background image

Points to Note when using the Switch 3226 and Switch 3250

7

3Com recommends that you set individual ports that 
are to be members of an aggregated link to the same 
VLAN membership. This ensures communication 
between all VLANs at all times.

Telnet and HyperTerminal

Accessing the Command Line Interface via Telnet or 
Windows HyperTerminal using TCP/IP may not work 
correctly on some platforms unless it has been 
configured to send line feeds with carriage returns. To 
set this for Telnet enter 

set crlf

 when in command 

mode. To set this for HyperTerminal click on the 

Settings

 tab in the 

Properties

 screen, click 

ASCII Setup

 

and ensure that 

Send line ends with line feeds

 is 

checked within the 

ASCII Sending

 section.

You should not configure HyperTerminal in the above 
way if you are using a console cable to make a direct 
connection to the Switch.

Accessing the Command Line Interface is not possible 
using the default Telnet program supplied with Win-
dows XP. Use another Telnet program, such as Hyper-
terminal. See the 3Com Knowledgebase for updates 
and a solution, when available:

http://knowledgebase.3com.com

Port Security and Authentication

When enabling the static port security feature on a 
port the Switch will report 

static fail

 if you exceed 

the maximum number of secure addresses (200). 
The unit will not move the port into secure mode. 
3Com recommends that port security be enabled 

on only edge ports which will typically have only a 
few addresses.

If the address of a device is added as a static secure 
address on one port and then it is subsequently 
moved to a different port with security disabled 
then the device may get intermittent network 
connectivity. To fix this problem you should remove 
the address from the original port and consider 
enabling security on the new port. 

When configuring RADIUS using the CLI command 

security radius setup

 you should note that 

the wizard does not include a step to configure the 
RADIUS shared secret. You will need to configure 
the shared secret using the 

security radius 

sharedSecret 

command before RADIUS will 

operate.

The Switch does not log authentication requests or 
support logging to a RADIUS accounting server. 
Please use the logs generated on your RADIUS 
authentication server instead. 

To create a user with administrator privileges when 
using RADIUS device authentication you must 
ensure that user has the “Service-Type” attribute 
set to 15.

Some RADIUS servers will not authenticate users 
with a blank password, all user accounts should 
have a valid password configured.

Link aggregation and Gigabit ports

When manually configuring an aggregated link the 
switch may report the following error message:

Summary of Contents for SUPERSTACK 3 3226

Page 1: ... Switch and in PDF format on the 3Com Web site SuperStack 3 Switch 3226 and Switch 3250 Management Interface Reference Guide Part number DHA1750 0AAA01 supplied in HTML format on the CD ROM that accompanies your Switch and on the 3Com Web site You can obtain the latest technical information for your Switch including a list of known problems and solutions from the 3Com Knowledgebase http knowledgeb...

Page 2: ...peeds SuperStack 3 Switch 3226 and Switch 3250 Getting Started Guide Pages 15 and 16 contain the following statement The console port uses a standard null modem cable and is set to auto baud 8 data bits no parity and 1 stop bit This is incorrect It should read The console port uses a standard null modem cable and is set to 19200 baud 8 data bits no parity and 1 stop bit If you change the speed mak...

Page 3: ... Spanning Tree column of the VLAN table Please note that the product supports a single spanning tree state for all VLANs as per the 802 1d Spanning Tree specification It does not support 802 1s Spanning Tree per VLAN The LACP PartnerID field now reports LACP disabled if the protocol is disabled or not supported on the port Traffic Prioritization In previous versions of the software the DSCP priori...

Page 4: ...irmware the firmware supporting the normal encryption level 1 02 and the strong encryption firmware 1 02s both appear as 1 02 when using this command The encryption level of the current firmware can be verified by running the system summary command Static port security and the bridge MAC address table If static port security is enabled on a port with more than 200 addresses the previous software v...

Page 5: ...e users will need to apply for a user name and password A link to software downloads can be found from this http eSupport 3com com page or located from the www 3Com com home page To update the software on the Switch do the follow ing 1 Locate the software update for the Switch and run the filename exe executable file 2 If necessary download the TFTP server applications into the management station ...

Page 6: ...he Web interface or CLI if an incorrect TFTP server IP address or software upgrade filename is entered you will not be able to correct the IP address or filename until the TFTP upgrade operation has timed out The default time out period is 1 minute When attempting to upgrade the software on the unit it may occasionally report the following error Error File service in progress If you encounter this...

Page 7: ...c fail if you exceed the maximum number of secure addresses 200 The unit will not move the port into secure mode 3Com recommends that port security be enabled on only edge ports which will typically have only a few addresses If the address of a device is added as a static secure address on one port and then it is subsequently moved to a different port with security disabled then the device may get...

Page 8: ...pting to enable the trunk with the linkState command will respond with an error that the trunk can not be configured In order to form the LACP trunk you must manually re enable the individual trunk member ports using the physicalInterface ethernet portState CLI command SFP Modules When adding or removing SFP modules the switch will reset a number of port parameters 3Com recommends that you verify ...

Page 9: ...e unit to a network with a DHCP server If using DHCP you will need to use a console connection or log information from your DHCP server to discover the address which has been assigned to the unit Reconfiguring an IP interface may cause the RIP configuration and static routes settings for that interface to be lost When adding or modifying an IP interface the CLI and Web interface may appear to hang...

Page 10: ...they traverse the network The Switch prioritizes traffic internally but does not mark or remark packets other than NBX packets NBX traffic is remarked to DSCP 46 and 802 1d priority 6 VLAN Configuration Every port on the unit must be an untagged member of a single VLAN Every port defaults to being an untagged member of VLAN1 If you add the port as an untagged member of another VLAN then this will ...

Page 11: ...want to avoid these warnings The software to generate these certificates is beyond the scope of this document The presence of both a secure HTTPS and insecure HTTP Web interface on a single unit causes some browsers to incorrectly report the following warning message This page contains both secure and insecure items Do you wish to proceed This warning message may be safely ignored All traffic to a...

Page 12: ...settings If you try to change spanning tree settings while the protocol is disabled the following error messages will be generated Failed to set forward time Failed to set hello time When you enable spanning tree all spanning tree settings are reset to their default values If you want to use custom settings for spanning tree you must configure spanning tree after enabling it Roving Analysis Port W...

Page 13: ...eed and duplex When autonegotiation is enabled the unit asks for a fallback mode to be entered for use when the port connects to a non autonegotiation device This fallback mode parameter has been left in the CLI for compatibility with other 3Com devices but is ignored by this device When connected to a device that will not autonegotiate the device follows the algorithm required by the autonegotiat...

Page 14: ...om Network Supervisor 3Com Network Supervisor provides powerful yet easy to use network management Focused on the needs of small to medium enterprises it enables you to manage your network more efficiently For larger networks up to 2 500 nodes and extra functionality you can purchase the 3Com Network Supervisor Advanced Package To download the latest 3Com Network Supervisor and Service Pack please...

Reviews: