|
|
This chapter gives an overview of Layer 3 switching. It shows how a Layer 3 switch router fits into the network, and lists the type of interfaces used in Layer 3 switching. Also included is a list of Layer 3 switching software features with brief descriptions of selected features. This chapter includes the following sections:
Layer 3 switching refers to a class of high-performance routers optimized for the campus LAN or intranet, providing both wirespeed Ethernet routing and switching services.
A Layer 3 switch router performs the following three major functions:
Compared to other routers, Layer 3 switch routers process more packets faster by using application-specific integrated circuit (ASIC) hardware instead of microprocessor-based engines. Layer 3 switch routers also improve network performance with two software functions---route processing and intelligent network services.
You can use Layer 3 switching software features in both campus switch routers (CSR) and multiservice switch routers (MSR). You can also combine Layer 3 (packet switching) and ATM (cell switching) at the same time in a Catalyst 8540 MSR chassis equipped with the ATM router module.
Layer 3 switching software features are present in the Catalyst 8540 CSR, Catalyst 8540 MSR, and the Catalyst 8510 CSR.
Figure 1-1 shows how the switch router can be used as a campus backbone.

The Catalyst 8540 MSR combines Layer 3 (packet) and ATM (cell) switching on a single platform for campus and WAN networks. Figure 1-2 shows an example of a Catalyst 8540 MSR used as a campus backbone.

Table 1-1 lists the interfaces supported in Layer 3 switching.
| Interface Types | Platform | Ports Per Slot | Max. Density |
|---|---|---|---|
10/100 Mbps Fast Ethernet---UTP | Catalyst 8540 CSR Catalyst 8540 MSR | 16 | 128 |
10/100 Mbps Fast Ethernet---UTP | Catalyst 8510 CSR | 8 | 32 |
100 Mbps Fast Ethernet---multimode fiber | Catalyst 8540 CSR Catalyst 8540 MSR | 16 | 128 |
100 Mbps Fast Ethernet---multimode fiber | Catalyst 8510 CSR | 8 | 32 |
1 Gbps Gigabit Ethernet uplink | Catalyst 8540 CSR Catalyst 8540 MSR | 2 | 16 |
1 Gbps Gigabit Ethernet uplink | Catalyst 8540 CSR Catalyst 8540 MSR | 8 | 64 |
1 Gbps Gigabit Ethernet uplink | Catalyst 8510 CSR | 1 | 4 |
This section lists Layer 3 switching software features.
Layer 2 filtering:
Layer 3 filtering using an ACL daughter card:
This section briefly describes key features supported in Layer 3 switching software.
Spanning-Tree Protocol is a standardized technique for maintaining a network of multiple bridges or switches. When the topology changes, Spanning-Tree Protocol transparently reconfigures bridges and switches to avoid the creation of loops by placing ports in a forwarding or blocking state. Each VLAN is treated as a separate bridge and a separate instance of Spanning-Tree Protocol is applied to each.
Spanning-Tree Protocol parameters are set for each VLAN. For each spanning-tree instance, you configure a set of global options with a set of port parameters. The port parameter list contains only ports that are members of a given VLAN. A maximum of 64 spanning-tree instances are supported, one for each VLAN.
To configure Spanning-Tree Protocol, see the Cisco IOS Bridging and IBM Networking Configuration Guide.
Specifically, local or unroutable traffic is bridged among the bridged interfaces in the same bridge group, while routable traffic is routed to other routed interfaces or bridge groups.
Layer 3 switching software supports IRB for IP and IPX only.
Here are some examples of when to use IRB:
To configure IRB, see the "Configuring IRB" section.
Layer 3 switching software supports up to 255 VLANs per system. Because routing will take place, each VLAN is assumed to terminate at the switch router. Since this might not necessarily be the case, integrated routing and bridging (IRB) is also supported. To configure IRB, see the "About Integrated Routing and Bridging" section.
To configure VLANs, you define a subinterface at the interface, define a bridge group, and map a VLAN to the subinterface.
To configure VLANs, see the "About Virtual LANs" section.
The IEEE 802.1Q standard provides a method for secure bridging of data across a shared backbone. Layer 3 switching software supports IEEE 802.1Q VLAN encapsulation over all media including Fast Ethernet, Gigabit Ethernet, Fast EtherChannel, and GigaChannel. The Layer 3 switch router can also route and bridge between IEEE 802.1Q and ISL stations.
IEEE 802.1Q encapsulation uses an internal, or one level, packet tagging scheme to multiplex VLANs across a single physical link, while maintaining strict adherence to the individual VLAN domains. IEEE 802.1Q can have access ports---untagged ports where frames are assigned to VLANs based on a port VLAN identifier (PVID)---or a native VLAN for the port. It can also have trunked ports where some frames can be tagged and others untagged. IEEE 802.1Q uses Per VLAN Spanning-Tree Plus (PVST+), mapping multiple spanning trees to the spanning tree of pure IEEE 802.1Q switches.
For an example of how to configure IEEE 802.1Q encapsulation, see the "Configuring 802.1Q VLAN Encapsulation" section.
Layer 3 switching software also supports Inter-Switch Link (ISL) encapsulation over all media, including Fast Ethernet, Gigabit Ethernet, Fast EtherChannel, and GigaChannel. The Layer 3 switch router can be deployed in environments with ISL trunking protocol or the 802.1Q trunking protocol, and can route and bridge between ISL and 802.1Q stations.
ISL encapsulation uses an external, or two level, packet tagging scheme to multiplex VLANs across a single physical link, while maintaining strict adherence to the individual VLAN domains. With ISL, all packets must be tagged on a physical link.
ISL uses one spanning tree per VLAN (PVST) over ISL trunks.
For an example of how to configure ISL encapsulation, see the "Configuring ISL VLAN Encapsulation" section.
To configure encapsulation over EtherChannel, see the "About Encapsulation over EtherChannel" section.
You can bundle up to four gigabit Ethernet connections as one logical link, which can provide up to 8-Gb aggregate capacity on up to 64-Gb EtherChannel logical links. If a failure of any one link is detected, the packets are switched on the remaining active links in the EtherChannel.
No dependencies are placed on which ports to configure in the channel. The ports can exist on the same or on different interface modules in the chassis.
Gigabit EtherChannel uses a source-destination IP address load-balancing scheme for up to four ports in a channel group. Each channel group has its own IP address.When a packet is queued to exit out of the port channel interface, the last two bits of the IP source and destination address determine which interface in the channel the packet takes.
As with all EtherChannel technologies, the traffic load is shared across all links within the bundled ports; convergence occurs within one second of a Gigabit EtherChannel failure.
To configure the EtherChannel, see "EtherChannel Configurations."
No dependencies are placed on which ports to configure in the channel. The ports can exist on the same or on different interface modules in the chassis.
To configure the EtherChannel, see "EtherChannel Configurations."
Quality of service (QoS) includes technologies such as Resource Reservation Protocol (RSVP) and weighted fair queuing (WFQ), which help control bandwidth, network delay, jitter, and packet loss in networks that become congested. In the switch router, QoS-based forwarding sorts traffic into a small number of classes and marks the packets accordingly. The QoS identifier provides specific treatment to traffic in different classes, so that different quality of service is provided to each class.
Frame and packet scheduling and discarding policies are determined by the class to which the frames and packets belong. For example, the overall service given to frames and packets in the premium class will be better than that given to the standard class; the premium class is expected to experience lower loss rate or delay.
The switch router has QoS-based forwarding for IP traffic only. The implementation of QoS forwarding is based on local administrative policy and IP precedence. The mapping between the IP precedence field and the QoS field determines the delay priority of the packet.
For a summary of QoS features and related commands, see "Quality of Service Feature Summary."
Layer 3 switching features hot-swappable Ethernet interface modules. The redundancy of Cisco IOS software provides key network features, such as Hot Standby Router Protocol (HSRP), routing protocol convergence with Routing Information Protocol (RIP), Open Shortest Path First (OSPF), Enhanced Interior Gateway Routing Protocol (EIGRP), Fast EtherChannel, and load sharing across equal cost Layer 3 paths and spanning trees (for Layer 2 based networks).
Layer 3 switching software supports the first four remote monitoring (RMON) groups.
RMON is a network management protocol for gathering network information and monitoring traffic data within remote LAN segments from a central location. RMON allows you to monitor all nodes and their interaction on a LAN segment. RMON, used in conjunction with the SNMP agent in the switch router, allows you to view both the traffic that flows through the switch router and segment traffic not necessarily destined for the switch router. Layer 3 switching software combines RMON alarms and events with existing MIBs so you can choose where monitoring will occur.
To configure RMON, refer to the Cisco IOS Configuraton Fundamentals Configuration Guide.
Port-based snooping augments the RMON events and alarms. Port-based snooping, or mirroring, lets you transparently mirror traffic from an individual source port or multiple source ports to a destination port. Typically, the destination port has a network analyzer or RMON probe attached.
In addition to having multiple source ports active, multiple snooping sessions can operate simultaneously. You can specify whether the source ports are mirrored for transmit, receive, or both. Up to ten ports may be monitored, but the combined bandwidth of the source ports must not exceed the bandwidth of the destination port.
To configure port-based snooping, refer to the "About Port Snooping" section.
When creating access lists, you define criteria to apply to each packet processed by the switch router; the switch router decides whether to forward or block the packet based on whether or not the packet matches the criteria in your list. Packets that do not match any criteria in your list are automatically blocked by the implicit "deny all traffic" criteria statement at the end of every access list.
The specific instructions for creating access lists and applying them to interfaces vary from protocol to protocol. Configuration of Layer 3 switching access lists is identical to the configuration methods currently employed on all Cisco routers.
For complete command information about access lists, refer to the Cisco IOS Network Protocols Configuration Guide.
Standard MAC address filtering is supported at Layer 2. IP/IPX filtering is supported at Layer 3 through the use of an ACL daughter card. For a list of supported ACLs, see the "Access Control List (ACL)" section.
ACL logging is not supported for traffic that is switched by line cards. However, ACL logging is supported for all traffic that goes to CPU (such as control packets).
Layer 3 switching software uses source + destination-based load balancing, an enhanced version of the Cisco IOS software per-destination load balancing. Essentially, this method takes certain bits from the source and destination IP addresses and maps them into a path.
Using this method has the following two benefits:
Layer 3 switching software supports load balancing for two equal-cost paths and uses the destination and source address pair to perform load balancing. Per-packet load balancing is not supported.
Layer 3 switching software provides a comprehensive suite of routing protocols based on Cisco IOS software. Table 1-2 lists supported routing protocols by networking protocol.
| IP Networks | IPX Networks | AppleTalk Networks |
|---|---|---|
RIP RIP-2 OSPF IGRP EIGRP BGP | IPX RIP EIGRP | RTMP EIGRP AURP |
Many of the Cisco IOS routing protocol features, such as route redistribution and load balancing over equal cost paths (for OSPF and EIGRP) are supported. Configuration of these routing protocols is identical to the configuration methods currently employed on all Cisco routers.
To configure network and routing protocols, see "Networking Protocol Configurations."
Each device configured for CDP sends periodic messages to a multicast address. Each device advertises at least one address at which it can receive Simple Network Management Protocol (SNMP) messages.
Devices that are running the HSRP detect a failure by sending and receiving multicast User Datagram Protocol (UDP) "hello" packets. When HSRP detects that the designated active router has failed, the selected backup router assumes control of the HSRP group's MAC and IP addresses. (You can also select a new standby router at that time.)
Layer 3 switching software supports HSRP over 10/100 Ethernet, Gigabit Ethernet, FEC, GEC, and BVI (Bridge-Group Virtual Interface).
CEF manages route distribution and forwarding by distributing routing information from the route processor (RP) to the individual Ethernet interface modules. This technology, used within the Internet, provides scalability in large campus core networks. CEF provides Layer 3 forwarding based on a topology map of the entire network, resulting in high-speed routing table lookups and forwarding.
One of the key benefits of CEF in Layer 3 switching is its routing convergence. Since the forwarding information base (FIB) is distributed to all interface modules, whenever a route goes away or is added, the FIB updates that information and provides it to the interface modules. Thus, RP interrupts are minimized. The interface modules receive the new topology very quickly and reconverge around a failed link based on the routing protocol being used.
![]()
![]()
![]()
![]()
![]()
![]()
![]()
Posted: Wed Dec 22 14:08:05 PST 1999
Copyright 1989-1999©Cisco Systems Inc.