Professional Documents
Culture Documents
Basic Commands On Alcatel Omniswitch
Basic Commands On Alcatel Omniswitch
Introduction
This page is based on the notes I took when managing Alcatel Omniswitchs 6600, 6800
in 2007 and later 6850. The full documentation can be found on Alcatel-Lucent website.
Configure VLANs
A layer 2 VLAN is created with vlan <vlan_number> enable name "vlan name" and
removed with no vlan <vlan_number>. show vlan lists all VLANs, show vlan
<vlan_number> shows vlan <vlan_number> details.
Depending on the microcode version (show microcode), a layer 3 VLAN is created
using:
•ip interface "interface name" vlan <vlan_number> address <address> mask
<netmask>
•vlan router "interface name" vlan <vlan_number> address <address> mask
<netmask>
and destroyed with:
•no ip interface "interface name"
•no vlan router "interface name"
Port association:
•To associate a port to a specific vlan: vlan <vlan_number> port default
<slot>/<port>
•To list the ports: show vlan port
•To list the ports of a specified vlan: show vlan <vlan_number> port
•To show a port: show vlan port <slot>/<port>802.1Q:
•To tag a port: vlan <vlan_number> 802.1Q <slot>/<port> [<"comment">]
•To remove a tag: vlan <vlan_number> no 802.1Q <slot>/<port>
Interfaces
Global status: Show interfaces status
Info about an interface (admin status, MAC, speed, duplex, errors, ...): show interfaces
[port|status|<slot>/<port>|...]
Summary of interfaces errors: show interfaces counters errors
To clear counters: interfaces <slot>[/port1-port2] no l2 statistics
To change an interface: interface <slot>/<port> [speed <10_100_1000>|duplex
<half_full>|autoneg <state>|flood rate <rate>]
To switch from autonegociation to 100FD, set
•autoneg off
•speed 100 and duplex full
If forced in 100FD while autoneg is on, the port will stay down
To disable an interface: interface <slot>/<port> admin down
Link Aggregation
Dynamic LAG (LACP)
lacp linkagg <id> size <size> admin state enable
lacp linkagg <id> actor admin key <key>
lacp agg <slot/port> actor admin key <key>
Static LAG
static linkagg <id> size <size> admin state enable
static linkagg <id> name <name>
static agg <slot/port> agg num <id>
Hardware
When stacking is operational, one switch is primary, one other secondary, the others
idle. If the primary disappears, the secondary becomes primary and the first idle
becomes secondary.
Get info about the chassis: show chassis and about the stack: show stack topology.
To monitor the health of the system: show health all (cpu|memory)
Show CMM (Control Management Module – Alcatel ) information: show cmm
System
Uptime, date, name, contact, location: show system
To change:
•system name <"name">
•system contact <"contact">
•system location <"location">
Logs
Show logging conf: show swlog
Get switch logs:
•show log swlog: get all logs
•show log swlog timestamp <mounth/day/year> <hour:minute>: only logs since
the specified hour
•empty logs: swlog clear
STP
STP can operates in two modes: flat and 1x1. In flat mode, there is only one instance for
the whole switch whereas in 1x1 mode, there is one instance per VLAN (like pvst on
Cisco switches or vstp on Juniper ones). I recommend the 1x1 mode if you do not want
to go the MSTP way. Change STP mode: bridge mode (flat|1x1)
Get STP conf: show spantree
It is possible to deactivate STP on specified vlans/ports : vlan <vlan_number> stp
(enable|disable) and bridge <vlan_number> <slot>/<port> (enable|disable)
Change STP algorithm: bridge protocol (802.1D|STP|RTSP). (In 2007), I did not
manage to set rstp for all vlan as a global config, I had to set it vlan per vlan
using: bridge 1x1 <vlan_number> protocol (802.1D|STP|RTSP).
DNS
•Name servers: ip name-server <IP1> <IP2>
•Domain name: ip domain-name <domain-name>
•Activate DNS client: ip domain-lookup
DHCP relay
•ip service udp-relay
•DHCP relay only for specified vlans: ip helper per-vlan only
•DHCP server address: ip helper address <dhcp_server> vlan <vlan_number>
•Enable DHCP relay: ip udp relay BOOTP
Services
Activate/deactivate services: [no] ip service (ftp|ssh|telnet|http|secure-http|udp-relay|
snmp|all). List of activated services: show ip service.
For https: ip http ssl
AAA
Authentification can be local or made with a radius
To activate a service, the authentification have to be set: aaa authentification default
"local", aaa authentification (console|ssh|ftp|802.1X|vlan|...) "local"
ARP
ARP table: show arp
Mac Address table: show mac-address-table
Add a static MAC/IP entry: arp <IP> <MAC>, no arp <IP> to remove it.
Clear dynamic arp entries: clear arp-table
To specify when an dynamic entry timeouts (default: 300seconds): mac-address-table
aging-time <seconds> [vlan <vlan_number>]
SNMP
First, you have to create a user and give it the right to do SNMP:
•user <"username"> read-only (all|ip|interface|...) password <password>
•The only way I found to give the user SNMP capabilities is to use the web
interface ..., but you can desactivate it with user <"username"> no snmp
Then configure the snmp server:
•snmp security no security
•Associate the community string with the user you created: snmp community map
<"community"> user <"username"> on
•To configure the SNMP trap server: snmp station <server_ip> [<port>] <"user">
(v1|v2c|v3) enable
•snmp authentification trap (enable|disable)
•To filter the traps sent by the switch: snmp trap filter <server_ip> <filter_code>
Port mirroring
Port mirroring works 12 ports by 12 ports. It is possible to configure multiple sources for
one session and thus see the traffic of multiple ports in one output.
•show port mirroring status
•port mirroring <session> source <slot>/<port> destination <slot>/<port> enable
•no port mirroring <session>
POE
By default, the POE is disabled on all ports.
To enable the POE on a given port: lanpower start <slot>/<port>
To enable it on the whole slot: lanpower start <slot>
To stop the POE, use the symmetric commande lanpower stop (<slot>/<port>|<slot>)
Show the POE configuration: show lanpower <slot>
To limit the power available for a given port: lanpower <slot>/<port> power
<milliwatts>
To limit the power available for a slot: lanpower <slot> maxpower <watts>
A power of 230W is enough for a full slot equipped with IP Phones (note: TBC).
It has been noticed that a switch may prove instable with POE if too many equipments
are connected and its PSU is not enough powerfull.