Cheat Sheet (Referencia Técnica)
STP / RSTP
Section titled “STP / RSTP”| Dato | Valor |
|---|---|
| Prioridad root por defecto | 32768 (pasos de 4096) |
| Bridge ID | Prioridad + MAC (menor gana) |
| Convergencia STP | 30-50 s |
| Convergencia RSTP | 1-2 s |
| Estados STP | Blocking → Listening → Learning → Forwarding |
| Estados RSTP | Discarding, Learning, Forwarding |
Roles de puerto
Section titled “Roles de puerto”| Rol | Descripción |
|---|---|
| Root port | Mejor camino hacia la raíz (uno por switch no raíz) |
| Designated port | Mejor puerto del segmento |
| Blocked/Alternate | Respaldo, no reenvía |
PVST / Rapid PVST
Section titled “PVST / Rapid PVST”# SW1spanning-tree mode rapid-pvstspanning-tree vlan 10,30 root primaryspanning-tree vlan 20 root secondary
# access + PortFast + BPDU guardint range f0/1 - 24switchport host
# SW2spanning-tree mode pvstspanning-tree vlan 10,30 root secondaryspanning-tree vlan 20 root primary
int range f0/1 - 24switchport hostMultiple Spanning Tree (MST)
Section titled “Multiple Spanning Tree (MST)”# Configuración de región - Identicalspanning-tree mode mstspanning-tree mst configurationname REGION1revision 1instance 1 vlan 10,30instance 2 vlan 20exit
# SW1spanning-tree mst 1 root primary
# access + PortFast + BPDU guardint range f0/1 - 24switchport host
# SW1spanning-tree mst 2 root secondaryint range f0/1 - 24switchport hostVerificación
Section titled “Verificación”show spanning-tree vlan 10show spanning-tree mst 1show spanning-tree summaryEtherChannel
Section titled “EtherChannel”| Protocolo | Estándar | Modos compatibles |
|---|---|---|
| LACP | IEEE 802.3ad | active+active o active+passive |
| PAgP | Propietario Cisco | desirable+desirable o desirable+auto |
| on | — | Forzado (ambos lados) |
Requisitos: misma velocidad, dúplex, VLAN y config de trunk en todos los puertos.
int range f0/1 - 4channel-group 1 mode activeexit
int Port-channel 1switchport mode trunkswitchport trunk native vlan 99sw trunk allowed vlan 10,20,99exitint range f0/1 - 4channel-group 1 mode passiveexit
int Port-channel 1switchport mode trunkswitchport trunk native vlan 99sw trunk allowed vlan 10,20,99exitBalanceo:
port-channel load-balance src-dst-ip # defaultshow etherchannel summary # (SU)=up, (P)=bundledshow etherchannel load-balanceSeguridad de capa 2
Section titled “Seguridad de capa 2”| Ataque | Mitigación |
|---|---|
| MAC flooding | Port Security |
| DHCP starvation / rogue | DHCP Snooping |
| ARP spoofing | DAI |
| VLAN hopping | switchport nonegotiate, trunks manuales |
| Switch no autorizado | PortFast + BPDU guard, puertos apagados |
Port Security
Section titled “Port Security”interface range f0/1 - 24switchport mode accesssw port-securitysw port-security maximum 2sw port-security mac-address stickysw port-security violation restrictModos de violación: protect (descarta), restrict (descarta + log), shutdown (errdisable).
Recuperar errdisable: shutdown + no shutdown, o errdisable recovery cause psecure-violation.
DHCP Snooping + DAI + IP Source Guard
Section titled “DHCP Snooping + DAI + IP Source Guard”# DHCP Snoopingip dhcp snoopingip dhcp snooping vlan 10,20int g0/1ip dhcp snooping trustint range f0/1 - 12ip dhcp snooping limit rate 10exit
# Dynamic ARP Inspection (DAI)ip arp inspection vlan 10,20int g0/1ip arp inspection trustexit
# IP Source Guard (IPSG)int range f0/1 - 12ip verify sourceexitBuenas prácticas
Section titled “Buenas prácticas”int range f0/10 - 24shutdown
interface g0/1switchport mode trunkswitchport nonegotiate
int range f0/1 - 24storm-control broadcast level 20show ip dhcp snoopingshow ip arp inspection vlan 10show port-security interface g0/1