Sunday, June 16, 2013

DO NOT Say You Don’t Know Cisco 3750


Cisco Catalyst 3750 Series Switches are enterprise-class lines of stackable and standalone switches. These switches provide high availability, scalability, security, energy efficiency, and ease of operation with innovative features such as Cisco Stack Power (available only on the Catalyst 3750-X), IEEE 802.3at Power over Ethernet Plus (PoE+) configurations, optional network modules, redundant power supplies, and Media Access Control Security (MACsec) features. The Cisco Catalyst 3750-X enhances productivity by enabling applications such as IP telephony, wireless, and video for borderless network experience.

The Cisco Catalyst 3750Series Switches are innovative switches that improve LAN operating efficiency by combining industry-leading ease of use and high resiliency for stackable switches. This product series features Cisco StackWise technology, a 32-Gbps stack interconnect that allows customers to build a unified, highly resilient switching system, one switch at a time.

For midsized organizations and enterprise branch offices, the Cisco Catalyst 3750Series eases deployment of converged applications and adapts to changing business needs by providing configuration flexibility, support for converged network patterns, and automation of intelligent network services configurations. In addition, the Cisco Catalyst 3750 Series is optimized for high-density Gigabit Ethernet deployments and includes a diverse range of switches that meet access, aggregation, or small-network backbone-connectivity requirements.

Figure1. Cisco Catalyst 3750 Series Switches for 10/100 and 10/100/1000 Access and Aggregation

Figure2. Cisco Catalyst 3750-24PS and Cisco Catalyst 3750-48PS Switches with IEEE 802.3af Power

Figure3. Cisco Catalyst 3750G-16TD Switch

Figure4. Cisco Catalyst 3750G-48TS Switch, Cisco Catalyst 3750G-48PS Switch with IEEE 802.3af Power, Cisco Catalyst 3750G-24TS-1U Switch, and Cisco Catalyst 3750G-24PS Switch with IEEE 802.3af Power



The Cisco Catalyst 3750 Series includes the following configurations:
•Cisco Catalyst 3750G-24TS-24 Ethernet 10/100/1000 ports and four Small Form-Factor Pluggable (SFP) uplinks
•Cisco Catalyst 3750G-24T-24 Ethernet 10/100/1000 ports
•Cisco Catalyst 3750G-12S-12 Gigabit Ethernet SFP ports
•Cisco Catalyst 3750-48TS-48 Ethernet 10/100 ports and four SFP uplinks
•Cisco Catalyst 3750-24TS-24 Ethernet 10/100 ports and two SFP uplinks
•Cisco Catalyst 3750-48PS-48 Ethernet 10/100 ports with IEEE 802.3af and Cisco prestandard Power over Ethernet (PoE) and four SFP uplinks
•Cisco Catalyst 3750-24PS-24 Ethernet 10/100 ports with IEEE 802.3af and Cisco prestandard PoE and two SFP uplinks
•Cisco Catalyst 3750-24FS-24 100BASE-FX Ethernet ports and two SFP uplinks
•Cisco Catalyst 3750G-24TS-1U-24 Ethernet 10/100/1000 ports and four SFP uplinks, 1-rack unit (RU) height
•Cisco Catalyst 3750G-24PS-24 Ethernet 10/100/1000 ports with IEEE 802.3af and Cisco prestandard PoE and four SFP uplinks
• Cisco Catalyst 3750G-48TS-48 Ethernet 10/100/1000 ports and four SFP uplinks
•Cisco Catalyst 3750G-48PS-48 Ethernet 10/100/1000 ports with IEEE 802.3af and Cisco prestandard PoE and four SFP uplinks
•Cisco Catalyst 3750G-24WS-24 Ethernet 10/100/1000 ports with IEEE 802.3af, Cisco prestandard PoE and two SFP uplinks and an integrated wireless LAN controller

The Cisco Catalyst 3750 Series is available with either the IP Base image or the IP Services image. The IP Base image feature set includes advanced quality of service (QoS), rate-limiting, access control lists (ACLs), static routing, Routing Information Protocol (RIP) and EIGRP stub routing, capabilities. The IP Services image provides a richer set of enterprise-class features, including advanced hardware-based IPv6 and multicast routing.

Note: More Cisco Catalyst 3750 Data Sheet: Cisco StackWise Technology offers Stackable Resiliency, Cisco EnergyWise Technology, Ease of Use: "Plug-and-Play" Configuration, Mix-and-Match Switch Types: Pay as You Expand Your Network, Management Options, etc. You can visit:http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps5023/product_data_sheet0900aecd80371991.html

More Cisco Catalyst 3750 Related:



Friday, June 7, 2013

Cisco ASA 5505 License Upgrade


There are several license options for the Cisco ASA 5505 firewall as shown below:
Description
Performance
Part Number
Cisco ASA 5505 10 User Firewall Edition Bundle
Includes: 10 users, 8-port Fast Ethernet switch with 2 Power over Ethernet ports, 10 IPsec VPN peers, 2 SSL VPN peers, Triple Data Encryption Standard/Advanced Encryption Standard (3DES/AES) license
• 150 Mbps Firewall
• 100 Mbps IPsec VPN
ASA5505-BUN-K9
Cisco ASA 5505 10 User Firewall Edition Bundle
Includes: 10 users, 8-port Fast Ethernet switch with 2 Power over Ethernet ports, 10 IPsec VPN peers, 2 SSL VPN peers, Data Encryption Standard (DES) license
• 150 Mbps Firewall
• 100 Mbps IPsec VPN
ASA5505-K8
Cisco ASA 5505 50 User Firewall Edition Bundle
Includes: 50 users, 8-port Fast Ethernet switch with 2 Power over Ethernet ports, 10 IPsec VPN peers, 2 SSL VPN peers, 3DES/AES license
• 150 Mbps Firewall
• 100 Mbps IPsec VPN
ASA5505-50-BUN-K9
Cisco ASA 5505 Unlimited User Firewall Edition Bundle
Includes: Unlimited users, 8-port Fast Ethernet switch with 2 Power over Ethernet ports, 10 IPsec VPN peers, 2 SSL VPN peers, 3DES/AES license
• 150 Mbps Firewall
• 100 Mbps IPsec VPN
ASA5505-UL-BUN-K9
Cisco ASA 5505 Security Plus Firewall Edition Bundle
Includes: Unlimited users, 8-port Fast Ethernet switch with 2 Power over Ethernet ports, 25 IPsec VPN peers, 2 SSL VPN peers, DMZ support, Stateless Active/Standby high availability, Dual ISP support, 3DES/AES license
• 150 Mbps Firewall
• 100 Mbps IPsec VPN
ASA5505-SEC-BUN-K9

A very common scenario for a small business is to initially order a 10 user license and then upgrade to 50 users as the company expands. You need to order via your local Cisco representative a 10-to-50 user license upgrade. The Cisco reseller will request to have the ASA 5505 serial number of your firewall which you can find by executing the “show version” command. After that, the Cisco reseller will provide you with a license key which is a long hexadecimal string (e.g e02888da 4ba7bed6 f1c123ae ffd8624e).

To configure the new license key use the following command:
Cisco-ASA(config)# activation-key Hex-activation-key
Cisco-ASA(config)# exit
Cisco-ASA# wr mem
Cisco-ASA# reload

After the firewall reboots, run the “show version” command to verify that the license features have been upgraded. The same procedure works also for the other Cisco ASA models.

More Cisco ASA News and Reviews:

Friday, May 31, 2013

ASA 5505, 5510 Base Vs. Security Plus License


The two smallest ASA Firewall models, the ASA 5505 and the Cisco 5510, are the only ones that have two types of licenses. They can be ordered either with a Base License or a Security Plus License.


Many customers of mine are always asking me what the difference is between the two licenses (except from the price of course), so I thought it would be useful to summarize below the differences between the two license types:
Base License
Security Plus License
10,000 Maximum Firewall Connections
25,000 Maximum Firewall Connections
10 Maximum VPN Sessions (site-to-site and remote access)
25 Maximum VPN Sessions (site-to-site and remote access)
3 Maximum VLANs (Trunking Disabled)(2 regular zones and 1 restricted zone that can only communicate with 1 other zone)
20 Maximum VLANs (Trunking enabled)(No restrictions of traffic flow between zones)
No High Availability (failover) supported
Supports Stateless Active/Standby failover

Base License
Security Plus License
50,000 Maximum Firewall Connections
130,000 Maximum Firewall Connections
5×10/100Integrated Network Interfaces
2×10/100/1000 and3×10/100
Integrated Network Interfaces
50 Maximum VLANs
100 Maximum VLANs
No High Availability (failover) supported
Supports Active/ActiveandActive/Standby failover
No Security Contexts (Virtual Firewalls)
Supports 2 Virtual Firewalls (included) and 5 maximum.
No Support for VPN Clustering and VPN Load Balancing
Supports VPN Clustering and VPN Load Balancing

More Cisco ASA Info and Tips:

Tuesday, May 28, 2013

Which Cisco ASA Models Support IPS Module?



The Cisco ASA 5500 appliance supports an Intrusion Detection/Intrusion Prevention plug-in module (AIP-SSM). However not all models support this. Specifically only the middle-range models support it. The lowest-end model (5505) and the highest-end models (asa 5550, ASA 5580) does not support the AIP-SSM IPS module.

ASA Models that support IPS Module:

Basically the ASA 5505 cannot support the AIP-SSM because of its small size. Also, the 5550 cannot support the module because its hardware is occupied with much more integrated network ports compared with other models (it has 8-10/100/1000 and 4 gigabit SFP ports). The highest-end asa 5580 does not support the module because an IPS inline module in the ASA 5580 series would decrease its packet forwarding performance (remember that the Cisco ASA 5580 is usually used in high traffic environments).

More…


Thursday, May 23, 2013

Layer 3 Switches vs. Cisco Routers



In general, a Layer-3 switch (routing switch) is primarily a switch (a Layer-2 device) that has been enhanced or taught some routing (Layer 3) capabilities. A router is a Layer-3 device that simply does routing only. In the case of a switching router, it is primarily a router that may use switching technology (high-speed ASICs) for speed and performance (as well as also supporting Layer-2 bridging functions).

As illustration, here are some examples
Layer-2 switches
Cisco: Catalyst 2950, 2960 series

Layer-3 switches or routing switches
Cisco: Catalyst 3550, 3560, 3750, 4500, 6500 series
Juniper: EX series

Routers (with some bridging and/or security features) or switching routers
Cisco: 1800, 1900, 2600, 2800, 2900, 3700, 3800, 3900, 7200, 7600, ASR 1000 series
Juniper: MX series, J series, M series

Several factors have created significant confusion surrounding the subject of Layer-3 switch and Layer-3 switching. Some of this bewilderment arises from the recent merging of several technologies. In the past, switches and routers have been separate and distinct devices. The term switch was reserved for hardware-based platforms that generally functioned at Layer-2. For example, ATM switches perform hardware-based forwarding of fixed-length cells whereas Ethernet switches use MAC addresses to make forwarding decisions. Conversely, the term router has been used to refer to a device that runs routing protocols to discover the Layer-3 topology and makes forwarding decisions based on hierarchical Layer-3 addresses. Because of the complexity of these tasks, routers have traditionally been software-based devices. Routers have also performed a wide variety of "high touch" and value added features such as tunneling, data-link switching (DLSw), protocol translation, access lists, and Dynamic Host Configuration Protocol (DHCP) relay.

To understand better of switching router and routing switch differences, following is an illustration. In early Cisco switches (i.e. Catalyst 3500 switches), there are only basic Layer-2 capabilities such as bridging and switching. With newer models (i.e. Catalyst 3550 or 3560 switches), there are also some routing capabilities such as terminating multiple Layer-3 interfaces and running dynamic routing protocol. In router world, early Cisco routers (i.e. 1600 or 2500 model), there are only basic Layer-3 capabilities such as running dynamic routing protocol, terminating Serial ports, and running non-IP protocols such as IPX and SNA. With newer models (i.e. 1700, 1800, 2600 or 2800 models), there are also some Layer-2 capabilities such as bridging and switching. In addition there are some WIC (WAN Interface Cards) and NM (Network Modules) with Ethernet ports supporting bridging and switching in those newer router models even further such as WIC-4ESW Ethernet Switching card for 1700 series, HWIC-4ESW High-Density Ethernet Switching card for 1800 and 2800 series, and NM-16ESW Ethernet Switching module for 2600 and 2800 series.

As a broad category, routing switches use hardware to create shortcut paths through the middle of the network, by bypassing the traditional software-based router. However, unlike traditional routers that utilize general-purpose CPUs for both control-plane and data-plane functions, Layer-3 switches use high-speed application specific integrated circuits (ASICs) in the data plane. By removing CPUs from the data-plane forwarding path, wire-speed performance can be obtained. This results in a much faster version of the traditional router. In Cisco world, this routing switch ASIC technology implementation as example applies to Catalyst 6500 switch series. These kind of switches are typically blade or module based switch which you have to specify which "switch brain" (called Supervisor Engine in Cisco world) and which port modules you like the switch to have.

In the case of a switching router as primarily a router that uses switching technology (high-speed ASICs) for speed and performance (as well as also supporting Layer-2 bridging functions), there are Cisco 7600 series and Juniper MX series routers as examples. These kind of routers are typically blade or module-based router which you have to specify which "router brain" (also called Supervisor Engine in Cisco world) and which port modules you like the router to have.

Further, the Cisco 7600 series router Supervisor Engine modules are compatible with the Cisco Catalyst 6500 series switch due to identical architecture between the router and the switch. In other words, you could use the same Supervisor Engine model on either Cisco 7600 series router or Catalyst 6500 series switch.

Some network topologies as illustrations

1. Single Router

                                        Internet
                                            |
                                            | 1.1.1.0/24
                                            |
                                         Router
                                            |
                             LAN 1 with Unmanaged Switch (UM)
                                       10.0.1.0/24

2. Single Router with multiple LAN subnets

                                        Internet
                                            |
                                            | 1.1.1.0/24
                                            |
                                         Router --- LAN 2 with UM 10.0.2.0/24
                                            |
                                      LAN 1 with UM
                                       10.0.1.0/24

3. Single Router with single connection to a switch and with multiple LAN subnets (also known as "Router on A Stick" design)

                                        Internet
                                            |
                                            | 1.1.1.0/24
                                            |
                                         Router
                                            *
                                            * Single Connection to a Switch using feature  called Trunking
                                            *
                                  Layer-2 Managed Switch
                                    |       |       |
                                    |     LAN 2     |
                                    |    with UM    |
                                    |  10.0.2.0/24  |
                                    |               |
                                  LAN 1           LAN 3
                                 with UM         with UM
                               10.0.1.0/24     10.0.3.0/24

4. Single Router with Layer-3 Switch and with multiple LAN subnets

                                        Internet
                                            |
                                            | 1.1.1.0/24
                                            |
                                     Internet Router
                                            |
                                            | 10.0.0.0/24
                                            |
                                      Layer-3 Switch
                                     |     |       |
                                     |   LAN 2     |
                                     |   with UM   |
                                     | 10.0.2.0/24 |
                                     |             |
                                   LAN 1         LAN 3
                                  with UM       with UM
                                10.0.1.0/24   10.0.3.0/24

5. Multiple Routers with multiple unmanaged (dumb) switches and with multiple LAN subnets

                                        Internet
                                            |
                                            | 1.1.1.0/24
                                            |
                                     Internet Router
                                            |
                                            | 10.0.0.0/24
                                            |
                                   Unmanaged Switch (UM)
                                     |     |       |
                                     |  Router 2   |
                                     |     |       |
                                     |   LAN 2     |
                                     |   with UM   |
                                     | 10.0.2.0/24 |
                                     |             |
                                  Router 1      Router 3
                                     |             |
                                   LAN 1         LAN 3
                                  with UM       with UM
                                10.0.1.0/24   10.0.3.0/24

Of the variety of other switching devices and terminology released by vendors, Layer-4 and Layer-7 switching have received considerable attention. In general, these approaches refer to the capability of a switch to act on Layer 4 (transport layer) information contained in packets. For example, Transmission Control Protocol (TCP) and User Datagram Protocol (UDP) port numbers can be used to make decisions affecting issues such as security and Quality of Service (QoS). However, rather than being viewed as a third type of campus switching devices, these should be seen as a logical extension and enhancement to the two types of switches already discussed. In fact, both routing switches and switching routers can perform these upper-layer functions.

More Related Network Hardware Tips and Guides