Page 1
Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x First Published: 2013-04-29 Last Modified: 2018-02-15 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883...
Page 2
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks . Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company.
Adding Ports to a VLAN Triggering the VLAN Membership Consistency Checker Configuring a VLAN as a Routed SVI Configuring a VLAN as a Management SVI Configuring VTP Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 4
Understanding Allowed VLANs Understanding Native 802.1Q VLANs Configuring Access and Trunk Interfaces Configuring a LAN Interface as an Ethernet Access Port Configuring Access Host Ports Configuring Trunk Ports Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 5
Creating the Spanning Tree Topology Understanding Rapid PVST+ Rapid PVST+ Overview Rapid PVST+ BPDUs Proposal and Agreement Handshake Protocol Timers Port Roles Port States Rapid PVST+ Port State Overview Blocking State Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 6
Triggering the VLAN STP State Consistency Checker Configuring Multiple Spanning Tree C H A P T E R 8 Information About MST MST Overview MST Regions MST BPDUs MST Configuration Information Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 7
Configuring the Maximum-Aging Time Configuring the Maximum-Hop Count Configuring PVST Simulation Globally Configuring PVST Simulation Per Port Specifying the Link Type Restarting the Protocol Verifying the MST Configuration Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 8
Information About Global LLDP Commands Configuring LLDP Information About LLDP Management TLV IP Addresses Configuring LLDP Management TLV IP Addresses on an Interface Configuring Interface LLDP MIBs for LLDP Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x viii OL-29545-03...
Page 9
Guidelines and Limitations for Traffic Storm Control Default Settings for Traffic Storm Control Configuring Traffic Storm Control Verifying the Traffic Storm Control Configuration Traffic Storm Control Example Configuration Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Configuring MAC Action down the port with the lower interface index Move Loop when a MAC address move loop is detected Detection, on page between two ports. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 12
Consistency Checker, on page 13 • Triggering the VLAN STP State Consistency Checker, on page 77 Added for vPC 6.0(2)U1(1) Configuring IGMP Snooping Parameters, on page 138 Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
VLAN must be forwarded through a bridge or a router. All ports are assigned to the default VLAN (VLAN1) when the device comes up. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
STP protocol. Note Cisco NX-OS uses the extended system ID and MAC address reduction; you cannot disable these features. In addition, Cisco has created some proprietary features to enhance the spanning tree activities. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x...
• Root Guard— Root guard prevents a port from becoming a root port or a blocked port. If you configure a port with root guard then the port receives a superior BPDU and it immediately goes to root-inconsistent (blocked) state. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
VLAN must be forwarded through a router. The following figure shows VLANs as logical networks. The stations in the engineering department are assigned to one VLAN, Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
VLANs into ranges, and you use each range slightly differently. For information about configuration limits, see the configuration limits documentation for your switch. This table describes the VLAN ranges. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Depending on the range of the VLAN, you can configure the following parameters for VLANs (except the default VLAN): • VLAN name • Shutdown or not shutdown Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
• SNMP can perform GET and SET operations on the CISCO-VTP-MIB objects. • VTP server mode and VTP client mode are not supported. The only supported mode is transparent mode, which is the default mode. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
This example shows how to create a range of VLANs from 15 to 20: switch# configure terminal switch(config)# vlan 15-20 You can also create and delete VLANs in the VLAN configuration submode. Note Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
VLANs 1006 to 4094. This example shows how to configure optional parameters for VLAN 5: switch# configure terminal switch(config)# vlan 5 switch(config-vlan)# name accounting switch(config-vlan)# state active switch(config-vlan)# no shutdown Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
You can configure a VLAN to be a routed switch virtual interface (SVI). Before You Begin • Install the Layer 3 license. For more information, see License and Copyright Information for Cisco NX-OS Software available at the following URL: http://www.cisco.com/en/US/docs/switches/datacenter/ sw/4_0/nx-os/license_agreement/nx-ossw_lisns.html.
[brief | id [vlan_id | vlan_range] | name name | Displays selected configuration summary ] information for the defined VLAN(s). Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
VLAN. The secondary VLAN ID differentiates one subdomain from another. The secondary VLANs can either be isolated VLANs or community VLANs. A host on an isolated VLAN can communicate only with Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
VLANs or in any isolated VLANs at the Layer 2 level. Private VLAN Ports The three types of PVLAN ports are as follows: Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
VLANs in a PVLAN domain. The ports within one community can communicate, but these ports cannot communicate with ports in any other community or isolated VLAN in the private VLAN. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
VLAN are brought down. You can associate a secondary VLAN with only one primary VLAN. Note For an association to be operational, the following conditions must be met: Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
• Configure interfaces connected to default gateways and selected end stations (for example, backup servers) as promiscuous ports to allow all end stations access to a default gateway. Guidelines and Limitations for Private VLANs When configuring PVLANs, follow these guidelines: Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Configuring a VLAN as a Private VLAN To create a PVLAN, you first create a VLAN, and then configure that VLAN to be a PVLAN. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
• The secondary-vlan-list parameter can contain multiple community VLAN IDs and one isolated VLAN • Enter a secondary-vlan-list or use the add keyword with a secondary-vlan-list to associate secondary VLANs with a primary VLAN. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
VLANs. Configuring a PVLAN host port involves two steps. First, you define the port as a PVLAN host port and then you configure a host association between the primary and secondary VLANs. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
First, you define the port as a promiscuous port and then you configure the mapping between a secondary VLAN and the primary VLAN. Before You Begin Ensure that the PVLAN feature is enabled. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
You must associate the primary and secondary VLANs before they become operational on the private Note VLAN isolated trunk port. Before You Begin Ensure that the private VLAN feature is enabled. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 39
VLANs to the isolated trunk port, the system switch(config-if)# switchport automatically puts all the primary VLANs into the private-vlan trunk allowed vlan add 1 allowed VLAN list for this port. switch(config-if)# Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 40
VLAN, to pass native VLAN traffic. Do not configure primary VLAN as part Note of allowed VLAN list. Step 7 Enter one of the following commands Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 41
Removes the private private-vlan VLAN association from association trunk the private VLAN [primary-vlan-id isolated trunk port. [secondary-vlan-id]] Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 42
1 switch(config-if)# switchport private-vlan association trunk 10 101 switch(config-if)# switchport private-vlan association trunk 20 201 Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Sets the native VLAN for the 802.1Q trunk. Valid values are from 1 to 3968 and 4048 to 4093. The default value is 1. Example: switch(config-if)# switchport private-vlan trunk native vlan 5 Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 44
Exits the interface configuration mode. Example: switch(config-if)# exit switch(config)# Step 9 show interface switchport (Optional) Displays information on all interfaces configured as switch ports. Example: switch# show interface switchport Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
The range is from 1 to 4094. You can enter a string of VLAN-IDs. • all—Accepts all the VLAN IDs (C-VLAN) entering the switch from the customer network. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Displays the features enabled on the switch. switch# show interface switchport Displays information on all interfaces configured as switch ports. switch# show vlan private-vlan [type] Displays the status of the PVLAN. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 47
This example shows how to display enabled features (some of the output has been removed for brevity): switch# show feature Feature Name Instance State -------------------- -------- -------- fcsp enabled interface-vlan enabled private-vlan enabled udld disabled Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
• A trunk port can have two or more VLANs configured on the interface; it can carry traffic for several VLANs simultaneously. Cisco NX-OS supports only IEEE 802.1Q-type VLAN trunk encapsulation. Note Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
To correctly deliver the traffic on a trunk port with several VLANs, the device uses the IEEE 802.1Q encapsulation (tagging) method. This tag carries information about the specific VLAN to which the frame Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
If you assign an access VLAN that is also a primary VLAN for a private VLAN, all access ports with that Note access VLAN will also receive all the broadcast traffic for the primary VLAN in the private VLAN mode. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
• On the egress side, all traffic is tagged. If traffic belongs to native VLAN it is tagged with the native VLAN ID. This feature is supported on all the directly connected Ethernet and Port Channel interfaces. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Configuring Access and Trunk Interfaces Configuring Access and Trunk Interfaces Cisco NX-OS Release 6.0(2)U2(1) introduces the tx-only option, which allows both tagged and untagged packets at ingress. You can use the vlan dot1q tag native tx-only command to perform the following functions: •...
You can specify the IDs for the VLANs that are allowed on the specific trunk port. Before you configure the allowed VLANs for the specified trunk ports, ensure that you are configuring the correct interfaces and that the interfaces are trunks. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Typically, you configure 802.1Q trunks with a native VLAN ID, which strips tagging from all packets on that VLAN. This configuration allows all untagged traffic and control traffic to transit the Cisco Nexus device. Packets that enter the switch with 802.1Q tags that match the native VLAN ID value are similarly stripped of tagging.
Displays the interface configuration switch# show interface switchport Displays information for all Ethernet interfaces, including access and trunk interfaces. switch# show interface brief Displays interface configuration information. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 58
Configuring Access and Trunk Interfaces Verifying the Interface Configuration Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
When store-and-forward switching is enabled, the switch checks each frame for cyclic redundancy check (CRC) errors before forwarding them to the network. Each frame is stored until the entire frame has been received and checked. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
• Packets with frame check sequence (FCS) errors are dropped. • For the Cisco Nexus 3064PQ platform, packets smaller than or equal to 768 bytes are dropped. • For Cisco Nexus 3016, 3064E, 3064X, and 3048 platforms, packets smaller than or equal to 560 bytes are dropped.
Cut-through switching mode and store-and-forward switching modes do not require licenses. Any feature not included in a license package is bundled with the Cisco NX-OS system images and is provided at no extra charge to you. For a complete explanation of the Cisco NX-OS licensing scheme, see the Cisco NX-OS Licensing Guide.
STP frames, which are called Bridge Protocol Data Units (BPDUs), at regular intervals. Switches do not forward these frames but use the frames to construct a loop-free path. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Bridge Priority Value The bridge priority is a 4-bit value when the extended system ID is enabled. In Cisco NX-OS, the extended system ID is always enabled; you cannot disable the extended system ID. Note Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x...
• A root port is selected. This is the port providing the best path from the bridge to the root bridge. • Ports included in the spanning tree are selected. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
By changing the STP port priority on the fiber-optic port to a higher priority (lower numerical value) than the root port, the fiber-optic port becomes the new root port. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
• Edge ports—When you configure a port as an edge port on an RSTP switch, the edge port immediately transitions to the forwarding state. (This immediate transition was previously a Cisco-proprietary feature named PortFast.) You should only configure on ports that connect to a single end station as edge ports.
Another important change is that the Rapid PVST+ BPDU is type 2, version 2, which makes it possible for the switch to detect connected legacy (802.1D) bridges. The BPDU for 802.1D is version 0. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
This proposal/agreement handshake is initiated only when a non-edge port moves from the blocking to the forwarding state. The handshaking process then proliferates step-by-step throughout the topology. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
In a stable topology with consistent port roles throughout the network, Rapid PVST+ ensures that every root port and designated port immediately transition to the forwarding state while all alternate and backup ports Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
When you enable Rapid PVST+, every port in the software, VLAN, and network goes through the blocking state and the transitory states of learning at power up. If properly configured, each LAN port stabilizes to the forwarding or blocking state. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
A LAN port in the forwarding state forwards frames. The LAN port enters the forwarding state from the learning state. A LAN port in the forwarding state performs as follows: Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
When the switch receives a proposal message on one of its ports and that port is selected as the new root port, Rapid PVST+ forces all other ports to synchronize with the new root information. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Rapid PVST+ sets the port to the blocking state and sends an agreement message. The designated port continues sending BPDUs with the proposal flag set until the forward-delay timer expires. At that time, the port transitions to the forwarding state. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
LAN interface. If a loop occurs, STP considers the port cost when selecting a LAN interface to put into the forwarding state. Table 6: Default Port Cost Bandwidth Short Path-Cost Method of Port Long Path-Cost Method of Port Cost Cost 10 Mbps 2,000,000 Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
When you connect a Cisco switch to a non-Cisco switch through an 802.1Q trunk, the Cisco switch combines the STP instance of the 802.1Q VLAN of the trunk with the STP instance of the non-Cisco 802.1Q switch. However, all per-VLAN STP information that is maintained by Cisco switches is separated by a cloud of non-Cisco 802.1Q switches.
Once you enable Rapid PVST+ on the switch, you must enable Rapid PVST+ on the specified VLANs. Rapid PVST+ is the default STP mode. You cannot simultaneously run MST and Rapid PVST+. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
STP convergence time. You can enter the hello-time keyword to override the automatically calculated hello time. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
With the switch configured as the root bridge, do not manually configure the hello time, forward-delay Note time, and maximum-age time using the spanning-tree mst hello-time, spanning-tree mst forward-time, and spanning-tree mst max-age global configuration commands. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
This example shows how to configure the access port priority of an Ethernet interface: switch# configure terminal switch(config)# interface ethernet 1/4 switch(config-if)# spanning-tree port-priority 160 You can only apply this command to a physical Ethernet interface. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
You can only apply this command to a physical Ethernet interface. Configuring the Rapid PVST+ Bridge Priority of a VLAN You can configure the Rapid PVST+ bridge priority of a VLAN. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
1 to 10 seconds. The default is 2 seconds. This example shows how to configure the hello time for a VLAN: switch# configure terminal switch(config)# spanning-tree vlan 5 hello-time 7 Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
If you have a half-duplex link physically connected point-to-point to a single port on a remote switch, you can override the default setting on the link type and enable rapid transitions. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Verifying the Rapid PVST+ Configuration Use the following commands to display Rapid PVST+ configuration information. Command Purpose show running-config spanning-tree [all] Displays the current spanning tree configuration. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
• Rapid per-VLAN spanning tree (Rapid PVST+) IEEE 802.1w defined the Rapid Spanning Tree Protocol (RSTP) and was incorporated into IEEE 802.1D. • IEEE 802.1s defined MST and was incorporated into IEEE 802.1Q. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
BPDU that the IST sends. Because the MST BPDU carries information for all instances, the number of BPDUs that need to be processed to support MSTIs is significantly reduced. Figure 13: MST BPDU with M-Records for MSTIs Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
An MSTI is local to the region; for example, MSTI 9 in region A is independent of MSTI 9 in region B, even if regions A and B are interconnected. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
The root of the subtree is the CIST regional root. The MST region appears as a virtual switch to adjacent STP switches and MST regions. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
The MST terminology is as follows: • The CIST root is the root bridge for the CIST, which is the unique instance that spans the whole network. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
STP bridge or receives an agreement proposal from an MST bridge with a different configuration or a Rapid PVST+ bridge. This definition allows two ports that are internal to a region to share a segment Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Switch A blocks (or keeps blocking) its port, which prevents the bridging loop. The block is shown as an STP dispute. Figure 16: Detecting a Unidirectional Link Failure Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
MST configuration. MST interoperates with the Cisco prestandard Multiple Spanning Tree Protocol (MSTP) whenever it Note receives prestandard MSTP on an MST port; no explicit configuration is necessary.
You must enable MST; Rapid PVST+ is the default. Changing the spanning tree mode disrupts traffic because all spanning tree instances are stopped for the Caution previous mode and started for the new mode. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Enters MST configuration mode on the system. You must be in mst configuration the MST configuration mode to assign the MST configuration parameters, as follows: • MST name • Instance-to-VLAN mapping Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
The default is an empty string. This example shows how to set the name of the MST region: switch# configure terminal switch(config)# spanning-tree mst configuration switch(config-mst)# name accounting Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Maps VLANs to an MST instance as follows: instance-id vlan vlan-range • For instance-id , the range is from 1 to 4094. • For vlan vlan-range , the range is from 1 to 4094. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Mapping Secondary VLANs to Same MSTI as Primary VLANs for Private VLANs When you are working with private VLANs on the system, all secondary VLANs must be in the same MSTI and their associated primary VLAN. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
• For hello-time seconds, specify the interval in seconds between the generation of configuration messages by the root bridge. The range is from 1 to 10 seconds; the default is 2 seconds. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
This example shows how to set the MST interface port priority for MSTI 3 on Ethernet port 3/1 to 64: switch# configure terminal switch(config)# interface ethernet 3/1 switch(config-if)# spanning-tree mst 3 port-priority 64 You can only apply this command to a physical Ethernet interface. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Configuring the Switch Priority You can configure the switch priority for an MST instance so that it is more likely that the specified switch is chosen as the root bridge. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Enters global configuration mode. Step 2 switch(config)# spanning-tree mst Configures the hello time for all MST instances. The hello hello-time seconds time is the interval between the generation of configuration Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
You set the maximum-aging timer for all MST instances on the switch with one command (the maximum age time only applies to the IST). Procedure Command or Action Purpose Step 1 switch# configure terminal Enters global configuration mode. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
You can block this automatic feature either globally or per port. You can enter the global command and change the PVST simulation setting for the entire switch while you are in interface command mode. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Sets the interface to the switch-wide MST and Rapid mst simulate pvst PVST+ interoperation that you configured using the spanning-tree mst simulate pvst global command. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Enter this command to restart the protocol negotiation (force the renegotiation with neighboring switches) on the entire switch or on specified interfaces. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
This example shows how to display the current MST configuration: switch# show spanning-tree mst configuration % Switch is not in mst mode Name [mist-attempt] Revision Instances configured 2 Instance Vlans mapped -------- --------------------------------------------------------------------- 1-12,14-41,43-4094 13,42 Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Information About STP Extensions Overview Cisco has added extensions to Spanning Tree Protocol (STP) that make convergence more efficient. In some cases, even though similar functionality may be incorporated into the IEEE 802.1w Rapid Spanning Tree Protocol (RSTP) standard, we recommend using these extensions. All of these extensions can be used with both RPVST+ and Multiple Spanning Tree Protocol (MST).
Once that port receives a BPDU, it resumes the normal spanning tree transitions. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
If the port configuration is not set to default BPDU Filtering, the edge configuration does not affect BPDU Filtering. The following table lists all the BPDU Filtering combinations. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Loop Guard is useful only in switched networks where devices are connected by point-to-point links. On a point-to-point link, a designated bridge cannot disappear unless it sends an inferior BPDU or brings the link down. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
• Loop Guard does not run on spanning tree edge ports. • Enabling Loop Guard on ports that are not connected to a point-to-point link will not work. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
This example shows how to configure all access and trunk ports connected to hosts as spanning tree edge ports: switch# configure terminal switch(config)# spanning-tree port type edge default Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Edge ports immediately transition to the forwarding state without passing through the blocking or learning state at linkup. By default, spanning tree ports are normal port types. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Configures the specified interfaces to be spanning network ports. If you enable Bridge Assurance, it automatically port type network runs on network ports. By default, spanning tree ports are normal port types. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
• no spanning-tree bpduguard—Enables BPDU Guard on the interface if it is an operational edge port and if the spanning-tree port type edge bpduguard default command is configured. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
BPDU Filtering is disabled. Before You Begin Ensure that STP is configured. Ensure that you have configured some spanning tree edge ports. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
When you enable BPDU Filtering locally on a port, this feature prevents the device from receiving or Note sending BPDUs on this port. Before You Begin Ensure that STP is configured. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Ensure that you have spanning tree normal ports or have configured some network ports. Procedure Command or Action Purpose Step 1 switch# configure terminal Enters global configuration mode. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
By default, Root Guard is disabled by default, and Loop Guard on specified ports is also disabled. Note Loop Guard runs only on spanning tree normal and network interfaces. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Nexus 3000 Series switches. If the Cisco Nexus 3000 Series switch displays the following message, it indicates that the switch receives frames with the same source MAC address on these two interfaces and that the switch learns the same MAC address on these interfaces at a very high speed.
In order to check if the MAC addresses move, enter the command: # show mac address-table notification mac-move MAC Move Notify Triggers: 1206 Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 128
By default, dynamic learning is reenabled after 180 seconds. At that point, any STP disputes or inconsistencies should be resolved. If not, the dynamic learning is disabled again. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
• Management address TLV • Port description TLV • Port VLAN ID TLV (IEEE 802.1 organizationally specific TLVs) • System capabilities TLV • System description TLV • System name TLV Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Use the port-description option to specify the port description TLV messages. Use the port-vlan option to specify the port VLAN ID TLV messages. Use the system-capabilities option to specify the system capabilities TLV messages. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
LLDP management IPv4 address configured on the port is used in the management TLV of the LLDP protocol data unit (PDU) to be sent. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 132
IPv6 address. This process follows the rules applied while selecting a management address to be sent in the LLDP management TLV for IPv4 and for IPv6. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
0dc3:0dc3:0000:0000:0218:baff:fed8:239d ipv6 This example shows how to specify the VLAN ID in the management TLV: switch# configure terminal switch(config)# interface ethernet 1/8 switch(config-if)# lldp tlv-set vlan 10 Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Total frames received in error: 2 Total frames discarded: 2 Total TLVs unrecognized: 0 MIBs for LLDP MIB Link LLDP-MIB To locate and download MIBs, go to the following URL: http://www.cisco.com/public/sw-center/netmgmt/ cmtk/mibs.shtml Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 136
Configuring LLDP MIBs for LLDP Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
The switch uses an aging mechanism, defined by a configurable aging timer, so if an address remains inactive for a specified number of seconds, it is removed from the address table. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
You can detect and limit the number of times that a MAC address moves from one port to another. This movement of MAC addresses between ports can cause loops. Until Cisco NX-OS Release 6.0(2)U3(1), when a loop was detected between two ports, MAC learning was disabled for 180 seconds. You can now configure the action of bringing down the port with the lower interface index when such a loop is detected by using the mac address-table loop-detect port-down command.
MAC table. MAC aging time can be configured in either interface configuration mode or in VLAN configuration mode. If the Cisco Nexus device is used as a Layer 2 or Layer 3 termination switch, Cisco recommends that you Note set the mac-address-table aging-time to 1800 (higher than the default ARP aging time of 1500 seconds) on all VLANs.
Configuring MAC Move Loop Detection When the number of MAC address moves between two ports exceeds a threshold, it forms a loop. Until Cisco NX-OS Release 6.0(2)U3(1), when a loop was detected between two ports, MAC learning was disabled for 180 seconds.
Verifying the MAC Address Configuration Note On Cisco Nexus 3000 and Cisco Nexus 3548 Series platforms, the self router MAC or HSRP VMAC are dynamically learned by the switch under the following condition: • When there is a transient loop in the network due to which the switch receives its own packets.
MAC addresses that are configured in the hardware, but not in the software. To manually trigger the Layer 2 consistency checker and display the results, use the following command in any mode: Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 143
Secure NTFY Ports ---------+-----------------+--------+---------+------+----+------------------ 0100.0100.0106 dynamic 0200.0100.0125 static Extra and Discrepant entries in the MAC Table VLAN MAC Address Type Secure NTFY Ports ---------+-----------------+--------+---------+------+----+------------------ 0000.0100.0109 dynamic Eth1/41 Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 144
Configuring MAC Address Tables Triggering the Layer 2 Consistency Checker Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Layer 2 forwarding decisions. Cisco NX-OS supports IGMPv2 and IGMPv3. IGMPv2 supports IGMPv1, and IGMPv3 supports IGMPv2. Although not all features of an earlier version of IGMP are supported, the features related to membership query and membership report messages are supported for all IGMP versions.
IGMPv1 does not provide an explicit IGMP leave message, so the software must rely on the membership message timeout to indicate that no hosts remain that want to receive multicast data for a particular group. Cisco NX-OS ignores the configuration of the last member query interval when you enable the fast leave Note feature because it does not check for remaining hosts.
IGMP Forwarding The control plane of the Cisco Nexus device is able to detect IP addresses but forwarding occurs using the MAC address only. When a host connected to the switch wants to join an IP multicast group, it sends an unsolicited IGMP join message, specifying the IP multicast group to join.
The default is enabled. Multicast router Configures a static connection to a multicast router. The interface to the router must be in the selected VLAN. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 149
Supports IGMPv2 hosts that cannot be explicitly tracked because of the host report suppression mechanism of the snooping fast-leave IGMPv2 protocol. When you enable fast leave, the IGMP Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
[[vlan] vlan-id] Displays IGMP snooping configuration by VLAN. show ip igmp snooping groups [[vlan] vlan-id] Displays IGMP snooping information about groups [detail] by VLAN. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 151
Switch-querier enabled, address 192.0.2.1, currently running Explicit tracking enabled Fast leave enabled Report suppression enabled Router port detection using PIM Hellos, IGMP Queries Number of router-ports: 1 Number of groups: 1 Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
When the ingress traffic reaches the traffic storm control level that is configured on the port, traffic storm control drops the traffic until the interval ends. Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
Page 154
• Shut down—When ingress traffic exceeds the traffic storm control level that is configured on a port, traffic storm control puts the port into the error-disabled state. To reenable this port, you can use either Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
You can control the number of traps generated per minute by using the snmp-server enable traps storm-control trap-rate command. By default, Cisco NX-OS takes no corrective action when traffic exceeds the configured level. Guidelines and Limitations for Traffic Storm Control When configuring the traffic storm control level, follow these guidelines and limitations: •...
This example shows how to configure traffic storm control for port channels 122 and 123: switch# configure terminal switch(config)# interface port-channel 122, port-channel 123 Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...
40 This example shows how to specify the number of Storm Control traps per minute: switch# configure terminal switch(config)# snmp-server enable traps storm-control trap-rate 100 switch(config)# Cisco Nexus 3000 Series NX-OS Layer 2 Switching Configuration Guide, Release 6.x OL-29545-03...