background image

 

©Copyright 2009. All rights reserved.

 

 

User Manual 

Product Model :

 

DES-1228/ME

 

Managed 10/100Mbps Metro Ethernet Switch 

Release 1  

 

Summary of Contents for DES-1228/ME

Page 1: ...Copyright 2009 All rights reserved User Manual ProductModel DES 1228 ME Managed10 100MbpsMetroEthernetSwitch Release1...

Page 2: ...ritten permission of D Link Corporation is strictly forbidden Trademarks used in this text D Link and the D LINK logo are trademarks of D Link Corporation Microsoft and Windows are registered trademar...

Page 3: ...orts 5 Installing the SFP ports 6 Installation 7 Package Contents 7 Before You Connect to the Network 7 Installing the Switch without the Rack 8 Installing the Switch in a Rack 8 Mounting the Switch i...

Page 4: ...nostics 39 Port Mirroring 41 System Log Settings 42 Log Settings 44 SNTP Settings 45 Time Settings 45 Time Zone and DST 46 MAC Notification Settings 48 Global Settings 48 Port Settings 48 TFTP Service...

Page 5: ...P Instance Settings 98 MSTP Port Information 99 Loopback Detection Settings 101 LLDP 102 LLDP Global Settings 102 Basic LLDP Port Settings 104 802 1 Extension LLDP Port Settings 105 802 3 Extension LL...

Page 6: ...Authentication 156 802 1X 157 802 1X Authenticator Settings 164 Local Users 167 802 1X Capability Settings 168 Configure 802 1X Guest VLAN 168 RADIUS Server 169 Trusted Host 171 Access Authentication...

Page 7: ...205 Gratuitous ARP Settings 207 Session Table 208 Port Access Control 208 RADIUS Authentication 208 RADIUS Accounting 210 Reset 211 Reboot System 212 Save Changes 212 Logout 213 Technical Specificatio...

Page 8: ...gine SNMP Manager Forwarding Filtering and SMTP Service Section 7 Layer 2 Features A discussion of Layer 2 features of the Switch including VLAN Trunking IGMP Snooping Spanning Tree Loopback Detection...

Page 9: ...ames and commands For example use the copy command Boldface Typewriter Font Indicates commands and responses to prompts that must be typed exactly as printed in the manual Initial capital letter Indic...

Page 10: ...ly with approved equipment Allow the product to cool before removing covers or touching internal components Operate the product only from the type of external power source indicated on the electrical...

Page 11: ...component refers to any system as well as to various peripherals or supporting hardware Before working on the rack make sure that the stabilizers are secured to the rack extended to the floor and that...

Page 12: ...onents inside your system To prevent static damage discharge static electricity from your body before you touch any of the electronic components such as the microprocessor You can do so by periodicall...

Page 13: ...port IEEE 802 1X Port based and Host based Access Control IEEE 802 1Q VLAN IEEE 802 1D Spanning Tree IEEE 802 1w Rapid Spanning Tree and IEEE 802 1s Multiple Spanning Tree support Access Control List...

Page 14: ...thernet port maximum 148 810 packet sec on 100Mbps Fast Ethernet port and 1 488 100 for each Gigabit port Full and half duplex for both 10Mbps and 100Mbps connections Full duplex allows the switch por...

Page 15: ...EM 314GT 1000BASE LH DEM 315GT 1000BASE ZX DEM 210 Single Mode 100BASE FX DEM 211 Multi Mode 100BASE FX WDM Transceiver Supported DEM 330T TX 1550 RX 1310nm up to 10km Single Mode DEM 330R TX 1310 RX...

Page 16: ...reception or transmission i e Activity Act of data occurring at a Fast Ethernet connected port Solid Amber When there is a secure 10Mbps Ethernet connection or link at any of the ports Blinking Amber...

Page 17: ...228 ME Rear Panel Description The rear panel of the Switch contains an AC power connector The AC power connector is a standard three pronged connector that supports the power cord Plug in the female c...

Page 18: ...00BASE T copper ports provided and Mini GBIC ports optional See the diagram below to view the two Mini GBIC port modules being plugged into the Switch Please note that although these two front panel m...

Page 19: ...abit link that may span great distances These SFP ports support full duplex transmissions have auto negotiation and can be used with the DEM 310GT 1000BASE LX DEM 311GT 1000BASE SX DEM 210 Single Mode...

Page 20: ...Install the Switch on a sturdy level surface that can support at least 4 24kg 9 35lbs of weight Do not place heavy objects on the Switch The power outlet should be within 1 82 meters 6 feet of the Swi...

Page 21: ...gh ventilation space between the Switch and any other objects in the vicinity Figure 2 1 Prepare Switch for installation on a desktop or shelf Installing the Switch in a Rack The Switch can be mounted...

Page 22: ...nto the power connector of the Switch and the other end into the local power source outlet After the Switch is powered on the LED indicators will momentarily blink This blinking of the LED indicators...

Page 23: ...e End nodes include PCs outfitted with a 10 100 or 1000 Mbps RJ 45 Ethernet Fast Ethernet Network Interface Card NIC and most routers An end node can be connected to the Switch via a twisted pair Cate...

Page 24: ...e connected to the Switch via a twisted pair Category 5 UTP STP cable A 1000BASE T switch can be connected to the Switch via a twisted pair Category 5e UTP STP cable A switch supporting a fiber optic...

Page 25: ...gent decodes the incoming SNMP messages and responds to requests with MIB objects stored in the database The SNMP agent updates the MIB objects to generate statistics and counters Connecting the Conso...

Page 26: ...Make sure the terminal or PC you are using to make this connection is configured to match these settings If you are having problems making this connection on a PC make sure the emulation is set to VT...

Page 27: ...1228 ME 4 Figure 4 2 Command Prompt NOTE The first user automatically gets Administrator level privileges It is recommended to create at least one Admin level user account for the Switch Password Pro...

Page 28: ...ME supports SNMP versions 1 2c and 3 You can specify which version of SNMP you want to use to monitor and control the Switch The three versions of SNMP vary in the level of security provided between...

Page 29: ...ts own IP Address which is used for communication with an SNMP network manager or other TCP IP application for example BOOTP TFTP The Switch s default IP address is 10 90 90 90 You can change the defa...

Page 30: ...dress xxx xxx xxx xxx z Where the x s represent the IP address to be assigned to the IP interface named System and the z represents the corresponding number of subnets in CIDR notation The IP interfac...

Page 31: ...universal access tool and can communicate directly with the Switch using the HTTP protocol The Web based management module and the Console program and Telnet are different ways to access the same inte...

Page 32: ...configuration and management windows allows you to view performance statistics and permits you to graphically monitor the system status Areas of the User Interface The figure below shows the user int...

Page 33: ...control depending on the specified mode Various areas of the graphic can be selected for performing management functions including port configuration Area 3 Presents switch information based on your...

Page 34: ...Tree Loopback Detection and LLDP CoS Contains windows concerning Port Bandwidth 802 1P Default Priority 802 1P User Priority CoS Scheduling Mechanism CoS Output Scheduling Priority Settings TOS Prior...

Page 35: ...P Address Port Configuration DHCP BOOTP Relay User Accounts Cable Diagnostics Port Mirroring System Log Settings Log Settings SNTP Settings MAC Notification Settings TFTP Services Multiple Image Servi...

Page 36: ...t Tool folder The Device Information window shows the Switch s MAC Address assigned by the factory and unchangeable the Boot PROM Firmware Version Hardware Version and Serial Number This information i...

Page 37: ...tion is Enabled by default If you do not want to allow configuration of the system through Telnet choose Disabled Telnet TCP Port Number 1 65535 The TCP port number TCP ports are numbered between 1 an...

Page 38: ...plaintext form Click Apply to implement changes made IP Address The IP address may initially be set using the console interface prior to connecting to it through the Ethernet If the Switch IP address...

Page 39: ...network and 255 255 255 0 for a Class C network but custom subnet masks are allowed Default Gateway IP address that determines where packets with a destination address outside the current subnet shoul...

Page 40: ...nd Line Interface CLI over the console serial port as follows Starting at the command line prompt enter the commands config ipif System ipaddress xxx xxx xxx xxx yyy yyy yyy yyy where the x s represen...

Page 41: ...nd flow control Port Settings Click Administration Port Configuration Port Settings to display the following window To configure switch ports 1 Choose the port or sequential range of ports using the F...

Page 42: ...ies related to duplex speed and physical layer type The master setting will also determine the master and slave relationship between the two connected physical layers This relationship is necessary fo...

Page 43: ...pports a port description feature where the user may name various ports on the Switch To assign names to various ports click Administration Port Configuration Port Description to view the following wi...

Page 44: ...e port whether Enabled or Disabled Connection This field will show if a port has been disabled due to an error detected in the port Reason Describes the reason why the port has been error disabled suc...

Page 45: ...an be toggled between Enabled and Disabled using the pull down menu It is used to enable or disable the DHCP Agent Information Option 82 on the Switch The default is Disabled Enabled When this field i...

Page 46: ...sts in the packet received from the DHCP client Drop The packet will be dropped if the option 82 field already exists in the packet received from the DHCP client Keep The option 82 field will be retai...

Page 47: ...sub option format 1 Sub option type 2 Length 3 Circuit ID type 4 Length 5 VLAN the incoming VLAN ID of DHCP client packet 6 Module For a standalone switch the Module is always 0 For a stackable switc...

Page 48: ...ay DHCP BOOTP Relay Interface Settings Figure 6 7 DHCP BOOTP Relay Interface Settings and DHCP BOOTP Relay Interface Table window The following parameters may be configured or viewed Parameter Descrip...

Page 49: ...DES 1228 ME Layer 2 Fast Ethernet Managed Switch 36 Figure 6 8 DHCP Local Relay Settings window...

Page 50: ...y to implement changes made User Accounts Use the User Account Management window to control user privileges To view existing User Accounts open the Administration folder and click on the User Accounts...

Page 51: ...password type in the New Password and retype it in the Confirm New Password entry field The level of privilege Admin or User can be viewed in the Access Right field The last option here is called Encr...

Page 52: ...sted Type FE ports have two pairs of cable will be diagnosed GE ports have four pairs of cable that will be diagnosed Link Status Link Up When a port is in link up status the test will be able to dete...

Page 53: ...or Crosstalk Open means that the cable in the error pair does not have a connection at the specified position Short means that the cable in the error pair has a short problem at the specified position...

Page 54: ...port 1 Select the Source Port from where you want to copy frames and the Target Port which receives the copies from the source port 2 Select the Source Direction Ingress Egress or Both and change the...

Page 55: ...ameters can be set Parameter Description Index Syslog server settings index 1 4 Host IP The IP address of the Syslog server Severity This drop down menu allows you to select the level of messages that...

Page 56: ...use 0 local0 local use 1 local1 local use 2 local2 local use 3 local3 local use 4 local4 local use 5 local5 local use 6 local6 local use 7 local7 UDP Port 514 or 6000 65535 Type the UDP port number u...

Page 57: ...following window Figure 6 17 Log Settings window The following parameters can be set Parameter Description Log Mode Use this drop down menu to choose the method that will trigger a log entry You can...

Page 58: ...ttings Enabling and configuring SNTP support will override any manually configured system time settings SNTP Primary Server This is the IP address of the primary server the SNTP information will be ta...

Page 59: ...nistration folder then the SNTP Settings folder and click on the Time Zone and DST link revealing the following window Figure 6 19 Time Zone and DST Settings window The following parameters can be set...

Page 60: ...the time of day that DST will start on To Which Week Enter the week of the month the DST will end To Which Day Enter the day of the week that DST will end To Which Month Enter the month that DST will...

Page 61: ...tate Enable or disable MAC notification globally on the Switch Interval sec The time in seconds between notifications History Size The maximum number of entries listed in the history log used for noti...

Page 62: ...ame for the Configuration file on the TFTP server Click Start to record the IP address of the TFTP server and to initiate the file transfer Upload Configuration Enter the IP address of the TFTP server...

Page 63: ...tion Multiple Image Services Firmware Information This window is used to view boot up firmware images To view this window click Administration Multiple Image Services Firmware Information Figure 6 22...

Page 64: ...imizing the workload of the Switch while the attack is ongoing thus making it capable to forward essential packets over its network in a limited bandwidth When the Switch either a receives too many pa...

Page 65: ...seconds Once the flooding is no longer detected the wait period for dropping ARP and IP broadcast packets will return to 5 seconds and the process will resume NOTE While in Exhausted mode only truste...

Page 66: ...nfigure the acceptable level of CPU utilization as a percentage where the Switch leaves the Exhausted state and returns to normal mode Trap Log Use the pull down menu to enable or disable the sending...

Page 67: ...nagers that are allowed to view read only information or receive traps using SNMPv1 while assigning a higher level of security to another group granting read write privi leges using SNMPv3 Using SNMPv...

Page 68: ...this window click Administration SNMP Manager SNMP User Table Figure 6 29 SNMP User Table window To delete an existing SNMP User Table entry click the below the Delete heading corresponding to the en...

Page 69: ...p Name This name is used to specify the SNMP group created to which the SNMP user will belong SNMP V3 Encryption Checking the corresponding box will enable encryption for SNMP V3 and is only operable...

Page 70: ...th this table maps SNMP users identified in the SNMP User Table to the views created in the previous window The following parameters can set Parameter Description View Name Type an alphanumeric string...

Page 71: ...Group Table window To delete an existing SNMP Group Table entry click the corresponding under the Delete heading To display the current settings for an existing SNMP Group Table entry click the hyperl...

Page 72: ...Priv Specifies that there will be no authorization and no encryption of packets sent between the Switch and a remote SNMP manager AuthNoPriv Specifies that authorization will be required but there wil...

Page 73: ...at SNMP community members using the community string created can read from and write to the contents of the MIBs on the Switch To implement the new settings click Apply To delete an entry from the SNM...

Page 74: ...level Community String SNMP V3 User Name Type in the community string or SNMP V3 user name as appropriate To implement your new settings click Apply To return to the SNMP Host Table click the Show Al...

Page 75: ...elete heading Multicast Forwarding The following figure and table describe how to set up Multicast Forwarding on the Switch To view this window click Administration Forwarding Filtering Multicast Forw...

Page 76: ...is chosen the port will not be a member of the Static Multicast Group Egress The port is a static member of the multicast group Click Apply to implement the changes made To delete an entry in the Stat...

Page 77: ...ilter settings will be applied Mode This drop down menu allows you to select the action the Switch will take when it receives a multicast packet that is to be forwarded to one of the ports in the rang...

Page 78: ...Switch will send out e mail to recipients when one or more of the following events occur When a cold start occurs on the Switch When a port enters a link down status When a port enters a link up statu...

Page 79: ...ith on the SMTP server The common port number for SMTP is 25 yet a value between 1 and 65535 can be chosen Self Mail Address Enter the e mail address from which mail messages will be sent This address...

Page 80: ...ervice window The following parameters can be set Parameter Description Subject Enter the subject of the test e mail Content Enter the content of the test e mail Once your message is ready click Send...

Page 81: ...g function can be used to remove the 802 1Q tag from packet headers to maintain compatibility with devices that are tag unaware The Switch s default is to assign all ports to a single 802 1Q VLAN name...

Page 82: ...he packet Egress rules determines if the packet must be sent tagged or untagged Figure 7 1 IEEE 802 1Q Packet Forwarding 802 1Q VLAN Tags The figure below shows the 802 1Q VLAN tag There are four addi...

Page 83: ...cide whether or not to forward the packet If the packet is tagged with VLAN information the ingress port will first determine if the ingress port itself is a member of the tagged VLAN If it is not the...

Page 84: ...ceive VLAN 2 packets If Port 10 is not a member of VLAN 2 then the packet will be dropped by the Switch and will not reach its destination If Port 10 is a member of VLAN 2 the packet will go through T...

Page 85: ...s and the set of ports to be separated from the other subsetted VLANs ports 9 16 VLAN V3 is then configured to include ports 1 8 shared ports and the set of ports to be separated from the other subset...

Page 86: ...click the Show All Static VLAN Entries link To change an existing 802 1Q VLAN entry click the Modify button of the corresponding entry you wish to modify A new window will appear to configure the por...

Page 87: ...ow All Static VLAN Entries link to return to the 802 1Q Static VLANs window To add a new 802 1Q Static Multiple VLAN by VID List click the Add or Configure VLAN by VID List in the Static VLAN Entry wi...

Page 88: ...member of the VLAN dynamically Click Apply to implement changes made Click the Show All Static VLAN Entries link to return to the 802 1Q Static VLANs window GVRP Settings The GVRP Settings window sho...

Page 89: ...llow you to specify the range of ports that will be included in the Port based VLAN that you are creating using this window GVRP The Group VLAN Registration Protocol GVRP enables the port to dynamical...

Page 90: ...ames will be accepted and Admit_All which mean both tagged and untagged frames will be accepted Admit_All is enabled by default Click Apply to implement changes made NOTE A VLAN group can support 255...

Page 91: ...a stream to arrive in the same order they were sent NOTE If any ports within the trunk group become disconnected packets intended for the discon nected port will be load shared among the other uplinke...

Page 92: ...n group If two redundant link aggregation groups are configured on the Switch STP will block one entire group in the same way STP will block a single port that has a redundant link Link Aggregation To...

Page 93: ...ged Switch 80 Figure 7 13 LACP Port Settings window To configure LACP port trunk settings select a port range using the From and To drop down menus select either Passive or Active Mode and then click...

Page 94: ...e device to the IGMP host or vice versa The Switch monitors IGMP messages and discontinues forwarding multicast packets when there are no longer hosts requesting that they continue Use the IGMP Snoopi...

Page 95: ...the membership query is received before the Leave Timer expires the multicast forwarding entry for that host is deleted The default setting is 2 Note The leave timer does not need to be configured as...

Page 96: ...ch devices are members of a particular multicast group the devices will respond to the query and inform the querier of its membership status RIPv2 multicast Routing Information Protocol Version 2 can...

Page 97: ...This is the name of the VLAN where the multicast router is attached Port Settings Select the individual ports and settings you wish to apply None No restrictions on the port dynamically becoming a rou...

Page 98: ...Switch 85 Dynamic IP Multicast Learning To configure the Dynamic IP Multicast Learning Max Entry Settings on the Switch click L2 Features IGMP Snooping Dynamic IP Multicast Learning Figure 7 18 Dynam...

Page 99: ...st VLANs can be implemented on edge and non edge switches 2 Member ports and source ports can be used in multiple ISM VLANs But member ports and source ports cannot be the same port in a specific ISM...

Page 100: ...indow VID Add or edit the corresponding VLAN ID of the Multicast VLAN Users may enter a value between 2 and 4094 State Use the pull down menu to enable or disable the selected Multicast VLAN Member Po...

Page 101: ...trees with a Common and Internal Spanning Tree CIST The CIST will automatically determine each MSTP region its maximum possible extent and will appear as one virtual bridge that runs a single spannin...

Page 102: ...from adjacent bridges 802 1w RSTP 802 1d STP Forwarding Learning Discarding Disabled No No Discarding Blocking No No Discarding Listening No No Learning Learning No Yes Forwarding Forwarding Yes Yes...

Page 103: ...ing State If another returning BPDU packet is received the port will remain in a blocked state the timer will reset to the specified value restart and the process will begin again For those who choose...

Page 104: ...DES 1228 ME Layer 2 Fast Ethernet Managed Switch 91 Figure 7 24 STP Bridge Global Settings window RSTP Figure 7 25 STP Bridge Global Settings window MSTP...

Page 105: ...40 seconds The default value is 20 Bridge Hello Time 1 2 Sec The Hello Time can be set from 1 to 2 seconds This is the interval between two transmissions of BPDU packets sent by the Root Bridge to tel...

Page 106: ...t signifies a loop on the network STP will automatically be blocked and an alert will be sent to the administrator The LBD STP port will restart change to discarding state when the Loopback Detection...

Page 107: ...will be blocked just as redundant links are blocked on the switch level The STP on the switch level blocks redundant links between switches and similar network devices The port level STP will block r...

Page 108: ...ows the port to have p2p status whenever possible and operate as if the p2p status were true If the port cannot maintain this status for example if the port is forced to half duplex operation the p2p...

Page 109: ...on Parameter Description Configuration Name A previously configured name set on the Switch to uniquely identify the MSTI Multiple Spanning Tree Instance If a configuration name is not set this field w...

Page 110: ...ance ID Settings window CIST modify The user may configure the following parameters to configure the CIST on the Switch Parameter Description MSTI ID The MSTI ID of the CIST is 0 and cannot be altered...

Page 111: ...wishes to add to this MSTI ID Supported VIDs on the Switch range from ID number 1 to 4094 This parameter can only be utilized if the Type chosen is Add or Remove Click Apply to implement changes made...

Page 112: ...ort Information and can be used to update the port configuration for an MSTI ID If a loop occurs the MSTP function will use the port priority to select an interface to put into the forwarding state Se...

Page 113: ...t setting is 0 auto There are two options 0 auto Selecting this parameter for the internalCost will set quickest route automatically and optimally for an interface The default value is derived from th...

Page 114: ...temporarily shutdown a port on the Switch when a CTP Configuration Testing Protocol packet has been looped back to the switch When the Switch detects CTP packets are received from a port it signifies...

Page 115: ...cifies the necessary protocol and management elements to 1 Facilitate multi vendor inter operability and the use of standard management tools to discover and make available physical topology informati...

Page 116: ...cates the interval at which LLDP frames are transmitted on behalf of this LLDP agent The default value is 30 seconds Message TX Hold Multiplier 2 10 This parameter is a multiplier that determines the...

Page 117: ...LLDP Port Settings The following window is used to set up LLDP on individual port s on the Switch To view this window click L2 Features LLDP Basic LLDP Port Settings Figure 7 38 Basic LLDP Port Settin...

Page 118: ...nged type includes any data update insert remove Admin Status Use the drop down menu to choose TX_Only RX_Only TX_and_RX or Disabled Port Description Use the drop down menu to toggle Port Description...

Page 119: ...DES 1228 ME Layer 2 Fast Ethernet Managed Switch 106 Figure 7 39 802 1 Extension LLDP Port Settings Table window...

Page 120: ...n menu to toggle among VLAN ID VLAN Name and All Use the drop down menu to toggle between Enabled and Disabled Protocol Identity Use the drop down menu to toggle among EAPOL LACP GVRP STP and All Use...

Page 121: ...xtension LLDP Port Settings Table window The following parameters can be set or displayed Parameter Description From To Select a port or group of ports using the pull down menus MAC PHY Use the drop d...

Page 122: ...drop down menu to toggle Maximum Frame Size between Enabled and Disabled Click Apply to implement changes made LLDP Management Address Settings The following window is used to set up LLDP management a...

Page 123: ...4 Address type Address Enter the LLDP management address in this field Port State Use the drop down menu to toggle the Port State between Enabled and Disabled Click Apply to implement changes made LLD...

Page 124: ...ment Address Table window Use the drop down menu to select the type of Management Address enter an IP address in the field provided and then click the Find button LLDP Local Port Table The following w...

Page 125: ...e The following window is used to display the LLDP Remote Port Brief Table To view this window click L2 Features LLDP LLDP Remote Port Table Figure 7 45 LLDP Remote Port Brief Table window Click the V...

Page 126: ...ant special consideration The Switch allows you to further tailor how priority tagged data packets are handled on your network Using queues to manage priority tagged data allows you to specify its rel...

Page 127: ...rrupted stream of packets which optimizes the use of bandwidth available for the video conference Understanding CoS The Switch has four priority classes of service These priority classes of service ar...

Page 128: ...the same weight value then each CoS queue has an equal opportunity to send packets just like round robin queuing For weighted round robin queuing if the weight for a CoS is set to 1 then it will conti...

Page 129: ...width The bandwidth control settings are used to place a ceiling on the transmitting and receiving data rates for any selected port To view this window click CoS Port Bandwidth Figure 8 2 Port Bandwid...

Page 130: ...s drop down menu allows you to specify that the selected port will have no bandwidth limit Enabled disables the limit Rate This field allows you to enter the data rate in Kbit s that will be the limit...

Page 131: ...t 802 1p priority to any given port on the Switch The priority tags are numbered from 0 the lowest priority to 7 the highest priority To implement a new default priority choose a port range by using t...

Page 132: ...r Priority window Once you have assigned a priority to the port groups on the Switch you can then assign this Class to each of the four levels of 802 1p priorities Click Apply to set your changes CoS...

Page 133: ...oS can be customized by changing the output scheduling used for the hardware classes of service in the Switch As with any changes to CoS implementation careful consideration should be given to how net...

Page 134: ...example if a port has been assigned a MAC priority the packet that has the CoS priority assigned to a MAC address will be sent to the CoS queue configured for that MAC address Once the configuration h...

Page 135: ...DES 1228 ME Layer 2 Fast Ethernet Managed Switch 122 Figure 8 7 Priority Settings window...

Page 136: ...ill assign ports to map CoS priorities to MAC addresses TOS Choosing this option will assign ports to map CoS priorities to ToS priorities DSCP Choosing this option will assign ports to map CoS priori...

Page 137: ...able queues When a packet is received containing this DSCP tag it will be mapped to the CoS queue configured here These settings will only take effect if at least one of the priority settings per port...

Page 138: ...gress port The frames will be assigned to either the highest queue or the lowest queue Please note the following limitation exists port based CoS only supports mapping to Queue 3 Port mapping Priority...

Page 139: ...opriate queue to be mapped to this destination MAC address using the following window 3 Once the previous parameters are set users should go to the Priority Settings window located in this folder and...

Page 140: ...lick ACL Access Profile Table Figure 9 1 Access Profile Table window To add an entry to the Access Profile Table click the Add button This will open the Access Profile Configuration window as shown be...

Page 141: ...This will change the menu according to the requirements for the type of profile Select Ethernet to instruct the Switch to examine the layer 2 part of each packet header Select IP to instruct the Swit...

Page 142: ...ill change the menu according to the requirements for the type of profile Select Ethernet to instruct the Switch to examine the layer 2 part of each packet header Select IP to instruct the Switch to e...

Page 143: ...Specify a TCP port mask for the destination port in hex form hex 0x0 0xffff which you wish to deny Select UDP to use the UDP port number contained in an incoming packet as the forwarding criterion Se...

Page 144: ...ch packet header IP instructs the Switch to examine the IP address in each frame s header Priority 0 7 This parameter is specified if you want to re write the 802 1p default priority previously set in...

Page 145: ...ort Number Enter the switch port number s to which you wish this rule to apply To view the settings of a previously correctly configured rule click in the Access Rule Table to view the following windo...

Page 146: ...rnet instructs the Switch to examine the layer 2 part of each packet header IP instructs the Switch to examine the IP address in each frame s header Priority 0 7 This parameter is specified if you wan...

Page 147: ...alue Ethernet Type Specifies that the access profile will apply only to packets with this hexadecimal 802 1Q Ethernet type value hex 0x0 0xffff in the packet header The Ethernet type value may be set...

Page 148: ...do with the frame The entire process is described below CPU Interface Filtering State In the following window the user may globally enable or disable the CPU Interface Filtering mechanism by using th...

Page 149: ...f each packet header Select IP to instruct the Switch to examine the IP address in each frame s header VLAN Selecting this option instructs the Switch to examine the VLAN identifier of each packet hea...

Page 150: ...e the IP address in each frame s header VLAN Selecting this option instructs the Switch to examine the VLAN part of each packet header and use this as the criterion or part of the criterion for forwar...

Page 151: ...which you wish to filter dest port mask Specify a TCP port mask for the destination port in hex form hex 0x0 0xffff which you wish to filter Select UDP to use the UDP port number contained in an inco...

Page 152: ...cess ID Type in a unique identifier number for this access and priority This value can be set from 1 to 5 Type Selected profile based on Ethernet MAC Address or IP address Ethernet instructs the Switc...

Page 153: ...view the following window Figure 9 17 CPU Interface Filtering Entry Display window Ethernet The following window is the CPU Interface Filtering Rule Table for IP Figure 9 18 CPU Interface Filtering R...

Page 154: ...hernet MAC Address or IP address Ethernet instructs the Switch to examine the layer 2 part of each packet header IP instructs the Switch to examine the IP address in each frame s header VLAN Name Allo...

Page 155: ...DES 1228 ME Layer 2 Fast Ethernet Managed Switch 142 Figure 9 20 CPU Interface Filtering Entry Display window IP...

Page 156: ...he packet storm is monitored to determine if too many packets are flooding the network based on the threshold level provided by the user Once a packet storm has been detected the Switch will drop pack...

Page 157: ...dministration folder and selecting the disabled port and returning it to an Enabled status alternatively the user can wait for the auto recovery function which will occur after 5 minutes the auto reco...

Page 158: ...nd drop packets until the issue is resolved Shut Down Utilizes the Switch s software Traffic Control mechanism to determine the Packet Storm occurring Once detected the port will deny all incoming tra...

Page 159: ...arding in Spanning Tree windows and implementations though these ports will still be forwarding BPDUs to the Switch s CPU NOTE Ports that are in rest mode will be seen as link down in all windows and...

Page 160: ...options are Permanent The locked addresses will not age out after the aging timer expires DeleteOnTimeout The locked addresses will age out after the aging timer expires DeleteOnReset The locked addr...

Page 161: ...ing of the corresponding MAC address to be deleted Only entries marked Secured_Permanent can be deleted Click the Next button to view the next page of entries listed in this table This window displays...

Page 162: ...aning a user can enable or disable the function on the individual port IMP Global Settings This window is used to enable or disable the Trap Log State on the switch The Trap Log field will enable and...

Page 163: ...meter Description From Port To Port Select a port or range of ports to set for IP MAC Binding State Use the pull down menu to enable or disable these ports for IP MAC Binding Allow Zero IP Use the pul...

Page 164: ...ified Parameter Description IP Address Enter the IP address to bind to the MAC address set below MAC Address Enter the MAC address to bind to the IP Address set above Ports Specify the switch ports fo...

Page 165: ...zed device that has been blocked by the IP MAC binding restrictions enter the VLAN Name and MAC Address in the appropriate fields and click Find To delete an entry click the delete button next to the...

Page 166: ...witch including specifying a password This password is used to logon to the Switch once a secure communication path has been established using the SSH protocol 2 Configure the User Account to use a sp...

Page 167: ...will be disconnected and the user must reconnect to the Switch to attempt another login The number of maximum attempts may be set between 2 and 20 The default setting is 2 Session Rekeying Using the...

Page 168: ...n algorithm with Cipher Block Chaining The default is Enabled AES256 CBC Use the pull down to enable or disable the Advanced Encryption Standard AES 256 encryption algorithm with Cipher Block Chaining...

Page 169: ...his parameter should be chosen to use the publickey on a SSH server for authentication Host Name Enter an alphanumeric string of no more than 32 characters to identify the remote SSH user This paramet...

Page 170: ...ated client via SNMP with the Radius command item in auth mib OID 1 3 6 1 4 1 171 12 3 7 by port based or Host based NOTE If the session timeout attribute on the radius server is set the client will b...

Page 171: ...ure 10 14 The Authentication Server Authenticator The Authenticator the Switch is an intermediary between the Authentication Server and the Client The Authenticator servers two purposes when utilizing...

Page 172: ...ess and therefore successfully unlocks the port Once unlocked normal traffic is allowed to pass through the port The following figure displays a more detailed explanation of how the authentication pro...

Page 173: ...ss Control Figure 10 18 Example of Typical Port Based Configuration Once the connected device has successfully been authenticated the Port then becomes Authorized and all subsequent traffic on the Por...

Page 174: ...ate The Switch learns each attached devices individual MAC addresses and effectively creates a logical Port that the attached device can then use to communicate with the LAN via the Switch NOTE To ena...

Page 175: ...authenticates successfully the device will not assign a priority to this port If the priority attribute configured on the RADIUS is a value out of range 7 it will not be set to the device Guest VLANs...

Page 176: ...t undergo this procedure 2 Ports supporting Guest VLANs cannot be GVRP enabled and vice versa 3 A port cannot be a member of a Guest VLAN and a static VLAN simultaneously 4 Once a client has been acce...

Page 177: ...ings To configure the 802 1X Authenticator Settings click Security 802 1X 802 1X Authenticator Settings Figure 10 21 802 1X Authenticator Settings window To configure the settings by port click on its...

Page 178: ...authorized is selected the port will remain in the unauthorized state ignoring all attempts by the client to authenticate The Switch cannot provide authentication services to the client through the in...

Page 179: ...erver The default setting is 30 seconds MaxReq The maximum number of times that the Switch will retransmit an EAP Request to the client before it times out of the authentication sessions The default s...

Page 180: ...e Switch To view this window click Security 802 1X 802 1X User Figure 10 23 Local Users Configuration window Enter a User Name Password and confirmation of that password Properly configured local user...

Page 181: ...N the user must first configure a normal VLAN which can be enabled here for Guest VLAN status To configure these settings click Security 802 1X Configure 802 1X Guest VLAN the following window will be...

Page 182: ...ith an error message Disabled Selecting this option will disable ports listed in the Port List below as part of the Guest VLAN Be sure that these ports are configured for this VLAN or users will be pr...

Page 183: ...e how many times the device will resend an authentication request when the Radius server timeout occurs The default setting is 2 seconds Succession Choose the desired RADIUS server to configure First...

Page 184: ...uthentication Control The TACACS XTACACS TACACS RADIUS commands allow users to secure access to the Switch using the TACACS XTACACS TACACS RADIUS protocols When a user logs in to the Switch or tries t...

Page 185: ...cess to the Switch the Switch will ask the first Authentication Server Hosts for authentication If no authentication is made the second server host in the list will be queried and so on The built in A...

Page 186: ...onds The default setting is 30 seconds User Attempts 1 255 This command will configure the maximum number of times the Switch will accept authentication attempts Users failing to be authenticated afte...

Page 187: ...t Method List or other Method List configured by the user See the Enable Method Lists window in this section for more information Click Apply to implement changes made Authentication Server Group This...

Page 188: ...t Authentication Server Hosts must be configured for their specific protocol on a remote centralized server before this function can work properly NOTE The four built in server groups can only have se...

Page 189: ...IP address hyperlink revealing the following window Figure 10 35 Authentication Server Host Setting Edit window Configure the following parameters to add an Authentication Server Host Parameter Descri...

Page 190: ...rity Timeout 1 255 Enter the time in seconds the Switch will wait for the server host to reply to an authentication request The default value is 5 seconds Retransmit 1 255 Enter the value in the retra...

Page 191: ...local method is used the privilege level will be dependant on the local account privilege configured on the Switch Successful login using any of these techniques will give the user a User privilege o...

Page 192: ...h Enable Method Lists The Enable Method List Settings window is used to set up Method Lists to promote users with user level privileges to Administrator Admin level privileges using authentication met...

Page 193: ...Enable Method List click on its hyperlinked Method List Name To configure a Method List click the Add button Both actions will result in the same window to configure Figure 10 40 Enable Method List E...

Page 194: ...the user to be authenticated using the RADIUS protocol from a remote RADIUS server tacacs Adding this parameter will require the user to be authenticated using the TACACS protocol from a remote TACACS...

Page 195: ...Enabled field will result in a fail message Enable Admin Figure 10 43 Enable Admin window Figure 10 44 Enter Network Password dialog box The Enable Admin window is for users who have logged on to the...

Page 196: ...of segmenting the flow of traffic is similar to using VLANs to limit traffic but is more restrictive It provides a method of directing traffic that does not increase the overhead of the Master switch...

Page 197: ...ndow allows the user to determine which port on a given switch will be allowed to forward packets to other ports on that switch To configure traffic segmentation specify a port from that switch using...

Page 198: ...Snooping Group Browse Router Port VLAN Status Static ARP Settings ARP FDB Gratuitous ARP Settings Session Table Port Access Control CPU Utilization The CPU Utilization displays the percentage of the...

Page 199: ...ands for seconds The default value is one second Record Number Select number of times the Switch will be polled between 20 and 200 The default value is 200 Show Hide Check whether to display Five Secs...

Page 200: ...t Parameter Description Time Interval Select the desired setting between 1s and 60s where s stands for seconds The default value is one second Record Number Select number of times the Switch will be p...

Page 201: ...r use the Port pull down menu The user may also use the real time graphic of the Switch at the top of the web page by simply clicking on a port To view this window click Monitoring Packets Received RX...

Page 202: ...unts the number of packets received on the port Unicast Counts the total number of good packets that were received by a unicast address Multicast Counts the total number of good packets that were rece...

Page 203: ...se the Port pull down menu The user may also use the real time graphic of the Switch at the top of the web page by simply clicking on a port To view this window click Monitoring Packets UMB Cast RX Fi...

Page 204: ...00 Unicast Counts the total number of good packets that were received by a unicast address Multicast Counts the total number of good packets that were received by a multicast address Broadcast Counts...

Page 205: ...cs for use the Port pull down menu The user may also use the real time graphic of the Switch at the top of the web page by simply clicking on a port To view this window click Monitoring Packets Transm...

Page 206: ...ckets Counts the number of packets successfully sent on the port Unicast Counts the total number of good packets that were transmitted by a unicast address Multicast Counts the total number of good pa...

Page 207: ...ys error packets received by the Switch To select a port to view these statistics for select the port by using the Port pull down menu The user may also use the real time graphic of the Switch at the...

Page 208: ...e Counts packets received that were longer than 1518 octets or if a VLAN frame is 1522 octets and less than the MAX_PKT_LEN Internally MAX_PKT_LEN is equal to 1522 Fragment The number of packets less...

Page 209: ...lect the port by using the Port pull down menu The user may also use the real time graphic of the Switch at the top of the web page by simply clicking on a port To view this window click Monitoring Pa...

Page 210: ...LateColl Counts the number of times that a collision is detected later than 512 bit times into the transmission of a packet ExColl Excessive Collisions The number of packets for which transmission fa...

Page 211: ...are offered To select a port to view these statistics for select the port by using the Port pull down menu The user may also use the real time graphic of the Switch at the top of the web page by simp...

Page 212: ...8 and 255 octets in length inclusive excluding framing bits but including FCS octets 256 511 The total number of packets including bad packets received that were between 256 and 511 octets in length i...

Page 213: ...rding table to be viewed When the Switch learns an association between a MAC address and a port number it makes an entry into its forwarding table These entries are then used to forward packets throug...

Page 214: ...MAC address VID The VLAN ID of the VLAN of which the MAC address above corresponds MAC Address The MAC address entered into the address table Port The port to which the MAC address corresponds Type De...

Page 215: ...tations and to the PC connected to the console manager Click Next to go to the next page of the Switch History Log Clicking Clear will allow the user to clear the Switch History Log The information is...

Page 216: ...top left hand corner and clicking Search The user may also delete Data Driven learning entries by entering the VLAN Name and clicking Delete or Delete All Data Driven learning Entries The following p...

Page 217: ...that is dynamically configured by the Switch is designated by D To view this window click Monitoring Browse Router Port Figure 11 18 Browse Router Port window VLAN Status This window allows the VLAN...

Page 218: ...n entry select it on the ARP Settings table and click Modify Figure 11 22 Static ARP Settings Edit window ARP FDB This window conveniently allows the user to add entries to the IP MAC Port Binding Tab...

Page 219: ...23 ARP FDB window To search for information regarding a specific entry enter the appropriate information and click Find The ARP FDB entries will be displayed in the ARP FDB Table to add an entry to th...

Page 220: ...IPIF status up This is used to enable disable the sending of gratuitous ARP request packets while an IPIF interface comes up This is used to automatically announce the interface s IP address to other...

Page 221: ...ndows to monitor NOTE The Authenticator State Authenticator Statistics Authenticator Session Statistics and Authenticator Diagnostics windows in this section cannot be viewed on the Switch unless 802...

Page 222: ...cond between the most recent Access Reply Access Challenge and the Access Request that matched it from this RADIUS authentication server AccessRetrans The number of RADIUS Access Request packets retra...

Page 223: ...me server is counted as a retransmit as well as a timeout A send to a different server is counted as an Accounting Request as well as a timeout Requests The number of RADIUS Accounting Request packets...

Page 224: ...options when resetting the Switch Some of the current configuration parameters can be retained while resetting all other configuration parameters to their factory defaults Figure 11 29 Reset window N...

Page 225: ...t button to restart the Switch Save Changes The Switch has two levels of memory normal RAM and non volatile or NV RAM Configuration changes are made effective clicking the Apply button When this is do...

Page 226: ...DES 1228 ME Layer 2 Fast Ethernet Managed Switch 213 Logout Click the Logout button on the Logout window to immediately exit the Switch Figure 11 32 Logout window...

Page 227: ...FX DEM 211 Multi Mode 100BASE FX WDM Transceivers Supported DEM 330T TX 1550 RX 1310nm up to 10km Single Mode DEM 330R TX 1310 RX 1550nm up to 10km Single Mode DEM 331T TX 1550 RX 1310nm up to 40km S...

Page 228: ...ss POST is failure Light off Console off LED Per 10 100 Mbps Port Link Act Speed Green Amber Solid Green When there is a secure 100Mbps Fast Ethernet connection or link at any of the ports Blinking Gr...

Page 229: ...nternal Power Supply AC Input 100 240 VAC 50 60 Hz Performance Feature Detailed Description Wire speed on all FE GE ports Full wire speed full duplex operation on all FE GE ports Forwarding Mode Store...

Page 230: ...ZX DEM 210 Single Mode 100BASE FX DEM 211 Multi Mode 100BASE FX WDM Transceiver Supported 1 DEM 330T TX 1550 RX 1310nm up to 10km Single Mode 2 DEM 330R TX 1310 RX 1550nm up to 10km Single Mode 3 DEM...

Page 231: ...d to flash Username username IP ipaddr MAC macaddr Informational Configuration and log saved to flash by console Configuration and log saved to flash by console Username username Informational Upload...

Page 232: ...ded by console Log message successfully uploaded by console Username username Informational Log message upload was unsuccessful Log message upload was unsuccessful Username username IP ipaddr Warning...

Page 233: ...ew Root selected Instance InstanceID Root bridge MAC macaddr Priority value Informational BPDU Loop Back on port BPDU Loop Back on Port portNum Warning Spanning Tree Protocol is enabled Spanning Tree...

Page 234: ...AAA local method Username username Informational Login failed through Telnet authenticated by AAA local method Login failed through Telnet from userIP authenticated by AAA local method Username userna...

Page 235: ...by AAA server serverIP Username username Warning Login failed through Web due to AAA server timeout or improper configuration Login failed through Web from userIP due to AAA server timeout or imprope...

Page 236: ...Admin through Telnet authenticated by AAA local_enable method Successful Enable Admin through Telnet from userIP authenticated by AAA local_enable method Username username Informational Enable Admin...

Page 237: ...me username Warning Successful Enable Admin through Web authenticated by AAA server Successful Enable Admin through Web from userIP authenticated by AAA server serverIP Username username Informational...

Page 238: ...colname connection failed Warning Port security Port security has exceeded its maximum learning size and will not learn any new addresses Port security violation MAC macaddr Port portNum Warning IP an...

Page 239: ...p assigned egress bandwidth bandwidth_value Kbits to Port portNum Account user_account Informational Radius server assigned egress bandwith no limit to Port Radius server server_ip assigned egress ban...

Page 240: ...d V2 rfc2819 RMON MIB LldpRemTablesChange 1 0 8802 1 1 2 0 0 1 lldpStatsRemTablesInserts lldpStatsRemTablesDeletes lldpStatsRemTablesDrops lldpStatsRemTablesAgeouts V2 LLDP MIB coldStart 1 3 6 1 6 3 1...

Page 241: ...agentGratuitousARPMacAddr agentGratuitousARPPortNumber agentGratuitousARPInterfaceNa me V2 Genmgmt AGENT GENERAL MIB agentCfgOperCompleteTrap 1 3 6 1 4 1 171 12 1 7 2 0 9 unitID agentCfgOperate agent...

Page 242: ...a Type Maximum Distance Mini GBIC 1000BASE LX Single mode fiber module 1000BASE SX Multi mode fiber module 1000BASE LHX Single mode fiber module 1000BASE ZX Single mode fiber module 10km 550m 40km 80k...

Page 243: ...volved Bridges form a single logical network centralizing network administration broadcast A message sent to all destination devices on the network broadcast storm Multiple simultaneous broadcasts tha...

Page 244: ...protocol which allows IP to run over a serial line connection SNMP Simple Network Management Protocol A protocol originally designed to be used in managing TCP IP internets SNMP is presently implement...

Page 245: ...quidators expressly disclaim their warranty obligation pertaining to the product and in that case the product is being sold As Is without any warranty whatsoever including without limitation the Limit...

Page 246: ...pyright Statement No part of this publication or documentation accompanying this product may be reproduced in any form or by any means or used to make any derivative such as translation transformation...

Page 247: ...egistration Register your D Link product online at http support dlink com register Product registration is entirely voluntary and failure to complete or return this form will not diminish your warrant...

Page 248: ...original purchaser for the defective Hardware will be refunded by D Link upon return to D Link of the defective Hardware All Hardware or part thereof that is replaced by D Link or for which the purch...

Page 249: ...nty provided by D Link does not cover Products that have been subjected to abuse accident alteration modification tampering negligence misuse faulty installation lack of reasonable care repair or serv...

Page 250: ...ght Statement No part of this publication may be reproduced in any form or by any means or used to make any derivative such as translation transformation or adaptation without permission from D Link C...

Page 251: ...warranty period on this product U S and Canadian customers can contact D Link technical support through our website or by phone Tech Support for customers within the United States D Link Technical Su...

Page 252: ...uk ftp ftp dlink co uk Technische Unterst tzung Deutschland Web http www dlink de E Mail support dlink de Telefon 49 0 1805 2787 0 14 pro Minute Zeiten Mo Fr 09 00 17 30 Uhr sterreich Web http www dl...

Page 253: ...15ppm anytime Tech Support for customers within Belgium 070 66 06 40 www dlink be 0 175ppm peak 0 0875ppm off peak Tech Support for customers within Luxemburg 32 70 66 06 40 www dlink be Asistencia T...

Page 254: ...PO P od 09 00 do 17 00 Pevna linka 1 78 CZK min mobil 5 40 CZK min Technikai T mogat s Tel 06 1 461 3001 Fax 06 1 461 3004 Land Line 14 99 HUG min Mobile 49 99 HUF min email support dlink hu URL http...

Page 255: ...rt Center 64 11251 210 86 11 114 09 00 17 00 210 8611114 http www dlink gr support Assist ncia T cnica Assist ncia T cnica da D Link na Internet http www dlink pt e mail soporte dlink es Teknisk Suppo...

Page 256: ...nk biz hr Tehni na podpora Zahvaljujemo se vam ker ste izbrali D Link proizvod Za vse nadaljnje informacije podporo ter navodila za uporabo prosimo obi ite D Link ovo spletno stran www dlink eu www dl...

Page 257: ...o in E Mail helpdesk dlink co in techsupport dlink co in Indonesia Malaysia Singapore and Thailand Tel 62 21 5731610 Indonesia Tel 1800 882 880 Malaysia Tel 65 6501 4200 Singapore Tel 66 2 719 8978 9...

Page 258: ...2 21 4548158 92 21 4548310 Monday to Friday 10 00am to 6 00pm Web http support dlink me com E mail zkashif dlink me com South Africa and Sub Sahara Region Tel 27 12 665 2165 08600 DLINK for South Afri...

Page 259: ...D Link D Link D Link D Link 7 495 744 00 99 http www dlink ru e mail support dlink ru...

Page 260: ...mbia 01800 9525465 Lunes a Viernes 06 00am a 19 00pm Costa Rica 0800 0521478 Lunes a Viernes 05 00am a 18 00pm Ecuador 1800 035465 Lunes a Viernes 06 00am a 19 00pm El Salvador 800 6335 Lunes a Vierne...

Page 261: ...o Brasil durante o per odo de vig ncia da garantia deste produto Suporte T cnico para clientes no Brasil Hor rios de atendimento Segunda Sexta feira das 9 00h s 21 00h S bado das 8 00h s 15 00h Websit...

Page 262: ...D Link D Link D Link 0800 002 615 9 00 9 00 http www dlink com tw dssqa_service dlink com tw D Link http www dlink com tw...

Page 263: ...kumentasi pengguna dapat diperoleh pada situs web D Link Dukungan Teknis untuk pelanggan Dukungan Teknis D Link melalui telepon Tel 62 21 5731610 Dukungan Teknis D Link melalui Internet Email support...

Page 264: ...Technical Support Web Web URL http www dlink jp com...

Page 265: ...36 B 26F 02 05 100013 8008296688 028 66052968 028 85176948 http www dlink com cn 09 00 18 00...

Page 266: ...site 1 employee 2 9 10 49 50 99 100 499 500 999 1000 or more 3 What network protocol s does your organization use XNS IPX TCP IP DECnet Others_____________________________ 4 What network operating sys...

Page 267: ......

Reviews: