What shoud we pay attention to do when a new switch is going to connecte with company network

Hi Expert,
Here is a question. Before we add a new switch to a network, we should configure VTP, especially make sure the VTP configuration version number is lower. In addition to this, are there anything else that we need to take care of it ? such as STP etc if we use STP or RSTP in the network ? Thank you.
EESkyAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

piattndCommented:
This link describes some of the best practices when adding a switch or router to an existing network.  Keep in mind it's only their "top 5" and they appear to be biased to Cisco.

http://www.networkcomputing.com/data-networking-management/5-basic-switch-settings-you-must-know/232500647
0
rauenpcCommented:
In my switch templates that I use to configure new switches, there are a couple things in there that are fairly important to me. Those will be in bold. Some of this overlaps with the article piattnd posted.


no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
!
hostname
!
[aaa commands if needed]
!
lldp run
!
system mtu jumbo 9198 [or whatever the max is]
!
spanning-tree mode rapid-pvst
spanning-tree portfast default
spanning-tree portfast bpduguard default
spanning-tree portfast bpdufilter default
no spanning-tree optimize bpdu transmission
spanning-tree extend system-id
spanning-tree vlan 1-4094 priority 40960
!        
vtp mode client
vtp mode transparent
vtp domain #VTPDOMAIN#
vtp mode #VTPMODE#

!
errdisable recovery cause all

ntp server x.x.x.x

Important stuff. I can't think of a single non-lab, non-educational reason to ever not enable password encryption. Make sure the spanning tree mode matches the rest of the network or is at least compatible if there is a mix. Set the priority appropriately - my template is normally for access switches and as such I increase the priority beyond the default to ensure that it is less likely to take over as root for any vlan. I purposely set the vtp mode multiple times to set the revision to 0. I find errdisable recovery to be very useful, not only do the customers like it because when they accidentally cause a loop or plug a bad device in to the network, the port will eventually recover. Also, when you have someone else plug in a switch and a port goes in to error disable mode (perhaps because they used the wrong port as an uplink and bpduguard was set), it will still give you the opportunity to possibly change the other end to get the port back up and make config changes. And lastly, having the correct time is always a nice thing to have.

Less important. I have no use for the pad service, tcp keepalives stop dead telnet/ssh sessions from locking out users from managing the switch. I like to see sensible timestamps in the log, not random looking number or delta timestamps. Hostnames are always useful and required if doing ssh (along with a domain-name). I like portfast to be on by default for access ports.

The rest of my template settings are based on customer specifics such as snmp, banners, ACL's, logging, etc.
Don't forget that these are what I personally find important in most of my switch configurations. Some of these could very well fall under a documented best practices guide, and others are purely personal.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Switches / Hubs

From novice to tech pro — start learning today.