Escolar Documentos
Profissional Documentos
Cultura Documentos
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
Clique
para
editar
o
ttulo
mestre
Comandos Bsicos de Switch
CISCO
mac-address-table, spanning-tree
portfast
Plano de aula
Objetivos especficos: adquirir conhecimentos e desenvolver a
capacidade de compreenso de Switch Cisco e VLAN.
Tpicos abordados:
mac-address-table, spanning-tree
portfast
Exercicio aplicao
Clique para
editar
o
ttulo
mestre
De VLAN
1 switch
Clique para editar o estilo do
Com
PCs
subttulo2mestre
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
Entendeu?
Clique para editar o estilo do
VLAN 1
VLAN 3
subttulo
mestre
VLAN
2
1
mac-address-table, spanning-tree
portfast
VLAN Name
Status Ports
---- -------------------------------- --------- ------------------------------1 default
active Fa0/1, Fa0/2, Fa0/3, Fa0/4
Fa0/5, Fa0/6, Fa0/7, Fa0/8
Fa0/9, Fa0/10, Fa0/11, Fa0/12
Fa0/13, Fa0/14, Fa0/15, Fa0/16
Fa0/17, Fa0/18, Fa0/19, Fa0/20
Fa0/21, Fa0/22, Fa0/23, Fa0/24
Gig1/1, Gig1/2
1002 fddi-default
active
1003 token-ring-default
active
1004 fddinet-default
active
1005 trnet-default
active
Switch#
mac-address-table, spanning-tree
portfast
Exercicio
VLAN entre dois switch - TRUNK
mac-address-table, spanning-tree
portfast
No switch 0
Criando as VLAN 2 Diretoria e VLAN 3 Vendas no Switch
Switch0>enable
Switch0#configure terminal
Switch0(config)#vlan 2
Switch0(config-vlan)#name diretoria
Switch0(config-vlan)#exit
Switch0(config)#exit
Switch0>enable
Switch0#configure terminal
Switch0(config)#vlan 3
Switch0(config-vlan)#name vendas
Switch0(config-vlan)#exit
Switch0(config)#exit
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
No switch 0
Associando uma faixa de interfaces
FastEthernet 0/1 at FastEthernet 0/12 a VLAN 2
Switch0>enable
Switch0#configure terminal
Switch0(config)#interface range fastEthernet 0/1-12
Switch0(config-if)#switchport access vlan 2
Switch0(config-if)#exit
Switch0#
mac-address-table, spanning-tree
portfast
No switch 0
Associando uma faixa de interfaces
FastEthernet 0/13 at FastEthernet 0/23 a VLAN 3
Switch0>enable
Switch0#configure terminal
Switch0(config)#interface range fastEthernet 0/13-23
Switch0(config-if)#switchport access vlan 3
Switch0(config-if)#exit
Switch0#
mac-address-table, spanning-tree
portfast
Clique
para editar o ttulo mestre
O proximo slide somente um
exemplo no deve ser feito
mac-address-table, spanning-tree
portfast
subttulo mestre
Switch0>enable
Switch0#configure terminal
Switch0(config)#interface range fastEthernet 0/1-4 , fastEthernet 0/8-10 , gigabitEthernet 1/1
Switch0(config-if)#switchport access vlan 3
Switch0(config-if)#exit
Switch0#
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
No switch 1
Criando as VLAN 2 Diretoria e VLAN 3 Vendas no Switch
Switch>enable
Switch1#configure terminal
Switch1(config)#vlan 2
Switch1(config-vlan)#name diretoria
Switch1(config-vlan)#exit
Switch1(config)#exit
Switch1>enable
Switch1#configure terminal
Switch1(config)#vlan 3
Switch1(config-vlan)#name vendas
Switch1(config-vlan)#exit
Switch1(config)#exit
mac-address-table, spanning-tree
portfast
No switch 1
Associando uma faixa de interfaces
FastEthernet 0/1 at FastEthernet 0/12 a VLAN 2
Switch1>enable
Switch1#configure terminal
Switch1(config)#interface range fastEthernet 0/1-12
Switch1(config-if)#switchport access vlan 2
Switch1(config-if)#exit
Switch1#
mac-address-table, spanning-tree
portfast
No switch 1
Associando uma faixa de interfaces
FastEthernet 0/12 at FastEthernet 0/24 a VLAN 3
Switch1>enable
Switch1#configure terminal
Switch1(config)#interface range fastEthernet 0/13-24
Switch1(config-if)#switchport access vlan 3
Switch1(config-if)#exit
Switch1#
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
Router>enable
Router#configure terminal
Modulo 0 e Interface 0
Router(config)#interface fastEthernet 0/0
Router(config-if)#no shutdown
Router(config-if)#exit
Nmero da Sub Interface 0.2
Router(config)#interface fastEthernet 0/0.2
Nmero da VLAN 2
Router(config-subif)#encapsulation dot1Q 2
Router(config-subif)#ip address 192.17.100.254 255.255.255.0
Router(config-subif)#exit
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
Clique
para
editar
o
ttulo
mestre
Switch1>enable
Switch1#configure terminal
Switch1(config)#interface fastEthernet 0/23
Switch1(config-if)#switchport mode trunk
Switch1(config-if)#exit
Switch1(config)#
mac-address-table, spanning-tree
portfast
Dica de segurana
mac-address-table, spanning-tree
portfast
editar
o estilo
## trunkClique
porta 24para
dos dois
switch
enable
subttulo mestre
configure terminal
interface fast 0/24
switchport mode trunk
switchport trunk allowed vlan 2,3
do
mac-address-table, spanning-tree
portfast
Baseado na topologia abaixo imagine que no switch1 PC1 queira se comunicar com o PC0 do
switch0 e s esta permitindo que a VLAN2 possa passar pela porta 24 trunk em direo ao
switch0 ou seja em outras palavras a porta trunk s permite VLANs especificas passar por ela e
nessa caso a VLAN 2.
VLAN2
VLAN2
VLAN2
mac-address-table, spanning-tree
portfast
PC3 que na vlan3 do switch1 e quer enviar um pacote para o PC2 que tambm esta
na vlan 3 porem em outro switch switch0 sendo assim tera que passar pela porta
trunk mas como no foi permitido passar pela porta 24 trunk a vlan 3, ento o pacote
no passa.
VLAN3
configure terminal
interface fast 0/24
switchport mode trunk
switchport trunk allowed vlan add 2
mac-address-table, spanning-tree
portfast
fim
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
Physical Address
0002.16D3.15D8
mac-address-table, spanning-tree
portfast
PC>
mac-address-table, spanning-tree
portfast
Switch0>enable
Switch0#configure terminal
Switch0(config)#interface fastEthernet 0/1
Physical Address
Switch0(config-if)#switchport mode access
0001.63CD.1B61
Switch0(config-if)#switchport port-security
Switch0(config-if)#switchport port-security maximum 1
Switch0(config-if)#switchport port-security mac-address 0002.16D3.15D8
Switch0(config-if)#switchport port-security violation shutdown
mac-address-table, spanning-tree
portfast
Switch0>enable
Switch0#show port-security interface fastEthernet 0/1
Port Security
: Enabled
Port Status
: Secure-up
Violation Mode
: Shutdown
Aging Time
: 0 mins
Aging Type
: Absolute
SecureStatic Address Aging : Disabled
Maximum MAC Addresses
:1
Total MAC Addresses
:1
Configured MAC Addresses : 1
Sticky MAC Addresses
:0
Last Source Address:Vlan : 0000.0000.0000:0
Security Violation Count : 0
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
Clique
para
editar
o
ttulo
mestre
switchport port-security violation protect
Bloqueia o trafego ofensivo, porem no precisa do administrador para reabilitar a
Interface ou seja a porta do switch.
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
fim
mac-address-table, spanning-tree
portfast
VTP
Vlan Trunking Protocol
mac-address-table, spanning-tree
portfast
subttulo mestre
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
O modo transparente, um switch especial, ele fica no meio termo entre server
e client, mas no participa do domnio VTP. Ele pode criar, alterar e apagar as
informaes localmente sem afetar a outros switches. Em modo transparante
h o encaminhamento de atualizaes de VTP pelos seus links. Se um switch
no modo transparente for configurado com um numero de vlan existente no
switch modo server os hosts deste switch participaro da mesma vlan, mesmo
tendo sido configurado separadamente.
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
Exercicio VTP
Criar as VLANs 2 diretoria e 3 vendas no switch0 VTP Server
Clique para
editar
o
estilo
do
trunk
trunk
trunk
subttulo mestre
trunk
mac-address-table, spanning-tree
portfast
Switch0#configure terminal
Switch0(config)#interface range fastEthernet 0/23-24
Switch0(config-if-range)#switchport mode trunk
mac-address-table, spanning-tree
portfast
VLAN Name
Status Ports
---- -------------------------------- --------- ------------------------------1 default
active Fa0/1, Fa0/2, Fa0/3, Fa0/4
Fa0/5, Fa0/6, Fa0/7, Fa0/8
Fa0/9, Fa0/10, Fa0/11, Fa0/12
Fa0/13, Fa0/14, Fa0/15, Fa0/16
Fa0/17, Fa0/18, Fa0/19, Fa0/20
Fa0/21, Fa0/22, Gig1/1, Gig1/2
2 diretoria
active
3 vendas
active
1002 fddi-default
active
1003 token-ring-default
active
1004 fddinet-default
active
1005 trnet-default
active
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
Native vlan
Port
Vlans allowed on trunk
Fa0/23
1-1005
Fa0/24
1-1005
Port
Vlans allowed and active in management domain
Fa0/23
1,2,3
Fa0/24
1,2,3
Port
Vlans in spanning tree forwarding state and not pruned
Fa0/23
1,2,3
Fa0/24
1,2,3
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
Switch1>enable
Switch1#configure terminal
Switch1(config)#vtp mode client
Setting device to VTP CLIENT mode.
Switch1(config)#vtp domain senailab10
Switch1(config)# vtp password cisco123
Switch1(config)#
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
Switch2>enable
Switch2#configure terminal
Switch2(config)#vtp mode client
Setting device to VTP CLIENT mode.
Switch2(config)#vtp domain senailab10
Switch2(config)# vtp password cisco123
Switch2(config)#
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
FIM
Clique para editar o estilo do
subttulo mestre
mac-address-table, spanning-tree
portfast
SWITCH
CliqueTabela
para editar
MAC oouttulo
CAMmestre
Clique para editar o estilo do
subttulo mestre
mac-address-table, spanning-tree
portfast
Informao util:
Uma porta do switch pode esta associada a 1 ou mais endereos MAC
Exemplo:
Vlan Mac Address
Type
--------------------10 0001.966c.6a80 DYNAMIC
10 00d0.bc43.9b77 DYNAMIC
20 00d0.d353.5829 DYNAMIC
20 00d0.ff72.bba6
DYNAMIC
Ports
----Fa0/1
Fa0/24
Fa0/2
Fa0/24
mac-address-table, spanning-tree
portfast
O que um switch?
Um switch (ou comutador) um equipamento ativo que
funciona normalmente na camada 2 do modelo OSI(Data
Link) e tem como principal funcionalidade a interligao de
equipamentos (estaes de trabalho, servidores, etc) de
uma rede uma vez que possui vrias portas RJ45 (ou ISO
8877) fmea.
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
Mostrando a tabela
Clique
para editar
o ttulo
de
endereamento
MAC dos
Switch0 mestre
e Switch1
mac-address-table, spanning-tree
portfast
Clique
para
editar
o
ttulo
mestre
switch0#show interfaces fastEthernet 0/2
mac-address-table, spanning-tree
portfast
Clique
para
editar
o
ttulo
mestre
Switch>enable
Switch#configure terminal
Switch(config)#hostname switch0
switch0(config)#exit
Clique
para editar o estilo do
switch0#show
mac-address-table
Mac Address Table
subttulo mestre
------------------------------------------Vlan Mac Address
Type
Ports
------------------------1 0060.2f96.0918 DYNAMIC Fa0/24
mac-address-table, spanning-tree
portfast
Clique
para
editar
o
ttulo
mestre
switch1#show interfaces fastEthernet 0/2
mac-address-table, spanning-tree
portfast
Switch>enable
Switch#configure terminal
Switch(config)#hostname switch1
switch1(config)#exit
Clique
para editar o estilo do
switch1#show
mac-address-table
Mac Address subttulo
Table
mestre
------------------------------------------Vlan Mac Address
Type
Ports
------------------------1 00e0.a3dd.3818 DYNAMIC Fa0/24
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
switch0>enable
switch0#show mac-address-table
Mac Address Table
------------------------------------------Clique
para
editar
o
estilo
Vlan Mac Address
Type
Ports
subttulo
--------------------- mestre
----1 0010.115e.6e64 DYNAMIC Fa0/2
1 00d0.d384.aa3d DYNAMIC Fa0/1
1 00e0.a3dd.3818 DYNAMIC Fa0/24
do
mac-address-table, spanning-tree
portfast
switch1>enable
switch1#show mac-address-table
Mac Address Table
------------------------------------------Vlan
----
1
1
Fa0/24
Fa0/24
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
switch1>enable
switch1#show mac-address-table
Mac Address Table
------------------------------------------Vlan Mac Address
Typeeditar oPorts
Clique para
estilo
--------------------- mestre
----subttulo
1 0010.115e.6e64 DYNAMIC Fa0/24
1 0050.0f8a.2c13 DYNAMIC Fa0/2
1 0060.2f96.0918 DYNAMIC Fa0/24
1 00d0.d384.aa3d DYNAMIC Fa0/24
do
mac-address-table, spanning-tree
portfast
switch1>enable
switch1#clear mac-address-table
Mac Address Table
------------------------------------------Vlan Mac Address
Typeeditar oPorts
Clique para
estilo
--------------------- mestre
----subttulo
do
mac-address-table, spanning-tree
portfast
Clique para
editar portfast
o ttulo mestre
Spannig-tree
Clique para editar o estilo do
subttulo mestre
mac-address-table, spanning-tree
portfast
Escuta - O switch processa BPDUs e espera por possveis novas informaes que
podem faz-lo voltar ao estado de Bloqueio. 15 segundos
Aprendizado - Quando a porta ainda est "aprendendo" e montando sua tabela de
endereos de origem dos frames recebidos. 15 segundos
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
No SWITCH0
Vamos habilitar spanning-tree portfast no intervalo da portas 1
at 23 fazendo com que ao ligar qualquer PC a esse intervalo a
luz laranja que antes viamos nao vamos mais perceber
switch0>enable
switch0#configure terminal
switch0(config)#interface range fastethernet 0/1-23
switch0(config-if-range)#spanning-tree portfast
%Warning: portfast should only be enabled on ports connected to a single
Clique
para editar
o estilo
host. Connecting hubs,
concentrators,
switches,
bridges,do
etc... to this
interface when portfast is enabled,
can cause
temporary bridging loops.
subttulo
mestre
Use with CAUTION
%Portfast will be configured in 23 interfaces due to the range command
but will only have effect when the interfaces are in a non-trunking mode.
mac-address-table, spanning-tree
portfast
No SWITCH1
Vamos habilitar spanning-tree portfast na faixas de portas 1 ate
23 fazendo com que ao ligar qualquer PC a esse intervalo a luz
laranja que antes viamos nao vamos mais perceber
switch1>enable
switch1#configure terminal
switch1(config)#interface range fastethernet 0/1-23
switch1(config-if-range)#spanning-tree portfast
%Warning: portfast should only be enabled on ports connected to a single
Clique
para editar
o estilo
host. Connecting hubs,
concentrators,
switches,
bridges,do
etc... to this
interface when portfast is enabled,
can cause
temporary bridging loops.
subttulo
mestre
Use with CAUTION
%Portfast will be configured in 23 interfaces due to the range command
but will only have effect when the interfaces are in a non-trunking mode.
mac-address-table, spanning-tree
portfast
switch1>enable
Clique
para editar o estilo
switch1#configure
terminal
switch1(config)#interfacesubttulo
range fastethernet
0/1-23
mestre
switch1(config-if-range)#no spanning-tree portfast
do
mac-address-table, spanning-tree
portfast
mac-address-table, spanning-tree
portfast
Fim
Clique para editar o estilo do
subttulo mestre