Table Of Contents
Configuration Reference
Integrated Services Design Configurations
Core Switch 1
Aggregation Switch 1
Core Switch 2
Aggregation Switch 2
Access Switch 4948-7
Access Switch 4948-8
Access Switch 6500-1
FWSM 1-Aggregation Switch 1 and 2
Services Switch Design Configurations
Core Switch 1
Core Switch 2
Distribution Switch 1
Distribution Switch 2
Service Switch 1
Service Switch 2
Access Switch 6500
ACE and FWSM
FWSM Baseline
ACE Baseline
FWSM Failover
ACE Failover
Additional References
Configuration Reference
This chapter provides the test bed diagram and configurations used in tests to support this guide. The chapter is broken down into two main sections,Integrated Services Design Configurations and Services Switch Design Configurations.
Integrated Services Design Configurations
The following configurations were used in testing the integrated services design:
•
Core Switch 1
•
Aggregation Switch 1
•
Core Switch 2
•
Aggregation Switch 2
•
Access Switch 4948-7
•
Access Switch 4948-8
•
Access Switch 6500-1
•
FWSM 1-Aggregation Switch 1 and 2
Figure 8-1 shows the test bed used without services switches.
Figure 8-1 Integrated Services Configuration Test Bed
Core Switch 1
service timestamps debug datetime msec localtime
service timestamps log datetime msec localtime
no service password-encryption
service counters max age 10
boot system sup-bootflash:s720_18SXD3.bin
enable secret 5 $1$3OjN$l/80W4JIQJf7l7fRlS7A2.
clock summer-time PDT recurring
mls ip cef load-sharing full simple
spanning-tree mode rapid-pvst
spanning-tree loopguard default
no spanning-tree optimize bpdu transmission
spanning-tree extend system-id
spanning-tree pathcost method long
vlan internal allocation policy descending
vlan access-log ratelimit 2000
ip address 10.10.3.3 255.255.255.0
description to 4948-1 testgear
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
description to 4948-4 testgear
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
interface GigabitEthernet3/33
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 1 mode active
interface GigabitEthernet3/34
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 1 mode active
interface GigabitEthernet3/41
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 2 mode active
interface GigabitEthernet3/42
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 2 mode active
interface TenGigabitEthernet4/1
ip address 10.10.20.2 255.255.255.0
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
ip ospf network point-to-point
logging event link-status
interface TenGigabitEthernet4/2
ip address 10.10.30.2 255.255.255.0
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
ip ospf network point-to-point
logging event link-status
interface TenGigabitEthernet4/3
ip address 10.10.55.1 255.255.255.0
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
ip ospf network point-to-point
logging event link-status
interface GigabitEthernet6/1
interface GigabitEthernet6/2
description test_client_subnet
ip address 10.20.15.1 255.255.255.0
description test_client_ subnet2
ip address 10.20.16.2 255.255.255.0
auto-cost reference-bandwidth 1000000
area 10 authentication message-digest
area 10 nssa default-information-originate
timers throttle spf 1000 1000 1000
passive-interface default
no passive-interface TenGigabitEthernet4/1
no passive-interface TenGigabitEthernet4/2
no passive-interface TenGigabitEthernet4/3
network 10.10.3.0 0.0.0.255 area 10
network 10.10.20.0 0.0.0.255 area 10
network 10.10.30.0 0.0.0.255 area 10
network 10.10.55.0 0.0.0.255 area 10
network 10.20.15.0 0.0.0.255 area 0
network 10.20.16.0 0.0.0.255 area 0
ip pim send-rp-discovery scope 2
transport input telnet ssh
ntp authentication-key 1 md5 02050D480809 7
ntp clock-period 17180053
Aggregation Switch 1
Current configuration : 22460 bytes
! No configuration change since last restart
service timestamps debug datetime msec localtime
service timestamps log datetime msec localtime
no service password-encryption
service counters max age 10
boot system disk0:s720_18SXD3.bin
clock summer-time PDT recurring
firewall multiple-vlan-interfaces
firewall module 4 vlan-group 1
firewall vlan-group 1 5-6,20,100,101,105-106
analysis module 9 management-port access-vlan 20
analysis module 9 data-port 1 capture allowed-vlan 5,6,105,106
analysis module 9 data-port 2 capture allowed-vlan 106
ip icmp rate-limit unreachable 2000
mls ip cef load-sharing full
mls ip multicast flow-stat-timer 9
mls acl tcam default-result permit
no mls acl tcam share-global
mls cef error action freeze
spanning-tree mode rapid-pvst
no spanning-tree optimize bpdu transmission
spanning-tree extend system-id
spanning-tree pathcost method long
spanning-tree vlan 1-4094 priority 24576
module ContentSwitchingModule 3
ip address 10.20.44.42 255.255.255.0
alias 10.20.44.44 255.255.255.0
replicate csrp connection
replicate csrp connection
port-channel load-balance src-dst-port
vlan internal allocation policy descending
vlan access-log ratelimit 2000
name AGG1_to_AGG2_L3-OSPF
name CSM_Onearm_Server_VLAN
name Service_switch_CSM_Onearm
name AGG_FWSM_failover_interface
name AGG_FWSM_failover_state
ip address 10.10.1.1 255.255.255.0
description ETHERCHANNEL_TO_AGG2
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 1-19,21-4094
logging event link-status
description to SERVICE_SWITCH1
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
logging event link-status
description to SERVICE_SWITCH2
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
logging event link-status
interface GigabitEthernet1/13
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 10 mode active
interface GigabitEthernet1/14
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 10 mode active
interface GigabitEthernet1/19
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 1-5,7-105,107-300,1010-1110
channel-group 12 mode active
interface GigabitEthernet5/1
interface GigabitEthernet5/2
interface GigabitEthernet6/1
interface GigabitEthernet6/2
interface TenGigabitEthernet7/2
ip address 10.10.40.1 255.255.255.0
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 7 112A481634424A
ip ospf network point-to-point
logging event link-status
interface TenGigabitEthernet7/3
ip address 10.10.20.1 255.255.255.0
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 7 15315A1F277A6A
ip ospf network point-to-point
logging event link-status
interface TenGigabitEthernet7/4
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 105
logging event link-status
interface TenGigabitEthernet8/1
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 1-19,21-4094
logging event link-status
channel-group 1 mode active
interface TenGigabitEthernet8/2
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 106
logging event link-status
interface TenGigabitEthernet8/3
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 106
logging event link-status
interface TenGigabitEthernet8/4
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 1-19,21-4094
logging event link-status
channel-group 1 mode active
description AGG1_to_AGG2_L3-RP
ip address 10.10.110.1 255.255.255.0
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
ip ospf network point-to-point
logging event link-status
description Outside_Webapp_Tier
ip address 10.20.6.2 255.255.255.0
ip policy route-map csmpbr
standby 1 preempt delay minimum 60
description AGG_CSM_Onearm
ip address 10.20.44.2 255.255.255.0
standby 1 preempt delay minimum 60
auto-cost reference-bandwidth 1000000
area 10 authentication message-digest
timers throttle spf 1000 1000 1000
redistribute static subnets route-map rhi
passive-interface default
no passive-interface Vlan3
no passive-interface TenGigabitEthernet7/2
no passive-interface TenGigabitEthernet7/3
network 10.10.1.0 0.0.0.255 area 10
network 10.10.20.0 0.0.0.255 area 10
network 10.10.40.0 0.0.0.255 area 10
network 10.10.110.0 0.0.0.255 area 10
distribute-list 1 in TenGigabitEthernet7/2 (for PBR testing purposes)
distribute-list 1 in TenGigabitEthernet7/3 (for PBR testing purposes)
access-list 1 deny 10.20.16.0
access-list 1 deny 10.20.15.0
access-list 44 permit 10.20.6.200 log
access-list 44 permit 10.20.6.201 log
route-map csmpbr permit 10
set ip default next-hop 10.20.44.44
privilege exec level 1 show
password 7 110D1A16021F060510
password 7 110D1A16021F060510
transport input telnet ssh
no monitor session servicemodule
ntp authentication-key 1 md5 104D000A0618 7
ntp clock-period 17179928
ntp server *********.42 key 1
Core Switch 2
Current configuration : 10867 bytes
service timestamps debug datetime msec localtime
service timestamps log datetime msec localtime
no service password-encryption
service counters max age 10
boot system sup-bootflash:s720_18SXD3.bin
enable secret 5 $1$k2Df$vfhT/CMz0IqFqluRCENw//
clock summer-time PDT recurring
mls ip multicast flow-stat-timer 9
mls cef error action freeze
power redundancy-mode combined
spanning-tree mode rapid-pvst
spanning-tree loopguard default
no spanning-tree optimize bpdu transmission
spanning-tree extend system-id
spanning-tree pathcost method long
vlan internal allocation policy descending
vlan access-log ratelimit 2000
ip address 10.10.4.4 255.255.255.0
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
interface GigabitEthernet2/9
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 1 mode active
interface GigabitEthernet2/10
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 1 mode active
interface GigabitEthernet2/13
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 2 mode active
interface GigabitEthernet2/14
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 2 mode active
interface TenGigabitEthernet4/1
ip address 10.10.40.2 255.255.255.0
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
ip ospf network point-to-point
logging event link-status
interface TenGigabitEthernet4/2
ip address 10.10.50.2 255.255.255.0
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
ip ospf network point-to-point
logging event link-status
interface TenGigabitEthernet4/3
ip address 10.10.55.2 255.255.255.0
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
ip ospf network point-to-point
logging event link-status
interface GigabitEthernet6/1
interface GigabitEthernet6/2
ip address 10.20.15.2 255.255.255.0
description test_client_subnet
ip address 10.20.16.1 255.255.255.0
auto-cost reference-bandwidth 1000000
area 10 authentication message-digest
area 10 nssa default-information-originate
timers throttle spf 1000 1000 1000
passive-interface default
no passive-interface TenGigabitEthernet4/1
no passive-interface TenGigabitEthernet4/2
no passive-interface TenGigabitEthernet4/3
no passive-interface TenGigabitEthernet4/4
network 10.10.4.0 0.0.0.255 area 10
network 10.10.40.0 0.0.0.255 area 10
network 10.10.50.0 0.0.0.255 area 10
network 10.10.55.0 0.0.0.255 area 10
network 10.20.15.0 0.0.0.255 area 0
network 10.20.16.0 0.0.0.255 area 0
ip pim send-rp-discovery scope 2
transport input telnet ssh
ntp authentication-key 1 md5 104D000A0618 7
ntp clock-period 17179940
ntp server ********* key 1
Aggregation Switch 2
Current configuration : 18200 bytes
service timestamps debug datetime msec localtime
service timestamps log datetime msec
no service password-encryption
service counters max age 10
boot system disk0:s720_18SXD3.bin
clock summer-time PDT recurring
firewall multiple-vlan-interfaces
firewall module 4 vlan-group 1
firewall vlan-group 1 5,6,20,100,101,105,106
ip icmp rate-limit unreachable 2000
mls ip cef load-sharing full
mls ip multicast flow-stat-timer 9
mls acl tcam default-result permit
mls cef error action freeze
spanning-tree mode rapid-pvst
no spanning-tree optimize bpdu transmission
spanning-tree extend system-id
spanning-tree pathcost method long
spanning-tree vlan 1-4094 priority 28672
port-channel load-balance src-dst-port
module ContentSwitchingModule 3
ip address 10.20.44.43 255.255.255.0
alias 10.20.44.44 255.255.255.0
replicate csrp connection
replicate csrp connection
vlan internal allocation policy descending
vlan access-log ratelimit 2000
name Outside_Database_Tier
name Service_switch_CSM_Onearm
name AGG_FWSM_failover_interface
name AGG_FWSM_failover_state
name Inside_Database_Tier
ip address 10.10.2.2 255.255.255.0
description ETHERCHANNEL_TO_AGG1
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 1-19,21-299,301-4094
description to SERVICE_SWITCH1
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
description to SERVICE_SWITCH2
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
interface GigabitEthernet1/13
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 13 mode active
interface GigabitEthernet1/14
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 13 mode active
interface GigabitEthernet1/19
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 11 mode active
interface GigabitEthernet1/20
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 11 mode active
interface GigabitEthernet5/1
interface GigabitEthernet5/2
interface TenGigabitEthernet7/2
ip address 10.10.50.1 255.255.255.0
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
ip ospf network point-to-point
logging event link-status
interface TenGigabitEthernet7/3
ip address 10.10.30.1 255.255.255.0
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
ip ospf network point-to-point
logging event link-status
interface TenGigabitEthernet7/4
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 5,6
interface TenGigabitEthernet8/1
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 1-19,21-299,301-4094
channel-group 1 mode passive
interface TenGigabitEthernet8/3
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 106
interface TenGigabitEthernet8/4
logging event link-status
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 1-19,21-299,301-4094
channel-group 1 mode passive
description AGG1_to_AGG2_L3-RP
ip address 10.10.110.2 255.255.255.0
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
ip ospf network point-to-point
logging event link-status
description Outside_Webapp_Tier
standby 1 preempt delay minimum 60
ip address 10.20.6.3 255.255.255.0
ip policy route-map csmpbr
standby 1 preempt delay minimum 60
description AGG_CSM_Onearm
ip address 10.20.44.3 255.255.255.0
standby 1 preempt delay minimum 60
auto-cost reference-bandwidth 1000000
area 10 authentication message-digest
timers throttle spf 1000 1000 1000
redistribute static subnets route-map rhi
passive-interface default
no passive-interface Vlan3
no passive-interface TenGigabitEthernet7/2
no passive-interface TenGigabitEthernet7/3
network 10.10.2.0 0.0.0.255 area 10
network 10.10.30.0 0.0.0.255 area 10
network 10.10.50.0 0.0.0.255 area 10
network 10.10.110.0 0.0.0.255 area 10
distribute-list 1 in TenGigabitEthernet7/2
distribute-list 1 in TenGigabitEthernet7/3
access-list 1 deny 10.20.16.0
access-list 1 deny 10.20.15.0
access-list 44 permit 10.20.6.200 log
access-list 44 permit 10.20.6.201 log
route-map csmpbr permit 10
set ip default next-hop 10.20.44.44
transport input telnet ssh
transport output pad telnet ssh acercon
no monitor session servicemodule
ntp authentication-key 1 md5 08701C1A2D495547335B5A5572 7
ntp clock-period 17179998
ntp server ***********key 1
Access Switch 4948-7
Current configuration : 4612 bytes
service timestamps debug datetime localtime
service timestamps log datetime localtime
no service password-encryption
boot system bootflash:cat4000-i5k91s-mz.122-25.EWA2.bin
clock summer-time PDT recurring
spanning-tree mode rapid-pvst
spanning-tree loopguard default
spanning-tree portfast bpduguard default
spanning-tree extend system-id
spanning-tree pathcost method long
port-channel load-balance src-dst-port
power redundancy-mode redundant
vlan internal allocation policy descending
name Outside_Database_Tier
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
logging event link-status
interface GigabitEthernet1/1 (all ports)
switchport access vlan 106
interface GigabitEthernet1/45
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 1 mode active
interface GigabitEthernet1/46
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 1 mode active
interface GigabitEthernet1/47
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 1 mode active
interface GigabitEthernet1/48
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 1 mode active
interface TenGigabitEthernet1/49
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
interface TenGigabitEthernet1/50
ntp server *********** key 1
Access Switch 4948-8
Current configuration : 4646 bytes
service timestamps debug datetime localtime
service timestamps log datetime localtime
no service password-encryption
boot system bootflash:cat4000-i5k91s-mz.122-25.EWA2.bin
clock summer-time PDT recurring
spanning-tree mode rapid-pvst
spanning-tree loopguard default
spanning-tree portfast bpduguard default
spanning-tree extend system-id
spanning-tree pathcost method long
port-channel load-balance src-dst-port
power redundancy-mode redundant
vlan internal allocation policy descending
name Outside_Database_Tier
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
logging event link-status
interface GigabitEthernet1/1 (all ports)
switchport access vlan 106
switchport trunk encapsulation dot1q
interface GigabitEthernet1/45
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 1 mode passive
interface GigabitEthernet1/46
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 1 mode passive
interface GigabitEthernet1/47
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 1 mode passive
interface GigabitEthernet1/48
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
channel-group 1 mode passive
interface TenGigabitEthernet1/49
interface TenGigabitEthernet1/50
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
ntp server ********* key 1
Access Switch 6500-1
Building configuration...
Current configuration : 11074 bytes
! Last configuration change at 13:33:08 PST Thu Feb 9 2006
! NVRAM config last updated at 16:58:39 PST Thu Nov 17 2005
service timestamps debug datetime localtime
service timestamps log datetime localtime
service password-encryption
service counters max age 10
boot system sup-bootflash:s720_18SXD3.bin
clock summer-time PDT recurring
no mls acl tcam share-global
mls cef error action freeze
spanning-tree mode rapid-pvst
spanning-tree loopguard default
spanning-tree portfast bpduguard default
no spanning-tree optimize bpdu transmission
spanning-tree extend system-id
spanning-tree pathcost method long
power redundancy-mode combined
no diagnostic cns publish
no diagnostic cns subscribe
fabric buffer-reserve queue
port-channel load-balance src-dst-port
vlan internal allocation policy descending
vlan access-log ratelimit 2000
name Outside_Database_Tier
interface TenGigabitEthernet1/1
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
logging event link-status
interface TenGigabitEthernet1/2
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
logging event link-status
logging event spanning-tree status
interface GigabitEthernet2/1 (all test ports)
description webapp_penguin_kvm5
transport input telnet ssh
no monitor event-trace timestamps
ntp authentication-key 1 md5 110A1016141D 7
ntp clock-period 17179938
ntp server ***********key 1
FWSM 1-Aggregation Switch 1 and 2
FWSM Version 2.3(2) <system>
resource acl-partition 12
enable password 2KFQnbNIdI.2KYOU encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
logging console debugging
limit-resource Mac-addresses 65535
failover lan unit primary
failover lan interface failover vlan 100
failover polltime unit msec 500 holdtime 3
failover polltime interface 3
failover interface-policy 100%
failover replication http
failover link state vlan 101
failover interface ip failover 10.20.100.1 255.255.255.0 standby 10.20.100.2
failover interface ip state 10.20.101.1 255.255.255.0 standby 10.20.101.2
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 rpc 0:10:00 h323 0:05:00
h225 1:00:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
sysopt nodnsalias inbound
sysopt nodnsalias outbound
allocate-interface vlan20 outside
config-url disk:/admin.cfg
description vlan6-106 context
allocate-interface vlan6 outside
allocate-interface vlan106 inside
config-url disk:/vlan6-106.cfg
Cryptochecksum:a73fe039e4dbeb45a9c6730bc2a55201
FWSM1-AGG1and2# ch co vlan6-106
FWSM1-AGG1and2/vlan6-106# wr t
Building configuration...
FWSM Version 2.3(2) <context>
nameif outside vlan6 security0
nameif inside vlan106 security100
enable password 8Ry2YjIyt7RRXU24 encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
fixup protocol dns maximum-length 512
fixup protocol h323 H225 1720
fixup protocol h323 ras 1718-1719
no fixup protocol sip udp 5060
fixup protocol skinny 2000
fixup protocol sqlnet 1521
access-list deny-flow-max 4096
access-list alert-interval 300
access-list IP extended permit ip any any
access-list IP extended permit icmp any any
access-list BPDU ethertype permit bpdu
logging trap informational
logging device-id hostname
ip address 10.20.6.104 255.255.255.0 standby 10.20.6.105
access-group BPDU in interface vlan6
access-group IP in interface vlan6
access-group BPDU in interface vlan106
access-group IP in interface vlan106
route vlan6 0.0.0.0 0.0.0.0 10.20.6.1 1
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 rpc 0:10:00 h323 0:05:00
h225 1:00:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server TACACS+ max-failed-attempts 3
aaa-server TACACS+ deadtime 10
aaa-server RADIUS protocol radius
aaa-server RADIUS max-failed-attempts 3
aaa-server RADIUS deadtime 10
aaa-server LOCAL protocol local
snmp-server community public
snmp-server enable traps snmp
fragment size 200 vlan106
fragment chain 24 vlan106
ssh 0.0.0.0 0.0.0.0 vlan6
Cryptochecksum:00000000000000000000000000000000
FWSM1-AGG1and2/vlan6-106# ch co admin
FWSM1-AGG1and2/admin# wr t
Building configuration...
FWSM Version 2.3(2) <context>
nameif outside vlan20 security0
enable password 8Ry2YjIyt7RRXU24 encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
fixup protocol dns maximum-length 512
fixup protocol h323 H225 1720
fixup protocol h323 ras 1718-1719
fixup protocol sip udp 5060
fixup protocol skinny 2000
fixup protocol sqlnet 1521
access-list deny-flow-max 4096
access-list alert-interval 300
access-list IP extended permit ip any any
access-list IP extended permit icmp any any
access-list IP extended permit udp any any
access-list BPDU ethertype permit bpdu
logging trap informational
logging device-id hostname
ip address *********.34 255.255.255.0 standby *********.35
access-group IP in interface vlan20
route vlan20 0.0.0.0 0.0.0.0 *********.1 1
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 rpc 0:10:00 h323 0:05:00
h225 1:00:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
username mshinn password fgXai3fBCmTT1r2e encrypted privilege 15
aaa-server TACACS+ protocol tacacs+
aaa-server TACACS+ max-failed-attempts 3
aaa-server TACACS+ deadtime 10
aaa-server RADIUS protocol radius
aaa-server RADIUS max-failed-attempts 3
aaa-server RADIUS deadtime 10
aaa-server LOCAL protocol local
http 0.0.0.0 0.0.0.0 vlan20
snmp-server community public
snmp-server enable traps snmp
sysopt nodnsalias inbound
sysopt nodnsalias outbound
Services Switch Design Configurations
The following configurations were used in support of the service chassis testing:
•
Core Switch 1
•
Core Switch 2
•
Distribution Switch 1
•
Distribution Switch 2
•
Service Switch 1
•
Service Switch 2
•
Access Switch 6500
•
ACE and FWSM
Figure 8-2 shows the test bed used with services switches.
Figure 8-2 Service Switches Configuration Test Bed
Core Switch 1
boot system flash disk0:s72033-adventerprisek9_wan-vz.122-18.SXF9.bin
clock summer-time EDT recurring
ip domain-name ese.cisco.com
mls ip cef load-sharing full simple
mls ip multicast flow-stat-timer 9
no mls acl tcam share-global
mls cef error action freeze
spanning-tree mode rapid-pvst
spanning-tree loopguard default
no spanning-tree optimize bpdu transmission
spanning-tree extend system-id
spanning-tree pathcost method long
fabric buffer-reserve queue
port-channel per-module load-balance
vlan internal allocation policy descending
vlan access-log ratelimit 2000
ip address 10.151.1.10 255.255.255.255
interface TenGigabitEthernet1/2
description To DCb-Dist-1 - Ten 1/8
ip address 10.160.1.1 255.255.255.252
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
ip ospf network point-to-point
logging event link-status
interface TenGigabitEthernet1/3
description to DCB-Dist-2 Ten 1/8
ip address 10.160.1.5 255.255.255.252
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
ip ospf network point-to-point
logging event link-status
interface TenGigabitEthernet1/4
description TO DCB-Core-2 - Ten 1/4
ip address 10.199.0.5 255.255.255.252
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
ip ospf network point-to-point
logging event link-status
interface GigabitEthernet6/1
ip address 10.150.1.3 255.255.255.0
interface GigabitEthernet6/2
auto-cost reference-bandwidth 1000000
area 0 authentication message-digest
area 0 nssa default-information-originate
area 0 range 10.199.0.0 255.255.0.0
area 2 authentication message-digest
area 2 nssa default-information-originate
area 2 range 10.160.0.0 255.255.255.0
area 2 range 10.161.0.0 255.255.0.0
area 2 range 10.151.1.0 255.255.255.0
timers throttle spf 1000 1000 1000
passive-interface default
no passive-interface TenGigabitEthernet1/1
no passive-interface TenGigabitEthernet1/2
no passive-interface TenGigabitEthernet1/3
no passive-interface TenGigabitEthernet1/4
network 10.160.1.0 0.0.0.3 area 2
network 10.161.0.0 0.0.0.3 area 2
network 10.199.0.0 0.0.0.3 area 0
snmp-server community public RO
snmp-server community cisco RW
Core Switch 2
clock summer-time EDT recurring
boot system flash disk0:s72033-adventerprisek9_wan-vz.122-18.SXF9.bin
mls ip cef load-sharing full simple
mls ip multicast flow-stat-timer 9
no mls acl tcam share-global
mls cef error action freeze
spanning-tree mode rapid-pvst
spanning-tree loopguard default
no spanning-tree optimize bpdu transmission
spanning-tree extend system-id
spanning-tree pathcost method long
fabric buffer-reserve queue
port-channel per-module load-balance
vlan internal allocation policy descending
vlan access-log ratelimit 2000
ip address 10.151.1.11 255.255.255.255
interface TenGigabitEthernet1/2
description To DCb-Dist-1 - Ten 1/7
ip address 10.160.1.9 255.255.255.252
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
ip ospf network point-to-point
logging event link-status
interface TenGigabitEthernet1/3
description To DCb-Dist-2 - Ten 1/7
ip address 10.160.1.13 255.255.255.252
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
ip ospf network point-to-point
logging event link-status
interface TenGigabitEthernet1/4
description DCB-Core-1 - Ten 1/4
ip address 10.199.0.6 255.255.255.252
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
ip ospf network point-to-point
logging event link-status
interface GigabitEthernet6/1
ip address 10.150.1.4 255.255.255.0
interface GigabitEthernet6/2
auto-cost reference-bandwidth 1000000
area 0 authentication message-digest
area 0 nssa default-information-originate
area 0 range 10.199.0.0 255.255.0.0
area 2 authentication message-digest
area 2 nssa default-information-originate
area 2 range 10.160.0.0 255.255.0.0
area 2 range 10.161.0.0 255.255.0.0
area 2 range 10.151.1.0 255.255.255.0
timers throttle spf 1000 1000 1000
passive-interface default
no passive-interface TenGigabitEthernet1/1
no passive-interface TenGigabitEthernet1/2
no passive-interface TenGigabitEthernet1/4
no passive-interface TenGigabitEthernet1/3
network 10.160.1.0 0.0.0.3 area 2
network 10.161.0.0 0.0.0.3 area 2
network 10.199.0.0 0.0.0.3 area 0
snmp-server community public RO
snmp-server community cisco RW
Distribution Switch 1
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
service counters max age 5
boot system flash disk0:s72033-adventerprisek9_wan-vz.122-18.SXF10.bin
enable secret 5 $1$wVQ/$8nsaKkBneJbHVrph5VnS41
clock summer-time EDT recurring
ip icmp rate-limit unreachable 2000
mls acl tcam default-result permit
no mls acl tcam share-global
mls ip cef load-sharing full simple
mls ip multicast flow-stat-timer 9
mls cef error action freeze
fabric switching-mode force bus-mode
fabric buffer-reserve queue
port-channel per-module load-balance
port-channel load-balance src-dst-port
diagnostic cns publish cisco.cns.device.diag_results
diagnostic cns subscribe cisco.cns.device.diag_commands
power redundancy-mode combined
spanning-tree mode rapid-pvst
no spanning-tree optimize bpdu transmission
spanning-tree extend system-id
spanning-tree pathcost method long
spanning-tree vlan 1-4094 priority 24576
vlan internal allocation policy descending
vlan access-log ratelimit 2000
no crypto ipsec nat-transparency udp-encaps
ip address 10.151.1.12 255.255.255.255
interface TenGigabitEthernet1/1
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 2,3,106,107,206,207
logging event link-status
interface TenGigabitEthernet1/2
description dcb-dist2-6k Te1/2
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 2,3,7,106,107,206,207
logging event link-status
interface TenGigabitEthernet1/5
description dcb-svc1-6k Te9/1
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 2,3,7,106,107,206,207
logging event link-status
logging event bundle-status
interface TenGigabitEthernet1/6
description dcb-svc2-6k Te9/1
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 2,3,7,106,107,206,207
logging event link-status
logging event bundle-status
interface TenGigabitEthernet1/7
description dcb-core-2 Te1/2
ip address 10.160.1.10 255.255.255.252
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
logging event link-status
interface TenGigabitEthernet1/8
description dcb-core-1 Te1/2
ip address 10.160.1.2 255.255.255.252
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
logging event link-status
ip address 10.80.1.2 255.255.0.0
logging event link-status
standby 1 preempt delay minimum 120
auto-cost reference-bandwidth 1000000
area 2 authentication message-digest
area 2 nssa default-information-originate
area 2 range 10.151.1.0 255.255.255.0
area 2 range 10.151.0.0 255.255.0.0
area 2 range 10.160.0.0 255.255.255.0
area 2 range 10.161.0.0 255.255.0.0
timers throttle spf 1000 1000 1000
redistribute static subnets route-map rhi
passive-interface default
no passive-interface TenGigabitEthernet1/7
no passive-interface TenGigabitEthernet1/8
no passive-interface GigabitEthernet3/24
network 10.74.0.0 0.0.255.255 area 2
network 10.80.0.0 0.0.255.255 area 2
network 10.81.0.0 0.0.255.255 area 2
network 10.151.1.0 0.0.0.0 area 2
network 10.151.0.0 0.0.255.255 area 2
network 10.160.1.0 0.0.0.255 area 2
network 10.161.0.0 0.0.0.0 area 2
snmp-server community public RO
snmp-server community cisco RW
Distribution Switch 2
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
service counters max age 5
boot system flash disk0:s72033-adventerprisek9_wan-vz.122-18.SXF10.bin
enable secret 5 $1$VUjJ$onovPQGW3pDtcxU2GlqY5.
clock summer-time EDT recurring
ip icmp rate-limit unreachable 2000
mls acl tcam default-result permit
no mls acl tcam share-global
mls ip cef load-sharing full
mls ip multicast flow-stat-timer 9
mls cef error action freeze
fabric switching-mode force bus-mode
fabric buffer-reserve queue
port-channel per-module load-balance
port-channel load-balance src-dst-port
diagnostic cns publish cisco.cns.device.diag_results
diagnostic cns subscribe cisco.cns.device.diag_commands
power redundancy-mode combined
spanning-tree mode rapid-pvst
no spanning-tree optimize bpdu transmission
spanning-tree extend system-id
spanning-tree pathcost method long
spanning-tree vlan 1-4094 priority 28672
vlan internal allocation policy descending
vlan access-log ratelimit 2000
no crypto ipsec nat-transparency udp-encaps
ip address 10.151.1.13 255.255.255.255
interface TenGigabitEthernet1/1
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 2,3,106,107,206,207
logging event link-status
interface TenGigabitEthernet1/2
description dcb-dist1-6k Te1/2
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 2,3,7,106,107,206,207
logging event link-status
interface TenGigabitEthernet1/4
interface TenGigabitEthernet1/5
description dcb-svc1-6k Te9/1
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 2,3,7,106,107,206,207
logging event link-status
logging event bundle-status
interface TenGigabitEthernet1/6
description dcb-svc2-6k Te9/1
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 2,3,7,106,107,206,207
logging event link-status
logging event bundle-status
interface TenGigabitEthernet1/7
description dcb-core-2 Te1/2
ip address 10.160.1.14 255.255.255.252
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
logging event link-status
interface TenGigabitEthernet1/8
description dcb-core-1 Te1/2
ip address 10.160.1.6 255.255.255.252
ip ospf authentication message-digest
ip ospf message-digest-key 1 md5 C1sC0!
logging event link-status
ip address 10.80.1.3 255.255.0.0
logging event link-status
auto-cost reference-bandwidth 1000000
area 2 authentication message-digest
area 2 nssa default-information-originate
area 2 range 10.151.0.0 255.255.0.0
area 2 range 10.160.0.0 255.255.255.0
area 2 range 10.161.0.0 255.255.0.0
timers throttle spf 1000 1000 1000
redistribute static subnets route-map rhi
passive-interface default
no passive-interface TenGigabitEthernet1/7
no passive-interface TenGigabitEthernet1/8
no passive-interface GigabitEthernet3/24
network 10.80.0.0 0.0.255.255 area 2
network 10.81.0.0 0.0.255.255 area 2
network 10.151.0.0 0.0.255.255 area 2
network 10.160.1.0 0.0.0.0 area 2
network 10.160.1.0 0.0.0.255 area 2
network 10.161.0.0 0.0.0.0 area 2
network 10.161.0.0 0.0.255.255 area 2
snmp-server community public RO
snmp-server community cisco RW
Service Switch 1
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
service counters max age 5
boot system flash disk0:s72033-adventerprisek9_wan-vz.122-18.SXF10.bin
enable secret 5 $1$rPXa$F4EKAVs1cCaD.X5WG68iK0
ipv6 mfib hardware-switching replication-mode ingress
mls ip multicast flow-stat-timer 9
no mls acl tcam share-global
mls cef error action freeze
diagnostic cns publish cisco.cns.device.diag_results
diagnostic cns subscribe cisco.cns.device.diag_commands
fabric buffer-reserve queue
port-channel per-module load-balance
vlan internal allocation policy ascending
vlan access-log ratelimit 2000
svclc multiple-vlan-interfaces
svclc module 3 vlan-group 1,2
svclc vlan-group 1 6,206,207
svclc vlan-group 2 106,107
svclc vlan-group 3 3,4,5,7,
firewall multiple-vlan-interfaces
firewall module 2 vlan-group 2,3
ip address 10.151.1.17 255.255.255.255
interface TenGigabitEthernet9/1
description conx to dist1
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 2,3,7,106,107,206,207
logging event link-status
logging event bundle-status
interface TenGigabitEthernet9/2
description conx to dist2
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 2,3,7,106,107,206,207
logging event link-status
logging event bundle-status
interface TenGigabitEthernet9/3
description connx to svc2 switch
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 4,5,6
logging event link-status
logging event bundle-status
snmp-server community public RO
Service Switch 2
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
service counters max age 5
boot system flash disk0:s72033-adventerprisek9_wan-vz.122-18.SXF10.bin
enable secret 5 $1$lB0P$HAIQrXSPQjLQtTDklRg2V.
ipv6 mfib hardware-switching replication-mode ingress
mls ip multicast flow-stat-timer 9
no mls acl tcam share-global
mls cef error action freeze
diagnostic cns publish cisco.cns.device.diag_results
diagnostic cns subscribe cisco.cns.device.diag_commands
fabric buffer-reserve queue
port-channel per-module load-balance
vlan internal allocation policy ascending
vlan access-log ratelimit 2000
svclc multiple-vlan-interfaces
svclc module 3 vlan-group 1,2
svclc vlan-group 1 6,206,207
svclc vlan-group 2 106,107
svclc vlan-group 3 3,4,5,7
firewall multiple-vlan-interfaces
firewall module 2 vlan-group 2,3
ip address 10.151.1.18 255.255.255.255
interface TenGigabitEthernet9/1
description connection to 6500 dist1
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 2,3,7,106,107,206,207
logging event link-status
logging event bundle-status
interface TenGigabitEthernet9/2
description connection to 6500 dist 2
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 2,3,7,106,107,206,207
logging event link-status
logging event bundle-status
interface TenGigabitEthernet9/3
description connx to svc1 switch
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
switchport trunk allowed vlan 4,5,6
logging event link-status
logging event bundle-status
snmp-server community public RO
Access Switch 6500
service timestamps debug datetime localtime
service timestamps log datetime localtime
service password-encryption
service counters max age 10
boot system flash disk0:s72033-adventerprisek9_wan-vz.122-18.SXF9.bin
clock summer-time PDT recurring
no mls acl tcam share-global
mls cef error action freeze
spanning-tree mode rapid-pvst
spanning-tree loopguard default
spanning-tree portfast bpduguard default
no spanning-tree optimize bpdu transmission
spanning-tree extend system-id
spanning-tree pathcost method long
power redundancy-mode combined
no diagnostic cns publish
no diagnostic cns subscribe
fabric buffer-reserve queue
port-channel load-balance src-dst-port
vlan internal allocation policy descending
vlan access-log ratelimit 2000
interface TenGigabitEthernet1/1
description to_dcb-Dist-1
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
logging event link-status
interface TenGigabitEthernet1/2
description to_dcb-Dist-2
switchport trunk encapsulation dot1q
switchport trunk native vlan 2
logging event link-status
logging event spanning-tree status
interface GigabitEthernet2/1 (all test ports)
switchport access vlan 207
transport input telnet ssh
no monitor event-trace timestamps
ntp authentication-key 1 md5 110A1016141D 7
ntp clock-period 17179938
ntp server ***********key 1
ACE and FWSM
FWSM Baseline
ip address 10.80.1.12 255.255.255.0 standby 10.80.1.13
access-list outside extended permit ip any any log
access-list inside extended permit ip any any log
access-list BPDU ethertype permit bpdu
access-group BPDU in interface inside
access-group inside in interface inside
access-group BPDU in interface outside
access-group outside in interface outside
route outside 0.0.0.0 0.0.0.0 10.80.1.1
ACE Baseline
access-list BPDU ethertype permit bpdu
access-list anyone line 10 extended permit ip any any
class-map type management match-any PING
description Allowed Admin Traffic
10 match protocol icmp any
11 match protocol telnet any
policy-map type management first-match PING-POLICY
description "Client-side Interface"
access-group input anyone
service-policy input PING-POLICY
description "Server-side Interface"
access-group input anyone
ip address 10.80.1.14 255.255.255.0
alias 10.80.1.16 255.255.255.0
peer ip address 10.80.1.13 255.255.255.0
ip route 0.0.0.0 0.0.0.0 10.80.1.1
FWSM Failover
Table 8-1 FWSM Failover Configuration
Primary FWSM Failover Configuration
|
Secondary FWSM Failover Configuration
|
description LAN Failover Interface
description STATE Failover Interface
failover lan unit primary
failover lan interface failover VLAN4
failover polltime unit msec 500 holdtime 3
failover polltime interface 3
failover replication http
failover link state VLAN5
failover interface ip failover 10.81.4.1
255.255.255.0 standby 10.81.4.2
failover interface ip state 10.81.5.1 255.255.255.0
standby 10.81.5.2
allocate-interface VLAN107
config-url disk:/V107.cfg
|
description LAN Failover Interface
description STATE Failover Interface
failover lan unit secondary
failover lan interface failover VLAN4
failover polltime unit msec 500 holdtime 3
failover polltime interface 3
failover replication http
failover link state VLAN5
failover interface ip failover 10.81.4.1
255.255.255.0 standby 10.81.4.2
failover interface ip state 10.81.5.1 255.255.255.0
standby
allocate-interface VLAN107
config-url disk:/V107.cfg
|
ACE Failover
ip address 10.81.6.6.1 255.255.255.0
peer ip address 10.81.6.2 255.255.255.0
allocate-interface vlan107
allocate-interface vlan207
associate-context vlan107
Most of the configuration is done on the primary (primary on the admin context) ACE module. Only a few items need to be defined on the secondary ACE module: the FT interface is defined with the addresses reversed, the FT peer is configured the same, and the FT group for the admin context is configured with the priorities reversed. With the FT VLAN up, this is enough for the ACE modules to synch up correctly and all of the rest of the configuration is copied over and the priority values are reversed.
Additional References
See the following URL for more information:
•
Cisco Catalyst 6500—http://www.cisco.com/en/US/products/hw/switches/ps708/index.html