- In VTP v1 & v2 change mode to transparent to reset revision number
- Vlan state(Active/Suspended) is advertised by VTP. Shutting down a vlan is locally significant to the device the the command was applied
- A transparent switch forwards VTP packets only if they match it's own configured VTP domain
- DTP negotiation between two switches requires VTP domain name to match between switches
- If a switch doesn't receive a VTP pruning response on a port, as a fallback mechanism, it doesn't prune any vlan on that port. As a consequence it requests all vlans from it VTP neighbors, which actually cancels VTP pruning operation. This is true for edge ports too. As a solution either disable VTP on that port(VTPv3) or manually set allowed vlan list.
- Don't use VTP pruning on a VTP domain that includes transparent switches. Transparent switches only forward VTP packets and don't take part in the negotiation, leading to traffic blackholes
- By default all standard vlans are included in the prune eligible list
- VTP domain name is case sensitive
- In transparent mode vlans are stored in running config
- In client/server mode vlans are stored in vlan database
- In VTPv3 you have to define a primary server in exec mode in order to be able to alter the vlan database
- In VTPv3 you need to disable VTP pruning in order to advertise the extended vlan range
- Useful debug command: debug sw-vlan vtp events
Wednesday, September 30, 2015
VTP notes
Thursday, May 2, 2013
Ping several hosts taking target IPs from a text file
Consider a file containing target IPs, one ip per line
With the following line you can ping them sequentially
for ip in `sort -u file` ; do fping -q -a -t200 ${ip} ; done
Only the ones that reply will be displayed on your screen
With the following line you can ping them sequentially
for ip in `sort -u file` ; do fping -q -a -t200 ${ip} ; done
Only the ones that reply will be displayed on your screen
Wednesday, May 18, 2011
7600 l2protocol forward vs ME3400 l2protocol-tunnel
ME3400
ME3400 is able to tunnel l2 protocols with the command "l2protocol-tunnel xxx"
Tunneled STP BPDUs have 01-00-0C-CD-CD-D0 as a destination mac-address
7600
On 7600 when using service instances on ES cards there is only one option, l2protocol forward.
As the name implies, the router does not alter the BPDUs. It just forwards them on the bridge domain bypassing the SP.
Tunneled STP BPDUs have 01-00-0C-CC-CC-CD as a destination mac-address
Following these different approaches, they can't interoperate in any easy way..
ME3400 is able to tunnel l2 protocols with the command "l2protocol-tunnel xxx"
Tunneled STP BPDUs have 01-00-0C-CD-CD-D0 as a destination mac-address
7600
On 7600 when using service instances on ES cards there is only one option, l2protocol forward.
As the name implies, the router does not alter the BPDUs. It just forwards them on the bridge domain bypassing the SP.
Tunneled STP BPDUs have 01-00-0C-CC-CC-CD as a destination mac-address
Following these different approaches, they can't interoperate in any easy way..
Wednesday, May 11, 2011
Creating a Private Key and Public Certificate
Use the following OpenSSL command to create your private key. The command creates a 1,024-bit RSA private key stored in the file private-key.pem.
openssl genrsa –out private-key.pem 1024
Use the following OpenSSL command to create your public certificate. Run the command from the same directory that you ran the previous command to generate your private key. You will be prompted to enter some basic information for inclusion in the certificate, such as your name. The command generates a public certificate stored in the file public-cert.pem.
openssl req –new –key private-key.pem –x509 –days 365 –out public-cert.pem
That's all
Source: http://goo.gl/Cd24F
openssl genrsa –out private-key.pem 1024
Use the following OpenSSL command to create your public certificate. Run the command from the same directory that you ran the previous command to generate your private key. You will be prompted to enter some basic information for inclusion in the certificate, such as your name. The command generates a public certificate stored in the file public-cert.pem.
openssl req –new –key private-key.pem –x509 –days 365 –out public-cert.pem
That's all
Source: http://goo.gl/Cd24F
Thursday, January 20, 2011
Enable the console of the standby supervisor on Cisco routers
By default, the console of the standby supervisor on Cisco routers is disabled.
If for any reason you need to enable it, do the following:
router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
router(config)#redundancy
router(config-red)#main-cpu
router(config-r-mc)#standby console enable
If for any reason you need to enable it, do the following:
router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
router(config)#redundancy
router(config-red)#main-cpu
router(config-r-mc)#standby console enable
Tuesday, January 11, 2011
Batch replace a string in several files
At your command prompt type the following
perl -p -i -e 's/oldstring/newstring/g' `grep -il oldstring *`
'oldstring' will be replaced by 'newstring' in all folder files
You can add change the grep command to "grep -ilr oldstring *" in order to make searching recursive
perl -p -i -e 's/oldstring/newstring/g' `grep -il oldstring *`
'oldstring' will be replaced by 'newstring' in all folder files
You can add change the grep command to "grep -ilr oldstring *" in order to make searching recursive
Thursday, November 25, 2010
Configure SSH to connect to a server without username/password
If you are bored having to enter your username and password everytime you connect to a server you can do the following
In your pc run "ssh-keygen"
This will generate public/private rsa key pair.
Then run "ssh-copy-id username@servername"
This will copy the appropriate files to the remote server
Now you can connect to the server and you will not be asked for your credentials.
You can also add the following lines to your ~/.ssh/config file
Host servername
User username
Port 2222
This will always connect you to the servername using username at port 2222
In your pc run "ssh-keygen"
This will generate public/private rsa key pair.
Then run "ssh-copy-id username@servername"
This will copy the appropriate files to the remote server
Now you can connect to the server and you will not be asked for your credentials.
You can also add the following lines to your ~/.ssh/config file
Host servername
User username
Port 2222
This will always connect you to the servername using username at port 2222
Subscribe to:
Posts (Atom)