Cisco NM-8AM-V2 User Guide

Cisco NM-8AM-V2 - Syst. 8PRT ANALG MODEM NET MOD Manual

Cisco NM-8AM-V2 manual content summary:

  • Cisco NM-8AM-V2 | User Guide - Page 1
    , and fallback bridging support for switch virtual interfaces (SVIs). This feature module describes the 16- and 36-Port Ethernet Switch Module (NM-16ESW and NM-36ESW) for Cisco 2600 series, Cisco 3600 series, and Cisco 3700 series routers in Cisco IOS Release 12.2(2)XT and Cisco IOS Release 12
  • Cisco NM-8AM-V2 | User Guide - Page 2
    Ethernet switch network modules support simultaneous, parallel connections between Layer 2 Ethernet segments. Switched connections between Ethernet segments last only for the duration of the packet. New connections can be made between different segments for the next packet. Cisco IOS Release
  • Cisco NM-8AM-V2 | User Guide - Page 3
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Feature Overview The Ethernet switch network module solves congestion problems Ethernet switch network module builds the address table by using the extend VLANs across an entire network and supports only one encapsulation on all
  • Cisco NM-8AM-V2 | User Guide - Page 4
    on the other end, spanning tree loops might result. Inconsistencies detected by a Cisco switch mark the line as broken and block traffic for the specific VLAN. Disabling spanning tree on the VLAN of an 802.1Q trunk without disabling spanning tree on every VLAN in the network can potentially cause
  • Cisco NM-8AM-V2 | User Guide - Page 5
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco an IP address. SVIs support routing protocol and bridging problems, such as duplicate VLAN names, incorrect VLAN-type specifications, and security violations. Before you create VLANs, you must decide whether to use VTP in your network
  • Cisco NM-8AM-V2 | User Guide - Page 6
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series VTP Domain A VTP . You make global VLAN configuration changes for the domain using either the command-line interface (CLI) or Simple Network Management Protocol (SNMP). By default, the switch is
  • Cisco NM-8AM-V2 | User Guide - Page 7
    Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Feature Overview VTP Version 2 If you use VTP in your network, you must decide whether to use VTP version 1 or version 2. VTP version 2 supports the following features not supported in version 1: Unrecognized
  • Cisco NM-8AM-V2 | User Guide - Page 8
    configured, some EtherChannel interfaces are disabled automatically to avoid network loops and other problems. Follow these guidelines and restrictions to avoid configuration problems: • All Ethernet interfaces on all modules support EtherChannel (maximum of eight interfaces) with no requirement
  • Cisco NM-8AM-V2 | User Guide - Page 9
    client) Cisco router with Ethernet switch network module • Client-the device (workstation) that requests access to the LAN and switch services and network connectivity and 802.1x authentication issues, read the Microsoft Knowledge Base article at this URL: http://support.microsoft.com/support
  • Cisco NM-8AM-V2 | User Guide - Page 10
    client's identity. Note If 802.1x is not enabled or supported on the network access device, any EAPOL frames from the client are dropped. using the One-Time-Password (OTP) authentication method with a RADIUS server. Figure 2 Client Message Exchange Cisco router with Ethernet switch network module
  • Cisco NM-8AM-V2 | User Guide - Page 11
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Feature Overview Ports in Authorized and Unauthorized States The switch port state determines whether or not the client is granted access to the network does not support 802.1x is state by using the dot1x authentication services
  • Cisco NM-8AM-V2 | User Guide - Page 12
    Wireless LAN Example Access point Cisco router with Ethernet switch network module Authentication server (RADIUS) 88850 network module uses STP (the IEEE 802.1D bridge protocol) on all VLANs. By default, a single instance of STP runs on each configured VLAN (provided that you do not manually
  • Cisco NM-8AM-V2 | User Guide - Page 13
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Feature Overview Bridge Protocol Data Units The stable active spanning tree topology of a switched network receives a BPDU, it does not forward the frame but instead uses the information in the frame to calculate a BPDU, and, if
  • Cisco NM-8AM-V2 | User Guide - Page 14
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco at different places in a switched network. When a Layer 2 interface loops. Ports must wait for new topology information to propagate through been forwarded using the old topology. Each Layer 2 interface on a switch using spanning tree
  • Cisco NM-8AM-V2 | User Guide - Page 15
    Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 port in the switch, VLAN, or network goes through the blocking state and the transitory interface continues to block frame forwarding as it learns end station location information for the forwarding database. 4. The
  • Cisco NM-8AM-V2 | User Guide - Page 16
    a blocking Layer 2 interface, so there is no address database update.) • Receives BPDUs and directs them to the system module. • Does not transmit BPDUs received from the system module. • Receives and responds to network management messages. Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 16
  • Cisco NM-8AM-V2 | User Guide - Page 17
    this point, so there is no address database update.) • Receives BPDUs and directs them to the system module. • Receives, processes, and transmits BPDUs received from the system module. • Receives and responds to network management messages. Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 17
  • Cisco NM-8AM-V2 | User Guide - Page 18
    for forwarding. • Incorporates end station location into its address database. • Receives BPDUs and directs them to the system module. • Receives, processes, and transmits BPDUs received from the system module. • Receives and responds to network management messages. Cisco IOS Release 12.2(2)XT
  • Cisco NM-8AM-V2 | User Guide - Page 19
    2 interface for forwarding. • Incorporates end station location information into its address database. • Receives BPDUs and directs them to the system module. • Processes BPDUs received from the system module. • Receives and responds to network management messages. Cisco IOS Release 12.2(2)XT, 12
  • Cisco NM-8AM-V2 | User Guide - Page 20
    has a pool of MAC addresses that are used as the bridge IDs for the VLAN spanning trees. In Table 3 you can view the number of VLANs allowed for each platform. Table 3 Number of VLANs Allowed by Platform Platform Cisco 3640 or higher Cisco 3620 Cisco 2600 Maximum number of VLANs allowed 64 VLANS
  • Cisco NM-8AM-V2 | User Guide - Page 21
    and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Feature Overview MAC 4 (the default is 128). Cisco IOS software uses the port priority value when the interface is configured as an access port and uses VLAN port priority values when the interface
  • Cisco NM-8AM-V2 | User Guide - Page 22
    - and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series cost values to interfaces rules. If the switch has alternate paths to the root switch, it uses these alternate paths to transmit a new kind of Protocol Data Unit (PDU) called the Root Link Query PDU
  • Cisco NM-8AM-V2 | User Guide - Page 23
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Feature Overview If link L1 the inferior BPDUs did not come from the recognized designated bridge (Switch B). The new switch begins sending inferior BPDUs that say it is the root switch. However,
  • Cisco NM-8AM-V2 | User Guide - Page 24
    Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Cisco Discovery Protocol Cisco Discovery Protocol (CDP) is a protocol that runs over Layer 2 (the data link layer) on all Cisco routers, bridges, access servers, and switches. CDP allows network management applications
  • Cisco NM-8AM-V2 | User Guide - Page 25
    . • Monitoring of VLANs is not supported • Only one SPAN session may be used by default. Network Security with ACLs Network security on your Ethernet switch network module can be implemented using access control lists (ACLs), which are also referred to in commands and tables as access lists. Cisco
  • Cisco NM-8AM-V2 | User Guide - Page 26
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Understanding ACLs Packet filtering can limit network traffic and restrict network use depends on the context in which the ACL is used. The Ethernet switch network module supports IP ACLs to filter IP traffic, including TCP or
  • Cisco NM-8AM-V2 | User Guide - Page 27
    Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Figure 13 Using ACLs to Control Traffic to a Network Feature Overview Host A Cisco router with Ethernet switch network module Host B Human Resources network Research & Development network = ACL denying
  • Cisco NM-8AM-V2 | User Guide - Page 28
    Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco configuring ACLs on the Ethernet switch network module, you must have a thorough understanding are no restrictions on the IP subnet to be specified.) You can use any combination or all of these fields simultaneously to define a flow.
  • Cisco NM-8AM-V2 | User Guide - Page 29
    a destination TCP port number of 23. Both the ACEs use the same mask; therefore, a Ethernet switch network module supports this ACL. • Only four user-defined masks can be defined for the entire system. These can be used for either security or quality of service (QoS) but cannot be shared by QoS and
  • Cisco NM-8AM-V2 | User Guide - Page 30
    Feature Overview 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Understanding Quality of Service (QoS) Typically, networks operate on a best-effort delivery basis, which means that all traffic has equal priority and an equal chance of being
  • Cisco NM-8AM-V2 | User Guide - Page 31
    the IP phone. The queues are then serviced on a weighted round robin (WRR) basis. The control traffic, which uses a CoS or ToS of 3, is placed in Queue 2. Table 6 summarizes the queues, CoS values, and weights for Layer 2 QoS on the Ethernet switch network module. Table 6 Queues, CoS values, and
  • Cisco NM-8AM-V2 | User Guide - Page 32
    Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco , then services the queues according to the configured weights. 60979 support exists for classifying packets at the VLAN or the switched virtual interface level. You specify which fields in the frame or packet that you want to use
  • Cisco NM-8AM-V2 | User Guide - Page 33
    Cisco 3700 Series Feature Overview • Configuration of a deny action is not supported in QoS ACLs on the 16- and 36-port Ethernet switch network modules. • System-defined masks are allowed in class maps with these restrictions: - A combination of system-defined and user-defined masks cannot be used
  • Cisco NM-8AM-V2 | User Guide - Page 34
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco down the packet with a new value that is user-defined use. The IETF defines the six most-significant bits of the 1-byte type of service (ToS) field as the DSCP. The priority represented by a particular DSCP value is configurable. The supported
  • Cisco NM-8AM-V2 | User Guide - Page 35
    and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Feature Overview • type of service. Note No policers can be configured on the egress interface on Ethernet switch network modules. Mapping Tables The Ethernet switch network modules support these
  • Cisco NM-8AM-V2 | User Guide - Page 36
    IGMP snooping-learned settings. Ethernet switch network modules support a maximum of 255 IP multicast groups and support both IGMP version 1 and IGMP version through PIM-DVMRP packets, use the ip igmp snooping vlan vlan-id mrouter learn pim-dvmrp interface command. Cisco IOS Release 12.2(2)XT, 12.2(8)T,
  • Cisco NM-8AM-V2 | User Guide - Page 37
    report multicast by Host 1, the CPU uses the information to set up a multicast forwarding table entry as shown in Table 7 that includes the port numbers of Host 1 and the router. Figure 16 Initial IGMP Join Message Cisco router with Ethernet switch network module 1 IGMP Report 224.1.2.3 CPU port
  • Cisco NM-8AM-V2 | User Guide - Page 38
    Feature Overview 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Figure 17 Second Host Joining a Multicast Group Cisco router with Ethernet switch network module 1 CPU port Multicast Forwarding Table 88848 2 3 4 5 Host 1 Host 2 Host 3
  • Cisco NM-8AM-V2 | User Guide - Page 39
    Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series -control is disabled by default. The switch supports global storm-control for broadcast, multicast, and traffic that was dropped is forwarded again. You use the storm-control broadcast, storm-control multicast, and
  • Cisco NM-8AM-V2 | User Guide - Page 40
    cannot be enabled at the same time. Port Security You can use port security to block input to an Ethernet, Fast Ethernet, or network module to support Cisco IP phones in a branch office on your network. Also included is a section describing the default settings on the Ethernet switch network module
  • Cisco NM-8AM-V2 | User Guide - Page 41
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Feature Overview Default Switch Configuration By default, the Ethernet switch network module provides the following settings with respect to Cisco , but autonegotiates flow control. You can use send desired when a remote port is
  • Cisco NM-8AM-V2 | User Guide - Page 42
    and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Fallback Bridging With support subinterfaces, but behaves like a normal routed interface. A bridge group is an internal organization of network interfaces on a switch. Bridge groups cannot be used
  • Cisco NM-8AM-V2 | User Guide - Page 43
    Cisco router with Ethernet switch network module Routed port 172.20.130.1 Host C 172.20.128.1 SVI 1 Host A SVI 2 172.20.129.1 Host B 88854 VLAN 20 VLAN 30 Benefits • Statistical gains by combining multiple traffic types over a common IP infrastructure. • Long distance savings • Support
  • Cisco NM-8AM-V2 | User Guide - Page 44
    about installing voice network modules and voice interface cards in Cisco 2600 series, Cisco 3600 series, and Cisco 3700 series routers refer to these documents: • Cisco 2600 Series Modular Routers Quick Start Guide • Cisco 2600 Series Hardware Installation Guide • Quick Start Guides for Cisco 3600
  • Cisco NM-8AM-V2 | User Guide - Page 45
    platform support and Cisco IOS software image support. Access Cisco Feature Navigator at http://www.cisco.com/go/fn. You must have an account on Cisco.com. If you do not have an account or have forgotten your username or password, click Cancel at the login dialog box and follow the instructions that
  • Cisco NM-8AM-V2 | User Guide - Page 46
    ENTITY-FRU-CONTROL-MIB.my • CISCO-RTTMON-MIB • CISCO-PROCESS-MIB • CISCO-COPS-CLIENT-MIB To obtain lists of supported MIBs by platform and Cisco IOS release, and to download MIB modules, go to the Cisco MIB website on Cisco.com at the following URL: http://www.cisco.com/public/sw-center/netmgmt/cmtk
  • Cisco NM-8AM-V2 | User Guide - Page 47
    Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Interfaces To configure a range of interfaces, use the interface range command in global configuration mode command only supports VLAN interfaces that are configured with the interface vlan command. Cisco IOS Release
  • Cisco NM-8AM-V2 | User Guide - Page 48
    If both ends of the line support autonegotiation, Cisco highly recommends the default autonegotiation settings. • If one interface supports autonegotiation and the other end does not, configure duplex and speed on both interfaces; do not use the auto setting on the supported side. • Both ends of the
  • Cisco NM-8AM-V2 | User Guide - Page 49
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Configuring the Interface Speed To set the interface speed, use the set the duplex mode of an Ethernet or Fast Ethernet interface, use the following commands beginning in global configuration mode: Step 1
  • Cisco NM-8AM-V2 | User Guide - Page 50
    - and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series 5 minute output rate for an interface, use the description command in no shutdown Router(config-if)# end Purpose Selects the interface to do not support Dynamic Trunk Protocol (DTP). Ensure that the
  • Cisco NM-8AM-V2 | User Guide - Page 51
    Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Verifying an Ethernet Interface as a Layer 2 Trunk Step 1 Use the following no ip address switchport switchport trunk encapsulation dot1q end Step 2 Step 3 Router# show interfaces fastethernet
  • Cisco NM-8AM-V2 | User Guide - Page 52
    )# no shutdown Router(config-if)# end Purpose Selects the interface to configure as a Layer 2 Access Step 1 Use the show running-config interface command to network modules, and it contains the following sections: • Configuring VLANs (optional) • Deleting a VLAN from the Database (optional) Cisco
  • Cisco NM-8AM-V2 | User Guide - Page 53
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Configuring VLANs To configure an Ethernet Interface as a Layer 2 access, use the following commands beginning in EXEC mode: Step 1 Step 2 Step 3 Command Router# vlan
  • Cisco NM-8AM-V2 | User Guide - Page 54
    the VLAN Trunking Protocol (VTP) on the Ethernet switch network module, and contains the following sections: • Configuring the VTP it propagate throughout the network. To configure the switch as a VTP server, use the following commands beginning in privileged EXEC mode: Cisco IOS Release 12.2(2)XT
  • Cisco NM-8AM-V2 | User Guide - Page 55
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Step 1 Step 2 modifies its configuration accordingly. To configure the switch as a VTP client, use the following commands beginning in privileged EXEC mode: Step 1 Step 2 Step
  • Cisco NM-8AM-V2 | User Guide - Page 56
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Verifying VTP Step 1 Use the show vtp status to verify VTP status: Router# show vtp status VTP Version : 2 Configuration Revision : 247 Maximum VLANs supported locally : 1005 Number of
  • Cisco NM-8AM-V2 | User Guide - Page 57
    Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Verifying Layer 2 EtherChannels Use the switchport access vlan 10 switchport mode access channel-group 2 mode on end Step 2 Router# show interfaces fastethernet 5/6 etherchannel Port state =
  • Cisco NM-8AM-V2 | User Guide - Page 58
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco Router(config)# end Purpose Configures EtherChannel load balancing, use the no form new load balancing to take affect, the EtherChannel must be first configured to the default configuration. Verifying EtherChannel Load Balancing Step 1 Use
  • Cisco NM-8AM-V2 | User Guide - Page 59
    src-dst-ip} Router(config)# end Purpose Configures EtherChannel load balancing. Use the no keyword to return use Group Port-channel Ports Router# Configuring 802.1x Authentication This section describes how to configure 802.1x port-based authentication on the Ethernet switch network module
  • Cisco NM-8AM-V2 | User Guide - Page 60
    Tasks 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series • Setting the Switch-to-Client period Retransmission time Maximum retransmission number Multiple host support Client timeout period Authentication server timeout period Default
  • Cisco NM-8AM-V2 | User Guide - Page 61
    protocol is supported on Layer 2 static-access ports, but it is not supported on these aaa new-model Use the list of all RADIUS servers for authentication. • none-Use no authentication. The client is automatically authenticated without the switch using the information supplied by the client. Cisco
  • Cisco NM-8AM-V2 | User Guide - Page 62
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Command Step 4 interface interface-id Step 5 dot1x port-control auto Step 6 end use the no aaa new-model global configuration command. To disable 802.1x AAA authentication, use for the same service-for example, authentication
  • Cisco NM-8AM-V2 | User Guide - Page 63
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Step 1 Step 2 because leading spaces are ignored, but spaces within and at the end of the key are used. If you use spaces in the key, do not enclose the key in quotation marks
  • Cisco NM-8AM-V2 | User Guide - Page 64
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Step 1 Step 2 Step 3 Step 4 Step 5 Step 6 Command configure terminal dot1x re-authentication dot1x timeout re-authperiod seconds end To return to the default quiet time, use the no dot1x timeout quiet-period global configuration
  • Cisco NM-8AM-V2 | User Guide - Page 65
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Note You should change the default value of this command only to adjust for unusual circumstances such as unreliable links or specific behavioral problems time, use the no Step 4 Step 5 end show dot1x copy
  • Cisco NM-8AM-V2 | User Guide - Page 66
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco attached clients are denied access to the network. Beginning in privileged EXEC mode, multiple hosts on the port, use the no dot1x multiple-hosts interface 5 Command configure terminal dot1x default end show dot1x copy running-config startup
  • Cisco NM-8AM-V2 | User Guide - Page 67
    Router(config)# end Verify Spanning Tree Purpose Enables spanning tree on a per-VLAN basis. Exits configuration mode. Step 1 Use the show spanning-tree vlan command to verify spanning tree configuration: Router# show spanning-tree vlan 200 VLAN200 is executing the ieee compatible Spanning Tree
  • Cisco NM-8AM-V2 | User Guide - Page 68
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuring Spanning Tree Port Priority To configure the spanning tree port priority of an interface, use port-priority port-priority Step 4 Router(config-if)# end Verify Spanning Tree Port Priority Purpose Selects an interface
  • Cisco NM-8AM-V2 | User Guide - Page 69
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Step 3 Command Router(config-if)# [no] spanning-tree vlan vlan-id cost port-cost Step 4 Router(config-if)# end of a VLAN Caution Exercise care when using this command. For most situations spanning-tree
  • Cisco NM-8AM-V2 | User Guide - Page 70
    Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Verifying the Bridge Priority of a VLAN Step 1 Use the time be from 1 to 10 seconds. Use the no form of this command to restore the defaults. Router(config)# end Exits configuration mode. Configuring the Forward-
  • Cisco NM-8AM-V2 | User Guide - Page 71
    to start the spanning-tree reconfiguration sooner. Note If you use BackboneFast, you must enable it on all switches in the network. BackboneFast is not supported on Token Ring VLANs. This feature is supported for use with third-party switches. Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ
  • Cisco NM-8AM-V2 | User Guide - Page 72
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Beginning in privileged EXEC mode, follow these steps to enable BackboneFast: Step 1 Step 2 Step 3 Step 4 Step 5 Command configure terminal spanning-tree backbonefast end the BackboneFast feature, use the no spanning-tree
  • Cisco NM-8AM-V2 | User Guide - Page 73
    mac address table, use the following commands end Purpose Enters global configuration mode. Creates static or dynamic entry in the MAC address table. Exits configuration mode. Note Only the port where the link is up will see the dynamic entry validated in the Ethernet switch network module. Cisco
  • Cisco NM-8AM-V2 | User Guide - Page 74
    MAC address aging-timer age in seconds Exits configuration mode. Caution Cisco advises that you not change the aging timer because the Ethernet switch network module could go out of synchronization. Verifying the Aging Timer Step 1 Use the show mac-address-table aging-time command to verify the
  • Cisco NM-8AM-V2 | User Guide - Page 75
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Enabling Cisco Discovery Protocol To enable Cisco Discovery Protocol (CDP) globally, use the following command in global configuration mode: Step 1 Command Router(config)#
  • Cisco NM-8AM-V2 | User Guide - Page 76
    Configuration Tasks 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Verifying CDP Neighbors Step 1 Use the show cdp neighbors command to verify information about the neighboring equipment: Router# show cdp neighbors Capability Codes: R -
  • Cisco NM-8AM-V2 | User Guide - Page 77
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Specifying the Switched Port Analyzer Session To configure the source for a Switched Port Analyzer (SPAN) session, use configured. But only one SPAN session is supported at a time. The following example shows
  • Cisco NM-8AM-V2 | User Guide - Page 78
    "Configuring IP Services" chapter in the Cisco IP Configuration Guide for Cisco IOS Release 12.2. For detailed information about the commands, refer to Cisco IOS IP Command Reference for Cisco IOS Release 12.2. For a list of Cisco IOS features not supported on the Ethernet switch network module, see
  • Cisco NM-8AM-V2 | User Guide - Page 79
    Cisco 3700 Series Configuration Tasks ACL Numbers The number you use to denote your ACL shows the type of access list that you are creating. Table 11 lists the access list number and corresponding type and shows whether or not they are supported by the switch. The Ethernet switch network module
  • Cisco NM-8AM-V2 | User Guide - Page 80
    36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Creating | permit | Defines a standard IP ACL by using a source address and wildcard. remark} {source log option is not supported on Ethernet switch network modules. end Returns to privileged EXEC
  • Cisco NM-8AM-V2 | User Guide - Page 81
    to each protocol, refer to the Cisco IP Command Reference for Cisco IOS Release 12.2. Note The Ethernet switch network module does not support dynamic or reflexive access lists. It also does not support filtering based on the minimize-monetary-cost type of service (TOS) bit. When creating ACEs in
  • Cisco NM-8AM-V2 | User Guide - Page 82
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco match any Internet protocol (including TCP and UDP), use the keyword ip. Note This step includes options for is the number of the network or host from which the packet is udp protocols are supported on Ethernet switch interfaces.
  • Cisco NM-8AM-V2 | User Guide - Page 83
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Use the it did not find a match before reaching the end. After creating an ACL, you must apply it ACL or extended ACL can also be a number in the supported range of access list numbers. That is, the name of
  • Cisco NM-8AM-V2 | User Guide - Page 84
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Beginning in privileged EXEC mode, follow these steps to create a standard access list using 255.255. Note The log option is not supported on Ethernet switch interfaces. end Returns to privileged EXEC mode. show access-lists
  • Cisco NM-8AM-V2 | User Guide - Page 85
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks When making the standard and extended ACL, remember that, by default, the end this task for network interfaces. Note these guidelines: • When controlling access to a line, you must use a number. Numbered
  • Cisco NM-8AM-V2 | User Guide - Page 86
    QoS on your Ethernet switch network module: • Understanding the Default QoS Configuration, page 87 • Configuring Classification Using Port Trust States, page 87 • Configuring a QoS Policy, page 90 • Configuring CoS Maps, page 96 • Displaying QoS Information, page 97 Cisco IOS Release 12.2(2)XT, 12
  • Cisco NM-8AM-V2 | User Guide - Page 87
    Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series the egress direction are not supported and cannot be attached to an interface by using the service-policy input policy-map-name network topology. Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 87
  • Cisco NM-8AM-V2 | User Guide - Page 88
    3700 Series Figure 20 Port Trusted States within the QoS Domain Trusted interface Catalyst 2950 wiring closet Trunk Cisco router with Ethernet switch network module Classification of traffic performed here 88855 Beginning in privileged EXEC mode, follow these steps to configure the port
  • Cisco NM-8AM-V2 | User Guide - Page 89
    Enter the dscp keyword if you are using an SVI that is a VLAN interface that you created by using the interface vlan vlan-id global configuration command. The DCSP-to-CoS map will be applied to packets arriving from a router to the Ethernet switch network module through an SVI. Returns to privileged
  • Cisco NM-8AM-V2 | User Guide - Page 90
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Step 3 Step 4 Step 5 Step 6 Command mls qos cos {default-cos | override} end the packet. The CoS range is 0 to 7. The default is 0. Use the override keyword to override the previously configured trust state of the incoming
  • Cisco NM-8AM-V2 | User Guide - Page 91
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Classifying Traffic by Using ACLs You can classify IP traffic by using of the network or host supported for QoS ACLS. See the "Classification Based on QoS ACLs" section on page 32 for more details. end
  • Cisco NM-8AM-V2 | User Guide - Page 92
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco Step 4 Step 5 end show access-lists copy using the host keyword for source 0.0.0.0. For destination, enter the network Use TCP port names only for TCP traffic. • Use UDP port names only for UDP traffic. Note Deny statements are not supported
  • Cisco NM-8AM-V2 | User Guide - Page 93
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Classifying Traffic by Using Class Maps You use Step 5 Step 6 Step 7 end show class-map [class-map- supported. Only one match criterion per class map is supported, and only one ACL per class map is supported
  • Cisco NM-8AM-V2 | User Guide - Page 94
    Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Classifying, Policing, and Marking Traffic by Using Policy Maps policy map, the class named class-default is not supported. The switch does not filter traffic based on the policy map defined by
  • Cisco NM-8AM-V2 | User Guide - Page 95
    Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 supported. Use input policy-map-name to apply the specified policy map to the input of an interface. Step 10 end association, use the no service-policy input policy-map-name interface configuration command. Cisco IOS Release
  • Cisco NM-8AM-V2 | User Guide - Page 96
    -CoS map to map DSCP values in incoming packets to a CoS value, which is used to select one of the four egress queues. The Ethernet switch network modules support these DSCP values: 0, 8, 10, 16, 18, 24, 26, 32, 34, 40, 46, 48, and 56. Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 96
  • Cisco NM-8AM-V2 | User Guide - Page 97
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco network, you need to modify them. Beginning in privileged EXEC mode, follow these steps to modify the DSCP-to-CoS map: Step 1 Step 2 Step 3 Step 4 Step 5 Command configure terminal mls qos map dscp-cos dscp-list to cos end supported used
  • Cisco NM-8AM-V2 | User Guide - Page 98
    Configuration Tasks 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuring Power Management on the Interface To manage the powering of the Cisco IP phones, use the following commands beginning in privileged EXEC mode: Step 1 Step 2
  • Cisco NM-8AM-V2 | User Guide - Page 99
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco Cisco IOS IP Configuration Guide, Release 12.2, at this URL: http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fipr_c/ • Cisco IOS IP Command Reference, Volume 1 of 3: Addressing and Services interface using the default
  • Cisco NM-8AM-V2 | User Guide - Page 100
    - and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Verifying IP Multicast Layer PIM interfaces and the number of packets received and sent on the interface. Use the following show commands to verify IP multicast Layer 3 switching information for an
  • Cisco NM-8AM-V2 | User Guide - Page 101
    Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 replies are disabled Policy routing is disabled Network address translation is disabled WCCP Redirect enabled Router# Verifying the IP Multicast Routing Table Step 1 Use the show ip mroute command to verify the IP multicast
  • Cisco NM-8AM-V2 | User Guide - Page 102
    Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series network module: Step 1 Step 2 Step 3 Step 4 Step 5 Command configure terminal ip igmp snooping end globally disable IGMP snooping on all VLAN interfaces, use the no ip igmp snooping global command. Beginning
  • Cisco NM-8AM-V2 | User Guide - Page 103
    use the no ip igmp snooping vlan vlan-id global configuration command for the specified VLAN number (for example, vlan1). Enabling IGMP Immediate-Leave Processing When you enable IGMP Immediate-Leave processing, the Ethernet switch network module vlan-id immediate-leave end Purpose Enters global
  • Cisco NM-8AM-V2 | User Guide - Page 104
    36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Step 4 vlan-id mrouter {interface interface-id | learn pim-dvmrp} end show ip igmp snooping [vlan vlan-id] show ip igmp snooping on dynamically learned and manually configured multicast router interfaces.
  • Cisco NM-8AM-V2 | User Guide - Page 105
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Enabling Global Storm-Control Enable global storm-control globally and enter the percentage of total available bandwidth that you want to be used Step 5 Router(config)# end Verifying Global Storm-Control
  • Cisco NM-8AM-V2 | User Guide - Page 106
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series The following is sample output the port during a storm. The default is to filter out the traffic. end Returns to privileged EXEC mode. show storm-control [interface] [{broadcast Verifies your
  • Cisco NM-8AM-V2 | User Guide - Page 107
    Voice and Data Subnets For ease of network administration and increased scalability, network managers can configure the Ethernet switch network module to support Cisco IP phones such that the voice and data traffic reside on separate subnets. You should always use separate VLANs when you are able to
  • Cisco NM-8AM-V2 | User Guide - Page 108
    that will be used exclusively for voice traffic. Voice Traffic and VVID The Ethernet switch network module can automatically configure Service (ToS) bits in all media streams to an IP Precedence value of 5. (With Cisco CallManager Release 3.0(5), this marking changed to a Differentiated Services
  • Cisco NM-8AM-V2 | User Guide - Page 109
    and separate VLANs for IP telephony. Managing the Ethernet Switch Network Module This section describes how to perform basic management tasks on the Ethernet switch network module with the Cisco IOS CLI. You might find this information useful when you configure the switch for the previous scenarios
  • Cisco NM-8AM-V2 | User Guide - Page 110
    )# end Returns to privileged EXEC mode. Verifying Trap Managers Step 1 Use the network module. The following topics are included: • Assigning IP Information to the Switch, page 110 • Specifying a Domain Name and Configuring the DNS, page 111 Assigning IP Information to the Switch You can use
  • Cisco NM-8AM-V2 | User Guide - Page 111
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks You can change the information in these fields. The mask identifies the bits that denote the network number in the IP address. When you use the mask to subnet a network config-subif)# end Purpose Enters
  • Cisco NM-8AM-V2 | User Guide - Page 112
    network module can supply electrical power to the circuit connecting it to the Cisco 7960 IP phone. Because the sound quality of an IP telephone call can deteriorate if the data is unevenly transmitted, the current release of the Cisco IOS software supports QoS based on IEEE 802.1p CoS. QoS uses
  • Cisco NM-8AM-V2 | User Guide - Page 113
    3700 Series Configuration Tasks Configuring a Port to Connect to a Cisco 7960 IP phone Because a Cisco 7960 IP phone also supports connection to a PC or other device, a port connecting a Ethernet switch network module to a Cisco 7960 IP phone can carry a mix of traffic. There are three ways to
  • Cisco NM-8AM-V2 | User Guide - Page 114
    Configuration Tasks 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Verifying Inline Power Configuration Step 1 Use the show power inline interface configured command to verifies the change by displaying the setting as configured: Router#
  • Cisco NM-8AM-V2 | User Guide - Page 115
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Managing the MAC Address Tables This section describes how to manage the MAC address tables on the Ethernet switch network module it is not in use. • Secure address-a manually entered unicast address that
  • Cisco NM-8AM-V2 | User Guide - Page 116
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Changing the Address Aging Time Dynamic addresses are source MAC addresses that the switch learns and then drops when they are not in use. Use new port. To configure the dynamic address table aging time, use config)# end Purpose
  • Cisco NM-8AM-V2 | User Guide - Page 117
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Verifying Dynamic Addresses Step 1 Use the show mac-address-table dynamic command to verify configuration: Router# show mac-address-table dynamic Adding Secure Addresses
  • Cisco NM-8AM-V2 | User Guide - Page 118
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuring Static Addresses A static address has the following characteristics: • It is manually entered in the address table and must be manually a static address, use the following commands Router(config)# end Purpose Enters
  • Cisco NM-8AM-V2 | User Guide - Page 119
    of the Ethernet switch network module, use the following commands beginning in global configuration mode: Step 1 Step 1 Step 2 Command Router(config)# interface Gigabit slot/port Router(config-if)# [no] switchport stacking-link interface Gigabit slot/port Router(config)# end Purpose Enters the
  • Cisco NM-8AM-V2 | User Guide - Page 120
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuring Layer 3 Interfaces The Ethernet switch network module supports which the interface is connected. When you use this command to put the interface into you shut down the interface.) end Returns to privileged EXEC mode.
  • Cisco NM-8AM-V2 | User Guide - Page 121
    and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Configuring Adjusting Spanning-Tree Parameters, page 124 • Monitoring and Maintaining the Network, page 129 Understanding the Default Fallback Bridging Configuration Table 16
  • Cisco NM-8AM-V2 | User Guide - Page 122
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Note The protected port feature is not compatible 6 Step 7 end show running-config The ibm and dec keywords are not supported. For bridge-group, specify the bridge interface that you created by using the interface vlan vlan-id
  • Cisco NM-8AM-V2 | User Guide - Page 123
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco it has dynamically learned, use the bridge bridge-group acquire network, decrease the aging-time to enable the switch to quickly adapt to the change. If hosts on a switched network bridge-group aging-time seconds end show running-config copy
  • Cisco NM-8AM-V2 | User Guide - Page 124
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series To return to the default aging-time interval, use back to its originating network segment. You can use the software to configure on which the address can be reached. end Returns to privileged EXEC mode. show running-config
  • Cisco NM-8AM-V2 | User Guide - Page 125
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Note Only network number Step 3 Step 4 Step 5 end show running-config copy running-config startup- exists. To return to the default setting, use the bridge bridge-group priority number global configuration
  • Cisco NM-8AM-V2 | User Guide - Page 126
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Step 3 Command bridge-group bridge-group priority number Step 4 Step 5 Step 6 end the configuration file. To return to the default path cost, use the no bridge-group bridge-group path-cost cost interface configuration
  • Cisco NM-8AM-V2 | User Guide - Page 127
    Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series configure terminal bridge bridge-group hello-time seconds end show running-config copy running-config startup-config file. To return to the default setting, use the no bridge bridge-group hello-time global
  • Cisco NM-8AM-V2 | User Guide - Page 128
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco Step 3 Step 4 Step 5 end show running-config copy running-config startup file. To return to the default setting, use the no bridge bridge-group max-age global yet still permit switching throughout the network as a whole. For example,
  • Cisco NM-8AM-V2 | User Guide - Page 129
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Tasks Monitoring and Maintaining the Network To monitor and maintain the network, use one or more of the privileged EXEC commands in Table 17: Table 17 Fallback Bridging Commands
  • Cisco NM-8AM-V2 | User Guide - Page 130
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module Configuration Examples for the 16- and 36-Port Ethernet Switch Module This section provides the following configuration
  • Cisco NM-8AM-V2 | User Guide - Page 131
    Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module *Oct 6 Multiple Range Configuration Example The following example shows how to use a comma to add different interface type strings to the range
  • Cisco NM-8AM-V2 | User Guide - Page 132
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module Interface interface is configured to support 802.1Q trunking: Router# configure terminal Enter configuration commands, one per line. End with CNTL/Z. Router(
  • Cisco NM-8AM-V2 | User Guide - Page 133
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module VTP Examples • VTP Server Example, page 133 • VTP Client Example, page 133 • Disabling VTP (VTP Transparent Mode) Example,
  • Cisco NM-8AM-V2 | User Guide - Page 134
    Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module Router(config-if)# end EtherChannel Load Balancing Example The following example shows EtherChannel being configured to use source and destination
  • Cisco NM-8AM-V2 | User Guide - Page 135
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module Switch(config)# aaa new-model Switch(config)# (config-if)# end Configuring the Switch .46 as the RADIUS server, to use port 1612 as the authorization port, and
  • Cisco NM-8AM-V2 | User Guide - Page 136
    Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module Switch -if)# spanning-tree vlan 200 port-priority 64 Router(config-if)# end Router# The following example shows how to verify the configuration of VLAN
  • Cisco NM-8AM-V2 | User Guide - Page 137
    Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module The Router(config)# spanning-tree vlan 200 forward-time 21 Router(config)# end Router# Maximum Aging Time for a VLAN Example The following example
  • Cisco NM-8AM-V2 | User Guide - Page 138
    configured as the root bridge for VLAN 10, with a network diameter of 4: Router# configure terminal Router(config)# spanning-tree end Cisco Discovery Protocol (CDP) Example The following example shows CDP counter configuration being configured on the NM-16ESW: Router# clear cdp counters 138 Cisco
  • Cisco NM-8AM-V2 | User Guide - Page 139
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module source interface fastethernet 5/2 Network Security and ACL )# end Switch# show access-lists Standard IP access list 2 deny 171.69.198.102 permit any Cisco IOS
  • Cisco NM-8AM-V2 | User Guide - Page 140
    on the other end. The same port numbers are used throughout the life of the connection. Mail packets coming in from the Internet have a destination port of 25. Because the secure system behind the switch always accepts mail connections on port 25, the incoming services are controlled. Creating
  • Cisco NM-8AM-V2 | User Guide - Page 141
    36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module Including Comments About Entries in ACLs Example The following example shows an IP numbered standard ACL using the access-list access
  • Cisco NM-8AM-V2 | User Guide - Page 142
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module When IP is enabled on an interface, you can use the show ip interface interface-id privileged EXEC command to enable end! 142 Cisco IOS Release 12.2(2)XT, 12
  • Cisco NM-8AM-V2 | User Guide - Page 143
    and the "IP Services" chapter of the Cisco IOS IP and IP Routing Configuration Guide for Cisco IOS Release 12.2. Figure 21 shows a small networked office with a stack of Catalyst 2950 switches that are connected to a Cisco router with an Ethernet switch network module installed. A host is connected
  • Cisco NM-8AM-V2 | User Guide - Page 144
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module The following example uses group 103 Switch(config-cmap)# end Switch# Classifying, Policing, and Marking Traffic by Using Policy Maps Example The following
  • Cisco NM-8AM-V2 | User Guide - Page 145
    are sent from the hosts connected to the Ethernet switch network module. Router(config)# ip multicast-routing Router(config-if)# interface VLAN1 Router(config-if)# ip-address 192.168.10.1 255.255.255.0 Router(config-if)# ip pim sparse-mode Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 145
  • Cisco NM-8AM-V2 | User Guide - Page 146
    Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module 90 255.255.255.0 ip pim sparse-mode end The following example shows output verifying multicasting support: Router# show ip igmp group IGMP Connected
  • Cisco NM-8AM-V2 | User Guide - Page 147
    Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module The following example config-if)# storm-control threshold 70 Router(config-if)# end Router# show storm-control Name: Gi0/2 Switchport: Enabled
  • Cisco NM-8AM-V2 | User Guide - Page 148
    50 description data vlan ip address 10.50.1.1 255.255.255.0 This configuration instructs the IP phone to generate a packet with an 802.1Q VLAN ID required for its configuration. Cisco IOS supports a DHCP server function. If this function is used, the Ethernet switch network module serves as a local
  • Cisco NM-8AM-V2 | User Guide - Page 149
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module network module supports the use of an 802.1p-only option when configuring the voice VLAN. Using The Ethernet switch network module instructs the IP phone to
  • Cisco NM-8AM-V2 | User Guide - Page 150
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module The following example illustrates the configuration on the PC: interface FastEthernet2/3 switchport access vlan 10 Note Using can use Cisco Network Registrar
  • Cisco NM-8AM-V2 | User Guide - Page 151
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module : Switch# configure terminal Enter configuration commands, one per line. End with CNTL/Z. Switch(config)# interface gigabitethernet0/10 Switch(config-if)#
  • Cisco NM-8AM-V2 | User Guide - Page 152
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module The following is sample output from the show interfaces privileged EXEC command for Gigabit Ethernet interface 0/2: Switch(
  • Cisco NM-8AM-V2 | User Guide - Page 153
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module RTP/IP header compression is disabled Probe proxy name replies are disabled Policy routing is disabled Network qos trust dscp end Configuring Layer 3
  • Cisco NM-8AM-V2 | User Guide - Page 154
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module replies are disabled Policy routing is disabled Network address translation is disabled WCCP Redirect end 154 Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12
  • Cisco NM-8AM-V2 | User Guide - Page 155
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module Fallback Bridging Example This section describes how to configure fallback bridging on your switch. It contains this
  • Cisco NM-8AM-V2 | User Guide - Page 156
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module Changing the Switch Priority Example The following example shows how to set the switch priority to 100 for bridge group 10:
  • Cisco NM-8AM-V2 | User Guide - Page 157
    36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Command Reference Command Reference This section documents new commands or existing commands that are newly ported to the 16- and 36-port Ethernet switch module. All other commands used with this feature
  • Cisco NM-8AM-V2 | User Guide - Page 158
    Command Reference 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series • show class-map • show dot1x • show ip access-lists • show ip igmp snooping • show ip igmp snooping mrouter • show mls masks • show mls
  • Cisco NM-8AM-V2 | User Guide - Page 159
    36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series aaa authentication dot1x aaa authentication dot1x To specify one or more authentication, authorization, and accounting (AAA) methods for use on interfaces running IEEE 802.1x, use the aaa authentication
  • Cisco NM-8AM-V2 | User Guide - Page 160
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series If you specify group radius, you must configure the RADIUS server by entering the radius-server host global configuration command. If you are not using a RADIUS server, you can use Switch(config)# aaa new model Switch(config)#
  • Cisco NM-8AM-V2 | User Guide - Page 161
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series class class To define a traffic classification for the policy to act on using the class-map name or access group, use the class policy-map configuration command. To delete an existing class map,
  • Cisco NM-8AM-V2 | User Guide - Page 162
    class 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series • exit: exits policy-map use the end command. Note For more information about configuring IP ACLs, refer to the "Configuring IP Services" chapter in the Cisco IOS IP Configuration Guide,
  • Cisco NM-8AM-V2 | User Guide - Page 163
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series class-map class-map To create a class map to be used for matching packets and to enter class-map configuration mode, use command. Only one match criteria per class map is supported. For example, when defining a class map, only
  • Cisco NM-8AM-V2 | User Guide - Page 164
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Note For more information about configuring IP ACLs, refer to the "Configuring IP Services" chapter in the Cisco IOS IP Configuration Guide classification for the policy to act on by using the class-map name or access group.
  • Cisco NM-8AM-V2 | User Guide - Page 165
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series debug dot1x debug dot1x To enable debugging of the 802.1x feature, use the debug dot1x command in privileged EXEC mode. To disable debugging output, use access to the network through 802. Dial-In User Service [RADIUS] client).
  • Cisco NM-8AM-V2 | User Guide - Page 166
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series debug eswilp To enable debugging of Ethernet switch network module features, use the debug eswilp command in privileged EXEC mode. To disable debugging output, use the no form of this command
  • Cisco NM-8AM-V2 | User Guide - Page 167
    the following platforms: Cisco 2600 series, Cisco 3600 series, and Cisco 3700 series routers. Usage Guidelines Use the debug ip igmp snooping command to troubleshoot the IGMP snooping feature. Examples The following example shows debugging messages for the IGMP snooping services being displayed
  • Cisco NM-8AM-V2 | User Guide - Page 168
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series debug spanning-tree To debug spanning-tree activities, use the debug spanning-tree command in privileged EXEC mode. To disable debugging output, use EtherChannel support. spanning-tree Simple Network Management Protocol (SNMP
  • Cisco NM-8AM-V2 | User Guide - Page 169
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series debug spanning-tree Related Commands Command show debugging show spanning-tree Description Displays information about the types of debugging that are enabled. Displays
  • Cisco NM-8AM-V2 | User Guide - Page 170
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series deny (access-list configuration) To configure conditions for a named or numbered IP access control list (ACL), use wildcard. The source is the source address of the network or host from which the packet is being sent, specified
  • Cisco NM-8AM-V2 | User Guide - Page 171
    Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 number can be from 0 to 65535. Use TCP port names only for TCP traffic. Use UDP port names only for UDP traffic. refer to the "Configuring IP Services" chapter in the Cisco IOS IP Configuration Guide, Release 12.2. Examples The
  • Cisco NM-8AM-V2 | User Guide - Page 172
    deny (access-list configuration) 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Note In these examples, all other IP access is implicitly denied. You can verify your settings by entering the show ip access-lists
  • Cisco NM-8AM-V2 | User Guide - Page 173
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series dot1x default dot1x default To reset the global 802.1x parameters to their default values, use the dot1x default command in global configuration mode. dot1x default Syntax Description This
  • Cisco NM-8AM-V2 | User Guide - Page 174
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series dot1x max-req To set before restarting the authentication process, use the dot1x max-req command in global configuration mode. To return to the default setting, use the no form of this command
  • Cisco NM-8AM-V2 | User Guide - Page 175
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series dot1x multiple-hosts dot1x multiple-hosts To allow multiple hosts (clients) on an 802.1x-authorized port that has the dot1x port-control interface configuration command set to auto, use to the network. Examples The manual
  • Cisco NM-8AM-V2 | User Guide - Page 176
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series dot1x port-control To enable manual control of the authorization state of the port, use the the client to authenticate. The switch cannot provide authentication services to the client through the interface. Defaults The
  • Cisco NM-8AM-V2 | User Guide - Page 177
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series dot1x port-control Examples The following example shows how to enable 802.1x on Fast Ethernet interface 0/1: Switch(config)# interface fastethernet0/1 Switch(config-
  • Cisco NM-8AM-V2 | User Guide - Page 178
    re-authenticate 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series dot1x re-authenticate To manually initiate a reauthentication of all 802.1x-enabled ports or the specified 802.1x-enabled port, use the dot1x re-authenticate command in privileged
  • Cisco NM-8AM-V2 | User Guide - Page 179
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series dot1x re-authentication dot1x re-authentication To enable periodic reauthentication of the client, use the dot1x re-authentication command in global configuration mode. To return to the default
  • Cisco NM-8AM-V2 | User Guide - Page 180
    -period 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series dot1x timeout quiet-period To set provided an invalid password), use the dot1x quiet-period command in global configuration mode. To return to the default setting, use the no form of this
  • Cisco NM-8AM-V2 | User Guide - Page 181
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series dot1x timeout re-authperiod dot1x timeout re-authperiod To set the number of seconds between reauthentication attempts, use the dot1x timeout re-authperiod command in global configuration mode.
  • Cisco NM-8AM-V2 | User Guide - Page 182
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 the default setting, use the no form Cisco 3700 series routers. Usage Guidelines You should change the default value of this command only to adjust for unusual circumstances such as unreliable links or specific behavioral problems
  • Cisco NM-8AM-V2 | User Guide - Page 183
    on Layer 2 and Layer 3 interfaces. Note For more information about configuring IP ACLs, refer to the "Configuring IP Services" chapter in the Cisco IOS IP Configuration Guide, Release 12.2. Examples The following example shows how to apply a numbered ACL to an interface: Switch(config)# interface
  • Cisco NM-8AM-V2 | User Guide - Page 184
    ip access-group 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series You can verify your settings by entering the show access-lists or show ip access-lists privileged EXEC command. Related Commands Command deny (
  • Cisco NM-8AM-V2 | User Guide - Page 185
    determines the prompt you get when you enter access-list configuration mode. Note For more information about configuring IP ACLs, refer to the "Configuring IP Services" chapter in the Cisco IOS IP Configuration Guide, Release 12.2. Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 185
  • Cisco NM-8AM-V2 | User Guide - Page 186
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Examples The following example shows list configuration) dot1x re-authenticate permit (access-list configuration) service-policy show access-lists show ip access-lists Description Configures
  • Cisco NM-8AM-V2 | User Guide - Page 187
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series ip igmp snooping ip igmp snooping To globally enable Internet Group Management Protocol (IGMP) snooping, use the ip igmp snooping command in global configuration mode. To disable IGMP snooping,
  • Cisco NM-8AM-V2 | User Guide - Page 188
    - and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Command ip igmp snooping vlan static show ip igmp snooping Description Configures a Layer 2 port as a member of a group. Displays the IGMP snooping configuration. 188 Cisco IOS Release 12.2(2)XT
  • Cisco NM-8AM-V2 | User Guide - Page 189
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series ip igmp snooping vlan ip igmp snooping vlan To enable Internet Group Management Protocol (IGMP) snooping on a specific VLAN, use the ip igmp snooping vlan command in global configuration mode. To
  • Cisco NM-8AM-V2 | User Guide - Page 190
    -leave 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series ip igmp snooping vlan immediate-leave To enable Internet Group Management Protocol (IGMP) Immediate-Leave processing on a VLAN interface, use the ip igmp snooping immediate-leave command
  • Cisco NM-8AM-V2 | User Guide - Page 191
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series ip igmp snooping vlan immediate-leave Command Description show ip igmp snooping Displays the IGMP snooping configuration. show mac-address-table multicast Displays
  • Cisco NM-8AM-V2 | User Guide - Page 192
    snooping vlan mrouter 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series ip igmp snooping vlan mrouter To add a multicast router port and to configure the multicast router learning method, use the ip igmp snooping vlan mrouter command in global
  • Cisco NM-8AM-V2 | User Guide - Page 193
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series ip igmp snooping vlan mrouter Command ip a member of a group. Displays the statically and dynamically learned multicast router ports. Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 193
  • Cisco NM-8AM-V2 | User Guide - Page 194
    ip igmp snooping vlan static 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series ip igmp snooping vlan static To add a Layer 2 port as a member of a multicast group, use the ip igmp snooping vlan vlan-id static command in global configuration mode
  • Cisco NM-8AM-V2 | User Guide - Page 195
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series ip igmp snooping vlan static Command Description ip igmp snooping vlan mrouter Configures a Layer 2 port as a multicast router port. show mac-address-table
  • Cisco NM-8AM-V2 | User Guide - Page 196
    per class map is supported. Note For more information about configuring IP ACLs, refer to the "Configuring IP Services" chapter in the Cisco IOS IP Configuration Guide, Release 12.2. Examples The following example shows how to classify traffic on an interface by using the access group named
  • Cisco NM-8AM-V2 | User Guide - Page 197
    Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series match (class-map configuration) Related Commands Command class class-map dot1x re-authenticate show class-map show policy-map Description Defines a traffic classification for a policy to act on using the class
  • Cisco NM-8AM-V2 | User Guide - Page 198
    mls qos cos 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series mls qos cos To define the default class of service (CoS) value of a port or to assign the default CoS to all incoming packets on the port, use the mls qos cos command in interface
  • Cisco NM-8AM-V2 | User Guide - Page 199
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series mls qos cos The following example shows how to Displays switchport interfaces. show mls qos interface Displays QoS information. Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 199
  • Cisco NM-8AM-V2 | User Guide - Page 200
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series mls qos map To define the class of service (CoS)-to-Differentiated Services Code Point (DSCP) map or DSCP-to-CoS map, use 0 to 7. Separate each DSCP value with a space. The supported DSCP values are 0, 8, 10, 16, 18, 24, 26
  • Cisco NM-8AM-V2 | User Guide - Page 201
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series mls qos map Usage you can define the CoS-to-DSCP or DSCP-to-CoS map by entering consecutive mls qos map commands. The supported DSCP values are 0, 8, 10, 16, 18, 24, 26, 32, 34, 40, 46, 48,
  • Cisco NM-8AM-V2 | User Guide - Page 202
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series mls qos trust To configure the port trust state and classify traffic by examining the class of service (CoS) or Differentiated Services Code Point (DSCP) value, use the mls qos trust command in
  • Cisco NM-8AM-V2 | User Guide - Page 203
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series mls qos trust The following example shows how to configure a VLAN -to-DSCP map or the DSCP-to-CoS map. Displays QoS information. Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 203
  • Cisco NM-8AM-V2 | User Guide - Page 204
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series permit (access-list configuration) To configure conditions for a named or numbered IP access control list (ACL), use wildcard. The source is the source address of the network or host from which the packet is being sent,
  • Cisco NM-8AM-V2 | User Guide - Page 205
    Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 number can be from 0 to 65535. Use TCP port names only for TCP traffic. Use UDP port names only for UDP traffic. refer to the "Configuring IP Services" chapter in the Cisco IOS IP Configuration Guide, Release 12.2. Examples The
  • Cisco NM-8AM-V2 | User Guide - Page 206
    permit (access-list configuration) 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Note In these examples, all other IP access is implicitly denied. You can verify your settings by entering the show ip access-lists
  • Cisco NM-8AM-V2 | User Guide - Page 207
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series police police To define a policer for classified traffic, use the police command in policy-map class configuration mode. To remove an existing policer, use the switch changes the Differentiated Services Code Point (DSCP) of
  • Cisco NM-8AM-V2 | User Guide - Page 208
    Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Note For more information about configuring access control lists (ACLs), refer to the "Configuring Network Security with ACLs" chapter in the Catalyst 2950 Desktop Switch Software Configuration Guide for this
  • Cisco NM-8AM-V2 | User Guide - Page 209
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series policy-map policy-map To create or modify a policy map that can be attached to multiple interfaces and to enter policy-map configuration mode, use supported. use the exit command. To return to privileged EXEC mode, use the end
  • Cisco NM-8AM-V2 | User Guide - Page 210
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series You can configure class policies in a policy map only if the classes have match criteria defined for them. Use "Configuring Network Security with ACLs" chapter in the Catalyst 2950 Desktop Switch Software Configuration Guide for
  • Cisco NM-8AM-V2 | User Guide - Page 211
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series service-policy service-policy To apply a policy map defined by the policy-map command to the input of a particular interface, use the service-policy command in interface configuration mode. To
  • Cisco NM-8AM-V2 | User Guide - Page 212
    show access-lists 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show access-lists To display access control lists (ACLs) configured on the switch, use the show access-lists command in privileged EXEC mode. show access-lists [name | number]
  • Cisco NM-8AM-V2 | User Guide - Page 213
    36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show access-lists Related Commands Command ip access-list show ip access-lists Description Configures an IP ACL on the switch. Displays the IP ACLs configured on a switch. Cisco IOS Release 12.2(2)XT
  • Cisco NM-8AM-V2 | User Guide - Page 214
    show class-map 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show class-map To display quality of service (QoS) class maps, which define the match criteria to classify traffic, use the show class-map command in privileged EXEC mode. show
  • Cisco NM-8AM-V2 | User Guide - Page 215
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show class-map Related Commands Command class-map match (class-map configuration) Description Creates a class map to be used for matching packets to the class whose name you specify. Defines the
  • Cisco NM-8AM-V2 | User Guide - Page 216
    show dot1x 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show dot1x To display the 802.1x statistics, administrative status, and operational status for the switch or for the specified interface, use the show dot1x command in privileged EXEC
  • Cisco NM-8AM-V2 | User Guide - Page 217
    Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 relaying a request from the Remote Authentication Dial-In User Service (RADIUS) authentication server to the client, the supp- the Catalyst 2950 Desktop Switch Software Configuration Guide. The following is sample output from
  • Cisco NM-8AM-V2 | User Guide - Page 218
    show dot1x 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Table 20 show dot1x interface Field Descriptions Field Description Status Status of the port (authorized or unauthorized). The status of a port appears as
  • Cisco NM-8AM-V2 | User Guide - Page 219
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show dot1x Table 21 show dot1x statistics Field default Description Resets the global 802.1x parameters to their default values. Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 219
  • Cisco NM-8AM-V2 | User Guide - Page 220
    show ip access-lists 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show ip access-lists To display IP access control lists (ACLs) configured on the switch, use the show ip access-lists command in privileged EXEC mode. show ip access-lists [
  • Cisco NM-8AM-V2 | User Guide - Page 221
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show ip access-lists Related Commands Command access-list (IP extended) access-list (IP standard) ip access-list show access-lists Description Configures
  • Cisco NM-8AM-V2 | User Guide - Page 222
    igmp snooping 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show ip igmp snooping To display the Internet Group Management Protocol (IGMP) snooping configuration of the switch or the VLAN, use the show ip igmp snooping command in privileged
  • Cisco NM-8AM-V2 | User Guide - Page 223
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show ip igmp snooping IGMP snooping immediate- . show mac-address-table multicast Displays the Layer 2 multicast entries for a VLAN. Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 223
  • Cisco NM-8AM-V2 | User Guide - Page 224
    igmp snooping mrouter 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show ip igmp snooping mrouter To display information on dynamically learned and manually configured multicast router ports, use the show ip igmp snooping mrouter command in
  • Cisco NM-8AM-V2 | User Guide - Page 225
    and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show mls masks show mls masks To display the details of the Access Control Parameters (ACPs) used for quality of service (QoS) and security access control lists (ACLs), use the show mls masks command
  • Cisco NM-8AM-V2 | User Guide - Page 226
    show mls masks 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Related Commands Command ip access-group policy-map Description Applies an IP ACL to an interface. Creates or modifies a policy map that can
  • Cisco NM-8AM-V2 | User Guide - Page 227
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show mls qos interface show mls qos interface To display quality of service (QoS) information at the interface level, use the show mls qos interface command in privileged EXEC mode. show mls qos
  • Cisco NM-8AM-V2 | User Guide - Page 228
    show mls qos maps 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show mls qos maps To display quality of service (QoS) mapping information, use the show mls qos maps command in privileged EXEC mode. show mls qos maps [cos-dscp | dscp-cos]
  • Cisco NM-8AM-V2 | User Guide - Page 229
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show mls qos maps The following is Related Commands Command mls qos map Description Defines the CoS-to-DSCP map and DSCP-to-CoS map. Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 229
  • Cisco NM-8AM-V2 | User Guide - Page 230
    show policy-map 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show policy-map To display quality of service (QoS) policy maps, which define classification criteria for incoming traffic, use the show policy-map command in privileged EXEC mode
  • Cisco NM-8AM-V2 | User Guide - Page 231
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show policy-map The following is sample output from policy map that can be attached to multiple interfaces to specify a service policy. Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 231
  • Cisco NM-8AM-V2 | User Guide - Page 232
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show spanning-tree To display spanning-tree information for the specified spanning-tree instances, use each interface separated by a space. Ranges are not supported. Valid interfaces include physical ports and VLANs. (Optional)
  • Cisco NM-8AM-V2 | User Guide - Page 233
    and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show spanning-tree Switch# show spanning-tree vlan 1 Spanning tree 1 is executing the IEEE compatible Spanning Tree protocol Bridge Identifier has priority 32768, address 00e0.1eb2.ddc0 Configured
  • Cisco NM-8AM-V2 | User Guide - Page 234
    show spanning-tree 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Designated bridge has priority 32768, address 00e0.1eb2.ddc0 Designated port is 1, path cost 10 Timers: message age 0, forward delay 0, hold 0 BPDU: sent 0,
  • Cisco NM-8AM-V2 | User Guide - Page 235
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show storm-control show storm-control To display the packet-storm control information, use the show storm-control command in privileged EXEC mode. This command also displays the action that the
  • Cisco NM-8AM-V2 | User Guide - Page 236
    36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Table new storm of a different type occurs before the current storm ends. Related Commands Command storm-control Description Enables broadcast, multicast, or unicast storm control on a port. 236 Cisco
  • Cisco NM-8AM-V2 | User Guide - Page 237
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series spanning-tree backbonefast spanning-tree backbonefast To enable the BackboneFast feature, use the spanning-tree backbonefast command in global configuration mode. To return to the default setting
  • Cisco NM-8AM-V2 | User Guide - Page 238
    -control 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series storm-control To enable broadcast, multicast, or unicast storm control on a port and to specify the action taken when a storm occurs on a port, use the storm-control command in interface
  • Cisco NM-8AM-V2 | User Guide - Page 239
    36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series storm-control Usage Guidelines Use the storm-control command to enable or disable broadcast, multicast, or unicast storm control on a port. After a port is disabled during a storm, use the no shutdown
  • Cisco NM-8AM-V2 | User Guide - Page 240
    switchport 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series switchport To set an interface that is in Layer 3 mode into Layer 2 mode for Layer 2 configuration, use the switchport command in interface configuration mode. To set an interface in
  • Cisco NM-8AM-V2 | User Guide - Page 241
    16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series switchport Note The switchport command without keywords is not used on platforms that do not support Cisco-routed ports. All physical ports on such platforms are assumed to be Layer 2-switched
  • Cisco NM-8AM-V2 | User Guide - Page 242
    based weighted fair queuing. Extends the standard WFQ functionality to provide support for user-defined traffic classes. CCN-Cisco Communications Network (Cisco services code point. In QoS, a modification of the type of service byte. Six bits of this byte are being reallocated for use as
  • Cisco NM-8AM-V2 | User Guide - Page 243
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Glossary DSL-digital subscriber line. Public network other at the customer site. Because most DSL technologies do not use the whole bandwidth network. General term referring to the variety of telephone networks and services
  • Cisco NM-8AM-V2 | User Guide - Page 244
    . The RMON specification provides numerous monitoring, problem detection, and reporting capabilities. RSVP-Resource Reservation Protocol. Protocol that supports the reservation of resources across an IP network. Applications running on IP end systems can use RSVP to indicate to other nodes the
  • Cisco NM-8AM-V2 | User Guide - Page 245
    Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Glossary VQP-VLAN Query Protocol. VTP-VLAN Trunking Protocol. WAN-wide area network. A communications network by assigning a weight to each flow, where lower weights are the first to be serviced. WRR-Weighted Round-Robin. Type
  • Cisco NM-8AM-V2 | User Guide - Page 246
    Glossary 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series 246 Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246

1
Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ
16- and 36-Port Ethernet Switch Module for
Cisco 2600 Series, Cisco 3600 Series, and
Cisco 3700 Series
Feature History
This feature module describes the 16- and 36-Port Ethernet Switch Module (NM-16ESW and
NM-36ESW) for Cisco 2600 series, Cisco 3600 series, and Cisco 3700 series routers in
Cisco IOS Release 12.2(2)XT and Cisco IOS Release 12.2(8)T and above. Enhancements were added in
Cisco IOS Release 12.2(15)ZJ.
This document includes the following sections:
Feature Overview, page 2
Supported Platforms, page 45
Supported Standards, MIBs, and RFCs, page 45
Prerequisites, page 46
Configuration Tasks, page 46
Configuration Examples for the 16- and 36-Port Ethernet Switch Module, page 130
Command Reference, page 157
Glossary, page 242
Release
Modification
12.2(2)XT
This feature was introduced on the Cisco
2600
series, Cisco
3600
series, and
Cisco 3700 series routers.
12.2(8)T
This feature was integrated into Cisco IOS Release 12.2(8)T.
12.2(15)ZJ
Added switching software enhancements: IEEE 802.1x, QoS (including
Layer 2/Layer 3 CoS/DSCP mapping and rate limiting), security ACL,
IGMP snooping, per-port storm control, and fallback bridging support for
switch virtual interfaces (SVIs).