Page 2 - Configuration Guide Page 2 of 55
Configuration Guide Page 2 of 55 Table of Contents Table of Contents Table of Contents Table of Contents p pp page age age age 1.0 IP-Address and Secondary Addresses configuration .............................................. 4 1.1 IP-Static-routing.....................................................
Page 3 - Configuration Guide Page 3 of 55; Appendix; Helpful commands for using the XSR platform:
Configuration Guide Page 3 of 55 9.0r1 VPN IPSEC site-to-site tunnel via pre-shared key .............................................. 31 9.0r2 VPN IPSEC site-to-site tunnel via pre-shared key .............................................. 32 9.1 VPN IPSEC site-to-site tunnel certification PKI.........
Page 5 - Configuration Guide Page 5 of 55
Configuration Guide Page 5 of 55 1.3 IP-OSPF-routing XSR-1805#show running-config!!! Version 4.0.0.0, Built Mar 26 2003, 19:47:17 !hostname XSR-1805!interface FastEthernet1description "LAN-Interface1"ip address 10.10.10.1 255.255.255.0ip address 40.40.40.1 255.255.255.0 secondaryno shutdown!...
Page 6 - Configuration Guide Page 6 of 55
Configuration Guide Page 6 of 55 1.4 IP-RIPv1,v2-routing XSR-1805#show running-config!!! Version 4.0.0.0, Built Mar 26 2003, 19:47:17 !hostname XSR-1805!interface FastEthernet1description "LAN-Interface1"ip address 10.10.10.1 255.255.255.0ip address 40.40.40.1 255.255.255.0 secondaryno shutd...
Page 7 - Configuration Guide Page 7 of 55; Hardware address
Configuration Guide Page 7 of 55 1.5 DHCP server, static / dynamic-pool 1.6 DHCP/Bootp relay argent / ip-helper XSR-1805#show running-config!!! Version 4.0.0.0, Built Mar 26 2003, 19:47:17 !hostname XSR-1805!interface FastEthernet1description "LAN-Interface1"ip address 10.10.10.1 255.255.255...
Page 9 - Welcome on Enterasys Networks
Configuration Guide Page 9 of 55 2.0 Interface description 2.1 Duplex configuration on Fast Ethernet full/half 2.2 Speed configuration on Fast Ethernet 10/100MBit/s XSR-1805#show running-config!!! Version 4.0.0.0, Built Mar 26 2003, 19:47:17 !hostname XSR-1805!interface FastEthernet1description "...
Page 12 - Configuration Guide Page 12 of 55
Configuration Guide Page 12 of 55 4.0 Virtual Router Redundancy Protocol (RFC 2338) Router-1-Master XSR-1805_1#show running-config!!! Version 4.0.0.0, Built Mar 26 2003, 19:47:17 !hostname XSR-1805_1!interface FastEthernet1description "LAN-Interface1"ip address 10.10.10.1 255.255.255.0ip add...
Page 19 - Configuration Guide Page 19 of 55; access-list 101 permit ip
Configuration Guide Page 19 of 55 5.4.1 VPN via Dialer Interface rtr1 XSR-1805-1#show running-config!!! Version 6.0.0.9, Built Dec 12 2003, 14:56:30 !hostname XSR-1805-1!interface bri 0/1/0isdn switch-type basic-net3no shutdowndialer pool-member 1 priority 0!access-list 101 permit ip 20.20.20.0 0.0....
Page 20 - Configuration Guide Page 20 of 55; access-list 102 permit ip
Configuration Guide Page 20 of 55 5.4.2 VPN via Dialer Interface rtr2 XSR-1805-2#show running-config!!! Version 6.0.0.9, Built Dec 12 2003, 14:56:30 !hostname XSR-1805-2!interface bri 0/2/0isdn switch-type basic-net3no shutdowndialer pool-member 1 priority 0!access-list 102 permit ip 10.10.10.0 0.0....
Page 21 - Configuration Guide Page 21 of 55; authenticated username if the following conditions are met:
Configuration Guide Page 21 of 55 5.5.1 Dialer Int. PRI to BRI with D-channel-callback central-site XSR-central#show running-config!!! Version 6.0.0.9, Built Dec 12 2003, 14:56:30 !hostname XSR-central!username remote1 privilege 0 password cleartext xsr1username remote2 privilege 0 password cleartex...
Page 22 - Configuration Guide Page 22 of 55
Configuration Guide Page 22 of 55 5.5.2 Dialer Int. PRI to BRI with D-channel-callback remote1-site remote1#show running-config!!! Version 6.0.0.9, Built Dec 12 2003, 14:56:30 !hostname remote1!username central privilege 0 password cleartext xsr!interface bri 0/2/0isdn switch-type basic-net3no shutd...
Page 23 - Configuration Guide Page 23 of 55
Configuration Guide Page 23 of 55 5.5.3 Dialer Int. PRI to BRI with D-channel-callback remote2-site remote1#show running-config!!! Version 6.0.0.9, Built Dec 12 2003, 14:56:30 !hostname remote2!username central privilege 0 password cleartext xsr!interface bri 0/1/0isdn switch-type basic-net3no shutd...
Page 25 - Configuration Guide Page 25 of 55
Configuration Guide Page 25 of 55 6.2 ISDN callback XSR-1805#show running-config!!! Version 4.0.0.0, Built Mar 26 2003, 19:47:17 !hostname XSR-1805!interface bri 1/0isdn switch-type basic-net3no shutdowndialer pool-member 1 priority 0!access-list 110 permit ip any any !interface FastEthernet1descrip...
Page 29 - Configuration Guide Page 29 of 55; SSH and Telnet are enabled by default
Configuration Guide Page 29 of 55 8.1 SSH / Telnet SSH and Telnet are enabled by default SSH and Telnet are enabled by default SSH and Telnet are enabled by default SSH and Telnet are enabled by default XSR-1805#show running-config!!! Version 4.0.0.0, Built Mar 26 2003, 19:47:17 !hostname XSR-1805!i...
Page 30 - Configuration Guide Page 30 of 55
Configuration Guide Page 30 of 55 8.3 SNMP configuration /contact/location/parameter XSR-1805#show running-config!!! Version 4.0.0.0, Built Mar 26 2003, 19:47:17 !hostname XSR-1805logging 10.10.10.100logging Console low logging Monitor high logging Buffered debug logging SNMP medium !interface FastE...
Page 31 - Configuration Guide Page 31 of 55
Configuration Guide Page 31 of 55 9.0r1 VPN IPSEC site-to-site tunnel via pre-shared key Router-1 XSR-1805_1#show running-config!!! Version 4.0.0.0, Built Mar 26 2003, 19:47:17 !hostname XSR-1805_1!crypto isakmp proposal prop-map1authentication pre-sharegroup 5lifetime 10800!access-list 101 permit i...
Page 32 - Configuration Guide Page 32 of 55
Configuration Guide Page 32 of 55 9.0r2 VPN IPSEC site-to-site tunnel via pre-shared key Router-2 XSR-1805_2#show running-config!!! Version 4.0.0.0, Built Mar 26 2003, 19:47:17 !hostname XSR-1805_2!crypto isakmp proposal prop-map1authentication pre-sharegroup 5lifetime 10800!access-list 101 permit i...
Page 33 - Configuration Guide Page 33 of 55
Configuration Guide Page 33 of 55 9.1 VPN IPSEC site-to-site tunnel certification PKI XSR-1805_1#show running-config!!! Version 4.0.0.0, Built Mar 26 2003, 19:47:17 !hostname XSR-1805_1!crypto isakmp proposal prop-map1authentication rsa-siggroup 5lifetime 10800!access-list 101 permit ip 10.10.10.0 0...
Page 34 - Configuration Guide Page 34 of 55
Configuration Guide Page 34 of 55 Issue Certificate via SCEP protocol to XSR Issue Certificate via SCEP protocol to XSR Issue Certificate via SCEP protocol to XSR Issue Certificate via SCEP protocol to XSR from from from from Wi Wi Wi Winnnndows dows dows dows 2000 2000 2000 2000 CA CA CA CA:::: 1.X...
Page 35 - Configuration Guide Page 35 of 55
Configuration Guide Page 35 of 55 9.1.1 Certification control / certificates / CRLS / CA identity XSR-1805_1#show crypto ca certificatesCertificate - issued by Enterasys-Networks-CA State: ENTITY-ACTIVE Version: V3 Serial Number: 458876448087542442491910 Issuer: [email protected],. . . , ...
Page 37 - Configuration Guide Page 37 of 55
Configuration Guide Page 37 of 55 9.4r1 GRE encapsulated in IPSEC site-to-site tunnel via pre-shared key Router-1 XSR-1805_1#show running-config!!! Version 6.0.0.0, Built Sep 14 2003, 11:09:28 !hostname XSR-1805_1!crypto isakmp proposal prop-map1authentication pre-sharegroup 5lifetime 10800!access-l...
Page 38 - Configuration Guide Page 38 of 55
Configuration Guide Page 38 of 55 9.4r2 GRE encapsulated in IPSEC site-to-site tunnel via pre-shared key Router-2 XSR-1805_2#show running-config!!! Version 6.0.0.0, Built Sep 14 2003, 11:09:28 !hostname XSR-1805_2!crypto isakmp proposal prop-map1authentication pre-sharegroup 5lifetime 10800!access-l...
Page 39 - Configuration Guide Page 39 of 55
Configuration Guide Page 39 of 55 9.5r1 GRE native site-to-site tunnel Router-1 XSR-1805_1#show running-config!!! Version 6.0.0.0, Built Sep 14 2003, 11:09:28 !hostname XSR-1805_1!access-list 101 permit gre any any access-list 101 deny ip any any !interface FastEthernet 1description "LAN-Interfa...
Page 40 - Configuration Guide Page 40 of 55
Configuration Guide Page 40 of 55 9.5r2 GRE native site-to-site tunnel Router-2 XSR-1805_2#show running-config!!! Version 6.0.0.0, Built Sep 14 2003, 11:09:28 !hostname XSR-1805_2!access-list 101 permit gre any any access-list 101 deny ip any any !interface FastEthernet 1description "LAN-Interfa...
Page 43 - Configuration Guide Page 43 of 55
Configuration Guide Page 43 of 55 12.1 Vlan configuration 802.1q tagged routing XSR-1805#show running-config!!! Version 6.0.0.0, Built Sep 14 2003, 11:09:28 !hostname XSR-1805!interface FastEthernet 1description "UnTagged-Native-Interface"ip address 11.11.11.1 255.255.255.0no ip proxy-arpno ...
Page 44 - Configuration Guide Page 44 of 55
Configuration Guide Page 44 of 55 Appendix Appendix Appendix Appendix:::: Important commands for using the XSR platform: A1.1 show version - Software, Bootrom, RAM, Flash, System Uptime XSR-1805#show versionEnterasys Networks Operating SoftwareCopyright 2002 by Enterasys Networks Inc. Hardware: Proc...
Page 45 - Configuration Guide Page 45 of 55; A1.4 telnet to other routers
Configuration Guide Page 45 of 55 A1.3 show interface - IP address, speed, duplex, statistics, errors XSR-1805#show interfaceFastEthernet1 is Admin UpDescription: LAN-Interface1Internet address is 10.10.10.1, subnet mask is 255.255.255.0 The name of this device is Eth1. The physical link is currentl...
Page 47 - Configuration Guide Page 47 of 55; Internet; FastEthernet1 is Admin Up
Configuration Guide Page 47 of 55 B1.0 show ip route XSR-1805#show ip route Codes: C-connected, S-static, R-RIP, O-OSPF, IA-OSPF interarea N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2E1 - 0SPF external type 1, E2 - 0SPF external type 2* - candidate default, D - default route origin...
Page 48 - Process Tunnel SPD
Configuration Guide Page 48 of 55 C1.0 show tunnels XSR-1805_2#show tunnels Tunnel MIB: ID Creation Time Proto Username Peer IP Packets In/Out 40000001 12/02/03, 13:21 IPSEC (Unknown) 0.0.0.0 0000003976/0000003949 XSR-1805_2# C1.1 show crypto isakmp sa XSR-1805_2#show crypto isakmp saConnection-ID S...
Page 49 - Configuration Guide Page 49 of 55; C1.6 show crypto ipsec sa / GRE via IPSEC
Configuration Guide Page 49 of 55 C1.4 show tunnels / GRE via IPSEC XSR-1805_2#show tunnels Tunnel MIB: ID Creation Time Proto Username Peer IP Packets In/Out 40000001 12/02/2003, 16:14 GRE 20.20.20.1 0000003528/0000002552 XSR-1805_2# C1.5 show interface vpn / GRE via IPSEC XSR-1805_2#show interface...
Page 50 - Configuration Guide Page 50 of 55
Configuration Guide Page 50 of 55 D1.1 show ip interface atm 1/0.1 XSR1805-ADSL#show ip interface atm 1/0.1ATM 1/0.1 is Admin Up Internet address is 212.184.161.76, subnet mask is 255.255.255.255Rcvd: 766 octets, 6 unicast packets, 0 discards, 0 errors, 0 unknown protocol. Sent: 800 octets, 8 unicas...
Page 51 - Configuration Guide Page 51 of 55; ATM PassData is TRUE
Configuration Guide Page 51 of 55 D1.3 show controllers atm 1/0.1 XSR1805-ADSL#show controllers atm 1/0.1 ********** ATM Sub-Interface Stats **********ATM 1/0.1 Packet Processor Tx Scheduler Stats:Output Q length is 0/40/40(5)48 Packet Tx OK0 Packet not Tx: drop0 Packet not Tx: MUX END_ERR_BLOCK0 Pa...
Page 52 - Configuration Guide Page 52 of 55; Administrative State is ENABLED
Configuration Guide Page 52 of 55 D1.4 show interface atm 1/0 XSR1805-ADSL #show interface atm 1/0 ********** ATM Interface Stats **********ATM 1/0 is Admin Up / Oper UpDescription: "ADSL-connection" The name of this device is adsl. Administrative State is ENABLED Operational State is UP. Th...
Page 53 - Configuration Guide Page 53 of 55; IPCP
Configuration Guide Page 53 of 55 D1.5 show interface atm 1/0.1 XSR1805-ADSL #show interface atm 1/0.1 ********** ATM Sub-Interface Stats **********ATM 1/0.1 is Admin Up / Oper Up Internet address is 212.184.161.76, subnet mask is 255.255.255.255LCP State: OPENED IPCP State: OPENED PPPoE is Oper UpT...
Page 54 - Configuration Guide Page 54 of 55; OPENED
Configuration Guide Page 54 of 55 D1.6 show ppp interface atm 1/0.1 XSR1805-ADSL#show ppp interface atm 1/0.1 ********** PPP Stats **********ATM 1/0.1: PPP is Admin Up / Oper UpLCP Current State: OPENED IPCP Current State: OPENED LCP STATSTotal Rcv Pck: 40 Total Rcv Control Pck: 26 Total Rcv Data Pc...
Page 55 - Configuration Guide Page 55 of 55; Getting Help
Configuration Guide Page 55 of 55 Getting Help Getting Help Getting Help Getting Help For additional support related to the XSR, contact Enterasys Networks using one of the following methods: World Wide Web World Wide Web World Wide Web World Wide Web http://www.enterasys.com http://www.enterasys.co...