Break Switches - Configuring and Best Practices

Slides:



Advertisements
Similar presentations
Ethernet Switch Features Important to EtherNet/IP
Advertisements

Mitigating Layer 2 Attacks
LAN Segmentation Virtual LAN (VLAN).
© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Common Layer 2 Attacks and Countermeasures.
Cisco 3 - Switch Perrine. J Page 15/8/2015 Chapter 8 What happens to the member ports of a VLAN when the VLAN is deleted? 1.They become inactive. 2.They.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 Implement VTP LAN Switching and Wireless – Chapter 4.
Computer Networking Macedonia VLAN’s, VTP, InterVLAN Routing, (And if there is enough time - STP)
Part III Working with Redundant Links
1 © 2005 Cisco Systems, Inc. All rights reserved. 111 © 2004, Cisco Systems, Inc. All rights reserved.
Course 301 – Secured Network Deployment and IPSec VPN
© 2009 Cisco Systems, Inc. All rights reserved. SWITCH v1.0—3-1 Implementing Spanning Tree Describing STP Stability Mechanisms.
© 2009 Cisco Systems, Inc. All rights reserved. SWITCH v1.0—3-1 Implementing Spanning Tree Spanning Tree Protocol Enhancements.
Layer 2: Redundancy and High Availability Part 1: General Overview on Assignment 1.
(part 3).  Switches, also known as switching hubs, have become an increasingly important part of our networking today, because when working with hubs,
© 2006 Cisco Systems, Inc. All rights reserved. ICND v2.3—2-1 Extending Switched Networks with Virtual LANs Configuring VLANs.
Layer 2 Switch  Layer 2 Switching is hardware based.  Uses the host's Media Access Control (MAC) address.  Uses Application Specific Integrated Circuits.
James Oryszczyn President, TBJ Consulting LLC Break 1320 Wireless Infrastructure & Networking Best Practices.
STP Part II PVST (Per Vlan Spanning Tree): A Vlan field is added to the BPDU header along with Priority & Mac. Priority is 32768, Mac Address is MAC or.
IEEE 802.1q - VLANs Nick Poorman.
Switching in an Enterprise Network
CIT 384: Network AdministrationSlide #1 CIT 384: Network Administration VLANs.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 Implement Spanning Tree Protocols LAN Switching and Wireless – Chapter 5 Part.
CN2668 Routers and Switches (V2) Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Building Cisco Multilayer Switched Networks (BCMSN)
Author: Bill Buchanan. Transparent bridge Author: Bill Buchanan CAM.
1/28/2010 Network Plus Network Device Review. Physical Layer Devices Repeater –Repeats all signals or bits from one port to the other –Can be used extend.
Chapter 9 Virtual LANs (VLANs). Setup 1 Setup 2.
Mahindra-British Telecom Ltd. Exploiting Layer 2 By Balwant Rathore.
LOGO Local Area Network (LAN) Layer 2 Switching and Virtual LANs (VLANs) Local Area Network (LAN) Layer 2 Switching and Virtual LANs (VLANs) Chapter 6.
S7C5 – Spanning Tree Protocol And other topics. Switch Port Aggregation Bundling –Combining 2 to 8 links of FE (Fast Ethernet) or GE (Gigabit) Full duplex.
Operating Wide-Area Ethernet Networks Matt Davy Global NOC Matt Davy Global NOC.
STP LAN Redundancy Introduction Network redundancy is a key to maintaining network reliability. Multiple physical links between devices provide redundant.
Switching Topic 6 Rapid spanning tree protocol. Agenda RSTP features – Port states – Port roles – BPDU format – Edge ports and link types – Proposals.
Switching Topic 2 VLANs.
1 Version 3.0 Module 7 Spanning Tree Protocol. 2 Version 3.0 Redundancy Redundancy in a network is needed in case there is loss of connectivity in one.
CCNP 3: Chapter 3 Implementing Spanning Tree. Overview Basics of implementing STP Election of Root Bridge and Backup Enhancing STP RSTP MSTP EtherChannels.
Implementing MST on a Large Campus Implementing MST in a Large Campus Environment February 13, 2007 Rich Ingram
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 Switching in an Enterprise Network Introducing Routing and Switching in the.
BZUPAGES.COM Introduction to Cisco Devices Interfaces and modules –LAN interfaces (Fast Ethernet, Gigabit Ethernet) –WAN interfaces(Basic Rate Interface.
W&L Page 1 CCNA CCNA Training 2.5 Describe how VLANs create logically separate networks and the need for routing between them Jose Luis.
Topic 5 Spanning tree protocol
CO5023 LAN Redundancy.
Layer-2 Switching and STP
W&L Page 1 CCNA CCNA Training 2.8 Identify enhanced switching technologies Jose Luis Flores / Amel Walkinshaw Aug, 2015.
W&L Page 1 CCNA CCNA Training 2.6 Configure and verify VLANs Jose Luis Flores / Amel Walkinshaw Aug, 2015.
Chapter-5 STP. Introduction Examine a redundant design In a hierarchical design, redundancy is achieved at the distribution and core layers through additional.
LAN Switching Virtual LANs. Virtual LAN Concepts A LAN includes all devices in the same broadcast domain. A broadcast domain includes the set of all LAN-connected.
Cisco Study Guide
© 2003, Cisco Systems, Inc. All rights reserved. 2-1 Implementing VLAN Trunks.
InterVLAN Routing 1. InterVLAN Routing 2. Multilayer Switching.
Instructor Materials Chapter 5: Network Security and Monitoring
Exploiting Layer 2 By Balwant Rathore.
Layer 2 Attacks and Security
Switching and VLANs.
Spanning Tree Protocol
Chapter 5: Inter-VLAN Routing
Chapter 2: Basic Switching Concepts and Configuration
Spanning Tree Protocol
Chapter 5: Network Security and Monitoring
Spanning Tree Protocol
Switching and VLANs.
Best Practices for Configuring Stratix Managed Switches
CCNA 3 v3 JEOPARDY Module 8 CCNA3 v3 Module 8 K. Martin.
CCNA 3 v3 JEOPARDY Module 8 CCNA3 v3 Module 8 K. Martin.
Spanning Tree Protocol (STP)
Cisco networking CNET-448
Sécurisation au niveau 2 pour certains matériels Cisco
CISCO SWITCHING Hussein Salameh Network Administrator
VLANS The Who, What Why, And Where's to using them
Presentation transcript:

Break-1521 - Switches - Configuring and Best Practices James Oryszczyn President, TBJ Consulting LLC

Who Am I I am President of TBJ Consulting LLC I have been working on Network Infrastructure for over 15 years Have help numerous school’s and Enterprise’s with Design and Implementation of switching/routing ETC….

Agenda Discuss Spanning Tree Discuss VLANS Discuss Layer 3 Discuss Interoperability

At the End of the Presentation I will discuss a survey you can take to determine if you are following best practices

Spanning Tree Who can tell me what this does and why it is needed? Do all switch manufactures enable it by default? How does it determine who is the master?

Spanning Tree Most misconfigured items on the network Need to make sure you set the root bridge to your core Some switches (HP) come with spanning tree disabled Can lead to network loops and also High Switch CPU If mulit-vendor, make sure spanning-tree types match. Should run Per VLAN spanning tree Enable Port-fast on all edge ports

Spanning Tree Examples HP Same MSTP Config name. Name is case sensitive. Core-1(config)# spanning-tree config-name "B10" ! Same MSTP Revision number. Core-1(config)# spanning-tree config-revision 1 ! Same MSTP Instances definition Core-1(config)# spanning-tree instance 1 vlan 10 20 108 Core-1(config)# spanning-tree instance 2 vlan 30 40 ! Enables Spanning Tree Core-1(config)# spanning-tree !Core-switch specific configuration: !Core-1 is Root in Instance 1 Core-1(config)# spanning-tree instance 1 priority 0 HP Spanning Tree White Paper http://h40060.www4.hp.com/procurve/uk/en/pdfs/application-notes/How_to_improve_and_harden_spanning-tree_configuration_Configuration_note_Dec_08_A4.pdf

Spanning Tree Examples Cisco spanning-tree mode rapid-pvst spanning-tree portfast bpdufilter default panning-tree vlan priority 10,14,18,40,190,212,216,220 24576 spanning-tree vlan priority 4,12,16,20,64,210,214,218,1000 28672 On Edge Port enable spanning-tree port fast What is port fast? It allows the Port to become active faster than the traditonal 60 second’s interface GigabitEthernet 1/0/11 spanning-tree portfast Cisco White Paper http://www.cisco.com/en/US/tech/tk389/tk621/technologies_configuration_example09186a008009467c.shtml

Spanning Tree Examples Juniper set protocols vstp vlan 10 bridge-priority 16k set protocols vstp vlan 1000 bridge-priority 16k Juniper Port fast set protocols stp interface ge-0/0/0.0 edge White paper found here http://www.juniper.net/us/en/local/pdf/implementation-guides/8010002-en.pdf

VLAN’s Why are VLAN’s needed? Who here has more than 1 VLAN? Is using VLAN 1 recommend?

VLAN’s Why are VLAN’s needed? Who here has more than 1 VLAN? Is using VLAN 1 recommended?

VLAN’s Should use VLAN’s to separate traffic Should not use VLAN 1, it is a security risk If network is large enough, create a VLAN for network devices Be careful not to create to many VLAN’s Network with 250 nodes over, should have more than 1 VLAN

Juniper VLAN Configuration Cisco VLAN Configuration http://www.juniper.net/techpubs/en_US/junos9.4/topics/task/configuration/bridging-vlans-ex-series-cli.html Cisco VLAN Configuration http://www.cisco.com/en/US/tech/tk389/tk815/technologies_configuration_example09186a008019e74e.shtml HP VLAN Configuration http://www.hp.com/rnd/support/config_examples/primary_vlan.pdf

VLAN Security Issues (Why not to use VLAN1) MAC Flooding Attack 802.1Q and ISL Tagging Attack Double-Encapsulated 802.1Q/Nested VLAN Attack ARP Attacks Private VLAN Attack Multicast Brute Force Attack Spanning-Tree Attack Random Frame Stress Attack

Switch Trunking Configuration How to Get VLAN to cross switches Puts a tag in the packet with the VLAN-ID Make sure you use Industry Standards for VLAN Trunks Make sure you set the Native VLAN-ID to something other than VLAN 1

Switch Trunking Configuration Continued.. Make sure you prune switch trunks for only needed VLANs Do not need all VLANS on all Switches

Switch Trunking Configuration Continued.. Make sure you prune switch trunks for only needed VLANs Do not need all VLANS on all Switches

Switch Trunking Configuration Continued.. Make sure you prune switch trunks for only needed VLANs Do not need all VLANS on all Switches If you are going to have Multiple Vendors, Use LACP uplinks

Switch Trunking Configuration Continued.. Cisco interface FastEthernet0/13 switchport trunk encapsulation dot1q switchport mode trunk switchport trunk native vlan 11 switchport trunk allowed vlan 2 Juniper set interfaces ge-0/0/1 unit 0 family ethernet-switching port-mode trunk set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members NAC-Guest-Vlan set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members TPA-Switch-MGMT set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members TPA-WiFi-Private set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members TPA-34-Voice set interfaces ge-0/0/1 unit 0 family ethernet-switching native-vlan-id TPA-Switch-MGMT

Switch Trunking Configuration Continued.. Juniper set interfaces ge-0/0/1 unit 0 family ethernet-switching port-mode trunk set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members NAC-Guest-Vlan set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members TPA-Switch-MGMT set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members TPA-WiFi-Private set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members TPA-34-Voice set interfaces ge-0/0/1 unit 0 family ethernet-switching native-vlan-id TPA-Switch-MGMT HP vlan 2 HP2910al(Vlan-2)#tagged 48

Switch Layer 3 best practices Should have redundant switches Should use a standard such as VRRP for redundancy in the core If possible, do layer 3 uplinks instead of layer 2 What are Layer3 uplinks?

Layer 3 Uplinks Connections between switches are routed Helps eliminate spanning tree and loops Millisecond failover instead of up to 60 sec’s Helps keep broadcast traffic down Cost can be a concern

Backups How often do you backup your switches? Do you use a tool to automate your backups? Do you have an email notifying you of changes? A simple tool like a product call CATTOOLS can backup your environment and is low cost. http://www.kiwisyslog.com/kiwi-cattools-overview/ Price is $750 plus maintenance.

Code Upgrades How often do you upgrade your switches? Do you use the recommended release when installing? Do you have plan on when/how you upgrade your switches Should attempt to upgrade yearly Should use the recommended release at that time Cisco, Juniper have links to the recommended releases They are no different than PC’s, they need to be patched

Port Security Port Security can help Do you disable unused and unneeded ports? Do you restrict how many devices can connect to a port? Do you prevent against a rouge DHCP server on the network? Port Security can help Allows to disable ports after a certain number of devices DHCP snooping can prevent rouge DHCP servers

Port Security Example Port Security can help Do you disable unused and unneeded ports? Do you restrict how many devices can connect to a port? Do you prevent against a rouge DHCP server on the network? Port Security can help Allows to disable ports after a certain number of devices DHCP snooping can prevent rouge DHCP servers Port Security Example

Additional Best Practices Should configure time zones on switches Should configure NTP on switches Should use SSH instead of telnet Should change default username and password Should use radius if possible

Survey If you give me your Business Card I will provide you an assessment about your current Switched Network

Questions????? Thank You………… You can contact me at James@tbjconsulting.com