<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Basic Switch Configuration Best Practices in ExtremeSwitching (EOS)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15736#M181</link>
    <description>This is a good idea for a knowledge article so when we have a few more posts i will create an article for general basic L2 switch best practises and post it on this thread.&lt;BR /&gt;
&lt;BR /&gt;
Below are my recommendations:&lt;BR /&gt;
&lt;BR /&gt;
- disable gvrp unless you have a specific requirement for it&lt;BR /&gt;
&lt;BR /&gt;
- Spantree&lt;BR /&gt;
&lt;BR /&gt;
  enabled by default - leave it enabled unless you have a specific case that requires disabling (eg. router connection)&lt;BR /&gt;
  Admin edge - for all edge / user ports&lt;BR /&gt;
  Spanguard - which will operate on admin edge ports&lt;BR /&gt;
  Loop Protect - on all uplink ports to LPCapable switches&lt;BR /&gt;
  Lptrap enable&lt;BR /&gt;
  use MSTP, which is default version and configure 2 instances if there is a redundant path that would otherwise be blocked&lt;BR /&gt;
&lt;BR /&gt;
- set movedaddrtrap enable  - crucial for L2 networks to get notification of moving mac addresses in the event of a loop&lt;BR /&gt;
&lt;BR /&gt;
- LACP &lt;BR /&gt;
&lt;BR /&gt;
  use dynamic lacp ( default )&lt;BR /&gt;
  manually configure aadminkey &lt;BR /&gt;
  set spantree portenable  disable - disable bridging on lag physical member ports and restrict to logical lag port.&lt;BR /&gt;
  configure short timers where appropriate - The default timers for the lag are "long". The protocol transmits maintenance packets every 30 seconds. &lt;BR /&gt;
&lt;BR /&gt;
- Set mac multicast &lt;BR /&gt;
&lt;BR /&gt;
  If user traffic consists of NLB this will be flooded on the network as unknown so will need to be scoped by manually configuring a multicast mac and static arp&lt;BR /&gt;
  &lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/EOS-How-to-configure-multicast-mac-to-stop-flooding-of-NLB-server-traffic-via-slow-path" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/EOS-How-to-configure-multicast-mac-to-stop...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
- set forcelinkdown enable &lt;BR /&gt;
&lt;BR /&gt;
- set port disable - on any unused ports for security&lt;BR /&gt;
- set port alias - crucial to troubleshooting connectivity&lt;BR /&gt;
- set port broadcast - prevent broadcast storms propagating &lt;BR /&gt;
&lt;BR /&gt;
- set logging local console enable file enable sfile enable&lt;BR /&gt;
- set logging server   ( having syslog is crucial to troubleshooting )&lt;BR /&gt;
&lt;BR /&gt;
- set system location &lt;BR /&gt;
- set system name &lt;BR /&gt;
- set system login&lt;BR /&gt;
&lt;BR /&gt;
- set prompt &lt;BR /&gt;
&lt;BR /&gt;
- set ssh enabled &lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Thu, 02 Jul 2015 14:39:00 GMT</pubDate>
    <dc:creator>Straw__Glyn</dc:creator>
    <dc:date>2015-07-02T14:39:00Z</dc:date>
    <item>
      <title>Basic Switch Configuration Best Practices</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15728#M173</link>
      <description>What types of features/commands do people recommend when implementing basic Layer 2 switch configurations for replacements, or when building configuration templates what things do you make sure you hit?&lt;BR /&gt;
So far my list looks like:&lt;BR /&gt;
&lt;BR /&gt;
set IP&lt;BR /&gt;
Set SNTP&lt;BR /&gt;
Set Timezone&lt;BR /&gt;
Set summertime&lt;BR /&gt;
Set SNMP v3 credentials&lt;BR /&gt;
set spanguard (and adminedge)&lt;BR /&gt;
set uplinks to tagged (to reduce future downtime if changes are needed)&lt;BR /&gt;
set port alias (as applicable)&lt;BR /&gt;
&lt;BR /&gt;
What other types of recommendations or best practices do other people have?&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 01 Apr 2014 19:15:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15728#M173</guid>
      <dc:creator>Ben_Parker</dc:creator>
      <dc:date>2014-04-01T19:15:00Z</dc:date>
    </item>
    <item>
      <title>RE: Basic Switch Configuration Best Practices</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15729#M174</link>
      <description>Hey Ben&lt;BR /&gt;
&lt;BR /&gt;
It looks like you are using this in regards to EOS is that correct? If so then this is a good list.  I would also add thinks like SNMP parameters, location contact etc. Also recommend using RADIUS for switch authentication versus local accounts.&lt;BR /&gt;
&lt;BR /&gt;
If you are using XOS then there are other items like DoS Protect as well as IP security that are always good to have enabled.  You can also have them set up as a default script that are automatically set every time the switch is factory defaulted.  If you need any help there let us know.&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
P&lt;BR /&gt;</description>
      <pubDate>Tue, 01 Apr 2014 19:49:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15729#M174</guid>
      <dc:creator>Paul_Russo</dc:creator>
      <dc:date>2014-04-01T19:49:00Z</dc:date>
    </item>
    <item>
      <title>RE: Basic Switch Configuration Best Practices</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15730#M175</link>
      <description>The first thing Extreme recommends is to remove all ports from vlan &lt;I&gt;default&lt;/I&gt; and disable it (vlan &lt;I&gt;default&lt;/I&gt; can't be deleted):&lt;BR /&gt;
&lt;I&gt;configure vlan default delete ports all&lt;/I&gt;&lt;BR /&gt;
&lt;I&gt;disable vlan default&lt;/I&gt;&lt;BR /&gt;
&lt;BR /&gt;
Then you should create and configure specific vlans as needed.&lt;BR /&gt;
&lt;BR /&gt;
Daniel&lt;BR /&gt;</description>
      <pubDate>Tue, 01 Apr 2014 20:02:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15730#M175</guid>
      <dc:creator>dflouret</dc:creator>
      <dc:date>2014-04-01T20:02:00Z</dc:date>
    </item>
    <item>
      <title>RE: Basic Switch Configuration Best Practices</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15731#M176</link>
      <description>Radius/Tacacs configuration&lt;BR /&gt;
&lt;BR /&gt;
SNMP server and community - for any monitoring server&lt;BR /&gt;
&lt;BR /&gt;
NTP configuration&lt;BR /&gt;
&lt;BR /&gt;
Switch administration credentials - Read Only &amp;amp; Read Write&lt;BR /&gt;
&lt;BR /&gt;
STP or EAPS configuration - Loop prevention protocol&lt;BR /&gt;
&lt;BR /&gt;
802.1x configuration - for end user authentication&lt;BR /&gt;
&lt;BR /&gt;
Telnet/SSH configuration - for remote access&lt;BR /&gt;
&lt;BR /&gt;
Access policies for Telnet/SSH access.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 01 Apr 2014 21:09:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15731#M176</guid>
      <dc:creator>Sathish_Arul</dc:creator>
      <dc:date>2014-04-01T21:09:00Z</dc:date>
    </item>
    <item>
      <title>RE: Basic Switch Configuration Best Practices</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15732#M177</link>
      <description>Paul, &lt;BR /&gt;
Thank you. These devices are all EOS legacy-Red. I did have the system contact information included. &lt;BR /&gt;
&lt;BR /&gt;
I did not have radius included because that would require also setting up their radius.  I do need to setup NAC for the customer as well though so that might be a good idea.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 01 Apr 2014 22:22:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15732#M177</guid>
      <dc:creator>Ben_Parker</dc:creator>
      <dc:date>2014-04-01T22:22:00Z</dc:date>
    </item>
    <item>
      <title>RE: Basic Switch Configuration Best Practices</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15733#M178</link>
      <description>Hi all.&lt;BR /&gt;
&lt;BR /&gt;
I recommend to configure&lt;BR /&gt;
&lt;BR /&gt;
set forcelinkdown enable&lt;BR /&gt;
set gvrp disable&lt;BR /&gt;
set line-editor delete backspace default&lt;BR /&gt;
&lt;BR /&gt;
as well.&lt;BR /&gt;
&lt;BR /&gt;
regards&lt;BR /&gt;
Alex&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 02 Apr 2014 12:58:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15733#M178</guid>
      <dc:creator>aloeffle</dc:creator>
      <dc:date>2014-04-02T12:58:00Z</dc:date>
    </item>
    <item>
      <title>RE: Basic Switch Configuration Best Practices</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15734#M179</link>
      <description>If configuring a EOS stackable product for use in a stack, I would suggest statically configuring the SNMPv3 Engine ID.  &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;show snmp engineid&lt;/B&gt;&lt;BR /&gt;
&lt;B&gt;set snmp engineid &lt;ENGINEID&gt;&lt;/ENGINEID&gt;&lt;/B&gt;&lt;BR /&gt;
&lt;BR /&gt;
The reason for this is the Engine ID is based off the mac address of the current manager unit.  If the manager were to change from one unit to another in the stack, SNMPv3 settings would need to be reset as the Engine ID would have changed.  If the Engine ID is statically configured any subsequent manager would use what is in the stack configuration instead of their own default Engine ID.&lt;BR /&gt;</description>
      <pubDate>Wed, 02 Apr 2014 21:25:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15734#M179</guid>
      <dc:creator>Langley__Michae</dc:creator>
      <dc:date>2014-04-02T21:25:00Z</dc:date>
    </item>
    <item>
      <title>RE: Basic Switch Configuration Best Practices</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15735#M180</link>
      <description>Hello&lt;BR /&gt;
&lt;BR /&gt;
As an addition  to SNMP config I always clear default SNMP settings for public and ro access.&lt;BR /&gt;
Regarding timezone, I also use:&lt;BR /&gt;
 &lt;B&gt;set summertime recurring last Sunday March 02:00 last Sunday October 03:00 60    &lt;/B&gt;Piotr</description>
      <pubDate>Thu, 02 Jul 2015 11:08:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15735#M180</guid>
      <dc:creator>Piotr_Owczarek</dc:creator>
      <dc:date>2015-07-02T11:08:00Z</dc:date>
    </item>
    <item>
      <title>RE: Basic Switch Configuration Best Practices</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15736#M181</link>
      <description>This is a good idea for a knowledge article so when we have a few more posts i will create an article for general basic L2 switch best practises and post it on this thread.&lt;BR /&gt;
&lt;BR /&gt;
Below are my recommendations:&lt;BR /&gt;
&lt;BR /&gt;
- disable gvrp unless you have a specific requirement for it&lt;BR /&gt;
&lt;BR /&gt;
- Spantree&lt;BR /&gt;
&lt;BR /&gt;
  enabled by default - leave it enabled unless you have a specific case that requires disabling (eg. router connection)&lt;BR /&gt;
  Admin edge - for all edge / user ports&lt;BR /&gt;
  Spanguard - which will operate on admin edge ports&lt;BR /&gt;
  Loop Protect - on all uplink ports to LPCapable switches&lt;BR /&gt;
  Lptrap enable&lt;BR /&gt;
  use MSTP, which is default version and configure 2 instances if there is a redundant path that would otherwise be blocked&lt;BR /&gt;
&lt;BR /&gt;
- set movedaddrtrap enable  - crucial for L2 networks to get notification of moving mac addresses in the event of a loop&lt;BR /&gt;
&lt;BR /&gt;
- LACP &lt;BR /&gt;
&lt;BR /&gt;
  use dynamic lacp ( default )&lt;BR /&gt;
  manually configure aadminkey &lt;BR /&gt;
  set spantree portenable  disable - disable bridging on lag physical member ports and restrict to logical lag port.&lt;BR /&gt;
  configure short timers where appropriate - The default timers for the lag are "long". The protocol transmits maintenance packets every 30 seconds. &lt;BR /&gt;
&lt;BR /&gt;
- Set mac multicast &lt;BR /&gt;
&lt;BR /&gt;
  If user traffic consists of NLB this will be flooded on the network as unknown so will need to be scoped by manually configuring a multicast mac and static arp&lt;BR /&gt;
  &lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/EOS-How-to-configure-multicast-mac-to-stop-flooding-of-NLB-server-traffic-via-slow-path" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/EOS-How-to-configure-multicast-mac-to-stop...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
- set forcelinkdown enable &lt;BR /&gt;
&lt;BR /&gt;
- set port disable - on any unused ports for security&lt;BR /&gt;
- set port alias - crucial to troubleshooting connectivity&lt;BR /&gt;
- set port broadcast - prevent broadcast storms propagating &lt;BR /&gt;
&lt;BR /&gt;
- set logging local console enable file enable sfile enable&lt;BR /&gt;
- set logging server   ( having syslog is crucial to troubleshooting )&lt;BR /&gt;
&lt;BR /&gt;
- set system location &lt;BR /&gt;
- set system name &lt;BR /&gt;
- set system login&lt;BR /&gt;
&lt;BR /&gt;
- set prompt &lt;BR /&gt;
&lt;BR /&gt;
- set ssh enabled &lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Jul 2015 14:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15736#M181</guid>
      <dc:creator>Straw__Glyn</dc:creator>
      <dc:date>2015-07-02T14:39:00Z</dc:date>
    </item>
    <item>
      <title>RE: Basic Switch Configuration Best Practices</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15737#M182</link>
      <description>I published the following article in case this helps others in future:&lt;BR /&gt;
&lt;BR /&gt;
Browser  View: &lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/EOS-Basic-Switch-Layer-2-Configuration-Best-Practices" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/EOS-Basic-Switch-Layer-2-Configuration-Best-Practices&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
    Mobile View:  &lt;A href="https://gtacknowledge.extremenetworks.com/pkb_mobile#article/How_To/kA134000000LymfCAC/s" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/pkb_mobile#article/How_To/kA134000000LymfCAC/s&lt;/A&gt;  &lt;BR /&gt;
&lt;BR /&gt;
    Please let  us know if this article was helpful by submitting article feedback. Thanks!  &lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Jul 2015 16:52:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15737#M182</guid>
      <dc:creator>Straw__Glyn</dc:creator>
      <dc:date>2015-07-02T16:52:00Z</dc:date>
    </item>
    <item>
      <title>RE: Basic Switch Configuration Best Practices</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15738#M183</link>
      <description>basic command to backup the configuration of the switch to a notepad so that in time restore the command to a new switch</description>
      <pubDate>Thu, 19 Sep 2019 17:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/basic-switch-configuration-best-practices/m-p/15738#M183</guid>
      <dc:creator>engelbert43</dc:creator>
      <dc:date>2019-09-19T17:51:00Z</dc:date>
    </item>
  </channel>
</rss>

