<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SGT CCIE &#187; 3550</title>
	<atom:link href="http://www.sgtccie.com/blog/tag/3550/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sgtccie.com/blog</link>
	<description>A man on a mission</description>
	<lastBuildDate>Sat, 20 Mar 2010 03:47:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>My new CCIE rack</title>
		<link>http://www.sgtccie.com/blog/2010/02/my-new-ccie-rack/</link>
		<comments>http://www.sgtccie.com/blog/2010/02/my-new-ccie-rack/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 22:35:09 +0000</pubDate>
		<dc:creator>Mike</dc:creator>
				<category><![CDATA[CCIE]]></category>
		<category><![CDATA[CCIE general]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[2511]]></category>
		<category><![CDATA[2522]]></category>
		<category><![CDATA[2611xm]]></category>
		<category><![CDATA[3550]]></category>
		<category><![CDATA[3640]]></category>
		<category><![CDATA[ccie lab]]></category>
		<category><![CDATA[ccie rack]]></category>

		<guid isPermaLink="false">http://www.sgtccie.com/blog/?p=481</guid>
		<description><![CDATA[I&#8217;ve ordered all of the components for my CCIE rack. Here is what it will consist of: (4) 3550&#8242;s (3) 2611xm&#8217;s (3) 3640&#8242;s (instead of 1841&#8242;s) (1) 2522 (Frame switch) (3) 2501&#8242;s (BB routers) (1) 2511 (Terminal server) If you&#8217;re familiar with Internetworkexpert&#8217;s topology, you&#8217;ll probably notice that you only really &#8220;need&#8221; two BB routers [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve ordered all of the components for my CCIE rack. Here is what it will consist of:</p>
<ul>
<li>(4) 3550&#8242;s</li>
<li>(3) 2611xm&#8217;s</li>
<li>(3) 3640&#8242;s (instead of 1841&#8242;s)</li>
<li>(1) 2522 (Frame switch)</li>
<li>(3) 2501&#8242;s (BB routers)</li>
<li>(1) 2511 (Terminal server)</li>
</ul>
<p>If you&#8217;re familiar with Internetworkexpert&#8217;s topology, you&#8217;ll probably notice that you only really &#8220;need&#8221; two BB routers (the 2501&#8242;s). I purchased an extra simply as a backup, so I could expand the topology a little bit and have a wildcard in there if I chose to experiment a little more. All of the gear is going in a 24U rack, and I estimate I&#8217;ll have about 20U&#8217;s occupied with the gear above (plus PDU&#8217;s, and possibly a shelf).</p>
<p>Anyway, can&#8217;t wait for it to all arrive. In the meantime I have a lot of cleaning to do, and will be reorganizing my computer desk-area (which is no small feat!). I will post pics as the gear comes in!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sgtccie.com/blog/2010/02/my-new-ccie-rack/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Command of the week: Switchport protected</title>
		<link>http://www.sgtccie.com/blog/2009/04/command-of-the-week-switchport-protected/</link>
		<comments>http://www.sgtccie.com/blog/2009/04/command-of-the-week-switchport-protected/#comments</comments>
		<pubDate>Thu, 23 Apr 2009 00:12:26 +0000</pubDate>
		<dc:creator>Mike</dc:creator>
				<category><![CDATA[CCIE]]></category>
		<category><![CDATA[Command of the week]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Routing & Switching]]></category>
		<category><![CDATA[3550]]></category>
		<category><![CDATA[3560]]></category>
		<category><![CDATA[ACL]]></category>
		<category><![CDATA[ccna]]></category>
		<category><![CDATA[ccnp]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[layer 2]]></category>
		<category><![CDATA[PVLAN]]></category>
		<category><![CDATA[switching]]></category>
		<category><![CDATA[switchport protected]]></category>
		<category><![CDATA[VLAN]]></category>

		<guid isPermaLink="false">http://www.sgtccie.com/blog/?p=183</guid>
		<description><![CDATA[I have done my share of work in the networking field, and had never heard of this command. I have also not been exposed to a wide variety of layer 2 technologies, but I must say, that this is a very cool command. Granted, it could be considered old- or not on par with private VLAN&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>I have done my share of work in the networking field, and had <strong>never</strong> heard of this command. I have also not been exposed to a wide variety of layer 2 technologies, but I must say, that this is a very cool command. Granted, it could be considered old- or not on par with private VLAN&#8217;s (which take the same idea of isolating particular ports a little bit further), but I like it&#8217;s simplicity. However, it IS available in older catalyst switches that may not support Private VLAN&#8217;s, so that is a bonus. Last but not least,  knowing how to configure PVLAN&#8217;s and protected ports, you can accomplish- to some degree- the same thing in two different ways- which is always a plus. This article will primarily function as a basic overview of the command, although I will briefly flyby the configuration as it is fairly straightforward. Let&#8217;s get to it. First, I&#8217;ll present you a scenario that will demonstrate what switchport protected does.</p>
<p>Let&#8217;s say you have a Cisco 3550 in a closet somewhere, and for whatever reason want two hosts coming off of that 3550 to have no traffic pass between them. <strong><em>Switchport protected</em></strong> will enable you to do just that. The idea is simple: Any protected port can not talk to any other protected port, but can talk with any unprotected port. The idea here is the same as private VLAN&#8217;s somewhat..just a more basic method. There&#8217;s a few caveats worth mentioning regarding protected ports:</p>
<ul>
<li>The protection is <em>only</em> local to that switch. If you have User A on SW1, and User B on SW1, both on VLAN 100, configured with switchport protected..they will <strong>not</strong> talk. However, if you split the two users up on two switches that are trunking, but still within VLAN 100&#8230;they WILL talk. The protection does not span multiple switches!</li>
<li>The protection is limited to Layer 2. Once the frame becomes a packet at Layer 3, it will allow the two hosts to communicate. </li>
<li>To block traffic at Layer 3 also, you would need to look at ACL&#8217;s, or Vlan Access-lists, or other methods of access control. </li>
</ul>
<p>So how do we configure a port to be protected? It&#8217;s cake. See below:</p>
<p><span style="font-size: x-small;"><em>Switch(config)# interface fa0/1</em></span></p>
<p><span style="font-size: x-small;"><em>Switch(config-if)# switchport protected</em></span></p>
<p><span style="font-size: small;">That is it! I know, almost a letdown, right? Well, the plus is, there&#8217;s more! Commonly when implementing protected ports, you will want to also block unknown unicast/multicast traffic. Why? Think about the basic nature of a switch when it receives an unknown unicast frame..it will flood it out all ports except the one it was received. This could introduce a possible avenue for attack. To mitigate this risk, we can block unknown unicast/multicasts on these ports by using the following configuration.</span></p>
<p><span style="font-size: x-small;"><em>Switch(config-if)#switchport block {multicast | unicast}</em></span></p>
<p>That&#8217;s all there really is to it. I hope this short article has at least given you a small insight into small lesser-known features the Cisco IOS has to offer. I look forward to finding the next one to share with all of you!<br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.sgtccie.com/blog/2009/04/command-of-the-week-switchport-protected/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
