<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Catalyst on Aaron&#39;s Worthless Words</title>
    <link>https://a996c8ee.aww-3cz.pages.dev/tags/catalyst/</link>
    <description>Recent content in Catalyst on Aaron&#39;s Worthless Words</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Thu, 04 Jul 2013 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://a996c8ee.aww-3cz.pages.dev/tags/catalyst/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Cisco Live 2013 Insights - Catalyst 3850</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2013/07/cisco-live-2013-insights-catalyst-3850/</link>
      <pubDate>Thu, 04 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2013/07/cisco-live-2013-insights-catalyst-3850/</guid>
      <description>&lt;p&gt;Cisco Live is obviously the biggest networking event of the year, and Cisco likes to use all the attention to show off some of their new gear.  I must say I was impressed with some of the Enterprise offerings including the &lt;a href=&#34;http://www.cisco.com/en/US/products/ps13195/index.html&#34;&gt;6807-XL&lt;/a&gt;, the &lt;a href=&#34;http://www.cisco.com/en/US/products/ps13194/index.html&#34;&gt;6880-X&lt;/a&gt;, the &lt;a href=&#34;http://www.cisco.com/en/US/products/ps12522/index.html&#34;&gt;4451-X&lt;/a&gt;, and the &lt;a href=&#34;http://www.cisco.com/en/US/products/ps13204/index.html&#34;&gt;Sup 8-E for the 4500-E&lt;/a&gt; (check out the &lt;a href=&#34;http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9402/data_sheet_c78-728187.html&#34;&gt;Nexus 7700&lt;/a&gt;, too, even though they aren&amp;rsquo;t Enterprise class).  Those boxes definitely gave me a bit of a tingle when I was checking them out, but my eyes opened up when I saw the 3850 in one of my sessions and on the show floor.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Configuring Dedicated Trunks for the CSM</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2008/11/configuring-dedicated-trunks-for-the-csm/</link>
      <pubDate>Mon, 24 Nov 2008 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2008/11/configuring-dedicated-trunks-for-the-csm/</guid>
      <description>&lt;p&gt;Did you catch the article on &lt;a href=&#34;http://aconaway.com/2008/10/10/configuring-fault-tolerance-on-the-csm/&#34; title=&#34;AConaway.com -- Configuring Fault Tolerance on the CSM&#34;&gt;setting up fault tolerance on the CSM&lt;/a&gt;?  In that article, I mentioned that Cisco recommends a dedicated trunk for the FT VLAN if you have two HA CSMs in two chassis.  Discuss amongst yourselves while I drone on.&lt;/p&gt;&#xA;&lt;p&gt;Why should you set up a dedicated trunk for this stuff?  The most obvious reason is to be sure that normal traffic doesn&amp;rsquo;t step on the syncing traffic.  Since we&amp;rsquo;re syncing state information as well as configuration, the frames need to arrive in a timely manner.  Any errors could potentially disrupt the FT process, which is bad.  You surely don&amp;rsquo;t want the primary to fail only to find out that the standby doesn&amp;rsquo;t have the complete or current config.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Using Probes on the CSM</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2008/11/using-probes-on-the-csm/</link>
      <pubDate>Thu, 06 Nov 2008 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2008/11/using-probes-on-the-csm/</guid>
      <description>&lt;p&gt;There are three different ways that a CSM checks for the health of the servers &amp;ndash; active probes, inband health checking, and inband HTTP monitoring.  Let&amp;rsquo;s talk about active probes.&lt;/p&gt;&#xA;&lt;p&gt;Active probes (or just probes) typically send traffic to one of the RIPs of a serverfarm, do some stuff, and give a pass or fail grade.  If the probe fails a certain number of times in a row, that server is considered sick and taken out of the pool for use.  The CSM keeps checking the unhealthy until it passes a number of times in a row, at which point it is placed back in the pool for use.  Almost everything is configurable, of course, so let&amp;rsquo;s look at some of those settings.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Using MAC Access-lists</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2008/10/using-mac-access-lists/</link>
      <pubDate>Mon, 27 Oct 2008 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2008/10/using-mac-access-lists/</guid>
      <description>&lt;p&gt;We ran into this today, and, though I knew it existed, I never actually saw it in the wild.  I&amp;rsquo;m talking about MAC access-lists.&lt;/p&gt;&#xA;&lt;p&gt;In the example setup, we have a DMZ off of a firewall that contains a whole mess of servers &amp;ndash; email, web, ftp, etc.  These should all be in the DMZ for sure, but they shouldn&amp;rsquo;t talk to each other.  If a bad guy was able to own my FTP server, he would have a nice platform to use to attack my email server.  That&amp;rsquo;s not cool, so we&amp;rsquo;ve put in MAC access-lists to help out.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Configuring Fault Tolerance on the CSM</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2008/10/configuring-fault-tolerance-on-the-csm/</link>
      <pubDate>Fri, 10 Oct 2008 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2008/10/configuring-fault-tolerance-on-the-csm/</guid>
      <description>&lt;p&gt;Like (nearly) everything in the Cisco world, you can set up your CSM to fail over to another module when the primary dies a horrible death.  You can have two in the same chassis or even have them in separate chassis &amp;ndash; the process is the same no matter how you have it set up.  Either way, you have a primary and a secondary module in fault tolerance (FT) mode.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Back to Basics -- CAM Table Population</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2008/07/back-to-basics-cam-table-population/</link>
      <pubDate>Mon, 14 Jul 2008 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2008/07/back-to-basics-cam-table-population/</guid>
      <description>&lt;p&gt;At the office, we reprovision servers like it&amp;rsquo;s going out of style.  It happens so often that my cabling documentation rarely matches what&amp;rsquo;s actually out in field, which is a pretty big problem when you&amp;rsquo;re trying to find to what switch port a server is connected.  I finally relegated myself to asking for the MAC address of the server, having the admin ping something, and then tracing it down through the CAM table entries of the switches.  It works, but the guys really don&amp;rsquo;t know how a switch populates its CAM table, so they always say &amp;ldquo;Why can&amp;rsquo;t you just look on the switch?  I shouldn&amp;rsquo;t have to ping anything.&amp;rdquo;  Here&amp;rsquo;s one just for the aspiring system admin.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Storm Control</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2008/05/storm-control/</link>
      <pubDate>Thu, 15 May 2008 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2008/05/storm-control/</guid>
      <description>&lt;p&gt;We run a large number of LANs all over the country that are &amp;ldquo;controlled&amp;rdquo; by the particular business unit. We manage the gear, but, since they have the money and have to pay for anything we do, they make the final decision on what gets put in. Sometimes that gets out of hand, as you can well imagine.&lt;/p&gt;&#xA;&lt;p&gt;A good terrible example came up a few months ago. It seems that, at some time in the past, one site needed some more LAN ports, but, instead of calling us and having us send them another switch, one of the &amp;ldquo;technical people&amp;rdquo; there brought in a hub from home. It really irks me to see a hub on the switched LAN, but we really have no control over those decisions. They plugged the hub into one of the existing drops somewhere in the building and plugged everyone in. It worked&amp;hellip;until somebody moved one of the machines. The machine was at a desk near the hub, and the network cable, still with one end plugged into the hub, was just left lying there. A good Samaritan came by, saw that the hub was not plugged into the network (though it was through another path), and plugged it back in for us &amp;ndash; providing a nice second link from the hub to the switch stack in the closet. Take one switch stack, add a hub, insert a switching loop, bake at 350F for a few milliseconds, and you have a broadcast storm. If you don&amp;rsquo;t know already, broadcast storms are bad and eat switch CPU like the yummy cookies we baked. In this case, several 3750s were taken completely down.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Getting Started with EtherChannel</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2008/04/getting-started-with-etherchannel/</link>
      <pubDate>Fri, 18 Apr 2008 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2008/04/getting-started-with-etherchannel/</guid>
      <description>&lt;p&gt;In my professional life at some point, I came across someone who had a stack of Catalyst 2950 switches all trunked together with their Internet routers connected to the top of the stack. This was all well and good until they kept adding hosts to the &amp;ldquo;middle&amp;rdquo; of the stack, then they had all sorts of latency and packet loss.&lt;/p&gt;&#xA;&lt;p&gt;The old adage of your chain only being as strong as your weakest length holds true in this case. Here, the weakest link is actually the most-congested trunk, though. Let&amp;rsquo;s step through to see. A 2950 is a 10/100 switch, so a single trunk can handle 100Mbps of traffic. We have 10 of these guys, Switch1 to Switch10, all trunked to the one above and below. If a server in the center of the stack on Switch5 is sending a lot of data to the Internet routers on Switch1, the trunks off of Switch5 will start to get saturated. Switch4 has a few hosts doing the same thing, so traffic from both Switch4 and Switch5 heads towards Switch1, further filling the trunks. Same for Switch3. Same for Switch2. Next thing you know, there&amp;rsquo;s 184Mbps or so trying to go across a 100Mbps link.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Trunking on a Catalyst Switch</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2008/03/trunking-on-a-catalyst-switch/</link>
      <pubDate>Fri, 21 Mar 2008 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2008/03/trunking-on-a-catalyst-switch/</guid>
      <description>&lt;p&gt;If you didn&amp;rsquo;t now already, trunks are connections between switches that carry traffic for all VLANs. It allows you to have, say, VLAN 10 and VLAN 20 on two switches appear as the same network. Unless you&amp;rsquo;re a really small shop, you&amp;rsquo;ve already dealt with trunks, so there&amp;rsquo;s no need for an introduction.&lt;/p&gt;&#xA;&lt;p&gt;Let&amp;rsquo;s say we have a Catlyst 2950 switch with multiple VLANs connected to another 2950 configured with those same VLANs. We&amp;rsquo;ll say we have VLANs 10, 20, and 30 and that the switches are connected to port F0/24 of each switch. First, let&amp;rsquo;s turn on the trunk.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
