vsrp-aware

Configures the security features on a VSRP-aware device.
Syntax
vsrp-aware vrid vrid tc-vlan-flush
no vsrp-aware vrid vrid tc-vlan-flush
vsrp-aware vrid vrid { no-auth | simple-text-auth password } { port-list { [ ethernet unit/slot/port [ to unit/slot/port ] ... ] [ lag lag-id [ to lag-id ] ... ] } }
no vsrp-aware vrid vrid { no-auth | simple-text-auth password } { port-list { [ ethernet unit/slot/port [ to unit/slot/port ] ... ] [ lag lag-id [ to lag-id ] ... ] } }
Command Default

VSRP-aware security features are not configured.

Parameters
vrid vrid
Specifies the VRID of the VSRP device. The valid range is from 1 through 255.
tc-vlan-flush
Flushes the MAC addresses learned on the VSRP-aware VLAN upon topology change.
no-auth
Configures no authentication as the preferred VSRP-aware security method. The VSRP device will not accept incoming packets that have authentication strings.
simple-text-auth password
Defines an authentication string to accept incoming VSRP Hello packets. The password can be up to 8 characters in length.
port-list
Specifies the set of ports to include in the configuration.
ethernet unit/slot/port [ to unit/slot/port ]
Specifies the Ethernet ports, set of ports, or range of ports.
lag lag-id [ to lag-id ]
Specifies a LAG, set of LAGs, or range of LAGs to include in the port list.
to
Specifies a range of Ethernet interfaces or LAG IDs.
Modes

VLAN configuration mode

Usage Guidelines

When the tc-vlan-flush option is enabled, MAC addresses will be flushed at the VLAN level, instead of at the port level. MAC addresses will be flushed for every topology change received on the VSRP-aware ports. When you configure the tc-vlan-flush option on a VSRP-aware device, and the device receives VSRP Hello packets from the VSRP master, VSRP authentication is automatically configured. However, if the VSRP-aware device does not receive VSRP Hello packets from the VSRP master when the tc-vlan-flush option is configured, you must manually configure VSRP authentication.

You can specify a list of ports, separated by a space, or a range of ports, or you can combine lists and ranges.

You can combine individual Ethernet ports, Ethernet port ranges, LAGs, and LAG ranges in the same command if you wish.

The no form of the command clears the security features on the VSRP-aware device.

Examples

The following example shows how to configure the MAC addresses to be flushed at the VLAN level.

device(config)# vlan 200
device(config-vlan-200)# vsrp-aware vrid 11 tc-vlan-flush

The following example shows how to configure a simple authentication string for the VSRP.

device(config)# vlan 10
device(config-vlan-10)# vsrp-aware vrid 3 simple-text-auth pri-key

The following example shows how to configure no authentication for the VSRP.

device(config)# vlan 10
device(config-vlan-10)# vsrp-aware vrid 2 no-auth

The following example shows how to configure no authentication for a range of Ethernet ports.

device(config)# vlan 10
device(config-vlan-10)# vsrp-aware vrid 4 no-auth port-list ethernet 1/1/1 to 1/1/4
History
Release version Command history
08.0.61 This command was updated to include the LAG ID option.