|
|
Table Of Contents
Configuring IP Multilayer Switching
Configuring and Monitoring MLS
Monitoring MLS for an Interface
Monitoring MLS Interfaces for VTP Domains
Configuring NetFlow Data Export
Specifying an NDE Address on the Router
Multilayer Switching Configuration Examples
Router Configuration Without Access Lists Example
Router Configuration with a Standard Access List Example
Router Configuration with an Extended Access List Example
Configuring IP Multilayer Switching
This chapter describes how to configure your network to perform IP Multilayer Switching (MLS). This chapter contains these sections:
•
Configuring and Monitoring MLS
•
Configuring NetFlow Data Export
•
Multilayer Switching Configuration Examples
For a complete description of the commands in this chapter, refer to the the Cisco IOS Switching Services Command Reference. To locate documentation of other commands that appear in this chapter, use the command reference master index or search online.
To identify the hardware platform or software image information associated with a feature, use the Feature Navigator on Cisco.com to search for information about the feature or refer to the software release notes for a specific release. For more information, see the section "Identifying Supported Platforms" in the chapter "Using Cisco IOS Software."
Note
The information in this chapter is a brief summary of the information contained in the Catalyst 5000 Series Multilayer Switching User Guide. The commands and configurations described in this guide apply only to the devices that provide routing services. Commands and configurations for Catalyst 5000 series switches are documented in the Catalyst 5000 Series Multilayer Switching User Guide. For configuration information for the Catalyst 6000 series switch, see Configuring and Troubleshooting IP MLS on Catalyst 6000 with an MSFC or the "Configuring IP Multilayer Switching" chapter in the Catalyst 6500 Series MSFC (12.x) & PFC Configuration Guide.
Configuring and Monitoring MLS
To configure your Cisco router for MLS, perform the tasks described in the following sections. The first section contains a required task; the remaining tasks are optional. To ensure a successful MLS configuration, you must also configure the Catalyst switches in your network. For a full description for the Catalyst 5000 series, see the Catalyst 5000 Series Multilayer Switching User Guide. For a full description for the Catalyst 6000 series, see the "Configuring IP Multilayer Switching" chapter in the Catalyst 6500 Series MSFC (12.x) & PFC Configuration Guide. Only configuration tasks and commands for routers are described in this chapter.
•
Configuring MLS on a Router (Required)
•
Monitoring MLS (Optional)
•
Monitoring MLS for an Interface (Optional)
•
Monitoring MLS Interfaces for VTP Domains (Optional)
Configuring MLS on a Router
To configure MLS on your router, use the following commands beginning in global configuration mode. Depending upon your configuration, you might not have to perform all the steps in the procedure.
Note
The interface-specific commands in this section apply only to Ethernet, Fast Ethernet, VLAN, and Fast Etherchannel interfaces on the Catalyst RSM/Versatile Interface Processor 2 (VIP2) or directly attached external router.
To globally disable MLS on the router, use the following command in global configuration mode:
Monitoring MLS
To display MLS details including specifics for MLSP, use the following commands in EXEC mode, as needed:
•
MLS status (enabled or disabled) for switch interfaces and subinterfaces
•
Flow mask used by this MLS-enabled switch when creating Layer 3-switching entries for the router
•
Current settings of the keepalive timer, retry timer, and retry count
•
MLSP-ID used in MLSP messages
•
List of interfaces in all VTP domains that are enabled for MLS
After entering this command, you see this display:
router# show mls rpmultilayer switching is globally enabledmls id is 00e0.fefc.6000mls ip address 10.20.26.64mls flow mask is ip-flowvlan domain name: WBUcurrent flow mask: ip-flowcurrent sequence number: 80709115current/maximum retry count: 0/10current domain state: no-changecurrent/next global purge: false/falsecurrent/next purge count: 0/0domain uptime: 13:03:19keepalive timer expires in 9 secondsretry timer not runningchange timer not runningfcp subblock count = 71 management interface(s) currently defined:vlan 1 on Vlan17 mac-vlan(s) configured for multi-layer switching:mac 00e0.fefc.6000vlan id(s)1 10 91 92 93 95 100router currently aware of following 1 switch(es):switch id 0010.1192.b5ffMonitoring MLS for an Interface
To show MLS information for a specific interface, use the following command in EXEC mode:
After entering this command, you see this display:
router# show mls rp int vlan 10mls active on Vlan10, domain WBUrouter#Monitoring MLS Interfaces for VTP Domains
To show MLS information for a specific VTP domain use the following command in EXEC mode:
Command PurposeRouter# show mls rp vtp-domain [domain-name]
Displays MLS interfaces for a specific VTP domain.
After entering this command, you see this display:
router# show mls rp vtp-domain WBUvlan domain name: WBUcurrent flow mask: ip-flowcurrent sequence number: 80709115current/maximum retry count: 0/10current domain state: no-changecurrent/next global purge: false/falsecurrent/next purge count: 0/0domain uptime: 13:07:36keepalive timer expires in 8 secondsretry timer not runningchange timer not runningfcp subblock count = 71 management interface(s) currently defined:vlan 1 on Vlan17 mac-vlan(s) configured for multi-layer switching:mac 00e0.fefc.6000vlan id(s)1 10 91 92 93 95 100router currently aware of following 1 switch(es):switch id 0010.1192.b5ffConfiguring NetFlow Data Export
Note
You need to enable NDE only if you will export MLS cache entries to a data collection application.
Perform the task in this section to configure your Cisco router for NDE. To ensure a successful NDE configuration, you must also configure the Catalyst switch. For a full description, see the Catalyst 5000 Series Multilayer Switching User Guide.
Specifying an NDE Address on the Router
To specify an NDE address on the router, use the following command in global configuration mode:
Multilayer Switching Configuration Examples
In these examples, VLAN interfaces 1 and 3 are in VTP domain named Engineering. The management interface is configured on the VLAN 1 interface. Only information relevant to MLS is shown in the following configurations:
•
Router Configuration Without Access Lists Example
•
Router Configuration with a Standard Access List Example
•
Router Configuration with an Extended Access List Example
Router Configuration Without Access Lists Example
This sample configuration shows a router configured without access lists on any of the VLAN interfaces. The flow mask is configured to be destination-ip.
router# more system:running-configBuilding configuration...Current configuration:...mls rp ipinterface Vlan1ip address 172.20.26.56 255.255.255.0mls rp vtp-domain Engineeringmls rp management-interfacemls rp ipinterface Vlan2ip address 172.16.2.73 255.255.255.0interface Vlan3ip address 172.16.3.73 255.255.255.0mls rp vtp-domain Engineeringmls rp ip..endrouter#router# show mls rpmultilayer switching is globally enabledmls id is 0006.7c71.8600mls ip address 172.20.26.56mls flow mask is destination-ipnumber of domains configured for mls 1vlan domain name: Engineeringcurrent flow mask: destination-ipcurrent sequence number: 82078006current/maximum retry count: 0/10current domain state: no-changecurrent/next global purge: false/falsecurrent/next purge count: 0/0domain uptime: 02:54:21keepalive timer expires in 11 secondsretry timer not runningchange timer not running1 management interface(s) currently defined:vlan 1 on Vlan12 mac-vlan(s) configured for multi-layer switching:mac 0006.7c71.8600vlan id(s)1 3router currently aware of following 1 switch(es):switch id 00e0.fe4a.aeffRouter Configuration with a Standard Access List Example
This configuration is the same as the previous example but with a standard access list configured on the VLAN 3 interface. The flow mask changes to source-destination-ip.
.interface Vlan3ip address 172.16.3.73 255.255.255.0ip access-group 2 outmls rp vtp-domain Engineeringmls rp ip.router# show mls rpmultilayer switching is globally enabledmls id is 0006.7c71.8600mls ip address 172.20.26.56mls flow mask is source-destination-ipnumber of domains configured for mls 1vlan domain name: Engineeringcurrent flow mask: source-destination-ipcurrent sequence number: 82078007current/maximum retry count: 0/10current domain state: no-changecurrent/next global purge: false/falsecurrent/next purge count: 0/0domain uptime: 02:57:31keepalive timer expires in 4 secondsretry timer not runningchange timer not running1 management interface(s) currently defined:vlan 1 on Vlan12 mac-vlan(s) configured for multi-layer switching:mac 0006.7c71.8600vlan id(s)1 3router currently aware of following 1 switch(es):switch id 00e0.fe4a.aeffRouter Configuration with an Extended Access List Example
This configuration is the same as the previous examples but with an extended access list configured on the VLAN 3 interface. The flow mask changes to ip-flow.
.interface Vlan3ip address 172.16.3.73 255.255.255.0ip access-group 101 outmls rp vtp-domain Engineeringmls rp ip.router# show mls rpmultilayer switching is globally enabledmls id is 0006.7c71.8600mls ip address 172.20.26.56mls flow mask is ip-flownumber of domains configured for mls 1vlan domain name: Engineeringcurrent flow mask: ip-flowcurrent sequence number: 82078009current/maximum retry count: 0/10current domain state: no-changecurrent/next global purge: false/falsecurrent/next purge count: 0/0domain uptime: 03:01:52keepalive timer expires in 3 secondsretry timer not runningchange timer not running1 management interface(s) currently defined:vlan 1 on Vlan12 mac-vlan(s) configured for multi-layer switching:mac 0006.7c71.8600vlan id(s)1 3router currently aware of following 1 switch(es):switch id 00e0.fe4a.aeff
Posted: Tue Jul 25 05:13:59 PDT 2006
All contents are Copyright © 1992--2006 Cisco Systems, Inc. All rights reserved.
Important Notices and Privacy Statement.