4
TRUNG TÂM TIN HC VNPRO 149/1D Ung Văn Khiêm, Phường 25, Qun Bình Thnh, Tp.HCM Tel: 08 35124257 Fax: 08 35124314 Website: www.vnpro.vn Forum: http://www.vnpro.org Livechat: www.vnpro,vn/support Email: [email protected] GV: Ngô Ngc Huy Spanning – Tree Protocol 1 Sơ đồ: Mô t: - Các Switch ASW1 và ASW2 là các Access – switch giao tiếp trc tiếp vi người dùng đầu cui. - Các Switch DSW1 và DSW2 là các Distribution Switch và Switch DSW2 đóng vai trò dphòng cho DSW1. - Router R sđịnh tuyến gia các VLAN trong hthng và đảm bo cho các user thuc các VLAN đều đi được Internet. Yêu cu: 1. Cu hình Trunking: Tt ccác đường ni gia các Switch và gia Switch DSW1 vi Router đều phi đường trunk dot1Q và được thiết lp tĩnh, tt DTP. 2. Cu hình VTP: Domain name: vnpro. Password: vnpro. DSW1, DSW2: Server; ASW1, ASW2: Client. Trên DSW1, to các VLAN: VLAN 10: CCNA. VLAN 20: Route. VLAN 30: Switch.

STP toolkitsdoc

Embed Size (px)

Citation preview

TRUNG TM TIN HC VNPRO 149/1D Ung Vn Khim, Phng 25, Qun Bnh Thnh, Tp.HCM Tel: 08 35124257 Fax: 08 35124314 Forum: http://www.vnpro.org Website: www.vnpro.vn Livechat: www.vnpro,vn/support Email: [email protected]

S :

M t: Cc Switch ASW1 v ASW2 l cc Access switch giao tip trc tip vi ngi dng u cui. Cc Switch DSW1 v DSW2 l cc Distribution Switch v Switch DSW2 ng vai tr d phng cho DSW1. Router R s nh tuyn gia cc VLAN trong h thng v m bo cho cc user thuc cc VLAN u i c Internet.

Yu cu: 1. Cu hnh Trunking: Tt c cc ng ni gia cc Switch v gia Switch DSW1 vi Router u phi l ng trunk dot1Q v c thit lp tnh, tt DTP.

2. Cu hnh VTP: Domain name: vnpro. Password: vnpro. DSW1, DSW2: Server; ASW1, ASW2: Client. Trn DSW1, to cc VLAN: VLAN 10: CCNA. VLAN 20: Route. VLAN 30: Switch.

GV: Ng Ngc Huy

1

Spanning Tree Protocol

TRUNG TM TIN HC VNPRO 149/1D Ung Vn Khim, Phng 25, Qun Bnh Thnh, Tp.HCM Tel: 08 35124257 Fax: 08 35124314 Forum: http://www.vnpro.org Website: www.vnpro.vn Livechat: www.vnpro,vn/support Email: [email protected]

Kim tra rng cu hnh VLAN ny lan truyn n c tt c cc Switch. Khng s dng VTP Prunning.

3. Cu hnh STP: Cu hnh m bo: DSW1 lm Root SW, DSW2 lm backup Root trn tt c cc VLAN. 4. Cu hnh Portfast mode interface: Cu hnh cc cng kt ni n Router v cc host ngi dng u cui b qua cc trng thi Listening, Learning, i thng vo trng thi Forwarding khi c active (up/up). Khng c s dng cu lnh STP trn mode global trong trng hp ny. Kim tra bng cch s dng cc cu lnh:SW#show spanning-tree interface tn_ cng portfast SW#debug spanning-tree events

5. Cu hnh Portfast mode global: G b cu hnh portfast thc hin bc 4. Cu hnh cc cng kt ni n host ngi dng u cui b qua cc trng thi Listening, Learning, i thng vo trng thi Forwarding khi c active (up/up). Khng c s dng cu lnh trn mode interface trong trng hp ny.

6. Cu hnh Uplinkfast: Cu hnh Uplinkfast trn cc Switch ASW1 v ASW2 nu Root port trn cc Switch ny b down, ngay lp tc chuyn cc cng kha sang trng thi forwarding m bo thng sut d liu. Tc cp nht dummy multicast c chnh thnh 200 packets/second. Kim tra cc gi tr priority v cc gi tr cost trn cc cng ca cc Switch mi c cu hnh tnh nng ny. Kim tra hot ng bng cch shutdown cng Root trn cc Switch ASW.

7. Cu hnh Backbonefast: Cu hnh Backbonefast trn cc Switch m bo rng khi link gia DSW1 v DSW2 down, cc Switch ASW1 v ASW2 b qua khong thi gian Max Age tin hnh ngay vic chuyn i trng thi cho cc cng d phng.

GV: Ng Ngc Huy

2

Spanning Tree Protocol

TRUNG TM TIN HC VNPRO 149/1D Ung Vn Khim, Phng 25, Qun Bnh Thnh, Tp.HCM Tel: 08 35124257 Fax: 08 35124314 Forum: http://www.vnpro.org Website: www.vnpro.vn Livechat: www.vnpro,vn/support Email: [email protected]

Kim tra hot ng ca tnh nng ny bng cch lm down kt ni gia DSW1 v DSW2 v thc hin lnh debug sau trn cc Switch ASW:SW#debug spanning-tree backbonefast

8. Cu hnh BPDUguard mode interface: Cu hnh BPDUguard trn cc cng thch hp nu cc cng ny nhn c BPDU s lp tc b chuyn vo trng thi err disabled. Nu cng khng cn nhn BPDU na, n s t khi phc li sau 02 pht. Khng c s dng cu lnh mode global thc hin yu cu ny. Kim tra bng cch s dng cc cu lnh:SW#show spanning-tree interface tn_cng detail SW#show interface tn_cng status

9. Cu hnh BPDUguard mode global: G b cu hnh BPDUguard thc hin bc 8. Cu hnh BPDUguard trn mode global nu cc cng thch hp (l cc cng nh th no?) nhn c BPDU s lp tc b chuyn vo trng thi err disabled. Khng c s dng cu lnh mode interface hon thnh yu cu ny. Thc hin kim tra.

10. Cu hnh BPDUfilter mode interface: G b cu hnh BPDUguard thc hin bc 9. Cu hnh BPDUfilter trn cc cng u ni vi cc host ngi dng u cui lc b BPDU trn cc cng ny. Khng c s dng cu lnh mode global hon thnh yu cu ny. Kim tra bng cch s dng cc cu lnh:SW#clear spanning-tree counter SW#show spanning-tree interface tn_cng detail

11. Cu hnh BPDUfilter mode global: G b cu hnh BPDUfilter thc hin bc 10. Cu hnh BPDUfilter mode global (trn cc Switch no?) khng gi BPDU ra cc cng u ni vi cc host ngi dng u cui. Khng c s dng cu lnh mode interface hon thnh yu cu ny.

GV: Ng Ngc Huy

3

Spanning Tree Protocol

TRUNG TM TIN HC VNPRO 149/1D Ung Vn Khim, Phng 25, Qun Bnh Thnh, Tp.HCM Tel: 08 35124257 Fax: 08 35124314 Forum: http://www.vnpro.org Website: www.vnpro.vn Livechat: www.vnpro,vn/support Email: [email protected]

Kim tra bng cch s dng cc cu lnh:SW#clear spanning-tree counter SW#show spanning-tree interface tn_cng detail

12. Cu hnh Rootguard: Cu hnh Rootguard trn DSW1 cc ng link dn n cc Switch cn li s b disable nu cc Switch DSW2, ASW1, ASW2 c bu lm Root Switch trn bt k VLAN no. Thc hin kim tra bng cch chnh mt trong 03 Switch DSW2, ASW1, ASW2 ln lm Root Switch ca bt k VLAN no. Quan st thng ip Syslog v thc hin cc lnh show:DSW1#show spanning-tree DSW1#show spanning-tree inconsistentports

Khi kim tra xong, nh tr li trng thi ca cc Switch tr li nh c. 13. Cu hnh Loopguard: Cu hnh Loopguard trn cc cng thch hp ca cc Switch ngn chn vic xy ra loop nu link b li truyn mt chiu (unidirectional link). Thc hin kim tra bng cch s dng lnh show:SW#show spanning-tree interface tn_cng detail

14. Hoch nh a ch IP: VLAN 10: subnet 10.1.10.0/24 VLAN 20: subnet 10.1.20.0/24. VLAN 30: subnet 10.1.30.0/24.

15. Cu hnh trn Router: Cu hnh Router R thc hin nh tuyn gia cc VLAN v cho php tt c cc VLAN u i c Internet (ng trunk gia Router v SW1 l dot1Q). Router R lm DHCP Server cp IP cho tt c cc VLAN.

GV: Ng Ngc Huy

4

Spanning Tree Protocol