www.dell.com | support.dell.comDell™ PowerConnect™ M6220/M6348/M8024 SwitchesConfiguration GuideModel PCM6220/PCM6348/PCM8024
10 About this DocumentAdditional DocumentationThe following documentation provides additional information about PowerConnect M6220/M6348/M8024 softwar
100 Device SecurityAdministrative Mode... EnabledPort Admin Oper Reauth Reauth Mode
Device Security 101Much of the configuration to assign hosts to a particular VLAN takes place on the RADIUS server or 802.1X authenticator. If you use
102 Device SecurityExample #1: Allow the Switch to Accept RADIUS-Assigned VLANsThe RADIUS server can place a port in a particular VLAN based on the re
Device Security 103802.1x MAC Authentication Bypass (MAB)MAB is a supplemental authentication mechanism that allows 802.1x unaware clients, such as pr
104 Device SecurityFigure 5-2. MAB Operation — Authentications Based on MAC Address in DatabaseCLI ExamplesExample 1: Enable/Disable MABTo enable/dis
Device Security 105Example 2: Show MAB ConfigurationTo show the MAB configuration for interface 1/5, use the following command:console#show dot1x ethe
106 Device SecurityFilter-id = “internet_access”3The DiffServ policy specified in the attribute must already be configured on the switch, and the poli
Device Security 107LimitationsThe following limitations apply to ingress and egress ACLs.• Maximum of 100 ACLs.• Maximum rules per ACL is 127.• You ca
108 Device SecurityIP ACLsIP ACLs classify for Layers 3 and 4.Each ACL is a set of up to ten rules applied to inbound traffic. Each rule specifies whe
Device Security 109Figure 5-3. IP ACL Example Network DiagramExample #1: Create an ACL and Define an ACL RuleThis command creates an ACL named list1
System Configuration 112System ConfigurationThis section provides configuration scenarios for the following features:•"Traceroute" on page 1
110 Device SecurityExample #2: Define the Second Rule for ACL 179Define the rule to set similar conditions for UDP traffic as for TCP traffic.console(
Device Security 111log Configure logging for this access list rule.mirror Configure the packet mirroring attribute.redirect Configure the packet redir
112 Device SecurityExample #7: Setup an ACL with Permit Actionconsole# Configconsole(config)#mac access-list extended mac2console(config-mac-access-li
Device Security 113MAC ACL Name: mac1Rule Number: 1Action... denyDestination MAC Address...
114 Device SecurityExample #1: Basic RADIUS Server ConfigurationThis example configures two RADIUS servers at 10.10.10.10 and 11.11.11.11. Each server
Device Security 115console(config)#aaa authentication dot1x default radiusExample #2: Set the NAS-IP Address for the RADIUS Server The NAS-IP address
116 Device SecurityTACACS+ Configuration ExampleThis example configures two TACACS+ servers at 10.10.10.10 and 11.11.11.11. Each server has a unique s
Device Security 117console(config)#priority 2 console(config)#exit console(config)#aaa authentication login tacacsList tacacs localCaptive PortalOverv
118 Device SecurityThere are three states for clients connecting to the Captive Portal interface:•Unknown State• Unauthenticated State• Authenticated
Device Security 119When using Local authentication, the administrator provides user identities for Captive Portal by adding unique user names and pass
12 System ConfigurationCLI ExampleThe following shows an example of using the traceroute command to determine how many hops there are to the destinati
120 Device SecurityClient Authentication Logout RequestThe administrator can configure and enable 'user logout'. This feature allows the au
Device Security 121Captive Portal Configuration ManagementIn order to provide text-based compatibility, Captive Portal converts the binary image data
122 Device SecurityThe size of the table has a limit of 1024 entries. If the list becomes full, new table entries are rejected and a trap is sent for
Device Security 123Example 5: Show Captive PortalTo show the status of Captive Portal, use the following command:console#show captive-portalAdministra
124 Device SecurityMax Input Octets (bytes)... 0Max Output Octets (bytes)... 0Max Total Octets (bytes)...
Device Security 125CP ID... 1CP Name... Default Client Client
126 Device Security
IPv6 1276IPv6This section includes the following subsections:• "Overview" on page 127• "Interface Configuration" on page 127•"
128 IPv6While optional in IPv4, router advertisement is mandatory in IPv6. Router advertisements specify the network prefix(es) on a link which can be
IPv6 129ipv6 router ospfrouter-id 1.1.1.1exitinterface vlan 15routingip address 20.20.20.1 255.255.255.0ip ospf area 0.0.0.0exitinterface vlan 2routin
System Configuration 13Configuration ScriptingConfiguration scripting allows you to generate a text-formatted script file that shows the current syste
130 IPv6ip address 10.10.10.1 255.255.255.0ip ospf area 0.0.0.0exitinterface vlan 2routingipv6 enableipv6 address 2020:2::2/64ipv6 ospfipv6 ospf netwo
IPv6 131causes DHCPv6 clients to send the DHCPv6 “Information Request” message in response. A DHCPv6 server then responds by providing only networking
132 IPv6DHCPv6 pool configuration:console# configipv6 dhcp pool testpooldomain-name dell.comdns-server 2001::1exitexitPer-interface DHCPv6 configurati
Quality of Service 1337Quality of ServiceThis section includes the following subsections:• "Class of Service Queuing" on page 133• "Dif
134 Quality of ServiceCoS Mapping Table for Trusted PortsMapping is from the designated field values on trusted ports’ incoming packets to a traffic c
Quality of Service 135Figure 7-1. CoS Mapping and Queue ConfigurationContinuing this example, you configured the egress Port 1/g8 for strict priority
136 Quality of ServiceFigure 7-2. CoS1/g Configuration Example System DiagramYou will configure the ingress interface uniquely for all cos-queue and
Quality of Service 137Differentiated ServicesDifferentiated Services (DiffServ) is one technique for implementing Quality of Service (QoS) policies. U
138 Quality of Service•Service – Assigns a policy to an interface for inbound traffic.CLI ExampleThis example shows how a network administrator can pr
Quality of Service 139exitclass-map match-all marketing_deptmatch srcip 172.16.20.0 255.255.255.0exitclass-map match-all test_deptmatch srcip 172.16.3
14 System ConfigurationExample #2: Viewing and Deleting Existing Scriptsconsole#script listConfiguration Script Name Size(Bytes)---------------
140 Quality of ServiceexitSet the CoS queue configuration for the (presumed) egress interface 1/g5 such that each of queues 1, 2, 3 and 4 get a minimu
Quality of Service 141Figure 7-4. DiffServ VoIP Example Network Diagram
142 Quality of ServiceExample #2: Configuring DiffServ VoIP SupportEnter Global Config mode. Set queue 6 on all ports to use strict priority mode. Thi
Multicast 1438MulticastOverviewIP Multicasting enables a network host (or multiple hosts) to send an IP datagram to multiple destinations simultaneous
144 MulticastIGMP ConfigurationThe Internet Group Management Protocol (IGMP) is used by IPv4 hosts to send requests to join (or leave) multicast group
Multicast 145The IGMP proxy offers a mechanism for multicast forwarding based only on IGMP membership information. The router must decide about forwar
146 Multicast• Use the following command to display interface parameters when IGMP Proxy is enabled:console#show ip igmp-proxy interface• Use this com
Multicast 147CLI ExampleThe following example configures two DVMRP interfaces. First, this example configures an OSPF router1 and globally enables IP
148 MulticastPIMProtocol Independent Multicast (PIM) is a standard multicast routing protocol that provides scalable inter-domain multicast routing ac
Multicast 149Example: PIM-SMThe following example configures PIM-SM for IPv4 on a router.First, configure an OSPF1 router and globally enable IP routi
System Configuration 15Example #5: Uploading a Configuration Script to the TFTP ServerUse this command to upload a configuration script to the TFTP se
To minimize the repeated flooding of datagrams and subsequent pruning associated with a particular source-group (S,G) pair, PIM-DM uses a State Refres
Utility 1519UtilityThis section describes the Auto Config commands.Auto ConfigOverviewAuto Config is a software feature that automatically configures
152 UtilityAfter an IP address is assigned to the switch, if a hostname is not already assigned, Auto Config issues a DNS request for the correspondin
Utility 153The default network configuration file should have IP address to hostname mappings using the command ip host <hostname> <address&g
154 UtilityTable 9-2. TFTP Request TypesMonitoring and Completing the Auto Config ProcessWhen a switch begins bootup and there is no saved configurat
Utility 155A file is not automatically deleted after it is downloaded. The file does not take effect upon a reboot unless an administrator opts to sav
156 UtilityOther FunctionsCLI ScriptingCLI scripting can apply config files. It can be used to manage (view, validate, delete) downloaded config files
Utility 157StackingThe downloaded configuration file is not distributed across a stack. When an administrator saves configuration, the config file is
158 UtilityExample 2: Enable Auto ConfigTo start or stop Auto Config on the switch, use the following commands:console#boot host dhcpconsole#no boot h
16 System ConfigurationExample #7: Validating a Scriptconsole#script validate abc.scrip address dhcp username "admin" password 16d7a4fca7442
System Configuration 17IP Address... 10.27.65.89Subnet Mask... 255.255.254.0Default
18 System ConfigurationExample #2: Configuring the SNTP Serverconsole(config)#sntp server ?<ipaddress/domain-name> Enter SNTP server address or
System Configuration 19SyslogOverviewSyslog:• Allows you to store system messages and/or errors.• Can store to local files on the switch or a remote s
Notes, Notices, and Cautions NOTE: A NOTE indicates important information that helps you make better use of your switch. NOTICE: A NOTICE indicates e
20 System ConfigurationSNMP Set Command Logging : disabled0 Messages were not logged.Buffer Log:<189> JAN 01 03:57:58 10.27.65.86-1 TRAPMGR[2162
System Configuration 21error Error conditionsinfo Informational messagesnotice Normal but sig
22 System ConfigurationConfiguring a storm-control level also enables that form of storm-control. Disabling a storm-control level (using the “no” vers
System Configuration 2310GBASE-T Plug-in Module Configuration NOTE: This feature is applicable to the PowerConnect M6220 and M8024 switches only.The
24 System ConfigurationUse the following command to display the current status of low-power mode on an interface (see the Admin State column):console#
Switching Configuration 253Switching ConfigurationThis section provides configuration scenarios for the following features:• "Virtual LANs"
26 Switching Configuration• The IP-subnet Based VLAN feature lets you map IP addresses to VLANs by specifying a source IP address, network mask, and t
Switching Configuration 27Example #1: Create Two VLANsUse the following commands to create two VLANs and to assign the VLAN IDs while leaving the name
28 Switching ConfigurationExample #4: Assign VLAN3 as the Default VLANThis example shows how to assign VLAN 3 as the default VLAN for port 1/g18.conso
Switching Configuration 29Web InterfaceUse the following screens to perform the same configuration using the Web Interface:•Switching > VLAN > M
3Contents1 About this Document . . . . . . . . . . . . . . . . . . . . . . . . . . . 9Organization . . . . . . . . . . . . . . . . . . . . . . . . .
30 Switching ConfigurationExample #4: Viewing IP Subnet and MAC-Based VLAN Associationsconsole#show vlan association macMAC Address VLAN ID----
Switching Configuration 31Private Edge VLANsUse the Private Edge VLAN feature to prevent ports on the switch from forwarding traffic to each other eve
32 Switching ConfigurationIGMP SnoopingThis section describes the Internet Group Management Protocol (IGMP) Snooping feature. IGMP Snooping enables th
Switching Configuration 33Example #3: Show IGMP Snooping Information for an Interfaceconsole#show ip igmp snooping interface ethernet 1/g17Slot/Port..
34 Switching Configurationconsole(config)#ip igmp snooping querier query-interval 100console(config)#ip igmp snooping querier timer expiry 100Example
Switching Configuration 35Example #5: Show IGMP Snooping Querier Information for VLAN 10console#show ip igmp snooping querier vlan 10Vlan 10 : IGMP
36 Switching ConfigurationFigure 3-2. LAG/Port-channel Example Network DiagramExample 1: Create Names for Two Port-Channelsconsole#configureconsole(c
Switching Configuration 37console(config)#interface ethernet 1/g18console(config-if-1/g18)#channel-group 1 mode autoconsole(config-if-1/g18)#exitconso
38 Switching ConfigurationWeb Interface Configuration: LAGs/Port-channelsTo perform the same configuration using the Graphical User Interface, click S
Switching Configuration 39Port SecurityThis section describes the Port Security feature.OverviewPort Security:• Allows for limiting the number of MAC
43 Switching Configuration. . . . . . . . . . . . . . . . . . . . . . . . . 25Virtual LANs . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
40 Switching Configurationdiscard Discard frames with unlearned source addresses.max Configure the maximum addre
Switching Configuration 41<interval-seconds> Range <5 - 3600> seconds.console(config)#lldp notification-interval 1000console(config)
42 Switching ConfigurationExample #4 Show Interface LLDP Parametersconsole#show lldp interface 1/g10LLDP Interface ConfigurationInterface Link Tra
Switching Configuration 43The following table describes the dos-control keywords.Table 3-1. DoS ControlCLI ExamplesThe commands shown below show how
44 Switching ConfigurationDHCP SnoopingDynamic Host Configuration Protocol (DHCP) Snooping is a security feature that monitors DHCP messages between a
Switching Configuration 45snooping removes bindings in response to DECLINE, RELEASE, and NACK messages. DHCP Snooping application ignores the ACK mess
46 Switching ConfigurationDHCP snooping can be configured on switching VLANs and routing VLANs. When a DHCP packet is received on a routing VLAN, the
Switching Configuration 47Example #7 Configure an interface as DHCP snooping trustedconsole(config-if-1/g1)#ip dhcp snooping trustconsole(config-if-1/
48 Switching Configuration1/g17 No No 1/g18 No No 1/g19 No No
Switching Configuration 491/g1 Yes 50 1 1/g2 No 15 1 1/g3
5CLI Examples . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54Simple Switch Mode Supported CLI Commands . . . . . . . . . . . . .
50 Switching ConfigurationExample #15 Show DHCP Snooping Per Port Statisticsconsole#show ip dhcp snooping statistics Interface MAC Verify Client
Switching Configuration 51ch16 0 0 0ch17 0 0 0--More-- or (q)uitPort
52 Switching ConfigurationFigure 3-4. Default Aggregator Groups on Standalone Switch (Blade)The default Port Aggregator Group mapping is shown in Tab
Switching Configuration 53To prevent traffic from different groups being seen by other groups, a VLAN is reserved for each Aggregator Group by default
54 Switching Configuration• Operational mode is set to Normal mode on resetting the configuration to Factory defaults from the software boot menu. The
Switching Configuration 55console(config)#mode simple Switching modes will immediately clear the configuration.Are you sure you want to continue? (y/n
56 Switching ConfigurationExample #6: Set Group LACP Mode to DynamicUse the lacp auto command to set the LACP (Link Aggregation) mode to dynamic for t
Switching Configuration 57Example #10: Show Group VLAN TableUse the show vlan [port-aggregator group < GroupId >] command to show the VLAN table
58 Switching ConfigurationExample #11: Show Group Configuration SummaryUse the show port-aggregator group summary [< GroupId >] command to show
Switching Configuration 59Simple Switch Mode Supported CLI CommandsCommands that were available in Interface mode of Normal switch mode are now availa
6802.1x Network Access Control Examples . . . . . . . . . . . . . . . . . 98802.1X Authentication and VLANs. . . . . . . . . . . . . . . . . . . . .
60 Switching Configuration• Dot1x feature commands:aaa authentication dot1x aaa authorization network default radiusdot1x max-req dot1x port-controldo
Switching Configuration 61• Port Channel Commands:show interfaces port-channelshow statistics port-channel• Radius commands:auth-portdeadtimekeypriori
62 Switching Configurationuser-key• System Management Commands:asset-taghostnamemembermovemanagementpingreloadset descriptionshow sessionsshow support
Switching Configuration 63ip https portip https serverkey-generatelocationorganization-unitshow crypto certificate mycertificateshow ip httpshow ip ht
64 Switching Configuration• sFlow collector can receive data from multiple switches, providing a real-time synchronized view of the whole network.• Th
Switching Configuration 65Counter SamplingThe primary objective of Counter Sampling is to efficiently, periodically export counters associated with Da
66 Switching ConfigurationExample #5: Show sFlow sampling for receiver index 1console#show sflow 1 sampling Sampler Receiver Packet Ma
Routing Configuration 674Routing ConfigurationThis section describes configuration scenarios and instructions for the following routing features:• &qu
68 Routing ConfigurationFigure 4-1. VLAN Routing Example Network DiagramExample 1: Create Two VLANsThe following code sequence shows an example of cr
Routing Configuration 69console(config-if-1/g2)#exitconsole#configureconsole(config)#interface ethernet 1/g3console(config-if-1/g3)#switchport mode ge
77 Quality of Service . . . . . . . . . . . . . . . . . . . . . . . . . . . . 133Class of Service Queuing . . . . . . . . . . . . . . . . . . . . .
70 Routing ConfigurationUsing the Web Interface to Configure VLAN RoutingUse the following screens to perform the same configuration using the Web Int
Routing Configuration 71Figure 4-2. VRRP Example Network ConfigurationExample 1: Configuring VRRP on the Switch as a Master RouterEnable routing for
72 Routing ConfigurationAssign virtual router IDs to the port that will participate in the protocol:console(config)#interface vlan 50console(config-if
Routing Configuration 73Enable VRRP on the port. console(config-if-vlan60)#ip vrrp 20 modeconsole(config-if-vlan60)#exitUsing the Web Interface to Con
74 Routing ConfigurationPrimary IP Address... 192.150.2.1/255.255.255.0Routing Mode... Enabl
Routing Configuration 75as 0.0.1.0). The area identified as 0.0.0.0 is referred to as Area 0 and is considered the OSPF backbone. All other OSPF areas
76 Routing ConfigurationExternal routes are those imported into OSPF from other routing protocol or processes. OSPF computes the path cost differently
Routing Configuration 77Enable routing and assign IP for VLANs 70, 80 and 90.config interface vlan 70routingip address 192.150.2.2 255.255.255.0exiti
78 Routing ConfigurationExample 2: Configuring Stub and NSSA AreasIn this example, Area 0 connects directly to two other areas: Area 1 is defined as a
Routing Configuration 79Figure 4-4. OSPF Configuration—Stub Area and NSSA AreaConfigure Router A: Router A is a backbone router. It links to an ASBR
80 Routing Configurationipv6 address 3000:3:100::/64 eui64ip ospf area 0.0.0.0ipv6 ospfexit• Define an OSPF router:ipv6 router ospfrouter-id 3.3.3.3ex
Routing Configuration 81ipv6 address 3000:2:4::/64 eui64ipv6 ospfipv6 ospf areaid 2exit• For IPv4: Define an OSPF router. Define Area 1 as a stub. Ena
82 Routing ConfigurationFigure 4-5. OSPF Configuration—Virtual LinkConfigure Router A: Router A is a backbone router. Configuration steps are similar
Routing Configuration 83Configure Router B: Router B is a ABR that directly connects Area 0 to Area 1. In addition to the configuration steps describe
84 Routing Configurationipv6 ospfipv6 ospf areaid 1exitinterface vlan 11routingip address 10.1.101.1 255.255.255.0ipv6 address 3000:1:101::/64 eui64ip
Routing Configuration 85The PowerConnect M6220/M6348/M8024 switches support both versions of RIP. You may configure a given port:• To receive packets
86 Routing ConfigurationExample #2: Enable Routing for PortsThe following command sequence enables routing and assigns IP addresses for VLAN 2 and VLA
Routing Configuration 87Using the Web Interface to Configure RIPUse the following screens to perform the same configuration using the Graphical User I
88 Routing ConfigurationExample 1: Configure Administrative PreferencesThe following commands configure the administrative preference for the RIP and
Routing Configuration 89Using Equal Cost MultipathThe equal cost multipath (ECMP) feature allows a router to use more than one next hop to forward pac
About this Document 91About this DocumentThis configuration guide provides examples of how to use the following switches in a typical network:• Dell™
90 Routing ConfigurationRouting protocols can also be configured to compute ECMP routes. For example, referring to Figure 4-8, if OSPF were configured
Routing Configuration 91Loopbacks are typically used for device management purposes. A client can use the loopback interface to communicate with the r
92 Routing ConfigurationIP HelperThe IP Helper feature provides the ability for a router to forward configured UDP broadcast packets to a particular I
Routing Configuration 93Certain pre-existing configurable DHCP relay options do not apply to relay of other protocols. These options are unchanged. Th
94 Routing ConfigurationExample 2: Configure IP Helper Globally (DHCP)To relay DHCP packets received on any interface to two DHCP servers (10.1.1.1 an
Routing Configuration 95Example 7: Show IP Helper ConfigurationsThe following command shows IP Helper configurations:console#show ip helper-addressIP
96 Routing Configuration
Device Security 975Device SecurityThis section describes configuration scenarios for the following features:• "802.1x Network Access Control"
98 Device SecurityCompletion of an authentication exchange requires all three roles. The PowerConnect M6220/M6348/M8024 switches support the authentic
Device Security 99IP address Type Port TimeOut Retran. DeadTime Source IP Prio. Usage------------- ----- ----- ------- ------- -------- -----
Komentáře k této Příručce