Table Of Contents
Integrated Services Design Configurations
FWSM 1-Aggregation Switch 1 and 2
Services Switch Design Configurations
Configuration Reference
This chapter provides the test bed diagram and configurations used in tests to support this guide. The chapter is broken down into two main sections,Integrated Services Design Configurations and Services Switch Design Configurations.
Integrated Services Design Configurations
The following configurations were used in testing the integrated services design:
•FWSM 1-Aggregation Switch 1 and 2
Figure 8-1 shows the test bed used without services switches.
Figure 8-1 Integrated Services Configuration Test Bed
Core Switch 1
version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeno service password-encryptionservice counters max age 10!hostname CORE1!boot system sup-bootflash:s720_18SXD3.binlogging snmp-authfailenable secret 5 $1$3OjN$l/80W4JIQJf7l7fRlS7A2.!no aaa new-modelclock timezone PST -8clock summer-time PDT recurringvtp domain datacentervtp mode transparentudld enableip subnet-zerono ip source-route!!no ip ftp passiveno ip domain-lookupip domain-name cisco.com!no ip bootp serverip multicast-routingmls ip cef load-sharing full simple!spanning-tree mode rapid-pvstspanning-tree loopguard defaultno spanning-tree optimize bpdu transmissionspanning-tree extend system-idspanning-tree pathcost method long!vlan internal allocation policy descendingvlan dot1q tag nativevlan access-log ratelimit 2000!vlan 2!vlan 15name testgear!vlan 16name testgear2!vlan 20name DNS-CA!vlan 802name mgmt_vlan!!interface Loopback0ip address 10.10.3.3 255.255.255.0!interface Port-channel1description to 4948-1 testgearno ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunk!interface Port-channel2description to 4948-4 testgearno ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunk!interface GigabitEthernet3/33no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 1 mode active!interface GigabitEthernet3/34no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 1 mode active!interface GigabitEthernet3/41no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 2 mode active!interface GigabitEthernet3/42no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 2 mode active!interface TenGigabitEthernet4/1description to Agg1ip address 10.10.20.2 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-status!interface TenGigabitEthernet4/2description to Agg2ip address 10.10.30.2 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-status!interface TenGigabitEthernet4/3description to core2ip address 10.10.55.1 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-status!interface GigabitEthernet6/1no ip addressshutdown!interface GigabitEthernet6/2********************!interface Vlan1no ip addressshutdown!interface Vlan15description test_client_subnetip address 10.20.15.1 255.255.255.0no ip redirectsno ip proxy-arp!interface Vlan16description test_client_ subnet2ip address 10.20.16.2 255.255.255.0no ip redirectsno ip proxy-arp!router ospf 10log-adjacency-changesauto-cost reference-bandwidth 1000000nsfarea 10 authentication message-digestarea 10 nssa default-information-originatetimers throttle spf 1000 1000 1000passive-interface defaultno passive-interface TenGigabitEthernet4/1no passive-interface TenGigabitEthernet4/2no passive-interface TenGigabitEthernet4/3network 10.10.3.0 0.0.0.255 area 10network 10.10.20.0 0.0.0.255 area 10network 10.10.30.0 0.0.0.255 area 10network 10.10.55.0 0.0.0.255 area 10network 10.20.15.0 0.0.0.255 area 0network 10.20.16.0 0.0.0.255 area 0!ip classlessno ip http serverip pim send-rp-discovery scope 2!!control-plane!!line con 0exec-timeout 0 0line vty 0 4exec-timeout 60 0password 7 05080F1C2243login localtransport input telnet ssh!ntp authentication-key 1 md5 02050D480809 7ntp trusted-key 1ntp clock-period 17180053ntp master 1ntp update-calendarendAggregation Switch 1
Current configuration : 22460 bytes!! No configuration change since last restart!upgrade fpd autoversion 12.2service timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeno service password-encryptionservice counters max age 10!hostname Aggregation-1!boot system disk0:s720_18SXD3.binlogging snmp-authfailno aaa new-modelclock timezone PST -8clock summer-time PDT recurringclock calendar-validfirewall multiple-vlan-interfacesfirewall module 4 vlan-group 1firewall vlan-group 1 5-6,20,100,101,105-106analysis module 9 management-port access-vlan 20analysis module 9 data-port 1 capture allowed-vlan 5,6,105,106analysis module 9 data-port 2 capture allowed-vlan 106ip subnet-zerono ip source-routeip icmp rate-limit unreachable 2000!!!ip multicast-routingudld enableudld message time 7vtp domain datacentervtp mode transparentmls ip cef load-sharing fullmls ip multicast flow-stat-timer 9no mls flow ipno mls flow ipv6mls acl tcam default-result permitno mls acl tcam share-globalmls cef error action freeze!redundancymode ssomain-cpuauto-sync running-configauto-sync standard!spanning-tree mode rapid-pvstno spanning-tree optimize bpdu transmissionspanning-tree extend system-idspanning-tree pathcost method longspanning-tree vlan 1-4094 priority 24576module ContentSwitchingModule 3ft group 1 vlan 102priority 20heartbeat-time 1failover 3preempt!vlan 44 serverip address 10.20.44.42 255.255.255.0gateway 10.20.44.1alias 10.20.44.44 255.255.255.0!probe RHI icmpinterval 3failed 10!serverfarm SERVER200nat serverno nat clientreal 10.20.6.56inserviceprobe RHI!serverfarm SERVER201nat serverno nat clientreal 10.20.6.25inserviceprobe RHI!vserver SERVER200virtual 10.20.6.200 anyvlan 44serverfarm SERVER200advertise activesticky 10replicate csrp stickyreplicate csrp connectionpersistent rebalanceinservice!vserver SERVER201virtual 10.20.6.201 anyvlan 44serverfarm SERVER201advertise activesticky 10replicate csrp stickyreplicate csrp connectionpersistent rebalanceinservice!port-channel load-balance src-dst-port!vlan internal allocation policy descendingvlan dot1q tag nativevlan access-log ratelimit 2000!vlan 3name AGG1_to_AGG2_L3-OSPF!vlan 5!vlan 6Webapp Inside!vlan 7!vlan 10name Database Inside!vlan 20!vlan 44name CSM_Onearm_Server_VLAN!vlan 45name Service_switch_CSM_Onearm!vlan 46name SERV-CSM2-onearm!vlan 100name AGG_FWSM_failover_interface!vlan 101name AGG_FWSM_failover_state!vlan 102name AGG_CSM_FT_Vlan!vlan 106name WebappOutside!vlan 110name DatabaseOutside!interface Loopback0ip address 10.10.1.1 255.255.255.0!interface Null0no ip unreachables!interface Port-channel1description ETHERCHANNEL_TO_AGG2switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 1-19,21-4094switchport mode trunkno ip addresslogging event link-statusarp timeout 200spanning-tree guard loop!interface Port-channel10description to SERVICE_SWITCH1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkno ip addresslogging event link-statusspanning-tree guard loop!interface Port-channel12description to SERVICE_SWITCH2switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkno ip addresslogging event link-statusspanning-tree guard loop!!interface GigabitEthernet1/13description to Service_1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkno ip addresschannel-protocol lacpchannel-group 10 mode active!interface GigabitEthernet1/14description to Service_1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkno ip addresschannel-protocol lacpchannel-group 10 mode active!interface GigabitEthernet1/19switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 1-5,7-105,107-300,1010-1110switchport mode trunkno ip addresschannel-protocol lacpchannel-group 12 mode active!!interface GigabitEthernet5/1***************!interface GigabitEthernet5/2****************!interface GigabitEthernet6/1no ip addressshutdown!interface GigabitEthernet6/2no ip addressshutdownmedia-type rj45!interface TenGigabitEthernet7/2description to Core2ip address 10.10.40.1 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 7 112A481634424Aip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-status!interface TenGigabitEthernet7/3description to Core1ip address 10.10.20.1 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 7 15315A1F277A6Aip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-status!interface TenGigabitEthernet7/4description TO_ACCESS1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 105switchport mode trunkno ip addresslogging event link-status!interface TenGigabitEthernet8/1description TO_AGG2switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 1-19,21-4094switchport mode trunkno ip addresslogging event link-statuschannel-protocol lacpchannel-group 1 mode active!interface TenGigabitEthernet8/2description TO_4948-7switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 106switchport mode trunkno ip addresslogging event link-statusspanning-tree guard root!interface TenGigabitEthernet8/3description TO_4948-8switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 106switchport mode trunkno ip addresslogging event link-statusspanning-tree guard root!interface TenGigabitEthernet8/4description TO_AGG2switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 1-19,21-4094switchport mode trunkno ip addresslogging event link-statuschannel-protocol lacpchannel-group 1 mode active!interface Vlan1no ip addressshutdown!interface Vlan3description AGG1_to_AGG2_L3-RPbandwidth 10000000ip address 10.10.110.1 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-status!interface Vlan6description Outside_Webapp_Tierip address 10.20.6.2 255.255.255.0no ip redirectsno ip proxy-arpip policy route-map csmpbrntp disablestandby 1 ip 10.20.6.1standby 1 timers 1 3standby 1 priority 120standby 1 preempt delay minimum 60!!interface Vlan44description AGG_CSM_Onearmip address 10.20.44.2 255.255.255.0no ip redirectsno ip proxy-arpstandby 1 ip 10.20.44.1standby 1 timers 1 3standby 1 priority 120standby 1 preempt delay minimum 60!router ospf 10log-adjacency-changesauto-cost reference-bandwidth 1000000nsfarea 10 authentication message-digestarea 10 nssatimers throttle spf 1000 1000 1000redistribute static subnets route-map rhipassive-interface defaultno passive-interface Vlan3no passive-interface TenGigabitEthernet7/2no passive-interface TenGigabitEthernet7/3network 10.10.1.0 0.0.0.255 area 10network 10.10.20.0 0.0.0.255 area 10network 10.10.40.0 0.0.0.255 area 10network 10.10.110.0 0.0.0.255 area 10distribute-list 1 in TenGigabitEthernet7/2 (for PBR testing purposes)distribute-list 1 in TenGigabitEthernet7/3 (for PBR testing purposes)!ip classlessip pim accept-rp auto-rp!access-list 1 deny 10.20.16.0access-list 1 deny 10.20.15.0access-list 1 permit anyaccess-list 44 permit 10.20.6.200 logaccess-list 44 permit 10.20.6.201 log!route-map csmpbr permit 10set ip default next-hop 10.20.44.44!route-map rhi permit 10match ip address 44set metric-type type-1!privilege exec level 1 show!line con 0exec-timeout 0 0password 7 110D1A16021F060510login localline vty 0 4no motd-bannerexec-timeout 0 0password 7 110D1A16021F060510login localtransport input telnet ssh!!no monitor session servicemodulentp authentication-key 1 md5 104D000A0618 7ntp authenticatentp trusted-key 1ntp clock-period 17179928ntp update-calendarntp server *********.42 key 1endCore Switch 2
Current configuration : 10867 bytes!version 12.2no service padservice timestamps debug datetime msec localtimeservice timestamps log datetime msec localtimeno service password-encryptionservice counters max age 10!hostname CORE2!boot system sup-bootflash:s720_18SXD3.binenable secret 5 $1$k2Df$vfhT/CMz0IqFqluRCENw//!no aaa new-modelclock timezone PST -8clock summer-time PDT recurringvtp domain datacentervtp mode transparentudld enable!ip subnet-zerono ip source-route!!no ip domain-lookupip domain-name cisco.com!no ip bootp serverip multicast-routingmls ip multicast flow-stat-timer 9no mls flow ipno mls flow ipv6mls cef error action freeze!power redundancy-mode combined!spanning-tree mode rapid-pvstspanning-tree loopguard defaultno spanning-tree optimize bpdu transmissionspanning-tree extend system-idspanning-tree pathcost method long!vlan internal allocation policy descendingvlan dot1q tag nativevlan access-log ratelimit 2000!vlan 2,15-16!!interface Loopback0ip address 10.10.4.4 255.255.255.0!interface Port-channel1description to 4948-1no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunk!interface Port-channel2description to 4948-4no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunk!interface GigabitEthernet2/9no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 1 mode active!interface GigabitEthernet2/10no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 1 mode active!interface GigabitEthernet2/13no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 2 mode active!interface GigabitEthernet2/14no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 2 mode active!interface TenGigabitEthernet4/1description to Agg1ip address 10.10.40.2 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-status!interface TenGigabitEthernet4/2description to Agg2ip address 10.10.50.2 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-status!interface TenGigabitEthernet4/3description to core1ip address 10.10.55.2 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-status!interface GigabitEthernet6/1no ip addressshutdown!interface GigabitEthernet6/2*****************!interface Vlan1no ip addressshutdown!interface Vlan15ip address 10.20.15.2 255.255.255.0!interface Vlan16description test_client_subnetip address 10.20.16.1 255.255.255.0no ip redirectsno ip proxy-arp!router ospf 10log-adjacency-changesauto-cost reference-bandwidth 1000000nsfarea 10 authentication message-digestarea 10 nssa default-information-originatetimers throttle spf 1000 1000 1000passive-interface defaultno passive-interface TenGigabitEthernet4/1no passive-interface TenGigabitEthernet4/2no passive-interface TenGigabitEthernet4/3no passive-interface TenGigabitEthernet4/4network 10.10.4.0 0.0.0.255 area 10network 10.10.40.0 0.0.0.255 area 10network 10.10.50.0 0.0.0.255 area 10network 10.10.55.0 0.0.0.255 area 10network 10.20.15.0 0.0.0.255 area 0network 10.20.16.0 0.0.0.255 area 0!ip classlessno ip http serverip pim send-rp-discovery scope 2!!line con 0exec-timeout 0 0line vty 0 4exec-timeout 60 0password ciscologin localtransport input telnet ssh!ntp authentication-key 1 md5 104D000A0618 7ntp authenticatentp trusted-key 1ntp clock-period 17179940ntp update-calendarntp server ********* key 1endAggregation Switch 2
Current configuration : 18200 bytesversion 12.2service timestamps debug datetime msec localtimeservice timestamps log datetime msecno service password-encryptionservice counters max age 10!hostname Aggregation-2!boot system disk0:s720_18SXD3.binno aaa new-modelclock timezone PST -8clock summer-time PDT recurringclock calendar-validfirewall multiple-vlan-interfacesfirewall module 4 vlan-group 1firewall vlan-group 1 5,6,20,100,101,105,106vtp domain datacentervtp mode transparentudld enable!udld message time 7!ip subnet-zerono ip source-routeip icmp rate-limit unreachable 2000!!ip multicast-routingno ip igmp snoopingmls ip cef load-sharing fullmls ip multicast flow-stat-timer 9no mls flow ipno mls flow ipv6mls acl tcam default-result permitmls cef error action freeze!!spanning-tree mode rapid-pvstno spanning-tree optimize bpdu transmissionspanning-tree extend system-idspanning-tree pathcost method longspanning-tree vlan 1-4094 priority 28672port-channel load-balance src-dst-portmodule ContentSwitchingModule 3ft group 1 vlan 102priority 10heartbeat-time 1failover 3preempt!vlan 44 serverip address 10.20.44.43 255.255.255.0gateway 10.20.44.1alias 10.20.44.44 255.255.255.0!probe RHI icmpinterval 3failed 10!serverfarm SERVER200nat serverno nat clientreal 10.20.6.56inserviceprobe RHI!serverfarm SERVER201nat serverno nat clientreal 10.20.6.25inserviceprobe RHI!vserver SERVER200virtual 10.20.6.200 anyvlan 44serverfarm SERVER200advertise activesticky 10replicate csrp stickyreplicate csrp connectionpersistent rebalanceinservice!vserver SERVER201virtual 10.20.6.201 anyvlan 44serverfarm SERVER201advertise activesticky 10replicate csrp stickyreplicate csrp connectionpersistent rebalanceinservice!!vlan internal allocation policy descendingvlan dot1q tag nativevlan access-log ratelimit 2000!vlan 3name AGG1_to_AGG2_L3-RP!vlan 5name Outside_Webapp!vlan 6name Outside_Webapp!!vlan 10name Outside_Database_Tier!vlan 20!vlan 44name AGG_CSM_Onearm!vlan 45name Service_switch_CSM_Onearm!vlan 46name SERV-CSM2-onearm!vlan 100name AGG_FWSM_failover_interface!vlan 101name AGG_FWSM_failover_state!vlan 102name AGG_CSM_FT_Vlan!vlan 105name Inside_Webapp_Tier!vlan 106name Inside_Webapp!vlan 110name Inside_Database_Tier!!interface Loopback0ip address 10.10.2.2 255.255.255.0!interface Null0no ip unreachables!interface Port-channel1description ETHERCHANNEL_TO_AGG1no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 1-19,21-299,301-4094switchport mode trunkarp timeout 200spanning-tree guard loop!interface Port-channel11description to SERVICE_SWITCH1no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunk!interface Port-channel13description to SERVICE_SWITCH2no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunk!interface GigabitEthernet1/13description to Service_2no ip addressswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 13 mode active!interface GigabitEthernet1/14description to Service_2no ip addressswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 13 mode active!interface GigabitEthernet1/19description to Service_1no ip addressswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 11 mode active!interface GigabitEthernet1/20description to Service_1no ip addressswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 11 mode active!interface GigabitEthernet5/1!interface GigabitEthernet5/2************!interface TenGigabitEthernet7/2description to Core2ip address 10.10.50.1 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-status!interface TenGigabitEthernet7/3description to Core1ip address 10.10.30.1 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-status!interface TenGigabitEthernet7/4description TO_ACCESS1no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 5,6switchport mode trunkchannel-protocol lacp!interface TenGigabitEthernet8/1description TO_AGG1no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 1-19,21-299,301-4094switchport mode trunkchannel-protocol lacpchannel-group 1 mode passive!!interface TenGigabitEthernet8/3description TO_4948-8no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 106switchport mode trunkspanning-tree guard root!interface TenGigabitEthernet8/4description TO_AGG1no ip addresslogging event link-statusswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 1-19,21-299,301-4094switchport mode trunkchannel-protocol lacpchannel-group 1 mode passive!interface Vlan1no ip addressshutdown!interface Vlan3description AGG1_to_AGG2_L3-RPbandwidth 10000000ip address 10.10.110.2 255.255.255.0no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-status!interface Vlan5description Outside_Webapp_Tierno ip addressno ip redirectsntp disablestandby 1 ip 10.20.5.1standby 1 timers 1 3standby 1 priority 115standby 1 preempt delay minimum 60!interface Vlan6ip address 10.20.6.3 255.255.255.0no ip redirectsno ip proxy-arpip policy route-map csmpbrntp disablestandby 1 ip 10.20.6.1standby 1 timers 1 3standby 1 priority 115standby 1 preempt delay minimum 60!interface Vlan44description AGG_CSM_Onearmip address 10.20.44.3 255.255.255.0no ip redirectsno ip proxy-arpstandby 1 ip 10.20.44.1standby 1 timers 1 3standby 1 priority 115standby 1 preempt delay minimum 60!!router ospf 10log-adjacency-changesauto-cost reference-bandwidth 1000000nsfarea 10 authentication message-digestarea 10 nssatimers throttle spf 1000 1000 1000redistribute static subnets route-map rhipassive-interface defaultno passive-interface Vlan3no passive-interface TenGigabitEthernet7/2no passive-interface TenGigabitEthernet7/3network 10.10.2.0 0.0.0.255 area 10network 10.10.30.0 0.0.0.255 area 10network 10.10.50.0 0.0.0.255 area 10network 10.10.110.0 0.0.0.255 area 10distribute-list 1 in TenGigabitEthernet7/2distribute-list 1 in TenGigabitEthernet7/3!ip classlessip pim accept-rp auto-rp!access-list 1 deny 10.20.16.0access-list 1 deny 10.20.15.0access-list 1 permit anyaccess-list 44 permit 10.20.6.200 logaccess-list 44 permit 10.20.6.201 log!route-map csmpbr permit 10set ip default next-hop 10.20.44.44!route-map rhi permit 10match ip address 44set metric +40set metric-type type-1!line con 0exec-timeout 0 0password dcsummitlogin localline vty 0 4exec-timeout 0 0password dcsummitlogin localtransport input telnet sshtransport output pad telnet ssh acercon!no monitor session servicemodulentp authentication-key 1 md5 08701C1A2D495547335B5A5572 7ntp authenticatentp clock-period 17179998ntp update-calendarntp server ***********key 1endAccess Switch 4948-7
Current configuration : 4612 bytesversion 12.2no service padservice timestamps debug datetime localtimeservice timestamps log datetime localtimeno service password-encryptionservice compress-config!hostname 4948-7!boot-start-markerboot system bootflash:cat4000-i5k91s-mz.122-25.EWA2.binboot-end-marker!logging snmp-authfailno aaa new-modelclock timezone PST -8clock summer-time PDT recurringclock calendar-validvtp domain datacentervtp mode transparentudld enableip subnet-zerono ip source-routeno ip domain-lookupip domain-name cisco.com!!spanning-tree mode rapid-pvstspanning-tree loopguard defaultspanning-tree portfast bpduguard defaultspanning-tree extend system-idspanning-tree pathcost method longport-channel load-balance src-dst-portpower redundancy-mode redundant!!!vlan internal allocation policy descendingvlan dot1q tag native!vlan 5-6!vlan 105name Outside_Webapp!vlan 106name Outside Webapp!vlan 110name Outside_Database_Tier!interface Port-channel1description inter_4948switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunklogging event link-status!interface GigabitEthernet1/1 (all ports)switchport access vlan 106switchport mode accessno cdp enablespanning-tree portfast!interface GigabitEthernet1/45description to 4948-8switchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 1 mode active!interface GigabitEthernet1/46switchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 1 mode active!interface GigabitEthernet1/47switchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 1 mode active!interface GigabitEthernet1/48switchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 1 mode active!interface TenGigabitEthernet1/49description to_AGG1switchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunk!interface TenGigabitEthernet1/50shutdown!interface Vlan1no ip addressshutdown!!line con 0exec-timeout 0 0stopbits 1line vty 0 4exec-timeout 0 0password dcsummitlogin local!ntp authenticatentp trusted-key 1ntp update-calendarntp server *********** key 1!endAccess Switch 4948-8
Current configuration : 4646 bytes!version 12.2no service padservice timestamps debug datetime localtimeservice timestamps log datetime localtimeno service password-encryptionservice compress-config!hostname 4948-8!boot-start-markerboot system bootflash:cat4000-i5k91s-mz.122-25.EWA2.binboot-end-marker!no aaa new-modelclock timezone PST -8clock summer-time PDT recurringclock calendar-validvtp domain datacentervtp mode transparentudld enable!ip subnet-zerono ip source-routeno ip domain-lookupip domain-name cisco.com!no ip bootp server!no file verify auto!spanning-tree mode rapid-pvstspanning-tree loopguard defaultspanning-tree portfast bpduguard defaultspanning-tree extend system-idspanning-tree pathcost method longport-channel load-balance src-dst-portpower redundancy-mode redundant!!vlan internal allocation policy descendingvlan dot1q tag native!vlan 2,5-6!vlan 105name Outside_Webapp_Tier!vlan 106name Outside_Webapp_Tier!vlan 110name Outside_Database_Tier!interface Port-channel1description inter_4948switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunklogging event link-status!interface GigabitEthernet1/1 (all ports)switchport access vlan 106switchport trunk encapsulation dot1qswitchport mode accessno cdp enablespanning-tree portfast!interface GigabitEthernet1/45switchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 1 mode passive!interface GigabitEthernet1/46switchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 1 mode passive!interface GigabitEthernet1/47switchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 1 mode passive!interface GigabitEthernet1/48switchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkchannel-protocol lacpchannel-group 1 mode passive!interface TenGigabitEthernet1/49shutdown!interface TenGigabitEthernet1/50description to_AGG2switchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunk!interface Vlan1no ip addressshutdown!line con 0exec-timeout 0 0stopbits 1line vty 0 4exec-timeout 0 0password dcsummitlogin local!ntp authenticatentp trusted-key 1ntp update-calendarntp server ********* key 1!endAccess Switch 6500-1
ACCESS1-6500#Building configuration...Current configuration : 11074 bytes!! Last configuration change at 13:33:08 PST Thu Feb 9 2006! NVRAM config last updated at 16:58:39 PST Thu Nov 17 2005!upgrade fpd autoversion 12.2no service padservice timestamps debug datetime localtimeservice timestamps log datetime localtimeservice password-encryptionservice counters max age 10!hostname ACCESS1-6500!boot system sup-bootflash:s720_18SXD3.binno aaa new-modelclock timezone PST -8clock summer-time PDT recurringclock calendar-validip subnet-zerono ip source-route!!!no ip bootp serverip domain-list cisco.comno ip domain-lookupip domain-name cisco.comudld enable!udld message time 7!vtp domain datacentervtp mode transparentno mls acl tcam share-globalmls cef error action freeze!spanning-tree mode rapid-pvstspanning-tree loopguard defaultspanning-tree portfast bpduguard defaultno spanning-tree optimize bpdu transmissionspanning-tree extend system-idspanning-tree pathcost method long!power redundancy-mode combinedno diagnostic cns publishno diagnostic cns subscribefabric buffer-reserve queueport-channel load-balance src-dst-port!vlan internal allocation policy descendingvlan dot1q tag nativevlan access-log ratelimit 2000!vlan 5name Outside_Webapp_Tier!vlan 105name Outside_Webapp_Tier!vlan 110name Outside_Database_Tier!interface TenGigabitEthernet1/1description to_AGG1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkno ip addresslogging event link-status!interface TenGigabitEthernet1/2description to_AGG2switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkno ip addresslogging event link-statuslogging event spanning-tree status!!interface GigabitEthernet2/1 (all test ports)description webapp_penguin_kvm5switchportswitchport access vlan 5switchport mode accessno ip addressno cdp enablespanning-tree portfast!!interface Vlan1no ip addressshutdown!no ip http server!line con 0exec-timeout 0 0line vty 0 4exec-timeout 0 0password 7 05080F1C2243login localtransport input telnet ssh!no monitor event-trace timestampsntp authentication-key 1 md5 110A1016141D 7ntp authenticatentp trusted-key 1ntp clock-period 17179938ntp update-calendarntp server ***********key 1no cns aaa enableendFWSM 1-Aggregation Switch 1 and 2
FWSM Version 2.3(2) <system>firewall transparentresource acl-partition 12enable password 2KFQnbNIdI.2KYOU encryptedpasswd 2KFQnbNIdI.2KYOU encryptedhostname FWSM1-AGG1and2ftp mode passivepager lines 24logging buffer-size 4096logging console debuggingclass defaultlimit-resource PDM 5limit-resource All 0limit-resource IPSec 5limit-resource Mac-addresses 65535limit-resource SSH 5limit-resource Telnet 5!failoverfailover lan unit primaryfailover lan interface failover vlan 100failover polltime unit msec 500 holdtime 3failover polltime interface 3failover interface-policy 100%failover replication httpfailover link state vlan 101failover interface ip failover 10.20.100.1 255.255.255.0 standby 10.20.100.2failover interface ip state 10.20.101.1 255.255.255.0 standby 10.20.101.2arp timeout 14400!timeout xlate 3:00:00timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 rpc 0:10:00 h323 0:05:00h225 1:00:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00timeout uauth 0:05:00 absolutesysopt nodnsalias inboundsysopt nodnsalias outboundterminal width 511admin-context admincontext adminallocate-interface vlan20 outsideconfig-url disk:/admin.cfg!context vlan6-106description vlan6-106 contextallocate-interface vlan6 outsideallocate-interface vlan106 insideconfig-url disk:/vlan6-106.cfg!Cryptochecksum:a73fe039e4dbeb45a9c6730bc2a55201: end[OK]FWSM1-AGG1and2# ch co vlan6-106FWSM1-AGG1and2/vlan6-106# wr tBuilding configuration...: Saved:FWSM Version 2.3(2) <context>firewall transparentnameif outside vlan6 security0nameif inside vlan106 security100enable password 8Ry2YjIyt7RRXU24 encryptedpasswd 2KFQnbNIdI.2KYOU encryptedhostname vlan6-106fixup protocol dns maximum-length 512fixup protocol ftp 21fixup protocol h323 H225 1720fixup protocol h323 ras 1718-1719fixup protocol rsh 514fixup protocol sip 5060no fixup protocol sip udp 5060fixup protocol skinny 2000fixup protocol smtp 25fixup protocol sqlnet 1521namesaccess-list deny-flow-max 4096access-list alert-interval 300access-list IP extended permit ip any anyaccess-list IP extended permit icmp any anyaccess-list BPDU ethertype permit bpdupager lines 24logging onlogging timestamplogging buffer-size 4096logging trap informationallogging device-id hostnamemtu vlan6 1500mtu vlan106 1500ip address 10.20.6.104 255.255.255.0 standby 10.20.6.105icmp permit any vlan6icmp permit any vlan106no pdm history enablearp timeout 14400access-group BPDU in interface vlan6access-group IP in interface vlan6access-group BPDU in interface vlan106access-group IP in interface vlan106!interface vlan6!!interface vlan106!!route vlan6 0.0.0.0 0.0.0.0 10.20.6.1 1timeout xlate 3:00:00timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 rpc 0:10:00 h323 0:05:00h225 1:00:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00timeout uauth 0:05:00 absoluteaaa-server TACACS+ protocol tacacs+aaa-server TACACS+ max-failed-attempts 3aaa-server TACACS+ deadtime 10aaa-server RADIUS protocol radiusaaa-server RADIUS max-failed-attempts 3aaa-server RADIUS deadtime 10aaa-server LOCAL protocol localno snmp-server locationno snmp-server contactsnmp-server community publicsnmp-server enable traps snmpfloodguard enablefragment size 200 vlan6fragment chain 24 vlan6fragment size 200 vlan106fragment chain 24 vlan106telnet timeout 5ssh 0.0.0.0 0.0.0.0 vlan6ssh timeout 60terminal width 511Cryptochecksum:00000000000000000000000000000000: end[OK]FWSM1-AGG1and2/vlan6-106# ch co adminFWSM1-AGG1and2/admin# wr tBuilding configuration...: Saved:FWSM Version 2.3(2) <context>firewall transparentnameif outside vlan20 security0enable password 8Ry2YjIyt7RRXU24 encryptedpasswd 2KFQnbNIdI.2KYOU encryptedhostname admindomain-name example.comfixup protocol dns maximum-length 512fixup protocol ftp 21fixup protocol h323 H225 1720fixup protocol h323 ras 1718-1719fixup protocol rsh 514fixup protocol sip 5060fixup protocol sip udp 5060fixup protocol skinny 2000fixup protocol smtp 25fixup protocol sqlnet 1521namesaccess-list deny-flow-max 4096access-list alert-interval 300access-list IP extended permit ip any anyaccess-list IP extended permit icmp any anyaccess-list IP extended permit udp any anyaccess-list BPDU ethertype permit bpdupager lines 24logging onlogging timestamplogging buffer-size 4096logging trap informationallogging device-id hostnamemtu vlan20 1500ip address *********.34 255.255.255.0 standby *********.35icmp permit any vlan20no pdm history enablearp timeout 14400access-group IP in interface vlan20!interface vlan20!!route vlan20 0.0.0.0 0.0.0.0 *********.1 1timeout xlate 3:00:00timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 rpc 0:10:00 h323 0:05:00h225 1:00:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00timeout uauth 0:05:00 absoluteusername mshinn password fgXai3fBCmTT1r2e encrypted privilege 15aaa-server TACACS+ protocol tacacs+aaa-server TACACS+ max-failed-attempts 3aaa-server TACACS+ deadtime 10aaa-server RADIUS protocol radiusaaa-server RADIUS max-failed-attempts 3aaa-server RADIUS deadtime 10aaa-server LOCAL protocol localhttp server enablehttp 0.0.0.0 0.0.0.0 vlan20no snmp-server locationno snmp-server contactsnmp-server community publicsnmp-server enable traps snmpfloodguard enablefragment size 200 vlan20fragment chain 24 vlan20sysopt nodnsalias inboundsysopt nodnsalias outboundtelnet timeout 5ssh 0.0.0.Services Switch Design Configurations
The following configurations were used in support of the service chassis testing:
Figure 8-2 shows the test bed used with services switches.
Figure 8-2 Service Switches Configuration Test Bed
Core Switch 1
hostname dcb-core-1!boot system flash disk0:s72033-adventerprisek9_wan-vz.122-18.SXF9.bin!no aaa new-modelclock timezone EDT -5clock summer-time EDT recurringip subnet-zerono ip source-route!no ip bootp serverip multicast-routingno ip domain-lookupip domain-name ese.cisco.comudld enablevtp domain datacentervtp mode transparentmls ip cef load-sharing full simplemls ip multicast flow-stat-timer 9no mls flow ipno mls flow ipv6no mls acl tcam share-globalmls cef error action freeze!redundancymode ssomain-cpuauto-sync running-config!spanning-tree mode rapid-pvstspanning-tree loopguard defaultno spanning-tree optimize bpdu transmissionspanning-tree extend system-idspanning-tree pathcost method long!fabric buffer-reserve queueport-channel per-module load-balance!vlan internal allocation policy descendingvlan dot1q tag nativevlan access-log ratelimit 2000!interface Loopback0ip address 10.151.1.10 255.255.255.255!interface TenGigabitEthernet1/2description To DCb-Dist-1 - Ten 1/8ip address 10.160.1.1 255.255.255.252no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-status!interface TenGigabitEthernet1/3description to DCB-Dist-2 Ten 1/8ip address 10.160.1.5 255.255.255.252no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-status!interface TenGigabitEthernet1/4description TO DCB-Core-2 - Ten 1/4ip address 10.199.0.5 255.255.255.252no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-status!interface GigabitEthernet6/1description flashnetip address 10.150.1.3 255.255.255.0no mop enabledmedia-type rj45!interface GigabitEthernet6/2no ip addressshutdown!interface Vlan1no ip addressshutdown!router ospf 2log-adjacency-changesauto-cost reference-bandwidth 1000000nsfarea 0 authentication message-digestarea 0 nssa default-information-originatearea 0 range 10.199.0.0 255.255.0.0area 2 authentication message-digestarea 2 nssa default-information-originatearea 2 range 10.160.0.0 255.255.255.0area 2 range 10.161.0.0 255.255.0.0area 2 range 10.151.1.0 255.255.255.0timers throttle spf 1000 1000 1000passive-interface defaultno passive-interface TenGigabitEthernet1/1no passive-interface TenGigabitEthernet1/2no passive-interface TenGigabitEthernet1/3no passive-interface TenGigabitEthernet1/4network 10.160.1.0 0.0.0.3 area 2network 10.161.0.0 0.0.0.3 area 2network 10.199.0.0 0.0.0.3 area 0!ip classless!no ip http server!snmp-server community public ROsnmp-server community cisco RW!control-plane!dial-peer cor custom!line con 0line vty 0 4exec-timeout 0 0password ciscologinline vty 5 15exec-timeout 0 0password ciscologin!no cns aaa enableendCore Switch 2
hostname dcb-core-2!no aaa new-modelclock timezone EST -5clock summer-time EDT recurringip subnet-zerono ip source-route!boot system flash disk0:s72033-adventerprisek9_wan-vz.122-18.SXF9.bin!no ip ftp passiveno ip bootp serverip multicast-routingno ip domain-lookupip domain-name cisco.comudld enable!vtp domain datacentervtp mode transparentmls ip cef load-sharing full simplemls ip multicast flow-stat-timer 9no mls flow ipno mls flow ipv6no mls acl tcam share-globalmls cef error action freeze!redundancymode ssomain-cpuauto-sync running-config!spanning-tree mode rapid-pvstspanning-tree loopguard defaultno spanning-tree optimize bpdu transmissionspanning-tree extend system-idspanning-tree pathcost method long!fabric buffer-reserve queueport-channel per-module load-balance!vlan internal allocation policy descendingvlan dot1q tag nativevlan access-log ratelimit 2000!interface Loopback0ip address 10.151.1.11 255.255.255.255!interface TenGigabitEthernet1/2description To DCb-Dist-1 - Ten 1/7ip address 10.160.1.9 255.255.255.252no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-statusload-interval 30!interface TenGigabitEthernet1/3description To DCb-Dist-2 - Ten 1/7ip address 10.160.1.13 255.255.255.252no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-statusload-interval 30!interface TenGigabitEthernet1/4description DCB-Core-1 - Ten 1/4ip address 10.199.0.6 255.255.255.252no ip redirectsno ip proxy-arpip pim sparse-dense-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf network point-to-pointip ospf hello-interval 2ip ospf dead-interval 6logging event link-status!interface GigabitEthernet6/1description flashnetip address 10.150.1.4 255.255.255.0media-type rj45!interface GigabitEthernet6/2no ip addressshutdown!interface Vlan1no ip addressshutdown!router ospf 2log-adjacency-changesauto-cost reference-bandwidth 1000000nsfarea 0 authentication message-digestarea 0 nssa default-information-originatearea 0 range 10.199.0.0 255.255.0.0area 2 authentication message-digestarea 2 nssa default-information-originatearea 2 range 10.160.0.0 255.255.0.0area 2 range 10.161.0.0 255.255.0.0area 2 range 10.151.1.0 255.255.255.0timers throttle spf 1000 1000 1000passive-interface defaultno passive-interface TenGigabitEthernet1/1no passive-interface TenGigabitEthernet1/2no passive-interface TenGigabitEthernet1/4no passive-interface TenGigabitEthernet1/3network 10.160.1.0 0.0.0.3 area 2network 10.161.0.0 0.0.0.3 area 2network 10.199.0.0 0.0.0.3 area 0!ip classless!no ip http server!snmp-server community public ROsnmp-server community cisco RW!control-plane!dial-peer cor custom!line con 0line vty 0 4exec-timeout 0 0password ciscologinline vty 5 15exec-timeout 0 0password ciscologin!no cns aaa enableendDistribution Switch 1
upgrade fpd autoversion 12.2service timestamps debug uptimeservice timestamps log uptimeno service password-encryptionservice counters max age 5!hostname dcb-Dist-1!boot system flash disk0:s72033-adventerprisek9_wan-vz.122-18.SXF10.binenable secret 5 $1$wVQ/$8nsaKkBneJbHVrph5VnS41enable password cisco!no aaa new-modelclock timezone EDT -5clock summer-time EDT recurringvtp domain datacentervtp mode transparentip subnet-zerono ip source-routeip icmp rate-limit unreachable 2000!no ip domain-lookupip domain-name cisco.comip multicast-routingno ip igmp snooping!udld enableudld message time 7no mls flow ipmls acl tcam default-result permitno mls acl tcam share-globalmls ip cef load-sharing full simplemls ip multicast flow-stat-timer 9mls cef error action freeze!fabric switching-mode force bus-modefabric buffer-reserve queueport-channel per-module load-balanceport-channel load-balance src-dst-portdiagnostic cns publish cisco.cns.device.diag_resultsdiagnostic cns subscribe cisco.cns.device.diag_commands!redundancymode ssomain-cpuauto-sync running-config!power redundancy-mode combined!spanning-tree mode rapid-pvstno spanning-tree optimize bpdu transmissionspanning-tree extend system-idspanning-tree pathcost method longspanning-tree vlan 1-4094 priority 24576!vlan internal allocation policy descendingvlan dot1q tag nativevlan access-log ratelimit 2000!vlan 2-7,106,107,206,207!no crypto ipsec nat-transparency udp-encaps!interface Loopback0ip address 10.151.1.12 255.255.255.255!interface TenGigabitEthernet1/1description to_dcb-Acc-1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 2,3,106,107,206,207switchport mode trunkno ip addresslogging event link-statusspanning-tree guard loop!interface TenGigabitEthernet1/2description dcb-dist2-6k Te1/2switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 2,3,7,106,107,206,207switchport mode trunkno ip addresslogging event link-statusspanning-tree guard loop!interface TenGigabitEthernet1/5description dcb-svc1-6k Te9/1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 2,3,7,106,107,206,207switchport mode trunkno ip addresslogging event link-statuslogging event bundle-statusspanning-tree guard root!interface TenGigabitEthernet1/6description dcb-svc2-6k Te9/1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 2,3,7,106,107,206,207switchport mode trunkno ip addresslogging event link-statuslogging event bundle-statusspanning-tree guard root!interface TenGigabitEthernet1/7description dcb-core-2 Te1/2ip address 10.160.1.10 255.255.255.252no ip redirectsno ip proxy-arpip pim sparse-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf hello-interval 2ip ospf dead-interval 6logging event link-statusload-interval 30!interface TenGigabitEthernet1/8description dcb-core-1 Te1/2ip address 10.160.1.2 255.255.255.252no ip redirectsno ip proxy-arpip pim sparse-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf hello-interval 2ip ospf dead-interval 6logging event link-statusload-interval 30!interface Vlan7ip address 10.80.1.2 255.255.0.0no ip redirectsno ip proxy-arpip flow ingressip route-cache flowlogging event link-statusload-interval 30standby 1 ip 10.80.1.1standby 1 timers 1 3standby 1 priority 51standby 1 preempt delay minimum 120!router ospf 2log-adjacency-changesauto-cost reference-bandwidth 1000000nsfarea 2 authentication message-digestarea 2 nssa default-information-originatearea 2 range 10.151.1.0 255.255.255.0area 2 range 10.151.0.0 255.255.0.0area 2 range 10.160.0.0 255.255.255.0area 2 range 10.161.0.0 255.255.0.0timers throttle spf 1000 1000 1000redistribute static subnets route-map rhipassive-interface defaultno passive-interface TenGigabitEthernet1/7no passive-interface TenGigabitEthernet1/8no passive-interface GigabitEthernet3/24network 10.74.0.0 0.0.255.255 area 2network 10.80.0.0 0.0.255.255 area 2network 10.81.0.0 0.0.255.255 area 2network 10.151.1.0 0.0.0.0 area 2network 10.151.0.0 0.0.255.255 area 2network 10.160.1.0 0.0.0.255 area 2network 10.161.0.0 0.0.0.0 area 2!ip classless!no ip http server!snmp-server community public ROsnmp-server community cisco RW!control-plane!dial-peer cor custom!line con 0line vty 0 4password ciscologin!exception core-fileno cns aaa enableendDistribution Switch 2
upgrade fpd autoversion 12.2service timestamps debug uptimeservice timestamps log uptimeno service password-encryptionservice counters max age 5!hostname dcb-Dist-2!boot system flash disk0:s72033-adventerprisek9_wan-vz.122-18.SXF10.binenable secret 5 $1$VUjJ$onovPQGW3pDtcxU2GlqY5.enable password cisco!no aaa new-modelclock timezone EDT -5clock summer-time EDT recurringvtp domain datacentervtp mode transparentip subnet-zerono ip source-routeip icmp rate-limit unreachable 2000!no ip domain-lookupip domain-name cisco.comip multicast-routingno ip igmp snooping!udld enableudld message time 7no mls flow ipmls acl tcam default-result permitno mls acl tcam share-globalmls ip cef load-sharing fullmls ip multicast flow-stat-timer 9mls cef error action freeze!fabric switching-mode force bus-modefabric buffer-reserve queueport-channel per-module load-balanceport-channel load-balance src-dst-portdiagnostic cns publish cisco.cns.device.diag_resultsdiagnostic cns subscribe cisco.cns.device.diag_commands!redundancymode ssomain-cpuauto-sync running-config!power redundancy-mode combined!spanning-tree mode rapid-pvstno spanning-tree optimize bpdu transmissionspanning-tree extend system-idspanning-tree pathcost method longspanning-tree vlan 1-4094 priority 28672!vlan internal allocation policy descendingvlan dot1q tag nativevlan access-log ratelimit 2000!vlan 2-7,106,107,206,207!no crypto ipsec nat-transparency udp-encaps!interface Loopback0ip address 10.151.1.13 255.255.255.255!!interface TenGigabitEthernet1/1description to_dcb-Acc-1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 2,3,106,107,206,207switchport mode trunkno ip addresslogging event link-statusspanning-tree guard loop!interface TenGigabitEthernet1/2description dcb-dist1-6k Te1/2switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 2,3,7,106,107,206,207switchport mode trunkno ip addresslogging event link-statusspanning-tree guard loop!!interface TenGigabitEthernet1/4no ip address!interface TenGigabitEthernet1/5description dcb-svc1-6k Te9/1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 2,3,7,106,107,206,207switchport mode trunkno ip addresslogging event link-statuslogging event bundle-statusspanning-tree guard root!interface TenGigabitEthernet1/6description dcb-svc2-6k Te9/1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 2,3,7,106,107,206,207switchport mode trunkno ip addresslogging event link-statuslogging event bundle-statusspanning-tree guard root!interface TenGigabitEthernet1/7description dcb-core-2 Te1/2ip address 10.160.1.14 255.255.255.252no ip redirectsno ip proxy-arpip pim sparse-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf hello-interval 2ip ospf dead-interval 6logging event link-statusload-interval 30!interface TenGigabitEthernet1/8description dcb-core-1 Te1/2ip address 10.160.1.6 255.255.255.252no ip redirectsno ip proxy-arpip pim sparse-modeip ospf authentication message-digestip ospf message-digest-key 1 md5 C1sC0!ip ospf hello-interval 2ip ospf dead-interval 6logging event link-statusload-interval 30!!interface Vlan7ip address 10.80.1.3 255.255.0.0no ip redirectsno ip proxy-arpip flow ingresslogging event link-statusload-interval 30standby 1 ip 10.80.1.1standby 1 timers 1 3standby 1 priority 50standby 1 preempt!router ospf 2log-adjacency-changesauto-cost reference-bandwidth 1000000nsfarea 2 authentication message-digestarea 2 nssa default-information-originatearea 2 range 10.151.0.0 255.255.0.0area 2 range 10.160.0.0 255.255.255.0area 2 range 10.161.0.0 255.255.0.0timers throttle spf 1000 1000 1000redistribute static subnets route-map rhipassive-interface defaultno passive-interface TenGigabitEthernet1/7no passive-interface TenGigabitEthernet1/8no passive-interface GigabitEthernet3/24network 10.80.0.0 0.0.255.255 area 2network 10.81.0.0 0.0.255.255 area 2network 10.151.0.0 0.0.255.255 area 2network 10.160.1.0 0.0.0.0 area 2network 10.160.1.0 0.0.0.255 area 2network 10.161.0.0 0.0.0.0 area 2network 10.161.0.0 0.0.255.255 area 2!ip classless!no ip http server!snmp-server community public ROsnmp-server community cisco RW!control-plane!dial-peer cor custom!line con 0line vty 0 4password ciscologin!exception core-fileno cns aaa enableendService Switch 1
upgrade fpd autoversion 12.2service timestamps debug uptimeservice timestamps log uptimeno service password-encryptionservice counters max age 5!hostname Svc-1boot system flash disk0:s72033-adventerprisek9_wan-vz.122-18.SXF10.bin!enable secret 5 $1$rPXa$F4EKAVs1cCaD.X5WG68iK0enable password cisco!no aaa new-modelip subnet-zero!ipv6 mfib hardware-switching replication-mode ingressvtp domain datacentervtp mode transparentmls ip multicast flow-stat-timer 9no mls flow ipno mls flow ipv6no mls acl tcam share-globalmls cef error action freeze!redundancymode ssomain-cpuauto-sync running-configspanning-tree mode pvstdiagnostic cns publish cisco.cns.device.diag_resultsdiagnostic cns subscribe cisco.cns.device.diag_commandsfabric buffer-reserve queueport-channel per-module load-balance!vlan internal allocation policy ascendingvlan access-log ratelimit 2000!vlan 2-7,106,107,206,207!svclc autostatesvclc multiple-vlan-interfacessvclc module 3 vlan-group 1,2svclc vlan-group 1 6,206,207svclc vlan-group 2 106,107svclc vlan-group 3 3,4,5,7,firewall multiple-vlan-interfacesfirewall module 2 vlan-group 2,3!interface Loopback0ip address 10.151.1.17 255.255.255.255!!interface TenGigabitEthernet9/1description conx to dist1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 2,3,7,106,107,206,207switchport mode trunkno ip addresslogging event link-statuslogging event bundle-statusspanning-tree guard root!interface TenGigabitEthernet9/2description conx to dist2switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 2,3,7,106,107,206,207switchport mode trunkno ip addresslogging event link-statuslogging event bundle-statusspanning-tree guard root!interface TenGigabitEthernet9/3description connx to svc2 switchswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 4,5,6switchport mode trunkno ip addresslogging event link-statuslogging event bundle-status!no ip http server!snmp-server community public RO!control-plane!dial-peer cor custom!line con 0line vty 0 4password ciscologin!no cns aaa enableendService Switch 2
upgrade fpd autoversion 12.2service timestamps debug uptimeservice timestamps log uptimeno service password-encryptionservice counters max age 5!hostname Svc-2boot system flash disk0:s72033-adventerprisek9_wan-vz.122-18.SXF10.bin!enable secret 5 $1$lB0P$HAIQrXSPQjLQtTDklRg2V.enable password cisco!no aaa new-modelip subnet-zero!ipv6 mfib hardware-switching replication-mode ingressvtp domain datacentervtp mode transparentmls ip multicast flow-stat-timer 9no mls flow ipno mls flow ipv6no mls acl tcam share-globalmls cef error action freeze!redundancymode ssomain-cpuauto-sync running-configspanning-tree mode pvstdiagnostic cns publish cisco.cns.device.diag_resultsdiagnostic cns subscribe cisco.cns.device.diag_commandsfabric buffer-reserve queueport-channel per-module load-balance!vlan internal allocation policy ascendingvlan access-log ratelimit 2000!vlan 2-7,106,107,206,207!svclc autostatesvclc multiple-vlan-interfacessvclc module 3 vlan-group 1,2svclc vlan-group 1 6,206,207svclc vlan-group 2 106,107svclc vlan-group 3 3,4,5,7firewall multiple-vlan-interfacesfirewall module 2 vlan-group 2,3!interface Loopback0ip address 10.151.1.18 255.255.255.255!!interface TenGigabitEthernet9/1description connection to 6500 dist1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 2,3,7,106,107,206,207switchport mode trunkno ip addresslogging event link-statuslogging event bundle-statusspanning-tree guard root!interface TenGigabitEthernet9/2description connection to 6500 dist 2switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 2,3,7,106,107,206,207switchport mode trunkno ip addresslogging event link-statuslogging event bundle-statusspanning-tree guard root!interface TenGigabitEthernet9/3description connx to svc1 switchswitchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport trunk allowed vlan 4,5,6switchport mode trunkno ip addresslogging event link-statuslogging event bundle-status!no ip http server!snmp-server community public RO!control-plane!dial-peer cor custom!line con 0line vty 0 4password ciscologin!!no cns aaa enableendAccess Switch 6500
upgrade fpd autoversion 12.2no service padservice timestamps debug datetime localtimeservice timestamps log datetime localtimeservice password-encryptionservice counters max age 10!hostname DCB-Access-1!boot system flash disk0:s72033-adventerprisek9_wan-vz.122-18.SXF9.binno aaa new-modelclock timezone PST -8clock summer-time PDT recurringclock calendar-validip subnet-zerono ip source-route!no ip bootp serverip domain-list cisco.comno ip domain-lookupip domain-name cisco.comudld enable!udld message time 7!vtp domain datacentervtp mode transparentno mls acl tcam share-globalmls cef error action freeze!spanning-tree mode rapid-pvstspanning-tree loopguard defaultspanning-tree portfast bpduguard defaultno spanning-tree optimize bpdu transmissionspanning-tree extend system-idspanning-tree pathcost method long!power redundancy-mode combinedno diagnostic cns publishno diagnostic cns subscribefabric buffer-reserve queueport-channel load-balance src-dst-port!vlan internal allocation policy descendingvlan dot1q tag nativevlan access-log ratelimit 2000!vlan 207name server Tier!interface TenGigabitEthernet1/1description to_dcb-Dist-1switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkno ip addresslogging event link-status!interface TenGigabitEthernet1/2description to_dcb-Dist-2switchportswitchport trunk encapsulation dot1qswitchport trunk native vlan 2switchport mode trunkno ip addresslogging event link-statuslogging event spanning-tree status!!interface GigabitEthernet2/1 (all test ports)switchportswitchport access vlan 207switchport mode accessno ip addressno cdp enablespanning-tree portfast!!interface Vlan1no ip addressshutdown!no ip http server!line con 0exec-timeout 0 0line vty 0 4exec-timeout 0 0password 7 05080F1C2243login localtransport input telnet ssh!no monitor event-trace timestampsntp authentication-key 1 md5 110A1016141D 7ntp authenticatentp trusted-key 1ntp clock-period 17179938ntp update-calendarntp server ***********key 1no cns aaa enableendACE and FWSM
FWSM Baseline
firewall transparent!interface Vlan107nameif insidebridge-group 1security-level 100!interface Vlan7nameif outsidebridge-group 1security-level 0!interface BVI1ip address 10.80.1.12 255.255.255.0 standby 10.80.1.13!access-list outside extended permit ip any any logaccess-list inside extended permit ip any any logaccess-list BPDU ethertype permit bpdu!access-group BPDU in interface insideaccess-group inside in interface insideaccess-group BPDU in interface outsideaccess-group outside in interface outsideroute outside 0.0.0.0 0.0.0.0 10.80.1.1ACE Baseline
access-list BPDU ethertype permit bpduaccess-list anyone line 10 extended permit ip any anyclass-map type management match-any PINGdescription Allowed Admin Traffic10 match protocol icmp any11 match protocol telnet anypolicy-map type management first-match PING-POLICYclass PINGpermitinterface vlan 107description "Client-side Interface"bridge-group 1access-group input BPDUaccess-group input anyoneservice-policy input PING-POLICYinterface vlan 207description "Server-side Interface"bridge-group 1access-group input BPDUaccess-group input anyoneinterface bvi 1ip address 10.80.1.14 255.255.255.0alias 10.80.1.16 255.255.255.0peer ip address 10.80.1.13 255.255.255.0no shutdownip route 0.0.0.0 0.0.0.0 10.80.1.1FWSM Failover
ACE Failover
ft interface vlan 6ip address 10.81.6.6.1 255.255.255.0peer ip address 10.81.6.2 255.255.255.0no shutdownft peer 1heartbeat interval 100heartbeat count 10ft-interface vlan 6ft group 2peer 1no preemptpriority 210peer priority 200associate-context Admininservicecontext v107allocate-interface vlan107allocate-interface vlan207ft group 3peer 1priority 220peer priority 200associate-context vlan107inserviceMost of the configuration is done on the primary (primary on the admin context) ACE module. Only a few items need to be defined on the secondary ACE module: the FT interface is defined with the addresses reversed, the FT peer is configured the same, and the FT group for the admin context is configured with the priorities reversed. With the FT VLAN up, this is enough for the ACE modules to synch up correctly and all of the rest of the configuration is copied over and the priority values are reversed.
Additional References
See the following URL for more information:
•Cisco Catalyst 6500—http://www.cisco.com/en/US/products/hw/switches/ps708/index.html