Allied Telesis AT-9924T/4SP-A-20 User Manual

Browse online or download User Manual for Network switches Allied Telesis AT-9924T/4SP-A-20. Technical tips and tricks for routers and managed

  • Download
  • Add to my manuals
  • Print
  • Page
    / 106
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 0
C613-16055-00 REV E
www.alliedtelesis.com
Introduction
This document contains useful technical tips and tricks for Allied
Telesis routers and managed Layer 3 switches.
Contents
This revision of Tips and Tricks contains the following new tips and tricks:
1. How to capture command output in a text file ...................... 3
2. How to automatically capture output when particular
events occur .................................................................................... 5
3. How to upgrade the GUI when upgrading to
Software Version 2.8.1 .................................................................. 9
4. A simpler way to save the current configuration ................. 10
5. How to store stack dump files ................................................. 11
6. How to securely manage remote devices from an Asyn
(console) port on a router or Rapier ..................................... 13
7. How to reduce the impact of storms by using QoS policy
storm protection ......................................................................... 16
8. How to reduce the impact of storms by controlling
rapid MAC movement ................................................................ 18
9. How to use SNMP to monitor STP and RSTP links ............ 20
10. How to use SNMP to monitor master and slave
SwitchBlade controller cards .................................................... 25
11. Why you need to use an idle timer on a PPPoE link ........... 32
12. How to handle RIP route tags .................................................. 34
13. Route compatibility when RIP is set to receive both
RIPv1 and RIPv2 routes .............................................................. 37
14. How to select the right ISAKMP policy during incoming
Phase 1 ISAKMP proposals ........................................................ 40
15. Why the remote peer VPN router may set up multiple
ISAKMP SAs when responding to my router ........................ 43
16. About the firewall’s aggressive mode ...................................... 47
17. How to combine firewall standard and enhanced NAT ...... 49
These Tips and
Tricks apply to:
Routers
AR415S
AR440S, AR441S
AR442S
AR450S
AR750S, AR750S-DP
AR770S
AR725, AR745
AR720, AR740
AR410, AR410S
Switches
AT-8624T/2M
AT-8624PoE
AT-8648T/2SP
AT-8724XL
AT-8748XL
Rapier 24i, Rapier 24
Rapier 48i, Rapier 48
Rapier 16fi
Rapier 16f
Rapier G6
AT-8824
AT-8848
AT-9812T
AT-9816GB
SwitchBlade
AT-8948, x900-48FE
x900-48FE-N
AT-9924T, AT-9924SP
AT-9924T/4SP
AT-9924Ts
x900-24XT
x900-24XT-N
Technical Tips and Tricks |
for Routers and Managed Layer 3 Switches
Page view 0
1 2 3 4 5 6 ... 105 106

Summary of Contents

Page 1 - Technical Tips and Tricks

C613-16055-00 REV Ewww.alliedtelesis.comIntroductionThis document contains useful technical tips and tricks for Allied Telesis routers and managed Lay

Page 2

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 10A simpler way to save the current configurationWith Software Versions 2.8.1 and

Page 3 - Capturing individual commands

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 100How to use the trustprivate parameter on the firewall to block users on the pr

Page 4 - 1. Create a script

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 101with trustprivate=off, and explicitly configure rules to block access from any

Page 5

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 102How to use the firewall to control Internet access on the basis of private hos

Page 6 - 4. Examine the file debug.txt

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 103Configuration on the firewallThe configuration required to enable this process

Page 7

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 104BUT for the MAC authentication, we need to be able to say that certain MAC add

Page 8 - 4. View the syslog server

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 105How to configure a timeout on particular UDP ports in a firewall policyYou can

Page 9 - Software Version 2.8.1

USA Headquar ters | 19800 Nor th Cr eek Parkwa y | Suite 200 | Bothell | WA 98011 | USA | T: +1 800 424 4284 | F: +1 425 481 3895

Page 10

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 11How to store stack dump filesSince Software Version 2.7.6, the router or switch

Page 11 - How to store stack dump files

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 12As mentioned previously, only a maximum of 8 files can be stored in flash at on

Page 12 - What to do with dmex files

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 13How to securely manage remote devices from an Asyn (console) port on a router o

Page 13 - 2. Create a service

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 14 Connect to the remote device (in this example, the device attached to asyn1) b

Page 14 - 6. Pause the remote session

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 15 Sending a Break command does not actually disconnect from the Asyn port. There

Page 15

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 16How to reduce the impact of storms by using QoS policy storm protectionSoftware

Page 16 - Configuring storm protection

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 17The following table explains the basic concepts involved with storm protection.

Page 17 - Re-enabling ports

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 18How to reduce the impact of storms by controlling rapid MAC movementSoftware Ve

Page 18 - • vlanDisable

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 19To set a thrash action for a trunk, use the command:set lacp priority=priority

Page 19

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 2This document also contains the following Tips and Tricks from earlier revisions

Page 20 - All that support STP or RSTP

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 20How to use SNMP to monitor STP and RSTP linksSpanning Tree Protocol is used to

Page 21 - 4. Link devices together

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 21 Now that you have placed the devices in the network, you need to link the devi

Page 22

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 22Set the Status Variable as follows:1. click on the >> button (next to the

Page 23

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 23 Now configure the alarms to alert you if a link fails in the STP loop. On the

Page 24

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 24Finally select the Actions tab. Here you select a colour for the STP link to ch

Page 25 - SwitchBlade controller cards

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 25How to use SNMP to monitor master and slave SwitchBlade controller cardsIf you

Page 26

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 26Creating an alert when a controller failsPerhaps the easiest way to create an a

Page 27

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 27Then select the Attributes tab. On the Attributes tab, select the entry called

Page 28

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 28 The final stage is to add alarms to alert you on screen if a SwitchBlade contr

Page 29

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 29Enter a name for the filter event, such as “SB controller failure” and enter a

Page 30 - 1. Configure the SwitchBlade

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 3How to capture command output in a text fileInstead of displaying command output

Page 31

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 30Finally select the Actions tab. Here you select a colour to indicate controller

Page 32 - The special case of PPPoE

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 31 If there are some events for which you want to see alerts on the screen, then

Page 33

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 32Why you need to use an idle timer on a PPPoE linkOn PPPoE interfaces, we recomm

Page 34 - How to handle RIP route tags

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 33If PPPoE behaved like an always-up Layer 1 link, as described above, re-establi

Page 35

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 34How to handle RIP route tagsRIP supports route tags from RIPv2 (RFC 1724). They

Page 36

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 35The following figure shows output of the show ip route command from the router

Page 37 - RIPv1 and RIPv2 routes

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 36The following figure shows the BGP route table by using the show bgp route comm

Page 38

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 37Route compatibility when RIP is set to receive both RIPv1 and RIPv2 routesThe r

Page 39 - Solution

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 38Switch_B sends two routes (172.17.0.0/16 and 192.168.0.0/16) to its neighbours,

Page 40 - Background comments

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 39SolutionSetting Switch_A to accept RIPv2 (and not be compatible with RIPv1) cau

Page 41 - Example problem

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 4Automatically uploading command output dailyYou can use the create file command,

Page 42

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 40How to select the right ISAKMP policy during incoming Phase 1 ISAKMP proposalsV

Page 43 - Cause 1: Power failure

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 41Understanding selectionIn these situations, it is important to appreciate which

Page 44

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 42• These policies have different ID fields, but when using ISAKMP main mode, the

Page 45

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 43Why the remote peer VPN router may set up multiple ISAKMP SAs when responding t

Page 46

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 44The configuration of Router 2 is:create isakmp pol=isakmp peer=any key=1 mode=a

Page 47

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 45that case, the ISAKMP SAs time out after 24 hours by default. If you have frequ

Page 48

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 46When you have multiple policies to the same peer, you also need to consider the

Page 49

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 47About the firewall’s aggressive modeAggressive mode is a state that the firewal

Page 50

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 48The maximum number of retransmissions may be reached before the session timeout

Page 51

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 49How to combine firewall standard and enhanced NATIt is possible to use standard

Page 52 - Command: show buffer scan

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 5How to automatically capture output when particular events occurOften when we ar

Page 53

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 50add firewall poli=example rule=25 act=nat int=eth0-1 protocol=udp port=1-65000

Page 54

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 51Why the switch has many “interface is UP” and “interface is DOWN” log messagesW

Page 55

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 52How to gather useful debugging information for a suspected memory leakSituation

Page 56

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 53The output of show buffer scan is also in the output of show debug, but it is i

Page 57

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 54Figure 3 on page 54 and Figure 4 on page 54 show the second show time and show

Page 58

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 55After the third show time and show buffer scan commands, the memory address has

Page 59

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 56Once an address has been identified from the repeated show buffer scan command

Page 60 - AR410 router

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 57Example output from the show buffer scan=0007cc20 command (Continued)Figure 7 o

Page 61 - Prot=6 Int=vlan128

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 58Screen outputs showing details of these commands are shown below in Figure 8 on

Page 62

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 59Figure 10: .Example output from the dump commandFigure 11: .Example output from

Page 63 - TTY connections

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 6Create a script called (for example) capture.scp, containing the following comma

Page 64

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 60Figure 13: Example output from the dump a=0aab5b0c command.Why unexpected SNMP

Page 65

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 61How to deal with spoofed packetsSpoofed packets are packets that have arrived i

Page 66 - -from-UTC parameter

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 62How to interrupt text flow that is continuously streaming to the CLIA keyboard

Page 67 - Description

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 63How to set an inactivity timeout on console and TTY connectionsIt is possible t

Page 68

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 64Figure 22: Example output from the show asyn commandManager > set asyn=0 idl

Page 69

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 65How to set Summer Time and time zonesYou can configure the switch or router to

Page 70 - 2.7.5A or later

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 66Figure 23: Example output from the show summertime commandIt is also possible t

Page 71

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 67How to ensure that system traffic is given priority when your switch is very bu

Page 72 - 2.7.5 or later

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 68On 8948_A we can see that the CPU is busy and the default queue (2) is overload

Page 73

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 69First, give priority to routing protocol traffic sent to the CPU, by using the

Page 74 - RSTP BPDU detection features

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 7Run the script and send the output to a syslog serverAlternatively (or on older

Page 75 - LAN side of the peer

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 70How to enable and install a release on the SwitchBlade with two controllersThis

Page 76 - • L2TP users

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 71If the switch is running a version prior to 2.7.5AThe above procedure was not a

Page 77 - Router 1 configuration

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 72How to fix switch port speed but still negotiate duplexIt is possible to fix th

Page 78 - Router 2 configuration

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 73How to make private and public VLANs share the same uplinkOn AT-8600, AT-8700XL

Page 79

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 74RSTP BPDU detection featuresWith RSTP it is never a good thing to have RSTP BPD

Page 80 - Service (DNS)

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 75How to allocate a WAN IP address to a PPP peer, and create a separate route to

Page 81

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 76How to reflect TOS onto L2TP tunnelled packetsIt is possible to configure the r

Page 82

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 77Router 1 configuration#L2TP configurationenable l2tpenable l2tp server=both# Co

Page 83 - Blacklist

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 78Router 2 configurationIn this example we are using a PPP template on Router 2,

Page 84

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 79The screenshot below shows an ethereal capture of a packet from IP address 172.

Page 85

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 8The output of a script that is called from a trigger can be sent to the log. The

Page 86 - Whitelist

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 80How to use Ping or Trace using Domain Name Service (DNS)It is possible to ping

Page 87 - How do I combat the worm?

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 81How OSPF metrics are calculated If O

Page 88

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 82AS External route typesThere are two types of AS external routes—Type-1 and Typ

Page 89

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 83Filtering OSPF static routes with a whitelist or blacklist route mapOSPF can be

Page 90

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 84Now we add the commands for the filtering. In the following configuration outpu

Page 91 - Configuring address adoption

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 85Once this “blacklist” route map has been applied on the ASBR, show ip route sho

Page 92

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 86WhitelistNow change a little bit of the IP config—the action taken on matching

Page 93

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 87How to identify and combat worm attacksThis Tip describes a method for dealing

Page 94

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 88Use the following commands on AT-8600, AT-8700XL, AT-8800, AT-8900, AT-9900, x9

Page 95

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 89Whether encryption is performed in hardware or softwareWhen no hardware encrypt

Page 96

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 9How to upgrade the GUI when upgrading to Software Version 2.8.1The naming conven

Page 97 - Figure 25: Ethereal LAN trace

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 90When an AT-AR011 v2 ECMAC is installed—AR300 Series routers, AR410, AR410S, AR7

Page 98

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 91How and when to use VRRP IP address adoptionVRRP IP address adoption is when th

Page 99 - Configuration example

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 92Support for RADIUS accounting for 802.1x dynamic VLAN assignmentSupport for RAD

Page 100

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 93How to configure the firewall to allow outward-going pings but to block inward-

Page 101

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 94How to use firewall NAT to translate subnetsThis Tip gives an example of how yo

Page 102 - Head Office

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 95A configuration example is shown below:create vlan="vlan10" vid=10add

Page 103 - Configuration on the firewall

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 96Correct use of firewall NAT when FTP does not use port 21Active and passive FTP

Page 104 - Caching results

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 97How to enable the firewall enhanced fragment handling modeWhen using the firewa

Page 105

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 98That packet gets dropped when it reaches the firewall. The results in the clien

Page 106 - C613-16055-00 REV E

Technical Tips and Tricks | for Routers and Managed Layer 3 Switches 99How to use the HTTP proxy (application gateway)The firewall's HTTP proxy i

Comments to this Manuals

No comments