background image

4-6

C

HAPTER

 4: M

ANAGING

 T

HE

 S

WITCH

 3000 TX

Assigning Local Security

The Local Security screen shows a matrix of options 
for access method (Console Port, Remote Telnet, 
Community-SNMP) and access level.

These steps assume the User Access Levels screen is 
displayed.

1

Select the LOCAL SECURITY option. The Local Secu-
rity screen is displayed, as shown in 

Figure 4-6

.

2

Fill in the fields as required.

3

When you have filled in the form, select OK.

The access option are:

Console Port

 

Enabled / Disabled

 To prevent access 

to the management facilities via the console port, 
disable access to the facility for each access level. 
Console port access for 

Security

 is enabled and 

cannot be changed. This prevents accidental dis-
abling of all access levels from management.

Remote Telnet

 

Enabled / Disabled

 Telnet is an inse-

cure protocol. You may want to disable all access 
to the management facilities via Telnet if there is 
important or sensitive data on your network.

Community-SNMP

 

Enabled / Disabled

 The Switch 

can be managed via SNMP using a remote Network 
Manager. Community-SNMP does have some 
simple security features, but it is an insecure proto-
col. You may want to disable all access to the man-
agement facilities if there is important or sensitive 
data on your network.

Figure 4-6   

Local Security screen

Summary of Contents for SuperStack II 3000 TX

Page 1: ... http www 3com com SuperStack II Switch 3000 TX 8 Port User Guide Agent Software Version 3 1 Document No DUA1694 1AAA04 Published June 1997 ...

Page 2: ...entre Boundary Way Hemel Hempstead Herts HP2 7YU United Kingdom For civilian agencies Restricted Rights Legend Use reproduction or disclosure is subject to restrictions set forth in subparagraph a through d of the Commercial Computer Software Restricted Rights Clause at 48 C F R 52 227 19 and the limitations set forth in 3Com Corporation s standard commercial agreement for the software Unpublished...

Page 3: ...undant Power System Socket 1 9 Reset Button 1 9 Console Port 1 9 Plug in Module Slot 1 9 Ethernet Address 1 9 Unit Defaults 1 10 Managing the Switch 3000 TX 1 10 Quick Start For SNMP Users 1 11 Entering an IP Address for the Switch 1 11 2 INSTALLATION AND SETUP Following Safety Information 2 1 Positioning the Switch 3000 TX 2 1 Configuration Rules for Fast Ethernet 2 2 Configuration Rules with Ful...

Page 4: ...ress 4 17 By Port 4 17 Adding an Entry into the SDB 4 17 Deleting an Entry from the SDB 4 17 Specifying that an Entry is Permanent 4 17 Setting Up Resilient Links 4 18 Configuring Resilient Links 4 19 Creating a Resilient Link Pair 4 20 Deleting a Resilient Link Pair 4 20 Viewing the Resilient Links Setup 4 21 Setting Up Traps 4 23 Setting up the Console Port 4 24 Resetting the Switch 3000 TX 4 26...

Page 5: ...tory 5 22 Alarms 5 22 Hosts 5 23 Hosts Top N 5 23 Matrix 5 23 Filter 5 23 Capture 5 23 Events 5 23 Benefits of RMON 5 24 RMON and the Switch 5 24 RMON Features of the Switch 5 25 About Alarm Actions 5 26 About Default Alarm Settings 5 27 About the Audit Log 5 27 6 STATUS MONITORING AND STATISTICS Summary Statistics 6 2 Port Statistics 6 3 Port Traffic Statistics 6 4 Port Error Analysis 6 6 Status ...

Page 6: ...ECHNICAL SUPPORT Online Technical Services F 1 World Wide Web Site F 1 3Com Bulletin Board Service F 1 Access by Analog Modem F 1 Access by Digital Modem F 2 3ComFacts Automated Fax Service F 2 3ComForum on CompuServe Online Service F 2 Support from Your Network Supplier F 3 Support from 3Com F 3 Returning Products for Repair F 4 GLOSSARY INDEX 3COM CORPORATION LIMITED WARRANTY ELECTRO MAGNETIC CO...

Page 7: ...TX 8 Port is referred to as the Switch 3000 TX or Switch How to Use This Guide This table shows where to find specific information in this guide If you are looking for Turn to An overview of the Switch Chapter 1 Information about installing the Switch into your net work Chapter 2 Information about the methods you can use to manage the Switch Chapter 3 Information about managing the Switch Chapter ...

Page 8: ...ord enter in this guide you must type something and then press the Return or Enter key Do not press the Return or Enter key when an instruction simply says type Key names Key names appear in text in one of two ways Referred to by their labels such as the Return key or the Escape key Written with brackets such as Return or Esc If you must press two or more keys simulta neously the key names are lin...

Page 9: ...s in the Switch Database Store and forward forwarding mode ensuring the switch forwards all valid Ethernet frames and discards invalid Ethernet frames such as those with an incorrect CRC Intelligent Flow Management for congestion con trol Full Duplex on all fixed ports and Fast Ethernet Plug in Module ports Resilient Links Support for 16 Virtual LANs VLANs Spanning Tree Protocol STP per VLAN PACE ...

Page 10: ...h is connected to another switch or endstation IFM prevents packet loss and inhibits the device from generating more packets until the period of congestion ends IFM should be enabled on a port if it is connected to another switch or an endstation IFM should be disabled on a port connected to a repeater For more information about enabling IFM refer to Setting Up the Switch Ports on page 4 11 Full D...

Page 11: ... allows you to implement parallel paths for network traffic and ensure that Redundant paths are disabled when the main paths are operational Redundant paths are enabled if the main traffic paths fail For more information about STP refer to Spanning Tree Protocol on page 5 12 PACE The Switch 3000 TX supports PACE Priority Access Control Enabled technology which allows multime dia traffic to be carr...

Page 12: ...s The following two illustrations show some exam ples of how the Switch 3000 TX can be used on your network Figure 1 1 The Switch 3000 TX used as a data center switch Examples of how the Switch 3000 TX can be used in a VLAN based network are given in Chapter 5 ...

Page 13: ...Network Configuration Examples 1 5 Figure 1 2 Increasing port density with the Switch 3000 TX ...

Page 14: ...1 6 CHAPTER 1 GETTING STARTED Unit Overview Front Figure 1 3 Switch 3000 TX front view ...

Page 15: ...resent port is enabled Green flashing Link is present port is disabled Off Link is not present Plug in Module Status LEDs port 9 Packet Yellow Frames are being transmitted received on the Plug in Module port Status Green Link is present port is enabled Green flashing Link is present port is disabled Green flashing long on short off Refer to the SuperStack II Switch ATM OC 3c Module User Guide Yell...

Page 16: ...1 8 CHAPTER 1 GETTING STARTED Unit Overview Rear Figure 1 4 Switch 3000 TX rear view ...

Page 17: ...ower off on cycle This has the same effect as carrying out a reset via the VT100 interface refer to Resetting the Switch 3000 TX on page 4 26 Console Port Connect a terminal to the console port to carry out remote or local out of band configuration and man agement Configuration for the console port is set to auto baud 8 data bits no parity and 1 stop bit Plug in Module Slot Use this slot to instal...

Page 18: ...sed management facility can manage the unit if the Management Information Base MIB is installed correctly in the management workstation The Switch 3000 TX supports SNMP over both IP and IPX protocols Port Status Enabled Intelligent Flow Management Enabled Duplex Mode Half duplex on all relevant ports Virtual LANs All ports use Port VLAN Mode and belong to the Default VLAN VLAN 1 PACE Disabled Span...

Page 19: ...l should be configured to 9600 line speed baud rate 8 data bits no par ity and 1 stop bit Refer to Connecting a VT100 Terminal on page 2 7 2 Press Return one or more times until the Main Banner screen is displayed 3 At the Main Banner screen press Return to dis play the Logon screen Log on using the default user name admin no password is required Select OK 4 The Main Menu is displayed From this me...

Page 20: ...1 12 CHAPTER 1 GETTING STARTED ...

Page 21: ...t containing two mounting brackets and six screws is supplied with the Switch When deciding where to site the unit ensure that You are able to meet the configuration rules detailed in the following section The unit is accessible and cables can be con nected easily Cabling is away from Sources of electrical noise such as radios transmitters and broadband amplifiers Power lines and fluorescent light...

Page 22: ...5m 1066ft is allowed in single repeater topologies one hub stack per wiring closet with a fiber run to the collapsed backbone For example a 225m 738ft fiber downlink from a repeater to a router or switch plus a 100m 328ft UTP run from a repeater out to the endstations Configuration Rules with Full Duplex The Switch 3000 TX provides full duplex support for all its fixed ports and Fast Ethernet Plug...

Page 23: ...Configuration Rules with Full Duplex 2 3 Figure 2 1 Fast Ethernet configuration rules ...

Page 24: ...hten with a suit able screwdriver 4 Repeat steps 2 and 3 for the other side of the unit 5 Insert the unit into the 19 inch rack and secure with suitable screws not provided Ensure that ventila tion holes are not obstructed 6 Connect network cabling Stacking the Switch and Other Units If the units are free standing up to four units can be placed on top of one another If mixing a variety of SuperSta...

Page 25: ...with a suitable screwdriver 4 Repeat for the other side of the unit 5 Ensure that the wall you are going to use is smooth flat dry and sturdy Attach a piece of plywood approximately 305mm x 510mm x 12mm 12in x 20in x 0 5in securely to the wall if necessary and mount the Switch as follows a Position the base of the unit against the wall or plywood ensuring that the ventilation holes face sidewards ...

Page 26: ... Switch is oper ating correctly refer to LEDs on page 1 7 Connecting a Redundant Power System RPS You can connect a Redundant Power System RPS to the Switch At 5V the current requirement for the Switch is 4 8A excluding a Plug in Module Check the docu mentation supplied with your Plug in Module for power consumption figures For most configurations you need only one Super Stack II RPS output and th...

Page 27: ... Terminal To connect a VT100 terminal directly to the console port on the Switch you need a standard null modem cable 1 Connect one end of the cable to the console port on the Switch and the other to the console port on the VT100 terminal 2 Ensure that your terminal is set to 8 data bits no parity 1 stop bit If auto configuration is enabled for the Switch the terminal s line speed baud rate is det...

Page 28: ...P Cables required for this connection depend on the type of workstation you are using You must config ure the workstation to run SLIP Refer to the docu mentation supplied with the workstation for more details You must configure the console port of the Switch to accept SLIP and set up the SLIP parameters address and subnet mask Refer to Switch Man agement Setup on page 3 9 You may need a 5 wire cab...

Page 29: ...management user sessions concurrently for example one con sole port and three Telnet connections You can establish VT100 management communica tion with the Switch through two different inter faces Via the Console Port You can access the local management interface using a VT100 termi nal or PC using suitable terminal emulation soft ware The terminal can be connected directly to the Switch or via a ...

Page 30: ...g on Managing Over The Network Any Network Manager running the Simple Network Management Protocol SNMP can manage the Switch provided the MIB Management Informa tion Base is installed correctly on the management workstation Each Network Manager provides its own user inter face to the management facilities 3Com s Tran scend range of Network Managers all have facilities for managing the Switch The S...

Page 31: ...f you do not have a registered IP address you may be using an identical address to someone else and your network will not operate correctly Obtaining a Registered IP Address InterNIC Registration Services is the organization responsible for supplying registered IP addresses The following contact information is correct at the time of publication Network Solutions Attn InterNIC Registration Service ...

Page 32: ... wish to replace the default simply enter a new value for this field the default entry is erased Press Down Arrow or Return to move to the next field Button OK Text for a button is always shown in uppercase letters A button carries out an action for example OK or CANCEL To operate a button move the cursor to the button and press Return List Box monitor manager security A listbox allows you to sele...

Page 33: ...aracter in an editable field Ctrl R refreshes the screen Ctrl B moves the cursor to the next button Ctrl P aborts the current screen and returns you to the previous screen Ctrl N actions the inputs for the current screen and moves to the next screen Ctrl K displays a list of the available key strokes Correcting Text Entry Use Delete on a VT100 terminal or Backspace on a PC This moves the cursor on...

Page 34: ...ocol the Switch is allocated an IPX address automatically You can start the SNMP Network Manager and begin managing the Switch If you are using IP without a BOOTP server you must enter the IP address of the Switch before the SNMP network manager can communicate with the device To do this take the following steps Figure 3 1 Main Banner 1 At your terminal press Return one or more times until the Mai...

Page 35: ...e Switch for management we suggest that you log on first as admin Figure 3 2 Logon screen Table 3 1 Default Users User Name Default Password Access Level monitor monitor monitor this user can view but not change all manageable parameters manager manager manager this user can access and change the operational parameters but not special security features security security security this user can acce...

Page 36: ...o options depends on the access level you have been assigned Access rights to the VT100 screens for the Switch are listed in Appendix B If you are a user with security access level and are using the management facility for the first time we suggest that you Assign a new password for your user using the Edit User screen as described in Editing User Details on page 4 5 Log on as each of the other de...

Page 37: ...determine the type of self test that the Switch carries out when it is powered up If the field is set to Normal the Switch performs a Fast Boot a basic confidence check lasting approximately 15 seconds When the Switch per forms a Fast Boot it carries out the following tests Checksum test of boot and system areas of Flash memory System memory tests MAC address verification test Figure 3 4 Managemen...

Page 38: ...wered up In addition to mapping an IP address BOOTP can also assign the subnet mask and default router Using a BOOTP server avoids having to configure devices individu ally SLIP Address If you are using SLIP enter an address that has a network part different to the network address of the Switch For more information con tact your network administrator You must reset the Switch after changing this p...

Page 39: ...tting up the Switch for Management 3 11 CONSOLE PORT Select this button to display the setup screen for console port parameters Console port setup is described in Setting up the Console Port on page 4 24 ...

Page 40: ...ys for 3 min utes the management facility warns you that the inactivity timer is about to expire If you do not press a key within 10 seconds the timer expires and the screen is locked any displayed statistics continue to be updated When you next press any key the display changes to the Auto Logout screen The Auto Logout screen see Figure 3 5 requests you to enter your password again If the passwor...

Page 41: ...l management facilities for the Switch While following steps in these chap ters you may find the screen map below useful If an ATM OC 3c Module is installed in the Switch extra screens are available Refer to the SuperStack II Switch ATM OC 3c Module User Guide for more information ...

Page 42: ...ows you to set up access levels for users on the Switch CREATE USER screen This allows you to create up to 10 users in addition to the default users set up on the Switch DELETE USERS screen This allows you to delete users from the Switch The default users cannot be deleted EDIT USER screen This allows you to change your own password and community string You cannot change details for other users Fi...

Page 43: ...en Access Level Assign an access level for the new user as follows monitor access to view but not change a subset of the manageable parameters of the Switch secure monitor as monitor manager access to all the manageable param eters of the Switch except security features specialist as manager security access to all manageable parameters of the Switch Figure 4 3 Create User screen Community String B...

Page 44: ...en is displayed 1 Select the DELETE USERS option The Delete Users screen is displayed as shown in Figure 4 4 2 Use the spacebar to highlight the user that you want to delete Note that you cannot delete default users or the current user that is yourself 3 Select DELETE USERS Figure 4 4 Delete Users screen ...

Page 45: ...be changed if you need to change the user name you must delete the user and create a new one Old Password To change the user s password you need to enter the current password in this field New Password This field allows you to enter a new password for the user Confirm Password Re enter the new password into this field Community String This field allows you to enter a community string for the user ...

Page 46: ...he console port disable access to the facility for each access level Console port access for Security is enabled and cannot be changed This prevents accidental dis abling of all access levels from management Remote Telnet Enabled Disabled Telnet is an inse cure protocol You may want to disable all access to the management facilities via Telnet if there is important or sensitive data on your networ...

Page 47: ...LAN If you choose Port the screen is displayed similar to Figure 4 7 and all operations that you initialize from this screen relate to an individual port If you choose Unit the screen is displayed similar to Figure 4 8 and all operations relate to the Switch unit If you choose VLAN the screen is displayed similar to Figure 4 9 and all operations relate to VLANs Port ID 1 2 3 7 8 9 If you choose to...

Page 48: ... management you have chosen port or unit Refer to Chapter 6 SDB Use this button to display the Unit Database View screen which is used to manage the Switch Database Refer to The Database View on page 4 16 RESILIENCE Use this button to display resilient link management screens for the level of management you have chosen port or unit Refer to Setting Up Resilient Links on page 4 18 You cannot set up...

Page 49: ...s Implicit Class of Service When multimedia traf fic is transmitted it is given a higher priority than other data and is therefore forwarded ahead of other data when it arrives at the Switch The Implicit Class of Service feature minimizes latency through the Switch and protects the quality of multimedia traffic Figure 4 10 Unit Setup screen Interactive Access When two way multimedia traffic passes...

Page 50: ...d allows you to specify the duplex mode of ports that have Unit Default specified in the Duplex Mode field of in the Port Setup screen The default setting is Half Duplex For more infor mation about Duplex Mode refer to Setting Up the Switch Ports on page 4 11 Full duplex is not supported on a port with Intelli gent Flow Management IFM enabled Therefore you cannot set the Duplex Mode field to Full ...

Page 51: ...lows you to enable or disable the port To prevent unauthorized access we recommend that you disable any unused ports Link State Present Not Available This read only field shows the state of the link Present The port is operating normally Not Available The link has been lost Figure 4 11 Port Setup screen Lost Links This read only field displays the number of times the link has been lost since the S...

Page 52: ...N Mode refer to the VLAN Configuration Mode field you cannot specify that the port is a VLT port Duplex Mode Half Duplex Full Duplex Unit Default This field allows you to specify the duplex mode of the port Full Duplex Full duplex allows frames to be transmitted and received simultaneously and in effect doubles the potential throughput of a link In addition full duplex also supports 100BASE FX cab...

Page 53: ...rt disable port notify blip blip port notify Use this field to specify the action for the alarm to take when it reaches the rising threshold none no action takes place event an SNMP trap is generated disable port the port is disabled disable port notify the port is disabled and an SNMP trap is generated blip the broadcast and multicast traffic on the port is blocked for 5 seconds blip port notify ...

Page 54: ...dth over the previous 20 second interval The average is based on four samples taken at 5 second intervals When the average value exceeds the rising threshold value the rising action is triggered The action is not triggered again until the aver age broadcast bandwidth falls below the falling threshold level ...

Page 55: ...ntries using a MIB browser an SNMP Network Manager or the Unit Database View screen described in the following sections There are three types of entries in the SDB Ageing entries Initially all entries in the data base are ageing entries Entries in the database are removed aged out if after a period of time ageing time the device has not transmitted This prevents the database from becoming full wit...

Page 56: ...u to specify that the current entry is permanent Refer to the previous section Setting Up the Switch Database SDB for a description of permanent and ageing entries You cannot specify that the current entry is perma nent if the port uses AutoSelect VLAN Mode For more information refer to Using AutoSelect VLAN Mode on page 5 4 Figure 4 12 Unit Database View screen A listbox containing the following ...

Page 57: ... Address field by moving into the field and pressing the spacebar 2 In the Port Number field enter the port ID for which you want MAC addresses displayed 3 Select FIND The listbox shows entries in the data base for that port only Adding an Entry into the SDB 1 In the MAC Address field enter the MAC address of the device 2 In the Port Number field enter the port identifier for this device 3 Select ...

Page 58: ... that it carries the data In addition the main port is disabled If a main link has a higher bandwidth than its standby link traffic is automatically switched back to the main link provided no loss of link is detected for two minutes Otherwise you need to manually switch traffic back to the main link When setting up resilient links you should note the following Up to four resilient link pairs can b...

Page 59: ...e port is not present in the cur rent hardware Standby Port ID This field shows the current standby port ID and allows you to enter a new port ID The standby port must be in the same VLAN as the main port Media Type Twisted Pair Fiber This read only field indicates the standby port media type Figure 4 14 Switch Port Resilience screen Link State Available Not Available Not Present This read only fi...

Page 60: ...air you must remove cabling from the ports to avoid creating loops in your network configuration Creating a Resilient Link Pair 1 Ensure that the port nominated as the standby port is not physically connected to the unit 2 Ensure both ports have an identical port security mode configuration and that they are members of the same VLAN 3 At the Switch Management screen select the port to be configure...

Page 61: ...ing traffic Both Failed Although the resilient link pair is correctly configured both links have failed Check for any loose connections or cable damage Unknown The network configuration has changed and the resilient link pair no longer con forms to the rules Not Available This resilient link pair is disabled Figure 4 15 Unit Resilience Summary screen Active Port Main Standby Both Failed This field...

Page 62: ...ether this resilient link pair is currently enabled or disabled You enable or disable a resilient link pair using the Port Resilience screen described in Con figuring Resilient Links on page 4 19 OK This button allows you to access the Port Resil ience screen for the current resilient link pair ...

Page 63: ... traps should be sent Community String This field allows you to enter community strings for each remote Network Man ager allowing a very simple method of authentica tion between the Switch and the remote Network Manager The text string can be of 32 characters or less If you want a Network Manager to receive traps generated by the device you must enter the community string of the Network Manager in...

Page 64: ...Local DCD Control Enabled Disabled This field is only applicable to local connection types It determines if DCD is required for a local connection and whether the connection is closed if DCD is removed Refer to your terminal or modem user documenta tion if you are unsure of the correct setting Figure 4 17 Console Port Setup screen DSR Control Enabled Disabled This field is only applicable to local...

Page 65: ...et automatically Char Size 8 This read only field displays the charac ter bit data bit size for the Switch You should set your terminal to the same value Parity NONE This read only field displays the parity setting for the Switch You should configure your terminal to the same setting Stop Bit 1 This read only field displays the stop bit setting for the Switch You should configure your terminal to ...

Page 66: ... From the Main Menu select the RESET option The Reset screen is displayed as shown in Figure 4 18 2 Select OK Resetting the Switch in this way is similar to per forming a power off on cycle No setup information is lost CAUTION Performing a reset may cause some of the data being transmitted at that moment to be lost Figure 4 18 Reset screen ...

Page 67: ...on is cleared from memory and cannot be recovered After initialization all user information is lost and only default users are available All ports are set to their default values and are therefore enabled and available to all users When initializing the Switch take particular note of the following Network loops occur if you have set up resilient links Before initializing the Switch ensure you have...

Page 68: ... if you have a Boot software version lower than version 2 0 The download does not work over an ATM link To upgrade Switch management software 1 From the Main Menu select the SOFTWARE UPGRADE option The Software Upgrade screen is displayed as shown in Figure 4 20 2 From the Destination field select Switch this is the default Figure 4 20 Software Upgrade screen 3 In the File Name field enter the nam...

Page 69: ...hich physically connects them the segments are defined by flexible user groups that you create using software With VLANs you can define your network according to Departmental groups For example you can have one VLAN for the Marketing department another for the Finance department and another for the Development department Hierarchical groups For example you can have one VLAN for directors another f...

Page 70: ...quire it or not VLANs increase the efficiency of your network because each VLAN can be set up to contain only those devices which need to communicate with each other How VLANs Provide Extra Security Devices within each VLAN can only communicate with devices in the same VLAN If a device in VLAN 1 needs to communicate with devices in VLAN 2 the traffic must cross a router An Example Figure 5 1 shows...

Page 71: ...p VLANs on the Switch on page 5 8 Connecting VLANs to a Router If the devices in a VLAN need to talk to devices in a different VLAN each VLAN requires a connection to a router Communication between VLANs can only take place if they are all connected to the router A VLAN not connected to a router is an isolated VLAN You need one port for each VLAN connected to the router Connecting Common VLANs Bet...

Page 72: ...port to another the Switch learns the MAC address of the endstation Figure 5 2 Switch learns the endstation s MAC address 2 If the relevant port uses AutoSelect VLAN Mode the Switch refers to the VLAN Server to determine the VLAN membership of the endstation Figure 5 3 Switch refers to the VLAN Server 3 Having obtained the VLAN membership for the end station the Switch places the relevant port in ...

Page 73: ... refer to Setting Up VLANs Using AutoSelect VLAN Mode on page 5 10 For more information about the VLAN Server data base refer to the documentation supplied with 3Com s Transcend Enterprise Manager Using Non routable Protocols If you are running non routable protocols on your network for example DEC LAT or NET BIOS devices within one VLAN are not able to communi cate with devices in a different VLA...

Page 74: ...00 TX is a backbone port For more information about backbone ports refer to the SuperStack II Switch 1000 User Guide b Specify that each Switch 1000 port connected to the Switch 3000 TX is a VLT port c Specify that each Switch 3000 TX port con nected to a Switch 1000 is a VLT port 4 Connect port 1 of the Switch 3000 TX to Server 1 5 Connect port 2 of the Switch 3000 TX to Server 2 6 Use the VT100 ...

Page 75: ...Virtual LANs VLANs 5 7 Figure 5 5 VLAN configuration with a Switch 3000 TX as a basement switch ...

Page 76: ...link which carries traffic for all the VLANs on each Switch For more information about VLTs in general refer to VLANs and the Switch 3000 TX on page 5 3 To specify that a port is a VLT port refer to Setting Up the Switch Ports on page 4 11 Figure 5 6 VLAN Setup screen Standby The port is the standby port of a resilient link pair The main port of the pair is displayed in brackets For more informati...

Page 77: ...PLY This button applies any changes to the VLAN database ATM LEC Setup If the port is an ATM OC 3c Module port this button allows you access the VLAN LEC Setup screen for extending your VLANs into an ATM network For more information refer to the SuperStack II Switch ATM OC 3c Module User Guide Assigning a Port to a VLAN When Using Port VLAN Mode 1 In the Port ID field enter the ID of the required ...

Page 78: ...er the IP address of your VLAN Server in this field Backup VLAN Server IP Address This field allows you to enter the IP address of a backup VLAN Server A backup VLAN Server can be used to supply VLAN allocations when the Switch cannot access the main VLAN Server VLAN Server Community String This field allows you to enter a community string for the VLAN Server s The default community string is publ...

Page 79: ... AutoSelect VLAN Mode To specify that the Switch uses AutoSelect VLAN Mode refer to Setting Up the Switch Unit on page 4 9 To specify that a port on the Switch uses AutoSe lect VLAN Mode refer to Setting Up the Switch Ports on page 4 11 ...

Page 80: ... paths for network traffic and ensure that Redundant paths are disabled when the main paths are operational Redundant paths are enabled if the main paths fail As an example Figure 5 8 shows a network contain ing three LAN segments separated by three bridges With this configuration each segment can commu nicate with the others using two paths This config uration creates loops which cause the networ...

Page 81: ...Spanning Tree Protocol 5 13 Figure 5 8 A network that creates loops Figure 5 9 Traffic flowing through Bridges C and A Figure 5 10 Traffic flowing through Bridge B ...

Page 82: ...network 1 Each network segment has one Designated Bridge Port All traffic destined to pass in the direction of or through the Root Bridge flows through this port The Designated Bridge Port is the port which has the lowest Root Path Cost for the segment The Root Path Cost consists of the path cost of the Root Port of the bridge plus the path costs across all the Root Ports back to the Root Bridge T...

Page 83: ...h Cost the route through Bridge C and B has a cost of 200 the route through Bridge Y and B has a cost of 300 You can set the path cost of a bridge port to influence the configuration of a network with a duplicate path Once the network topology is stable all the bridges listen for special Hello BPDUs transmitted from the Root Bridge at regular intervals If the STP Max Age time of a bridge expires r...

Page 84: ...cov ers a duplicate path and disables one of the links If the enabled link breaks the disabled link becomes re enabled therefore maintaining con nectivity Configuration 2 Redundancy through Meshed Backbone In this configuration four Switch 3000 TX units are connected such that there are multiple paths between them STP discovers the duplicate paths and disables two of the links If an enabled link b...

Page 85: ...gement screen is displayed 2 In the Management Level field choose Unit 3 Choose the SETUP button The Unit Setup screen is displayed as shown in Figure 5 13 4 In the Spanning Tree field specify Enable 5 Choose OK You cannot enable STP if you have set up resilient links on any of the Switch ports or if you are using VLAN 16 Figure 5 13 Unit Setup screen ...

Page 86: ...is field allows you to specify the VLAN to be configured If you are using STP you cannot use VLAN 16 Also if you are using AutoSelect VLAN Mode you cannot use VLAN 15 In these cases the relevant VLANs are used internally by the Switch and are therefore not available Figure 5 14 VLAN STP screen Topology Changes This read only field shows the number of network topology changes that have occurred in ...

Page 87: ...ng for this field is 32768 Bridge Max Age 6 40 This field allows you to specify the time in seconds that the Switch waits before trying to re configure the network when it is the Root Bridge If the Switch has not received a BPDU within the time specified in this field it will try to re configure the STP topology The default set ting for this field is 20 seconds The time must be greater than or equ...

Page 88: ...packets and does not participate in STP opera tion Listening A port in this state is preparing to forward packets but has temporarily blocked to prevent a loop During the Listening state BPDUs are transmitted received and processed Figure 5 15 Port STP screen Blocking A port in this state does not forward packets to prevent more than one active path existing on the network The port is included in ...

Page 89: ...iority of the port you can make it more or less likely to become the Root Port The lower the number the more likely it is that the port will be the Root Port The default setting for this field is 128 Path Cost 0 65535 This field allows you to spec ify the path cost of the port The Switch automatically assigns the default path costs shown in Table 5 1 on page 5 14 If you spec ify a new path cost in...

Page 90: ...mmuni cates with the RMON probe and collects the sta tistics from it The workstation does not have to be on the same network as the probe and can manage the probe by in band or out of band connections About the RMON Groups The IETF define nine groups of Ethernet RMON sta tistics This section describes these groups and details how they can be used Statistics The Statistics group provides traffic an...

Page 91: ...LAN segment or VLAN For each pair the Matrix group maintains counters of the number of packets number of octets and error packets between the nodes The conversation matrix helps you to examine net work statistics in more detail to discover who is talk ing to whom or if a particular PC is producing more errors when communicating with its file server for example Combined with Hosts Top N this allows...

Page 92: ... workstation and also generates large amounts of traffic An RMON probe however autonomously looks at the network on behalf of the management workstation without affecting the characteristics and performance of the network The probe reports by exception which means that it only informs the management workstation when the network has entered an abnormal state RMON and the Switch RMON requires one pr...

Page 93: ...out Alarm Actions on page 5 26 and About Default Alarm Settings on page 5 27 Hosts Although Hosts is supported by the Switch there are no Hosts sessions defined on a new or initialized Switch by default You can specify that a Hosts session is defined on the Default VLAN for more information refer to Setting Up the Switch Unit on page 4 9 Hosts Top N Although Hosts Top N is supported by the Switch ...

Page 94: ...le 5 3 Alarm Actions Action High Threshold Low Threshold No action Notify only Send Trap Notify and blip port Send Trap Block broad cast and multicast traffic on the port for 5 sec onds Notify and disable port Send Trap Turn port off Notify and enable port Send Trap Turn port on Blip port Block broadcast and mul ticast traffic on the port for 5 seconds Disable port Turn port off Enable port Turn p...

Page 95: ... SNMP Network Manager Each entry in the log contains information in the fol lowing order Entry number Timestamp User ID Item ID including qualifier New value of item There is a limit of 16 records on the number of changes stored The oldest records are overwritten first Table 5 4 Initial settings for the default alarms Statistic High Threshold Low Threshold Recovery Samples per average Period Bandw...

Page 96: ...5 28 CHAPTER 5 ADVANCED MANAGEMENT ...

Page 97: ...reens for the Switch and advises you on actions to take if you see unexpected values for the statistics Please note however that as all networks are different any actions listed are only suggestions Viewing statistics on a regular basis allows you to see how well your network is performing If you keep simple daily records you will see trends emerg ing and notice problems arising before they cause ...

Page 98: ... with errors FRAMES TRANSMITTED Displays the total number of frames successfully transmitted by the current port FRAMES FORWARDED Displays the total number of frames that were received by the current port and forwarded to other ports FRAMES FILTERED Displays the total number of frames that were filtered because the destination station was on the same segment port as the source station Figure 6 1 S...

Page 99: ...ndstation segments is an indica tion that your network is operating efficiently However if multiple endstations are connected to this port and you see values of around 40 you should reconsider the topology of your network because each user will see degraded network per formance Figure 6 2 Port Statistics screen Frames Forwarded This counter provides a running average of the proportion of the frame...

Page 100: ...tet boundary Octets Transmitted The number of octets transmit ted by the port The calculation includes the MAC header and CRC but excludes preamble SFD Octet counters are accurate to the nearest 256 octet boundary Figure 6 3 Port Traffic Statistics screen Multicasts Received The number of frames suc cessfully received that have a multicast destination address This does not include frames directed ...

Page 101: ... value shown should be a very small proportion of the total data traffic IFM Count The number of times Intelligent Flow Management IFM has had to operate to minimize packet loss Frame Size Analysis The number of frames of a specified length as a percentage of the total number of frames of between 64 and 1518 octets This indi cates the composition of frames in the network The frame size ranges are ...

Page 102: ... This counter is incremented by one for each carrier event whose duration is less than the short event maximum time Short events are error frames smaller than the minimum size defined for Ethernet frames They may indicate externally generated noise causing problems on the network Check the cabling routing and re route any cabling which may be affected by external noise sources Figure 6 4 Switch Po...

Page 103: ... but including FCS octets CLEAR SCREEN COUNTERS Select this button to set all counters shown on the screen to zero It is useful for trend analysis if you wish to see changes in counters over a short period of time This button does not clear the counters on the device or affect counters at the network management workstation ...

Page 104: ...was first installed or initial ized either power on manual reset or a watchdog expiry Last Reset Type Other Command Watchdog Power Reset System Error This field indicates the cause of the last reset It may be due to manage ment command watchdog timeout expiry power interruption a manual reset or a system error Hardware Version The hardware version number of the Switch Figure 6 5 Status screen Upgr...

Page 105: ...The Fault Log is screen is displayed as shown in Figure 6 6 The Fault Log screen shows the following Reset Count The number of resets recorded at the time of the fault Time The time in seconds elapsed since the last reset when the fault occurred Area This information may be used for fault diagno sis by your technical support representative Fault Number The hexadecimal number in this field indicate...

Page 106: ...l a device 1 From the Main Menu select Remote Poll The Remote Poll screen is displayed as shown in Figure 6 7 2 In the Target Address field enter the IP or IPX address of the device you want to poll 3 Select the POLL button at the foot of the screen When the poll is complete the Round Trip Time field shows the interval in milliseconds between sending the frame to the target device and receiving a ...

Page 107: ...be earthed Connect the unit to an earthed power supply to ensure compliance with European safety stan dards The power cord set must be approved for the country where it will be used The appliance coupler that is the connector to the device itself and not the wall plug must have a configuration for mating with an EN60320 IEC320 appliance inlet For U S A and Canada The cord set must be UL approved a...

Page 108: ...hich it is connected is also opera tional under SELV Under no circumstances should the unit be con nected to an A C outlet power supply without an Earth Ground connection To comply with European safety standards a spare fuse must not be fitted to the appliance inlet Only fuses of the same manufacturer make and type should be used with the unit Ensure that the power supply lead is discon nected bef...

Page 109: ...nly 5A Time Delay anti surge fuses of the same type and manufacture as the original should be used Sockets for Redundant Power System RPS Only connect a 3Com Redundant Power System to this socket For details follow the installation instructions in the manuals accompanying the Redundant Power System RJ45 Ports WARNING The RJ45 ports are shielded RJ45 data sockets They cannot be used as telephone so...

Page 110: ...ission d appareil EN60320 IEC320 Pour USA et le Canada Le cordon surmoulé doit être UL Certifié et CSA Certifié Les spécifications minimales pour le cordon souple sont No 18 AWG Type SV ou SJ 3 conducteur Le cordon surmoulé doit avoir une capacité de courant calculée au moins de 10A La fiche de fixation doit être un type mis à la terre avec une configuration NEMA 5 15P 15A 125V ou NEMA 6 15P 15A 2...

Page 111: ...étiqueté Neutre branché directement à la Terre à la Masse Ne pas enlever le Module Plug in ou la plaque d occultation de module d émetteur récepteur avec la puissance encore branchée La Source de Courant et Le Fusible L unité s ajuste automatiquement à la tension d ali mentation Le fusible est convenable aux deux opérations 110 V C A et 220 240 V C A AVERTISSEMENT Assurer que l alimentation soit d...

Page 112: ...ne l alimentation multiple Les Ports RJ45 AVERTISSEMENT Ceux ci sont les prises de courant de données RJ45 protégées Ils ne peuvent pas être utilisés comme prises de courant télépho niques Brancher seulement les connecteurs RJ45 de données à ces prises de courant Les câbles de données blindés ou non blindés avec les jacks blindés ou non blindés l un ou l autre peuvent être branchés à ces prises de...

Page 113: ...tecker muß in den EN60320 IEC320 Zuführungsstecker am Gerät passen Es ist wichtig daß der Netzstecker sich in unmit telbarer Nähe zum Gerät befindet und leicht erre ichbar ist Das Gerät kann nur durch Herausziehen des Verbindungssteckers aus der Steckdose vom Stromnetz getrennt werden Das Gerät wird mit Sicherheits Kleinspannung nach IEC 950 SELV Safety Extra Low Voltage betrieben Angeschloßen wer...

Page 114: ...ie die Originalsicherung ersetzen Sicherung auswech seln und die Klappe der Sicherungshalterung wieder schließen Steckdose für Redundant Power System Nur ein 3Com Redundant Power System an diese Steckdose anschließen Für weitere Angaben die genauen Einbauanweisungen im Handbuch zum Redundant Power System befolgen RJ45 Anschlußen WARNUNG Hierbei handelt es sich um abge schirmte RJ45 Datenbuchsen di...

Page 115: ...ty Switch Management Monitor Manager Security Port STP Monitor read only Manager Security Port Statistics Monitor Manager Security Port Traffic Statistics Monitor Manager Security Port Error Analysis Monitor Manager Security Port Resilience Monitor Manager Security Port Setup Monitor read only Manager Security Unit Statistics Monitor Manager Security Unit Database View Monitor Manager Security Uni...

Page 116: ...ity Create User Security Delete Users Security Edit User Monitor Manager Security Status Monitor Manager Security Fault Log Monitor Manager Security Management Setup Monitor read only Manager Security Screen Available to Trap Setup Monitor read only Manager Security Console Port Setup Monitor read only Manager Security Software Upgrade Security Initialize Security Reset Manager Security Remote Pol...

Page 117: ...alling the Plug in Module ensuring it is properly seated If the prob lem persists contact your supplier for advice The Plug in Module Status LED lights yellow If the MGMT LED is flashing yellow the Module has failed its Power On Self Test refer to the previ ous advice Otherwise the Module s agent software is not installed correctly Refer to the User Guide supplied with the Module The Plug in Modul...

Page 118: ...nnot access the device Check that the device s IP address subnet mask and default router are correctly configured and that the device has been reset Check that the device s IP address is correctly recorded by the SNMP Network Manager refer to the user documentation for the Network Manager The Telnet workstation cannot access the device Check the device s IP address subnet mask and default router a...

Page 119: ... to the initial values In the case where no one knows a password for a security level user contact your supplier Using the Switch You see network problems and the Packet LED is on continuously with constant collisions refer to Port Traffic Statistics on page 6 4 You are using PACE equipped devices and have the Interactive Access feature of PACE enabled at both ends of the link Interactive Access m...

Page 120: ...d and then reboot the endstation For more informa tion about specifying Fast Start for a port refer to Configuring the STP Parameters of Ports on page 5 20 The Switch keeps ageing out endstation entries in the Switch Database SDB The Switch has STP enabled and STP is instructing the Switch to age entries in the SDB faster because topology changes are occurring in the network 1 Reduce the number of...

Page 121: ...Us across a VLAN other than VLAN 1 Switch A learns the MAC address of Switch B through the port on that VLAN The management agent of Switch B is only accessible through VLAN 1 and so your manage ment workstation cannot communicate with Switch B until it transmits BPDUs across VLAN 1 When that occurs Switch A learns the MAC address of Switch B through the port on VLAN 1 To avoid this situation we r...

Page 122: ...C 6 APPENDIX C TROUBLE SHOOTING ...

Page 123: ...D PIN OUTS Null Modem Cable 9 pin to RS 232 25 pin PC AT Serial Cable 9 pin to 9 pin ...

Page 124: ...D 2 APPENDIX D PIN OUTS Modem Cable 9 pin to RS 232 25 pin RJ45 Pin Assignments ...

Page 125: ... AC Protection 5A Time Delay Fuse Electromagnetic Compatibility EN55022 Class B FCC Part 15 Subpart B Class A ICES 003 Class A VCCI Class 2 AS NZS 3548 Class B EN 50082 1 Category 5 screened cables must be used to ensure compliance with the Class B Class 2 requirements of this standard The use of unscreened cables Category 5 for 100BASE TX ports complies with the Class A Class 1 requirements Heat ...

Page 126: ...NMP protocol RFC 1157 MIB II RFC 1213 Bridge MIB RFC 1493 Repeater MIB RFC 1516 VLAN MIB RFC 1573 RMON MIB RFC 1271 and RFC 1757 Terminal Emulation Telnet RFC 854 Protocols Used for Administration UDP RFC 768 IP RFC 791 ICMP RFC 792 TCP RFC 793 ARP RFC 826 TFTP RFC 783 BOOTP RFC 951 ...

Page 127: ... features news and information about 3Com products customer service and support 3Com Corporation s latest news releases NetAge Magazine technical documentation and more 3Com Bulletin Board Service 3ComBBS contains patches software and drivers for all 3Com products as well as technical articles This service is available via modem or ISDN 24 hours a day 7 days a week Access by Analog Modem To reach ...

Page 128: ...atches software drivers and technical articles about all 3Com products as well as a messaging section for peer support To use 3ComForum you need a CompuServe account To use 3ComForum 1 Log on to your CompuServe account 2 Type go threecom 3 Press Return to see the 3ComForum main menu Taiwan up to 14400 bps 886 2 377 5840 U K up to 28800 bps 44 1442 438278 U S A up to 28800 bps 1 408 980 8204 Countr...

Page 129: ...are available from 3Com Contact your local 3Com sales office to find your authorized service provider using one of these numbers Regional Sales Office Telephone Number 3Com Corporation U S 3Com ANZA East West 3Com Asia Limited P R of China Hong Kong India Indonesia Korea Malaysia Singapore Taiwan R O C Thailand 3Com Benelux B V Belgium Netherlands 3Com Canada Calgary Montreal Ottawa Toronto Vancou...

Page 130: ...taly 3Com Middle East 3Com Nordic AB Denmark Finland Norway Sweden 3Com Russia 3Com South Africa 3Com U K Limited 54 1 312 3266 55 11 546 0869 56 2 633 9242 57 1 629 4110 52 5 520 7841 51 1 221 5399 58 2 953 8122 39 2 253011 Milan 39 6 5279941 Rome 971 4 349049 45 39 27 85 00 358 0 435 420 67 47 22 18 40 03 46 8 632 56 00 007 095 2580940 27 11 807 4397 44 131 2478558 Edinburgh 44 161 8737717 Manch...

Page 131: ... part of a network used as the primary path for transporting traffic between network segments bandwidth Information capacity measured in bits per second that a channel can transmit The bandwidth of Ethernet is 10Mbps the bandwidth of Fast Ether net is 100Mbps baud rate The switching speed of a line Also known as line speed BOOTP The BOOTP protocol allows you to automatically map an IP address to a...

Page 132: ... nection and a control point for network manage ment and security Ethernet A LAN specification developed jointly by Xerox Intel and Digital Equipment Corporation Ethernet networks operate at 10Mbps using CSMA CD to run over cabling Fast Ethernet 100Mbps technology based on the Ethernet CD net work access method forwarding The process of sending a frame toward its destina tion by an internetworking...

Page 133: ...racteristics and parameters MIBs are used by the Simple Network Management Proto col SNMP to contain attributes of their managed systems The Switch contains its own internal MIB multicast Single packets copied to a specific subset of net work addresses These addresses are specified in the destination address field of the packet PACE Priority Access Control Enabled 3Com s innovative technology whic...

Page 134: ...anage many aspects of network and endstation operation Spanning Tree Protocol STP A bridge based system for providing fault tolerance on networks STP works by allowing you to imple ment parallel paths for network traffic and ensure that redundant paths are disabled when the main paths are operational and enabled if the main paths fail standby port The port in a resilient link that will take over d...

Page 135: ...tagram protocol An Internet standard proto col that allows an application program on one device to send a datagram to an application pro gram on another device VLAN Virtual LAN A group of location and topol ogy independent devices that communicate as if they are on a common physical LAN VLT Virtual LAN Trunk A Switch to Switch link which carries traffic for all the VLANs on each Switch VT100 A typ...

Page 136: ...6 GLOSSARY ...

Page 137: ...y strings changing 4 5 entering 4 3 role in trap setup 4 23 VLAN server 5 10 Community SNMP field 4 6 CompuServe F 2 Confirm Password field 4 5 Connection Type field 4 24 console port 1 9 auto configuration 4 24 connecting equipment to 2 7 connection type 4 24 disabling access 4 6 setting up 4 24 speed 4 24 Console Port field 4 6 Console Port Setup screen 4 24 conventions notice icons About This G...

Page 138: ...l 4 13 Char Size 4 25 Community String 4 3 4 5 4 23 Community SNMP 4 6 Confirm Password 4 5 Connection Type 4 24 Console Port 4 6 Data Link Protocol 3 10 Database Entries 4 16 DCD Control 4 24 Default RMON Host Matrix 4 10 Default Router 3 10 Designated Bridge 5 21 Designated Cost 5 21 Designated Port 5 20 Designated Root 5 18 5 21 Destination 4 28 Device IP Address 3 10 Device SubNet Mask 3 10 Di...

Page 139: ...izing the Switch 4 27 installing the Switch 2 4 Intelligent Flow Management 1 2 Intelligent Flow Management field 4 11 Interactive Access 4 9 disabling 4 12 IP address backup VLAN server 5 10 device 3 10 entering 1 11 format 3 2 VLAN server 5 10 IP or IPX Address field 4 23 IP protocol 1 10 IPX address 1 11 IPX Network field 3 10 IPX protocol 1 10 K keyboard shortcuts 3 5 L Last Reset Type field 6...

Page 140: ...me since last 6 8 type 6 8 resetting the Switch 4 26 resilient link pair 4 18 resilient links configuring 4 19 creating 4 20 deleting 4 20 rules 4 18 viewing 4 21 returning products for repair F 4 Rising Action field 4 13 Rising Threshold field 4 13 RMON 5 22 alarm actions 5 26 benefits 5 24 default alarm settings 5 27 features supported 5 25 groups supported 5 25 probe 5 22 Root Bridge 5 14 Root ...

Page 141: ... 2 1 rack mounting 2 4 rear view 1 8 resetting 4 26 size E 1 stacking with other units 2 4 technical specifications E 1 unit defaults 1 10 unit setup 4 9 upgrading software 4 28 wall mounting 2 5 weight E 1 Switch Database 4 15 ageing entries 4 15 configuring 4 16 non ageing entries 4 15 permanent entries 4 15 traps 4 15 switch database adding an entry 4 17 deleting an entry 4 17 searching 4 17 Sw...

Page 142: ...5 10 VLAN Server screen 5 10 VLAN Setup screen 5 8 VLAN STP screen 5 18 VLANs 1 3 5 1 assigning ports 5 9 AutoSelect VLAN Mode 5 4 Default 5 3 extending into an ATM network 5 5 Port VLAN Mode 5 4 setting up 5 8 using non routable protocols 5 5 using unique MAC addresses 5 5 VLTs 5 8 VLT Mode field 4 12 VLTs 5 3 5 8 5 9 VT100 interface accessing 3 1 definition 1 10 logging on 3 6 navigating 3 4 VT1...

Page 143: ...ithin the warranty period Products returned to 3Com s Corporate Service Center must be pre authorized by 3Com with a Return Material Authorization RMA number marked on the outside of the package and sent prepaid insured and packaged appropriately for safe shipment The repaired or replaced item will be shipped to Customer at 3Com s expense not later than thirty 30 days after receipt of the defectiv...

Page 144: ...se A respecte toutes les exigences du Règlement sur le matériel brouilleur du Canada VCCI STATEMENT INFORMATION TO THE USER If this equipment does cause interference to radio or television reception which can be determined by turning the equipment off and on the user is encouraged to try to correct the interference by one or more of the following measures Reorient the receiving antenna Relocate th...

Reviews: