconds between 1to 1000. By default, it is 1 second.
Step 5interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list }Configure notification traps on the specified port.port/ port-list: The number or the list of the Ethernet port that you want to configure notification traps.
Step 6 mac address-table notification {[learn-mode-change enable | disable] [new-mac-learned enable | disable]}Enable learn-mode-change, exceed-max-learned, or new-MAC-learned notification traps on the specified port.enable | disable:Enable or disable learn-mode-change, exceed-max-learned, or new-MAC-learned notification traps on the specified port.learn-mode-change: With learn-mode-change enabled, when the learned mode of the specified port is changed, a notification will be generated and sent to the management host.new-mac-learned: With new-mac-learned enabled, when the specified port learns a new MAC address, a notification will be generated and sent to the management host.

Step 7 end

Return to privileged EXEC mode.

Step 8 copy running-config startup-config

Save the settings in the configuration file.

Now you have configured MAC notification traps. To receive notifications, you need to further enable SNMP and set a management host. For detailed SNMP configurations, please refer to Configuring SNMP & RMON.

The following example shows how to enable new-MAC-learned trap on port 1, and set the interval time as 10 seconds. After you have further configured SNMP, the switch will bundle notifications of new addresses in every 10 seconds and send to the management host.

Switch#configure

Switch(config)#mac address-table notification global-status enable

Switch(config)#mac address-table notification interval 10

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#mac address-table notification new-mac-learned enable

Switch(config-if)#show mac address-table notification interface gigabitEthernet 1/0/1

Mac Notification Global Config

Notification Global Status : enable

Table Full Notification Status: disable

Notification Interval : 10

Port LrnMode Change New Mac Learned

Gi1/0/1 disable enable

Switch(config-if)#end

Switch#copy running-config startup-config

3.2.2 Limiting the Number of MAC Addresses in VLANs

■ For Certain Devices

Follow these steps to limit the number of MAC addresses in VLANs:

Step 1 configure

Enter global configuration mode.

Step 2 mac address-table vlan-security mode {drop | forward}

Specify the VLAN security mode for all the VLANs.

drop | forward: The mode that the switch adopts when the maximum number of MAC addresses in the specified VLAN is exceeded.

drop: Packets of new source MAC addresses in the VLAN will be dropped when the maximum number of MAC addresses in the specified VLAN is exceeded.

forward: Packets of new source MAC addresses will be forwarded but the addresses not learned when the maximum number of MAC addresses in the specified VLAN is exceeded.

Step 3 mac address-table vlan-security vid vid max-learn num

Configure the maximum number of MAC addresses in the specified VLAN and select a mode for the switch to adopt when the maximum number is exceeded.

vid: Specify an existing VLAN in which you want to limit the number of MAC addresses.

num: Set the maximum number of MAC addresses in the specific VLAN. It ranges from 0 to 16383.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to limit the number of MAC addresses to 100 in VLAN 10, and configure the switch to drop packets of new source MAC addresses when the limit is exceeded.

Switch#configure

Switch(config)#mac address-table vlan-security mode drop

Switch(config)#mac address-table vlan-security vid 10 max-learn 100

Switch(config)#show mac address-table vlan-security vid 10

VlanIdMax-learnCurrent-learnStatus
----------------
101000Drop

Switch(config)#end

Switch#copy running-config startup-config

■ For Certain Devices

Follow these steps to limit the number of MAC addresses in VLANs:

Step 1 configure

Enter global configuration mode.

Step 2 mac address-table security vid

vid max-learn num {drop | forward}

Configure the maximum number of MAC addresses in the specified VLAN and select a mode for the switch to adopt when the maximum number is exceeded.

vid: Specify an existing VLAN in which you want to limit the number of MAC addresses.

num: Set the maximum number of MAC addresses in the specific VLAN. It ranges from 0 to 16383.

drop | forward: The mode that the switch adopts when the maximum number of MAC addresses in the specified VLAN is exceeded.

drop: Packets of new source MAC addresses in the VLAN will be dropped when the maximum number of MAC addresses in the specified VLAN is exceeded.

forward: Packets of new source MAC addresses will be forwarded but the addresses not learned when the maximum number of MAC addresses in the specified VLAN is exceeded.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to limit the number of MAC addresses to 100 in VLAN 10, and configure the switch to drop packets of new source MAC addresses when the limit is exceeded.

Switch#configure

Switch(config)#mac address-table security vid 10 max-learn 100 drop

Switch(config)#show mac address-table security vid 10

VlanIdMax-learnCurrent-learnStatus
----------------
101000Drop

Switch(config)#end

Switch#copy running-config startup-config

4 Example for Security Configurations

4.1 Network Requirements

Several departments are connected to the company network as shown in Figure 4-1. Now the Marketing Department that is in VLAN 10 has network requirements as follows:

■ Free the network system from illegal accesses and MAC address attacks by limiting the number of access users in this department to 100. ■ Assist the network manager supervising the network with notifications of any new access users.

Figure 4-1 The Network Topologygraph TD A["Internet"] --> B["Gi1/0/1"] B --> C["Gi1/0/2"] B --> D["Gi1/0/3"] C --> E["..."] D --> F["..."] G["Marketing Department VLAN 10"] --> H["..."] I["R&D Department VLAN 30"] --> J["..."] K["..."]

4.2 Configuration Scheme

VLAN Security can be configured to limit the number of access users and in this way to prevent illegal accesses and MAC address attacks.

MAC Notification and SNMP can be configured to monitor the interface which is used by the Marketing Department. Enable the new-MAC-learned notification and the SNMP, then the network manager can get notifications when new users access the network.

Demonstrated with T2600G-28TS, this chapter provides configuration procedures in two ways: using the GUI and using the CLI.

4.3 Using the GUI

1) Choose the menu L2 FEATURES > Switching > MAC Address > MAC VLAN Security and click Add to load the following page. Set the maximum number of MAC addresses in VLAN 10 as 100, choose drop mode, and click Create.

Figure 4-2 Configuring VLAN SecurityVLAN Security Config VLAN ID: 10 (1-4094) Max Learned Number: 100 (0-16383) Mode: Drop Cancel Create

2) Choose the menu L2 FEATURES > Switching > MAC Address > MAC Notification to load the following page. Enable Global Status, set notification interval as 10 seconds, and click Apply. Then, enable new-mac-learned trap on port 1/0/2 and click Apply.

Figure 4-3 Configuring New-MAC-learned TrapsMAC Notification Global Config Global Status: ✓ Enable Table Full Notification: □ Enable Notification Interval 10 seconds (1-1000) Apply MAC Notification Port Config UNIT1 Port Learned Mode Change New MAC Learned Enable Gi1/0/1 Disabled Disabled ✓ Gi1/0/2 Disabled Enabled Gi1/0/3 Disabled Disabled G…

3) Click Save to save the settings.

4) Enable SNMP and set a management host. For detailed SNMP configurations, please refer to Configuring SNMP & RMON.

4.4 Using the CLI

1) Set the maximum number of MAC addresses in VLAN 10 as 100, and choose drop mode. Switch#configure Switch(config)#mac address-table security vid 10 max-learn 100 drop 2) Configure the new-MAC-learned trap on port 1/0/2 and set notification interval as 10 seconds. Switch(config)#mac address-table notification global-status enable Switch(config)#mac address-table notification interval 10 Switch(config)#interface gigabitEthernet 1/0/2 Switch(config-if)#mac address-table notification new-mac-learned enable Switch(config-if)#end Switch#copy running-config startup-config

3) Configure SNMP and set a management host. For detailed SNMP configurations, please refer to Configuring SNMP & RMON.

Verify the Configurations

Verify the configuration of VLAN Security.

Switch#show mac address-table security vid 10

VlanIdMax-learnCurrent-learnStatus
----------------
101000Drop

Verify the configuration of MAC Notification on port 1/0/2.

Switch#show mac address-table notification interface gigabitEthernet 1/0/2

Port LrnMode Change New Mac Learned

Gi1/0/2 disable enable

5 Appendix: Default Parameters

Default settings of the MAC Address Table are listed in the following tables.

Table 5-1 Entries in the MAC Address Table

Parameter Default Setting
Static Address Entries None
Dynamic Address Entries Auto-learning
Filtering Address Entries None

Table 5-2 Default Settings of Dynamic Address Table

Parameter Default Setting
Auto Aging Enabled
Aging Time 300 seconds

Table 5-3 Default Settings of MAC Notification

Parameter Default Setting
Global Status Disabled
Table Full Notification Disabled
Notification Interval 1 Second
Learned Mode Change NotificationDisabled
Exceed Max Learned NotificationDisabled
New MAC Learned Notification Disabled

Part 8

Configuring

802.1Q VLAN

CHAPTERS

  1. Overview
  2. 802.1Q VLAN Configuration
  3. Configuration Example
  4. Appendix: Default Parameters

1 Overview

VLAN (Virtual Local Area Network) is a network technology that solves broadcasting issues in local area networks. It is usually used to restrict broadcast domain and enhance network security. 802.1Q VLAN is a technology to classify the VLANs based on IEEE 802.1Q protocol. The VLANs are distinguished by VLAN IDs. It is usually applied in the following occasions:

■ To restrict broadcast domain: VLAN technique divides a big local area network into several VLANs, and all VLAN traffic remains within its VLAN. It reduces the influence of broadcast traffic in Layer 2 network to the whole network. ■ To enhance network security: Devices from different VLANs cannot achieve Layer 2 communication, and thus users can group and isolate devices to enhance network security. ■ For easier management: VLANs group devices logically instead of physically, so devices in the same VLAN need not be located in the same place. It eases the management of devices in the same work group but located in different places.

2 802.1Q VLAN Configuration

To complete 802.1Q VLAN configuration, follow these steps:

1) Configure the VLAN, including creating a VLAN and adding the desired ports to the VLAN.

2) Configure port parameters for 802.1Q VLAN.

2.1 Using the GUI

2.1.1 Configuring the VLAN

Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > VLAN Config and click to load the following page.

Figure 2-1 Configuring VLANVLAN Config VLAN ID: (2-4094, format: 2,4-5,8) VLAN Name: (1-16 characters) Untagged Ports Port: (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 49 51 53 42 44 46 4…

Follow these steps to configure VLAN:

1) Enter a VLAN ID and a description for identification to create a VLAN.

VLAN ID Enter an ID number for the VLAN with the values between 2 and 4094.

VLAN Name Specify a VLAN description for identification with up to 16 characters.

Members Displays the port members in the VLAN.

2) Select the untagged port(s) and the tagged port(s) respectively to add to the created VLAN based on the network topology.

Untagged port

Select untagged ports to be added to the VLAN. The ports will take out the VLAN tags of the packets and forward them in the target VLAN.

Tagged port Select tagged ports to be added to the VLAN. The ports will keep the VLAN tags of the packets and forward them in the target VLAN.

3) Click Apply.

TP-LINK Omada Pro S5500-24GP4F - Configuring the VLAN - 2

Note:

- Deleting VLANs may affect some other related features, such as ACL, IP-MAC binding, Guest VLAN, MVR, Static Address and so on.

2.1.2 Configuring Port Parameters for 802.1Q VLAN

Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > Port Config to load the following page.

Figure 2-2 Configuring the Port

Port Config
UNIT1LAGS
PortPVIDIngress CheckingAcceptable Frame TypesLAGDetails
1/0/11EnabledAdmit All-Details
1/0/21EnabledAdmit All-Details
1/0/31EnabledAdmit All-Details
1/0/41EnabledAdmit All-Details
1/0/51EnabledAdmit All-Details
1/0/61EnabledAdmit All-Details
1/0/71EnabledAdmit All-Details
1/0/81EnabledAdmit All-Details
1/0/91EnabledAdmit All-Details
1/0/101EnabledAdmit All-Details
Total: 54

Select a port and configure the parameters. Click Apply.

PVID Enter the default VLAN ID for the port. It can be added to the untagged packets as VLAN ID, and then the port will forward the packets in the corresponding VLAN.

Ingress CheckingEnable or disable Ingress Checking. With this function enabled, the port will accept the packet of which the VLAN ID is in the port's VLAN list and discard others. With this function disabled, the port will forward the packet directly.
Acceptable Frame TypesSelect the acceptable frame type for the port and the port will perform this operation before Ingress Checking.
Admit All: The port will accept both the tagged packets and the untagged packets.
Tagged Only: The port will accept the tagged packets only.
LAG Displays the LAG that the port belongs to.
Details Click the Detail button to view the VLANs to which the port belongs.

2.2 Using the CLI

2.2.1 Creating a VLAN

Follow these steps to create a VLAN:

Step 1configure
Enter global configuration mode.
Step 2vlanvlan-listWhen you enter a new VLAN ID, the switch creates a new VLAN and enters VLAN configuration mode; when you enter an existing VLAN ID, the switch directly enters VLAN configuration mode.vlan-list: Specify the ID or the ID list of the VLAN(s) for configuration. Valid values are from 2 to 4094, for example, 2-3,5.
Step 3namedescript(Optional) Specify a VLAN description for identification.descript: The length of the description should be 1 to 16 characters.
Step 4show vlan [ idvlan-list ]Show the global information of the specified VLAN(s). When no VLAN is specified, this command shows global information of all 802.1Q VLANs.vlan-list: Specify the ID or the ID list of the VLAN(s) to show information. Valid values are from 1 to 4094.
Step 5end
Return to privileged EXEC mode.
Step 6copy running-config startup-config
Save the settings in the configuration file.

The following example shows how to create VLAN 2 and name it as RD:

Switch#configure

Switch(config)#vlan 2

Switch(config-vlan)#name RD

Switch(config-vlan)#show vlan id 2

VLANNameStatusPorts
2RDactiveGi1/0/1, Gi1/0/2

Switch(config-vlan)#end

Switch#copy running-config startup-config

2.2.2 Adding the Port to the Specified VLAN

Follow these steps to add the port to the specified VLAN:

Step 1configureEnter global configuration mode.
Step 2interface{fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}Enter interface configuration mode.
Step 3switchport general allowed vlanvlan-list { tagged | untagged }Add ports to the specified VLAN.vlan-list: Specify the ID or ID list of the VLAN(s) that the port will be added to. The ID ranges from 1 to 4094.tagged | untagged: Select the egress rule for the port.
Step 4show interface switchport [fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel lag-id]Verify the information of the port.
Step 5endReturn to privileged EXEC mode.
Step 6copy running-config startup-configSave the settings in the configuration file.

The following example shows how to add the port 1/0/5 to VLAN 2, and specify its egress rule as tagged:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/5

Switch(config-if)#switchport general allowed vlan 2 tagged

Switch(config-if)#show interface switchport gigabitEthernet 1/0/5

Port Gi1/0/5:

PVID: 2

Acceptable frame type: All

Ingress Checking: Enable

Member in LAG: N/A

Link Type: General

Member in VLAN:

Vlan Name Egress-rule

1 System-VLAN Untagged

2 RD Tagged

Switch(config-if)#end

Switch#copy running-config startup-config

2.2.3 Configuring the Port

Follow these steps to configure the port:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 3 switchport pvid vlan-id

Configure the PVID of the port(s). By default, it is 1.

vlan-id: The default VLAN ID of the port with the values between 1 and 4094.

Step 4 switchport check ingress

Enable or disable Ingress Checking. With this function enabled, the port will accept the packet of which the VLAN ID is in the port's VLAN list and discard others. With this function disabled, the port will forward the packet directly.

Step 5switchport acceptable frame {all | tagged}Select the acceptable frame type for the port and the port will perform this operation before Ingress Checking.all: The port will accept both the tagged packets and the untagged packets. tagged: The port will accept the tagged packets only.
Step 6 endReturn to privileged EXEC mode.
Step 7 copy running-config startup-configSave the settings in the configuration file.

The following example shows how to configure the PVID of port 1/0/5 as 2, enable the ingress checking and set the acceptable frame type as all:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/5

Switch(config-if)#switchport pvid 2

Switch(config-if)#switchport check ingress

Switch(config-if)#switchport acceptable frame all

Switch(config-if)#show interface switchport gigabitEthernet 1/0/5

Port Gi1/0/5:

PVID: 2

Acceptable frame type: All

Ingress Checking: Enable

Member in LAG: N/A

Link Type: General

Member in VLAN:

Vlan Name Egress-rule


1 System-VLAN Untagged

Switch(config-if)#end

Switch#copy running-config startup-config

3 Configuration Example

3.1 Network Requirements

■ Offices of Department A and Department B in the company are located in different places, and some computers in different offices connect to the same switch. It is required that computers can communicate with each other in the same department but not with computers in the other department.

3.2 Configuration Scheme

■ Divide computers in Department A and Department B into two VLANs respectively so that computers can communicate with each other in the same department but not with computers in the other department. ■ Terminal devices like computers usually do not support VLAN tags. Add untagged ports to the corresponding VLANs and specify the PVID. ■ The intermediate link between two switches carries traffic from two VLANs simultaneously. Add the tagged ports to both VLANs.

3.3 Network Topology

The figure below shows the network topology. Host A1 and Host A2 are in Department A, while Host B1 and Host B2 are in Department B. Switch 1 and Switch 2 are located in two different places. Host A1 and Host B1 are connected to port 1/0/2 and port 1/0/3 on Switch 1 respectively, while Host A2 and Host B2 are connected to port 1/0/6 and port 1/0/7 on Switch 2 respectively. Port 1/0/4 on Switch 1 is connected to port 1/0/8 on Switch 2.

Figure 3-1 Network Topologygraph TD subgraph VLAN 10 HostA1["Host A1"] -->|Gi1/0/2| Switch1["Switch 1"] HostA2["Host A2"] -->|Gi1/0/6| Switch2["Switch 2"] HostB1["Host B1"] -->|Gi1/0/4| Switch1 HostB2["Host B2"] -->|Gi1/0/7| Switch2 end subgraph VLAN 20 Switch1 -->|Gi1/0/3| Switch1 Switch2 -->|Gi1/0/8| Switch1 Switch2 -->|Gi1…

Demonstrated with S6500-24GP4XF, the following sections provide configuration procedure in two ways: using the GUI and using the CLI.

3.4 Using the GUI

The configurations of Switch 1 and Switch 2 are similar. The following introductions take Switch 1 as an example.

1) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > VLAN Config and click + Add to load the following page. Create VLAN 10 with the description of Department_A. Add port 1/0/2 as an untagged port and port 1/0/5 as a tagged port to VLAN 10. Click Create.

Figure 3-2 Creating VLAN 10 for Department AVLAN Config VLAN ID: 10 (2-4094, format 2,4-5,6) VLAN Name: Department_A (1-16 characters) Untagged Ports Port: 1/0/2 (Format: 1/0/1, input or choose below) UNIT1 LAOS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 4…

2) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > VLAN Config and click + Add to load the following page. Create VLAN 20 with the description of Department_B. Add port 1/0/3 as an untagged port and port 1/0/5 as a tagged port to VLAN 20. Click Create.

Figure 3-3 Creating VLAN 20 for Department BVLAN Config VLAN ID: 20 (2-4094, format: 2,4-5,6) VLAN Name: Department_B (1-16 characters) Untagged Ports Port: 1/0/3 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45…

3) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > Port Config to load the following page. Set the PVID of port 1/0/2 as 10 and click Apply. Set the PVID of port 1/0/3 as 20 and click Apply.

Figure 3-4 Specifying the PVID for the PortsPort Config UNIT1 LAGS Port PVID Ingress Checking Acceptable Frame Types LAG Details 20 1/0/1 1 Enabled Admit All -- Details 1/0/2 10 Enabled Admit All -- Details ✓ 1/0/3 20 Enabled Admit All -- Details 1/0/4 1 Enabled Admit All -- Details 1/0/5 1 Enabled Admit All -- Details 1/0/6 1 Enabled Admit A…

4) Click to save the settings.

3.5 Using the CLI

The configurations of Switch 1 and Switch 2 are similar. The following introductions take Switch 1 as an example.

1) Create VLAN 10 for Department A, and configure the description as Department-A. Similarly, create VLAN 20 for Department B, and configure the description as Department-B.

Switch_1#configure

Switch_1(config)#vlan 10

Switch_1(config-vlan)#name Department-A

Switch_1(config-vlan)#exit

Switch_1(config)#vlan 20

Switch_1(config-vlan)#name Department-B

Switch_1(config-vlan)#exit

2) Add untagged port 1/0/2 and tagged port 1/0/4 to VLAN 10. Add untagged port 1/0/3 and tagged port 1/0/4 to VLAN 20.

Switch_1(config)#interface gigabitEthernet 1/0/2

Switch_1(config-if)#switchport general allowed vlan 10 untagged

Switch_1(config-if)#exit

Switch_1(config)#interface gigabitEthernet 1/0/3

Switch_1(config-if)#switchport general allowed vlan 20 untagged

Switch_1(config-if)#exit

Switch_1(config)#interface gigabitEthernet 1/0/4

Switch_1(config-if)#switchport general allowed vlan 10 tagged

Switch_1(config-if)#switchport general allowed vlan 20 tagged

Switch_1(config-if)#exit

3) Set the PVID of port 1/0/2 as 10, and set the PVID of port 1/0/3 as 20.

Switch_1(config)#interface gigabitEthernet 1/0/2

Switch_1(config-if)#switchport pvid 10

Switch_1(config-if)#exit

Switch_1(config)#interface gigabitEthernet 1/0/3

Switch_1(config-if)#switchport pvid 20

Switch_1(config-if)#end

Switch_1#copy running-config startup-config

Verify the Configurations

Verify the VLAN configuration:

Switch_1#show vlan

VLANNameStatusPorts
1System-VLANactiveGi1/0/1, Gi1/0/2, Gi1/0/3, Gi1/0/4, Gi1/0/5, Gi1/0/6, Gi1/0/7, Gi1/0/8, Gi1/0/9, Gi1/0/10, Gi1/0/11, Gi1/0/12, Gi1/0/13, Gi1/0/14, Gi1/0/15, Gi1/0/16, Gi1/0/17, Gi1/0/18, Gi1/0/19, Gi1/0/20, Gi1/0/21, Gi1/0/22, Gi1/0/23, Gi1/0/24, Gi1/0/25, Gi1/0/26, Gi1/0/27, Gi1/0/28
10Department-AactiveGi1/0/2, Gi1/0/4
20Department-BactiveGi1/0/3, Gi1/0/4
PrimarySecondary TypePorts

Verify the VLAN configuration:

Switch_1(config)#show interface switchport

PortLAGTypePVIDAcceptable frame typeIngress Checking
-----------------------
Gi1/0/1N/AGeneral1AllEnable
Gi1/0/2N/AGeneral10AllEnable
Gi1/0/3N/AGeneral20AllEnable
Gi1/0/4N/AGeneral1AllEnable
Gi1/0/5N/AGeneral1AllEnable

...

4 Appendix: Default Parameters

Default settings of 802.1Q VLAN are listed in the following table.

Table 4-1 Default Settings of 802.1Q VLAN

Parameter Default Setting
VLAN ID 1
PVID 1
Ingress Checking Enabled
Acceptable Frame Types Admit All

Part 9

Configuring MAC VLAN

CHAPTERS

  1. Overview
  2. MAC VLAN Configuration
  3. Configuration Example
  4. Appendix: Default Parameters

1 Overview

VLAN is generally divided by ports. It is a common way of division but isn't suitable for those networks that require frequent topology changes. With the popularity of mobile office, at different times a terminal device may access the network via different ports. For example, a terminal device that accessed the switch via port 1 last time may change to port 2 this time. If port 1 and port 2 belong to different VLANs, the user has to re-configure the switch to access the original VLAN. Using MAC VLAN can free the user from such a problem. It divides VLANs based on the MAC addresses of terminal devices. In this way, terminal devices always belong to their MAC VLANs even when their access ports change.

The figure below shows a common application scenario of MAC VLAN.

Figure 1-1 Common Application Scenario of MAC VLANgraph TD ServerA["Server A VLAN 10"] --> Switch3["Switch 3"] ServerB["Server B VLAN 20"] --> Switch3 Switch1["Switch 1 Switch 2"] --> Switch3 Switch1 --> LaptopA["Laptop A"] Switch1 --> LaptopB["Laptop B"] Switch1 --> MeetingRoom1["Meeting Room 1"] Switch1 --> MeetingRoom2["Meeting Room 2"]

Two departments share all the meeting rooms in the company, but use different servers and laptops. Department A uses Server A and Laptop A, while Department B uses Server B and Laptop B. Server A is in VLAN 10 while Server B is in VLAN 20. It is required that Laptop A can only access Server A and Laptop B can only access Server B, no matter which meeting room the laptops are being used in. To meet this requirement, simply bind the MAC addresses of the laptops to the corresponding VLANs respectively. In this way, the MAC address determines the VLAN each laptop joins. Each laptop can access only the server in the VLAN it joins.

2 MAC VLAN Configuration

To complete MAC VLAN configuration, follow these steps:

1) Configure 802.1Q VLAN. 2) Bind the MAC address to the VLAN. 3) Enable MAC VLAN for the port.

Configuration Guidelines

When a port in a MAC VLAN receives an untagged data packet, the switch will first check whether the source MAC address of the data packet has been bound to the MAC VLAN. If yes, the switch will insert the corresponding tag to the data packet and forward it within the VLAN. If no, the switch will continue to match the data packet with the matching rules of other VLANs (such as the protocol VLAN). If there is a match, the switch will forward the data packet. Otherwise, the switch will process the data packet according to the processing rule of the 802.1Q VLAN. When the port receives a tagged data packet, the switch will directly process the data packet according to the processing rule of the 802.1Q VLAN.

2.1 Using the GUI

2.1.1 Configuring 802.1Q VLAN

Before configuring MAC VLAN, create an 802.1Q VLAN and set the port type according to network requirements. For details, refer to Configuring 802.1Q VLAN.

2.1.2 Binding the MAC Address to the VLAN

Choose the menu L2 FEATURES > VLAN > MAC VLAN and click to load the following page.

Figure 2-1 Creating MAC VLANMAC VLAN Config MAC Address: (Format: 00-00-00-00-00-01) Description: (1-8 characters) VLAN: ID Name (1-4094) Cancel Create

Follow these steps to bind the MAC address to the 802.1Q VLAN:

1) Enter the MAC address of the device, give it a description, and enter the VLAN ID to bind it to the VLAN.

MAC Address: Enter the MAC address of the device in the format 00-00-00-00-00-01.

Description: Give a MAC address description for identification with up to 8 characters.

VLAN ID/Name: Enter the ID number or name of the 802.1Q VLAN that will be bound to the MAC VLAN.

2) Click Create.

TP-LINK Omada Pro S5500-24GP4F - Binding the MAC Address to the VLAN - 2

Note:

One MAC address can be bound to only one VLAN.

2.1.3 Enabling MAC VLAN for the Port

By default, MAC VLAN is disabled on all ports. You need to enable MAC VLAN for your desired ports manually.

Choose the menu L2 FEATURES > VLAN > MAC VLAN to load the following page.

Figure 2-2 Enabling MAC VLAN for the PortPort Enable UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 Select All 35 37 39 41 43 45 47 49 51 53 36 38 40 42 44 46 48 50 52 54 Selected Unselected Not Available Apply MAC VLAN Config Index MAC Address Description VLAN ID VLAN Name Operation…

In the Port Enable section, select the desired ports to enable MAC VLAN, and click Apply.

TP-LINK Omada Pro S5500-24GP4F - Enabling MAC VLAN for the Port - 2

Note:

The member ports of an LAG follow the configurations of the LAG and not their own. The individual configurations of the ports can take effect only after the ports leave the LAG.

2.2 Using the CLI

2.2.1 Configuring 802.1Q VLAN

Before configuring MAC VLAN, create an 802.1Q VLAN and set the port type according to network requirements. For details, refer to Configuring 802.1Q VLAN.

2.2.2 Binding the MAC Address to the VLAN

Follow these steps to bind the MAC address to the VLAN:

Step 1 configure

Enter global configuration mode.

Step 2 mac-vlan mac-address

mac-addr vlan vlan-id [description descript]

Bind the MAC address to the VLAN.

mac-addr: Specify the MAC address of the device in the format of xx:xx:xx:xx:xx:xx.

vlan-id: Enter the ID number of the 802.1Q VLAN that will be bound to the MAC VLAN.

descript: Specify the MAC address description for identification, with up to 8 characters.

Step 3 show mac-vlan { all | mac-address

mac-addr | vlan vlan-id }

Verify the configuration of MAC VLAN.

vid: Specify the MAC VLAN to be displayed.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to bind the MAC address 00:19:56:8A:4C:71 to VLAN 10, with the address description as Dept.A.

Switch#configure

Switch(config)#mac-vlan mac-address 00:19:56:8a:4c:71 vlan 10 description Dept.A

Switch(config)#show mac-vlan vlan 10

MAC-Addr

Name

VLAN-ID

00:19:56:8A:4C:71

Dept.A

10

Switch(config)#end

Switch#copy running-config startup-config

2.2.3 Enabling MAC VLAN for the Port

Follow these steps to enable MAC VLAN for the port:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 3 mac-vlan

Enable MAC VLAN for the port.

Step 4 show mac-vlan interface

Verify the configuration of MAC VLAN on each interface.

Step 5 end

Return to privileged EXEC mode.

Step 6: copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable MAC VLAN for port 1/0/1.

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#mac-vlan

Switch(config-if)#show mac-vlan interface

Port STATUS

Gi1/0/1 Enable

Gi1/0/2 Disable

Switch(config-if)#end

Switch#copy running-config startup-config

3 Configuration Example

3.1 Network Requirements

Two departments share all the meeting rooms in the company, but use different servers and laptops. Department A uses Server A and Laptop A, while Department B uses Server B and Laptop B. Server A is in VLAN 10 while Server B is in VLAN 20. It is required that Laptop A can only access Server A and Laptop B can only access Server B, no matter which meeting room the laptops are being used in. The figure below shows the network topology.

Figure 3-1 Network Topologygraph TD ServerA["Server A VLAN 10"] --> Switch1["Switch 1 Switch 2"] ServerB["Server B VLAN 20"] --> Switch1 Switch1 -->|Gi1/0/2 Gi1/0/2| Switch3["Switch 3"] Switch3 -->|Gi1/0/5Gi1/0/4| Switch1 Switch1 -->|Gi1/0/3Gi1/0/2| Switch3 Switch1 -->|Gi1/0/1Gi1/0/1| MeetingRoom1["Meeting Room 1"] Switch1 --…

3.2 Configuration Scheme

You can configure MAC VLAN to meet this requirement. On Switch 1 and Switch 2, bind the MAC addresses of the laptops to the corresponding VLANs respectively. In this way, each laptop can access only the server in the VLAN it joins, no matter which meeting room the laptops are being used in. The overview of the configuration is as follows:

1) Create VLAN 10 and VLAN 20 on each of the three switches and add the ports to the VLANs based on the network topology. For the ports connecting the laptops, set the

egress rule as Untagged; for the ports connecting to other switch, set the egress rule as Tagged.

2) On Switch 1 and Switch 2, bind the MAC addresses of the laptops to their corresponding VLANs, and enable MAC VLAN for the ports.

Demonstrated with S6500-24GP4XF, the following sections provide configuration procedure in two ways: using the GUI and using the CLI.

3.3 Using the GUI

■ Configurations for Switch 1 and Switch 2

The configurations of Switch 1 and Switch 2 are similar. The following introductions take Switch 1 as an example.

1) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > VLAN Config and click Add to load the following page. Create VLAN 10, and add untagged port 1/0/1 and tagged port 1/0/3 to VLAN 10. Click Create.

Figure 3-2 Creating VLAN 10VLAN Config VLAN ID: 10 (2-4094, format: 2,4-5,5) VLAN Name: Department_A (1-16 characters) Untagged Ports Port 1/0/1 (Format: 1/0/1, Input or choose below) UNIT1 LAGS Select All 41 43 45 47 49 51 53 42 44 45 48 50 52 54 Selected Unselected Not Available Tagged Ports Port 1/0/3 (Format: 1/0/1, input…

2) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > VLAN Config and click Add to load the following page. Create VLAN 20, and add untagged port 1/0/1 and tagged port 1/0/3 to VLAN 20. Click Create.

Figure 3-3 Creating VLAN 20VLAN Config VLAN ID: 20 (2-4094, format 2,4-5,8) VLAN Name: Department_B (1-16 characters) Untagged Ports Port: 1/0/1 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 4…

3) Choose the menu L2 FEATURES > VLAN > MAC VLAN and click Add to load the following page. Specify the corresponding parameters and click Create to bind the MAC address of Laptop A to VLAN 10 and bind the MAC address of Laptop B to VLAN 20.

Figure 3-4 Creating MAC VLANMAC VLAN Config MAC Address: 00-19-56-8A-4C-71 (Format: 00-00-00-00-00-01) Description: PCA (1-8 characters) VLAN: ID Name (1-4094) 10 Cancel Create

4) Choose the menu L2 FEATURES > VLAN > MAC VLAN to load the following page. In the Port Enable section select port 1/0/1 and click Apply to enable MAC VLAN.

Figure 3-5 Enabling MAC VLAN for the PortPort Enable | Port Enable | Selected | Unselected | Not Available | | :--- | :--- | :--- | :--- | | 1 | 3 | 5 | 7 | | 2 | 4 | 6 | 8 | | 3 | 35 | 39 | 41 | | 4 | 36 | 38 | 40 | | 5 | 42 | 44 | 46 | | 6 | 48 | 50 | 52 | | 7 | Unselected | Unselected | Not Available | | 8 | Unselected | Unselected | No…

5) Click Save the settings.

■ Configurations for Switch 3

1) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > VLAN Config and click Add to load the following page. Create VLAN 10, and add untagged port 1/0/4 and tagged ports 1/0/2-3 to VLAN 10. Click Create.

Figure 3-6 Creating VLAN 10VLAN Config VLAN ID: 10 (2-4094, format: 2,4-5,6) VLAN Name: Department_A (1-16 characters) Untagged Ports Port: 1/0/4 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45…

2) Click Create to load the following page. Create VLAN 20, and add untagged port 1/0/5 and tagged ports 1/0/2-3 to VLAN 20. Click Create.

Figure 3-7 Creating VLAN 20VLAN Config VLAN ID: 20 (2-4094, format: 2,4-5,6) VLAN Name: Department_B (1-16 characters) Untagged Ports Port: 1/0/5 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45…

3) Click Save the settings.

3.4 Using the CLI

■ Configurations for Switch 1 and Switch 2

The configurations of Switch 1 and Switch 2 are the same. The following introductions take Switch 1 as an example.

1) Create VLAN 10 for Department A and create VLAN 20 for Department B.

Switch_1#configure

Switch_1(config)#vlan 10

Switch_1(config-vlan)#name deptA

Switch_1(config-vlan)#exit

Switch_1(config)#vlan 20

Switch_1(config-vlan)#name deptB

Switch_1(config-vlan)#exit

2) Add tagged port 1/0/2 and untagged port 1/0/1 to both VLAN 10 and VLAN 20. Then enable MAC VLAN on port 1/0/1.

Switch_1(config)#interface gigabitEthernet 1/0/2
Switch_1(config-if)#switchport general allowed vlan 10,20 tagged
Switch_1(config-if)#exit
Switch_1(config)#interface gigabitEthernet 1/0/1
Switch_1(config-if)#switchport general allowed vlan 10,20 untagged
Switch_1(config-if)#mac-vlan
Switch_1(config-if)#exit 
3) Bind the MAC address of Laptop A to VLAN 10 and bind the MAC address of Laptop B to VLAN 20.
Switch_1(config)#mac-vlan mac-address 00:19:56:8A:4C:71 vlan 10 description PCA
Switch_1(config)#mac-vlan mac-address 00:19:56:82:3B:70 vlan 20 description PCB
Switch_1(config)#end
Switch_1#copy running-config startup-config 

■ Configurations for Switch 3

1) Create VLAN 10 for Department A and create VLAN 20 for Department B.
Switch_3#configure
Switch_3(config)#vlan 10
Switch_3(config-vlan)#name deptA
Switch_3(config-vlan)#exit
Switch_3(config)#vlan 20
Switch_3(config-vlan)#name deptB
Switch_3(config-vlan)#exit 
2) Add tagged port 1/0/2 and port 1/0/3 to both VLAN 10 and VLAN 20.
Switch_3(config)#interface gigabitEthernet 1/0/2
Switch_3(config-if)#switchport general allowed vlan 10,20 tagged
Switch_3(config-if)#exit
Switch_3(config)#interface gigabitEthernet 1/0/3
Switch_3(config-if)#switchport general allowed vlan 10,20 tagged
Switch_3(config-if)#exit 
3) Add untagged port 1/0/4 to VLAN 10 and untagged port 1/0/5 to VLAN 20. Switch_3(config)#interface gigabitEthernet 1/0/4 

Switch_3(config-if)#switchport general allowed vlan 10 untagged Switch_3(config-if)#exit Switch_3(config)#interface gigabitEthernet 1/0/5 Switch_3(config-if)#switchport general allowed vlan 20 untagged Switch_3(config-if)#end Switch_3#copy running-config startup-config

Verify the Configurations

Switch 1

Switch_1#show mac-vlan all

Switch_2#show mac-vlan all

MAC Address Description VLAN

00:19:56:8A:4C:71 PCA 10

00:19:56:82:3B:70 PCB 20

Switch 3

Switch_3#show vlan

VLANNameStatusPorts
1System-VLANactiveGi1/0/1, Gi1/0/2, Gi1/0/3, Gi1/0/4, Gi1/0/5, Gi1/0/6, Gi1/0/7, Gi1/0/8 ...
10DeptAactiveGi1/0/2, Gi1/0/3, Gi1/0/4
20DeptBactiveGi1/0/2, Gi1/0/3, Gi1/0/5

4 Appendix: Default Parameters

Default settings of MAC VLAN are listed in the following table.

Table 4-1 Default Settings of MAC VLAN

Parameter Default Setting
MAC Address None
Description None
VLAN ID None
Port Enable Disabled

Part 10

Configuring Protocol VLAN

CHAPTERS

  1. Overview
  2. Protocol VLAN Configuration
  3. Configuration Example
  4. Appendix: Default Parameters

1 Overview

Protocol VLAN is a technology that divides VLANs based on the network layer protocol. With the protocol VLAN rule configured on the basis of the existing 802.1Q VLAN, the switch can analyze specific fields of received packets, encapsulate the packets in specific formats, and forward the packets with different protocols to the corresponding VLANs. Since different applications and services use different protocols, network administrators can use protocol VLAN to manage the network based on specific applications and services.

The figure below shows a common application scenario of protocol VLAN. With protocol VLAN configured, Switch 2 can forward IPv4 and IPv6 packets from different VLANs to the IPv4 and IPv6 networks respectively.

Figure 1-1 Common Application Scenario of Protocol VLANgraph TD A["IPv4 Internet"] --> B["Switch 1"] C["IPv6 Internet"] --> D["Switch 2"] E["RouterRouter"] --> D B --> F["VLAN 20VLAN 10"] D --> G["VLAN 20VLAN 10"] F --> H["Switch 1"] G --> I["Switch 2"] H --> J["IPv4 Hosts VLAN 10"] H --> K["IPv6 Hosts VLAN 20"]

2 Protocol VLAN Configuration

To complete protocol VLAN configuration, follow these steps:

1) Configure 802.1Q VLAN. 2) Create protocol template. 3) Configure Protocol VLAN.

Configuration Guidelines

■ You can use the IP, ARP, RARP, and other protocol templates provided by TP-Link switches, or create new protocol templates. In a protocol VLAN, when a port receives an untagged data packet, the switch will first search for the protocol VLAN matching the protocol type value of the packet. If there is a match, the switch will insert the corresponding VLAN tag to the data packet and forward it within the VLAN. Otherwise, the switch will forward the data packet to the default VLAN based on the PVID (Port VLAN ID) of the receiving port. (If MAC VLAN is also configured, the switch will first process Protocol VLAN, then MAC VLAN.) When the port receives a tagged data packet, the switch will directly process the data packet according to the processing rule of the 802.1Q VLAN.

2.1 Using the GUI

2.1.1 Configuring 802.1Q VLAN

Before configuring protocol VLAN, create an 802.1Q VLAN and set the port type according to network requirements. For details, refer to Configuring 802.1Q VLAN.

2.1.2 Creating Protocol Template

Choose the menu L2 FEATURES > VLAN > Protocol VLAN > Protocol Template to load the following page.

Figure 2-1 Check the Protocol TemplateProtocol Template Config ID Template Name Protocol Type 1 IP Ethernet II 0800 2 ARP Ethernet II 0806 3 RARP Ethernet II 8035 4 IPX SNAP 5 AT SNAP Total: 5

Follow these steps to create a protocol template:

1) Check whether your desired template already exists in the Protocol Template Config section. If not, click + Add to create a new template.

Figure 2-2 Creating a Protocol TemplateProtocol Template Config Template Name: Frame Type: Ether Type: (1-8 characters) Ethernet II SNAP LLC (4 hexadecimal integers, 0600-FFFF) Cancel Create

Template Name: Give a template name to identify the protocol template.

Frame Type: Select the frame type for the protocol template.

Ethernet II: A common Ethernet frame format. Select to specify the Frame Type by entering the Ether Type.

SNAP: An Ethernet 802.3 frame format based on IEEE 802.3 and IEEE 802.2 SNAP. Select to specify the Frame Type by entering the Ether Type.

LLC: An Ethernet 802.3 frame format based on IEEE 802.3 and IEEE 802.2 LLC. Select to specify the Frame Type by entering the DSAP and SSAP.

Ether Type: Enter the Ethernet protocol type value for the protocol template. It is available when Ethernet II and SNAP is selected. It is the Ether Type field in the frame and is used to identify the data type of the frame.

DSAPEnter the DSAP value for the protocol template. It is available when LLC is selected. It is the DSAP field in the frame and is used to identify the data type of the frame.
SSAPEnter the SSAP value for the protocol template. It is available when LLC is selected. It is the SSAP field in the frame and is used to identify the data type of the frame.

2) Click Create.

TP-LINK Omada Pro S5500-24GP4F - 2) Click Create. - 1

Note:

A protocol template that is bound to a VLAN cannot be deleted.

2.1.3 Configuring Protocol VLAN

Choose the menu L2 FEATURES > VLAN > Protocol VLAN > Protocol VLAN Group and click + Add to load the following page.

Figure 2-3 Configure the Protocol VLAN GroupProtocol VLAN Group Config Template Name: VLAN: VLAN ID VLAN Name VLAN ID: (1-4094) 802.1p Priority: 0 Port: (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 49 51 5…

Follow these steps to configure the protocol group:

1) In the Protocol Group Config section, specify the following parameters.

Template Name Select the previously defined protocol template.

VLAN Specify the VLAN to be bound to the protocol template by entering the 802.1Q VLAN ID or 802.1Q VLAN Name.

VLAN ID/Name Enter the ID number or name of the 802.1Q VLAN that will be bound to the Protocol VLAN.

802.1p Priority

Specify the 802.1p priority for the packets that belong to the protocol VLAN. The switch will determine the forwarding sequence according to this value. The packets with larger values for the 802.1p priority have the higher priority.

Members Displays the port members in the protocol VLAN.

2) Select the desired ports. Click Create.

TP-LINK Omada Pro S5500-24GP4F - 2) Select the desired ports. Click Create. - 1

Note:

The member ports of an LAG (Link Aggregation Group) follow the configurations of the LAG and not their own. The individual configurations of the ports can take effect only after the ports leave the LAG.

2.2 Using the CLI

2.2.1 Configuring 802.1Q VLAN

Before configuring protocol VLAN, create an 802.1Q VLAN and set the port type according to network requirements. For details, refer to Configuring 802.1Q VLAN.

2.2.2 Creating a Protocol Template

Follow these steps to create a protocol template:

Step 1 configure

Enter global configuration mode.

Step 2 protocol-vlan template name

protocol-name frame { ether_2 ether-type type | snap

ether-type type | llc dsap dsap_type ssap ssap_type}

Create a protocol template.

protocol-name: Specify the protocol name with 1 to 8 characters.

type: Enter 4 hexadecimal numbers as the Ethernet protocol type for the protocol template. It is the Ether Type field in the frame and is used to identify the data type of the frame.

dsap_type: Enter 2 hexadecimal numbers as the DSAP value for the protocol template. It is the DSAP field in the frame and is used to identify the data type of the frame.

ssap_type: Enter 2 hexadecimal numbers as the SSAP value for the protocol template. It is the SSAP field in the frame and is used to identify the data type of the frame.

Step 3 show protocol-vlan template

Verify the protocol templates.

Step 4 end

Return to Privileged EXEC Mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to create an IPv6 protocol template:

Switch#configure

Switch(config)#protocol-vlan template name IPv6 frame ether_2 ether-type 86dd

Switch(config)#show protocol-vlan template

Index Protocol Name Protocol Type

1IPEthernetll ether-type 0800
2ARPEthernetll ether-type 0806
3RARPEthernetll ether-type 8035
4IPXSNAP ether-type 8137
5ATSNAP ether-type 809B
6IPv6Ethernetll ether-type 86DD

Switch(config)#end

Switch#copy running-config startup-config

2.2.3 Configuring Protocol VLAN

Follow these steps to configure protocol VLAN:

Step 1 configure

Enter global configuration mode.

Step 2 show protocol-vlan template

Check the index of each protocol template.

Step 3 protocol-vlan vlan vid priority priority template index

Bind the protocol template to the VLAN.

vid: Enter the ID number of the 802.1Q VLAN that will be bound to the Protocol VLAN.

priority: Specify the 802.1p priority for the packets that belong to the protocol VLAN. The switch will determine the forwarding sequence according to this value. The packets with larger value of 802.1p priority have the higher priority.

index: Specify the protocol template index.

Step 4: show protocol-vlan vlan

Check the protocol VLAN index (entry-id) of each protocol group.

Step 5: interface {fastEthernet

port | range fastEthernet port-list | gigabitEthernet port | range

gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 6: protocol-vlan group

entry-id

Add the specified port to the protocol group.

entry-id: Protocol VLAN index.

Step 7: end

Return to Privileged EXEC Mode.

Step 8: copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to bind the IPv6 protocol template to VLAN 10 and add port 1/0/2 to the protocol VLAN:

Switch#configure

Switch(config)#show protocol-vlan template

IndexProtocol NameProtocol Type
1IPEthernetll ether-type 0800
2ARPEthernetll ether-type 0806
3RARPEthernetll ether-type 8035
4IPXSNAP ether-type 8137
5ATSNAP ether-type 809B
6IPv6Ethernetll ether-type 86DD

Switch(config)#protocol-vlan vlan 10 priority 5 template 6

Switch(config)#show protocol-vlan vlan

IndexProtocol-NameVIDPriorityMember
1IPv6100

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)#protocol-vlan group 1

Switch(config-if)#show protocol-vlan vlan

IndexProtocol-NameVIDPriorityMember
1IPv6105Gi1/0/2

Switch(config-if)#end

Switch#copy running-config startup-config

3 Configuration Example

3.1 Network Requirements

A company uses both IPv4 and IPv6 hosts, and these hosts access the IPv4 network and IPv6 network respectively via different routers. It is required that IPv4 packets are forwarded to the IPv4 network, IPv6 packets are forwarded to the IPv6 network, and other packets are dropped.

The figure below shows the network topology. The IPv4 host belongs to VLAN 10, the IPv6 host belongs to VLAN 20, and these hosts access the network via Switch 1. Switch 2 is connected to two routers to access the IPv4 network and IPv6 network respectively. The routers belong to VLAN 10 and VLAN 20 respectively.

Figure 3-1 Network Topologygraph TD A["IPv4 Internet"] --> B["Router 2Router 1"] B --> C["Switch 2"] C --> D["Gi1/0/3 VLAN 20"] C --> E["Gi1/0/2 VLAN 10"] F["IPv6 Internet"] --> G["Router 2Router 1"] G --> H["Switch 1"] H --> I["Gi1/0/2 VLAN 20"] H --> J["Gi1/0/1 VLAN 10"] K["IPv4 Host IPv6 Host"] --> L["Computer"] M["Switch…

3.2 Configuration Scheme

You can configure protocol VLAN on port 1/0/1 of Switch 2 to meet this requirement. When this port receives packets, Switch 2 will forward them to the corresponding VLANs according to their protocol types. The overview of the configuration on Switch 2 is as follows:

1) Create VLAN 10 and VLAN 20 and add each port to the corresponding VLAN. 2) Use the IPv4 protocol template provided by the switch, and create the IPv6 protocol template. 3) Bind the protocol templates to the corresponding VLANs to form protocol groups, and add port 1/0/1 to the groups.

For Switch 1, configure 802.1Q VLAN according to the network topology.

Demonstrated with S6500-24GP4XF, this chapter provides configuration procedures in two ways: using the GUI and using the CLI.

3.3 Using the GUI

■ Configurations for Switch 1

1) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > VLAN Config and click

Add to load the following page. Create VLAN 10, and add untagged port 1/0/1 and untagged port 1/0/3 to VLAN 10. Click Create.

Figure 3-2 Create VLAN 10VLAN Config VLAN ID: 10 (2-4094, format: 2,4-5,6) VLAN Name: IPv4 (1-16 characters) Untagged Ports Port: 1/0/1,1/0/3 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47…

2) Click + Add to load the following page. Create VLAN 20, and add untagged ports 1/0/2-3 to VLAN 20. Click Create.

Figure 3-3 Create VLAN 20VLAN Config VLAN ID: 20 (2-4094, format: 2,4-5,6) VLAN Name: IPv6 (1-16 characters) Untagged Ports Port: 1/0/2-3 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 49…

3) Click Save the settings.

■ Configurations for Switch 2

1) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > VLAN Config and click Add to load the following page. Create VLAN 10, and add tagged port 1/0/1 and untagged port 1/0/2 to VLAN 10. Click Create.

Figure 3-4 Create VLAN 10VLAN Config VLAN ID: 10 (2-4094, format: 2,4-5,8) VLAN Name: IPv4 (1-16 characters) Untagged Ports Port: 1/0/2 (Format: 1/0/1, input or choose below) UNIT 1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 49 5…

2) Click + Add to load the following page. Create VLAN 20, and add tagged port 1/0/1 and untagged port 1/0/3 to VLAN 20. Click Create.

Figure 3-5 Create VLAN 20VLAN Config VLAN ID: 20 (2-4094, format 2,4-5,8) VLAN Name: IPv6 (1-16 characters) Untagged Ports Port: 1/0/3 (Format 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 49 51 5…

3) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > Port Config to load the following page. Set the PVID of port 1/0/2 and port 1/0/3 as 10 and 20 respectively. Click Apply.

Figure 3-6 Port ConfigurationPort Config UNIT1 LAGS Port PVID Ingress Checking Acceptable Frame Types LAG Details 20 1/0/1 1 Enabled Admit All --- Details 1/0/2 10 Enabled Admit All --- Details ✓ 1/0/3 20 Enabled Admit All --- Details 1/0/4 1 Enabled Admit All --- Details 1/0/5 1 Enabled Admit All --- Details 1/0/6 1 Enabled Ad…

4) Choose the menu L2 FEATURES > VLAN > Protocol VLAN > Protocol Template and click + Add to load the following page. Enter IPv6 in the protocol name, select the Ethernet II frame type, enter 86DD in the Ether Type field, and click Create to create the IPv6 protocol template.

Tips: The IPv4 protocol template is already provided by the switch. You only need to create the IPv6 protocol template.

Figure 3-7 Create the IPv6 Protocol TemplateProtocol Template Config Template Name: IPv6 (1-8 characters) Frame Type: Ethernet II ○ SNAP ○ LLC Ether Type: 86DD (4 hexadecimal integers, 0600-FFFF) Cancel Create

5) Choose the menu L2 FEATURES > VLAN > Protocol VLAN > Protocol VLAN Group and click + Add to load the following page. Select the IP protocol name (that is the IPv4 protocol template), enter VLAN ID 10, select port 1, and click Create.

Figure 3-8 Configure the IPv4 Protocol GroupProtocol VLAN Group Config Template Name: IP VLAN: VLAN ID VLAN Name VLAN ID: 10 1-4094 802.1p Priority: 0 Port: 1/0/1 (Format: 1/0/1, input or choose below) UNIT LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 4…

6) Click Save the settings.

3.4 Using the CLI

■ Configurations for Switch 1

1) Create VLAN 10 and VLAN 20.

Switch_1#configure

Switch_1(config)#vlan 10

Switch_1(config-vlan)#name IPv4

Switch_1(config-vlan)#exit

Switch_1(config)#vlan 20

Switch_1(config-vlan)#name IPv6

Switch_1(config-vlan)#exit

2) Add untagged port 1/0/1 to VLAN 10. Add untagged port 1/0/2 to VLAN 20. Add untagged port 1/0/3 to both VLAN 10 and VLAN 20.

Switch_1(config)#interface gigabitEthernet 1/0/1

Switch_1(config-if)#switchport general allowed vlan 10 untagged

Switch_1(config-if)#exit

Switch_1(config)#interface gigabitEthernet 1/0/2
Switch_1(config-if)#switchport general allowed vlan 20 untagged
Switch_1(config-if)#exit
Switch_1(config)#interface gigabitEthernet 1/0/3
Switch_1(config-if)#switchport general allowed vlan 10,20 untagged
Switch_1(config-if)#end
Switch_1#copy running-config startup-config 

■ Configurations for Switch 2

1) Create VLAN 10 and VLAN 20.

Switch_2#configure
Switch_2(config)#vlan 10
Switch_2(config-vlan)#name IPv4
Switch_2(config-vlan)#exit
Switch_2(config)#vlan 20
Switch_2(config-vlan)#name IPv6
Switch_2(config-vlan)#exit 

2) Add tagged port 1/0/1 to both VLAN 10 and VLAN 20. Specify the PVID of untagged port 1/0/2 as 10 and add it to VLAN 10. Specify the PVID of untagged port 1/0/3 as 20 and add it to VLAN 20.

Switch_2(config)#interface gigabitEthernet 1/0/1
Switch_2(config-if)#switchport general allowed vlan 10,20 tagged
Switch_2(config-if)#exit
Switch_2(config)#interface gigabitEthernet 1/0/2
Switch_2(config-if)#switchport pvid 10
Switch_2(config-if)#switchport general allowed vlan 10 untagged
Switch_2(config-if)#exit
Switch_2(config)#interface gigabitEthernet 1/0/3
Switch_2(config-if)#switchport mode general
Switch_2(config-if)#switchport pvid 20
Switch_2(config-if)#switchport general allowed vlan 20 untagged
Switch_2(config-if)#exit 

3) Create the IPv6 protocol template.

Switch_2(config)#protocol-vlan template name IPv6 frame ether_2 ether-type 86dd Switch_2(config)#show protocol-vlan template

IndexProtocol NameProtocol Type
-----------
1IPEthernetll ether-type 0800
2ARPEthernetll ether-type 0806
3RARPEthernetll ether-type 8035
4IPXSNAP ether-type 8137
5ATSNAP ether-type 809b
6IPv6Ethernet ll ether-type 86dd

4) Configure the protocol groups.

Switch_2(config)#protocol-vlan vlan 10 priority 0 template 1 Switch_2(config)#protocol-vlan vlan 20 priority 0 template 6

5) Add port 1/0/1 to the protocol groups.

Switch_2(config)#show protocol-vlan vlan

IndexProtocol-NameVIDMember
---------------
1IP10
2IPv620

Switch_2(config)#interface gigabitEthernet 1/0/1

Switch_2(config-if)#protocol-vlan group 1

Switch_2(config-if)#protocol-vlan group 2

Switch_2(config-if)#exit

Switch_2(config)#end

Switch_2#copy running-config startup-config

Verify the Configurations

Switch 1

Verify 802.1Q VLAN configuration:

Switch_1#show vlan

VLANNameStatusPorts
1System-VLANactiveGi1/0/1, Gi1/0/2, Gi1/0/3, Gi1/0/4...Gi2/0/48, Te2/0/49, Te2/0/50, Te2/0/51,Te2/0/52, Te2/0/53, Te2/0/54
10IPv4activeGi1/0/1, Gi1/0/3
20IPv6activeGi1/0/2, Gi1/0/3

Switch 2

Verify 802.1Q VLAN configuration:

Switch_2#show vlan

VLANNameStatusPorts
1System-VLANactiveGi1/0/1, Gi1/0/2, Gi1/0/3, Gi1/0/4...Gi2/0/48, Te2/0/49, Te2/0/50, Te2/0/51,Te2/0/52, Te2/0/53, Te2/0/54
10IPv4activeGi1/0/1, Gi1/0/2
20IPv6activeGi1/0/1, Gi1/0/3

Verify protocol group configuration:

Switch_2#show protocol-vlan vlan

IndexProtocol-NameVIDPriorityMember
1IP100Gi1/0/1
2IPv6200Gi1/0/1

4 Appendix: Default Parameters

Default settings of Protocol VLAN are listed in the following table.

Table 4-1 Default Settings of Protocol VLAN

Parameter Default Setting
Protocol Template Table1 IP Ethernet II ether-type 08002 ARP Ethernet II ether-type 08063 RARP Ethernet II ether-type 80354 IPX SNAP ether-type 81375 AT SNAP ether-type 809B

Part 11

Configuring VLAN-VPN

(Only for Certain Devices)

CHAPTERS

  1. VLAN-VPN
  2. Basic VLAN-VPN Configuration
  3. Flexible VLAN-VPN Configuration
  4. Configuration Examples
  5. Appendix: Default Parameters

1 VLAN-VPN

1.1 Overview

TP-LINK Omada Pro S5500-24GP4F - Overview - 1

Note:

VLAN VPN is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If VLAN VPN is available, there is L2 FEATURES > VLAN > VLAN VPN in the menu structure.

VLAN-VPN (Virtual Private Network) is an easy-to-implement layer 2 VLAN technology, and it is usually deployed at the edge of the ISP (Internet Service Provider) network.

With VLAN-VPN, when forwarding packets from the customer network to the ISP network, the switch adds an outer tag to the packets with outer VLAN ID. Thus, packets can be transmitted through ISP networks with double VLAN tags. In the ISP network, packets are forwarded according to the outer VLAN tag (VLAN tag of the ISP network), while the inner VLAN tag is treated as part of the payload. When forwarding packets from the ISP network to the customer network, the switch removes the outer VLAN tag of the packets. Thus, packets are forwarded according to the inner VLAN tag (VLAN tag of the customer network) in the customer network.

The following figure shows the typical application scenario of VLAN-VPN. To realize the communication between two customer VLANs across the ISP network, you can configure VLAN-VPN at the ISP edge switches to allow packets from customer VLAN 100 and VLAN 200 to be forwarded through the ISP network with the outer tag of VLAN 1050.

Figure 1-1 Application Scenario of VLAN-VPNgraph LR A["VLAN 100"] --> B["↔"] C["VLAN 200"] --> B B --> D["VLAN 1050"] D --> E["↔"] F["VLAN 100"] --> E E --> G["VLAN 200"] G --> H["↔"]

1.2 Supported Features

The VLAN-VPN function includes: basic VLAN-VPN and flexible VLAN-VPN (VLAN mapping).

Basic VLAN-VPN

All packets from customer VLANs are encapsulated with the same VLAN tag of the ISP network, and sent to the ISP network. Additionally, you can set the TPID (Tag Protocol Identifier) for compatibility with devices in the ISP network.

Flexible VLAN-VPN

You can configure different VLANs in the customer network to map to different VLANs in the ISP network.

When the switch receives a packet with the customer network tag, the switch will check the VLAN Mapping List. If a match is found, the switch encapsulates the packet with the corresponding VLAN tag of the ISP network, and forwards it to the corresponding port. If no match is found, the switch processes the packet according to the rules of MAC VLAN, Protocol VLAN, and 802.1Q VLAN. For untagged packets, the switch directly processes them according to the rules of MAC VLAN, Protocol VLAN, and 802.1Q VLAN.

2 Basic VLAN-VPN Configuration

To complete the basic VLAN-VPN configuration, follow these steps:

1) Configure 802.1Q VLAN. 2) Configure NNI ports and UNI ports. 3) Enable VLAN-VPN globally.

Configuration Guidelines

■ The TPID preset by the switch is 0x8100. If the devices in the ISP network do not support this value, you should change it to ensure VLAN-VPN packets sent to the ISP network can be recognized and forwarded by devices of other manufacturers. - You can go to the 802.1Q VLAN section to specify the Ingress Checking feature according to your needs. If Ingress Checking is enabled, the port will perform this operation first, then process the packets based on the VLAN-VPN configuration. If Ingress Checking is disabled, the port will process the packets directly based on the VLAN-VPN configuration.

2.1 Using the GUI

2.1.1 Configuring 802.1Q VLAN

Before configuring VLAN-VPN, create 802.1Q VLAN, add ports to corresponding VLANs, and configure Ingress Checking on ports according to your needs. For details, refer to Configuring 802.1Q VLAN.

2.1.2 Configuring Basic VLAN-VPN

Choose the menu L2 FEATURES > VLAN > VLAN VPN > VPN Config to load the following page.

Figure 2-1 Basic VPN ConfigurationGlobal Config VLAN VPN: ☐ Enable Apply Port Config UNIT1 LAGS ☐ Port Port Role TPID Use Inner Priority ☐ 1/0/1 -- 8100 Disabled ☐ 1/0/2 -- 8100 Disabled ☐ 1/0/3 -- 8100 Disabled ☐ 1/0/4 -- 8100 Disabled ☐ 1/0/5 -- 8100 Disabled ☐ 1/0/6 -- 8100 Disabled ☐ 1/0/7 -- 8100 Disabled ☐ 1/0/8 -- 8100 Disabl…

Follow these steps to configure the basic VLAN-VPN parameters:

1) In the Global Config section, enable VLAN VPN globally, and click Apply.

VLAN VPN: Enable or disable VLAN VPN.

2) In the Port Config section, select one or more ports and configure the corresponding parameters. Click Apply.

Port Role: Select the port role that will take effect in the VLAN-VPN function.

NNI: NNI ports are usually connected to the ISP network, and the packets forwarded by these ports have double VLAN tags.

UNI: UNI ports are usually connected to the customer network. The outer VLAN tags will be added or removed when the packets are forwarded by the VPN port.

Note:

The direct shift between port modes UNI and NNI is not supported. To switch from the current mode to another mode, you can change the port role to "--" first.

TPID: Specify the value of TPID. TPID is a field of VLAN tag and is modified to make the double tagged packets identifiable to devices from different vendors.

Use Inner Priority

Enable this function and the switch will determine the forwarding sequence of the packets according to the 802.1p priority of the inner VLAN tag.

It is available only when the port role is UNI.

TP-LINK Omada Pro S5500-24GP4F - Note: - 1

Note:

• The PVID of the UNI port should be specified as the VLAN ID of the ISP VLAN. - The member ports of an LAG follow the configurations of the LAG and not their own. The individual configurations of the ports can take effect only after the ports leave the LAG.

2.2 Using the CLI

2.2.1 Configuring 802.1Q VLAN

Before configuring VLAN-VPN, create 802.1Q VLAN, add ports to corresponding VLANs and configure Ingress Checking on ports according to your needs. For details, refer to Configuring 802.1Q VLAN.

2.2.1 Configuring Basic VLAN-VPN

Follow these steps to configure basic VLAN-VPN:

Step 1 configure

Enter global configuration mode.

Step 2 dot1q-tunnel

Enable the VLAN-VPN feature globally.

Step 3 interface {fastEthernet

port | range fastEthernet port-list | gigabitEthernet port | range

gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 4 switchport dot1q-tunnel mode { nni | uni }

Select the port role that will take effect in the VLAN-VPN function.

nni: NNI ports are usually connected to the ISP network, and the packets forwarded by these port have outer VLAN tags.

UNI: UNI ports are usually connected to the customer network. The outer VLAN tags will be added or removed when the packets are forwarded by the UNI port.

Note:

The direct shift between ports modes uni and nni is not supported. To switch from the current mode to another mode, you can use no switchport dot1q-tunnel mode to disable the current mode.

Step 5 switchport dot1q-tunnel tpid

tpid

Specify the value of TPID. TPID is a field of VLAN tag and is modified to make the double tagged packets identifiable to devices from different vendors.

tpid: Enter the IPID for the port. It must be 4 Hex integers. By default, it is 8100.

Step 6 switchport dot1q-tunnel missdrop

Enable the Missdrop feature. This option only can take effect on tagged packets. With Missdrop enabled, the tagged packets that don't match the VLAN Mapping entries will be dropped. By default, it is disabled.

Step 7 switchport dot1q-tunnel use_inner_priority

Enable this function and the switch will determine the forwarding sequence of the packets according to the 802.1p priority of the inner VLAN tag. By default, it is disabled.

It is available only when the port mode is UNI.

Step 8 show dot1q-tunnel

Verify the global configuration of VLAN-VPN.

Step 9 show dot1q-tunnel interface

Verify the interface configuration of basic VLAN-VPN.

Step 10 end

Return to privileged EXEC mode.

Step 11 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the VLAN-VPN feature globally, set port 1/0/1 of switch as the UNI port and 1/0/2 as the NNI port:

Switch#configure

Switch(config)#dot1q-tunnel

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#switchport dot1q-tunnel mode uni

Switch(config-if)#exit

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)#switchport dot1q-tunnel mode nni

Switch(config-if)#show dot1q-tunnel

VLAN-VPN Mode: Enabled

Mapping Mode: Disabled

Switch(config-if)#show dot1q-tunnel interface

PortTypeTpidUse Inner PriorityLAG
-------------------
Gi1/0/1UNI0x8100DisableN/A
Gi1/0/2NNI0x8100EnableN/A

...

Switch(config-if)#end

Switch#copy running-config startup-config

3 Flexible VLAN-VPN Configuration

To complete the flexible VLAN-VPN configuration, follow these steps:

1) Configure 802.1Q VLAN and basic VLAN-VPN. 2) Configure VLAN mapping.

Configuration Guidelines

■ Before you start, configure 802.1Q VLAN and the basic VLAN-VPN.

- You can specify the PVID of the UNI port according to your needs. The untagged packets and the tagged packets that don't match the VLAN mapping entry may be added the outer VLAN tag with this PVID according to your configuration.

3.1 Using the GUI

Choose the menu L2 FEATURES > VLAN > VLAN VPN > VLAN Mapping to load the following page.

Figure 3-1 Enable Flexible VLAN-VPNGlobal Config VLAN Mapping: Enable Apply VLAN Mapping Config Index Port C VLAN ID C VLAN Name SP VLAN ID SP VLAN Name Description Operation No entries in this table. Total: 0

Follow these steps to configure flexible VLAN-VPN:

1) In the Global Config section, enable VLAN mapping globally and click Apply. 2) In the VLAN Mapping Config section, click + Add to load the following page. Configure the following parameters.

Figure 3-2 Create VLAN Mapping EntryVLAN Mapping Config Port: Cancel (Format: 1/9/1) UNIT1 LAGS Select All C VLAN: ID Name (1-4064) SP VLAN: ID Name (1-4064) Description: (Optional: 1-16 characters) Cancel Create

Port: For some devices, choose a UNI port to enable VLAN mapping. Usually, ports that are connected to the customer network are set as UNI ports.

C VLAN: Specify the customer VLAN of the UNI port by entering the VLAN ID or VLAN Name.

C VLAN ID: Enter the VLAN ID of the customer network.

C VLAN Name: Enter the VLAN Name of the customer network.

SP VLAN: Specify the ISP VLAN of the UNI port by entering the VLAN ID or VLAN Name.

SP VLAN ID: Enter the VLAN ID of the ISP network.

SP VLAN Name: Enter the VLAN Name of the ISP network.

Description: Give a description to identify the VLAN Mapping.

3) Click Create.

3.2 Using the CLI

Follow these steps to configure flexible VLAN-VPN:

Step 1 configure

Enter global configuration mode.

Step 2 dot1q-tunnel mapping

Enable VLAN mapping globally.

Step 3 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}For some devices, choose a UNI port to enable VLAN mapping. For other devices, choose a NNI port to enable VLAN mapping.
Step 4 switchport dot1q-tunnel mapping c-vlan sp-vlan [ descript ]Set VLAN mapping entries for the specified port.c vlan: Enter VLAN ID of the customer network.sp vlan: Enter VLAN ID of the ISP network.descript: Give a description to identify the VLAN Mapping.
Step 5 endReturn to privileged EXEC mode.
Step 6 copy running-config startup-configSave the settings in the configuration file.

The following example shows how to enable VLAN mapping and set a VLAN mapping entry named mapping1 on port 1/0/3 to map customer network VLAN 15 to ISP network VLAN 1040:

Switch#configure

Switch(config)#dot1q-tunnel mapping

Switch(config)#show dot1q-tunnel

VLAN-VPN Mode: Enabled

Mapping Mode: Enabled

Switch(config)#interface gigabitEthernet 1/0/3

Switch(config-if)#switchport dot1q-tunnel mapping 15 1040 mapping1

Switch(config-if)#show dot1q-tunnel mapping

PortC-VLANSP-VLANName
Gi1/0/3151040mapping1

Switch(config-if)#end

Switch#copy running-config startup-config

4 Configuration Examples

4.1 Example for Basic VLAN VPN

4.1.1 Network Requirements

A company has two stations, and the computers belong to VLAN 100 and VLAN 200 respectively. The ISP VLAN is VLAN 1050 and the TPID adopted by the ISP network is 0x9100.

The two stations need to communicate with each other through the ISP network. And it is required that the traffic from VLAN 100 and VLAN 200 should be transmitted in VLAN 1050.

Figure 4-1 Network Topologygraph TD A["TPiD=0x9100 VLAN1050"] --> B["Switch 1"] A --> C["Switch 2"] B --> D["Switch 3"] C --> E["Switch 4"] D --> F["VLAN 200"] D --> G["VLAN 100"] E --> H["VLAN 200"] E --> I["VLAN 100"] B --> J["GI1/0/1"] C --> K["GI1/0/2"] D --> L["GI1/0/3"] E --> M["GI1/0/4"] B --> N["GI1/0/2 UNI Port"] C -…

4.1.2 Configuration Scheme

To meet the requirement that all the traffic from VLAN 100 and VLAN 200 should be transmitted through VLAN 1050, users can configure basic VLAN VPN on Switch 1 and Switch 2 to allow packets sent with double VLAN tags, and thus ensure the communication between them. The general configuration procedure is as follows:

Here we only introduce the configuration schemes on switch 1 and switch 3, for the configurations on switch 2 are the same as those on switch 1, and the configurations on switch 4 are the same as those on switch 3.

1) Configure 802.1Q VLAN on switch 1. The parameters are shown below:

VLAN 100 VLAN 200 VLAN 1050 PVID
Port 1/0/1 -- Tagged Keep thedefault value
Port 1/0/2 Tagged Tagged Untagged 1050

2) Configure 802.1Q VLAN on switch 3. The parameters are shown below:

VLAN 100 VLAN 200 PVID
Port 1/0/1 Untagged - 100
Port 1/0/2 - Untagged 200
Port 1/0/3 Tagged Tagged Keep the default value

3) Configure VLAN VPN on switch 1. Set port 1/0/1 as NNI port and port 1/0/2 as UNI port; configure the TPID as 0x9100.

Demonstrated with T2600G-28TS, this chapter provides configuration procedures in two ways: using the GUI and using the CLI.

4.1.3 Using the GUI

■ Configuring Switch 1:

1) Go to L2 FEATURES > VLAN > 802.1Q VLAN to create VLAN 100, VLAN 200 and VLAN 1050. Configure the egress rule of port 1/0/2 in VLAN 100 and VLAN 200 as Tagged, and in VLAN 1050 as Untagged; Configure the egress rule of port 1/0/1 in VLAN 1050 as Tagged.

Figure 4-2 Create VLAN 100VLAN Config VLAN ID: 100 (2-4094, format: 2,4-5,0) VLAN Name: C_VLAN 100 (1-10 characters) Untagged Ports Port: (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 49 5…

Figure 4-3 Create VLAN 200VLAN Config VLAN ID: 200 (2-4094, format 2,4-5,8) VLAN Name: C_VLAN 200 (1-10 characters) Untagged Ports Port: (Format: 1/3/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 49 51…

Figure 4-4 Create VLAN 1050VLAN Config VLAN ID: 1050 (2-4094, format: 2.4-5.8) VLAN Name: SP VLAN_1050 (1-16 characters) Untagged Ports Port: 1/0/2 (Format: 1/0/1, input or choose below) UNIT1 LAGS Select All 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 15 18 20 22 24 26 28 30 32 34 36 38 40 41 43 4…

2) Go to L2 FEATURES > VLAN > Port Config to set the PVID as 1050 for port 1/0/2 and leave the default value 1 for port 1/0/1.

Figure 4-5 Configuring PVIDPort Config UNIT1 LAGS Port PVID Ingress Checking Acceptable Frame Types LAG Details 1050 ▼ ▼ 1/0/1 1 Enabled Admit All — Details ✓ 1/0/2 1050 Enabled Admit All — Details

3) Go to L2 FEATURES > VLAN > VLAN VPN > VPN Config, enable VLAN VPN globally; set port 1/0/1 as NNI port and port 1/0/2 as UNI port. Specify the TPID of port 1/0/1 as 9100.

Figure 4-6 Enabling VLAN VPN Globally and Configuring the PortsGlobal Config VLAN VPN: ✓ Enable Port Config UNIT1 LAGS Port Port Role TPID Missdrop Use Inner Priority 1/0/1 NNI 9100 Disabled Disabled 1/0/2 UNI 8100 Disabled Disabled 1/0/3 -- 8100 Disabled Disabled

4) Click Save the settings.

- Configuring Switch 3:

1) Go to L2 FEATURES > VLAN > 802.1Q VLAN to create VLAN 100 and VLAN 200. Configure the egress rules of port 1/0/1 in VLAN 100 as Untagged; egress rules of port 1/0/2 in VLAN 200 as Untagged; egress rule of port 1/0/3 in VLAN 100 and VLAN 200 as Tagged.

Figure 4-7 Creating VLAN 100VLAN Config VLAN ID: 100 (2-4094, format: 2,4-5,3) VLAN Name: C_VLAN 100 (1-16 characters) Untagged Ports Port: 1/0/1 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 4…

Figure 4-8 Creating VLAN 200VLAN Config VLAN ID: 200 (2-4094 format; 2-4-5.6) VLAN Name: C_VLAN 200 (1-10 characters) Untagged Ports Port: 1/0/2 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47…

2) Go to L2 FEATURES > VLAN > Port Config to set the PVID as 100 for port 1/0/1 and 200 for port 1/0/2.

Figure 4-9 Configuring PVIDPort Config UNIT1 LAGS Port PVID Ingress Checking Acceptable Frame Types LAG Details 1/0/1 100 Enabled Admit All --- Details 1/0/2 200 Enabled Admit All --- Details 1/0/3 1 Enabled Admit All --- Details

3) Click Save the settings.

4.1.4 Using the CLI

The configurations of Switch 1 and Switch 2 are similar. The following introductions take Switch 1 as an example.

1) Create VLAN 1050, VLAN 100 and VLAN 200.

Switch_1#configure

Switch_1(config)#vlan 1050

Switch_1(config-vlan)#name SP_VLAN

Switch_1(config-vlan)#exit
Switch_1(config)#vlan 100
Switch_1(config-vlan)#name C_VLAN100
Switch_1(config-vlan)#exit
Switch_1(config)#vlan 200
Switch_1(config-vlan)#name C_VLAN200
Switch_1(config-vlan)#exit 
2) Add port 1/0/1 to VLAN 1050 as tagged port, modify PVID as 1050, set the port as NNI port and specify the TPID as 9100.
Switch_1(config)#interface gigabitEthernet 1/0/1
Switch_1(config-if)#switchport general allowed vlan 1050 tagged
Switch_1(config-if)#switchport pvid1050
Switch_1(config-if)#switchport dot1q-tunnel mode nni
Switch_1(config-if)#switchport dot1q-tunnel tpid 9100
Switch_1(config-if)#exit 
3) Add port 1/0/2 to VLAN 1050 as untagged port, and add it to VLAN 100 and VLAN 200 as tagged port. Modify PVID of the port as 1050. Set the port as the UNI port.
Switch_1(config)#interface gigabitEthernet 1/0/2
Switch_1(config-if)#switchport general allowed vlan 1050 untagged
Switch_1(config-if)#switchport general allowed vlan 100,200 tagged
Switch_1(config-if)#switchport pvid 1050
Switch_1(config-if)#switchport dot1q-tunnel mode uni
Switch_1(config-if)#exit 
4) Enable VLAN VPN globally
Switch_1(config)#dot1q-tunnel
Switch_1(config)#end
Switch_1#copy running-config startup-config 

■ Configuring Switch 3

1) Create VLAN 100 and VLAN 200.
Switch_3#configure
Switch_3(config)#vlan 100 
Switch_3(config-vlan)#name C_VLAN100
Switch_3(config-vlan)#exit
Switch_3(config)#vlan 200
Switch_3(config-vlan)#name C_VLAN200
Switch_3(config-vlan)#exit 

2) Add port 1/0/1 to VLAN 100 and port 1/0/2 to VLAN 200 as untagged ports; add port 1/0/3 to VLAN 100 and VLAN 200 as tagged ports. Configure the PVID as 100 for port 1/0/1 and 200 for port 1/0/2.

Switch_3(config)#interface gigabitEthernet 1/0/1
Switch_3(config-if)#switchport general allowed vlan 100 untagged
Switch_3(config-if)#switchport pvid 100
Switch_3(config-if)#exit
Switch_3(config)#interface gigabitEthernet 1/0/2
Switch_3(config-if)#switchport general allowed vlan 200 untagged
Switch_3(config-if)#switchport pvid 200
Switch_3(config-if)#exit
Switch_3(config)#interface gigabitEthernet 1/0/3
Switch_3(config-if)#switchport general allowed vlan 100,200 tagged
Switch_3(config-if)#end
Switch_3#copy running-config startup-config 

Verify the VLAN VPN Configurations on Switch 1

Verify the configurations of global VLAN VPN:

Switch_3#show dot1q-tunnel

VLAN VPN Mode: Enabled

Mapping Mode: Disabled

Verify the configurations of VPN up-link port and VPN port:

Switch_3#show dot1q-tunnel interface

PortTypeTpidUse Inner PriorityLAG
-------------------
Gi1/0/1NNI0x9100DisableN/A

Gi1/0/2 UNI 0x8100 Enable N/A

Gi1/0/3 NONE 0x8100 Disable N/A

Gi1/0/4 NONE 0x8100 Disable N/A

...

Verify the port configuration:

Switch_3#show interface switchport gigabitEthernet 1/0/1

Port Gi1/0/1:

PVID: 1050

Acceptable frame type: All

Ingress Checking: Enable

Member in LAG: N/A

Link Type: General

Member in VLAN:

Vlan Name Egress-rule


1 System-VLAN Untagged

1050 SP_VLAN Tagged

Switch_3#show interface switchport gigabitEthernet 1/0/2

Port Gi1/0/2:

PVID: 1050

Acceptable frame type: All

Ingress Checking: Enable

Member in LAG: N/A

Link Type: General

Member in VLAN:

Vlan Name Egress-rule

......

1 System-VLAN Untagged

100 C_VLAN100 Tagged

200C_VLAN200Tagged
1050SP_VLANUntagged

4.2 Example for Flexible VLAN VPN

4.2.1 Network Requirements

A company has two stations, and the computers belong to VLAN 100 and VLAN 200 respectively. The ISP VLAN is VLAN 1050 and VLAN 1060, and the TPID adopted by the ISP network is 0x9100.

The two stations need to communicate with each other through the ISP network. And it is required that the traffic from VLAN 100 should be transmitted in VLAN 1050, while the traffic from VLAN 200 should be transmitted in VLAN 1060.

Figure 4-10 Network Topologygraph TD A["TPID=0x9100\nVLAN1050\nVLAN1060"] --> B["Switch 1"] A --> C["Switch 2"] B --> D["Switch 3"] C --> E["Switch 4"] D --> F["VLAN 200"] D --> G["VLAN 100"] E --> H["VLAN 200"] E --> I["VLAN 100"] B --> J["GI1/0/1\nGi1/0/2 UNI Port"] C --> K["GI1/0/2 UNI Port"] D --> L["GI1/0/2\nGi1/0/3 UNI P…

4.2.2 Configuration Scheme

To meet the requirement that all the traffic from VLAN 100 and VLAN 200 need to be transmitted through different ISP VLANs, users can configure flexible VLAN VPN on Switch 1 and Switch 2 to map VLAN 100 to VLAN 1050 and VLAN 200 to VLAN 1060, so packets from VLAN 100 and VLAN 200 will be transmitted through VLAN 1050 and VLAN 1060 respectively.

Here we only introduce the configuration scheme on Switch 1 and Switch 3, for the configurations on Switch 2 are the same as that on Switch 1, and the configurations on Switch 4 are the same as that on Switch 3.

1) Configure 802.1Q VLAN on Switch 1. The parameters are shown below:

VLAN 100 VLAN 200 VLAN 1050 VLAN 1060
Port 1/0/1 -- Tagged Tagged
Port 1/0/2 Tagged Tagged Untagged Untagged

2) Configure 802.1Q VLAN on Switch 3. The parameters are shown below:

VLAN 100 VLAN 200 PVID
Port 1/0/1 Untagged - 100
Port 1/0/2 - Untagged 200
Port 1/0/3 Tagged Tagged Keep thedefault value

3) Configure VLAN VPN on Switch 1. Set port 1/0/1 as NNI port and port 1/0/2 as UNI port; configure the TPID as 0x9100; map VLAN 100 to VLAN 1050 and VLAN 200 to VLAN 1060.

Demonstrated with T2600G-28TS, this chapter provides configuration procedures in two ways: using the GUI and using the CLI.

4.2.3 Using the GUI

■ Configuring Switch 1:

1) Go to L2 FEATURES > VLAN > 802.1Q VLAN to create VLAN 100, VLAN 200, VLAN 1050 and VLAN 1060. Configure the egress rule of port 1/0/2 in VLAN 100 and VLAN 200 as Tagged, and Untagged in VLAN 1050 and VLAN 1060; Configure the egress rule of port 1/0/1 in VLAN 1050 and VLAN 1060 as Tagged.

Figure 4-11 Create VLAN 100VLAN Config VLAN ID: 100 (2-4094, format: 2,4-5,0) VLAN Name: C_VLAN 100 (1-10 characters) Untagged Ports Port: (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 49 5…

Figure 4-12 Create VLAN 200VLAN Config VLAN ID: 200 (2-3094, format 2,4-5,8) VLAN Name: C_VLAN 200 (1-16 characters) Untagged Ports Port: (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 49 51…

Figure 4-13 Create VLAN 1050VLAN Config VLAN ID: 1050 (2-4094, format: 2.4-5.8) VLAN Name: SP VLAN_1050 (1-10 characters) Untagged Ports Port: 1/0/2 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 4…

Figure 4-14 Create VLAN 1060VLAN Config VLAN ID: 1060 (2-4084, format 2.4.5.8) VLAN Name: SP VLAN_1060 (1-16 characters) Untagged Ports Port: 1/0/2 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 25 28 30 32 34 36 38 40 Select All 41 43 45…

2) Go to L2 FEATURES > VLAN > VLAN VPN > VPN Config, enable VLAN VPN globally; set port 1/0/1 as NNI port and port 1/0/2 as UNI port. Specify the TPID of port 1/0/1 as 9100.

Figure 4-15 Enabling VLAN VPN Globally and Configuring the PortsGlobal Config VLAN VPN: ✓ Enable Port Config UNIT1 LAGS Port Port Role TPID Missdrop Use Inner Priority 1/0/1 NNI 9100 Disabled Disabled 1/0/2 UNI 8100 Disabled Disabled 1/0/3 - 8100 Disabled Disabled

3) Go to L2 FEATURES > VLAN > VLAN VPN > VLAN Mapping, enable VLAN Mapping globally. Then configure VLAN mapping for the UNI port 1/0/2.

Figure 4-16 Mapping VLAN 100 to VLAN 1050VLAN Mapping Config Port: 1/0/2 Choose (Format: 1/0/1) UNIT1 LAGS Select All 1 3 5 7 9 11 13 15 17 19 21 23 25 27 2 4 6 8 10 12 14 16 18 20 22 24 26 28 C VLAN: ID Name 100 (1-4094) SP VLAN: ID Name 1050 (1-4094) Description: (Optional: 1-16 characters) Cancel Create

Figure 4-17 Mapping VLAN 200 to VLAN 1060VLAN Mapping Config Port: 1/0/2 Choose (Format: 1/0/1) UNIT1 LAGS Select All 1 3 5 7 9 11 13 15 17 19 21 23 25 27 2 4 6 8 10 12 14 16 18 20 22 24 26 28 C VLAN: ID Name 200 (1-4094) SP VLAN: ID Name 1060 (1-4094) Description: (Optional: 1-16 characters) Cancel Create

4) Click Save the settings.

■ Configuring Switch 3:

1) Go to L2 FEATURES > VLAN > 802.1Q VLAN to create VLAN 100 and VLAN 200. Configure the egress rules of port 1/0/1 in VLAN 100 as Untagged; egress rules of port 1/0/2 in VLAN 200 as Untagged; egress rule of port 1/0/3 in VLAN 100 and VLAN 200 as Tagged.

Figure 4-18 Creating VLAN 100VLAN Config VLAN ID: 100 (2-4094, format: 2.4-5.0) VLAN Name: C_VLAN 100 (1-16 characters) Untagged Ports Port: 1/0/1 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 4…

Figure 4-19 Creating VLAN 200

VLAN Config VLAN ID: 200 (2-4094, format: 2.4-5.6) VLAN Name: C_VLAN 200 (1-10 characters) Untagged Ports Port: 1/0/2 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 4…

2) Go to L2 FEATURES > VLAN > Port Config to set the PVID as 100 for port 1/0/1 and 200 for port 1/0/2.

Figure 4-20 Configuring PVIDPort Config UNIT1 LAGS Port PVID Ingress Checking Acceptable Frame Types LAG Details 1/0/1 100 Enabled Admit All — Details 1/0/2 200 Enabled Admit All — Details 1/0/3 1 Enabled Admit All — Details

3) Click Save the settings.

4.2.4 Using the CLI

- Configuring Switch 1

1) Create VLAN 100, VLAN 200, VLAN 1050 and VLAN 1060.

Switch_1#configure
Switch_1(config)#vlan 1050
Switch_1(config-vlan)#name SP_VLAN1050
Switch_1(config-vlan)#exit
Switch_1(config)#vlan 1060
Switch_1(config-vlan)#name SP_VLAN1060
Switch_1(config-vlan)#exit
Switch_1(config)#vlan 100
Switch_1(config-vlan)#name C_VLAN100
Switch_1(config-vlan)#exit
Switch_1(config)#vlan 200
Switch_1(config-vlan)#name C_VLAN200
Switch_1(config-vlan)#exit 

2) Add port 1/0/1 to VLAN 1050 and VLAN 1060 as tagged port, set the port as NNI port and specify the TPID as 9100.

Switch_1(config)#interface gigabitEthernet 1/0/1
Switch_1(config-if)#switchport general allowed vlan 1050,1060 tagged
Switch_1(config-if)#switchport dot1q-tunnel mode nni 

Switch_1(config-if)#switchport dot1q-tunnel tpid 9100

Switch_1(config-if)#exit

3) Add port 1/0/2 to VLAN 1050 and VLAN 1060 as untagged port, and add it to VLAN 100 and VLAN 200 as tagged port. Set the port as the UNI port.

Switch_1(config)#interface gigabitEthernet 1/0/2

Switch_1(config-if)#switchport general allowed vlan 1050,1060 untagged

Switch_1(config-if)#switchport general allowed vlan 100,200 tagged

Switch_1(config-if)#switchport dot1q-tunnel mode uni

Switch_1(config-if)#exit

4) Enable VLAN mapping. Map VLAN 100 to VLAN 1050 and VLAN 200 to VLAN 1060 for port 1/0/2.

Switch_1(config)#dot1q-tunnel mapping

Switch_1(config)#interface gigabitEthernet 1/0/2

Switch_1(config-if)#switchport dot1q-tunnel mapping 100 1050 mapping

Switch_1(config-if)#switchport dot1q-tunnel mapping 200 1060

Switch_1(config-if)#exit

5) Enable VLAN VPN globally

Switch_1(config)#dot1q-tunnel

Switch_1(config)#end

Switch_1#copy running-config startup-config

■ Configuring Switch 3

1) Create VLAN 100 and VLAN 200.

Switch_3#configure

Switch_3(config)#vlan 100

Switch_3(config-vlan)#name C_VLAN100

Switch_3(config-vlan)#exit

Switch_3(config)#vlan 200

Switch_3(config-vlan)#name C_VLAN200

Switch_3(config-vlan)#exit

2) Add port 1/0/1 to VLAN 100 and port 1/0/2 to VLAN 200 as untagged ports; add port 1/0/3 to VLAN 100 and VLAN 200 as tagged ports. Configure the PVID as 100 for port 1/0/1 and 200 for port 1/0/2.

Switch_3(config)#interface gigabitEthernet 1/0/1 Switch_3(config-if)#switchport general allowed vlan 100 untagged Switch_3(config-if)#switchport pvid 100 Switch_3(config-if)#exit Switch_3(config)#interface gigabitEthernet 1/0/2 Switch_3(config-if)#switchport general allowed vlan 200 untagged Switch_3(config-if)#switchport pvid 200 Switch_3(config-if)#exit Switch_3(config)#interface gigabitEthernet 1/0/3 Switch_3(config-if)#switchport general allowed vlan 100,200 tagged Switch_3(config-if)#end Switch_3#copy running-config startup-config

5 Appendix: Default Parameters

Default settings of VLAN VPN are listed in the following table.

Table 5-1 Default Settings of VLAN VPN

Parameter Default Setting
Global VLAN VPN Disabled
Port Role None
Global TPID 0x8100
Missdrop Disabled
Use Inner Priority Disabled
VLAN Mapping Disabled

Part 12

Configuring GVRP

CHAPTERS

  1. Overview
  2. GVRP Configuration
  3. Configuration Example
  4. Appendix: Default Parameters

1 Overview

GVRP (GARP VLAN Registration Protocol) is a GARP (Generic Attribute Registration Protocol) application that allows registration and deregistration of VLAN attribute values and dynamic VLAN creation.

Without GVRP operating, configuring the same VLAN on a network would require manual configuration on each device. As shown in Figure 1-1, Switch A, B and C are connected through trunk ports. VLAN 10 is configured on Switch A, and VLAN 1 is configured on Switch B and Switch C. Switch C can receive messages sent from Switch A in VLAN 10 only when the network administrator has manually created VLAN 10 on Switch B and Switch C.

Figure 1-1 VLAN Topologygraph TD A["VLAN 10"] --> B["Switch A"] B --> C["Switch B"] C --> D["Switch C"]

The configuration may seem easy in this situation. However, for a larger or more complex network, such manual configuration would be time-consuming and error-prone. GVRP can be used to implement dynamic VLAN configuration. With GVRP, the switch can exchange VLAN configuration information with adjacent GVRP switches and dynamically create and manage VLANs. This reduces VLAN configuration workload and ensures correct VLAN configuration.

Figure 1-2 GVRP Topologygraph LR A["Switch 1"] --> B["Switch 3 Switch n"] B --> C["..."] C --> D["Switch 2"] D --> E["Switch 2"] style A fill:#cce5ff,stroke:#333 style B fill:#cce5ff,stroke:#333 style C fill:#cce5ff,stroke:#333 style D fill:#cce5ff,stroke:#333 style E fill:#cce5ff,stroke:#333

2 GVRP Configuration

To complete GVRP configuration, follow these steps:

1) Create a VLAN. 2) Enable GVRP globally. 3) Enable GVRP on each port and configure the corresponding parameters.

Configuration Guidelines

To dynamically create a VLAN on all ports in a network link, you must configure the same static VLAN on both ends of the link.

We call manually configured 802.1Q VLAN as static VLAN and VLAN created through GVRP as dynamic VLAN. Ports in a static VLAN can initiate the sending of GVRP registration messages to other ports. And a port registers VLANs only when it receives GVRP messages. As the messages can only be sent from one GVRP participant to another, two-way registration is required to configure a VLAN on all ports in a link. To implement two-way registration, you need to manually configure the same static VLAN on both ends of the link.

As shown in the figure below, VLAN registration from Switch A to Switch C adds Port 2 to VLAN 2. And VLAN registration from Switch C to Switch A adds Port 3 to VLAN 2.

Figure 2-1graph TD A["Switch A"] -->|Port 1 Port 4| B["Switch B"] B -->|Port 2| A B -->|Port 3| C["Switch C"] C -->|Port 4| A style A fill:#cce5ff,stroke:#333 style B fill:#cce5ff,stroke:#333 style C fill:#cce5ff,stroke:#333 note right of B: "Dynamic VLAN 2" note right of C: "Static VLAN 2"

Similarly, if you want to delete a VLAN from the link, two-way deregistration is required. You need to manually delete the static VLAN on both ends of the link.

2.1 Using the GUI

Choose the menu L2 FEATURES > VLAN > GVRP > GVRP to load the following page.

Figure 2-1 GVRP ConfigGVRP GVRP: Enable Apply Port Config UNIT1 LAGS Port Status Registration Mode LeaveAll Timer (1000-30000 centiseconds) Join Timer (20-1000 centiseconds) Leave Timer (60-3000 centiseconds) LAG 1/0/1 Disabled Normal 1000 20 60 --- 1/0/2 Disabled Normal 1000 20 60 --- 1/0/3 Disabled Normal 1000 20 60 --…

Follow these steps to configure GVRP:

1) In the GVRP section, enable GVRP globally, then click Apply. 2) In the Port Config section, select one or more ports, set the status as Enable and configure the related parameters according to your needs.

Port: Select the desired port for GVRP configuration. It is multi-optional.

Status: Enable or disable GVRP on the port. By default, it is disabled.

Registration Mode:

Select the GVRP registration mode for the port.

Normal: In this mode, the port can dynamically register and deregister VLANs, and transmit both dynamic and static VLAN registration information.

Fixed: In this mode, the port is unable to dynamically register and deregister VLANs, and can transmit only the information of VLAN 1.

Forbidden: In this mode, the port is unable to dynamically register and deregister VLANs, and can transmit only the information of VLAN 1.

LeaveAll Timer (centisecond)When a GVRP participant is enabled, the LeaveAll timer will be started. When the LeaveAll timer expires, the GVRP participant will send LeaveAll messages to request other GVRP participants to re-register all its attributes. After that, the participant restarts the LeaveAll timer.The timer ranges from 1000 to 30000 centiseconds and should be an integral multiple of 5. The default value is 1000 centiseconds.
Join Timer (centisecond)Join timer controls the sending of Join messages. A GVRP participant starts the Join timer after sending the first Join message. If the participant does not receive a response before the Join timer expires, it will send the second Join message to ensure that the Join message can be sent to other participants.The timer ranges from 20 to 1000 centiseconds and should be an integral multiple of 5. The default value is 20 centiseconds.
Leave Timer (centisecond)The Leave timer controls attribute deregistration. A participant will send a Leave message if it wants other participants to deregister some of its attributes. The participant receiving the message starts the Leave timer. If the participant does not receive any Join message of the corresponding attribute before the Leave timer expires, the participant deregisters the attribute.The timer ranges from 60 to 3000 centiseconds and should be an integral multiple of 5. The default value is 60 centiseconds.

LAG: Displays the LAG that the port belongs to.

3) Click Apply.

TP-LINK Omada Pro S5500-24GP4F - 3) Click Apply. - 1

Note:

  • The member ports of an LAG follow the configurations of the LAG and not their own. The individual configurations of the ports can take effect only after the ports leave the LAG. • The egress rule of the ports that are dynamically added to the VLAN is tagged. • The egress rule of the fixed ports should be tagged.
  • When setting the timer values, make sure that the values are within the required range. The configuration value for LeaveAll timer should be greater than or equal to ten times the Leave timer value. The value for Leave timer should be greater than or equal to two times the Join timer value.

2.2 Using the CLI

Step 1 configure

Enter Global Configuration Mode.

Step 2 gvrp

Enable GVRP globally.

Step 3 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 4 gvrp

Enable GVRP on the port.

Step 5 gvrp registration { normal | fixed | forbidden }

Configure the GVRP registration mode for the port. By default, it is normal.

normal: In this mode, the port can dynamically register and deregister VLANs, and transmit both dynamic and static VLAN registration information.

fixed: In this mode, the port is unable to dynamically register and deregister VLANs, and can transmit only the static VLAN registration information.

forbidden: In this mode, the port is unable to dynamically register and deregister VLANs, and can transmit only information of VLAN 1.

Step 6 gvrp timer { leaveall | join | leave } value

Set the GARP timers according to your needs.

leaveAll: When a GARP participant is enabled, the LeaveAll timer will be started. When the LeaveAll timer expires, the GARP participant will send LeaveAll messages to request other GARP participants to re-register all its attributes. After that, the participant restarts the LeaveAll timer.

join: Join timer controls the sending of Join messages. A GVRP participant starts the Join timer after sending the first Join message. If the participant does not receive any response, it will send the second Join message when the Join timer expires to ensure that the Join message can be sent to other participants.

leave: The Leave timer controls attribute deregistration. A participant will send a Leave message if it wants other participants to deregister some of its attributes. The participant receiving the message starts the Leave timer. If the participant does not receive any Join message of the corresponding attribute before the Leave timer expires, the participant deregisters the attribute.

value: Set a value for the timer. It should be an integral multiple of 5. For LeaveAll timer, the valid values are from 1000 to 30000 centiseconds and the default value is 1000 centiseconds. For Join timer, the valid values are from 20 to 1000 centiseconds and the default value is 20 centiseconds. For Leave timer, the valid values are from 60 to 3000 centiseconds and the default value is 60 centiseconds.

Step 7 show gvrp global

Verify the global configurations of GVRP.

Step 8 show gvrp interface [ fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel-id ]

Verify the GVRP configuration of the specified port or LAG.

Step 9 end

Return to privileged EXEC mode.

Step 10 copy running-config startup-config

Save the settings in the configuration file.

TP-LINK Omada Pro S5500-24GP4F - Using the CLI - 1

Note:

  • The member ports of an LAG follow the configurations of the LAG and not their own. The individual configurations of the ports can take effect only after the ports leave the LAG. • The egress rule of the ports dynamically added to the VLAN is tagged. • The egress rule of the fixed port should be tagged.
  • When setting the timer values, make sure that the values are within the required range. The configuration value for LeaveAll timer should be greater than or equal to ten times the Leave timer value. The value for Leave timer should be greater than or equal to two times the Join timer value.

The following example shows how to enable GVRP globally and on port 1/0/1, configure the GVRP registration mode as fixed, and keep the values of timers as default:

Switch#configure

Switch(config)#gvrp

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#gvrp

Switch(config-if)#gvrp registration fixed

Switch(config-if)#show gvrp global

GVRP Global Status: Enable

Switch(config-if)# show gvrp interface gigabitEthernet 1/0/1

PortStatusReg-ModeLeaveAllJoinInLeaveLAG
---------------------------
Gi1/0/1EnabledFixed10002060N/A

Switch(config-if)#end

Switch#copy running-config startup-config

3 Configuration Example

3.1 Network Requirements

Department A and Department B of a company are connected using switches. Offices of one department are distributed on different floors. As shown in Figure 3-1, the network topology is complicated. Configuration of the same VLAN on different switches is required so that computers in the same department can communicate with each other.

Figure 3-1 Network Topologygraph TD A["Dept. A: VLAN 10"] --> B["Switch 1"] B --> C["Gi1/0/1"] C --> D["Switch 5 Switch 6"] D --> E["Gi1/0/3"] E --> F["Switch 2"] F --> G["Dept. B: VLAN 20"] D --> H["..."] H --> I["Switch 4"] I --> J["Dept. A: VLAN 10"] J --> K["Switch 3"] K --> L["Gi1/0/1"] L --> M["Switch 4"] M --> N["Dept.…

3.2 Configuration Scheme

To reduce manual configuration and maintenance workload, GVRP can be enabled to implement dynamic VLAN registration and update on the switches.

When configuring GVRP, please note the following:

■ The two departments are in separate VLANs. To make sure the switches only dynamically create the VLAN of their own department, you need to set the registration mode for ports on Switch 1-4 as Fixed to prevent dynamic registration and deregistration of VLANs and allow the port to transmit only the static VLAN registration information. ■ To configure dynamic VLAN creation on the other switches, set the registration mode of the corresponding ports as Normal to allow dynamic registration and deregistration of VLANs.

Demonstrated with S6500-24GP4XF, the following sections provide configuration procedure in two ways: using the GUI and using the CLI.

3.3 Using the GUI

GVRP configurations for Switch 3 are the same as Switch 1, and Switch 4 are the same as Switch 2. Other switches share similar configurations.

The following configuration procedures take Switch 1, Switch 2 and Switch 5 as examples.

■ Configurations for Switch 1

1) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > VLAN Config and click Add to load the following page. Create VLAN 10 and add tagged port 1/0/1 to it. Click Create.

Figure 3-2 Create VLAN 10VLAN Config VLAN ID: 10 (2-4094, format: 2.4-5.8) VLAN Name: Department_A (1-16 characters) Untagged Ports Port (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 49 5…

2) Choose the menu L2 FEATURES > VLAN > GVRP to load the following page. Enable GVRP globally, then click Apply. Select port 1/0/1, set Status as Enable, and set Registration Mode as Fixed. Keep the values of the timers as default. Click Apply.

Figure 3-3 GVRP ConfigurationGVRP GVRP: ✓ Enable Apply Port Config UNIT1 LAGS Port Status Registration Mode LeaveAll Timer Join Timer (20- (1000-30000 Leave Timer (60- (1000-30000 (LAG centiseconds) 1000-30000 1000 3000 centiseconds) centiseconds)LAG Enable Fixed ✓ 1/0/1 Enabled Fixed 1000 20 60 -- □ 1/0/2 Disabled Normal 1000…

3) Click save the settings.

■ Configurations for Switch 2

1) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > VLAN Config and click

+ Add to load the following page. Create VLAN 20 and add tagged port 1/0/1 to it. Click Create.

Figure 3-4 Create VLAN 20VLAN Config VLAN ID: 20 (2-4/04, format: 2.4-5.8) VLAN Name: Department_B (1-16 characters) Unlagged Ports Port: (Format: 1/0/1, input or choose below) UNIT1 LAOS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 49…

2) Choose the menu L2 FEATURES > VLAN > GVRP to load the following page. Enable GVRP globally, then click Apply. Select port 1/0/1, set Status as Enable, and set Registration Mode as Fixed. Keep the values of the timers as default. Click Apply.

Figure 3-5 GVRP ConfigurationGVRP GVRP: ✓ Enable Port Config UNIT1 LAGS Port Status Registration Mode LeaveAll Timer Join Timer (20- Leave Timer (60- (1000-30000 (1000-30000 LAG) (centiseconds) (centiseconds) (centiseconds) Enable Fixed ✓ 1/0/1 Enabled Fixed 1000 20 60 -- □ 1/0/2 Disabled Normal 1000 20 60 -- □ 1/0/3 Disabled N…

3) Click Save the settings.

■ Configurations for Switch 5

1) Choose the menu L2 FEATURES > VLAN > GVRP to load the following page. Enable GVRP globally, then click Apply. Select ports 1/0/1-3, set Status as Enable, and keep the Registration Mode and the values of the timers as default. Click Apply.

Figure 3-6 GVRP ConfigurationGVRP GVRP: ✓ Enable Apply Port Config UNIT1 LAGS Port Status Registration Mode LeaveAll Timer(1000-30000centiseconds) Join Timer (20-1000centiseconds) Leave Timer (60-3000centiseconds) LAG Enable ✓ 1/0'1 Enabled Normal 1000 20 60 --- ✓ 1/0'2 Enabled Normal 1000 20 60 --- ✓ 1/0'3 Enabled Normal 1000…

2) Click save the settings.

3.4 Using the CLI

GVRP configuration for Switch 3 is the same as Switch 1, and Switch 4 is the same as Switch 2. Other switches share similar configurations.

The following configuration procedures take Switch 1, Switch 2 and Switch 5 as examples.

■ Configurations for Switch 1

1) Enable GVRP globally.

Switch_1#configure

Switch_1(config)#gvrp

2) Create VLAN 10.

Switch_1(config)#vlan 10

Switch_1(config-vlan)#name Department_A

Switch_1(config-vlan)#exit

3) Add tagged port 1/0/1 to VLAN 10. Enable GVRP on the port and set the registration mode as Fixed.

Switch_1(config)#interface gigabitEthernet 1/0/1
Switch_1(config-if)#switchport general allowed vlan 10 tagged
Switch_1(config-if)#gvrp
Switch_1(config-if)#gvrp registration fixed
Switch_1(config-if)#end
Switch_1#copy running-config startup-config 

■ Configurations for Switch 2

1) Enable GVRP globally.

Switch_2#configure

Switch_2(config)#gvrp

2) Create VLAN 20.

Switch_2(config)#vlan 20

Switch_2(config-vlan)#name Department_B

Switch_2(config-vlan)#exit

3) Add tagged port 1/0/1 to VLAN 20. Enable GVRP on the port and set the registration mode as Fixed.

Switch_2(config)#interface gigabitEthernet 1/0/1

Switch_2(config-if)#switchport general allowed vlan 20 tagged

Switch_2(config-if)#gvrp

Switch_2(config-if)#gvrp registration fixed

Switch_2(config-if)#end

Switch_2#copy running-config startup-config

■ Configurations for Switch 5

1) Enable GVRP globally.

Switch_5#configure

Switch_5(config)#gvrp

2) Enable GVRP on ports 1/0/1-3.

Switch_5(config)#interface range gigabitEthernet 1/0/1-3

Switch_5(config-if-range)#gvrp

Switch_5(config-if-range)#end

Switch_5#copy running-config startup-config

Verify the Configuration

Switch 1

Verify the global GVRP configuration:

Switch_1#show gvrp global

GVRP Global Status

Enabled

Verify GVRP configuration for port 1/0/1:

Switch_1#show gvrp interface

PortStatusReg-ModeLeaveAllJoinInLeaveLAG
---------------------------
Gi1/0/1EnabledFixed10002060N/A
Gi1/0/2DisabledNormal10002060N/A
...

Switch 2

Verify the global GVRP configuration:

Switch_2#show gvrp global

GVRP Global Status

Enabled

Verify GVRP configuration for port 1/0/1:

Switch_2#show gvrp interface

PortStatusReg-ModeLeaveAllJoinInLeaveLAG
---------------------------
Gi1/0/1EnabledFixed10002060N/A

Gi1/0/2 Disabled Normal 1000 20 60 N/A

...

Switch 5

Verify global GVRP configuration:

GVRP Global Status

Enabled

Verify GVRP configuration for ports 1/0/1-3:

Switch_5#show gvrp interface

PortStatusReg-ModeLeaveAllJoinInLeaveLAG
---------------------------
Gi1/0/1EnabledNormal10002060N/A
Gi1/0/2EnabledNormal10002060N/A
Gi1/0/3EnabledNormal10002060N/A
Gi1/0/4DisabledNormal10002060N/A
...

4 Appendix: Default Parameters

Default settings of GVRP are listed in the following tables.

Table 4-1 Default Settings of GVRP

Parameter Default Setting
Global Config
GVRP Disabled
Port Config
Status Disabled
Registration Mode Normal
LeaveAll Timer 1000 centiseconds
Join Timer 20 centiseconds
Leave Timer 60 centiseconds

Part 13

Configuring Private VLAN

(Only for Certain Devices)

Chapters

  1. Overview
  2. Private VLAN Configurations
  3. Configuration Example
  4. Appendix: Default Parameters

1 Overview

TP-LINK Omada Pro S5500-24GP4F - Overview - 1

Note:

Private VLAN is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If Private VLAN is available, there is L2 FEATURES > VLAN > Private VLAN in the menu structure.

Common large networks such as ISP networks generally isolate users by VLANs. However, with the increasing number of users, upper-layer devices have to create a large amount of VLANs to manage all the users. According to IEEE 802.1Q protocol, each upper-layer device can create no more than 4094 VLANs, which means upper-layer devices in backbone networks will face a shortage of VLANs. By creating primary VLAN and secondary VLAN, private VLAN is an effective solution to this problem.

Based on 802.1Q VLAN, private VLAN pairs a secondary VLAN with a primary VLAN. A primary VLAN can pair with more than one secondary VLAN to compose several private VLANs. In a private VLAN, Layer 2 isolation can be achieved between end users with secondary VLANs, while upper-layer devices only need to recognize primary VLANs, which solves the problem of VLAN shortage. Meanwhile, private VLAN resolves the conflicts triggered when users' need of VLANs is different from what the ISP can provide.

The network models of traditional VLAN and private VLAN are shown in Figure 1-1 and Figure 1-2 respectively. In the network model of traditional VLAN, isolation between users is achieved by creating VLAN2, VLAN3 and VLAN4. In this case, the upper-layer device, Switch A, needs to recognize 3 VLANs including VLAN2, VLAN3 and VLAN4.

Figure 1-1 Topology of Traditional VLANgraph TD A["Switch A"] --> B["Switch B"] B --> C["VLAN2"] B --> D["VLAN3"] B --> E["VLAN4"]

If private VLAN is configured on Switch B, Switch A only needs to recognize primary VLAN, VLAN5; and end users can be isolated by secondary VLANs, VLAN2, VLAN3 and VLAN4, saving VLAN resources for Switch A.

Figure 1-2 Topology of Private VLANgraph TD SwitchA["Switch A"] --> SwitchB["Switch B"] SwitchB --> VLAN5["VLAN5"] SwitchB --> VLAN2["VLAN2"] SwitchB --> VLAN3["VLAN3"] SwitchB --> VLAN4["VLAN4"] SwitchB --> VLAN5b["VLAN5"] SwitchB --> VLAN4b["VLAN4"]

2 Private VLAN Configurations

2.1 Using the GUI

TP-LINK Omada Pro S5500-24GP4F - Using the GUI - 1

Note:

If you need to create a private VLAN with existing VLANs, delete all member ports of the existing VLANs before creating the private VLAN.

Choose the menu L2 FEATURES > VLAN > Private VLAN and click + Add to load the following page.

Figure 2-1 Configuring Private VLANPrivate VLAN Config Primary VLAN: (2-4094) Secondary VLAN: (2-4094, format: 2.4-5.8) Secondary VLAN Type: Community Isolated Promiscuous Ports Port: (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34…

1) Enter the IDs of Primary VLAN and Secondary VLAN, and select Secondary VLAN Type.

Primary VLAN Specify the primary VLAN ID. A primary VLAN can pair with more than one secondary VLAN to compose several private VLANs.

Primary VLAN ID Displays the primary VLAN ID.

Secondary VLANSpecify the secondary VLAN ID. A secondary VLAN can pair with only one primary VLAN to create one private VLAN. To avoid long response times from the switch, you are recommended to create less than 10 secondary VLANs at a time.
Secondary VLAN IDDisplays the secondary VLAN ID.
Secondary VLAN TypeSelect the Secondary VLAN Type.Community: Select to allow users in the same community VLAN to communicate with each other.Isolated: Select to prevent users in the same isolated VLAN from communicating with each other.

2) Select promiscuous ports and host ports to be added to the private VLAN.

Promiscuous PortSelect promiscuous ports to be added to the VLAN. This type of port connects to the upper-layer devices or other switches. The PVID of this port is its primary VLAN ID.
Host Port Select host ports to be added to the VLAN. This type of port connects to end users and shields information from upper-layer devices. The PVID of this port is its secondary VLAN ID.

Members Displays the port members in the private VLAN.

3) Click Create.

TP-LINK Omada Pro S5500-24GP4F - 3) Click Create. - 1

Note:

When configuring the up-link port, you only need to add the port to one private VLAN and set the port type as Promiscuous. The switch will automatically add the port to private VLANs with the same primary VLAN.

2.2 Using the CLI

2.2.1 Creating Private VLAN

TP-LINK Omada Pro S5500-24GP4F - Creating Private VLAN - 1

Note:

If you need to create a private VLAN with existing VLANs, delete all member ports of the existing VLANs before creating the private VLAN.

Follow these steps to create Private VLAN:

Step 1 configure

Enter global configuration mode.

Step 2vlanvlan-listSpecify Primary VLAN ID, and enter VLAN configuration mode.vlan-list: Specify the ID or the ID list of the VLAN(s) for configuration. The ID ranges from 2 to 4094, for example, 2-3,5.
Step 3 private-vlan primarySpecify the VLAN to be the primary VLAN.
Step 4 exitExit VLAN configuration mode.
Step 5 vlanvlan-listSpecify Primary VLAN ID, and enter VLAN configuration mode.vlan-list: Specify the ID or the ID list of the VLAN(s) for configuration. The ID ranges from 2 to 4094, for example, 2-3,5.
Step 6private-vlan { community | isolated }Specify the VLAN to be the secondary VLAN, and configure the secondary VLAN type.community: Set the secondary VLAN type as Community. Users in the same isolated VLAN cannot communicate with each other.isolated: Set the secondary VLAN type as Isolated. Users in the same community VLAN can communicate with each other.
Step 7 exitExit VLAN configuration mode.
Step 8 vlanvlan-idSpecify the primary VLAN ID, and enter VLAN configuration mode.
Step 9 private-vlan association vlan-listSpecify the ID or the ID list of the secondary VLAN(s) to pair with this primary VLAN. To avoid long response time of the switch, you are recommended to pair less than 10 secondary VLANs with the primary VLAN at a time.vlan-list: Specify the ID or the ID list of the secondary VLAN(s).
Step 10 show vlan private-vlanVerify configurations of private VLAN.
Step 11 endReturn to Privileged EXEC Mode.
Step 12 copy running-config startup-configSave the settings in the configuration file.

The following example shows how to create primary VLAN 6 and secondary VLAN 5, set the secondary VLAN type as community, and pair primary VLAN 6 with secondary VLAN 5 as a private VLAN.

Switch#configure

Switch(config)#vlan 6

Switch(config-vlan)#private-vlan primary

Switch(config-vlan)#exit

Switch(config)#vlan 5

Switch(config-vlan)#private-vlan community

Switch(config-vlan)#exit

Switch(config)#vlan 6

Switch(config-vlan)#private-vlan association 5

Switch(config-vlan)#exit

Switch(config)#show vlan private-vlan

Primary Secondary Type Ports

6 5 Community

Switch(config)#end

Switch#copy running-config startup-config

Follow these steps to add up-link ports to Private VLAN:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 3 switchport private-vlan promiscuous

Configure the port type as Promiscuous. The port type of up-link port in a primary VLAN must be Promiscuous. This type of port is used to connect upper-layer devices or connect the switch with other switches. The PVID of this port is its primary VLAN ID.

Step 4 switchport private-vlan mapping

primary-vlan-id secondary-vlan-id

Add the specified port(s) to the private VLAN.

primary-vlan-id: Specify the ID of the primary VLAN. The ID ranges from 2 to 4094.

secondary-vlan-id: Specify the ID of the secondary VLAN. The ID ranges from 2 to 4094.

Step 5 show vlan private-vlan

Verify configurations of private VLAN.

Step 6 show vlan private-vlan interface [fastEthernet

port | gigabitEthernet port | ten-

gigabitEthernet port | port-channel lag-id]

Verify private VLAN configurations of ports.

port: Specify the ID of the port to show information.

lag-id: Specify the ID of the LAG to show information.

Step 7 end

Return to Privileged EXEC Mode.

Step 8 copy running-config startup-config

Save the settings in the configuration file.

TP-LINK Omada Pro S5500-24GP4F - Step 8 copy running-config startup-config - 1

Note:

When configuring the up-link port, you only need to add the port to one private VLAN and set the port type as Promiscuous. The switch will automatically add the port to private VLANs with the same primary VLAN.

The following example shows how to configure the port type of port 1/0/2 as Promiscuous, and add it to the private VLAN composed of primary VLAN 6 and secondary VLAN 5.

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)#switchport private-vlan promiscuous

Switch(config-if)#switchport private-vlan mapping 6 5

Switch(config-if)#exit

Switch(config)#show vlan private-vlan

Primary

Secondary

Type

Ports

6

5

Community

Gi1/0/2

Switch(config)#show vlan private-vlan interface gigabitEthernet 1/0/2

Port

type

Gi1/0/2 Promiscuous

Switch(config)#end

Switch#copy running-config startup-config

Follow these steps to add down-link ports to Private VLAN:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet

port | range fastEthernet port-list | gigabitEthernet port | range}

gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list

Enter interface configuration mode.

Step 3 switchport private-vlan host

Configure the port type as host. The port type of down-link port in a secondary VLAN must be Host. This type of port is used to connect to end users and shield information from upper-layer devices. The PVID of this port is its secondary VLAN ID.

Step 4 switchport private-vlan host-association

primary-vlan-id secondary-vlan-id vlantype

Add the specified port(s) to the private VLAN.

primary-vlan-id: Specify the ID of the primary VLAN. The ID ranges from 2 to 4094.

secondary-vlan-id: Specify the ID of the secondary VLAN. The ID ranges from 2 to 4094.

vlantype: Specify the secondary VLAN type, either community or isolated.

Step 5 show vlan private-vlan

Verify configurations of private VLAN.

Step 6 show vlan private-vlan interface [fastEthernet

port | gigabitEthernet port | ten-

gigabitEthernet port | port-channel lag-id]

Verify private VLAN configurations of ports.

port: Specify the ID of the port to show information.

lag-id: Specify the ID of the LAG to show information.

Step 7 end

Return to Privileged EXEC Mode.

Step 8 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the port type of port 1/0/3 as Host, and add it to the private VLAN composed of primary VLAN 6 and secondary VLAN 5.

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/3

Switch(config-if)#switchport private-vlan host

Switch(config-if)#switchport private-vlan host-association 6 5 community

Switch(config-if)#exit

Switch(config)#show vlan private-vlan

Primary Secondary Type Ports

6 5 Community Gi1/0/3

Switch(config)#show vlan private-vlan interface gigabitEthernet 1/0/3

Port type

Gi1/0/3 Host

Switch(config)#end

Switch#copy running-config startup-config

3 Configuration Example

3.1 Network Requirements

Usually, an ISP divides its network into subnets to differentiate different areas by using VLAN. Company A belongs to Area VI which is marked as VLAN 6 by the ISP. It is required that departments in Company A can achieve Layer 2 isolation by using VLAN and users in the same department can communicate with each other.

3.2 Configuration Scheme

You can create primary VLAN and secondary VLAN and pair them into private VLAN. This allows upper-layer switch to recognize only the primary VLAN instead of all the secondary VLANs. Also, Company A can achieve Layer 2 isolation by using secondary VLAN.

Since it is required that users in the same department can communicate with each other, secondary VLAN type should be configured as Community.

3.3 Network Topology

As shown in the following figure, Switch C is the ISP's central switch, and Switch A is in Company A. To meet the requirement, configure private VLAN on Switch A. This chapter provides configuration procedures in two ways: using the GUI and using the CLI.

Demonstrated with S6500-24GP4XF, this chapter provides configuration procedures in two ways: using the GUI and using the CLI.

Figure 3-1 Network Topologygraph TD A["Switch C\nGi1/0/3"] --> B["Switch A\nGi1/0/2"] A --> C["Company A\nGi1/0/10 Gi1/0/11"] B --> D["VLAN6"] B --> E["VLAN7"] C --> F["..."] C --> G["..."]

3.4 Using the GUI

■ Configurations for Switch A

1) Choose the menu L2 FEATURES > VLAN > Private VLAN and click + Add to load the following page. Create primary VLAN 6 and secondary VLAN 5, select Community as the Secondary VLAN Type. Add promiscuous port 1/0/2 and host port 1/0/10 to private VLAN.

Figure 3-2 Creating Primary VLAN 6 and Secondary VLAN 5Private VLAN Config Primary VLAN: 6 (2-4094) Secondary VLAN: 5 (2-4094, format: 2,4-5,8) Secondary VLAN Type: Community Isolated Promiscuous Ports Port 1/0/2 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28…

2) Choose the menu L2 FEATURES > VLAN > Private VLAN and click Add to load the following page. Create primary VLAN 6 and secondary VLAN 7, select Community as the Secondary VLAN Type. Add promiscuous port 1/0/2 and host port 1/0/11 to private VLAN.

Figure 3-3 Creating Primary VLAN 6 and Secondary VLAN 7Private VLAN Config Primary VLAN: 6 (2-4094) Secondary VLAN: 7 (2-4094, format: 2.4-5.8) Secondary VLAN Type: Community Isolated Promiscuous Ports Port: 1/0/2 (Format: 1/0/1, input or choose below) UNIT 1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26…

3) Click to save the settings.

■ Configurations for Switch C

1) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > VLAN Config and click Add to load the following page. Create VLAN 6 and add untagged port 1/0/3 to VLAN 6. Click Create.

Figure 3-4 Creating VLAN 6VLAN Config VLAN ID: 6 (2-4094, format 2,4-5,8) VLAN Name: VLAN 6 (1-16 characters) Untagged Ports Port: 1/0/3 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 49 51…

2) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > Port Config to load the following page. Set the PVID of port 1/0/3 as 6. Click Apply.

Figure 3-5 Specifying the PVIDPort Config UNIT1 LAGS Port PVID Ingress Checking Acceptable Frame Types LAG Details 6 ▼ ▼ 1/0/1 1 Enabled Admit All --- Details 1/0/2 1 Enabled Admit All --- Details ✓ 1/0/3 6 Enabled Admit All --- Details 1/0/4 1 Enabled Admit All --- Details 1/0/5 1 Enabled Admit All --- Details 1/0/6 1 Enabled A…

3) Click Save the settings.

3.5 Using the CLI

Configurations for Switch A

1) Enter global configuration mode.

Switch_A>enable

Switch_A#configure

2) Create primary VLAN 6 and secondary VLAN 5, and pair them into a private VLAN.

Switch_A(config)#vlan 6

Switch_A(config-vlan)#private-vlan primary

Switch_A(config-vlan)#exit

Switch_A(config)#vlan 5

Switch_A(config-vlan)#private-vlan community

Switch_A(config-vlan)#exit

Switch_A(config)#vlan 6

Switch_A(config-vlan)#private-vlan association 5

Switch_A(config-vlan)#exit

3) Create secondary VLAN 7, and pair it with primary VLAN 6 into a private VLAN.

Switch_A(config)#vlan 7

Switch_A(config-vlan)#private-vlan community

Switch_A(config-vlan)#exit

Switch_A(config)#vlan 6

Switch_A(config-vlan)#private-vlan association 7

Switch_A(config-vlan)#exit

4) Add up-link port to the corresponding private VLAN and configure the port type as Promiscuous.

Switch_A(config)#interface gigabitEthernet 1/0/2

Switch_A(config-if)#switchport private-vlan promiscuous

Switch_A(config-if)#switchport private-vlan mapping 6 5

Switch_A(config-if)#exit

5) Add down-link port to the corresponding private VLAN and configure the port type as Host.

Switch_A(config)#interface gigabitEthernet 1/0/10

Switch_A(config-if)#switchport private-vlan host
Switch_A(config-if)#switchport private-vlan host-association 6 5 community
Switch_A(config-if)#exit
Switch_A(config)#interface gigabitEthernet 1/0/11
Switch_A(config-if)#switchport private-vlan host
Switch_A(config-if)#switchport private-vlan host-association 6 7 community
Switch_A(config-if)#end
Switch_A#copy running-config startup-config 

■ Configurations for Switch C

1) Enter global configuration mode.

Switch_C>enable

Switch_C#configure

2) Create VLAN 6, add port 1/0/3 to VLAN 6 and set the PVID of port 1/0/3 as 6.

Switch_C(config)#vlan 6

Switch_C(config-vlan)#name vlan6

Switch_C(config-vlan)#exit

Switch_C(config)#interface gigabitEthernet 1/0/3

Switch_C(config-if)#switchport pvid 6

Switch_C(config-if)#switchport general allowed vlan 6 untagged

Switch_C(config-if)#end

Switch_C#copy running-config startup-config

Verify the Configurations

Switch A

Verify the configuration of private VLAN:

Switch_A#show vlan private-vlan

PrimarySecondaryTypePorts
65CommunityGi1/0/2,1/0/10
67CommunityGi1/0/2,1/0/11

Verify the configuration of ports:

Switch_A#show vlan private-vlan interface

Port type


Gi1/0/1 Normal

Gi1/0/2 Promiscuous

Gi1/0/3 Normal

Gi1/0/4 Normal

Gi1/0/5 Normal

Gi1/0/6 Normal

Gi1/0/7 Normal

Gi1/0/8 Normal

Gi1/0/9 Normal

Gi1/0/10 Host

Gi1/0/11 Host

Gi1/0/12 Normal

...

Switch C

Verify the configuration of 802.1Q VLAN:

Switch_C#show vlan

VLANNameStatusPorts
1System-VLANactiveGi1/0/1, Gi1/0/2, Gi1/0/3, Gi1/0/4,Gi1/0/5, Gi1/0/6, Gi1/0/7, Gi1/0/8,Gi1/0/9, Gi1/0/10, Gi1/0/11, Gi1/0/12,Gi1/0/13, Gi1/0/14, Gi1/0/15, Gi1/0/16,Gi1/0/17, Gi1/0/18, Gi1/0/19, Gi1/0/20,Gi1/0/21, Gi1/0/22, Gi1/0/23, Gi1/0/24,Gi1/0/25, Gi1/0/26, Gi1/0/27, Gi1/0/28
6vlan6activeGi1/0/3

Primary Secondary Type Ports

4 Appendix: Default Parameters

Default settings of Private VLAN are listed in the following tables.

Table 4-1 Default Settings of Private VLAN

Parameter Default Setting
Primary VLAN None
Secondary VLAN None
Secondary VLAN Type Community

Part 14

Configuring Multicast

CHAPTERS

  1. Layer 2 Multicast
  2. IGMP Snooping Configuration
  3. MLD Snooping Configuration
  4. MVR Configuration
  5. Multicast Filtering Configuration
  6. Viewing Multicast Snooping Information
  7. PIM & Static Multicast-Routing Configuration
  8. Layer 3 IGMP Configuration
  9. Configuration Examples
  10. Appendix: Default Parameters

1 Layer 2 Multicast

1.1 Overview

In a point-to-multipoint network, packets can be sent in three ways: unicast, broadcast, and multicast. With unicast, many copies of the same information are sent to all receivers, occupying a large bandwidth.

With broadcast, information is sent to all users in the network, whether they need it or not, wasting network resources and impacting information security.

Multicast, however, solves all the problems caused by unicast and broadcast. With multicast, the source only needs to send one piece of information, and all and only the users who need the information receive copies of it. In a point-to-multipoint network, multicast technology not only transmits data with high efficiency but also saves a large bandwidth and reduces network load.

In practical applications, Internet information providers can offer value-added services such as Online Live, IPTV, Distance Education, Telemedicine, Internet Radio, and Real-time Video Conferences more conveniently using multicast.

Layer 2 Multicast allows Layer 2 switches to listen for IGMP (Internet Group Management Protocol) packets between the IGMP Querier and user hosts to establish a multicast forwarding table and to manage and control the transmission of packets.

Take IGMP Snooping as an example. When IGMP Snooping is disabled on the Layer 2 device, multicast packets are broadcast in the Layer 2 network; when IGMP Snooping is enabled on the Layer 2 device, multicast data from a known multicast group is transmitted to the designated receivers instead of being broadcast in the Layer 2 network.

Layer 3 Multicast features, including PIM (Protocol Independent Multicast), static multicast-routing, and IGMP, are only supported on Layer 3 switches.

Demonstrated as below:

Figure 1-1 IGMP Snoopinggraph TD A["Source"] --> B["IGMP Querier"] B --> C["Non-Snooping Switch"] C --> D["Host A Host B Host C"] C --> E["Host A Host B Host C"] C --> F["Host A Host B Host C"] C --> G["Host A Host B Host C"] style A fill:#333,stroke:#fff,color:#fff style B fill:#999,stroke:#000,color:#fff style C fill:#99…

graph TD A["Source"] --> B["IGMP Querier"] B --> C["Router Port"] C --> D["Snooping Switch"] D --> E["Host A Host B Host C"] D --> F["Member Port"] D --> G["Member Port"] style A fill:#333,stroke:#fff,color:#fff style B fill:#999,stroke:#000,color:#fff style C fill:#999,stroke:#000,color:#fff style…

The following basic concepts of IGMP Snooping will be introduced: IGMP querier, snooping switch, router port and member port.

IGMP Querier

An IGMP querier is a multicast router (a router or a Layer 3 switch) that sends query messages to maintain a list of multicast group memberships for each attached network, and a timer for each membership.

Normally only one device acts as querier per physical network. If there are more than one multicast router in the network, a querier election process will be implemented to determine which one acts as the querier.

Snooping Switch

A snooping switch indicates a switch with IGMP Snooping enabled. The switch maintains a multicast forwarding table by snooping on the IGMP transmissions between the host and the querier. With the multicast forwarding table, the switch can forward multicast data only to the ports that are in the corresponding multicast group, so as to constrain the flooding of multicast data in the Layer 2 network.

Router Port

A router port is a port on snooping switch that is connecting to the IGMP querier.

Member Port

A member port is a port on snooping switch that is connecting to the host.

1.2 Supported Features

Layer 2 Multicast protocol for IPv4: IGMP Snooping

On the Layer 2 device, IGMP Snooping transmits data on demand on data link layer by analyzing IGMP packets between the IGMP querier and the users, to build and maintain Layer 2 multicast forwarding table.

Layer 2 Multicast protocol for IPv6: MLD Snooping

On the Layer 2 device, MLD Snooping (Multicast Listener Discovery Snooping) transmits data on demand on the data link layer by analyzing MLD packets between the MLD querier and the users, to build and maintain a Layer 2 multicast forwarding table.

Multicast VLAN Registration (MVR)

MVR allows a single multicast VLAN to be shared for multicast member ports in different VLANs in an IPv4 network. In IGMP Snooping, if member ports are in different VLANs, a copy of the multicast streams is sent to each VLAN that has member ports. MVR provides a dedicated multicast VLAN to forward multicast traffic over the Layer 2 network, to avoid duplication of multicast streams for clients in different VLANs. Clients can dynamically join or leave the multicast VLAN without interfering with their relationships in other VLANs.

There are two types of MVR modes:

■ Compatible Mode

In compatible mode, the MVR switch does not forward report or leave messages from the hosts to the IGMP querier. So the IGMP querier cannot learn the multicast group membership information from the MVR switch. You have to statically configure the IGMP querier to transmit all the required multicast streams to the MVR switch via the multicast VLAN.

■ Dynamic Mode

In dynamic mode, after receiving report or leave messages from the hosts, the MVR switch forwards them to the IGMP querier via the multicast VLAN (with appropriate translation of the VLAN ID). So the IGMP querier can learn the multicast group membership information through the report and leave messages, and transmit the multicast streams to the MVR switch via the multicast VLAN according to the multicast forwarding table.

Multicast Filtering

Multicast Filtering allows you to control the set of multicast groups to which a host can belong. You can filter multicast joins on a per-port basis by configuring IP multicast profiles (IGMP profiles or MLD profiles) and associating them with individual switch ports.

Protocol Independent Multicast

The Protocol Independent Multicast protocol, abbreviated as PIM, uses unicast routing information to provide multicast forwarding functions in a Layer 3 network. PIM works in dense mode.

Static Multicast Routing

Multicast routing creates multicast routing table entries based on existing unicast routing information or multicast static routing. When creating multicast routing table entries, multicast routing protocols use the RPF (Reverse Path Forwarding) checking mechanism to ensure that multicast data can be forwarded along the correct path. Multicast static route entries are one of the important bases for RPF inspection and are mainly used to change or connect RPF routes.

IP IGMP

IP IGMP is used to enable the IGMP function on the specified interface, and the no command is used to disable the IGMP function on the specified interface.

2 IGMP Snooping Configuration

To complete IGMP Snooping configuration, follow these steps:

1) Enable IGMP Snooping globally and configure the global parameters. 2) Configure IGMP Snooping for VLANs. 3) Configure IGMP Snooping for ports. 4) (Optional) Configure hosts to statically join a group.

TP-LINK Omada Pro S5500-24GP4F - IGMP Snooping Configuration - 1

Note:

IGMP Snooping takes effect only when it is enabled globally, in the corresponding VLAN and port at the same time.

2.1 Using the GUI

2.1.1 Configuring IGMP Snooping Globally

Choose the menu L2 FEATURES > Multicast > IGMP Snooping > Global Config to load the following page.

Figure 2-1 Configure IGMP Snooping GloballyGlobal Config IGMP Snooping: Enable IGMP Version: v1 v2 v3 Unknown Multicast Groups Forward Discard Header Validation: Enable Apply

Follow these steps to configure IGMP Snooping globally:

1) In the Global Config section, enable IGMP Snooping globally and configure the global parameters.

IGMP Snooping Enable or disable IGMP snooping globally.

IGMP Version Specify the IGMP version. The switch supports IGMPv1, IGMPv2 and IGMPv3.
v1: The switch works as an IGMPv1 Snooping switch. It can only process IGMPv1 messages from the host. Messages of other versions are ignored.
v2: The switch works as an IGMPv2 Snooping switch. It can process both IGMPv1 and IGMPv2 messages from the host. IGMPv3 messages are ignored.
v3: The switch works as an IGMPv3 Snooping switch. It can process IGMPv1, IGMPv2 and IGMPv3 messages from the host.
Unknown Multicast GroupsSet the way in which the switch processes packets that are sent to unknown multicast groups as either Forward or Discard. Unknown multicast groups are multicast groups whose destination multicast address is not in the multicast forwarding table of the switch.
Note: IGMP Snooping and MLD Snooping share the setting of Unknown Multicast Groups..
Header Validation Enable or disable Header Validation. By default, it is disabled.
Generally, for IGMP packets, the TTL value should be 1, ToS field should be 0xC0, and Router Alert option should be 0x94040000. The fields to be validated depend on the IGMP version being used. IGMPv1 only checks the TTL field. IGMPv2 checks the TTL field and the Router Alert option. IGMPv3 checks the TTL field, ToS field and Router Alert option. Packets that fail the validation process will be dropped.

2) Click Apply.

2.1.2 Configuring IGMP Snooping for VLANs

Before configuring IGMP Snooping for VLANs, set up the VLANs that the router ports and the member ports are in. For details, refer to Configuring 802.1Q VLAN.

The switch supports configuring IGMP Snooping on a per-VLAN basis. After IGMP Snooping is enabled globally, you also need to enable IGMP Snooping and configure the corresponding parameters for the VLANs that the router ports and the member ports are in.

Choose the menu L2 FEATURES > Multicast > IGMP Snooping > Global Config, and click in your desired VLAN entry in the IGMP VLAN Config section to load the following page.

Figure 2-2 Configure IGMP Snooping for VLANConfigure IGMP Snooping for VLAN VLAN ID: 1 IGMP Snooping Status: Enable Fast Leave: Enable Report Suppression: Enable Member Port Aging Time: 260 seconds (50-600) Router Port Aging Time: 300 seconds (60-800) Leave Time: 1 seconds (-1.30) IGMP Snooping Question: Enable Static Router Ports UNIT1 LAGS…

Follow these steps to configure IGMP Snooping for a specific VLAN:

1) Enable IGMP Snooping for the VLAN, and configure the corresponding parameters.

VLAN ID: Displays the VLAN ID.

IGMP Snooping Status: Enable or disable IGMP snooping for the VLAN.

Fast Leave: Enable or disable Fast Leave for the VLAN. IGMPv1 does not support Fast Leave.

Fast Leave Enable or disable Fast Leave for the VLAN. IGMPv1 does not support Fast Leave.

Without Fast Leave, after a receiver sends an IGMP leave message to leave a multicast group, the switch will forward the leave message to the Layer 3 device (the querier).

From the point of view of the querier, the port connecting to the switch is a member port of the corresponding multicast group. After receiving the leave message from the switch, the querier will send out a configured number (Last Member Query Count) of group-specific queries on that port with a configured interval (Last Member Query Interval), and wait for IGMP group membership reports. If there are other receivers connecting to the switch, they will respond to the queries before the Last Member Query Interval expires. If no reports are received after the response time of the last query expires, the querier will remove the port from the forwarding list of the corresponding multicast group.

That is, if there are other receivers connecting to the switch, the one that sent the leave message has to wait until the port ages out from the switch's forwarding list of the corresponding multicast group (the maximum waiting time is decided by the Member Port Aging Time).

With Fast Leave enabled on a VLAN, the switch will remove the (Multicast Group, Port, VLAN) entry from the multicast forwarding table before forwarding the leave message to the querier. This helps to reduce bandwidth waste since the switch no longer sends the corresponding multicast streams to the VLAN of the port as soon as the port receives a leave message from the VLAN.

Report SuppressionEnable or disable Report Suppression for the VLAN. When enabled, the switch will only forward the first IGMP report message for each multicast group to Layer 3 devices and suppress subsequent IGMP report messages for the same multicast group during one query interval. This feature prevents duplicate report messages from being sent to the Layer 3 devices.
Member Port Aging TimeSpecify the aging time of the member ports in the VLAN. If the switch does not receive any IGMP membership report messages for a specific multicast group from a dynamic member port, it will no longer consider this port as a member port of this multicast group and delete it from the multicast forwarding table.
Router Port Aging TimeSpecify the aging time of the router ports in the VLAN. If the switch does not receive any IGMP general query message from a dynamic router port within the router port aging time, the switch will no longer consider this port as a router port and delete it from the router port list.
Leave TimeSpecify the leave time for the VLAN. When the switch receives a leave message from a port to leave a multicast group, it will wait for a leave time before removing the port from the multicast group. During the period, if the switch receives any report messages from the port, the port will not be removed from the multicast group. Exceptions are as follows:If the member port ages out before the Leave Time ends and no report messages are received, the port will be removed from the multicast group once its Member Port Aging Time ends.The Leave Time mechanism will not take effect when Fast Leave takes effect.A proper leave time value can avoid other hosts connecting to the same port of the switch being mistakenly removed from the multicast group when only some of them want to leave.
IGMP Snooping QuerierEnable or disable the IGMP Snooping Querier for the VLAN.When enabled, the switch acts as an IGMP Snooping Querier for the hosts in this VLAN. A querier periodically sends a general query on the network to solicit membership information, and sends group-specific queries when it receives leave messages from hosts.
Query IntervalWith IGMP Snooping Querier enabled, specify the interval between general query messages sent by the querier.
Maximum Response TimeWith IGMP Snooping Querier enabled, specify the host's maximum response time to general query messages.
Last Member Query IntervalWith IGMP Snooping Querier enabled, when the switch receives an IGMP leave message, it obtains the address of the multicast group that the host wants to leave from the message. Then the switch sends out group-specific queries to this multicast group through the port receiving the leave message. This parameter determines the interval between group-specific queries.
Last Member Query CountWith IGMP Snooping Querier enabled, specify the number of group-specific queries to be sent. If specified count of group-specific queries are sent and no report message is received, the switch will delete the multicast address from the multicast forwarding table.
General Query Source IPWith IGMP Snooping Querier enabled, specify the source IP address of the general query messages sent by the querier. It should be a unicast address.
Dynamic Router PortsDisplays all the dynamic router ports in the multicast VLAN.
Static Router PortsSelect one or more ports to be the static router ports in the VLAN. All multicast data in this VLAN will be forwarded through the static router ports.
Forbidden Router PortsSelect ports to forbid them from being router ports in the VLAN.

2) Click Save.

2.1.3 Configuring IGMP Snooping for Ports

Choose the menu L2 FEATURES > Multicast > IGMP Snooping > Port Config to load the following page.

Figure 2-3 Configure IGMP Snooping for PortsPort Config UNIT1 LAGS Port IGMP Snooping Fast Leave LAG Gi1/0/1 Enabled Disabled --- Gi1/0/2 Enabled Disabled --- Gi1/0/3 Enabled Disabled --- Gi1/0/4 Enabled Disabled --- Gi1/0/5 Enabled Disabled --- Gi1/0/6 Enabled Disabled --- Gi1/0/7 Enabled Disabled --- Gi1/0/8 Enabled Disabled --- Gi1/0/9 Ena…

Follow these steps to configure IGMP Snooping for ports:

1) Enable IGMP Snooping for the port and enable Fast Leave if there is only one receiver connected to the port.

IGMP Snooping: Enable or disable IGMP Snooping on the port.

Fast Leave: Enable or disable Fast Leave for the port. IGMPv1 does not support fast leave.

Fast Leave can be enabled on a per-port basis or per-VLAN basis. When enabled, the switch will remove this port from the forwarding list of the corresponding multicast group once the port receives a leave message, without verifying if there are other members of this multicast group. You should only use this function when there is a single receiver present on the port.

You should only use Fast Leave for a port when there is a single receiver connected to the port. For more details about Fast Leave, see 2.1.2 Configuring IGMP Snooping for VLANs.

LAG: Displays the LAG that the port belongs to.

2) Click Apply.

2.1.4 Configuring Hosts to Statically Join a Group

Hosts or Layer 2 ports normally join multicast groups dynamically, but you can also configure hosts to statically join a group.

Choose the menu L2 FEATURES > Multicast > IGMP Snooping > Static Group Config and click + Add to load the following page.

Figure 2-4 Configure Hosts to Statically Join a GroupCreate Static Multicast Group Multicast IP: (Farmal 235 0.0.1) VLAN ID: (1.4204) Member Ports: UNIT1 LAGS Select All 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 41 43 45 47 49 51 53 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 42 44 46 48 50 52 54 Selected Unselected Not Availa…

Follow these steps to configure hosts to statically join a group:

1) Specify the multicast IP address, VLAN ID. Select the ports to be the static member ports of the multicast group.

Multicast IP Specify the multicast group that the static member is in.

VLAN ID Specify the VLAN that the static member is in.

Member Ports Specify one or more ports to be the static member ports in the multicast group. Without aging, the static member ports receive all multicast data sent to this multicast group.

2) Click Create.

2.1.5 Configuring IGMP Accounting and Authentication Features

TP-LINK Omada Pro S5500-24GP4F - Configuring IGMP Accounting and Authentication Features - 1

Note:

IGMP Accounting and Authentication is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface.

You can enable IGMP accounting and authentication according to your need. IGMP accounting is configured globally, and IGMP authentication can be enabled on a per-port basis.

To use these features, you should also set up a RADIUS server and go to SECURITY > AAA > RADIUS Config to configure RADIUS server for the switch.

Choose the menu L2 FEATURES > Multicast > IGMP Snooping > IGMP Authentication to load the following page.

Figure 2-5 Configure IGMP Accounting and AuthenticationGlobal Config Accounting: Enable Apply Port Config UNIT1 LAGS ID Port IGMP Authentication LAG 1 Gi1/0/1 Disabled --- 2 Gi1/0/2 Disabled --- 3 Gi1/0/3 Disabled --- 4 Gi1/0/4 Disabled --- 5 Gi1/0/5 Disabled --- 6 Gi1/0/6 Disabled --- 7 Gi1/0/7 Disabled --- 8 Gi1/0/8 Disabled --- 9 Gi1/0/9 Disabled ---…

Follow these steps to enable IGMP accounting:

1) In the Global Config section, enable IGMP Accounting globally.

Accounting Enable or disable IGMP Accounting globally.

2) Click Apply.

Follow these steps to configure IGMP Authentication on ports:

1) In the Port Config section, select the ports and enable IGMP Authentication.

IGMP

Enable or disable IGMP Authentication for the port.

Authentication

LAG Displays the LAG that the port belongs to.

2) Click Apply.

2.2 Using the CLI

2.2.1 Configuring IGMP Snooping Globally

Follow these steps to configure IGMP Snooping globally:

Step 1 configure

Enter global configuration mode.

Step 2 ip igmp snooping

Enable IGMP Snooping Globally.

Step 3 ip igmp snooping version {v1 | v2 | v3}

Configure the IGMP version.

v1: The switch works as an IGMPv1 Snooping switch. It can only process IGMPv1 report messages from the host. Report messages of other versions are ignored.

v2: The switch works as an IGMPv2 Snooping switch. It can process both IGMPv1 and IGMPv2 report messages from the host. IGMPv3 report messages are ignored.

v3: The switch works as an IGMPv3 Snooping switch. It can process IGMPv1, IGMPv2 and IGMPv3 report messages from the host.

Step 4 ip igmp snooping drop-unknown

(Optional) Configure the way how the switch processes multicast streams that are sent to unknown multicast groups as Discard. By default, it is Forward.

Unknown multicast groups are multicast groups that do not match any of the groups announced in earlier IGMP membership reports, and thus cannot be found in the multicast forwarding table of the switch.

Note: IGMP Snooping and MLD Snooping share the setting of Unknown Multicast Groups.

Step 5 ip igmp snooping header-validation

(Optional) Enable header validation.

Generally, for IGMP packets, the TTL value should be 1, ToS field should be 0xC0, and Router Alert option should be 0x94040000. The fields validated depend on the IGMP version being used. IGMPv1 only checks the TTL field. IGMPv2 checks the TTL field and the Router Alert option. IGMPv3 checks TTL field, ToS field and Router Alert option. Packets that fail the validation process will be dropped.

Step 6 show ip igmp snooping

Show the basic IGMP Snooping configuration.

Step 7 end

Return to privileged EXEC mode.

Step 8 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable IGMP Snooping and header validation globally, and specify the IGMP Snooping version as IGMPv3, the way how the switch processes multicast streams that are sent to unknown multicast groups as discard.

Switch#configure

Switch(config)#ip igmp snooping

Switch(config)#ip igmp snooping version v3

Switch(config)#ipv6 mld snooping

Switch(config)#ip igmp snooping drop-unknown

Switch(config)#ip igmp snooping header-validation

Switch(config)#show ip igmp snooping

IGMP

Snooping

:Enable

IGMP

Version

:V3

Unknown

Multicast

:Discard

Header

Validation

:Enable

Global Authentication Accounting :Disable

...

Switch(config)#end

Switch#copy running-config startup-config

2.2.2 Configuring IGMP Snooping for VLANs

Before configuring IGMP Snooping for VLANs, set up the VLANs that the router ports and the member ports are in. For details, please refer to Configuring 802.1Q VLAN.

The switch supports configuring IGMP Snooping on a per-VLAN basis. After IGMP Snooping is enabled globally, you also need to enable IGMP Snooping and configure the corresponding parameters for the VLANs that the router ports and the member ports are in.

Follow these steps to configure IGMP Snooping for VLANs:

Step 1 configure

Enter global configuration mode.

Step 2 ip igmp snooping vlan-config

vlan-id-list

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

Step 3 ip igmp snooping vlan-config

vlan-id-list rtime router-time

Specify the router port aging time for the VLANs.

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

router-time: Specify the aging time of the router ports in the specified VLANs. Valid values are from 60 to 600 seconds. By default, it is 300 seconds.

Once the switch receives an IGMP general query message from a port, the switch adds this port to the router port list. Router ports that are learned in this way are called dynamic router ports.

If the switch does not receive any IGMP general query message from a dynamic router port within the router port aging time, the switch will no longer consider this port as a router port and delete it from the router port list.

Step 4 ip igmp snooping vlan-config

vlan-id-list ltime leave-time

Specify the router port aging time for the VLANs.

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

leave-time: Specify the leave time for the VLAN(s). Valid values are from 1 to 30 in seconds, and the default value is 1 second.

When the switch receives a leave message from a port to leave a multicast group, it will wait for a leave time before removing the port from the multicast group. During the period, if the switch receives any report messages from the port, the port will not be removed from the multicast group. Exceptions are as follows:

- If the member port ages out before the Leave Time ends and no report messages are received, the port will be removed from the multicast group once its Member Port Aging Time ends.

• The Leave Time mechanism will not take effect when Fast Leave takes effect.

A proper leave time value can avoid other hosts connecting to the same port of the switch being mistakenly removed from the multicast group when only some of them want to leave.

Step 5 ip igmp snooping vlan-config

vlan-id-list report-suppression

(Optional) Enable the Report Suppression for the VLANs. By default, it is disabled.

When enabled, the switch will only forward the first IGMP report message for each multicast group to the IGMP querier and suppress subsequent IGMP report messages for the same multicast group during one query interval. This feature prevents duplicate report messages from being sent to the IGMP querier.

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

Step 6 ip igmp snooping vlan-config

vlan-id-list immediate-leave

(Optional) Enable Fast Leave for the VLANs. By default, it is disabled. IGMPv1 does not support fast leave.

Without Fast Leave, after a receiver sends an IGMP leave message to leave a multicast group, the switch will forward the leave message to the Layer 3 device (the querier).

From the point of view of the querier, the port connecting to the switch is a member port of the corresponding multicast group. After receiving the leave message from the switch, the querier will send out a configured number (Last Member Query Count) of group-specific queries on that port with a configured interval (Last Member Query Interval), and wait for IGMP group membership reports. If there are other receivers connecting to the switch, they will respond to the queries before the Last Member Query Interval expires. If no reports are received after the response time of the last query expires, the querier will remove the port from the forwarding list of the corresponding multicast group.

That is, if there are other receivers connecting to the switch, the one that sent the leave message has to wait until the port ages out from the switch's forwarding list of the corresponding multicast group (the maximum waiting time is decided by the Member Port Aging Time).

With Fast Leave enabled on a VLAN, the switch will remove the (Multicast Group, Port, VLAN) entry from the multicast forwarding table before forwarding the leave message to the querier. This helps to reduce bandwidth waste since the switch no longer sends the corresponding multicast streams to the VLAN of the port as soon as the port receives a leave message from the VLAN.

You should only enable Fast Leave for a VLAN when there is a single receiver belonging to this VLAN on every port of the VLAN.

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

Step 7 ip igmp snooping vlan-config

vlan-id-list rport interface { fastEthernet port-list |

gigabitEthernet port-list | ten-gigabitEthernet port-list | port-channel lag-list}

(Optional) Specify the static router ports for the VLANs. Static router ports do not age.

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

port-list: The number or the list of the Ethernet ports that need to be configured as static router ports.

lag-list: The ID or the list of the LAGs that need to be configured as static router ports.

Step 8 ip igmp snooping vlan-config

vlan-id-list router-ports-forbidden interface { fastEthernet

port-list | gigabitEthernet port-list | ten-gigabitEthernet port-list | port-channel lag-list }

(Optional) Specify the ports to forbid them from being router ports in the VLANs.

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

port-list: The number or the list of the Ethernet port that need to be forbidden from being router ports.

lag-list: The ID or the list of the LAG that need to be forbidden from being router ports.

Step 9 ip igmp snooping vlan-config

vlan-id-list querier

(Optional) Enable the IGMP Snooping Querier for the VLAN. By default, it is disabled.

When enabled, the switch acts as an IGMP Snooping Querier for the hosts in this VLAN. A querier periodically sends a general query on the network to solicit membership information, and sends group-specific queries when it receives leave messages from hosts.

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

After enabling IGMP Snooping Querier feature, you need to specify the corresponding parameters including the Last Member Query Count, Last Member Query Interval, Maximum Response Time, Query Interval and General Query Source IP. Use the command below in global configuration mode to configure the parameters:

ip igmp snooping vlan-config vlan-id-list querier {max-response-time response-time | query-interval interval | general-query source-ip ip-addr | last-member-query-count num | last-member-query-interval interval }

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

response-time: Specify the host's maximum response time to general query messages. Valid values are from 1 to 25 seconds, and the default value is 10 seconds.

query-interval interval: Specify the interval between general query messages sent by the switch. Valid values are from 10 to 300 seconds, and the default value is 60 seconds.

ip-addr: Specify the source IP address of the general query messages sent by the switch. It should be a unicast address. By default, it is 192.168.0.1.

num: Specify the number of group-specific queries to be sent. With IGMP Snooping Querier enabled, when the switch receives an IGMP leave message, it obtains the address of the multicast group that the host wants to leave from the message. Then the switch sends out group-specific queries to this multicast group through the port receiving the leave message. If specified count of group-specific queries are sent and no report message is received, the switch will delete the multicast address from the multicast forwarding table. Valid values are from 1 to 5, and the default value is 2.

last-member-query-interval interval: Specify the interval between group-specific queries. Valid values are from 1 to 5 seconds, and the default value is 1 second.

Step 10 show ip igmp snooping vlan vlan-id

Show the basic IGMP Snooping configuration in the specified VLAN.

Step 11 end

Return to privileged EXEC mode.

Step 12 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable IGMP Snooping for VLAN 1, and configure the member port aging time as 300 seconds, the router port aging time as 320 seconds, and then enable Fast Leave and Report Suppression for the VLAN:

Switch#configure

Switch(config)#ip igmp snooping vlan-config 1

Switch(config)#ip igmp snooping vlan-config 1 mtime 300

Switch(config)#ip igmp snooping vlan-config 1 rtime 320

Switch(config)#ip igmp snooping vlan-config 1 immediate-leave

Switch(config)#ip igmp snooping vlan-config 1 report-suppression

Switch(config)#show ip igmp snooping vlan 1

Vlan Id: 1

Vlan IGMP Snooping Status: Enable

Fast Leave: Enable

Report Suppression: Enable

Router Time: 320

Member Time: 300

Querier: Disable

...

Switch(config)#end

Switch#copy running-config startup-config

The following example shows how to enable IGMP Snooping querier for VLAN 1, and configure the query interval as 100 seconds, the maximum response time as 15 seconds, the last member query interval as 2 seconds, the last member query count as 3, and the general query source IP as 192.168.0.5:

Switch#configure

Switch(config)#ip igmp snooping vlan-config 1 querier

Switch(config)#ip igmp snooping vlan-config 1 querier query-interval 100

Switch(config)#ip igmp snooping vlan-config 1 querier max-response-time 15

Switch(config)#ip igmp snooping vlan-config 1 querier last-member-query-interval 2

Switch(config)#ip igmp snooping vlan-config 1 querier last-member-query-count 3

Switch(config)#ip igmp snooping vlan-config 1 querier general-query source-ip192.168.0.5

Switch(config)#show ip igmp snooping vlan 1

Vlan Id: 1

...

Querier:

Maximum Response Time: 15

Query Interval: 100

Last Member Query Interval: 2

Last Member Query Count: 3

General Query Source IP: 192.168.0.5

...

Switch(config)#end

Switch#copy running-config startup-config

2.2.3 Configuring IGMP Snooping for Ports

Follow these steps to configure IGMP Snooping for ports:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 3 ip igmp snooping

Enable IGMP Snooping for the port. By default, it is enabled.

Step 4 ip igmp snooping immediate-leave

(Optional) Enable Fast Leave on the specified port.

Fast Leave can be enabled on a per-port basis or per-VLAN basis. When enabled on a per-port basis, the switch will remove the port from the corresponding multicast group of all VLANs before forwarding the leave message to the querier.

You should only use Fast Leave for a port when there is a single receiver connected to the port. For more details about Fast Leave, see 2.2.2 Configuring IGMP Snooping for VLANs.

Step 5 show ip igmp snooping interface [fastEthernet [ port-list] | gigabitEthernet [port-list] | ten-gigabitEthernet [port-list] | port-channel [port-channel-list] ] basic-config

Show the basic IGMP Snooping configuration on the specified port(s) or of all the ports.

Step 6 end

Return to privileged EXEC mode.

Step 7 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable IGMP Snooping and fast leave for port 1/0/1-3:

Switch#configure

Switch(config)#interface range gigabitEthernet 1/0/1-3

Switch(config-if-range)#ip igmp snooping

Switch(config-if-range)#ip igmp snooping immediate-leave

Switch(config-if-range)#show ip igmp snooping interface gigabitEthernet 1/0/1-3 basic-config

PortIGMP-SnoopingFast-Leave
Gi1/0/1enableenable
Gi1/0/2enableenable
Gi1/0/3enableenable

Switch(config-if-range)#end

Switch#copy running-config startup-config

2.2.4 Configuring Hosts to Statically Join a Group

Hosts or Layer 2 ports normally join multicast groups dynamically, but you can also configure hosts to statically join a group.

Follow these steps to configure hosts to statically join a group:

Step 1 configure

Enter global configuration mode.

Step 2 ip igmp snooping vlan-config vlan-id-list static ip interface {fastEthernet port-list| gigabitEthernet port-list | ten-gigabitEthernet port-list| port-channel lag-list}

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

ip: Specify the IP address of the multicast group that the hosts want to join.

port-list / lag-list: Specify the ports that are connected to the hosts. These ports will become static member ports of the group.

Step 3 show ip igmp snooping groups static

Show the static IGMP Snooping configuration.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure port 1/0/1-3 in VLAN 2 to statically join the multicast group 239.1.2.3:

Switch#configure

Switch(config)#ip igmp snooping vlan-config 2 static 239.1.2.3 interface gigabitEthernet 1/0/1-3

Switch(config)#show ip igmp snooping groups static

Multicast-ip VLAN-id Addr-type Switch-port Expire

239.1.2.3

2

static

Gi1/0/1-3

Switch(config)#end

Switch#copy running-config startup-config

2.2.5 Configuring IGMP Accounting and Authentication Features

TP-LINK Omada Pro S5500-24GP4F - Configuring IGMP Accounting and Authentication Features - 1

Note:

IGMP Accounting and Authentication is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface.

You can enable IGMP accounting and authentication according to your need. IGMP accounting is configured globally, and IGMP authentication can be enabled on a per-port basis.

To use these features, you need to set up a RADIUS server and configure the switch to use it.

Follow these steps to add the RADIUS server and enable IGMP accounting globally:

Step 1

configure

Enter global configuration mode.

Step 2 radius-server host ip-address [auth-port port-id] [acct-port port-id] [timeout time] [retransmit number] [nas-id nas-id] key { [0] string | 7 encrypted-string}

Add the RADIUS server and configure the related parameters as needed.

host ip-address: Enter the IP address of the server running the RADIUS protocol.

auth-port port-id: Specify the UDP destination port on the RADIUS server for authentication requests. The default setting is 1812.

acct-port port-id: Specify the UDP destination port on the RADIUS server for accounting requests. The default setting is 1813. Usually, it is used in the 802.1X feature.

timeout time: Specify the time interval that the switch waits for the server to reply before resending. The valid values are from 1 to 9 seconds and the default setting is 5 seconds.

retransmit number: Specify the number of times a request is resent to the server if the server does not respond. The valid values are from 1 to 3 and the default setting is 2.

nas-id nas-id: Specify the name of the NAS (Network Access Server) to be contained in RADIUS packets for identification. It ranges from 1 to 31 characters. The default value is the MAC address of the switch. Generally, the NAS indicates the switch itself.

key { [0] string | 7 encrypted-string }: Specify the shared key. 0 and 7 represent the encryption type. 0 indicates that an unencrypted key will follow. 7 indicates that a symmetric encrypted key with a fixed length will follow. By default, the encryption type is 0. string is the shared key for the switch and the server, which contains 31 characters at most. encrypted-string is a symmetric encrypted key with a fixed length, which you can copy from the configuration file of another switch. The key or encrypted-key you configure here will be displayed in the encrypted form.

Step 3 ip igmp snooping accounting

Enable IGMP accounting globally.

Step 4 show ip igmp snooping

Show the basic IGMP Snooping configuration.

Step 5 end

Return to privileged EXEC mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

Follow these steps to enable IGMP authentication for ports:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 3 ip igmp snooping authentication

Enable IGMP Snooping authentication for the port. By default, it is enabled.

Step 4 show ip igmp snooping interface [fastEthernet [ port-list] | gigabitEthernet [port-list] | ten-gigabitEthernet [port-list] | port-channel [port-channel-list] ] authentication

Show the basic IGMP Snooping configuration on the specified port(s) or on all ports.

Step 5 end

Return to privileged EXEC mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable IGMP accounting globally:

Switch#configure

Switch(config)#ip igmp snooping accounting

Switch(config)#show ip igmp snooping

...

Global Authentication Accounting: Enable

Enable Port: Gi1/0/1-28, Po1-14

Enable VLAN:

Switch(config)#end

Switch#copy running-config startup-config

The following example shows how to enable IGMP authentication on port 1/0/1-3:

Switch#configure

Switch(config)#interface range gigabitEthernet 1/0/1-3

Switch(config-if-range)#ip igmp snooping authentication

Switch(config-if-range)#show ip igmp snooping interface gigabitEthernet 1/0/1-3 authentication

PortIGMP-Authentication
Gi1/0/1enable
Gi1/0/2enable
Gi1/0/3enable

Switch(config)#end

Switch#copy running-config startup-config

3

MLD Snooping Configuration

To complete MLD Snooping configuration, follow these steps:

1) Enable MLD Snooping globally and configure the global parameters. 2) Configure MLD Snooping for VLANs. 3) Configure MLD Snooping for ports. 4) (Optional) Configure hosts to statically join a group.

TP-LINK Omada Pro S5500-24GP4F - MLD Snooping Configuration - 1

Note:

MLD Snooping takes effect only when it is enabled globally, in the corresponding VLAN and port at the same time.

3.1 Using the GUI

3.1.1 Configuring MLD Snooping Globally

Choose the menu L2 FEATURES > Multicast > MLD Snooping > Global Config to load the following page.

Figure 3-1 Configure MLD Snooping GloballyGlobal Config MLD Snooping: Enable Unknown Multicast Groups: Forward Discard Apply

Follow these steps to configure MLD Snooping globally:

1) In the Global Config section, enable MLD Snooping and configure the Unknown Multicast Groups feature globally.

MLD Snooping Enable or disable MLD snooping globally.

Unknown Multicast GroupsConfigure the way in which the switch processes data that are sent to unknown multicast groups as Forward or Discard. By default, it is Forward.
Unknown multicast groups are multicast groups whose destination multicast address is not in the multicast forwarding table of the switch.
Note: IGMP Snooping and MLD Snooping share the setting of Unknown Multicast Groups.

2) Click Apply.

3.1.2 Configuring MLD Snooping for VLANs

Before configuring MLD Snooping for VLANs, set up the VLANs that the router ports and the member ports are in. For details, please refer to Configuring 802.1Q VLAN.

The switch supports configuring MLD Snooping on a per-VLAN basis. After MLD Snooping is enabled globally, you also need to enable MLD Snooping and configure the corresponding parameters for the VLANs that the router ports and the member ports are in.

Choose the menu L2 FEATURES > Multicast > MLD Snooping > Global Config, and click in your desired VLAN entry in the MLD VLAN Config section to load the following page.

Figure 3-2 Configure MLD Snooping for VLANConfigure MLD Snooping for VLAN VLAN ID: 1 MLD Snooping Status: Enable Fast Leave: Enable Report Suppression: Enable Member Port Aging Time: 260 seconds (60-600) Router Port Aging Time: 300 seconds (60-600) Leave Time: 1 second (1-30) MLD Snooping Querier: Enable Static Router Ports UNIT1 LAGS Selec…

Follow these steps to configure MLD Snooping for a specific VLAN:

1) Enable MLD Snooping for the VLAN, and configure the corresponding parameters.

VLAN ID Displays the VLAN ID.

MLD Snooping

Status

Enable or disable MLD snooping for the VLAN.

Fast Leave: Enable or disable the Fast Leave feature for the VLAN.

Without Fast Leave, after a receiver sends an MLD done message (equivalent to an IGMP leave message) to leave a multicast group, the switch will forward the done message to the Layer 3 device (the querier).From the point of view of the querier, the port connecting to the switch is a member port of the corresponding multicast group. After receiving the done message from the switch, the querier will send out a configured number (Last Listener Query Count) of Multicast-Address-Specific Queries (MASQs) on that port with a configured interval (Last Listener Query Interval), and wait for MLD reports. If there are other receivers connecting to the switch, they will response to the MASQs before the Last Listener Query Interval expires. If no reports are received after the response time of the last query expires, the querier will remove the port from the forwarding list of the corresponding multicast group.That is, if there are other receivers connecting to the switch, the one sent done message have to wait until the port ages out from the switch's forwarding list of the corresponding multicast group (the maximum waiting time is decided by the Member Port Aging Time).With Fast Leave enabled on a VLAN, the switch will remove the (Multicast Group, Port, VLAN) entry from the multicast forwarding table before forwarding the done message to the querier. This helps to reduce bandwidth waste since the switch no longer sends the corresponding multicast streams to the VLAN of the port as soon as the port receives a done message from the VLAN.
Report SuppressionEnable or disable Report Suppression feature for the VLAN.When enabled, the switch will only forward the first MLD report message to layer 3 devices and suppress subsequent MLD report messages from the same multicast group during one query interval.This feature prevents duplicate report messages from being sent to the layer 3 devices.
Member Port Aging TimeSpecify the aging time of the member ports in the VLAN.Once the switch receives an MLD report message from a port, the switch adds this port to the member port list of the corresponding multicast group. Member ports that are learned in this way are called dynamic member ports.If the switch does not receive any MLD membership report message for a specific multicast group from a dynamic member port, it will no longer consider this port as a member port of this multicast group and delete it from the multicast forwarding table.
Router Port Aging TimeSpecify the aging time of the router ports in the VLAN.Once the switch receives an MLD general query message from a port, the switch adds this port to the router port list. Router ports that are learned in this way are called dynamic router ports.If the switch does not receive any MLD general query message from a dynamic router port within the router port aging time, the switch will no longer consider this port as a router port and delete it from the router port list.
Leave TimeSpecify the leave time for the VLAN. When the switch receives a leave message from a port to leave a multicast group, it will wait for a leave time before removing the port from the multicast group. During the period, if the switch receives any report messages from the port, the port will not be removed from the multicast group. Exceptions are as follows:If the member port ages out before the Leave Time ends and no report messages are received, the port will be removed from the multicast group once its Member Port Aging Time ends.The Leave Time mechanism will not take effect when Fast Leave takes effect.
MLD Snooping QuerierEnable or disable the MLD Snooping Querier feature for the VLAN. When enabled, the switch acts as an MLD Snooping Querier for the hosts in this VLAN. A querier periodically sends a general query on the network to solicit membership information, and sends MASQs when it receives done messages from hosts.
Query Interval Specify the interval between general query messages sent by the querier.
Maximum Response TimeWith MLD Snooping Querier enabled, specify the host's maximum response time to general query messages.
Last Listener Query IntervalWith MLD Snooping Querier enabled, when the switch receives an MLD leave message, the switch obtains the address of the multicast group that the host wants to leave from the message. Then the switch sends out Multicast-Address-Specific Queries (MASQs) to this multicast group through the port receiving the leave message. This parameter determines the interval between MASQs.
Last Listener Query CountWith MLD Snooping Querier enabled, specify the number of MASQs to be sent. If specified count of MASQs are sent and no report message is received, the switch will delete the multicast address from the multicast forwarding table.
General Query Source IPWith MLD Snooping Querier enabled, specify the source IP address of the general query messages sent by the querier. It should be a unicast address.
Dynamic Router PortsDisplays all the dynamic router ports in the multicast VLAN.
Static Router PortsSelect one or more ports to be the static router ports in the VLAN. All multicast data in this VLAN will be forwarded through the static router ports.Multicast streams and MLD packets to all groups in this VLAN will be forwarded through the static router ports. Multicast streams and MLD packets to the groups that have dynamic router ports will be also forwarded through the corresponding dynamic router ports.
Forbidden Router PortsSelect the ports to forbid them from being router ports in the VLAN.

2) Click Save.

3.1.3 Configuring MLD Snooping for Ports

Choose the menu L2 FEATURES > Multicast > MLD Snooping > Port Config to load the following page.

Figure 3-3 Configure MLD Snooping for PortsPort Config UNIT1 LAGS Port MLD Snooping Fast Leave LAG Gi1/0/1 Enabled Disabled --- Gi1/0/2 Enabled Disabled --- Gi1/0/3 Enabled Disabled --- Gi1/0/4 Enabled Disabled --- Gi1/0/5 Enabled Disabled --- Gi1/0/6 Enabled Disabled --- Gi1/0/7 Enabled Disabled --- Gi1/0/8 Enabled Disabled --- Gi1/0/9 Enab…

Follow these steps to configure MLD Snooping for ports:

1) Enable MLD Snooping for the port and enable Fast Leave if there is only one receiver connected to the port.

MLD Snooping: Enable or disable MLD Snooping on the port.

Fast Leave: Enable or disable Fast Leave on the port.

Fast Leave can be enabled on a per-port basis or per-VLAN basis. When enabled, the switch will remove this port from the forwarding list of the corresponding multicast group once the port receives a leave message, without verifying if there are other members of this multicast group.

You should only use this function when there is a single receiver present on the port. For more details about Fast Leave, see 3.1.2 Configuring MLD Snooping for VLANs.

LAG: Displays the LAG that the port belongs to.

2) Click Apply.

3.1.4 Configuring Hosts to Statically Join a Group

Hosts or Layer 2 ports normally join multicast groups dynamically, but you can also configure hosts to statically join a group.

Choose the menu L2 FEATURES > Multicast > MLD Snooping > Static Group Config and click + Add to load the following page.

Figure 3-4 Configure Hosts to Statically Join a GroupCreate Static Multicast Group Multicast IP: (Format: F730 1234.01) VLAN ID: (1-4094) Member Ports: UNIT1 LAGS Select All 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 41 43 45 47 49 51 53 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 42 44 46 48 50 52 54 Selected Unselected Not Av…

Follow these steps to configure hosts to statically join a group:

1) Specify the multicast IP address, VLAN ID. Select the ports to be the static member ports of the multicast group.

Multicast IP Specify the multicast group that the static member is in.

VLAN ID Specify the VLAN that the static member is in.

Member Ports Specify one or more ports to be the static member ports in the multicast group. Without aging, the static member ports receive all multicast data sent to the multicast group.

2) Click Create.

3.2 Using the CLI

3.2.1 Configuring MLD Snooping Globally

Follow these steps to configure MLD Snooping globally:

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 mld snooping

Enable MLD Snooping Globally.

Step 3 ipv6 mld snooping drop-unknown

(Optional) Configure the way how the switch processes multicast streams that are sent to unknown multicast groups as Discard. By default, it is Forward.

Unknown multicast groups are multicast groups that do not match any of the groups announced in earlier MLD membership reports, and thus cannot be found in the multicast forwarding table of the switch.

Note: IGMP Snooping and MLD Snooping share the setting of Unknown Multicast Groups.

Step 4 show ipv6 mld snooping

Show the basic IGMP Snooping configuration.

Step 5 end

Return to privileged EXEC mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable MLD Snooping globally, and the way how the switch processes multicast streams that are sent to unknown multicast groups as discard.

Switch#configure

Switch(config)#ipv6 mld snooping

Switch(config)#ipv6 mld snooping drop-unknown

Switch(config)#show ipv6 mld snooping

MLD Snooping: Enable

Unknown Multicast: Discard

...

Switch(config)#end

Switch#copy running-config startup-config

3.2.2 Configuring MLD Snooping for VLANs

Before configuring MLD Snooping for VLANs, set up the VLANs that the router ports and the member ports are in. For details, please refer to Configuring 802.1Q VLAN.

The switch supports configuring MLD Snooping on a per-VLAN basis. After MLD Snooping is enabled globally, you also need to enable MLD Snooping and configure the corresponding parameters for the VLANs that the router ports and the member ports are in.

Follow these steps to configure MLD Snooping for VLANs:

3.2.2 Configuring MLD Snooping for VLANs

Before configuring MLD Snooping for VLANs, set up the VLANs that the router ports and the member ports are in. For details, please refer to Configuring 802.1Q VLAN.

The switch supports configuring MLD Snooping on a per-VLAN basis. After MLD Snooping is enabled globally, you also need to enable MLD Snooping and configure the corresponding parameters for the VLANs that the router ports and the member ports are in.

Follow these steps to configure MLD Snooping for VLANs:

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 mld snooping vlan-config

vlan-id-list

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

Step 3 ipv6 mld snooping vlan-config

vlan-id-list rtime router-time

Specify the router port aging time for the VLANs.

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

router-time: Specify the aging time of the router ports in the specified VLANs. Valid values are from 60 to 600 seconds. By default, it is 300 seconds.

Once the switch receives an MLD general query message from a port, the switch adds this port to the router port list. Router ports that are learned in this way are called dynamic router ports.

If the switch does not receive any MLD general query message from a dynamic router port within the router port aging time, the switch will no longer consider this port as a router port and delete it from the router port list.

Step 4 ipv6 mld snooping vlan-config

vlan-id-list ltimeleave-time

Specify the router port aging time for the VLANs.

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

leave-time: Specify the leave time for the VLAN(s). Valid values are from 1 to 30 in seconds, and the default value is 1 second.

When the switch receives a leave message from a port to leave a multicast group, it will wait for a leave time before removing the port from the multicast group. During the period, if the switch receives any report messages from the port, the port will not be removed from the multicast group. Exceptions are as follows:

- If the member port ages out before the Leave Time ends and no report messages are received, the port will be removed from the multicast group once its Member Port Aging Time ends.

• The Leave Time mechanism will not take effect when Fast Leave takes effect.

A proper leave time value can avoid other hosts connecting to the same port of the switch being mistakenly removed from the multicast group when only some of them want to leave.

Step 5 ipv6 mld snooping vlan-config

vlan-id-list report-suppression

(Optional) Enable Report Suppression for the VLANs. By default, it is disabled.

When enabled, the switch will only forward the first MLD report message for each multicast group to the MLD querier and suppress subsequent MLD report messages for the same multicast group during one query interval. This feature prevents duplicate report messages from being sent to the MLD querier.

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

Step 6 ipv6 mld snooping vlan-config

vlan-id-list immediate-leave

(Optional) Enable Fast Leave for the VLANs. By default, it is disabled.

Without Fast Leave, after a receiver sends an MLD done message (equivalent to an IGMP leave message) to leave a multicast group, the switch will forward the done message to the Layer 3 device (the querier).

From the point of view of the querier, the port connecting to the switch is a member port of the corresponding multicast group. After receiving the done message from the switch, the querier will send out a configured number (Last Listener Query Count) of Multicast-Address-Specific Queries (MASQs) on that port with a configured interval (Last Listener Query Interval), and wait for MLD reports. If there are other receivers connecting to the switch, they will respond to the MASQs before the Last Listener Query Interval expires. If no reports are received after the response time of the last query expires, the querier will remove the port from the forwarding list of the corresponding multicast group.

That is, if there are other receivers connecting to the switch, the one that sent the done message has to wait until the port ages out from the switch's forwarding list of the corresponding multicast group (the maximum waiting time is decided by the Member Port Aging Time).

With Fast Leave enabled on a VLAN, the switch will remove the (Multicast Group, Port, VLAN) entry from the multicast forwarding table before forwarding the done message to the querier. This helps to reduce bandwidth waste since the switch no longer sends the corresponding multicast streams to the VLAN of the port as soon as the port receives a done message from the VLAN.

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

Step 7 ipv6 mld snooping vlan-config

vlan-id-list rport interface { fastEthernet port-list |

gigabitEthernet port-list | ten-gigabitEthernet port-list| port-channel lag-list}

(Optional) Specify the static router ports for the VLANs. Static router ports do not age.

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

port-list: The number or the list of the Ethernet port that need to be configured as static router ports.

lag-list: The ID or the list of the LAG that need to be configured as static router ports.

Step 8 ipv6 mld snooping vlan-config

vlan-id-list router-ports-forbidden interface { fastEthernet

port-list | gigabitEthernet port-list | ten-gigabitEthernet port-list | port-channel lag-list }

(Optional) Specify the ports to forbid them from being router ports in the VLANs.

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

port-list: The number or the list of the Ethernet port that need to be forbidden from being router ports.

lag-list: The ID or the list of the LAG that need to be forbidden from being router ports.

Step 9 ipv6 mld snooping vlan-config

vlan-id-list querier

(Optional) Enable MLD Snooping Querier for the VLAN. By default, it is disabled.

When enabled, the switch acts as an MLD Snooping Querier for the hosts in this VLAN. A querier periodically sends a general query on the network to solicit membership information, and sends group-specific queries when it receives done messages from hosts.

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

After enabling MLD Snooping Querier feature, you need to specify the corresponding parameters including the Last Member Query Count, Last Member Query Interval, Maximum Response Time, Query Interval and General Query Source IP. Use the command below in global configuration mode to configure the parameters:

ipv6 mld snooping vlan-config vlan-id-list querier { max-response-time response-time | query-interval interval | general-query source-ip ip-addr | last-listener-query-count num | last-listener-query-interval interval }

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

response-time: Specify the host's maximum response time to general query messages.

query-interval interval: Specify the interval between general query messages sent by the switch.

ip-addr: Specify the source IP address of the general query messages sent by the switch. It should be a unicast address.

num: Specify the number of group-specific queries to be sent. With MLD Snooping Querier enabled, when the switch receives a done message, it obtains the address of the multicast group that the host wants to leave from the message. Then the switch sends out MASQs to this multicast group through the port receiving the done message. If specified count of MASQs are sent and no report message is received, the switch will delete the multicast address from the multicast forwarding table.

last-listener-query-interval interval: Specify the interval between MASQs.

Step 10 show ipv6 mld snooping vlan

vlan-id

Show the basic MLD snooping configuration in the specified VLAN.

Step 11 end

Return to privileged EXEC mode.

Step 12 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable MLD Snooping for VLAN 1, and configure the member port aging time as 300 seconds, the router port aging time as 320 seconds, and then enable Fast Leave and Report Suppression for the VLAN:

Switch#configure

Switch(config)#ipv6 mld snooping vlan-config 1

Switch(config)#ipv6 mld snooping vlan-config 1 mtime 300

Switch(config)#ipv6 mld snooping vlan-config 1 rtime 320

Switch(config)#ipv6 mld snooping vlan-config 1 immediate-leave

Switch(config)#ipv6 mld snooping vlan-config 1 report-suppression

Switch(config)#show ipv6 mld snooping vlan 1

Vlan Id: 1

Vlan MLD Snooping Status: Enable

Fast Leave: Enable

Report Suppression: Enable

Router Time: Enable

Member Time: Enable

Querier: Disable

...

Switch(config)#end

Switch#copy running-config startup-config

The following example shows how to enable MLD Snooping querier for VLAN 1, and configure the query interval as 100 seconds, the maximum response time as 15 seconds, the last listener query interval as 2 seconds, the last listener query count as 3, and the general query source IP as fe80::123:

Switch#configure

Switch(config)#ipv6 mld snooping vlan-config 1 querier

Switch(config)#ipv6 mld snooping vlan-config 1 querier query-interval 100

Switch(config)#ipv6 mld snooping vlan-config 1 querier max-response-time 15

Switch(config)#ipv6 mld snooping vlan-config 1 querier last-listener-query-interval 2

Switch(config)#ipv6 mld snooping vlan-config 1 querier last-listener-query-count 3

Switch(config)#ipv6 mld snooping vlan-config 1 querier general-query source-ip fe80::123

Switch(config)#show ipv6 mld snooping vlan 1

Vlan Id: 1

...

Querier:

Enable

Maximum Response Time: 15

Query Interval: 100

Last Member Query Interval: 2

Last Member Query Count: 3

General Query Source IP: fe80::123

...

Switch(config)#end

Switch#copy running-config startup-config

3.2.3 Configuring MLD Snooping for Ports

Follow these steps to configure MLD Snooping for ports:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 3 ipv6 mld snooping

Enable MLD Snooping for the port. By default, it is enabled.

Step 4 ipv6 mld snooping immediate-leave

(Optional) Enable Fast Leave on the specified port.

Fast Leave can be enabled on a per-port basis or per-VLAN basis. When enabled on a per-port basis, the switch will remove the port from the corresponding multicast group of all VLANs before forwarding the done message to the querier.

You should only use Fast Leave for a port when there is a single receiver connected to the port. For more details about Fast Leave, see 3.2.2 Configuring MLD Snooping for VLANs.

Step 5 show ipv6 mld snooping interface [fastEthernet [ port-list] | gigabitEthernet [ port-list] | ten-gigabitEthernet [ port-list] | port-channel [port-channel-list]] basic-config

Show the basic MLD Snooping configuration on the specified port(s) or on all ports.

Step 6 end

Return to privileged EXEC mode.

Step 7 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable MLD Snooping and fast leave for ports 1/0/1-3:

Switch#configure

Switch(config)#interface range gigabitEthernet 1/0/1-3

Switch(config-if-range)#ipv6 mld snooping

Switch(config-if-range)#ipv6 mld snooping immediate-leave

Switch(config-if-range)#show ipv6 mld snooping interface gigabitEthernet 1/0/1-3 basic config

PortMLD-SnoopingFast-Leave
Gi1/0/1enableenable
Gi1/0/2enableenable
Gi1/0/3enableenable

Switch(config-if-range)#end

Switch#copy running-config startup-config

3.2.4 Configuring Hosts to Statically Join a Group

Hosts or Layer 2 ports normally join multicast groups dynamically, but you can also configure hosts to statically join a group.

Follow these steps to configure hosts to statically join a group:

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 mld snooping vlan-config

vlan-id-list static ip interface {fastEthernet port-list |

gigabitEthernet port-list | ten-gigabitEthernet port-list | port-channel lag-list

vlan-id-list: Specify the ID or the ID list of the VLAN(s).

ip: Specify the IP address of the multicast group that the hosts want to join.

port-list/ lag-list: Specify the ports that is connected to the hosts. These ports will become

static member ports of the group.

Step 3 show ipv6 mld snooping groups static

Show the static MLD Snooping configuration.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure port 1/0/1-3 in VLAN 2 to statically join the multicast group ff80::1234:1:

Switch#configure

Switch(config)#ipv6 mld snooping vlan-config 2 static ff80::1234:1 interface gigabitEthernet 1/0/1-3

Switch(config)#show ipv6 mld snooping groups static

Multicast-ipVLAN-idAddr-typeSwitch-port
----------------
ff80::1234:12staticGi1/0/1-3

Switch(config)#end

Switch#copy running-config startup-config

4 MVR Configuration

To complete MVR configuration, follow these steps:

1) Configure 802.1Q VLANs. 2) Configure MVR globally. 3) Add multicast groups to MVR. 4) Configure MVR for the ports. 5) (Optional) Statically add ports to MVR groups.

Configuration Guidelines

■ MVR does not support IGMPv3 messages. ■ Do not configure MVR on private VLAN ports, otherwise MVR cannot take effect. ■ MVR operates on the underlying mechanism of IGMP Snooping, but the two features operate independently of each other. Both protocols can be enabled on a port at the same time. When both are enabled, MVR listens to the report and leave messages only for the multicast groups configured in MVR. All other multicast groups are managed by IGMP Snooping.

4.1 Using the GUI

4.1.1 Configuring 802.1Q VLANs

Before configuring MVR, create an 802.1Q VLAN as the multicast VLAN. Add all source ports (uplink ports that receive multicast data from the router) to the multicast VLAN as tagged ports. Configure 802.1Q VLANs for the receiver ports (ports that are connecting to the hosts) according to network requirements. Note that receiver ports can only belong to one VLAN and cannot be added to the multicast VLAN. For details, refer to Configuring 802.1Q VLAN.

4.1.2 Configuring MVR Globally

Choose the menu L2 FEATURES > Multicast > MVR > MVR Config to load the following page.

Figure 4-1 Configure MVR GloballyMVR Config MVR: Enable MVR Mode: Compatible Dynamic Multicast VLAN ID: 1 (1-4094) Query Response Time: 5 tenths of a second (1-100) Maximum Multicast Groups: 4093 Current Multicast Groups: 0 Apply

Follow these steps to configure MVR globally:

1) Enable MVR globally and configure the global parameters.

MVR Enable or disable MVR globally.

MVR Mode Specify the MVR mode as compatible or dynamic.

Compatible: In Compatible mode, the MVR switch does not forward IGMP reports from the hosts to the IGMP router. This means the IGMP router cannot learn the multicast groups' membership information from the MVR switch. The IGMP router must be statically configured to transmit all the required multicast streams to the MVR switch.

Dynamic: In Dynamic mode, after receiving report or leave messages from the hosts, the MVR switch will forward them to the multicast router on the multicast VLAN (with appropriate translation of the VLAN ID). The multicast router can learn the multicast groups' membership information through the report and leave messages, and transmit the multicast streams according to the multicast forwarding table.

Multicast VLAN ID Specify the VLAN on which the multicast data will be received.

Query Response Time Specify the maximum time to wait for the IGMP membership report since the switch receives an IGMP leave message on a receiver port. After receiving an IGMP leave message from a receiver port, the switch will send out group-specific queries and wait for IGMP membership reports. If no IGMP membership reports are received before the Query Response Time expires, the switch will remove the port from the multicast group.

Maximum Displays the max number of multicast groups that MVR supports.

Multicast Groups

Current Multicast Displays the current number of the MVR groups.

Groups

2) Click Apply.

4.1.3 Adding Multicast Groups to MVR

You need to manually add multicast groups to the MVR. Choose the menu L2 FEATURES > Multicast > MVR > MVR Group Config and click + Add to load the following page.

Figure 4-2 Add Multicast Groups to MVRMVR Group IP MVR Group IP: (Format: 235.0.0.1) MVR Group Count: (1-256) Cancel Create

Follow these steps to add multicast groups to MVR:

1) Specify the IP address of the multicast groups.

MVR Group IP

Specify the start IP address of contiguous series of multicast groups to be added to the MVR. Multicast data sent to the address specified here will be sent to all source ports on the switch and all receiver ports that have requested to receive data from that multicast address.

MVR Group Count Specify the number of contiguous multicast IP group addresses.

2) Click Create.

Then the added multicast groups will appear in the MVR group table, as the following figure shows:

Figure 4-3 MVR Group TableMVR Group Table Index MVR Group IP Status Members Operation 1 239.1.2.3 Inactive 2 239.1.2.4 Inactive Total: 2

MVR Group IP Displays the IP address of multicast group.

StatusDisplays the status of the MVR group. In compatible mode, all the MVR groups are added manually, so the status is always active. In dynamic mode, there are two status:Inactive:The MVR group is added successfully, but the source port has not received any query messages from this multicast group.Active:The MVR group is added successfully and the source port has received query messages from this multicast group.
Member Displays the member ports in this MVR group.

4.1.4 Configuring MVR for the Port

Choose the menu L2 FEATURES > Multicast > MVR > Port Config to load the following page.

Figure 4-4 Configure MVR for the Port

Port Config
UNIT1
PortModeTypeStatusFast Leave
Gi1/0/1DisableNoneActive/InVLANDisable
Gi1/0/2DisableNoneInactive/InVLANDisable
Gi1/0/3DisableNoneInactive/InVLANDisable
Gi1/0/4DisableNoneInactive/InVLANDisable
Gi1/0/5DisableNoneInactive/InVLANDisable
Gi1/0/6DisableNoneInactive/InVLANDisable
Gi1/0/7DisableNoneInactive/InVLANDisable
Gi1/0/8DisableNoneInactive/InVLANDisable
Gi1/0/9DisableNoneInactive/InVLANDisable
Gi1/0/10DisableNoneInactive/InVLANDisable
Total: 54

Follow these steps to add multicast groups to MVR:

1) Select one or more ports to configure. 2) Enable MVR, and configure the port type and Fast Leave feature for the port.

Mode: Enable or disable MVR for the selected ports.

Type: Configure the port type.

None: The port is a non-MVR port. If you attempt to configure a non-MVR port with MVR characteristics, the operation will be unsuccessful.

Source: Configure the uplink ports that receive and send multicast data on the multicast VLAN as source ports. Source ports should belong to the multicast VLAN. In compatible mode, source ports will be automatically added to all multicast groups, while in dynamic mode, you need to manually add them to the corresponding multicast groups.

Receiver: Configure the ports that are connecting to the hosts as receiver ports. A receiver port can only belong to one VLAN, and cannot belong to the multicast VLAN. In both modes, the switch will add or remove the receiver ports to the corresponding multicast groups by snooping the report and leave messages from the hosts.

Status: Displays the port's status.

Active/InVLAN: The port is physically up and in one or more VLANs.

Active/NotInVLAN: The port is physically up and not in any VLAN.

Inactive/InVLAN: The port is physically down and in one or more VLANs.

Inactive/NotInVLAN: The port is physically down and not in any VLAN.

Fast Leave

Enable or disable Fast Leave on this port. When enabled, the receiver port will be removed from the multicast group when an IGMP leave message is received on this port, without verifying if there are other members of this multicast group.

This function should only be enabled on receiver ports to which a single receiver device is connected.

3) Click Apply.

4.1.5 (Optional) Adding Ports to MVR Groups Statically

You can add only receiver ports to MVR groups statically. The switch adds or removes receiver ports to the corresponding multicast groups by snooping the report and leave messages from the hosts. You can also statically add a receiver port to an MVR group.

Choose the menu L2 FEATURES > Multicast > MVR > Static Group Members, and click in your desired MVR group entry to load the following page.

Figure 4-5 Configure Hosts to Statically Join an MVR groupStatic Group Member MVR Group IP: 235.0.0.1 Static Member Ports: UNIT1 Select All 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 41 43 45 47 48 51 53 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 42 44 46 48 50 52 54 Selected Unselected Not Available Cancel Save

Follow these steps to statically add ports to an MVR group:

1) Select the ports to add them to the MVR group. 2) Click Save.

4.2 Using the CLI

4.2.1 Configuring 802.1Q VLANs

Before configuring MVR, create an 802.1Q VLAN as the multicast VLAN. Add the all source ports to the multicast VLAN as tagged ports. Configure 802.1Q VLANs for the receiver ports according to network requirements. Note that receiver ports can only belong to one VLAN and cannot be added to the multicast VLAN. For details, refer to Configuring 802.1Q VLAN.

4.2.2 Configuring MVR Globally

Follow these steps to configure MVR globally:

Step 1 configure

Enter global configuration mode.

Step 2 mvr

Enable MVR Globally.

Step 3 mvr mode { compatible | dynamic }

Configure the MVR mode as compatible or dynamic.

compatible: In this mode, the switch does not forward report or leave messages from the hosts to the IGMP querier. So the IGMP querier cannot learn the multicast groups membership information from the switch. You have to statically configure the IGMP querier to transmit all the required multicast streams to the switch via the multicast VLAN.

dynamic: In this mode, after receiving report or leave messages from the hosts, the switch will forward them to the IGMP querier via the multicast VLAN (with appropriate translation of the VLAN ID). So the IGMP querier can learn the multicast groups membership information through the report and leave messages, and transmit the multicast streams to the switch via the multicast VLAN according to the multicast forwarding table.

Step 4 mvr vlan

vlan-id

Specify the multicast VLAN.

vlan-id: Specify the ID of the multicast VLAN. Valid values are from 1 to 4094.

Step 5 mvr querytime

time

Specify the maximum time to wait for IGMP report on a receiver port before removing the port from multicast group membership.

time: Specify the maximum response time. Valid values are from 1 to 100 tenths of a second, and the default value is 5 tenths of a second.

Step 6 mvr group ip-addr count

Add multicast groups to the MVR.

ip-addr: Specify the start IP address of the contiguous series of multicast groups.

count: Specify the number of the multicast groups to be added to the MVR. The range is 1 to 256.

Step 7 show mvr

Show the global MVR configuration.

show mvr members

Show the existing MVR groups.

Step 8 end

Return to privileged EXEC mode.

Step 9 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable MVR globally, and configure the MVR mode as compatible, the multicast VLAN as VLAN 2 and the query response time as 5 tenths of a second. Then add 239.1.2.3-239.1.2.5 to MVR group.

Switch#configure

Switch(config)#mvr

Switch(config)#mvr mode compatible

Switch(config)#mvr vlan 2

Switch(config)#mvr querytime 5

Switch(config)#mvr group 239.1.2.3 3

Switch(config)#show mvr

MVR :Enable

MVR Multicast Vlan :2

MVR Max Multicast Groups :4093

MVR Current Multicast Groups :3

MVR Global Query Response Time :5 (tenths of sec)

MVR Mode Type :Compatible

Switch(config)#show mvr members

MVR Group IP status Members

239.1.2.3active
239.1.2.4active
239.1.2.5active

Switch(config)#end

Switch#copy running-config startup-config

4.2.3 Configuring MVR for the Ports

Follow these steps to configure MVR for the ports:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 mvr

Enable MVR for the port.

Step 4 mvr type { source | receiver }

Configure the MVR port type as receiver or source. By default, the port is a non-MVR port. If you attempt to configure a non-MVR port with MVR characteristics, the operation fails.

source: Configure the uplink ports that receive and send multicast data on the multicast VLAN as source ports. Source ports should belong to the multicast VLAN.

receiver: Configure the ports that are connecting to the hosts as receiver ports. A receiver port can only belong to one VLAN, and cannot belong to the multicast VLAN.

Step 5 mvr immediate

(Optional) Enable the Fast Leave feature of MVR for the port. Only receiver ports support Fast Leave. Before enabling Fast Leave for a port, make sure there is only a single receiver device connecting to the port.

Step 6 mvr vlan vlan-id group ip-addr

(Optional) Statically add the port to an MVR group. Then the port can receive multicast traffic sent to the IP multicast address via the multicast VLAN.

This command applies to only receiver ports. The switch adds or removes the receiver ports to the corresponding multicast groups by snooping the report and leave messages from the hosts. You can also statically add a receiver port to an MVR group.

vlan-id: Enter the multicast VLAN ID.

ip-addr: Specify the IP address of the multicast group.

Step 7 show mvr interface {fastEthernet [port-list] | gigabitEthernet [port-list] | ten-gigabitEthernet [port-list]}

Show the MVR configuration of the specified interface(s).

show mvr members

Show the membership information of all MVR groups.

Step 8 end

Return to privileged EXEC mode.

Step 9 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure port 1/0/7 as source port, and port 1/0/1-3 as receiver ports. Then statically add port 1/0/1-3 to group 239.1.2.3 and enable MVR Fast Leave for these ports. The multicast VLAN is VLAN 2.

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/7

Switch(config-if)#mvr

Switch(config-if)#mvr type source

Switch(config-if)#exit

Switch(config)#interface range gigabitEthernet 1/0/1-3

Switch(config-if-range)#mvr

Switch(config-if-range)#mvr type receiver

Switch(config-if-range)#mvr immediate

Switch(config-if-range)#mvr vlan 2 group 239.1.2.3

Switch(config-if-range)#show mvr interface gigabitEthernet 1/0/1-3,1/0/7

PortModeTypeStatusImmediate
----------------------------------------

Gi1/0/1 Enable Receiver INACTIVE/InVLAN Enable

Gi1/0/2 Enable Receiver INACTIVE/InVLAN Enable

Gi1/0/3 Enable Receiver INACTIVE/InVLAN Enable

Gi1/0/7 Enable Source INACTIVE/InVLAN Disable

Switch(config-if-range)#show mvr members

MVR Group IP status Members


239.1.2.3

active

Gi1/0/1-3,

1/0/7

Switch(config)#end

Switch#copy running-config startup-config

5 Multicast Filtering Configuration

To complete multicast filtering configuration, follow these steps:

1) Create the IGMP profile or MLD profile. 2) Configure multicast groups a port can join and the overflow action.

5.1 Using the GUI

5.1.1 Creating the Multicast Profile

You can create multicast profiles for both IPv4 and IPv6 network. With multicast profile, the switch can define a blacklist or whitelist of multicast groups so as to filter multicast sources.

The process for creating multicast profiles for IPv4 and IPv6 are similar. The following introductions take creating an IPv4 profile as an example.

Choose the menu L2 FEATURES > Multicast > Multicast Filtering > IPv4 Profile, and click

+ Add to load the following page.

TP-LINK Omada Pro S5500-24GP4F - Creating the Multicast Profile - 1

Note:

To create a multicast profile for IPv6, choose the menu L2 FEATURES > Multicast > Multicast Filtering > IPv6 Profile.

Figure 5-1 Create IPv4 ProfileGeneral Config Profile ID: (1-999) Mode: Permit Deny IP-Range Index Start IP Address End IP Address Operation No entries in this table Total: 0 Bind Ports UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 37 39 41 43 45 47 49 51 53 38 40 42…

Follow these steps to create a profile.

1) In the General Config section, specify the Profile ID and Mode.

Profile ID: Enter a profile ID between 1 and 999.

Mode: Configure the filtering mode. There are two filtering modes:

Permit: Acts as a whitelist and only allows specific member ports to join specified multicast groups.

Deny: Acts as a blacklist and prevents specific member ports from joining specific multicast groups.

2) In the IP-Range section, click + Add to load the following page. Configure the start IP address and end IP address of the multicast groups to be filtered, and click Create.

Figure 5-2 Configure Multicast Groups to Be FilteredIP-Range Start IP Address: (Format: 235.0.0.1) End IP Address: (Format: 235.0.0.1) Cancel Create

3) In the Bind Ports section, select your desired ports to be bound with the profile. 4) Click Save.

5.1.2 Configure Multicast Filtering for Ports

You can modify the mapping relation between ports and profiles in batches, and configure the number of multicast groups a port can join and the overflow action.

The process for configuring multicast filtering for ports in IPv4 and IPv6 are similar. The following introductions take configuring multicast filtering for ports in IPv4 as an example.

Choose the menu L2 FEATURES > Multicast > Multicast Filtering > IPv4 Port Config to load the following page.

TP-LINK Omada Pro S5500-24GP4F - Configure Multicast Filtering for Ports - 1

Note:

For IPv6, choose the menu L2 FEATURES > Multicast > Multicast Filtering > IPv6 Port Config.

Figure 5-3 Configure Multicast Filtering for Ports

Port Config
UNIT1LAGS
PortProfile IDMaximum GroupsOverflow ActionLAGOperation
Gi1/0/14093Drop-Clear Profile
Gi1/0/24093Drop-Clear Profile
Gi1/0/34093Drop-Clear Profile
Gi1/0/44093Drop-Clear Profile
Gi1/0/54093Drop-Clear Profile
Gi1/0/64093Drop-Clear Profile
Gi1/0/74093Drop-Clear Profile
Gi1/0/84093Drop-Clear Profile
Gi1/0/94093Drop-Clear Profile
Gi1/0/104093Drop-Clear Profile
Total: 54

Follow these steps to bind the profile to ports and configure the corresponding parameters for the ports:

1) Select one or more ports to configure. 2) Specify the profile to be bound, and configure the maximum groups the port can join and the overflow action.

Profile IDSpecify the ID of an existing profile to bind the profile to the selected ports. One port can only be bound to one profile.
Maximum GroupsEnter the number of multicast groups the port can join. Valid values are from 0 to 4093.
Overflow ActionSelect the action the switch will take with the new multicast member groups when the number of multicast groups the port hasjoined exceeds the maximum.Drop: Drop all subsequent membership report messages to prevent the port joining a new multicast group.Replace: Replace the existing multicast group that has the lowest multicast MAC address with the new multicast group.

LAG Displays the LAG that the port belongs to.

3) Click Apply.

5.2 Using the CLI

5.2.1 Creating the Multicast Profile

You can create multicast profiles for both IPv4 and IPv6 network. With multicast profile, the switch can define a blacklist or whitelist of multicast groups so as to filter multicast sources.

Creating IGMP Profile (Multicast Profile for IPv4)

Step 1 configure

Enter global configuration mode.

Step 2 ip igmp profile

id

Create a new profile and enter profile configuration mode.

Step 3 Permit

Configure the profile's filtering mode as permit. Then the profile acts as a whitelist and only allows specific member ports to join specified multicast groups.

deny

Configure the profile's filtering mode as deny. Then the profile acts as a blacklist and prevents specific member ports from joining specific multicast groups.

Step 4 range start-ip end-ip

Configure the range of multicast IP addresses to be filtered.

start-ip / end-ip: Specify the start IP address and end IP address of the IP range.

Step 5 show ip igmp profile [ id]

Show the detailed IGMP profile configuration.

Step 6 end

Return to privileged EXEC mode.

Step 7 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure Profile 1 so that the switch filters multicast streams sent to 226.0.0.5-226.0.0.10:

Switch#configure

Switch(config)#ip igmp snooping

Switch(config)#ip igmp profile 1

Switch(config-igmp-profile)#deny

Switch(config-igmp-profile)#range 226.0.0.5 226.0.0.10

Switch(config-igmp-profile)#show ip igmp profile

IGMP Profile 1

deny

range 226.0.0.5 226.0.0.10

Switch(config)#end

Switch#copy running-config startup-config

Creating MLD Profile (Multicast Profile for IPv6)

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 mld profile id

Create a new profile and enter profile configuration mode.

Step 3 Permit

Configure the profile's filtering mode as permit. It is similar to a whitelist, indicating that the switch only allows specific member ports to join specific multicast groups.

deny

Configure the profile's filtering mode as deny. It is similar to a blacklist, indicating that the switch disallows specific member ports to join specific multicast groups.

Step 4 range start-ip end-ip

Configure the range of multicast IP addresses to be filtered.

start-ip / end-ip: Specify the start IP address and end IP address of the IP range.

Step 5 show ipv6 mld profile [ id]

Show the detailed MLD profile configuration.

Step 6 end

Return to privileged EXEC mode.

Step 7 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure Profile 1 so that the switch filters multicast streams sent to ff01::1234:5-ff01::1234:8:

Switch#configure

Switch(config)#ipv6 mld snooping

Switch(config)#ipv6 mld profile 1

Switch(config-mld-profile)#deny

Switch(config-mld-profile)#range ff01::1234:5 ff01::1234:8

Switch(config-mld-profile)#show ipv6 mld profile

MLD Profile 1

deny

range ff01::1234:5 ff01::1234:8

Switch(config)#end

Switch#copy running-config startup-config

5.2.2 Binding the Profile to Ports

You can bind the created IGMP profile or MLD profile to ports, and configure the number of multicast groups a port can join and the overflow action.

Binding the IGMP Profile to Ports

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 3 ip igmp filter profile-id

Bind the IGMP profile to the specified ports.

profile-id: Specify the ID of the profile to be bound. It should be an existing profile.

Step 4 ip igmp snooping max-groups maxgroup

Configure the maximum number of multicast groups the port can join.

maxgroup: Specify the maximum number of multicast groups the port can join. The range is 0 to 4093.

Step 5 ip igmp snooping max-groups action {drop | replace}

Specify the action towards the new multicast group when the number of multicast groups the port joined exceeds the limit.

drop: Drop all subsequent membership report messages, and the port join no more new multicast groups.

replace: Replace the existing multicast group owning the lowest multicast MAC address with the new multicast group.

Step 6 show ip igmp profile [ id]

Show the detailed IGMP profile configurations.

show ip igmp snooping interface [fastEthernet [port-list] | gigabitEthernet [port-list] | ten-gigabitEthernet [port-list] | port-channel [port-channel-list] ] max-groups

Show the multicast group limitation on the specified port(s) or of all the ports.

Step 7 end

Return to privileged EXEC mode.

Step 8 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to bind the existing Profile 1 to port 1/0/2, and specify the maximum number of multicast groups that port 1/0/2 can join as 50 and the Overflow Action as Drop:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)#ip igmp snooping

Switch(config-if)#ip igmp filter 1

Switch(config-if)#ip igmp snooping max-groups 50

Switch(config-if)#ip igmp snooping max-groups action drop

Switch(config-if)#show ip igmp profile

IGMP Profile 1

...

Binding Port(s)

Gi1/0/2

Switch(config-if)#show ip igmp snooping interface gigabitEthernet 1/0/2 max-groups

PortMax-GroupsOverflow-Action
Gi1/0/250Drop

Switch(config)#end

Switch#copy running-config startup-config

Binding the MLD Profile to Ports

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 3 ipv6 mld filter profile-id

Bind the MLD profile to the specified ports.

profile-id: Specify the ID of the profile to be bound. It should be an existing profile.

Step 4 ipv6 mld snooping max-groups

maxgroup

Configure the maximum number of multicast groups the port can join.

maxgroup: Specify the maximum number of multicast groups the port can join. The range is 0 to 4093.

Step 5 ipv6 mld snooping max-groups action {drop | replace}

Specify the action towards the new multicast group when the number of multicast groups the port joined exceeds max group.

drop: Drop all subsequent membership report messages, and the port join no more new multicast groups.

replace: Replace the existing multicast group owning the lowest multicast MAC address with the new multicast group.

Step 6 show ipv6 mld profile [ id]

Show the detailed MLD profile configuration.

show ipv6 mld snooping interface [fastEthernet [port-list] | gigabitEthernet [port-list] | ten-gigabitEthernet [port-list] | port-channel [port-channel-list]] max-groups

Show the multicast group limitation on the specified port(s) or of all the ports.

Step 7 end

Return to privileged EXEC mode.

Step 8 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to bind the existing Profile 1 to port 1/0/2, and specify the maximum number of multicast groups that port 1/0/2 can join as 50 and the Overflow Action as Drop:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)#ipv6 mld snooping

Switch(config-if)#ipv6 mld filter 1

Switch(config-if)#ipv6 mld snooping max-groups 50

Switch(config-if)#ipv6 mld snooping max-groups action drop

Switch(config-if)#show ipv6 mld profile

MLD Profile 1

...

Binding Port(s)

Gi1/0/2

Switch(config-if)#show ipv6 mld snooping interface gigabitEthernet 1/0/2 max-groups

PortMax-GroupsOverflow-Action
Gi1/0/250Drop

Switch(config)#end

Switch#copy running-config startup-config

6 Viewing Multicast Snooping Information

You can view the following multicast snooping information:

■ View IPv4 multicast table. ■ View IPv4 multicast statistics on each port. ■ View IPv6 multicast table. ■ View IPv6 multicast statistics on each port.

6.1 Using the GUI

6.1.1 Viewing IPv4 Multicast Table

Choose the menu L2 FEATURES > Multicast > Multicast Info > IPv4 Multicast Table to load the following page:

Figure 6-1 IPv4 Multicast Table

Multicast IP Address Table
AllRefresh
IndexMulticast IPVLAN IDSourceTypeForward Ports
1235.0.0.11MVRDynamic
2235.0.0.21MVRDynamic

The multicast IP address table shows all valid Multicast IP-VLAN-Port entries:

Multicast IP Displays the multicast IP address.

VLAN ID Displays the ID of the VLAN the multicast group belongs to.

Source Displays the source of the multicast entry.

IGMP Snooping: The multicast entry is learned by IGMP Snooping.

MVR: The multicast entry is learned by MVR.

Type Displays how the multicast entry is generated.

Dynamic: The entry is dynamically learned. All the member ports are dynamically added to the multicast group.

Static: The entry is manually added. All the member ports are manually added to the multicast group.

Mix: The entry is dynamically learned (manually learned), and some of the member ports are manually added (dynamically added) to the multicast group.

Forward Ports

Displays all ports in the multicast group, including router ports and member ports.

6.1.2 Viewing IPv4 Multicast Statistics on Each Port

Choose the menu L2 FEATURES > Multicast > Multicast Info > IPv4 Multicast Statistics to load the following page:

Figure 6-2 IPv4 Multicast StatisticsAuto Refresh Auto Refresh: ✓ Refresh Interval: 300 seconds (3-300) Apply Port Statistics UNIT1 LAGS Refresh ID Port Query Packets Report Packets Report Packets Leave Packets Error Packets 1 Gi1/0/1 0 0 0 0 0 0 2 Gi1/0/2 0 0 0 0 0 0 3 Gi1/0/3 0 0 0 0 0 0 4 Gi1/0/4 0 0 0 0 0 0 5 Gi1/0/5 0 0 0 0 0 0 6…

Follow these steps to view IPv4 multicast statistics on each port:

1) To get the real-time multicast statistics, enable Auto Refresh, or click Refresh.

Auto Refresh

With this option enabled, the switch will automatically refresh the traffic summary.

Refresh Interval After Auto Refresh is enabled, specify the time interval for the switch to refresh the traffic summary.

2) In the Port Statistics section, view IPv4 multicast statistics on each port.

Query Packets Displays the number of query packets received by the port.

Report Packets Displays the number of IGMPv1 report packets received by the port. (v1)

Report Packets Displays the number of IGMPv2 report packets received by the port. (v2)

Report Packets Displays the number of IGMPv3 report packets received by the port. (v3)

Leave Packets Displays the number of leave packets received by the port.

Error Packets Displays the number of error packets received by the port.

6.1.3 Viewing IPv6 Multicast Table

Choose the menu L2 FEATURES > Multicast > Multicast Info > IPv6 Multicast Table to load the following page:

Figure 6-3 IPv6 Multicast TableMulticast IP Address Table Index Multicast IP VLAN ID Source Type Forward Ports No entries in this table. Total: 0

The multicast IP address table shows all valid Multicast IP-VLAN-Port entries:

Multicast IP Displays the multicast IP address.

VLAN ID Displays the ID of the VLAN the multicast group belongs to.

Source Displays the source of the multicast entry.

MLD Snooping: The multicast entry is learned by MLD Snooping.

Type Displays how the multicast entry is generated.

Dynamic: The entry is dynamically learned. All the member ports are dynamically added to the multicast group.

Static: The entry is manually added. All the member ports are manually added to the multicast group.

Mix: The entry is dynamically learned (manually learned), and some of the member ports are manually added (dynamically added) to the multicast group.

Forward Port: All ports in the multicast group, including router ports and member ports.

6.1.4 Viewing IPv6 Multicast Statistics on Each Port

Choose the menu L2 FEATURES > Multicast > Multicast Info > IPv6 Multicast Statistics to load the following page:

Figure 6-4 IPv6 Multicast StatisticsAuto Refresh Auto Refresh: ✓ Refresh Interval: 300 seconds (3-300) Apply Port Statistics UNIT1 LAGS Refresh ID Port Query Packets Report Packets (v1) Report Packets (v2) Done Packets Error Packets 1 Gi1/0/1 0 0 0 0 0 2 Gi1/0/2 0 0 0 0 0 3 Gi1/0/3 0 0 0 0 0 4 Gi1/0/4 0 0 0 0 0 5 Gi1/0/5 0 0 0 0 0 6 G…

Follow these steps to view IPv6 multicast statistics on each port:

1) To get the real-time IPv6 multicast statistics, enable Auto Refresh, or click Refresh.

Auto Refresh

With this option enabled, the switch will automatically refresh the traffic summary.

Refresh IntervalAfter Auto Refresh is enabled, specify the time interval for the switch to refresh the traffic summary.
2) In the Port Statistics section, view IPv6 multicast statistics on each port.
Query Packets Displays the number of quey packets received by the port.
Report Packets (v1)Displays the number of MLDv1 packets received by the port.
Report Packets (v2)Displays the number of MLDv2 packets received by the port.
Done Packets Displays the number of done packets received by the port.
Error Packets Displays the number of error packets received by the port.

6.2 Using the CLI

6.2.1 Viewing IPv4 Multicast Snooping Information

show ip igmp snooping groups [vlan vlan-id] [count | dynamic | dynamic count | static | static count]

Displays information of specific multicast group in all VLANs or in the specific VLAN.

count: Displays the number of multicast groups.

dynamic: Displays information of all dynamic multicast groups.

dynamic count: Displays the number of dynamic multicast groups.

static: Displays information of all static multicast groups.

static count: Displays the number of static multicast groups.

show ip igmp snooping interface [fastEthernet [port-list] | gigabitEthernet [port-list] | ten-gigabitEthernet [port-list] ] packet-stat

Displays the packet statistics on specified ports or all ports.

clear ip igmp snooping statistics

Clear all statistics of all IGMP packets.

6.2.2 Viewing IPv6 Multicast Snooping Configurations

show ipv6 mld snooping groups [vlan vlan-id] [count | dynamic | dynamic count | static | static count ]

Displays information of specific multicast group in all VLANs or in the specific VLAN.

count displays the number of multicast groups.

dynamic displays information of all dynamic multicast groups.

dynamic count displays the number of dynamic multicast groups.

static displays information of all static multicast groups.

static count displays the number of static multicast groups.

show ipv6 mld snooping interface [fastEthernet [port-list] | gigabitEthernet [port-list] | ten-gigabitEthernet [port-list] ] packet-stat

Displays the packet statistics on specified ports or all ports.

clear ipv6 mld snooping statistics

Clear all statistics of all MLD packets.

7 PIM Configuration

PIM (Protocol Independent Multicast) uses unicast routing information to provide multicast forwarding in a L3 network. PIM works in dense mode.

You must enable IP multicast routing. Then the software can forward multicast packets, and the switch can populate its multicast routing table.

7.1 Using the GUI

7.1.1 Configuring Multicast Routing Globally

Choose the menu L3 FEATURES> Multicast Routing> Global Config> Global Config to load the following page.

Figure 7-1 Configuring Multicast Routing GloballyMulticast Global Config Multicast Routing: Enable Protocol Mode: Disable Protocol State: None / Non-Operational Table Maximum Entry Count: 1024 Table Entry Count: 0 Apply

Follow these steps to configure Multicast Routing globally.

1) In the Multicast Global Config section, enable Multicast Routing. Then specify the corresponding parameters.

Multicast RoutingChoose to enable or disable the Multicast Routing function, default is Disable.
Protocol ModeSelect PIM DM or PIM SM from the radio button to set the administrative status in the router. The default is Disable.
Protocol StateThe multicast routing protocol presently activated and operational state of the multicast forwarding module.
Table Maximum Entry CountThe maximum number of entries in the IP Multicast routing table.
Table Entry CountThe number of multicast route entries currently present in the Multicast route table.

2) Click Apply.

7.1.2 Viewing Mroute Information

Choose the menu L3 FEATURES > Multicast Routing > Global Config > Mroute Table to load the following page.

Figure 7-2 Mroute TableMroute Table All Refresh Group Source Incoming Uptime Expires RPF Protocol Flags Operation No entries in this table. Total: 0

In the Mroute Table section, you can view the desired mroute information through different search options.

Search Option: Here you can set the search options for the mroute table.

All: Select All to display all entries.

Group: Select Group and enter the group of the desired entry.

Source: Select Source and enter the source of the desired entry.

Group: The destination group IP address.

Source: The IP address of the multicast packet source to be combined with the Group IP to fully identify a single route whose Mroute table entry.

Incoming Interface: The incoming interface on which multicast packets for this source/group arrive.

Uptime: The time in seconds since the entry was created.

Expires: The time in seconds before this entry will age out and be removed from the table.

RPF Neighbor: The IP address of the Reverse Path Forwarding neighbor.

Protocol: The multicast routing protocol which created this entry. The possibilities are PIM-DM and PIM-SM.

Flags: The value displayed in this field is valid if the multicast routing protocol running is PIM-SM. The possible values are RPT or SPT. For other protocols an "----" is displayed.

Outgoing Interface The list of outgoing interfaces on which multicast packets for this source/group are forwarded.

7.1.3 Configuring PIM DM Interface

Choose the menu L3 FEATURES> Multicast Routing> PIM DM> PIM DM Interface to load the following page.

Figure 7-3 Configuring PIM DM InterfacePIM DM Interface Config Interface Status Hello Interval DR Priority IP Address Neighbor Count DR Address VLAN1 Disable 30 1 192.168.0.1 0 --- Total: 1

In dense mode, a PIM DM router assumes that all other routers forward multicast packets for a group. If a PIM DM device receives a multicast packet and has no directly connected members or PIM neighbors present, a prune message is sent back to the source to stop unwanted multicast traffic.

Follow these steps to configure the L3 interfaces as PIM DM mode:

1) In the PIM DM Interface Config section, select the desired PIM DM interface entry to modify, then specify the corresponding parameters.

Interface The interface for which data is to be displayed or configured. You must have configured at least one router interface before configuring or displaying data for a PIM-DM interface.
StatusSelect enable or disable from the pull-down list to set the administrative status of PIM DM for the selected interface. The default is disable.
Hello IntervalSpecify the rate (time in seconds) at which PIM hello messages are transmitted from the selected interface. The valid value ranges from 1 to 18725 and the default is 30 seconds.
DR PrioritySpecify the DR priority for the selected interface. The valid value range from 0 to 2147483647. The default value is 1.
IP Address The IP address of this interface.
Neighbor Count The neighbor numbers of this interface.
DR Address The designated router on the selected PIM interface.

TP-LINK Omada Pro S5500-24GP4F - Configuring PIM DM Interface - 2

Note:

- You must have enabled Multicast Routing and Protocol Mode before configuring interface status.

2) Click Apply.

7.1.4 Viewing PIM DM Neighbor

Choose the menu L3 FEATURES> Multicast Routing> PIM DM> PIM DM Neighbor to load the following page.

Figure 7-4 Viewing PIM DM NeighborPIM DM Neighbor All Refresh Interface Neighbor UpTime Expires No entries in this table. Total: 0

PIM DM neighbor is automatically learned by sending and receiving Hello Packets when PIM DM is enabled.

In the PIM DM Neighbor section, you can view all the PIM DM neighbors.

Search Option Here you can set the search options for the PIM DM neighbor table.

ALL: Displays all entries.

Neighbor: Select Neighbor and enter the neighbor address of your desired entry.

Interface: Select Interface and enter the interface ID of your desired entry.

Neighbor The IP address of the PIM neighbor for which this entry contains information.

Interface The physical interface on which PIM DM is enabled.

Uptime The time since the PIM neighbor (last) became a neighbor of the local switch.

Expires The time remaining before the PIM neighbor will be aged out.

7.1.5 Configuring PIM SM Interface

Choose the menu L3 FEATURES > Multicast Routing > PIM SM > PIM SM Interface to load the following page.

Figure 7-5 Configuring PIM SM Interface

PIM SM Interface Config
InterfaceStatusHello IntervalJoin/Prune IntervalDR PriorityBSR BorderIP AddressNeighbor CountDR Address
VLAN1Disable30601Disable192.168.0.10-
Total: 1

PIM-SM uses shared trees by default and implements source-based trees for efficiency; it assumes that no hosts want the multicast traffic unless they specifically ask for it. It creates a shared distribution tree centered on a defined “rendezvous point” (RP) from which source traffic is relayed to the receivers.

Follow these steps to configure the L3 interfaces as PIM SM mode:

1) In the PIM SM Interface Config section, select the desired interface to configure, then specify the corresponding parameters.

Interface Displays the interface which you can configure.
Status Select to enable or disable PIM SM function on the interface.
Hello IntervalSpecify the rate (time in seconds) at which PIM hello messages are transmitted from the selected interface. The valid value ranges from 1 to 18725 and the default is 30 seconds.
Join/Prune IntervalSpecify the frequency at which PIM Join/Prune messages are transmitted on this PIM interface. The valid value range from 1 to 18000 and the default value is 60.
DR PrioritySpecify the DR priority for the selected interface. The valid value range from 0 to 4294967295. The default value is 1.
BSR BorderSelect to enable or disable the BSR border to define a PIM bootstrap message boundary for the PIM domain.
IP Address Displays the IP address of the interface.
Neighbor Count Displays the number of PIM neighbors of this interface.
DR Address Displays the DR address of the interface.

TP-LINK Omada Pro S5500-24GP4F - Configuring PIM SM Interface - 1

Note:

- You must have enabled Multicast Routing and Protocol Mode before configuring interface status.

2) Click Apply.

7.1.6 Viewing PIM SM Neighbor

Choose the menu L3 FEATURES> Multicast Routing> PIM SM> PIM SM Neighbor to load the following page.

Figure 7-6 Viewing PIM SM NeighborPIM SM Neighbor Q All Refresh Interface Neighbor UpTime Expires No entries in this table. Total: 0

PIM SM neighbor is automatically learned by sending and receiving Hello Packets when PIM SM is enabled.

In the PIM SM Neighbor section, you can view all the PIM SM neighbors.

Search Option Here you can set the search options for the PIM DM neighbor table.

ALL: Displays all entries.

Neighbor: Select Neighbor and enter the neighbor address of your desired entry.

Interface: Select Interface and enter the interface ID of your desired entry.

Interface The physical interface on which PIM DM is enabled.

Neighbor The IP address of the PIM neighbor for which this entry contains information.

Uptime The time since the PIM neighbor(last) became a neighbor of the local switch.

Expires The time remaining before the PIM neighbor will be aged out.

7.1.7 Configuring BSR

Choose the menu L3 FEATURES> Multicast Routing> PIM SM> BSR to load the following page.

Figure 7-7 Configuring BSRPIM SM Candidate BSR Config Interface: VLAN1 Hash Mask Length: 30 (0-32) Priority: 0 (0-255) Interval: 60 (1-16383) Apply PIM SM Elected BSR Information BSR Address: NA Priority: 0 Hash Mask Length: 0 Expires: -- PIM SM Candidate BSR Information Candidate BSR Address: NA Priority: 0 Hash Mask Length…

PIM-SM uses a Bootstrap Router (BSR), which advertises information to other multicast routers about the rendezvous point (RP). In a given network, a set of routers can be administratively enabled as candidate bootstrap routers (C-BSR). If it is not apparent which router should be the BSR, the candidates flood the domain with advertisements. The router with the highest priority is elected. If all the priorities are equal, then the candidate with the highest IP address becomes the BSR.

Follow these steps to configure the BSR:

1) In the PIM SM Candidate BSR Config section, configure the candidate BSR of the current device.

Interface Select the interface on this switch from which the BSR address is derived to make it a candidate. This interface must be enabled with PIM SM.
Hash Mask LengthSpecify the mask length that is to be ANDed with the group address before the hash function is called. All groups with the same seed hash correspond to the same RP The valid value range from 0 to 32 and the default value is 30.
PrioritySpecify the priority of the BSR. The BSR with the larger priority is preferred. If the priority values are the same, the device with the highest IP address is selected as the BSR. The valid value range from 0 to 255 and the default value is 0.

Interval: The BSR Advertisement interval, valid range is 1-16383.

2) Click Apply. 3) The PIM SM Elected BSR Information section displays the elected BSR information.

BSR Address: Displays the elected BSR address.

Priority: Displays the priority of the elected BSR.

Hash Mask Length: Displays the hash mask length of the elected BSR.

Expire: Displays the expire time of the elected BSR.

4) The PIM SM Candidate BSR Information section displays the Candidate BSR information.

Candidate BSR Address: Displays the Candidate BSR address.

Priority: Displays the priority of the Candidate BSR.

Hash Mask Length Displays the hash mask length of the Candidate BSR.

7.1.8 Configuring RP

Choose the menu L3 FEATURES> Multicast Routing> PIM SM> RP to load the following page.

Figure 7-8 Configuring RPPIM SM Static RP Table RP Address Group Group Mask Override No entries in this table. Total: 0 PIM SM Candidate RP Table Interface Group Group Mask Interval Next advertisement time No entries in this table. Total: 0

In the PIM SM mode, RP receives multicast data from the source and transmits the data down the shared tree to the multicast group members. You must have an RP if the interface is in sparse mode, and you can manually assign static RP or config candidate RP to generate the RP.

Follow these steps to configure the RP:

1) In the PIM SM Static RP Table section, click Add to configure the IP address of RPs on all multilayer switches.

RP Address Specify the IP address of the static RP.

Group Group Address of the RP to be created or deleted.

Group Mask Group Mask of the RP to be created or deleted.

Override Choose to enable or disable the override mode. If the override mode is enabled, the static RP will take effect no matter the candidate RP is configured or not. Otherwise the static RP will be invalid when the candidate RP is configured.

2) Click Create. 3) In the PIM SM Candidate RP Table section, click Add to configure the candidate RP on this device. Candidate RPs periodically send multicast RP-announce messages to a particular group or group range to announce their availability.

Interface Select interface of the candidate RP.

Group The group address transmitted in Candidate-RP-Advertisements.

Group Mask The group address mask transmitted in Candidate-RP-Advertisements.

Interval Specify the interval of advertisement message of the candidate RP in seconds. The default value is 60.

Next advertisement time Displays the remaining time to send the next RP advertisement packet.

4) Click Create.

7.1.9 Viewing Group to RP Mapping Information

Choose the menu L3 FEATURES> Multicast Routing> PIM SM> RP Mapping to load the following page.

Figure 7-9 Viewing Group to RP Mapping InformationGroup to RP Mapping Information All Refresh Group RP Info Source HoldTime Expires No entries in this table. Total: 0

In the Group to RP Mapping Information section, you can view active RPs that are cached with associated multicast routing entries.

Search Option Here you can set the search options for the entry.

ALL: Select All to display all entries.

RP: Select RP and enter the RP IP address of desired entry.

Group Displays the group address.

RP Displays the RP address.

Info Source Displays the origin of RP information.

HoldTime Displays the holdtime of the RP.

Expires Displays the expiry time of the RP. If RP is static, the expiry time will be Never.

7.1.10 Viewing RP Information

Choose the menu L3 FEATURES> Multicast Routing> PIM SM> RP Info to load the following page.

Figure 7-10 Viewing RP InformationHash Option Hash Option: All RP Information Group RP No entries in this table. Total: 0

In the Hash Option section, you can view the PIM RP Address for a specific group.

ALL Select All to display all entries.

Group Select Group and enter the group IP address of desired entry.

In the RP Information section, you can view the selected RP of group or all group.

Group Displays the group address.

RP Displays the RP address.

7.1.11 Configuring PIM SSM

Choose the menu L3 FEATURES> Multicast Routing> PIM SM> PIM SSM to load the following page.

Figure 7-11 Configuring PIM SSMPIM SSM Config Table Group Mask No entries in this table. Total: 0

While PIM-SM employs a specially-configured RP router that serves as a meeting junction for multicast senders and listeners, Protocol-Independent Multicast Source Specific Multicast (PIM-SSM) does not use an RP. It supports only source-route deliver trees. It is used between routers so that they can track which multicast packets to forward to each other and to their directly-connected LANs. The SSM service model can be implemented with a strict subset of the PIM-SM protocol mechanisms. Both regular IP Multicast and SSM semantics can coexist on a single router and both can be implemented using the PIM-SM protocol. A range of multicast addresses, currently 232.0.0.0/8 in IPv4, is reserved for SSM.

Follow these steps to configure the PIM SSM:

1) In the PIM SSM Config Table section, click Add to add a PIM SSM entry.

Group Enter the source-specific multicast group IP address.

Group Mask Enter the source-specific multicast group IP address mask.

2) Click Create.

7.1.12 Viewing PIM SM Packet Statistics

Choose the menu L3 FEATURES > Multicast Routing > PIM SM > Packet Statistics to load the following page.

Figure 7-12 Viewing PIM SM Packet StatisticsAuto Refresh Auto Refresh: Enable Refresh Period: 3 sec(3-300) Apply PIM SM Statistics Interface Stat Hello Register Reg-Stop Join/Prune BSR Assert CRP Error Packet No entries in this table. Total: 0

In the Auto Refresh section, you can configure the auto refresh feature.

Auto Refresh Choose to enable or disable the auto refresh feature.

Refresh Period Enter the time from 3 to 300 seconds to specify the auto refresh period.

In the PIM SM Statistics section, you can view PIM SM packet statistics over each interface.

Rx Packet Received in Protocol.

Tx Packet Sent from Protocol.

Interface The interface on which PIM SM is enabled.

Hello Hello Format Packets Statistics.

Register Register Format Packets Statistics.

Reg-Stop Register-Stop Format Packets Statistics.

Join/Prune Join/Prune Format Packets Statistics.

BSR Bootstrap Format Packets Statistics.

Assert Assert Format Packets Statistics.

CRP Candidate-RP-Advertisement Format Packets Statistics.

Error Packet Err Packets Statistics.

7.1.13 Configuring Static Mroute

Choose the menu L3 FEATURES> Multicast Routing> Static Mroute to load the following page.

Figure 7-13 Configuring Static MrouteStatic Mroute Config Table Source Source Mask RPF Neighbor Distance No entries in this table. Total: 0

Static mroutes are special routes manually configured by the administrator and cannot change automatically with the network topology accordingly.

Follow these steps to configure the Static Mroute entry:

1) In the Static Mroute Config Table section, click Add to add a static mroute entry.

Source Enter the IP Address that identifies the multicast source of the entry you are creating.

Source Mask Enter the subnet mask to be applied to the Source.

RPF Neighbor Enter the IP address of the neighbor router on the path to the mroute source.

Distance: Enter the administrative distance of the static mroute. The range is 1-255. The lower the distance, the better the preference.

2) Click Create.

7.2 Using the CLI

7.2.1 Configuring IP Multicast-routing Globally

Follow these steps to configure IP multicast-routing globally:

Step 1 configure

Enter global configuration mode.

Step 2 ip multicast-routing

no ip multicast-routing

Enable/Disable IP multicast-routing globally.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable IP multicast-routing globally.

Switch#configure

Switch(config)#ip multicast-routing

Switch(config)#end

Switch#copy running-config startup-config

7.2.2 Configuring IP PIM Globally

Follow these steps to configure IP PIM globally:

Step 1 configure

Enter global configuration mode.

Step 2 ip pim {dense-mode | sparse-mode}
no ip pim{dense-mode | sparse-mode}
Enable/Disable IP PIM Globally.
dense-mode: Enable PIM DM globally
sparse-mode: Enable PIM SM globally
Step 3 end
Return to privileged EXEC mode.
Step 4 copy running-config startup-config
Save the settings in the configuration file.

The following example shows how to enable PIM DM globally.

Switch#configure

Switch(config)#ip pim dense-mode

Switch(config)#end

Switch#copy running-config startup-config

7.2.3 Configuring IP PIM On Specified Interface

Follow these steps to configure IP PIM on a specified interface:

Step 1 configure
Enter global configuration mode.
Step 2 interface {vlan vid | fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channelport-channel | range port-channel port-channel-id}Enter interface configuration mode.
Step 3 ip pim
no ip pim
Enable/Disable IP PIM on the specified port.
Step 4 end
Return to privileged EXEC mode.
Step 5 copy running-config startup-config
Save the settings in the configuration file.

The following example shows how to enable PIM DM on port 2.

Switch#configure

Switch(config)# interface vlan 2

Switch(config-if)# ip pim

Switch(config)#end

Switch#copy running-config startup-config

7.2.4 Configuring Candidate BSR on Specified Interface

Follow these steps to configure a candidate BSR on a specified interface:

Step 1 configure

Enter global configuration mode.

Step 2 ip pim bsr-candidate interface {{fastEthernet | gigabitEthernet | ten-gigabitEthernet} port | vlan vlan-id} [hash-mask-length mask-len] [priority pri] [interval interval]

no ip pim bsr-candidate

Configure a candidate BSR on the interface.

fastEthernet | gigabitEthernet | ten-gigabitEthernet: interface type

port: port number

vlan-id: VLAN interface ID.

mask-len: Hashmask length, ranging from 0 to 32.

pri: The priority of the candidate BSR, ranging from 0 to 255.

interval: The interval for the candidate BSR to send Bootstrap messages. The value range is from 1 to 16383 seconds.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure a candidate BSR on VLAN interface 2 with a hash mask length of 10 and a priority of 20:

Switch#configure

Switch(config)#ip pim bsr-candidate interface vlan 2 10 20

Switch(config)#end

Switch#copy running-config startup-config

7.2.5 Configuring Candidate RP on Specified Interface

Follow these steps to configure a candidate RP on a specified interface:

Step 1configure
Enter global configuration mode.
Step 2ip pim rp-candidate interface {{fastEthernet | gigabitEthernet | ten-gigabitEthernet} port |vlan vlan-id} [group-addr grouplp] [group-mask groupMask] [interval interval]no ip pim rp-candidate interface {{ fastEthernet | gigabitEthernet | ten-gigabitEthernet }port | vlan vlan-id } [ group-addr grouplp ] [ group-mask groupMask ]Configure a candidate RP on the interface.fastEthernet | gigabitEthernet | ten-gigabitEthernet:interface typeport: port numbervlan-id: VLAN interface ID.grouplp: Multicast group IP address of the candidate RP.groupMask: Multicast group subnet mask of the candidate RP.interval: The interval for the candidate BSR to send Bootstrap messages. The value range is from 1 to 16383 seconds.
Step 3endReturn to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure a candidate RP on VLAN interface 2, with the multicast group address 235.0.0.1, the multicast group mask 255.255.255.0, and the interval for sending RP advertisement messages 70 seconds:

Switch#configure

Switch(config)#ip pim rp-candidate interface vlan 2 235.0.0.1 255.255.255.0 70

Switch(config)#end

Switch#copy running-config startup-config

7.2.6 Configuring Static RP

Follow these steps to configure a static RP:

Step 1 configure

Enter global configuration mode.

Step 2 ip pim rp-address ip-addr [group-address grouplp] [group-mask groupMask] [override]

no ip pim rp-address ip-addr [group-address grouplp] [group-mask groupMask] [override]

Configure a static RP on the interface.

ip-addr: P address of static RP.

groupIp: Multicast group IP address of static RP.

groupMask: Multicast group subnet mask of static RP.

override: If the static RP configured by this command is inconsistent with the RP elected by BSR, the static RP will take effect.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the static RP address to 20.20.20.2, and the RP multicast group and mask to 235.0.0.0 255.255.255.0:

Switch#configure

Switch(config)#ip pim rp-address 20.20.20.2 235.0.0.0 255.255.255.0

Switch(config)#end

Switch#copy running-config startup-config

7.2.7 Configuring BSR Domain Border

Follow these steps to configure the management border of the BSR domain:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan vid | fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel | range port-channel port-channel-id}

Enter interface configuration mode.

Step 3 ip pim bsr-border

no ip pim bsr-border

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the BSR management border on VLAN interface 2:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)# ip pim bsr-border

Switch(config)#end

Switch#copy running-config startup-config

7.2.8 Configuring PIM-SSM

Follow these steps to configure the PIM-SSM:

Step 1 configure

Enter global configuration mode.

Step 2 ip pim ssm { group-address

grouplp [ group-mask groupMask] | default }

no ip pim ssm { group-address grouplp [ group-mask groupMask] | default}

grouplp: SSM multicast group address.

groupMask: SSM multicast group subnet mask

default: Configure the default SSM multicast group address range. (The default range is 232.0.0.0/8)

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the SSM multicast group address range to 235.0.0.1 255.255.0.0:

Switch#configure

Switch(config)#ip pim ssm 235.0.0.1 255.255.0.0

Switch(config)#end

Switch#copy running-config startup-config

7.2.9 Configuring DR Priority

Follow these steps to configure the priority of the designated router (DR).

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan vid | fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel | range port-channel port-channel-id |} Enter interface configuration mode.

Step 3 ip pim dr-priority pri no ip pim dr-priority

pri: DR priority, ranging from 0 to 4294967295. Its default value is 1.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the DR priority on VLAN interface 2 to 100:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)# ip pim dr-priority 100

Switch(config)#end

Switch#copy running-config startup-config

7.2.10 Configuring IP PIM Hello-Interval

Follow these steps to configure the interval for sending Hello messages on the interface:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan vid | fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel | range port-channel port-channel-id}

Enter interface configuration mode.

Step 3 ip pim hello-interval interval

no ip pim hello-interval

Configure the interval for sending Hello messages on the interface.

interval: The time interval for sending Hello messages, ranging from 1 to 18725 seconds. The default value is 30 seconds.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the interval for VLAN interface 2 to send Hello messages to 100 seconds.

Switch#configure

Switch(config)# interface vlan 2

Switch(config-if)# ip pim hello-interval 100

Switch(config)#end

Switch#copy running-config startup-config

7.2.11 Configuring IP PIM Join-prune-interval

Follow these steps to configure the interval for sending join/prune messages on the interface:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan vid | fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel | range port-channel port-channel-id}

Enter interface configuration mode.

Step 3 ip pim join-prune-interval interval

no ip pim join-prune-interval

Configure the interval for sending join/prune messages on the interface. To restore the default configuration, use the no ip pim join-prune-interval command.

interval: The interval for sending join/prune messages, ranging from 1 to 18724 seconds. The default value is 60 seconds.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the interval for VLAN interface 2 to send Hello messages to 100 seconds.

Switch#configure

Switch(config)# interface vlan 2

Switch(config-if)# ip pim hello-interval 100

Switch(config)#end

Switch#copy running-config startup-config

7.2.12 Viewing IP Multicast Info

Follow these steps to view the global configuration information of IP multicast:

Step 1 configure

Enter global configuration mode.

Step 2 show ip multicast

View the global configuration information of IP multicast.

Step 3 end

Return to privileged EXEC mode.

The following example shows how to view the global configuration information of IP multicast.

Switch#configure

Switch(config)# show ip multicast

Admin Mode...... Enabled

Protocol State.... Operational

Table Max Size.... 1024

Protocol...... No protocol enabled.

Multicast forwarding cache entry count...... 0

7.2.13 Viewing IP Mroute

Follow these steps to view the multicast routing table:

Step 1 configure

Enter global configuration mode.

Step 2 show ip mroute { group summary }

ip-addr | source ip-addr | detail | static [ source source-ip ] |

group ip-addr: Multicast group IP address

source ip-addr: Multicast source IP address

detail: Displays detailed multicast routing table

static [ source source-ip]: Displays all static multicast routing entries or static multicast routing entries with a specified source IP address

summary: Displays summary information of multicast routing entries

Step 3 end

Return to privileged EXEC mode.

The following example shows how to view all multicast routing entries.

Switch#configure

Switch(config)# show ip mroute

7.2.14 Viewing IP PIM Interface Info

Follow these steps to view the IP PIM interface information:

Step 1 configure

Enter global configuration mode.

Step 2 show ip pim interface { fastEthernet | gigabitEthernet | ten-gigabitEthernet port | port-channel [port-channel-list] | vlanid vlan-id }

Displays the IP PIM interface information.

fastEthernet | gigabitEthernet | ten-gigabitEthernet: interface type

port: Port number

port-channel-list: Port channel list

vlan-id: VLAN interface ID, ranging from 1 to 4094.

Step 3 end

Return to privileged EXEC mode.

The following example shows how to view the information on PIM VLAN 2.

Switch#configure

Switch(config)# show ip pim interface vlan 2

Interface...... VLAN2

Mode...... None

Hello Interval (secs)...... 30

Join Prune Interval (secs)...... 60

DR Priority.... 1

BSR Border...... Disabled

7.2.15 Viewing IP PIM Neighbor Info

Follow these steps to view the IP PIM neighbor information:

Step 1 configure

Enter global configuration mode.

Step 2show ip pim neighbor { fastEthernet | gigabitEthernet | ten-gigabitEthernet port | vlanid vlan-id }Displays the IP PIM neighbor information.fastEthernet | gigabitEthernet | ten-gigabitEthernet: interface typeport: Port numbervlan-id : VLAN interface ID, ranging from 1 to 4094.
Step 3 endReturn to privileged EXEC mode.

The following example shows how to view all PIM neighbor information.

Switch#configure

Switch(config)# show ip pim neighbor

7.2.16 Viewing IP PIM Statistics

Follow these steps to view the IP PIM statistics:

Step 1configure
Enter global configuration mode.
Step 2show ip pim statistic { fastEthernet | gigabitEthernet | ten-gigabitEthernet port | vlanid vlan-id }Displays the IP PIM statistic information.fastEthernet | gigabitEthernet | ten-gigabitEthernet: interface typeport: Port numbervlan-id : VLAN interface ID, ranging from 1 to 4094.
Step 3end
Return to privileged EXEC mode.

The following example shows how to view packet count information for all PIM interfaces.

Switch#configure

Switch(config)# show ip pim statistic

Rx - Packet received in protocol.

Tx - Packet sent from protocol.

7.2.17 Viewing Candidate BSR and Candidate RP

Follow these steps to view the information of candidate BSRs and candidate RPs.

Step 1 configure

Enter global configuration mode.

Step 2 show ip pim bsr-router

Displays the information of candidate BSRs and candidate RPs.

Step 3 end

Return to privileged EXEC mode.

The following example shows how to view the information of candidate BSRs and candidate RPs.

Switch#configure

Switch(config)#show ip pim bsr-router

7.2.18 Viewing RP

Follow these steps to view the RP information. The data of each multicast group can only be forwarded by one unique RP.

Step 1 configure

Enter global configuration mode.

Step 2 show ip pim rp mapping { rp-address

rpAddr | candidate candidate | static static}

Displays the RP information.

rpAddr: Displays the RP information corresponding to the specified multicast group address.

candidate: Displays the information of candidate RPs in the switch.

static: Displays the information of static RPs in the switch.

Step 3 end

Return to privileged EXEC mode.

The following example shows how to view the RP information corresponding to all multicast groups:

Switch#configure

Switch(config)#show ip pim rp mapping

7.2.19 Viewing Hash Result of Specified Multicast Group

Follow these steps to view the hash result of the specified multicast group.

Step 1 configure

Enter global configuration mode.

Step 2 show ip pim rp-hash ip-addr

Displays the hash result of the specified multicast group.

ip-addr: Multicast group address.

Step 3 end

Return to privileged EXEC mode.

The following example shows how to view the hash result for multicast group 224.1.1.2:

Switch#configure

Switch(config)# show ip pim rp-hash 224.1.1.2

7.2.20 Configuring Static Multicast-routing Entries

Follow these steps to add or modify static multicast routing entries globally:

Step 1 configure

Enter global configuration mode.

Step 2 ip mroute { source-address } {mask} { rpf-address } {distance}

no ip mroute { source-address} { mask }

Add/Modify static multicast routing entries globally or delete the specified static multicast routing entry.

source-address: IP address of the multicast source, in the format 192.168.0.1

mask: Subnet mask for the multicast source IP address

rpf-address: Specify the ingress interface of the RPF entry

distance: Management parameters of static multicast routing entries, ranging from 0 to 255. The smaller the value, the higher the priority. If the value of the static multicast route is smaller than the value of other RPF entries, the static multicast route takes effect. The default value is 1.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to add a static multicast routing entry with the source address 192.168.0.1, the subnet mask 255.255.255.255, the incoming interface of the RPF entry 192.168.1.1, and the management parameter 1.

Switch#configure

Switch(config)#ip mroute 192.168.0.1 255.255.255.255 192.168.1.1 1

Switch(config)#end

Switch#copy running-config startup-config

7.2.21 Viewing IP Mroute Static Info

Follow these steps to view the IP mroute static information:

Step 1 configure

Enter global configuration mode.

Step 2 show ip mroute static { source source-ip }

View all static multicast routing entries.

The following example shows how to display all static multicast routing entries.

Switch#configure

Switch(config)#show ip mroute static

8

Layer 3 IGMP Configuration

8.1 Using the GUI

8.1.1 Configuring IGMP Globally

Choose the menu L3 FEATURES > Multicast Routing > IGMP > Global Config to load the following page.

Figure 8-1 Configuring IGMP GloballyIGMP Global Configuration Admin Mode: □ Enable Header Validation: □ Enable Apply

Follow these steps to configure IGMP globally.

1) In the IGMP Global Configuration section, enable the features according to your needs.

Admin Mode: Choose to enable or disable the IGMP function globally.

Header Validation

Choose to enable or disable the validation of the IGMP header field Router Alert options. The fields are validated for IGMPv2 and IGMPv3 only. Regardless of whether the validation is enabled, TTL (Time To Live) must be 1.

8.1.2 Configuring IGMP on the Interface

Choose the menu L3 FEATURES > Multicast Routing > IGMP > Interface Config to load the following page.

Figure 8-2 Configuring IGMP on the InterfaceInterface Configuration All Interface Admin Mode Version Robustness Query Interval Query Max Response Time Startup Query Interval Startup Query Count Last Member Query Interval Last Member Query Count VLAN1 Disable v3 2 125 100 31 2 10 2 Total: 1

Follow these steps to configure the IGMP parameters of the interface.

1) In the Interface Configuration section, search for and select the interface for which parameters are to be configured, then specify the corresponding parameters.

Search Option Here you can set the search options for the interface table.
All: Displays all interface entries.
Interface: Enter the VLAN ID the desired entry must carry.
Interface The interface for which data is to be displayed or configured.
Admin Mode The interface administrative status. You can select Enable/Disable the IGMP function for the interface.
Version There are three versions for IGMP protocol.
IGMPv1: The interface is now a IGMPv1 Router.
IGMPv2: The interface is now a IGMPv2 Router.
IGMPv3: The interface is now a IGMPv3 Router.
RobustnessSpecify the robustness of the selected interface, ranging from 1 to 255. The default is 2.
Query IntervalSpecify the IGMP query interval at which IGMP router sends out a general query, ranging from 1 to 3600. The default is 125 seconds.
Query Max Response TimeWhen IGMP router sends out a query packet, the host should response within the specified Query Max Response Time, the value is in tenths of a second, ranging from 0 to 255. The default value is 100 (10 seconds).
Startup Query IntervalWhen IGMP router starts up, it will send out a general query every Startup Query Interval, ranging from 1 to 300. The default is 31 seconds.
Startup Query CountThe number of general queries to be sent on startup, ranging from 1 to 20. The default value is 2.
Last Member Query IntervalWhen the last member leaves a multicast group, IGMP router will send out a specific query every Last Member Query Interval, the value is in tenths of a second, ranging from 0 to 255. The default value is 10 (1 second).
Last Member Query CountThe number of queries to be sent on receiving a leave group report, ranging from 1 to 20. The default value is 2.

2) Click Apply.

8.1.3 Viewing Interface State

Choose the menu L3 FEATURES > Multicast Routing > IGMP > Interface State to load the following page.

Figure 8-3 Viewing Interface StateInterface State All Refresh Interface Operational Status Querier State IP Address Querier IP Querier Up Time Querier Expiry Time Wrong Version Queries Received Number of Joins Received Number of Groups VLAN1 Non-Operational Non-Operational 192.168.0.1 --- --- 0 0 0 Total: 1

In the Interface State section, you can set the search options and view the interface state table.

Search Option: Here you can set the search options for the interface state table.

All: Displays all interface entries.

Interface: Enter the VLAN ID the desired entry must carry.

Interface: The interface for which data is to be displayed or configured.

Operational Status: The operational state of IGMP on the selected interface.

Querier State: Indicates whether the selected interface is in querier or non-querier mode.

IP Address: The IP address of the selected interface.

Querier IP: The address of the IGMP querier on the IP subnet to which the selected interface is attached.

Querier Up Time: The time in seconds from the querier start.

Querier Expiry Time The time in seconds remaining before the other querier present timer expires. If the local system is the querier, this will be zero.

Wrong Version Queries Received The number of queries that have been received on the selected interface with an IGMP version that does not match the IGMP version configured for the interface, over the lifetime of the entry. IGMP requires that all routers on a LAN be configured to run the same version of IGMP. Therefore, a configuration error is indicated if any queries are received with the wrong version number.

Number of Joins Received The number of times a group membership has been added on the selected interface; that is, the number of times an entry for this interface has been added to the cache table. This gives an indication of the amount of IGMP activity on the interface.

Number of Groups The current number of entries for the selected interface in the cache table.

8.1.4 Viewing Multicast Group Information

Choose the menu L3 FEATURES> Multicast Routing> IGMP> Multicast Group Table to load the following page.

Figure 8-4 Viewing Multicast Group TableMulticast Group Table All Refresh Interface Multicast IP Operation No entries in this table. Total: 0

1) In the Multicast Group Table section, you can view the information of IGMP Router Group table.

Search OptionSelect the rules for displaying multicast IP table to find the desired entries quickly.
All: Displays all multicast IP entries.
Interface: Enter the VLAN ID the desired entry must carry.
Multicast IP: Enter the multicast IP address the desired entry must carry.
Interface Displays the VLAN ID the desired entry must carry.
Multicast IP Displays the multicast IP address the desired entry must carry.
OperationClick the Detail button to view the mode and source IP address of the multicast group.

2) In the Detail of Multicast Group Table section, you can view the detail information for existing multicast group. 3) In the Basic Information section, you can view the basic information of the selected multicast group.

Interface Display the interface ID of the entry.
Multicast IP Displays the multicast IP address the entry.
Filter Mode Multicast group has one source filter mode: EXCLUDE or INCLUDE. The INCLUDE mode means that the port will forward the qualified packet,while the EXCLUDE mode means that the port will not forward the qualified packet.
CompatibilityThis parameter shows group compatibility mode(v1, v2 and v3) for this group on the specified interface.

4) In the Dynamic Information section, you can get some dynamic information of the special multicast group. This page will only display when viewing the detail of the multicast group.

Last ReporterThe IP address of the source of the last membership report received for the selected IP Multicast group.
Up Time The time elapsed since this entry was created.
Expire Time The minimum amount of time remaining before this entry will be aged out.
Version 1 Host TimerThe time remaining until the local router will assume that there are no longer any IGMP version 1 members on the IP subnet attached to this interface. When an IGMPv1 membership report is received, this timer is reset to the group membership timer. While this timer is non-zero, the local router ignores any IGMPv2 leave messages for this group that it receives on the selected interface. This field is displayed only if the interface is configured for IGMP version 1.
Version 2 Host TimerThe time remaining until the local router will assume that there are no longer any IGMP version 2 members on the IP subnet attached to this interface. When an IGMPv2 membership report is received, this timer is reset to the group membership timer. While this timer is non-zero, the local router ignores any IGMPv1 and IGMPv3 leave messages for this group that it receives on the selected interface. This field is displayed only if the interface is configured for IGMP version 2.

5) In the Source List section, you can view the source IP which the Forward Port participates in.

Index The index of the entry.
Source IP Displays the Source IP of the entry.
Source Filter ModeDisplays the type of the source IP.
Expire Time The source IP will be invalid after this time.

8.2 Using the CLI

8.2.1 Configuring IP IGMP Globally

Follow these steps to configure IP IGMP globally:

Step 1 configure

Enter global configuration mode.

Step 2 ip igmp

Enable IGMP globally.

Step 3 ip igmp header-validation

Enable IGMP header-validation globally.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure IP IGMP globally.

Switch#configure

Switch(config)#ip igmp

Switch(config)#ip igmp header-validation

Switch(config)#end

Switch#copy running-config startup-config

8.2.2 Configuring IP IGMP On Ports

Follow these steps to configure IP IGMP on specified ports:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list |}

Enter interface configuration mode.

Step 3 ip igmp version {1|2|3}

Specify the IGMP version. The switch supports IGMPv1, IGMPv2 and IGMPv3.

1: The switch works as an IGMPv1 switch. It can only process IGMPv1 messages from the host. Messages of other versions are ignored. 2: The switch works as an IGMPv2 switch. It can process both IGMPv1 and IGMPv2 messages from the host. IGMPv3 messages are ignored. 3: The switch works as an IGMPv3 switch. It can process IGMPv1, IGMPv2 and IGMPv3 messages from the host.

Step 4 ip igmp last-member-query-count count

Configure the number of times special group query messages are sent on the specified interface. The no command is used to restore the default value.

count: The number of times IGMP group-specific query messages are sent, ranging from 1-20. The default value is 2.

Step 5 ip igmp last-member-query-interval interval

Configure the time interval for sending special group query messages on the specified interface. The no command is used to restore the default value.

interval: The interval for sending IGMP group-specific query messages. The value range is 10-255 (1/10 second). The default value is 10 (1/10 second).

Step 6 ip igmp query-interval interval

Configure the IGMP general query interval on a specified interface. The no command is used to restore the default value.

interval: The time interval for sending IGMP general query messages on the specified interface. The value range is 1-3600 seconds. The default value is 125 seconds.

Step 7 ip igmp query-max-response-time time

Configure the maximum response time to IGMP general query messages on the specified interface. The no command is used to restore the default value.

time: The maximum response time for general group query messages on the specified interface, the value range is 10-255 (1/10 seconds), the default value is 100 (1/10 seconds)

Step 8 ip igmp robustness robustness

Configure the robustness coefficient on the specified interface. The no command is used to restore the default value.

robustness: Specify the IGMP robustness coefficient, the value range is 1-255, and the default value is 2.

Step 9 ip igmp startup-query-interval interval

Configure the time interval for sending initial query packets on the specified interface. The no command is used to restore the default value.

interval: The interval for sending IGMP initial query messages. The value range is 1-300 seconds. The default value is 31 seconds.

Step 10 ip igmp last-member-query-count count

Configure the number of initial query packets sent on the specified interface. The no command is used to restore the default value.

count: The number of times IGMP initial query message is sent, the value range is 1-20, the default value is 2

Step 11 show ip igmp

Display basic IGMP information.

Step 12 show ip igmp groups { group-address } [ detail]

Display information of all dynamic multicast groups or specified multicast groups

group-address: Multicast group address

detail: Detailed information of dynamic multicast group

Step 13 show ip igmp groups interface { fastEthernet | gigabitEthernet | ten-gigabitEthernet port | port-channel [port-channel-list] | detail }

Display all dynamic multicast group information on the specified port.

fastEthernet | gigabitEthernet | ten-gigabitEthernet: interface type

port: Port number

port-channel-list: Port channel list

detail: Detailed information of dynamic multicast group

Step 14 show ip igmp groups interface vlan vlan-id {detail}

Display all dynamic multicast group information on the specified VLAN interface.

fastEthernet | gigabitEthernet | ten-gigabitEthernet: interface type

vlan-id: VLAN port ID

detail: Detailed information of dynamic multicast group

Step 15 show ip igmp interface { fastEthernet | gigabitEthernet | ten-gigabitEthernet port | port-channel [port-channel-list] | statistic }

Display IGMP configuration information on a specified port.

fastEthernet | gigabitEthernet | ten-gigabitEthernet: interface type

port: Port number

port-channel-list: Port channel list

statistic: Statistics of IGMP packets received on the specified port

Step 16 show ip igmp interface vlan vlan-id{statistic}

Display IGMP configuration information on the specified VLAN interface.

vlan-id: VLAN port ID

statistic: Statistics of IGMP packets received on the specified port

Step 17 end

Return to privileged EXEC mode.

Step 18 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable IGMP on a specified port.

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ip igmp

Switch(config-if)#ip igmp version 3

Switch(config-if)#ip igmp last-member-query-count 3

Switch(config-if)#ip igmp last-member-query-interval 20

Switch(config-if)#ip igmp query-interval 50

Switch(config-if)#ip igmp query-max-response-time 50

Switch(config-if)#ip igmp robustness 3

Switch(config-if)#ip igmp query-interval 10

Switch(config-if)#ip igmp last-member-query-count 3

Switch(config-if)#ip igmp last-member-query-count 3

Switch(config-if)#show ip igmp

IGMP admin mode...... Disabled

IGMP header validation...... Disabled

IGMP INTERFACE STATUS

VLAN2 Enabled Non-Operational

Switch(config-if)#show ip igmp

Switch(config-if)#show ip igmp groups 224.0.2.40

Switch(config-if)#show ip igmp groups interface gigabitEthernet 1/0/1 detail

Switch(config-if)#show ip igmp groups interface vlan 1

IP Address.... 192.168.0.1

Subnet Mask.... 255.255.255.0

Interface Mode...... Disabled

Switch(config-if)#show ip igmp interface gigabitEthernet 1/0/1 statistic

Switch(config-if)#show ip igmp interface vlan 2

Interface...... VLAN2

IP address.... 0.0.0.0

Subnet mask.... 0.0.0.0

IGMP admin mode...... Disabled

Interface Mode...... Enabled

IGMP Version.... 3

Query Interval (secs)...... 10

Query Max Response Time(1/10 th of a sec) ..... 50

Robustness...... 3

Startup Query Interval (secs).... 31

Startup Query Count...... 2

Last Member Query Interval (1/10 of a second)... 10

Last Member Query Count...... 3

Switch(config-if)#end

Switch#copy running-config startup-config

9 Configuration Examples

9.1 Example for Configuring Basic IGMP Snooping

9.1.1 Network Requirements

Host B, Host C, and Host D are in the same VLAN of the switch. All of them want to receive multicast streams sent to multicast group 225.1.1.1.

As shown in the following topology, Host B, Host C, and Host D are connected to port 1/0/1, port 1/0/2, and port 1/0/3 respectively. Port 1/0/4 is the router port connected to the multicast querier.

Figure 9-1 Network Topology for Basic IGMP Snoopinggraph TD A["Source"] --> B["Internet"] B --> C["Querier"] C --> D["Gi1/0/4"] C --> E["Gi1/0/2"] D --> F["Host B Receiver"] D --> G["Host C Receiver"] D --> H["Host D Receiver"] E --> I["VLAN 10"]

9.1.2 Configuration Scheme

■ Add the three member ports and the router port to a VLAN and configure their PVIDs. ■ Enable IGMP Snooping globally and in the VLAN.

■ Enable IGMP Snooping on the ports.

Demonstrated with S6500-24GP4XF, this section provides configuration procedures in two ways: using the GUI and using the CLI.

9.1.3 Using the GUI

1) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > VLAN Config and click

Add to load the following page. Create VLAN 10 and add Untagged port 1/0/1-3 and Tagged port 1/0/4 to VLAN 10.

Figure 9-2 Create VLAN 10VLAN Config VLAN ID: 10 (2-40/4, format: 2.4-5.8) VLAN Name: VLAN 10 (1-16 characters) Untagged Ports Port 1/0/1-3 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 4…

2) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > Port Config to load the following page. Configure the PVID of port 1/0/1-4 as 10.

Figure 9-3 Configure PVID for the PortsPort Config UNIT1 LAGS Port PVID Ingress Checking Acceptable Frame Types LAG Details 10 ✓ 1/0/1 10 Enabled Admit All --- Details ✓ 1/0/2 10 Enabled Admit All --- Details ✓ 1/0/3 10 Enabled Admit All --- Details ✓ 1/0/4 10 Enabled Admit All --- Details □ 1/0/5 1 Enabled Admit All --- Details □ 1/0/6…

3) Choose the menu L2 FEATURES > Multicast > IGMP Snooping > Global Config to load the following page. In the Global Config section, enable IGMP Snooping globally. Configure the IGMP version as v3 so that the switch can process IGMP messages of all versions. Then click Apply.

Figure 9-4 Configure IGMP Snooping GloballyGlobal Config IGMP Snooping: ✓ Enable IGMP Version: ○ v1 ○ v2 ○ v3 Unknown Multicast Groups: ● Forward ○ Discard Header Validation: □ Enable Apply IGMP VLAN Config VLAN ID VLAN ID IGMP Snooping Status Fast Leave Report Suppression IGMP Snooping Querier Dynamic Router Ports Static Router Ports Forbid…

4) In the IGMP VLAN Config section, click √ in VLAN 10 to load the following page. Enable IGMP Snooping for VLAN 10.

Figure 9-5 Enable IGMP Snooping for VLAN 10Configure IGMP Snooping for VLAN VLAN ID 10 IGMP Snooping Status: Enable Fast Leave: Enable Report Suppression: Enable Member Port-Aging Time: 260 seconds (50-300) Router Port-Aging Time: 300 seconds (50-800) Leave Time: 1 seconds (1-30) IGMP Snooping Question: Enable Static Router Ports UNITI LAGS…

5) Choose the menu L2 FEATURES > Multicast > IGMP Snooping > Port Config to load the following page. Enable IGMP Snooping for ports 1/0/1-4.

Figure 9-6 Enable IGMP Snooping for the PortsPort Config UNIT1 LAGS Port IGMP Snooping Fast Leave LAG ✓ Gi1/0/1 Enabled Disabled --- ✓ Gi1/0/2 Enabled Enabled --- ✓ Gi1/0/3 Enabled Disabled --- ✓ Gi1/0/4 Enabled Disabled --- □ Gi1/0/5 Enabled Disabled --- □ Gi1/0/6 Enabled Disabled --- □ Gi1/0/7 Enabled Disabled --- □ Gi1/0/8 Enabled Disabled…

6) Click Save the settings.

9.1.4 Using the CLI

1) Create VLAN 10.

Switch#configure

Switch(config)#vlan 10

Switch(config-vlan)#name vlan10

Switch(config-vlan)#exit

2) Add port 1/0/1-3 to VLAN 10 and set the link type as untagged. Add port 1/0/4 to VLAN 10 and set the link type as tagged.

Switch(config)#interface range gigabitEthernet 1/0/1-3

Switch(config-if-range)#switchport general allowed vlan 10 untagged

Switch(config-if-range)#exit

Switch(config)#interface gigabitEthernet 1/0/4

Switch(config-if)#switchport general allowed vlan 10 tagged

Switch(config-if)#exit

3) Set the PVID of port 1/0/1-4 as 10.

Switch(config)#interface range gigabitEthernet 1/0/1-4

Switch(config-if-range)#switchport pvid 10

Switch(config-if-range)#exit

4) Enable IGMP Snooping globally.

Switch(config)#ip igmp snooping

5) Enable IGMP Snooping in VLAN 10.

Switch(config)#ip igmp snooping vlan-config 10

6) Enable IGMP Snooping on port 1/0/1-4.

Switch(config)#interface range gigabitEthernet 1/0/1-4

Switch(config-if-range)#ip igmp snooping

Switch(config-if-range)#exit

7) Save the settings.

Switch(config)#end

Switch#copy running-config startup-config

Verify the Configurations

Show members in the VLAN:

Switch(config)#show vlan brief

VLAN

Name

Status

Ports

Show status of IGMP Snooping globally, on the ports and in the VLAN:

Switch(config)#show ip igmp snooping

IGMP Snooping :Enable

IGMP Version :V3

Header Validation: Disable

Global Authentication Accounting: Disable

Enable Port: Gi1/0/1-4

Enable VLAN: 10

9.2 Example for Configuring MVR

9.2.1 Network Requirements

Host B, Host C, and Host D are in three different VLANs of the switch. All of them want to receive multicast streams sent to multicast group 225.1.1.1.

9.2.2 Network Topology

As shown in the following network topology, Host B, Host C, and Host D are connected to port 1/0/1, port 1/0/2, and port 1/0/3 respectively. Port 1/0/1, port 1/0/2, and port 1/0/3 belong to VLAN 10, VLAN 20, and VLAN 30 respectively. Port 1/0/4 is connected to the multicast network in the upper layer network.

Figure 9-7 Network Topology for Multicast VLANgraph TD A["Source"] --> B["Internet"] B --> C["Querier"] C --> D["Gi1/0/4"] C --> E["Gi1/0/2"] D --> F["Host B Receiver"] D --> G["Host C Receiver"] D --> H["Host D Receiver"] E --> I["Host B Receiver"] E --> J["Host C Receiver"] E --> K["Host D Receiver"]

9.2.3 Configuration Scheme

As the hosts are in different VLANs, in IGMP Snooping, the Querier needs to duplicate multicast streams for hosts in each VLAN. To avoid duplication of multicast streams being sent between Querier and the switch, you can configure MVR on the switch.

The switch can work in either MVR compatible mode or MVR dynamic mode. When in compatible mode, remember to statically configure the Querier to transmit the streams of multicast group 225.1.1.1 to the switch via the multicast VLAN. Here we take the MVR dynamic mode as an example.

Demonstrated with S6500-24GP4XF, this section provides configuration procedures in two ways: using the GUI and using the CLI.

9.2.4 Using the GUI

1) Add port 1/0/1-3 to VLAN 10, VLAN 20 and VLAN 30 as Untagged ports respectively, and configure the PVID of port 1/0/1 as 10, port 1/0/2 as 20, port 1/0/3 as 30. Make sure port 1/0/1-3 only belong to VLAN 10, VLAN 20 and VLAN 30 respectively. For details, refer to Configuring 802.1Q VLAN.

Figure 9-8 VLAN Configurations for Port 1/0/1-3VLAN Config VLAN ID VLAN Name Members Operation 1 System-VLAN 1/0/4-28 10 VLAN10 1/0/1 20 VLAN20 1/0/2 30 VLAN30 1/0/3 Total: 4

Figure 9-9 PVID for Port 1/0/1-3

TP-LINK Omada Pro S5500-24GP4F - Using the GUI - 2

2) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > VLAN Config and click Add to load the following page. Create VLAN 40 and add port 1/0/4 to the VLAN as Tagged port.

Figure 9-10 Create Multicast VLANVLAN Config VLAN ID: 40 (2-40/4, format: 2.4-5.8) VLAN Name: Multicast_VLAN (1-16 characters) Unlagged Ports Port: (Format: 1/9/1, Input or choice below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 4…

3) Choose the menu L2 FEATURES > Multicast > MVR > MVR Config to load the following page. Enable MVR globally, and configure the MVR mode as Dynamic, multicast VLAN ID as 40.

Figure 9-11 Configure MVR GloballyMVR Config MVR: Enable MVR Mode: Compatible Dynamic Multicast VLAN ID: 40 (1-4094) Query Response Time: 5 tenths of a second (1-100) Maximum Multicast Groups: 4093 Current Multicast Groups: 0 Apply

4) Choose the menu L2 FEATURES > Multicast > MVR > MVR Group Config and click

Add to load the following page. Add multicast group 225.1.1.1 to MVR.

Figure 9-12 Add Multicast Group to MVRMVR Group IP MVR Group IP: 225.1.1.1 (Format: 235.0.0.1) MVR Group Count: 1 (1-250) Cancel Create

5) Choose the menu L2 FEATURES > Multicast > MVR > Port Config to load the following page. Enable MVR for port 1/0/1-4. Configure port 1/0/1-3 as Receiver ports and port 1/0/4 as Source port.

Figure 9-13 Configure MVR for the PortsPort Config UNIT1 Port Mode Type Status Fast Leave Gi1/0/1 Enable Receiver Active/InVLAN Gi1/0/2 Enable Receiver Inactive/InVLAN Gi1/0/3 Enable Receiver Inactive/InVLAN Gi1/0/4 Enable Source Inactive/InVLAN Gi1/0/5 Disable None Inactive/InVLAN Gi1/0/6 Disable None Inactive/InVLAN Gi1/0/7 Disable Non…

6) Click save the settings.

9.2.5 Using the CLI

1) Create VLAN 10, VLAN 20, VLAN 30 and VLAN 40.

Switch#configure

Switch(config)#vlan 10,20,30,40

Switch(config-vlan)#exit

2) Add port 1/0/1-3 to VLAN 10, VLAN 20 and VLAN 30 as untagged ports respectively, and configure the PVID of port 1/0/1 as 10, port 1/0/2 as 20, port 1/0/3 as 30. Add port 1/0/4 to VLAN 40 as tagged port and configure the PVID of port 1/0/4 as 40.

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#switchport general allowed vlan 10 untagged

Switch(config-if)#switchport pvid 10

Switch(config-if)#exit

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)#switchport general allowed vlan 20 untagged

Switch(config-if)#switchport pvid 20

Switch(config-if)#exit

Switch(config)#interface gigabitEthernet 1/0/3

Switch(config-if)#switchport general allowed vlan 30 untagged

Switch(config-if)#switchport pvid 30

Switch(config-if)#exit

Switch(config)#interface gigabitEthernet 1/0/4

Switch(config-if)#switchport general allowed vlan 40 tagged

Switch(config-if)#switchport pvid 40

Switch(config-if)#exit

3) Check whether ports 1/0/1-3 only belong to VLAN 10, VLAN 20, and VLAN 30 respectively. If not, delete them from the other VLANs. By default, all ports are in VLAN 1, so you need to delete them from VLAN 1.

Switch(config)#show vlan brief

VLANNameStatusPorts
----------------

4) Enable MVR globally, and configure the MVR mode as Dynamic, multicast VLAN ID as 40. Add multicast group 225.1.1.1 to MVR.

Switch(config)#mvr

Switch(config)#mvr mode dynamic

Switch(config)#mvr vlan 40

Switch(config)#mvr group 225.1.1.1

5) Enable MVR for ports 1/0/1-4. Configure ports 1/0/1-3 as Receiver ports and port 1/0/4 as Source port.

Switch(config)#interface range gigabitEthernet 1/0/1-3

Switch(config-if-range)#mvr

Switch(config-if-range)#mvr type receiver

Switch(config-if-range)#exit

Switch(config)#interface gigabitEthernet 1/0/4

Switch(config-if)#mvr

Switch(config-if)#mvr type source

Switch(config-if)#exit

6) Save the settings.

Switch(config)#end

Switch#copy running-config startup-config

Verify the Configurations

Show the brief information of all VLANs:

Switch(config)#show vlan brief

VLAN

Name

Status

Ports

1 System-VLAN active Gi1/0/4, Gi1/0/5, Gi1/0/6, Gi1/0/7,

...

10 VLAN10

active

Gi1/0/1

20 VLAN20

active

Gi1/0/2

30 VLAN30

active

Gi1/0/3

40 VLAN40

active

Gi1/0/4

Show the brief information of MVR:

Switch(config)#show mvr

MVR: Enable

9.3 Example for Configuring Unknown Multicast and Fast Leave

MVRMulticastVlan:40
MVR Max Multicast Groups:511
MVR Current Multicast Groups:1
MVR Global Query Response Time:5 (tenths of sec)
MVRModeType:Dynamic
Show the membership of MVR groups:
Switch(config)#show mvr members
MVRGroupIPStatusMembers
225.1.1.1activeGi1/0/4

9.3 Example for Configuring Unknown Multicast and Fast Leave

A user experiences lag when he is changing channel on his IPTV. He wants solutions to this problem. As shown in the following network topology, port 1/0/4 on the switch is connected to the upper layer network, and port 1/0/2 is connected to Host B.

A user experiences lag when changing channels on his IPTV. He wants solutions to this problem. As shown in the following network topology, port 1/0/4 on the switch is connected to the upper layer network, and port 1/0/2 is connected to Host B.

Figure 9-14 Network Topology for Unknown Multicast and Fast Leavegraph TD A["Source"] --> B["Internet"] B --> C["Querier"] C --> D["VLAN 10"] D --> E["Host B Receiver"] D --> F["Gi1/0/4 VLAN 10"] D --> G["Gi1/0/2"]

After the channel is changed, the client (Host B) still receives irrelevant multicast data, the data from the previous channel and possibly other unknown multicast data, which increases the network load and results in network congestion.

After the channel is changed, the client (Host B) still receives irrelevant multicast data, the data from the previous channel and possibly other unknown multicast data, which increases the network load and results in network congestion.

To avoid Host B from receiving irrelevant multicast data, you can enable Fast Leave on port 1/0/2 and configure the switch to discard unknown multicast data. To change channel, Host B sends a leave message about leaving the previous channel. With Fast Leave enabled on port 1/0/2, the switch will then drop multicast data from the previous channel, which ensures that Host B only receives multicast data from the new channel and that the multicast network is unimpeded.

Demonstrated with S6500-24GP4XF, this section provides configuration procedures in two ways: using the GUI and using the CLI.

1) Create VLAN 10. Add port 1/0/4 to the VLAN as untagged port and port 1/0/5 as tagged port. Configure the PVID of the two ports as 10. For details, refer to Configuring 802.1Q VLAN.

1) Create VLAN 10. Add port 1/0/4 to the VLAN as an untagged port and port 1/0/5 as a tagged port. Configure the PVID of the two ports as 10. For details, refer to Configuring 802.1Q VLAN.

2) Choose the menu L2 FEATURES > Multicast > IGMP Snooping > Global Config to load the following page. In the Global Config section, enable IGMP Snooping globally and configure Unknown Multicast Groups as Discard.

Figure 9-15 Configure IGMP Snooping GloballyGlobal Config IGMP Snooping: Enable IGMP Version: v1 v2 v3 Unknown Multicast Groups: Forward Discard Header Validation: Enable Apply IGMP VLAN Config VLAN ID IGMP Snooping Status Fast Leave Report Suppression IGMP Snooping Querier Dynamic Router Ports Static Router Ports Forbidden Router Ports Opera…

3) In the IGMP VLAN Config section, click √ in VLAN 10 to load the following page. Enable IGMP Snooping for VLAN 10 and click Save.

Figure 9-16 Enable IGMP Snooping for VLAN 10Configure IGMP Snooping for VLAN VLAN ID: 10 IGMP Snooping Status: Enable Fast Leave: Enable Report Suppression: Enable Member Port Aging Time: 260 seconds (01 AM) Router Port Aging Time: 300 seconds (10 PM) Leave Time: 1 seconds (1-30) IGMP Snooping Queue: Enable Static Router Ports UNIT LAGS Selec…

4) Choose the menu L2 FEATURES > Multicast > IGMP Snooping > Port Config to load the following page. Enable IGMP Snooping on port 1/0/2 and port 1/0/4 and enable Fast Leave on port 1/0/2.

Figure 9-17 Configure IGMP Snooping on PortsPort Config UNIT1 LAGS Port IGMP Snooping Fast Leave LAG Gi1/0/1 Enabled Disabled -- Gi1/0/2 Enabled Enabled -- Gi1/0/3 Enabled Disabled -- Gi1/0/4 Enabled Disabled -- Gi1/0/5 Enabled Disabled -- Gi1/0/6 Enabled Disabled -- Gi1/0/7 Enabled Disabled -- Gi1/0/8 Enabled Disabled -- Gi1/0/9 Enabled Disa…

5) Click Save the settings.

9.3.4 Using the CLI

1) Enable IGMP Snooping and MLD Snooping globally.

Switch#configure

Switch(config)#ip igmp snooping

Switch(config)#ipv6 mld snooping

2) Configure Unknown Multicast Groups as Discard globally.

Switch(config)#ip igmp snooping drop-unknown

3) Enable IGMP Snooping on port 1/0/2 and enable Fast Leave. On port 1/0/4, enable IGMP Snooping.

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)#ip igmp snooping

Switch(config-if)#ip igmp snooping immediate-leave

Switch(config-if)#exit

Switch(config)#interface gigabitEthernet 1/0/4

Switch(config-if)#ip igmp snooping

Switch(config-if)#exit

4) Enable IGMP Snooping in VLAN 10.

Switch(config)#ip igmp snooping vlan-config 10

5) Save the settings.

Switch(config)#end

Switch#copy running-config startup-config

Verify the Configurations

Show global settings of IGMP Snooping:

Switch(config)#show ip igmp snooping

IGMP Snooping :Enable

IGMP Version: V3

Unknown Multicast: Discard

...

Enable Port: Gi1/0/1-28

Enable VLAN: 10

Show settings of IGMP Snooping on port 1/0/2:

Switch(config)#show ip igmp snooping interface gigabitEthernet 1/0/2 basic-config

Port IGMP-Snooping Fast-Leave

Gi1/0/2 enable enable

9.4 Example for Configuring Multicast Filtering

9.4.1 Network Requirements

Host B, Host C and Host D are in the same subnet. Host C and Host D only receive multicast data sent to 225.0.0.1, while Host B receives all multicast data except the one sent from 225.0.0.2.

9.4.2 Configuration Scheme

With the functions for managing multicast groups, whitelist and blacklist mechanism (profile binding), the switch can only allow specific member ports to join specific multicast groups or disallow specific member ports to join specific multicast groups. You can achieve this filtering function by creating a profile and binding it to the corresponding member port.

9.4.3 Network Topology

As shown in the following network topology, Host B is connected to port 1/0/1, Host C is connected to port 1/0/2, and Host D is connected to port 1/0/3. They are all in VLAN 10.

Figure 9-18 Network Topology for Multicast Filteringgraph TD A["Source"] --> B["Internet"] B --> C["Querier"] C --> D["Gi1/0/4"] C --> E["Gi1/0/3"] D --> F["VLAN 10"] E --> G["Host B Receiver"] E --> H["Host C Receiver"] E --> I["Host D Receiver"]

Demonstrated with S6500-24GP4XF, this section provides configuration procedures in two ways: using the GUI and using the CLI.

9.4.4 Using the GUI

1) Create VLAN 10. Add ports 1/0/1-3 to the VLAN as untagged ports and port 1/0/4 as a tagged port. Configure the PVID of the four ports as 10. For details, refer to Configuring 802.1Q VLAN. 2) Choose the menu L2 FEATURES > Multicast > IGMP Snooping > Global Config to load the following page. In the Global Config section, enable IGMP Snooping globally.

Figure 9-19 Enable IGMP Snooping GloballyGlobal Config IGMP Snooping: ✓ Enable IGMP Version: ○ v1 ○ v2 ○ v3 Unknown Multicast Groups: ● Forward ○ Discard Header Validation: □ Enable Apply IGMP VLAN Config VLAN ID VLAN ID IGMP Snooping Status Fast Leave Report Suppression IGMP Snooping Querier Dynamic Router Ports Static Router Ports Forbid…

3) In the IGMP VLAN Config section, click the checkmark in VLAN 10 to load the following page. Enable IGMP Snooping for VLAN 10.

Figure 9-20 Enable IGMP Snooping for VLAN 10Configure IGMP Snooping for VLAN VLAN ID: 10 IGMP Snooping Status: Enable Fast Leave: Enable Report Suppression: Enable Member Port Aging Time: 260 seconds (60-640) Router Port Aging Time: 300 seconds (60-640) Leave Time: 1 seconds (1-30) IGMP Snooping Querier: Enable Static Router Ports UNIT1 LAGS…

4) Choose the menu L2 FEATURES > Multicast > IGMP Snooping > Port Config to load the following page.

Figure 9-21 Enable IGMP Snooping on the PortPort Config UNIT1 LAGS Port IGMP Snooping Fast Leave LAG ✓ Gi1/0/1 Enabled Disabled --- ✓ Gi1/0/2 Enabled Enabled --- ✓ Gi1/0/3 Enabled Disabled --- ✓ Gi1/0/4 Enabled Disabled --- □ Gi1/0/5 Enabled Disabled --- □ Gi1/0/6 Enabled Disabled --- □ Gi1/0/7 Enabled Disabled --- □ Gi1/0/8 Enabled Disabled…

5) Choose the menu L2 FEATURES > Multicast > Multicast Filtering > IPv4 Profile and click + Add to load the following page. Create Profile 1, specify the mode as Permit, bind the profile to ports 1/0/2-3, and specify the filtering multicast IP address as 225.0.0.1. Then click Back to return to the IPv4 Profile Table page.

Figure 9-22 Configure Filtering Profile for Host C and Host DGeneral Config Profile ID: 1 (1-009) Mode: Permit Deny IP-Range Index Start IP Address End IP Address Operation 0 225.0.0.1 225.0.0.1 Total: 0 Bind Ports UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 37 39 41 43 45 47 49 51 53 38 40 42…

6) Click + Add again to load the following page. Create Profile 2, specify the mode as Deny, bind the profile to port 1/0/1, and specify the filtering multicast IP address as 225.0.0.2.

Figure 9-23 Configure Filtering Profile for Host BGeneral Config Profile ID: 2 (1-999) Mode: Permit Deny IP-Range Index Start IP Address End IP Address Operation 0 225.0.0.2 225.0.0.2 Total: 0 Bind Ports UNIT1 LAGS 1 Selected Unselected Not Available 37 39 41 43 45 47 49 51 53 38 40 42 44 46 48 50 52 54 Discard Save

7) Click Save the settings.

9.4.5 Using the CLI

1) Create VLAN 10.

Switch#configure

Switch(config)#vlan 10

Switch(config-vlan)#name vlan10

Switch(config-vlan)#exit

2) Add port 1/0/1-3 to VLAN 10 and set the link type as untagged. Add port 1/0/4 to VLAN 10 and set the link type as tagged.

Switch(config)#interface range gigabitEthernet 1/0/1-3

Switch(config-if-range)#switchport general allowed vlan 10 untagged

Switch(config-if-range)#exit

Switch(config)#interface gigabitEthernet 1/0/4

Switch(config-if)#switchport general allowed vlan 10 tagged

Switch(config-if)#exit

3) Set the PVID of port 1/0/1-4 as 10.

Switch(config)#interface range gigabitEthernet 1/0/1-4

Switch(config-if-range)#switchport pvid 10

Switch(config-if-range)#exit

4) Enable IGMP Snooping Globally.

Switch(config)#ip igmp snooping

5) Enable IGMP Snooping in VLAN 10.

Switch(config)#ip igmp snooping vlan-config 10

6) Enable IGMP Snooping on port 1/0/1-4.

Switch(config)#interface range gigabitEthernet 1/0/1-4

Switch(config-if-range)#ip igmp snooping

Switch(config-if-range)#exit

7) Create Profile 1, configure the mode as permit, and add an IP range with both start IP and end IP being 225.0.0.1.

Switch(config)#ip igmp profile 1

Switch(config-igmp-profile)#permit

Switch(config-igmp-profile)#range 225.0.0.1 225.0.0.1

Switch(config-igmp-profile)#exit

8) Bind Profile 1 to Port 1/0/2 and Port 1/10/3.

Switch(config)#interface range gigabitEthernet 1/0/2-3

Switch(config-if-range)#ip igmp filter 1

Switch(config-if-range)#exit

9) Create Profile 2, configure the mode as deny, and add an IP range with both start IP and end IP being 225.0.0.2.

Switch(config)#ip igmp profile 2

Switch(config-igmp-profile)#deny

Switch(config-igmp-profile)#range 225.0.0.2 225.0.0.2

Switch(config-igmp-profile)#exit

10) Bind Profile 2 to Port 1/0/1.

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#ip igmp filter 2

Switch(config-if)#exit

11) Save the settings.

Switch(config)#end

Switch#copy running-config startup-config

Verify the Configurations

Show global settings of IGMP Snooping:

Switch(config)#show ip igmp snooping

IGMP

Snooping

:Enable

IGMP

Version

:V3

...

Enable Port:Gi1/0/1-4

Enable VLAN:10

Show all profile bindings:

Switch(config)#show ip igmp profile

IGMP Profile 1

permit

range 225.0.0.1 225.0.0.1

Binding Port(s)

Gi1/0/2-3

IGMP Profile 2

deny

range 225.0.0.2 225.0.0.2

Binding Port(s)

Gi1/0/1

10 Appendix: Default Parameters

10.1 Default Parameters for IGMP Snooping

Table 10-1 Default Parameters of IGMP Snooping

Function Parameter Default Setting
Global Settings of IGMP SnoopingIGMP Snooping Disabled
IGMP Version v3
Unknown Multicast Groups Forward
Header Validation Disabled
IGMP Snooping Settings in the VLANIGMP Snooping Disabled
Fast Leave Disabled
Report Suppression Disabled
Member Port Aging Time 260 seconds
Router Port Aging Time 300 seconds
Leave Time 1 second
IGMP Snooping QuerierDisabled
Query Interval60 seconds
Maximum Response Time10 seconds
Last Member Query Interval1 second
Last Member Query Count2
General Query Source IP0.0.0.0
Static Router PortsNone
Forbidden Router PortsNone
IGMP Snooping Settings on the Port and LAGIGMP Snooping Enabled
Fast Leave Disabled
Static Multicast Group SettingsStatic Multicast Group EntriesNone
IGMP Accounting and AuthenticationIGMP Accounting Disabled
IGMP Authentication Disabled

10.2 Default Parameters for MLD Snooping

Table 10-2 Default Parameters of MLD Snooping

Function Parameter Default Setting
Global Settings of IGMP SnoopingMLD Snooping Disabled
Unknown Multicast Groups Forward
MLD Snooping Settings in the VLANMLD Snooping Disabled
Fast Leave Disabled
Report Suppression Disabled
Member Port Aging Time 260 seconds
Router Port Aging Time 300 seconds
Leave Time1 second
MLD Snooping QuerierDisabled
Query Interval60 seconds
Maximum Response Time10 seconds
Last Listener Query Interval1 second
Last Listener Query Count2
General Query Source IP::
Static Router PortsNone
Forbidden Router PortsNone
MLD Snooping Settings on the Port and LAGMLD Snooping Enabled
Fast Leave Disabled
Static Multicast Group SettingsStatic Multicast Group EntriesNone

10.3 Default Parameters for MVR

Table 10-3 Default Parameters of MVR

Function Parameter Default Setting
Global Settings of MVRMVR Disabled
MVR Mode Compatible
Multicast VLAN ID 1
Query Response Time 5 tenths of a second
Maximum Multicast Groups 511
MVR Group Settings MVR Group Entries None
MVR Settings on the PortMVR Mode Disabled
MVR Port Type None
Fast Leave Disabled
MVR Static Group Members MVR Static Group Member Entries None

10.4 Default Parameters for Multicast Filtering

Table 10-4 Default Parameters of Multicast Filtering

FunctionParameter Default Setting
Profile SettingsIPv4 Profile and IPv6 Profile EntriesNone
Multicast Filtering Settings on the Port and LAGBound ProfileNone
Maximum Groups4093
Overflow ActionDrop

10.5 Default Parameters for PIM

Table 10-5 Default Parameters of PIM

FunctionParameter Default Setting
IP PIM DR-PriorityPri1
IP PIM Join-Prune-IntervalInterval60
Function Parameter Default Setting
IP PIM Hello-Interval Interval 30

10.6 Default Parameters for Static Multicast-Routing

Table 10-6 Default Parameters of Static Multicast-Routing

Function Parameter Default Setting
IP Mroute distance 0

10.7 Default Parameters for Layer 3 IGMP

Table 10-7 Default Parameters of Layer 3 IGMP

Function Parameter Default Setting
ip igmp version 1 | 2 | 3 3
ip igmp last-member-query-count countcount 2
ip igmp last-member-query-intervalinterval 10
ip igmp query-interval interval 125
ip igmp query-max-response-timetime 100
ip igmp robustnessrobustness2
ip igmp startup-query-intervalinterval 31
ip igmp last-member-query-countcount 2

Part 15

Configuring

Spanning Tree

CHAPTERS

  1. Spanning Tree
  2. STP/RSTP Configurations
  3. MSTP Configurations
  4. STP Security Configurations
  5. Configuration Example for MSTP
  6. Appendix: Default Parameters

1 Spanning Tree

1.1 Overview

STP

STP (Spanning Tree Protocol) is a layer 2 protocol that prevents loops in the network. As shown in Figure 1-1, STP helps to:

■ Block specific ports of the switches to build a loop-free topology. ■ Detect topology changes and automatically generate a new loop-free topology.

Figure 1-1 STP Functiongraph TD A["Switch"] --> B["Switch"] B --> C["Switch"] C --> D["Switch"] D --> E["Switch"] F["STP"] --> G["Switch"] G --> H["Switch"] H --> I["Switch"] I --> J["Switch"] style F stroke:#000,stroke-width:2px style G stroke:#000,stroke-width:2px style H stroke:#000,stroke-width:2px style I stroke:#000…

RSTP

RSTP (Rapid Spanning Tree Protocol) provides the same features as STP. Besides, RSTP can provide much faster spanning tree convergence.

MSTP

MSTP (Multiple Spanning Tree Protocol) also provides the fast spanning tree convergence as RSTP. In addition, MSTP enables VLANs to be mapped to different spanning trees (MST instances), and traffic in different VLANs will be transmitted along their respective paths, implementing load balancing.

1.2 Basic Concepts

1.2.1 STP/RSTP Concepts

Based on the networking topology below, this section will introduce some basic concepts in STP/RSTP.

Figure 1-2 STP/RSTP Topologygraph TD A["Root bridge"] -->|Designated port| B["Root port"] A -->|Designated port| C["Root port"] B -->|Designated port| D["Root port"] C -->|Designated port| E["Root port"] D -->|Backup port| F["Alternate port"] E -->|Alternate port| F

Root Bridge

The root bridge is the root of a spanning tree. The switch with the lowest bridge ID will be the root bridge, and there is only one root bridge in a spanning tree.

Bridge ID

Bridge ID is used to select the root bridge. It is composed of a 2-byte priority and a 6-byte MAC address. The priority is allowed to be configured manually on the switch, and the switch with the lowest priority value will be elected as the root bridge. If the priority of the switches is the same, the switch with the smallest MAC address will be selected as the root bridge.

Port Role

■ Root Port

The root port is selected on non-root bridge that can provide the lowest root path cost. There is only one root port in each non-root bridge.

■ Designated Port

The designated port is selected in each LAN segment that can provide the lowest root path cost from that LAN segment to the root bridge.

Alternate Port

If a port is not selected as the designated port for it receives better BPDUs from another switch, it will become an alternate port.

In RSTP/MSTP, the alternate port is the backup for the root port. It is blocked when the root port works normally. Once the root port fails, the alternate port will become the new root port.

In STP, the alternate port is always blocked.

■ Backup Port

If a port is not selected as the designated port because it receives better BPDUs from the switch it belongs to, it will become a backup port.

In RSTP/MSTP, the backup port is the backup for the designated port. It is blocked when the designated port works normally. Once the root port fails, the backup port will become the new designated port.

In STP, the backup port is always blocked.

■ Disable Port

The disconnected port with spanning tree function enabled.

Port Status

Generally, in STP, the port status includes: Blocking, Listening, Learning, Forwarding and Disabled.

■ Blocking

In this status, the port receives and sends BPDUs. The other packets are dropped.

■ Listening

In this status, the port receives and sends BPDUs. The other packets are dropped.

■ Learning

In this status, the port receives and sends BPDUs. It also receives other user packets to update its MAC address table, but does not forward them.

Forwarding

In this status, the port receives and sends BPDUs. It also receives other user packets to update its MAC address table, and forwards them.

■ Disabled

In this status, the port is not participating in the spanning tree, and drops all the packets it receives.

In RSTP/MSTP, the port status includes: Discarding, Learning, and Forwarding. The Discarding status is the grouping of STP's Blocking, Listening, and Disabled, and the

Learning and Forwarding status correspond exactly to the Learning and Forwarding status specified in STP.

In TP-Link switches, the port status includes: Blocking, Learning, Forwarding, and Disconnected.

■ Blocking

In this status, the port receives and sends BPDUs. Other packets are dropped.

■ Learning

In this status, the port receives and sends BPDUs. It also receives other user packets to update its MAC address table, but does not forward them.

Forwarding

In this status, the port receives and sends BPDUs. It also receives other user packets to update its MAC address table, and forwards them.

■ Disconnected

In this status, the port is enabled with spanning tree function but not connected to any device.

Path Cost

The path cost reflects the link speed of the port. The smaller the value, the higher link speed the port has.

The path cost can be manually configured on each port. If not, the path cost values are automatically calculated according to the link speed as shown below:

Table 1-1 The Default Path Cost Value

Link Speed Path Cost Value
10Mb/s 2,000,000
100Mb/s 200,000
1Gb/s 20,000
10Gb/s 2,000

Root Path Cost

The root path cost is the accumulated path costs from the root bridge to the other switches. When root bridge sends its BPDU, the root path cost value is 0. When a switch receives this BPDU, the root path cost will be increased according to the path cost of the receive port. Then it creates a new BPDU with the new root path cost and forwards it to the

downstream switch. The value of the accumulated root path cost increases as the BPDU spreads further.

BPDU

BPDU is a kind of packet that is used to generate and maintain the spanning tree. The BPDUs (Bridge Protocol Data Unit) contain a lot of information, like bridge ID, root path cost, port priority and so on. Switches share these information to help determine the spanning tree topology.

1.2.2 MSTP Concepts

MSTP, compatible with STP and RSTP, has the same basic elements used in STP and RSTP. Based on the networking topology, this section will introduce some concepts only used in MSTP.

Figure 1-3 MSTP Topologygraph TD subgraph Region 1 A["region 1"] --> B["region 2"] B --> C["region 3"] C --> D["region 4"] D --> E["region 4"] style A fill:#f9f,stroke:#333 style B fill:#bbf,stroke:#333 style C fill:#bbf,stroke:#333 style D fill:#bbf,stroke:#333 style E fill:#bbf,stroke:#333 end Note: Red 'x' marks the blo…

MST Region

An MST region consists of multiple interconnected switches. The switches with the same following characteristics are considered as in the same region:

■ Same region name ■ Same revision level ■ Same VLAN-Instance mapping

MST Instance

The MST instance is a spanning tree running in the MST region. Multiple MST instances can be established in one MST region and they are independent of each other. As is shown in Figure 1-4, there are three instances in a region, and each instance has its own root bridge.

Figure 1-4 MST Regiongraph TD A["Router A"] -->|Instance 1 (root bridge: A) VLAN 3| B["Router B"] A -->|Instance 2 (root bridge: B) VLAN 4-5| C["Router C"] B -->|Blocked port| A C -->|Other VLANs| A style A fill:#f9f,stroke:#333 style B fill:#bbf,stroke:#333 style C fill:#bfb,stroke:#333

VLAN-Instance Mapping

VLAN-Instance Mapping describes the mapping relationship between VLANs and instances. Multiple VLANs can be mapped to a same instance, but one VLAN can be mapped to only one instance. As Figure 1-4 shows, VLAN 3 is mapped to instance 1, VLAN 4 and VLAN 5 are mapped to instance 2, the other VLANs are mapped to the IST.

IST

The Internal Spanning Tree (IST), which is a special MST instance with an instance ID 0. By default, all the VLANs are mapped to IST.

CST

The Common Spanning Tree (CST), that is the spanning tree connecting all MST regions. As is shown in Figure 1-3, region1-region 4 are connected by the CST.

CIST

The Common and Internal Spanning Tree (CIST), comprising IST and CST. CIST is the spanning tree that connects all the switches in the network.

1.3 STP Security

STP Security prevents the loops caused by wrong configurations or BPDU attacks. It contains Loop Protect, Root Protect, BPDU Protect, BPDU Filter and TC Protect functions.

» Loop Protect

Loop Protect function is used to prevent loops caused by link congestions or link failures. It is recommended to enable this function on root ports and alternate ports.

If the switch cannot receive BPDUs because of link congestions or link failures, the root port will become a designated port and the alternate port will transit to forwarding status, so loops will occur.

With Loop Protect function enabled, the port will temporarily transit to blocking state when the port does not receive BPDUs. After the link restores to normal, the port will transit to its normal state, so loops can be prevented.

» Root Protect

Root Protect function is used to ensure that the desired root bridge will not lose its position. It is recommended to enable this function on the designated ports of the root bridge.

Generally, the root bridge will lose its position once receiving higher-priority BPDUs caused by wrong configurations or malicious attacks. In this case, the spanning tree will be regenerated, and traffic needed to be forwarded along high-speed links may be lead to low-speed links.

With root protect function enabled, when the port receives higher-priority BDPUs, it will temporarily transit to blocking state. After two times of forward delay, if the port does not receive any higher-priority BDPUs, it will transit to its normal state.

» BPDU Protect

BPDU Protect function is used to prevent the port from receiving BPUDs. It is recommended to enable this function on edge ports.

Normally edge ports do not receive BPDUs, but if a user maliciously attacks the switch by sending BPDUs, the system automatically configures these ports as non-edge ports and regenerates the spanning tree.

With BPDU protect function enabled, the edge port will be shutdown when it receives BPDUs, and reports these cases to the administrator. Only the administrator can restore it.

» BPDU Filter

BPDU filter function is to prevent BPDU flooding in the network. It is recommended to enable this function on edge ports.

If a switch receives malicious BPDUs, it forwards these BPDUs to the other switches in the network, and the spanning tree will be continuously regenerated. In this case, the switch occupies too much CPU or the protocol status of BPDUs is wrong.

With the BPDU Filter function enabled, the port does not forward BPDUs from the other switches.

» TC Protect

TC Protect function is used to prevent the switch from frequently removing MAC address entries. It is recommended to enable this function on the ports of non-root switches.

A switch removes MAC address entries upon receiving TC-BPDUs (the packets used to announce changes in the network topology). If a user maliciously sends a large number of TC-BPDUs to a switch in a short period, the switch will be busy with removing MAC address entries, which may decrease the performance and stability of the network.

With TC protect function enabled, if the number of the received TC-BPDUs exceeds the maximum number you set in the TC threshold, the switch will not remove MAC address entries in the TC protect cycle.

2 STP/RSTP Configurations

To complete the STP/RSTP configuration, follow these steps:

1) Configure STP/RSTP parameters on ports. 2) Configure STP/RSTP globally. 3) Verify the STP/RSTP configurations.

Configuration Guidelines

■ Before configuring the spanning tree, it's necessary to make clear the role that each switch plays in a spanning tree. ■ To avoid any possible network flapping caused by STP/RSTP parameter changes, it is recommended to enable STP/RSTP function globally after configuring the relevant parameters.

2.1 Using the GUI

2.1.1 Configuring STP/RSTP Parameters on Ports

Choose the menu L2 FEATURES > Spanning Tree > Port Config to load the following page.

Figure 2-1 Configuring STP/RSTP Parameters on Ports

UNIT1LAGS
PortStatusPriorityExt-Path CostInt-Path CostEdge PortP2P LinkMCheckPort ModePort I
1/0/1Disabled128AutoAutoDisabledAuto---
1/0/2Disabled128AutoAutoDisabledAuto---
1/0/3Disabled128AutoAutoDisabledAuto---
1/0/4Disabled128AutoAutoDisabledAuto---
1/0/5Disabled128AutoAutoDisabledAuto---
1/0/6Disabled128AutoAutoDisabledAuto---
1/0/7Disabled128AutoAutoDisabledAuto---
1/0/8Disabled128AutoAutoDisabledAuto---
1/0/9Disabled128AutoAutoDisabledAuto---
1/0/10Disabled128AutoAutoDisabledAuto---

Follow these steps to configure STP/RSTP parameters on ports:

1) In the Port Config section, configure STP/RSTP parameters on ports.

Port Select the desired ports to configure.
Status Enable or disable spanning tree function on the desired port.
Priority Specify the Priority for the desired port. The value should be an integral multiple of 16, ranging from 0 to 240. Ports with lower values have higher priority. When the root path of the port is the same as other ports', the switch will compare the port priorities and select a root port with the highest priority.
Ext-Path CostEnter the value of the external path cost. The valid values are from 0 to 2000000. The default setting is Auto, which means the port calculates the external path cost automatically according to the port's link speed.For STP/RSTP, external path cost indicates the path cost of the port in spanning tree. The Port with the lowest root path cost will be elected as the root port of the switch.For MSTP, external path cost indicates the path cost of the port in CST.
Int-Path CostEnter the value of the internal path cost. The valid values are from 0 to 2000000. The default setting is Auto, which means the port calculates the internal path cost automatically according to the port's link speed. This parameter is only used in MSTP.For MSTP, internal path cost is used to calculate the path cost in IST. The port with the lowest root path cost will be elected as the root port of the switch in IST.
Edge Port Select Enable to set the port as an edge port. When the topology is changed,the edge port can transit its state from blocking to forwarding directly. For the quick generation of the spanning tree, it is recommended to set the ports that are connected to the end devices as edge ports.
P2P Link Select the status of the P2P (Point-to-Point) link to which the ports are connected. During the regeneration of the spanning tree, if the port of P2P link is elected as the root port or the designated port, it can transit its state to forwarding directly.Three options are supported: Auto, Open(Force) and Closed(Force). By default, it is Auto.Auto:The switch automatically checks if the port is connected to a P2P link, then sets the status as Open or Closed.Open(Force): A port is set as the one that is connected to a P2P link. You should check the link first.Close(Force): A port is set as the one that is not connected to a P2P link. You should check the link first.
MCheck Perform MCheck operations on the port. If a port on an RSTP-enabled/MSTP-enabled device is connected to an STP-enabled device, the port will switch to STP compatible mode and send packets in STP format. MCheck is used to switch the mode of the port back to RSTP/MSTP after the port is disconnected from the STP-enabled device. The MCheck function will take effect immediately after clicking Apply. Every time the situation above happens, you need to do the MCheck action manually.

Port Mode Displays the spanning tree mode of the port.

STP: The spanning tree mode of the port is STP.

RSTP: The spanning tree mode of the port is RSTP.

MSTP: The spanning tree mode of the port is MSTP.

Port Role Displays the role that the port plays in the spanning tree.

Root Port: Indicates that the port is the root port in the spanning tree. It has the lowest path cost from the root bridge to this switch and is used to communicate with the root bridge.

Designated Port: Indicates that the port is the designated port in the spanning tree. It has the lowest path cost from the root bridge to this physical network segment and is used to forward data for the corresponding network segment.

Alternate Port: Indicates that the port is the alternate port in the spanning tree. It is the backup of the root port or master port.

Backup Port: Indicates that the port is the backup port in the spanning tree. It is the backup of the designated port.

Master Port: Indicates the port provides the lowest root path cost from the region to the root bridge in CIST. In CIST, each region is regarded as a switch, and the master port is the root port of the corresponding region.

Disabled: Indicates that the port is not participating in the spanning tree.

Port Status Displays the port status.

Forwarding: The port receives and sends BPDUs, and forwards user traffic.

Learning: The port receives and sends BPDUs. It also receives user traffic, but doesn't forward the traffic.

Blocking: The port only receives and sends BPDUs.

Disconnected: The port is enabled with spanning tree function but not connected to any device.

LAG Displays the LAG the port belongs to.

2) Click Apply.

2.1.2 Configuring STP/RSTP Globally

Choose the menu L2 FEATURES > Spanning Tree > STP Config > STP Config to load the following page.

Figure 2-2 Configuring STP/RSTP GloballyGlobal Config Spanning Tree: ✓ Enable Mode: STP Parameters Config CIST Priority: 32768 (0-61440, in increments of 4096) Hello Time: 2 seconds (1-10) Max Age: 20 seconds (6-40) Forward Delay: 15 seconds (4-30) Tx Hold Count: 5 pps (1-20) Max Hops: 20 hop (1-40) Apply Apply

Follow these steps to configure STP/RSTP globally:

1) In the Parameters Config section, configure the global parameters of STP/RSTP and click Apply.

CIST PrioritySpecify the CIST priority for the switch. CIST priority is a parameter used to determine the root bridge for spanning tree. The switch with the lower value has the higher priority.In STP/RSTP, CIST priority is the priority of the switch in spanning tree. The switch with the highest priority will be elected as the root bridge.In MSTP, CISP priority is the priority of the switch in CIST. The switch with the higher priority will be elected as the root bridge in CIST.
Hello Time Specify the interval between BPDUs' sending. The default value is 2.The root bridge sends configuration BPDUs at an interval of Hello Time. It works with the MAX Age to test the link failures and maintain the spanning tree.
Max Age Specify the maximum time that the switch can wait without receiving a BPDU before attempting to regenerate a new spanning tree. The default value is 20.
Forward Delay Specify the interval between the port state transition from listening to learning. The default value is 15. It is used to prevent the network from causing temporary loops during the regeneration of spanning tree. The interval between the port state transition from learning to forwarding is also the Forward Delay.
Tx Hold Count Specify the maximum number of BPDU that can be sent in a second. The default value is 5.

Max Hops Specify the maximum BPDU counts that can be forwarded in a MST region.

The default value is 20. A switch receives BPDU, then decrements the hop count by one and generates BPDUs with the new value. When the hop reaches zero, the switch will discard the BPDU. This value can control the scale of the spanning tree in the MST region.

Note: Max Hops is a parameter configured in MSTP. You need not configure it if the spanning tree mode is STP/RSTP.

TP-LINK Omada Pro S5500-24GP4F - Configuring STP/RSTP Globally - 2

Note:

To prevent frequent network flapping, make sure that Hello Time, Forward Delay, and Max Age conform to the following formulas:

• 2*(Hello Time + 1) <= Max Age • 2*(Forward Delay - 1) >= Max Age

2) In the Global Config section, enable spanning tree function, choose the STP mode as STP/RSTP, and click Apply.

Spanning Tree Enable or disable the spanning tree function globally.

Mode Select the desired spanning tree mode as STP/RSTP on the switch. By default, it's STP.

STP: Set the spanning tree mode as STP. It is the basic spanning tree protocol based on IEEE 802.1d.

RSTP: Set the spanning tree mode as RSTP. RSTP has the same function as STP, but it can speed up the spanning tree convergence.

MSTP: Set the spanning tree mode as MSTP. MSTP can work with VLANs and implement load balancing.

2.1.3 Verifying the STP/RSTP Configurations

Verify the STP/RSTP information of your switch after all the configurations are finished.

Choose the menu L2 FEATURES > Spanning Tree > STP Config > STP Summary to load the following page.

Figure 2-3 Verifying the STP/RSTP Configurations

STP Summary
Spanning Tree:Enable
Spanning Tree Mode:STP
Local Bridge:32768-5c-e9-31-50-a6-34
Root Bridge32768-5c-e9-31-50-a6-34
External Path Cost:0
Regional Root Bridge:
Internal Path Cost
Designated Bridge:32768-5c-e9-31-50-a6-34
Root Port:
Latest TC Time:2006-01-01 08:01:45
TC Count:0
MSTP Instance Summary
Instance ID:1▼
Instance Status:Disable
Local Bridge:
Regional Root Bridge:
Internal Path Cost
Designated Bridge:
Root Port:
Latest TC Time:
TC Count:

The STP Summary section shows the summary information of spanning tree :

Spanning Tree Displays the status of the spanning tree function.
Spanning Tree Mode Displays the spanning tree mode.
Local BridgeDisplays the bridge ID of the local bridge. The local bridge is the current switch.
Root Bridge Displays the bridge ID of the root bridge.
External Path Cost Displays the root path cost from the switch to the root bridge.
Regional Root BridgeIt is the root bridge of IST. It is not displayed when you choose the spanning tree mode as STP/RSTP.
Internal Path CostThe internal path cost is the root path cost from the switch to the root bridge of IST. It is not displayed when you choose the spanning tree mode as STP/RSTP.
Designated BridgeDisplays the bridge ID of the designated bridge. The designated bridge is the switch that has designated ports.
Root Port Displays the root port of the current switch.
Latest TC Time Displays the latest time when the topology is changed.
TC Count Displays how many times the topology has changed.

2.2 Using the CLI

2.2.1 Configuring STP/RSTP Parameters on Ports

Follow these steps to configure STP/RSTP parameters on ports:

Step 1 configure

Enter global configuration mode.

Step 2: interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 3: spanning-tree

Enable spanning tree function for desired ports.

Step 4: spanning-tree common-config [ port-priority pri ] [ ext-cost ext-cost ] [ portfast { enable | disable }] [ point-to-point { auto | open | close }]

Configure STP/RSTP parameters on the desired port.

pri: Specify the priority for the desired port. The value should be an integral multiple of 16, ranging from 0 to 240. The default value is 128. Ports with lower values have higher priority. When the root path of the port is the same as other ports', the switch will compare the port priorities and select a root port with the highest priority.

ext-cost: Specify the value of the external path cost. The valid values are from 0 to 2000000 and the default setting is Auto, which means the port calculates the external path cost automatically according to the port's link speed.

For STP/RSTP, external path cost indicates the path cost of the port in spanning tree. The port with the lowest root path cost will be elected as the root port of the switch.

For MSTP, external path cost indicates the path cost of the port in CST.

portfast { enable | disable }: Enable to set the port as an edge port. By default, it is disabled. When the topology is changed, the edge port can transit its state from blocking to forwarding directly. For the quick generation of the spanning tree, it is recommended to set the ports that are connected to the end devices as edge ports.

point-to-point { auto | open | close }: Select the status of the P2P (Point-to-Point) link to which the ports are connected. During the regeneration of the spanning tree, if the port of P2P link is elected as the root port or the designated port, it can transit its state to forwarding directly. Auto indicates that the switch automatically checks if the port is connected to a P2P link, then sets the status as Open or Closed. Open is used to set the port as the one that is connected to a P2P link. Close is used to set the port as the one that is not connected to a P2P link.

Step 5: spanning-tree mcheck

(Optional) Perform MCheck operations on the port.

If a port on an RSTP-enabled/MSTP-enabled device is connected to an STP-enabled device, the port will switch to STP compatible mode and send packets in STP format. MCheck is used to switch the mode of the port back to RSTP/MSTP after the port is disconnected from the STP-enabled device. The MCheck configuration can take effect only once, after that the MCheck status of the port will switch to Disabled.

Step 6 show spanning-tree interface [fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel lagid] [edge | ext-cost | int-cost | mode | p2p | priority | role | state | status]

(Optional) View the information of all ports or a specified port.

port: Specify the port number.

lagid: Specify the ID of the LAG.

ext-cost | int-cost | mode | p2p | priority | role | state | status: Display the specified information.

Step 7 end

Return to privileged EXEC mode.

Step 8 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable spanning tree function on port 1/0/3 and configure the port priority as 32 :

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/3

Switch(config-if)#spanning-tree

Switch(config-if)#spanning-tree common-config port-priority 32

Switch(config-if)#show spanning-tree interface gigabitEthernet 1/0/3

Interface State Prio Ext-Cost Int-Cost Edge P2p Mode


Gi1/0/3 Enable 32 Auto Auto No No(auto) N/A

Role Status LAG


N/A LnkDwn N/A

Switch(config-if)#end

Switch#copy running-config startup-config

2.2.2 Configuring Global STP/RSTP Parameters

Follow these steps to configure global STP/RSTP parameters of the switch:

Step 1 configure

Enter global configuration mode.

Step 2 spanning-tree priority pri

Configure the priority of the switch.

pri: Specify the priority for the switch. The valid value is from 0 to 61440, which are divisible by 4096. The priority is a parameter used to determine the root bridge for spanning tree. The switch with the lower value has the higher priority.

In STP/RSTP, the value is the priority of the switch in spanning tree. The switch with the highest priority will be elected as the root bridge.

In MSTP, the value is the priority of the switch in CIST. The switch with the higher priority will be elected as the root bridge in CIST.

Step 3 spanning-tree timer {[ forward-time forward-time] [hello-time hello-time] [max-age max-age]}

(Optional) Configure the Forward Delay, Hello Time and Max Age.

forward-time: Specify the value of Forward Delay. It is the interval between the port state transition from listening to learning. The valid values are from 4 to 30 in seconds, and the default value is 15. Forward Delay is used to prevent the network from causing temporary loops during the regeneration of spanning tree. The interval between the port state transition from learning to forwarding is also the Forward Delay.

hello-time: Specify the value of Hello Time. It is the interval between BPDUs' sending. The valid values are from 1 to 10 in seconds, and the default value is 2. The root bridge sends configuration BPDUs at an interval of Hello Time. It works with the MAX Age to test the link failures and maintain the spanning tree.

max-age: Specify the value of Max Age. It is the maximum time that the switch can wait without receiving a BPDU before attempting to regenerate a new spanning tree. The valid values are from 6 to 40 in seconds, and the default value is 20.

Step 4 spanning-tree hold-count value

Specify the maximum number of BPDU that can be sent in a second.

value: Specify the maximum number of BPDU packets that can be sent in a second. The valid values are from 1 to 20 pps, and the default value is 5.

Step 5 show spanning-tree bridge

(Optional) View the global STP/RSTP parameters of the switch.

Step 6 end

Return to privileged EXEC mode.

Step 7 copy running-config startup-config

Save the settings in the configuration file.

TP-LINK Omada Pro S5500-24GP4F - Step 7 copy running-config startup-config - 1

Note:

To prevent frequent network flapping, make sure that Hello Time, Forward Delay, and Max Age conform to the following formulas:

• 2*(Hello Time + 1) <= Max Age • 2*(Forward Delay - 1) >= Max Age

This example shows how to configure the priority of the switch as 36864, the Forward Delay as 12 seconds:

Switch#configure

Switch(config)#spanning-tree priority 36864

Switch(config)#spanning-tree timer forward-time 12

Switch(config)#show spanning-tree bridge

StateModePriorityHello-TimeFwd-TimeMax-AgeHold-CountMax-Hops
--------------------------------
EnableRstp3686421220520

Switch(config)#end

Switch#copy running-config startup-config

2.2.3 Enabling STP/RSTP Globally

Follow these steps to configure the spanning tree mode as STP/RSTP, and enable spanning tree function globally:

Step 1 configure

Enter global configuration mode.

Step 2 spanning-tree mode {stp | rstp}

Configure the spanning tree mode as STP/RSTP.

stp: Specify the spanning tree mode as STP.

rstp: Specify the spanning tree mode as RSTP.

Step 3 spanning-tree

Enable spanning tree function globally.

Step 4 show spanning-tree active

(Optional) View the active information of STP/RSTP.

Step 5 end

Return to privileged EXEC mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

This example shows how to enable spanning tree function, configure the spanning tree mode as RSTP and verify the configurations:

Switch#configure

Switch(config)#spanning-tree mode rstp

Switch(config)#spanning-tree

Switch(config)#show spanning-tree active

Spanning tree is enabled

Spanning-tree's mode: RSTP (802.1w Rapid Spanning Tree Protocol)

Latest topology change time: 2006-01-02 10:04:02

Root Bridge

Priority : 32768

Address : 00-0a-eb-13-12-ba

Local bridge is the root bridge

Designated Bridge

Priority : 32768

Address : 00-0a-eb-13-12-ba

Local Bridge

Priority : 32768

Address : 00-0a-eb-13-12-ba

Interface State Prio Ext-Cost Int-Cost Edge P2p Mode


Gi1/0/16 Enable 128 200000 200000 No Yes(auto) Rstp

Gi1/0/18 Enable 128 200000 200000 No Yes(auto) Rstp

Gi1/0/20 Enable 128 200000 200000 No Yes(auto) Rstp

Role Status LAG

Desg Fwd N/A

Desg Fwd N/A

Desg Fwd N/A

Switch(config)#end

Switch#copy running-config startup-config

3 MSTP Configurations

To complete the MSTP configuration, follow these steps:

1) Configure parameters on ports in CIST. 2) Configure the MSTP region. 3) Configure the MSTP globally. 4) Verify the MSTP configurations.

Configuration Guidelines

■ Before configuring the spanning tree, it's necessary to make clear the role that each switch plays in a spanning tree. ■ To avoid any possible network flapping caused by MSTP parameter changes, it is recommended to enable MSTP function globally after configuring the relevant parameter.

3.1 Using the GUI

3.1.1 Configuring Parameters on Ports in CIST

Choose the menu L2 FEATURES > Spanning Tree > Port Config to load the following page.

Figure 3-1 Configuring the Parameters of the Ports

UNIT1LAGS
PortStatusPriorityExt-Path CostInt-Path CostEdge PortP2P LinkMCheckPort ModePort I
1/0/1Disabled128AutoAutoDisabledAuto------
1/0/2Disabled128AutoAutoDisabledAuto------
1/0/3Disabled128AutoAutoDisabledAuto------
1/0/4Disabled128AutoAutoDisabledAuto------
1/0/5Disabled128AutoAutoDisabledAuto------
1/0/6Disabled128AutoAutoDisabledAuto------
1/0/7Disabled128AutoAutoDisabledAuto------
1/0/8Disabled128AutoAutoDisabledAuto------
1/0/9Disabled128AutoAutoDisabledAuto------
1/0/10Disabled128AutoAutoDisabledAuto----

Follow these steps to configure parameters on ports in CIST:

1) In the Port Config section, configure the parameters on ports.

Port Select the desired ports to configure.
Status Enable or disable spanning tree function on the desired port.
Priority Specify the Priority for the desired port. The value should be an integral multiple of 16, ranging from 0 to 240. Ports with lower values have higher priority. When the root path of the port is the same as other ports', the switch will compare the port priorities and select a root port with the highest priority.
Ext-Path CostEnter the value of the external path cost. The default setting is Auto, which means the port calculates the external path cost automatically according to the port's link speed.For STP/RSTP, external path cost indicates the path cost of the port in spanning tree. The port with the lowest root path cost will be elected as the root port of the switch.For MSTP, external path cost indicates the path cost of the port in CST.
Int-Path CostEnter the value of the internal path cost. The valid values are from 0 to 2000000. The default setting is Auto, which means the port calculates the internal path cost automatically according to the port's link speed. This parameter is only used in MSTP and you need not to configure it if the spanning tree mode is STP/RSTP.For MSTP, internal path cost is used to calculate the path cost in IST. The port with the lowest root path cost will be elected as the root port of the switch in IST.
Edge Port Select Enable to set the port as an edge port. When the topology is changed, the edge port can transit its state from blocking to forwarding directly. For the quick generation of the spanning tree, it is recommended to set the ports that are connected to the end devices as edge ports.
P2P Link Select the status of the P2P (Point-to-Point) link to which the ports are connected. During the regeneration of the spanning tree, if the port of P2P link is elected as the root port or the designated port, it can transit its state to forwarding directly.Three options are supported: Auto, Open(Force) and Closed(Force). By default, it is Auto.Auto:The switch automatically checks if the port is connected to a P2P link, then sets the status as Open or Closed.Open(Force): A port is set as the one that is connected to a P2P link. You should check the link first.Close(Force): A port is set as the one that is not connected to a P2P link. You should check the link first.

MCheck Perform MCheck operations on the port. If a port on an RSTP-enabled/

When an MSTP-enabled device is connected to an STP-enabled device, the port will switch to STP-compatible mode and send packets in STP format. MCheck is used to switch the port mode back to RSTP/MSTP after the port is disconnected from the STP-enabled device. The MCheck function takes effect immediately after clicking Apply. Every time the above situation occurs, you need to perform the MCheck action manually.

STP: The spanning tree mode of the port is STP.

RSTP: The spanning tree mode of the port is RSTP.

MSTP: The spanning tree mode of the port is MSTP.

Port Role Displays the role that the port plays in the spanning tree.

Port Role Displays the role that the port plays in the spanning tree.

Designated Port: Indicates that the port is the designated port in the spanning tree. It has the lowest path cost from the root bridge to this physical network segment and is used to forward data for the corresponding network segment.

Alternate Port: Indicates that the port is the alternate port in the spanning tree. It is the backup of the root port or master port.

Backup Port: Indicates that the port is the backup port in the spanning tree. It is the backup of the designated port.

Backup Port: Indicates that the port is the backup port in the spanning tree. It is the backup of the designated port.

Master Port: Indicates the port provides the lowest root path cost from the region to the root bridge in CIST. In CIST, each region is regarded as a switch, and the master port is the root port of the corresponding region.

Disabled: Indicates that the port is not participating in the spanning tree.

Port Status: Displays the port status.

Forwarding: The port receives and sends BPDUs, and forwards user traffic.

Learning: The port receives and sends BPDUs. It also receives user traffic, but doesn't forward the traffic.

Blocking: The port only receives and sends BPDUs.

Disconnected: The port has the spanning tree function enabled but is not connected to any device.

LAG: Displays the LAG that the port belongs to.

2) Click Apply.

3.1.2 Configuring the MSTP Region

Configure the region name, revision level, and VLAN-Instance mapping of the switch. The switches with the same region name, the same revision level, and the same VLAN-Instance mapping are considered as in the same region.

Besides, configure the priority of the switch, the priority and path cost of ports in the desired instance.

■ Configuring the Region Name and Revision Level

Choose the menu L2 FEATURES > Spanning Tree > MSTP Instance > Region Config to load the following page.

Figure 3-2 Configuring the RegionRegion Config Region Name: 5c-e9-31-50-a6-34 Revision: 0 (0-65535) Apply

Follow these steps to create an MST region:

1) In the Region Config section, set the name and revision level to specify an MSTP region.

Region Name Specify the name for an MST region. It contains 32 characters at most. By default, it is the MAC address of the switch.

Revision Enter the revision level number. By default, it is 0.

2) Click Apply.

■ Configuring the VLAN-Instance Mapping and Switch Priority

Choose the menu L2 FEATURES > Spanning Tree > MSTP Instance > Instance Config to load the following page.

Figure 3-3 Configuring the VLAN-Instance MappingInstance Config + Add Delete Instance ID Priority VLAN ID Operation CIST 36864 1-4094. Total: 1

Follow these steps to map VLANs to the corresponding instance, and configure the priority of the switch in the desired instance:

1) In the Instance Config section, click Add and enter the instance ID, Priority and corresponding VLAN ID.

Figure 3-4 Configuring the InstanceInstance Config Instance ID: (1-8) Priority: (0-61440, in increments of 4096) VLAN ID: Add Delete (1-4094, format 1,3,4-7,11-30) Cancel Create

Instance ID Enter the ID number for the instance.

Priority Specify the priority for the switch in the corresponding instance. The value should be an integral multiple of 4096, ranging from 0 to 61440. It is used to determine the root bridge for the instance. Switches with a lower value have higher priority, and the switch with the highest priority will be elected as the root bridge in the corresponding instance.

VLAN ID Enter the VLAN ID to map the VLAN to the desired instance or unbind the VLAN-instance mapping.

2) Click Create.

Configuring Parameters on Ports in the Instance

Choose the menu L2 FEATURES > Spanning Tree > MSTP Instance > Instance Port Config to load the following page.

Figure 3-5 Configuring Port Parameters in the InstanceInstance Port Config Instance ID: 1 UNIT1 LAGS Port Priority Path Cost Port Role Port Status LAG Gi1/0/1 128 Auto -- -- -- Gi1/0/2 128 Auto -- -- -- Gi1/0/3 128 Auto -- -- -- Gi1/0/4 128 Auto -- -- -- Gi1/0/5 128 Auto -- -- -- Gi1/0/6 128 Auto -- -- -- Gi1/0/7 128 Auto -- -- -- Gi1/0/8 128 Auto -- -…

Follow these steps to configure port parameters in the instance:

1) In the Instance Port Config section, select the desired instance ID.

Instance ID: Select the ID number of the instance that you want to configure.

2) Configure port parameters in the desired instance.

Port: Select one or more ports to configure.

Priority: Specify the priority for the port in the corresponding instance. The value should be an integral multiple of 16, ranging from 0 to 240. The port with a lower value has higher priority. When the root path of the port is the same as other ports', the switch will compare the port priorities between these ports and select a root port with the highest priority.

Path Cost: Enter the value of the path cost in the corresponding instance. The valid values are from 0 to 2000000. The default setting is Auto, which means the port calculates the path cost automatically according to the port's link speed. The port with the lowest root path cost will be elected as the root port of the switch in the desired instance.

Port Role: Displays the role that the port plays in the desired instance.

Root Port: Indicates that the port is the root port in the desired instance. It has the lowest path cost from the root bridge to this switch and is used to communicate with the root bridge.

Designated Port: Indicates that the port is the designated port in the desired instance. It has the lowest path cost from the root bridge to this physical network segment and is used to forward data for the corresponding network segment.

Alternate Port: Indicates that the port is the alternate port in the desired instance. It is the backup of the root port or master port.

Backup Port: Indicates that the port is the backup port in the desired instance. It is the backup of the designated port.

Master Port: Indicates the port provides the lowest root path cost from the region to the root bridge in CIST. In CIST, each region is regarded as a switch, and the master port is the root port of the corresponding region.

Disabled: Indicates that the port is not participating in the spanning tree.

Port Status: Displays the port status.

Forwarding: The port receives and sends BPDUs, and forwards user traffic.

Learning: The port receives and sends BPDUs. It also receives user traffic, but doesn't forward the traffic.

Blocking: The port only receives and sends BPDUs.

Disconnected: The port has the spanning tree function enabled but is not connected to any device.

LAG: Displays the LAG that the port belongs to.

3.1.3 Configuring MSTP Globally

Choose the menu L2 FEATURES > Spanning Tree > STP Config > STP Config to load the following page.

Figure 3-6 Configure MSTP Function GloballyGlobal Config Spanning Tree: ✓ Enable Mode: MSTP Parameters Config CIST Priority: 36864 (0-61440, in increments of 4096) Hello Time: 2 seconds (1-10) Max Age: 20 seconds (6-40) Forward Delay: 12 seconds (4-30) Tx Hold Count: 5 pps (1-20) Max Hops: 20 hop (1-40) Apply Apply

Follow these steps to configure MSTP globally:

1) In the Parameters Config section, configure the global parameters of MSTP and click Apply.

CIST PrioritySpecify the CIST priority for the switch. CIST priority is a parameter used to determine the root bridge for spanning tree. The switch with the lower value has the higher priority.In STP/RSTP, CIST priority is the priority of the switch in spanning tree. The switch with the highest priority will be elected as the root bridge.In MSTP, CISP priority is the priority of the switch in CIST. The switch with the higher priority will be elected as the root bridge in CIST.
Hello Time Specify the interval between BPDUs' sending. The default value is 2. The root bridge sends configuration BPDUs at an interval of Hello Time. It works with the MAX Age to test the link failures and maintain the spanning tree.
Max Age Specify the maximum time that the switch can wait without receiving a BPDU before attempting to regenerate a new spanning tree. The default calue is 20.

Forward Delay: Specify the interval between the port state transition from listening to

learning. The default value is 15. It is used to prevent the network from causing temporary loops during the regeneration of the spanning tree. The interval between the port state transition from learning to forwarding is also the Forward Delay.

Tx Hold Count: Specify the maximum number of BPDUs that can be sent in a second. The

default value is 5.

Max Hops: Specify the maximum BPDU hop counts that can be forwarded in a MST

region. The default value is 20. A switch receives BPDU, then decrements the hop count by one and generates BPDUs with the new value. When the hop reaches zero, the switch will discard the BPDU. This value can control the scale of the spanning tree in the MST region.

Note: Max Hops is a parameter configured in MSTP. You need not configure

it if the spanning tree mode is STP/RSTP.

TP-LINK Omada Pro S5500-24GP4F - Configuring MSTP Globally - 2

Note:

To prevent frequent network flapping, make sure that Hello Time, Forward Delay, and Max Age conform to the following formulas:

• 2*(Hello Time + 1) <= Max Age • 2*(Forward Delay - 1) >= Max Age

2) In the Global Config section, enable Spanning-Tree function and choose the STP mode as MSTP and click Apply.

Spanning-Tree: Enable or disable the spanning tree function globally.

Mode: Select the desired spanning tree mode as STP/RSTP on the switch. By default, it's STP.

STP: Specify the spanning tree mode as STP.

RSTP: Specify the spanning tree mode as RSTP.

MSTP: Specify the spanning tree mode as MSTP.

3.1.4 Verifying the MSTP Configurations

Choose the menu Spanning Tree > STP Config > STP Summary to load the following page.

Figure 3-7 Verifying the MSTP Configurations

STP Summary
Spanning Tree:Enable
Spanning Tree Mode:MSTP
Local Bridge:36864---00-0a-eb-13-a2-02
Root Bridge:36864---00-0a-eb-13-a2-02
External Path Cost:0
Regional Root Bridge:36864---00-0a-eb-13-a2-02
Internal Path Cost:0
Designated Bridge:36864---00-0a-eb-13-a2-02
Root Port:---
Latest TC Time:2006-01-01 08:00:45
TC Count:0
MSTP Instance Summary
Instance ID:
Instance Status:Disable
Local Bridge:---
Regional Root Bridge:---
Internal Path Cost:---
Designated Bridge:---
Root Port:---
Latest TC Time:---
TC Count:---

The STP Summary section shows the summary information of CIST:

Spanning Tree Displays the status of the spanning tree function.
Spanning-Tree Mode Displays the spanning tree mode.
Local BridgeDisplays the bridge ID of the local switch. The local bridge is the current switch.
Root Bridge Displays the bridge ID of the root bridge in CIST.
External Path CostDisplays the external path cost. It is the root path cost from the switch to the root bridge in CIST.
Regional Root Bridge Displays the bridge ID of the root bridge in IST.
Internal Path CostDisplays the internal path cost. It is the root path cost from the current switch to the root bridge in IST.
Designated Bridge Displays the bridge ID of the designated bridge in CIST.
Root Port Displays the root port of in CIST.
Latest TC Time Displays the latest time when the topology is changed.
TC Count Displays how many times the topology has changed.
The MSTP Instance Summary section shows the information in MST instances:
Instance ID Select the desired instance.
Instance Status Displays the status of the desired instance.
Local BridgeDisplays the bridge ID of the local switch. The local bridge is the current switch.
Regional Root Bridge Displays the bridge ID of the root bridge in the desired instance.
Internal Path CostDisplays the internal path cost. It is the root path cost from the current switch to the regional root bridge.
Designated Bridge Displays the bridge ID of the designated bridge in the desired instance.
Root Port Displays the root port of the desired instance.
Latest TC Time Displays the latest time when the topology is changed.
TC Count Displays how many times the topology has changed.

3.2 Using the CLI

3.2.1 Configuring Parameters on Ports in CIST

Follow these steps to configure the parameters of the port in CIST:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 3 spanning-tree

Enable spanning tree function for the desired port.

Step 4 spanning-tree common-config [ port-priority pri ] [ ext-cost ext-cost ] [ int-cost int-cost ][ portfast { enable | disable }] [ point-to-point { auto | open | close }]

Configure the parameters on ports in CIST.

pri: Specify the priority for the desired port. The value should be an integral multiple of 16, ranging from 0 to 240. The default value is 128. Ports with lower values have higher priority. When the root path of the port is the same as other ports', the switch will compare the port priorities and select a root port with the highest priority.

ext-cost: Specify the value of the external path cost. The valid values are from 0 to 2000000 and the default setting is Auto, which means the port calculates the external path cost automatically according to the port's link speed.

For STP/RSTP, external path cost indicates the path cost of the port in spanning tree. The port with the lowest root path cost will be elected as the root port of the switch.

For MSTP, external path cost indicates the path cost of the port in CST.

int-cost: Specify the value of the internal path cost. The valid values are from 0 to 2000000. The default setting is Auto, which means the port calculates the internal path cost automatically according to the port's link speed. This parameter is only used in MSTP.

For MSTP, internal path cost is used to calculate the path cost in IST. The port with the lowest root path cost will be elected as the root port of the switch in IST.

portfast { enable | disable }: Enable to set the port as an edge port. By default, it is disabled. When the topology is changed, the edge port can transit its state from blocking to forwarding directly. For the quick generation of the spanning tree, it is recommended to set the ports that are connected to the end devices as edge ports.

point-to-point { auto | open | close }: Select the status of the P2P (Point-to-Point) link to which the ports are connected. During the regeneration of the spanning tree, if the port of P2P link is elected as the root port or the designated port, it can transit its state to forwarding directly. Auto indicates that the switch automatically checks if the port is connected to a P2P link, then sets the status as Open or Closed. Open is used to set the port as the one that is connected to a P2P link. Close is used to set the port as the one that is not connected to a P2P link.

Step 5 spanning-tree mcheck

(Optional) Perform MCheck operations on the port.

If a port on an RSTP-enabled/MSTP-enabled device is connected to an STP-enabled device, the port will switch to STP compatible mode and send packets in STP format. MCheck is used to switch the mode of the port back to RSTP/MSTP after the port is disconnected from the STP-enabled device. The MCheck configuration can take effect only once, after that the MCheck status of the port will switch to Disabled.

Step 6show spanning-tree interface [ fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel lagid ] [ edge | ext-cost | int-cost | mode | p2p | priority | role | state | status ](Optional) View the information of all ports or a specified port.port: Specify the port number.lagid: Specify the ID of the LAG.ext-cost | int-cost | mode | p2p | priority | role | state | status: Display the specified information.

Step 7 end

Return to privileged EXEC mode.

Step 8 copy running-config startup-config

Save the settings in the configuration file.

This example shows how to enable spanning tree function for port 1/0/3 and configure the port priority as 32:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/3

Switch(config-if)#spanning-tree

Switch(config-if)#spanning-tree common-config port-priority 32

Switch(config-if)#show spanning-tree interface gigabitEthernet 1/0/3

MST-Instance 0 (CIST)

InterfaceStatePrioExt-CostInt-CostEdgeP2pModeRoleStatus
Gi1/0/3Enable32AutoAutoNoNo(auto)N/AN/ALnkDwn

MST-Instance 5

InterfacePrio CostRoleStatus
Gi1/0/3144 200N/ALnkDwn

Switch(config-if)#end

Switch#copy running-config startup-config

3.2.2 Configuring the MSTP Region

■ Configuring the MST Region

Follow these steps to configure the MST region and the priority of the switch in the instance:

Step 1 configure

Enter global configuration mode.

Step 2 spanning-tree mst instance

instance-id priority pri

Configure the priority of the switch in the instance.

instance-id: Specify the instance ID, the valid values range from 1 to 8.

pri: Specify the priority for the switch in the corresponding instance. The value should be an integral multiple of 4096, ranging from 0 to 61440. The default value is 32768. It is used to determine the root bridge for the instance. Switches with a lower value have higher priority, and the switch with the highest priority will be elected as the root bridge in the corresponding instance.

Step 3 spanning-tree mst configuration

Enter MST configuration mode, as to configure the VLAN-Instance mapping, region name and revision level.

Step 4 name

name

Configure the region name of the region.

name: Specify the region name, used to identify an MST region. The valid values are from 1 to 32 characters.

Step 5 revision

revision

Configure the revision level of the region.

revision: Specify the revision level of the region. The valid values are from 0 to 65535.

Step 6 instance

instance-id vlan vlan-id

Configure the VLAN-Instance mapping.

instance-id: Specify the Instance ID. The valid values are from 1 to 8.

vlan-id: Specify the VLAN mapped to the corresponding instance.

Step 7

show spanning-tree mst { configuration [digest] | instance instance-id [interface [ fastEthernet port | gigabitEthernet port | port-channel lagid | ten-gigabitEthernet port]] }

(Optional) View the related information of MSTP Instance.

digest: Specify to display the digest calculated by instance-vlan map.

instance-id: Specify the Instance ID desired to view, ranging from 1 to 8.

port: Specify the port number.

lagid: Specify the ID of the LAG.

Step 8 end

Return to privileged EXEC mode.

Step 9 copy running-config startup-config

Save the settings in the configuration file.

This example shows how to create an MST region, of which the region name is R1, the revision level is 100 and VLAN 2-VLAN 6 are mapped to instance 5:

Switch#configure

Switch(config)#spanning-tree mst configuration

Switch(config-mst)#name R1

Switch(config-mst)#revision 100

Switch(config-mst)#instance 5 vlan 2-6

Switch(config-mst)#show spanning-tree mst configuration

Region-Name: R1

Revision : 100

MST-Instance Vlans-Mapped

0 1,7-4094

5 2-6,

Switch(config-mst)#end

Switch#copy running-config startup-config

Configuring the Parameters on Ports in Instance

Follow these steps to configure the priority and path cost of ports in the specified instance:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 3 spanning-tree mst instanceinstance-id { [ port-priority pri ] | [ cost cost] }Configure the priority and path cost of ports in the specified instance.
instance-id: Specify the instance ID, the valid values ranges from 1 to 8.
pri: Specify the Priority for the port in the corresponding instance. The value should be an integral multiple of 16, ranging from 0 to 240. The default valueis 128. The port with lower value has the higher priority. When the root path of the port is the same as other ports', the switch will compare the port priorities between these ports and select a root port with the highest priority.
cost: Enter the value of the path cost in the corresponding instance. The valid values are from 0 to 2000000. The default setting is Auto, which means the port calculates the external path cost automatically according to the port's link speed. The port with the lowest root path cost will be elected as the root port of the switch.
Step 4show spanning-tree mst { configuration [ digest ] | instance instance-id [ interface [ fastEthernet port | gigabitEthernet port | port-channel lagid | ten-gigabitEthernet port ] ] } (Optional) View the related information of MSTP Instance.
digest: Specify to display the digest calculated by instance-vlan map.
instance-id: Specify the Instance ID desired to view, ranging from 1 to 8.
port: Specify the port number.
lagid: Specify the ID of the LAG.
Step 5 endReturn to privileged EXEC mode.
Step 6 copy running-config startup-config

This example shows how to configure the priority as 144, the path cost as 200 of port 1/0/3 in instance 5:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/3

Switch(config-if)#spanning-tree mst instance 5 port-priority 144 cost 200

Switch(config-if)#show spanning-tree interface gigabitEthernet 1/0/3

MST-Instance 0 (CIST)

InterfaceStatePrioExt-CostInt-CostEdgeP2pModeRoleStatusLAG
Gi1/0/3Enable32AutoAutoNoNo(auto)N/AN/ALnkDwnN/A
MST-Instance 5
InterfacePrioCostRoleStatusLAG
Gi1/0/3144200N/ALnkDwnN/A

Switch(config-if)#end

Switch#copy running-config startup-config

3.2.3 Configuring Global MSTP Parameters

Follow these steps to configure the global MSTP parameters of the switch:

Step 1 configure

Enter global configuration mode.

Step 2 spanning-tree priority pri

Configure the priority of the switch for comparison in CIST.

pri: Specify the priority for the switch. The valid value is from 0 to 61440, which are divisible by 4096. The priority is a parameter used to determine the root bridge for spanning tree. The switch with the lower value has the higher priority.

In STP/RSTP, the value is the priority of the switch in spanning tree. The switch with the highest priority will be elected as the root bridge.

In MSTP, the value is the priority of the switch in CIST. The switch with the higher priority will be elected as the root bridge in CIST.

Step 3 spanning-tree timer { [ forward-time forward-time ] [ hello-time hello-time ] [ max-age max-age] }

(Optional) Configure the Forward Delay, Hello Time and Max Age.

forward-time: Specify the value of Forward Delay. It is the interval between the port state transition from listening to learning. The valid values are from 4 to 30 in seconds, and the default value is 15. Forward Delay is used to prevent the network from causing temporary loops during the regeneration of spanning tree. The interval between the port state transition from learning to forwarding is also the Forward Delay.

hello-time: Specify the value of Hello Time. It is the interval between BPDUs' sending. The valid values are from 1 to 10 in seconds, and the default value is 2. The root bridge sends configuration BPDUs at an interval of Hello Time. It works with the MAX Age to test the link failures and maintain the spanning tree.

max-age: Specify the value of Max Age. It is the maximum time that the switch can wait without receiving a BPDU before attempting to regenerate a new spanning tree. The valid values are from 6 to 40 in seconds, and the default value is 20.

Step 4 spanning-tree hold-count value

(Optional) Specify the maximum number of BPDU that can be sent in a second.

value: Specify the maximum number of BPDU packets that can be sent in a second. The valid values are from 1 to 20 pps, and the default value is 5.

Step 5 spanning-tree max-hops value

(Optional) Specify the maximum BPDU hop counts that can be forwarded in a MST region. A switch receives BPDU, then decrements the hop count by one and generates BPDUs with the new value. When the hop reaches zero, the switch will discard the BPDU. This value can control the scale of the spanning tree in the MST region.

value: Specify the maximum number of hops that occur in a specific region before the BPDU is discarded. The valid values are from 1 to 40 in hop, and the default value is 20.

Step 6 show spanning-tree bridge

(Optional) View the global parameters of the switch.

Step 7 end

Return to privileged EXEC mode.

Step 8 copy running-config startup-config

Save the settings in the configuration file.

TP-LINK Omada Pro S5500-24GP4F - Step 4 spanning-tree hold-count value - 1

Note:

To prevent frequent network flapping, make sure that Hello Time, Forward Delay, and Max Age conform to the following formulas:

• 2*(Hello Time + 1) <= Max Age • 2*(Forward Delay - 1) >= Max Age

This example shows how to configure the CIST priority as 36864, the Forward Delay as 12 seconds, the Hold Count as 8 and the Max Hop as 25:

Switch#configure

Switch(config)#spanning-tree priority 36864

Switch(config-if)#spanning-tree timer forward-time 12

Switch(config-if)#spanning-tree hold-count 8

Switch(config-if)#spanning-tree max-hops 25

Switch(config-if)#show spanning-tree bridge

StateModePriorityHello-TimeFwd-TimeMax-AgeHold-CountMax-Hops
--------------------------------
EnableMstp3686421220825

Switch(config-if)#end

Switch#copy running-config startup-config

3.2.4 Enabling Spanning Tree Globally

Follow these steps to configure the spanning tree mode as MSTP and enable spanning tree function globally:

Step 1 configure

Enter global configuration mode.

Step 2 spanning-tree mode mstp

Configure the spanning tree mode as MSTP.

mstp: Specify the spanning tree mode as MSTP.

Step 3 spanning-tree

Enable spanning tree function globally.

Step 4 show spanning-tree active

(Optional) View the active information of MSTP.

Step 5 end

Return to privileged EXEC mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

This example shows how to configure the spanning tree mode as MSTP and enable spanning tree function globally:

Switch#configure

Switch(config)#spanning-tree mode mstp

Switch(config)#spanning-tree

Switch(config)#show spanning-tree active

Spanning tree is enabled

Spanning-tree's mode: MSTP (802.1s Multiple Spanning Tree Protocol)

Latest topology change time: 2006-01-04 10:47:42

MST-Instance 0 (CIST)

Root Bridge

Priority: 32768

Address: 00-0a-eb-13-23-97

External Cost: 200000

Root Port: Gi/0/20

Designated Bridge

Priority: 32768

Address: 00-0a-eb-13-23-97

Regional Root Bridge

Priority: 36864

Address: 00-0a-eb-13-12-ba

Local bridge is the regional root bridge

Local Bridge

Priority: 36864

Address : 00-0a-eb-13-12-ba

InterfaceStatePrioExt-CostInt-CostEdgeP2pModeRoleStatus
Gi/0/16Enable128200000200000NoYes(auto)MstpAltnBlk
Gi/0/20Enable128200000200000NoYes(auto)MstpRootFwd

MST-Instance 1

Root Bridge

Priority : 32768

Address : 00-0a-eb-13-12-ba

Local bridge is the root bridge

Designated Bridge

Priority : 32768

Address : 00-0a-eb-13-12-ba

Local Bridge

Priority : 32768

Address : 00-0a-eb-13-12-ba

Interface Prio Cost Role Status

Gi/0/16 128 200000 Altn Blk

Gi/0/20 128 200000 Mstr Fwd

Switch(config)#end

Switch#copy running-config startup-config

4 STP Security Configurations

4.1 Using the GUI

Choose the menu L2 FEATURES > Spanning Tree > STP Security to load the following page.

Figure 4-1 Configuring the Port Protect

Port Protect
UNIT1LAGS
PortLoop ProtectRoot ProtectTC GuardBPDU ProtectBPDU FilterBPDU ForwardLAG
Gi1/0/1DisabledDisabledDisabledDisabledDisabledEnabled-
Gi1/0/2DisabledDisabledDisabledDisabledDisabledEnabled-
Gi1/0/3DisabledDisabledDisabledDisabledDisabledEnabled-
Gi1/0/4DisabledDisabledDisabledDisabledDisabledEnabled-
Gi1/0/5DisabledDisabledDisabledDisabledDisabledEnabled-
Gi1/0/6DisabledDisabledDisabledDisabledDisabledEnabled-
Gi1/0/7DisabledDisabledDisabledDisabledDisabledEnabled-
Gi1/0/8DisabledDisabledDisabledDisabledDisabledEnabled-
Gi1/0/9DisabledDisabledDisabledDisabledDisabledEnabled-
Gi1/0/10DisabledDisabledDisabledDisabledDisabledEnabled-

Configure the Port Protect features for the selected ports, and click Apply.

UNIT Select the desired ports to configure.

Loop Protect

Enable or disable Loop Protect. It is recommended to enable this function on root ports and alternate ports.

When there are link congestions or link failures in the network, the switch will not receive BPDUs from the upstream device in time. Loop Protect is used to avoid loop caused by the recalculation in this situation. With Loop Protect function enabled, the port will temporarily transit to a blocking state after it does not receive BPDUs in time.

Root ProtectEnable or disable Root Protect. It is recommended to enable this function on the designated ports of the root bridge.Switches with faulty configurations may produce a higher-priority BPDUs than the root bridge's, and this situation will cause recalculation of the spanning tree. Root Protect is used to ensure that the desired root bridge will not lose its position in the scenario above. With root protect enabled, the port will temporarily transit to blocking state when it receives higher-priority BDPUs. After two forward delays, if the port does not receive any other higher-priority BDPUs, it will transit to its normal state.
TC Guard Enable or disable the TC Guard function. It is recommended to enable this function on the ports of non-root switches.TC Guard function is used to prevent the switch from frequently changing the MAC address table. With TC Guard function enabled, when the switch receives TC-BPDUs, it will not process the TC-BPDUs at once. The switch will wait for a fixed time and process the TC-BPDUs together after receiving the first TC-BPDU, then it will restart timing.
BPDU ProtectEnable or disable the BPDU Protect function. It is recommended to enable this function on edge ports.Edge ports in spanning tree are used to connect to the end devices and it doesn't receive BPDUs in the normal situation. If edge ports receive BPDUs, it may be an attack. BPDU Protect is used to protect the switch from the attack talked above. With BPDU protect function enabled, the edge ports will be shutdown when they receive BPDUs, and will report these cases to the administrator. Only the administrator can restore the state of the ports.
BPDU FilterEnable or disable BPDU Filter. It is recommended to enable this function on edge ports.With the BPDU Filter function enabled, the port does not forward BPDUs from the other switches.
BPDU Forward Enable or disable BPDU Forward. This function only takes effect when the spanning tree function is disabled globally.With BPDU forward enabled, the port can still forward spanning tree BPDUs when the spanning tree function is disabled.

4.2 Using the CLI

4.2.1 Configuring the STP Security

Follow these steps to configure the Root protect feature, BPDU protect feature and BPDU filter feature for ports:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 3 spanning-tree guard loop

(Optional) Enable Loop Protect. It is recommended to enable this function on root ports and alternate ports.

When there are link congestions or link failures in the network, the switch will not receive BPDUs from the upstream device in time. Loop Protect is used to avoid loops caused by the recalculation in this situation. With Loop Protect function enabled, the port will temporarily transit to a blocking state after it does not receive BPDUs in time.

Step 4 spanning-tree guard root

(Optional) Enable Root Protect. It is recommended to enable this function on the designated ports of the root bridge.

Switches with faulty configurations may produce higher-priority BPDUs than the root bridge's, and this situation will cause recalculation of the spanning tree. Root Protect is used to ensure that the desired root bridge will not lose its position in the scenario above. With root protect enabled, the port will temporarily transit to blocking state when it receives higher-priority BPDUs. After two forward delays, if the port does not receive any other higher-priority BPDUs, it will transit to its normal state.

Step 5 spanning-tree guard tc

(Optional) Enable the TC Guard function. It is recommended to enable this function on the ports of non-root switches.

TC Guard function is used to prevent the switch from frequently changing the MAC address table. With TC Guard function enabled, when the switch receives TC-BPDUs, it will not process the TC-BPDUs at once. The switch will wait for a fixed time and process the TC-BPDUs together after receiving the first TC-BPDU, then it will restart timing.

Step 6 spanning-tree bpduguard

(Optional) Enable the BPDU Protect function. It is recommended to enable this function on edge ports.

Edge ports in spanning tree are used to connect to the end devices and they don't receive BPDUs in the normal situation. If edge ports receive BPDUs, it may be an attack. BPDU Protect is used to protect the switch from the attack mentioned above. With BPDU protect function enabled, the edge ports will be shutdown when they receive BPDUs, and will report these cases to the administrator. Only the administrator can restore the state of the ports.

Step 7 spanning-tree bpdufilter

(Optional) Enable or disable BPDU Filter. It is recommended to enable this function on edge ports.

With the BPDU Filter function enabled, the port does not forward BPDUs from the other switches.

Step 8 spanning-tree bpduflood(Optional) Enable BPDU Forward. This function only takes effect when the spanning tree function is disabled globally. By default, it is enabled.With BPDU forward enabled, the port can still forward spanning tree BPDUs when the spanning tree function is disabled.
Step 9 show spanning-tree interface-security [ fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel-id ] [ bpdufilter | bpduguard | bpduflood | loop | root | tc ](Optional) View the protect information of ports.port: Specify the port number.lagid: Specify the ID of the LAG.
Step 10 endReturn to privileged EXEC mode.
Step 11 copy running-config startup-configSave the settings in the configuration file.

This example shows how to enable Loop Protect, Root Protect, BPDU Filter and BPDU Protect functions on port 1/0/3:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/3

Switch(config-if)#spanning-tree guard loop

Switch(config-if)#spanning-tree guard root

Switch(config-if)#spanning-tree bpdufilter

Switch(config-if)#spanning-tree bpduguard

Switch(config-if)#show spanning-tree interface-security gigabitEthernet 1/0/3

5 Configuration Example for MSTP

MSTP, backwards-compatible with STP and RSTP, can map VLANs to instances to implement load-balancing, thus providing a more flexible method in network management. Here we take the MSTP configuration as an example.

5.1 Network Requirements

As shown in figure 5-1, the network consists of three switches. Traffic in VLAN 101-VLAN 106 is transmitted in this network. The link speed between the switches is 100Mb/s (the default path cost of the port is 200000).

It is required that traffic in VLAN 101 - VLAN 103 and traffic in VLAN 104 - VLAN 106 should be transmitted along different paths.

Figure 5-1 Network Topologygraph TD SwitchA["Switch A\nMAC: 00-0A-EB-13-23-97"] -->|200000 Gi1/0/1| SwitchB["Switch B\nMAC: 00-0A-EB-13-12-97"] SwitchA -->|200000 Gi1/0/2| SwitchB SwitchB -->|200000 Gi1/0/2| SwitchC["Switch C\nMAC: 3C-46-D8-9D-88-F7"]

5.2 Configuration Scheme

To meet this requirement, you are suggested to configure MSTP function on the switches. Map the VLANs to different instances to ensure traffic can be transmitted along the respective instance.

Here we configure two instances to meet the requirement, as is shown below:

Figure 5-2 VLAN-Instance Mappinggraph TD SwitchA["Switch A"] -->|Gi1/0/1| SwitchB["Switch B"] SwitchA -->|Gi1/0/2| SwitchC["Switch C"] SwitchB -->|Gi1/0/1 Gi1/0/1| SwitchA SwitchB -->|Gi1/0/2 Gi1/0/2| SwitchC SwitchA -.->|Instance 1: VLAN 101 -VLAN 103| SwitchB SwitchA -.->|Instance 2: VLAN 104 -VLAN 106| SwitchC SwitchA -.->|Bloc…

The overview of configuration is as follows:

1) Enable MSTP function globally in all the switches. 2) Enable Spanning Tree function on the ports in each switch. 3) Configure Switch A, Switch B and Switch C in the same region. Configure the region name as 1, and the revision level as 100. Map VLAN 101 - VLAN 103 to instance 1 and VLAN 104 - VLAN 106 to instance 2. 4) Configure the priority of Switch B as 0 to set it as the root bridge in instance 1; configure the priority of Switch C as 0 to set it as the root bridge in instance 2. 5) Configure the path cost to block the specified ports. For instance 1, set the path cost of port 1/0/1 of Switch A to be greater than the default path cost (200000); for instance 2, set the path cost of port 1/0/2 of Switch B to be greater than the default path cost (200000). After this configuration, port 1/0/2 of Switch A in instance 1 and port 1/0/1 of Switch B in instance 2 will be blocked for they cannot be neither root port nor designated port.

TP-LINK Omada Pro S5500-24GP4F - Configuration Scheme - 2

Note:

Please configure MSTP for each switch first and then connect them together to avoid broadcast storm.

5.3 Using the GUI

■ Configurations for Switch A

1) Choose the menu L2 FEATURES > Spanning Tree > STP Config > STP Config to load the following page. Enable MSTP function globally, here we leave the values of the other global parameters as default settings. Click Apply.

Figure 5-3 Configure the Global MSTP Parameters of the SwitchGlobal Config Spanning Tree: ✓ Enable Mode: MSTP Apply Parameters Config CIST Priority: 32768 (0-51440, in increments of 4096) Hello Time: 2 seconds (1-10) Max Age: 20 seconds (6-40) Forward Delay: 15 seconds (4-30) Tx Hold Count: 5 pps (1-20) Max Hops: 20 (1-40) Apply

2) Choose the menu L2 FEATURES > Spanning Tree > STP Config > Port Config to load the following page. Enable spanning tree function on port 1/0/1 and port 1/0/2. Here we leave the values of the other parameters as default settings. Click Apply.

Figure 5-4 Enable Spanning Tree Function on PortsPort Config UNIT1 LAGS Port Status Priority Ext-Path Cost Int-Path Cost Edge Port P2P Link MCheck Port Mode Port I Enabl▼ ✓ 1/0/1 Enabled 128 Auto Auto Disabled Auto -- -- ✓ 1/0/2 Enabled 128 Auto Auto Disabled Auto -- -- □ 1/0/3 Disabled 128 Auto Auto Disabled Auto -- -- □ 1/0/4 Disabled 128 Auto A…

3) Choose the menu L2 FEATURES > Spanning Tree > MSTP Instance > Region Config to load the following page. Set the region name as 1 and the revision level as 100. Click Apply.

Figure 5-5 Configuring the MST RegionRegion Config Region Name: 1 Revision: 100 (0-65535) Apply

4) Choose the menu L2 FEATURES > Spanning Tree > MSTP Instance > Instance Config. Click Add, map VLAN101-VLAN103 to instance 1 and set the priority as 32768; map VLAN104-VLAN106 to instance 2 and set the priority as 32768. Click Create.

Figure 5-6 Configuring the VLAN-Instance MappingInstance Config + Add Delete Instance ID Priority VLAN ID Operation CIST 32768 1-100,107-4094. 1 32768 101-103. 2 32768 104-106. Total: 3

5) Choose the menu L2 FEATURES > Spanning Tree > MSTP Instance > Instance Port Config to load the following page. Set the path cost of port 1/0/1 in instance 1 as 300000 so that port 1/0/1 of switch C can be selected as the designated port.

Figure 5-7 Configure the Path Cost of Port 1/0/1 In Instance 1Instance Port Config Instance ID: 1 UNIT1 LAGS Port Priority Path Cost Port Role Port Status LAG 300000 ✓ GI1/0/1 128 300000(Auto) Designated Forwarding -- GI1/0/2 128 Auto Disable Disconnected -- GI1/0/3 128 Auto -- -- GI1/0/4 128 Auto -- -- GI1/0/5 128 Auto -- -- GI1/0/6 128 Auto -- -- GI1/0/7 128…

6) Click Save the settings.

■ Configurations for Switch B

1) Choose the menu L2 FEATURES > Spanning Tree > STP Config > STP Config to load the following page. Enable MSTP function globally, here we leave the values of the other global parameters as default settings. Click Apply.

Figure 5-8 Configure the Global MSTP Parameters of the SwitchGlobal Config Spanning Tree: ✓ Enable Mode: MSTP Apply Parameters Config CIST Priority: 32768 (0-61440, in increments of 4096) Hello Time: 2 seconds (1-10) Max Age: 20 seconds (6-40) Forward Delay: 15 seconds (4-30) Tx Hold Count: 5 pps (1-20) Max Hops: 20 (1-40) Apply

2) Choose the menu L2 FEATURES > Spanning Tree > STP Config > Port Config to load the following page. Enable the spanning tree function on port 1/0/1 and port 1/0/2. Here we leave the values of the other parameters as default settings. Click Apply.

Figure 5-9 Enable Spanning Tree Function on PortsPort Config UNIT1 LAGS Port Status Priority Ext-Path Cost Int-Path Cost Edge Port P2P Link MCheck Port Mode Port I Enabl▼ ✓ 1/0/1 Enabled 128 Auto Auto Disabled Auto -- -- ✓ 1/0/2 Enabled 128 Auto Auto Disabled Auto -- -- □ 1/0/3 Disabled 128 Auto Auto Disabled Auto -- -- □ 1/0/4 Disabled 128 Auto A…

3) Choose the menu L2 FEATURES > Spanning Tree > MSTP Instance > Region Config to load the following page. Set the region name as 1 and the revision level as 100. Click Apply.

Figure 5-10 Configuring the RegionRegion Config Region Name: 1 Revision: 100 (0-65535) Apply

4) Choose the menu L2 FEATURES > Spanning Tree > MSTP Instance > Instance Config. Map VLAN101-VLAN103 to instance 1 and set the Priority as 0; map VLAN104-VLAN106 to instance 2 and set the priority as 32768. Click Create.

Figure 5-11 Configuring the VLAN-Instance MappingInstance Config Instance ID Priority VLAN ID Operation CIST 32768 1-100,107-4094, 1 0 101-103, 2 32768 104-106, Total: 3

5) Choose the menu L2 FEATURES > Spanning Tree > MSTP Instance > Instance Port Config to load the following page. Set the path cost of port 1/0/2 in instance 2 as 300000 so that port 1/0/1 of switch A can be selected as the designated port.

Figure 5-12 Configure the Path Cost of Port 1/0/2 in Instance 2Instance Port Config Instance ID: 2 UNIT1 LAGS Port Priority Path Cost Port Role Port Status LAG 300000 Gi1/0/1 128 Auto -- -- -- ✓ Gi1/0/2 128 300000 -- -- -- Gi1/0/3 128 Auto -- -- -- Gi1/0/4 128 Auto -- -- -- Gi1/0/5 128 Auto -- -- -- Gi1/0/6 128 Auto -- -- -- Gi1/0/7 128 Auto -- -- -- Gi1/0/8 12…

6) Click Save the settings.

■ Configurations for Switch C

1) Choose the menu L2 FEATURES > Spanning Tree > STP Config > STP Config to load the following page. Enable MSTP function globally, here we leave the values of the other global parameters as default settings. Click Apply.

Figure 5-13 Configure the Global MSTP Parameters of the SwitchGlobal Config Spanning Tree: ✓ Enable Mode: MSTP Apply Parameters Config CIST Priority: 32768 (0-61440, in increments of 4096) Hello Time: 2 seconds (1-10) Max Age: 20 seconds (6-40) Forward Delay: 15 seconds (4-30) Tx Hold Count: 5 pps (1-20) Max Hops: 20 (1-40) Apply

2) Choose the menu L2 FEATURES > Spanning Tree > STP Config > Port Config to load the following page. Enable the spanning tree function on port 1/0/1 and port 1/0/2. Here we leave the values of the other parameters as default settings. Click Apply.

Figure 5-14 Enable Spanning Tree Function on PortsPort Config UNIT1 LAGS Port Status Priority Ext-Path Cost Int-Path Cost Edge Port P2P Link MCheck Port Mode Port I Enabl▼ ✓ 1/0/1 Enabled 128 Auto Auto Disabled Auto -- -- ✓ 1/0/2 Enabled 128 Auto Auto Disabled Auto -- -- □ 1/0/3 Disabled 128 Auto Auto Disabled Auto -- -- □ 1/0/4 Disabled 128 Auto A…

3) Choose the menu Spanning Tree > MSTP Instance > Region Config to load the following page. Set the region name as 1 and the revision level as 100. Click Apply.

Figure 5-15 Configuring the RegionRegion Config Region Name: 1 Revision: 100 (0-63535) Apply

4) Choose the menu L2 FEATURES > Spanning Tree > MSTP Instance > Instance Config. Click Add, map VLAN101-VLAN103 to instance 1 and set the priority as 32768; map VLAN104-VLAN106 to instance 2 and set the priority as 0. Click Create.

Figure 5-16 Configuring the VLAN-Instance MappingInstance Config Instance ID Priority VLAN ID Operation CIST 32768 1-100,107-4094, 1 32768 101-103, 2 0 104-106, Total: 3

5) Click save the settings.

5.4 Using the CLI

■ Configurations for Switch A

1) Configure the spanning tree mode as MSTP, then enable spanning tree function globally.

Switch#configure

Switch(config)#spanning-tree mode mstp

Switch(config)#spanning-tree

2) Enable the spanning tree function on port 1/0/1 and port 1/0/2, and specify the path cost of port 1/0/1 in instance 1 as 300000.

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#spanning-tree

Switch(config-if)#spanning-tree mst instance 1 cost 300000

Switch(config-if)#exit

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)#spanning-tree

Switch(config-if)#exit

3) Configure the region name as 1, the revision number as 100; map VLAN101-VLAN103 to instance 1; map VLAN104-VLAN106 to instance 2: Switch(config)#spanning-tree mst configuration Switch(config-mst)#name 1 Switch(config-mst)#revision 100 Switch(config-mst)#instance 1 vlan 101-103 Switch(config-mst)#instance 2 vlan 104-106 Switch(config-mst)#end Switch#copy running-config startup-config

■ Configurations for Switch B

1) Configure the spanning tree mode as MSTP, then enable spanning tree function globally. Switch#configure Switch(config)#spanning-tree mode mstp Switch(config)#spanning-tree

2) Enable the spanning tree function on port 1/0/1 and port 1/0/2, and specify the path cost of port 1/0/2 in instance 2 as 300000.

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)#spanning-tree

Switch(config-if)#spanning-tree mst instance 2 cost 300000

Switch(config-if)#exit

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#spanning-tree

Switch(config-if)#exit

3) Configure the region name as 1, the revision number as 100; map VLAN101-VLAN103 to instance 1; map VLAN104-VLAN106 to instance 2; configure the priority of Switch B in instance 1 as 0 to set it as the root bridge in instance 1:

Switch(config)#spanning-tree mst configuration

Switch(config-mst)#name 1

Switch(config-mst)#revision 100

Switch(config-mst)#instance 1 vlan 101-103

Switch(config-mst)#instance 2 vlan 104-106

Switch(config-mst)#exit

Switch(config)#spanning-tree mst instance 1 priority 0

Switch(config)#end

Switch#copy running-config startup-config

■ Configurations for Switch C

1) Configure the spanning tree mode as MSTP, then enable spanning tree function globally.

Switch#configure

Switch(config)#spanning-tree mode mstp

Switch(config)#spanning-tree

2) Enable the spanning tree function on port 1/0/1 and port 1/0/2.

Switch(config)#interface range gigabitEthernet 1/0/1-2

Switch(config-if-range)#spanning-tree

Switch(config-if-range)#exit

3) Configure the region name as 1, the revision number as 100; map VLAN101-VLAN103 to instance 1; map VLAN104-VLAN106 to instance 2; configure the priority of Switch C in instance 2 as 0 to set it as the root bridge in instance 2:

Switch(config)#spanning-tree mst configuration

Switch(config-mst)#name 1

Switch(config-mst)#revision 100

Switch(config-mst)#instance 1 vlan 101-103

Switch(config-mst)#instance 2 vlan 104-106

Switch(config-mst)#exit

Switch(config)#spanning-tree mst instance 2 priority 0

Switch(config)#end

Switch#copy running-config startup-config

Verify the Configurations

Switch A

Verify the configurations of Switch A in instance 1:

Switch(config)#show spanning-tree mst instance 1

MST-Instance 1

Root Bridge

Priority : 0

Address :00-0a-eb-13-12-ba

Internal Cost : 400000

Root Port : 1

Designated Bridge

Priority : 0

Address :00-0a-eb-13-12-ba

Local Bridge

Priority :32768

Address : 00-0a-eb-13-23-97

InterfacePrioCostRoleStatusLAG
------------------------
Gi1/0/1128300000RootFwdN/A
Gi1/0/2128200000AltnBlkN/A

Verify the configurations of Switch A in instance 2:

Switch(config)#show spanning-tree mst instance 2

MST-Instance 2

Root Bridge

Priority : 0

Address : 3c-46-d8-9d-88-f7

Internal Cost: 200000

Root Port : 2

Designated Bridge

Priority : 0

Address : 3c-46-d8-9d-88-f7

Local Bridge

Priority : 32768

Address : 00-0a-eb-13-23-97

Interface Prio Cost Role Status LAG


Gi1/0/1 128 200000 Desg Fwd N/A

Gi1/0/2 128 200000 Root Fwd N/A

Switch B

Verify the configurations of Switch B in instance 1:

Switch(config)#show spanning-tree mst instance 1

MST-Instance 1

Root Bridge

Priority : 0

Address : 00-0a-eb-13-12-ba

Local bridge is the root bridge

Designated Bridge

Priority : 0

Address : 00-0a-eb-13-12-ba

Local Bridge

Priority : 0

Address : 00-0a-eb-13-12-ba

Interface Prio Cost Role Status

Gi1/0/1 128 200000 Desg Fwd

Gi1/0/2 128 200000 Desg Fwd

Verify the configurations of Switch B in instance 2:

Switch(config)#show spanning-tree mst instance 2

MST-Instance 2

Root Bridge

Priority : 0

Address : 3c-46-d8-9d-88-f7

Internal Cost : 400000

Root Port : 2

Designated Bridge

Priority : 0

Address : 3c-46-d8-9d-88-f7

Local Bridge

Priority :32768

Address : 00-0a-eb-13-12-ba

Interface Prio Cost Role Status

Gi1/0/1 128 200000 Altn Blk

Gi1/0/2 128 300000 Root Fwd

Switch C

Verify the configurations of Switch C in instance 1:

Switch(config)#show spanning-tree mst instance 1

MST-Instance 1

Root Bridge

Priority : 0

Address : 00-0a-eb-13-12-ba

Internal Cost : 200000

Root Port : 2

Designated Bridge

Priority : 0

Address : 00-0a-eb-13-12-ba

Local Bridge

Priority :32768

Address : 3c-46-d8-9d-88-f7

Interface Prio Cost Role Status

Gi1/0/1 128 200000 Desg Fwd

Gi1/0/2 128 200000 Root Fwd

Verify the configurations of Switch C in instance 2:

Switch(config)#show spanning-tree mst instance 2

MST-Instance 2

Root Bridge

Priority : 0

Address : 3c-46-d8-9d-88-f7

Local bridge is the root bridge

Designated Bridge

Priority : 0

Address : 3c-46-d8-9d-88-f7

Local Bridge

Priority: 0

Address: 3c-46-d8-9d-88-f7

Interface Prio Cost Role Status

Gi1/0/1 128 200000 Desg Fwd

Gi1/0/2 128 200000 Desg Fwd

6

Appendix: Default Parameters

Default settings of the Spanning Tree feature are listed in the following table.

Table 6-1 Default Settings of the Global Parameters

Parameter Default Setting
Spanning-tree Disabled
Mode STP
CIST Priority 32768
Hello Time 2 seconds
Max Age 20 seconds
Forward Delay 15 seconds
Tx Hold Count 5 pps
Max Hops 20 hops

Table 6-2 Default Settings of the Port Parameters

Parameter Default Setting
Status Disabled
Priority 128
Ext-Path Cost Auto
In-Path Cost Auto
Edge Port Disabled
P2P Link Auto
MCheck----

Table 6-3 Default Settings of the MSTP Instance

Parameter Default Setting
Status Disabled
Revision Level 0
Priority 32768
Port Priority 128
Path Cost Auto

Table 6-4 Default Settings of the STP Security

Parameter Default Setting
Loop Protect Disabled
Root Protect Disabled
TC Guard Disabled
BPDU Protect Disabled
BPDU Filter Disabled
BPDU Forward Enabled

Part 16

Configuring LLDP

CHAPTERS

  1. LLDP
  2. LLDP Configurations
  3. LLDP-MED Configurations
  4. Viewing LLDP Settings
  5. Viewing LLDP-MED Settings
  6. Configuration Example
  7. Appendix: Default Parameters

1 LLDP

1.1 Overview

LLDP (Link Layer Discovery Protocol) is a neighbor discovery protocol that is used for network devices to advertise information about themselves to other devices on the network. This protocol is a standard IEEE 802.1ab defined protocol and runs over the Layer 2 (the data-link layer), which allows for interoperability between network devices of different vendors.

With LLDP enabled, the switch can get its neighbors' information, and network administrators can use the NMS (Network Management System) to gather these information, helping them to know about the network topology, examine the network connectivity and troubleshoot the network faults.

LLDP-MED (LLDP for Media Endpoint Discovery) is an extension of LLDP and is used to advertise information between network devices and media endpoints. It is specially used together with Auto VoIP (Voice over Internet Protocol) to allow VoIP device to access the network. VoIP devices can use LLDP-MED for auto-configuration to minimize the configuration effort.

1.2 Supported Features

The switch supports LLDP and LLDP-MED.

LLDP allows the local device to encapsulate its management address, device ID, interface ID and other information into a LLDPDU (Link Layer Discovery Protocol Data Unit) and periodically advertise this LLDPDU to its neighbor devices. The neighbors store the received LLDPDU in a standard MIB (Management Information Base), making it possible for the information to be accessed by a NMS (Network Management System) using a management protocol such as the SNMP (Simple Network Management Protocol).

LLDP-MED allows the network device to send its information including Auto VoIP information, PoE (Power over Ethernet) capacity and more to the media endpoint devices (for example, IP phones) for auto-configuration. The media endpoint devices receive the Auto VoIP information and finish the auto-configuration, then send the voice traffic with the desired configuration, which can provide preferential treatment to the voice traffic.

2 LLDP Configurations

To configure the LLDP function, follow the steps:

1) Configure the LLDP feature globally. 2) Configure the LLDP feature for the port.

2.1 Using the GUI

2.1.1 Configuring LLDP Globally

Choose the L2 FEATURES > LLDP > LLDP Config > Global Config to load the following page.

Figure 2-1 Global ConfigGlobal Config LLDP: □ Enable LLDP Forwarding: □ Enable Parameter Config Apply Transmit Interval: 30 seconds (5-32768) Hold Multiplier: 4 (2-10) Transmit Delay: 2 seconds (1-8192) Reinitialization Delay: 2 seconds (1-10) Notification Interval: 5 seconds (5-3600) Fast Start Repeat Count: 3 (1-10) Appl…

Follow these steps to configure the LLDP feature globally.

1) In the Global Config section, enable LLDP. You can also enable the switch to forward LLDP messages when LLDP function is disabled. Click Apply.

LLDP: Enable or disable LLDP globally.

LLDP (Optional): Enable or disable LLDP forwarding when LLDP is disabled. When LLDP Forwarding is disabled, this option can be enabled and the switch can forward LLDP packets.

3) In the Parameter Config section, configure the LLDP parameters. Click Apply.

Transmit IntervalEnter the interval between successive LLDP packets that are periodically sent from the local device to its neighbors. The default is 30 seconds.
Hold MultiplierThis parameter is a multiplier on the Transmit Interval that determines the actual TTL (Time To Live) value used in an LLDP packet. TTL is the duration that the neighbor device should hold the received LLDP packet before discarding it. The default value is 4.TTL= Hold Multiplier * Transmit Interval.
Transmit DelaySpecify the amount of time that the local device waits before sending another LLDP packet to its neighbors. When the local information changes, the local device will send LLDP packets to inform its neighbors. If frequent changes occur to the local device, LLDP packets will flood. After specifying a transmit delay time, the local device will wait for a delay time to send LLDP packets when changes occur to avoid frequent LLDP packet forwarding. The default is 2 seconds.
Reinitialization DelaySpecify the amount of delay from when Admin Status of ports becomes 'Disable' until reinitialization will be attempted. The default value is 2 seconds.
Notification IntervalEnter the interval between successive Trap messages that are periodically sent from the local device to the NMS. The default is 5 seconds.
Fast Start Repeat CountSpecify the number of LLDP packets that the local port sends when its Admin status is changed from Disable (or Rx_Only) to Tx&RX (or Tx_Only). The default is 3.In this case, the local device will shorten the Transmit Interval of LLDP packets to 1 second so it is quickly discovered by its neighbors. After the specified number of LLDP packets are sent, the Transmit Interval will be restored to the specified value.

2.1.2 Configuring LLDP For the Port

Choose the menu L2 FEATURES > LLDP > LLDP Config > Port Config to load the following page.

Figure 2-2 Port Config

UNIT1
PortAdmin StatusNotification ModeManagement AddressIncluded TLVs
1/0/1Tx & RxDisabledPDSCSDSNSAPVVPVALAPSFSPW
1/0/2Tx & RxDisabledPDSCSDSNSAPVVPVALAPSFSPW
1/0/3Tx & RxDisabledPDSCSDSNSAPVVPVALAPSFSPW
1/0/4Tx & RxDisabledPDSCSDSNSAPVVPVALAPSFSPW
1/0/5Tx & RxDisabledPDSCSDSNSAPVVPVALAPSFSPW
1/0/6Tx & RxDisabledPDSCSDSNSAPVVPVALAPSFSPW
1/0/7Tx & RxDisabledPDSCSDSNSAPVVPVALAPSFSPW
1/0/8Tx & RxDisabledPDSCSDSNSAPVVPVALAPSFSPW
1/0/9Tx & RxDisabledPDSCSDSNSAPVVPVALAPSFSPW
1/0/10Tx & RxDisabledPDSCSDSNSAPVVPVALAPSFSPW

Follow these steps to configure the LLDP feature for the interface.

1) Select one or more ports to configure. 2) Configure the Admin Status and Notification Mode for the port.

Admin Status: Specify the Admin Status for the port to deal with LLDP packets.

Disabled: The port will not transmit LLDP packets or process the received LLDP packets.

Tx_Only: The port will only transmit LLDP packets but not process the received LLDP packets.

Rx_Only: The port will only process the received LLDP packets but not transmit LLDP packets.

Tx & Rx: The port will transmit LLDP packets and process the received LLDP packets.

Notification ModeEnable or disable the Notification mode for the port. With this option enabled, the local device will send Trap messages to inform the NMS when the information of the neighbor device connected to this port changes.
Management AddressSpecify the Management IP address of the port to be notified to the neighbor. Value 0.0.0.0 means the port will notify its default management address to the neighbor.

3) Select the TLVs (Type/Length/Value) included in the LLDP packets according to your needs.

Included TLVs: Configure the TLVs included in the outgoing LLDP packets.

The switch supports the following TLVs:

PD: Used to advertise the port description defined by the IEEE 802 LAN station.

SC: Used to advertise the supported functions and whether or not these functions are enabled.

SD: Used to advertise the system's description including the full name and version identification of the system's hardware type, software operating system, and networking software.

SN: Used to advertise the system name.

SA: Used to advertise the local device's management address to make it possible to be managed by SNMP.

PV: Used to advertise the 802.1Q VLAN ID of the port.

VP: Used to advertise the protocol VLAN ID of the port.

VA: Used to advertise the name of the VLAN which the port is in.

LA: Used to advertise whether the link is capable of being aggregated, whether the link is currently in an aggregation, and the port ID when it is in an aggregation.

PS: Used to advertise the port's attributes including the duplex and bit-rate capability of the sending IEEE 802.3 LAN node that is connected to the physical medium, the current duplex and bit-rate settings of the sending IEEE 802.3 LAN node and whether these settings are the result of auto-negotiation during link initiation or of manual set override action.

FS: Used to advertise the maximum frame size capability of the implemented MAC and PHY.

PW: Used to advertise the port's PoE (Power over Ethernet) support capabilities.

4) Click Apply.

2.2 Using the CLI

2.2.1 Global Config

Enable the LLDP feature on the switch and configure the LLDP parameters.

Step 1 configure

Enter global configuration mode.

Step 2 lldp

Enable the LLDP feature on the switch.

Step 3 lldp forward_message

(Optional) Enable the switch to forward LLDP messages when LLDP function is disabled.

Step 4 lldp hold-multiplier

multiplier

(Optional) Specify the amount of time the neighbor device should hold the received information before discarding it. This parameter is a multiplier on the Transmit Interval that determines the actual TTL (Time To Live) value used in an LLDP packet. TTL is the duration that the neighbor device should hold the received LLDP packet before discarding it.

TTL = Hold Multiplier * Transmit Interval.

multiplier: Specify the hold-multiplier. The valid value ranges from 2 to 10, and the default value is 4.

Step 5 lldp timer { tx-interval

tx-interval | tx-delay tx-delay | reinit-delay reinit-delay | notify-interval | fast-count fast-count }

(Optional) Configure the timers for LLDP packet forwarding.

tx-interval: Enter the interval between successive LLDP packets that are periodically sent from the local device to its neighbors.

tx-delay: Specify the amount of time that the local device waits before sending another LLDP packet to its neighbors. The default is 2 seconds.

reinit-delay: Specify the amount of time that the local device waits before sending another LLDP packet to its neighbors. The default is 2 seconds.

notify-interval: Enter the interval between successive Trap messages that are periodically sent from the local device to the NMS. The default is 5 seconds.

fast-count: Specify the number of packets that the local port sends when its Admin Status changes. The default is 3.

Step 6 show lldp

Display the LLDP information.

Step 7 end

Return to Privileged EXEC Mode.

Step 8 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the following parameters: lldp timer=4, tx-interval=30 seconds, tx-delay=2 seconds, reinit-delay=3 seconds, notify-interval=5 seconds, fast-count=3.

Switch#configure

Switch(config)#lldp

Switch(config)#lldp hold-multiplier 4

Switch(config)#lldp timer tx-interval 30 tx-delay 2 reinit-delay 3 notify-interval 5 fast-count 3

Switch(config)#show lldp

LLDP Status: Enabled

LLDP Forward Message: Disabled

Tx Interval: 30 seconds

TTL Multiplier: 4

Tx Delay: 2 seconds

Initialization Delay: 2 seconds

Trap Notification Interval: 5 seconds

Fast-packet Count: 3

LLDP-MED Fast Start Repeat Count: 4

Switch(config)#end

Switch#copy running-config startup-config

2.2.2 Port Config

Select the desired port and set its Admin Status, Notification Mode and the TLVs included in the LLDP packets.

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list ]

Enter interface configuration mode.

Step 3 lldp receive

(Optional) Set the mode for the port to receive LLDP packets. It is enabled by default.

Step 4 lldp transmit

(Optional) Set the mode for the port to send LLDP packets. It is enabled by default.

Step 5 lldp snmp-trap

(Optional) Enable the Notification Mode feature on the port. If it is enabled, the local device will send trap messages to the NMS when neighbor information changes. It is disabled by default.

Step 6 lldp tlv-select

(Optional) Configure the TLVs included in the outgoing LLDP packets. By default, the outgoing LLDP packets include all TLVs.

Step 7 show lldp interface { fastEthernet

port | gigabitEthernet port | ten-gigabitEthernet port}

Display LLDP configuration of the corresponding port.

Step 8 end

Return to Privileged EXEC Mode.

Step 9 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure port 1/0/1. The port can receive and transmit LLDP packets, its notification mode is enabled, and the outgoing LLDP packets include all TLVs.

Switch#configure

Switch(config)#lldp

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#lldp receive

Switch(config-if)#lldp transmit

Switch(config-if)#lldp snmp-trap

Switch(config-if)#lldp tlv-select all

Switch(config-if)#show lldp interface gigabitEthernet 1/0/1

LLDP interface config:

gigabitEthernet 1/0/1:

Admin Status: TxRx

SNMP Trap: Enabled

TLV Status

Port-Description Yes

System-Capability Yes

System-Description Yes

System-Name Yes

Management-Address Yes

Port-VLAN-IDYes
Protocol-VLAN-IDYes
VLAN-NameYes
Link-AggregationYes
MAC-PhysicYes
Max-Frame-SizeYes
PowerYes

Switch(config-if)#end

Switch#copy running-config startup-config

3 LLDP-MED Configurations

To configure LLDP-MED function, follow the steps:

1) Enable LLDP feature globally and configure the LLDP parameters for the ports. 2) Configure LLDP-MED fast repeat count globally. 3) Enable and configure the LLDP-MED feature on the port.

Configuration Guidelines

LLDP-MED is used together with Auto VoIP to implement VoIP access. Besides the configuration of LLDP-MED feature, you also need to configure the Auto VoIP feature. Refer to Configuring QoS for detailed instructions.

3.1 Using the GUI

3.1.1 Configuring LLDP Globally

Enable LLDP globally and configure the LLDP parameters for the ports. For the details of LLDP configuration, refer to LLDP Configuration.

3.1.1 Configuring LLDP-MED Globally

Choose the menu L2 FEATURES > LLDP > LLDP-MED Config > Global Config to load the following page.

Figure 3-1 LLDP-MED Parameters ConfigLLDP-MED Parameters Config Fast Start Repeat Count: 4 (1-10) Device Class: Network Connectivity Apply

Configure the Fast Start Count and view the current device class. Click Apply.

Fast Start Specify the number of successive LLDP-MED frames that the local device sends Repeat Count when fast start mechanism is activated. The default is 4.

If the LLDP-MED status on the port is changed from Disable to Enable, the fast start mechanism will be activated, and the local device will send the specified number of LLDP packets carrying LLDP-MED information to the endpoints. After that, the Transmit Interval will be restored to the specified value.

Device Class Displays the current device class.

LLDP-MED defines two device classes: Network Connectivity Device and Endpoint Device. The switch is a Network Connectivity device.

3.1.2 Configuring LLDP-MED for Ports

Choose the menu L2 FEATURES > LLDP > LLDP-MED Config > Port Config to load the following page.

Figure 3-2 LLDP-MED Port ConfigPort Config UNIT1 Port LLDP-MED Status Included TLVs 1/0/1 Disabled Detail 1/0/2 Disabled Detail 1/0/3 Disabled Detail 1/0/4 Disabled Detail 1/0/5 Disabled Detail 1/0/6 Disabled Detail 1/0/7 Disabled Detail 1/0/8 Disabled Detail 1/0/9 Disabled Detail 1/0/10 Disabled Detail Total: 54

Follow these steps to enable LLDP-MED:

1) Select the desired port and enable LLDP-MED. Click Apply. 2) Click Detail to enter the following page. Configure the TLVs included in the outgoing LLDP packets. If Location Identification is selected, you need configure the Emergency Number or select Civic Address to configure the details. Click Apply.

Figure 3-3 LLDP-MED Port Config-DetailIncluded TLVs Detail(Port:1/0/1) Included TLVs All Network Policy Location Identification Extended Power-Via-MDI Inventory Location Identification Parameters Emergency Number Civic Address (Parameters in total should not exceed 230 characters in length) What: Switch Country Code: CN China(Default) L…

Network PolicyUsed to advertise VLAN configuration and the associated Layer 2 and Layer 3 attributes of the port to the Endpoint devices.
Location IdentificationUsed to assign the location identifier information to the Endpoint devices.If this option is selected, you can configure the emergency number or the detailed address of the Endpoint device in the Location Identification Parameters section.
Extended Power-Via-MDIUsed to advertise the detailed PoE information including power supply priority and supply status between LLDP-MED Endpoint devices and Network Connectivity devices.
Inventory Used to advertise the inventory information. The Inventory TLV set contains seven basic Inventory management TLVs, that is, Hardware Revision TLV, Firmware Revision TLV, Software Revision TLV, Serial Number TLV, Manufacturer Name TLV, Model Name TLV and Asset ID TLV.
Emergency NumberEmergency number is Emergency Call Service ELIN identifier, which is used during emergency call setup to a traditional CAMA or ISDN trunk-based PSAP.

Civic Address

The Civic address is defined to reuse the relevant sub-fields of the DHCP option for Civic Address based Location Configuration Information as specified by IETF.

What: Specify the role type of the local device, DHCP Server, Switch or LLDP-MED Endpoint.

Country Code: Enter the country code defined by ISO 3166, for example, CN, US.

Language, Province/State etc.: Enter the regular details.

3.2 Using the CLI

3.2.1 Global Config

Step 1 configure

Enter global configuration mode.

Step 2 lldp

Enable the LLDP feature on the switch.

Step 3 lldp med-fast-count

count

(Optional) Specify the number of successive LLDP-MED frames that the local device sends when fast start mechanism is activated. When the fast start mechanism is activated, the local device will send the specified number of LLDP packets carrying LLDP-MED information.

count: The valid value are from 1 to 10. The default is 4.

Step 4 show lldp

Display the LLDP information.

Step 5 end

Return to Privileged EXEC Mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure LLDP-MED fast count as 4:

Switch#configure

Switch(config)#lldp

Switch(config)#lldp med-fast-count 4

Switch(config)#show lldp

LLDP Status:

Enabled

LLDP Forward Message:Disabled
Tx Interval:30 seconds
TTL Multiplier:4
Tx Delay:2 seconds
Initialization Delay:2 seconds
Trap Notification Interval:5 seconds
Fast-packet Count:3
LLDP-MED Fast Start Repeat Count:4

Switch(config)#end

Switch#copy running-config startup-config

3.2.2 Port Config

Select the desired port, enable LLDP-MED and select the TLVs (Type/Length/Value) included in the outgoing LLDP packets according to your needs.

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list ]Enter interface configuration mode.

Step 3 lldp med-status

(Optional) Enable LLDP-MED on the port. It is disabled by default.

Step 4 lldp med-tlv-select { [inventory-management] [location] [network-policy] [power-management] [all] }

(Optional) Configure the LLDP-MED TLVs included in the outgoing LLDP packets. By default, the outgoing LLDP packets include all TLVs.

If LLDP-MED Location TLV is selected, configure the parameters as follows:

lldp med-location {emergency-number identifier | civic-address [language language | province-state province-state | lci-county-name county | lci-city city | street street | house-number house-number | name name | postal-zipcode postal-zipcode | room-number room-number | post-office-box post-office-box | additional additional | country-code country-code | what { dhcp-server | endpoint | switch }}

Configure the LLDP-MED Location TLV included in the outgoing LLDP packets. Used to assign the location identifier information to the Endpoint devices.

identifier: Configure the emergency number to call CAMA or PSAP. The number should contain 10-25 characters.

language, province-state, county, etc.: Configure the address in the IETF defined address format.

Step 5 show lldp interface { fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port }Display LLDP configuration of the corresponding port.
Step 6 endReturn to Privileged EXEC Mode.
Step 7 copy running-config startup-configSave the settings in the configuration file.

The following example shows how to enable LLDP-MED on port 1/0/1, configure the LLDP-MED TLVs included in the outgoing LLDP packets.

Switch(config)#lldp

Switch(config)#lldp med-fast-count 4

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#lldp med-status

Switch(config-if)#lldp med-tlv-select all

Switch(config-if)#show lldp interface gigabitEthernet 1/0/1

LLDP interface config:

gigabitEthernet 1/0/1:

Admin Status: TxRx

SNMP Trap: Enabled

TLV Status


Port-Description Yes

System-Capability Yes

System-Description Yes

System-Name Yes

Management-Address Yes

Port-VLAN-ID Yes

Protocol-VLAN-ID Yes

VLAN-Name Yes

Link-Aggregation Yes

MAC-Physic Yes

Max-Frame-Size Yes

Power Yes

LLDP-MED Status: Enabled

TLV Status

Network Policy Yes

Location Identification Yes

Extended Power Via MDI Yes

Inventory Management Yes

Switch(config)#end

Switch#copy running-config startup-config

4 Viewing LLDP Settings

This chapter introduces how to view the LLDP settings on the local device.

4.1 Using GUI

4.1.1 Viewing LLDP Device Info

■ Viewing the Local Info

Choose the menu L2 FEATURES > LLDP > LLDP Config > Local Info to load the following page.

Figure 4-1 Local InfoAuto Refresh | Port ID | Selected | Unselected | Not Available | | :--- | :--- | :--- | :--- | | Local Interface: | 1/0/1 | | | | Chassis ID Subtype: | MAC address | | | | Chassis ID: | 5C-E9-31-50-A6-34 | | | | Port ID Subtype: | Interface name | | | | Port ID: | gigabitEthernet 1/0/1 | | | | TTL:…

Follow these steps to view the local information:

1) In the Auto Refresh section, enable the Auto Refresh feature and set the Refresh Rate according to your needs. Click Apply. 2) In the Local Info section, select the desired port and view its associated local device information.

Local Interface Displays the local port ID.
Chassis ID Subtype Displays the Chassis ID type.
Chassis ID Displays the value of the Chassis ID.
Port ID Subtype Displays the Port ID type.
Port ID Displays the value of the Port ID.
TTL Specify the amount of time in seconds the neighbor device should hold the received information before discarding it.
Port Description Displays the description of the local port.
System Name Displays the system name of the local device.
System Description Displays the system description of the local device.
System Capabilities SupportedDisplays the supported capabilities of the local system.
System Capabilities EnabledDisplays the primary functions of the local device.
Management Address TypeDisplays the management IP address type of the local device.
Management AddressDisplays the management IP address of the local device.
Management Address Interface TypeDisplays the interface numbering type that is used to define the interface ID.
Management Address Interface IDDisplays the interface ID that is used to identify the specific interface associated with the MAC address of the local device.
Management Address OIDDisplays the OID (Object Identifier) of the local device. A value of 0 means that the OID is not provided.
Port VLAN ID(PVID) Displays the PVID of the local port.
Port And Protocol VLAN ID(PPVID)Displays the PPVID of the local port.
Port And Protocol SupportedDisplays whether the local device supports port and protocol VLAN feature.
Port And Protocol VLAN EnabledDisplays the status of the port and protocol VLAN feature.
VLAN Name of VLAN 1Displays the VLAN name of VLAN 1 for the local device.
Protocol Identify Displays the particular protocol that the local device wants to advise.
Auto-negotiation SupportedDisplays whether the local device supports auto-negotiation.
Auto-Negotiation EnableDisplays the status of auto-negotiation for the local device.
OperMau Displays the OperMau (Optional Mau) field of the TLV configured by the local device.
Link Aggregation SupportedDisplays whether the local device supports link aggregation.
Link Aggregation EnabledDisplays the status of link aggregation fot the local device.
Aggregation Port ID Displays the aggregation port ID of the local device.
Power Port Class Displays the power port class of the local device.
PSE Power SupportedDisplays whether the local device supports PSE power.
PSE Power Enabled Displays the status of PSE power for the local device.
PSE Pairs Control AbilityDisplays whether the PSE pairs can be controlled for the local device.
Maximum Frame SizeDisplays the maximum frame size supported by the local device.

■ Viewing the Neighbor Info

Choose the menu L2 FEATURES > LLDP > LLDP Config > Neighbor Info to load the following page.

Figure 4-2 Neighbor InfoAuto Refresh Auto Refresh: Enable Apply Neighbor Info UNIT1 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 37 39 41 43 45 47 49 51 53 38 40 42 44 46 48 50 52 54 Selected Unselected Not Available Port 1/0/1 System Name Chassis ID System Description…

Follow these steps to view the neighbor information:

1) In the Auto Refresh section, enable the Auto Refresh feature and set the Refresh Rate according to your needs. Click Apply. 2) In the Neighbor Info section, select the desired port and view its associated neighbor device information.

System Name Displays the system name of the neighbor device.

Chassis ID Displays the Chassis ID of the neighbor device.

System Displays the system description of the neighbor device.

Description

Neighbor Port Displays the port ID of the neighbor device that is connected to the local port.

Information Click to view the details of the neighbor device.

4.1.2 Viewing LLDP Statistics

Choose the menu L2 FEATURES > LLDP > LLDP Config > Statistics Info to load the following page.

Figure 4-3 Static InfoAuto Refresh Auto Refresh: ☐ Enable Apply Global Statistics Last Update Total Inserts Total Deletes Total Drops Total Age-outs 0 days 00h:19m:16s 0 0 0 0 Neighbor Statistics UNIT1 Port Transmit Total Receive Total Discards Errors.Age-outs Discarded TLVs Unknown TLVs 1/0/1 17 0 0 0 0 0 0 1/0/2 0 0 0…

Follow these steps to view LLDP statistics:

1) In the Auto Refresh section, enable the Auto Refresh feature and set the Refresh Rate according to your needs. Click Apply. 2) In the Global Statistics section, view the global statistics of the local device.

Last Update Displays the latest update time of the statistics.

Total Inserts Displays the total number of neighbors during the latest update time.

Total Deletes

Displays the number of neighbors deleted by the local device. The port will delete neighbors when the port is disabled or the TTL of the LLDP packets sent by the neighbor is 0.

Total Drops

Displays the number of neighbors dropped by the local device. Each port can learn a maximum of 80 neighbor devices, and subsequent neighbors will be dropped when the limit is exceeded.

Total Age-outs Displays the number of neighbors that have aged out on the local device.

3) In the Neighbors Statistics section, view the statistics of the corresponding port.

Transmit Total: Displays the number of LLDP packets sent by this port.

Receive Total: Displays the number of LLDP packets received by this port.

Discards: Displays the number of LLDP packets discarded by this port.

Errors: Displays the number of error LLDP packets received by this port.

Age-outs: Displays the number of aged out neighbors that are connected to the port.

Discarded TLVs: Displays the number of discarded TLVs.

Unknown TLVs: Displays the number of unknown TLVs received by this port.

4.2 Using CLI

■ Viewing the Local Info

show lldp local-information interface { fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port }

View the LLDP details of a specific port or all the ports on the local device.

■ Viewing the Neighbor Info

show lldp neighbor-information interface { fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port }

Display the information of the neighbor device which is connected to the port.

Viewing LLDP Statistics

show lldp traffic interface { fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port }

View the statistics of the corresponding port on the local device.

5 Viewing LLDP-MED Settings

5.1 Using GUI

Choose the menu L2 FEATURES > LLDP > LLDP-MED Config > Local Info to load the following page.

Viewing the Local Info

Figure 5-1 LLDP-MED Local InfoAuto Refresh | Device Type | Network Connectivity | | :--- | :--- | | Application Type: | Reserved | | Unknown Policy Flag: | Yes | | VLAN tagged: | 0 | | Media Policy VLAN ID: | 0 | | Media Policy Layer 2 Priority: | 0 | | Media Policy DSCP: | 0 | | Location Data Format: | Civic Address LCI |

Follow these steps to view LLDP-MED local information:

1) In the Auto Refresh section, enable the Auto Refresh feature and set the Refresh Rate according to your needs. Click Apply. 2) In the LLDP-MED Local Info section, select the desired port and view the LLDP-MED settings.

Local Interface Displays the local port ID.
Device Type Displays the local device type defined by LLDP-MED.LLDP-MED.
Application TypeDisplays the supported applications of the local device.
Unknown Policy FlagDisplays the unknown location settings included in the network policy TLV.
VLAN tagged Displays the VLAN Tag type of the applications, tagged or untagged.
Media Policy VLAN IDDisplays the 802.1Q VLAN ID of the port.
Media Policy Layer 2 PriorityDisplays the Layer 2 priority used in the specific application.
Media Policy DSCPDisplays the DSCP value used in the specific application.
Location Data FormatDisplays the Location ID data format of the local device.
What Displays the type of the local device.
Country Code Displays the country code of the local device.
Power Type Displays the whether the local device is a PSE device or PD device.
Power Source Displays the power source of the local device.
Power PriorityDisplays the power priority of the local device, which represents the priority of power that is received by the PD devices, or the priority of power that the PSE devices supply.
Power Value Displays the power required by the PD device or supplied by the PSE device.
Hardware RevisionDisplays the hardware revision of the local device.
Firmware RevisionDisplays the firmware revision of the local device.
Software RevisionDisplays the software revision of the local device.
Serial Number Displays the serial number of the local device.
Manufacturer NameDisplays the manufacturer name of the local device.
Model Name Displays the model name of the local device.

Asset ID Displays the asset ID of the local device.

Viewing the Neighbor Info

Choose the menu L2 FEATURES > LLDP > LLDP-MED Config > Neighbor Info to load the following page.

Figure 5-2 LLDP-MED Neighbor InfoAuto Refresh Auto Refresh: Enable Neighbor Info UNIT1 2 4 6 8 10 12 14 16 18 20 22 24 26 28 1 3 5 7 9 11 13 15 17 19 21 23 25 27 Selected Unselected Not Available Port 1/0/1 Device Type Application Type Location Data Format Power Type Information No Entries in this table.

Follow these steps to view LLDP-MED neighbor information:

1) In the Auto Refresh section, enable the Auto Refresh feature and set the Refresh Rate according to your needs. Click Apply. 2) In the Neighbor Info section, select the desired port and view the LLDP-MED settings.

Device Type Displays the LLDP-MED device type of the neighbor device.

Application Type Displays the application type of the neighbor device.

Location Data Format Displays the location type of the neighbor device.

Power Type Displays the power type of the neighbor device.

Information View more LLDP-MED details of the neighbor device.

5.2 Using CLI

■ Viewing the Local Info

show lldp local-information interface { fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port }

View the LLDP details of a specific port or all the ports on the local device.

■ Viewing the Neighbor Info

show lldp neighbor-information interface { fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port }

Display the information of the neighbor device which is connected to the port.

■ Viewing LLDP Statistics

show lldp traffic interface { fastEthernet port | gigabitEthernet port | tengigabitEthernet port }

View the statistics of the corresponding port.

6 Configuration Example

6.1 Configuration Example for LLDP

6.1.1 Network Requirements

The network administrator needs to view the information of the devices in the company network to know about the link situation and network topology so that he can troubleshoot potential network faults in advance.

6.1.2 Network Topology

The following situation is used as an example:

Port Gi1/0/1 on Switch A is directly connected to port Gi1/0/2 on Switch B. Switch B is directly connected to the PC. The administrator can view the device information using the NMS.

Figure 6-1 LLDP Network Topologygraph LR A["Switch A"] -->|Gi1/0/1| B["Switch B"] B -->|Gi1/0/2| A B --> C["PC"]

6.1.3 Configuration Scheme

LLDP can meet the network requirements. Enable the LLDP feature globally on Switch A and Switch B. Configure the related LLDP parameters on the corresponding ports.

Configuring Switch A and Switch B:

The configurations of Switch A and Switch B are similar. The following introductions take Switch A as an example. Demonstrated with S6500-24GP4XF, this chapter provides configuration procedures in two ways: using the GUI and using the CLI.

6.1.4 Using the GUI

1) Choose the menu L2 FEATURES > LLDP > LLDP Config > Global Config to load the following page. Enable LLDP globally and configure the related parameters. Here we take the default settings as an example.

Figure 6-2 LLDP Global ConfigGlobal Config LLDP: ✓ Enable LLDP Forwarding: ☐ Enable Parameter Config Apply Transmit Interval: 30 seconds (5-32768) Hold Multiplier: 4 (2-10) Transmit Delay: 2 seconds (1-8192) Reinitialization Delay: 2 seconds (1-10) Notification Interval: 5 seconds (5-3600) Fast Start Repeat Count: 3 (1-10) Appl…

2) Choose the menu L2 FEATURES > LLDP > LLDP Config > Port Config to load the following page. Set the Admin Status of port Gi1/0/1 as Tx&Rx, enable Notification Mode and configure all the TLVs included in the outgoing LLDP packets.

Figure 6-3 LLDP Port ConfigPort Config UNIT1 Port Admin Notification Management Status Mode Address Included TLVs Tx & Rx ▼ Enable ▼ ✓ 1/0/1 Tx & Rx Enabled PD SC SD SN SA PV VP VA LA PS FS PW 1/0/2 Tx & Rx Disabled PD SC SD SN SA PV VP VA LA PS FS PW 1/0/3 Tx & Rx Disabled PD SC SD SN SA PV VP VA LA PS FS PW 1/0/4 Tx & Rx Di…

6.1.5 Using CLI

1) Enable LLDP globally and configure the corresponding parameters.

Switch_A#configure

Switch_A(config)#lldp

Switch_A(config)#lldp hold-multiplier 4

Switch_A(config)#lldp timer tx-interval 30 tx-delay 2 reinit-delay 3 notify-interval 5 fast-count 3

2) Set the Admin Status of port Gi1/0/1 to Tx&Rx, enable Notification Mode and configure all the TLVs included in the outgoing LLDP packets.

Switch_A#configure

Switch_A(config)#interface gigabitEthernet 1/0/1

Switch_A(config-if)#lldp receive

Switch_A(config-if)#lldp transmit

Switch_A(config-if)#lldp snmp-trap

Switch_A(config-if)#lldp tlv-select all

Switch_A(config-if)#end

Switch_A#copy running-config startup-config

Verify the Configurations

View LLDP settings globally

Switch_A#show lldp

LLDP Status: Enabled

LLDP Forward Message: Disabled

Tx Interval: 30 seconds

TTL Multiplier: 4

Tx Delay: 2 seconds

Initialization Delay: 2 seconds

Trap Notification Interval: 5 seconds

Fast-packet Count: 3

LLDP-MED Fast Start Repeat Count: 4

View LLDP settings on each port

Switch_A#show lldp interface gigabitEthernet 1/0/1

LLDP interface config:

gigabitEthernet 1/0/1:

Admin Status: TxRx

SNMP Trap: Enabled

TLVStatus
-------
Port-DescriptionYes
System-CapabilityYes
System-DescriptionYes
System-NameYes
Management-AddressYes
Port-VLAN-IDYes
Protocol-VLAN-IDYes
VLAN-NameYes
Link-AggregationYes
MAC-PhysicYes
Max-Frame-SizeYes
PowerYes
LLDP-MED Status:Disabled
TLVStatus
-------
Network PolicyYes
Location IdentificationYes
Extended Power Via MDIYes
Inventory ManagementYes

View the Local Info

Switch_A#show lldp local-information interface gigabitEthernet 1/0/1

LLDP local Information:

gigabitEthernet 1/0/1:

Chassis type:MAC address
Chassis ID:00:0A:EB:13:23:97
Port ID type:Interface name
Port ID:GigabitEthernet1/0/1
Port description:GigabitEthernet1/0/1 Interface

TTL: 120

System name: S6500-24GP4XF

System description: Omada Pro 24-Port Gigabit Stackable L3 Managed PoE+ Switch with 4 10G Slots

System capabilities supported: Bridge Router

System capabilities enabled: Bridge Router

Management address type: ipv4

Management address: 192.168.0.226

Management address interface type: IfIndex

Management address interface ID: 1

Management address OID: 0

Port VLAN ID (PVID): 1

Port and protocol VLAN ID (PPVID): 0

Port and protocol VLAN supported: Yes

Port and protocol VLAN enabled: No

VLAN name of VLAN 1: System-VLAN

Protocol identity:

Auto-negotiation supported: Yes

Auto-negotiation enabled: Yes

OperMau: speed(1000)/duplex(Full)

Link aggregation supported: Yes

Link aggregation enabled: No

Aggregation port ID: 0

Power port class: PD

PSE power supported: No

PSE power enabled: No

PSE pairs control ability: No

Maximum frame size: 1518

LLDP-MED Capabilities: Capabilities

Network Policy

Location Identification Inventory

Device Type:Network Connectivity
Application type:Reserved
Unknown policy:Yes
Tagged:No
VLAN ID:0
Layer 2 Priority:0
DSCP:0
Location Data Format:Civic Address LCI
- What:Switch
- Country Code:CN
Hardware Revision:S6500-24GP4XF 1.0
Firmware Revision:Reserved
Software Revision:3.0.0 Build 20170918 Rel.71414(s)
Serial Number:Reserved
Manufacturer Name:TP-Link
Model Name:S6500-24GP4XF 1.0
Asset ID:unknown

View the Neighbor Info

Switch_A#show lldp neighbor-information interface gigabitEthernet 1/0/1

LLDP Neighbor Information:

gigabitEthernet 1/0/1:

Neighbor index 1:

Chassis type:MAC address
Chassis ID:00:0A:EB:13:18:2D
Port ID type:Interface name
Port ID:GigabitEthernet1/0/2
Port description:GigabitEthernet1/0/2 Interface
TTL:120
System name:SG6654X
System description:Omada 48-Port Gigabit Stackable L3 Managed Switch with 24-Port PoE+
System capabilities supported:Bridge Router
System capabilities enabled:Bridge Router
Management address type:ipv4
Management address:192.168.0.1
Management address interface type:IfIndex
Management address interface ID:1
Management address OID:0
Port VLAN ID(PVID):1
Port and protocol VLAN ID(PPVID):0
Port and protocol VLAN supported:Yes
Port and protocol VLAN enabled:No
VLAN name of VLAN 1:System-VLAN
Protocol identity:
Auto-negotiation supported:Yes
Auto-negotiation enabled:Yes
OperMau:speed(1000)/duplex(Full)
Link aggregation supported:Yes
Link aggregation enabled:No
Aggregation port ID:0
Power port class:PSE
PSE power supported:Yes
PSE power enabled:Yes
PSE pairs control ability:No

6.2 Example for LLDP-MED

6.2.1 Network Requirements

As the following figure shows, an IP phone and a PC are both connected to port 1/0/1 of the switch. It is required that the voice data stream is sent to VLAN2 and other untagged data stream is sent to the default VLAN1.

Figure 6-1 LLDP-MED Network Topologygraph LR PC["PC"] --> IPPhone["IP Phone"] IPPhone --> Switch["Switch"] Switch -->|Gi1/0/1| IPPhone

6.2.2 Configuration Scheme

LLDP-MED allows the switch to send its Auto VoIP information to the IP phones for auto-configuration. In this example, you can configure Auto VoIP and LLDP-MED to meet the network requirements.

The configuration overview is as follows:

1) Create VLAN2 for the voice data and keep the PVID of port 1/0/1 as the default value 1. In this way, all the untagged packets from the PC are sent to VLAN1; all the packets with VLAN Tag 2 from the IP phone are sent to VLAN2. 2) Configure Auto VoIP on port 1/0/1. 3) Enable LLDP globally. 4) Configure LLDP-MED on port 1/0/1.

Demonstrated with T1600G-28TS, this chapter provides configuration procedures in two ways: using the GUI and using the CLI.

6.2.3 Using the GUI

1) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > VLAN Config and click Add to load the following page. Specify VLAN ID as 2, give a VLAN name, and select port 1/0/1 as untagged member port. Click Create.

Figure 6-2 VLAN ConfigVLAN Config VLAN ID: 2 (2-4094, format: 2.4-5.8) VLAN Name: voice_vlan (1-16 characters) Untagged Ports Port: 1/0/1 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 6 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47…

2) Choose the menu QoS > Auto VoIP to load the following page. Select port 1/0/1, configure the interface mode as VLAN ID and set the VLAN ID value as 2. Click Apply.

Figure 6-3 Auto VoIP ConfigGlobal Config Auto VoIP: ✓ Enable Apply Port Config UNIT1 Port Interface Mode Value CoS Override Mode Operational Status DSCP Value VLAN ID 2 ✓ 1/0/1 VLAN ID 2 Disabled Disabled 0 □ 1/0/2 Disable 0 Disabled Disabled 0 □ 1/0/3 Disable 0 Disabled Disabled 0 □ 1/0/4 Disable 0 Disabled Disabled 0 □ 1/0/…

3) Choose the menu L2 FEATURES > LLDP > LLDP Config > Global Config to load the following page. Enable LLDP globally and click Apply.

Figure 6-4 LLDP Global ConfigGlobal Config LLDP: ✓ Enable LLDP Forwarding: □ Enable Apply

4) Choose the menu L2 FEATURES > LLDP > LLDP-MED Config > Port Config to load the following page. Enable LLDP-MED on port 1/0/1 and click Apply.

Figure 6-5 LLDP-MED ConfigPort Config UNIT1 Port LLDP-MED Status Included TLVs Enable ✓ 1/0/1 Enabled Detail 1/0/2 Disabled Detail 1/0/3 Disabled Detail 1/0/4 Disabled Detail 1/0/5 Disabled Detail 1/0/6 Disabled Detail 1/0/7 Disabled Detail 1/0/8 Disabled Detail 1/0/9 Disabled Detail 1/0/10 Disabled Detail Total: 54 1 entry…

5) Click Save the settings.

6.2.4 Using CLI

1) Create VLAN2 and add untagged port 1/0/1 to VLAN2.

Switch#configure

Switch(config)#vlan 2

Switch(config-vlan)#name voice_vlan

Switch(config-vlan)#exit

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#switch general allowed vlan 2 untagged

Switch(config-if)#exit

2) Enable Auto VoIP globally.

Switch(config)#auto-voip

3) Configure Auto VoIP. On port 1/0/1, configure the interface mode as VLAN ID and set the VLAN ID value as 2.

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#auto-voip 2

Switch(config-if)#exit

4) Enable LLDP globally.

Switch(config)#lldp

5) Enable LLDP-MED on port 1/0/1.

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#lldp med-status

Switch(config-if)#end

Switch#copy running-config startup-config

Verify the Configurations

View VLAN settings:

Switch#show vlan

VLANNameStatusPorts
1System-VLANactiveGi1/0/1, Gi1/0/2, Gi1/0/3, Gi1/0/4,Gi1/0/5, Gi1/0/6, Gi1/0/7, Gi1/0/8,Gi1/0/9, Gi1/0/10, Gi1/0/11, Gi1/0/12,Gi1/0/13, Gi1/0/14, Gi1/0/15, Gi1/0/16,Gi1/0/17, Gi1/0/18, Gi1/0/19, Gi1/0/20,Gi1/0/21, Gi1/0/22, Gi1/0/23, Gi1/0/24,Gi1/0/25, Gi1/0/26, Gi1/0/27, Gi1/0/28
2voice_vlanactiveGi1/0/1

View VoIP settings:

Switch#show auto-voip interface

Interface.Gi1/0/1

Auto-VoIP Interface Mode: Enabled

Auto-VoIP VLAN ID: 2

Auto-VoIP COS Override: False

Auto-VoIP DSCP Value: 0

Auto-VoIP Port Status: Enabled

...

View global LLDP settings:

Switch_A#show lldp

LLDP Status: Enabled

LLDP Forward Message: Disabled

...

View LLDP-MED settings on port 1/0/1:

Switch_A#show lldp interface gigabitEthernet 1/0/1

LLDP interface config:

gigabitEthernet 1/0/1:

...

LLDP-MED Status: Enabled

TLV Status


Network Policy Yes

Location Identification Yes

Extended Power Via MDI Yes

Inventory Management Yes

7

Appendix: Default Parameters

Default settings of LLDP are listed in the following tables.

Default LLDP Settings

Table 7-1 Default LLDP Settings

Parameter Default Setting
LLDP Disabled
LLDP Forward Message Disabled
Transmit Interval 30 seconds
Hold Multiplier 4
Transmit Delay 2 seconds
Reinitialization Delay 2 seconds
Notification Interval 5 seconds
Fast Start Repeat Count 3

Table 7-2 Default LLDP Settings on the Port

Parameter Default Setting
Admin StatusTx&Rx
Notification ModeDisabled
Included TLVsAll

Default LLDP-MED Settings

Table 7-3 Default LLDP-MED Settings

Parameter Default Setting
Fast Start Repeat Count 4
LLDP-MED Status (port) Disabled
Included TLVsAll

Part 17

Configuring L2PT

(Only for Certain Devices)

CHAPTERS

  1. Overview
  2. L2PT Configuration
  3. Configuration Example
  4. Appendix: Default Parameters

1 Overview

TP-LINK Omada Pro S5500-24GP4F - Overview - 1

Note:

L2PT is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If L2PT is available, there is L2 FEATURES > L2PT in the menu structure.

L2PT (Layer 2 Protocol Tunneling) is used to transparently transmit layer 2 protocol data units (PDUs) between customer networks at different locations through a public ISP network. Upon receiving a PDU from the customer network, the switch replaces the destination MAC address of the PDU with a special multicast MAC address (01:00:0C:CD:CD:D0) and sends it to the ISP network. This PDU can then be identified and sent directly on the ISP network. Some terminology that is used in this section is defined as follows:

■ Edge Switch: The switch that is connected to the customer network and placed on the boundary of the ISP network. ■ UNI: User Network Interface, a port configured on the edge switch which is connected to the customer network. ■ NNI: Network Network Interface, a port configured on the edge switch which is connected to the ISP network.

As shown in Figure 1-1, a customer has two local networks which are connected through the ISP network. When the two customer networks run the same Layer 2 protocol, the Layer 2 PDUs between them must be transmitted through the ISP network to perform Layer 2 protocol calculation (for example, calculating a spanning tree). Generally, the PDUs of the same Layer 2 protocol use the same destination MAC address. Therefore, when a Layer 2 PDU from a customer network reaches an edge switch in the ISP network, the switch cannot identify whether the PDU comes from a customer network or the ISP network and then the PDU will be discarded. As a result, the Layer 2 PDUs cannot be transmitted through the ISP network to the other side.

Figure 1-1 L2PT Applicationgraph TD A["Customer Network"] -->|PE1| B["ISP Network"] B -->|UNI| C["CE1"] B -->|NNINN| D["PE2"] D -->|UNI| E["CE2"] E --> F["Customer Network"]

To resolve this problem, the ISP network should transparently transmit the Layer 2 PDUs between the two customer networks. In this case, L2PT feature can be configured on the edge switches (PE1 and PE2) to allow the Layer 2 PDUs to be tunneled through the network.

The following describes the PDUs transmission procedure through the ISP network from one customer network to the other side:

1) Upon receiving a Layer 2 PDU from CE1 via the UNI port, PE1 replaces the destination MAC address of the PDU with a special multicast MAC address (01:00:0c:cd:cd:d0) and then sends the PDU to the ISP network via the NNI port. 2) The ISP network identifies the PDU and directly forwards it to the other end. 3) PE2 receives the PDU via its NNI port and restores the destination MAC address of the PDU to its original destination MAC address.

With L2PT feature configured accordingly, the switch can transparently transmit the PDUs of the following Layer 2 protocols: STP (Spanning Tree Protocol), GVRP (GARP VLAN Registration Protocol), LACP (Link Aggregation Control Protocol), CDP (Cisco Discovery Protocol), VTP (VLAN Trunking Protocol), PAgP (Port Aggregation Protocol), UDLD (UniDirectional Link Detection) and PVST+ (Per VLAN Spanning Tree Plus).

2 L2PT Configuration

2.1 Using the GUI

Choose the menu L2 FEATURES > L2PT to load the following page.

Figure 2-1 Configuring L2PTL2PT Config Layer 2 Protocol Tunneling: □ Enable Apply Port Config UNIT1 LAGS □ Port Type Protocol Threshold LAG □ 1/0/1 None --/--/----/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---/---…

Follow these steps to configure L2PT:

1) In the L2PT Config section, enable L2PT globally and click Apply. 2) In the Port Config section, configure the port that is connected to the customer network as a UNI port and specify your desired protocols on the port. In addition, you can also set the threshold for packets-per-second to be processed on the UNI port.

Port Select one or more ports to configure.

Type Configure the port connected to the customer network as an UNI port, and connected to the ISP network as an NNI port. NONE means that L2PT is disabled on this port.

Protocol Specify the layer 2 protocol types of the packets that can be transparently transmitted on the UNI port.

STP: Enable protocol tunneling for the GVRP packets.

GVRP: Enable protocol tunneling for the GVRP packets.

01000CCCCCC: Enable protocol tunneling for the packets with the destination MAC address 01:00:0C:CC:CC:CC, which includes CDP, VTP, PAgP and UDLD.

01000CCCCCCD: Enable protocol tunneling for the PVST+ packets with the destination MAC address 01:00:0C:CC:CC:CD.

LACP: Enable protocol tunneling for the LACP packets.

All: All the above layer 2 protocols are supported for tunneling.

Threshold: Specify the maximum number of packets that can be processed for the specified protocol on the UNI port each second. When the threshold is exceeded, the port drops the specified layer 2 protocol packets.

This value ranges from 1 to 1000 (packets per second). 0 indicates that the threshold feature is disabled.

LAG: Displays the LAG that the port belongs to.

3) In the Port Config section, configure the port that is connected to the ISP network as an NNI port. Note that the protocols and threshold cannot be configured on the NNI port.

Port: Select one or more ports to configure.

Type: Configure the port connected to the customer network as an UNI port, and connected to the ISP network as an NNI port. NONE means that L2PT is disabled on this port.

LAG: Displays the LAG that the port belongs to.

4) Click Apply.

TP-LINK Omada Pro S5500-24GP4F - Using the GUI - 2

Note:

If the port is a member port of an LAG, it will follow the L2PT configuration of the LAG and not its own.

2.2 Using the CLI

Follow these steps to configure the L2PT feature.

Step 1 configure

Enter global configuration mode.

Step 2 l2protocol-tunnel

Enable the L2PT feature globally.

Step 3interface{fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-id-list }Enter interface configuration mode.
Step 4l2protocol-tunnel type uni {01000ccccc | 01000ccccc | gvrp | stp | lacp | all } [threshold threshold]Configure the port as a UNI port, specify the Layer 2 protocol types of the packets that can be transparently transmitted on the port, and set the threshold for packets-per-second accepted for encapsulation on the UNI port.01000ccccc: Enable protocol tunneling for the packets with their destination MAC address as 01000CCCCCC, which includes CDP, VTP, PAgP and UDLD.01000ccccc: Enable protocol tunneling for the PVST+ packets with the destination MAC address as 01000CCCCCCd.gvrp: Enable protocol tunneling for the GVRP packets.stp: Enable protocol tunneling for the STP packets.lacp: Enable protocol tunneling for the LACP packets.all: All the above Layer 2 protocols are supported for tunneling.threshold:Set a threshold which determines the maximum number of packets to be processed for the specified protocol on the port in one second. When the threshold is exceeded, the port drops the specified Layer 2 protocol packets. The valid values are from 1 to 1000 (packets/second). 0 indicates that the threshold feature is disabled.
Step 5 exitReturn to global configuration mode.
Step 6interface{fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-id-list }Enter interface configuration mode.
Step 7 l2protocol-tunnel type nniConfigure the port as an NNI port.
Step 8show l2protocol-tunnel globalVerify the global L2PT configuration.
Step 9show l2protocol-tunnel interface[ fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel-id ]Verify the L2PT configuration of the port or LAG.
Step 10 endReturn to privileged EXEC mode.
Step 11copy running-config startup-configSave the settings in the configuration file.

TP-LINK Omada Pro S5500-24GP4F - Using the CLI - 1

Note:

The member port of an LAG (Link Aggregation Group) follows the configuration of the LAG and not its own. The configurations of the port can take effect only after it leaves the LAG.

This example shows how to enable L2PT globally:

Switch#configure

Switch(config)#l2protocol-tunnel

Switch(config)#show l2protocol-tunnel global

l2protocol-tunnel State: Enable

Switch(config)#end

Switch#copy running-config startup-config

This example shows how to configure port 1/0/1 as a UNI port for the Layer 2 protocol GVRP and set the threshold as 1000:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#l2protocol-tunnel type uni gvrp threshold 1000

Switch(config-if)#show l2protocol-tunnel interface gigabitEthernet 1/0/1

InterfaceTypeProtocolThresholdLAG
--------------------
Gi1/0/1unigvrp,--,--,--1000,--,--,--N/A

Switch(config-if)#end

Switch#copy running-config startup-config

This example shows how to configure port 1/0/5 as an NNI port.

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/5

Switch(config-if)#l2protocol-tunnel type nni

Switch(config-if)#show l2protocol-tunnel interface gigabitEthernet 1/0/5

InterfaceTypeProtocolThresholdLAG
--------------------

Gi1/0/5

nni

--,--,--,--

--,--,--,--

N/A

Switch(config-if)#end

Switch#copy running-config startup-config

3 Configuration Example

3.1 Network Requirements

As shown below, the two branches of a company are connected through the ISP network, and they want to achieve spanning tree calculation by exchanging Layer 2 STP packets with each other. To meet this requirement, the ISP network needs to transparently transmit the STP packets between the two customer networks.

Figure 3-1 Network Topologygraph TD A["Switch A"] -->|1/0/2| B["ISP Network"] B -->|1/0/11/0/1| C["Switch B"] C -->|1/0/2| D["Customer Network Customer Network"] style A fill:#4A90E2,stroke:#333 style B fill:#4A90E2,stroke:#333 style C fill:#4A90E2,stroke:#333 style D fill:#4A90E2,stroke:#333

3.2 Configuration Scheme

The service provider can configure L2PT on the two edge switches (Switch A and Switch B). With the L2PT feature, the STP packets can be encapsulated as normal data packets and sent to the other side without being processed by the devices in the ISP network.

The overview of configuration is as follows:

1) Enable the L2PT feature globally. 2) Specify port 1/0/1 which is connected to the ISP network as an NNI port. 3) Specify port 1/0/2 which is connected to the customer network as a UNI port for the STP. In addition, configure the threshold as 1000 to limit the number of packets to be processed on the port in one second.

Demonstrated with T2600G-28TS, the following sections provide configuration procedure in two ways: using the GUI and using the CLI.

3.3 Using the GUI

The configurations of Switch A and Switch B are similar. The following introductions take Switch A as an example.

1) Choose the menu L2 FEATURES > L2PT to load the following page. Enable the L2PT feature globally and click Apply. 2) Specify port 1/0/1 as an NNI port and click Apply. Specify port 1/0/2 as a UNI port for the STP and set the threshold as 1000. Then click Apply. The configuration result is as follows:

Figure 3-2 Global ConfigL2PT Config Layer 2 Protocol Tunneling: ✓ Enable Apply Port Config UNIT1 LAGS Port Type Protocol Threshold LAG UNI STP 1000 1/0/1 NNI ----/---- ✓ 1/0/2 UNI STP 1000 1/0/3 None ----/---- 1/0/4 None ----/---- 1/0/5 None ----/---- 1/0/6 None ----/---- 1/0/7 None ----/---- 1/0/8 None ----/---- 1/0/9 Non…

3) Click Save the settings.

3.4 Using the CLI

The configurations of Switch A and Switch B are similar. The following introductions take Switch A as an example.

Switch_A#configure

Switch_A(config)#l2protocol-tunnel

Switch_A(config)#interface gigabitEthernet 1/0/1

Switch_A(config-if)#l2protocol-tunnel type nni

Switch_A(config-if)#exit

Switch_A(config)#interface gigabitEthernet 1/0/2

Switch_A(config-if)#l2protocol-tunnel type uni stp 1000

Switch_A(config-if)#end

Switch_A#copy running-config startup-config

Verify the Configuration

Verify the global configuration:

Switch_A#show l2protocol-tunnel global

I2protocol-tunnel State: Enable

Verify the configuration on port 1/0/1:

Switch_A#show l2protocol-tunnel interface gigabitEthernet 1/0/1

InterfaceTypeProtocolThresholdLAG
--------------------
Gi1/0/1nni--,--,--,----,--,--,--N/A

Verify the configuration on port 1/0/2:

Switch_A#show l2protocol-tunnel interface gigabitEthernet 1/0/2

InterfaceTypeProtocolThresholdLAG
--------------------
Gi1/0/2unistp,--,--,--1000,--,--,--N/A

4 Appendix: Default Parameters

Default settings of L2PT are listed in the following table.

Table 4-1 Default Settings of L2PT

Parameter Defualt Setting
L2PT Config
Layer 2 Protocol Tunneling Disable
Port Config
Type None
Protocol None
Threshold None

Part 18

Configuring PPPoE ID Insertion

(Only for Certain Devices)

CHAPTERS

  1. Overview
  2. PPPoE ID Insertion Configuration
  3. Appendix: Default Parameters

1 Overview

TP-LINK Omada Pro S5500-24GP4F - Overview - 1

Note:

PPPoE ID Insertion is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If PPPoE ID Insertion is available, there is L2 FEATURES > PPPoE in the menu structure.

In common PPPoE (Point to Point Protocol over Ethernet) dialup mode, when users dial up through PPPoE, they can access the network as long as their accounts are authenticated successfully on the RADIUS server. As a result, illegal users can authenticate their accounts to access the internet. PPPoE ID Insertion resolves this problem by attaching a tag to the PPPoE Active Discovery packets. The tag records the client information, such as the connected port number and the MAC address of the client. If the client's tag information is different from the configured one, the authentication will fail. In this way, the illegal users cannot embezzle the accounts of legal users to access the Internet.

Additionally, after receiving the PPPoE Active Discovery Offer packet or Session-confirmation packet from the BRAS, the switch will remove the tag in the packet and send it to the client.

Figure 1-1 Network Topology of PPPoE ID-Insertiongraph LR A["Client"] --> B["Switch"] B --> C["BRAS PPPoE Server"] C --> D["RADIUS Server"]

2 PPPoE ID Insertion Configuration

2.1 Using the GUI

Choose the menu L2 FEATURES > PPPoE to load the following page.

Figure 2-1 Configuring PPPoE ID InsertionPPPoE ID Insertion PPPoE ID Insertion: ☐ Enable Apply Port Config UNIT1 ☐ Port Circuit-ID Circuit-ID Type UDF Value Remote-ID Remote-ID Value ☐ 1/0/1 Disabled.IP --- Disabled -- ☐ 1/0/2 Disabled.IP --- Disabled -- ☐ 1/0/3 Disabled.IP --- Disabled -- ☐ 1/0/4 Disabled.IP --- Disabled -- ☐ 1/0/5 Disabl…

Follow these steps to configure PPPoE ID-Insertion:

1) In the PPPoE ID Insertion section, enable PPPoE ID Insertion and click Apply. 2) In the Port Config section, select one or more ports, and configure the relevant parameters. Then click Apply.

Circuit-ID Choose whether to insert a Circuit-ID into the received PPPoE Discovery packet on this port.

Circuit-ID Type Select the Circuit-ID type. The following options are provided:

IP: The circuit ID includes the following three parts: the source MAC address of the packet, the IP address of the switch and the port number. This is the default value.

MAC: The circuit ID includes the following three parts: the source MAC address of the packet, the MAC address of the switch and the port number.

UDF: The circuit ID includes the following three parts: the source MAC address of the packet, the user-specified string and the port number.

UDF Only: Only the user specified string will be used to encode the Circuit-ID option.

UDF Value If UDF or UDF ONLY is selected, specify a string with a maximum of 40 characters to encode the Circuit-ID option.

Remote-ID Enable or disable the switch to insert a Remote ID to the received PPPoE Discovery packet on this port.

Remote-ID Value Specify a string to encode the Remote-ID option.

2.2 Using the CLI

Follow these steps to configure PPPoE ID Insertion:

Step 1 configure

Enter global configuration mode.

Step 2 pppoe id-insertion

Globally enable the PPPoE ID Insertion feature.

Step 3 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list }

Enter interface configuration mode.

Step 4 pppoe circuit-id

Enable Circuit-ID Insertion feature, and the switch will insert a Circuit ID to the received PPPoE Discovery packet on this port.

Step 5 pppoe circuit-id type { mac | ip | udf [

Value] | udf-only [Value] }

Specify the type of the Circuit ID. The following options are provided:

mac: The source MAC address of the packet, the MAC address of the switch and the port number will be used to encode the Circuit-ID option.

ip: The circuit ID includes the following three parts: the source MAC address of the received packet, the IP address of the switch and the port number. This is the default value.

udf [Value]: Specify a string with at most 40 characters. The circuit ID includes the following three parts: the source MAC address of the packet, the user-specified string and the port number.

udf-only [Value]: Specify a string with at most of 40 characters. Only the specified string will be used to encode the Circuit-ID option.

Step 6 pppoe remote-id [ Value]

Enable Remote-ID Insertion feature and specify the Remote ID.

Value Specify a string with at most 40 characters. The source MAC address of the packet and the specified string will be used to encode the Remote-ID option.

Step 7 show pppoe global

Verify the global configuration of PPPoE ID Insertion.

Step 8 show pppoe interface { fastEthernet port}

port | gigabitEthernet port | ten-gigabitEthernet

Verify the configuration of PPPoE ID Insertion on the port.

Step 9 end

Return to privileged EXEC mode.

Step 10 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable PPPoE ID Insertion globally and on port 1/0/1, and configure the Circuit-ID as 123 without other information and Remote-ID as host1.

Switch#configure

Switch(config)#pppoe id-insertion

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#pppoe circuit-id

Switch(config-if)#pppoe circuit-id type udf-only 123

Switch(config-if)#pppoe remote-id host1

Switch(config-if)#show pppoe global

PPPoE ID Insertion State: Enable

Switch(config-if)#show pppoe port

Default settings of L2PT are listed in the following table.

Table 3-1 PPPoE ID Insertion

Parameter Default Setting
Global Config
PPPoE ID Insertion Disabled
Port Config
Circuit-ID Disabled
Circuit-ID Type IP
UDF Value None
Remote-ID Disabled
Remote-ID Value None

Part 19

Configuring Layer 3 Interfaces

CHAPTERS

  1. Overview
  2. Layer 3 Interface Configurations
  3. Configuration Example
  4. Appendix: Default Parameters

1 Overview

Interfaces are used to exchange data and interact with interfaces of other network devices. Interfaces are classified into Layer 2 interfaces and Layer 3 interfaces.

■ Layer 2 interfaces are the physical ports on the switch panel. They forward packets based on MAC address table. ■ Layer 3 interfaces are used to forward IPv4 and IPv6 packets using static or dynamic routing protocols. You can use Layer 3 interfaces for IP routing and inter-VLAN routing.

This chapter introduces the configurations for Layer 3 interfaces. The supported types of Layer 3 interfaces are shown as below:

Table 1-1 Supported Types of Layer 3 interfaces

Type Description
VLAN InterfaceA Layer 3 interface with which acts as the default gateway of all the hosts in the corresponding VLAN.
Loopback Interface An interface of which the status is always up.
Routed Port A physical port configured as an Layer 3 port.
Port-channel InterfaceSeveral routed ports are bound together and configured as an Layer 3 interface.

2 Layer 3 Interface Configurations

To complete IPv4 interface configuration, follow these steps:

1) Create a Layer 3 interface 2) Configure IPv4 parameters of the created interface 3) View detailed information of the created interface

To complete IPv6 interface configuration, follow these steps:

1) Create a Layer 3 interface 2) Configure IPv6 parameters of the created interface 3) View detailed information of the created interface

2.1 Using the GUI

2.1.1 Creating a Layer 3 Interface

Choose the menu L3 FEATURES> Interface to load the following page.

Figure 2-1 Creating a Layer 3 InterfaceRouting Config IPv4 Routing: ✓ Enable IPv6 Routing: □ Enable Interface Config Add Delete Interface ID IP Address Mode IP Address Subnet Mask Interface Name Status Operation VLAN1 DHCP 192.168.0.1 255.255.255.0 Up Edit IPv4 Detail Total: 1 Edit IPv6

Follow these steps to create a Layer 3 interface.

1) In the Routing Config section, enable IPv4 routing or IPv6 routing. Then click Apply.

IPv4 RoutingEnable IPv4 routing function globally for all Layer 3 interfaces. It is enabled by default.
IPv6 Routing(Optional) Enable IPv6 routing function globally for all Layer 3 interfaces. It is disabled by default.

2) In the Interface Config section, click + Add to load the following page, and configure the corresponding parameters for the Layer 3 interface. Then click Create.

Interface

Interface ID:

VLAN

TP-LINK Omada Pro S5500-24GP4F - Interface - 1

(1-4094)

IP Address Mode:

TP-LINK Omada Pro S5500-24GP4F - Interface - 2

None

TP-LINK Omada Pro S5500-24GP4F - Interface - 3

Static

TP-LINK Omada Pro S5500-24GP4F - Interface - 4

DHCP

TP-LINK Omada Pro S5500-24GP4F - Interface - 5

BOOTP

Admin Status:

TP-LINK Omada Pro S5500-24GP4F - Interface - 6

Enable

Interface Name:

(Optional. 1-16 characters)

Cancel

Create

Interface ID Select an interface type and enter the ID of the interface.

IP Address Mode: Specify the IP address assignment mode of the interface.

None: No IP address will be assigned.

Static: Assign an IP address manually.

DHCP: Assign an IP address through DHCP.

BOOTP: Assign an IP address through BOOTP.

DHCP Option 12: If you select DHCP as the IP Address Mode, configure the Option 12 here.

DHCP Option 12 is used to specify the client's name.

IP Address: Specify the IP address of the interface if you choose "Static" as the IP address assignment mode.

Subnet Mask: Specify the subnet mask of the interface if you choose "Static" as the IP address assignment mode.

Admin Status: Enable or disable the interface's Layer 3 capabilities.

Interface Name (Optional): Enter a name for the interface.

TP-LINK Omada Pro S5500-24GP4F - Interface - 7

Note:

The created interface is an IPv4 interface. To configure the IPv6 features, please click "Edit IPv6" after the interface is created.

2.1.2 Configuring IPv4 Parameters of the Interface

In Figure 2-1 you can view the corresponding interface you have created in the Interface List section. On the corresponding interface entry, click Edit IPv4 to load the following page and edit the IPv4 parameters of the interface.

Figure 2-2 Configuring the IPv4 ParametersModify IPv4 Interface Interface ID: VLAN1 Admin Status: Enable Interface Name: (Optional. 1-16 characters) IP Address Mode: None Static DHCP BOOTP IP Address: 192.168.0.28 (Format: 192.168.0.1) Subnet Mask: 255.255.255.0 (Format: 255.255.255.0) Apply Secondary IP List ID IP Address Subnet Mask No En…

1) In the Modify IPv4 Interface section, configure relevant parameters for the interface according to your actual needs. Then click Apply.

Interface ID Displays the interface ID.
Admin Status Enable the Layer 3 capabilities for the interface.
Interface Name (Optional) Enter a name for the interface.
IP Address Mode Specify the IP address assignment mode of the interface.
None: No IP address will be assigned.
Static: Assign an IP address manually.
DHCP: Obtain an IP address through DHCP.
BOOTP: Obtain an IP address through BOOTP.
IP AddressSpecify the IP address of the interface if you choose "Static" as the IP address assignment mode.
Subnet MaskSpecify the subnet mask of the interface if you choose "Static" as the IP address assignment mode.

DHCP Option 12 If you select DHCP as the IP Address Mode, configure the Option 12 here.

DHCP Option 12 is used to specify the client's name.

2) In the Secondary IP List section, click + Add to add a secondary IP for the specified interface which allows you to have two logical subnets. Then click Create.

Secondary IP IP Address: (Format: 192.168.0.1) Subnet Mask: (Format: 255.255.255.0) Cancel Create

IP Address Specify the secondary IP address of the interface.

Subnet Mask Specify the subnet mask of the secondary IP address.

3) (Optional) In the Secondary IP List section, you can view the corresponding secondary IP entry you have created.

2.1.3 Configuring IPv6 Parameters of the Interface

In Figure 2-1, you can view the corresponding interface entry you have created in the Interface List section. On the corresponding interface entry, click Edit IPv6 to load the following page and configure the IPv6 parameters of the interface.

Figure 2-3 Configuring the IPv6 ParametersModify IPv6 Interface Interface ID: VLAN1 Admin Status: Enable IPv6 Enable: Enable Link-local Address Mode: Manual Auto Link-local Address: fe80::c66e:1fff.febf.7251 (Format:3001::1) Status: Normal Enable global address auto configuration via RA message Enable global address auto configuration via D…

1) In the Modify IPv6 Interface section, enable IPv6 feature for the interface and configure the corresponding parameters. Then click Apply.

Interface ID Displays the interface ID.
Admin Status Enable or disable the interface's Layer 3 capabilities.
IPv6 Enable Enable or disable IPv6 function on the interface of switch.
Link-local Address ModeSelect the link-local address configuration mode.Manual:With this option selected, you can assign a link-local address manually.Auto:With this option selected, the switch generates a link-local address automatically.
Link-local AddressEnter a link-local address if you choose "Manual" as the link-local address configuration mode.

Status Displays the status of the link-local address. An IPv6 address cannot be used before pass the DAD (Duplicate Address Detection), which is used to detect the address conflicts. In the DAD process, the IPv6 address may in three different status:

Normal: Indicates that the link-local address is normal.

Try: Indicates that the link-local address is newly configured and is in the progress of DAD (Duplicat Address Detection).

Repeat: Indicates that the link-local address is duplicate. It is illegal to access the switch using the IPv6 address (including link-local and global address).

2) Configure IPv6 global address of the interface via following three ways:

Via RA Message:

Enable global address auto configuration via RA message With this option enabled, the interface automatically generates a global address and other information according to the address prefix and other configuration parameters from the received RA (Router Advertisement) message.

Via DHCPv6 Server:

Enable global address auto configuration via DHCPv6 Server With this option enabled, the switch will try to obtain the global address from the DHCPv6 Server.

Manually:

In the Global Address Config section, click + Add to manually assign an IPv6 global address to the interface.

Global Address

Address Format:

Global Address:

Prefix Length:

TP-LINK Omada Pro S5500-24GP4F - Global Address - 1

○ Not EUI-64

TP-LINK Omada Pro S5500-24GP4F - Global Address - 2

(Format 3001:1)

TP-LINK Omada Pro S5500-24GP4F - Global Address - 3

TP-LINK Omada Pro S5500-24GP4F - Global Address - 4

Add to manually assign an IPv6 global

Address Format Select the global address format according to your needs.

EUI-64: Indicates that you only need to specify an address prefix, then the system will create a global address automatically.

Not EUI-64: Indicates that you have to specify an intact global address.

Global Address

When EUI-64 is selected, please input the address prefix here, otherwise, please input an intact IPv6 address here.

Prefix Length Configure the prefix length of the global address.

3) View the global address entry in the Global Address Table.

Global Address Displays the global address.
Prefix Length Displays the prefix length of the global address.
Type Displays the configuration mode of the global address.
Manual: Indicates the global IPv6 address is manually configured.
Auto: Indicates the global IPv6 address is automatically created by using the RA message or assigned by the DHCpv6 server.
Preferred LifetimeDisplays the preferred lifetime of the global address.
Preferred lifetime is the length of time that a valid IPv6 address is preferred. When the preferred time expires, the address becomes deprecated but still can be used, and you need to switch to another address.
Valid Lifetime Displays the valid lifetime of the global address.
Valid lifetime is the length of time that an IPv6 address is in the valid state. When the valid lifetime expires, the address become invalid and can be no longer usable.
Status Displays the status of the global address. An IPv6 address cannot be used before pass the DAD (Duplicate Address Detection), which is used to detect the address conflicts. In the DAD process, the IPv6 address may in three different status:
Normal: Indicates that the link-local address can be normally used by the interface.
Try: Indicates that the link-local address is newly configured and is in the progress of DAD (Duplicat Address Detection).
Repeat: Indicates that the link-local address is duplicated. It is illegal to access the switch using the IPv6 address (including link-local and global address).

2.1.4 Viewing Detail Information of the Interface

In Figure 2-1 you can view the corresponding interface entry you have created in the Interface List section. On the corresponding interface entry, click Detail to load the following page and view the detail information of the interface.

Figure 2-4 Viewing the detail information of the interface

Interface ID:VLAN1
Detail InformationInterface Setting Detail Information
Interface ID:1MTU is 1500 byte
IP Address Mode:StaticDirected broadcast forwarding is Disabled
IP Address:192.168.0.1ICMP redirects are never sent
Subnet Mask:255,255,255,0ICMP unreachables are never sent
Admin Status:EnabledICMP mask replies are never sent
Interface Status:Up
Line Protocol Status:Up
Secondary IP:
IPv6 Address Mode:EnabledMTU is 1500 byte
Link-Local Address:fe80::20a:ebff:fe13:a23aND DAD is Enabled
Admin Status:EnabledND retrans timer is 1000 ms
IPv6 Interface Status:UpND reachable time is 30000 ms
Line Protocol Status:UpGlobal address auto configuration via RA message is Enabled
IPv6 Address:Global address auto configuration via DHCPv6 Server is Disabled

2.2 Using the CLI

2.2.1 Creating a Layer 3 Interface

Follow these steps to create a Layer 3 interface. You can create a VLAN interface, a loopback interface, a routed port or a port-channel interface according to your needs.

Step 1 configure

Enter global configuration mode.

Step 2 Create a VLAN interface:

interface vlan vlan-id

vlan-id: Specify an IEEE 802.1Q VLAN ID that already exists, ranging from 1 to 4094.

Create a loopback interface:

interface loopback {id}

id: Specify the ID of the loopback interface, ranging from 1 to 64.

Create a routed port:

interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list }

Enter interface configuration mode.

port: Specify the Ethernet port number, for example 1/0/1.

port-list: Specify the list of Ethernet ports, for example 1/0/1-3, 1/0/5.

no switchport

Switch the Layer 2 port into the Layer 3 routed port.

Create a port-channel interface:

interface { port-channel port-channel| range port-channel port-channel-list }

Enter interface configuration mode.

port-channel: Specify the port channel, the valid value ranges from 1 to 14.

port-channel-list: Specify the list of the port-channel interface, for example 1-3, 5.

no switchport

Switch the port channel to a Layer 3 port channel interface.

Step 3 description

string

Specify a description for the Layer 3 interface.

string: The description of the Layer 3 interface, ranging from 1 to 32 characters.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to create a VLAN interface with a description of VLAN-2.

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#description VLAN-2

Switch(config-if)#end

Switch#copy running-config startup-config

2.2.2 Configuring IPv4 Parameters of the Interface

Follow these steps to configure the IPv4 parameters of the interface.

Step 1 configure

Enter global configuration mode.

Step 2 interface {

interface-type } { interface-id }

Enter Layer 3 interface configuration mode.

interface-type: Type of the Layer 3 interface, including fastEthernet, gigabitEthernet, ten-gigabitEthernet, loopback and VLAN.

interface-id: The interface ID.

Step 3 Automatically assign an IP Address for the interface via DHCP or BOOTP:

ip address-alloc { dhcp | bootp }

Specify the IP Address assignment mode of the interface.

dhcp: Specify the Layer 3 interface to obtain an IPv4 address from the DHCP Server.

bootp: Specify the Layer 3 interface to obtain an IPv4 address from the BOOTP Server.

Manually assign an IP Address for the interface:

ip address {ip-addr} {mask} [secondary]

Configure the IP address and subnet mask for the specified interface manually.

ip-addr: Specify the IP address of the Layer 3 interface.

mask: Specify the subnet mask of the Layer 3 interface.

secondary: Specify the interface's secondary IP address, which allows you to have two logical subnets. If this parameter is omitted, the configured IP address is the interface's primary address.

logical subnets. If this parameter is omitted here, the configured IP address is the interface's primary address.

Verify the summary information of the Layer 3 interfaces.

Verify the summary information of the Layer 3 interfaces.

Return to privileged EXEC mode.

Step 6: copy running-config startup-config

Step 6: copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the IPv4 parameters of a routed port, including setting a static IP address for the port and enabling the Layer 3 capabilities:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#no switchport

Switch(config-if)#ip address 192.168.0.100 255.255.255.0

Switch(config-if)#show ip interface brief

InterfaceIP-AddressMethodStatusProtocolShutdown
Gi1/0/1192.168.0.100/24StaticUpUpno

Switch(config-if)#end

Switch#copy running-config startup-config

2.2.3 Configuring IPv6 Parameters of the Interface

Follow these steps to configure the IPv6 parameters of the interface.

Step 1 configure

Enter global configuration mode.

Step 2 interface {

interface-type } { interface-id }

Enter Layer 3 interface configuration mode.

interface-type: Type of the Layer 3 interface, including fastEthernet, gigabitEthernet, ten-gigabitEthernet, loopback and VLAN.

interface-id: The interface ID.

Step 3 ipv6 enable

Enable the IPv6 feature on the specified Layer 3 interface. By default, it is enabled on VLAN interface 1. IPv6 function can only be enabled on one Layer 3 interface at a time.

Step 4 Configure the IPv6 link-local address for the specified interface:

Manually configure the ipv6 link-local address for the specified interface:

ipv6 address ipv6-addr link-local

ipv6-addr: Specify the link-local address of the interface. It should be a standardized IPv6 address with the prefix fe80::/10, otherwise this command will be invalid.

Automatically configure the ipv6 link-local address for the specified interface: ipv6 address autoconfig

Step 5 Configure the IPv6 global address for the specified interface:

Automatically configure the interface's global IPv6 address via RA message: ipv6 address ra

Configure the interface's global IPv6 address according to the address prefix and other configuration parameters from its received RA (Router Advertisement) message.

Automatically configure the interface's global IPv6 address via DHCPv6 server: ipv6 address dhcp

Enable the DHCPv6 Client function. When this function is enabled, the Layer 3 interface will try to obtain the IPv6 address from DHCPv6 server.

Manually configure the interface's global IPv6 address:

ipv6 address ipv6-addr

ipv6-addr: The Global IPv6 address with network prefix, for example 3ffe::1/64.

ipv6 address ipv6-addr eui-64

Specify a global IPv6 address with an extended unique identifier (EUI) in the low-order 64 bits of the IPv6 address. Specify only the network prefix; the last 64 bits are automatically computed from the switch MAC address. This enables IPv6 processing on the interface.

Step 6 show ipv6 interface

Verify the configured ipv6 information of the interface.

Step 7 end

Return to privileged EXEC mode.

Step 8 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the IPv6 function and configure the IPv6 parameters of a VLAN interface:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ipv6 enable

Switch(config-if)#ipv6 address autoconfig

Switch(config-if)#ipv6 address dhcp

Switch(config-if)#show ipv6 interface

Vlan2 is up, line protocol is up

IPv6 is enabled, Link-Local Address: fe80::20a:ebff:fe13:237b[NOR]

Global Address RA: Disabled

Global Address DHCPv6: Enabled

Global unicast address(es): ff02::1:ff13:237b

Joined group address(es): ff02::1

ICMP error messages limited to one every 1000 milliseconds

ICMP redirects are enabled

MTU is 1500 bytes

ND DAD is enabled, number of DAD attempts: 1

ND retrans timer is 1000 milliseconds

ND reachable time is 30000 milliseconds

Switch(config-if)#end

Switch#copy running-config startup-config

3 Configuration Example

3.1 Network Requirement

The administrator needs to allow the hosts in VLANs to access the internet. The topology is shown below.

Figure 3-1 Network Topologygraph TD A["Internet"] --> B["Router"] B --> C["Switch"] C --> D["VLAN 2"] C --> E["VLAN 10"] C --> F["..."]

3.2 Configuration Scheme

Since the hosts in VLANs are separated at layer 2, to enable these hosts to access the internet, we need to configure a VLAN interface on the switch for each VLAN. The VLAN interface can be considered as the default gateway for the hosts in the VLAN. All requests to the internet are sent to the VLAN interface first, and then the VLAN interface forwards the packets to the internet according to the routing table.

Demonstrated with S6500-24GP4XF, this chapter provides configuration procedures in two ways: using the GUI and using the CLI.

3.3 Using the GUI

Since the configurations for all VLANs are similar, here we only take the configuration of the VLAN interface for VLAN 2 as an example.

1) Go to L2 FEATURES > VLAN > 802.1Q VLAN to create VLAN 2. Add port 1/0/2 to VLAN 2 with its egress rule as Untagged.

Table 3-2 Create VLAN 2VLAN Config VLAN ID: 2 VLAN Name: VLAN 2 (2-8094, turnsat: 2,6-3,0) 1-16 characters Unlagged Ports Port 1/0/2 (Format: 1/WT, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 Select All 4 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 41 43 45 47 49 51 5…

2) Go to L3 FEATURES > Interface to enable IPv4 routing (enabled by default), then click Add to create VLAN interface 2. Here we choose the IP address mode as Static and manually assign an IP address 192.168.2.1 to the interface.

Table 3-3 Create VLAN Interface 2Interface Config Interface ID: VLAN 2 (1-4094) IP Address Mode: None Static DHCP BOOTP IP Address: 192.168.2.1 (Format: 192.168.0.1) Subnet Mask: 255.255.255.0 (Format: 255.255.255.0) Admin Status: Enable Interface Name: (Optional: 1-16 characters) Cancel Create

3) Click Save the settings.

3.4 Using the CLI

1) Create VLAN 2 and add port 1/0/2 to VLAN 2 with its egress rule as Untagged.

Switch#configure

Switch(config)#vlan 2

Switch(config-vlan)#exit

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)#switchport general allowed vlan 2 untagged

Switch(config-if)#exit

2) Create VLAN interface 2 for VLAN 2. Configure the IP address of VLAN interface 2 as 192.168.2.1.

Switch(config)#interface vlan 2

Switch(config-if)#ip address 192.168.2.1 255.255.255.0

Switch(config-if)#end

Switch#copy running-config startup-config

Verify the VLAN Interface Configurations

Verify the configurations of VLAN interface 2.

Switch#show interface vlan 2

VLAN2 is down, line protocol is down

Hardware is CPU Interface, address is 00:0a:eb:13:a2:98

ip is 192.168.2.1/24

4 Appendix: Default Parameters

Default settings of interface are listed in the following tables.

Table 4-1 Default Settings of Routing Config

Parameter Default Setting
IPv4 Routing Enabled
IPv6 Routing Disabled

Table 4-2 Configuring the IPv4 Parameters of the Interface

Parameter Default Setting
Interface ID VLAN
IP Address Mode None
Admin Status Enabled

Table 4-3 Configuring the IPv6 Parameters of the Interface

Parameter Default Setting
Admin Status Enabled
IPv6 Enable Enabled
Link-local Address Mode Auto
Enable global address auto configuration via RA messageEnabled
Enable global address auto configuration via DHCPv6 ServerDisabled

Part 20

Configuring Routing

CHAPTERS

  1. Overview
  2. IPv4 Static Routing Configuration
  3. IPv6 Static Routing Configuration
  4. Viewing Routing Table
  5. RIP Configuration
  6. RIPng Configuration
  7. OSPF Configuration
  8. OSPFv3 Configuration
  9. BFD Configuration
  10. BGP Configuration
  11. IS-IS Configuration
  12. URPF Configuration
  13. Tunnel Configuration
  14. Example for Static Routing

1 Overview

The routing table is used by a Layer 3 device (in this configuration guide, it refers to the switch) to forward packets to the correct destination. When the switch receives packets whose source IP address and destination IP address are in different subnets, it checks the routing table, finds the correct outgoing interface, and then forwards the packets.

The routing table mainly contains two types of routing entries: dynamic routing entries and static routing entries.

Dynamic routing entries are automatically generated by the switch. The switch uses dynamic routing protocols to automatically calculate the best route to forward packets. Dynamic routing protocols, such as OSPF (Open Shortest Path First) running in the network layer, would apply different working mechanisms according to the features of different data link layers.

Static routing entries are manually added non-aging routing entries. In a simple network with a small number of devices, you only need to configure static routes to ensure that the devices from different subnets can communicate with each other. On a complex large-scale network, static routes ensure stable connectivity for important applications because the static routes remain unchanged even when the topology changes.

The switch supports IPv4 static routing and IPv6 static routing configuration.

2 IPv4 Static Routing Configuration

2.1 Using the GUI

Choose the menu L3 FEATURES > Static Routing > IPv4 Static Routing and click to load the following page.

TP-LINK Omada Pro S5500-24GP4F - Using the GUI - 1

Add

Figure 2-1 Configuring the IPv4 Static RoutingIPv4 Static Routing Destination: (Format: 10.10.10.0) Subnet Mask: (Format: 255.255.255.0) Next Hop: (Format: 192.168.0.2) Distance: (Optional. range: 1-255) Cancel Create

Configure the corresponding parameters to add an IPv4 static routing entry. Then click Create.

Destination Specify the destination IPv4 address of the packets.
Subnet Mask Specify the subnet mask of the destination IPv4 address.
Next Hop Specify the IPv4 gateway address to which the packet should be sent next.
DistanceSpecify the administrative distance. The distance is the trust rating of a routing entry.A higher value means a lower trust rating. Among routes to the same destination, thereoute with the lowest distance value will be recorded in the routing table.The valid value ranges from 1 to 255 and the default value is 1.

2.2 Using the CLI

Follow these steps to create an IPv4 static route.

Step 1 configure

Enter global configuration mode.

Step 2 ip route {

dest-address}{mask}{next-hop-address}[distance]

Add an IPv4 static route.

dest-address: Specify the destination IPv4 address of the packets.

mask: Specify the subnet mask of the destination IPv4 address.

next-hop-address: Specify the IPv4 gateway address to which the packet should be sent next.

distance: Specify the administrative distance, which is a rating of the trustworthiness of the routing information. A higher value means a lower trust rating. When more than one routing protocols have routes to the same destination, only the route that has the shortest distance will be recorded in the IP routing table. The valid values are from 1 to 255 and the default value is 1.

Step 3 show ip route [static | connected]

Verify the IPv4 route entries of the specified type.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to create an IPv4 static route with the destination IP address as 192.168.2.0, the subnet mask as 255.255.255.0 and the next-hop address as 192.168.0.2:

Switch#configure

Switch(config)#ip route 192.168.2.0 255.255.255.0 192.168.0.2

Switch(config)#show ip route

Codes: C - connected, S - static

* - candidate default

C 192.168.0.0/24 is directly connected, Vlan1

S 192.168.2.0/24 [1/0] via 192.168.0.2, Vlan1

Switch(config)#end

Switch#copy running-config startup-config

3 IPv6 Static Routing Configuration

3.1 Using the GUI

Choose the menu L3 FEATURES > Static Routing > IPv6 Static Routing > IPv6 Static Routing Table and click + Add to load the following page.

Figure 3-1 Configuring the IPv6 Static RoutingIPv6 Static Routing IPv6 Address: (Format: 2001::) Prefix Length: (Format: 64. range: 0-128) Next Hop: (Format: 3001::2) Distance: (Optional. range: 1-255) Cancel Create

Configure the corresponding parameters to add an IPv6 static routing entry. Then click Create.

IPv6 Address Specify the destination IPv6 address of the packets.
Prefix Length Specify the prefix length of the IPv6 address.
Next Hop Specify the IPv6 gateway address to which the packet should be sent next.
DistanceSpecify the administrative distance. The distance is the trust rating of a routing entry.A higher value means a lower trust rating. Among routes to the same destination, thereoute with the lowest distance value will be recorded in the routing table.The valid value ranges from 1 to 255 and the default value is 1

3.2 Using the CLI

Follow these steps to enable IPv6 routing function and create an IPv6 static route.

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 routing

Enable the IPv6 routing function on the specified Layer 3 interface.

Step 3 ipv6 route {

ipv6-dest-address}{next-hop-address}[distance]

Add an IPv6 static route.

ipv6-dest-address: Specify the destination IPv6 address of the packets, in the format of X:X:X::X/<0-128>.

next-hop-address: Specify the IPv6 gateway address to which the packet should be sent next.

distance: Specify the administrative distance, which is a rating of the trustworthiness of the routing information. A higher value means a lower trust rating. When more than one routing protocols have routes to the same destination, only the route that has the shortest distance will be recorded in the IP routing table. The valid values are from 1 to 255 and the default value is 1.

Step 4 show ipv6 route [static | connected]

Verify the IPv6 route entries of the specified type.

Step 5 end

Return to privileged EXEC mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to create an IPv6 static route with the destination IP address as 3200::/64 and the next-hop address as 3100::1234:

Switch#configure

Switch(config)#ipv6 route 3200::/64 3100::1234

Switch(config)#show ipv6 route static

Codes: C - connected, S - static

* - candidate default

C 3000::/64 is directly connected, Vlan1

S 3200::/64 [1/0] via 3100::1234, Vlan2

Switch(config)#end

Switch#copy running-config startup-config

4 Viewing Routing Table

You can view the routing tables to learn about the network topology. The switch supports IPv4 routing table and IPv6 routing table.

4.1 Using the GUI

4.1.1 Viewing IPv4 Routing Table

Choose the menu L3 FEATURES > Routing Table > IPv4 Routing Table > IPv4 Routing Table to load the following page.

Figure 4-1 Viewing IPv4 Routing Table

ProtocolDestination NetworkNext HopDistanceMetricInterface Name
Connected192.168.0.0/24192.168.0.2601
Static192.168.30.0/24192.168.0.3650
Total: 2

View the IPv4 routing entries.

Protocol Displays the type of the routing entry.

Connected: The destination network is directly connected to the switch.

Static: The routing entry is a manually added static routing entry.

Destination NetworkDisplays the destination network and subnet mask.
Next HopDisplays the IP address of the next hop to which the packet is to be sent on the way to its final destination.
DistanceDisplays the administrative distance, which is the trust rating of a routing entry. A higher value means a lower trust rating. When more than one routing protocol have routes to the same destination, only the route which has the smallest distance will be recorded in the IP routing table.

Metric Displays the metric to reach the destination IP address.

Interface Name Displays the gateway interface name.

4.1.2 Viewing IPv6 Routing Table

Choose the menu L3 FEATURES> Routing Table > IPv6 Routing Table > IPv6 Routing Table to load the following page.

Figure 4-2 Viewing IPv6 Routing Table

ProtocolDestination NetworkNext HopDistanceMetricInterface Name
No Entries in this table.
Total: 0

View the IPv6 routing entries.

Protocol Displays the type of the routing entry.
Connected: The destination network is directed connected to the switch.
Static: The routing entry is a manually added static routing entry.
Destination NetworkDisplays the destination IPv6 network address and subnet mask.
Next HopDisplays the IPv6 address of the next station to which the packet is to be sent on the way to its final destination.
DistanceDisplays the administrative distance, which is the trust rating of a routing entry. A higher value means a lower trust rating. When more than one routing protocol have routes to the same destination, only the route which has the smallest distance will be recorded in the IP routing table.
Metric Displays the metric to reach the destination IPv6 address.
Interface Name Displays the gateway interface name.

4.2 Using the CLI

4.2.1 Viewing IPv4 Routing Table

On privileged EXEC mode or any other configuration mode, you can use the following command to view IPv4 routing table:

show ip route [static | connected]

View the IPv4 route entries of the specified type. If not specified, all types of route entries will be displayed.

static: View the static routes.

connected: View the connected routes.

4.2.2 Viewing IPv6 Routing Table

On privileged EXEC mode or any other configuration mode, you can use the following command to view IPv6 routing table:

show ipv6 route [static | connected]

View the IPv6 route entries of the specified type. If not specified, all types of route entries will be displayed.

static: View the static IPv6 routes.

connected: View the connected IPv6 routes.

5 RIP Configurations

TP-LINK Omada Pro S5500-24GP4F - RIP Configurations - 1

Note:

RIP is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If VRRP is available, there is L3 FEATURES > RIP in the menu structure.

RIP (Routing Information Protocol) is a routing protocol suitable for small networks and has lower requirements in terms of bandwidth, configuration, and management. As a routing protocol based on distance vector algorithm, RIP uses hop count as the measurement standard.

5.1 Using the GUI

5.1.1 Configuring RIP Globally

Choose the menu L3 FEATURES > RIP > Basic Config to load the following page.

Figure 5-1 Configuring RIP GloballyRIP Enable RIP Protocol: Enable Global Config RIP Version: Default RIP Distance: (1-255) Auto Summary: Enable Allow-ecmp: Enable Default information- Originate: Enable Default Metric: (1-15) Update Timer: 30 seconds (1-100) Timeout Timer: 180 seconds (1-300) Garbage Timer: 240 seconds (1-500) Apply…

Follow these steps to configure IGMP Snooping globally:

1) In the RIP Enable section, enable RIP Protocol, and then configure the global parameters in the Global Config section.

RIP Protocol: Choose to enable or disable the RIP function. By default, it is enabled.

RIP Version: Choose the global RIP version.

Default: Send with RIP version 2 and receive with both RIP version 1 and 2.

RIPv1: Send and receive RIP version 1 formatted packets via broadcast.

RIPv2: Send and receive RIP version 2 packets using multicast.

RIP Distance: Set the RIP router distance.

Auto Summary: If you select enable, groups of adjacent routes will be summarized into single entries, in order to reduce the total number of entries. The default is disable.

Allow ECMP: Allow Equal Cost MultiPath.

Default: When this parameter is Enable, RIP distributes a default route (0.0.0.0/0.0.0.0) information into its route table and advertises it.

Default Metric: Set the default metric for the redistributed routes. The valid values are (1 to 15).

Update Timer: The timer interval to generate a complete response to every neighboring gateway.

Timeout Timer: Upon expiration of the timeout, the route is no longer valid and set to unreachable.

Garbage Timer Upon expiration of the garbage-collection timer, the route is finally removed from the tables.

2) Click Apply.

5.1.2 Configuring Network

Choose the menu L3 FEATURES > RIP > Network Config to load the following page.

Figure 5-2 Configuring NetworkRIP Network List Add Delete Added Network Total: 0 RIP Neighbor List Add Delete Added Network Total: 0

Follow these steps to configure networks with RIP protocol enabled and RIP neighbor:

1) In the RIP Network List section, click Add to add an RIP network.

RIP Network List

You could add the network to enable RIP protocol here, so the interface in the network would enable RIP protocol. The network enabled would be displayed in the list. You could choose to delete the network here.

2) In the RIP Neighbor List section, click Add to add an RIP neighbor network.

RIP Neighbor List

You could add the RIP neighbor here, so the response would be sent using unicast. The neighbor added would be displayed in the list. You could choose to delete the neighbor here.

5.1.3 Configuring Interface

Choose the menu L3 FEATURES > RIP > Interface Config to load the following page.

Figure 5-3 Configuring Interface

Interface Config
InterfaceIP AddressStatusSend VersionReceive VersionAuthen ModeKey IDKey
Vlan 1192.168.0.1UpRIPv2BothNone-
Total: 1

Follow these steps to configure the RIP parameters of the interface:

1) In the Interface Config section, select the interface to be configured, then specify the parameters.

IP Address: The interface IP address. You can't change it here.

Status: The interface RIP status (up or down) is decided by the network status. You can't change it here.

Send Version: Select the version of RIP control packets the interface should send from the pull-down menu.

RIPv1: Send and receive RIP version 1 formatted packets via broadcast.

RIPv2: Send and receive RIP version 2 packets using multicast.

RIPv2-bc: Send RIP version 2 packets using broadcast.

Receive Version:

Select what RIP control packets the interface will accept from the pull-down menu.

RIPv1: Accept only RIP version 1 formatted packets.

RIPv2: Accept only RIP version 2 formatted packets.

Both: Accept both RIP version 1 and RIP version 2 formatted packets.

Authen Mode: Select an authentication type.

None: This is the initial interface state. If you select this option from the pull-down menu, no authentication protocols will be run.

Simple: If you select 'Simple', you will be prompted to enter an authentication key. This key will be included, in the clear, in the RIP header of all packets sent on the network. All routers on the network must be configured with the same key.

MD5: If you select 'MD5', you will be prompted to enter both an authentication key and an authentication ID. All routers on the network must be configured with the same key and ID.

Key ID: Enter the RIP Authentication Key ID for the specified interface. If you choose not to use authentication or to use 'simple', you will not be prompted to enter the key ID.

Password: Enter the RIP Authentication Key for the specified interface. If you do not choose to use authentication, you will not be prompted to enter a key. If you choose 'simple' or 'MD5', the key may be up to 16 octets long.

2) Click Apply.

5.1.4 Configuring Route Redistribution

Choose the menu L3 FEATURES > RIP > Route Redistribution to load the following page.

Figure 5-4 Configuring Route RedistributionRoute Redistribution Config Source: Connected Metric: (Optional, 1-15) Cancel Create

Follow these steps to configure the RIP route redistribution parameters:

1) In the Route Redistribution section, click Add to configure the parameters.

Source: The available source routes for redistribution by RIP. The valid values are 'Static', 'Connected', 'BGP', 'ISIS', and 'OSPF'.

The available source routes for redistribution by RIP. The valid values are 'Static', 'Connected', 'BGP', 'ISIS', and 'OSPF'.

Process ID: Specify the process ID of OSPF to redistribute.

Metric: Set the metric value to be used as the metric of redistributed routes. The valid value ranges from 1 to 15, and the default is equal to the Default Metric configured on the Basic page.

2) Click Create.

5.2 Using the CLI

5.2.1 Enabling RIP Function

Follow these steps to enable the RIP function on the switch.

Step 1 configure

Enter global configuration mode.

Step 2 router rip

Enable the RIP function. Only when the RIP function is enabled can the global configuration of the RIP function be performed. When the RIP function is disabled, the global configuration of the RIP function will be cleared. To disable this function, use the no router rip command.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the RIP function on the switch:

Switch#configure

Switch(config)#router rip

Switch(config-router)#end

Switch#copy running-config startup-config

5.2.2 Enabling RIP Function for Specific Network Segment

Follow these steps to enable the RIP function for a specific network segment.

Step 1 configure

Enter global configuration mode.

Step 2 router rip

Enable the RIP function. Only when the RIP function is enabled can the global configuration of the RIP function be performed. When the RIP function is disabled, the global configuration of the RIP function will be cleared. To disable this function, use the no router rip command.

Step 3 networknetwork number
Enable the RIP function on the corresponding interface of the configured network segment. To disable this function, use the no network command.
network number: Network number, the format is 192.168.0.0. If you enter an IP address, the network number will be automatically obtained based on the mask length of the natural network segment. Entering 0.0.0.0 means enabling the RIP function on all interfaces.
Step 4 end
Return to privileged EXEC mode.
Step 5 copy running-config startup-config
Save the settings in the configuration file.
The following example shows how to enable the RIP function on the switch:
Switch#configure
Switch(config)#router rip
Switch(config-router)#192.168.0.0
Switch(config-router)#end
Switch#copy running-config startup-config

5.2.3 Configuring RIP Message Version

Follow these steps to configure the version of packets sent and received by RIP.

Step 1configureEnter global configuration mode.
Step 2router ripEnable the RIP function. Only when the RIP function is enabled can the global configuration of the RIP function be performed. When the RIP function is disabled, the global configuration of the RIP function will be cleared. To disable this function, use the no router rip command.
Step 3version{1/2}Configure the version of packets sent and received by RIP. By default, the switch sends RIPv2 packets and receives RIPv1 and RIPv2 packets. To restore the default message version settings, use the no version command.1: Send and receive RIPv1 messages.2: Send and receive RIPv2 messages.
Step 4endReturn to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the RIP message version as RIPv1:

Switch#configure

Switch(config)#router rip

Switch(config-router)#version 1

Switch(config-router)#end

Switch#copy running-config startup-config

5.2.4 Configuring RIP Timer

Follow these steps to configure the RIP timer.

Step 1 configure

Enter global configuration mode.

Step 2 router rip

Enable the RIP function. Only when the RIP function is enabled can the global configuration of the RIP function be performed. When the RIP function is disabled, the global configuration of the RIP function will be cleared. To disable this function, use the no router rip command.

Step 3 timer basic

update-value timeout-value garbage-collect-value

Configure the RIP timer. To restore the timer configuration to its default, use the no timer basic command.

update-value: Routing table update time, ranging from 5 to 86400 seconds. The default value is 30.

timeout-value: Routing table aging time, ranging from 5 to 86400 seconds. The default value is 180.

garbage-collect-value: The expiration time after the routing entry is unreachable. When the entry is unreachable, the routing entry is removed from the routing table after the expiration time. The range is 5~86400 seconds, and the default value is 120.

Step 4 end

Return to privileged EXEC mode.

Step 5: copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the routing table update time to 50 seconds, the routing table aging time to 100 seconds, and the routing entry expiration time to 100 seconds:

Switch#configure

Switch(config)#router rip

Switch(config-router)#timer basic 50 100 100

Switch(config-router)#end

Switch#copy running-config startup-config

5.2.5 Configuring Management Distance

Follow these steps to configure the management distance of RIP routing.

Step 1: configure

Enter global configuration mode.

Step 2: router rip

Enable the RIP function. Only when the RIP function is enabled can the global configuration of the RIP function be performed. When the RIP function is disabled, the global configuration of the RIP function will be cleared. To disable this function, use the no router rip command.

Step 3 distance

distance

Configure the management distance of RIP routing. To restore the default configuration, use the no distance command.

distance: Management distance of RIP routing, ranging from 1 to 255. The default value is 120.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the management distance of RIP routing to 100:

Switch#configure

Switch(config)#router rip

Switch(config-rtr)#distance 110

Switch(config-rtr)#end

Switch#copy running-config startup-config

5.2.6 Enabling Auto-summary Function

Follow these steps to enable the automatic summary function of RIP.

Step 1 configure

Enter global configuration mode.

Step 2 router rip

Enable the RIP function. Only when the RIP function is enabled can the global configuration of the RIP function be performed. When the RIP function is disabled, the global configuration of the RIP function will be cleared. To disable this function, use the no router rip command.

Step 3 auto-summary

Enable the automatic summary function of RIP. After this function is enabled, routing entries will be automatically summarized into natural network segments, which can reduce the number of routing entries issued for each update. To disable this function, use the no auto-summary command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the automatic summary function of RIP:

Switch#configure

Switch(config)#router rip

Switch(config-router)#auto-summary

Switch(config-router)#end

Switch#copy running-config startup-config

5.2.7 Setting Default Metric

Follow these steps to set the default metric for redirection routes.

Step 1 configure

Enter global configuration mode.

Step 2 router rip

Enable the RIP function. Only when the RIP function is enabled can the global configuration of the RIP function be performed. When the RIP function is disabled, the global configuration of the RIP function will be cleared. To disable this function, use the no router rip command.

Step 3 default-metric metric

Set the default metric for redirection routes. To restore the default configuration, use the no default-metric command.

metric: The default metric of the redirect route, ranging from 1 to 15, and the default value is 1.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the default metric for redirection routes to 5:

Switch#configure

Switch(config)#router rip

Switch(config-router)#default-metric 5

Switch(config-router)#end

Switch#copy running-config startup-config

5.2.8 Configuring RIP Redirection

Follow these steps to set RIP to redirect external routes.

Step 1 configure

Enter global configuration mode.

Step 2 router rip

Enable the RIP function. Only when the RIP function is enabled can the global configuration of the RIP function be performed. When the RIP function is disabled, the global configuration of the RIP function will be cleared. To disable this function, use the no router rip command.

Step 3 redistribute

{ ospf process-id | connected | static } [ metric metric-value ]

Set RIP to redirect external routes. Its no command has two forms: if it does not contain the metric parameter, it is used to disable the redirection function of the corresponding external route. If it contains the metric parameter, it is used to restore the metric used for redirect routes to the default value.

ospf: Enable RIP redirect OSPF routing function.

process-id: Redirected OSPF process number.

connected: Enable RIP redirect direct routing function.

static: Enable RIP redirect static routing function.

metric-value: The metric of the redirect route.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set RIP to redirect ospf process 1, and set metric to 3:

Switch#configure

Switch(config)#router rip

Switch(config-router)#redistribute ospf 1 metric 3

Switch(config-router)#end

Switch#copy running-config startup-config

5.2.9 Enabling ECMP Function

Follow these steps to enable the ECMP (Equal-cost multi-path routing) function of RIP.

Step 1 configure

Enter global configuration mode.

Step 2 router rip

Enable the RIP function. Only when the RIP function is enabled can the global configuration of the RIP function be performed. When the RIP function is disabled, the global configuration of the RIP function will be cleared. To disable this function, use the no router rip command.

Step 3 allow-ecmp

Enable the ECMP function. To disable this function, use the no allow-ecmp command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the ECMP function of RIP:

Switch#configure

Switch(config)#router rip

Switch(config-router)#allow-ecmp

Switch(config-router)#end

Switch#copy running-config startup-config

5.2.10 Introducing Default Route

Follow these steps to introduce a default route into RIP.

Step 1 configure

Enter global configuration mode.

Step 2 router rip

Enable the RIP function. Only when the RIP function is enabled can the global configuration of the RIP function be performed. When the RIP function is disabled, the global configuration of the RIP function will be cleared. To disable this function, use the no router rip command.

Step 3 default-information originate

Introduce a default route into RIP. To disable this function, use the no default-information originate command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to introduce a default route into RIP:

Switch#configure

Switch(config)#router rip

Switch(config-router)#default-information originate

Switch(config-router)#end

Switch#copy running-config startup-config

5.2.11 Configuring RIP Neighbor

Follow these steps to configure the neighbor of RIP.

Step 1 configure

Enter global configuration mode.

Step 2 router rip

Enable the RIP function. Only when the RIP function is enabled can the global configuration of the RIP function be performed. When the RIP function is disabled, the global configuration of the RIP function will be cleared. To disable this function, use the no router rip command.

Step 3 neighbor ip-address

Configure the neighbor of RIP. After configuring the neighbor, RIP will send RIP packets to the neighbor through unicast packets. To clear the neighbor configuration, use the no neighbor command.

ip-address: IP address of RIP's neighbor.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to specify 192.168.0.100 as the RIP neighbor:

Switch#configure

Switch(config)#router rip

Switch(config-router)#neighbor 192.168.0.100

Switch(config-router)#end

Switch#copy running-config startup-config

5.2.12 Configuring Passive-Interface

Follow these steps to configure the interface not to send RIP packets but only to receive RIP packets.

Step 1 configure

Enter global configuration mode.

Step 2 router rip

Enable the RIP function. Only when the RIP function is enabled can the global configuration of the RIP function be performed. When the RIP function is disabled, the global configuration of the RIP function will be cleared. To disable this function, use the no router rip command.

Step 3 passive-interface interface {fastEthernet| gigabitEthernet| hundred-gigabitEthernet | loopback | port-channel | ten-gigabitEthernet | twentyFive-gigabitEthernet | two-gigabitEthernet | vlan}interface-value

Configure the interface not to send RIP packets but only to receive RIP packets. A unicast response will be sent out when a neighbor is configured at the same time. To disable this function, use the no passive-interface interface command.

interface-value: Specify the interface to be configured as passive-interface.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure VLAN 2 as passive-interface:

Switch#configure

Switch(config)#router rip

Switch(config-router)#passive-interface interface vlan 2

Switch(config-router)#end

Switch#copy running-config startup-config

5.2.13 Configuring Authentication Mode

Follow these steps to configure the authentication mode of RIP packets.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 ip rip authentication mode {

md5 | simple }

Configure the authentication mode of RIP packets. The authentication function only takes effect after the authentication mode and authentication password are configured. To clear the authentication mode configuration, use the no ip rip authentication mode command.

md5: Configure the authentication mode of RIP to md5 authentication.

simple: Configure the authentication mode of RIP to plain text authentication.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the RIP authentication mode of VLAN 2 to md5 authentication:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ip rip authentication mode md5

Switch(config-if)#end

Switch#copy running-config startup-config

5.2.14 Configuring Authentication String

Follow these steps to configure the password and key ID for RIP authentication.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernetport-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}Enter interface configuration mode.
Step 3 ip rip authentication stringpassword [ key-id key-id-value ]Configure the password and key ID for RIP authentication. The key ID is only used for md5 authentication. This command cannot be configured at the same time as the ip rip authentication key-chain command. To clear the password and key ID of RIP authentication, use the no ip rip authentication string command.password: RIP authentication password, 16 characters at most.key-id-value: Key ID for RIP authentication, ranging from 1 to 255. The default value is 1.
Step 4 endReturn to privileged EXEC mode.
Step 5 copy running-config startup-configSave the settings in the configuration file.

The following example shows how to configure the rip authentication password of interface VLAN 2 as tplink and the key ID as 2:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ip rip authentication string tplink key-id 2

Switch(config-if)#end

Switch#copy running-config startup-config

5.2.15 Configuring Authentication Key-chain

Follow these steps to configure the password and key ID for RIP authentication by binding key-chain.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 ip rip authentication key-chain

key-chain-name

Configure the password and key ID for RIP authentication by binding key-chain. This command cannot be configured at the same time as the ip rip authentication string command. To clear key-chain binding, use the no ip rip authentication key-chain command.

key-chain-name: The name of the key-chain to be bound.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure key chain as 1, set key as 0, the corresponding password as tplink, and bind the RIP authentication of VLAN 2 to key chain 1:

Switch#configure

Switch(config)#key chain 1

Switch(config-keychain)#key 0 key-string tplink

Switch(config-keychain)#exit

Switch(config)#interface vlan 1

Switch(config-if)#ip rip authentication key-chain 1

Switch(config-if)#end

Switch#copy running-config startup-config

5.2.16 Configuring Receive Version

Follow these steps to configure the version of RIP packets received by the interface.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 ip rip receive version {1 | 2}

Configure the version of RIP packets received by the interface. If the receive version of an interface is not configured, it will be determined by the global configuration. To restore the default configuration, use the no ip rip receive version command.

1: Configure the receive version of the interface to RIPv1. 2: Configure the receive version of the interface to RIPv2.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the receive version of VLAN 1 to RIPv1:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#ip rip receive version 1

Switch(config-if)#end

Switch#copy running-config startup-config

5.2.17 Configuring Send Version

Follow these steps to configure the version of RIP packets sent by the interface.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 ip rip send version {1 | 2}

Configure the version of RIP packets sent by the interface. If the send version of an interface is not configured, it will be determined by the global configuration. To restore the default configuration, use the no ip rip send version command.

1: Configure the send version of the interface to RIPv1. 2: Configure the send version of the interface to RIPv2.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the send version of VLAN 1 to RIPv1:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#ip rip send version 1

Switch(config-if)#end

Switch#copy running-config startup-config

5.2.18 Configuring Split Horizon

Follow these steps to configure the split horizon function of the interface.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 ip rip split-horizon [poison-reverse]

Configure the split horizon function of the interface. This function is enabled by default. When this function is enabled, RIP will not send routing entries learned from this interface out of this interface. When this function is disabled, RIP will only send routing entries according to the routing table. To disable this function, use the no ip rip split-horizon function.

poison-reverse: Enable the poison-reverse function of the interface. After this function is enabled, the entries learned from the interface will have the metric set to 16 before being sent out. Disable the poison reversal function by configuring the ip rip split-horizon command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the poison-reverse function of VLAN 1:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#ip rip split-horizon poison-reverse

Switch(config-if)#end

Switch#copy running-config startup-config

5.2.19 Enabling RIPv2 Packet Broadcast

Follow these steps to enable the RIPv2 packet broadcast function of the interface.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 ip rip v2-broadcast

Enable the RIPv2 packet broadcast function of the interface. By default, RIPv2 messages are sent through multicast. After this function is enabled on an interface, RIPv2 messages on the interface are sent through broadcast. To disable this function, use the no ip rip v2-broadcast function.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the RIPv2 packet broadcast function of VLAN 1:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#ip rip v2-broadcast

Switch(config-if)#end

Switch#copy running-config startup-config

5.2.20 Viewing RIP Routing Table

Follow these steps to view the RIP routing table.

Step 1 show ip rip

Display RIP routing table.

The following example shows how to view the RIP routing table:

Switch#show ip rip

Codes: R - RIP, C - connected, S - Static, O - OSPF, B - BGP

Sub-codes:

Follow these steps to view the RIP status.

Step 1 show ip rip status

Display RIP status.

The following example shows how to view the RIP status:

Switch#show ip rip status

Routing Protocol is "rip"

Sending updates every 30 seconds with +/-25%, next due in 0 seconds

Timeout after 180 seconds, garbage collect after 120 seconds

Outgoing update filter list for all interface is not set

Incoming update filter list for all interface is not set

Default redistribution metric is 1

Redistributing:

Default version control: send version 2, receive any version

Interface Send Recv Key-chain

Routing for Networks:

Routing Information Sources:

Gateway BadPackets BadRoutes Last Update

Distance: 120 (default is 120)

5.2.22 Clearing IP RIP

Follow these steps to clear the routing entries for RIP learning and re-request routing information from other devices.

Step 1 clear ip rip

Clear the routing entries for RIP learning and re-request routing information from other devices.

The following example shows how to clear the routing entries for RIP learning and re-request routing information from other devices:

Switch#clear ip rip

6

RIPng Configurations

RIPng (RIP next generation) is a routing protocol that improves the RIP protocol in order to solve the compatibility problem between the RIP protocol and IPv6.

6.1 Using the CLI

6.1.1 Enabling RIPng Function

Follow these steps to enable the RIPng function on the switch.

Step 1 configure

Enter global configuration mode.

Step 2 router ripng

Enable the RIPng function. Only when the RIPng function is enabled can the global configuration of the RIPng function be performed. When the RIPng function is disabled, the global configuration of the RIPng function will be cleared. To disable this function, use the no router ripng command.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the RIPng function on the switch:

Switch#configure

Switch(config)#router ripng

Switch(config-router)#end

Switch#copy running-config startup-config

Switch#copy running-config startup-config

6.1.2 Enabling RIP Function on Specific Port

Follow these steps to enable the RIPng function on a specific port.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}
Enter interface configuration mode.

Step 3 ipv6 rip enable

Enable the ripng function of the interface. This command only takes effect after the global switch of RIPng is enabled. To disable this function, use the no ipv6 rip enable command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the RIPng function of VLAN 1:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#ipv6 rip enable

Switch(config-if)#end

Switch#copy running-config startup-config

6.1.3 Configuring RIPng Timer

Follow these steps to configure the RIPng timer.

Step 1 configure

Enter global configuration mode.

Step 2 router ripng

Enable the RIPng function. Only when the RIPng function is enabled can the global configuration of the RIPng function be performed. When the RIPng function is disabled, the global configuration of the RIPng function will be cleared. To disable this function, use the no router ripng command.

Step 3 timer basic

update-value timeout-value garbage-collect-value

Configure the RIPng timer. To restore the timer configuration to its default, use the no timer basic command.

update-value: Routing table update time, ranging from 1 to 65535 seconds. The default value is 30.

timeout-value: Routing table aging time, ranging from 1 to 65535 seconds. The default value is 180.

garbage-collect-value: The expiration time after the routing entry is unreachable. When the entry is unreachable, the routing entry is removed from the routing table after the expiration time. The range is 1 to 65535 seconds, and the default value is 120.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the routing table update time to 50 seconds, the routing table aging time to 100 seconds, and the routing entry expiration time to 100 seconds:

Switch#configure

Switch(config)#router ripng

Switch(config-router)#timer basic 50 100 100

Switch(config-router)#end

Switch#copy running-config startup-config

6.1.4 Setting Default Metric

Follow these steps to set the default metric for redirection routes.

Step 1 configure

Enter global configuration mode.

Step 2 router ripng

Enable the RIPng function. Only when the RIPng function is enabled can the global configuration of the RIPng function be performed. When the RIPng function is disabled, the global configuration of the RIPng function will be cleared. To disable this function, use the no router ripng command.

Step 3 default-metric metric
Set the default metric for redirection routes. To restore the default configuration, use the no default-metric command.
metric: The default metric of the redirect route, ranging from 1 to 15, and the default value is 1.
Step 4 end
Return to privileged EXEC mode.
Step 5 copy running-config startup-config
Save the settings in the configuration file.

The following example shows how to set the default metric for redirection routes to 5:

Switch#configure

Switch(config)#router ripng

Switch(config-router)#default-metric 5

Switch(config-router)#end

Switch#copy running-config startup-config

6.1.5 Configuring RIPng Redirection

Follow these steps to set RIPng to redirect external routes.

Step 1configureEnter global configuration mode.
Step 2router ripngEnable the RIPng function. Only when the RIPng function is enabled can the global configuration of the RIPng function be performed. When the RIPng function is disabled, the global configuration of the RIPng function will be cleared. To disable this function, use the no router ripng command.
Step 3redistribute{ ospfv3 | static } [ metric metric-value ]Set RIPng to redirect external routes. Its no command has two forms: if it does not contain the metric parameter, it is used to disable the redirection function of the corresponding external route. If it contains the metric parameter, it is used to restore the metric used for redirect routes to the default value.ospfv3: Enable RIPng redirect OSPF V3 routing function.static: Enable RIPng redirect static routing function.metric-value:The metric of the redirect route.
Step 4endReturn to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set RIPng to redirect OSPFv3, and set metric to 3:

Switch#configure

Switch(config)#router ripng

Switch(config-router)#redistribute ospfv3 metric 3

Switch(config-router)#end

Switch#copy running-config startup-config

6.1.6 Enabling ECMP Function

Follow these steps to enable the ECMP (Equal-cost multi-path routing) function of RIP.

Step 1 configure

Enter global configuration mode.

Step 2 router ripng

Enable the RIPng function. Only when the RIPng function is enabled can the global configuration of the RIPng function be performed. When the RIPng function is disabled, the global configuration of the RIPng function will be cleared. To disable this function, use the no router ripng command.

Step 3 allow-ecmp

Enable the ECMP function. To disable this function, use the no allow-ecmp command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the ECMP function of RIPng:

Switch#configure

Switch(config)#router ripng

Switch(config-router)#allow-ecmp

Switch(config-router)#end

Switch#copy running-config startup-config

6.1.7 Introducing Default Route

Follow these steps to introduce a default route into RIPng.

Step 1 configure

Enter global configuration mode.

Step 2 router ripng

Enable the RIPng function. Only when the RIPng function is enabled can the global configuration of the RIPng function be performed. When the RIPng function is disabled, the global configuration of the RIPng function will be cleared. To disable this function, use the no router ripng command.

Step 3 default-information originate

Introduce a default route into RIPng. To disable this function, use the no default-information originate command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to introduce a default route into RIPng:

Switch#configure

Switch(config)#router ripng

Switch(config-router)#default-information originate

Switch(config-router)#end

Switch#copy running-config startup-config

6.1.8 Configuring Passive-Interface

Follow these steps to configure the interface not to send RIPng packets but only to receive RIPng packets.

Step 1 configure

Enter global configuration mode.

Step 2 router ripng

Enable the RIPng function. Only when the RIPng function is enabled can the global configuration of the RIPng function be performed. When the RIPng function is disabled, the global configuration of the RIPng function will be cleared. To disable this function, use the no router ripng command.

Step 3passive-interface interface { fastEthernet | gigabitEthernet | hundred-gigabitEthernet | loopback | port-channel | ten-gigabitEthernet | twentyFive-gigabitEthernet | two-gigabitEthernet | vlan }interface-valueConfigure the interface not to send RIPng packets but only to receive RIPng packets. To disable this function, use the no passive-interface interface command.interface-value: Specify the interface to be configured as passive-interface.
Step 4 endReturn to privileged EXEC mode.
Step 5 copy running-config startup-configSave the settings in the configuration file.
The following example shows how to configure VLAN 2 as passive-interface:Switch#configureSwitch(config)#router ripngSwitch(config-router)#passive-interface interface vlan 2Switch(config-router)#endSwitch#copy running-config startup-config

6.1.9 Configuring Split Horizon

Follow these steps to configure the split horizon function of the interface.

Step 1configureEnter global configuration mode.
Step 2interface {vlan vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernetport-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}Enter interface configuration mode.
Step 3ipv6 rip split-horizon [ poison-reverse ]Configure the split horizon function of the interface. This function is enabled by default.When this function is enabled, RIPng will not send routing entries learned from this interfaceout of this interface. When this function is disabled, RIPng will only send routing entriesaccording to the routing table. To disable this function, use the no ipv6 rip split-horizonfunction.poison-reverse: Enable the poison-reverse function of the interface. After this function isenabled, the entries learned from the interface will have the metric set to 16 before beingsent out. Disable the poison reversal function by configuring the ipv6 rip split-horizoncommand.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the poison-reverse function of VLAN 1:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#ipv6 rip split-horizon poison-reverse

Switch(config-if)#end

Switch#copy running-config startup-config

6.1.10 Viewing RIPng Routing Table

Follow these steps to view the RIPng routing table.

Step 1 show ipv6 rip

Display RIPng routing table.

The following example shows how to view the RIPng routing table:

Switch#show ipv6 rip

Codes: R - RIPng, C - connected, S - Static, O - OSPF, B - BGP

Sub-codes:

(i) - interface, (a/S) - aggregated/Suppressed

Network

Next Hop

Via

Metric Tag Time

6.1.11 Viewing RIPng Status

Follow these steps to view the RIPng status.

Step 1 show ipv6 rip status

Display RIP status.

The following example shows how to view the RIPng status:

Switch#show ipv6 rip status

Routing Protocol is "RIPng"

Sending updates every 30 seconds with +/-25%, next due in 9 seconds

Timeout after 180 seconds, garbage collect after 120 seconds

Outgoing update filter list for all interface is not set

Incoming update filter list for all interface is not set

Default redistribution metric is 1

Redistributing:

Default version control: send version 1, receive version 1

Interface

Send Recv

Routing for Networks:

Routing Information Sources:

Gateway

BadPackets BadRoutes Last Update

6.1.12 Clearing IPv6 RIP

Follow these steps to clear the routing entries for RIPng learning and re-request routing information from other devices.

Step 1 clear ipv6 rip

Clear routes learned by RIPng and request routing information.

The following example shows how to clear the routing entries for RIPng learning and re-request routing information from other devices:

Switch#clear ipv6 rip

7 OSPF Configurations

TP-LINK Omada Pro S5500-24GP4F - OSPF Configurations - 1

Note:

OSPF is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If VRRP is available, there is L3 FEATURES > OSPF in the menu structure.

OSPF is an Interior Gateway Protocol (IGP) designed expressly for IP networks, supporting IP subnetting and tagging of externally derived routing information. OSPF also allows packet authentication and uses IP multicast when sending and receiving packets.

Currently, OSPF Version 2 (RFC2328) is used for the IPv4 protocol; Use OSPF Version 3 (RFC2740) for IPv6 protocol. Unless otherwise specified, the OSPF referred to in this chapter is OSPF Version 2.

7.1 Using the GUI

7.1.1 Configuring OSPF Process

Choose the menu L3 FEATURES > OSPF > Process Config to load the following page.

Figure 7-1 Configuring OSPF ProcessOSPF Process Table Add Delete Restart Process ID Active Router ID Type Router ID Status Total: 0

Each OSPF process will run OSPF protocol independently, acting like a unique router. OSPF process should be created before you taking other operations. Follow these steps to configure the OSPF process:

1) In the OSPF Process Table section, click Add to create a new OSPF process, and then configure the corresponding parameters.

Process ID The 16 bit integer that uniquely identifies the OSPF process, ranging from 1 to 65535.
Router IDThe 32 bit unsigned integer in dotted decimal format that uniquely identifies the router within the autonomous system (AS). When you change the router ID of a process, it will not take effect until you restart the process.
Active Router ID Displays the active router ID that is currently used by the process.
Type Displays the type of the process.

Status Displays the status of the process.

Running: The process is running and its router ID has been configured or auto selected.

Pending: The process has no router ID and can not start.

2) Click Create.

7.1.2 Configuring OSPF

Choose the menu L3 FEATURES > OSPF > Basic Config to load the following page.

Figure 7-2 Configuring OSPF InformationSelect Current Process Current Process: Default Route Advertise Config Originate: Enable Always: Enable Metric: (Optional. Range: 1-16777214) Metric Type: External Type 1 External Type 2 Apply OSPF Config ASBR Mode: ABR Status: Distance: (1-255) RFC 1583 Compatibility: SPF Delay Time: 0 ms (0-600000…

Follow these steps to complete OSPF basic configurations:

1) In the Select Current Process section, select one OSPF process for configuration.

Current Process Select the desired OSPF process for configuration.

2) In the Default Route Advertise Config section, configure the default route origination.

Originate When this parameter is Enable, OSPF originates an AS-External LSA advertising a default route (0.0.0.0/0.0.0.0).
Always If Originate is Enable, but the Always option is DISABLE, OSPF will only originate a default route if the router already has a default route in its routing table. Set Always to ENABLE to force OSPF to originate a default route regardless of whether the router has a default route.
Metric Specify the metric of the default route. The valid value ranges from 1 to 16777214 and the default is 1.
Metric Type Set the OSPF metric type of the default route. Two types are supported: External Type 1 and External Type 2. The default value is External Type 2.

3) In the OSPF Config section, configure all the global parameters.

ASBR Mode The router is an Autonomous System Boundary Router if it is configured to redistribute routes from another protocol, or if it is configured to originate an AS-External LSA advertising the default route.
ABR StatusThe router is an Area Border Router if it has active non-virtual interfaces in two or more OSPF areas.
Distance Specify OSPF route distance. When more than two protocols have routes to the same destination, only the route which have smallest distance will be inserted to IP routing table. The valid value ranges from 1 to 255 and the default is 110.
Metric Type Set the OSPF metric type of the default route. Two types are supported: External Type 1 and External Type 2. The default value is External Type 2.
RFC 1583 CompatibilitySelect the preference rules that will be used when choosing among multiple AS-external LSAs advertising the same destination. If you select Enable, the preference rules will be those defined by RFC 1583. Else the preference rules will be those defined in RFC 2328, which will prevent routing loops when AS-external LSAs for the same destination have been originated from different areas. All routers in the OSPF domain must be configured the same. The default value is 'Enable'.
SPF Delay Time The number of seconds from when OSPF receives a topology change to the start of the next SPF calculation. The valid value ranges from 0 to 600000 milliseconds and the default is 0. When the SPF Delay Time is set to 0, the SPF Hold Time (Min) and SPF Hold Time (Max) will be reset to their default values.
SPF Hold Time (Min)The minimum time in seconds between two consecutive SPF calculations. The valid value ranges from 1 to 600000 milliseconds and the default is 50.
SPF Hold Time (Max)The maximum time in seconds between two consecutive SPF calculations. The valid value ranges from 1 to 600000 milliseconds and the default is 5000.
Default MetricSet a default for the metric of redistributed routes. The valid value ranges from 1 to 16777214 and the default is 20.
Maximum PathsSet the number of paths that OSPF can report for a given destination. The valid value ranges from 1 to 32 and the default is 5.

Auto Cost Reference Bandwidth

Specify the reference bandwidth in megabits per second. The valid value ranges from 1 to 4294967 Mbps and the default is 100.

4) Click Apply.

7.1.3 Configuring Network

Choose the menu L3 FEATURES > OSPF > Network Config to load the following page.

Figure 7-3 Configuring NetworkNetwork Table Process ID: IP Address Wildcard Mask Area ID Total: 0

Follow these steps to configure networks contained by an area on this page. The interfaces, whose IP address fall into the networks, will be imported to the associated area:

1) In the Network Table section, select the Process ID and click Add to specify the parameters.

IP Address The IP address of the network.

Wildcard Mask The wildcard mask of the network. Normal subnet mask is also supported.

Area ID

The 32 bit unsigned integer that uniquely identifies the area to which a router interface connects. If you assign an Area ID which does not exist, the area will be created with default values. It can be in decimal format or dotted decimal format.

2) Click Create.

Process ID: Select one OSPF process to display its network list.

Select: Select the desired item for configuration. It is multi-optional.

IP Address: Displays the IP address of the network.

Metric Type: Set the OSPF metric type of the default route. Two types are supported: External Type 1 and External Type 2. The default value is External Type 2.

Wildcard Mask: Displays the wildcard mask of the network.

Area ID: Displays the area to which the network belongs.

7.1.4 Configuring Interface

Choose the menu L3 FEATURES > OSPF > Interface Config to load the following page.

Figure 7-4 Configuring InterfaceInterface Table Edit Refresh Recovery Interface IP Address/Mask Process Area ID Router Priority Retransmit interval Hello Interval Dead Interval Total: 0

Follow these steps to configure the interface parameters:

1) In the Interface Table section, click Edit to load the following page and specify the corresponding parameters.

Figure 7-5 Configuring InterfaceBack Interface Config Interface: Router Priority: (0-255) Retransmit interval: sec (1-65535) Hello Interval: sec (1-65535) Dead Interval: sec (1-65535) Transmit Delay: sec (1-65535) Cost: (1-65535) Network Type: ▼ Passive Mode: ▼ MTU Ignore: ▼ Authentication Type: ▼ Simple Key: (1-8 characters) MD5…

Interface: The interface for which data is to be displayed or configured.

IP Address/Mask: The IP address and subnet mask of the interface.

Process: The process to which the interface belongs.

Area ID The area to which a router interface connects.

Router PriorityThe router priority for the selected interface. The priority of an interface is specified as an integer from 0 to 255. A value of '0' indicates that the router is not eligible to become the designated router on this network. The default is 1.
Retransmit IntervalThe retransmit interval for the specified interface. This is the number of seconds between link-state advertisements for adjacencies belonging to this router interface. This value is also used when retransmitting database descriptions and link-state request packets. The valid value ranges from 1 to 65535 seconds and the default is 5 seconds.
Hello IntervalThe hello interval for the specified interface in seconds. This parameter must be the same for all routers attached to a network. The valid value ranges from 1 to 65535 seconds and the default is 10 seconds.
Dead IntervalThe dead interval for the specified interface in seconds. This specifies how long a router will wait to see a neighbor router's Hello packets before declaring that the router is down. This parameter must be the same for all routers attached to a network. The valid value ranges from 1 to 65535 seconds and the default is 40.
Transmit DelayThe Transit Delay for the specified interface. This specifies the estimated number of seconds it takes to transmit a link state update packet over the selected interface. The valid value ranges from 1 to 65535 seconds and the default is 1 second.
Cost The link cost. OSPF uses this value in computing shortest paths. The valid value ranges from 1 to 65535.
Network Type The OSPF network type on the interface. The default network type for Ethernet interfaces is broadcast.
Passive Mode Make an interface passive to prevent OSPF from forming an adjacency on an interface. OSPF advertises networks attached to passive interfaces as stub networks. Interfaces are not passive by default.
MTU Ignore Disables OSPF MTU mismatch detection on received database description packets. Default value is Disable(MTU mismatch detection is enabled).
Authentication TypeDisplays the authentication type of the interface. One of the following:null: No authentication.simple: Use simple password.md5: Use md5 message-digest algorithm.
Simple Key Displays the key used for simple authentication.
MD5 Key ID Displays the key ID used for md5 authentication.
MD5 Key Displays the key used for md5 authentication.

2) Click Apply. The information will be displayed in the Interface Table.

7.1.5 Configuring Area

Choose the menu L3 FEATURES > OSPF > Area Config to load the following page.

Figure 7-6 Configuring AreaArea Table Process ID: Add Delete Default Route Advertise Metric Type Metric SPF runs Area LSA Count No entries in this table. Total: 0

Follow these steps to create areas and configure area features:

1) In the Area Table section, click Add to load the following page, then specify the corresponding parameters.

Figure 7-7 Adding New AreaArea Config Area ID: (0-4294957295 or a.b.c.d) Area Type: Stub Default Cost: (Optional. Range: 1-16777214) Summary: Enable Cancel Create

Area IDThe 32 bit unsigned integer that uniquely identifies the area. It can be in decimal format or dotted decimal format.
Area Type OSPF area type: Stub or NSSA.
Default CostThe metric value you want to apply for the default Summary-LSA advertised into the stub area. The valid value ranges from 1 to 16777214.
Summary Set whether or not the specified Area will allow Summary Link-State Advertisements (Summary LSAs) to be imported into the area from other areas. It is always Enable in Normal areas. The default is Enable.

2) Click Create. You can view and manage the existed areas in the Area Table.

Default Route AdvertiseEnable or disable advertising default route into NSSA area by sending a NSSA-External LSA. OSPF will not advertise default route if this parameter is not specified.
Metric Type Set the OSPF metric type of the default route. Two types are supported: External Type 1 and External Type 2. The default value is External Type 2.
Metric Specify the metric of the default route. The valid value ranges from 1 to 16777214 and the default is 1.
Process ID Select one OSPF Process to display its area list.
Select Select the desired item for configuration. It is multi-optional.
Default Route AdvertiseDisplays the Default Route Advertise status.
SPF runs Displays the number of times that the intra-area route table has been calculated using this area's link-state database. This is typically done using Dijkstra's algorithm.
Area LSA CountDisplays the total number of link-state advertisements in this area's link-state database, excluding AS-External LSAs.

7.1.6 Configuring Area Aggregation

Choose the menu L3 FEATURES > OSPF > Area Aggregation to load the following page.

Figure 7-8 Configuring Area AggregationArea Aggregation Table Process ID: Add Delete Area ID IP Address Subnet Mask Cost Advertise No entries in this table. Total: 0

You can configure address ranges for an area on this page. The address range is used to consolidate or summarize routes for an area at an area boundary. The result is that a single summary route is advertised to other areas by the ABR. Routing information is condensed at area boundaries, a single route is advertised for each address range. Follow these steps to configure a new address range:

1) In the Area Aggregation Table section, click Add to load the following page, then specify the corresponding parameters.

Figure 7-9 Adding New Area AggregationArea Aggregation Config Area ID: (0-4294957295 or a.b.c.d) IP Address: (Format: 192.168.0.0) Subnet Mask: (Format: 255.255.0.0) Cost: (Optional. Range: 1-16777214) Advertise: Enable Cancel Create

2) Click Create. You can view and manage the existing area address ranges.

Area IDThe 32 bit unsigned integer that uniquely identifies the area. It can be in decimal format or dotted decimal format.
IP Address The IP address of the address range.
Subnet Mask The subnet mask of the address range.
Cost Specify the path cost to the address range. If not specified, it will be dynamic calculated by OSPF. The valid value ranges from 1 to 16777214.
AdvertiseSet whether or not the area address range will be advertised outside the area via a Network-Summary LSA. The default is Enable.
Default Route AdvertiseDisplays the Default Route Advertise status.
Process ID Select one OSPF Process to display its address range list.
Select Select the desired item for configuration. It is multi-optional.

Choose the menu L3 FEATURES > OSPF > Virtual Link to load the following page.

Figure 7-10 Configuring Virtual LinkVirtual Link Table Process ID: Transit Area ID Neighbor Router ID Retransmit Interval Hello Interval Dead Interval Transmit Delay Authentication Type Simple Key MD5 Key ID Total: 0

Follow these steps to create and manage virtual links:

1) In the Virtual Link Table section, click Add to load the following page, then specify the corresponding parameters.

Figure 7-11 Adding New AreaVirtual Link Creation Transit Area ID: (0-4294957295 or a.b.c.d) Neighbor Router ID: (Format: 1.1.1.1) Cancel Create

Transit Area IDThe ID of the transit area. Virtual links can be configured between any pair of area border routers having interfaces to a common (non-backbone) area. Here the common area is named Transit Area.
Neighbor Router IDThe router ID of the neighbor portion of a virtual link.

2) Click Create. You can view and manage the existing virtual links in the Virtual Link Table.

Process ID Select one OSPF Process to display its virtual link list.
Select Select the desired item for configuration. It is multi-optional.
Transit Area ID Displays the transit area ID of the virtual link.
Neighbor Router IDDisplays the neighbor router ID of the virtual link.
Retransmit IntervalThe retransmit interval for the specified interface. This is the number of seconds between link-state advertisements for adjacencies belonging to this router interface. This value is also used when retransmitting database descriptions and link-state request packets. The valid value ranges from 1 to 65535 seconds and the default is 5 seconds.
Hello IntervalThe hello interval for the specified interface in seconds. This parameter must be the same for all routers attached to a network. The valid value ranges from 1 to 65535 seconds and the default is 10 seconds.
Dead IntervalThe dead interval for the specified interface in seconds. This specifies how long a router will wait to see a neighbor router's Hello packets before declaring that the router is down. This parameter must be the same for all routers attached to a network. The valid value ranges from 1 to 65535 seconds and the default is 40.
Transmit DelayThe Transit Delay for the specified interface. This specifies the estimated number of seconds it takes to transmit a link state update packet over the selected interface. The valid value ranges from 1 to 65535 seconds and the default is 1 second.
Authentication TypeYou may select an authentication type other than none by clicking on the 'Authentication Type' button. The choices are:null: No authentication.simple: Uses simple password.md5: Uses md5 message-digest algorithm.
Simple Key The key used for simple authentication.
MD5 Key ID The key ID used for md5 authentication.
MD5 Key The key used for md5 authentication.

7.1.8 Configuring Route Redistribution

Choose the menu L3 FEATURES > OSPF > Route Redistribution to load the following page.

Figure 7-12 Configuring Virtual LinkRoute Redistribution Table Process ID: Add Delete Source Process ID Metric Metric Type Total: 0

Follow these steps to configure the RIP route redistribution parameters:

1) In the Route Redistribution section, click Add to load the following page, then specify the corresponding parameters.

Figure 7-13 Adding Route RedistributionRoute Redistribution Source: Metric: Metric Type: (Optional. Range: 1-16777214) (Optional) Cancel Create Source The available source routes for redistribution by RIP. The valid values are 'Static', 'Connected', 'BGP', 'ISIS', and 'OSPF'. Metric Set the metric value to be used as the metric of redist…

2) Click Create. You can view the RIP route redistribution information on this page.

7.1.9 Viewing Neighbor Table

Choose the menu L3 FEATURES > OSPF > Neighbor Table to load the following page.

Figure 7-14 Viewing Neighbor TableNeighbor Table Process ID: Refresh Interface Neighbor IP Address Router ID Router Priority State Dead Time No entries in this table. Total: 0

In the Neighbor Table section, you can view the neighbor list:

Process ID Select one OSPF Process to display its virtual link list.
Interface Displays the interface for which neighbor list is to be displayed.
Neighbor IP AddressThe IP address of the neighboring router's interface to the attached network.

Neighbor Router ID

A 32-bit integer in dotted decimal format representing the neighbor.

Router Priority: The router priority of the neighbor.

State: The state of the neighbor.

Down: This is the initial state of a neighbor conversation. It indicates that there has been no recent information received from the neighbor. On NBMA networks, Hello packets may still be sent to 'Down' neighbors, although at a reduced frequency.

Attempt: This state is only valid for neighbors attached to NBMA networks. It indicates that no recent information has been received from the neighbor, but that a more concerted effort should be made to contact the neighbor. This is done by sending the neighbor Hello packets at intervals of Hello Interval.

Init: In this state, a Hello packet has recently been seen from the neighbor. However, bidirectional communication has not yet been established with the neighbor (i.e., the router itself did not appear in the neighbor's Hello packet). All neighbors in this state (or greater) are listed in the Hello packets sent from the associated interface.

2-Way: In this state, communication between the two routers is bidirectional. This has been assured by the operation of the Hello Protocol. This is the most advanced state short of beginning adjacency establishment. The (Backup) Designated Router is selected from the set of neighbors in state 2-Way or greater.

ExStart: This is the first step in creating an adjacency between the two neighboring routers. The goal of this step is to decide which router is the master, and to decide upon the initial DD sequence number. Neighbor conversations in this state or greater are called adjacencies.

Exchange: In this state the router is describing its entire link state database by sending Database Description packets to the neighbor. In this state, Link State Request Packets may also be sent asking for the neighbor's more recent LSAs. All adjacencies in Exchange state or greater are used by the flooding procedure. These adjacencies are fully capable of transmitting and receiving all types of OSPF routing protocol packets.

Loading: In this state, Link State Request packets are sent to the neighbor asking for the more recent LSAs that have been discovered (but not yet received) in the Exchange state.

Full: In this state, the neighboring routers are fully adjacent. These adjacencies will now appear in Router LSAs and Network LSAs.

Dead Time: The amount of time, in seconds, to wait before the router assumes the neighbor is unreachable.

7.2 Using the CLI

7.2.1 Configuring Router OSPF

Follow these steps to create an OSPF routing process and enter the router configuration mode.

Step 1: configure

Enter global configuration mode.

Step 2: router ospf

process-id

Create an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they work separately. To delete the specified OSPF routing process, use the no router ospf command.

process-id: Process ID, ranging from 1 to 65535. Up to sixteen processes can be created.

Step 3: end

Return to privileged EXEC mode.

Step 4: copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to create an OSPF routing process with the process ID as 1:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.2 Configuring Router ID

Follow these steps to configure the router ID.

Step 1 configure

Enter global configuration mode.

Step 2 router ospf process-idCreate an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they works separately. To delete the specified OSPF routing process, please use the no router ospf command.process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.
Step 3 router-id router-idConfigure the router ID. The no router-id command is used to delete the configured router ID.router-id: The route ID in the format of dotted decimal notation. 0.0.0.0 is illegal.
Step 4 endReturn to privileged EXEC mode.
Step 5 copy running-config startup-configSave the settings in the configuration file.

The following example shows how to configure the router ID of OSPF routing process 1 as 1.1.1.1:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#router-id 1.1.1.1

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.3 Configuring Network

Follow these steps to configure the network of a specified area.

Step 1configureEnter global configuration mode.
Step 2router ospfprocess-idCreate an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they works separately. To delete the specified OSPF routing process, please use the no router ospf command.process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.

Step 3 network

ip-address wildcard-mask area area-id

Configure the network of a specified area. All the interfaces fallen into the configured network will belong to this area. To delete the specified network and its corresponding interfaces from this area, please use the no network command.

ip-address: The IP address of the network.

wildcard-mask: The wildcard mask of the network (such as 0.0.0.255). The subnet mask is also compatible (such as 255.0.0.0).

area-id: The area ID, in the format of an IP address in dotted decimal notation or decimal value ranging from 0 to 4294967295.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the network 192.168.0.0/24 in the area 0.0.0.0:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#network 192.168.0.0 255.255.255.0 area 0.0.0.0

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.4 Configuring Max-Paths

Follow these steps to configure the maximum number of equal-cost multipath routings.

Step 1 configure

Enter global configuration mode.

Step 2 router ospf

process-id

Create an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they work separately. To delete the specified OSPF routing process, use the no router ospf command.

process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.

Step 3 maximum-paths number
Configure the maximum number of the equal-cost multipath routings. To restore to default value, please use the no maximum-paths command.
number: The maximum number of the equal-cost multipath routings, ranging from 1 to 32. The default value is 32.
Step 4 end
Return to privileged EXEC mode.
Step 5 copy running-config startup-config
Save the settings in the configuration file.

The following example shows how to configure the maximum number of equal-cost multipath routings as 2:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#maximum-paths 2

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.5 Configuring ASBR

Follow these steps to configure the ASBR to redistribute the external routes from other routing protocols to the OSPF domain in type-5 LSAs.

Step 1 configure Enter global configuration mode. Step 2 router ospf process-id

Create an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they works separately. To delete the specified OSPF routing process, please use the no router ospf command.
process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.

Step 3 redistribute { connected | static | rip | ospf

process-id } [ metric cost ] [ metric-type type ]

Configure the ASBR to redistribute the external routes from other routing protocols to the OSPF domain in type-5 LSAs. To restore the certain optional parameters to default values, please use the no redistribute command with corresponding parameters.

connected: Specify the external route type as connected.

static: Specify the external route type as static.

rip: Specify the external route type as RIP.

ospf: Specify the external route type as OSPF.

process-id: The OSPF routing process ID, ranging from 1 to 65535. It's not allowed to redirect to the own process, for example, OSPF process 1 cannot redirect itself.

cost: The cost of the external routes, ranging from 1 to 16777214. Its default value is defined in the command default-metric.

type: The type of the external routes, either 1 or 2. The default value is 2.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to redistribute the RIP routes from the external and advertise them as type 1 external routes in the OSPF domain:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#redistribute rip metric-type 1

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.6 Configuring Default-Metric

Follow these steps to configure the default cost of the redistributing external route.

Step 1 configure

Enter global configuration mode.

Step 2 router ospf process-idCreate an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they works separately. To delete the specified OSPF routing process, please use the no router ospf command.process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.
Step 3 default-metric costConfigure the default cost of the redistributing external route. To restore to the default value, please use the no default-metric command.cost: The default cost of the redistributing external route, ranging form 1 to 16777214.
Step 4 endReturn to privileged EXEC mode.
Step 5 copy running-config startup-configSave the settings in the configuration file.

The following example shows how to configure the default cost of the redistributing external route as 12:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#default-metric 12

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.7 Configuring Default-Information Originate

Follow these steps to advertise the default route as an AS-External LSA.

Step 1 configure

Enter global configuration mode.

Step 2 router ospf process-id

Create an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they work separately. To delete the specified OSPF routing process, use the no router ospf command.

process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.

Step 3 default-information originate [always] [metric

cost ] [metric-type type]

Advertise the default route as an AS-External LSA. To cancel the advertisement of the default route, use the no default-information originate command without any optional parameters. To restore certain parameters to default values, use the no default-information originate command with corresponding parameters.

always: OSPF will advertise the default route whether there is a default route in the IP routing table or not. If this parameter is not configured, OSPF will advertise the default route only when there is a default route in the IP routing table.

cost: The default cost of the default route, ranging from 1 to 16777214. Its default value is 1.

type: The type of the external routes, either 1 or 2. The default value is 2.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure OSPF to advertise the default route whether there is a default route in the IP routing table or not:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#default-information originate always

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.8 Configuring Auto-Cost

Follow these steps to enable the auto computing function of the interface cost and configure the reference bandwidth.

Step 1 configure

Enter global configuration mode.

Step 2 router ospf

process-id

Create an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they work separately. To delete the specified OSPF routing process, use the no router ospf command.

process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.

Step 3 auto-cost reference-bandwidth

bandwidth

Enable the auto computing function of the interface cost and configure the reference bandwidth. The interface cost is the ratio of the reference bandwidth to the interface bandwidth. To restore the reference bandwidth to default value, use the no auto-cost reference-bandwidth command.

bandwidth: The reference bandwidth, ranging from 1 to 4294967 Mbps. Its default value is 100Mbps.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure OSPF to enable the auto computing function of the interface cost and configure the reference bandwidth as 10000 Mbps:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#auto-cost reference-bandwidth 10000

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.9 Configuring OSPF Administrative Distance

Follow these steps to configure the OSPF administrative distance.

Step 1 configure

Enter global configuration mode.

Step 2 router ospf

process-id

Create an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they work separately. To delete the specified OSPF routing process, use the no router ospf command.

process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.

Step 3 distance

administrative-distance

Configure the OSPF administrative distance. To restore to the default distance, use the no distance command. The administrative distance represents the priority of the routes. The smaller the administrative distance, the higher the priority. When different routing protocols have the same route to the same destination, the route with the highest priority will be selected to add to the IP routing table according to the administrative distance.

administrative-distance: Routing administrative distance, ranging from 1 to 255. Its default value is 110. When this value is set to 255, it indicates that the source of routing information is unreliable and all related routes are ignored.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the OSPF routing administrative distance as 100:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#distance 100

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.10 Configuring Computing Delay and Interval

Follow these steps to configure the computing delay and interval of the SPF.

Step 1 configure

Enter global configuration mode.

Step 2: router ospf

process-id

Create an OSPF routing process and enter router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they work separately. To delete the specified OSPF routing process, use the no router ospf command.

process-id: Process ID, ranging from 1 to 65535. Up to sixteen processes can be created.

Step 3: timers throttle spf

spf-delay spf-holdtime spf-max-holdtime

Configure the computing delay and interval of the SPF, thus preventing the consumption of CPU and memory caused by frequent SPF computing. To restore to the default value, use the no timers throttle spf command.

spf-delay: The delay time of the SPF computing, ranging from 1 to 600000 milliseconds. The default value is 0 milliseconds.

spf-holdtime: The minimum interval between two SPF computations, ranging from 1 to 600000 milliseconds. The default value is 50 milliseconds.

spf-max-holdtime: The maximum interval between two SPF computations, ranging from 1 to 600000 milliseconds. The default value is 5000 milliseconds.

Step 4: end

Return to privileged EXEC mode.

Step 5: copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the SPF computing delay as 10 seconds and the interval between 10 and 50 seconds:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#timers throttle spf 10000 10000 50000

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.11 Configuring RFC 1583

Follow these steps to configure the OSPF's compatibility for the routing rules in the RFC 1583.

Step 1 configure

Enter global configuration mode.

Step 2 router ospf

process-id

Create an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they work separately. To delete the specified OSPF routing process, use the no router ospf command.

process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.

Step 3 compatible rfc1583

Configure the OSPF's compatibility for the routing rules in RFC 1583. To cancel the compatibility, use the no compatible rfc1583 command. It is compatible by default.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the OSPF's compatibility for the routing rules in RFC 1583:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#compatible rfc1583

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.12 Defining Stub Area

Follow these steps to define an area as a stub area.

Step 1 configure

Enter global configuration mode.

Step 2 router ospf

process-id

Create an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they work separately. To delete the specified OSPF routing process, use the no router ospf command.

process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.

Step 3 area

area-id stub [no-summary]

Define an area as a stub area. To restore the stub area to a normal one, use the no area stub command without any optional parameters. To restore the certain parameters to default values, use the no area stub command with corresponding parameters.

area-id: The area ID, in the format of an IP address in dotted decimal notation or decimal value ranging from 1 to 4294967295.

no-summary: Configure the stub area as a totally stub area, where the ABR advertises neither the destinations in other areas nor the external routes. The stub area is not a totally stub area by default.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the area 1 as a totally stub area:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#area 1 stub no-summary

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.13 Defining NSSA Area

Follow these steps to define an area as an NSSA area.

Step 1 configure

Enter global configuration mode.

Step 2 router ospf

process-id

Create an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they work separately. To delete the specified OSPF routing process, use the no router ospf command.

process-id: Process ID, ranging from 1 to 65535. Up to sixteen processes can be created.

Step 3 area

area-id nssa [no-summary | default-information-originate [metric cost] [metric-type type]]

Define an area as an NSSA area. To restore the NSSA area to a normal one, use the no area nssa command without any optional parameters. To restore certain parameters to default values, use the no area nssa command with the corresponding parameters.

area-id: The area ID, in the format of an IP address in dotted decimal notation or decimal value ranging from 1 to 4294967295.

no-summary: Configure the NSSA area as a totally NSSA area, where the ABR advertises neither the destinations in other areas nor the external routes. The NSSA area is not a totally NSSA area by default.

default-information-originate: Enable or disable advertising default route into NSSA area by sending a NSSA-External LSA. OSPF will not advertise default route if this parameter is not specified

cost: The default cost of the default route, ranging from 1 to 16777214. Its default value is 1.

type: The type of the external routes, either 1 or 2. The default value is 2.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the Area 1 as a totally NSSA area:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#area 1 nssa no-summary

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.14 Configuring Area Default-Cost

Follow these steps to configure the cost of the default route sent from an ABR to a stub or NSSA area.

Step 1 configure

Enter global configuration mode.

Step 2 router ospfprocess-id
Create an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they works separately. To delete the specified OSPF routing process, please use the no router ospf command.
process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.
Step 3 areaarea-id nssa
Define an area as a NSSA area. To restore the NSSA area to a normal one, please use the no area NSSA command without any optional parameters. To restore the certain parameters to default values, please use the no area NSSA command with corresponding parameters.
area-id: The area ID, in the format of an IP address in dotted decimal notation or decimal value ranging from 1 to 4294967295.
Step 4 areaarea-id default-cost cost
Configure the cost of default route sent from ABR to stub or NSSA area.
area-id: The area ID, in the format of an IP address in dotted decimal notation or decimal value ranging from 1 to 4294967295.
cost: The cost value. It ranges from 1 to 16777214 and the default value is 1.
Step 5 end
Return to privileged EXEC mode.
Step 6 copy running-config startup-config
Save the settings in the configuration file.

The following example shows how to configure the cost of the default route sent to Area 1 as 10:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#area 1 nssa

Switch(config-router)#area 1 default-cost 10

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.15 Configuring Summary Route

Follow these steps to configure a summary route.

Step 1 configure

Enter global configuration mode.

Step 2 router ospf process-idCreate an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they works separately. To delete the specified OSPF routing process, please use the no router ospf command.process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.
Step 3 areaarea-id range ip-address mask [advertise] [cost cost] [not-advertise]Configure a summary route. To delete this route, please use the no area range command. By default no route is summarized.This command is only used with the ABR to summarize the route information of a certain area. The ABR only sends one summarized route of the routes in the aggregated segment to the other areas. An area can be configured with multiple summary segments, which can be aggregated by OSPF.If the no area range command is configured, the formally summarized routes will be redistributed.area-id: The area ID, in the format of an IP address in dotted decimal notation or decimal value ranging from 0 to 4294967295.ip-address: The destination of the aggregated route.mask: The network mask of the aggregated route, in the format of dotted decimal notation.advertise: Allow route aggregation of ABR broadcast.not-advertise: Suppress route aggregation of ABR broadcast.cost: The cost of the aggregated route, ranging from 1 to 16777214. The default value is the maximum one of all the aggregated routes. The cost parameter can be configured only when the advtise parameter is enabled. When configured as not-advtise, the cost parameter will be restored to the default value.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config
Save the settings in the configuration file.

The following example shows how to configure one aggregated route 100.100.0.0/16 with the cost 10 in Area 0:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#area 0 range 100.100.0.0 255.255.0.0 cost 10

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.16 Configuring Area Authentication

Follow these steps to configure the authentication type of the OSPF process.

Step 1 configure

Enter global configuration mode.

Step 2 router ospf

process-id

Create an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they work separately. To delete the specified OSPF routing process, use the no router ospf command.

process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.

Step 3 area

area-id authentication [message-digest]

Configure the authentication type of the OSPF process. The process is not authenticated by default. To restore to default value, use the no area authentication command.

area-id: The area ID, in the format of an IP address in dotted decimal notation or decimal value ranging from 0 to 4294967295.

message-digest: Configure the configuration type as MD5.

If no authentication mode is specified here, the default mode will be simple authentication.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the authentication method to MD5 in Area 0:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#area 0 authentication message-digest

Switch(config-router)#end

Switch#copy running-config startup-config

Follow these steps to configure the virtual-link.

Step 1 configure

Enter global configuration mode.

Step 2 router ospf process-idCreate an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they works separately. To delete the specified OSPF routing process, please use the no router ospf command.process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.
Step 3 area transit-area virtual-link router-id [dead-interval dead-interval] [hello-interval hello-interval] [retransmit-interval rtx-interval] [transmit-delay trans-delay]Configure the virtual-link. To delete the configured virtual-link, please use the no area virtual-link without any optional parameters.transit-area: The area ID, in the format of an IP address in dotted decimal notation or decimal value ranging from 1 to 4294967295.router-id: The ID of the neighboring router on the opposite end of the virtual link, in the format of dotted decimal notation.hello-interval: The interval of the hello packets, ranging from 1 to 65535 seconds and the default value is 10 seconds.dead-interval: The time after which the neighbor becomes invalid. It ranges from 1 to 65535 seconds and the default value is 4 times as the hello-interval.rtx-interval: The retransmission interval of the LSA, DD and LSR packets. It ranges from 1 to 65535 seconds and the default value is 5 seconds.trans-delay: The LSA transmission delay. It ranges from 1 to 65535 seconds and the default value is 1 seconds.
Step 4 endReturn to privileged EXEC mode.
Step 5 copy running-config startup-configSave the settings in the configuration file.

The following example shows how to configure a virtual-link with the transmission area as Area 1 and the ID of the neighboring router on the other endpoint as 1.1.1.1:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#area 1 virtual-link 1.1.1.1

Switch(config-router)#end

Switch#copy running-config startup-config

Follow these steps to configure the authentication type of the virtual link.

Step 1configureEnter global configuration mode.
Step 2router ospfprocess-idCreate an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they works separately. To delete the specified OSPF routing process, please use the no router ospf command.process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.
Step 3areatransit-area virtual-link router-id authentication [message-digest | null]Configure the authentication type of the virtual link. The virtual link is not authenticated by default. To restore to default value, please use the no area virtual-link authentication command.transit-area: The transition area ID in the format of an IP address in dotted decimal notation or decimal value ranging from 1 to 4294967295.router-id: The ID of the neighboring router on the other endpoint of the virtual link, in the format of dotted decimal notation.message-digest: Configure the configuration type as MD5.null: No authentication. By default it is no authentication.If no authentication mode is specified here, the default mode will be simple authentication.
Step 4endReturn to privileged EXEC mode.
Step 5copy running-config startup-configSave the settings in the configuration file.

The following example shows how to configure simple authentication as the authentication mode of a virtual-link with the transmission area as Area 2 and the ID of the neighboring router on the other endpoint as 3.3.3.3:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#area 2 virtual-link 3.3.3.3 authentication

Switch(config-router)#end

Switch#copy running-config startup-config

Follow these steps to configure the simple authentication key of virtual-link.

Step 1configureEnter global configuration mode.
Step 2router ospfprocess-idCreate an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they works separately. To delete the specified OSPF routing process, please use the no router ospf command.process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.
Step 3areatransit-area virtual-link router-id authentication-key [0|7] passwordConfigure the simple authentication key. To delete the key, please use the no area virtual-link authentication-key command.transit-area: The transition area ID in the format of an IP address in dotted decimal notation or decimal value ranging from 1 to 4294967295.router-id: The ID of the neighboring router on the other endpoint of the virtual link, in the format of dotted decimal notation.[0|7]: Key form, 0 represents plaintext, 7 represents ciphertext.password: A string from 1 to 8 alphanumeric characters or symbols. The password is case sensitive, and cannot contain question marks. By default, it is empty.
Step 4endReturn to privileged EXEC mode.
Step 5copy running-config startup-configSave the settings in the configuration file.

The following example shows how to configure the authentication mode of a virtual-link as simple authentication, with the transmission area as Area 2 and the ID of the neighboring router on the other endpoint as 3.3.3.3, and the authentication key as 123456:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#area 2 virtual-link 3.3.3.3 authentication-key 123456

Switch(config-router)#end

Switch#copy running-config startup-config

Follow these steps to configure the MD5 authentication ID and key of the virtual-link.

Step 1configureEnter global configuration mode.
Step 2router ospfprocess-idCreate an OSPF routing process and enter the router configuration mode. Each OSPF routing process is an independent instance running the OSPF protocol, and they works separately. To delete the specified OSPF routing process, please use the no router ospf command.process-id: Process ID, ranging from 1 to 65535. Sixteen processes can be created at most.
Step 3areatransit-area virtual-link router-id message-digest-key id md5 [0|7] passwordConfigure the MD5 authentication ID and key of the virtual-link. To delete the specified configuration, please use the no area virtual-link message-digest- key command.transit-area: The transition area ID in the format of an IP address in dotted decimal notation or decimal value ranging from 1 to 4294967295.router-id: The ID of the neighboring router on the other endpoint of the virtual link, in the format of dotted decimal notation.id: The key ID of the MD5, ranging from 1 to 255.[0|7]: Key form, 0 represents plaintext, 7 represents ciphertext.password: A string from 1 to 16 alphanumeric characters or symbols. The password is case sensitive, and cannot contain question marks.
Step 4endReturn to privileged EXEC mode.
Step 5copy running-config startup-configSave the settings in the configuration file.

The following example shows how to configure the authentication mode of a virtual-link as MD5 authentication, with the transmission area as Area 2 and the ID of the neighboring router on the other endpoint as 3.3.3.3, with the authentication ID as 2 and the authentication key as 123456:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#area 2 virtual-link 3.3.3.3 message-digest-key 2 md5 123456

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.21 Configuring Opaque LSA Support

Follow these steps to enable the Opaque LSA feature:

Step 1 configure

Enter global configuration mode.

Step 2 router ospf

process-id

Create an OSPF routing process and enter the router configuration mode.

Step 3 capability opaque

Enable the Opaque LSA feature. To disable this feature, use the no capability opaque command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the Opaque LSA feature:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#capability opaque

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.22 Configuring OSPF GR

Follow these steps to enable the OSPF GR feature:

Step 1 configure

Enter global configuration mode.

Step 2 router ospf

process-id

Create an OSPF routing process and enter the router configuration mode.

Step 3 graceful-restart

Enable the OSPF GR feature. Before performing a graceful restart, ensure that the GR Restarter is configured with this feature. To disable this feature, use the no graceful-restart command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the OSPF GR feature:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#graceful-restart

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.23 Configuring Graceful Restart Period

Follow these steps to configure the graceful restart period:

Step 1 configure

Enter global configuration mode.

Step 2 router ospf

process-id

Create an OSPF routing process and enter the router configuration mode.

Step 3 graceful-restart grace-period

period

Configure the graceful restart period, that is, the maximum time required for the graceful restart process. If the actual restart time exceeds this value, the graceful restart will fail. To restore the default configuration, please use the no graceful-restart grace-period command.

period: Graceful restart period, ranging from 1 to 1800 seconds, and the default value is 120.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the graceful restart period to 180 seconds:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#graceful-restart grace-period 180

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.24 Configuring GR Helper

Follow these steps to enable the GR Helper function:

Step 1 configure

Enter global configuration mode.

Step 2 router ospf

process-id

Create an OSPF routing process and enter the router configuration mode.

Step 3 graceful-restart helper

[rid]

Enable the GR Helper feature to assist the GR Restarter in its graceful restart process. To restore the default configuration, please use the no graceful-restart helper command.

rid: GR Helper is supported for the neighboring GR Restarter whose router-id is rid. If rid is not specified, GR Helper is supported for all neighboring GR Restarters by default.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure GR Helper to support graceful restart for all neighboring GR Restarters:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#graceful-restart helper

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.25 Configuring Planned-only Restart

Follow these steps to enable the GR Helper to only support planned-only restart function:

Step 1 configure

Enter global configuration mode.

Step 2 router ospf

process-id

Create an OSPF routing process and enter the router configuration mode.

Step 3 graceful-restart helper planned-only

Configure the GR Helper to only support planned-only restart function, which is disabled by default. To restore the default configuration, use the no graceful-restart helper planned-only command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the GR Helper to support planned-only restart function:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#graceful-restart helper planned-only

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.26 Configuring Strict LSA Checking

Follow these steps to configure the GR Helper to strictly check LSA:

Step 1 configure

Enter global configuration mode.

Step 2 router ospf

process-id

Create an OSPF routing process and enter the router configuration mode.

Step 3 graceful-restart helper strict-lsa-checking

Configure the GR Helper to strictly check LSA, which is disabled by default. When this function is configured, once the LSAs of the GR Restarter and the GR Helper do not match, the graceful restart will be failed. To restore the default configuration, please use the no graceful-restart helper strict-lsa-checking command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the GR Helper to strictly check LSA:

Switch#configure

Switch(config)#router ospf 1

Switch(config-router)#graceful-restart helper strict-lsa-checking

Switch(config-router)#end

Switch#copy running-config startup-config

7.2.27 Configuring Interface Cost

Follow these steps to configure the interface cost.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}
Enter interface configuration mode.

Step 3 ip ospf cost

cost

Configure the interface cost. To restore to the default value, use the no ip ospf cost command.

cost: The interface cost, ranging from 1 to 65535. The default value is calculated according to the bandwidth.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the cost of interface VLAN 2 as 10:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)# ip ospf cost 10

Switch(config)#end

Switch#copy running-config startup-config

7.2.28 Configuring IP OSPF Retransmit-Interval

Follow these steps to configure the interval to retransmit the LSA, DD and LSR packets on the specified interface.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernetport-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list }Enter interface configuration mode.
Step 3 ip ospf retransmit-interval intervalConfigure the interval to retransmit the LSA, DD and LSR packets on the specified interface.To restore to default value, please use the no ip ospf retransmit-interval command.interval: The retransmit interval, ranging from 1 to 65535 seconds. The default value is 5 seconds.
Step 4 endReturn to privileged EXEC mode.
Step 5 copy running-config startup-configSave the settings in the configuration file.

The following example shows how to configure the retransmission interval of interface VLAN 2 as 10 seconds:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ip ospf retransmit-interval 10

Switch(config)#end

Switch#copy running-config startup-config

7.2.29 Configuring IP OSPF Transmit-Delay

Follow these steps to configure the interval to retransmit the transmission delay of LSA on the specified interface.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list }

Enter interface configuration mode.

Step 3 ip ospf transmit-delay delay
Configure the transmission delay of LSA on the specified interface. To restore to default value, please use the no ip ospf transmit-delay.
delay: The LSA transmission delay, ranging from 1 to 65535 seconds. The default value is 1 second.
Step 4 end
Return to privileged EXEC mode.
Step 5 copy running-config startup-config
Save the settings in the configuration file.

The following example shows how to configure LSA transmission delay of interface VLAN 2 as 2 seconds

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)# ip ospf transmit-delay 2

Switch(config)#end

Switch#copy running-config startup-config

7.2.30 Configuring IP OSPF Priority

Follow these steps to configure the priority of the specified interface.

Step 1configureEnter global configuration mode.
Step 2interface {vlan vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernetport-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}Enter interface configuration mode.
Step 3ip ospf priority priorityConfigure the priority of the specified interface. To restore to the default value, please use the no ip ospf priority command.priority:The priority of the interface, ranging from 0 to 255 and the default value is 1. Interface with the priority 0 cannot be elected as DR or BDR.
Step 4endReturn to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the priority of the interface VLAN 2 as 1:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ip ospf priority 1

Switch(config)#end

Switch#copy running-config startup-config

7.2.31 Configuring IP OSPF Hello-Interval

Follow these steps to configure the hello intervals on the specified interface.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list }

Enter interface configuration mode.

Step 3 ip ospf hello-interval

interval

Configure the hello intervals on the specified interface. To restore to the default value, please use the no ip ospf hello-interval command.

interval: The interval of the hello packets, ranging from 1 to 65535 seconds and the default value is 10 seconds. When hello-interval is set, dead-interval will be set to 4 times it by default, but no more than 65535.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the interval of the hello packets sent on interface VLAN 2 as 20 seconds:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ip ospf hello-interval 20

Switch(config)#end

Switch#copy running-config startup-config

7.2.32 Configuring IP OSPF Dead-Interval

Follow these steps to set the number of seconds after the last device hello packet was seen before its neighbors declare the OSPF router to be down.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list }

Enter interface configuration mode.

Step 3 ip ospf dead-interval

interval

Set the number of seconds after the last device hello packet was seen before its neighbors declare the OSPF router to be down. To restore to default value, please use the no ip ospf dead-interval command.

interval: The neighbor's dead-interval, ranging from 1 to 65535 seconds and the default is 4 times the hello interval.

Step 4 end

Return to privileged EXEC mode.

Step 5: copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the neighbor's dead-interval on interface VLAN 2 as 50 seconds:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ip ospf dead-interval 50

Switch(config)#end

Switch#copy running-config startup-config

7.2.33 Configuring IP OSPF Authentication

Follow these steps to configure the authentication mode of the specified interface.

Step 1: configure

Enter global configuration mode.

Step 2: interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port}

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 ip ospf authentication [ message-digest | null ]

Configure the authentication mode of the specified interface. To restore to default value, please use the no ip ospf authentication command.

message-digest: Specify the authentication type as MD5.

null: No authentication. By default it is no authentication.

If no authentication mode is specified here, the default mode will be simple authentication.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the authentication type of interface VLAN 2 as MD5:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ip ospf authentication message-digest

Switch(config)#end

Switch#copy running-config startup-config

7.2.34 Configuring IP OSPF Authentication-Key

Follow these steps to configure the key of the simple authentication.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernetport-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list }Enter interface configuration mode.
Step 3 ip ospf authentication-key [0|7] passwordConfigure the key of the simple authentication. To cancel this configuration, please use theno ip ospf authentication-key command.[0|7]: Key form, 0 represents plaintext, 7 represents ciphertext.password: Super password, a string from 1 to 8 alphanumeric characters or symbols. Thepassword is case sensitive, and cannot contain question marks. By default, it is empty.
Step 4 endReturn to privileged EXEC mode.
Step 5 copy running-config startup-configSave the settings in the configuration file.

The following example shows how to configure the authentication mode of interface VLAN 2 as simple authentication, and the password as 123:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ip ospf authentication-key 123

Switch(config)#end

Switch#copy running-config startup-config

7.2.35 Configuring IP OSPF Message-Digest-Key

Follow these steps to configure the ID and password of the md5 authentication on the specified interface.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 ip ospf message-digest-key

id md5 [0|7] password

Configure the ID and password of the md5 authentication on the specified interface. To cancel the configuration, please use no ip ospf message-digest-key command.

id: The ID of the md5 authentication key, ranging from 1 to 255.

[0|7]: Key form, 0 represents plaintext, 7 represents ciphertext.

password: A string from 1 to 16 alphanumeric characters or symbols. The password is case sensitive, and cannot contain question marks. Key configuration is required to take effect.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure md5 authentication key ID as 1 and password as abc on interface VLAN 2:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ip ospf message-digest-key 1 md5 abc

Switch(config)#end

Switch#copy running-config startup-config

7.2.36 Configuring IP OSPF Network Type

Follow these steps to configure the network type on the specified interface.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list }

Enter interface configuration mode.

Step 3ip ospf network { broadcast | non-broadcast | point-to-multipoint | point-to-point }Configure the network type on the specified interface. To restore to default, please use the no ip ospf network command.broadcast: The broadcast network type. It is the default value.non-broadcast: The NBMA network type.point-to-multipoint: The point-to-multipoint network type.point-to-point: The point-to-point network type.
Step 4 endReturn to privileged EXEC mode.
Step 5 copy running-config startup-configSave the settings in the configuration file.

The following example shows how to configure the network type on interface VLAN 2 as broadcast:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ip ospf network broadcast

Switch(config)#end

Switch#copy running-config startup-config

7.2.37 Ignoring MTU Check

Follow these steps to ignore the MTU check in the DD exchanging process.

Step 1configureEnter global configuration mode.
Step 2interface {vlan vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernetport-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}Enter interface configuration mode.
Step 3ip ospf mtu-ignoreIgnore the MTU check in the DD exchanging process. This check is scheduled by default and the adjacency relationship will not establish if the MTUs are not matched. To restore to the default value, please use the no ip ospf mtu-ignore command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure interface VLAN 2 to ignore the MTU field check in the DD exchange process:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ip ospf mtu-ignore

Switch(config)#end

Switch#copy running-config startup-config

7.2.38 Preventing OSPF Packets

Follow these steps to prevent an interface from sending OSPF packets.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 ip ospf passive

Prevent an interface from sending OSPF packets. To restore to the default settings, please use no ip ospf passive command. The interface is allowed to send OSPF packets by default.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to prevent interface VLAN 2 from sending OSPF packets:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ip ospf passive

Switch(config)#end

Switch#copy running-config startup-config

7.2.39 Resetting OSPF Process

Follow these steps to reset the OSPF process, which will clear all the dynamic information.

Step 1 clear ip ospf {process

process-id}

Reset the OSPF process, which will clear all the dynamic information. The clear ip ospf process command will reset all the OSPF processes.

process: Clear all the OSPF processes.

process-id: The process ID, ranging from 1 to 65535.

The following example shows how to reset all the OSPF processes:

Switch#clear ip ospf process

Switch#Reset selected OSPF processes? (Y/N):n

7.2.40 Viewing OSPF Global Information

Follow these steps to view the global information of the OSPF process.

Step 1 show ip ospf

[process-id]

Display the global information of the OSPF process.

process-id: The process ID, ranging from 1 to 65535. The global information of all the OSPF processes will be displayed if no process-id is specified.

The following example shows how to view the global information of all the OSPF processes:

Switch#show ip ospf

7.2.41 Viewing OSPF LSDB

Follow these steps to view the LSDB.

Step 1 show ip ospf [

process-id] database [asbr-summary | external | network | nssa-external | router | summary]

View the LSDB information.

process-id: The process ID, ranging from 1 to 65535. The LSDBs of all processes will be displayed if no process ID is specified.

asbr-summary | external | network | nssa-external | router | summary: The LSA type.

The following example shows how to view the detailed information of router-LSA in process 1:

Switch#show ip ospf 1 database router

7.2.42 Viewing OSPF Interface

Follow these steps to view the interface information.

Step 1 show ip ospf [ process-id ] interface [ interface-name interface-number ]

View the interface information.

process-id: The process ID. The information of all the processes will be displayed if process ID is not specified.

interface-name interface-number: Specify the interface name and number to display the interface's detailed information.

The following example shows how to view the information of the interfaces in all the OSPF processes:

Switch#show ip ospf interface

7.2.43 Viewing OSPF Neighbor

Follow these steps to view the information of the OSPF neighbor.

Step 1 show ip ospf [ process-id ] neighbor [ detail | interface-name interface-number ]

View the interface information.

process-id: The process ID, ranging from 1 to 65535. The neighbors' information of all processes will be displayed if no process ID is specified.

detail: The detailed information of the neighbor.

interface-name interface-number: Specify the interface name and number to display the neighbor's detailed information on this interface.

The following example shows how to view the neighbors' detailed information in process 1.

Switch#show ip ospf 1 neighbor detail

7.2.44 Viewing OSPF ABR/ASBR Routing Table

Follow these steps to view the routing tables of the ABR/ASBR.

Step 1 show ip ospf [ process-id ] border-routers

View the routing tables of the ABR/ASBR.

process-id: The process ID, ranging from 1 to 65535. The ABR/ASBR routing tables of all processes will be displayed if no process ID is specified.

The following example shows how to view the ABR/ASBR routing tables of all the OSPF processes:

Switch#show ip ospf border-routers

7.2.45 Viewing OSPF Routing Table

Follow these steps to view the OSPF routing table.

Step 1 show ip ospf route

View the OSPF routing table.

The following example shows how to view the routing tables of OSPF:

Switch#show ip ospf route

7.2.46 Viewing OSPF GR Helper Status

Follow these steps to view the status and configuration information of the GR Helper and the reason of last exit.

Step 1 show ip ospf [ process-id ] graceful-restart helper

View the status and configuration information of the GR Helper and the reason of last exit.

process-id: The process ID, ranging from 1 to 65535.

The following example shows how to view the status and configuration information of the GR Helper and the reason of last exit:

Switch#show ip ospf graceful-restart helper

8

OSPFv3 Configurations

OSPF is an Interior Gateway Protocol (IGP) designed expressly for IP networks, supporting IP subnetting and tagging of externally derived routing information. OSPF also allows packet authentication and uses IP multicast when sending and receiving packets.

Currently, OSPF Version 2 (RFC2328) is used for the IPv4 protocol; Use OSPF Version 3 (RFC2740) for IPv6 protocol. OSPFv3 is short for OSPF Version 3 and is the OSPF routing protocol running on IPv6 (RFC5340, same as RFC2740).

8.1 Using the CLI

8.1.1 Enabling OSPFv3 Routing

Follow these steps to enable an OSPFv3 routing process and enter the router configuration mode.

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 router ospf

Enable an OSPFv3 routing process and enter the router configuration mode. To delete the specified OSPFv3 routing process, use the no ipv6 router ospf command.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable an OSPFv3 routing process:

Switch#configure

Switch(config)#ipv6 router ospf

Switch(config)#end

Switch#copy running-config startup-config

8.1.2 Configuring Router ID

Follow these steps to configure the router ID.

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 router ospf

Enable an OSPFv3 routing process and enter the router configuration mode. To delete the specified OSPFv3 routing process, use the no ipv6 router ospf command.

Step 3 router-id

router-id

Configure the router ID. The no router-id command is used to delete the configured router ID.

router-id: The router ID in the format of dotted decimal notation. 0.0.0.0 is illegal.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the router ID of OSPFv3 routing process as 1.1.1.1:

Switch#configure

Switch(config)#ipv6 router ospf

Switch(config-rtr)#router-id 1.1.1.1

Switch(config)#end

Switch#copy running-config startup-config

8.1.3 Configuring Max-Paths

Follow these steps to configure the maximum number of equal-cost multipath routes.

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 router ospf

Enable an OSPFv3 routing process and enter router configuration mode. To delete the specified OSPFv3 routing process, use the no ipv6 router ospf command.

Step 3 maximum-paths

number

Configure the maximum number of equal-cost multipath routes. To restore the default value, use the no maximum-paths command.

number: The maximum number of equal-cost multipath routes, ranging from 1 to 32. The default value is 32.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the maximum number of the equal-cost multipath routings as 2:

Switch#configure

Switch(config)#ipv6 router ospf

Switch(config-rtr)#maximum-paths 2

Switch(config)#end

Switch#copy running-config startup-config

8.1.4 Configuring ASBR

Follow these steps to configure the ASBR to redistribute the external routes from other routing protocols to the OSPFv3 domain in type-5 LSAs.

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 router ospf

Enable an OSPFv3 routing process and enter the router configuration mode. To delete the specified OSPFv3 routing process, please use the no ipv6 router ospf command.

Step 3 redistribute { connected | static | rip }

Configure the ASBR to redistribute the external routes from other routing protocols to the OSPFv3 domain in type-5 LSAs. To restore the certain optional parameters to default values, please use the no redistribute command with corresponding parameters.

connected: Specify the external route type as connected.

static: Specify the external route type as static.

rip: Specify the external route type as RIPNG.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to redistribute the RIPNG routes from the external in the OSPFv3 domain:

Switch#configure

Switch(config)#ipv6 router ospf

Switch(config-rtr)#redistribute rip

Switch(config)#end

Switch#copy running-config startup-config

8.1.5 Configuring Default-Information Originate

Follow these steps to advertise the default route as an AS-External LSA.

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 router ospf

Enable an OSPFv3 routing process and enter router configuration mode. To delete the specified OSPFv3 routing process, use the no ipv6 router ospf command.

Step 3 default-information originate [always] [metric

cost ] [metric-type type]

Advertise the default route as an AS-External LSA. To cancel the advertisement of the default route, use the no default-information originate command without any optional parameters. To restore certain parameters to default values, use the no default-information originate command with the corresponding parameters.

always: OSPFv3 will advertise the default route whether or not there is a default route in the IPv6 routing table. If this parameter is not configured, OSPFv3 will advertise the default route only when there is a default route in the IPv6 routing table.

cost: The default cost of the default route, ranging from 1 to 16777214. Its default value is 1.

type: The type of external routes, either 1 or 2. The default value is 2.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure OSPFv3 to advertise the default route regardless of whether the IPv6 routing table has a default route or not:

Switch#configure

Switch(config)#ipv6 router ospf

Switch(config-rtr)#default-information originate always

Switch(config)#end

Switch#copy running-config startup-config

8.1.6 Configuring Auto-Cost

Follow these steps to enable the auto-computing function of the interface cost and configure the reference bandwidth.

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 router ospf

Enable an OSPFv3 routing process and enter the router configuration mode. To delete the specified OSPFv3 routing process, use the no ipv6 router ospf command.

Step 3 auto-cost reference-bandwidth

bandwidth

Enable the auto computing function of the interface cost and configure the reference bandwidth. The interface cost is the ratio of the reference bandwidth to the interface bandwidth. To restore the reference bandwidth to default value, use the no auto-cost reference-bandwidth command.

bandwidth: The reference bandwidth, ranging from 1 to 4294967 Mbps. Its default value is 100Mbps.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the auto computing function of the interface cost and configure the reference bandwidth as 10000 Mbps:

Switch#configure

Switch(config)#ipv6 router ospf

Switch(config-rtr)#auto-cost reference-bandwidth 10000

Switch(config)#end

Switch#copy running-config startup-config

8.1.7 Configuring OSPFv3 Administrative Distance

Follow these steps to configure the OSPFv3 administrative distance.

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 router ospf

Enable an OSPFv3 routing process and enter the router configuration mode. To delete the specified OSPFv3 routing process, use the no ipv6 router ospf command.

Step 3 distance

administrative-distance

Configure the OSPFv3 administrative distance. To restore to the default distance, use the no distance command. The administrative distance represents the priority of the routes. The smaller administrative distance corresponds to higher priority. When different routing protocols possess the same route to the same destination, the route with the highest priority will be selected to add to the IPv6 routing table according to the administrative distance.

administrative-distance: Routing administrative distance, ranging from 1 to 254. Its default value is 110.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the OSPFV3 routing administrative distance as 100:

Switch#configure

Switch(config)#ipv6 router ospf

Switch(config-rtr)#distance 100

Switch(config)#end

Switch#copy running-config startup-config

8.1.8 Configuring OSPFv3 Distance

Follow these steps to configure the OSPFv3 distance for different types of routes.

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 router ospf

Enable an OSPFv3 routing process and enter the router configuration mode. To delete the specified OSPFv3 routing process, please use the no ipv6 router ospf command.

Step 3 distance ospf { external

distance | inter-area distance | intra-area distance }

Configure the OSPFv3 distance for different types of routes. To restore to the default distance, please use the no distance command.

external: External type 5 and type 7 routes.

inter-area: Inter-area routes.

intra-area: Intra-area routes.

distance: Distance for different types of routes, ranging from 1 to 254. Its default value is 110.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the OSPFV3 routing distance of the external routers as 100:

Switch#configure

Switch(config)#ipv6 router ospf

Switch(config-rtr)#distance ospf external 100

Switch(config)#end

Switch#copy running-config startup-config

8.1.9 Configuring Computing Delay and Interval

Follow these steps to configure the computing delay and interval of the SPF.

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 router ospf

Enable an OSPFv3 routing process and enter the router configuration mode. To delete the specified OSPFv3 routing process, use the no ipv6 router ospf command.

Step 3: timers throttle spf

spf-delay spf-holdtime spf-max-holdtime

Configure the computing delay and interval of the SPF, thus preventing the consumption of the CPU and memory caused by frequent SPF computing. To restore to the default value, use the no timers throttle spf command.

spf-delay: The delay time of the SPF computing, ranging from 1 to 600000 milliseconds. The default value is 0 milliseconds.

spf-holdtime: The minimum interval between two SPF computations, ranging from 1 to 600000 milliseconds. The default value is 50 milliseconds.

spf-max-holdtime: The maximum interval between two SPF computations, ranging from 1 to 600000 milliseconds. The default value is 5000 milliseconds.

Step 4: end

Return to privileged EXEC mode.

Step 5: copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the SPF computing delay as 10 seconds and the interval between 10 and 50 seconds:

Switch#configure

Switch(config)#ipv6 router ospf

Switch(config-rtr)#timers throttle spf 10000 10000 50000

Switch(config)#end

Switch#copy running-config startup-config

8.1.10 Configuring OSPFv3 LSA Reception Interval

Follow these steps to configure the time interval for OSPFv3 LSA reception.

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 router ospf

Enable an OSPFv3 routing process and enter the router configuration mode. To delete the specified OSPFv3 routing process, use the no ipv6 router ospf command.

Step 3 timers lsa arrival

delay-time

Configure the time interval for OSPFv3 LSA reception. To restore the default value, use the no timers lsa arrival command.

delay-time: The time interval for OSPFv3 LSA reception, ranging from 0 to 600000 milliseconds. The default value is 1000 milliseconds.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the time interval for OSPFv3 LSA reception as 10 seconds:

Switch#configure

Switch(config)#ipv6 router ospf

Switch(config-rtr)# timers Isa arrival 10000

Switch(config)#end

Switch#copy running-config startup-config

8.1.11 Defining Stub Area

Follow these steps to define an area as a stub area.

Step 1configureEnter global configuration mode.
Step 2ipv6 router ospfEnable an OSPFv3 routing process and enter the router configuration mode. To delete the specified OSPFv3 routing process, please use the no ipv6 router ospf command.
Step 3areaarea-id stub [no-summary]Define an area as a stub area. To restore the stub area to a normal one, please use the no area stub command. To restore the certain parameters to default values, please use the no area stub command with corresponding parameters.area-id:The area ID, in the format of an IP address in dotted decimal notation or decimal value ranging from 1 to 4294967295.no-summary:Configure the stub area as a totally stub area, where the ABR advertises neither the destinations in other areas nor the external routes. The stub area is not a totally stub area by default.
Step 4endReturn to privileged EXEC mode.
Step 5copy running-config startup-configSave the settings in the configuration file.
The following example shows how to configure the area 1 as a totally stub area:Switch#configureSwitch(config)#ipv6 router ospfSwitch(config-rtr)#area 1 stub no-summarySwitch(config)#endSwitch#copy running-config startup-config

8.1.12 Defining NSSA Area

Follow these steps to define an area as a NSSA area.

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 router ospf

Enable an OSPFv3 routing process and enter the router configuration mode. To delete the specified OSPFv3 routing process, please use the no ipv6 router ospf command.

Step 3 area

area-id nssa [no-summary]

Define an area as a NSSA area. To restore the NSSA area to a normal one, use the no area nssa command without any optional parameters. To restore certain parameters to default values, use the no area nssa command with corresponding parameters.

area-id: The area ID, in the format of an IP address in dotted decimal notation or decimal value ranging from 1 to 4294967295.

no-summary: Configure the NSSA area as a totally NSSA area, where the ABR advertises neither the destinations in other areas nor the external routes. The NSSA area is not a totally NSSA area by default.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure Area 1 as a totally NSSA area:

Switch#configure

Switch(config)#ipv6 router ospf

Switch(config-rtr)#area 1 nssa no-summary

Switch(config)#end

Switch#copy running-config startup-config

8.1.13 Configuring Summary Route

Follow these steps to configure a summary route

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 router ospf

Enable an OSPFv3 routing process and enter the router configuration mode. To delete the specified OSPFv3 routing process, please use the no ipv6 router ospf command.

Step 3

area area-id range ipv6-address/mask-num [advertise | cost cost | not-advertise]

Configure a summary route. To delete this route, please use the no area range command. By default no route is summarized.

This command is only used with the ABR to summarize the route information of a certain area. The ABR only sends one summarized route of the routes in the aggregated segment to the other areas. An area can be configured with multiple summary segments, which can be aggregated by OSPFv3.

If the no area range command is configured, the formally summarized routes will be redistributed.

area-id: The area ID, in the format of an IP address in dotted decimal notation or decimal value ranging from 0 to 4294967295.

ipv6-address: The destination of the aggregated route.

mask-num: The network mask for aggregated route, in the format of mask bits.

advertise: Allow route aggregation of ABR broadcast.

not-advertise: Suppress route aggregation of ABR broadcast.

cost: The cost of the aggregated route, ranging from 1 to 16777214. The default value is the maximum one of all the aggregated routes. The cost parameter can be configured only when the advertise parameter is enabled. When configured as not-advertise, the cost parameter will be restored to the default value.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure one aggregated route 2001::1/64 with the cost 10 in the Area 0:

Switch#configure

Switch(config)#ipv6 router ospf

Switch(config-rtr)#area 0 range 2001::1/64 cost 10

Switch(config)#end

Switch#copy running-config startup-config

8.1.14 Assigning Interfaces

Follow these steps to assign the interface to different regions.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port
| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}
Enter interface configuration mode.
Step 3 ipv6 ospf areaarea-id [instance-id instance-id]

Assign the interface to different regions. By default, the interface does not belong to any area. Only the interface attached to a certain area can receive OSPFv3 packets normally. To restore to the default value, use the no ipv6 ospf area command.

area-id: The area ID, in the format of an IP address in dotted decimal notation or decimal value ranging from 0 to 4294967295.

instance-id: The instance ID, ranging from 0 to 255. OSPFv3 supports running multiple instances on a single link, using the optional parameter instance-id as the instance identifier. The instance number only affects the reception of OSPFv3 messages. By default, this parameter value is 0. To restore the default value, use the no ipv6 ospf area area-id instance-id command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to assign interface VLAN 2 to area 10:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ipv6 ospf area 10

Switch(config)#end

Switch#copy running-config startup-config

8.1.15 Configuring Interface Cost

Follow these steps to configure the interface cost.

Step 1 configure

Enter global configuration mode.

Step 2interface {vlan vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernetport-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list }Enter interface configuration mode.
Step 3 ipv6 ospf cost costConfigure the interface cost. To restore to the default value, please use the no ipv6 ospf cost command.cost: The interface cost, ranging from 1 to 65535. The default value is calculated according to the bandwidth.
Step 4 endReturn to privileged EXEC mode.
Step 5 copy running-config startup-configSave the settings in the configuration file.
The following example shows how to configure the cost of interface VLAN 2 as 10:Switch#configureSwitch(config)#interface vlan 2Switch(config-if)#ipv6 ospf cost 10Switch(config)#endSwitch#copy running-config startup-config

8.1.16 Configuring IPv6 OSPF Retransmit-Interval

Follow these steps to configure the interval to retransmit the LSA, DD and LSR packets on the specified interface.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list }

Enter interface configuration mode.

Step 3 ipv6 ospf retransmit-intervalinterval
Configure the interval to retransmit the LSA, DD and LSR packets on the specified interface. To restore to default value, please use the no ipv6 ospf retransmit-interval command.
interval: The retransmit interval, ranging from 1 to 65535 seconds. The default value is 5 seconds.
Step 4 end
Return to privileged EXEC mode.
Step 5 copy running-config startup-config
Save the settings in the configuration file.

The following example shows how to configure the retransmission interval of interface VLAN 2 as 10 seconds:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ipv6 ospf retransmit-interval 10

Switch(config)#end

Switch#copy running-config startup-config

8.1.17 Configuring IPv6 OSPF Transmit-Delay

Follow these steps to configure the interval to retransmit the transmission delay of LSA on the specified interface.

Step 1configureEnter global configuration mode.
Step 2interface {vlan vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernetport-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}Enter interface configuration mode.
Step 3ipv6 ospf transmit-delay delayConfigure the transmission delay of LSA on the specified interface. To restore to default value, please use the no ipv6 ospf transmit-delay.delay: The LSA transmission delay, ranging from 1 to 3600 seconds. The default value is 1 second.
Step 4endReturn to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure LSA transmission delay of interface VLAN 2 as 2 seconds.

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)# ipv6 ospf transmit-delay 2

Switch(config)#end

Switch#copy running-config startup-config

8.1.18 Configuring IPv6 OSPF Priority

Follow these steps to configure the priority of the specified interface.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 ipv6 ospf priority

priority

Configure the priority of the specified interface. To restore to the default value, please use the no ipv6 ospf priority command.

priority: The priority of the interface, ranging from 0 to 255 and the default value is 1. Interface with the priority 0 cannot be elected as DR or BDR.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the priority of the interface VLAN 2 as 10:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ipv6 ospf priority 10

Switch(config)#end

Switch#copy running-config startup-config

8.1.19 Configuring IPv6 OSPF Hello-Interval

Follow these steps to configure the hello intervals on the specified interface.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 ipv6 ospf hello-interval

interval

Configure the hello intervals on the specified interface. To restore to the default value, please use the no ipv6 ospf hello-interval command.

interval: The interval of the hello packets, ranging from 1 to 65535 seconds and the default value is 10 seconds. When hello-interval is set, dead-interval will be set to 4 times it by default, but no more than 65535.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the interval of the hello packets sent on interface VLAN 2 as 20 seconds:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ipv6 ospf hello-interval 20

Switch(config)#end

Switch#copy running-config startup-config

8.1.20 Configuring IPv6 OSPF Dead-Interval

Follow these steps to set the number of seconds after the last device hello packet was seen before its neighbors declare the OSPFv3 router to be down.

Step 1 configure

Enter global configuration mode.

Step 2interface {vlan vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernetport-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list }Enter interface configuration mode.
Step 3 ipv6 ospf dead-interval intervalSet the number of seconds after the last device hello packet was seen before its neighborsdeclare the OSPFv3 router to be down. To restore to default value, please use the no ipv6ospf dead-interval command.interval: The neighbor's dead-interval, ranging from 1 to 65535 seconds and the default is 4times the hello interval.
Step 4 endReturn to privileged EXEC mode.
Step 5 copy running-config startup-configSave the settings in the configuration file.
The following example shows how to configure the neighbor's dead-interval on interfaceVLAN 2 as 50 seconds:Switch#configureSwitch(config)#interface vlan 2Switch(config-if)#ipv6 ospf dead-interval 50Switch(config)#endSwitch#copy running-config startup-config

8.1.21 Configuring IPv6 OSPF Network Type

Follow these steps to configure the network type on the specified interface.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}
Enter interface configuration mode.

Step 3 ipv6 ospf network { broadcast | point-to-point }

Configure the network type on the specified interface. To restore to default, use the no ipv6 ospf network command.

broadcast: The broadcast network type. It is the default value.

point-to-point: The point-to-point network type.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the network type on interface VLAN 2 as broadcast:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ipv6 ospf network broadcast

Switch(config)#end

Switch#copy running-config startup-config

8.1.22 Ignoring MTU Check

Follow these steps to ignore the MTU check in the DD exchanging process.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 ipv6 ospf mtu-ignore

Ignore the MTU check in the DD exchanging process. This check is scheduled by default and the adjacency relationship will not establish if the MTUs are not matched. To restore to the default value, please use the no ipv6 ospf mtu-ignore command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure interface VLAN 2 to ignore the MTU field check in the DD exchange process:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ipv6 ospf mtu-ignore

Switch(config)#end

Switch#copy running-config startup-config

8.1.23 Preventing OSPFv3 Packets

Follow these steps to prevent an interface from sending OSPFv3 packets.

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 ipv6 ospf passive

Prevent an interface from sending OSPFv3 packets. To restore to the default settings, use the no ipv6 ospf passive command. By default, the interface is allowed to send OSPFv3 packets.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to prevent interface VLAN 2 from sending OSPFv3 packets:

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ipv6 ospf passive

Switch(config)#end

Switch#copy running-config startup-config

8.1.24 Resetting OSPFv3 Process

Follow these steps to reset the OSPFv3 process, which will clear all the dynamic information.

Step 1 clear ipv6 ospf

{process | interface}

Reset the OSPFv3 process, which will clear all the dynamic information. The clear ipv6 ospf process command will reset the OSPFv3 process. The clear ipv6 ospf interface command will reset the configuration of the interface in the OSPFv3 process.

Step 2: copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to reset the OSPFv3 process:

Switch#clear ipv6 ospf process

Switch#Reset OSPFv3 process? (Y/N):y

Switch#copy running-config startup-config

8.1.25 Viewing OSPFv3 Global Information

Follow these steps to view the global information of the OSPFv3 process.

Step 1: show ipv6 ospf

Display the global information of the OSPFv3 process.

The following example shows how to view the global information of the OSPFv3 process:

Switch#show ipv6 ospf

8.1.26 Viewing OSPFv3 LSDB

Follow these steps to view the LSDB.

Step 1: show ipv6 ospf database

Display the LSDB.

The following example shows how to view the LSDB in OSPFv3 process:

Switch#show ipv6 ospf database

8.1.27 Viewing OSPFv3 Interface

Follow these steps to view the interface information.

Step 1: show ipv6 ospf interface

Display the interface information.

The following example shows how to view the information of the interfaces in the OSPFv3 process:

Switch#show ip ospf interface

8.1.28 Viewing OSPFv3 Neighbor

Follow these steps to view the information of the OSPFv3 neighbor.

Step 1: show ipv6 ospf neighbor

Display the information of the OSPFv3 neighbor.

The following example shows how to view the neighbors' detailed information in OSPFv3 process:

Switch#show ipv6 ospf neighbor

8.1.29 Viewing OSPFv3 ABR/ASBR Routing Table

Follow these steps to view the routing table of the ABR/ASBR.

Step 1 show ipv6 ospf border-routers

Display the routing tables of the ABR/ASBR.

The following example shows how to view the ABR/ASBR routing table of the OSPFv3 process:

Switch#show ipv6 ospf border-routers

8.1.30 Viewing OSPFv3 Routing Table

Follow these steps to view the OSPFv3 routing table.

Step 1 show ipv6 ospf rib

Display the routing tables of the ABR/ASBR.

The following example shows how to view the routing table of OSPFv3 process:

Switch#show ipv6 ospf rib

9

BFD Configurations

TP-LINK Omada Pro S5500-24GP4F - BFD Configurations - 1

Note:

BFD is only available on Omada Pro L3 Stackable Switches.

Bidirectional Forwarding Detection (BFD) is a unified network detection mechanism used for rapidly detecting and monitoring the forwarding connectivity status of links or IP routes in a network.

In order to minimize the impact of device failures on business operations and enhance network reliability, network devices need to promptly detect communication failures with neighboring devices to take timely action and ensure uninterrupted services. In existing networks, some links are often monitored for faults through hardware detection signals such as SDH alarms; however, not all mediums can provide hardware detection. In such cases, applications rely on the upper-layer protocol's own Hello message mechanism for fault detection. The fault detection time of upper-layer protocols typically exceeds 1 second, which is intolerable for certain applications. In L3 networks, the Hello message detection mechanism cannot detect faults for all routes, such as static routes, posing challenges in diagnosing faults in interconnection between systems.

BFD facilitates rapid detection and monitoring of forwarding connectivity status for links or IP routes in a network, thereby improving network performance. By swiftly identifying communication failures between neighboring systems, users can establish backup channels promptly for communication recovery, ensuring network reliability.

9.1 Using the CLI

9.1.1 Creating BFD-template

Follow these steps to create a BFD template:

Step 1 configure

Enter global configuration mode.

Step 2 bfd-template

template

Create a BFD template. To delete the BFD template, please use the no bfd-template command.

template: Template name, the value range is 1 to 32 characters.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to create a BFD template named b1:

Switch#configure

Switch(config)#bfd-template b1

Switch(config)#end

Switch#copy running-config startup-config

9.1.2 Configuring Detect-multiplier

Follow these steps to create a detect-multiplier:

Step 1 configure

Enter global configuration mode.

Step 2 bfd-template

template

Enter the BFD template mode

Step 3 detect-multiplier

multiplier

Specify the detect-multiplier of the BFD template. To restore the detect-multiplier of the BFD template to the default, use the no detect-multiplier command.

multiplier: The detect-multiplier of the BFD template. The value range is an integer between 3 and 50, and the default value is 3.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the detect-multiplier of BFD template b1 to 10:

Switch#configure

Switch(config)#bfd-template b1

Switch(config-bfd)#detect-multiplier 10

Switch(config)#end

Switch#copy running-config startup-config

9.1.3 Configuring Receive Interval

Follow these steps to configure the receive interval for BFD packets:

Step 1 configure

Enter global configuration mode.

Step 2 bfd-template

template

Enter the BFD template mode

Step 3 receive-interval

interval

Configure the receive interval for BFD packets. To restore the default value, please use the no receive-interval command

interval: The receive interval for BFD packets. The value range is an integer between 100 to 1000 milliseconds, and the default value is 300.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the receive interval of BFD template b1 to 500 milliseconds:

Switch#configure

Switch(config)#bfd-template b1

Switch(config-bfd)#receive-interval 500

Switch(config)#end

Switch#copy running-config startup-config

9.1.4 Configuring Transmit Interval

Follow these steps to configure the transmit interval for BFD packets:

Step 1 configure

Enter global configuration mode.

Step 2 bfd-template

template

Enter the BFD template mode

Step 3 transmit-interval interval
Configure the transmit interval for BFD packets. To restore the default value, please use the no transmit-interval command
interval: The transmit interval for BFD packets. The value range is an integer between 100 to 1000 milliseconds, and the default value is 300.
Step 4 end
Return to privileged EXEC mode.
Step 5 copy running-config startup-config
Save the settings in the configuration file.

The following example shows how to configure the transmit interval of BFD template b1 to 500 milliseconds:

Switch#configure

Switch(config)#bfd-template b1

Switch(config-bfd)#transmit-interval 500

Switch(config)#end

Switch#copy running-config startup-config

9.1.5 Disabling BFD Session Detection

Follow these steps to disable BFD session detection:

Step 1configureEnter global configuration mode.
Step 2bfd-template templateEnter the BFD template mode
Step 3shutdownDisable BFD session detection (enabled by default) and put it into AdminDown state. To enable the session, please use thenoshutdowncommand
Step 4endReturn to privileged EXEC mode.
Step 5copy running-config startup-configSave the settings in the configuration file.

The following example shows how to disable the BFD session detection of BFD template b1:

Switch#configure

Switch(config)#bfd-template b1

Switch(config-bfd)#shutdown

Switch(config)#end

Switch#copy running-config startup-config

9.1.6 Enabling Passive Mode

Follow these steps to enable the passive mode of the BFD session:

Step 1 configure

Enter global configuration mode.

Step 2 bfd-template

template

Enter the BFD template mode

Step 3 passive-mode

Enable the passive mode of the BFD session (disabled by default). When it is enabled, the local BFD will not actively send BFD packets. To disable the passive mode of the BFD session, use the no passive-mode command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the passive mode of BFD template b1:

Switch#configure

Switch(config)#bfd-template b1

Switch(config-bfd)#passive mode

Switch(config)#end

Switch#copy running-config startup-config

9.1.7 Enabling OSPF BFD

Follow these steps to enable the BFD feature on a specific OSPF interface:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}
Enter interface configuration mode.

Step 3 ip ospf bfd

Enable the BFD feature on a specific OSPF interface (disabled by default). When it is enabled, the default BFD session parameters are used. To disable BFD feature on the interface, please use the no ip ospf bfd command

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable BFD on interface vlan 10:

Switch#configure

Switch(config)#interface vlan 10

Switch(config-if)#ip ospf bfd

Switch(config)#end

Switch#copy running-config startup-config

The following example shows how to enable BFD on interface GE1/0/1:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#no switchport

Switch(config-if)#ip ospf bfd

Switch(config)#end

Switch#copy running-config startup-config

9.1.8 Binding BFD Template to OSPF-enabled Interface

Follow these steps to bind a BFD template to a specific interface with OSPF enabled:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}
Enter interface configuration mode.
Step 3 ip ospf bfd templatetemplate

Bind a BFD template to a specific interface with OSPF enabled. The BFD template to be bound must exist. To cancel the binding and restore the BFD session parameters to the default values, use the no ip ospf bfd template command. By default, no BFD template is bound to a specific interface with OSPF enabled.

template: Template name. It should be a configured BFD template.

Step 4 endReturn to privileged EXEC mode.
Step 5 copy running-config startup-config
Save the settings in the configuration file.

The following example shows how to create BFD template b1, set the minimum sending interval to 400 ms, the minimum receiving interval to 400 ms, and the local detection multiplier to 4, enable BFD on interface vlan 10, and bind BFD template b1:

Switch#configure

Switch(config)#bfd-template b1

Switch(config-bfd)#detect-multiplier 4

Switch(config-bfd)#receive-interval 400

Switch(config-bfd)#transmit-interval 400

Switch(config-bfd)#exit

Switch(config)#interface vlan 10

Switch(config-if)#ip ospf bfd

Switch(config-if)#ip ospf bfd template b1

9.1.9 Enabling OSPFv3 BFD

Follow these steps to enable the BFD feature on a specific OSPFv3 interface:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}
Enter interface configuration mode.

Step 3 ipv6 ospf bfd

Enable the BFD feature on a specific OSPFv3 interface (disabled by default). When it is enabled, the default BFD session parameters are used. To disable BFD feature on the interface, please use the no ipv6 ospf bfd command

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable BFD on interface vlan 10:

Switch#configure

Switch(config)#interface vlan 10

Switch(config-if)#ipv6 ospf bfd

Switch(config)#end

Switch#copy running-config startup-config

The following example shows how to enable BFD on interface GE1/0/1:

Switch#configure

Switch(config)# interface gigabitEthernet 1/0/1

Switch(config-if)#no switchport

Switch(config-if)#ip ospfv6 bfd

Switch(config)#end

Switch#copy running-config startup-config

9.1.10 Binding BFD Template to OSPFv3-enabled Interface

Follow these steps to bind a BFD template to a specific interface with OSPFv3 enabled:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernetport-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}Enter interface configuration mode.
Step 3 ipv6 ospf bfd templatetemplateBind a BFD template to a specific interface with OSPF enabled. The BFD template to bebound must exist. To cancel the binding and restore the BFD session parameters to thedefault values, please use theno ipv6 ospf bfd templatecommand. By default, no BFDtemplate is bound to a specific interface with OSPF enabled.template: Template name. It should be configured BFD template.
Step 4 endReturn to privileged EXEC mode.
Step 5copy running-config startup-configSave the settings in the configuration file.

The following example shows how to create BFD template b1, set the minimum sending interval to 400 ms, the minimum receiving interval to 400 ms, and the local detection multiplier to 4, enable BFD on interface vlan 10, and bind BFD template b1:

Switch#configure

Switch(config)#bfd-template b1

Switch(config-bfd)#detect-multiplier 4

Switch(config-bfd)#receive-interval 400

Switch(config-bfd)#transmit-interval 400

Switch(config-bfd)#exit

Switch(config)#interface vlan 10

Switch(config-if)#ip ospfv6 bfd

Switch(config-if)#ip ospfv6 bfd template b1

9.1.11 Configuring BFD on IS-IS-enabled Port

Follow these steps to configure BFD or bind a BFD template on a specific interface with IS-IS enabled:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}
Enter interface configuration mode.
Step 3 isis bfd [template]

Configure BFD features or bind a BFD template on a specific interface with IS-IS enabled. The BFD template to be bound must exist. To disable the BFD features on the interface or cancel the binding to restore the BFD session parameters to default values, please use the no isis bfd command. By default, the BFD feature is disabled on a specific interface with IS-IS enabled.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to create a BFD template b1, set the minimum sending interval to 400 ms, the minimum receiving interval to 400 ms, and the local detection multiplier to 4, enable BFD on interface vlan 10, and bind BFD template b1 to the interface:

Switch#configure

Switch(config)#bfd-template b1

Switch(config-bfd)#detect-multiplier 4

Switch(config-bfd)#receive-interval 400

Switch(config-bfd)#transmit-interval 400

Switch(config-bfd)#exit

Switch(config)#interface vlan 10

Switch(config-if)#ipv6 enable

Switch(config-if)#isis bfd

Switch(config-if)#isis bfd b1

Switch(config)#end

9.1.12 Viewing BFD Counters

Follow these steps to view the statistics of BFD sessions:

Step 1 show bfd counters

Display the statistics of BFD sessions (such as the number of sent and received packets).

The following example shows how to view the statistics of BFD sessions:

Switch#show bfd counters

9.1.13 Viewing BFD Info

Follow these steps to view the BFD information:

Step 1 show bfd neighbors

show bfd neighbors details show bfd neighbors ipv4 [ip]

Display the information of BFD sessions. The details command is used to display the detailed information. The ipv4 command is used to display the neighbor information of a BFD session.

ip:IPv4 address.

The following example shows how to view the neighbor information of 192.168.0.100:

Switch#show bfd neighbors ipv4 192.168.0.100

10 BGP Configurations

TP-LINK Omada Pro S5500-24GP4F - BGP Configurations - 1

Note:

BGP is only available on Omada Pro L3 Stackable Switches.

Border Gateway Protocol (BGP) is a distance vector routing protocol that enables routing reachability between Autonomous Systems (AS) and selects the best route.

BGP establishes a unique unicast-based connection for each BGP neighbor. To enhance the reliability of peer connections, BGP uses TCP (port 179) as the underlying transmission mechanism. Since tasks like acknowledgment, retransmission, and sequencing are handled by the TCP layer, the session maintenance and update mechanisms of BGP are greatly simplified. As BGP operates over TCP, a separate point-to-point session needs to be established for each peer.

Each BGP node passes routes from the routing table via downstream neighbors. BGP nodes perform route calculations based on the routes they advertise and pass the calculated results to upstream neighbors, so it's the primary task for routing BGP routes to successfully establish BGP neighbors.

The three earlier versions are BGP-1, BGP-2, and BGP-3, which are mainly used to exchange reachable routing information between ASs, build inter-AS propagation paths, prevent routing loops, and apply some routing policies at the AS level. The current version is BGP-4.

10.1 Using the CLI

10.1.1 Enabling BGP Globally

Follow these steps to enable the BGP function globally:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

no router bgp as-number

Enable the BGP function and enter the Router BGP configuration mode. To disable BGP and clear BGP instances, please use the no router bgp command.

as-number: BGP AS number.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the BGP function on the switch:

Switch#configure

Switch(config)#router bgp 100

Switch(config)#end

Switch#copy running-config startup-config

10.1.2 Creating Aggregate Route

Follow these steps to create an aggregate route in the BGP routing table:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 aggregate-address

ipv4-address ipv4-mask [as-set | summary-only]

no aggregate-address ipv4-address ipv4-mask

Create an aggregate route in the BGP routing table. To delete an aggregate route in the BGP routing table, please use the no aggregate-address command.

ipv4-address: Specifies the IPv4 address of the aggregated route

ipv4-mask: The network mask of the aggregated route

as-set Specifies the generation of routes with AS-SET

summary-only: Neighbors will not learn the aggregated source detailed routes

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to create an aggregate route. The path advertised by this route is an AS set segment that contains all aggregate path information:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#aggregate-address 1.1.1.0 255.255.255.0 as-set

Switch(config)#end

Switch#copy running-config startup-config

10.1.3 Configuring BGP Management Distance

Follow these steps to configure the BGP management distance:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 distance bgp

external-distance internal-distance local-distance

Specify the management distance.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the BGP management distance:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#distance bgp 120 100 100

Switch(config)#end

Switch#copy running-config startup-config

10.1.4 Configuring Load-balancing Path

Follow these steps to configure the number of paths for BGP to perform load balancing:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 maximum-paths

path-number [ibgp]

Set the number of paths for BGP to perform load balancing.

path-number: Specifies the number of paths

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the number of load-balanced paths to 12 when the next-hop neighbors of multiple paths are all iBGP:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)# maximum-paths 12 ibgp

Switch(config)#end

Switch#copy running-config startup-config

10.1.5 Configuring BGP Network

Follow these steps to configure the network for BGP:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 network

ipv4-address [mask] [ipv4-mask] [backdoor]

no networkipv4-address [mask] [ipv4-mask]

Configure the network routing prefix. To restore the default value, please use the no network command.

ipv4-address: IPv4 address to be announced

ipv4-mask: IPv4 mask to be announced

backdoor: Declare as backdoor link and change ebgp route to ibgp route (advanced BGP feature)

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the LSP refresh interval to 10s:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#network 1.1.1.1 mask 255.255.255.0 backdoor

Switch(config)#end

Switch#copy running-config startup-config

10.1.6 Enabling Route Redistribution

Follow these steps to enable the route redistribution feature:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 redistribute { connected | static | rip | isis | ospf

instance-id } [ metric cost ]

no redistribute { connected | static | rip | isis | ospf instance-id }

Enable the route redistribution feature to allow routing information of other routing protocols to be published to BGP. The no command without optional parameters can cancel external route redistribution, and the no command with optional parameters can restore the optional parameters to their default values.

connected | static | rip | ospf: Select the source routing protocol. Differentiated metrics can be defined when the routing information learned by the routing protocol is published to BGP.

cost: Configure the metric for redistributing routes. The valid value is from 0 to 4294967295. This parameter is optional and defaults to the value specified by the default-metric command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to republish RIP routing information to BGP:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#redistribute rip

Switch(config)#end

Switch#copy running-config startup-config

10.1.7 Configuring Timers

Follow these steps to configure the interval for sending keepalive messages and the neighbor hold time:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 timers bgp

keepalive hold

no timers bgp

Configure the interval for sending keepalive messages and the neighbor hold time. The no command is used to cancel the configuration.

keepalive: The interval between for sending keepalive messages between neighbors, ranging from 1-65535 seconds.

hold: Neighbor hold time, ranging from 1-65535 seconds.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the keepalive message sending interval to 10 seconds and the hold time to 30 seconds:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#timers bgp 10 30

Switch(config)#end

Switch#copy running-config startup-config

10.1.8 Allowing MED Comparison

Follow these steps to allow the comparison of MED attribute values of routing paths from different AS neighbors:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp always-compare-med

no bgp always-compare-med

Allow the comparison of MED attribute values of routing paths from different AS neighbors.

To restore the default value, please use the no bgp always-compare-med command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to allow the comparison of MED attribute values of routing paths from different AS neighbors:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp always-compare-med

Switch(config)#end

Switch#copy running-config startup-config

10.1.9 Configuring Route from Confederation Neighbors in Best Path Selection

Follow these steps to configure BGP routing to use as-path information for routes obtained from confederation neighbors:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp bestpath as-path confed

no bgp bestpath as-path confed

Configure BGP routing to use as-path information for routes obtained from confederation neighbors. To cancel this configuration, please use the no bgp bestpath as-path confed command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure BGP routing to use as-path information for routes obtained from confederation neighbors:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp bestpath as-path confed

Switch(config)#end

Switch#copy running-config startup-config

10.1.10 Ignoring AS Path Information in Best Path Selection

Follow these steps to configure BGP to ignore AS path information when selecting routes:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp bestpath as-path ignore

no bgp bestpath as-path ignore

Configure BGP to ignore AS path information when selecting routes. To cancel this configuration, use the no bgp bestpath as-path ignore command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure BGP to ignore AS path information when selecting routes:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp bestpath as-path ignore

Switch(config)#end

Switch#copy running-config startup-config

10.1.11 Configuring Multipath in Best Path Selection

Follow these steps to configure the BGP multipath decision process to consider paths with the same AS_PATH length:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp bestpath as-path multipath-relax

no bgp bestpath as-path multipath-relax

Configure the BGP multipath decision process to consider paths with the same AS_PATH length. If not configured, the entire AS_PATH must match the multipath calculation. To cancel this configuration, use the no bgp bestpath as-path multipath-relax command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the BGP multipath decision process to consider paths with the same AS_PATH length:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp bestpath as-path multipath-relax

Switch(config)#end

Switch#copy running-config startup-config

10.1.12 Enabling Router ID Comparison in Best Path Selection

Follow these steps to enable the router ID information comparison when selecting EBGP routes:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp bestpath compare-routerid

no bgp bestpath compare-routerid

Enable the router ID information comparison when selecting EBGP routes. To disable this configuration, please use the no bgp bestpath compare-routerid command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the router ID information comparison when selecting EBGP routes:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp bestpath as-path compare-routerid

Switch(config)#end

Switch#copy running-config startup-config

10.1.13 Allowing MED Comparison between BGP Confederations in Best Path Selection

Follow these steps to allow MED comparison between BGP confederation paths:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp bestpath med confed

no bgp bestpath med confed

Allow MED comparison between BGP confederation paths. To disable this configuration, use the no bgp bestpath med confed command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the router ID information comparison when selecting EBGP routes:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp bestpath med confed

Switch(config)#end

Switch#copy running-config startup-config

10.1.14 Configuring MED Missing-as-worst

Follow these steps to configure BGP to regard the missed MED as the worst:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp bestpath med missing-as-worst

no bgp bestpath med missing-as-worst

Allow MED comparison between BGP confederation paths. To disable this configuration, please use the no bgp bestpath med missing-as-worst command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure BGP to regard the missed MED as the worst:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp bestpath med missing-as-worst

Switch(config)#end

Switch#copy running-config startup-config

10.1.15 Configuring Client-to-client Reflection

Follow these steps to configure the client-to-client route reflection:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp client-to-client reflection

no bgp client-to-client reflection

Configure the client-to-client route reflection. To disable this configuration, please use the no bgp client-to-client reflection command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the client-to-client route reflection:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp client-to-client reflection

Switch(config)#end

Switch#copy running-config startup-config

10.1.16 Configuring Cluster ID

Follow these steps to configure the cluster ID of the route reflector:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp cluster-id

ip-address

no bgp cluster-id

Configure the cluster ID of the route reflector. To disable this configuration, use the no bgp cluster-id command.

ip-address: IP address.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the reflector's cluster ID to be 1.1.1.1:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp cluster-id 1.1.1.1

Switch(config)#end

Switch#copy running-config startup-config

10.1.17 Configuring Confederation ID

Follow these steps to configure the confederation ID:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp confederation identifier

as

no bgp confederation identifier

Configure the confederation ID. To disable this configuration, use the no bgp confederation identifier command.

as: The confederation ID of the route reflector, ranging from 1 to 4294967295.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the confederation ID to 1:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp confederation identifier 1

Switch(config)#end

Switch#copy running-config startup-config

10.1.18 Configuring Confederation Peers

Follow these steps to configure the confederation sub-AS:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp as-numberEnable the BGP function and enter the Router BGP configuration mode.
Step 3 bgp confederation peers asno bgp confederation peersConfigure a sub-AS belonging to the confederation. To disable this configuration, please use the no bgp confederation peers command.as: The sub-AS number of the confederation, ranging from 1 to 4294967295.
Step 4 endReturn to privileged EXEC mode.
Step 5 copy running-config startup-configSave the settings in the configuration file.

The following example shows how to configure the sub-AS belonging to the confederation to 1:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp confederation peers 1

Switch(config)#end

Switch#copy running-config startup-config

10.1.19 Configuring Route Dampening

Follow these steps to configure route dampening:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp dampening

Configure route dampening. To disable this configuration, please use the no bgp dampening command.

half-life: The time it takes for the penalty value to be halved. The range is 1-45 minutes, and the default value is 15.

reuse: The value at which the oscillating route can be reused. The range is 1-20000, and the default value is 750.

suppress: The value at which the oscillating route is suppressed. The range is 1-20000, and the default value is 2000.

max-suppress-time: The maximum duration of route suppression. The range is 1-255, and the default value is 4.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the time required for the route attenuation penalty value to be halved to 30 minutes, the reuse value to 500, the suppression value to 500, and the maximum suppression duration to 10:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp dampening 30 500 500 10

Switch(config)#end

Switch#copy running-config startup-config

10.1.20 Activating IPv4 Unicast

Follow these steps to configure IPv4 unicast to be activated for neighbors by default:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp default ipv4-unicast

no bgp default ipv4-unicast

Configure IPv4 unicast to be activated for neighbors by default. To disable this configuration, use the no bgp default ipv4-unicast command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure IPv4 unicast to be activated for neighbors by default:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp default ipv4-unicast

Switch(config)#end

Switch#copy running-config startup-config

10.1.21 Configuring Local Preference

Follow these steps to configure the local preference:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp default local-preference

preference

no bgp default local-preference

Configure the local preference. To disable this configuration, use the no bgp default local-preference command.

preference: Local preference, ranging from 0 to 4294967295, and the default value is 100.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the local preference to 200:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp default local-preference 200

Switch(config)#end

Switch#copy running-config startup-config

10.1.22 Configuring Deterministic-med

Follow these steps to configure BGP to select the path with the best MED from the paths advertised from the adjacent AS:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp deterministic-med

no bgp deterministic-med

Configure BGP to select the path with the best MED from the paths advertised from the adjacent AS. To disable this configuration, use the no bgp deterministic-med command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure BGP to select the path with the best MED from the paths advertised from the adjacent AS:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp deterministic-med

Switch(config)#end

Switch#copy running-config startup-config

10.1.23 Configuring Enforce-first-as

Follow these steps to configure BGP to check whether the first path in the AS path of the received route is the neighbor AS:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp enforce-first-as

no bgp enforce-first-as

Configure BGP to check whether the first path in the AS path of the received route is the neighbor AS. To disable this configuration, please use the no bgp enforce-first-as command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure BGP to check whether the first path in the AS path of the received route is the neighbor AS:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp enforce-first-as

Switch(config)#end

Switch#copy running-config startup-config

10.1.24 Configuring Fast-external-failover

Follow these steps to configure BGP to reset the session immediately after the directly connected external neighbor is disconnected:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp fast-external-failover

no bgp fast-external-failover

Configure BGP to reset the session immediately after the directly connected external neighbor is disconnected. To disable this configuration, use the no bgp fast-external-failover command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure BGP to reset the session immediately after the directly connected external neighbor is disconnected:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp fast-external-failover

Switch(config)#end

Switch#copy running-config startup-config

10.1.25 Configuring Network import-check

Follow these steps to configure BGP to check the reachability of the routes configured by the network command:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp network import-check

no bgp network import-check

Configure BGP to check the reachability of the routes configured by the network command.

To disable this configuration, use the no bgp network import-check command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure BGP to check the reachability of the routes configured by the network command:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp network import-check

Switch(config)#end

Switch#copy running-config startup-config

10.1.26 Setting Router ID

Follow these steps to set the router ID:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 bgp router-id

router-id

no bgp router-id

Set the router ID. If you do not manually configure the router ID, or cancel the configured router ID, BGP will automatically select an interface IP address as the router ID. To delete the router ID, use the no bgp router-id command.

router-id: Router ID, which is a 32-bit unsigned integer in dotted decimal format, excluding 0.0.0.0. To avoid multiple routers using the same router ID during automatic election, it is recommended to configure this manually.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the BGP route ID to 1.1.1.1:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#bgp router-id 1.1.1.1

Switch(config)#end

Switch#copy running-config startup-config

10.1.27 Activating Address Family

Follow these steps to configure BGP to enable the address family for the neighbor:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor ip-address | tag activate

no neighbor ip-address | tag activate

Configure BGP to enable the address family for the neighbor. To disable this configuration, please use the no neighbor activate command.

ip-address: Neighbor IP address.

tag: Peer-group name.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure BGP to enable address family for neighbor 1.1.1.1:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 activate

Switch(config)#end

Switch#copy running-config startup-config

10.1.28 Configuring Advertisement-interval

Follow these steps to configure the minimum interval for advertising BGP route updates:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag advertisement-interval interval

no neighbor ip-address | tag advertisement-interval

Configure the minimum interval for advertising BGP route updates. To disable this configuration, please use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

interval: The minimum interval for advertising BGP routing updates, ranging from 0-600 seconds.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure BGP to advertise BGP routing updates for neighbor 1.1.1.1 at a minimum interval of 10 seconds:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 advertisement-interval 10

Switch(config)#end

Switch#copy running-config startup-config

10.1.29 Configuring Neighbor Allowas-in

Follow these steps to configure the maximum number of ASs in the AS path sent by the neighbor, including its own AS:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag allowas-in number

no neighbor ip-address | tag allowas-in

Configure the maximum number of ASs in the AS path sent by the neighbor, including its own AS. To disable this configuration, please use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

number: AS number, ranging from 1 to 10.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the maximum number of ASs in the AS path sent by neighbor 1.1.1.1, including its own AS, to 10:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 allowas-in 10

Switch(config)#end

Switch#copy running-config startup-config

10.1.30 Configuring Attribute-unchanged

Follow these steps to configure BGP attributes to be sent to neighbors without change:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag attribute-unchanged [as-path] [med] [next-hop]

no neighbor ip-address | tag attribute-unchanged

Configure BGP attributes to be sent to neighbors without change. To disable this

configuration, please use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

as-path: AS path attribute.

med: MED attribute

next-hop: Next hop attribute

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure BGP AS path attributes to be sent to neighbor 1.1.1.1 without change:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 attribute-unchanged as-path

Switch(config)#end

Switch#copy running-config startup-config

10.1.31 Announcing Dynamic Capability

Follow these steps to announce dynamic capabilities to neighbors:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag capability dynamic

no neighbor ip-address | tag capability dynamic

Announce dynamic capabilities to neighbors. To disable this configuration, use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to announce dynamic capabilities to neighbor 1.1.1.1:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 capability dynamic

Switch(config)#end

Switch#copy running-config startup-config

10.1.32 Sending Default Route

Follow these steps to send the default route to the neighbor:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag default-originate

no neighbor ip-address | tag default-originate

Send the default route to the neighbor. To disable this configuration, use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to send the default route to neighbor 1.1.1.1:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 default-originate

Switch(config)#end

Switch#copy running-config startup-config

10.1.33 Configuring Neighbor Description

Follow these steps to configure the neighbor description:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag description description

no neighbor ip-address | tag description

Configure the neighbor description. To delete the neighbor description, use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

description: Neighbor description.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the description for neighbor 1.1.1.1 to be internet:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 description internet

Switch(config)#end

Switch#copy running-config startup-config

10.1.34 Disabling Connect Check

Follow these steps to configure the use of loopback address for one-hop EBGP neighbors:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag disable-connected-check

no neighbor ip-address | tag disable-connected-check

Configure the use of loopback address for one-hop EBGP neighbors. To cancel this configuration, use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to use loopback address for neighbor 1.1.1.1:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 disable-connected-check

Switch(config)#end

Switch#copy running-config startup-config

10.1.35 Configuring Distribute List

Follow these steps to configure the distribution list to be applied to neighbors to filter routes:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag distribute-list name [in|out]

no neighbor ip-address | tag distribute-list

Configure the distribution list to be applied to neighbors to filter routes. To cancel this configuration, use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

name: Distribution list name.

in: Filter in the inbound direction.

out: Filter in the outbound direction.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure neighbor 1.1.1.1 to apply distribute-list a to filter incoming routes:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 distribute-list a in

Switch(config)#end

Switch#copy running-config startup-config

10.1.36 Disabling Capability Negotiation

Follow these steps to disable the negotiation of capabilities with neighbors:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag dont-capability-negotiate

no neighbor ip-address | tag dont-capability-negotiate

Disable the negotiation on capabilities with neighbors. To cancel this configuration, please use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to disable capability negotiation with neighbor 1.1.1.1:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 dont-capability-negotiate

Switch(config)#end

Switch#copy running-config startup-config

10.1.37 Configuring EBGP Multihop

Follow these steps to allow the establishment of a connection with an EBGP neighbor on an indirect network:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag ebgp-multihop hops

no neighbor ip-address | tag ebgp-multihop

Configure not to negotiate capabilities with neighbors. To cancel this configuration, please use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

hops: The maximum number of hops to reach an EBGP neighbor. The default value is 1, which means only directly connected neighbors are allowed.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the maximum number of hops to neighbor 1.1.1.1 to 10:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 ebgp-multihop 10

Switch(config)#end

Switch#copy running-config startup-config

10.1.38 Configuring Local-AS

Follow these steps to prepend the specified local AS to the AS path when BGP sends or receives the AS path from the specified neighbor:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag local-as as [no-prepend] [replace-as]

no neighbor ip-address | tag local-as

Prepend the specified local AS to the AS path when BGP sends or receives the AS path from the specified neighbor. To cancel this configuration, use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

no-prepend: The provided local AS is not added to the received AS list.

replace-as: Only the provided local AS is pre-appended to the AS path when transmitting local routing updates to this neighbor.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to prepend the specified local AS 5 to the AS path when sending or receiving the AS path from neighbor 1.1.1.1:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 local-as 5

Switch(config)#end

Switch#copy running-config startup-config

10.1.39 Configuring Maximum-prefix

Follow these steps to specify the maximum number of routes received from a specific neighbor:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag maximum-prefix number

no neighbor ip-address | tag maximum-prefix

Specify the maximum number of routes received from a specific neighbor. To cancel this configuration, use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

number: The maximum number of routes that can be received from this neighbor.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the maximum number of routes received from neighbor 1.1.1.1 to 100:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 maximum-prefix 100

Switch(config)#end

Switch#copy running-config startup-config

10.1.40 Configuring Next-hop-self

Follow these steps to cancel BGP's processing of the next hop in the route to be released, and use its own address as the next hop:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighborip-address | tag next-hop-self
no neighbor ip-address | tag next-hop-self
Cancel BGP's processing of the next hop in the route to be released, and use its own address as the next hop. To cancel this configuration, please use the no command.
ip-address: Neighbor IP address.
tag: Peer-group name.

Step 4 end Return to privileged EXEC mode. Step 5 copy running-config startup-config Save the settings in the configuration file.

The following example shows how to configure the route sent to neighbor 1.1.1.1 to use its own address as the next hop:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 next-hop-self

Switch(config)#end

Switch#copy running-config startup-config

10.1.41 Configuring Override-capability

Follow these steps to ignore neighbor capability negotiation information and use the default capability information:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag override-capability

no neighbor ip-address | tag override-capability

Ignore neighbor capability negotiation information and use the default capability information. To cancel this configuration, please use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to ignore the capability negotiation information of neighbor 1.1.1.1:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 override-capability

Switch(config)#end

Switch#copy running-config startup-config

10.1.42 Disabling OPEN Message Sending

Follow these steps to disable the OPEN message sent to the neighbor:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag passive

no neighbor ip-address | tag passive

Disable the OPEN message sent to the neighbor. To cancel this configuration, use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to disable the OPEN message sent to neighbor 1.1.1.1:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 passive

Switch(config)#end

Switch#copy running-config startup-config

10.1.43 Configuring Neighbor Password

Follow these steps to configure the neighbor password:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag passwordpassword

no neighbor ip-address | tag password

Configure the neighbor password. To cancel this configuration, please use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

password: Neighbor password.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the password for neighbor 1.1.1.1 to be abc:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 password abc

Switch(config)#end

Switch#copy running-config startup-config

10.1.44 Configuring Peer-group

Follow these steps to configure neighbors to join the specified neighbor group:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor ip-address | tag peer-group name

no neighbor ip-address | tag peer-group

Configure neighbors to join the specified neighbor group. To cancel this configuration, please use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

name: Neighbor group name.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to join neighbor 1.1.1.1 to neighbor group abc:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 peer-group abc

Switch(config)#end

Switch#copy running-config startup-config

10.1.45 Configuring BGP Port

Follow these steps to configure the BGP port number of the neighbor:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag port port

no neighbor ip-address | tag port

Configure the BGP port number of the neighbor. To cancel this configuration, please use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

port: TCP port number, ranging from 0-65535.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the BGP port number of neighbor 1.1.1.1 to 200:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 port 200

Switch(config)#end

Switch#copy running-config startup-config

10.1.46 Configuring Remote AS

Follow these steps to configure BGP neighbors:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag remote-as as

no neighbor ip-address | tag remote-as

Configure BGP neighbors. To cancel this configuration, please use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

as: AS number of the neighbor.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure neighbor 1.1.1.1 in AS 1:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 remote-as 2

Switch(config)#end

Switch#copy running-config startup-config

10.1.47 Removing Private AS

Follow these steps to remove the private AS number from outbound updates:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag remove-private-AS

no neighbor ip-address | tag remove-private-AS

Remove the private AS number from outbound updates. To cancel this configuration, please use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to remove the private AS number from updates sent to neighbor 1.1.1.1:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 remove-private-AS

Switch(config)#end

Switch#copy running-config startup-config

10.1.48 Configuring Route-reflector-client

Follow these steps to configure a neighbor as a client of a route reflector:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighborip-address | tag route-reflector-client
no neighbor ip-address | tag route-reflector-client
Configure a neighbor as a client of a route reflector. To cancel this configuration, please use the no command.
ip-address: Neighbor IP address.
tag: Peer-group name.

Step 4 end Return to privileged EXEC mode. Step 5 copy running-config startup-config Save the settings in the configuration file.

The following example shows how to configure neighbor 1.1.1.1 as a client of the route reflector:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 route-reflector-client

Switch(config)#end

Switch#copy running-config startup-config

10.1.49 Disabling Neighbor Manually

Follow these steps to manually shut down a neighbor:

Step 1 configure Enter global configuration mode.

Step 2 router bgpas-number
Enable the BGP function and enter the Router BGP configuration mode.

Step 3: neighbor ip-address | tag shutdown

no neighbor ip-address | tag shutdown

Manually shut down a neighbor. To cancel this configuration, please use the no command.ip-address: Neighbor IP address.tag: Peer-group name.

Step 4: end. Return to privileged EXEC mode. Step 5: copy running-config startup-config. Save the settings in the configuration file.

The following example shows how to manually shut down neighbor 1.1.1.1:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 shutdown

Switch(config)#end

Switch#copy running-config startup-config

10.1.50 Configuring Soft-reconfiguration Inbound

Follow these steps to enable BGP to make the newly configured route-map and distribution list effective without clearing the neighbor session:

Step 1: configure. Enter global configuration mode.

Step 2: router bgp as-number

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag soft-reconfiguration inbound

no neighbor ip-address | tag soft-reconfiguration inbound

Enable BGP to make the newly configured route-map and distribution list effective without clearing the neighbor session. To disable this feature, use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to make the route-map applied to neighbor 1.1.1.1 effective without clearing the session:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 soft-reconfiguration inbound

Switch(config)#end

Switch#copy running-config startup-config

10.1.51 Configuring Strict-capability-match

Follow these steps to enable BGP to strictly match the capability negotiation between neighbors:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag strict-capability-match

no neighbor ip-address | tag strict-capability-match

Strictly match the capability negotiation between neighbors. To disable this feature, use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to strictly match the capability negotiation between neighbor 1.1.1.1:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 strict-capability-match

Switch(config)#end

Switch#copy running-config startup-config

10.1.52 Configuring Neighbor Timers

Follow these steps to configure the interval for sending keepalive messages between neighbors and the neighbor hold time:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag timers keepalive hold

no neighbor ip-address | tag timers

Configure the interval for sending keepalive messages between neighbors and the neighbor hold time. To disable this feature, use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

keepalive: The interval for sending keepalive messages between neighbors, ranging from 1-65535 seconds.

hold: Neighbor hold time, ranging from 1-65535 seconds.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the keepalive message interval between neighbor 1.1.1.1 to 10 seconds and the keepalive time to 30 seconds:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 timers 10 30

Switch(config)#end

Switch#copy running-config startup-config

10.1.53 Configuring Neighbor Timers Connect

Follow these steps to configure the interval of the neighbor reconnecting to the timer:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag connectconnect

no neighbor ip-address | tag connect

Configure the interval of the neighbor reconnecting to the timer. To disable this feature, use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

connect: Interval of the neighbor reconnecting to the timer.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the interval of the neighbor reconnecting to the timer to 100 seconds:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 timers connect 100

Switch(config)#end

Switch#copy running-config startup-config

10.1.54 Configuring Neighbor Max Hops

Follow these steps to configure the maximum hops of neighbors:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag ttl-security hops hops

no neighbor ip-address | tag ttl-security hops

Configure the interval of the neighbor reconnecting to the timer. To disable this feature, please use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

hops: Hop count.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the maximum hop count for neighbor 1.1.1.1 to 10:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 ttl-security hops 10

Switch(config)#end

Switch#copy running-config startup-config

10.1.55 Configuring Update-source

Follow these steps to configure the neighbor's routing update source:

Step 1 configure

Enter global configuration mode.

Step 2 router bgp

as-number

Enable the BGP function and enter the Router BGP configuration mode.

Step 3 neighbor

ip-address | tag update-source source

no neighbor ip-address | tag update-source

Configure the neighbor's routing update source. To disable this feature, use the no command.

ip-address: Neighbor IP address.

tag: Peer-group name.

source: Specify the IP address of the source of routing updates.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the routing update source of neighbor 1.1.1.1 to 2.2.2.2:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 update-source 2.2.2.2

Switch(config)#end

Switch#copy running-config startup-config

10.1.56 Configuring Default Weight

Follow these steps to set the default weight for routes from this neighbor:

Step 1 configure

Enter global configuration mode.

Step 2 router bgpas-number
Enable the BGP function and enter the Router BGP configuration mode.
Step 3 neighborip-address | tag weight weight
no neighbor ip-address | tag weight
Set the default weight for routes from this neighbor. To delete the weight, please use the no command.
ip-address:Neighbor IP address.
tag: Peer-group name.
weight: Default weight, ranging from 0-65535.
Step 4 end
Return to privileged EXEC mode.
Step 5 copy running-config startup-config
Save the settings in the configuration file.

The following example shows how to set the default weight of routes from neighbor 1.1.1.1 to be 10:

Switch#configure

Switch(config)#router bgp 100

Switch(config-router)#neighbor 1.1.1.1 weight 10

Switch(config)#end

Switch#copy running-config startup-config

10.1.57 Viewing BGP Routing Table

Follow these steps to view the BGP routing table:

Step 1 show ip bgp

[ip-address| ip-address/mask-len]

ip-address: The network segment to be displayed.

ip-address/mask-len: The network segment IP address and mask length to be displayed.

The following example shows how to view the BGP routing table for the network segment 2.2.2.0:

Switch#show ip bgp 2.2.2.0

10.1.58 Viewing BGP Attribute

Follow these steps to view all BGP attribute information:

Step 1 show ip bgp attribute-info

The following example shows how to view all BGP attribute information:

Switch#show ip bgp attribute-info

10.1.59 Viewing IP BGP CIDR only

Follow these steps to view only routes with non-natural network masks:

Step 1 show ip bgp cidr-only

The following example shows how to view only routes with non-natural network masks:

Switch#show ip bgp cidr-only

10.1.60 Viewing IP BGP Dampening Flap-statistics

Follow these steps to view the statistics of route flap penalty:

Step 1 show ip bgp dampening flap-statistics

The following example shows how to view the statistics of route flap penalty:

Switch#show ip bgp dampening flap-statistics

10.1.61 Viewing IP BGP Dampening Dampened-paths

Follow these steps to view information about dampened paths due to flapping:

Step 1 show ip bgp dampening dampened-paths

The following example shows how to view information about dampened paths due to flapping:

Switch#show ip bgp dampening dampened-paths

10.1.62 Viewing IP BGP Dampening Parameters

Follow these steps to view the parameters related to route flapping:

Step 1 show ip bgp dampening parameters

The following example shows how to view the parameters related to route flapping:

Switch#show ip bgp dampening parameters

10.1.63 Viewing BGP Neighbor Information

Follow these steps to view the BGP neighbor information:

Step 1 show ip bgp neighbors

The following example shows how to view the BGP neighbor information:

Switch#show ip bgp neighbors

10.1.64 Viewing Advertised-routes

Follow these steps to view the routing information advertised to neighbors:

Step 1 show ip bgp neighbors

ip-address advertised-routes

ip-address: The network segment to be displayed.

The following example shows how to view the routing information advertised to neighbor 1.1.1.1:

Switch#show ip bgp neighbors 1.1.1.1 advertised-routes

10.1.65 Viewing Dampened Routes from Neighbors

Follow these steps to view the dampened routes received from neighbors:

Step 1 show ip bgp neighbors

ip-address dampened-routes

ip-address: The network segment to be displayed.

The following example shows how to view the dampened routes received from neighbor 1.1.1.1:

Switch#show ip bgp neighbors 1.1.1.1 dampened-routes

10.1.66 Viewing Neighbor Flapping Route

Follow these steps to view the flapping route information of a neighbor:

Step 1 show ip bgp neighbors

ip-address flap-statistics

ip-address: The network segment to be displayed.

The following example shows how to view the flapping route information of neighbor 1.1.1.1:

Switch#show ip bgp neighbors 1.1.1.1 flap-statistics

10.1.67 Viewing Neighbor Prefix-counts

Follow these steps to view the detailed prefix counts of a neighbor:

Step 1 show ip bgp neighbors

ip-address prefix-counts

ip-address: The network segment to be displayed.

The following example shows how to view the detailed prefix counts of neighbor 1.1.1.1:

Switch#show ip bgp neighbors 1.1.1.1 prefix-counts

10.1.68 Viewing Routes from Neighbors

Follow these steps to view the routes received from neighbors:

Step 1 show ip bgp neighbors

ip-address received-routes

ip-address: The network segment to be displayed.

The following example shows how to view the routes received from neighbor 1.1.1.1:

Switch#show ip bgp neighbors 1.1.1.1 received-routes

10.1.69 Viewing Routes Learned from Neighbors

Follow these steps to view the routes learned from neighbors:

Step 1 show ip bgp neighbors

ip-address routes

ip-address: The network segment to be displayed.

The following example shows how to view the routes learned from neighbor 1.1.1.1:

Switch#show ip bgp neighbors 1.1.1.1 routes

10.1.70 Viewing Next Hop

Follow these steps to view the next hop information:

Step 1 show ip bgp nexthop

The following example shows how to view the BGP next hop information:

Switch#show ip bgp nexthop

10.1.71 Viewing BGP Path

Follow these steps to view the BGP path information:

Step 1 show ip bgp paths

The following example shows how to view the BGP path information:

Switch#show ip bgp paths

10.1.72 Viewing Specific Network Information

Follow these steps to view the specific network information:

Step 1 show ip bgp specify

ip-address [mask] [bestpath] [multipath]

ip-address: The IP address to match.

mask: The mask to match.

bestpath: Only display the best matching network segment.

multipath: Only display the multipath network segment.

The following example shows how to view the network information of 2.2.2.0/24:

Switch#show ip bgp specify 2.2.2.0 255.255.255.0

10.1.73 Viewing BGP Neighbor Summary

Follow these steps to view the summary of BGP neighbors:

Step 1 show ip bgp summary

The following example shows how to view the summary of BGP neighbors:

Switch#show ip bgp summary

10.1.74 Resetting Specific BGP Neighbor

Follow these steps to reset a specific BGP neighbor:

Step 1 clear ip bgp

clear ip bgp ip-address

as: AS number of the neighbor.

ip-address: Neighbor's IP.

The following example shows how to reset BGP neighbor 1.1.1.1:

Switch#clear ip bgp 1.1.1.1

10.1.75 Resetting All BGP Neighbors

Follow these steps to reset all BGP neighbors:

Step 1 clear ip bgp all

The following example shows how to reset all BGP neighbors:

Switch#clear ip bgp all

10.1.76 Resetting BGP Route Dampening

Follow these steps to reset BGP route dampening.:

Step 1 clear ip bgp dampening

ip-address [mask]

ip-address: Network segment IP address.

mask: Network segment mask.

The following example shows how to reset route dampening for network segment 1.1.1.0/24:

Switch#clear ip bgp dampening 1.1.1.0 255.255.255.0

11 IS-IS Configurations

TP-LINK Omada Pro S5500-24GP4F - IS-IS Configurations - 1

Note:

IS-IS is only available on Omada Pro L3 Stackable Switches.

Intermediate System to Intermediate System (IS-IS) is a dynamic routing protocol proposed by ISO. Currently, IS-IS is also supported in TCP/IP environments. It is a widely used protocol in Interior Gateway Protocols (IGP).

IS-IS is a link-state protocol, and the core concept of its routing calculation is the Shortest Path First (SPF) algorithm.

11.1 Using the CLI

11.1.1 Enabling IS-IS Globally

Follow these steps to enable the IS-IS function globally:

Step 1 configure

Enter global configuration mode.

Step 2 router isis

area-name

no router isis area-name

Enable the IS-IS function and enter the Router configuration mode. To disable IS-IS, use the no router isis command.

area-name: IS-IS area name, used to identify an IS-IS instance on this switch.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the IS-IS function on the switch:

Switch#configure

Switch(config)#router isis 1

Switch(config)#end

Switch#copy running-config startup-config

11.1.2 Enabling Level-1 Authentication

Follow these steps to enable the IS-IS Level-1 area authentication function:

Step 1 configure

Enter global configuration mode.

Step 2 router isis

area-name

Enable the IS-IS function and enter the Router configuration mode.

Step 3 area-password { clear | md5 } { 0 | 7 }

text

no area-password

Enable the IS-IS Level-1 area authentication function. After the function is enabled, IS-IS will carry authentication information in the message exchange in the area and verify the authentication information. To disable this function, please use the no area-password command.

clear: Encrypt in plain text.

md5: Encrypt using md5 algorithm.

0: Enter plain text.

7: Enter in cipher text.

text: Password text

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure MD5 encrypted authentication for the IS-IS Level-1 area:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#area-password md5 0 tp-link

Switch(config)#end

Switch#copy running-config startup-config

11.1.3 Enabling Level-2 Authentication

Follow these steps to enable the IS-IS Level-2 area authentication function:

Step 1 configure

Enter global configuration mode.

Step 2 router isis area-nameEnable the IS-IS function and enter the Router configuration mode.
Step 3 domain-password {clear | md5}{0|7} text
no domain-password
Enable the authentication function of the IS-IS Level-2 area. After enabling this function, IS-IS will carry authentication information in the message exchange in this area and verify the authentication information. To disable this function, please use the no domain-password command.
clear: Encrypt in plain text.
md5: Encrypt using md5 algorithm.
0: Enter plain text.
7: Enter in cipher text.
text: Password text
Step 4 end
Return to privileged EXEC mode.
Step 5 copy running-config startup-config
Save the settings in the configuration file.

The following example shows how to configure MD5 encrypted authentication for the IS-IS Level-2 area:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#domain-password md5 0 tp-link

Switch(config)#end

Switch#copy running-config startup-config

11.1.4 Enabling Host Name

Follow these steps to enable the dynamic host name function of IS-IS:

Step 1 configure

Enter global configuration mode.

Step 2 router isis

area-name

Enable the IS-IS function and enter the Router configuration mode.

Step 3 hostname { name | dynamic }

no hostname

Enable the dynamic host name function of IS-IS. After enabling this function, IS-IS will configure a dynamic host name for the IS-IS system on the local switch and notify the neighbor device through the LSP message. To disable this function, please use the no hostname command.

name: Specified host name, in text form.

dynamic: Use dynamic host name, in this mode, the system configured host name will be obtained.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the dynamic host name function of IS-IS:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#hostname dynamic

Switch(config)#end

Switch#copy running-config startup-config

11.1.5 Configuring Area Type

Follow these steps to set the IS area type:

Step 1 configure

Enter global configuration mode.

Step 2 router isis

area-name

Enable the IS-IS function and enter the Router configuration mode.

Step 3 is-type {level-1 | level-1-2 | level-2-only}

no is-type

Set the IS area type, which is Level-1-2 by default. To restore the default configuration, please use the no is-type command.

level-1: Set the IS-IS area type to Level-1

level-1-2: Set the IS-IS area types to Level-1 and Level-2

level-2-only: Set the IS-IS area type to Level-2

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the IS-IS area type to Level-1:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#is-type level-1

Switch(config)#end

Switch#copy running-config startup-config

11.1.6 Configuring Log Adjacency Change

Follow these steps to enable IS-IS to record events of adjacency state changes:

Step 1 configure

Enter global configuration mode.

Step 2 router isis

area-name

Enable the IS-IS function and enter the Router configuration mode.

Step 3 log-adjacency-changes

no log-adjacency-changes

Enable IS-IS to record events of adjacency state changes. To disable this function, please use the no log-adjacency-changes command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable IS-IS to record events of adjacency state changes:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#log-adjacency-changes

Switch(config)#end

Switch#copy running-config startup-config

11.1.7 Configuring LSP Generate Interval

Follow these steps to configure the interval for generating LSPs:

Step 1 configure

Enter global configuration mode.

Step 2 router isis

area-name

Enable the IS-IS function and enter the Router configuration mode.

Step 3 lsp-gen-interval

interval

no lsp-gen-interval

Configure the interval for generating LSPs. When the local network flaps, the IS-IS local LSP may be frequently refreshed, causing frequent IS-IS flapping. To restore the default configuration, use the no lsp-gen-interval command.

interval: The interval for generating LSPs, ranging from 1 to 120 seconds. The default is 30 seconds.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the LSP generating interval to 10 seconds:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#lsp-gen-interval 10

Switch(config)#end

Switch#copy running-config startup-config

11.1.8 Configuring LSP Max Length

Follow these steps to configure the maximum length of a self-generated LSP:

Step 1 configure

Enter global configuration mode.

Step 2 router isis

area-name

Enable the IS-IS function and enter the Router configuration mode.

Step 3 lsp-mtu

size

no lsp-mtu

Configure the maximum length of a self-generated LSP. To restore the default configuration, use the no lsp-mtu command.

size: The maximum length of LSP, ranging from 512 to 4352 bytes. It is 1497 bytes by default.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the maximum length of LSP to 1024 bytes:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#lsp-mtu 1024

Switch(config)#end

Switch#copy running-config startup-config

11.1.9 Configuring LSP Refresh Interval

Follow these steps to configure the interval for refreshing the IS-IS LSP:

Step 1 configure

Enter global configuration mode.

Step 2 router isis

area-name

Enable the IS-IS function and enter the Router configuration mode.

Step 3 lsp-refresh-interval

interval

no lsp-refresh-interval

Configure the interval for refreshing the IS-IS LSP. To restore the default configuration, use the no lsp-refresh-interval command.

interval: The interval for refreshing the IS-IS LSP, ranging from 1 to 65535 seconds. The default is 900 seconds.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the LSP refresh interval to 100 seconds:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#lsp-refresh-interval 100

Switch(config)#end

Switch#copy running-config startup-config

11.1.10 Configuring LSP Lifetime

Follow these steps to configure the maximum lifetime of an IS-IS LSP packet:

Step 1 configure

Enter global configuration mode.

Step 2 router isis

area-name

Enable the IS-IS function and enter the Router configuration mode.

Step 3 max-lsp-lifetime

time

no max-lsp-lifetime

Configure the maximum lifetime of an IS-IS LSP packet. To restore the default configuration, use the no max-lsp-lifetime command.

time: The maximum lifetime of LSP, ranging from 350 to 65535 seconds. The default is 1200 seconds.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the maximum lifetime of an LSP to 1000s:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#max-lsp-lifetime 1000

Switch(config)#end

Switch#copy running-config startup-config

11.1.11 Configuring Metric Style

Follow these steps to configure the IS-IS metric style:

Step 1 configure

Enter global configuration mode.

Step 2 router isis

area-name

Enable the IS-IS function and enter the Router configuration mode.

Step 3 metric-style { narrow | transition | wide }

no metric-style

Configure IS-IS metric style. To restore the default configuration, use the no metric-style command.

narrow: Narrow mode. This is the default mode.

transition: Compatible mode, supporting both narrow and wide modes.

wide: Wide mode, mainly used for TE scenarios.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set IS-IS metric style to wide:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#metric-style wide

Switch(config)#end

Switch#copy running-config startup-config

11.1.12 Configuring Network Entity Title

Follow these steps to configure the Network Entity Name (NET) of IS-IS:

Step 1 configure

Enter global configuration mode.

Step 2 router isis

area-name

Enable the IS-IS function and enter the Router configuration mode.

Step 3 netnet-name
no net net-name
Configure NET of IS-IS. To delete NET, please use the no net command.
net-name: Network Entity Title, in the format of X...X.XXXX.XXXX.XXXX.00. The first "X...X" is the IS-IS area address, the 12 "X"s in the middle are the switch's System ID, and the last "00" is the SEL.
Step 4 endReturn to privileged EXEC mode.
Step 5 copy running-config startup-config
Save the settings in the configuration file.

The following example shows how to configure IS-IS NET as 10.0000.0000.0000.1111.00:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#net 10.0000.0000.0000.1111.00

Switch(config)#end

Switch#copy running-config startup-config

11.1.13 Enabling Purge Originator

Follow these steps to enable the purge originator of IS-IS:

Step 1configureEnter global configuration mode.
Step 2router isisarea-nameEnable the IS-IS function and enter the Router configuration mode.
Step 3purge-originatorno purge-originatorEnable the purge originator of IS-IS . To disable this function, please use theno purge-originatorcommand.
Step 4endReturn to privileged EXEC mode.
Step 5copy running-config startup-configSave the settings in the configuration file.

The following example shows how to enable the purge originator of IS-IS:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#purge-originator

Switch(config)#end

Switch#copy running-config startup-config

11.1.14 Configuring ATT

Follow these steps to set the ATT bit of IS-IS LSP:

Step 1 configure

Enter global configuration mode.

Step 2 router isis

area-name

Enable the IS-IS function and enter the Router configuration mode.

Step 3 set-attached-bit

no set-attached-bit

Set the ATT bit of IS-IS LSP. By default, Level-1-2 devices will set the ATT bit according to the rules of IS-IS protocol. After this command is configured, the ATT bit will always be set in Level-1 LSP. To cancel the setting of ATT bit, please use the no set-attached-bit command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the ATT bit of IS-IS LSP:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#set-attached-bit

Switch(config)#end

Switch#copy running-config startup-config

11.1.15 Configuring Overload Bit

Follow these steps to set the overload bit in IS-IS LSP:

Step 1 configure

Enter global configuration mode.

Step 2 router isisarea-name
Enable the IS-IS function and enter the Router configuration mode.
Step 3 set-overload-bit
no set-overload-bit
Set the overload bit in IS-IS LSP. To cancel the overload bit setting, please use the no set-overload-bit command.
Step 4 end
Return to privileged EXEC mode.
Step 5 copy running-config startup-config
Save the settings in the configuration file.

The following example shows how to set the overload bit in IS-IS LSP:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#set-overload-bit

Switch(config)#end

Switch#copy running-config startup-config

11.1.16 Configuring Prefix Priority

Follow these steps to configure the IS-IS route convergence priority for a specific ACL entry:

Step 1 configure

Enter global configuration mode.

Step 2 router isis

area-name

Enable the IS-IS function and enter the Router configuration mode.

Step 3 spf prefix-priority { critical | high | medium }

acl-name

no spf prefix-priority { critical | high | medium }

Configure the IS-IS route convergence priority for a specific ACL entry. Before configuration, the corresponding ACL needs to be created. By default, the convergence priority of IS-IS host routes and default routes is medium, and the convergence priority of other IS-IS routes is low. To cancel the overload bit setting, use the no spf prefix-priority command.

critical: Highest priority.

high: High priority.

medium: Medium priority.

acl-name: ACL list name.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the route calculation priority of ACL tplink to critical:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#spf prefix-priority critical tplink

Switch(config)#end

Switch#copy running-config startup-config

11.1.17 Clearing IS-IS Neighbor

Follow these steps to clear the neighbor relationship established by IS-IS and re-establish the relationship with neighbor device:

Step 1 configure

Enter global configuration mode.

Step 2 router isis

area-name

Enable the IS-IS function and enter the Router configuration mode.

Step 3 clear isis neighbor [

system-id]

Clear the neighbor relationship established by IS-IS and re-establish the relationship with neighbor device.

system-id: System ID of the specified neighbor.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to clear all IS-IS neighbors:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#clear isis neighbor

Switch(config)#end

Switch#copy running-config startup-config

11.1.18 Redistributing Route

Follow these steps to redistribute routes:

Step 1 configure

Enter global configuration mode.

Step 2 router isis

area-name

Enable the IS-IS function and enter the Router configuration mode.

Step 3 redistribute {ipv4 {bgp | connected | rip | static | ospf instance-id} | ipv6 {bgp | connected | ospf6 | ripng | static }} {level-1 | level-2}

no redistribute { ipv4 { bgp | connected | rip | static | ospf instance-id} | ipv6 { bgp | connected | ospf6 | ripng | static }} { level-1 | level-2 }

Redistribute routes. In a multi-protocol deployment scenario, routes of other protocols can be redistributed to IS-IS, which will then flood the routes throughout the entire area.

ipv4: Redistribute IPv4 routes.

ipv6: Redistribute IPv6 routes.

bgp: Redistribute BGP routes.

connected: Redistribute direct routes.

rip: Redistribute RIP routes.

static: Redistribute static routes.

ospf6: Redistribute OSPFv3 routes.

ripng: Redistribute RIPng routes.

level-1: Redirect to level-1 area

level-2: Redirect to level-2 area

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to redistribute IPv4 BGP routes to the level-1 area of IS-IS:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#redistribute ipv4 bgp level-1

Switch(config)#end

Switch#copy running-config startup-config

11.1.19 Setting Route Distance

Follow these steps to configure the distance of IS-IS routes:

Step 1 configure

Enter global configuration mode.

Step 2 router isis

area-name

Enable the IS-IS function and enter the Router configuration mode.

Step 3 distance

Configure the distance of IS-IS protocol routes, that is, the route priority of IS-IS protocol. This function can change the priority strategy of different protocol routes in multi-protocol scenarios.

value: Distance value, ranging from 1 to 255, and the default value is 110.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the distance of the IS-IS protocol to 100:

Switch#configure

Switch(config)#router isis 1

Switch(config-router)#distance 100

Switch(config)#end

Switch#copy running-config startup-config

11.1.20 Enabling IS-IS on the Interface

Follow these steps to enable IS-IS on an interface:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}
Enter interface configuration mode.

Step 3 ip router isis area-name

no ip router isis

Enable IS-IS on an interface. To disable this function, use the no ip router isis command.

area-name: Specify the area name of the IS-IS instance.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable IS-IS instance 1 on interface VLAN 1:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#ip router isis 1

Switch(config)#end

Switch#copy running-config startup-config

11.1.21 Enabling BFD

Follow these steps to enable BFD on an interface and notify IS-IS:

Step 1 configure

Enter global configuration mode.

Step 2interface {vlan vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernetport-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list }Enter interface configuration mode.
Step 3ip router isis [ bfd-template ]no isis bfdEnable BFD on an interface and notify IS-IS. IS-IS can quickly detect changes in interface status. To disable this function, please use theno isis bfdcommand.bfd-template:BFD template name, depending on the global BFD template configuration
Step 4 endReturn to privileged EXEC mode.
Step 5copy running-config startup-configSave the settings in the configuration file.

The following example shows how to enable BFD on interface VLAN 1 and notify IS-IS:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#isis bfd

Switch(config)#end

Switch#copy running-config startup-config

11.1.22 Configuring IS-IS Type

Follow these steps to configure the IS-IS area type of the interface:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port
| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}
Enter interface configuration mode.

Step 3 isis circuit-type { level-1 | level-1-2 | level-2-only }

no isis circuit-type

Configure the IS-IS area type of the interface. By default, the area type of the IS-IS interface is the area type configured globally for IS-IS. To restore the default configuration, use the no isis circuit-type command.

level-1: Set the IS-IS area type to Level-1

level-1-2: Set the IS-IS area types to Level-1 and Level-2

level-2-only: Set the IS-IS area type to Level-2

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the IS-IS area type of interface VLAN 1 to Level-1:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#isis circuit-type level-1

Switch(config)#end

Switch#copy running-config startup-config

11.1.23 Configuring CSNP Interval

Follow these steps to configure the interval for sending CSNP packets of IS-IS on the interface:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 isis csnp-interval interval

no isis csnp-interval

Configure the interval for sending CSNP packets of IS-IS on the interface. To restore the default configuration, please use the no isis csnp-interval command.

interval: The interval for sending CSNP packets, ranging from 1 to 600s, and the default value is 10.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the CSNP message sending interval of IS-IS on interface VLAN 1 to 20s:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#isis csnp-interval 20

Switch(config)#end

Switch#copy running-config startup-config

11.1.24 Configuring Hello Interval

Follow these steps to configure the interval for sending Hello packets of IS-IS on the interface:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}
Enter interface configuration mode.

Step 3 isis hello-interval interval

no isis hello-interval

Configure the interval for sending Hello packets of IS-IS on the interface. To restore the default configuration, please use the no isis csnp-interval command.

interval: The interval for sending Hello packets, ranging from 1 to 600s, and the default value is 3.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the Hello message sending interval of IS-IS on interface VLAN 1 to 10s:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#isis hello-interval 10

Switch(config)#end

Switch#copy running-config startup-config

11.1.25 Configuring Hello Multiplier

Follow these steps to configure the multiplier of the IS-IS Hello message on the interface:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 isis hello-multiplier

value

no isis hello-multiplier

Configure the multiplier of the IS-IS Hello message on the interface. Hello-interval * Hello-multiplier is the neighbor's Hold timer. To restore the default configuration, please use the no isis hello-multiplier command.

value: Hello multiplier, ranging from 2 to 100. It is 10 by default.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the IS-IS Hello multiplier on interface VLAN 1 to 20:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#isis hello-multiplier 20

Switch(config)#end

Switch#copy running-config startup-config

11.1.26 Configuring Metric

Follow these steps to configure the IS-IS metric on the interface:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 isis metric

value

no isis metric

Configure the IS-IS metric on the interface. To restore the default configuration, please use the no isis metric command.

IS-IS metric, ranging from 0 to 16777215. It is 10 by default.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the IS-IS metric on interface VLAN 1 to 20:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#isis metric 20

Switch(config)#end

Switch#copy running-config startup-config

11.1.27 Configuring Network Type

Follow these steps to configure the IS-IS network type of the interface:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}
Enter interface configuration mode.

Step 3 isis network point-to-point

no isis network point-to-point

Configure the IS-IS network type of the interface. To restore the default configuration, use the no isis network point-to-point command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the IS-IS network type of interface VLAN 1 to P2P:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#isis network point-to-point

Switch(config)#end

Switch#copy running-config startup-config

11.1.28 Making IS-IS Silent

Follow these steps to make the IS-IS on the interface silent:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}
Enter interface configuration mode.

Step 3 isis passive

no isis passive

Configure the IS-IS silent function on the interface. After it is enabled, the interface will not be able to perform IS-IS message exchange and route calculation. To disable this dunction, please use the no isis passive command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to make the IS-IS on VLAN 1 silent:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#isis passive

Switch(config)#end

Switch#copy running-config startup-config

11.1.29 Enabling IS-IS Authentication

Follow these steps to enable the IS-IS authentication on an interface:

Step 1 configure

Enter global configuration mode.
Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}
Enter interface configuration mode.

Step 3 isis password-key {clear | md5} {0 | 7} text

no isis password-key

Enable the IS-IS authentication function. After the function is enabled, IS-IS will carry authentication information in the message exchange in the area and verify the authentication information. To disable this function, please use the no area-password command.

clear: Encrypt in plain text.

md5: Encrypt using md5 algorithm.

0: Enter plain text.

7: Enter in cipher text.

text: Password text

Step 4 end Return to privileged EXEC mode.

Step 5 copy running-config startup-config Save the settings in the configuration file.

The following example shows how to configure MD5 encrypted authentication for the IS-IS on VLAN 1:

Switch#configure

Switch(config)#vlan 1

Switch(config-if)#isis password-ket md5 0 tp-link

Switch(config)#end

Switch#copy running-config startup-config

11.1.30 Configuring Priority

Follow these steps to configure the IS-IS priority of the interface:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlan vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list} Enter interface configuration mode.

Step 3 isis priority value

no isis priority

Configure the IS-IS priority of the interface. The IS-IS interface priority is mainly used for DIS election in LAN type networks. The interface with higher priority will be preferred. To restore the default configuration, please use the no isis priority command.

value: The DIS election priority of the interface, ranging from 0 to 127, and the default value is 64.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the IS-IS priority of interface VLAN 1 to 100:

Switch#configure

Switch(config)#vlan 1

Switch(config-if)#isis priority 100

Switch(config)#end

Switch#copy running-config startup-config

11.1.31 Configuring Three-way Handshake

Follow these steps to configure the three-way handshake mechanism of the IS-IS neighbor on the interface:

Step 1 configure

Enter global configuration mode.

Step 2 interface {vlanvid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port
| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}
Enter interface configuration mode.

Step 3 isis three-way-handshake

no isis three-way-handshake

Configure the three-way handshake mechanism of the IS-IS neighbor on the interface. By default, IS-IS neighbor establishment is a two-way handshake mechanism. Two-way handshakes have the problem of one-way neighbor establishment. It is recommended to use the three-way handshake mechanism. To restore the default configuration, please use the no isis three-way-handshake command.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the IS-IS three-way handshake neighbor establishment mechanism on interface VLAN 1:

Switch#configure

Switch(config)#vlan 1

Switch(config-if)#isis three-way-handshake

Switch(config)#end

Switch#copy running-config startup-config

11.1.32 Viewing IS-IS Database

Follow these steps to view the IS-IS database information:

Step 1 show isis database [

lsp-id | detail ]

Isp-id: Specify the LSP ID to query.

detail: View detailed information.

The following example shows how to view the brief information of IS-IS database:

Switch#show isis database

Area 1:

IS-IS Level-1 link-state database:

LSP ID

PduLen SeqNumber Chksum Holdtime ATT/P/OL

0000.0000.0001.00-00 *

68 0x00000052 0xfce2 1158 0/0/0

1 LSPs

IS-IS Level-2 link-state database:

LSP ID

PduLen SeqNumber Chksum Holdtime ATT/P/OL

0000.0000.0001.00-00 *

49 0x00000052 0x9b51 1138

0/0/0

1 LSPs

11.1.33 Viewing IS-IS Host Name

Follow these steps to view the IS-IS host name mapping information:

Step 1 show isis hostname

The following example shows how to view the IS-IS host name mapping information:

Switch#show isis hostname

vrf : default

Level System ID Dynamic Hostname

* 0000.0000.0001 MARVELL_LINUX

11.1.34 Viewing IS-IS Neighbor

Follow these steps to view the IS-IS neighbor information.:

Step 1 show isis neighbor [ system-id | detail ]

system-id: Specify the neighbor's system ID to query.

detail: View detailed information.

The following example shows how to view the brief information of IS-IS neighbor:

Switch#show isis neighbor

Area 1:

System Id Interface L State Holdtime SNPA

0000.0000.0002 Gi1/0/1 1 Up 29 000a.eb00.1318

11.1.35 Viewing IS-IS Routing Info

Follow these steps to view the IS-IS routing information:

Step 1 show isis route

The following example shows how to view the IS-IS routing information:

Switch#show isis route

Area 1:

IS-IS L1 IPv4 routing table:

Prefix Metric Interface Nexthop Label(s)

10.1.1.0/24 0---
20.1.1.0/24 20Gi1/0/110.1.1.1 -
50.1.1.0/24 0---

11.1.36 Viewing IS-IS Summary

Follow these steps to view the IS-IS summary:

Step 1 show isis summary

The following example shows how to view the IS-IS summary:

Switch#show isis summary

vrf : default

Process Id : 2349

System Id : 0000.0000.0001

Up time : 23:29:01 ago

Number of areas : 1

Area 1:

Net: 10.0000.0000.0000.0001.00

TX counters per PDU type:

L1 IIH: 2061

L2 IIH: 2056

LSP RXMT: 0

RX counters per PDU type:

Level-1:

LSP0 regenerated: 82

LSPs purged: 0

SPF:

minimum interval : 1

IPv4 route computation:

last run elapsed : 00:10:17 ago

last run duration : 77 usec

run count : 8

Level-2:

LSP0 regenerated: 82

LSPs purged: 0

SPF:

minimum interval : 1

IPv4 route computation:

last run elapsed : 00:10:17 ago

last run duration : 44 usec

run count : 8

11.1.37 Viewing IS-IS Interface

Follow these steps to view the IS-IS interface information:

Step 1

show isis interface [fastEthernet | gigabitEthernet | hundred-gigabitEthernet | loopback | port-channel | ten-gigabitEthernet | twentyFive-gigabitEthernet | two-gigabitEthernet | vlan] [detail]

The following example shows how to view the IS-IS interface information:

Switch#show isis interface

IS-IS 1:

Interface

Circld

State

Type

Level

Gi1/0/11

0xf0

Up

lan

L1

12 URPF Configurations

TP-LINK Omada Pro S5500-24GP4F - URPF Configurations - 1

Note:

URPF is only available on Omada Pro L3 Stackable Switches.

Unicast Reverse Path Forwarding (URPF) aims to prevent network attacks based on source IP address spoofing. To safeguard against forged IP packet attacks on the network, at the network ingress point, the origin of IP packets is verified. If the source is suspicious, the packet is dropped directly; if it passes the URPF check, the IP packet is allowed to enter.

12.1 Using the CLI

12.1.1 Enabling URPF

Follow these steps to enable the URPF feature.

Step 1 configure

Enter global configuration mode.

Step 2 urpf { enable| disable }

Enable or disable the URPF feature. When enabled, it retrieves the previously configured filtering mode for security checks. If no mode was previously configured, it performs security checks based on the default strict-vlan filtering mode. Disabling the URPF feature will not modify the set filtering mode for when URPF was disabled.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable the URPF feature on the switch:

Switch#configure

Switch(config)#urpf enable

Switch(config)#end

Switch#copy running-config startup-config

12.1.2 Configuring URPF Filter Mode

Follow these steps to configure the URPF filter mode.

Step 1 configure

Enter global configuration mode.

Step 2 urpf mode { strict-vlan | strict-port | loose }

Configure the URPF filter mode.

strict-vlan: Filter the packets whose IP or VLAN do not meet the requirements

strict-port: Filter the packets whose IP or port do not meet the requirements

loose: Filter the packets whose IP does not meet the requirements

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the URPF filter mode to strict-vlan:

Switch#configure

Switch(config)#urpf mode strict-vlan

Switch(config)#end

Switch#copy running-config startup-config

13 Tunnel Configurations

TP-LINK Omada Pro S5500-24GP4F - Tunnel Configurations - 1

Note:

Tunnel configurations are only available on Omada Pro L3 Stackable Switches.

Tunnel is an encapsulation technique that uses one network protocol to transport another network protocol. It encapsulates data packets generated by another protocol within its own packets, enabling the transmission of IPv6 packets over an IPv4 network and facilitating interconnection between IPv6 networks. A tunnel represents a virtual point-to-point connection where it provides a channel for the transmission of encapsulated data packets, allowing for encapsulation and decapsulation of data packets at both ends of the tunnel.

13.1 Using the CLI

13.1.1 Creating Tunnel Interface

Follow these steps to create a tunnel interface:

Step 1 configure

Enter global configuration mode.

Step 2 interface tunnel

tunnel-number

no interface tunnel tunnel-number

Create a tunnel interface. Only after a tunnel interface is created can different tunnel-related parameters be configured in the interface view. To delete all configurations of the tunnel interface, please use the no interface tunnel command.

tunnel-number: Tunnel interface number, a positive integer ranging from 1 to 100.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to create a tunnel interface1:

Switch#configure

Switch(config)#interface tunnel 1

Switch(config-tunnel)#end

Switch#copy running-config startup-config

13.1.2 Specifying Tunnel Mode

Follow these steps to specify the tunnel mode:

Step 1 configure

Enter global configuration mode.

Step 2 interface tunnel

tunnel-number

Create a tunnel interface and enter the tunnel configuration mode.

Step 3 tunnel mode

mode-type

no tunnel mode

Specify the tunnel mode. The tunnel will encapsulate different protocol headers for passenger messages according to different tunnel types. To delete the type of the tunnel interface, please use the no tunnel mode command.

mode-type: Tunnel protocol type, currently three manual tunnel types are supported: IPv6IP, GRE IPv4-IPv4, GRE IPv6-IPv4.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to specify Tunnel as IPv6IP manual tunnel:

Switch#configure

Switch(config)#interface tunnel 1

Switch(config-tunnel)#tunnel mode ipv6ip

Switch(config)#end

Switch#copy running-config startup-config

13.1.3 Specifying Tunnel Source

Follow these steps to specify the source address or source interface of the tunnel:

Step 1 configure

Enter global configuration mode.

Step 2 interface tunnel

tunnel-number

Create a tunnel interface and enter the tunnel configuration mode.

Step 3 tunnel source

{ip | interface interface-type interface-number | vlan-if}

no tunnel source

Specify the source address or source interface of the tunnel. To delete the source address or source interface of the tunnel, use the no tunnel source command.

ip: Tunnel source IPv4 address.

interface interface-type interface-number: Tunnel source interface.

vlan-if: Tunnel source VLAN type interface.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to specify the source address of the tunnel as 192.168.1.0:

Switch#configure

Switch(config)#interface tunnel 1

Switch(config-tunnel)#tunnel source ip address 192.168.1.0

Switch(config)#end

Switch#copy running-config startup-config

13.1.4 Specifying Tunnel Destination

Follow these steps to specify the destination address of the tunnel:

Step 1 configure

Enter global configuration mode.

Step 2 interface tunnel

tunnel-number

Create a tunnel interface and enter the tunnel configuration mode.

Step 3 tunnel destination ip address

ipv4-address

no tunnel destination

Specify the destination address of the tunnel. To delete the destination address of the tunnel, please use the no tunnel destination command.

ipv4-address: Tunnel destination IPv4 address.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to specify the destination address of the tunnel as 192.168.2.0:

Switch#configure

Switch(config)#interface tunnel 1

Switch(config-tunnel)#tunnel destination ip address 192.168.2.0

Switch(config)#end

Switch#copy running-config startup-config

13.1.5 Configuring TTL

Follow these steps to configure the time-to-live (TTL) value of the encapsulated external protocol header:

Step 1 configure

Enter global configuration mode.

Step 2 interface tunnel

tunnel-number

Create a tunnel interface and enter the tunnel configuration mode.

Step 3 tunnel ttl

ttl-number

no tunnel ttl

Configure the TTL value of the encapsulated outer protocol header. It is 0 by default, indicating that the TTL of the external protocol header matches that of the inner passenger packet. To delete the TTL configuration and restore it to the default value of 0, please use the no tunnel ttl command.

ttl-number: The TTL value of the external protocol header of the tunnel encapsulation, ranging from 1 to 255. The default value is 0, which means it is consistent with the TTL of the passenger message.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the tunnel TTL to 110:

Switch#configure

Switch(config)#interface tunnel 1

Switch(config-tunnel)#tunnel tti 110

Switch(config)#end

Switch#copy running-config startup-config

13.1.6 Specify Interface IP Address

Follow these steps to specify the interface IP address of the tunnel:

Step 1 configure

Enter global configuration mode.

Step 2 interface tunnel

tunnel-number

Create a tunnel interface and enter the tunnel configuration mode.

Step 3 ip address

ip-address/ipv6 address ipv6-address

no ip address

Specify the interface IP address of the tunnel. GRE IPv4-IPv4 tunnels need to be configured with an IPv4 address, and IPv6IP and GRE IPV6-IPv4 tunnels need to be configured with an IPv6 address. To delete the IP address of the tunnel, please use the no ip address command.

ip-address: IPv4 address of the tunnel interface.

ipv6-address: IPv6 address of the tunnel interface.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example specifies the interface IP address of the GRE IPv4-IPv4 tunnel as 10.1.1.1:

Switch#configure

Switch(config)#interface tunnel 1

Switch(config-tunnel)#ip address 10.1.1.1

Switch(config)#end

Switch#copy running-config startup-config

13.1.7 Disabling Tunnel Encapsulation

Follow these steps to disable the tunnel interface encapsulation and decapsulation functions:

Step 1 configure

Enter global configuration mode.

Step 2interface tunneltunnel-number
Create a tunnel interface and enter the tunnel configuration mode.
Step 3shutdown
no shutdown
Disable the tunnel interface encapsulation and decapsulation functions. To enable the functions, please use theno shutdowncommand.
Step 4end
Return to privileged EXEC mode.
Step 5copy running-config startup-config
Save the settings in the configuration file.

The following example shows how to disable the tunnel interface encapsulation and decapsulation functions:

Switch#configure

Switch(config)#interface tunnel 1

Switch(config-tunnel)#shutdown

Switch(config)#end

Switch#copy running-config startup-config

13.1.8 Configuring IPv4 Tunnel Route

Follow these steps to configure a static route for IPv4 packets to point to the tunnel:

Step 1configureEnter global configuration mode.
Step 2ip routeip-address mask tunnel tunnel-numberno ip route ip-address mask tunnel tunnel-numberConfigure a static route for IPv4 packets to point to a tunnel, so that IPv4 packets can enter the tunnel (including only GRE IPv4-IPv4 type tunnels). To delete the static route configuration, please use theno command.ip-address: IP address of the static route.mask: Mask of the static route.tunnel-number: Tunnel interface to which the static route points
Step 3endReturn to privileged EXEC mode.
Step 4copy running-config startup-configSave the settings in the configuration file.

The following example shows how to configure the IPv4 static route to point to tunnel interface 1:

Switch#configure

Switch(config)#ip route 192.168.2.0 255.255.255.0 tunnel 1

Switch(config)#end

Switch#copy running-config startup-config

13.1.9 Configuring IPv6 Tunnel Route

Follow these steps to configure a static route for IPv6 packets to point to the tunnel:

Step 1 configure

Enter global configuration mode.

Step 2 ipv6 route

ipv6-dest-address tunnel tunnel-number

no ipv6 route ipv6-dest-address tunnel tunnel-number

Configure a static route for IPv6 packets to point to a tunnel, so that IPv6 packets can enter the tunnel (including only IPv6IP and GRE IPv6-IPv4 type tunnels). To delete the static route configuration, please use the no command.

ipv6-dest-address: Specify the destination IPv6 address of the packets, in the format of X:X:X:X::X/<0-128>.

tunnel-number: Tunnel interface to which the static route points

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the IPv6 static route to point to tunnel interface 1:

Switch#configure

Switch(config)#ipv6 route fc00:2::/64 tunnel 1

Switch(config)#end

Switch#copy running-config startup-config

13.1.10 Viewing Tunnel Interface

Follow these steps to view the configuration information of the tunnel interface:

Step 1 show interface tunnel {

tunnel-number | all }

The following example shows how to view the configuration information of the tunnel interface 1:

Switch#show interface tunnel 1

tunnelNum: 1

tunnelEnable: enable

tunnelStatus: not active,

ttl: 110

tunnelMode: ipv6 over ipv4 manual

src interface: Gi1/0/1

dstlp: 192.168.1.1

nextHop to Tunnel: 3001::1/64

14 Example for Static Routing

14.1 Network Requirements

As shown below, Host A and Host B are on different network segments. To meet business needs, Host A and Host B need to establish a connection without using dynamic routing protocols to ensure stable connectivity.

Figure 14-1 Network Topologygraph LR A["Host A\n0.1.1.100/24"] -->|Gi1/0/1\n10.1.1.1/24| B["Switch A Switch B"] B -->|Gi1/0/2\n10.1.10.1/24| C["Switch A Switch B"] C -->|Gi1/0/1\n10.1.10.2/24| D["Switch A Switch B"] D -->|Gi1/0/2\n10.1.2.1/24| E["Host B\n10.1.2.100/24"]

14.2 Configuration Scheme

To implement this requirement, you can configure the default gateway of host A as 10.1.1.1/24, the default gateway of host B as 10.1.2.1/24, and configure IPv4 static routes on Switch A and Switch B so that hosts on different network segments can communicate with each other.

Demonstrated with S6500-24GP4XF, the following sections provide configuration procedure in two ways: using the GUI and using the CLI.

14.3 Using the GUI

The configurations of Switch A and Switch B are similar. The following introductions take Switch A as an example.

1) Choose the menu L3 FEATURES > Interface to create a routed port Gi1/0/1 with the mode as static, the IP address as 10.1.1.1, the mask as 255.255.255.0 and the admin status as Enable. Create a routed port Gi1/0/2 with the mode as static, the IP address as 10.1.10.1, the mask as 255.255.255.0 and the admin status as Enable.

Figure 14-2 Create a Routed Port Gi1/0/1 for Switch AInterface Interface ID: Routed Port 1/0/1 (Format: 1/0/1) UNIT1 2 4 6 8 10 12 14 16 18 20 22 24 26 28 1 3 5 7 9 11 13 15 17 19 21 23 25 27 IP Address Mode: None Static DHCP BOOTP IP Address: 10.1.1.1 (Format: 192.168.0.1) Subnet Mask: 255.255.255.0 (Format: 255.255.255.0) Admin Status: Enable Interf…

Figure 14-3 Create a Routed Port Gi1/0/2 for Switch A

Interface Interface ID: Routed Port 1/0/2 (Format: 1/0/1) UNIT1 IP Address Mode: None Static DHCP BOOTP IP Address: 10.1.10.1 (Format: 192.168.0.1) Subnet Mask: 255.255.255.0 (Format: 255.255.255.0) Admin Status: Enable Interface Name: (Optional. 1-16 characters) Cancel Create

2) Choose the menu L3 FEATURES > Static Routing > IPv4 Static Routing to load the following page. Add a static routing entry with the destination as 10.1.2.0, the subnet

mask as 255.255.255.0 and the next hop as 10.1.10.2. For switch B, add a static route entry with the destination as 10.1.1.0, the subnet mask as 255.255.255.0 and the next hop as 10.1.10.1.

Figure 14-4 Add a Static Route for Switch AIPv4 Static Routing Destination: 10.1.2.0 (Format: 10.10.10.0) Subnet Mask: 255.255.255.0 (Format: 255.255.255.0) Next Hop: 10.1.10.2 (Format: 192.168.0.2) Distance: (Optional range: 1-255) Cancel Create

14.4 Using the CLI

The configurations of Switch A and Switch B are similar. The following introductions take Switch A as an example.

1) Create a routed port Gi1/0/1 with the mode as static, the IP address as 10.1.1.1, the mask as 255.255.255.0 and the admin status as Enable. Create a routed port Gi1/0/2 with the mode as static, the IP address as 10.1.10.1, the mask as 255.255.255.0 and the admin status as Enable.

Switch_A#configure

Switch_A(config)#interface gigabitEthernet 1/0/1

Switch_A(config-if)#no switchport

Switch_A(config-if)#ip address 10.1.1.1 255.255.255.0

Switch_A(config-if)#exit

Switch_A(config)#interface gigabitEthernet 1/0/2

Switch_A(config-if)#no switchport

Switch_A(config-if)#ip address 10.1.10.1 255.255.255.0

2) Add a static route entry with the destination as 10.1.2.0, the subnet mask as 255.255.255.0 and the next hop as 10.1.10.2. For switch B, add a static route entry with the destination as 10.1.1.0, the subnet mask as 255.255.255.0 and the next hop as 10.1.10.1.

Switch_A#configure

Switch_A(config)#ip route 10.1.2.0 255.255.255.0 10.1.10.2

Switch_A(config)#end

Switch_A#copy running-config startup-config

Verify the Configurations

Switch A

Verify the static routing configuration:

Switch_A#show ip route

Codes: C - connected, S - static

* - candidate default

C 10.1.1.0/24 is directly connected, Vlan10

C 10.1.10.0/24 is directly connected, Vlan20

S 10.1.2.0/24 [1/0] via 10.1.10.2, Vlan20

Switch B

Verify the static routing configuration:

Switch_B#show ip route

Codes: C - connected, S - static

* - candidate default

C 10.1.2.0/24 is directly connected, Vlan30

C 10.1.10.0/24 is directly connected, Vlan20

S 10.1.1.0/24 [1/0] via 10.1.10.1, Vlan20

Connectivity Between Switch A and Switch B

Run the ping command on switch A to verify the connectivity:

Switch_A#ping 10.1.2.1

Pinging 10.1.2.1 with 64 bytes of data:

Reply from 10.1.2.1: bytes=64 time<16ms TTL=64

Reply from 10.1.2.1: bytes=64 time<16ms TTL=64

Reply from 10.1.2.1: bytes=64 time<16ms TTL=64

Reply from 10.1.2.1: bytes=64 time<16ms TTL=64

Ping statistics for 10.1.2.1:

Packets: Sent = 4, Received = 4, Lost = 0 (0% loss)

Approximate round trip times in milli-seconds:

Minimum = 1ms, Maximum = 3ms, Average = 1ms

Part 21

Configuring DHCP Service

CHAPTERS

  1. DHCP
  2. DHCP Server Configuration
  3. DHCP Relay Configuration
  4. DHCP Relay Configuration
  5. DHCP L2 Relay Configuration
  6. DHCP L2 Relay Configuration
  7. Configuration Examples
  8. Appendix: Default Parameters

1 DHCP

1.1 Overview

DHCP (Dynamic Host Configuration Protocol) is widely used to dynamically assign IP addresses and other parameters to clients in the LAN, enhancing the utilization of IP address.

1.2 Supported Features

The supported DHCP features of the switch include DHCP Server, DHCP Relay, and DHCP L2 Relay.

DHCP Server

DHCP Server is used to dynamically assign IP addresses, default gateway, and other parameters to DHCP clients. As the following figure shows, the switch acts as a DHCP server and assigns IP addresses to the clients.

Figure 1-1 Application Scenario of DHCP Servergraph LR A["Switch DHCP Server"] --> B["DHCP Clients"] B --> C["Four Laptops"] C --> D["Dotted Lines"]

DHCP Relay

DHCP Relay is used to process and forward DHCP packets between different subnets or VLANs.

DHCP clients broadcast DHCP request packets to require IP addresses. Without this function, clients cannot obtain IP addresses from a DHCP server in a different LAN because the broadcast packets can be transmitted only in the same LAN. To equip each LAN with a DHCP server can solve this problem, but the costs of network construction will be increased and the management of the central network will become inconvenient.

A device with DHCP Relay function is a better choice. It acts as a relay agent and can forward DHCP packets between DHCP clients and DHCP servers in different LANs. Therefore, DHCP clients in different LANs can share one DHCP server.

DHCP Relay includes three features: Option 82, DHCP Interface Relay, and DHCP VLAN Relay.

Option 82

Option 82 is called the DHCP Relay Agent Information Option. It provides additional security and a more flexible way to allocate network addresses compared with traditional DHCP.

When enabled, the DHCP relay agent can inform the DHCP server of some specified information of clients by inserting an Option 82 payload into DHCP request packets before forwarding them to the DHCP server, so that the DHCP server can distribute the IP addresses or other parameters to clients based on the payload. In this way, Option 82 prevents DHCP client requests from untrusted sources. Besides, it allows the DHCP server to assign IP addresses of different address pools to clients in different groups.

An Option 82 has two sub-options, namely, the Agent Circuit ID and Agent Remote ID. The information that the two sub-options carry depends on the settings of the DHCP relay agent, and are different among devices from different vendors. To allocate network addresses using Option 82, you need to define the two sub-options on the DHCP relay agent, and create a DHCP class on the DHCP server to identify the Option 82 payload.

TP-Link switches preset a default circuit ID and remote ID in TLV (Type, Length, and Value) format. You can also configure the format to include Value only and customize the Value.

Table 1-1 and Table 1-2 show the packet formats of the Agent Circuit ID and Agent Remote ID, respectively.

Table 1-1 Packet Formats of the Agent Circuit ID with Different Option 82 Settings

Option 82 Settings*Type (Hex)*Length (Hex) *Value
*FormatCircuit ID Customization
Normal (TLV)Disabled 00 04 Default circuit ID
Enabled 01 Length of the customized circuit ID Customized circuit ID
Private (Only the value)Disabled -- Default circuit ID
Enabled -- Customized circuit ID

Table 1-2 Packet Formats of the Agent Remote ID with Different Option 82 Settings

Option 82 Settings*Type (Hex)*Length (Hex) *Value
*FormatRemote ID Customization
Normal (TLV)Disabled 00 06Default remote ID
Enabled 01 Length of the customized remote IDCustomized remote ID
Private (Only the value)Disabled --Default remote ID
Enabled --Customized remote ID

*Format

Indicates the packet format of the sub-option field. Two options are available:

■ Normal: Indicates the field consists of three parts: Type, Length, and Value (TLV). ■ Private: Indicates the field consists of the value only.

*Type

A one-byte field indicating whether the Value field is customized or not. 00 in hexadecimal means the Value field is not customized (uses the default circuit/remote ID) while 01 in hexadecimal means it is customized.

*Length

A one-byte field indicating the length of the Value field. The length of the default circuit ID is 4 bytes and that of default remote ID is 6 bytes. For the customized circuit ID and remote ID, the length is variable, ranging from 1 to 64 bytes.

*Value

Indicates the value of the sub-option. The switch has preset a default circuit ID and remote ID. You can also customize them with Circuit ID Customization and Remote ID Customization enabled.

■ Default circuit ID: A 4-byte value which consists of 2-byte VLAN ID and 2-byte Port ID. The VLAN ID indicates which VLAN the DHCP client belongs to, and the Port ID indicates which port the DHCP client is connected to. For example, if the DHCP client is connected to port 1/0/1 in VLAN 2, this field is 00:02:00:01 in hexadecimal. ■ Default remote ID: A 6-byte value which indicates the MAC address of the DHCP relay agent. - Customized circuit/remote ID: You can configure a string using up to 64 characters. The switch encodes the string using ASCII. When configuring your DHCP server to identify the string, use the correct notation that is used by your DHCP server to represent ASCII strings, or convert it into hexadecimal format if necessary.

Tips:

As shown in Table 1-1 and Table 1-2, by default, the circuit ID records the ports of the DHCP relay agent that are connected to the clients and the VLANs that the clients belong to, and the remote ID records the MAC address of the DHCP relay agent. That is, the two sub-options together record the location of the clients. To record the accurate location of clients, configure Option 82 on the switch which is closest to the clients.

■ DHCP Interface Relay

DHCP Interface Relay allows clients to obtain IP addresses from a DHCP server in a different LAN. In DHCP Interface Relay, you can specify a DHCP server for the Layer 3 interface that the clients are connected to. When receiving DHCP packets from clients, the switch fills the corresponding interface's IP address in the Relay Agent IP Address field of the DHCP packets, and forwards the packets to the DHCP server. Then the DHCP server

can assign IP addresses that are in the same subnet with the Relay Agent IP Address to the clients.

The switch supports specifying a DHCP server for multiple Layer 3 interfaces, which makes it possible to assign IP addresses to clients in different subnets from the same DHCP server.

As the following figure shows, the IP address of VLAN 20 is 192.168.2.1/24 and that of the routed port Gi1/0/1 is 192.168.3.1/24. With DHCP Interface VLAN configured, the switch fills in the Relay Agent IP Address field of the DHCP packets with the IP address of VLAN 20 (192.168.2.1/24) when applying for IP addresses for clients in VLAN 20, and fills with the IP address of Gi1/0/1 (192.168.3.1/24) when applying for an IP address for PC 1. As a result, the DHCP server will assign IP addresses in Pool A (the same subnet with the IP address of VLAN 20) to clients in VLAN 20, and assign an IP address in Pool B (the same subnet with the Gi1/0/1) to PC 1.

Figure 1-2 Application Scenario of DHCP Interface Relaygraph TD A["DHCP Clients\nVLAN 20\n192.168.2.0/24"] -->|VLAN 20\n192.168.2.1/24| B["Switch\nDHCP Relay"] C["PC 1\nDHCP Client\n192.168.3.2/24"] -->|Gi1/0/1\nRouted Port\n192.168.3.1/24| B D["DHCP Server\nPool A:192.168.2.0/24\nPool B:192.168.3.0/24"] --> B

DHCP VLAN Relay

DHCP VLAN Relay allows clients in different VLANs to obtain IP addresses from the DHCP server using the IP address of a single agent interface.

In DHCP Interface Relay, to achieve this goal, you need to create a Layer 3 interface for each VLAN to ensure the reachability.

In DHCP VLAN Relay, you can simply specify a Layer 3 interface as the default agent interface for all VLANs. The switch fills this default agent interface's IP address in the Relay Agent IP Address field of the DHCP packets from all VLANs.

As the following figure shows, no IP addresses are assigned to VLAN 10 and VLAN 20, but a default relay agent interface is configured with the IP address 192.168.2.1/24. The switch fills in the Relay Agent IP Address field of the DHCP packets with the IP address of the default agent interface (192.168.2.1/24) when applying for IP addresses for clients in both VLAN 10 and VLAN 20. As a result, the DHCP server will assign IP addresses on 192.168.2.0/24 (the same subnet with the IP address of the default agent interface) to clients in both VLAN 10 and VLAN 20.

Figure 1-3 Application Scenario of DHCP VLAN Relaygraph TD A["DHCP Server"] --> B["DHCP Relay"] B --> C["DHCP Clients VLAN 10 192.168.2.0/24"] B --> D["DHCP Clients VLAN 20 192.168.2.0/24"] B --> E["Default Agent Interface: 192.168.2.1/24"]

TP-LINK Omada Pro S5500-24GP4F - DHCP VLAN Relay - 2

Note:

  • If the VLAN already has an IP address, the switch will use the IP address of the VLAN as the relay agent IP address. The default relay agent IP address will not take effect.
  • DHCP VLAN Relay will not work on routed ports or port channel interfaces, because they are not associated with any particular VLAN.

DHCP L2 Relay

Unlike DHCP relay, DHCP L2 Relay is used in the situation that the DHCP server and clients are in the same VLAN. In DHCP L2 Relay, in addition to normally assigning IP addresses to clients from the DHCP server, the switch can inform the DHCP server of some specified information, such as the location information, of clients by inserting an Option 82 payload to DHCP request packets before forwarding them to the DHCP server. This allows the DHCP server which supports Option 82 can set the distribution policy of IP addresses and other parameters, providing a more flexible way to distribute IP addresses.

Figure 1-4 Application Scenario of DHCP L2 Relaygraph TD A["DHCP Server"] --> B["VLAN 1"] B --> C["Switch DHCP L2 Relay"] C --> D["DHCP Clients"] style A fill:#333,stroke:#fff,color:#fff style B fill:#999,stroke:#000,color:#fff style C fill:#ccc,stroke:#000,color:#fff style D fill:#999,stroke:#000,color:#fff

2

DHCP Server Configuration

To complete DHCP server configuration, follow these steps:

1) Enable DHCP Server globally on the switch. 2) Configure DHCP Server Pool. 3) (Optional) Manually assign static IP addresses for some clients.

2.1 Using the GUI

2.1.1 Enabling DHCP Server

Choose the menu L3 FEATURES > DHCP Service > DHCP Server > DHCP Server to load the following page.

Figure 2-1 Configure DHCP ServerDHCP Server Pool Setting Manual Binding DHCP Pool Options DHCP Client List Packet Statistics Global Config DHCP Server: Enable Option 60: (Optional. 1-64 characters) Option 138: (Optional. Format:192.168.0.1) Ping Time Config Ping Packets: 1 (0-10 packets, 0 for disabling ping) Ping Timeout: 100 (10…

Follow these steps to configure DHCP Server:

1) In the Global Config section, enable DHCP Server. Click Apply.

DHCP Server Enable or disable DHCP Server. By default, it is disabled.

Option 60(Optional) Configure Option 60 for device identification. Mostly it is used under the scenario where the APs (Access Points) apply for different IP addresses from different servers according to their needs.If an AP requests option 60, the server will respond by sending a packet containing the Option 60 configured here. The AP will compare the received Option 60 with its own. If they are the same, the AP will accept the IP address assigned by the server, otherwise the assigned IP address will not be accepted.
Option 138 (Optional) Specify Option 138, which can be configured as the management IP address of an AC (Access Control) device. If the APs in the local network request this option, the server will respond by sending a packet containing this option to inform the APs of the AC's IP address.

2) In the Ping Time Config section, configure Ping Packets and Ping Timeout for ping tests. Click Apply.

Ping PacketsSpecify the number of ping packets the server can broadcast to test whether the IP address is occupied. The valid values are from 1 to 10, and the default is 1.When the switch is configured as a DHCP server to dynamically assign IP addresses to clients, the switch will ping test to avoid IP address conflict resulting from assigning IP addresses repeatedly.
Ping TimeoutSpecify the ping timeout period in milliseconds. It ranges from 100 to 10000 ms and the default is 100 ms.The DHCP server broadcasts an ICMP Echo Request (ping packet) to test whether an IP address is occupied or not. If there is no response within the ping timeout period, the server will broadcast the ping packet again. If the number of ping packets reaches the specified number and there is still no response, the server will assign the IP address. Otherwise, the server will record the IP address as a conflicted IP address and assign another IP address to the client.

3) In the Excluded IP Address Config section, click + Add to load the following page to specify the IP addresses that should not be assigned to the clients.

Figure 2-2 Configure Excluded IP AddressExcluded IP Address Starting IP Address: (Format: 192.168.0.10) Ending IP Address: (Format: 192.168.0.10) Cancel Create

Enter the Starting IP Address and Ending IP Address to specify the range of reserved IP addresses. Click Create.

Starting IP Address/ Ending IP Address

Specify the starting IP address and ending IP address of the excluded IP address range. If the starting IP address and the ending IP address are the same, the server excludes only one IP address.

Specify the starting IP address and ending IP address of the excluded IP address range. If the starting IP address and the ending IP address are the same, the server excludes only one IP address.

When configuring DHCP Server, you need to reserve certain IP addresses for each subnet, such as default gateway address, broadcast address and DNS server address.

DHCP Server Pool defines the parameters that will be assigned to DHCP clients.

DHCP Server Pool defines the parameters that will be assigned to DHCP clients.

Choose the menu L3 FEATURES > DHCP Service > DHCP Server > Pool Setting and click

TP-LINK Omada Pro S5500-24GP4F - DHCP Server Pool defines the parameters that will be assigned to DHCP clients. - 1

TP-LINK Omada Pro S5500-24GP4F - DHCP Server Pool defines the parameters that will be assigned to DHCP clients. - 2

TP-LINK Omada Pro S5500-24GP4F - DHCP Server Pool defines the parameters that will be assigned to DHCP clients. - 3

TP-LINK Omada Pro S5500-24GP4F - DHCP Server Pool defines the parameters that will be assigned to DHCP clients. - 4

TP-LINK Omada Pro S5500-24GP4F - DHCP Server Pool defines the parameters that will be assigned to DHCP clients. - 5

TP-LINK Omada Pro S5500-24GP4F - DHCP Server Pool defines the parameters that will be assigned to DHCP clients. - 6

TP-LINK Omada Pro S5500-24GP4F - DHCP Server Pool defines the parameters that will be assigned to DHCP clients. - 7

TP-LINK Omada Pro S5500-24GP4F - DHCP Server Pool defines the parameters that will be assigned to DHCP clients. - 8

TP-LINK Omada Pro S5500-24GP4F - DHCP Server Pool defines the parameters that will be assigned to DHCP clients. - 9

TP-LINK Omada Pro S5500-24GP4F - DHCP Server Pool defines the parameters that will be assigned to DHCP clients. - 10

DHCP Server PoolTP-LINK Omada Pro S5500-24GP4F - DHCP Server Pool defines the parameters that will be assigned to DHCP clients. - 11

Pool Name:

Network Address:

Subnet Mask

Subnet Mask

Lease Time:

Default Gateway:

DNS Server:

NetBIOS Server:

NetBIOS Node Type:

Next Server Address:

Domain Name:

Bootfile:

TP-LINK Omada Pro S5500-24GP4F - Pool Name: - 1

(8 characters maximum)

(Format: 192.168.0.0)

(Format: 255.255.255.0)

(Optional. 1-2880 min, Default: 120)

(Optional, Format: 192.168.0.1)

(Optional. Format: 192.168.0.1)

(Optional. Format: 192.168.0.1)

(Optional, b/p/m/h/none)

(Optional. Format: 192.168.0.1)

(0 to 200 characters)

(0 to 128 characters)

Cancel

Create

Configure the parameters for DHCP Server Pool. Then click Create.

Pool Name Specify a name for the pool.

Network Address /

Subnet Mask

Configure the network address and subnet mask of the IP pool.

The network address and subnet mask decide the range of the pool. In the same subnet, all the addresses can be assigned except the excluded addresses.

Lease Time

Specify how long the client can use the assigned IP address. The value ranges from 1 to 2880 minutes and the default value is 120 minutes.

Default GatewayConfigure the default gateway of the DHCP server pool. You can create up to 8 default gateways for each DHCP server pool.Generally, you can configure the IP address of the VLAN interface as the default gateway address.
DNS Server Specify the DNS server of the DHCP server pool. You can specify up to 8 DNS servers for each DHCP server pool.Generally, you can configure the IP address of the VLAN interface as the DNS server address.
NetBIOS ServerSpecify the NetBIOS name server. You can specify up to 8 NetBIOS servers for each DHCP server pool.When a DHCP client uses the Network NetBIOS (Basic Input Output System) protocol for communication, the host name must be mapped to IP address. NetBIOS name server can resolve host names to IP addresses.
NetBIOS Node TypeSpecify the Netbios type for the clients, which is the way of inquiring IP address resolution. The following options are provided:b-node Broadcast: The client sends query message via broadcast.p-node Peer-to-Peer: The client sends query message via unicast.m-node Mixed: The client sends query message via broadcast first. If it fails, the client will try again via unicast.h-node Hybrid: The client sends query message via unicast first. If it fails, the client will try again via broadcast.
Next Server AddressSpecify the IP address of a TFTP server for the clients. If needed, the clients can get the configuration file from the TFTP server for auto installation.
Domain NameSpecify the domain name that the clients should use when resolving host names via DNS.
BootfileSpecify the name of the bootfile. If needed, the clients can get the bootfile from the TFTP server for auto installation.

2.1.3 Configuring Manual Binding

Some devices like web servers require static IP addresses. To meet this requirement, you can bind an IP address in the pool with a specified client. The server will then assign the bound IP address to the client on receiving the client's request.

Choose the menu L3 FEATURES > DHCP Service > DHCP Server > Manual Binding and click + Add to load the following page.

Figure 2-4 Manual BindingManual Binding Pool Name: IP Address: Binding Mode: Client ID Client ID: (Format: 192.168.0.1) (Even number of characters, 4-200 length, in Hexadecimal) Cancel Create

Select a pool name and enter the IP address to be bound. Select a binding mode and finish the configuration accordingly. Click Create.

Pool Name Select an IP pool from the drop-down box.
IP Address Enter the IP address to be bound to the client.
Binding Mode Select a binding mode:
Client ID: Bind the IP address to the client ID.
Client ID in ASCII: Bind the IP address to the client ID in ASCII format.
Hardware Address: Bind the IP address to the MAC address of the client.
Client IDIf you select Client ID or Client ID in ASCII as the binding mode, enter the client ID in this field.
Hardware AddressIf you select Hardware Address as the binding mode, enter the MAC address in this field.
Hardware TypeIf you select Hardware Address as the binding mode, select a hardware type. The hardware type includes Ethernet and IEEE 802.

2.2 Using the CLI

2.2.1 Enabling DHCP Server

Follow these steps to enable DHCP Server and to configure ping packets and ping timeout.

Step 1 configure

Enter Global Configuration Mode.

Step 2 service dhcp server

Enable DHCP Server.

Step 3 ip dhcp server extend-option vendor-class-id vendor

(Optional) Specify the Option 60 for server identification. If a client requests Option 60, the server will respond a packet containing the Option 60 configured here. And then the client will compare the received Option 60 with its own. If they are the same, the client will accept the IP address assigned by the server. Otherwise, the assigned IP address will not be accepted.

vendor: Specify the Option 60 with 1 to 64 characters.

Step 4 ip dhcp server extend-option capwap-ac-ip ip-address

(Optional) Specify Option 138, which should be configured as the management IP address of an AC (Access Control) device. If the APs (Access Points) in the local network request this option, the server will respond with a packet containing this option to inform the APs of the AC's IP address.

ip-address: Specify the IP address of the AC device that controls the APs.

Step 5: ip dhcp server ping timeout value

Specify the timeout period for ping tests. The DHCP server broadcasts an ICMP Echo Request (ping packet) to test whether an IP address is occupied or not. If there is no response within the timeout period, the server will broadcast the ping packet again. If the number of ping packets reaches the specified number without response, the server will assign the IP address. Otherwise, the server will record the IP address as a conflicted IP address and assign another IP address to the client.

value: Specify the timeout period for ping tests in milliseconds. It ranges from 100 to 10000 ms, and the default is 100 ms.

Step 6: ip dhcp server ping packets num

Specify the number of ping packets the server can broadcast to test whether the IP address is occupied. When the switch is configured as a DHCP server to dynamically assign IP addresses to clients, the switch will deploy ping tests to avoid IP address conflicts resulted from assigning IP addresses repeatedly.

num: Enter the number of ping packets. The valid values are from 1 to 10, and the default is 1.

Step 7: ip dhcp server exclude-address start-ip-address end-ip-address

Specify the starting IP address and ending IP address of the excluded IP address range. If the starting IP address and the ending IP address are the same, the server excludes only one IP address.

When configuring DHCP Server, you need to reserve certain IP addresses for each subnet, such as default gateway address, broadcast address and DNS server address.

start-ip-address/end-ip-address: Specify the starting IP address and ending IP address.

Step 8: show ip dhcp server status

Verify the DHCP status, including whether it is enabled and the configuration of ping packet number and ping packet timeout.

Step 9: show ip dhcp server extend-option

Verify the configuration of the extended options.

Step 10 show ip dhcp server excluded-address

Verify the configuration of the excluded IP address.

Step 11 end

Return to Privileged EXEC Mode.

Step 12 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable DHCP Server globally on the switch, configure the number of ping packets as 2 and configure the timeout period for ping tests as 200 ms:

Switch#configure

Switch(config)#service dhcp server

Switch(config)#ip dhcp server ping packets 2

Switch(config)#ip dhcp server ping timeout 200

Switch(config)#show ip dhcp server status

DHCP server is enable.

Ping packet number: 2.

Ping packet timeout: 200 milliseconds.

Switch(config)#end

Switch#copy running-config startup-config

The following example shows how to configure the Option 60 as abc and Option 138 as 192.168.0.155:

Switch#configure

Switch(config)#ip dhcp server extend-option vendor-class-id abc

Switch(config)#ip dhcp server extend-option capwap-ac-ip 192.168.0.155

Switch(config)#show ip dhcp server extend-option

Option 60: abc

Option 138: 192.168.0.155

Switch(config)#end

Switch#copy running-config startup-config

The following example shows how to configure the 192.168.1.1 as the default gateway address and excluded IP address:

Switch#configure

Switch(config)#ip dhcp server excluded-address 192.168.1.1 192.168.1.1

Switch(config)#show ip dhcp server excluded-address

No. Start IP Address End IP Address

......

1 192.168.1.1 192.168.1.1

Switch(config)#end

Switch#copy running-config startup-config

2.2.2 Configuring DHCP Server Pool

Follow these steps to configure DHCP server pool:

Step 1 configure

Enter Global Configuration Mode.

Step 2 ip dhcp server pool

pool-name

Configure a name for the DHCP server pool for identification.

pool-name: Specify a pool name with 1 to 8 characters.

Step 3 network

network-address subnet-mask

Configure the network address and subnet mask of the DHCP server pool.

The network address and subnet mask decide the range of the DHCP server pool. On the same subnet, all addresses can be assigned except the excluded addresses and addresses for special uses.

network-address: Configure the network address of the DHCP server pool.

subnet-mask: Configure the subnet mask of the DHCP server pool.

Step 4 lease

lease-time

Specify how long the client can use the IP address assigned from this address pool.

lease-time: Enter the value of lease-time. It ranges from 1 to 2880 minutes, and the default is 120 minutes.

Step 5 default-gateway

gateway-list

(Optional) Configure the default gateway of the DHCP server pool. In general, you can configure the IP address of the VLAN interface as the default gateway address.

gateway-list: Specify the IP address of the default gateway. You can create up to 8 default gateways for each DHCP server pool.

Step 6 dns-server

dns-server-list

(Optional) Specify the DNS server of the DHCP server pool. In general, you can configure the IP address of the VLAN interface as the DNS server address.

dns-server-list: Specify the IP address of the DNS server. You can specify up to 8 DNS servers for each DHCP server pool.

Step 7 netbios-name-server

NBNS-list

(Optional) Specify the NetBIOS name server. You can specify up to 8 NetBIOS servers for each DHCP server pool.

When a DHCP client uses the Network NetBIOS (Basic Input Output System) protocol for communication, the host name must be mapped to IP address. NetBIOS name server can resolve host names to IP addresses.

NBNS-list: Specify the IP address of the NetBIOS server. You can specify up to 8 NetBIOS servers for each DHCP server pool.

Step 8 netbios-node-type

type

(Optional) Specify the NetBIOS type for the clients, which is the way of inquiring IP address resolution.

type: Specify the NetBIOS type. The following options are provided:

b-node: The client sends query messages via broadcast.

p-node: The client sends query messages via unicast.

m-node: The client sends query messages via broadcast first. If it fails, the client will try again via unicast.

h-node: The client sends query messages via unicast first. If it fails, the client will try again via broadcast.

Step 9 next-server

ip-address

(Optional) Specify the IP address of a TFTP server for the clients. If needed, the clients can get the configuration file from the TFTP server for auto installation.

ip-address: Specify the IP address of the TFTP server.

Step 10 domain-name

domainname

(Optional) Specify the domain name that the clients should use when resolving host names via DNS.

domainname: Specify the domain name with up to 200 characters.

Step 11 bootfile

file-name

(Optional) Specify the name of the bootfile. If needed, the clients can get the bootfile from the TFTP server for auto installation.

file-name: Specify the bootfile name with up to 128 characters.

Step 12 show ip dhcp server pool

Verify the configuration of the DHCP server pool.

Step 13 end

Return to Privileged EXEC Mode.

Step 14 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to create a DHCP server pool with the parameters shown in Table 2-1.

Table 2-1 Parameters for the DHCP Server Pool

Parameter Value
Pool Name pool 1
Network Address 192.168.1.0
Subnet Mask 255.255.255.0
Lease Time 180 minutes
Default Gateway 192.168.1.1
DNS Server 192.168.1.4
NetBIOS Server 192.168.1.19
NetBIOS Node Type B-node (Broadcast)
TFTP server 192.168.1.30
Domain Namecom
Bootfilebootfile

Switch#configure

Switch(config)#ip dhcp server pool pool1

Switch(dhcp-config)#network 192.168.1.0 255.255.255.0

Switch(dhcp-config)#lease 180

Switch(dhcp-config)#default-gateway 192.168.1.1

Switch(dhcp-config)#dns-server 192.168.1.4

Switch(dhcp-config)#netbios-name-server 192.168.1.19

Switch(dhcp-config)#netbios-node-type b-node

Switch(dhcp-config)#next server 192.168.1.30

Switch(dhcp-config)#domain-name com

Switch(dhcp-config)#bootfile bootfile

Switch(dhcp-config)#show ip dhcp server pool

Pool Name: pool1

Network Address: 192.168.1.0

Subnet Mask: 255.255.255.0

Lease Time: 180

Default Gateway: 192.168.1.1

DNS Server: 192.168.1.4

Netbios Server: 192.168.1.19

Netbios Node Type: b-node

Next Server Address: 192.168.1.30

Domain Name: com

Bootfile Name: bootfile

Switch(dhcp-config)#end

Switch#copy running-config startup-config

2.2.3 Configuring Manual Binding

Some hosts, such as WWW servers, require a static IP address. To satisfy this requirement, you can manually bind the MAC address or client ID of the host to an IP address, and the DHCP server will reserve the bound IP address for this host at all times.

Follow these steps to configure Manual Binding:

Step 1 configure

Enter Global Configuration Mode.

Step 2 ip dhcp server pool

name

Create a DHCP server pool and enter DHCP Configuration Mode.

Step 3 Bind an IP address to a client:

address ip-address client-identifier client-id

Bind the specified IP address to the client with a specific hexadecimal client ID.

ip-address: Specify the IP address to be bound.

client-id: Specify the client ID in hexadecimal format.

address ip-address client-identifier client-id ascii

Bind the specified IP address to the client with a specific ASCII client ID.

ip-address: Specify the IP address to be bound.

client-id: Specify the client ID with ASCII characters.

address ip-address hardware-address hardware-address hardware-type { ethernet | ieee802 }

Bind the specified IP address to the client with a specific MAC address.

ip-address: Specify the IP address to be bound.

hardware-address: Enter the MAC address of the client.

ethernet | ieee802: Specify a hardware type for the client, either Ethernet or IEEE802.

Step 4 show ip dhcp server manual-binding

Verify the manual binding configuration.

Step 5 end

Return to Privileged EXEC Mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to bind the IP address 192.168.1.33 in pool1 (on the subnet of 192.168.1.0) to the host with the MAC address 74:D4:68:22:3F:34:

Switch#configure

Switch(config)#ip dhcp server pool pool1

Switch(dhcp-config)#address 192.168.1.33 hardware-address 74:d4:68:22:3f:34 hardware-type ethernet

Switch(dhcp-config)#show ip dhcp server manual-binding

Pool NameClient Id/Hardware AddressIP AddressHardware TypeBind Mode
----------------------------------------
pool174:d4:68:22:3f:34192.168.1.33EthernetMAC Address

Switch(dhcp-config)#end

Switch#copy running-config startup-config

3 DHCP Relay Configuration

To complete DHCP Relay configuration, follow these steps:

1) Enable DHCP Relay. Configure Option 82 if needed. 2) Specify DHCP server for the Interface or VLAN.

3.1 Using the GUI

3.1.1 Enabling DHCP Relay and Configuring Option 82

Choose the menu L3 FEATURES > DHCP Service > DHCP Relay > DHCP Relay Config to load the following page.

Figure 3-1 Enable DHCP Relay and Configure Option 82Global Config DHCP Relay: Enable DHCP Relay Hops: 4 (1-16) DHCP Relay Time Threshold: 0 seconds (0-65535) Apply Option 82 Config UNIT1 LAGS Port Option 82 Option 82 Format Circuit ID Circuit ID Remote ID Remote ID LAG Support Policy Customization Customization Customization 1/0/1 Disabled Keep Norma…

Follow these steps to enable DHCP Relay and configure Option 82:

1) In the Global Config section, enable DHCP Relay globally and configure the relay hops and time threshold. Click Apply.

DHCP Relay Enable or disable DHCP relay globally.
DHCP Relay HopsSpecify the DHCP relay hops. The value ranges from 1 to 16, and the default value is 4.DHCP Relay Hops defines the maximum number of hops (DHCP Relay agent) that the DHCP packets can be relayed. If a packet's hop count is more than the value you set here, the packet will be dropped.
DHCP Relay Time ThresholdSpecify the DHCP relay time threshold. The value ranges from 0 to 65535 seconds.DHCP relay time is the time elapsed since client began address acquisition or renewal process. When the time is greater than the value set here, the DHCP packet will be dropped by the switch. Value 0 means the switch will not examine this field of the DHCP packets.

2) (Optional) In the Option 82 Config section, configure Option 82.

Option 82 SupportEnable or disable the Option 82 feature for the port.
Enable it if you want to prevent DHCP client requests from untrusted sources, or assign different IP addresses to clients in different groups from the same DHCP server.

Option 82 Policy: Select the operation for the Option 82 field of the DHCP request packets. Keep: The switch will not change the Option 82 field of the packets. Replace: The switch will replace the Option 82 field of the packets with the manually defined content. By default, the Circuit ID is filled with the VLAN ID and the port number which receives the DHCP Request packets. The Remote ID is filled with the MAC address of the switch which receives the DHCP Request packets.

Drop: Indicates discarding the packets that include the Option 82 field. Format: Select the format of the Option 82 sub-option value field. Normal: The format of the sub-option value field is TLV (type-length-value). Private: The format of the sub-option value field is just value.

Circuit IDCustomizationEnable or disable the switch to define the Option 82 sub-option Circuit ID field. If it is enabled, you can manually configure the circuit ID; if it is disabled, the switch will automatically configure the VLAN ID and the port number of the port that received the DHCP packets as the circuit ID.
Circuit IDWith Circuit ID Customization enabled, you can manually configure the circuit ID here.
Remote IDCustomizationEnable or disable the switch to define the Option 82 sub-option Remote ID field. If it is enabled, you can manually configure the remote ID; if it is disabled, the switch will automatically configure the switch’s MAC address as the remote ID.

Remote ID

With Remote ID Customization enabled, you can manually configure the remote ID here.

3) Click Apply.

3.1.2 Configuring DHCP Interface Relay

DHCP Interface Relay allows clients to obtain IP addresses from a DHCP server in a different subnet.

Choose the menu L3 FEATURES > DHCP Service > DHCP Relay > DHCP Interface Relay and click + Add to load the following page.

Figure 3-2 Configuring DHCP Interface RelayDHCP Interface Relay Interface ID: VLAN (1-4094) Server Address: (Format: 192.168.0.1) Cancel Create

Select the interface type and enter the interface ID, then enter the IP address of the DHCP server. Click Create.

Interface ID: Select the L3 interface, which is the interface that the clients are connected to.

VLAN: Enter the VLAN ID to specify the VLAN interface.

Routed Port: Enter the port number or click the port icon to specify the routed port.

Port Channel: Enter the port channel ID to specify the port channel.

Server Address: Enter the IP address of the DHCP server.

3.1.3 Configuring DHCP VLAN Relay

DHCP VLAN Relay allows clients in different VLANs to obtain IP addresses from a DHCP server using the IP address of a single agent interface. It is often used when the relay switch does not support configuring multiple Layer 3 interfaces.

Choose the menu L3 FEATURES > DHCP Service > DHCP Relay > DHCP VLAN Relay to load the following page.

Figure 3-3 Configure DHCP VLAN RelayDefault Relay Agent Interface Interface ID: VLAN (1-4094) IP Address: Apply DHCP VLAN Relay Config Index VLAN ID Server Address No entries in this table. Total: 0

Follow these steps to specify DHCP Server for the specific VLAN:

1) In the Default Relay Agent Interface section, specify a Layer 3 interface as the default relay agent interface. Then click Apply.

Interface ID: Select a L3 interface as the default relay agent interface.

VLAN: Enter the VLAN ID to specify the VLAN interface.

Routed Port: Enter the port number or click the port icon to specify the routed port.

Port Channel: Enter the port channel ID to specify the port channel.

IP Address: Displays the IP address of the interface.

TP-LINK Omada Pro S5500-24GP4F - Configuring DHCP VLAN Relay - 2

Note:

  • If the VLAN the clients belong to already has an IP address, the switch will use the client's own VLAN interface as the relay-agent interface. The manually specified default relay agent will not take effect.
  • DHCP VLAN Relay will not work on routed ports or port channel interfaces, because they are not associated with any particular VLAN.

2) In the DHCP VLAN Relay Config section, click + Add to load the configuration page.

Figure 3-4 Specify a DHCP server for the VLANDHCP VLAN Relay VLAN ID: (1-4094) Server Address: (Format: 192.168.0.1) Cancel Create

Specify the VLAN the clients belong to and the server address. Click Create.

VLAN ID: Specify the VLAN in which the hosts can get IP addresses from the DHCP server.

Server Address: Enter the IP address of the DHCP server.

3.2 Using the CLI

3.2.1 Enabling DHCP Relay

Follow these steps to enable DHCP Relay and configure the corresponding parameters:

Step 1: configure

Enter Global Configuration Mode.

Step 2: service dhcp relay

Enable DHCP Relay.

Step 3: ip dhcp relay hops

hops

Specify the maximum hops (DHCP relay agent) that the DHCP packets can be relayed. If a packet's hop count is more than the value you set here, the packet will be dropped.

hops: Specify the maximum hops for DHCP packets. Valid values are from 1 to 16, and the default value is 4.

Step 4 ip dhcp relay time

time

Specify the threshold for the DHCP relay time.

DHCP relay time is the time elapsed since the client began address acquisition or renewal process. There is a field in DHCP packets which specially records this time, and the switch will drop the packets if the value of this field is greater than the threshold. Value 0 means the switch will not examine this field of the DHCP packets.

time: Specify the threshold for the DHCP relay time. Valid values are from 1 to 65535. By default, the value is 0, which means the switch will not examine this field of the DHCP packets.

Step 5 show ip dhcp relay

Verify the configuration of DHCP Relay.

Step 6 end

Return to Privileged EXEC Mode.

Step 7 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable DHCP Relay, configure the relay hops as 5 and configure the relay time as 10 seconds :

Switch#configure

Switch(config)#service dhcp relay

Switch(config)#show ip dhcp relay

Switch(config)#ip dhcp relay hops 5

Switch(config)#ip dhcp relay time 10

DHCP relay state: enabled

DHCP relay hops: 5

DHCP relay Time Threshold: 10 seconds

...

Switch(config)#end

Switch#copy running-config startup-config

3.2.2 (Optional) Configuring Option 82

Follow these steps to configure Option 82:

Step 1 configure

Enter Global Configuration Mode.

Step 2 interface { fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list }

Enter Interface Configuration Mode.

Step 3 ip dhcp relay information option

Enable the Option 82 feature on the port.

Step 4 ip dhcp relay information strategy { keep | replace | drop }

Specify the operation for the switch to take when receiving DHCP packets that include the Option 82 field.

keep: The switch keeps the Option 82 field of the packets.

replace: The switch replaces the Option 82 field of the packets with a new one. The switch presets a default circuit ID and remote ID in TLV (Type, Length, and Value) format. You can also configure the format to include Value only and customize the Value.

drop: The switch discards the packets that include the Option 82 field.

Step 5 ip dhcp relay information format {normal | private}

Specify the packet format for the sub-option fields of Option 82.

normal: Indicates the fields consist of three parts: Type, Length, and Value (TLV).

private: Indicates the fields consist of the value only.

Step 6 ip dhcp relay information circuit-id

string

(Optional) A default circuit ID is preset on the switch, and you can also run this command to customize the circuit ID. The circuit ID configurations of the switch and the DHCP server should be compatible with each other.

The default circuit ID is a 4-byte value which consists of 2-byte VLAN ID and 2-byte Port ID. The VLAN ID indicates which VLAN the DHCP client belongs to, and the Port ID indicates which port the DHCP client is connected to. For example, if the DHCP client is connected to port 1/0/1 in VLAN 2, this field is 00:02:00:01 in hexadecimal.

string: Enter the customized circuit ID with up to 64 characters.

Step 7 ip dhcp relay information remote-id

string

(Optional) The switch uses its own MAC address as the default remote ID, and you can also run this command to customize the remote ID. The remote ID configurations of the switch and the DHCP server should be compatible with each other.

string: Enter the remote ID with up to 64 characters.

Step 8 show ip dhcp relay information interface { fastEthernet gigabitEthernet port | port-channel port-channel-id }

port | gigabitEthernet port | ten-

Verify the Option 82 configurations of the port.

Step 9 end

Return to Privileged EXEC Mode.

Step 10 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable Option 82 on port 1/0/7 and configure the strategy as replace, the format as normal, the circuit-id as VLAN20 and the remote-id as Host1:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/7

Switch(config-if)#ip dhcp relay information option

Switch(config-if)#ip dhcp relay information strategy replace

Switch(config-if)#ip dhcp relay information format normal

Switch(config-if)#ip dhcp relay information circuit-id VLAN20

Switch(config-if)#ip dhcp relay information remote-id Host1

Switch(config-if)#show ip dhcp relay information interface gigabitEthernet 1/0/7

Interface Option 82 Status Operation Strategy Format Circuit ID Remote ID LAG

Gi1/0/7 Enable Replace Normal VLAN20 Host1 N/A

Switch(config-if)#end

Switch#copy running-config startup-config

3.2.3 Configuring DHCP Interface Relay

You can specify a DHCP server for a Layer 3 interface or for a VLAN. The following introduces how to configure DHCP Interface Relay and DHCP VLAN Relay, respectively.

Follow these steps to DHCP Interface Relay:

Step 1 configure

Enter Global Configuration Mode.

Step 2 Enter Layer 3 Interface Configuration Mode:

Enter VLAN Interface Configuration Mode:

interface vlan vlan-id

vlan-id: Specify an IEEE 802.1Q VLAN ID that already exists, ranging from 1 to 4094.

Enter Routed Port Configuration Mode:

interface { fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port }

Enter Interface Configuration Mode.

port: Specify the Ethernet port number, for example, 1/0/1.

no switchport

Switch the Layer 2 port into the Layer 3 routed port.

Enter Port-channel Interface Configuration Mode:

interface { port-channel port-channel }

Enter Interface Configuration Mode.

port-channel: Specify the port channel. Valid values are from 1 to 14.

no switchport

Switch the port channel to a Layer 3 port channel interface.

Step 3 ip helper-address

ip-addr

Specify DHCP server for the Layer 3 interface.

ip-addr: Enter the IP address of the DHCP server.

Step 4 show ip dhcp relay

Verify the configuration of DHCP Relay.

Step 5 end

Return to Privileged EXEC Mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the DHCP server address as 192.168.1.7 on VLAN interface 66:

Switch#configure

Switch(config)#interface vlan 66

Switch(config-if)#ip helper-address 192.168.1.7

Switch(config-if)#show ip dhcp relay

...

DHCP relay helper address is configured on the following interfaces:

Interface Helper address

VLAN 66 192.168.1.7

Switch(config-if)#end

Switch#copy running-config startup-config

3.2.4 Configuring DHCP VLAN Relay

Follow these steps to configure DHCP VLAN Relay:

Step 1 configure

Enter Global Configuration Mode.

Step 2 Enter Layer 3 Interface Configuration Mode:

Enter VLAN Interface Configuration Mode:

interface vlan vlan-id

vlan-id: Specify an IEEE 802.1Q VLAN ID that already exists, ranging from 1 to 4094.

Enter Routed Port Configuration Mode:

interface { fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port }

Enter Interface Configuration Mode.

port: Specify the Ethernet port number, for example, 1/0/1.

no switchport

Switch the Layer 2 port into the Layer 3 routed port.

Enter Port-channel Interface Configuration Mode:

interface { port-channel port-channel }

Enter Interface Configuration Mode.

port-channel: Specify the port channel. Valid values are from 1 to 14.

no switchport

Switch the port channel to a Layer 3 port channel interface.

Step 3 ip dhcp relay default-interface

Set the interface as the default relay-agent interface. If the VLAN that the clients belong to does not have an IP address, the switch will use the IP address of this interface to fill in the Relay Agent IP Address field of DHCP packets from the DHCP clients.

Step 4 exit

Return to Global Configuration Mode.

Step 5 ip dhcp relay vlan

vid helper-address ip-address

Specify the VLAN ID and the DHCP server.

vid: Enter the ID of the VLAN, in which the hosts can dynamically get the IP addresses from the DHCP server.

ip-address: Enter the IP address of the DHCP server.

Step 6 show ip dhcp relay

Verify the configuration of DHCP Relay.

Step 7 end

Return to Privileged EXEC Mode.

Step 8 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to set the routed port 1/0/2 as the default relay agent interface and configure the DHCP server address as 192.168.1.8 on VLAN 10:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)#no switchport

Switch(config-if)# ip dhcp relay default-interface

Switch(config-if)# exit

Switch(config)# ip dhcp relay vlan 10 helper-address 192.168.1.8

Switch(config)# show ip dhcp relay

...

DHCP VLAN relay helper address is configured on the following VLAN:

VLAN Helper address

VLAN 10 192.168.1.8

Switch(config)# end

Switch# copy running-config startup-config

4 DHCPv6 Relay Configuration

TP-LINK Omada Pro S5500-24GP4F - DHCPv6 Relay Configuration - 1

Note:

DHCPv6 Relay is only available on Omada Pro L3 Stackable Switches.

A DHCPv6 Relay agent is a Layer 3 device that forwards DHCPv6 packets between clients and servers. DHCPv6 Relay forwards requests and replies between clients and servers when they are not on the same physical subnet.

4.1 Using the CLI

4.1.1 Enabling DHCPV6 Relay

Follow these steps to enable DHCPV6 Relay function globally:

Step 1 configure

Enter Global Configuration Mode.

Step 2 ipv6 dhcp relay

no ipv6 dhcp relay

Enable DHCPV6 Relay function globally. To disable DHCPV6 Relay function, please use no ipv6 dhcp relay command.

Step 3 end

Return to Privileged EXEC Mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable DHCPV6 Relay function globally:

Switch#configure

Switch(config)#ipv6 dhcp relay

Switch(config)#end

Switch#copy running-config startup-config

4.1.2 Adding DHCPV6 Server Address

Follow these steps to add DHCPV6 Server address to the Layer 3 interface:

Step 1 configure

Enter Global Configuration Mode.

Step 2 ipv6 dhcp relay vlan 1 helper-address

ipv6-address

no ipv6 dhcp relay vlan 1 helper-address [ipv6-address]

Add DHCPV6 Server address to the Layer 3 interface. To delete the server address, please use no ipv6 dhcp relay vlan 1 helper-address command.

ipv6-address: DHCPV6 Server address.

Step 3 end

Return to Privileged EXEC Mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to add DHCPV6 Server address

2019:2020::21D:FFF:FE61:2005 to interface VLAN 1:

Switch#configure

Switch(config)# ipv6 dhcp relay vlan 1 helper-address 2019:2020::21D:FFF:FE61:2005

Switch(config)#end

Switch#copy running-config startup-config

4.1.3 Enabling Option 18\37 Support

Follow these steps to enable option 18\37 support of a specified port in DHCPV6 Relay:

Step 1 configure

Enter Global Configuration Mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 ipv6 dhcp relay information

no ipv6 dhcp relay information

Enable option 18\37 support of a specified port in DHCPV6 Relay. To disable this function, please use no ipv6 dhcp relay information command.

Step 4 end

Return to Privileged EXEC Mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable option 18\37 support in DHCPV6 Relay for port 2:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)# ipv6 dhcp relay information option 18

Switch(config-if)# ipv6 dhcp relay information option 37

Switch(config-if)#end

Switch#copy running-config startup-config

4.1.4 Specifying Custom Remote ID

Follow these steps to specify the custom remote ID when option 37 customization is enabled:

Step 1 configure

Enter Global Configuration Mode.

Step 2: interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3: ipv6 dhcp relay information remote-id

remoteID

no ipv6 dhcp relay information remote-id

Specify the custom remote ID when option 37 customization is enabled. To clear the remote ID, use the no ipv6 dhcp relay information remote-id command.

remoteID: Specify the remote ID, ranging from 1 to 64 characters.

Step 4: end

Return to Privileged EXEC Mode.

Step 5: copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to specify the remote ID as "tplink192.168.0.3" for port 2:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)# ipv6 dhcp relay information remote-id tplink 192.168.0.3

Switch(config-if)#end

Switch#copy running-config startup-config

4.1.5 Viewing DHCPV6 Relay Info

Follow these steps to view the global status and Option 18\37 configuration of DHCPV6 Relay.

Step 1 show ipv6 dhcp relay

Display the global status and Option 18\37 configuration of DHCPV6 Relay.

The following example shows how to view the configuration of DHCPV6 Relay:

Switch#show ipv6 dhcp relay

4.1.6 Viewing DHCPV6 Relay Counters

Follow these steps to view the packet counter of the DHCPV6 Relay.

Step 1 show ipv6 dhcp relay counters

Display the packet counter of the DHCPV6 relay.

The following example shows how to view the configuration of DHCPv6 Relay:

Switch#show ipv6 dhcp relay counters

5 DHCP L2 Relay Configuration

To complete DHCP L2 Relay configuration, follow these steps:

1) Enable DHCP L2 Relay. 2) Configure Option 82 for ports.

5.1 Using the GUI

5.1.1 Enabling DHCP L2 Relay

Choose the menu L3 FEATURES > DHCP Service > DHCP L2 Relay > Global Config to load the following page.

Figure 5-1 Enable DHCP L2 RelayGlobal Config DHCP L2 Relay: Enable VLAN Config Filter by VLAN: From To Apply VLAN Status 1 Disabled 8 Disabled Total: 2 1 entry selected. Cancel Apply

Follow these steps to enable DHCP L2 Relay globally for the specified VLAN:

1) In the Global Config section, enable DHCP L2 Relay globally. Click Apply.

DHCP L2 Relay: Enable or disable DHCP L2 Relay globally.

2) In the VLAN Config section, enable DHCP L2 Relay for the specified VLAN. Click Apply.

VLAN: Displays the VLAN ID.

Status: Enable DHCP L2 Relay function for the VLAN.

5.1.2 Configuring Option 82 for Ports

Choose the menu L3 FEATURES > DHCP Service > DHCP L2 Relay > Port Config to load the following page.

Figure 5-2 Configure Option 82 for Ports

UNIT1LAGS
PortOption 82 SupportOption 82 PolicyFormatCircuit ID CustomizationCircuit IDRemote ID CustomizationRemote IDLAG
1/0/1DisabledKeepNormalDisabledDisabled---
1/0/2DisabledKeepNormalDisabledDisabled---
1/0/3DisabledKeepNormalDisabledDisabled---
1/0/4DisabledKeepNormalDisabledDisabled---
1/0/5DisabledKeepNormalDisabledDisabled---
1/0/6DisabledKeepNormalDisabledDisabled---
1/0/7DisabledKeepNormalDisabledDisabled---
1/0/8DisabledKeepNormalDisabledDisabled---
1/0/9DisabledKeepNormalDisabledDisabled---
1/0/10DisabledKeepNormalDisabledDisabled---

Follow these steps to enable DHCP Relay and configure Option 82:

1) Select one or more ports to configure Option 82.

Option 82 Support

Enable or disable the Option 82 feature for the port.

Enable it if you want to prevent DHCP client requests from untrusted sources, or assign different IP addresses to clients in different groups from the same DHCP server.

Option 82 Policy: Select the operation for the Option 82 field of the DHCP request packets.

Keep: Indicates keeping the Option 82 field of the packets.

Replace: Indicates replacing the Option 82 field of the packets with one defined by the switch. By default, the Circuit ID is defined to be the VLAN and the number of the port which receives the DHCP Request packets. The Remote ID is defined as the MAC address of the switch which receives the DHCP Request packets.

Drop: Indicates discarding the packets that include the Option 82 field.

Format: Select the format of option 82 sub-option value field.

Normal: The format of sub-option value field is TLV (type-length-value).

Private: The format of sub-option value field is just value.

Circuit ID CustomizationEnable or disable the switch to define the Option 82 sub-option Circuit ID field. If it is enabled, you can manually configure the circuit ID; if it is disabled, the switch will automatically configure the VLAN ID and the port number of the port that received the DHCP packets as the circuit ID.
Circuit IDWith Circuit ID Customization enabled, you can manually configure the circuit ID here.
Remote ID CustomizationEnable or disable the switch to define the Option 82 sub-option Remote ID field. If it is enabled, you can manually configure the remote ID; if it is disabled, the switch will automatically configure the switch’s MAC address as the remote ID.
Remote IDWith Remote ID Customization enabled, you can manually configure the remote ID here.
LAG Displays the LAG that the port belongs to.

2) Click Apply.

5.2 Using the CLI

5.2.1 Enabling DHCP L2 Relay

Follow these steps to enable DHCP L2 Relay:

Step 1 configure

Enter Global Configuration Mode.

Step 2 ip dhcp l2relay

Enable DHCP L2 Relay.

Step 3 ip dhcp l2relay vlan

vlan-list

Enable DHCP L2 Relay for specified VLANs.

vlan-list: Specify the vlan to be enabled with DHCP L2 relay.

Step 5 show ip dhcp l2relay

Verify the configuration of DHCP Relay.

Step 6 end

Return to Privileged EXEC Mode.

Step 7 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable DHCP L2 Relay globally and for VLAN 2:

Switch#configure

Switch(config)#ip dhcp l2relay

Switch(config)#ip dhcp l2relay vlan 2

Switch(config)#show ip dhcp l2relay

Global Status: Enable

VLAN ID: 2

Switch(config)#end

Switch#copy running-config startup-config

5.2.2 Configuring Option 82 for Ports

Follow these steps to configure Option 82:

Step 1 configure

Enter Global Configuration Mode.

Step 2 interface { fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list }

Enter Interface Configuration Mode.

Step 3 ip dhcp l2relay information option

Enable the Option 82 feature on the port.

Step 4 ip dhcp l2relay information strategy { keep | replace | drop }

Specify the operation for the switch to take when receiving DHCP packets that include the Option 82 field.

keep: The switch keeps the Option 82 field of the packets.

replace: The switch replaces the Option 82 field of the packets with a new one. The switch presets a default circuit ID and remote ID in TLV (Type, Length, and Value) format. You can also configure the format to include Value only and customize the Value.

drop: The switch discards the packets that include the Option 82 field.

Step 5 ip dhcp l2relay information format {normal | private}

Specify the packet format for the sub-option fields of Option 82.

normal: Indicates the fields consist of three parts: Type, Length, and Value (TLV).

private: Indicates the fields consist of the value only.

Step 6 ip dhcp l2relay information circuit-id string(Optional) A default circuit ID is preset on the switch, and you can also run this command to customize the circuit ID. The circuit ID configurations of the switch and the DHCP server should be compatible with each other.The default circuit ID is a 4-byte value which consists of 2-byte VLAN ID and 2-byte Port ID. The VLAN ID indicates which VLAN the DHCP client belongs to, and the Port ID indicates which port the DHCP client is connected to. For example, if the DHCP client is connected to port 1/0/1 in VLAN 2, this field is 00:02:00:01 in hexadecimal.string: Enter the customized circuit ID with up to 64 characters.
Step 7 ip dhcp l2relay information remote-id string(Optional) The switch uses its own MAC address as the default remote ID, and you can also run this command to customize the remote ID. The remote ID configurations of the switch and the DHCP server should be compatible with each other.string: Enter the remote ID with up to 64 characters.
Step 8 show ip dhcp l2relay information interface { fastEthernet port | gigabitEthernet port | port-channel port-channel-id}Verify the Option 82 configuration of the port.
Step 9 endReturn to Privileged EXEC Mode.
Step 10 copy running-config startup-configSave the settings in the configuration file.

The following example shows how to enable Option 82 on port 1/0/7 and configure the strategy as replace, the format as normal, the circuit-id as VLAN20 and the remote-id as Host1:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/7

Switch(config-if)#ip dhcp l2relay information option

Switch(config-if)#ip dhcp l2relay information strategy replace

Switch(config-if)#ip dhcp l2relay information format normal

Switch(config-if)#ip dhcp l2relay information circuit-id VLAN20

Switch(config-if)#ip dhcp l2relay information remote-id Host1

Switch(config-if)#show ip dhcp l2relay information interface gigabitEthernet 1/0/7

InterfaceOption 82 StatusOperation StrategyFormatCircuit IDRemote IDLAG
Gi1/0/7EnableReplaceNormalVLAN20Host1N/A

Switch(config-if)#end

Switch#copy running-config startup-config

6 DHCPV6 L2 Relay Configuration

TP-LINK Omada Pro S5500-24GP4F - DHCPV6 L2 Relay Configuration - 1

Note:

DHCPV6 L2 Relay is only available on Omada Pro L3 Stackable Switches.

6.1 Using the CLI

6.1.1 Enabling DHCPV6 L2 Relay Globally

Follow these steps to enable DHCPV6 L2 Relay function globally:

Step 1 configure

Enter Global Configuration Mode.

Step 2 ipv6 dhcp l2relay

no ipv6 dhcp l2relay

Enable DHCPV6 L2 Relay function globally. To disable DHCPV6 L2 Relay function, please use the no ipv6 dhcp l2relay command.

Step 3 end

Return to Privileged EXEC Mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable DHCPV6 L2 Relay function globally:

Switch#configure

Switch(config)#ipv6 dhcp l2relay

Switch(config)#end

Switch#copy running-config startup-config

6.1.2 Enabling DHCPV6 L2 Relay of VLAN

Follow these steps to enable DHCPV6 L2 relay in the specified VLAN.

Step 1 configure

Enter Global Configuration Mode.

Step 2 ipv6 dhcp l2relay vlan

vlan-id

no ipv6 dhcp l2relay vlan vlan-id

Enable DHCPV6 L2 relay in the specified VLAN. To disable DHCPV6 L2 Relay in the specific VLAN, use the no ipv6 dhcp l2relay vlan command.

vlan-id: Specify the VLAN to be enabled with DHCPV6 L2 relay.

Step 3 end

Return to Privileged EXEC Mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable DHCP L2 Relay for VLAN 1:

Switch#configure

Switch(config)#ipv6 dhcp l2relay vlan 1

Switch(config)#end

Switch#copy running-config startup-config

6.1.3 Enabling Option 18\37 Support

Follow these steps to enable option 18\37 support of a specified port in DHCPV6 L2Relay:

Step 1 configure

Enter Global Configuration Mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list }

Enter interface configuration mode.

Step 3 ipv6 dhcp l2relay information

no ipv6 dhcp I2relay information

Enable option 18\37 support of a specified port in DHCPV6 L2 Relay. To disable this function, please use no ipv6 dhcp l2relay information command.

Step 4 end

Return to Privileged EXEC Mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to enable option 18\37 support in DHCPV6 L2 Relay for port 2:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)# ipv6 dhcp l2relay information option 18

Switch(config-if)# ipv6 dhcp l2relay information option 37

Switch(config)#end

Switch#copy running-config startup-config

6.1.4 Specifying Custom Remote ID

Follow these steps to specify the custom remote ID when option 37 customization is enabled:

Step 1 configure

Enter Global Configuration Mode.

Step 2 interface {vlan

vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port

| range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list }

Enter interface configuration mode.

Step 3 ipv6 dhcp l2relay information remote-id

remoteID

no ipv6 dhcp l2relay information remote-id

Specify the custom remote ID when option 37 customization is enabled. To clear the remote ID, use the no ipv6 dhcp l2relay information remote-id command.

remoteID: Specify the remote ID, ranging from 1 to 64 characters.

Step 4 end

Return to Privileged EXEC Mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to specify the remote ID as "tplink192.168.0.3" for port 2:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)# ipv6 dhcp l2relay information remote-id tplink 192.168.0.3

Switch(config)#end

Switch#copy running-config startup-config

6.1.5 Viewing DHCPV6 L2 Relay Info

Follow these steps to view the global status and Option 18\37 configuration of DHCPV6 L2Relay.

Step 1 show ipv6 dhcp relay

Display the global status and Option 18\37 configuration of DHCPV6 Relay.

The following example shows how to view the configuration of DHCPV6 L2 Relay:

Switch#show ipv6 dhcp l2relay

7 Configuration Examples

7.1 Example for DHCP Server

7.1.1 Network Requirements

As the network topology shows, the administrator uses the switch as the DHCP server to assign IP addresses to all the connected devices. The office computers need to obtain IP addresses dynamically, while the FTP server needs a fixed IP address.

Figure 7-1 Network Topology for DHCP ServerTP-LINK Omada Pro S5500-24GP4F - Network Requirements - 1

You can enable the DHCP Server service on the switch and create a DHCP IP pool for all the connected devices. Then manually bind the MAC address of the FTP server to an IP address specified for the FTP server.

Demonstrated with S6500-24GP4XF, the following sections provide configuration procedures in two ways: using the GUI and using the CLI.

7.1.3 Using the GUI

1) Choose the menu L3 FEATURES > DHCP Service > DHCP Server > DHCP Server to load the following page. In the Global Config section, enable DHCP Server and click Apply.

Figure 7-2 Configuring DHCP ServerGlobal Config DHCP Server: ✓ Enable Option 60: (Optional. 1-64 characters) Option 138: (Optional. Format 192.168.0.1) Apply

2) Choose the menu L3 FEATURES > DHCP Service > DHCP Server > Pool Setting and click + Add to load the following page. Specify the Pool Name, Network Address,

Subnet Mask, Lease Time, Default Gateway and DNS Server as shown below. Click Create.

Figure 7-3 Configuring DHCP Server PoolDHCP Server Pool Pool Name: pool (8 characters maximum) Network Address: 192.168.0.0 (Format: 192.168.0.0) Subnet Mask: 255.255.255.0 (Format: 255.255.255.0) Lease Time: 120 (Optional: 1-2880 min, Default: 120) ► Default Gateway: (Optional. Format: 192.168.0.1) ► DNS Server: (Optional. Format: 192.1…

3) Choose the menu L3 FEATURES > DHCP Service > DHCP Server > Manual Binding and click + Add to load the following page. Select the DHCP server pool you just created, and enter the IP address of the FTP server in the IP Address field. Select Hardware Address as the binding mode, and enter the MAC address of the FTP server in the Hardware Address field. Select Ethernet as the Hardware Type. Click Create.

Figure 7-4 Configuring Manual BindingManual Binding Pool Name: pool IP Address: 192.168.0.8 (Format: 192.168.0.1) Binding Mode: Hardware Address Hardware Address: FC-AA-14-59-E9-4A (Format: 00-11-22-33-44-55) Hardware Type: Ethernet Cancel Create

4) Click Save the settings.

7.1.4 Using the CLI

1) Enable DHCP Server.

Switch#configure

Switch(config)#service dhcp server

2) Specify the Pool Name, Network Address, Subnet Mask and Lease Time.

Switch(config)#ip dhcp server pool pool

Switch(dhcp-config)#network 192.168.0.0 255.255.255.0

Switch(dhcp-config)#lease 120

Switch(dhcp-config)#exit

3) Bind the specified IP address to the MAC address of the FTP server.

Switch(config)# ip dhcp server pool pool

Switch(dhcp-config)# address 192.168.0.8 hardware-address FC-AA-14-59-E9-4A hardware-type ethernet

Switch(dhcp-config)#end

Switch#copy running-config startup-config

Verify the Configuration

Switch#show ip dhcp server binding

IP Address Client id/Hardware Address Type Lease Time Left

192.168.0.2 01-d43d-7ebf-615f Automatic 01:57:27

192.168.0.8 01-fcaa-1459-e94a Manual Infinite

7.2 Example for DHCP Interface Relay

7.2.1 Network Requirements

The administrator deploys one DHCP server on the network, and wants the server to assign IP addresses to the computers in the Marketing department and the R&D department. It is required that computers in the same department should be on the same subnet, while computers in different departments should be on different subnets.

After adding the DHCP server, the network topology will be as shown in Figure 7-5. The Marketing department and the R&D department belong to VLAN 10 and VLAN 20, respectively. The IP address of VLAN interface 10 is 192.168.2.1/24, and the IP address of VLAN interface 20 is 192.168.3.1/24. The DHCP server is connected to the routed port of

the switch. The Marketing department is connected to port 1/0/1 of the relay agent, and the R&D department is connected to port 1/0/2 of the relay agent.

Figure 7-5 Network Topology for DHCP Interface Relaygraph TD A["DHCP Server 192.168.0.59/24"] --> B["Switch DHCP Relay Agent"] C["VLAN 10 192.168.2.1/24"] --> B D["Marketing Dept. 192.168.2.0/24"] --> B E["Routed Port (Gi1/0/5) 192.168.0.1"] --> B F["Gi1/0/1"] --> B G["Gi1/0/2"] --> B H["VLAN 20 192.168.3.1/24"] --> B I["R&D Dept. 192.168.3.0/24"] --…

7.2.2 Configuration Scheme

In the given situation, the DHCP server and the computers are isolated in different network segments, so the DHCP requests from the clients cannot be directly forwarded to the DHCP server. To assign IP addresses in two different subnets to two departments respectively, we recommend you to configure DHCP Interface Relay to satisfy the requirement.

The overview of the configurations are as follows:

1) Before configuring DHCP Interface Relay, create two DHCP IP pools on the DHCP server for the two departments, respectively. Then create static routes or enable dynamic routing protocol like RIP on the DHCP server to make sure the DHCP server can reach the clients in the two VLANs. 2) Configure 802.1Q VLAN on the DHCP relay agent. Add all computers in the marketing department to VLAN 10, and add all computers in the R&D department to VLAN 20. 3) Create VLAN interfaces for VLAN 10 and VLAN 20 on the DHCP relay agent. 4) Configure DHCP Interface Relay on the DHCP relay agent. Enable DHCP Relay globally, and specify the DHCP server address for each VLAN.

In this example, the DHCP server is demonstrated with S6500-24GP4XF and the DHCP relay agent is demonstrated with S6500-24G4XF. This section provides configuration procedures in two ways: using the GUI and using the CLI.

7.2.3 Using the GUI

■ Configuring the DHCP Server

1) Choose the menu L3 FEATURES > DHCP Service > DHCP Server > DHCP Server to load the following page. In the Global Config section, enable DHCP Server globally.

Figure 7-6 Configuring DHCP ServerGlobal Config DHCP Server: ✓ Enable Option 60: (Optional, 1-64 characters) Option 138: (Optional, Format 192.168.0.1) Apply

2) Choose the menu L3 FEATURES > DHCP Service > DHCP Server > Pool Setting and click + Add to load the following page. Create pool 1 for VLAN 10 and pool 2 for VLAN 20. Configure the corresponding parameters as shown in the following figures.

Figure 7-7 Configuring DHCP Pool 1 for VLAN 10DHCP Server Pool Pool Name: pool1 (8 characters maximum) Network Address: 192.168.2.0 (Format: 192.168.0.0) Subnet Mask: 255.255.255.0 (Format: 255.255.255.0) Lease Time: 120 (Optional: 1-2880 min, Default: 120) ► Default Gateway: 192.168.2.1 (Optional: Format: 192.168.0.1) ► DNS Server: ► NetBIOS S…

Figure 7-8 Configuring DHCP Pool 2 for VLAN 20DHCP Server Pool Pool Name: pool2 (8 characters maximum) Network Address: 192.168.3.0 (Format: 192.168.0.0) Subnet Mask: 255.255.255.0 (Format: 255.255.255.0) Lease Time: 120 (Optional: 1-2880 min, Default: 120) ► Default Gateway: 192.168.3.1 (Optional: Format: 192.168.0.1) ► DNS Server: ► NetBIOS S…

3) Choose the menu L3 FEATURES > Static Routing > IPv4 Static Routing and click Add to load the following page. Create two static routing entries for the DHCP server to ensure that the DHCP server can reach the clients in the two VLANs.

Figure 7-9 Creating the Static Routing Entry for VLAN 10IPv4 Static Routing Destination: 192.168.2.0 (Format: 10.10.10.0) Subnet Mask: 255.255.255.0 (Format: 255.255.255.0) Next Hop: 192.168.0.1 (Format: 192.168.0.2) Distance: (Optional range: 1-255) Cancel Create

Figure 7-10 Creating the Static Routing Entry for VLAN 20IPv4 Static Routing Destination: 192.168.3.0 (Format: 10.10.10.0) Subnet Mask: 255.255.255.0 (Format: 255.255.255.0) Next Hop: 192.168.0.1 (Format: 192.168.0.2) Distance: (Optional range: 1-255) Cancel Create

■ Configuring the VLANs on the Relay Agent

1) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > VLAN Config and click Add to load the following page. Create VLAN 10 for the Marketing department and add port 1/0/1 as an untagged port to the VLAN.

Figure 7-11 Creating VLAN 10VLAN Config VLAN ID: 10 (3-1094, format 2,4-5,8) VLAN Name: Marketing (1-16 characters) Untagged Ports Port: 1/0/1 (Format 1/0/1, input or choose below) UNIT 1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 4…

2) On the same page, click again to create VLAN 20 for the R&D department and add port 1/0/2 as an untagged port to the VLAN.

Figure 7-12 Creating VLAN 20VLAN Config VLAN ID: 20 (2-4094, format: 2,4-5,8) VLAN Name: RD (1-10 characters) Untagged Ports Port: 1/0/2 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 49 51 5…

■ Configuring the VLAN Interface and Routed Port on the Relay Agent

1) Choose the menu L3 FEATURES > Interface and click + Add to load the following page. Create VLAN interface 10 and VLAN interface 20. Configure port 1/0/5 as the routed port.

Figure 7-13 Creating VLAN Interface 10Interface Config Interface ID: VLAN 10 (1-4094) IP Address Mode: None Static DHCP BOOTP IP Address: 192.168.2.1 (Format: 192.168.0.1) Subnet Mask: 255.255.255.0 (Format: 255.255.255.0) Admin Status: Enable Interface Name: (Optional. 1-16 characters) Cancel Create

Figure 7-14 Creating VLAN Interface 20Interface Config Interface ID: VLAN 20 (1-4094) IP Address Mode: None Static DHCP BOOTP IP Address: 192.168.3.1 (Format: 192.168.0.1) Subnet Mask: 255.255.255.0 (Format: 255.255.255.0) Admin Status: Enable Interface Name: (Optional. 1-16 characters) Cancel Create

2) On the same page, click again to configure port 1/0/5 as the routed port.

Figure 7-15 Configuring the Routed PortInterface Config Interface ID: Routed Port 1/0/5 (Format: 1/0/1) UNIT3 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 41 43 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 42 44 45 47 49 51 53 46 48 50 52 54 IP Address Mode: None Static DHCP BOOTP IP Address: 192.168.0.1 (Format: 192…

■ Configuring DHCP Interface Relay on the Relay Agent

1) Choose the menu L3 FEATURES > DHCP Service > DHCP Relay > DHCP Relay Config to load the following page. In the Global Config section, enable DHCP Relay, and click Apply.

Figure 7-16 Enable DHCP RelayGlobal Config DHCP Relay: ✓ Enable DHCP Relay Hops: 4 (1-16) DHCP Relay Time Threshold: 0 seconds (0-65535) Apply

2) Choose the menu L3 FEATURES > DHCP Service > DHCP Relay > DHCP Interface Relay and click + Add to load the following page. Specify the DHCP server for the clients in VLAN 10 and VLAN 20.

Figure 7-17 Specify DHCP Server for Interface VLAN 10DHCP Interface Relay Interface ID: VLAN 10 (1-4094) Server Address: 192.168.0.59 (Format: 192.168.0.1) Cancel Create

Figure 7-18 Specify DHCP Server for Interface VLAN 20DHCP Interface Relay Interface ID: VLAN 20 (1-4094) Server Address: 192.168.0.59 (Format: 192.168.0.1) Cancel Create

3) Click Save the settings.

7.2.4 Using the CLI

■ Configuring the DHCP Server

1) Enable DHCP service globally.

Switch#configure

Switch(config)#service dhcp server

2) Create DHCP pool 1 and configure its network address as 192.168.2.0, subnet mask as 255.255.255.0, lease time as 120 minutes, default gateway as 192.168.2.1; Create DHCP pool 2 and configure its network address as 192.168.3.0, subnet mask as 255.255.255.0, lease time as 120 minutes, default gateway as 192.168.3.1.

Switch(config)#ip dhcp server pool pool1

Switch(dhcp-config)#network 192.168.2.0 255.255.255.0

Switch(dhcp-config)#lease 120

Switch(dhcp-config)#default-gateway 192.168.2.1

Switch(dhcp-config)#exit

Switch(config)#ip dhcp server pool pool2

Switch(dhcp-config)#network 192.168.2.0 255.255.255.0

Switch(dhcp-config)#lease 120

Switch(dhcp-config)#default-gateway 192.168.3.1

Switch(dhcp-config)#exit

3) Create two static routing entries to make sure that the DHCP server can reach the clients in the two VLANs.

Switch(config)# ip route 192.168.2.0 255.255.255.0 192.168.0.1

Switch(config)# ip route 192.168.3.0 255.255.255.0 192.168.0.1

Switch(config)#end

Switch#copy running-config startup-config

■ Configuring the VLAN on the Relay Agent

Switch(config)# vlan 10

Switch(config-vlan)#name Marketing

Switch(config-vlan)#exit

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#switchport general allowed vlan 10 untagged

Switch(config-if)#exit

Switch(config)# vlan 20

Switch(config-vlan)#name RD

Switch(config-vlan)#exit

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)#switchport general allowed vlan 20 untagged

Switch(config-if)#exit

■ Configuring the VLAN Interfaces Routed Port on the Relay Agent

Switch(config)#interface vlan 10

Switch(config-if)#ip address 192.168.2.1 255.255.255.0

Switch(config-if)#exit

Switch(config)#interface vlan 20

Switch(config-if)#ip address 192.168.3.1 255.255.255.0

Switch(config-if)#exit

Switch(config)#interface gigabitEthernet 1/0/5

Switch(config-if)#ip address 192.168.0.1 255.255.255.0

Switch(config-if)#exit

Configuring DHCP Interface Relay on the Relay Agent

1) Enable DHCP Relay.

Switch#configure

Switch(config)#service dhcp relay

2) Specify the DHCP server for the interface VLAN 10.

Switch(config)#interface vlan 10

Switch(config-if)#ip helper-address 192.168.0.59

Switch(config-if)#exit

3) Specify the DHCP server for interface VLAN 20

Switch(config)#interface vlan 20

Switch(config-if)#ip helper-address 192.168.0.59

Switch(config-if)#end

Switch#copy running-config startup-config

Verify the Configurations of the DHCP Relay Agent

Switch#show ip dhcp relay

DHCP relay is enabled

...

DHCP relay helper address is configured on the following interfaces:

Interface Helper address

VLAN10 192.168.0.59

VLAN20 192.168.0.59

...

7.3 Example for DHCP VLAN Relay

7.3.1 Network Requirements

The administrator needs to deploy the office network for the Marketing department and the R&D department. The detailed requirements are listed below:

■ The Marketing department and the R&D department belong to VLAN 10 and VLAN 20, respectively. Both of the VLANs have no Layer 3 gateways. ■ Computers in the two departments need to obtain IP addresses from the same DHCP server.

The network topology designed by the administrator is shown below.

Figure 7-19 Network Topology for DHCP VLAN Relaygraph TD A["DHCP Server 192.168.0.59/24"] --> B["DHCP Relay Agent 192.168.0.1"] C["Marketing Dept. R&D Dept."] -->|Gi1/0/1| B D["VLAN 20VLAN 10"] -->|Gi1/0/2| B

7.3.2 Configuration Scheme

In the given situation, the DHCP server and the computers are isolated by VLANs, so the DHCP request from the clients cannot be directly forwarded to the DHCP server. Considering that the two VLANs have no Layer 3 gateways, we recommend you to configure DHCP VLAN Relay to satisfy the requirement.

The overview of the configurations are as follows:

1) Create one DHCP IP pool on the DHCP server, which is on 192.168.0.0/24 network segment. 2) Configure 802.1Q VLAN on the DHCP relay agent. Add all computers in the marketing department to VLAN 10, and add all computers in the R&D department to VLAN 20. 3) Configure DHCP VLAN Relay on the DHCP relay agent. Enable DHCP Relay globally, choose the VLAN interface 1 (the default management VLAN interface) as the default relay agent interface, and specify the DHCP server address for VLAN 10 and VLAN 20.

In this example, the DHCP server is demonstrated with S6500-24GP4XF and the DHCP relay agent is demonstrated with S6500-24G4XF. The following sections provide configuration procedures in two ways: using the GUI and using the CLI.

7.3.3 Using the GUI

■ Configuring the DHCP Server

1) Choose the menu L3 FEATURES > DHCP Service > DHCP Server > DHCP Server to load the following page. In the Global Config section, enable DHCP Server globally.

Figure 7-20 Configuring DHCP ServerGlobal Config DHCP Server: ✓ Enable Option 60: (Optional. 1-64 characters) Option 138: (Optional. Format 192.168.0.1) Apply

2) Choose the menu L3 FEATURES > DHCP Service > DHCP Server > Pool Setting and click + Add to load the following page. Create a DHCP pool for the clients. Configure the corresponding parameters as shown in the following figure.

Figure 7-21 Configuring DHCP Pool 1 for VLAN 10DHCP Server Pool Pool Name: pool (8 characters maximum) Network Address: 192.168.0.0 (Format: 192.168.0.0) Subnet Mask: 255.255.255.0 (Format: 255.255.255.0) Lease Time: 120 (Optional: 1-2880 min, Default: 120) ► Default Gateway: (Optional. Format: 192.168.0.1) ► DNS Server: (Optional. Format: 192.1…

■ Configuring the VLANs on the Relay Agent

1) Choose the menu L2 FEATURES > VLAN > 802.1Q VLAN > VLAN Config and click Add to load the following page. Create VLAN 10 for the Marketing department and add port 1/0/1 as an untagged port to the VLAN.

Figure 7-22 Creating VLAN 10VLAN Config VLAN ID: 10 2-4094, format: 2,4-5,8) VLAN Name: Marketing (1-16 characters) Untagged Ports Port 1/0/1 (Format: 1/0/1, input or choose below) UNIT1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 25 28 30 32 34 36 38 40 Select All 41 43 45 47 49…

2) On the same page, click again to create VLAN 20 for the R&D department and add port 1/0/2 as an untagged port to the VLAN.

Figure 7-23 Creating VLAN 20VLAN Config VLAN ID: 20 (2-4094, format: 2.4-5.8) VLAN Name: RD (1-10 characters) Untagged Ports Port: 1/0/2 (Format: 1/0/1, input or choose below) UNIT 1 LAGS 1 3 5 7 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 2 4 6 8 10 12 14 16 18 20 22 24 26 28 30 32 34 36 38 40 Select All 41 43 45 47 49 51…

■ Configuring DHCP VLAN Relay on the Relay Agent

1) Choose the menu L3 FEATURES > DHCP Service > DHCP Relay > DHCP Relay Config to load the following page. In the Global Config section, enable DHCP Relay, and click Apply.

Figure 7-24 Enable DHCP RelayGlobal Config DHCP Relay: ✓ Enable DHCP Relay Hops: 4 (1-16) DHCP Relay Time Threshold: 0 seconds (0-65535) Apply

2) Choose the menu L3 FEATURES > DHCP Service > DHCP Relay > DHCP VLAN Relay to load the following page. In the Default Relay Agent Interface section, specify VLAN interface 1 (the default management VLAN interface) as the default relay-agent interface. Click Apply.

Figure 7-25 Specify the Default Relay Agent InterfaceDefault Relay Agent Interface Interface ID: VLAN 1 (1-4094) IP Address: 192.168.0.1 Apply

3) Choose the menu L3 FEATURES > DHCP Service > DHCP Relay > DHCP VLAN Relay and click + Add to load the following page. Specify the DHCP server address for the clients in VLAN 10 and VLAN 20.

Figure 7-26 Specify DHCP Server for Interface VLAN 10DHCP VLAN Relay VLAN ID: 10 (1-4094) Server Address: 192.168.0.59 (Format: 192.168.0.1) Cancel Create

Figure 7-27 Specify DHCP Server for Interface VLAN 20

DHCP VLAN Relay VLAN ID: 20 (1-4094) Server Address: 192.168.0.59 (Format: 192.168.0.1) Cancel Create

4) Click Save the settings.

7.3.4 Using the CLI

■ Configuring the DHCP Server

1) Enable DHCP service globally.

Switch#configure

Switch(config)#service dhcp server

2) Create a DHCP pool and name it as "pool" and configure its network address as 192.168.0.0, subnet mask as 255.255.255.0, lease time as 120 minutes, default gateway as 192.168.0.1.

Switch(config)#ip dhcp server pool pool

Switch(dhcp-config)#network 192.168.0.0 255.255.255.0

Switch(dhcp-config)#lease 120

Switch(dhcp-config)#default-gateway 192.168.0.1 Switch(dhcp-config)#dns-server 192.168.0.2 Switch(dhcp-config)#end Switch#copy running-config startup-config

■ Configuring the VLAN on the Relay Agent

Switch#configure

Switch(config)# vlan 10

Switch(config-vlan)#name Marketing

Switch(config-vlan)#exit

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#switchport general allowed vlan 10 untagged

Switch(config-if)#exit

Switch(config)# vlan 20

Switch(config-vlan)#name RD

Switch(config-vlan)#exit

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)#switchport general allowed vlan 20 untagged

Switch(config-if)#exit

Configuring DHCP VLAN Relay on the Relay Agent

1) Enable DHCP Relay.

Switch(config)#service dhcp relay

2) Specify the routed port 1/0/5 as the default relay agent interface.

Switch(config)#interface vlan 1

Switch(config-if)#ip dhcp relay default-interface

Switch(config-if)#exit

3) Specify the DHCP server for VLAN 10 and VLAN 20

Switch(config)#ip dhcp relay vlan 10 helper-address 192.168.0.59

Switch(config)#ip dhcp relay vlan 20 helper-address 192.168.0.59

Switch(config)#exit

Verify the Configurations of the DHCP Relay Agent

Switch#show ip dhcp relay

Switch#show ip dhcp relay

DHCP relay state: enabled

...

DHCP relay default relay agent interface:

Interface: VLAN 1

IP address: 192.168.0.1

DHCP vlan relay helper address is configured on the following vlan:

vlan Helper address

VLAN 10 192.168.0.59

VLAN 20 192.168.0.59

7.4 Example for Option 82 in DHCP Relay

7.4.1 Network Requirements

As the following figure shows, there are two groups of computers. Group 1 is connected to Switch A via port 1/0/1, and Group 2 is connected via port 1/0/2. All computers are in the same VLAN, but the computers and the DHCP server are in different subnets. For management convenience, the administrator wants to allocate separate address spaces for the two groups of computers.

Figure 7-28 Network Topology for Option 82 in DHCP Relaygraph TD A["DHCP Server\n192.168.0.59/24"] --> B["Switch A\nGi1/0/2Gi1/0/1"] B --> C["VLAN 2\n192.168.2.1/24"] B --> D["VLAN 2\n192.168.2.1/24"] B --> E["Group 1\nPC\nGroup 1\n192.168.2.50-192.168.2.100"] B --> F["Group 2\nPC\nGroup 2\nPC\nGroup 2\n192.168.2.150-192.168.2.200"]

7.4.2 Configuration Scheme

To meet the requirements, you can configure Option 82 in DHCP Relay on Switch A. With DHCP Relay enabled, the switch can forward DHCP requests and replies between clients and the server. With Option 82 enabled, Switch A informs the DHCP server of the group information of each computer, so that the DHCP server can assign IP addresses of different address pools to the computers in different groups.

The overview of the configurations is as follows:

1) Configuring Switch A

a. Configure 802.1Q VLAN. Add all computers to VLAN 2. For details, refer to Configuring 802.1Q VLAN.

b. Configure the interface address of VLAN 2. For details, refer to Configuring Layer 3 Interfaces.

c. Configure DHCP relay and enable Option 82 in DHCP Relay. In this example, both DHCP Interface Relay and DHCP VLAN Relay can implement the requirements. Demonstrated with S6500-24GP4XF, 7.4.3 Configuring the DHCP Relay Switch provides configuration procedures to configure DHCP Interface Relay in two ways: using the GUI and using the CLI.

2) Configuring the DHCP Server

The detailed configurations on the DHCP server may be different among different devices. You can refer to the related document that is for the DHCP server you use. Demonstrated with a Linux ISC DHCP Server, Section 7.4.4 Configuring the DHCP Server provides information about how to set its DHCP configuration file.

7.4.3 Configuring the DHCP Relay Switch

Using the GUI

Follow these steps to configure DHCP relay and enable Option 82 in DHCP Relay on Switch A:

1) Choose the menu L3 FEATURES > DHCP Service > DHCP Relay > DHCP Relay Config to load the following page. In the Global Config section, enable DHCP Relay, and click Apply.

Figure 7-29 Enable DHCP RelayGlobal Config DHCP Relay: ✓ Enable DHCP Relay Hops: 4 (1-16) DHCP Relay Time Threshold: 0 seconds (0-65535) Apply

2) In the Option 82 Config section, select port 1/0/1 and port 1/0/2, enable Option 82 Support and set Option 82 Policy as Replace. You can configure other parameters according to your needs. In this example, the Format is set as Normal, and Circuit ID Customization and Remote ID Customization as Disabled. Click Apply.

Figure 7-30 Configure Option 82Option 82 Config UNIT1 LAGS Port Option 82 Support Option 82 Policy Format Circuit ID Customization Circuit ID Remote ID Customization Remote ID LAG Enable Replace ✓ 1/0/1 Enabled Replace Normal Disabled Disabled -- ✓ 1/0/2 Enabled Replace Normal Disabled Disabled -- □ 1/0/3 Disabled Keep Normal Dis…

3) Choose the menu L3 FEATURES > DHCP Service > DHCP Relay > DHCP Interface

Relay and click + Add to load the following page. Specify the DHCP server address to assign IP addresses for clients in VLAN 2. Click Create.

Figure 7-31 Specify DHCP Server for Interface VLAN 2DHCP Interface Relay Interface ID: VLAN 2 (1-4094) Server Address: 192.168.0.59 (Format: 192.168.0.1) Cancel Create

4) Click Save the settings.

Using the CLI

Follow these steps to configure DHCP relay and enable Option 82 in DHCP Relay on Switch A:

1) Enable DHCP Relay.

Switch#configure

Switch(config)#service dhcp relay

2) Enable Option 82 for port 1/0/1 and port 1/0/2. Set Option 82 policy as Replace. You can configure other parameters according to your needs. In this example, the Format is set as Normal, and Circuit ID Customization and Remote ID Customization as Disabled.

Switch(config)#interface range gigabitEthernet 1/0/1-2

Switch(config-if)#ip dhcp relay information option

Switch(config-if)#ip dhcp relay information strategy replace

Switch(config-if)#ip dhcp relay information format normal

Switch(config-if)#exit

3) Specify the DHCP server for the interface VLAN 2.

Switch(config)#interface vlan 2

Switch(config-if)#ip helper-address 192.168.0.59

Switch(config-if)#end

Switch#copy running-config startup-config

4) Verify the Configurations

View global settings:

Switch#show ip dhcp relay

DHCP relay state: enabled

...

DHCP relay helper address is configured on the following interfaces:

Interface Helper address

VLAN2 192.168.0.59

...

View port settings:

Switch#show ip dhcp relay information interface

Interface Option 82 Status Operation Strategy Format Circuit ID ...

......

Gi1/0/1 Enable Replace Normal Default:VLAN-PORT ...

Gi1/0/2 Enable Replace Normal Default:VLAN-PORT ...

...

7.4.4 Configuring the DHCP Server

TP-LINK Omada Pro S5500-24GP4F - Configuring the DHCP Server - 1

Note:

• Make sure the DHCP server supports Option 82 and more than one DHCP address pool. - To make sure the DHCP server can reach the computers, you can create static routes or enable dynamic routing protocol like RIP on the DHCP server. - In this section, we use different notations to distinguish ASCII strings from hexadecimal numbers. An ASCII string is enclosed with quotation marks, such as "123", while a hexadecimal number is divided by colon into parts of two digits, such as 31:32:33.

On the DHCP server, you need to create two DHCP classes to identify the Option 82 payloads of DHCP request packets from Group 1 and Group 2, respectively.

In this example, the DHCP relay agent uses the default circuit ID and remote ID in TLV format. According to packet formats described in Table 1-1 and Table 1-2, the sub-options of the two groups are as shown in the following table.

Table 7-1 Sub-options of Group1 and Group 2

Group Sub-option Type (Hex) Length (Hex) Value (Hex)
1Circuit ID 00 04 00:02:00:01
Remote ID00 06 00:00:FF:FF:27:12
2Circuit ID 00 04 00:02:00:02
Remote ID 00 06 00:00:FF:FF:27:12

The configuration file /etc/dhcpd.conf of the Linux ISC DHCP Server is:

ddns-update-style interim; ignore client-updates;

<h1 id="create-two-classes-to-match-the-pattern-of-option-82-in-dhcp-request-packets-from">Create two classes to match the pattern of Option 82 in DHCP request packets from</h1>
<h1 id="group-1-and-group-2-respectively">Group 1 and Group 2, respectively.</h1>
<h1 id="the-agent-circuit-id-inserted-by-the-dhcp-relay-switch-is-6-bytes-long-in-tlv-format-one">The agent circuit ID inserted by the DHCP relay switch is 6 bytes long in TLV format, one</h1>
<h1 id="byte-for-type-one-byte-for-length-and-4-bytes-for-value-therefore-the-offset-is-2-and-the">byte for Type, one byte for Length, and 4 bytes for Value. Therefore, the offset is 2 and the</h1>
length is 4.
<h1 id="similarly-the-offset-of-the-agent-remote-id-is-2-and-the-length-is-6">Similarly, the offset of the agent remote ID is 2 and the length is 6.</h1>
class "VLAN2Port1" {
    match if substring (option agent.circuit-id, 2, 4) = 00:02:00:01
    and substring (option agent.remote-id, 2, 6) = 00:00:ff:ff:27:12;
}

class "VLAN2Port2" {
    match if substring (option agent.circuit-id, 2, 4) = 00:02:00:02
    and substring (option agent.remote-id, 2, 6) = 00:00:ff:ff:27:12;
}

<h1 id="create-two-ip-address-pools-in-the-same-subnet">Create two IP Address pools in the same subnet.</h1>
<h1 id="assign-different-ip-addresses-to-the-dhcp-clients-in-different-groups">Assign different IP addresses to the DHCP clients in different groups.</h1>
subnet 192.168.2.0 netmask 255.255.255.0 {
    option routers 192.168.2.1;
    option subnet-mask 255.255.255.0;
    option domain-name-servers 192.168.0.59;
    option domain-name "example.com";
    default-lease-time 600;
    max-lease-time 7200;
    authoritative;

pool {
    range 192.168.2.50 192.168.2.100;
    allow members of "VLAN2Port1";
}

pool {
    range 192.168.2.150 192.168.2.200;
    allow members of "VLAN2Port2";
} 

7.5 Example for DHCP L2 Relay

7.5.1 Network Requirements

As the following figure shows, two groups of computers are connected to Switch A, and Switch A is connected to the DHCP server. All devices on the network are in the default VLAN 1. All computers get dynamic IP addresses from the DHCP server. For management convenience, the administrator wants to allocate separate address spaces for the two groups of computers.

Figure 7-32 Network Topology for DHCP L2 Relaygraph TD A["DHCP Server"] -->|192.168.10.1/24| B["Switch A\nDHCP Relay\n00:00:FF:FF:27:12"] B --> C["Group 1 Group 2"] B --> D["PC PCPC PC"]

192.168.10.100-192.168.10.150 192.168.10.151-192.168.10.200

7.5.2 Configuration Scheme

To meet the requirements, you can configure DHCP L2 Relay on Switch A to inform the DHCP server of the group information of each PC, so that the DHCP server can assign IP addresses of different address pools to the PCs in different groups.

The overview of the configurations are as follows:

1) Configuring Switch A

a. Enable DHCP L2 Relay globally and on VLAN 1. b. Configure Option 82 on ports 1/0/1 and 1/0/2.

Demonstrated with S6500-24GP4XF, 7.5.3 Configuring the DHCP Relay Switch provides configuration procedures in two ways: using the GUI and using the CLI.

2) Configuring the DHCP Server

The detailed configurations on the DHCP server may be different among different devices. You can refer to the related document that is for the DHCP server you use. Demonstrated with a Linux ISC DHCP Server, 7.5.4 Configuring the DHCP Server provides information about how to set its DHCP configuration file.

7.5.3 Configuring the DHCP Relay Switch

Using the GUI

1) Choose the menu L3 FEATURES > DHCP Service > DHCP L2 Relay > Global Config to load the following page. In the Global Config section, enable DHCP L2 Relay globally and click Apply. Enable DHCP L2 Relay on VLAN 1 and click Apply.

Figure 7-33 Enabling DHCP L2 RelayGlobal Config DHCP L2 Relay: ✓ Enable VLAN Config Filter by VLAN. From To Apply ✓ VLAN Status Enable ✓ 1 Enabled Total: 1 ↑ entry selected. Cancel Apply

2) Choose the menu L3 FEATURES > DHCP Service > DHCP L2 Relay > Port Config to load the following page. Select port 1/0/1, enable Option 82 Support and select Option 82 Policy as Replace. You can configure other parameters according to your needs. In this example, keep Format as Normal and Remote ID Customization as Disabled. Enable Circuit ID Customization and specify the Circuit ID as Group1. Click Apply.

Figure 7-34 Configuring Port 1/0/1Port Config UNIT1 LAGS Port Option 82 Support Option 82 Policy Format Circuit ID Customization Circuit ID Remote ID Customization Remote ID LAG Enable Replace Enable Group1 ✓ 1/0/1 Enabled Replace Normal Enabled Group1 Disabled — □ 1/0/2 Disabled Keep Normal Disabled Disabled — □ 1/0/3 Disabled Keep…

3) On the same page, select port 1/0/2, enable Option 82 Support and select Option 82 Policy as Replace. You can configure other parameters according to your needs. In this example, keep Format as Normal and Remote ID Customization as Disabled. Enable Circuit ID Customization and specify the Circuit ID as Group2. Click Apply.

Figure 7-35 Configuring Port 1/0/2Port Config UNIT1 LAGS Port Option 82 Option 82 Format Circuit ID Circuit ID Remote ID Remote ID LAG Support Policy Customization Customization Enable Replace Enable Group2 1/0/1 Enabled Replace Normal Enabled Group1 Disabled — ✓ 1/0/2 Enabled Replace Normal Enabled Group2 Disabled — 1/0/3 Disabled…

4) Click Save the settings.

Using the CLI

1) Enable DHCP L2 Relay globally and on VLAN1.

Switch#configure

Switch(config)#ip dhcp l2relay

Switch(config)#ip dhcp l2relay vlan 1

2) On port 1/0/1, enable Option 82 and select Option 82 Policy as Replace. You can configure other parameters according to your needs. In this example, keep Format as Normal and Remote ID Customization as Disabled. Enable Circuit ID Customization and specify the Circuit ID as Group1.

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#ip dhcp l2relay information option

Switch(config-if)#ip dhcp l2relay information strategy replace

Switch(config-if)#ip dhcp l2relay information circuit-id Group1

Switch(config-if)#exit

3) On port 1/0/2, enable Option 82 and select Option 82 Policy as Replace. You can configure other parameters according to your needs. In this example, keep Format as Normal and Remote ID Customization as Disabled. Enable Circuit ID Customization and specify the Circuit ID as Group2.

Switch(config)#interface gigabitEthernet 1/0/2

Switch(config-if)#ip dhcp l2relay information

Switch(config-if)#ip dhcp l2relay information strategy replace

Switch(config-if)#ip dhcp l2relay information circuit-id Group2

Switch(config-if)#end

Switch#copy running-config startup-config

Verify the Configurations

View global settings:

Switch#show ip dhcp l2relay

Global Status: Enable

VLAN ID: 1

View port settings:

Switch#show ip dhcp l2relay information interface gigabitEthernet 1/0/1

Interface Option 82 Status Operation Strategy Format Circuit ID ...

......

Gi1/0/1 Enable Replace Normal Group1 ...

Switch#show ip dhcp l2relay information interface gigabitEthernet 1/0/1

Interface Option 82 Status Operation Strategy Format Circuit ID ...

……

Gi1/0/2 Enable Replace Normal Group2 ...

7.5.4 Configuring the DHCP Server

TP-LINK Omada Pro S5500-24GP4F - Configuring the DHCP Server - 1

Note:

• Make sure the DHCP server supports Option 82 and more than one DHCP address pool. - To make sure the DHCP server can reach the computers, you can create static routes or enable dynamic routing protocol like RIP on the DHCP server. - In this section, we use different notations to distinguish ASCII strings from hexadecimal numbers. An ASCII string is enclosed with quotation marks, such as "123", while a hexadecimal number is divided by colon into parts of two digits, such as 31:32:33.

On the DHCP server, you need to create two DHCP classes to identify the Option 82 payloads of DHCP request packets from Group 1 and Group 2, respectively.

In this example, the DHCP relay agent uses the customized circuit ID and default remote ID in TLV format. According to packet format described in Table 1-1 and Table 1-2, the sub-options of the two groups are as shown in the following table.

Table 7-2 Sub-options of Group1 and Group 2

Group Sub-option Type (Hex) Length (Hex) Value
1Circuit ID 00 06“Group1” as an ASCII string (or47:72:6F:75:70:31 in hexadecimal)
Remote ID 00 0600:00:FF:FF:27:12
2Circuit ID 00 06“Group2” as an ASCII string (or47:72:6F:75:70:32 in hexadecimal)
Remote ID 00 0600:00:FF:FF:27:12

The configuration file /etc/dhcpd.conf of the Linux ISC DHCP Server is:

ddns-update-style interim;

ignore client-updates;

# Create two classes to match the pattern of Option 82 in DHCP request packets from # Group 1 and Group 2, respectively.

# The agent circuit ID inserted by the DHCP relay switch is 8 byte long in TLV format, one # byte for Type, one byte for Length, and 6 bytes for Value. Therefore, the offset is 2 and the length is 6.

# Similarly, the offset of the agent remote ID is 2 and the length is 6.

class "Group1" {
    match if substring (option agent.circuit-id, 2, 6) = "Group1"
    and substring (option agent.remote-id, 2, 6) = 00:00:ff:ff:27:12;
}

class "Group2" {
    match if substring (option agent.circuit-id, 2, 6) = "Group2"
    and substring (option agent.remote-id, 2, 6) = 00:00:ff:ff:27:12;
}

<h1 id="create-two-ip-address-pools-in-the-same-subnet-2">Create two IP Address pools in the same subnet.</h1>
<h1 id="assign-different-ip-addresses-to-the-dhcp-clients-in-different-groups-2">Assign different IP addresses to the DHCP clients in different groups.</h1>
subnet 192.168.10.0 netmask 255.255.255.0 {
    option routers 192.168.10.1;
    option subnet-mask 255.255.255.0;
    option domain-name-servers 192.168.10.1;
    option domain-name "example.com";
    default-lease-time 600;
    max-lease-time 7200;
    authoritative;

    pool {
    range 192.168.10.100 192.168.10.150;
    allow members of "Group1";
    }

    pool {
    range 192.168.10.151 192.168.10.200;
    allow members of "Group2";
    } 

8

Appendix: Default Parameters

Default settings of DHCP Server are listed in the following table.

Table 8-1 Default Settings of DHCP Server

Parameter Default Setting
Global Config
DHCP Server Disabled
Option 60 None
Option 138 None
Ping Time Config
Ping Packets 1
Ping Timeout 100 ms
Excluded IP Address
Start IP Address None
End IP Address None
Pool Setting
Pool Name None
Network Address None
Subnet Mask None
Lease Time 120 min
Default GatewayNone
DNS ServerNone
NetBIOS ServerNone
NetBIOS Node TypeNone
Next Server AddressNone
Domain NameNone
BootfileNone
Manual Binding
Pool Name None
IP Address None
Binding Mode Client ID
Client Id None
Hardware Address None
Hardware Type Ethernet

Default settings of DHCP Relay are listed in the following table.

Table 8-2 Default Settings of DHCP Relay

Parameter Default Setting
DHCP Relay
DHCP Relay Disabled
DHCP Relay Hops 4
DHCP Relay Time Threshold 0
Option 82 Configuration
Option 82 Support Disabled
Option 82 Policy Keep
Format Normal
Circuit ID CustomizationDisabled
Circuit IDNone
Remote ID CustomizationDisabled
Remote ID None
DHCP Interface Relay
Interface IDNone
Server AddressNone
DHCP VLAN Relay
Interface ID None
VLAN ID None
Server Address None

Default settings of DHCP L2 Relay are listed in the following table.

Table 8-3 Default Settings of DHCP L2 Relay

Parameter Default Setting
Global Config
DHCP Relay Disabled
VLAN Status Disabled
Port Config
Option 82 Support Disabled
Option 82 Policy Keep
Format Normal
Circuit ID Customization Disabled
Circuit ID None
Remote ID CustomizationDisabled
Remote ID None

Part 22

Configuring ARP

CHAPTERS

  1. Overview
  2. ARP Configurations
  3. Appendix: Default Parameters

1 Overview

ARP (Address Resolution Protocol) is used to map IP addresses to MAC addresses. Taking an IP address as input, ARP learns the associated MAC address, and stores the IP-MAC address association in an ARP entry for rapid retrieval.

1.1 Supported Features

ARP Table

The ARP table displays all the ARP entries, including dynamic entries and static entries.

Dynamic Entry: Automatically learned and will be deleted after aging time.

Static Entry: Added manually and will be remained unless modified or deleted manually.

Static ARP

You can manually add ARP entries by specifying the IP addresses and MAC addresses.

Gratuitous ARP

Gratuitous ARP is a special kind of ARP. Both the source and destination addresses of the gratuitous ARP packet are the sender's own IP address. It is used to detect duplicate IP addresses. If an interface sends a gratuitous ARP packet and no replies are received, then the sender knows its IP address is not used by other devices.

Proxy ARP

Normally, ARP packets can only be transmitted within one broadcast domain, which means if two devices in the same network segment are connected to different Layer 3 interfaces, they cannot communicate with each other because they cannot learn each other's MAC address using ARP packets.

Proxy ARP solves this problem. As shown below, when a host sends an ARP request to another device that is not in the same broadcast domain but on the same network segment, the Layer 3 interface with Proxy ARP enabled will respond to the ARP request with its own MAC address if the destination IP is reachable. After that, the ARP request sender sends packets to the switch, and the switch forwards the packets to the intended device.

Figure 1-1 Proxy ARP Applicationgraph LR A["Server 1: 192.168.2.10/16"] -->|VLAN Interface 2 192.168.2.1/24| B["Server 2: 192.168.3.1/24"] B -->|VLAN Interface 3 192.168.3.1/24| C["Server 3: 192.168.3.20/16"]

Local Proxy ARP

Local Proxy ARP is similar to Proxy ARP. As shown below, two hosts are in the same VLAN and connected to VLAN interface 1, but port 1/0/1 and port 1/0/2 are isolated on Layer 2. In this case, both hosts cannot receive each other's ARP requests. So they cannot communicate with each other because they cannot learn each other's MAC address using ARP packets.

To solve this problem, you can enable Local Proxy ARP on the Layer 3 interface and the interface will respond to the ARP request sender with its own MAC address. After that, the ARP request sender sends packets to the Layer 3 interface, and the interface forwards the packets to the intended device.

Figure 1-2 Local Proxy ARP Applicationgraph TD A["VLAN Interface 1\nIP: 192.168.0.1/24"] --> B["Port 1/0/1 Port 170/2"] B --> C["VLAN 1"] C --> D["Computer 1"] C --> E["Computer 2"]

2 ARP Configurations

With ARP configurations, you can:

View dynamic and static ARP entries. Add or delete static ARP entries.

To configure the Gratuitous ARP feature:

Configure the Gratuitous ARP globally and set the Gratuitous ARP sending interval.

To configure the Proxy ARP feature:

Enable Proxy function for VLAN interfaces or routed ports.

To configure the Local Proxy ARP feature:

Enable Local Proxy function for VLAN interfaces or routed ports.

2.1 Using the GUI

2.1.1 Viewing the ARP Entries

The ARP table consists of two kinds of ARP entries: dynamic and static.

Dynamic Entry: Automatically learned and will be deleted after aging time. Static Entry: Added manually and will be remained unless modified or deleted manually.

Choose the menu L3 FEATURES > ARP > ARP Table > ARP Table to load the following page.

Figure 2-1 Viewing the ARP Entries

ARP Table
Refresh
InterfaceIP AddressMAC AddressType
VLAN1192.168.0.10140-ed-00-22-30-40Dynamic
Total: 1

Interface Displays the network interface of the ARP entry.

IP Address Displays the IP address of the ARP entry.

MAC Address Displays the MAC address of the ARP entry.

Type Displays the type of the ARP entry.

Static: The entry is added manually and will always remain the same.

Dynamic: The entry that will be deleted after the aging time. The aging time is 600 seconds by default. You can also use the command line to change the aging time. For the command line, go to the CLI guide.

2.1.2 Adding Static ARP Entries Manually

You can add desired static ARP entries by manually specifying the IP addresses and MAC addresses.

Choose the menu L3 FEATURES > ARP > Static ARP and click + Add to load the following page.

Figure 2-2 Adding Static ARP EntriesStatic ARP IP Address: (Format: 192.168.0.10) MAC Address: (Format: 00-00-00-00-00-01) Cancel Create

Enter the IP address and MAC address, then click Create.

IP address Enter the IP address of the static ARP entry.

MAC address Enter the MAC address of the static ARP entry.

2.1.3 Configuring Gratuitous ARP

Choose the menu L3 FEATURES > ARP > Gratuitous ARP to load the following page.

Figure 2-3 Configuring Gratuitous ARPGratuitous ARP Global Settings Send on IP Interface Status Up: ✓ Enable Send on Duplicate IP Detected: □ Enable Gratuitous ARP Learning: □ Enable Apply Gratuitous ARP Config □ Interface Name Gratuitous ARP Periodical Send Interval □ VLAN1 0 □ VLAN2 0 □ VLAN10 0 □ VLAN20 0 □ Gi1/0/5 0 Total: 5

Follow these steps to configure the Gratuitous feature for the interface.

1) In the Gratuitous ARP Global Settings section, configure the global parameters for gratuitous ARP. Then click Apply.

Send on IP Interface Status UpWith this option enabled, the interface will send gratuitous ARP request packets when its status becomes up. This is used to announce the interface's IP address to the other hosts. It is enabled by default.
Send on Duplicate IP DetectedWith this option enabled, the interface will send gratuitous ARP request packets when a gratuitous ARP request packet is received for which the IP address is the same as the interface's. In this case, the switch knows that another host is using the same IP address as its own. To claim the IP address for the correct owner, the interface sends gratuitous ARP packets. It is disabled by default.
Gratuitous ARP LearningNormally, the switch only updates the MAC address table by learning from the ARP reply packet or normal ARP request packet. With this option enabled, the switch will also update the MAC address table by learning from the received gratuitous ARP packets. It is disabled by default.

2) In the Gratuitous ARP Config section, configure the interval of sending gratuitous ARP request packets for the interface. Then click Apply.

Interface Name Displays the Interface ID of the Layer 3 interface.
Gratuitous ARP Periodical Send IntervalEnter the interval of sending gratuitous ARP request packets for the interface. A value 0 means the interface will not send gratuitous ARP request packets periodically.

2.1.4 Configuring Proxy ARP

Proxy ARP is used in the situation that two devices are in the same network segment but connected to different Layer 3 interfaces.

Choose the menu L3 FEATURES > ARP > Proxy ARP > Proxy ARP to load the following page.

Figure 2-4 Configuring Proxy ARP

Proxy ARP Config
IndexIP AddressSubnet MaskInterfaceStatus
1192.168.0.1255.255.255.0VLAN1Disabled
20.0.0.00.0.0.0VLAN2Disabled
3192.168.2.1255.255.255.0VLAN10Disabled
4192.168.3.1255.255.255.0VLAN20Disabled
50.0.0.00.0.0.0Gi1/0/5Disabled
Total: 5

Select the desired interface and enable proxy ARP. Then click Apply.

IP Address Displays the IP address of the Layer 3 interface

Subnet Mask Displays the subnet mask of the Layer 3 interface.

Interface Displays the ID of the Layer 3 interface.

Status Enable or disable Proxy ARP function for the Layer 3 interface. The interface will respond the ARP request sender with its own MAC address.

2.1.5 Configuring Local Proxy ARP

Local Proxy ARP is used in the situation that two devices are in the same VLAN but isolated on the layer 2 ports.

Choose the menu L3 FEATURES > ARP > Proxy ARP > Local Proxy ARP to load the following page.

Figure 2-5 Configuring Local Proxy ARP Local Proxy ARP Config

IndexIP AddressSubnet MaskInterfaceStatus
1192.168.0.1255.255.255.0VLAN1Disabled
20.0.0.00.0.0.0VLAN2Disabled
3192.168.2.1255.255.255.0VLAN10Disabled
4192.168.3.1255.255.255.0VLAN20Disabled
50.0.0.00.0.0.0Gi1/0/5Disabled
Total: 5

Select the desired interface and enable local proxy ARP. Then click Apply.

IP Address Displays the IP address of the Layer 3 interface

Subnet Mask Displays the subnet Mask of the Layer 3 interface.

Status

Enable or disable Local Proxy ARP function for the Layer 3 interface. The interface will respond the ARP request sender with its own MAC address.

2.2 Using the CLI

2.2.1 Configuring the ARP Entry

■ Adding Static ARP Entries

Follow these steps to add static ARP entries:

Step 1 configure

Enter global configuration mode.

Step 2 arp

ip mac type

Add a static ARP entry.

ip: Enter the IP address of the static ARP entry.

mac: Enter the MAC address of the static ARP entry.

type: Enter the ARP type. Configure it as 'arpa'.

Step 3 show arp [

ip] [mac]

ip: Specify the IP address of your desired ARP entry.

mac: Specify the MAC address of your desired ARP entry.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

This example shows how to create a static ARP entry with the IP as 192.168.0.1 and the MAC as 00:11:22:33:44:55:

Switch#configure

Switch(config)#arp 192.168.0.1 00:11:22:33:44:55 arpa

Switch(config)#show arp 192.168.0.1

Interface

Address

Hardware Addr

Type

Vlan1

192.168.0.1

00:11:22:33:44:55

STATIC

Switch(config)#end

Switch#copy running-config startup-config

■ Configuring the Aging Time of Dynamic ARP Entries

Follow these steps to configure the aging time of dynamic ARP entries:

Step 1 configure

Enter global configuration mode.

Step 2 arp timeout timeout

Configure the ARP aging time of the VLAN interface or routed port.

timeout: Specify the value of aging time, which ranges from 1 to 3000 in seconds. The default value is 1200 seconds.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

This example shows how to configure the aging time of dynamic ARP entries as 1000 seconds:

Switch#configure

Switch(config)#arp timeout 1000

Switch(config)#end

Switch#copy running-config startup-config

■ Clearing Dynamic Entries

Step 1 configure

Enter global configuration mode.

Step 2 clear arp-cache

Clear all the dynamic ARP entries.

Step 3 copy running-config startup-config

Save the settings in the configuration file.

■ Renewing Dynamic ARP Entries Automatically

Step 1 configure

Enter global configuration mode.

Step 2 arp dynamic-renew

Enable the switch to automatically renew dynamic ARP entries. By default, it is enabled.

Step 3 copy running-config startup-config

Save the settings in the configuration file.

■ Viewing ARP Entries

On privileged EXEC mode or any other configuration mode, you can use the following command to view ARP entries:

show arp [ip] [mac]

ip: Specify the IP address of your desired ARP entry.

mac: Specify the MAC address of your desired ARP entry.

show ip arp { fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel lagid | vlan vid }

Verify the active ARP entries associated with a Layer 3 interface.

port: Specify the number of the routed port.

lagid: Specify the ID of the LAG.

vid: Specify the VLAN interface ID.

2.2.2 Configuring the Gratuitous ARP

■ Configuring Gratuitous ARP Globally

Follow these steps to add static ARP entries:

Step 1 configure

Enter global configuration mode.

Step 2 gratuitous-arp intf-status-up enable

Enable the Layer 3 interface to send a gratuitous ARP packet to detect if its IP address is used by other devices. It is enabled by default

Step 3 gratuitous-arp dup-ip-detected enable

(Optional) Enable the Layer 3 interface to send a gratuitous packet when the interface receives a gratuitous ARP packet with the same IP address as its own. It is disabled by default.

Step 4 gratuitous-arp learning enable

(Optional) Enable the switch to learn MAC address entries from gratuitous ARP packets. Generally, the switch only learns MAC address entries from normal ARP packets. With this option enabled, the switch will also learn MAC address entries from gratuitous ARP packets. By default, it is disabled.

Step 5 show gratuitous-arp

Show the gratuitous ARP configuration.

Step 6 end

Return to privileged EXEC mode.

Step 7 copy running-config startup-config

Save the settings in the configuration file.

This example shows how to enable Send on IP Interface Status Up, Send on Duplicate IP Detected, and Gratuitous ARP Learning features:

Switch#configure

Switch(config)#gratuitous-arp dup-ip-detected enable

Switch(config)# gratuitous-arp intf-status-up enable

Switch(config)#gratuitous-arp learning enable

Switch(config)#show gratuitous-arp

Send on IP interface Status up : Enabled

Send on Duplicate IP Detected : Enabled

Gratuitous ARP Learning : Enabled

Interface Gratuitous ARP Periodical Send Interval

Gi1/0/18 0

VLAN1 0

Switch(config)#end

Switch#copy running-config startup-config

■ Configuring Interval of Sending Gratuitous ARP Packets

Follow these steps to configure gratuitous ARP packets for Layer 3 interfaces:

Step 1 configure

Enter global configuration mode.

Step 2There are three types of Layer 3 interface that are able to send gratuitous ARP packets: routed port, port-channel and VLAN interface.interface (vlan vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list )no switch portEnter interface configuration mode and change the port or port-channel to be a Layer 3 interface.
Interface vlan vlan-idEnter the vlan interface configuration mode.vlan-id: Enter the interface VLAN ID.
Step 3 gratuitous-arp send-interval intervalSpecify the periodical interval at which the interface sends the gratuitous ARP packet.interval: Specify the interval in seconds. The valid value ranges from 0 to 65535. Value 0 means the interface does not periodically send gratuitous ARP packets.
Step 4 show gratuitous-arpShow the gratuitous ARP configuration.
Step 5 endReturn to privileged EXEC mode.
Step 6 copy running-config startup-configSave the settings in the configuration file.

This example shows how to configure the interval of sending gratuitous ARP packets for VLAN interface 1 as 10 seconds:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#gratuitous-arp send-interval 10

Switch(config-if)#show gratuitous-arp

...

Interface Gratuitous ARP Periodical Send Interval

VLAN1 10

Switch(config-if)#end

Switch#copy running-config startup-config

2.2.3 Configuring Proxy ARP

You can configure proxy ARP and local proxy ARP.

■ Configuring Proxy ARP

Follow these steps to Proxy ARP on the VLAN interface, routed port or port channel.

Step 1 configure

Enter global configuration mode.
Step 2There are three types of Layer 3 interface can be enabled with Proxy ARP: routed port, port-channel and VLAN interface.
interface {vlan vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list |}
no switch port
Enter interface configuration mode and change the port or port-channel to be a Layer 3 interface.
Interface vlan vlan-id
Enter the vlan interface configuration mode.
vlan-id: Enter the interface VLAN ID.

Step 3 ip proxy-arp

Enable Proxy ARP function on the specified Layer 3 interface..
Step 4show ip proxy-arpShow the Proxy ARP configuration..
Step 5endReturn to privileged EXEC mode.
Step 6copy running-config startup-configSave the settings in the configuration file.

This example shows how to enable Proxy ARP function for VLAN interface 1:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#ip proxy-arp

Switch(config-if)#show ip proxy-arp

InterfaceIP AddressIP MaskStatus
vlan 1192.168.0.1255.255.255.0Enabled

Switch(config-if)#end

Switch#copy running-config startup-config

■ Configuring Local Proxy ARP

Follow these steps to configure Local Proxy ARP on the VLAN interface, routed port, or port channel.

Step 1 configure

Enter global configuration mode.
Step 2There are three types of Layer 3 interface can be enabled with Local Proxy ARP: routed port, port-channel and VLAN interface.interface {vlan vid | fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel | range port-channel port-channel-list }}no switch portEnter interface configuration mode and change the port or port-channel to be a Layer 3 interface.
Interface vlan vlan-idEnter the vlan interface configuration mode.vlan-id: Enter the interface VLAN ID.

Step 3 ip local-proxy-arp

Enable Local Proxy ARP function on the specified Layer 3 interface..
Step 4 show ip local-proxy-arpShow the Local Proxy ARP configuration..
Step 5 endReturn to privileged EXEC mode.
Step 6 copy running-config startup-configSave the settings in the configuration file.

This example shows how to enable the Local Proxy ARP function for VLAN interface 1:

Switch#configure

Switch(config)#interface vlan 1

Switch(config-if)#ip local-proxy-arp

Switch(config-if)#show ip local-proxy-arp

InterfaceIP AddressIP MaskStatus
vlan 1192.168.0.1255.255.255.0Enabled

Switch(config-if)#end

Switch#copy running-config startup-config

3 Appendix: Default Parameters

Default ARP settings are listed in the following tables.

Table 3-1 Default Gratuitous Settings

Parameter Default Setting
Send on IP Interface Status Up Enabled
Send on Duplicate IP Detected Disabled
Gratuitous ARP Learning Disabled
Gratuitous ARP Periodical Send Interval 0 second

Part 23

Configuring VRRP

(Only for Certain Devices)

CHAPTERS

  1. Overview
  2. VRRP Configuration
  3. Appendix: Default Parameters

1 Overview

TP-LINK Omada Pro S5500-24GP4F - Overview - 1

Note:

VRRP is only available on certain devices. To check whether your device supports this feature, refer to the actual web interface. If VRRP is available, there is L3 FEATURES > VRRP in the menu structure.

VRRP (Virtual Routing Redundancy Protocol) is a function on the switch that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN. The VRRP router that controls the IP address associated with a virtual router is called the Master and will forward packets sent to this IP address. This will allow any Virtual Router IP address on the LAN to be used as the default first hop router by end hosts.

2 VRRP Configuration

2.1 Using the GUI

  1. Choose the menu L3 FEATURES > VRRP > Basic Config to load the following page.

Figure 2-1 VRRP Basic ConfigBasic Config Advanced Config Virtual IP Config Track Config Virtual Router Statistics VRRP Table Add Delete Refresh VRID Interface IP Virtual IP Priority Status Operation No entries in this table. Total: 0

Follow these steps to configure VRRP:

1) Click + Add to load the configuration page. 2) Enter the appropriate VRID, interface ID and virtual IP, and then click Create.

Figure 2-2 Add VRRPBasic Config Advanced Config Virtual IP Config Track Config Virtual Router Statistics VRRP Table Add Delete Refresh VRID Interface IP Virtual IP Priority Status Operation No entries in this table. Total: 0 VRRP Basic Config VRID: 100 (1-255) Interface: VLAN 1 (1-4004) Virtual IP: 192.168.0.100 (Form…

Figure 2-3 VRRP TableBasic Config Advanced Config Virtual IP Config Track Config Virtual Router Statistics

VRRP TableAdd Delete Refresh ✓ VRID Interface IP Virtual IP Priority Status Operation ✓ 100 192.168.0.1 192.168.0.100 100 Master Detail Total. 1 1 entry selected.

Select: Select one or more items.

VRID: Displays the VRID associated with the VRRP.

Interface: Displays the Interface ID associated with the VRRP.

Interface IP: Displays the IP Address associated with the selected interface.

Virtual IP: Displays the primary Virtual IP associated with the VRRP.

Priority: Displays the priority associated with the VRRP.

Status VRRP status.

Operation Displays more information about the VRRP.

Delete Delete the selected items.

Refresh Update the status of the items.

3) Click Detail to check the Details of the Specified VRRP.

Figure 2-4 Details of the Specified VRRPTP-LINK Omada Pro S5500-24GP4F - 3) Click Detail to check the Details of the Specified VRRP. - 1

Details of the Specified VRRP
VRID:100
Interface:VLAN1
Description
Interface IP:192.168 0.1
Status:Master
Configure Priority:100
Running Priority:100
Advertise Timer:100
Preempt Delay Timer:0
Preempt Mode:Enable
Authentication Type:None
Key
Primary Virtual IP:192.168 0.100
Secondary Virtual IP:
Virtual MAC:00-00-5E-00-01-64

Refresh

VRID Displays the VRID associated with the VRRP.
Interface Displays the Interface ID associated with the VRRP.
Description Displays the description associated with the VRRP.
Interface IP Displays the IP Address associated with the selected interface.
Status Displays the status associated with the VRRP.
Configure PriorityDisplays the configured priority associated with the VRRP. It ranges from 1 to 254.
PriorityDisplays the running priority associated with the VRRP. It ranges from 0 to 255.
Advertise TimerDisplays the advertise timer associated with the VRRP. For V2 it ranges from 1 to 255; For V3 it ranges from 100 to 4095.
Preempt Delay TimerDisplays the preempt delay timer associated with the VRRP. It ranges from 0 to 255.
Preempt Mode Displays the preempt mode associated with the VRRP.
Authentication TypeDisplays the authentication type associated with the VRRP.
KeyDisplays the key associated with authentication type. If the authentication type is 'normal', it will display '--'.
Primary Virtual IP Displays the primary virtual IP associated with the VRRP.
Secondary Virtual IPDisplays all the secondary virtual IP associated with the VRRP.
Virtual MAC Displays the Virtual MAC address associated with the VRRP.
Tracked InterfaceDisplays the tracked interface ID.
Reduced Priority Displays the reduced priority when the interface tracked is 'down'.
Back Click the button to go back to the VRRP basic config page.
Refresh Click the button to refresh this page.
  1. Choose the menu L3 FEATURES > VRRP > Advanced Config to make advanced configuration.

1) Choose the VRID created and modify the features of the VRRP.

Figure 2-5 VRRP Advanced ConfigBasic Config | Advanced Config | Virtual IP Config | Track Config | Virtual Router Statistics

VRRP Advanced Config

VRID Interface Description Priority Advertise Timer Preempt Mode Delay Time Authentication Key 120 Enable 20 100 VLAN1 120 100 Enable 20 None Total: 1 1 entry selected Cancel Apply

2) Click Apply.

Select Select one or more items.

VRID Displays the VRID associated with the VRRP.

Interface Displays the Interface ID associated with the VRRP.

DescriptionEnter the description associated with the VRRP.Numbers,characters and '-' are the only valid inputs,and the maximal length of the inputs is 256.
Priority Enter the Priority associated with the VRRP. It ranges from 1 to 254.
Advertise TimerEnter the advertise timer associated with the VRRP. The VRRP-v2 ranges from 1 to 255 s, and the VRRP-v3 ranges from 100 to 4095 cs.
Preempt ModeSelect Enable or disable the preempt Mode from the pull-down list. If you select Enable, a backup router will preempt the master router if it has a priority greater than the master virtual router's priority. The Preempt Mode is enabled by default.
Delay Time Enter the delay time associated with the VRRP. It ranges from 0 to 255.
AuthenticationSelect the type of Authentication for the Virtual Router from the pull-down list. The default is None.None: No authentication will be performed.Simple: Authentication will be performed using a text password.MD5: Authentication of MD5 will be performed using a text password.
Key If you select Simple or MD5 as authentication mode, enter the key.
Apply Click the button to submit the modified configuration.
  1. Choose the menu L3 FEATURES > VRRP > Virtual IP Config to configure virtual IP for the virtual routers.

Figure 2-6 VRRP Virtual IP ConfigBasic Config Advanced Config Virtual IP Config Track Config Virtual Router Statistics VRRP Virtual IP Table Add Delete VRID Interface Virtual IP Type 100 VLAN1 192.168.0.100 Primary IP Total: 1

1) Click Add to load the configuration page. 2) Enter the VRID, interface ID, type and virtual IP, and then click Create.

Figure 2-7 Add Virtual IPBasic Config Advanced Config Virtual IP Config Track Config Virtual Router Statistics VRRP Virtual IP Table Add Virtual IP Interface: VLAN1 VRID: 100 Interface IP: Primary IP Secondary IP Virtual IP: 192.168.0.101 (Format:192.168.0.1) Cancel Create

Figure 2-8 VRRP Virtual IP Table

Basic Config Advanced Config Virtual IP Config Track Config Virtual Router Statistics VRRP Virtual IP Table VRID Interface Virtual IP Type 100 VLAN1 192.168.0.101 Primary IP Total: 1

Select: Select one or more items.

VRID: Displays the VRID associated with the VRRP.

Interface: Displays the Interface ID associated with the VRRP.

Virtual IP: Displays the Virtual IP associated with the VRRP.

Apply: Click the Apply button to make the modification take effect. You should not select more than one item at one time.

Delete: Delete the selected Virtual IP.

4. Choose the menu L3 FEATURES > VRRP > Track Config to configure Track information for virtual routers.

Figure 2-9 Track ConfigBasic Config Advanced Config Virtual IP Config Track Config Virtual Router Statistics Track Table Add Delete Refresh VRID Interface Tracked Interface Reduced Priority Link State No entries in this table. Total: 0

1) Click Add to load the configuration page.

2) Enter the VRID, interface ID, tracked interface and reduced priority, then click Create.

Figure 2-10 Add TrackBasic Config Advanced Config Virtual IP Config Track Config Virtual Router Statistics Track Table Add Delete Refresh VRID Interface Tracked Interface Reduced Priority Link State No entries in this table. Total: 0 Add Track Interface: VLAN1 VRID: 100 Interface: VLAN 2 (1-4094) Reduced Priority: 30 (1…

Figure 2-11 Track TableBasic Config Advanced Config Virtual IP Config Track Config Virtual Router Statistics Track Table Add Delete Refresh VRID Interface Tracked Interface Reduced Priority Link State 100 VLAN1 VLAN2 30 OT Total: 1

Figure 2-12 VRRP Table_Priority Reduced

Basic Config Advanced Config Virtual IP Config Track Config Virtual Router Statistics VRRP Table Add Delete Refresh VRID Interface IP Virtual IP Priority Status Operation 100 192.158.0.1 192.168.0.100 90 Master Detal Total: 1

Select: Select one or more items.

VRID: Displays the VRID associated with the VRRP.

Interface: Displays the Interface ID associated with the VRRP.

Tracked Interface: Displays the Interface ID tracked by the VRRP.

Reduced Priority: Displays the reduced priority associated with the Interface tracked by the VRRP.

Link Status: Displays the status of the Interface tracked by the VRRP.

Apply: Change the selected reduced priority. A new reduced priority should be provided before the 'Apply' button is clicked.

Delete: Delete the selected Interface.

Refresh: Update the link state of the Interface tracked.

4. Choose the menu L3 FEATURES > VRRP > Virtual Router Statistics to check the statistics of the VRRP created.

Figure 2-13 Virtual Router StatisticsBasic Config Advanced Config Virtual IP Config Track Config Virtual Router Statistics Global Statistics Global Statistics Router Checksum Errors: 0 Router Version Errors: 0 Router VRID Errors: 0 Statistics Refresh Clear VRID Interface State Transitioned to Master Advertisement Received Advertisement…

VRID: The VRID for the selected Virtual Router.

Interface The interface ID for the selected Virtual Router.
State Transitioned to MasterState Transitioned to Master Displays the number of times that this virtual router's state has transitioned to Master.
Advertisement ReceivedDisplays the number of VRRP advertisements received by this virtual router.
Advertisement Sent Displays the number of VRRP advertisements sent by this virtual router.
Advertisement Interval ErrorsDisplays the number of the received VRRP advertisement packets whose advertisement interval was different from the one configured for the local virtual router.
Authentication FailureDisplays the number of VRRP packets received that did not pass the authentication check.
IP TTL ErrorsDisplays the number of VRRP packets received by the virtual router with IP TTL (Time-To-Live) not equal to 255.
Zero Priority Packets ReceivedDisplays the number of VRRP packets received by the virtual router with a priority of '0'.
Zero Priority Packets SentDisplays the number of VRRP packets sent by the virtual router with a priority of '0'.
Invalid Type Packets ReceivedDisplays the number of VRRP packets received by the virtual router with an invalid value in the 'type' field.
Address List ErrorsDisplays the number of packets received for which the address list does not match the locally configured list for the virtual router.
Invalid Authentication TypeDisplays the number of packets received with an unknown authentication type.
Authentication Type MismatchDisplays the number of packets received with an authentication type different to the locally configured authentication method.
Packet Length ErrorsDisplays the number of packets received with a packet length less than the length of the VRRP header.
Clear Clear the statistics displayed on the web.

Refresh the web page to show the latest VRRP information.

2.2

2.3 Using the CLI

2.3.1 Configuring VRRP on Specified Ports

Follow these steps to configure VRRP on specified ports:

Step 1configureEnter global configuration mode.
Step 2interface {vlan vid | fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel }]Enter interface configuration mode.
Step 3ip vrrp vrid vrid-indexEnable the VRRP-V2 protocol on the interface and specify the virtual router ID for it. To disable the protocol on the interface, use the no ip vrrp vrid command.vrid-index:Virtual router ID, ranging from 1 to 255.
Step 4ipv6 vrrp vrid vrid-indexEnable the VRRP-V3 protocol on the interface and specify the virtual router ID for it. To disable the protocol on the interface, use the no ipv6 vrrp vrid command.vrid-index:Virtual router ID, ranging from 1 to 255.

Step 5: ip vrrp vrid vrid-index authentication-mod {simple | md5} password

Configure the authentication mode of the virtual router on the specified interface. To restore to the default authentication mode, use the no ip vrrp vrid authentication-mode command.

vrid-index: Virtual router ID, ranging from 1 to 255.

simple | md5: Authentication mode, by default it is None and no authentication will be performed. "simple" refers to using a text password for authentication, and "md5" refers to using a text password to perform the authentication of MD5, which has a higher security than Simple mode.

password: Password, a string of 1 to 8 alphabets, numbers or symbols. Passwords are case-sensitive, spaces allowed but leading spaces ignored, and cannot contain question marks. Empty by default.

Step 6: ip vrrp vrid vrid-index description description

Configure and modify the description for the virtual router. To delete the description, use the no ip vrrp vrid description command.

vrid-index: Virtual router ID, ranging from 1 to 255.

description: A string describing the virtual router, containing up to 256 characters, consisting only of numbers, English letters, and dashes.

Step 7: ip vrrp vrid vrid-index preempt-mode [timer-delay delay-value]

Configure the preemption mode and delay time of the specified virtual router on the interface. To set the specified virtual router on the interface to non-preempt mode, use the no ip vrrp vrid preempt-mode command. By default, the virtual router is in preempt mode.

vrid-index: Virtual router ID, ranging from 1 to 255.

delay-value: When the current primary router is deemed unavailable, the backup router waits before switching to the primary router. The value ranges from 0 to 255 seconds, and the default is 0.

Step 8 ip vrrp vrid vrid-index priority priority

Configure the priority of the specified virtual router on the interface. To restore the default priority, use the no ip vrrp vrid priority command.

vrid-index: Virtual router ID, ranging from 1 to 255.

priority: Priority, value ranges from 1 to 254. The default priority is 100.

Step 9 ip vrrp vrid vrid-index timer-advertise adver-interval

Configure the frequency at which the specified virtual router sends advertisements on the interface. To restore the default advertisement interval, use the no ip vrrp vrid timer-advertise command.

vrid-index: Virtual router ID, ranging from 1 to 255.

adver-interval: Advertisement interval, for VRRP-V2, the value range is 1~255, the unit is seconds, the default is 1 second; for VRRP-V3, the value range is 100~4095, the unit is centiseconds, the default is 100 centiseconds.

Step 10 ip vrrp vrid vrid-index track interface {{fastEthernet | gigabitEthernet | hundred-gigabitEthernet | ten-gigabitEthernet | twentyFive-gigabitEthernet | two-gigabitEthernet} port / port-channel portchannel-id / vlan vlan-id} [reduce-priority priority]

Configure the specified virtual router on the interface to add a tracking interface. To delete the tracking interface, use the no ip vrrp vrid track interface command.

port: Port number.

portchannel-id: LAG group number.

vrid-index: Virtual router ID, ranging from 1 to 255.

priority: Decreasing priority of the tracked interface, ranging from 1 to 254, and the default is 10.

Step 11: ip vrrp vrid vrid-index version vrrp-version

Configure or switch the VRRP version of the specified virtual router on the interface. The default is VRRP-V2.

vrid-index: Virtual router ID, ranging from 1 to 255.

vrrp-version: VRRP protocol version, the value is 2 or 3. Due to the differences between VRRP-V2 and VRRP-V3, version switching is only allowed when authentication is not configured, ipv6 virtual address is not configured, and the default notification time is used.

Step 12: ip vrrp vrid vrid-index virtual-ip virtual-ip

Add a primary virtual IPv4 address to a virtual router. Each virtual router has only one primary virtual IP that cannot be deleted. If the virtual router does not exist, a VRRP-V2 version of the virtual router will be automatically created.

vrid-index: Virtual router ID, ranging from 1 to 255.

virtual-ip: The virtual IP address of the virtual router, which must be in the same network segment as the interface.

Step 13: ip vrrp vrid vrid-index virtual-ip virtual-ip secondary

Add a secondary virtual IPv4 address to a virtual router. Each virtual router can be configured with up to 32 IP addresses. To delete the corresponding secondary virtual IP address, use the no ip vrrp vrid virtual-ip secondary command.

vrid-index: Virtual router ID, ranging from 1 to 255.

virtual-ip: The virtual IP address of the virtual router, which must be in the same network segment as the interface.

Step 14: ipv6 vrrp vrid vrid-index address virtual-linklocal link-local

Add a virtual IPv6 link-local address to a virtual router. Each virtual router has only one virtual link-local address. If the virtual router does not exist, a VRRP-V3 version of the virtual router will be automatically created. To delete the virtual link-local address, use the no ipv6 vrrp vrid address link-local command.

vrid-index: Virtual router ID, ranging from 1 to 255.

virtual-linklocal: The virtual link-local address of the virtual router. The address prefix should be the fe80::/10 standard IPv6 address.

Step 15 ipv6 vrrp vrid vrid-index address virtual-ipv6

Add a virtual IPv6 address to a virtual router. Each virtual router can be configured with up to 32 IPv6 addresses. To delete the virtual address, use the no ipv6 vrrp vrid address command.

vrid-index: Virtual router ID, ranging from 1 to 255.

virtual-ipv6: The global IPv6 address of the virtual router, which must be in the same network segment as the interface IPv6 address.

Step 16 show ip vrrp [vrid vrid-index] [interface {{fastEthernet | gigabitEthernet | hundred-

gigabitEthernet | ten-gigabitEthernet | twentyFive-gigabitEthernet | two-gigabitEthernet } port / port-channel portchannel-id / vlan vlan-id}]

Display basic configuration information of all virtual routers or a specified virtual router.

vrid-index: Virtual router ID, ranging from 1 to 255.

fastEthernet | gigabitEthernet | hundred-gigabitEthernet | ten-gigabitEthernet | twentyFive-gigabitEthernet | two-gigabitEthernet: Port type, which must be a layer 3 interface.

port: Port number.

portchannel-id: LAG group number.

vlan-id: VLAN value

Step 17 show ip vrrp statistics [vrid vrid-index] [interface {{fastEthernet | gigabitEthernet | hundred-

gigabitEthernet | ten-gigabitEthernet | twentyFive-gigabitEthernet | two-gigabitEthernet } port / port-channel portchannel-id / vlan vlan-id}

Display statistics for all virtual routers or a specified virtual router.

vrid-index: Virtual router ID, ranging from 1 to 255.

fastEthernet | gigabitEthernet | hundred-gigabitEthernet | ten-gigabitEthernet | twentyFive-gigabitEthernet | two-gigabitEthernet: Port type, which must be a layer 3 interface.

port: Port number.

portchannel-id: LAG group number.

vlan-id: VLAN value

Step 18 end

Return to privileged EXEC mode.

Step 19 copy running-config startup-config

Save the settings in the configuration file.

Step 20 clear ip vrrp statistics

Clear the statistics of all virtual routers on the switch.

The following example shows how to configure VRRP on a specified port.

Switch#configure

Switch(config)#interface vlan 2

Switch(config-if)#ip vrrp vrid 5

Switch(config-if)#ip vrrp vrid 5 authentication-mode md5 123

Switch(config-if)#ip vrrp vrid 5 description vr5

Switch(config-if)#ip vrrp vrid 5 preempt-mode timer-delay 12

Switch(config-if)#ip vrrp vrid 5 priority 110

Switch(config-if)#ip vrrp vrid 5 timer-advertise 12

Switch(config-if)#ip vrrp vrid 5 track interface vlan 3 reduce-priority 20

Switch(config-if)#ip vrrp vrid 5 version 3

Switch(config-if)#ip vrrp vrid 5 virtual-ip 192.168.0.10

Switch(config-if)#ip vrrp vrid 5 virtual-ip 192.168.0.11 secondary

Switch(config-if)#ipv6 vrrp vrid 5 address fe80::10 link-local

Switch(config-if)#ipv6 vrrp vrid 5 address 3001::1

Switch(config-if)#show ip vrrp vrid 5 interface vlan 2

Interface: VLAN2

VRID: 5

Version: 2

Description: vr5

Interface IP(v4):

Interface Link-Local IP(v6): fe80::5ee9:31ff:fe43:31fa

...

Switch(config-if)#end

Switch#copy running-config startup-config

Switch#clear ip vrrp statistics

3 Appendix: Default Parameters

Default settings of VRRP are listed in the following tables.

Table 3-1 Default Settings of VRRP

Parameter Default Setting
Description N/A
Priority 100
Advertise Timer 100
Preempt Mode Enable
Delay Time 0
Authentication None
Key N/A
adver-interval (VRRP-V2) 1
adver-interval (VRRP-V3) 100
track priority 10
vrrp-version VRRP-V2

Part 24

Configuring QoS

CHAPTERS

  1. QoS
  2. Class of Service Configuration
  3. QoS for VLAN Configuration
  4. WRED Configuration
  5. Bandwidth Control Configuration
  6. OUI-Based VLAN Configuration
  7. Voice VLAN Configuration
  8. Auto VoIP Configuration
  9. Configuration Examples
  10. Appendix: Default Parameters

1 QoS

1.1 Overview

With network scale expanding and applications developing, internet traffic is dramatically increased, thus resulting in network congestion, packet drops and long transmission delay. Typically, networks treat all traffic equally on FIFO (First In First Out) delivery basis, but nowadays many special applications like VoD, video conferences, VoIP, etc, require more bandwidth or shorter transmission delay to guarantee the performance.

With QoS (Quality of Service) technology, you can classify and prioritize network traffic to provide differentiated services to certain types of traffic.

1.2 Supported Features

You can configure the class of service, bandwidth control, OUI-Based VLAN, Voice VLAN, and Auto VoIP features on the switch to maximize network performance and bandwidth utilization.

Class of Service

The switch classifies the ingress packets, maps the packets to different priority queues, and then forwards the packets according to specified scheduler settings to implement QoS function.

■ Priority Mode: Three modes are supported: Port Priority, 802.1p Priority, and DSCP Priority. ■ Scheduler Mode: Two scheduler types are supported: Strict and Weighted.

QoS for VLAN

The QoS for VLAN feature aims to configure a specific 802.1P/DSCP priority for a VLAN after it has been set up. This allows packets within that VLAN to be prioritized based on the 802.1P/DSCP priority level specified.

TP-LINK Omada Pro S5500-24GP4F - QoS for VLAN - 1

Note:

QoS for VLAN is only available when the switch is adopted by the Omada Pro SDN Controller.

WRED

WRED (Weighted Random Early Detection) is a congestion avoidance mechanism. When network traffic experiences congestion, it regulates the congestion situation by proactively discarding packets that may cause congestion, thus preventing the TCP global synchronization phenomenon. WRED determines the actual drop probability by setting lower thresholds, upper thresholds, and maximum drop probabilities.

Bandwidth Control

Bandwidth Control functions to control the traffic rate and traffic threshold on each port to ensure network performance.

■ Rate limit functions to limit the ingress/egress traffic rate on each port. In this way, the network bandwidth can be reasonably distributed and utilized. ■ Storm Control function allows the switch to monitor broadcast packets, multicast packets, and UL-frames (Unknown unicast frames) in the network. If the transmission rate of the packets exceeds the set rate, the packets will be automatically discarded to avoid network broadcast storm.

OUI-Based VLAN

OUI-Based VLAN (Organizationally Unique Identifier-Based Virtual Local Area Network) is a functionality that transmits and modifies the 802.1p priority of packets within a specified VLAN based on the source MAC address of the packets. Similar to Voice VLAN, OUI-Based VLAN differs in the following ways:

■ OUI-Based VLAN does not provide users with default templates for OUI entries; users can configure them themselves. ■ Voice VLAN can only specify one VLAN as the Voice VLAN, whereas OUI-Based VLAN can assign different VLANs to different OUI entries. ■ The mask length for Voice VLAN is fixed, while OUI-Based VLAN allows for variable-length masks to be set for MAC addresses during configuration. ■ For each OUI entry, OUI-Based VLAN can specify which port the entry applies to.

Voice VLAN and Auto VoIP

The voice VLAN and Auto VoIP features are used to prioritize the transmission of voice traffic. Voice traffic is typically more time-sensitive than data traffic, and the voice quality can deteriorate a lot because of packet loss and delay. To ensure the high voice quality, you can configure Voice VLAN or Auto VoIP.

These two features can be enabled on the ports that transmit voice traffic only or transmit both voice traffic and data traffic. Voice VLAN can change the voice packets' 802.1p priority and transmit the packets in desired VLAN. Auto VoIP can inform the voice devices of send the packets with specific configuration by working with the LLDP-MED feature.

2 Class of Service Configuration

With class of service configurations, you can:

■ Configure port priority ■ Configure 802.1p priority ■ Configure DSCP priority ■ Specify the scheduler settings

Configuration Guidelines

■ Select the priority mode that the ports trust according to your network requirements.

A port can use only one priority to classify the ingress packets. Three priority modes are supported on the switch: Port Priority, 802.1P Priority and DSCP Priority.

■ Port Priority

In this mode, the switch prioritizes packets according to their ingress ports, regardless of the packet field or type.

■ 802.1P Priority

802.1P defines the first three bits in 802.1Q Tag as PRI field. The PRI values are from 0 to 7. 802.1P priority determines the priority of packets based on the PRI value.

In this mode, the switch only prioritizes packets with VLAN tag, regardless of the IP header of the packets.

■ DSCP Priority

DSCP priority determines the priority of packets based on the ToS (Type of Service) field in their IP header. RFC2474 re-defines the ToS field in the IP packet header as DS field. The first six bits (bit 0-bit 5) of the DS field is used to represent DSCP priority. The DSCP values are from 0 to 63.

In this mode, the switch only prioritizes IP packets.

■ Specify the 802.1p to queue mapping according to your needs.

For 802.1p Priority, the packets will be forwarded according to the 802.1p to queue mapping directly.

For Port Priority and DSCP Priority, the port priority and DSCP priority will first be mapped to the 802.1p priority, and then mapped to the queue according to the 802.1p to queue mapping.

2.1 Using the GUI

2.1.1 Configuring Port Priority

■ Configuring the Trust Mode and Port to 802.1p Mapping

Choose the menu QoS > Class of Service > Port Priority to load the following page.

Figure 2-1 Configuring the Trust Mode and Port to 802.1p MappingPort Priority Config UNIT1 LAGS Port 802.1p Priority Trust Mode LAG 1/0/1 0 Untrusted -- 1/0/2 0 Untrusted -- 1/0/3 0 Untrusted -- 1/0/4 0 Untrusted -- 1/0/5 0 Untrusted -- 1/0/6 0 Untrusted -- 1/0/7 0 Untrusted -- 1/0/8 0 Untrusted -- 1/0/9 0 Untrusted -- 1/0/10 0 Untrusted -- Total: 54

Follow these steps to configure the parameters of the port priority:

1) Select the desired ports, specify the 802.1p priority and set the trust mode as Untrusted.

802.1p PrioritySpecify the port to 802.1p priority mapping for the desired port. The ingress packets are first mapped to 802.1p priority, then to TC queues according to the 802.1p to queue mappings. The untagged packets from one port will be added an 802.1p priority value according to the port to 802.1p priority mapping.
Trust ModeSelect the Trust mode for the desired port. The switch will process the ingress packets according to the trusted priority mode.Untrusted: In this mode, the packets will be processed according to the port priority configuration.Trust 802.1p: In this mode, the packets will be processed according to the 802.1p priority configuration.Trust DSCP: In this mode, the packets will be processed according to the DSCP priority configuration.

LAG Displays the LAG that the port belongs to.

2) Click Apply.

■ Configuring the 802.1p to Queue Mapping

Choose the menu QoS > Class of Service > 802.1p Priority to load the following page.

Figure 2-2 Configuring the 802.1p to Queue Mapping802.1p to Queue Mapping 802.1p Priority Queue 0: TC-1 1: TC-0 2: TC-2 3: TC-3 4: TC-4 5: TC-5 6: TC-6 7: TC-7 802.1p Remap 802.1p Priority Remap 0: 0 1: 1 2: 2 3: 3 4: 4 5: 5 6: 6 7: 7 Apply Apply

In the 802.1p to Queue Mapping section, configure the mappings and click Apply.

802.1p PriorityDisplays the number of 802.1p priority. In QoS, 802.1p priority is used to represent class of service.
Queue Select the TC queue for the desired 802.1p priority. The packets with the desired 802.1p priority will be put in the corresponding queue.

2.1.2 Configuring 802.1p Priority

■ Configuring the Trust Mode

Choose the menu QoS > Class of Service > Port Priority to load the following page.

Figure 2-3 Configuring the Trust ModePort Priority Config UNIT1 LAGS Port 802.1p Priority Trust Mode LAG 1/0/1 0 Untrusted -- 1/0/2 0 Untrusted -- 1/0/3 0 Untrusted -- 1/0/4 0 Untrusted -- 1/0/5 0 Untrusted -- 1/0/6 0 Untrusted -- 1/0/7 0 Untrusted -- 1/0/8 0 Untrusted -- 1/0/9 0 Untrusted -- 1/0/10 0 Untrusted -- Total: 54

Follow these steps to configure the trust mode:

1) Select the desired ports and set the trust mode as Trust 802.1p.

Trust ModeSelect the Trust mode for the desired port. The switch will process the ingress packets according to the trusted priority mode.
Untrusted: In this mode, the packets will be processed according to the port priority configuration.
Trust 802.1p: In this mode, the packets will be processed according to the 802.1p priority configuration.
Trust DSCP: In this mode, the packets will be processed according to the DSCP priority configuration.

2) Click Apply.

■ Configuring the 802.1p to Queue Mapping and 802.1p Remap

For Certain Devices:

Choose the menu QoS > Class of Service > 802.1p Priority to load the following page.

Figure 2-4 Configuring the 802.1p to Queue Mapping and 802.1p Remap802.1p to Queue Mapping 802.1p Priority Queue 0: TC-0 1: TC-1 2: TC-2 3: TC-3 4: TC-4 5: TC-5 6: TC-6 7: TC-7 Apply 802.1p Remap UNIT1 LAGS Port 0 1 2 3 4 5 6 7 LAG ✓ 1/0/1 0 1 2 3 4 5 6 7 -- □ 1/0/2 0 1 2 3 4 5 6 7 -- □ 1/0/3 0 1 2 3 4 5 6 7 -- □ 1/0/4 0 1 2 3 4 5 6 7 -- □ 1/0/5 0 1 2 3 4 5 6 7 --…

Follow these steps to configure the parameters of the 802.1p priority:

1) In the 802.1p to Queue Mapping section, configure the mappings and click Apply.

802.1p Priority

Displays the number of 802.1p priority. In QoS, 802.1p priority is used to represent class of service. IEEE 802.1p standard defines three bits in 802.1Q tag as PRI field. The PRI values are called 802.1p priority and used to represent the priority of the layer 2 packets. This function requires packets with VLAN tags.

Queue Select the TC queue for the desired 802.1p priority. The packets with the desired 802.1p priority will be put in the corresponding queue.

2) (Optional) In the 802.1p Remap section, configure the 802.1p to 802.1p mappings for ports and click Apply.

0 - 7

Select the number of 802.1p priority to which the desired 802.1p priority will be remapped. 802.1p Remap is used to modify the 802.1p priority of the ingress packets. When the switch detects the packets with desired 802.1p priority, it will modify the value of 802.1p priority according to the map.

For Certain Devices:

Choose the menu QoS > Class of Service > 802.1p Priority to load the following page.

Figure 2-5 Configuring the 802.1p to Queue Mapping and 802.1p Remap802.1p to Queue Mapping 802.1p Priority Queue 0: TC-1 1: TC-0 2: TC-2 3: TC-3 4: TC-4 5: TC-5 6: TC-6 7: TC-7 802.1p Remap 802.1p Priority Remap 0: 0 1: 1 2: 2 3: 3 4: 4 5: 5 6: 6 7: 7 Apply Apply

Follow these steps to configure the parameters of the 802.1p priority:

1) In the 802.1p to Queue Mapping section, configure the mappings and click Apply.

802.1p Priority

Displays the number of 802.1p priority. In QoS, 802.1p priority is used to represent class of service. IEEE 802.1p standard defines three bits in 802.1Q tag as PRI field. The PRI values are called 802.1p priority and used to represent the priority of the layer 2 packets. This function requires packets with VLAN tags.

Queue Select the TC queue for the desired 802.1p priority. The packets with the desired 802.1p priority will be put in the corresponding queue.

2) (Optional) In the 802.1p Remap section, configure the 802.1p to 802.1p mappings and click Apply.

802.1p PriorityDisplays the number of 802.1p priority. In QoS, 802.1p priority is used to represent class of service. IEEE 802.1p standard defines three bits in 802.1Q tag as PRI filed. The PRI values are called 802.1p priority and used to represent the priority of the layer 2 packets. This function requires packets with VLAN tags.
RemapSelect the number of 802.1p priority to which the original 802.1p priority will be remapped. 802.1p Remap is used to modify the 802.1p priority of the ingress packets. When the switch detects the packets with desired 802.1p priority, it will modify the value of 802.1p priority according to the map.

TP-LINK Omada Pro S5500-24GP4F - For Certain Devices: - 2

Note:

In Trust 802.1p mode, the untagged packets will be added an 802.1p priority based on the port to 802.1p mapping and will be forwarded according to the 802.1p to queue mapping.

2.1.3 Configuring DSCP Priority

■ Configuring the Trust Mode

Choose the menu QoS > Class of Service > Port Priority to load the following page.

Figure 2-6 Configuring the Trust ModePort Priority Config UNIT1 LAGS Port 802.1p Priority Trust Mode LAG 1/0/1 0 Untrusted -- 1/0/2 0 Untrusted -- 1/0/3 0 Untrusted -- 1/0/4 0 Untrusted -- 1/0/5 0 Untrusted -- 1/0/6 0 Untrusted -- 1/0/7 0 Untrusted -- 1/0/8 0 Untrusted -- 1/0/9 0 Untrusted -- 1/0/10 0 Untrusted -- Total: 54

Follow these steps to configure the trust mode:

1) Select the desired ports and set the trust mode as Trust DSCP.

Trust Mode

Select the Trust mode for the desired port. The switch will process the ingress packets according to the trusted priority mode.

Untrusted: In this mode, the packets will be processed according to the port priority configuration.

Trust 802.1p: In this mode, the packets will be processed according to the 802.1p priority configuration.

Trust DSCP: In this mode, the packets will be processed according to the DSCP priority configuration.

2) Click Apply.

■ Configuring the 802.1p to Queue Mapping

Choose the menu QoS > Class of Service > 802.1p Priority to load the following page.

Figure 2-7 Configuring the 802.1p to Queue Mapping802.1p to Queue Mapping 802.1p Priority Queue 0: TC-1 1: TC-0 2: TC-2 3: TC-3 4: TC-4 5: TC-5 6: TC-6 7: TC-7 802.1p Remap 802.1p Priority Remap 0: 0 1: 1 2: 2 3: 3 4: 4 5: 5 6: 6 7: 7 Apply Apply

In the 802.1p to Queue Mapping section, configure the mappings and click Apply.

802.1p Priority

Displays the number of 802.1p priority. In QoS, 802.1p priority is used to represent class of service.

Queue Select the TC queue for the desired 802.1p priority. The packets with the desired 802.1p priority will be put in the corresponding queue.

■ Configuring the DSCP to 802.1p Mapping and the DSCP Remap

For Certain Devices:

Choose the menu QoS > Class of Service > DSCP Priority to load the following page.

Figure 2-8 Configuring the DSCP to 802.1p Mapping and the DSCP RemapDSCP Priority Config DSCP Priority 802.1p Priority DSCP Remap 0 0 0 be (000000) 1 0 1 2 0 2 3 0 3 4 0 4 5 0 5 6 0 6 7 0 7 8 1 8 cs1 (001000) 9 1 9 Total: 64 1 entry selected. Cancel Apply

Follow these steps to configure the DSCP Priority:

1) Select the desired port, configure the DSCP to 802.1p mapping and the DSCP remap.

DSCP PriorityDisplays the number of DSCP priority. DSCP Priority is used to classify the packets based on the value of DSCP, and map them to different queues. ToS (Type of Service) is a part of IP header, and DSCP uses the first six bits of ToS to represent the priority of IP packets. The DSCP values range from 0 to 63.
802.1p PrioritySpecify the DSCP to 802.1p mapping for the desired port. The ingress packets are first mapped to 802.1p priority, then to TC queues according to the 802.1p to queue mappings.
DSCP Remap(Optional) Select the DSCP priority to which the desired DSCP priority will be remapped for the port. When the switch detects the packets with desired DSCP value, it will modify the packets' DSCP value according to the map.

2) Click Apply.

For Certain Devices:

Choose the menu QoS > Class of Service > DSCP Priority to load the following page.

Figure 2-9 Configuring the DSCP to 802.1p Mapping and the DSCP RemapDSCP Priority Config □ DSCP Priority 802.1p Priority DSCP Remap ✓ 0 0 0 be (000000) □ 1 0 1 □ 2 0 2 □ 3 0 3 □ 4 0 4 □ 5 0 5 □ 6 0 6 □ 7 0 7 □ 8 1 8 cs1 (001000) □ 9 1 9 Total: 64 1 entry selected. Cancel Apply

Follow these steps to configure the DSCP Priority:

1) In the DSCP Priority Config section, configure the DSCP to 802.1p mapping and the DSCP remap.

DSCP PriorityDisplays the number of DSCP priority. DSCP Priority is used to classify the packets based on the value of DSCP, and map them to different queues. ToS (Type of Service) is a part of IP header, and DSCP uses the first six bits of ToS to represent the priority of IP packets. The DSCP values range from 0 to 63.
802.1p PrioritySpecify the DSCP to 802.1p mapping for the desired port. The ingress packets are first mapped to 802.1p priority, then to TC queues according to the 802.1p to queue mappings.
DSCP Remap(Optional) Select the DSCP priority to which the desired DSCP priority will be remapped for the port. When the switch detects the packets with desired DSCP value, it will modify the packets' DSCP value according to the map.

2) Click Apply.

TP-LINK Omada Pro S5500-24GP4F - For Certain Devices: - 2

Note:

In Trust DSCP mode, non-IP packets will be added an 802.1p priority based on the port to 802.1p mapping and will be forwarded according to the 802.1p to queue mapping.

2.1.4 Specifying the Scheduler Settings

Specify the scheduler settings to control the forwarding sequence of different TC queues when congestion occurs.

For Certain Devices:

Choose the menu QoS > Class of Service > Scheduler Settings to load the following page.

Figure 2-10 Specifying the Scheduler Settings

Scheduler Config
Queue TC-idScheduler TypeQueue WeightManagement Type
0Weighted1Taildrop
1Weighted1Taildrop
2Weighted1Taildrop
3Weighted1Taildrop
4Weighted1Taildrop
5Weighted1Taildrop
6Weighted1Taildrop
7Weighted1Taildrop
Total: 8

Follow these steps to configure the schedule mode:

1) In the Scheduler Config section, select the desired port. 2) Select the desired queue and configure the parameters.

Queue TC-id Displays the ID number of priority Queue.
Scheduler TypeSelect the type of scheduling used for corresponding queue. When the network congestion occurs, the port will determine the forwarding sequence of the packets according to the type.
Strict: In this mode, the switch will use SP (Strict Priority) to process the traffic in different queues. When congestion occurs, the traffic will be transmitted according to its queue priority strictly. The queue with higher priority occupies the whole bandwidth. Packets in the queue with lower priority are sent only when the queue with higher priority is empty.
Weighted: In this mode, the switch will use WRR (Weighted Round Robin) to process the traffic in different queues. When congestion occurs, all the traffic will be transmitted, but the bandwidth that each traffic queue occupies will be allocated based on the queue weight.
Note: If the two scheduler types are both applied to a port, the queues in Strict mode will take precedence.
Queue WeightSpecify the queue weight for the desired queue. This value can be set only in the Weighted mode. The valid values are from 1 to 127.
Management TypeDisplays the Management Type for the queues. The switch currently supports Taildrop mode. When the traffic exceeds the limit, the additional traffic will be dropped.

3) Click Apply.

For Certain Devices:

Choose the menu QoS > Class of Service > Scheduler Settings to load the following page.

Figure 2-11 Specifying the Scheduler SettingsScheduler Config UNIT1 LAGS 2 4 6 8 10 12 14 16 18 20 22 24 26 28 1 3 5 7 9 11 13 15 17 19 21 23 25 27 Selected Unselected Not Available Port 1/0/1 Queue TC-id Scheduler Type Queue Weight Management Type ✓ 0 Weighted 1 Taildrop □ 1 Weighted 1 Taildrop □ 2 Weighted 1 Taildrop □ 3 Weighted 1 Taildrop…

Follow these steps to configure the schedule mode:

1) In the Scheduler Config section, select the desired queue and configure the parameters.

Queue TC-id Displays the ID number of priority Queue.

Scheduler Type

Select the type of scheduling used for corresponding queue. When the network congestion occurs, the port will determine the forwarding sequence of the packets according to the type.

Strict: In this mode, the switch will use SP (Strict Priority) to process the traffic in different queues. When congestion occurs, the traffic will be transmitted according to its queue priority strictly. The queue with higher priority occupies the whole bandwidth. Packets in the queue with lower priority are sent only when the queue with higher priority is empty.

Weighted: In this mode, the switch will use WRR (Weighted Round Robin) to process the traffic in different queues. When congestion occurs, all the traffic will be transmitted, but the bandwidth that each traffic queue occupies will be allocated based on the queue weight.

Note: If the two scheduler types are both applied to a port, the queues in Strict mode will take precedence.

Queue WeightSpecify the queue weight for the desired queue. This value can be set only in the Weighted mode. The valid values are from 1 to 127.
Management TypeDisplays the Management Type for the queues. The switch currently supports Taildrop mode. When the traffic exceeds the limit, the additional traffic will be dropped.

2) Click Apply.

TP-LINK Omada Pro S5500-24GP4F - 2) Click Apply. - 1

Note:

With the ACL Redirect feature, the switch maps all packets that meet the configured ACL rules to the new TC queue, regardless of the mapping relations configured in this section.

2.2 Using CLI

2.2.1 Configuring Port Priority

■ Configuring the Trust Mode and the Port to 802.1p Mapping

Follow these steps to configure the trust mode and the port to 802.1p mapping:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 3 qos trust mode { untrust | dot1p | dscp}

Select the trust mode for the port. By default, it is untrust. Here we set the trust mode as untrust.

untrust: Specify the port's trust mode as untrust. In this mode, the packets will be processed according to the port priority configuration.

Step 4 qos port-priority { dot1p-priority}

Specify the port to 802.1p priority mapping for the desired port. The ingress packets from one port are first mapped to 802.1p priority based on the port to 802.1p mapping, then to TC queues based on the 802.1p to queue mapping. The untagged packets from one port will be added an 802.1p priority value according to the port to 802.1p mapping.

dot1p-priority: Specify the 802.1p priority ranging from 0 to 7. The default value is 0.

Step 5: show qos trust interface [fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel-id]

Verify the trust mode of the ports.

Step 6: show qos port-priority interface [fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel-id]

Verify the port to 802.1p mappings.

Step 7: end

Return to privileged EXEC mode.

Step 8: copy running-config startup-config

Save the settings in the configuration file.

Configuring the 802.1p to Queue Mapping

Follow these steps to configure the 802.1p to queue mapping:

Step 1: configure

Enter global configuration mode.

Step 2: qos cos-map { dot1p-priority } {tc-queue}

Specify the 802.1p to queue mapping. The packets with the desired 802.1p priority will be put in the corresponding queues. By default, the 802.1p priority 0 to 7 is respectively mapped to TC-1, TC-0, TC-2, TC-3, TC-4, TC-5, TC-6, TC-7.

dot1p-priority: Specify the 802.1p priority. The valid values are from 0 to 7.

tc-queue: Specify the ID number of the TC queue. The valid values are from 0 to 7.

Step 3 show qos cos-map

Verify the 802.1p to queue mappings.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the trust mode of port 1/0/1 as untrust, map the port 1/0/1 to 802.1p priority 1 and map 802.1p priority 1 to TC3:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#qos trust mode untrust

Switch(config-if)#qos port-priority 1

Switch(config-if)#exit

Switch(config)#qos cos-map 1 3

Switch(config)#show qos trust interface gigabitEthernet 1/0/1

Port Trust Mode LAG

Gi1/0/1 untrust N/A

Switch(config)#show qos port-priority interface gigabitEthernet 1/0/1

Port CoS Value LAG

Gi1/0/1 CoS 1 N/A

Switch(config)#show qos cos-map

+ + + + + + + + +

Dot1p Value |0 |1 |2 |3 |4 |5 |6 |7

+ + + + + + + +

TC |TC0 |TC3 |TC2 |TC3 |TC4 |TC5 |TC6 |TC7

Switch(config)#end

Switch#copy running-config startup-config

2.2.2 Configuring 802.1p Priority

■ Configuring the Trust Mode

Follow these steps to configure the trust mode:

Step 1 configure

Enter global configuration mode

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 3 qos trust mode { untrust | dot1p | dscp}

Select the trust mode for the port. By default, it is untrust. Here we set the trust mode as dot1p.

dot1p: Specify the ports' trust mode as dot1p. In this mode, the tagged packets will be processed according to the 802.1p priority configuration and the untagged packets will be processed according to the port priority configuration.

Step 4 show qos trust interface [fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel-id]

Verify the trust mode of the ports.

Step 5 end

Return to privileged EXEC mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

■ Configuring the 802.1p to Queue Mapping and 802.1p Remap

Follow these steps to configure the 802.1p to queue mapping and 802.1p remap:

Step 1 configure

Enter global configuration mode

Step 2 qos cos-map { dot1p-priority } {tc-queue}

Specify the 802.1p to queue mapping. The packets with the desired 802.1p priority will be put in the corresponding queues. By default, the 802.1p priority 0 to 7 is respectively mapped to TC-1, TC-0, TC-2, TC-3, TC-4, TC-5, TC-6, TC-7.

dot1p-priority: Specify the 802.1p priority. The valid values are from 0 to 7.

tc-queue: Specify the ID number of the TC queue. The valid values are from 0 to 7.

Step 3 For Certain Devices:

interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

qos dot1p-remap {dot1p-priority} {new-dot1p-priority}

(Optional) Specify the 802.1p to 802.1p mappings for the desired port. 802.1p Remap is used to modify the 802.1p priority of the ingress packets. When the switch detects the packets with desired 802.1p priority, it will modify the value of 802.1p priority according to the map. By default, the original 802.1p priority 0 is mapped to the 802.1p priority 0, the original 802.1p priority 1 is mapped to the 802.1p priority 1 and so on.

dot1p-priority: Specify the original 802.1p priority. The valid values are from 0 to 7.

new-dot1p-priority: Specify the new 802.1p priority. The valid values are from 0 to 7.

For Certain Devices:

qos dot1p-remap {dot1p-priority} {new-dot1p-priority}

(Optional) Specify the 802.1p to 802.1p mappings. 802.1p Remap is used to modify the 802.1p priority of the ingress packets. When the switch detects the packets with desired 802.1p priority, it will modify the value of 802.1p priority according to the map. By default, the original 802.1p priority 0 is mapped to the 802.1p priority 0, the original 802.1p priority 1 is mapped to the 802.1p priority 1 and so on.

dot1p-priority: Specify the original 802.1p priority. The valid values are from 0 to 7.

new-dot1p-priority: Specify the new 802.1p priority. The valid values are from 0 to 7.

Step 4 show qos cos-map

Verify the 802.1p to queue mappings.

Step 5 For Certain Devices:

show qos dot1p-remap interface [fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel-id]

Verify the 802.1p to 802.1p mappings of the ports.

For Certain Devices:

show qos dot1p-remap

Verify the 802.1p to 802.1p mappings globally.

Step 6 end

Return to privileged EXEC mode.

Step 7 copy running-config startup-config

Save the settings in the configuration file.

TP-LINK Omada Pro S5500-24GP4F - Configuring 802.1p Priority - 1

Note:

In Trust 802.1p mode, untagged packets will be assigned an 802.1p priority based on the port-to-802.1p mapping and will be forwarded according to the 802.1p-to-queue mapping.

The following example shows how to configure the trust mode of port 1/0/1 as dot1p, map 802.1p priority 3 to TC4, and configure to map the original 802.1p 1 to 802.1p priority 3:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#qos trust mode dot1p

Switch(config-if)#exit

Switch(config)#qos cos-map 3 4

Switch(config)#qos dot1p-remap 13

Switch(config)#show qos trust interface gigabitEthernet 1/0/1

PortTrust ModeLAG
------------------------

Gi1/0/1 trust 802.1P N/A

Switch(config)#show qos cos-map

+ + + + + + + + +

Dot1p Value |0 |1 |2 |3 |4 |5 |6 |7

+ + + + + + + +

TC |TC0 |TC1 |TC2 |TC4 |TC4 |TC5 |TC6 |TC7

+ + + + + + + +

Switch(config)#show qos dot1p-remap

Dot1p Value 0 1 2 3 4 5 6 7 LAG


Dot1p Remap 0 3 2 3 4 5 6 7 N/A

Switch(config)#end

Switch#copy running-config startup-config

2.2.3 Configuring DSCP Priority

■ Configuring the Trust Mode

Follow these steps to configure the trust mode:

Step 1 configure

Enter global configuration mode

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 3 qos trust mode { untrust | dot1p | dscp}

Select the trust mode for the port. By default, it is untrust. Here we set the trust mode as dscp.

dscp: Specify the ports' trust mode as dscp. In this mode, the IP packets will be processed according to the DSCP priority configuration and the non-IP packets will be processed according to the port priority configuration.

Step 4 show qos trust interface [fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel-id]

Verify the trust mode of the ports.

Step 5 end

Return to privileged EXEC mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

■ Configuring the 802.1p to Queue Mapping

Follow these steps to configure the 802.1p to queue mapping:

Step 1 configure

Enter global configuration mode

Step 2 qos cos-map { dot1p-priority } {tc-queue}

Specify the 802.1p to queue mapping. The packets with the desired 802.1p priority will be put in the corresponding queues. By default, the 802.1p priority 0 to 7 is respectively mapped to TC-1, TC-0, TC-2, TC-3, TC-4, TC-5, TC-6, TC-7.

dot1p-priority: Specify the 802.1p priority. The valid values are from 0 to 7.

tc-queue: Specify the ID number of the TC queue. The valid values are from 0 to 7.

Step 3 show qos cos-map

Verify the 802.1p to queue mappings.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

■ Configuring the DSCP to 802.1p Mapping and DSCP Remap

Follow these steps to configure the DSCP to 802.1p mapping and DSCP remap:

Step 1 configure

Enter global configuration mode

Step 2 For Certain Devices:

interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

qos dscp-map {dscp-value-list} {dot1p-priority}

Specify the DSCP to 802.1p mapping for the desired port. The ingress packets with the desired DSCP priority are first mapped to 802.1p priority based on the DSCP to 802.1p mapping, then to TC queues based on the 802.1p to queue mapping. By default, the DSCP priorities 0-7 are mapped to the 802.1p priority 0, the DSCP priorities 8-15 are mapped to the 802.1p priority 1 and so on.

dscp-value-list: Specify the DSCP value list in the format of "1-3,5,7". The valid values are from 0 to 63.

dot1p-priority: Specify the 802.1p priority. The valid values are from 0 to 7.

For Certain Devices:

qos dscp-map {dscp-value-list} {dot1p-priority}

Specify the DSCP to 802.1p mapping. The ingress packets with the desired DSCP priority are first mapped to 802.1p priority based on the DSCP to 802.1p mapping, then to TC queues based on the 802.1p to queue mapping. The untagged packets with the desired DSCP priority will be added an 802.1p priority value according to the DSCP to 802.1p mapping. By default, the DSCP priorities 0-7 are mapped to the 802.1p priority 0, the DSCP priorities 8-15 are mapped to the 802.1p priority 1 and so on.

dscp-value-list: Specify the DSCP value list in the format of "1-3,5,7". The valid values are from 0 to 63.

dot1p-priority: Specify the 802.1p priority. The valid values are from 0 to 7.

Step 3 qos dscp-remap { dscp-value-list } {dscp-remap-value}

(Optional) Specify the DSCP to DSCP mappings. DSCP Remap is used to modify the DSCP priority of the ingress packets. When the switch detects the packets with the desired DSCP priority, it will modify the value of DSCP priority according to the map. By default, the original DSCP priority 0 is mapped to the DSCP priority 0, the original DSCP priority 1 is mapped to the DSCP priority 1 and so on.

dscp-value-list: Specify the original DSCP priority list in the format of "1-3,5,7". The valid values are from 0 to 63.

dscp-remap-value: Specify the new DSCP priority. The valid values are from 0 to 63.

Step 4 For Certain Devices:

show qos dscp-map interface [fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel-id]

Verify the DSCP to queue mappings of ports.

For Certain Devices:

show qos dscp-map

Verify the DSCP to queue mappings globally.

Step 5 For Certain Devices:

show qos dscp-remap interface [fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channel port-channel-id]

Verify the DSCP to DSCP mappings of the ports.

For Certain Devices:

show qos dscp-remap

Verify the DSCP to DSCP mappings globally.

Step 6 end

Return to privileged EXEC mode.

Step 7 copy running-config startup-config

Save the settings in the configuration file.

TP-LINK Omada Pro S5500-24GP4F - Step 3 qos dscp-remap { dscp-value-list } {dscp-remap-value} - 1

Note:

In Trust DSCP mode, non-IP packets will be added an 802.1p priority based on the port to 802.1p mapping and will be forwarded according to the 802.1p to queue mapping.

The following example shows how to configure the trust mode of port 1/0/1 as dscp, map 802.1p priority 3 to TC4, map DSCP priority 1-3,5,7 to 802.1p priority 3, and configure to map the original DSCP priority 9 to DSCP priority 5:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#qos trust mode dscp

Switch(config-if)#exit

Switch(config)#qos cos-map 3 4

Switch(config)#qos dscp-map 1-3,5,7 3

Switch(config)#qos dscp-remap 9 5

Switch(config)#show qos trust interface gigabitEthernet 1/0/1

PortTrust ModeLAG
------------
Gi1/0/1trust DSCPN/A

Switch(config)#show qos cos-map

Dot1p Value01234567
TC|TC0|TC1|TC2|TC4|TC4|TC5|TC6|TC7

Switch(config)#show qos dscp-map

DSCP:01234567
DSCP to 802.1P03330303
--------------------------------
DSCP:89101112131415
DSCP to 802.1P11111111
--------------------------------
DSCP:1617181920212223
DSCP to 802.1P22222222
--------------------------------
DSCP:2425262728293031
DSCP to 802.1P33333333
--------------------------------
DSCP:3233343536373839
DSCP to 802.1P44444444
--------------------------------
DSCP:4041424344454647
DSCP to 802.1P55555555
--------------------------------
DSCP:4849505152535455
DSCP to 802.1P66666666
--------------------------------
DSCP:5657585960616263
DSCP to 802.1P77777777
--------------------------------

Switch(config)#show qos dscp-remap

DSCP:01234567
DSCP remap value01234567
--------------------------------
DSCP:89101112131415
DSCP remap value85101112131415
--------------------------------
DSCP:1617181920212223
DSCP remap value1617181920212223
--------------------------------
DSCP:2425262728293031
DSCP remap value2425262728293031
--------------------------------
DSCP:3233343536373839
DSCP remap value3233343536373839
--------------------------------
DSCP:4041424344454647
DSCP remap value4041424344454647
--------------------------------
DSCP:4849505152535455
DSCP remap value4849505152535455
--------------------------------
DSCP:5657585960616263
DSCP remap value5657585960616263
--------------------------------

Switch(config-if)#end

Switch#copy running-config startup-config

2.2.4 Specifying the Scheduler Settings

Follow these steps to specify the scheduler settings to control the forwarding sequence of different TC queues when congestion occurs.

Step 1 configure

Enter global configuration mode.

For Certain Devices:

interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

qos queue tc-queue mode {sp | wrr} [weight weight]

Specify the type of scheduling used for corresponding queue. When the network congestion occurs, the egress queue will determine the forwarding sequence of the packets according to the type. By default, it is wrr mode and the all the queue weights are 1.

tc-queue: Specify the ID number of TC queue. The valid values are from 0 to 7.

sp: In sp mode, the egress queue will use SP (Strict Priority) to process the traffic in different queues. When congestion occurs, the traffic will be transmitted according to its queue priority strictly. The queue with higher priority occupies the whole bandwidth. Packets in the queue with lower priority are sent only when the queue with higher priority is empty.

wrr: In wrr mode, the egress queue will use WRR (Weighted Round Robin) to process the traffic in different queues. When congestion occurs, all the traffic will be transmitted, but the bandwidth that each traffic queue occupies will be allocated based on the queue weight.

weight: Specify the queue weight for the desired queue. This value can be set only in the wrr mode. The valid values are from 1 to 127.

For Certain Devices:

qos queue tc-queue mode {sp | wrr} [weight weight]

Specify the type of scheduling used for corresponding queue. When the network congestion occurs, the egress queue will determine the forwarding sequence of the packets according to the type. By default, it is wrr mode and the all the queue weights are 1.

tc-queue: Specify the ID number of TC queue. The valid values are from 0 to 7.

sp: In sp mode, the egress queue will use SP (Strict Priority) to process the traffic in different queues. When congestion occurs, the traffic will be transmitted according to its queue priority strictly. The queue with higher priority occupies the whole bandwidth. Packets in the queue with lower priority are sent only when the queue with higher priority is empty.

wrr: In wrr mode, the egress queue will use WRR (Weighted Round Robin) to process the traffic in different queues. When congestion occurs, all the traffic will be transmitted, but the bandwidth that each traffic queue occupies will be allocated based on the queue weight.

weight: Specify the queue weight for the desired queue. This value can be set only in the wrr mode. The valid values are from 1 to 127.

Step 3 qos queue tc-queue bandwidth rate

Specify the minimum guaranteed bandwidth for the desired queue. If the queue bandwidth calculated according to the weight is smaller than the minimum bandwidth, the switch will be forced to allocated the minimum bandwidth to the queue, and the other queue will share the rest bandwidth based on the weight.

tc-queue: Specify the ID number of the TC queue. The valid values are from 0 to 7.

rate: Specify the rate for the desired TC queue. The valid values are from 1 to 100. The default value is 0.

Note: Minimum Bandwidth is only available on certain devices.

Step 4 show qos queue interface [fastEthernet port | port-channel port-channel-id]

port | gigabitEthernet port | ten-gigabitEthernet

Verify the scheduler settings.

Step 5 end

Return to privileged EXEC mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

TP-LINK Omada Pro S5500-24GP4F - Step 6 copy running-config startup-config - 1

Note:

With ACL Redirect feature, the switch maps all the packets that meet the configured ACL rules to the new TC queue, regardless of the mapping relations configured in this section.

The following example shows how to specify the scheduler settings for port 1/0/1. Set the scheduler mode of TC1 as sp mode, set the scheduler mode of TC4 as wrr mode and set the queue weight as 5.

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/1

Switch(config-if)#qos queue 1 mode sp

Switch(config-if)#qos queue 4 mode wrr weight 5

Switch(config-if)#show qos queue interface gigabitEthernet 1/0/1

Gi1/0/1----LAG: N/A

Queue Schedule Mode Weight

TC0 WRR 1

TC1 Strict N/A

TC2 WRR 1

TC3 WRR 1

TC4WRR5
TC5WRR1
TC6WRR1
TC7WRR1

Switch(config-if)#end

Switch#copy running-config startup-config

3 QoS for VLAN Configuration

TP-LINK Omada Pro S5500-24GP4F - QoS for VLAN Configuration - 1

Note:

QoS for VLAN is only available on Omada Pro L3 Stackable Switches.

The QoS for VLAN feature aims to configure a specific 802.1P/DSCP priority for a VLAN after it has been set up. This allows packets within that VLAN to be prioritized based on the 802.1P/DSCP priority level specified.

3.1 Using the CLI

3.1.1 Configuring Local Priority

Follow these steps to configure the egress queue of packets:

Step 1 configure

Enter global configuration mode.

Step 2 vlan

vid

Specify the port to be isolated and enter VLAN configuration mode.

Step 3 qos localPri queue

Configure the egress queue of packets. After configuration, the packets of the corresponding VLAN will be assigned to the specified egress queue.

queue: The egress queue of the packets.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the egress queue for VLAN 2:

Switch#configure

Switch(config)#vlan 2

Switch(config-vlan)#qos localPri 3

Switch(config-vlan)#end

Switch#copy running-config startup-config

3.1.2 Configuring 802.1P Priority

Follow these steps to configure the 802.1P priority carried by packets when they leave:

Step 1 configure

Enter global configuration mode.

Step 2 vlan

vid

Specify the port to be isolated and enter VLAN configuration mode.

Step 3 qos cosPri priority

Configure the egress queue of packets. After configuration, the packets of the corresponding VLAN will be assigned to the specified egress queue.

priority: 802.1P priority specified for the packets.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the 802.1P priority for VLAN 2:

Switch#configure

Switch(config)#vlan 2

Switch(config-vlan)#qos cosPri 4

Switch(config-vlan)#end

Switch#copy running-config startup-config

3.1.3 Configuring DSCP Priority

Follow these steps to configure the DSCP priority carried by packets when they leave:

Step 1 configure

Enter global configuration mode.

Step 2 vlan

vid

Specify the port to be isolated and enter VLAN configuration mode.

Step 3 qos dscpPri dscp

Configure the egress queue of packets. After configuration, the packets of the corresponding VLAN will be assigned to the specified egress queue.

dscp: DSCP priority specified for the packets.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the DSCP priority for VLAN 2:

Switch#configure

Switch(config)#vlan 2

Switch(config-vlan)#dscp localPri 10

Switch(config-vlan)#end

Switch#copy running-config startup-config

4 WRED Configuration

TP-LINK Omada Pro S5500-24GP4F - WRED Configuration - 1

Note:

WRED is only available on Omada Pro L3 Stackable Switches.

WRED (Weighted Random Early Detection) is a congestion avoidance mechanism. When network traffic experiences congestion, it regulates the congestion situation by proactively discarding packets that may cause congestion, thus preventing the TCP global synchronization phenomenon. WRED determines the actual drop probability by setting lower thresholds, upper thresholds, and maximum drop probabilities.

4.1 Using the CLI

4.1.1 Configuring Drop Template

Follow these steps to configure the parameters of the WRED drop profile:

Step 1 configure

Enter global configuration mode.

Step 2 qos wired-profile name low high drop-percentage no qos wired-profile [name]

Configure the parameters of the WRED drop profile, including the lower threshold, upper threshold, and maximum drop percentage. To delete the corresponding WRED drop profile, use the no qos wred-profile command.

name: WRED drop profile name.

low: Drop threshold lower limit.

high: Drop threshold upper limit.

drop-percentage: Maximum drop percentage.

Step 3 end

Return to privileged EXEC mode.

Step 4 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to create a WRED drop profile:

Switch#configure

Switch(config)#qos wred-profile test 40 80 50

Switch(config)#end

Switch#copy running-config startup-config

4.1.2 Binding Drop Template

Follow these steps to bind the WRED drop template to the specified port:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet

port | range fastEthernet port-list | gigabitEthernet port |

range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet

port-list| port-channel port-channel | range port-channel port-channel-list | hundred-gigabitEthernet port | range hundred-gigabitEthernet port-list | twentyFive-

gigabitEthernet port | range twentyFive-gigabitEthernet port-list | two-gigabitEthernet port | range two-gigabitEthernet port-list}

Enter interface configuration mode.

Step 3 qos wred-bind name

no qos wred-bind

Bind the WRED drop template to the specified port. When traffic exits the port, the WRED policy will be implemented. To unbind the WRED drop profile, please use the no qos wred-bind command.

name: WRED drop profile name.

Step 4 end

Return to privileged EXEC mode.

Step 5 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to bind the WRED drop profile to ports 1/0/1-4:

Switch#configure

Switch(config)# interface range gigabitEthernet 1/0/1-4

Switch(config-if-range)#qos wred-bind test

Switch(config)#end

Switch#copy running-config startup-config

4.1.3 Viewing WRED Template Info

Follow these steps to view the WRED profile info:

Step 1 show qos wred-profile [name]

Display the WRED profile configuration.

name: WRED configuration profile name.

The following example shows how to view the WRED profile configuration:

Switch#show qos wred-profile

4.1.4 Viewing WRED Template Binding Info

Follow these steps to view the binding information of the WRED template:

Step 1 show qos wred-bind interface [(fastEthernet | gigabitEthernet | hundred-gigabitEthernet | port-channel | ten-gigabitEthernet | twentyFive-gigabitEthernet | two-gigabitEthernet} interface-value]

Display the binding information of the WRED template.

interface-value: Port number.

The following example shows how to view the information of the WRED template bound to ports 1/0/1-3:

Switch#show qos wred-bind interface gigabitEthernet 1/0/1-3

5 Bandwidth Control Configuration

With bandwidth control configurations, you can:

■ Configure rate limit ■ Configure storm control

5.1 Using the GUI

5.1.1 Configuring Rate Limit

Choose the menu QoS > Bandwidth Control > Rate Limit to load the following page.

Figure 5-1 Configuring Rate LimitRate Limit Config UNIT1 LAGS Port Ingress Rate (0-1,000,000Kbps) Egress Rate (0-1,000,000Kbps) LAG 1/0/1 0 0 -- 1/0/2 0 0 -- 1/0/3 0 0 -- 1/0/4 0 0 -- 1/0/5 0 0 -- 1/0/6 0 0 -- 1/0/7 0 0 -- 1/0/8 0 0 -- 1/0/9 0 0 -- 1/0/10 0 0 -- Total: 54

Follow these steps to configure the Rate Limit function:

1) Select the desired port and configure the upper rate limit to receive and send packets.

Ingress Rate (0-1,000,000Kbps)Specify the upper rate limit for receiving packets on the port.The rate ranges from 1 to 1000000 kbps for the gigaport and 1 to 100000 kbps for the fast port, and is rounded off to the nearest multiple of 64.0 means the ingress rate limit is disabled.
Egress Rate (0-1,000,000Kbps)Specify the upper rate limit for sending packets on the port.The rate ranges from 1 to 1000000 kbps for the gigaport and 1 to 100000 kbps for the fast port, and is rounded off to the nearest multiple of 64.0 means the egress rate limit is disabled.

2) Click Apply.

5.1.2 Configuring Storm Control

Choose the menu QoS > Bandwidth Control > Storm Control to load the following page.

Figure 5-2 Configuring Storm Control

Storm Control Config
UNIT1LAGSRecover
PortRate ModeBroadcast ThresholdMulticast ThresholdUL-Frame ThresholdActionRecover TimeLAG
1/0/1kbps000Drop0--
1/0/2kbps000Drop0--
1/0/3kbps000Drop0--
1/0/4kbps000Drop0--
1/0/5kbps000Drop0--
1/0/6kbps000Drop0--
1/0/7kbps000Drop0--
1/0/8kbps000Drop0--
1/0/9kbps000Drop0--
1/0/10kbps000Drop0--

Follow these steps to configure the Storm Control function:

1) Select the desired port and configure the upper rate limit for forwarding broadcast packets, multicast packets and UL-frames (Unknown unicast frames).

Rate ModeSpecify the Rate Mode for the broadcast threshold, multicast threshold and UL-Frame threshold on the desired port.
kbps: The switch will limit the maximum speed of the specific kinds of traffic in kilo-bits per second.
ratio: The switch will limit the percentage of bandwidth utilization for specific kinds of traffic.
pps: The switch will limit the maximum number of packets per second for specific kinds of traffic.
Note: pps is only available on certain devices.
Broadcast Threshold (0-1,000,000)Specify the upper rate limit for receiving broadcast packets. The broadcast traffic exceeding the limit will be processed according to the Action configurations.
The valid values differ among different rate modes. For kbps, the rate ranges from 1 to 1000000 kbps, and is rounded off to the nearest multiple of 64. For ratio, the rate ranges from 1 to 100 percent. For pps, the rate ranges from 1 to 1488000 packets per second. The value 0 means the broadcast threshold is disabled.
Multicast Threshold (0-1,000,000)Specify the upper rate limit for receiving multicast packets. The multicast traffic exceeding the limit will be processed according to the Action configurations.The valid values differ among different rate modes. For kbps, the rate ranges from 1 to 1000000 kbps, and is rounded off to the nearest multiple of 64. For ratio, the rate ranges from 1 to 100 percent. For pps, the rate ranges from 1 to 1488000 packets per second. The value 0 means the multicast threshold is disabled.
UL-Frame Threshold (0-1,000,000)Specify the upper rate limit for receiving unknown unicast frames. The traffic exceeding the limit will be processed according to the Action configurations.The valid values differ among different rate modes. For kbps, the rate ranges from 1 to 1000000 kbps, and is rounded off to the nearest multiple of 64. For ratio, the rate ranges from 1 to 100 percent. For pps, the rate ranges from 1 to 1488000 packets per second. The value 0 mean the unknown unicast threshold is disabled.
Action Select the action that the switch will take when the traffic exceeds its corresponding limit.Drop:Set the Action as Drop. The port will drop the subsequent packets when the traffic exceeds the limit.Shutdown:Set the Action as Shutdown. The port will be shutdown when the traffic exceeds the limit.
Recover TimeSpecify the recover time for the port. When the traffic exceeds the limit, the port will process the packets according to the Action configurations. After the recover time has passed, the port will recover to its normal state. If the recover time is specified as 0, which means the port will not recover to its normal state automatically and you can click Recover to recover the port manually.

LAG Displays the LAG that the port belongs to.

2) Click Apply.

TP-LINK Omada Pro S5500-24GP4F - 2) Click Apply. - 1

Notes:

  • The member ports of an LAG follow the configurations of the LAG and not their own. The individual configurations of the ports can take effect only after the ports leave the LAG. • You cannot enable Storm Control and Ingress Rate control at the same time for a port. • The Shutdown action only takes effect on broadcast storm and multicast storm. • The Shutdown and Recover action take effect on Ports instead of LAG.

5.2 Using the CLI

5.2.1 Configuring Rate Limit

Follow these steps to configure the upper rate limit for the port to receive and send packets:

Step 1 configure

Enter global configuration mode.

Step 2 interface {fastEthernet port | range fastEthernet port-list | gigabitEthernet port | range gigabitEthernet port-list | ten-gigabitEthernet port | range ten-gigabitEthernet port-list | port-channel port-channel-id | range port-channel port-channel-list}

Enter interface configuration mode.

Step 3 bandwidth {ingress ingress-rate | egress egress-rate}

Configure the upper rate limit for the port to receive and send packets.

ingress-rate: Specify the upper rate limit for receiving packets on the port. The rate ranges from 1 to 1000000 kbps for the gigaport and 1 to 100000 kbps for the fast port, and is rounded off to the nearest multiple of 64.

egress-rate: Specify the upper rate limit for sending packets on the port. The rate ranges from 1 to 1000000 kbps for the gigaport and 1 to 100000 kbps for the fast port, and is rounded off to the nearest multiple of 64.

Step 4 show bandwidth interface [fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port | port-channelport-channel-id]

Verify the ingress/egress rate limit for forwarding packets on the port or LAG. If no port or LAG is specified, it displays the upper ingress/egress rate limit for all ports or LAGs.

Step 5 end

Return to privileged EXEC mode.

Step 6 copy running-config startup-config

Save the settings in the configuration file.

The following example shows how to configure the ingress-rate as 5120 Kbps and egress-rate as 1024 Kbps for port 1/0/5:

Switch#configure

Switch(config)#interface gigabitEthernet 1/0/5

Switch(config-if)#bandwidth ingress 5120 egress 1024

Switch(config-if)#show bandwidth interface gigabitEthernet 1/0/5

PortIngressRate(Kbps)EgressRate(Kbps)LAG
Gi1/0/551201024N/A

Switch(config-if)#end

Switch#copy running-config startup-config

Table of contents Click a title to access it
Manual assistant
Powered by Anthropic
Waiting for your message
Product information

Brand : TP-LINK

Model : Omada Pro S5500-24GP4F

Category : Network switch