Wednesday, September 30, 2015

VTP notes


  • In VTP v1 & v2 change mode to transparent to reset revision number
  • Vlan state(Active/Suspended) is advertised by VTP. Shutting down a vlan is locally significant to the device the the command was applied
  • A transparent switch forwards VTP packets only if they match it's own configured VTP domain
  • DTP negotiation between two switches requires VTP domain name to match between switches
  • If a switch doesn't receive a VTP pruning response on a port, as a fallback mechanism, it doesn't prune any vlan on that port. As a consequence it requests all vlans from it VTP neighbors, which actually cancels VTP pruning operation. This is true for edge ports too. As a solution either disable VTP on that port(VTPv3) or manually set allowed vlan list. 
  • Don't use VTP pruning on a VTP domain that includes transparent switches. Transparent switches only forward VTP packets and don't take part in the negotiation, leading to traffic blackholes
  • By default all standard vlans are included in the prune eligible list
  • VTP domain name is case sensitive
  • In transparent mode vlans are stored in running config
  • In client/server mode vlans are stored in vlan database
  • In VTPv3 you have to define a primary server in exec mode in order to be able to alter the vlan database
  • In VTPv3 you need to disable VTP pruning in order to advertise the extended vlan range
  • Useful debug command: debug sw-vlan vtp events

Thursday, May 2, 2013

Ping several hosts taking target IPs from a text file

Consider a file containing target IPs, one ip per line

With the following line you can ping them sequentially

for ip in `sort -u file` ; do fping -q -a -t200 ${ip} ; done

Only the ones that reply will be displayed on your screen

Wednesday, May 18, 2011

7600 l2protocol forward vs ME3400 l2protocol-tunnel

ME3400

ME3400 is able to tunnel l2 protocols with the command "l2protocol-tunnel xxx"

Tunneled STP BPDUs have 01-00-0C-CD-CD-D0 as a destination mac-address

7600

On 7600 when using service instances on ES cards there is only one option, l2protocol forward.
As the name implies, the router does not alter the BPDUs. It just forwards them on the bridge domain bypassing the SP.

Tunneled STP BPDUs have 01-00-0C-CC-CC-CD as a destination mac-address

Following these different approaches, they can't interoperate in any easy way..

Wednesday, May 11, 2011

Creating a Private Key and Public Certificate

Use the following OpenSSL command to create your private key. The command creates a 1,024-bit RSA private key stored in the file private-key.pem.

openssl genrsa –out private-key.pem 1024

Use the following OpenSSL command to create your public certificate. Run the command from the same directory that you ran the previous command to generate your private key. You will be prompted to enter some basic information for inclusion in the certificate, such as your name. The command generates a public certificate stored in the file public-cert.pem.

openssl req –new –key private-key.pem –x509 –days 365 –out public-cert.pem

That's all

Source: http://goo.gl/Cd24F

Thursday, January 20, 2011

Enable the console of the standby supervisor on Cisco routers

By default, the console of the standby supervisor on Cisco routers is disabled.

If for any reason you need to enable it, do the following:


router#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
router(config)#redundancy
router(config-red)#main-cpu
router(config-r-mc)#standby console enable

Tuesday, January 11, 2011

Batch replace a string in several files

At your command prompt type the following

perl -p -i -e 's/oldstring/newstring/g' `grep -il oldstring *`

'oldstring' will be replaced by 'newstring' in all folder files

You can add change the grep command to "grep -ilr oldstring *" in order to make searching recursive

Thursday, November 25, 2010

Configure SSH to connect to a server without username/password

If you are bored having to enter your username and password everytime you connect to a server you can do the following

In your pc run "ssh-keygen"

This will generate public/private rsa key pair.

Then run "ssh-copy-id username@servername"

This will copy the appropriate files to the remote server

Now you can connect to the server and you will not be asked for your credentials.

You can also add the following lines to your ~/.ssh/config file

Host servername
 User username
 Port 2222


This will always connect you to the servername using username at port 2222