LLD - Draft-V1 5
LLD - Draft-V1 5
LLD - Draft-V1 5
Konnect Colombia
SEBIN – Network Transformation
Project
2
Table of Contents
1 INTRODUCTION ......................................................................................... 4
1.1 GOAL .............................................................................................................. 4
1.2 SCOPE.............................................................................................................. 4
2 OVERVIEW .................................................................................................. 5
2.1 DESIGN SUMMARY .............................................................................................. 6
2.2 OMNISWITCH 10K PHYSICAL BUILD ....................................................................... 7
2.3 OMNISWITCH 6860 PHYSICAL BUILD ..................................................................... 7
2.4 L2/L3 INFORMATION .......................................................................................... 7
2.5 PORT CONNECTIVITY ........................................................................................... 9
2.6 NETWORK DIAGRAM .......................................................................................... 11
3 PORT CONFIGURATION ........................................................................... 12
3.1 CORE SWITCHES ............................................................................................... 12
3.2 EDGE SWITCHES ............................................................................................... 12
3.3 HYBRID PORT CONFIGURATION ON EDGE SWITCHES ................................................ 13
4 BASE CONFIGURATION............................................................................ 14
5 OPTIONAL: NETWORK PROFILE (UNP) CONFIGURATION ....................... 17
6 QOS CONFIGURATION ............................................................................ 18
7 VLAN, LINKAGG, IP AND INTERFACE CONFIGURATION ......................... 19
8 NMS CONFIGURATION ............................................................................ 20
9 VIRTUAL CHASSIS (VC) CONFIGURATION/SCRIPT ................................... 21
10 EXCEPTIONS ............................................................................................. 22
10.1 EXCEPTION STATUS ........................................................................................... 22
10.2 DETAILS FOR EACH EXCEPTION ............................................................................ 22
11 AGREEMENT ............................................................................................. 23
12 APPENDIX A: CORE SWITCH CONFIGURATION SAMPLE ......................... 24
13 APPENDIX B: EDGE SWITCH CONFIGURATION SAMPLE ......................... 28
3
1 Introduction
1.1 Goal
This document serves as a low level design (LLD) reference to implement the required
network architecture for the CARACAS SEBIN LAN network consisting of Alcatel-Lucent
Enterprise OmniSwitch 10K and 6860E and non-E’s using Virtual Chassis (VC) and a
traditional star topology design. The new architecture shall conform to the existing SEBIN
design requirements to provide compatible integration to the existing network as well as
enhance availability, secure separation, scalability, simplicity, and performance.
1.2 Scope
The document scope is limited to the network design for the Caracas SEBIN LAN network
building.
The parameter values referred in this document is based out of the project IP Info
spreadsheet.
SEBIN VLAN-SUBNET
LLD.xlsx
4
2 Overview
The Caracas SEBIN LAN network shall be implemented with a redundant OmniSwitch 10K
setup as a virtual chassis at the core and thirteen IDF locations having redundant
OmniSwitch 6860 in a virtual chassis setup of three for user connections and power-over-
Ethernet (PoE). All 6860 connections will be multi-linked to the core using dynamic link
aggregation, a standard IEEE 802.3ad LACP. Local subnets will route at the core switch
and all other routing will take place on the customer supplied Firewalls (this additional FW
configuration will not be provided in this LLD). Additionally, the OmniVista Network
Management System (NMS) will be used to manage and monitor up to 60 nodes including
the 14 below:
5
IDF13 OS6860E-P48 SW-PICO-13 10.10.0.13/24 1
OS6860-P48
OS6860-P48
The overall site design for SEBIN is a traditional star topology where thirteen IDF location
of (3) 6860 virtual chassis (VC) switches are dual-homed to the core MDF location. The
MDF consist of two OS10K switches setup as the single logical core VC switch for
redundancy. Each IDF will have two 10 Gigabit redundant uplink that connects to the
OS10K-1 and OS10K-2 respectively.
The core VC will have dual-homed connection to the customer provided firewall which will
provide all the routing to the Internet. The connection between the core VC and the
firewall will be four 1 Gigabit links.
Each location will be configured as virtual chassis to simplify the management and to
provide both node level and link level redundancy. The two core switches will be inter-
connected using the two 40 Gigabit ports for VFL connection. All IDF switches will be inter-
connected using the two 20 Gigabit ports per 6860 for VFL connection.
All required VLAN will be configured and tagged on the uplink ports accordingly and all
VLAN router interfaces will be configured at the core VC. Universal Network Profile (UNP)
will be defined on the IDF nodes to determine UNP VLAN assignment based on
classification rules.
6
2.2 OmniSwitch 10K Physical Build
C CFM D C CFM D
A CMM B A CMM B
1 2 3 4 5 6 7 8 1 2 3 4 5 6 7 8
OS10K-XNI-U16L
OS10K-XNI-U16L
OS10K-XNI-U16L
OS10K-XNI-U16L
OS10K-QNI-U4E
OS10K-QNI-U4E
OS10K-CMM
OS10K-CMM
OS10K-CMM
OS10K-CMM
2
1
OK1 OK1 OK1 OK1
1
TEMP TEMP TEMP TEMP
2
2
1
1
3
3
4
4
CONSOLE CONSOLE CONSOLE CONSOLE
5
5
6
6
2
2
7
7
USB USB USB USB
8
8
8
7
ETHERNET ETHERNET ETHERNET ETHERNET
10
10
10
9
9
9
9
10
10
10
10
3
3
11
11
11
11
12
12
12
12
13
13
13
13
14
14
14
14
15
15
15
15
4
4
AQM
AQM
AQM
AQM
16
16
16
16
16
15
16
15
16
15
16
15
CLASS 1 LASER PRODUCT
OS10K-CFM
OS10K-CFM
OS10K-CFM
OK1 OK1 OK1 OK1
WARNING: HAZARDOUS MOVING PARTS WHEN EXPOSED. ONLY WARNING: HAZARDOUS MOVING PARTS WHEN EXPOSED. ONLY
QUALIFIED PERSONNEL SHOULD REMOVE FAN TRAYS QUALIFIED PERSONNEL SHOULD REMOVE FAN TRAYS
! FOR MAINTENANCE. ! FOR MAINTENANCE.
WARNING: HAZARDOUS MOVING PARTS WHEN EXPOSED. ONLY WARNING: HAZARDOUS MOVING PARTS WHEN EXPOSED. ONLY
QUALIFIED PERSONNEL SHOULD REMOVE FAN TRAYS QUALIFIED PERSONNEL SHOULD REMOVE FAN TRAYS
! FOR MAINTENANCE. ! FOR MAINTENANCE.
USB
USB
Console
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 VFL/54
RS232
USB
USB
Console
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 VFL/54
RS232
USB
USB
Console
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 VFL/54
RS232
There are several VLANs defined in SEBIN network. Table below list the VLANs that are
said to be used today. Re-evaluate whether all VLANs are required on every node and
change accordingly.
The network switching equipment can be managed in-band or out-of-band (via EMP port).
SEBIN will determine which option to use for management. EMP ports will be also used for
the remote chassis detection (RCD) feature to prevent split brain scenario in case of a VFL
failure.
7
Table 2 VLAN and Subnet
8
prueba_aislado 517 192.168.17.0 24
DAI 601 10.61.61.0 24
APC 700 10.80.0.0 24
CONEXIONINTERNET 801 190.202.82.34
820
VLAN-SERVIDORES-CONTROLDEMDIOS 900 172.96.10.0 24
EBI_NEW 1000 10.200.200.14 28
PERIFERICOS_EBI 1001 10.201.201.0 24
Chassis/VFL ID Port
1/0 1/4/1
1/1 1/4/3
2/0 2/4/1
2/1 2//4/3
Each IDF locations will inter-connect using the following 20 Gigabit ports on the 6860
switches.
Table 4 OS6860 VFL Ports
Chassis/VFL ID Port
1/0 1/1/53
1/1 1/1/54
2/0 2/1/53
2/1 2/1/54
3/0 3/1/53
3/1 3/1/54
9
1/1/4 piso4 1/1/49 10GIG
1/1/5 piso5 1/1/49 10GIG
1/1/6 piso6 1/1/49 10GIG
1/1/7 piso7 1/1/49 10GIG
1/1/8 piso8 1/1/49 10GIG
1/1/16 fgt-internal 1GIG
1/2/1 piso9 1/1/49 10GIG
1/2/2 piso10 1/1/49 10GIG
1/2/3 piso11 1/1/49 10GIG
1/2/4 piso12 1/1/49 10GIG
1/2/5 piso13 1/1/49 10GIG
1/2/16 fgt-internal 1GIG
1/4/1 to_10K2 VFL Link 2/4/1 40GIG
1/4/3 to_10K2 VFL Link 2/4/3 40GIG
1/4/4 to_10K3???
10
2.6 Network Diagram
Key:
Internet
1 Gigabit Link
OS10K-2
10.1.1.2
1/4/1
CISCO ASA 5510
1/4/3 CENTRO
DE
DATOS
0/1 0/2
1/4/5
2/4/5
1/1/16 2/1/16
OS6860E-P48
OS6860E-P48 1/1/13 1/1/49
1/1/49 1/1/1 10.1.1.15
10.1.1.3
2/1/2 Piso13
Sotano1 2/1/12
1/1/10 OS6860-P48
OS6860-P48 1/1/4 2/1/5 2/1/9
2/1/6 2/1/7 2/1/8
2/1/10
1/1/5 1/1/9 OS6860-P48
OS6860-P48 2/1/4 1/1/6 1/1/7 1/1/8
1/1/49 Piso12
Piso1
1/1/49
2/1/49
2/1/49
OS6860E-P48 OS6860E-P48
10.1.1.5 10.1.1.13
OS6860-P48 OS6860-P48
OS6860-P48 OS6860-P48
1/1/49
1/1/49 1/1/49
2/1/49 Piso11
Piso3 1/1/49 1/1/49
2/1/49 1/1/49 2/1/49
1/1/49
2/1/49 2/1/49
2/1/49
2/1/49
C CFM D C CFM D
A CMM B A CMM B
1 2 3 4 5 6 7 8 1 2 3 4 5 6 7 8
Ports 2/1/1-8 and 2/2/1-8
OS10K-XNI-U16L
OS10K-XNI-U16L
OS10K-XNI-U16L
OS10K-XNI-U16L
OS10K-QNI-U4E
OS10K-QNI-U4E
designated to IDF port 2/1/49
OS10K-CMM
OS10K-CMM
OS10K-CMM
OS10K-CMM
2
1
OK1 OK1 OK1 OK1
1
Ports 1/1/1-8 and 1/2/1-8 1/4/1 TEMP TEMP
2
1
1
3
3
4
4
CONSOLE CONSOLE CONSOLE CONSOLE
5
6
6
2
2
7
7
USB USB USB USB
8
8
8
7
ETHERNET ETHERNET
VFL Links ETHERNET ETHERNET
10
10
10
9
9
1/4/3
9
9
10
10
10
10
Ports 1/1/16 and 1/2/16 2/4/3
3
3
11
11
11
11
12
12
12
12
13
13
13
13
designated to FW ports Ports 2/1/16 and 2/2/16
14
14
14
14
15
15
15
15
4
4
AQM
AQM
AQM
AQM
16
16
16
16
designated to FW ports
16
15
16
15
16
15
16
15
CLASS 1 LASER PRODUCT
OS10K-CFM
OS10K-CFM
OS10K-CFM
OK1 OK1 OK1 OK1
WARNING: HAZARDOUS MOVING PARTS WHEN EXPOSED. ONLY WARNING: HAZARDOUS MOVING PARTS WHEN EXPOSED. ONLY
QUALIFIED PERSONNEL SHOULD REMOVE FAN TRAYS QUALIFIED PERSONNEL SHOULD REMOVE FAN TRAYS
! FOR MAINTENANCE. ! FOR MAINTENANCE.
WARNING: HAZARDOUS MOVING PARTS WHEN EXPOSED. ONLY WARNING: HAZARDOUS MOVING PARTS WHEN EXPOSED. ONLY
QUALIFIED PERSONNEL SHOULD REMOVE FAN TRAYS QUALIFIED PERSONNEL SHOULD REMOVE FAN TRAYS
! FOR MAINTENANCE. ! FOR MAINTENANCE.
To_10K-2
USB
1/1/53
USB
Console
RS232
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52
1/1/54
VFL/54
USB
2/1/53 VFL Link
USB
Console
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52
2/1/54
VFL/54
RS232
USB
3/1/53
USB
Console
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52
3/1/54
VFL/54
RS232
13
4 Base Configuration
!
ip domain-name aa.bb.cc.dd
ip domain-lookup
ip name-server xx.xx.xx.xx
!
ntp server xx.xx.xx.xx
ntp client admin-state enable
!
! trap port link should be used on switch to switch ports
! may also use on server host ports
! User ports should remain disabled
interfaces port 1/1/1-8 link-trap enable
interfaces port 1/2/1-8 link-trap enable
interfaces port 2/1/1-8 link-trap enable
interfaces port 2/2/1-8 link-trap enable
!
! AUTHENTICATION SECTION
! change user password requirements
user password-size 12
user password-policy min-digit 1
user password-policy min-nonalpha 1
user password-policy min-uppercase 1
user password-policy min-lowerercase 1
user password-policy cannot-contain-username
14
! aaa authentication.
aaa tacacs+-server tacacs host xx.xx.xx.xx key "%secret%"
! Turn off what is not used.
no aaa authentication telnet
no aaa authentication ftp
aaa authentication http tacacs local
aaa authentication console tacacs local
aaa authentication ssh tacacs local
aaa authentication snmp local
!IPMS
ip multicast admin-state enable
ip multicast querying enable
ipv6 multicast admin-state enable
ipv6 multicast querying enable
! LLDP:
lldp nearest-bridge chassis tlv management port-description enable system-name
enable system-description enable system-capabilities enable
lldp nearest-bridge chassis tlv dot1 vlan-name enable port-vlan enable
lldp nearest-bridge chassis tlv dot3 mac-phy enable
lldp nearest-bridge port 1/1 tlv management management-address enable
15
! SNMP
user private read-write all password %secret% sha+des
! LOGGING
! Command log will provide a timestamped log file with what username did which
commands.
Command-log enable
swlog remote command-log enable
swlog output socket xx.xx.xx.xx remote command-log
swlog console level info
16
5 Optional: Network Profile (UNP) Configuration
Universal Network Profile (UNP) is a feature that provides network administrators with the
ability to define and apply network access control to specific types of devices. Use default
classification rule to define UNP VLAN assignment. Sample shows using MAC based rule
to move IP Phone sets into the Voice VLAN and IP Address based rule to move to particular
VLANs.
! Create UNP
!
! DA-UNP:
unp edge-profile DEFAULT
unp edge-profile VLAN-VOIP
unp edge-profile DATOS-S1
unp vlan-mapping edge-profile DEFAULT vlan 1
unp vlan-mapping edge-profile VLAN-VOIP vlan 2
unp vlan-mapping edge-profile DATOS-S1 vlan 10
17
6 QOS Configuration
! QOS
! If required to enable VOIP or UNP enabled mobile ports on all user ports.
vlan port mobile #/##-## bpdu ignore enable
18
7 VLAN, Linkagg, IP and Interface Configuration
! LACP
linkagg lacp agg x size y admin-state enable
linkagg lacp agg x name "switchname"
linkagg lacp agg x actor admin-key x
linkagg lacp agg x partner admin-key x
linkagg lacp port #/#/# actor admin-key x
linkagg lacp port #/#/# actor admin-key x
linkagg lacp port #/#/# partner admin-key x
linkagg lacp port #/#/# partner admin-key x
! VLAN
vlan 10 name "DATOS-S1"
vlan 10 members port x/x (or linkagg x) tagged/untagged
19
8 NMS Configuration
20
9 Virtual Chassis (VC) Configuration/Script
21
10 Exceptions
22
11 Agreement
The signatures below serve as an acknowledgement that the ALU/Konnect Colombia and SEBIN
are in agreement with this design document and that the project is prepared to move forward.
By: By:
(print name) (print name)
Name: Name:
(signature) (signature)
By: By:
(print name) (print name)
Name: Name:
(signature) (signature)
By: By:
(print name) (print name)
Name: Name:
(signature) (signature)
Title: Title:
By: By:
(print name) (print name)
Name: Name:
(signature) (signature)
Title: Title:
23
12 Appendix A: Core Switch Configuration Sample
10K-1
!========================================!
! File: /flash/working/vcsetup.cfg !
!========================================!
! Virtual Chassis Manager:
virtual-chassis chassis-id 1 configured-chassis-id 1
virtual-chassis vf-link-mode static
virtual-chassis chassis-id 1 vf-link 1 create
virtual-chassis chassis-id 1 vf-link 1 member-port 1/4/1
virtual-chassis chassis-id 1 vf-link 1 member-port 1/4/3
virtual-chassis chassis-id 1 chassis-group 1
virtual-chassis chassis-id 1 configured-chassis-priority 200
10K-2
!========================================!
! File: /flash/working/vcsetup.cfg !
!========================================!
! Virtual Chassis Manager:
virtual-chassis chassis-id 2 configured-chassis-id 2
virtual-chassis vf-link-mode static
24
virtual-chassis chassis-id 2 vf-link 1 create
virtual-chassis chassis-id 2 vf-link 1 member-port 2/4/1
virtual-chassis chassis-id 2 vf-link 1 member-port 2/4/3
virtual-chassis chassis-id 2 chassis-group 1
!========================================!
! VC 10K SET EMP ADDRESS !
!========================================!
!========================================!
! Create the VLANs !
!========================================!
vlan 1 admin-state enable
vlan 2 admin-state enable
vlan X admin-state enable - This is automatic once a VLAN is created.
vlan 1 name "VLAN-GESTION"
vlan 2 name "VLAN-VOIP"
vlan 9 name "VLAN-OUTSIDE-EUDEMON"
vlan 10 name "DATOS-S1"
vlan 20 name "DATOS-P2"
vlan 30 name "DATOS-P3"
vlan 40 name "DATOS-P4"
vlan 50 name "DATOS-P5"
vlan 60 name "DATOS-P6"
vlan 70 name "DATOS-P7"
vlan 80 name "DATOS-P8"
vlan 90 name "DATOS-P9"
vlan 100 name "DATOS-P10"
vlan 110 name "DATOS-P11"
vlan 120 name "DATOS-P12"
vlan 130 name "DATOS-P13"
vlan 131 name "GPS"
vlan 200 name "VLAN-CCTV"
vlan 201 name "CCTV-S1"
vlan 202 name "CCTV-P1"
vlan 204 name ""
vlan 210 name "CCTV-P10"
vlan 211 name "PUERTO-HIBRIDO-VOIP-DATOS"
vlan 300 name "EBI-CA-CI-DI"
vlan 500 name "VLAN-SERVIDOREs-DATOS"
vlan 501 name "SERVER_PUBLIC"
vlan 507 name "VLAN_HP_SAN"
vlan 512 name "prueba_bondingC"
vlan 601 name "DAI"
vlan 700 name "APC"
25
vlan 900 name "control_medios"
vlan 1000 name "EBI_NEW"
VLAN 1001 name "PERIFERICOS_EBI"
!========================================!
! Create the IP Interfaces !
!========================================!
!========================================!
! Create the Link Aggregation !
!========================================!
=====LinkAgg to Sotano1
linkagg lacp agg 1 size 2 admin-state enable
linkagg lacp agg 1 name "to_Sotano1"
linkagg lacp agg 1 actor admin-key 1
linkagg lacp port 1/1/1 actor admin-key 1
linkagg lacp port 2/1/1 actor admin-key 1
vlan 1 members linkagg 1 untagged
vlan 2 members linkagg 1 tagged
vlan X members linkagg 1 tagged (Add for each VLAN to the linkagg 1)
=====LinkAgg to Pico 1
linkagg lacp agg 2 size 2 admin-state enable
linkagg lacp agg 2 name "to_Pico1"
linkagg lacp agg 2 actor admin-key 2
linkagg lacp port 1/1/2 actor admin-key 2
linkagg lacp port 2/1/2 actor admin-key 2
vlan 1 members linkagg 2 untagged
vlan 2 members linkagg 2 tagged
vlan X members linkagg 2 tagged (Add for each VLAN to the linkagg 2)
=====LinkAgg to Pico X
linkagg lacp agg X size 2 admin-state enable
linkagg lacp agg X name "to_Pico X"
linkagg lacp agg X actor admin-key X
linkagg lacp port 1/1/X actor admin-key X
linkagg lacp port 2/1/X actor admin-key X
vlan 1 members linkagg X untagged
vlan 2 members linkagg X tagged
vlan X members linkagg X tagged (Add for each VLAN to the linkagg X)
26
!========================================!
! Add the static route to FW !
!========================================!
27
13 Appendix B: Edge Switch Configuration Sample
Use the automatic configuration of virtual chassis method as your first option. This requires that the
6860 switch is either brand new or that there are no vcsetup.cfg and vcboot.cfg present on the
switch.
Steps of Automatic Virtual Chassis Creation (Reference Switch Management Guide AOS Release 8
for more details).
1. Connect each chassis to the next in a ring configuration using the dedicated VFL ports.
2. Power on each chassis.
3. The VFL ports will be automatically detected and configured.
4. The chassis with the lowest MAC address will become the Master and be configured with
chassis-id 1.
5. All other chassis will become Slave chassis and be assigned a unique chassis-id.
Unit 1: 6860E-P48
!========================================!
! File: /flash/working/vcsetup.cfg !
!========================================!
! Virtual Chassis Manager:
virtual-chassis chassis-id 1 configured-chassis-id 1
virtual-chassis vf-link-mode auto
virtual-chassis auto-vf-link-port 1/1/53
virtual-chassis auto-vf-link-port 1/1/54
virtual-chassis chassis-id 1 chassis-group 1
! IP:
ip interface local chassis-id 1 emp address xx.xx.xx.xx mask 255.255.255.0
Unit 2: 6860-P48
!========================================!
! File: /flash/working/vcsetup.cfg !
!========================================!
! Virtual Chassis Manager:
virtual-chassis chassis-id 2 configured-chassis-id 2
virtual-chassis vf-link-mode auto
virtual-chassis auto-vf-link-port 2/1/53
virtual-chassis auto-vf-link-port 2/1/54
virtual-chassis chassis-id 2 chassis-group 1
! IP:
Unit 3: 6860-P48
!========================================!
! File: /flash/working/vcsetup.cfg !
28
!========================================!
! Virtual Chassis Manager:
virtual-chassis chassis-id 3 configured-chassis-id 3
virtual-chassis vf-link-mode auto
virtual-chassis auto-vf-link-port 3/1/53
virtual-chassis auto-vf-link-port 3/1/54
virtual-chassis chassis-id 3 chassis-group 1
! IP:
After the three 6860 are in a VC, the boot file will be configured with the following and is
in a filename called vcboot.cfg. The main configuration are described in the configuration
file. Highlighted in yellow references where additional parameters will be added per
design.
! Configuration:
configuration error-file-limit 2
! Capability Manager:
hash-control extended
! Multi-Chassis:
! Virtual Flow Control:
! LFP
! Interface:
! Port_Manager:
! Link Aggregate:
linkagg lacp agg 1 size 2 admin-state enable
linkagg lacp agg 1 name "to_10K"
linkagg lacp agg 1 actor admin-key 1
linkagg lacp port 1/1/49 actor admin-key 1
linkagg lacp port 2/1/49 actor admin-key 1
! VLAN:
vlan 1 admin-state enable
vlan 2 admin-state enable
vlan X admin-state enable - This is automatic once a VLAN is created.
vlan 1 name "VLAN-GESTION"
vlan 2 name "VLAN-VOIP"
vlan 9 name "VLAN-OUTSIDE-EUDEMON"
29
vlan 10 name "DATOS-S1"
vlan 20 name "DATOS-P2"
vlan 30 name "DATOS-P3"
vlan 40 name "DATOS-P4"
vlan 50 name "DATOS-P5"
vlan 60 name "DATOS-P6"
vlan 70 name "DATOS-P7"
vlan 80 name "DATOS-P8"
vlan 90 name "DATOS-P9"
vlan 100 name "DATOS-P10"
vlan 110 name "DATOS-P11"
vlan 120 name "DATOS-P12"
vlan 130 name "DATOS-P13"
vlan 131 name "GPS"
vlan 200 name "VLAN-CCTV"
vlan 201 name "CCTV-S1"
vlan 202 name "CCTV-P1"
vlan 204 name ""
vlan 210 name "CCTV-P10"
vlan 211 name "PUERTO-HIBRIDO-VOIP-DATOS"
vlan 300 name "EBI-CA-CI-DI"
vlan 500 name "VLAN-SERVIDOREs-DATOS"
vlan 501 name "SERVER_PUBLIC"
vlan 507 name "VLAN_HP_SAN"
vlan 512 name "prueba_bondingC"
vlan 601 name "DAI"
vlan 700 name "APC"
vlan 900 name "control_medios"
vlan 1000 name "EBI_NEW"
VLAN 1001 name "PERIFERICOS_EBI"
vlan 1 members linkagg 1 untagged
vlan 2 members linkagg 1 tagged
vlan X members linkagg 1 tagged (Add for each VLAN to the linkagg 1)
! Spanning Tree:
spantree vlan 1 admin-state enable
spantree vlan 2 admin-state enable
spantree vlan X admin-state enable
! Bridging:
! Port Mirroring:
! Port Mapping:
! IP:
ip service port 123 admin-state enable
ip interface master emp address xx.xx.xx.xx mask 255.255.255.0
ip interface "VLAN-1" address 10.10.0.xx mask 255.255.255.0 vlan 1 ifindex 1
ip interface "VLAN-2" address 10.20.0.xx mask 255.255.255.0 vlan 2 ifindex 2
ip interface "VLAN-X" address xx.xx.xx.xx mask 255.255.255.0 vlan X ifindex 3
30
! IPv6:
! IPSec:
! IPMS:
! AAA:
aaa authentication default "local"
aaa authentication console "local"
! NTP:
ntp server xx.xx.xx.xx minpoll 4 prefer
ntp client admin-state enable
! QOS:
! Policy Manager:
! VLAN Stacking:
! ERP:
! MVRP:
! LLDP:
! UDLD:
! Server Load Balance:
! High Availability Vlan:
! Session Manager:
session cli timeout 65535
session http timeout 15
session prompt default "SW-PISO-X ->"
command-log enable
! Web:
! Trap Manager:
snmp station xx.xx.xx.xx 162 "snmpuserv3" v3 enable
! Health Monitor:
! System Service:
ip name-server xx.xx.xx.xx
ip domain-lookup
system timezone CST
! SNMP:
snmp security no-security
snmp community-map mode enable
snmp community-map "publc" user "snmpuser" enable (If you need to use SNMPv2)
! BFD:
! IP Route Manager:
ip static-route 0.0.0.0/0 gateway xx.xx.xx.xx metric 1
! VRRP:
ip load vrrp
31
! UDP Relay:
ip helper address xx.xx.xx.xx
! RIP:
! OSPF:
! IP Multicast:
! DVMRP:
! IPMR:
! RIPng:
! OSPF3:
! BGP:
! ISIS:
! Netsec:
! Module:
! LAN Power:
lanpower slot 1/1 service start
lanpower slot 2/1 service start
lanpower slot 3/1 service start
! RDP:
! DA-UNP:
unp edge-profile DEFAULT
unp edge-profile VLAN-VOIP
unp vlan-mapping edge-profile DEFAULT vlan 10
unp vlan-mapping edge-profile VLAN-VOIP vlan 2
32
unp port 1/1/7 port-type edge
unp port 1/1/7 classification enable
unp port 1/1/7 default-edge-profile DEFAULT
unp port 1/1/8 port-type edge
unp port 1/1/8 classification enable
unp port 1/1/8 default-edge-profile DEFAULT
unp port 1/1/9 port-type edge
unp port 1/1/9 classification enable
unp port 1/1/9 default-edge-profile DEFAULT
unp port 1/1/10 port-type edge
unp port 1/1/10 classification enable
unp port 1/1/10 default-edge-profile DEFAULT
unp port 1/1/11 port-type edge
unp port 1/1/11 classification enable
unp port 1/1/11 default-edge-profile DEFAULT
unp port 1/1/12 port-type edge
unp port 1/1/12 classification enable
unp port 1/1/12 default-edge-profile DEFAULT
unp port 1/1/13 port-type edge
unp port 1/1/13 classification enable
unp port 1/1/13 default-edge-profile DEFAULT
unp port 1/1/14 port-type edge
unp port 1/1/14 classification enable
unp port 1/1/14 default-edge-profile DEFAULT
unp port 1/1/15 port-type edge
unp port 1/1/15 classification enable
unp port 1/1/15 default-edge-profile DEFAULT
unp port 1/1/16 port-type edge
unp port 1/1/16 classification enable
unp port 1/1/16 default-edge-profile DEFAULT
unp port 1/1/17 port-type edge
unp port 1/1/17 classification enable
unp port 1/1/17 default-edge-profile DEFAULT
unp port 1/1/18 port-type edge
unp port 1/1/18 classification enable
unp port 1/1/18 default-edge-profile DEFAULT
unp port 1/1/19 port-type edge
unp port 1/1/19 classification enable
unp port 1/1/19 default-edge-profile DEFAULT
unp port 1/1/20 port-type edge
unp port 1/1/20 classification enable
unp port 1/1/20 default-edge-profile DEFAULT
unp port 1/1/21 port-type edge
unp port 1/1/21 classification enable
unp port 1/1/21 default-edge-profile DEFAULT
33
unp port 1/1/22 port-type edge
unp port 1/1/22 classification enable
unp port 1/1/22 default-edge-profile DEFAULT
unp port 1/1/23 port-type edge
unp port 1/1/23 classification enable
unp port 1/1/23 default-edge-profile DEFAULT
unp port 1/1/24 port-type edge
unp port 1/1/24 classification enable
unp port 1/1/24 default-edge-profile DEFAULT
unp port 1/1/25 port-type edge
unp port 1/1/25 classification enable
unp port 1/1/25 default-edge-profile DEFAULT
unp port 1/1/26 port-type edge
unp port 1/1/26 classification enable
unp port 1/1/26 default-edge-profile DEFAULT
unp port 1/1/27 port-type edge
unp port 1/1/27 classification enable
unp port 1/1/27 default-edge-profile DEFAULT
unp port 1/1/28 port-type edge
unp port 1/1/28 classification enable
unp port 1/1/28 default-edge-profile DEFAULT
unp port 1/1/29 port-type edge
unp port 1/1/29 classification enable
unp port 1/1/29 default-edge-profile DEFAULT
unp port 1/1/30 port-type edge
unp port 1/1/30 classification enable
unp port 1/1/30 default-edge-profile DEFAULT
unp port 1/1/31 port-type edge
unp port 1/1/31 classification enable
unp port 1/1/31 default-edge-profile DEFAULT
unp port 1/1/32 port-type edge
unp port 1/1/32 classification enable
unp port 1/1/32 default-edge-profile DEFAULT
unp port 1/1/33 port-type edge
unp port 1/1/33 classification enable
unp port 1/1/33 default-edge-profile DEFAULT
unp port 1/1/34 port-type edge
unp port 1/1/34 classification enable
unp port 1/1/34 default-edge-profile DEFAULT
unp port 1/1/35 port-type edge
unp port 1/1/35 classification enable
unp port 1/1/35 default-edge-profile DEFAULT
unp port 1/1/36 port-type edge
unp port 1/1/36 classification enable
unp port 1/1/36 default-edge-profile DEFAULT
34
unp port 1/1/37 port-type edge
unp port 1/1/37 classification enable
unp port 1/1/37 default-edge-profile DEFAULT
unp port 1/1/38 port-type edge
unp port 1/1/38 classification enable
unp port 1/1/38 default-edge-profile DEFAULT
unp port 1/1/39 port-type edge
unp port 1/1/39 classification enable
unp port 1/1/39 default-edge-profile DEFAULT
unp port 1/1/40 port-type edge
unp port 1/1/40 classification enable
unp port 1/1/40 default-edge-profile DEFAULT
unp port 1/1/41 port-type edge
unp port 1/1/41 classification enable
unp port 1/1/41 default-edge-profile DEFAULT
unp port 1/1/42 port-type edge
unp port 1/1/42 classification enable
unp port 1/1/42 default-edge-profile DEFAULT
unp port 1/1/43 port-type edge
unp port 1/1/43 classification enable
unp port 1/1/43 default-edge-profile DEFAULT
unp port 1/1/44 port-type edge
unp port 1/1/44 classification enable
unp port 1/1/44 default-edge-profile DEFAULT
! DHL:
! Ethernet-OAM:
! SAA:
! SPB-ISIS:
! SVCMGR:
! LDP:
! EVB:
! APP-FINGERPRINT:
! FCOE:
! QMR
! OPENFLOW:
! Dynamic auto-fabric
! SIP Snooping
! DHCP Server:
! DPI:
35
! DHCPv6 Relay:
! DHCPv6 Server:
! QIP Message Service:
! QIP Active Lease Service:
! Virtual Chassis Split Protection:
! DHCP Snooping:
! APP-MONITORING:
! Loopback Detection:
36