Monday, April 4, 2011

Cisco Best Practice - Turn off http, telnet and enable https, ssh

ip domain-name cisco.local
ip ssh version 2
no ip http server
ip http secure-server
line vty 0 15
transport input ssh

Configuring Cisco EtherChannel Load Balancing Method

- Use soure and destination IP address when calculating which link to send traffic across

Switch(config)#port-channel load-balance src-dst-ip

Unidirectional Link Detection (UDLD) Cisco Switch Configuration

- Unidirectional links can cause problems such as spanning-tree loops, black holes, and non-deterministic forwarding
- Unidirectional Link Detection (UDLD) detects a Unidirectional link and disables the interface

Switch(config)#udld enable

Rapid Per-VLAN Spanning-Tree (PVST+) Cisco Switch Configuration

- Instance of RSTP per VLAN
- Improves detection of indirect failures over classic spanning tree (802.1D)
- Even if network doesn't have any layer 2 loops you still should enable spanning tree for protection against unexpected layer 2 loops

Switch(config)#spanning-tree mode rapid-pvst

Virtual Trunk Protocol (VTP) Cisco Switch Configuration Best Practices

Virtual Trunk Protocol (VTP) allows you to configure a VLAN on one switch and have it propogate to all the other switches in the network. Cisco Best Practice is to not use VTP because of the potential issues it can cause and to put the switch in transparent mode.

Switch(config)#vtp mode transparent

Enable Stateful Switchover (SSO) on Cisco Switch Supervisor Modules

Stateful Switchover (SSO) synchronizes process and configuration information between supervisor modules to enable a fast transparent failover.

Router(config)# redundancy
Router(config-red)# mode sso
Router(config-red)# end
Router# show redundancy states
my state = 13 -ACTIVE
peer state = 8 -STANDBY HOT
Mode = Duplex
Unit = Primary
Unit ID = 5

Redundancy Mode (Operational) = sso
Redundancy Mode (Configured) = sso
Split Mode = Disabled
Manual Swact = Enabled
Communications = Up

client count = 29
client_notification_TMR = 30000 milliseconds
keep_alive TMR = 9000 milliseconds
keep_alive count = 1
keep_alive threshold = 18
RF debug mask = 0x0
Router#

Set Cisco Stack Master Placement in Switch Stack

- Multiple Catalyst 2960-S or 3750-X switches configured in stack
- One switch in stack (Master Switch) controls operation of stack
- When 3 or more switches in stack configure switch that does not have uplinks as master switch

Set Stack Master Switch:
switch [switch number] priority 15

Ensure original master MAC address remains stack MAC address after failure:
stack-mac persistent timer 0