Jump to content

Recommended Posts

Posted

Just taken delivery of a few new switches, does anyone have a checklist for a new switch setup?

 

I've got things such as - Change default password, Change IP address, VLAN config (if applicable).

 

Thanks

Posted
Enable spanning tree and port security. Set up SNMP reporting back to zabbix. Add to documentation. Upgrade firmware. Leave it running for a week to avoid the bathtub curve
  • Thanks 1
Posted
lockdown user access to CLI and web interface , add to monitoring solution, add it to asset register, name switch by location/cab. Print Label for cab of the switch ip
  • Thanks 1
Posted
Enable spanning tree and port security. Set up SNMP reporting back to zabbix. Add to documentation. Upgrade firmware. Leave it running for a week to avoid the bathtub curve

With Firmware, is upgrading to the latest firmware ok? (Always a bit edgy about updating to the latest release) -I'm using Aruba Switches

Posted

Ideally label interfaces in the config:

 

For a classroom switch, you'd just do something like:

 

1-30 - Rm14 Desktops

31 - Rm14 Printer

32 - Rm14 Access Point

33-40 - Rm15 Desktops

41-48 - Spare and disabled

49-50 - Spare Uplinks

51-52 - LACP back to Core.

 

Why? Cos those labels will show up in monitoring tools and make your life easier.

  • Thanks 1
Posted (edited)
With Firmware, is upgrading to the latest firmware ok? (Always a bit edgy about updating to the latest release) -I'm using Aruba Switches

 

I don't know about Aruba, but Cisco normally have a "suggested" release listed alongside the latest releases. All of these are normally newer than what the device shipped with.

 

As for checklist, I make sure I've got the configs and documentation for the old switch it's replacing so I know what the new one should be doing if it's a replacement.

Edited by jtotheb
Posted

Don't use vlan 1, separate management to seperate vlan and tagg vlans on uplink ports. Lock down management to specific IPs/ranges. Setup NTP etc.

 

And naming ports is very handy as long as you have keep this updated, lol. But that is the same for all documentation.

 

We normally go to 1 before the latest firmware unless the latest is years old. But just check the release notes.

Posted

Make sure you save the config. Repeatedly.

 

Enable LLDP/CDP

 

Save the Config

 

Label patch panels and cables with room numbers or something that won't change. Using staff, office or department names will probably lead to problems down the line. At some point in 10 years, some poor soul is going to pull their hair out trying to work out who 'Wilkie' was and which office(s) he used when he was here... Label your power connections to - especially where you have more than 1 device in a cab.

 

Save the config

 

Double check any ip routing setup.

 

Save the config again.

 

Make sure your network map exists and is up to date. put a copy in each cab, with the date it was last updated.

 

Get called out at some horrible hour of the day because someone didn't - you guessed it - save the config...

 

I'd also recommend keeping things as simple as possible. I'd keep some sort of offline copy of the config as well. Having a standard config across your switches helps to.

Posted

Enable DHCP snooping and Dynamic ARP inspection.

 

The first stops anything other than your DHCP server to give addresses. Dynamic ARP inspection stops man in the middle attacks.

Posted
If the switches all support it, enable MVRP. With that on, any created VLAN gets automatically propagated to your other switches and the vlan is automatically tagged on the uplink ports. Makes life a lot easier.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...