<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Switching on Aaron&#39;s Worthless Words</title>
    <link>https://38a8db03.aww-3cz.pages.dev/tags/switching/</link>
    <description>Recent content in Switching on Aaron&#39;s Worthless Words</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Sun, 07 Jul 2013 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://38a8db03.aww-3cz.pages.dev/tags/switching/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>CCIE R&amp;S Written - Epic Fail (Again)</title>
      <link>https://38a8db03.aww-3cz.pages.dev/posts/2013/07/ccie-rs-written-epic-fail-again/</link>
      <pubDate>Sun, 07 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://38a8db03.aww-3cz.pages.dev/posts/2013/07/ccie-rs-written-epic-fail-again/</guid>
      <description>&lt;p&gt;Yes, I failed.  I think it&amp;rsquo;s pretty typical when you&amp;rsquo;re at Cisco Live, you stay out drinking and smoking cigars until 01:00, then you sit the exam at 08:00 the next morning.  Considering the situation I put myself in, I wasn&amp;rsquo;t very optimistic about passing, but I figured I had maybe a 40% chance to pass since I didn&amp;rsquo;t really even study.  Are you sensing a theme of ill-preparedness and self-sabotage?  Yeah, me, too.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CCIE R&amp;S Written - Epic WIN!</title>
      <link>https://38a8db03.aww-3cz.pages.dev/posts/2011/08/ccie-rs-written-epic-win/</link>
      <pubDate>Wed, 24 Aug 2011 00:00:00 +0000</pubDate>
      <guid>https://38a8db03.aww-3cz.pages.dev/posts/2011/08/ccie-rs-written-epic-win/</guid>
      <description>&lt;p&gt;The wife and I had a romantic day driving several hours to a small town to take Cisco exams.  If this doesn&amp;rsquo;t get me some action, I don&amp;rsquo;t know what else to try.&lt;/p&gt;&#xA;&lt;p&gt;I&amp;rsquo;ve already used the phrases &amp;ldquo;skin of my teeth&amp;rdquo; and &amp;ldquo;a pass is a pass&amp;rdquo; on Twitter today for good reason.  Passing is a score of 790, and I blew that away with a 790.  One more lapse in concentration and I would have been making up more excuses instead of smiling.  I think I&amp;rsquo;ve mentioned this before, but I have this weird reaction to taking exams where I don&amp;rsquo;t get nervous at all until after I&amp;rsquo;m finished.  Walking into the testing center, I was fine.  Walking out, I was shaking like &lt;a href=&#34;http://www.cnn.com/2011/US/08/23/virginia.quake/&#34;&gt;Northern Virginia&lt;/a&gt;.  It was so bad that I could barely hold on to the door knob when trying to leave, so I guess that I&amp;rsquo;m really prouder than I thought I was.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CCIE R&amp;S Written Materials</title>
      <link>https://38a8db03.aww-3cz.pages.dev/posts/2011/06/ccie-rs-written-materials/</link>
      <pubDate>Mon, 13 Jun 2011 00:00:00 +0000</pubDate>
      <guid>https://38a8db03.aww-3cz.pages.dev/posts/2011/06/ccie-rs-written-materials/</guid>
      <description>&lt;p&gt;I&amp;rsquo;m scheduled to take the CCIE R&amp;amp;S Written exam on 10 July at Cisco Live, and I&amp;rsquo;ve been asked by a handful of people on Twitter exactly what materials I&amp;rsquo;m using.  I figured it would be a good idea to let everyone know so that we all can determine whether or not I&amp;rsquo;m on the right track.  I may get to the exam and find out that the books I&amp;rsquo;ve been reading aren&amp;rsquo;t even close.  It&amp;rsquo;s happened before.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Configuring Dedicated Trunks for the CSM</title>
      <link>https://38a8db03.aww-3cz.pages.dev/posts/2008/11/configuring-dedicated-trunks-for-the-csm/</link>
      <pubDate>Mon, 24 Nov 2008 00:00:00 +0000</pubDate>
      <guid>https://38a8db03.aww-3cz.pages.dev/posts/2008/11/configuring-dedicated-trunks-for-the-csm/</guid>
      <description>&lt;p&gt;Did you catch the article on &lt;a href=&#34;http://aconaway.com/2008/10/10/configuring-fault-tolerance-on-the-csm/&#34; title=&#34;AConaway.com -- Configuring Fault Tolerance on the CSM&#34;&gt;setting up fault tolerance on the CSM&lt;/a&gt;?  In that article, I mentioned that Cisco recommends a dedicated trunk for the FT VLAN if you have two HA CSMs in two chassis.  Discuss amongst yourselves while I drone on.&lt;/p&gt;&#xA;&lt;p&gt;Why should you set up a dedicated trunk for this stuff?  The most obvious reason is to be sure that normal traffic doesn&amp;rsquo;t step on the syncing traffic.  Since we&amp;rsquo;re syncing state information as well as configuration, the frames need to arrive in a timely manner.  Any errors could potentially disrupt the FT process, which is bad.  You surely don&amp;rsquo;t want the primary to fail only to find out that the standby doesn&amp;rsquo;t have the complete or current config.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Using CDP To Track Down Physical Connections</title>
      <link>https://38a8db03.aww-3cz.pages.dev/posts/2008/10/using-cdp-to-track-down-physical-connections/</link>
      <pubDate>Fri, 31 Oct 2008 00:00:00 +0000</pubDate>
      <guid>https://38a8db03.aww-3cz.pages.dev/posts/2008/10/using-cdp-to-track-down-physical-connections/</guid>
      <description>&lt;p&gt;We have a location that&amp;rsquo;s a few blocks down from the main office here, and we were reviewing the circuit size to make sure it was sized properly.  Since not one person knows what&amp;rsquo;s going on and the trending graphs gave us conflicting details, one of our network dudes took me down to the site to do a physical survey to see what&amp;rsquo;s going on.  Well, besides the fact that no one was there, we discovered a hodgepodge of routers and switches that were cross-connected to one another on multiple floors of the building (I really wish I could post pics to emote the effect).  It&amp;rsquo;s kind of hard to figure out what&amp;rsquo;s going on when you can&amp;rsquo;t see both ends of the cable, so we had to abandon all hope.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Using MAC Access-lists</title>
      <link>https://38a8db03.aww-3cz.pages.dev/posts/2008/10/using-mac-access-lists/</link>
      <pubDate>Mon, 27 Oct 2008 00:00:00 +0000</pubDate>
      <guid>https://38a8db03.aww-3cz.pages.dev/posts/2008/10/using-mac-access-lists/</guid>
      <description>&lt;p&gt;We ran into this today, and, though I knew it existed, I never actually saw it in the wild.  I&amp;rsquo;m talking about MAC access-lists.&lt;/p&gt;&#xA;&lt;p&gt;In the example setup, we have a DMZ off of a firewall that contains a whole mess of servers &amp;ndash; email, web, ftp, etc.  These should all be in the DMZ for sure, but they shouldn&amp;rsquo;t talk to each other.  If a bad guy was able to own my FTP server, he would have a nice platform to use to attack my email server.  That&amp;rsquo;s not cool, so we&amp;rsquo;ve put in MAC access-lists to help out.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Back to Basics -- CAM Table Population</title>
      <link>https://38a8db03.aww-3cz.pages.dev/posts/2008/07/back-to-basics-cam-table-population/</link>
      <pubDate>Mon, 14 Jul 2008 00:00:00 +0000</pubDate>
      <guid>https://38a8db03.aww-3cz.pages.dev/posts/2008/07/back-to-basics-cam-table-population/</guid>
      <description>&lt;p&gt;At the office, we reprovision servers like it&amp;rsquo;s going out of style.  It happens so often that my cabling documentation rarely matches what&amp;rsquo;s actually out in field, which is a pretty big problem when you&amp;rsquo;re trying to find to what switch port a server is connected.  I finally relegated myself to asking for the MAC address of the server, having the admin ping something, and then tracing it down through the CAM table entries of the switches.  It works, but the guys really don&amp;rsquo;t know how a switch populates its CAM table, so they always say &amp;ldquo;Why can&amp;rsquo;t you just look on the switch?  I shouldn&amp;rsquo;t have to ping anything.&amp;rdquo;  Here&amp;rsquo;s one just for the aspiring system admin.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cheat Sheets from Packetlife.net</title>
      <link>https://38a8db03.aww-3cz.pages.dev/posts/2008/05/cheat-sheets-from-packetlifenet/</link>
      <pubDate>Wed, 28 May 2008 00:00:00 +0000</pubDate>
      <guid>https://38a8db03.aww-3cz.pages.dev/posts/2008/05/cheat-sheets-from-packetlifenet/</guid>
      <description>&lt;p&gt;My friend Josh over at &lt;a href=&#34;http://blindhog.net&#34; title=&#34;Blindhog.net -- Main&#34;&gt;blindhog.net&lt;/a&gt; has found a collection of cheat sheet gems for the network dude(tte).  There&amp;rsquo;s sheets on BGP, OSPF, Subnetting, QoS, connector types, and more.  Check it out.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://packetlife.net/cheatsheets/&#34; title=&#34;Packetlife.net -- Cheat Sheets&#34;&gt;Cheat Sheets - Packetlife.net&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Storm Control</title>
      <link>https://38a8db03.aww-3cz.pages.dev/posts/2008/05/storm-control/</link>
      <pubDate>Thu, 15 May 2008 00:00:00 +0000</pubDate>
      <guid>https://38a8db03.aww-3cz.pages.dev/posts/2008/05/storm-control/</guid>
      <description>&lt;p&gt;We run a large number of LANs all over the country that are &amp;ldquo;controlled&amp;rdquo; by the particular business unit. We manage the gear, but, since they have the money and have to pay for anything we do, they make the final decision on what gets put in. Sometimes that gets out of hand, as you can well imagine.&lt;/p&gt;&#xA;&lt;p&gt;A good terrible example came up a few months ago. It seems that, at some time in the past, one site needed some more LAN ports, but, instead of calling us and having us send them another switch, one of the &amp;ldquo;technical people&amp;rdquo; there brought in a hub from home. It really irks me to see a hub on the switched LAN, but we really have no control over those decisions. They plugged the hub into one of the existing drops somewhere in the building and plugged everyone in. It worked&amp;hellip;until somebody moved one of the machines. The machine was at a desk near the hub, and the network cable, still with one end plugged into the hub, was just left lying there. A good Samaritan came by, saw that the hub was not plugged into the network (though it was through another path), and plugged it back in for us &amp;ndash; providing a nice second link from the hub to the switch stack in the closet. Take one switch stack, add a hub, insert a switching loop, bake at 350F for a few milliseconds, and you have a broadcast storm. If you don&amp;rsquo;t know already, broadcast storms are bad and eat switch CPU like the yummy cookies we baked. In this case, several 3750s were taken completely down.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Getting Started with EtherChannel</title>
      <link>https://38a8db03.aww-3cz.pages.dev/posts/2008/04/getting-started-with-etherchannel/</link>
      <pubDate>Fri, 18 Apr 2008 00:00:00 +0000</pubDate>
      <guid>https://38a8db03.aww-3cz.pages.dev/posts/2008/04/getting-started-with-etherchannel/</guid>
      <description>&lt;p&gt;In my professional life at some point, I came across someone who had a stack of Catalyst 2950 switches all trunked together with their Internet routers connected to the top of the stack. This was all well and good until they kept adding hosts to the &amp;ldquo;middle&amp;rdquo; of the stack, then they had all sorts of latency and packet loss.&lt;/p&gt;&#xA;&lt;p&gt;The old adage of your chain only being as strong as your weakest length holds true in this case. Here, the weakest link is actually the most-congested trunk, though. Let&amp;rsquo;s step through to see. A 2950 is a 10/100 switch, so a single trunk can handle 100Mbps of traffic. We have 10 of these guys, Switch1 to Switch10, all trunked to the one above and below. If a server in the center of the stack on Switch5 is sending a lot of data to the Internet routers on Switch1, the trunks off of Switch5 will start to get saturated. Switch4 has a few hosts doing the same thing, so traffic from both Switch4 and Switch5 heads towards Switch1, further filling the trunks. Same for Switch3. Same for Switch2. Next thing you know, there&amp;rsquo;s 184Mbps or so trying to go across a 100Mbps link.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VTP and You</title>
      <link>https://38a8db03.aww-3cz.pages.dev/posts/2008/04/vtp-and-you/</link>
      <pubDate>Wed, 16 Apr 2008 00:00:00 +0000</pubDate>
      <guid>https://38a8db03.aww-3cz.pages.dev/posts/2008/04/vtp-and-you/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.cisco.com/warp/public/473/21.html&#34; title=&#34;Cisco.com -- Understanding VLAN Trunk Protocol&#34;&gt;VLAN Trunk Protocol (VTP)&lt;/a&gt; is a little gem on Cisco switches that allows you configure VLANs in one place and have them appear on all of your switches. This is great for large enterprises with 8457839 switches all trunked together because who wants to configure the new VLAN for that one-off application on all 8457839 switches?&lt;/p&gt;&#xA;&lt;p&gt;VTP works by having designated VTP &lt;em&gt;servers&lt;/em&gt; (not real servers like your Linux box, but a switch) tell the rest of the switches in the network with what VLANs they should be configured. All the designated VTP &lt;em&gt;clients&lt;/em&gt; say &amp;ldquo;OK&amp;rdquo; and configure themselves with those VLANs. When you take a VLAN out of the server, all the clients take it out; when you add a new VLAN, all the clients add it as well. The server and client designation is known as the VTP &lt;em&gt;mode&lt;/em&gt;, and there&amp;rsquo;s one more to mention. When a switch is in VTP &lt;em&gt;transparent&lt;/em&gt; mode, he will see VTP from the servers but will ignore them and pass them on to the next switch as if nothing ever happened.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Setting Up VLANs on an ASA 5505</title>
      <link>https://38a8db03.aww-3cz.pages.dev/posts/2008/04/setting-up-vlans-on-an-asa-5505/</link>
      <pubDate>Tue, 01 Apr 2008 00:00:00 +0000</pubDate>
      <guid>https://38a8db03.aww-3cz.pages.dev/posts/2008/04/setting-up-vlans-on-an-asa-5505/</guid>
      <description>&lt;p&gt;I&amp;rsquo;ve had my ASA 5505 in place at home on my Comcast cable for a few weeks now, and, let me tell you, this thing rocks. I did, however, have a few problems finding a clear answer on how I could set up my VLANs. It turns out that the base license on the ASA 5505 comes with a few restrictions with regards to VLANning &amp;ndash; in particular the number of VLANs and the number of trunks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Trunking on a Catalyst Switch</title>
      <link>https://38a8db03.aww-3cz.pages.dev/posts/2008/03/trunking-on-a-catalyst-switch/</link>
      <pubDate>Fri, 21 Mar 2008 00:00:00 +0000</pubDate>
      <guid>https://38a8db03.aww-3cz.pages.dev/posts/2008/03/trunking-on-a-catalyst-switch/</guid>
      <description>&lt;p&gt;If you didn&amp;rsquo;t now already, trunks are connections between switches that carry traffic for all VLANs. It allows you to have, say, VLAN 10 and VLAN 20 on two switches appear as the same network. Unless you&amp;rsquo;re a really small shop, you&amp;rsquo;ve already dealt with trunks, so there&amp;rsquo;s no need for an introduction.&lt;/p&gt;&#xA;&lt;p&gt;Let&amp;rsquo;s say we have a Catlyst 2950 switch with multiple VLANs connected to another 2950 configured with those same VLANs. We&amp;rsquo;ll say we have VLANs 10, 20, and 30 and that the switches are connected to port F0/24 of each switch. First, let&amp;rsquo;s turn on the trunk.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
