2022年2月9日 星期三

VMWare Convertor 轉換經驗

 VMWare ESXi發展至今,相信很多IT人員已經經歷過企業內部的許多運行在實體機器上面的系統透過VMWare Converter轉到ESXi上運行,在此就不在贅述轉換方式。最近因為公司汰換電腦,原本拿來當作跳板機的筆電要被公司收回去了,已經習慣使用這台電腦當作遠端到客戶環境的跳板機了,因此打算將這台筆電上的系統轉到公司內的ESXi系統上,不過在VMWare官網上找了一段時間一直苦尋不到Converter,後來找到以下這一篇原廠的公告:


https://blogs.vmware.com/vsphere/2022/02/vcenter-converter-unavailable-for-download.html



好在同事之前下載後有備份,於是就依照converter的指示將系統轉到ESXi上。不過,初次開機登入後,卻發現連登入的密碼欄位都沒有辦法使用鍵盤輸入,找了一些資料之後發現可能的原因是原本筆電上的Lenovo驅動程式所致,所幸就把筆電上關於Lenovo相關的程式都移除掉,同時參考以下這一篇討論 https://communities.vmware.com/t5/VMware-Workstation-Player/Keyboard-Not-Working-after-VMWare-Conversion/td-p/2166269 的做法解決了。

2016年5月5日 星期四

Cisco Flexible Netflow(FNF)中使用Legacy Netflow的show ip cache flow

Legacy Netflow中使用show ip cache flow可以看到以下資訊:


CC6509#show ip cache flow

-------------------------------------------------------------------------------
MSFC:
IP packet size distribution (2562M total packets):
   1-32   64   96  128  160  192  224  256  288  320  352  384  416  448  480
   .004 .982 .005 .000 .003 .000 .000 .000 .000 .000 .000 .000 .000 .001 .000

    512  544  576 1024 1536 2048 2560 3072 3584 4096 4608
   .000 .000 .000 .000 .000 .000 .000 .000 .000 .000 .000

IP Flow Switching Cache, 4456704 bytes
  6 active, 65530 inactive, 98905147 added
  1786040762 ager polls, 0 flow alloc failures
  Active flows timeout in 30 minutes
  Inactive flows timeout in 15 seconds
IP Sub Flow Cache, 270664 bytes
  6 active, 16378 inactive, 194430814 added, 98905147 added to flow
  0 alloc failures, 133224 force free
  1 chunk, 113 chunks added
  last clearing of statistics never
Protocol         Total    Flows   Packets Bytes  Packets Active(Sec) Idle(Sec)
--------         Flows     /Sec     /Flow  /Pkt     /Sec     /Flow     /Flow
TCP-Telnet    20522857      4.7         6    47     30.0       5.8      15.4
TCP-FTP         593365      0.1         1    44      0.1       0.6      15.3
TCP-FTPD          6766      0.0         1    42      0.0       0.0      17.1
TCP-WWW        8095942      1.8         1    48      2.3       1.0      14.7
TCP-SMTP        439001      0.1         1    43      0.1       0.1      15.4
TCP-X          4197700      0.9         1    40      0.9       0.0      15.6
TCP-BGP          23777      0.0         1    40      0.0       0.0      16.0
TCP-NNTP         32306      0.0         1    40      0.0       0.0      16.0
TCP-Frag          2338      0.0         1    86      0.0       0.0       5.8
TCP-other     35616655      8.2        66    40    550.8       0.8      16.0
UDP-DNS        1801203      0.4         1    65      0.4       0.0      15.5
UDP-NTP        5469491      1.2         1    78      1.2       0.0      15.5
UDP-TFTP         24794      0.0         1    43      0.0       0.0      15.5
UDP-Frag          1523      0.0       417  1497      0.1       1.0      15.4
UDP-other     15663208      3.6         2   138      8.3       2.0      15.5
ICMP           6414014      1.4         1    71      1.8       1.3      15.4
GRE                 20      0.0         1   490      0.0       0.0      15.5
IP-other           177      0.0         1   248      0.0       3.3      15.4
Total:        98905137     23.0        25    42    596.6       2.0      15.6

SrcIf         SrcIPaddress    DstIf         DstIPaddress    Pr SrcP DstP  Pkts
Vl900         0.0.0.0         Null          255.255.255.255 11 0044 0043     1
Vl900         172.16.0.113    Local         172.16.0.254    11 007B 007B     1
Vl900         172.16.0.42     Local         172.16.0.254    11 007B 007B     1
Vl900         172.16.0.226    Local         172.16.0.254    11 007B 007B     1
Vl900         172.16.0.223    Null          239.255.255.250 11 076C 076C     1
Vl900         172.16.0.250    Null          140.127.198.12  11 007B 007B     1
Vl900         172.16.0.250    Null          140.127.198.11  11 007B 007B     1

-------------------------------------------------------------------------------
PFC:

Displaying Hardware entries in Module 2
 SrcIf            SrcIPaddress          DstIPaddress      Pr       SrcP      DstP      Pkts
 Vl249            140.117.195.154       10.0.0.138        udp      9775      28622     0
 Vl200            10.0.143.215          54.250.232.2      tcp      50420     443       15
 Vl249            52.193.251.190        10.0.86.114       tcp      www       55411     1
 Vl249            140.127.206.254       140.127.198.61    icmp     0         0         7
 Vl249            64.233.189.189        10.0.20.106       udp      443       51188     10
 Vl249            172.19.9.197          140.127.198.6     udp      59737     dns       1
 Vl200            10.0.120.1            205.251.212.19    tcp      34178     443       12
 Vl200            10.0.156.185          213.155.215.185   udp      16768     17181     1
 Vl249            10.2.140.98           140.127.198.3     udp      63104     dns       1
 Vl249            74.125.194.127        10.0.172.14       udp      19302     59466     2
 Vl249            205.251.199.239       140.127.198.6     udp      dns       43517     1
 Vl249            140.127.212.25        140.127.198.1     udp      51909     dns       1
 Vl200            10.0.182.206          17.253.17.208     tcp      58054     www       649
 Vl200            140.127.200.249       172.17.0.42       udp      5247      1545      16859
 Vl200            1.1.1.1               10.0.227.120      tcp      444       12536     6
 Vl249            10.1.213.115          140.127.198.10    udp      137       137       6
...........(以下省略)




那如何在Flexible Netflow上如何顯示類似的資料呢?
可以嘗試以下指令:

LIC_4500X#show flow monitor CM-v4-monitor cache format table
  Cache type:                               Normal
  Cache size:                                 1024
  Current entries:                             973
  High Watermark:                             1024

  Flows added:                          1130251984
  Flows aged:                           1130251011
    - Active timeout      (  1800 secs)      11343
    - Inactive timeout    (    15 secs)   99157047
    - Event aged                                 0
    - Watermark aged                     301513880
    - Emergency aged                     729568741

IPV4 SRC ADDR    IPV4 DST ADDR    TRNS SRC PORT  TRNS DST PORT  INTF INPUT            IP PROT       bytes        pkts    time first     time last
===============  ===============  =============  =============  ====================  =======  ==========  ==========  ============  ============
130.211.141.52   140.127.223.104            443          49900  Te2/1                       6          64           1  17:25:48.983  17:25:48.983
123.187.78.231   140.127.232.208          16001           6999  Te2/1                      17         147           1  17:25:48.983  17:25:48.983
203.70.119.117   140.127.233.120             80          49390  Te2/1                       6       55138          40  17:25:48.983  17:25:51.983
203.69.105.248   140.127.220.212             80          58305  Te2/1                       6        1544           4  17:25:48.983  17:25:48.983
10.1.220.3       203.70.119.117           49428             80  Te1/5                       6        9947          24  17:25:48.983  17:25:53.987
104.250.142.226  140.127.233.62              80          55613  Te2/1                       6         722           1  17:25:48.983  17:25:48.983
115.79.44.172    140.127.218.30           54747          31999  Te2/1                       6          64           1  17:25:48.983  17:25:48.983
88.168.81.160    140.127.205.84           33826          10150  Te2/1                       6          64           1  17:25:48.983  17:25:48.983
59.50.158.60     140.127.231.3            16001           7436  Te2/1                      17         294           2  17:25:48.983  17:25:48.983
163.28.130.44    140.127.206.35             443          14145  Te2/1                       6       69031          93  17:25:48.983  17:25:57.987
111.221.77.162   140.127.233.122          40022          14515  Te2/1                      17          67           1  17:25:55.986  17:25:55.986
94.72.2.170      140.127.213.165          19689           6881  Te2/1                      17         149           1  17:25:55.986  17:25:55.986
106.10.150.171   140.127.233.192             25           2521  Te2/1                       6         463           5  17:25:55.986  17:25:55.986
114.24.176.211   140.127.205.84            8733           7345  Te2/1                      17         355           1  17:25:55.986  17:25:55.986
140.127.220.214  72.186.58.131             6881           9862  Te1/5                      17         337           1  17:25:55.986  17:25:55.986
10.1.219.44      65.55.162.26             61786            443  Te1/5                       6         537           6  17:25:55.986  17:25:55.986
123.193.80.185   140.127.206.239           9669          51413  Te2/1                      17         161           1  17:25:55.986  17:25:55.986
114.33.204.253   140.127.206.101           6690          63609  Te2/1                       6         326           1  17:25:55.986  17:25:55.986
140.127.219.216  52.26.91.224              6423            443  Te1/5                       6          64           1  17:25:59.982  17:25:55.986
114.47.175.31    140.127.205.84            7673          10214  Te2/1                       6         128           2  17:25:55.986  17:25:55.986
..........(以下省略)

不過,因為FNF的欄位都是管理者自己定義的,所以無法顯示Legacy Netflow最上方的service port使用排名。(或許可以,不過還要再"菸酒菸酒")


F5的SNAT與NAT觀念


SNAT(Secure NAT或Source NAT)是一種多對少的轉址關係,通常用於從F5流出去的outbound流量,如上圖,10.10.10.1、10.10.10.2、10.10.10.3經由F5出去時會被SNAT成Ext這個VLAN的SelfIP(在Automap的情況下),因為有兩個SelfIP,所以會輪流SNAT成這兩個IP。

SNAT的IP無法被直接存取,也就是60.249.69.36無法initial session到210.96.88.12及198.66.87.35這兩個IP(Secure NAT由此而來),但可以接受由這兩個IP所發起的回應連線。











NAT是一種一對一的轉址關係,是一種雙向的轉址,在這種關係下,VLAN的SelfIP可以直接被存取,例如:60.249.69.36可以直接存取198.66.87.35,存取時其destination IP會被轉成10.10.10.2。而10.10.10.2存取60.249.68.36時,其source address會被轉成198.66.87.35







PaloAlto 7.0版關於Global Protect無法顯示網頁(404 Not Found)問題

更新完PANOS至7.0版後,發現登入https://vpn-ip後會顯示404 Not Found

進入PA系統內的Network->GlobalProtect->Portals->進入設定會看到Appearance下方的Disable login page預設是打勾的
所以解決方式就是把這個勾拿掉
然後
把Custom Login Page改選factory-default就大功告成了



2015年8月14日 星期五

DNS master與slave同步問題

資料同步化過程 :
      在資料同步的過程中。簡單來說,Slave的資料內容來自於Master。但Slave是如何判斷何時才要同步更新資料。基本上不論是Master或是Slave都會有「序號」,並且以此序號的大小來研判是否要更新或是同步。同步更新的方式大約分成兩種:
Master主動通知】在修改Master的資料內容,並增加序號大小,一但當重啟DNS
                                務時,Master會主動通知Slave有資料更新。以便達到同步。
Slave主動提出要求】基本上Slave會定時的查看Master的序號大小,當發現Master
                                  的序號比Slave大時,就會主動更新。若序號不變,則不會更新。

2013年4月29日 星期一

Cisco無線AP與Controller的互聯方式

準備工作:
       進入到AP console,設定AP的IP address==>


In a new installation, when a LAP is unable to find a WLC using the discovery algorithms, you can statically configure the information necessary to join a controller via the console port and the AP’s CLI. Refer to Lightweight AP (LAP) Registration to a Wireless LAN Controller (WLC) for more information on the WLC discovery algorithms and the LAP registration process.
In order to manually configure static information on a LAP using the AP CLI interface, you can use these EXEC mode CLI commands:
AP#capwap ap ip address <IP address> <subnet mask>

AP#capwap ap ip default-gateway <IP-address>

AP#capwap ap controller ip address <IP-address>

AP#capwap ap hostname <name>
  (optional)


=======================================================================

最近常有機會在不同的環境將thin ap 加入controller裡面好讓controller控制,方法很多,到底環境要用什麼樣的方式來加呢?先了解ap如何與controller溝通,再依不同的環境選合適的方式。

Cisco 瘦AP加入Controller的順序依序如下:
1.區域廣播(Local IP Subnet Discovery):
原理:先用廣播的方式,找到環境內的Controller,也就是thin AP與Controller在同一個網段裡,這是最快也最簡單的方式。
方法:只要把AP插上電與網路即可。

2.空中廣播Over The Air Provisioning(OTAP):
原理:當從網路線上廣播找不到controller時,第二步透過空氣中的無線電廣播,找尋有沒有其它ap已經有controller的資訊,有的話就跟著去找到Controller
方法: 把AP放置在已加入controller的thin ap 附近。

3.Locally Stored Controller IP Address:
原理:如果從空氣中找不到其它AP的訊號,第三步就是找尋自已AP內是不是有設定過Controller的資訊?Controller 的IP地址,有的話即透過此IP地址去找Controller
方法:以console線接到ap,從CLI輸入下列指令
lwapp ap controller ip add x.x.x.x
上面指令即是告訴AP controller在哪裡,如果環境沒有dhcp先配方ip的話,需要先設定ip給thin ap,指令如下:
lwapp ap ip address x.x.x.x x.x.x.x

4. DHCP option 43:
原理:如果AP本身沒有設定Controller的IP資訊,接下來即找尋DHCP的option43資訊,是否有設定controller的位址,有的話即套用此IP位址與controller溝通
方法: 以cisco switch為例,設定dhcp 的option如下:
ip dhcp pool wireless
   network 192.168.1.x 255.255.255.0
   dns-server 192.168.1.x
   default-router 192.168.1.254
   option 43 hex f104.c0a8.a202
簡單說明option 43,option43是16進制的IP位址,所以在option43之前需指定hex(16進),而這16進的號碼是由Type + Length + Value 所組成。Type比較簡單,永遠是0xF1,只取F1為開頭。而Length就看有設定多少個IP位址,以IPv4來說,192.168.10.5是一個IP有四段,所以length為4,如果是兩個ip,比如192.168.10.5與192.168.10.6有兩個IP, length為8。最後Value就是把IP位址改成16進。
下面的例子是把192.168.10.5與192.168.10.20這兩個controller ip設定成option 43的格式:
option 43 hex f108c0a80a05c0a80a14

5. DNS Discovery:
原理:最後,DHCP沒設定option 43的話,就是看DNS有沒有指定Controller在哪?有的話即進行與controller的溝通。
方法: 即是在DNS上加入一比Recorder ,如下:
 CISCO-CAPWAP-CONTROLLER.localdomain  10.0.0.1
後面的localdomain為環境的網域名稱,上面紅色的部份是ap會找尋的固定名稱,需要一樣


當跑完上面五個流程都沒找到,就會從頭再來一次,直到找到controller為止,因為…thin AP沒辦法像FAT AP能夠勇敢、單獨的存在著。

所以可以簡單的把Thin AP 加入Controller的方式概分為兩種環境:
1.同一個網段裡: 這是最簡單的,即上面介紹的第一種方式區域廣播,只需要確認ap有電、有網路線即可。
2.不同網段裡:跨網段可以從上面2~4方式選一種,以簡單方便為主。




2013年2月24日 星期日

關於VMWare ESX裡面的網路(轉載)

很不錯的一篇文章,轉載自 http://www.weithenn.org/cgi-bin/wiki.pl?VMware_Networking


vNetwork 介紹

vNetwork 支援二種 Virtual Switch 也就是 Standard Switches (VSS) 及 Distributed Switches (VDS),而 vNetwrok 提供三種網路服務存取型態 Virtual Machine Port Group、VMKernel Port、Service Console Port
  1. VSS、VDS: 用於 VM 與 VM 之間溝通或 VM 與實體 Switch 溝通之用
    1. vNetwork Standard Switches (VSS) 無法跨 Host 使用
    2. vNetwork Distributed Switches (VDS) 可以跨 Host 使用 (Enterprise Plus 版本才有支援此功能),且當 VM 透過 VMotion 機制移轉至其它台 Host 時原先在虛擬交換器針對 VM 所做的設定,仍然會自動套用到該 Host 上
虛擬網路 (vNetwork): vSwitch 支援下列三種連線類型
  1. Virtual Machine: VM,也就是給虛擬機器 VM 連接使用並搭配後續談到的 Port Group 使用
  2. VMKernel: vmknic,需要連接 iSCSI、NFS 等 IP Storage 及後續談到的進階功能 vMotion 時使用 (ESXi 稱為 Management Network)
  3. Service Console: vswif,安裝完 ESX Host 後與外界溝通的唯一管道用於 vSphere Client 連入時及後續談到的進階功能 HA (HA Heartbeat) 時使用 (只有 ESX Host 才有 Service Console 若是安裝 ESXi 則無)

vSwitch 介紹

  • vSwitch 提供 VM 與實體網路交換資訊的能力
  • vSwitch 可配合指定 多片 實體網路卡 (UpLink) 來達到頻寬的負載平衡 (Balances Traffic) 及容錯 (Failover) 也就是 NIC Teaming 功能
  • vSwitch 建立時預設會提供 56 Ports (最大值 4088 Ports) VM 及實體網卡 (UpLink) 存取使用, ESX / ESXi 顯示預設值為 24 Ports,若更改 vSwitch Ports 設定值則必須將 ESX / ESXi Host 重新啟動才會套用新的設定值
  • 建立 vSwitch 時若 不勾選任何 vmnic 則表示屆時連接此 vSwitch 的 VM  與實體網路卡 (UpLink) 介接也就是只能 VM 與 VM 之間互通,例如可使用於該 VM 是 NAT Client 環境下
  • vSwitch 上面沒有接任何 VM 但有連接實體網路卡 (Up Link) 時表示用於 VMkernel 之用通常使用於 VMotion 或 IP-SAN(iSCSI) 連接之用且不與 VM 共用實體網路頻寬
  • 每一台 Host 最多可以建立 248 台 vSwitch (VI3 則為 127 台)
  • 每一台 vSwitch 上面皆可切出多個 Port Group 出來,例如 VLAN、頻寬管理...等用途
  • 若要支援 Jumbo Frames 則請將 MTU 數值設定為 9000,而 ESXi 則只有及上運作的 VM 能進行設定 ESXi Host 本身無法進行設定。
了解上述 vSwitch 特性後我們可知您可將不同功能用途例如 iSCSI、VMotion、VM、Service Console 都放在同一個 vSwitch 上也可放在不同的 vSwitch 上,至於何種方式比較好則必須視實際環境、流量負載、傳輸效能而定因為二種方式各有其優缺點。
舉例來說若一台 Host 上有三張實體網路卡,若將 iSCSI、VMotion、VM、Service Console 都放在同一個 vSwitch 上或不同 vSwitch 上大致可想得到的優缺點為
  • 同一個 vSwitch: 由於多張實體網路卡指定給同一個 vSwitch 後將具有頻寬的負載平衡 (Balances Traffic) 及容錯 (Failover) 功能,因此好處當實體網路發生問題時因為容錯功能發揮將使得連線不致中斷,但缺點就是所有的服務都在同一個 vSwitch 上亂竄互相影響 (雖然可透過 Port Group 設定進行微調)。
  • 不同一個 vSwitch: 好處當然就是相關服務及傳輸都互相隔離,如此一來傳輸效能及品質都將保持一定的水準,但相對來說若實體網路發生問題時服務也將因此中斷。



Port Group

Port Binding 模式

  • Static Binding: 表示對應一個 VM 就佔用一個 Port
  • Dynamic Binding: 表示該 VM Power ON 時才佔用一個 Port 若 VM Power Off 則釋放 Port 出來
  • Ephemeral - no Binding: 表示沒有 Port Binding 功能

限制流入/流出流量

Distributed Switches (VDS) 支援網路流量 流入 Inbound / 流出 Outbound 的限制,而 Standard Switches (VSS) 僅支援 網路流量 流出 Outbound 的限制
  • Ingress: 即 Traffic Inbound (流入)
  • Dgress: 即 Traffic Outbound (流出)

Security

  • Promiscuous Mode: 是否啟用網卡混亂模式,也就是開啟網卡監聽功能
  • MAC Address Changes: 是否允許 VM 能更改 MAC Address
  • Forged Transmits: 是否啟用阻擋 VM 所送出的封句 (通常配合 Application 進行設定)

VLANs

VLAN 在虛擬環境下有三種不同的方式:
  • VST (Virtual Switch Tagging): 虛擬 vSwitch 進行 tagged 及 untagged,由虛擬 vSwitch 來定義 VLAN 而實體 Switch 不作任何 VLAN 設定 (也就是實體網卡 Uplink Port 必須接至實體 Switch 的 Trunk Port),由於 vSwitch 的 VLAN 是由 VMkernel 來執行 tagged 及 untagged 的動作因此對於 Host 效能有一定程度影響。
  • VGT (Vitual Guest Tagging): VM (Guest OS) 進行 tagged 及 untagged,由 VM 本身自行設定 VLAN 通常很少使用此方式。
  • EST (External Switch Tag): 實體 Switch 進行 tagged 及 untagged,由實體 Switch 設定 VLAN 而 VM 及 vSwitch 不作任何 VLAN 設定,也就是 VM 從哪個 Uplink Port 至實體 Switch 即屬於該 VLAN。
  • PVLAN (Private VLAN): 也就是 VLAN 中又有 VLAN,有如下三種模式 (VDS 才支援,VSS 未支援此功能)
    • Promiscuous: VM E 及 VM F 可互通,同時也可跟 VM ABCD 互通
    • Isolated: VM C 及 VM D 不會通,跟 VM AB 不通,但跟 VM EF 可互通
    • Community: VM A 及 VM B 可互通,跟 VM CD 不通,但跟 VM EF 會通
Community (PVLAN 17)Isolated (PVLAN 155)Promiscuous (PVLAN 5)
VM AVM BVM CVM DVM EVM F
vDS
Primary PVLAN 5

2013年2月20日 星期三

NAT的種類與特性

假設內部位址(Private IP)為N,外部位址(Public IP)為M,NAT的種類分為:

1.Dynamic NAT
   # N個Private IP嘗試從M個Public IP中挑出一個轉址,如果N>M有可能會導致有IP無法轉
      址,另一個缺點是會浪費Public IP,這種情況建議改用PAT
   # NAT timeout可以藉由timeout xlate來改變。
   # 無法提供反向存取,遠端Host無法藉由存取Public IP來存取Private IP,
      但在位址轉換期間,遠端Host有機會嘗試藉由存取Public IP來存取Private IP(前提是
      Security policy有allow),有心攻擊者仍有機會藉由工具達成入侵的目的。


2.PAT
   # M=1,N個Private IP嘗試從1個Public IP中挑出一個轉址,由於只有一個Public IP,所以
      藉由轉換Port(Port Number > 1024)的方式來達到轉址的目的。
      這種方式在某些多媒體運用無法提供正常運作。
   # PAT timeout=30秒,無法改變。
   # 無法提供反向存取,遠端Host無法藉由存取Public IP來存取Private IP,
      但在位址轉換期間,遠端Host有機會嘗試藉由存取Public IP來存取Private IP(前提是
      Security policy有allow),有心攻擊者仍有機會藉由工具達成入侵的目的。

3.Static NAT
   # N=M,提供一對一的轉址
   # 提供反向存取,遠端Host可藉由存取Public IP來直接存取Private IP。
      (在Juniper Firewall上稱為MIP)
   # Static NAT和Dynamic NAT的不同

4.Static PAT
   #提供外部對內部的存取
   #M=1,藉由存取外部IP:port 來直接存取內部IP。 (在Juniper Firewall上稱為VIP)

2013年1月31日 星期四

Cisco Catalyst 2960系列交換器(LAN Base & LAN Lite) Q & A

標題:Cisco Catalyst 2960系列交換器(LAN Base & LAN Lite) Q & A

Q1: 請問2960可以透過IOS軟體升級或降級達到功能的新增或減少嗎?
A1: No2960 不支援軟體相互更新

Q2: 請問2960 LAN Base  LAN Lite 主要的差異在哪裡?
A2: 重點的主要差異如下:
 Gigabit Ethernet connectivity in 8, 24, and 48 port configurations

‧ RPS support and support for a wide range of SFP transceivers

‧ Enhanced security through Layer 2-4 access control lists (ACLs), DHCP Snooping, and more 
  extensive Network Admission Control  capabilities such as Web authentication and 802.1x
  enhancements

‧ Additional QoS capabilities: The LAN Base IOS supports policing, class and policy maps, 
  differentiated services code point (DSCP), AutoQoS, and configurable queue weights, buffers,  
  and thresholds

 Higher network-level availability with features such as Flex Links and Link State Tracking

 Increased number of VLANs (256) and other enhancements such as IPv6 Host, MLD 
  Snooping, LLDP-MED, RSPAN, MVR, DHCP Option 82, and IP SLA (responder)

Q3: 請問哪些是2960 LAN Base  LAN Lite相同功能?
A3: 相同點如下:
 Scalable and secure network management: Secure Shell (SSH), Secure Sockets Layer (SSL),  
  Secure Copy Protocol (SCP), and SNMPv3 crypto

 Network management tool support by CiscoWorks, Cisco Network Assistant, and Catalyst  
  Device Manager

 Baseline Network Admission Control and 802.1x MAC Auth Bypass and Protected Port

 Voice VLAN and voice-aware port security, BPDU Guard, and Root Guard

 Standard QoS with Class of Service (CoS) marking, Shaped Round Robin, Weighted Tail Drop,   
  and Strict Priority scheduling

 Link aggregation using Port Aggregation Protocol (PAgP) and 802.3ad LACP

 Complete Spanning Tree Protocol support via 802.1s, 802.1w, and PVST+

 VLAN Trunking Protocol (VTP), Cisco Discovery Protocol v2, and LLDP

 Multicast support in hardware with IGMP Snooping, Filtering, and Querier

 Troubleshooting and monitoring tools such as TDR, SPAN, and UDLD

2013年1月4日 星期五

Spanning Tree Link Type and lt's applications...

分成兩種Type: P2p and Shared

P2p link type指的是port為full duplex,通常在STP的過程中會比較快收斂;
而Shared指的是half duplex( 也可設定spanning-tree link-type shared   ),在STP過程中收斂較慢。

Loop Guard使用原則:

1. Loop Guard用在跟其他鄰近Switch連接的port (non-edge port)上

2.不要在Portfast port上同時使用Loop Guard,反之亦然 (跟第一點的描述相同,就是接edge
   device的port上不要啟用loop guard);而因為dynamic vlan port(通常就是edge port)上需要該
   port為portfast,所以也不建議在dynamic vlan port上設定loop guard。

3.不要在link type是shared的port上使用loop guard

4.不要在同一個port上同時使用loop guard和root guard

5.建議在access switch的root port和alternate root port(目前是blocked port)上設定loop guard

Root guard是強行指定某個port為root port。


RSTP (802.1w)的運行過程中不使用到任何timer做參數,而是使用link type和edge port

2013年1月1日 星期二

802.11N MIMO的spatial stream

802.11N MIMO的spatial stream指的是802.11N所使用的天線中所形成的傳輸空間,這些空間分成transmit、receive、transmit and receive,每一台AP所能夠使用的傳輸空間不同,大致上可分為以下幾種:

1x1:1 - 1 transmitter, 1 receiver, can transmit or receive 1 spatial stream

1x2:1 - 1 transmitter, 2 receivers, can transmit 1 spatial stream, but receive 2 spatial streams

2x2:2 - 2 transmitters, 2 receivers, can transmit and receive 2 spatial streams

2x3:2 - 2 transmitters, 3 receivers, can transmit and receive 2 spatial streams

3x3:2 - 3 transmitters, 3 receivers, can transmit and receive 2 spatial streams

3x3:3 - 3 transmitters, 3 receivers, can transmit and receive 3 spatial streams

4x4:4 - 4 transmitters, 4 receivers, can transmit and receive 4 spatial streams

不同的傳輸空間所能夠提供的傳輸速度大概有300 Mbps (2x2:2), 450 Mbps (3x3:3), and 600 Mbps (4x4:4).

使用Spanning Tree做Layer2 Load Sharing 的運用

使用Spanning Tree最常做的運用就是用來做不同VLAN在不同trunk link上的流量負載分流。
以本案為例,Switch0 Fa0/1<-->Switch1 Fa0/1間 與 Switch0 Fa0/2<-->Switch1 Fa0/2間都是VLAN trunk,我們建立兩個VLAN(VLAN1、VLAN2),原本的Spanning Tree結果,VLAN1和VLAN2的Blocking port會在Switch0的Fa0/2上,我們在Switch0上使用spanning-tree vlan 2 root primary讓vlan2的Root bridge為Switch0,也讓vlan2的blocking port在switch1的fa0/2上。

現在我們希望讓vlan 2的blocking port改成switch1的Fa0/1(當然,也可以讓vlan 2的blocking port也是在switch0上,但為了公平起見,我們希望switch1也有blocking port),在switch上可以調整的設定有兩種:

1.調整port priority
2.調整port cost

以上兩種設定的值一定是調整upstream的switch,在本案例中要改變switch1上的spanning tree port的狀態就要調整switch0(switch0為switch1的upstream、switch1為switch0的upstream)。

設定的方式就是打開原本的blocking port(打開Switch1的Fa0/2)或是block原本相比較的
port(關閉Switch1的Fa0/1)

A.調整port priority

    option1:調整switch0的Fa0/1,讓其port priority的值大於預設值128

    option2:調整switch1的Fa0/2,讓其port priority的值小於預設值128


    option1: Switch0(config)#interface fa 0/1
                 Switch0(config-if)#spanning-tree vlan 2 port-priority 240

   
    option2:Switch1(config)#interface fa 0/2
                Switch1(config-if)#spanning-tree vlan 2 port-priority 0



B.調整port cost

    option1:調整switch0的Fa0/1,讓其port cost的值大於預設值19

    option2:調整switch1的Fa0/2,讓其port cost的值小於預設值19


    option1: Switch0(config)#interface fa 0/1
                 Switch0(config-if)#spanning-tree vlan 2 cost 21

   
    option2:Switch1(config)#interface fa 0/2
                Switch1(config-if)#spanning-tree vlan 2 cost 18



 

2012年12月27日 星期四

OSPF LSA Type and Special Area

LSA Type 1 (Router LSA): Area內每個Router用來宣告自己的LSA,無法跨Area

LSA Type 2 (Network LSA): Area內每個Router用來宣告自己network的LSA,無法跨Area

LSA Type 3 (Summary Network LSA): ABR用來宣告不同Area所擁有的network的LSA,這個
                LSA通常是跨Area

LSA Type 4 (Summary ASBR LSA): 鄰近ASBR的router用來宣告ASBR位置的LSA

LSA Type 5 (External LSA): 用來傳遞從ASBR學到的network的LSA

LSA Type 7 (NSSA LSA): NSSA中表示從ASBR中學到的network的LSA


stub area會過濾Type 4 和Type 5,繼續過濾Type 3的area叫做totally stub area。
totally stub area如果允許ASBR(這個ASBR應該改稱NSSA ASBR)學到的路由進來,這個area叫做Not-So-Stub Area(NSSA),而這個LSA定義為Type 7 LSA,Type 7 LSA再由ABR(嚴格的說,應該稱NSSA ABR)轉換成Type 5 LSA傳到其他Area。





回到上述的totally stub area,看來這個area內的router都不收其他area來了路由,那這些router的流量怎麼出去?唯一的方式就是靠ABR注入一筆default router。

2012年12月26日 星期三

OSPF vs RIPv2 Redistribution心得


我們的目的是希望所有Router都收到除了其他Router Fa interface上的Routing,但Router0和Router1所有的網段是在同一個major net(172.16.0.0/16),所以每個Router收到的routing必須是
subnet過後的。


Router0:

configuration:


interface FastEthernet0/0
 ip address 172.16.1.254 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/1
 ip address 172.16.2.254 255.255.255.0
 duplex auto
 speed auto
!
interface Serial0/1/0
 ip address 10.1.1.1 255.255.255.252
 clock rate 19200
!
interface Serial0/1/1
 no ip address
 clock rate 2000000
 shutdown
!
interface Vlan1
 no ip address
 shutdown
!
router rip
 version 2
 network 10.0.0.0
 network 172.16.0.0
 no auto-summary
!
ip classless


RIP需要設定v2,否則其他Router收到的會是summary過後的routing(Classful only)

=======================================================================

Router1:

configuration:


interface FastEthernet0/0
 ip address 192.168.1.254 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/1
 ip address 192.168.2.254 255.255.255.0
 duplex auto
 speed auto
!
interface Ethernet0/0/0
 no ip address
 duplex auto
 speed auto
 shutdown
!
interface Serial0/1/0
 ip address 10.1.1.2 255.255.255.252
!
interface Serial0/1/1
 ip address 10.2.2.1 255.255.255.252
!
interface Vlan1
 no ip address
 shutdown
!
router ospf 1
 log-adjacency-changes
 redistribute rip subnets
 network 10.2.2.0 0.0.0.3 area 0
 network 192.168.2.0 0.0.0.255 area 0
!
router rip
 version 2
 redistribute ospf 1 metric 2
 network 10.0.0.0
 network 192.168.1.0
 no auto-summary
!
ip classless
!

1.Router0無法收到Router2的subnet routing,必須在RIP的redistribution設定中設定metric值,
   這個值範圍可為0~16,但必須設定1~15(我設定2),否則無法學習完整的路由(設定15,無 
   法學到192.168.2.0/24)。

2.RIPv2需要設定no auto-summary,否則Router0收到的不是172.16.3.0/24、172.16.4.0/24,而
  是summary過後的172.16.0.0/16。

  no auto-summary指的是設定的那一台Router送出去的的是沒有summary過後的Routing。

  所以如果Router1不下這個指令,  Router0收到的不是172.16.3.0/24、172.16.4.0/24,而
  是summary過後的172.16.0.0/16。

  同樣的,如果Router0不下這個指令,  Router1收到的不是172.16.1.0/24、172.16.2.0/24,而
  是summary過後的172.16.0.0/16。

3.RIPv2 redistribute到OSPF需要設定subnet,否則Router2收到的不是172.16.1.0/24、 
   172.16.2.0/24,而  是summary過後的172.16.0.0/16。

=======================================================================
Router2:

configuration:


interface FastEthernet0/0
 ip address 172.16.3.254 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/1
 ip address 172.16.4.254 255.255.255.0
 duplex auto
 speed auto
!
interface Serial0/1/0
 no ip address
 clock rate 2000000
!
interface Serial0/1/1
 ip address 10.2.2.2 255.255.255.252
 clock rate 19200
!
interface Vlan1
 no ip address
 shutdown
!
router ospf 1
 log-adjacency-changes
 network 10.2.2.0 0.0.0.3 area 0
 network 172.16.3.0 0.0.0.255 area 0
 network 172.16.4.0 0.0.0.255 area 0
!
ip classless

=======================================================================


Router0:

show ip route :



     10.0.0.0/30 is subnetted, 2 subnets
C       10.1.1.0 is directly connected, Serial0/1/0
R       10.2.2.0 [120/1] via 10.1.1.2, 00:00:06, Serial0/1/0
     172.16.0.0/24 is subnetted, 4 subnets
C       172.16.1.0 is directly connected, FastEthernet0/0
C       172.16.2.0 is directly connected, FastEthernet0/1
R       172.16.3.0 [120/2] via 10.1.1.2, 00:00:06, Serial0/1/0
R       172.16.4.0 [120/2] via 10.1.1.2, 00:00:06, Serial0/1/0
R    192.168.1.0/24 [120/1] via 10.1.1.2, 00:00:06, Serial0/1/0
R    192.168.2.0/24 [120/2] via 10.1.1.2, 00:00:06, Serial0/1/0




=======================================================================

Router1:

show ip route :

Router#sh ip route
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
       i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
       * - candidate default, U - per-user static route, o - ODR
       P - periodic downloaded static route

Gateway of last resort is not set

     10.0.0.0/30 is subnetted, 2 subnets
C       10.1.1.0 is directly connected, Serial0/1/0
C       10.2.2.0 is directly connected, Serial0/1/1
     172.16.0.0/24 is subnetted, 4 subnets
R       172.16.1.0 [120/1] via 10.1.1.1, 00:00:13, Serial0/1/0
R       172.16.2.0 [120/1] via 10.1.1.1, 00:00:13, Serial0/1/0
O       172.16.3.0 [110/65] via 10.2.2.2, 00:16:44, Serial0/1/1
O       172.16.4.0 [110/65] via 10.2.2.2, 00:16:44, Serial0/1/1
C    192.168.1.0/24 is directly connected, FastEthernet0/0
C    192.168.2.0/24 is directly connected, FastEthernet0/1

=======================================================================

Router2:

show ip route :


Router#sh ip route
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
       i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
       * - candidate default, U - per-user static route, o - ODR
       P - periodic downloaded static route

Gateway of last resort is not set

     10.0.0.0/30 is subnetted, 2 subnets
O E2    10.1.1.0 [110/20] via 10.2.2.1, 00:22:10, Serial0/1/1
C       10.2.2.0 is directly connected, Serial0/1/1
     172.16.0.0/24 is subnetted, 4 subnets
O E2    172.16.1.0 [110/20] via 10.2.2.1, 00:22:10, Serial0/1/1
O E2    172.16.2.0 [110/20] via 10.2.2.1, 00:22:10, Serial0/1/1
C       172.16.3.0 is directly connected, FastEthernet0/0
C       172.16.4.0 is directly connected, FastEthernet0/1
O E2 192.168.1.0/24 [110/20] via 10.2.2.1, 00:22:10, Serial0/1/1
O    192.168.2.0/24 [110/65] via 10.2.2.1, 00:22:10, Serial0/1/1

從任何其他Routing protocol redistribute到OSPF的default metric為20
而各Routing protocol的redistribution default metric如下:
SourceInto
RIPEIGRPOSPFISISBGP (MED)
Connected1Int metric20 (E2)00
Static1Int metric20 (E2)00
RIPInfinite20 (E2)0IGP metric
EIGRPInfinite20 (E2)0IGP metric
OSPFInfiniteInfinite0IGP metric
ISISInfiniteInfinite20 (E2)IGP metric
BGPInfiniteInfinite1 (E2)0




2012年12月23日 星期日

Spanning Tree的過程!



Spanning Tree的過程包含以下重要步驟:

1.選擇Root Bridge:
   Root Bridge的選擇是以各Bridge(Switch)的ID大小來做選擇,ID值越小,優先權越高。
   這個ID值包含Priority + VLAN ID,Priority預設值為32768,要調整這個值需要以4096為單
   位做增減。
 一般來說這一個ID值都會是一樣的,所以一開始,每一台Switch會以各自的
   System MAC address來做比較,這一個MAC address也可以從show version中的Base ethernet  MAC Address的知,MAC address的大小最好以二進位來做比較,值越小優先權越高。
 如上圖,由於每一台的ID值都是32768+1=32769 (1為VLAN ID),所以比較每一台Switch
   System MAC address結果:00E0>0030>000D>0004,優先權0004>000D>0030>00E0,
 也就是Switch1>Switch0>Switch2>Switch4,所以Switch1為Root Bridge。
 
 總的來說,這一個比較值的組合為4個bit的單位值(A)+12個bit的4096(B)+MAC address(C)
    ,預設值A=8,B永遠都是4096,C則因機器而異。



2.選擇Root Port(簡稱RP):
 Root Port為每一個Switch通往Root Bridge的最短路徑的那一個Port,每一個Switch必須選  
   出唯一一個Root Port,最端路徑的計算方式為每一個通往Root Bridge的Cost加總,每一種
 網路介面的速度有其預設上被定義好的cost,10G cost=1,1G cost=10,100M cost=19, 
 10M cost=100。在抉擇的過程中會遇到以下情況:
 a.同一個Switch通往Root Bridge的cost相同,這時候以相鄰的Bridge中ID值最小的為優先,
  如上圖,Switch4有四個Port(Fa0/5、Fa0/6、Fa0/7、Fa0/8)通往Root Bridge Switch1的cost
  都相同,因Fa0/7、Fa0/8通往Root Bridge的路徑中相鄰的Switch1其Bridge ID比Fa0/5、
       Fa0/6通往Root Bridge路徑中相鄰的Switch2其Bridge ID較低,所以會從Fa0/7、Fa0/8兩者
  選擇其中一個Port當作Root Port。

 b.同一台Switch通往Root Bridge的Root Port有兩個以上可以選擇,則選擇Port ID較低的
      當作Root Port,如a.的結果,因為Fa0/7的Port ID較Fa0/7的Port ID低,所以選擇Fa0/7
      作Root Port。依此類推,整體架構中的Root Port還有Switch0的Fa0/1、Switch2的Fa0/3
  而與其做比較的Port就是non-Designated Port,也就是blocked Port。所以Switch3的
      Fa0/8、Switch0的Fa0/2、Switch2的Fa0/4都是blocked port。

3.選擇Designated Port(簡稱DP):
    Designated Port是除了Root Port以外通往Root Bridge的最短路徑的Port,其選擇方式與
 Root Port相同,Root Bridge本身所有的Port都是Designated Port,而與Root Port相鄰的Port
    也一定是Designated Port。
  如果同一個Segment中無法依照上述原則決定DP時,則以Bridge ID較小的Switch上的Port
 為DP,而相對應的就是non-DP。如本架構,Switch2的F0/5、Fa0/6與Switch3的Fa0/5、
 Fa0/6做比較,因Switch2的Bridge ID較小,所以選擇Switch2的Fa0/5、Fa0/6當作DP(同一台
 Switch可以有好幾個DP,所以不需要做Port ID比較)。所以Switch3的Fa0/5、Fa0/6會是
    non-DP


其他:
如上圖,如果要更改Switch0的blocked port為Fa0/1,則需要更改對口的Port Priority,即
Switch1的Fa0/1的Port Priority大於預設值128。


  綜合來說,STP的運算過程需要依賴所有參與的交換器所提供的資訊來做運算的依據,
  這些資訊包含Bridge ID、通往Root Bridge的cost、Port Priority等。如果所有參與的交換器
  所提供的資訊不足以作判斷時,就自己做判斷,比如說以Port ID來做判斷。

 

2012年10月30日 星期二

RedHat 6.3上的yum

這幾天幫客戶裝了RedHat 6.3 Enterprise版本,安裝完成後客戶又要求安裝其他套件,
下載了rpm檔之後,安裝上出了問題,於是下載source檔(.tar.gz),又是因為相依性的問題無法安裝,於是只好改用yum,但問題來了,yum需要向原廠註冊一個帳號才能用,還好客戶是買正式版,也已經註冊了,所以採取以下幾個步驟做註冊:

rm -rf /etc/sysconfig/rhn_systemid
rm -rf /var/cache/yum/*
yum clean all
subscription-manager register     ==>這個步驟會要求輸入註冊的帳號與密碼
subscription-manager subscribe --auto   ==>這個步驟之後會再做一次確認的動作

最後就是做yum update和yum install xxx


大功告成~~~

2012年8月31日 星期五

Cisco Nexus 7000 support I/O modules (so far on Aug 2012)




 截至2012/8/31為止,Cisco Nexus 7000支援以下I/o module"
F1-Series 32-port 1- and 10-Gigabit Ethernet I/O modules (N7K-F132XP-15)

F2-Series 48-port 1-/10-Gigabit Ethernet I/O modules with XL (N7K-F248XP-25)


M1-Series 48-port 10/100/1000 I/O modules (N7K-M148GT-11)

M1-Series 48-port 10/100/1000 I/O modules with XL option (N7K-M148GT-11L)

M1-Series 48-port 1-Gigabit Ethernet I/O modules (N7K-M148GS-11)

M1-Series 48-port 1-Gigabit Ethernet I/O modules with XL option (N7K-M148GS-11L)

M1-Series 32-port 10-Gigabit Ethernet I/O modules (N7K-M132XP-12)

M1-Series 32-port 10-Gigabit Ethernet I/O modules with XL option (N7K-M132XP-12L)

M1-Series 8-port 10-Gigabit Ethernet I/O modules with XL option(N7K-M108X2-12L)


M2-Series 24-port 10-Gigabit Ethernet I/O modules with XL option (N7K-M224XP-23L)

M2-Series 6-port 40-Gigabit Ethernet I/O modules with XL option (N7K-M206XP-23L)

M2-Series 2-port 100-Gigabit Ethernet I/O modules with XL option (N7K-M202XP-23L)


而針對這些module,在設定VDC時需要注意port group,有些模組同一個port group必需配置到同一個VDC中。Port group的分配狀況如下:
•       N7K-M202CF-22L (1 interface x 2 port groups = 2 interfaces 100G modules)—There are no restrictions on the interface allocation between VDCs. 


N7K-M206FQ-23L (1 interface x 6 port groups = 6 interfaces 40G modules)—There are no restrictions on the interface allocation between VDCs. 


N7K-M224XP-23L (1 interface x 24 port groups = 24 interfaces 10G modules)—There are no restrictions on the interface allocation between VDCs. 


N7K-M108X2-12L (1 interface x 8 port groups = 8 interfaces)—There are no restrictions on the interface allocation between VDCs. 


N7K-M148GS-11L, N7K-M148GT-11, and N7K-M148GS-11 (12 interfaces x 4 port groups = 48 interfaces)—There are no restrictions on the interface allocation between VDCs, but we recommend that interfaces that belong to the same port group be in a single VDC. 


N7K-M132XP-12 (4 interfaces x 8 port groups = 32 interfaces)—Interfaces belonging to the same port group must belong to the same VDC.


N7K-M148GT-11L (same as non-L M148) (1 interface x 48 port groups = 48 interfaces)—There are no restrictions on the interface allocation between VDCs. 


N7K-M132XP-12L (same as non-L M132) (1 interface x 8 port groups = 8 interfaces)—All M132 cards require allocation in groups of 4 ports and you can configure 8 port groups.











M系列和F系列的module都可以安裝XL

And the Fabric supporting matrix is as follows:
Cisco Nexus 7009 chassis uses the Fabric 2 (N7K-C7009-FAB-2) modules.


Cisco Nexus 7010 chassis uses the Fabric 1 (N7K-C7010-FAB-1) or Fabric 2 (N7K-C7010-FAB-2) modules.


Cisco Nexus 7018 chassis uses the Fabric 1 (N7K-C7018-FAB-1) or Fabric 2 (N7K-C7018-FAB-2) modules.
      You can replace a Fabric 1 module with a Fabric 2 module in the Cisco Nexus 7010 and 7018 switches during operations, but while there is a mix of fabric module types, all of the fabric modules perform as Fabric 1 modules.
      Nexus7010及7018可以開機狀況下將FAB2換成FAB1,但必須是全換,如果是混插的狀況下,只有FAB1會發揮作用

       If you power up a switch with two types of fabric modules installed, only the Fabric 1 modules will power up. To utilize the Fabric 2 module capabilities, all of the installed fabric modules must be Fabric 2 modules.
      在FAB1及FAB2混插的情況下,只有FAB1會啟動,只有在全部都是FAB2時,FAB2才會全部啟動