background image

User Manual

Gigabit Managed PoE+ Switches

LPB2910A

LPB2926A

LPB2952A

Order toll-free in the U.S. or for FREE 24/7 technical support: Call 877-877-BBOX  

(outside U.S. call 724-746-5500) 

www.blackbox.com   •   [email protected]

Contact 

Information

Summary of Contents for LPB2910A

Page 1: ...abit Managed PoE Switches LPB2910A LPB2926A LPB2952A Order toll free in the U S or for FREE 24 7 technical support Call 877 877 BBOX outside U S call 724 746 5500 www blackbox com info blackbox com Contact Information ...

Page 2: ...ort at 724 746 5500 or go to blackbox com and click on Talk to Black Box You ll be live with one of our technical experts in less than 60 seconds Trademarks Used in this Manual Black Box and the Double Diamond logo are registered trademarks of BB Technologies Inc Any other trademarks mentioned in this manual are acknowledged to be the property of the trademark owners ...

Page 3: ...xpense will be required to take whatever measures may be necessary to correct the interference Changes or modifications not expressly approved by the party responsible for compliance could void the user s authority to operate the equipment This digital apparatus does not exceed the Class A limits for radio noise emis sion from digital apparatus set out in the Radio Interference Regulation of Indus...

Page 4: ...l flujo de aire por los orificios de ventilación 10 El equipo eléctrico deber ser situado fuera del alcance de fuentes de calor como radiadores registros de calor estufas u otros aparatos incluyendo amplificadores que producen calor 11 El aparato eléctrico deberá ser connectado a una fuente de poder sólo del tipo descrito en el instructivo de operación o como se indique en el aparato 12 Precaución...

Page 5: ...on A1 i LPB2900 Series Gigabit Managed PoE Switch User s Manual LPB2910A Gigabit Managed PoE Switch 10 Port LPB2926A Gigabit Managed PoE Switch 26 Port LPB2952A Gigabit Managed PoE Switch 52 Port Release 6 33 2015 Black Box Corporation ...

Page 6: ... found to comply with the limits for a Class B digital device pursuant to Part 15 of the FCC Rules These limits are designed to provide reasonable protection against harmful interference when the equipment is operated in a commercial environment This equipment generates uses and can radiate radio frequency energy and if not installed and used in accordance with the Instruction manual may cause har...

Page 7: ...Publication date Sept 2015 Revision A1 ii ...

Page 8: ...2 4 1 1 Mode 21 2 4 1 2 Excluded IP 23 2 4 1 3 Pool 24 2 4 2 Snooping 26 2 4 3 Relay 28 2 5 Security 30 2 5 1 Switch 30 2 5 1 1 Users 30 2 5 1 2 Privilege Level 32 2 5 1 3 Authentication Method 34 2 5 1 4 SSH 35 2 5 1 5 HTTPs 36 2 5 1 6 Access Management 37 2 5 1 7 SNMP 39 2 5 1 8 RMON 54 2 5 2 Network 61 2 5 2 1 Limit Control 61 2 5 2 2 NAS 65 2 5 2 3 ACL 73 2 5 2 4 IP Source Guard 80 2 5 2 5 ARP...

Page 9: ...Configuration 130 2 12 2 LLDP MED Configuration 133 2 13 PoE 139 2 13 1 Configuration 139 2 13 2 Power Delay 142 2 13 3 Scheduling 143 3 13 4 Auto Checking 145 2 14 MAC Table 147 2 16 Private VLANs 152 2 16 1 VLAN Membership 152 2 16 2 Port Isolation 154 2 17 VCL 155 2 17 1 MAC based VLAN 155 2 17 2 Protocol based VLAN 157 2 17 2 1 Protocol to Group 157 2 17 2 2 Group to VLAN 159 2 17 3 IP Subnet ...

Page 10: ...12 3 2 1 Port Power Savings 212 3 3 Ports 213 3 3 1 Traffic Overview 213 3 3 2 Qos Statistics 215 3 3 3 QCL Status 216 3 3 4 Detailed Statistics 218 3 3 5 SFP Information 221 3 4 DHCP 223 3 4 1 Server 223 3 4 1 1 Statistics 223 3 4 1 2 Binding 224 3 4 1 3 Declined IP 225 3 4 2 Snooping Table 226 3 4 3 Relay Statistics 227 3 4 4 Detailed Statistics 229 3 5 Security 231 3 5 1 Access Management Stati...

Page 11: ... 10 1 3 IPv4 SFM Information 280 3 10 2 MLD Snooping 282 3 10 2 1 Status 282 3 10 2 2 Group Information 284 3 10 2 3 IPv6 SFM Information 286 3 11 LLDP 288 3 11 1 Neighbor 288 3 11 2 LLDP MED Neighbor 290 3 11 3 PoE 293 3 11 4EEE 295 3 11 5 Port Statistics 297 3 12 PoE Statistics 299 3 13 MAC Table 301 3 14 VLANs 303 3 14 1 VLAN Membership 303 3 14 2 VLAN Port 305 3 15 VCL 307 3 15 1 MAC based VLA...

Page 12: ...Information 330 6 3 Device List 332 DMS GRAPHIC MONITORING 334 7 1 Topology View 334 7 2 Floor View 337 7 3 Map View 338 DMS MAINTENANCE 339 8 1 Floor Image 339 8 2 Troubleshooting 340 8 3 Traffic Chart 341 DMS MEDIA CONTROLLER OPTION 342 9 1 Obtaining Your Media Controller License Key 342 9 2 Key Installation Instructions 340 9 3 Media Controller Options 345 APPLICATION PROGRAMMING INTERRFACE API...

Page 13: ...Publication date Sept 2015 Revision A1 ix Revision History Release Date Revision V6 33 09 16 2015 A1 ...

Page 14: ... and capabilities for entry level networking includes small business or enterprise application and helps you create a more efficient better connected workforce LPB2910A provides 10 ports in a single device LPB2926A provides 26 ports and LPB2952A provides 52 ports Features common to all three switches are listed below L2 features provide better manageability security QoS and performance IPv4 IPv6 d...

Page 15: ...nput the username and password to login and access authentication The default username is admin and password is empty The first time you use the switch enter the default username and password and then click the Login button The login process now is completed In this login menu you have to input the complete username and password respectively the LPB2000 Series switch will not give you a shortcut t...

Page 16: ...Publication date June 2015 Revision A2 5 NOTE To enable dhcp so If you do not have DHCP server to provide ip addresses to the switch the switch s default ip is 192 168 1 1 Figure 1 The login page ...

Page 17: ...ocation information in this page 3 Click Apply Figure 2 1 1 System Information Parameter description System Contact The text that identifies the contact person for this managed node together with information on how to contact this person The allowed string length is 0 to 128 and the allowed content is the ASCII characters from 32 to 126 System name This is the name assigned to the switch for this ...

Page 18: ...e Sept 2015 Revision A1 7 System Location This is the physical location of this node e g telephone closet 3rd floor The allowed string length is 0 to 128 and the allowed content is the ASCII characters from 32 to 126 ...

Page 19: ...ent stations that exist on another network segment Configure the switch managed IP information on this page Configure IP basic settings control IP interfaces and IP routes The maximum number of interfaces supported is 8 and the maximum number of routes is 32 Web Interface To configure an IP address in the web interface 1 Click Configuration System IP 2 Click Add Interface then you can create a new...

Page 20: ...led Enable the DHCP client by checking this box If this option is enabled the system will configure the IPv4 address and mask of the interface using the DHCP protocol The DHCP client will announce the configured System Name as hostname to provide DNS lookup IPv4 DHCP Fallback Timeout The number of seconds that the switch will try to obtain a DHCP lease After this period expires a configured IPv4 a...

Page 21: ...r of bits prefix length It defines how much of a network address that must match to qualify for this route Valid values are between 0 and 32 bits respectively 128 for IPv6 routes Only a default route will have a mask length of 0 because it will match anything Gateway The IP address of the IP gateway Valid format is dotted decimal notation or valid IPv6 notation Gateway and Network must be of the s...

Page 22: ...orrect time The switch supports configurable time zones from 12 to 13 step 1 hour Default Time zone 8 Hrs Web Interface To configure NTP in the web interface 1 Click Configuration System NTP 2 Specify the Time parameter manually 3 Click Apply Figure 2 1 3 The NTP configuration Parameter description Mode Indicates the NTP mode operation Possible modes are Enabled Enable NTP client mode operation Di...

Page 23: ...ublication date Sept 2015 Revision A1 11 Buttons These buttons are displayed on the NTP page Apply Click to save changes Reset Click to undo any changes made locally and revert to previously saved values ...

Page 24: ...e system time via NTP Manual setting is simple just input Year Month Day Hour and Minute within the valid value range indicated in each item Web Interface To configure Time in the web interface 1 Click Configuration System and Time 2 Specify the Time parameter 3 Click Apply Figure 2 1 4 The time configuration ...

Page 25: ...own and click Apply to set Acronym Set the acronym for the time zone This is a User configurable acronym that identifies the time zone Range Up to 16 characters Daylight Saving Time Configuration Daylight Saving Time This is used to set the clock forward or backward according to the configurations set below for a defined Daylight Saving Time duration Select Disable to disable the Daylight Saving T...

Page 26: ...y Month Select the ending month Hours Select the ending hour Minutes Select the ending minute Offset settings Offset Enter the number of minutes to add during Daylight Saving Time Range 1 to 1440 NOTE Start Time Settings and End Time Settings displays what you set on the Start Time Settings and End Time Settings fields Buttons These buttons are displayed on the NTP page Apply Click to save changes...

Page 27: ...de operation is enabled the syslog message will be sent out to the syslog server The syslog protocol is based on UDP communication and received on UDP port 514 and the syslog server will not send acknowledgments back to the sender because UDP is a connectionless protocol and it does not provide acknowledgments The syslog packet will always be sent out even if the syslog server does not exist Possi...

Page 28: ... using the LLDP protocol EEE works for ports in auto negotiation mode where the port is negotiated to either 1 G or 100 Mbit full duplex mode For ports that are not EEE capable the corresponding EEE checkboxes are grayed out You cannot enable EEE for these ports When a port is powered down to save power outgoing traffic is stored in a buffer until the port is powered on again Because there is some...

Page 29: ...with short cables EEE Controls whether EEE is enabled for this switch port To maximize power savings the circuit isn t started once transmit data is ready for a port but is instead queued until a burst of data is ready to be transmitted This will give some traffic latency You can minimize the latency for specific frames by mapping the frames to a specific queue done with QOS and then marking the q...

Page 30: ...b Interface To configure a Current Port Configuration in the web interface 1 Click Configuration Ports Configuration and Ports 2 Specify the Speed Configured Flow Control Maximum Frame size Excessive Collision mode And Power Control 3 Click Apply Figure 2 3 1 The Port Configuration Parameter description Port This is the logical port number for this row Link The current link state is displayed grap...

Page 31: ... SFP port in 100 FX speed The copper port is in Auto mode 1000 X SFP port in 1000 X speed The copper port is disabled 1000 X_AMS Port in AMS mode SFP port in 1000 X speed The copper port is in Auto mode Ports in AMS mode with 1000 X speed prefer the copper port Ports in AMS mode with 100 FX speed prefer the fiber port Flow Control When Auto Speed is selected on a port this section indicates the fl...

Page 32: ...e web interface 1 Click Configuration Port then Port Description 2 Specify the detail Port alias or description an alphanumeric string describing the full name and version identification for the system s hardware type software version and networking application 3 Click Apply Figure 2 3 2 The Port Configuration Parameter description Port This is the logical port number for this row Description Ente...

Page 33: ...o the network 2 4 1 Server 2 4 1 1 Mode This page configures global mode and VLAN mode to enable disable a DHCP server per system and per VLAN Web Interface To configure DHCP server mode in the web interface 1 Click Configuration DHCP Server Mode 2 Select Enabled in the Global Mode of DHCP Server Mode Configuration 3 Add VLAN range 4 Click Apply Figure 2 4 1 1 The DHCP server Mode Parameter descri...

Page 34: ...IDs or both On the other hand if you want to disable an existing VLAN range follow the steps 1 Press ADD VLAN Range to add a new VLAN range 2 Input the VLAN range that you want to disable 3 Choose Mode to be Disabled 4 Press Apply to apply the change Then you will see the disabled VLAN range is removed from the DHCP Server mode configuration page Mode Indicate the operation mode per VLAN Possible ...

Page 35: ... a new IP Range on the switch 3 Click Apply Figure 2 4 1 2 The DHCP server excluded IP Parameter description IP Range Define the IP range to be excluded IP addresses The first excluded IP must be smaller than or equal to the second excluded IP But if the IP range contains only 1 excluded IP then you can input it to either one of the first and second excluded IP fields or both Buttons Add IP Range ...

Page 36: ...ool Setting Add or delete pools Adding a pool and giving a name to create a new pool with default configuration If you want to configure all settings including type IP subnet mask and lease time you can click the pool name to go to the configuration page Name Configure the pool name that accepts all printable characters except white space If you want to configure detailed settings click the pool n...

Page 37: ...is displayed it means not defined Subnet Mask Display the subnet mask of the DHCP address pool If is displayed it means not defined Lease Time Display the lease time of the pool Buttons Add New Pool Click to add a new DHCP pool Apply Click to save changes Reset Click to undo any changes made locally and revert to previously saved values ...

Page 38: ... snooping in the web interface 1 Click Configuration DHCP Snooping 2 Select Enabled in the DHCP Snooping Configuration mode 3 Select Trusted for the specific port in Port Mode Configuration 4 Click Apply Figure 2 4 2 The DHCP Snooping Configuration Parameter description Snooping Mode Indicates the DHCP snooping mode operation Possible modes are Enabled Enable DHCP snooping mode operation When DHCP...

Page 39: ...onfigures the port as a trusted source of the DHCP messages Untrusted Configures the port as an untrusted source of the DHCP messages Buttons Apply Click to save changes Reset Click to undo any changes made locally and revert to previously saved values ...

Page 40: ... agent forwards and transfers DHCP messages between the clients and the server when they are not in the same subnet domain The DHCP broadcast message won t be flooded for security considerations Disabled Disable DHCP relay mode operation Relay Server Indicates the DHCP relay server IP address Relay Information Mode Indicates the DHCP relay information mode option operation The option 82 circuit ID...

Page 41: ...ay agent information it will enforce the policy The Replace policy is invalid when relay information mode is disabled Possible policies are Replace Replace the original relay information when a DHCP message that already contains it is received Keep Keep the original relay information when a DHCP message that already contains it is received Drop Drop the package when a DHCP message that already con...

Page 42: ...1 1 Users This page provides an overview of the current users The only way to login as another user on the web server is to close and reopen the browser Web Interface To configure User in the web interface 1 Click Configuration Security Switch Users 2 Click Add new user 3 Specify the User Name parameter 4 Click Apply Figure 2 5 1 1 The Users configuration Parameter description User Name The name t...

Page 43: ... or greater than the group privilege level to access that group By default setting most groups privilege level 5 have read only access and privilege level 10 has read write access The system maintenance software upload factory defaults and etc need user privilege level 15 Generally the privilege level 15 can be used for an administrator account privilege level 10 for a standard user account and pr...

Page 44: ...rivilege Level in the web interface 1 Click System Account Privilege Level 2 Specify the Privilege parameter 3 Click Apply Figure2 5 1 2 The Privilege Level configuration Parameter description Group Name The name that identifies the privilege group In most cases a privilege level group consists of a single module e g LACP RSTP or QoS but a few contain more than one The following description define...

Page 45: ...ng in Maintenance Debug Only present in CLI Privilege Levels Every group has an authorized Privilege level for the following sub groups configuration read only configuration execute read write status statistics read only status statistics read write e g for clearing of statistics User Privilege should be the same or greater than the authorized Privilege level to access that group Buttons Apply Cli...

Page 46: ... one of the following values none authentication is disabled and login is not possible local use the local user database on the switch for authentication radius use a remote RADIUS server for authentication tacacs use a remote TACACS server for authentication Methods that involve remote servers time out if the remote servers are offline In this case the next method is tried Each method is tried fr...

Page 47: ...pted communication Web Interface To configure a SSH Configuration in the web interface 1 Select Enabled in the SSH Configuration mode 2 Click Apply Figure 2 5 1 4 The SSH Configuration Parameter description Mode Indicates SSH mode operation Possible modes are Enabled Enable SSH mode operation Disabled Disable SSH mode operation Buttons Apply Click to save changes Reset Click to undo any changes ma...

Page 48: ...nabled in HTTPS Configuration mode 2 Select Enabled in the HTTPS Configuration Automatic Redirect mode 3 Click Apply Figure 2 5 1 5 The HTTPS Configuration Parameter description Mode Indicates the HTTPS mode operation Possible modes are Enabled Enable HTTPS mode operation Disabled Disable HTTPS mode operation Automatic Redirect Indicates the HTTPS redirect mode operation Automatically redirect web...

Page 49: ...TELNET SSH in the entry 5 Click Apply Figure 2 5 1 6 The Access Management Configuration Parameter description Mode Indicates the access management mode operation Possible modes are Enabled Enable access management mode operation Disabled Disable access management mode operation VLAN ID Indicates the VLAN ID for the access management entry Delete Check to delete the entry It will be deleted during...

Page 50: ...nge provided in the entry TELNET SSH Indicates that the host can access the switch from TELNET SSH interface if the host IP address matches the IP address range provided in the entry Buttons Add New Entry Click to add a new access management entry Apply Click to save changes Reset Click to undo any changes made locally and revert to previously saved values ...

Page 51: ...ed via SNMP manager If the field SNMP is set to Disable the SNMP agent will be deactivated and the related Community Name Trap Host IP Address Trap and all MIB counters will be ignored 2 5 1 7 1 System This section describes how to configure SNMP System on the switch This function is used to configure SNMP settings community name trap host and public traps as well as the throttle of SNMP A SNMP ma...

Page 52: ... string a particular range of source addresses can be used to restrict source subnet Write Community Indicates the community write access string to permit access to SNMP agent The allowed string length is 0 to 255 and the allowed content is the ASCII characters from 33 to 126 The field is applicable only when SNMP version is SNMPv1 or SNMPv2c If SNMP version is SNMPv3 the community string will be ...

Page 53: ...terface To display the configure SNMP Trap Configuration in the web interface 1 Click Configuration Switch SNMP Trap 2 Click Add New Entry then you can create new SNMP Trap on the switch 3 Click Apply Figure2 5 1 7 2 The SNMP Trap Configuration Trap Mode Indicates the trap mode operation Possible modes are Enabled Enable SNMP trap mode operation ...

Page 54: ...ds represented as eight fields of up to four hexadecimal digits with a colon separating each field For example fe80 215 c5ff fe03 4dc7 The symbol is a special syntax that can be used as a shorthand way of representing multiple 16 bit groups of contiguous zeros but it can appear only once It can also represent a legally valid IPv4 address For example 192 1 2 34 Destination port Indicates the SNMP t...

Page 55: ...mber in hexadecimal format with number of digits between 10 and 64 but all zeros and all F s are not allowed Trap Security Name Indicates the SNMP trap security name SNMPv3 traps and informs using USM for authentication and privacy A unique security name is needed when traps and informs are enabled ...

Page 56: ...modify or clear the setting then click Reset Figure2 4 1 7 3 The SNMPv1 v2 Communities Security Configuration Parameter description Delete Check to delete the entry It will be deleted during the next save Community Indicates the community access string to permit access to SNMPv3 agent The allowed string length is 1 to 32 and the allowed content is ASCII characters from 33 to 126 The community stri...

Page 57: ... must contain an even number in hexadecimal format with number of digits between 10 and 64 but all zeros and all F s are not allowed The SNMPv3 architecture uses the User based Security Model USM for message security and the View based Access Control Model VACM for access control For the USM entry the usmUserEngineID and usmUserName are the entry s keys In a simple agent usmUserEngineID is always ...

Page 58: ...ional flag to indicate that this user uses SHA authentication protocol The value of security level cannot be modified if entry already exists That means must first ensure that the value is set correctly Authentication Password A string identifying the authentication password phrase For MD5 authentication protocol the allowed string length is 8 to 32 For SHA authentication protocol the allowed stri...

Page 59: ...information then check Save Max Group Number v1 2 v2 2 v3 10 Web Interface To display the configure SNMP Groups in the web interface 1 Click SNMP Groups 2 Specify the Privilege parameter 3 Click Apply Figure 2 5 1 7 5 The SNMP Groups Configuration Parameter description Delete Check to delete the entry It will be deleted during the next save Security Model Indicates the security model that this ent...

Page 60: ...string identifying the security name that this entry should belong to The allowed string length is 1 to 32 and the allowed content is ASCII characters from 33 to 126 Group Name A string identifying the group name that this entry should belong to The allowed string length is 1 to 32 and the allowed content is ASCII characters from 33 to 126 ...

Page 61: ...ing click Reset Figure 2 5 1 7 6 The SNMP Views Configuration Parameter description Delete Check to delete the entry It will be deleted during the next save View Name A string identifying the view name that this entry should belong to The allowed string length is 1 to 32 and the allowed content is ASCII characters from 33 to 126 View Type Indicates the view type that this entry should belong to Po...

Page 62: ... display the configure SNMP Access in the web interface 1 Click SNMP Access 2 Click Add new Access 3 Specify the SNMP Access parameters 4 Click Apply 5 If you want to modify or clear the setting then click Reset Figure 2 5 1 7 7 The SNMP Accesses Configuration Parameter description Delete Check to delete the entry It will be deleted during the next save Group Name A string identifying the group na...

Page 63: ...hentication and no privacy Auth Priv Authentication and privacy Read View Name The name of the MIB view defining the MIB objects for which this request may request the current values The allowed string length is 1 to 32 and the allowed content is ASCII characters from 33 to 126 Write View Name The name of the MIB view defining the MIB objects for which this request may potentially set new values T...

Page 64: ... Severity Level 3 Click Apply to save the setting 4 To cancel the setting click the Reset button It will revert to previously saved values Figure 2 5 1 7 8 The Trap Event Severity Configuration Parameter description Group Name The name identifying the severity group Severity Level Every group has a severity level The following level types are supported 0 Information Information messages 1 Warning ...

Page 65: ...Publication date Sept 2015 Revision A1 53 SMTP Enable Select this Group Name in SMTP ...

Page 66: ...ace 1 Click RMON Statistics 2 Click Add New Entry 3 Specify the ID parameters 4 Click Apply Figure 2 5 1 8 1 The RMON Statics Configuration Parameter description These parameters are displayed on the RMON Statistics Configuration page Delete Check to delete the entry It will be deleted during the next save ID Indicates the index of the entry The range is from 1 to 65535 Data Source Indicates the p...

Page 67: ... 2015 Revision A1 55 Indicates the maximum data entries associated this History control entry stored in RMON The range is from 1 to 3600 and the default value is 50 Buckets Granted The number of data to be saved in the RMON ...

Page 68: ...ge Delete Check to delete the entry It will be deleted during the next save ID Indicates the index of the entry The range is from 1 to 65535 Data Source Indicates the port ID to monitor If in a stacking switch the value must add 1000 switch ID 1 For example if the port is switch 3 port 5 the value is 2005 Interval Indicates the interval in seconds for sampling the history statistics data The range...

Page 69: ...Publication date Sept 2015 Revision A1 57 The number of data to be saved in the RMON ...

Page 70: ...uring the next save ID Indicates the index of the entry The range is from 1 to 65535 Interval Indicates the interval in seconds for sampling and comparing the rising and falling threshold The range is from 1 to 2 31 1 Variable Indicates the particular variable to be sampled the possible variables are InOctets The total number of octets received on the interface including framing characters InUcast...

Page 71: ...n packets Sample Type The method of sampling the selected variable and calculating the value to be compared against the thresholds Possible sample types are Absolute Get the sample directly Delta Calculate the difference between samples default Value The value of the statistic during the last sampling period Startup Alarm The method of sampling the selected variable and calculating the value to be...

Page 72: ...xt save ID Indicates the index of the entry The range is from 1 to 65535 Desc Indicates this event The string length is from 0 to 127 and the default is a null string Type Indicates the notification of the event The possible types are none No SNMP log is created no SNMP trap is sent log Create SNMP log entry when the event is triggered snmptrap Send SNMP trap when the event is triggered logandtrap...

Page 73: ...e a Configuration of Limit Control in the web interface 1 Select Enabled in the Mode of System Configuration 2 Checked Aging Enabled 3 Set Aging Period The default is 3600 seconds To configure a Port Configuration of Limit Control in the web interface 1 Select Enabled in the Mode of Port Configuration 2 Specify the maximum number of MAC addresses in the Limit of Port Configuration 3 Set Ation Trap...

Page 74: ...Publication date Sept 2015 Revision A1 62 ...

Page 75: ...t is assumed to be disconnected and the corresponding resources are freed on the switch Port Configuration The table has one row for each port on the selected switch and a number of columns which are Port The port number that the configuration below applies to Mode Controls whether Limit Control is enabled on this port Both this and the Global Mode must be set to Enabled for Limit Control to be in...

Page 76: ...ed Indicates that the limit is reached on this port This state can only be shown if Action is set to None or Trap Shutdown Indicates that the port is shut down by the Limit Control module This state can only be shown if Action is set to Shutdown or Trap Shutdown Re open Button If a port is shutdown by this module you may reopen it by clicking this button which will only be enabled if this is the c...

Page 77: ...er in the web interface 1 Select Enabled in the Network Access Server Configuration mode 2 Check Reauthentication Enabled 3 Set Reauthentication Period Default is 3600 seconds 4 Set EAPOL Timeout Default is 30 seconds 5 Set Aging Period Default is 300 seconds 6 Set Hold Time Default is 10 seconds 7 Checked RADIUS Assigned QoS Enabled 8 Checked RADIUS Assigned VLAN Enabled 9 Checked Guest VLAN Enab...

Page 78: ...s Valid values are in the range 1 to 255 seconds This has no effect for MAC based ports Aging Period This setting applies to the following modes i e modes using the Port Security functionality to secure MAC addresses Single 802 1X Multi 802 1X MAC Based Auth When the NAS module uses the Port Security module to secure MAC addresses the Port Security module needs to check for activity on the MAC add...

Page 79: ...switched on the RADIUS assigned VLAN The RADIUS server must be configured to transmit special RADIUS attributes to take advantage of this feature see RADIUS Assigned VLAN Enabled below for a detailed description The RADIUS Assigned VLAN Enabled checkbox provides a quick way to globally enable disable RADIUS server assigned VLAN functionality When checked the individual ports ditto setting determin...

Page 80: ...rames EAPOL frames encapsulate EAP PDUs RFC3748 Frames sent between the switch and the RADIUS server are RADIUS packets RADIUS packets also encapsulate EAP PDUs together with other attributes like the switch s IP address name and the supplicant s port number on the switch EAP is very flexible it allows for different authentication methods like MD5 Challenge PEAP and TLS The important thing is that...

Page 81: ... would cause all supplicants attached to the port to reply to requests sent from the switch Instead the switch uses the supplicant s MAC address which is obtained from the first EAPOL Start or EAPOL Response Identity frame sent by the supplicant An exception to this is when no supplicants are attached In this case the switch sends EAPOL Request Identity frames using the BPDU multicast MAC address ...

Page 82: ...cket transmitted by the RADIUS server when a supplicant is successfully authenticated If present and valid the port s Port VLAN ID will be changed to this VLAN ID the port will be set to be a member of that VLAN ID and the port will be forced into VLAN unaware mode Once assigned all traffic arriving on the port will be classified and switched on the RADIUS assigned VLAN ID If re authentication fai...

Page 83: ...n EAPOL Success frame when entering the Guest VLAN While in the Guest VLAN the switch monitors the link for EAPOL frames and if one such frame is received the switch immediately takes the port out of the Guest VLAN and starts authenticating the supplicant according to the port mode If an EAPOL frame is received the port will never be able to go back into the Guest VLAN if the Allow Guest VLAN if E...

Page 84: ... 2015 Revision A1 72 Buttons Apply Click to save changes Reset Click to undo any changes made locally and revert to previously saved values Upper right icon Refresh Click this icon to refresh the NAS Configuration manually ...

Page 85: ...ure the ACL parameters ACE of the switch port These parameters will affect frames received on a port unless the frame matches a specific ACE Web Interface To configure the ACL Ports Configuration in the web interface 1 Click Configuration ACL then Ports 2 Scroll to the specific parameter value to select the correct value for port ACL setting 3 Click save to save the setting 4 To cancel the setting...

Page 86: ...sabled Frames received on the port are not logged The default value is Disabled Please note that the System Log memory size and logging rate is limited Shutdown Specify the port shut down operation of this port The allowed values are Enabled If a frame is received on the port the port will be disabled Disabled Port shut down is disabled The default value is Disabled State Specify the port state of...

Page 87: ...bps 4 Click Apply to save the setting 5 If you want to cancel the setting then you need to click the reset button It will revert to previously saved values Figure 2 5 2 3 2 The ACL Rate Limiter Configuration Parameter description Rate Limiter ID The rate limiter ID for the settings contained in the same row Rate The allowed values are 0 3276700 in pps or 0 100 200 300 1000000 in kbps Unit Specify ...

Page 88: ... of ACEs is 256 on each switch Click on the lowest plus sign to add a new ACE to the list The reserved ACEs used for internal protocol cannot be edited or deleted the order sequence cannot be changed and the priority is highest Web Interface To configure Access Control List in the web interface 1 Click Configuration ACL then Configuration 2 Click the button to add a new ACL or use the other ACL mo...

Page 89: ...e matched by IP and ARP frames ARP The ACE will match ARP RARP frames IPv4 The ACE will match all IPv4 frames IPv4 ICMP The ACE will match IPv4 frames with ICMP protocol IPv4 UDP The ACE will match IPv4 frames with UDP protocol IPv4 TCP The ACE will match IPv4 frames with TCP protocol IPv4 Other The ACE will match IPv4 frames which are not ICMP UDP TCP IPv6 The ACE will match all IPv6 standard fra...

Page 90: ...sabled Port shut down is disabled for the ACE Counter The counter indicates the number of times the ACE was hit by a frame Modification Buttons You can modify each ACE Access Control Entry in the table using the following buttons Inserts a new ACE before the current row Edits the ACE row Moves the ACE up the list Moves the ACE down the list Deletes the ACE The lowest plus sign adds a new entry at ...

Page 91: ...er you can enter a specific destination MAC address The legal format is xx xx xx xx xx xx or xx xx xx xx xx xx or xxxxxxxxxxxx x is a hexadecimal digit A frame that hits this ACE matches this DMAC value Buttons Apply Click to save changes Reset Click to undo any changes made locally and revert to previously saved values Auto refresh Select auto refresh to refresh the information automatically Uppe...

Page 92: ...ic Clients 0 1 2 Unlimited of the specific port in the Port Mode Configuration mode 4 Click Apply Figure 2 5 2 4 1 The IP Source Guard Configuration Parameter description Mode of IP Source Guard Configuration Enable the Global IP Source Guard or disable the Global IP Source Guard All configured ACEs will be lost when the mode is enabled Port Mode Configuration Specify IP Source Guard as enabled on...

Page 93: ...ess in the entry 3 Click Apply Figure 2 5 2 5 2 The Static IP Source Guard Table Parameter description Delete Check to delete the entry It will be deleted during the next save Port The logical port for the settings VLAN ID The VLAN id for the settings IP Address Allowed Source IP address MAC address Allowed Source MAC address Adding new entry Click to add a new entry to the Static IP Source Guard ...

Page 94: ... mode 3 Click Apply Figure 2 5 2 5 1 The ARP Inspection Configuration Parameter description Mode of ARP Inspection Configuratio Enable the Global ARP Inspection or disable the Global ARP Inspection Port Mode Configuration Specify ARP Inspection as enabled on which ports Only when both Global Mode and Port Mode on a given port are enabled ARP Inspection is enabled on this given port Possible modes ...

Page 95: ...he Global Mode and Port Mode on a given port are enabled and the Check VLAN setting is disabled the log type of ARP Inspection will refer to the port setting There are four log types and possible types are None Log nothing Deny Log denied entries Permit Log permitted entries ALL Log all entries Buttons Apply Click to save changes Reset Click to undo any changes made locally and revert to previousl...

Page 96: ... the currently displayed VLAN entry will be used as a basis for the next lookup When the end is reached the warning message is shown in the displayed table Use the button to start over Web Interface To configure a VLAN Mode Configuration in the web interface 1 Click Add new entry 2 Specify the VLAN ID Log Type 3 Click Apply Figure 2 5 2 5 2 The VLAN Mode Configuration Parameter description VLAN Mo...

Page 97: ... Log nothing Deny Log denied entries Permit Log permitted entries ALL Log all entries Buttons Add New Entry Click to add a new VLAN to the ARP Inspection VLAN table Apply Click to save changes Reset Click to undo any changes made locally and revert to previously saved values ...

Page 98: ...ick Apply Figure 2 5 2 5 3 The Static ARP Inspection Table Parameter description Delete Check to delete the entry It will be deleted during the next save Port The logical port for the settings VLAN ID The vlan id for the settings MAC Address Allowed Source MAC address in ARP request packets IP Address Allowed Source IP address in ARP request packets Adding new entry Click to add a new entry to the...

Page 99: ...n Table Clicking the button will update the displayed table starting from that or the closest next Dynamic ARP Inspection Table match In addition the two input fields will upon a button click assume the value of the first displayed entry allowing for continuous refresh with the same start address The switch will use the last entry of the currently displayed table as a basis for the next lookup Whe...

Page 100: ...Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Refreshes the displayed table starting from the input fields Save Click to save changes Reset Click to undo any changes made locally and revert to previously saved values Updates the table starting from the first entry in the Dynamic ARP Inspection Table Updates the table starting with the entry after...

Page 101: ...create and manage objects that contain settings for using AAA servers 2 5 3 1 RADIUS Web Interface To configure a Common Configuration of AAA RADIUS in the web interface Figure 2 5 3 1 The RADIUS Authentication Server Configuration Parameter description Global Configuration These settings are common for all of the RADIUS servers Timeout Timeout is the number of seconds in the range 1 to 1000 to wa...

Page 102: ...te 95 in RADIUS Access Request packets If this field is left blank the IP address of the outgoing interface is used NAS Identifier Attribute 32 The identifier up to 255 characters long to be used as attribute 32 in RADIUS Access Request packets If this field is left blank the NAS Identifier is not included in the packet Server Configuration The table has one row for each RADIUS server and a number...

Page 103: ...Publication date Sept 2015 Revision A1 91 Buttons Apply Click to save changes Reset Click to undo any changes made locally and revert to previously saved values ...

Page 104: ...s in the range 1 to 1000 to wait for a reply from a TACACS server before it is considered to be dead Deadtime Deadtime which can be set to a number between 0 to 1440 minutes is the period during which the switch will not send new requests to a server that has failed to respond to a previous request This will stop the switch from continually trying to contact a server that it has already determined...

Page 105: ...t to use on the TACACS server for authentication Timeout This optional setting overrides the global timeout value Leaving it blank will use the global timeout value Key This optional setting overrides the global key Leaving it blank will use the global key Adding a New Server Click to add a new TACACS server An empty row is added to the table and the TACACS server can be configured as needed Up to...

Page 106: ...tic Trunk method is that a port can immediately become a member of a trunk group without any handshaking with its peer port This is also a disadvantage because the peer ports of your static trunk group may not know that they should aggregate together to form a logical trunked port Using Static Trunk on both end of a link is strongly recommended NOTE Low speed links will stay in not ready state whe...

Page 107: ...y default IP Address is enabled TCP UDP Port Number The TCP UDP port number can be used to calculate the destination port for the frame Check to enable the use of the TCP UDP Port Number or uncheck to disable By default TCP UDP Port Number is enabled Aggregation Group Configuration Group ID Indicates the group ID for the settings contained in the same row Group ID Normal indicates there is no aggr...

Page 108: ... the setting 5 If you want to cancel the setting click the reset button It will revert to previously saved values Figure 2 6 2 The LACP Port Configuration Parameter description Port The switch port number LACP Enabled Controls whether LACP is enabled on this switch port LACP will form an aggregation when 2 or more ports are connected to the same partner Key The Key value incurred by the port range...

Page 109: ... LACP packet Prio The Prio controls the priority of the port If the LACP partner wants to form a larger group than is supported by this device then this parameter will control which ports will be active and which ports will be in a backup role Lower number means greater priority Buttons Apply Click to save changes Reset Click to undo any changes made locally and revert to previously saved values ...

Page 110: ...Protection frames If you want to resume the locked port find out the looping path and remove the looping path then click on Resume to turn on the locked ports Web Interface To configure the Loop Protection parameters in the web interface 1 Click Configuration Loop Protection 2 Select enable or disable the port loop Protection 3 Click save to save the setting 4 If you want to cancel the setting cli...

Page 111: ...id values are 0 to 604800 seconds 7 days A value of zero will keep a port disabled until next device restart Port No The switch port number of the port Enable Controls whether loop protection is enabled on this switch port Action Configures the action performed when a loop is detected on a port Valid values are Shutdown Port Shutdown Port and Log or Log Only Tx Mode Controls whether the port is ac...

Page 112: ... root ports and designated ports and disables all other ports Network packets are therefore only forwarded between root ports and designated ports eliminating any possible network loops Once a stable network topology has been established all bridges listen for Hello BPDUs Bridge Protocol Data Units transmitted from the Root Bridge If a bridge does not get a Hello BPDU after a predefined interval M...

Page 113: ...ST Otherwise this is the priority of the STP RSTP bridge Forward Delay The delay used by STP Bridges to transit Root and Designated Ports to Forwarding used in STP compatible mode Valid values are in the range 4 to 30 seconds Max Age The maximum age of the information transmitted by the Bridge when it is the Root Bridge Valid values are in the range 6 to 40 seconds and MaxAge must be FwdDelay 1 2 ...

Page 114: ...ption of a BPDU The port will enter the error disabled state and will be removed from the active topology Port Error Recovery Control whether a port in the error disabled state automatically will be enabled after a certain time If recovery is not enabled ports have to be disabled and re enabled for normal STP operation The condition is also cleared by a system reboot Port Error Recovery Timeout Th...

Page 115: ...st be left empty i e It will not have any VLANs mapped to it This section describes how to inspect the current STP MSTI bridge instance priority configurations and possibly change them Web Interface To configure the Spanning Tree MSTI Mapping parameters in the web interface 1 Click Configuration Spanning Tree MSTI Mapping 2 Specify the configuration identification parameters in the field Specify t...

Page 116: ... revision of the MSTI configuration named above This must be an integer between 0 and 65535 MSTI The bridge instance The CIST is not available for explicit mapping because it will receive the VLANs not explicitly mapped VLANs Mapped The list of VLANs mapped to the MSTI The VLANs can be given as a single VLAN xx xx is between 1 and 4094 or a range xx yy each of which must be separated with comma an...

Page 117: ...ing Tree MSTI Priorities parameters in the web interface 1 Click Configuration Spanning Tree MSTI Priorities 2 Scroll the Priority the maximum is 240 Default is 128 3 Click Save to save the setting 4 To cancel the setting click the Reset button It will revert to previously saved values Figure 2 8 3 The MSTI Configuration Parameter description MSTI The bridge instance The CIST is the default instan...

Page 118: ...t configuration 4 Click Apply to save the setting 5 To cancel the setting click the Reset button It will revert to previously saved values Figure 2 8 4 The STP CIST Port Configuration Parameter description Port The switch port number of the logical STP port STP Enabled Controls whether STP is enabled on this switch port Path Cost Controls the path cost incurred by the port The Auto setting will se...

Page 119: ...e network influence the spanning tree active topology possibly because those bridges are not under the full control of the administrator This feature is also known as Root Guard Restricted TCN If enabled causes the port not to propagate received topology change notifications and topology changes to other ports If set it can cause temporary loss of connectivity after changes in a spanning tree s ac...

Page 120: ...actual MSTI port configuration options It contains MSTI port settings for physical and aggregated ports Web Interface To configure the Spanning Tree MSTI Port Configuration parameters in the web interface 1 Click Configuration Spanning Tree MSTI Ports 2 Scroll to select the MST1 or other MSTI Port 3 Click Get to set detailed parameters of the MSTI Ports 4 Scroll to set all parameters of the MSTI P...

Page 121: ...Using the Specific setting a user defined value can be entered The path cost is used when establishing the active topology of the network Lower path cost ports are chosen as forwarding ports in favor of higher path cost ports Valid values are in the range 1 to 200000000 Priority Controls the port priority This can be used to control priority of ports that have identical port cost see above Buttons...

Page 122: ... 2 9 1 Profile Table The IPMC profile is used to deploy the access control on IP multicast streams It is allowed to create at maximum 64 Profiles with a maximum 128 corresponding rules for each Web Interface To configure the IPMC Profile Configuration in the web interface Figure 2 9 1 The IPMC Profile Configuration ...

Page 123: ...ription sentence Rule When the profile is created click the edit button to enter the rule setting page of the designated profile A summary about the designated profile will be shown by clicking the view button You can manage or inspect the rules of the designated profile by using the following buttons List the rules associated with the designated profile Adjust the rules associated with the design...

Page 124: ...icates the logging preference upon receiving the Join Report frame that has the group address matches the address range of the rule Enable Corresponding information of the group address that matches the range specified in the rule will be logged Disable Corresponding information of the group address that matches the range specified in the rule will not be logged Rule Management Buttons You can man...

Page 125: ...or indexing the address entry table Each entry has the unique name that is composed of a maximum of 16 alphabetic and numeric characters At least one alphabetic character must be present Start Address The starting IPv4 IPv6 Multicast Group Address that will be used as an address range End Address The ending IPv4 IPv6 Multicast Group Address that will be used as an address range Buttons Add New Add...

Page 126: ...Publication date Sept 2015 Revision A1 114 Updates the table starting with the entry after the last entry currently displayed ...

Page 127: ...ubscriber selects a channel the set top box or PC sends an IGMP join message to Switch A to join the appropriate multicast Uplink ports that send and receive multicast data to and from the multicast VLAN are called MVR source ports Web Interface To configure the MVR Configuration in the web interface 1 Click Configuration MVR Configuration 2 Scroll the MVR mode to enable or disable and Scroll to s...

Page 128: ...rface associated with this VLAN When the IPv4 management address is not set the system uses the first available IPv4 management address Otherwise the system uses a pre defined value By default this value will be 192 0 2 1 Mode Specify the MVR mode of operation In Dynamic mode MVR allows dynamic MVR membership reports on source ports In Compatible mode MVR membership reports are forbidden on source...

Page 129: ...eiver port if it is a subscriber port and should only receive multicast data It does not receive data unless it becomes a member of the multicast group by issuing IGMP MLD messages Be Caution MVR source ports are not recommended to be overlapped with management VLAN ports Select the port role by clicking the Role symbol to switch the setting I indicates Inactive S indicates Source R indicates Rece...

Page 130: ...this function once a switch receives an IP multicast packet it will forward the packet to the members who joined a specified IP multicast group before The packets will be discarded by IGMP Snooping if the user transmits multicast packets to the multicast group that had not been built up in advance IGMP mode enables the switch to issue the IGMP function that you enable IGMP proxy or snooping on the...

Page 131: ...o avoid forwarding unnecessary leave messages to the router side Proxy Enabled Enable IGMP Proxy This feature can be used to avoid forwarding unnecessary join and leave messages to the router side Port This shows the physical Port index of switch Router Port Specify which ports act as router ports A router port is a port on the Ethernet switch that leads to the Layer 3 multicast device or IGMP que...

Page 132: ...nterface To configure the IGMP Snooping VLAN Configuration in the web interface 1 Click Configuration IPMC IGMP Snooping VLAN Configuration 2 Select enable or disable Snooping IGMP Querier Specify the parameters in the blank field 3 Click the refresh button to update the data or click or to display the previous entry or next entry 4 Click Save to save the setting 5 To cancel the setting click the ...

Page 133: ...al The Query Interval is the interval between General Queries sent by the Querier The allowed range is 1 to 31744 seconds the default query interval is 125 seconds QRI Query Response Interval The Max Response Time used to calculate the Max Resp Code inserted into the periodic General Queries The allowed range is 0 to 31744 in tenths of seconds the default query response interval is 100 in tenths o...

Page 134: ...P join report requesting the stream of IP multicast traffic is dropped and the port is not allowed to receive IP multicast traffic from that group If the filtering action permits access to the multicast group the IGMP report from the port is forwarded for normal processing IGMP filtering controls only IGMP membership join reports and has no relationship to the function that directs the forwarding ...

Page 135: ... Button You can inspect the rules of the designated profile by using the following button List the rules associated with the designated profile Buttons Apply Click to save changes Reset Click to undo any changes made locally and revert to previously saved values ...

Page 136: ...perates to determine what multicast address to use NOTE This is a function of the application software not of MLD When MLD snooping is enabled on a VLAN the switch acts to minimize unnecessary multicast traffic If the switch receives multicast traffic destined for a given multicast address it forwards that traffic only to ports on the VLAN that have MLD hosts for that address It drops that traffic...

Page 137: ...es effect only when MLD Snooping is enabled When MLD Snooping is disabled unregistered IPMCv6 traffic flooding is always active in spite of this setting MLD SSM Range SSM Source Specific Multicast Range allows the SSM aware hosts and routers to run the SSM service model for the groups in the address Using IPv6 Address range Leave Proxy Enabled Enable MLD Leave Proxy This feature can be used to avo...

Page 138: ...as router ports A router port is a port on the Ethernet switch that leads towards the Layer 3 multicast device or MLD querier If an aggregation member port is selected as a router port the whole aggregation will act as a router port Throttling Enable to limit the number of multicast groups to which a switch port can belong Buttons Apply Click to save changes Reset Click to undo any changes made lo...

Page 139: ...er page 3 Click Refresh to refresh an entry of the MLD Snooping VLAN Configuration Information 4 Click or to move to previous or next entry Figure 2 11 2 2 The MLD Snooping VLAN Configuration Parameter description Delete Check to delete the entry The designated entry will be deleted during the next save VLAN ID This displays the VLAN ID of the entry IGMP Snooping Enabled Enable the per VLAN IGMP S...

Page 140: ...ime used to calculate the Max Resp Code inserted into the periodic General Queries The allowed range is 0 to 31744 in tenths of seconds default query response interval is 100 in tenths of seconds 10 seconds LLQI LMQI for IGMP Last Member Query Interval The Last Member Query Time is the time value represented by the Last Member Query Interval multiplied by the Last Member Query Count The allowed ra...

Page 141: ...ly to save the setting 5 To cancel the setting click the Reset button It will revert to previously saved values Figure 2 11 2 3 The MLD Snooping Port Group Filtering Configuration Parameter description Port The logical port for the settings Filtering Profile Select the IPMC Profile as the filtering condition for the specific port View a summary about the designated profile by clicking the view but...

Page 142: ...n IEEE 802 local area network principally wired Ethernet The protocol is formally referred to by the IEEE as Station and Media Access Control Connectivity Discovery specified in standards document IEEE 802 1AB 2 12 1 LLDP Configuration You can configure LLDP and detaied parameters per port and the settings will take effect immediately This page allows the user to inspect and configure the current ...

Page 143: ...l value Valid values are restricted to 1 8192 seconds Tx Reinit When a port is disabled LLDP is disabled or the switch is rebooted an LLDP shutdown frame is transmitted to the neighboring units signaling that the LLDP information isn t valid anymore Tx Reinit controls the amount of seconds between the shutdown frame and a new LLDP initialization Valid values are restricted to 1 10 seconds LLDP Por...

Page 144: ...t the CDP capabilities cover capabilities that are not part of the LLDP These capabilities are shown as others in the LLDP neighbors table If all ports have CDP awareness disabled the switch forwards CDP frames received from neighbor devices If at least one port has CDP awareness enabled all CDP frames are terminated by the switch NOTE When CDP awareness on a port is disabled the CDP information i...

Page 145: ...ower over Ethernet PoE end points Inventory management allowing network administrators to track their network devices and determine their characteristics manufacturer software and hardware versions serial or asset number This page allows you to configure the LLDP MED This function applies to VoIP devices that support LLDP MED Web Interface To configure LLDP MED 1 Click LLDP MED Configuration 2 Mod...

Page 146: ... an LLDP MED capable Network Connectivity Device start to advertise LLDP MED TLVs in outgoing LLDPDUs on the associated port The LLDP MED application will temporarily speed up the transmission of the LLDPDU to start within a second when a new LLDP MED neighbor is detected to share LLDP MED information as fast as possible with new neighbors Because there is a risk of an LLDP frame being lost during...

Page 147: ...ap Datum The Map Datum is used for the coordinates given in these options WGS84 Geographical 3D World Geodesic System 1984 CRS Code 4327 Prime Meridian Name Greenwich NAD83 NAVD88 North American Datum 1983 CRS Code 4269 Prime Meridian Name Greenwich The associated vertical datum is the North American Vertical Datum of 1988 NAVD88 This datum pair is to be used when referencing locations on land not...

Page 148: ...te Example Apt 42 Floor Floor Example 4 Room no Room number Example 450F Place type Place type Example Office Postal community name Postal community name Example Leonia P O Box Post office box P O BOX Example 12345 Additional code Additional code Example 1320300003 Emergency Call Service Emergency Call Service e g E911 and others such as defined by TIA or NENA Emergency Call Service Emergency Call...

Page 149: ...OTE LLDP MED is not intended to run on links other than between Network Connectivity Devices and Endpoints and does not need to advertise the multitude of network policies that frequently run on an aggregated link interior to the LAN Delete Check to delete the policy It will be deleted during the next save Policy ID ID for the policy This is auto generated and will be used when selecting the polic...

Page 150: ...y the DSCP value is relevant Tagged indicates that the device is using the IEEE 802 1Q tagged frame format and that both the VLAN ID and the Layer 2 priority values are being used as well as the DSCP value The tagged format includes an additional field known as the tag header The tagged frame format also includes priority tagged frames as defined by IEEE 802 1Q 2003 VLAN ID VLAN identifier VID for...

Page 151: ...icating power range 14 5 20 5 Mark 1 Signals PSE is 802 3at capable PD presents a 0 25 4 mA load 7 10 Class 2 PSE outputs classification voltage again to indicate 802 3at capability 14 5 20 5 Mark 2 Signals PSE is 802 3at capable PD presents a 0 25 4 mA load 7 10 Startup Startup voltage 42 42 Normal operation Supply power to device 37 45 42 5 57 Power levels available Class Usage Power range Watt ...

Page 152: ...ccording to the class the connected PD belongs to and reserves the power accordingly Four different port classes for 4 7 15 4 or 30 Watts In this mode the Maximum Power fields have no effect 3 LLDP MED mode This mode is similar to the Class mode except that each port determines the amount of power it reserves by exchanging PoE information using the LLDP protocol and reserves power accordingly If n...

Page 153: ... the backup power source will take over To determine the amount of power the PD may use you must define the amount of power that the primary and backup power sources can deliver Valid values are in the range 0 to 2000 Watts Port This is the logical port number for this row Ports that are not PoE capable are grayed out and impossible to configure PoE for PoE Mode The PoE Mode represents the PoE ope...

Page 154: ...t to the power device 3 Specify the power providing delay time when reboot 4 Click Apply to apply the change Figure 2 13 2 The PoE Power Delay Parameter description Power Supply Configuration Port This is the logical port number for this row Delay Mode Turn on off the power delay function Enabled Enable POE Power Delay Disabled Disable POE Power Delay Delay Time 0 300sec When rebooting the PoE por...

Page 155: ...t also saves more energy Web Interface To Display Power Over Ethernet Scheduling in the web interface 1 Click Configuration PoE and Scheduling 2 Select the local port and enable 3 Select time and day to supply power 4 Click Apply to apply the change Figure 2 13 3 The PoE Scheduling Parameter description Power Supply Configuration Port This is the logical port number for this row Status ...

Page 156: ...Publication date Sept 2015 Revision A1 144 PoE Scheduling Status Enabled Enable POE Scheduling Disabled Disable POE Scheduling Hour The time the PoE port is powered during the day ...

Page 157: ...k function 3 Specify the PD s IP address checking interval retry time failure action and reboot time 4 Click Apply to apply the change Figure 2 13 4 The PoE Scheduling Parameter description Power Supply Configuration Ping Check Enable the Ping Check function to detect the connection between the PoE port and the powered device Disable will turn off the detection Port This is the logical port number...

Page 158: ...lure action Default 3 range 1 5 Failure Log Failure log counter Failure Action The action after the third failure is detected Nothing Ping the remote PD but does nothing further Reboot Remote PD Cut off the power of the PoE port reboot the PD Reboot time sec When PD reboots the PoE port restores power after the specified time Default 15 range 3 120 sec ...

Page 159: ...e MAC address of the equipment sending the frame The SMAC address is used by the switch to automatically update the MAC table with these dynamic MAC addresses Dynamic entries are removed from the MAC table if it does not see any frames with the corresponding SMAC address after a configurable age time Web Interface To configure the MAC Address Table in the web interface Aging Configuration 1 Click ...

Page 160: ...sure you add the link used for managing the switch to the Static Mac Table before changing to secure learning mode otherwise the management link is lost and can only be restored by using another non secure port or by connecting to the switch via the serial interface Static MAC Table Configuration The static entries in the MAC table are shown in this table The static MAC table can contain 64 entrie...

Page 161: ...hrough a multi VLAN route Web Interface To configure VLAN membership configuration in the web interface 1 Click Configuration VLANS 2 Specify Existiong VLANs Ether type for Custom S ports 3 Click Apply Figure 2 15 1 The VLAN Configuration Parameter description Global VLAN Configuration Existing VLANs This field shows the VLANs that are created on the switch By default only VLAN 1 exists More VLANs...

Page 162: ...ave additional port configuration features In addition to the characteristics described for trunk ports hybrid ports have these abilities Can be configured to be VLAN tag unaware C tag aware S tag aware or S custom tag aware ingress filtering can be controlled ingress acceptance of frames and configuration of egress tagging can be configured independently Port VLAN Determines the port s VLAN ID a ...

Page 163: ...ed and untagged frames are accepted Tagged Only Only tagged frames are accepted on ingress Untagged frames are discarded Untagged Only Only untagged frames are accepted on ingress Tagged frames are discarded Egress Tagging Ports in Trunk and Hybrid mode may control the tagging of frames on egress Untag Port VLAN Frames classified to the Port VLAN are transmitted untagged Other frames are transmitt...

Page 164: ... The entry will be deleted during the next save PVLAN ID Indicates the ID of this particular private VLAN Port Members A row of check boxes for each port is displayed for each VLAN ID To include a port in a VLAN check the box To remove or exclude the port from the VLAN make sure the box is unchecked By default no ports are members and all boxes are unchecked Adding a New VLAN Click to add a new VL...

Page 165: ...Publication date Sept 2015 Revision A1 153 Apply Click to save changes Reset Click to undo any changes made locally and revert to previously saved values ...

Page 166: ...ta packet based upon the destination address on the data packet The data packet is then sent to the ports in accordance with the forwarding map generated based upon whether the ingress port was configured as a protected or non protected port This page is used for enabling or disabling port isolation on ports in a Private VLAN A port member of a VLAN can be isolated to other isolated ports on the s...

Page 167: ... to use the resources in the old VLAN On the other hand if Port A and Port B belong to the same VLAN after terminal devices access the network through Port B they will have access to the same resources as those accessing the network through Port A do which brings security issues To provide user access and ensure data security in the meantime the MAC based VLAN technology was developed MAC based VL...

Page 168: ...pty row is added to the table and the MAC based VLAN entry can be configured as needed Any unicast MAC address can be configured for the MAC based VLAN entry No broadcast or multicast MAC addresses are allowed Legal values for a VLAN ID are 1 through 4095 The MAC based VLAN entry is enabled on the selected stack switch unit when you click Save A MAC based VLAN without any port members on any stack...

Page 169: ...tinguished by the 8 bit 802 2 Service Access Point SAP fields SNAP supports identifying protocols by Ethernet type field values it also supports vendor private protocol identifier spaces It is used with IEEE 802 3 IEEE 802 4 IEEE 802 5 IEEE 802 11 and other IEEE 802 physical network layers as well as with non IEEE 802 physical network layers such as FDDI that use 802 2 LLC 2 17 2 1 Protocol to Gro...

Page 170: ...b PID If the OUI is hexadecimal 000000 the protocol ID is the Ethernet type EtherType field value for the protocol running on top of SNAP if the OUI is an OUI for a particular organization the protocol ID is a value assigned by that organization to the protocol running on top of SNAP In other words if the value of the OUI field is 00 00 00 then the value of the PID will be etype 0x0600 0xffff If a...

Page 171: ...he Protocol to Group mapping table and must not be already used by any other existing mapping entry on this page VLAN ID Indicates the ID to which the Group Name will be mapped A valid VLAN ID ranges from 1 4095 Port Members A row of check boxes for each port is displayed for each Group Name to VLAN ID mapping To include a port in a mapping check the box To remove or exclude the port from the mapp...

Page 172: ... is user configurable Its value ranges from 0 128 If a VCE ID is 0 the application will auto generate the VCE ID for that entry Deletion and lookup of IP subnet based VLAN are based on VCE ID IP Address Indicates the IP address Mask Length Indicates the network mask length VLAN ID Indicates the VLAN ID This can be changed for the existing entries Port Members A row of check boxes for each port is ...

Page 173: ...Publication date Sept 2015 Revision A1 161 Save Press the Delete button to undo the addition of new IP subnet based VLANs The maximum possible IP subnet based VLAN entries are limited to 128 ...

Page 174: ...warding on the Voice VLAN then the switch can classify and schedule network traffic We recommend having two VLANs on a port one for voice one for data Before connecting the IP device to the switch the IP phone should configure the voice VLAN ID correctly Configure it through its own GUI Web Interface To configure Voice VLAN in the web interface 1 Select Enabled in the Voice VLAN Configuration 2 Sp...

Page 175: ... mode isn t equal to disabled we must disable the MSTP feature before we enable Voice VLAN to avoid an ingress filtering conflict Possible port modes are Disabled Disjoin from Voice VLAN Auto Enable auto detect mode This detects whether there is a VoIP phone attached to the specific port and configures the Voice VLAN members automatically Forced Force join to Voice VLAN Port Security Indicates the...

Page 176: ...n Delete Check to delete the entry It will be deleted during the next save Telephony OUI A telephony OUI address is a globally unique identifier assigned to a vendor by IEEE It must be 6 characters long and the input format is xx xx xx x is a hexadecimal digit Description The description of the OUI address Normally it describes which vendor telephony device it belongs to The allowed string length ...

Page 177: ...mory control mechanisms providing excellent performance of all QoS classes under any traffic scenario including jumbo frame A super priority queue with dedicated memory and strict highest priority is in the arbitration The ingress super priority queue allows traffic recognized as CPU traffic to be received and queued for transmission to the CPU even when all the QoS class queues are congested 2 19...

Page 178: ...ed by a QCL entry PCP Controls the default PCP value All frames are classified to a PCP value If the port is VLAN aware and the frame is tagged then the frame is classified to the PCP value in the tag Otherwise the frame is classified to the default PCP value DEI Controls the default DEI value All frames are classified to a DEI value If the port is VLAN aware and the frame is tagged then the frame...

Page 179: ...licing 2 Select which port needs to enable the QoS Ingress Port Policers and type the Rate limit condition 3 Scroll to select the Rate limit Unit with kbps Mbps fps and kfps 4 Click Apply to save the configuration Figure 2 19 2 The QoS Ingress Port Policers Configuration Parameter description Port The logical port for the settings contained in the same row Click on the port number to configure the...

Page 180: ...s an overview of QoS Egress Port Schedulers for all switch ports The ports belong to the currently selected stack unit as reflected by the page header Web Interface To display the QoS Port Schedulers in the web interface 1 Click Configuration QoS Port Schedulers 2 Display the QoS Egress Port Schedulers Figure 2 19 3 The QoS Egress Port Schedules Click the Port index to set the QoS Egress Port Sche...

Page 181: ...s the scheduling mode for this port Weight Qn Shows the weight for this queue and port Scheduler Mode Controls whether the scheduler mode is Strict Priority or Weighted on this switch port Queue Shaper Enable Controls whether the queue shaper is enabled for this queue on this switch port Queue Shaper Rate If you select the scheduler mode with wighted then the screen will change as the figure ...

Page 182: ...cted to 1 100 This parameter is only shown if Scheduler Mode is set to Weighted Queue Scheduler Percent Shows the weight in percent for this queue This parameter is only shown if Scheduler Mode is set to Weighted Port Shaper Enable Controls whether the port shaper is enabled for this switch port Port Shaper Rate Controls the rate for the port shaper The default value is 1 This value is restricted ...

Page 183: ...r can get all detail information for the ports belong to the currently selected stack unit as reflected by the page header Web Interface To display the QoS Port Shapers in the web interface 1 Click Configuration QoS Port Shapers 2 Display the QoS Egress Port Shapers Figure 2 19 4 The QoS Egress Port Shapers Click the Port index to set the QoS Egress Port Shapers ...

Page 184: ...ows the scheduling mode for this port Shapers Qn Shows disabled or the actual queue shaper rate e g 800 Mbps Scheduler Mode Controls whether the scheduler mode is Strict Priority or Weighted on this switch port Queue Shaper Enable Controls whether the queue shaper is enabled for this queue on this switch port If you select the scheduler mode with wighted then the screen will change as the figure ...

Page 185: ...is restricted to 1 100 This parameter is only shown if Scheduler Mode is set to Weighted Queue Scheduler Percent Shows the weight in percent for this queue This parameter is only shown if Scheduler Mode is set to Weighted Port Shaper Enable Controls whether the port shaper is enabled for this switch port Port Shaper Rate Controls the rate for the port shaper The default value is 1 This value is re...

Page 186: ...arking for all switch ports Otherwise the ports belong to the currently selected stack unit as reflected by the page header Web Interface To display the QoS Port Tag Remarking in the web interface 1 Click Configuration QoS Port Tag Remarking Figure 2 19 5 The Port Tag Remarking Click the Port index to set the QoS Port Tag Remarking ...

Page 187: ...arking mode for this port Classified Use classified PCP DEI values Default Use default PCP DEI values Mapped Use mapped versions of QoS class and DP level PCP DEI Configuration Controls the default PCP and DEI values used when the mode is set to Default QoS class DP level to PCP DEI Mapping ...

Page 188: ... the mapping of the classified QoS class DP level to PCP DEI values when the mode is set to Mapped Buttons Apply Click to save changes Reset Click to undo any changes made locally and revert to previously saved values Cancel Click to cancel the changes ...

Page 189: ...ngs 5 To cancel the settings click the Reset button It will revert to previously saved values Figure 2 19 6 The QoS Port DSCP Configuration Parameter description Port The Port column shows the list of ports for which you can configure DSCP ingress and egress settings Ingress In Ingress settings you can change ingress translation and classification settings for individual ports There are two config...

Page 190: ...ng Remap DSCP from analyzer is remapped and frame is marked with remapped DSCP value Buttons Apply Click to save changes Reset Click to undo any changes made locally and revert to previously saved values Auto refresh Click on the auto refresh icon and the device will refresh the information automatically Upper right icon Refresh Click to for refresh the QoS Port DSCP information manually ...

Page 191: ...l switches Web Interface To configure the DSCP Based QoS Ingress Classification parameters in the web interface 1 Click Configuration QoS DSCP Based QoS 2 Enable or disable the DSCP for Trust 3 Scroll to select QoS Class and DPL parameters 4 Click Save to save the settings 5 To cancel the settings click the Reset button It will revert to previously saved values Figure 2 19 7 The DSCP Based QoS Ing...

Page 192: ...ss value can be between 0 7 DPL Drop Precedence Level range is 0 3 Buttons Apply Click to save changes Reset Click to undo any changes made locally and revert to previously saved values Auto refresh Select the auto refresh icon and the device will refresh the information automatically Upper right icon Refresh Click to refresh the DSCP Based QoS Ingress Classification information manually ...

Page 193: ...ess Web Interface To configure the DSCP Translation parameters in the web interface 1 Click Configuration QoS DSCP Translation 2 Scroll to set the Ingress Translate and Egress Remap DP0 and Remap DP1 Parameters 3 Enable or disable Classify 4 Click Save to save the setting 5 To cancel the setting click the Reset button It will revert to previously saved values Figure 2 19 8 The DSCP Translation Con...

Page 194: ...ters apply to the Egress side 1 Remap DP0 Select the DSCP value from select menu to which you want to remap DSCP value ranges from 0 to 63 2 Remap DP1 Select the DSCP value from select menu to which you want to remap DSCP value ranges from 0 to 63 There is following configurable parameter for Egress side Remap Select the DSCP value from select menu that want to remap to The DSCP value ranges form ...

Page 195: ...selected stack unit as reflected by the page header Web Interface To configure the DSCP Classification parameters in the web interface 1 Click Configuration QoS DSCP Translation 2 Scroll to set the DSCP Parameters 3 Click Save to save the setting 4 To cancel the setting click the Reset button It will revert to previously saved values Figure 2 19 9 The DSCP Classification Configuration Parameter de...

Page 196: ...QoS Classes DSCP Select DSCP value 0 63 from DSCP menu to map DSCP to corresponding QoS Class and DPL value Buttons Apply Click to save changes Reset Click to undo any changes made locally and revert to previously saved values Auto refresh Click on the auto refresh icon and the device will refresh the information automatically Upper right icon Refresh Click to refresh the DSCP Classification infor...

Page 197: ...b Interface To configure the QoS Control List parameters in the web interface 1 Click Configuration QoS QoS Control List 2 Click the to add a new QoS Control List 3 Scroll all parameters and enable the Port Member to join the QCE rules 4 Click Save to save the setting 5 To cancel the setting click the Reset button It will revert to previously saved values Figure 2 19 10 The QoS Control List Config...

Page 198: ...3 4 5 6 7 0 3 4 7 or Any DEI Drop Eligible Indicator Valid values of DEI are 0 1 or Any Frame Type Indicates the type of frame to look for incoming frames Possible frame types are Any The QCE will match all frame type Ethernet Only Ethernet frames with Ether Type 0x600 0xFFFF are allowed LLC Only LLC frames are allowed SNAP Only SNAP frames are allowed IPv4 The QCE will match only IPV4 frames IPv6...

Page 199: ...Any Frame Type Frame Type can have any of the following values 1 Any 2 Ethernet 3 LLC 4 SNAP 5 IPv4 6 IPv6 NOTE All frame types are explained below 1 Any Allow all types of frames 2 Ethernet Ethernet Type Valid Ethernet type can have value within 0x600 0xFFFF or Any default value is Any 3 LLC SSAP Address Valid SSAP Source Service Access Point can vary from 0x00 to 0xFF or Any the default value is...

Page 200: ...ny 32 LS bits DSCP Diffserv Code Point value DSCP It can be specific value range of values or Any DSCP values are in the range 0 63 including BE CS1 CS7 EF or AF11 AF43 Sport Source TCP UDP port 0 65535 or Any specific or port range applicable for IP protocol UDP TCP Dport Destination TCP UDP port 0 65535 or Any specific or port range applicable for IP protocol UDP TCP Action Configuration Class Q...

Page 201: ...t the frame type to enable storm control 3 Scroll to set the Rate Parameters 4 Click Save to save the setting 5 To cancel the setting click the Reset button It will revert to previously saved values Figure 2 19 11 The Storm Control Configuration Parameter description Frame Type The settings in a particular row apply to the frame type listed here Unicast Multicast or Broadcast Enable Enable or disa...

Page 202: ...e network For example if Port A and Port B are Monitoring Port and Monitored Port respectively the traffic received by Port B will be copied to Port A for monitoring Web Interface To configure the Mirror in the web interface 1 Click Configuration Mirroring 2 Scroll to select Port to mirror on which port 3 Scroll to disabled enable TX Only and RX Only to set the Port mirror mode 4 Click Save to sav...

Page 203: ... on this port are mirrored on the mirror port Frames transmitted are not mirrored Tx only Frames transmitted on this port are mirrored on the mirror port Frames received are not mirrored Disabled Neither frames transmitted nor frames received are mirrored Enabled Frames received and frames transmitted are mirrored on the mirror port NOTE For a given port a frame is only transmitted once It is not ...

Page 204: ... Disabled Disable UPnP mode operation When the mode is enabled two ACEs are added automatically to trap UPNP related packets to CPU The ACEs are automatically removed when the mode is disabled TTL The TTL value is used by UPnP to send SSDP advertisement messages Valid values are in the range 1 to 255 Advertising Duration The duration carried in SSDP packets is used to inform a control point or con...

Page 205: ...d out by the GARP Information Propagation GIP component Protocol exchanges take place between GARP participants by means of LLC Type 1 services using the group MAC address and PDU format defined for the GARP application concerned 2 22 1 Global Config The switch stores its configuration in a number of text files in CLI format The files are either virtual RAM based or stored in flash on the switch T...

Page 206: ...second The default is 20 Leave time is a value in the range 60 300 in the units of centi seconds i e in units of one hundredth of a second The default is 60 LeaveAll time is a value in the range 1000 5000 in the units of centi seconds i e in units of one hundredth of a second The default is 1000 Max number of VLANs When GVRP is enabled a maximum number of VLANs supported by GVRP is specified By de...

Page 207: ...eflected by the page header Web Interface To configure the sFlow Agent in the web interface 1 Click Configuration GVRP Port Config 2 Specify Port mode 3 Click Apply Figure 2 22 2 The GVRP Configuration Parameter description GVRP Mode Use this configuration is to enable disable GVRP Mode on a particular port locally Disable Select to Disable GVRP mode on this port Enable Select to Enable GVRP mode ...

Page 208: ...nfiguration of per port flow and counter samplers sFlow configuration is not saved to non volatile memory which means that a reboot or master change will disable sFlow sampling Web Interface To configure the sFlow Agent in the web interface 1 Click Configuration sFlow 2 Set the parameters 3 Click Save to save the setting 4 To cancel the setting click the Reset button It will revert to previously s...

Page 209: ...hrough SNMP Owner contains a string identifying the sFlow receiver If sFlow is configured through SNMP all controls except for the Release button are disabled to avoid inadvertent reconfiguration The button allows for releasing the current owner and disable sFlow sampling The button is disabled if sFlow is currently unclaimed If configured through SNMP the release must be confirmed a confirmation ...

Page 210: ...port Not all sampling rates are achievable If an unsupported sampling rate is requested the switch will automatically adjust it to the closest achievable This will be reported back in this field Flow Sampler Max Header The maximum number of bytes that should be copied from a sampled packet to the sFlow datagram Valid range is 14 to 200 bytes and the default is 128 bytes If the maximum datagram siz...

Page 211: ... mode Indicates the Management mode operation When the mode operation is enabled the message will send out to receive from the server The protocol is based on TCP communication and received on TCP port 443 and the server will send acknowledgments information back sender since TCP is a connection oriented protocol Possible modes are Enabled Enable Switch2go Management mode operation Disabled Disabl...

Page 212: ...rnal Port and Your IGN NAT s Port Forward function manually When Link function works properly Mobile s can access this NAT by Internet Possible modes are Automatic Link Option in Automatic Manual Link Option in Manual Link State Report network information between the Switch and Internet Gateway Device IGN External Port When the Link Option is manual you can choose Setting External Port Internal Po...

Page 213: ...t Activity Code Figure 2 24 2 The User Link Management Parameter description Mobile 1 3 Information about the mobile devices that can access this switch User Mode Assign This Activity Code Privilege Level Activity Code The Activity Code to register the mobile device to the Switch2go Setting Server Validity Period The expiration time of the Activity Code Get Activity Code Click to Get Activity Code...

Page 214: ...row Port Name Enter up to 47 characters to be descriptive name that identifies this port Role Selects any available role for the given switch port Possible roles are Server Assign this as Server Port Client Assign this as Client Port 2 25 SMTP Configuration Use this function to set an Alarm trap You can set the SMTP server to send you an alarm mail when the switch senses an alarm Web Interface To ...

Page 215: ... dotted decimal notation This will be the device that sends out the mail for you User name Specify the username on the mail server Password Specify the password on the mail server Sender Specify the sender name of the alarm mail Return Path Specify the sender email address of the alarm mail This address will be the from address on the email message Email Address 1 6 Email address that will receive...

Page 216: ...tion System Up Time Firmware Version Host Mac Address and Device Port With this information you will know the software version used MAC address serial number how many ports are good and so on This is helpful while troubleshooting 3 1 1 Information The switch system information is provided here Web interface To configure System Information in the web interface 1 Click Monitor System and Information...

Page 217: ...act Platform Name Displays the user defined system name that was configured in System System Information Configuration System Name System Date The current GMT system time and date The system time is obtained through the Timing server running on the switch if any System Uptime The period of time the device has been operational Bootloader Version Displays the current boot loader version number Firmw...

Page 218: ...Publication date Sept 2015 Revision A1 206 MAC Address The MAC Address of this switch Memory Displays the memory size of the system FLASH Displays the flash size of the system ...

Page 219: ...routes and the neighbor cache ARP cache status Web Interface To display the log configuration in the web interface 1 Click Monitor System and IP Status 2 Display the IP address information Figure 3 1 2 The IP Status Parameter description IP Interfaces Interface Show the name of the interface Type Show the address type of the entry This may be LINK or IPv4 Address ...

Page 220: ...ost address of this route Gateway Show the gateway address of this route Status Show the status flags of the route Neighbor cache IP Address Show the IP address of the entry Link Address Show the Link MAC address for which a binding to the IP address given exists Buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh ...

Page 221: ...description Auto refresh Click the auto refresh icon and the device will refresh the log automatically Level level of the system log entry The following level types are supported Information level of the system log Warning Warning level of the system log Error Error level of the system log All All levels ID ID 1 of the system log entry Time It will display the log record by device time The time of...

Page 222: ...ntries starting from the current entry ID Clear Flushes the selected log entries Updates the system log entries starting from the first available entry ID Updates the system log entries ending at the last entry currently displayed Updates the system log entries starting from the last entry currently displayed Updates the system log entries ending at the last available entry ID ...

Page 223: ...ption ID The ID 1 of the system log entry Message The detailed message of the system log entry Upper right icon Refresh clear You can click them for refresh the system log or clear them by manual others for next up page or entry Buttons Refresh Updates the system log entries starting from the current entry ID Updates the system log entries to the first available entry ID Updates the system log ent...

Page 224: ... the link is up for the port green link up red link down EEE Shows if EEE is enabled for the port reflects the settings at the Port Power Savings configuration page LP EEE cap Shows if the link partner is EEE capable EEE Savings Shows if the system is currently saving power due to EEE When EEE is enabled the system will powered down if no frame has been received or transmitted in 5 uSec Actiphy Sa...

Page 225: ...ew in the web interface 1 Click Monitor Port then Traffic Overview 2 If you want to auto refresh then you need to select Auto refresh 3 Click Refresh to refresh the port statistics or clear all information when you click Clear Figure 3 3 1 The Port Statistics Overview Parameter description Port The logical port for the settings contained in the same row Packets The number of received and transmitt...

Page 226: ...214 The number of received frames filtered by forwarding Buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh the page Clear Clears the counters for all ports ...

Page 227: ...d to evoke the Auto refresh 3 Click Refresh to refresh the Queuing Counters or clear all information when you click Clear Figure 3 3 2 The Queuing Counters Overview Parameter description Port The logical port for the settings contained in the same row Qn Qn is the Queue number There are 8 QoS queues per port Q0 is the lowest priority queue Rx Tx The number of received and transmitted packets per q...

Page 228: ...ry of the MVR Statistics Information Figure 3 3 3 The QoS Control List Status Parameter description User Indicates the QCL user QCE Indicates the index of QCE Frame Type Indicates the type of frame to look for incoming frames Possible frame types are Any The QCE will match all frame type Ethernet Only Ethernet frames with Ether Type 0x600 0xFFFF are allowed LLC Only LLC frames are allowed LLC Only...

Page 229: ...s may be required to add a QCE that may not available in that case it shows conflict status as Yes otherwise it is always No NOTE Conflict can be resolved by releasing the H W resources required to add QCL entry when you press the Resolve Conflict button Buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Resolve Conflict Click to release ...

Page 230: ...ansmit and the error counters for receive and transmit Web Interface To Display per Port detailed Statistics Overview in the web interface 1 Click Monitor Ports then Detailed Port Statistics 2 Scroll the Port Index to select which port you want to show the detailed statistics for 3 Port statistics overview 4 If you want to auto refresh the information then you need to click Auto refresh 5 Click Re...

Page 231: ...nd transmitted good and bad packets Rx and Tx Octets The number of received and transmitted good and bad bytes Includes FCS but excludes framing bits Rx and Tx Unicast The number of received and transmitted good and bad unicast packets Rx and Tx Multicast The number of received and transmitted good and bad multicast packets Rx and Tx Broadcast The number of received and transmitted good and bad br...

Page 232: ...r of short 1 frames received with invalid CRC Rx Jabber The number of long 2 frames received with invalid CRC Rx Filtered The number of received frames filtered by the forwarding process Short frames are frames that are smaller than 64 bytes Long frames are frames that are longer than the configured maximum frame length for this port Transmit Error Counters Tx Drops The number of frames dropped du...

Page 233: ...tion Figure 3 3 5 The SFP Information Overview Parameter description Connector Type Display the connector type for instance UTP SC ST LC and so on Fiber Type Display the fiber mode for instance Multi Mode Single Mode Tx Central Wavelength Display the fiber optical transmitting central wavelength for instance 850nm 1310nm 1550nm and so on Baud Rate Display the maximum baud rate of the fiber module ...

Page 234: ...r Serial Number Show the serial number assigned by the manufacturer Date Code Show the date this SFP module was made Temperature Show the current temperature of SFP module Vcc Show the working DC voltage of SFP module Mon1 Bias mA Show the Bias current of SFP module Mon2 TX PWR Show the transmit power of SFP module Mon3 RX PWR Show the receiver power of SFP module ...

Page 235: ...se counters and the number of DHCP messages sent and received by DHCP server Web Interface Display the DHCP server Statistics Overview in the web interface Click Protocol based VLAN configuration and add new entry Figure 3 4 1 1 The Protocol to Group Mapping Table Parameter description Database Counters Pool Number of pools Excluded IP Address Number of excluded IP address ranges Declined IP Addre...

Page 236: ...REQUEST Number of DHCP REQUEST messages received DECLINE Number of DHCP DECLINE messages received RELEASE Number of DHCP RELEASE messages received INFORM Number of DHCP INFORM messages received DHCP Message Sent Counters OFFER Number of DHCP OFFER messages sent ACK Number of DHCP ACK messages sent NAK Number of DHCP NAK messages sent 3 4 1 2 Binding This page displays bindings generated for DHCP c...

Page 237: ...3 Declined IP This page displays declined IP addresses Web Interface To Display DHCP Server Declined IP in the web interface Click DHCP Server and Declined IP Figure 3 4 1 3 The Declined IP Parameter description IP IP address allocated to DHCP client Type Type of binding Possible types are Automatic Manual Expired State State of binding Possible states are Committed Allocated Expired Pool Name The...

Page 238: ...es in the Dynamic DHCP snooping Table are shown on this page Web Interface To monitor an DHCP in the web interface Click Monitor DHCP Snooping table Figure 3 4 2 The DHCP snooping table Parameter description MAC Address User MAC address of the entry VLAN ID VLAN ID in which the DHCP traffic is permitted Source Port Switch Port Number for which the entries are displayed IP Address User IP address o...

Page 239: ...s that resulted in errors while being sent to clients Receive from Server The number of packets received from server Receive Missing Agent Option The number of packets received without agent information options Receive Missing Circuit ID The number of packets received with the Circuit ID option missing Receive Missing Remote ID The number of packets received with the Remote ID option missing Recei...

Page 240: ... The number of received packets from a server Receive Agent Option The number of received packets with relay agent information option Replace Agent Option The number of packets that were replaced with a relay agent information option Keep Agent Option The number of packets whose relay agent information was retained Drop Agent Option The number of packets that were dropped that were received with r...

Page 241: ... Interface To monitor a DHCP Relay statistics in the web interface Click Monitor DHCP Detailed Statistics Figure 3 4 4 The DHCP Detailed Statistics Parameter description Server Statistics Rx and Tx Discover The number of discover option 53 with value 1 packets received and transmitted Rx and Tx Offer The number of offer option 53 with value 2 packets received and transmitted Rx and Tx Request The ...

Page 242: ...he number of lease query option 53 with value 10 packets received and transmitted Rx and Tx Lease Unassigned The number of lease unassigned option 53 with value 11 packets received and transmitted Rx and Tx Lease Unknown The number of lease unknown option 53 with value 12 packets received and transmitted Rx and Tx Lease Active Rx and Tx Lease Active The number of lease active option 53 with value ...

Page 243: ...r Figure 3 5 1 The Access Management Statistics Parameter description Interface The interface type through which the remote host can access the switch Received Packets Number of received packets from the interface when access management mode is enabled Allowed Packets Number of allowed packets from the interface when access management mode is enabled Discarded Packets Number of packets discarded f...

Page 244: ... block it For a MAC address to be set in the forwarding state all enabled user modules must unanimously agree on allowing the MAC address to forward If only one chooses to block it it will be blocked until that user module decides otherwise The status page is divided into two sections one with a legend of user modules and one with the actual port status Web Interface To configure a Port Security S...

Page 245: ...MAC addresses to arrive Limit Reached The Port Security service is enabled by at least the Limit Control user module and that module has indicated that the limit is reached and no more MAC addresses should be taken in Shutdown The Port Security service is enabled by at least the Limit Control user module and that module has indicated that the limit is exceeded No MAC addresses can be learned on th...

Page 246: ... 3 Check Auto refresh 4 Click Refresh to refresh the port detailed statistics Figure 3 5 2 1 2 The Port Security Port Status Parameter description MAC Address VLAN ID The MAC address and VLAN ID for this port If no MAC addresses are learned a single row stating No MAC addresses attached is displayed State Indicates whether the corresponding MAC address is blocked or forwarding In the blocked state...

Page 247: ...Publication date Sept 2015 Revision A1 235 Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh the page ...

Page 248: ...ailed NAS statistics for this port Admin State The port s current administrative state Refer to NAS Admin State for a description of possible values Port State The current state of the port Refer to NAS Port State for a description of the individual states Last Source The source MAC address carried in the most recently received EAPOL frame for EAPOL based authentication and the most recently recei...

Page 249: ...N ID is assigned by the RADIUS server RADIUS assigned is appended to the VLAN ID Read more about RADIUS assigned VLANs here If the port is moved to the Guest VLAN Guest is appended to the VLAN ID Read more about Guest VLANs here Buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh the page ...

Page 250: ...Refer to NAS Admin State for a description of possible values Port State The current state of the port Refer to NAS Port State for a description of the individual states QoS Class The QoS class assigned by the RADIUS server The field is blank if no QoS class is assigned Port VLAN ID The VLAN ID that NAS has put the port in The field is blank if the Port VLAN ID is not overridden by NAS If the VLAN...

Page 251: ...causes the supplicant s EAPOL and Backend Server counters to be shown in the Selected Counters table If no supplicants are attached it shows No supplicants attached This column is not available for MAC based Auth MAC Address For Multi 802 1X this column holds the MAC address of the attached supplicant For MAC based Auth this column holds the MAC address of the attached client Clicking the link cau...

Page 252: ...rized Force Unauthorized Port based 802 1X Single 802 1X Clear All Click to clear the counters for the selected port This button is available in the following modes Multi 802 1X MAC based Auth X Clear This Click to clear both the port counters and all of the attached client s counters The Last Client will not be cleared however This button is available in the following modes Multi 802 1X MAC based...

Page 253: ...Port Indicates the ingress port of the ACE Possible values are All The ACE will match any ingress port Port The ACE will match a specific ingress port Frame Type Indicates the frame type of the ACE Possible values are Any The ACE will match any frame type EType The ACE will match Ethernet Type frames Note that an Ethernet Type based ACE will not get matched by IP and ARP frames ARP The ACE will ma...

Page 254: ...layed the port copy operation is disabled Mirror Specify the mirror operation of this port The allowed values are Enabled Frames received on the port are mirrored Disabled Frames received on the port are not mirrored The default value is Disabled CPU Forward the packet that matched the specific ACE to CPU CPU Once Forward that first packet that matched the specific ACE to CPU Counter The counter i...

Page 255: ...hrough the entries per page input field When first visited the web page will show the first 20 entries from the beginning of the Dynamic ARP Inspection Table The Start from port address VLAN MAC address and IP address input fields allow the user to select the starting point in the Dynamic ARP Inspection Table Clicking the button will update the displayed table starting from that or the closest nex...

Page 256: ...n by IP address and then by MAC address Web Interface To configure a Dynamic IP Source Guard Table Configuration in the web interface 1 Click Security Network IP Source Guard 2 Check Auto refresh 3 Click Refresh to refresh the port detailed statistics 4 Specify the Start from port VLAN ID IP Address and entries per page Figure 3 5 2 4 The Dynamic IP Source Table Parameter description Port Switch P...

Page 257: ...Publication date Sept 2015 Revision A1 245 Refresh Click to refresh the page Updates the system log entries to the first available entry ID Updates the system log entry to the next available entry ID ...

Page 258: ...lick Security AAA then RADIUS Overview 2 Check Auto refresh 3 Click Refresh to refresh the port detailed statistics Figure 3 5 3 1 The RADIUS Authentication Server Status Overview Parameter description The RADIUS server number Click to navigate to detailed statistics for this server IP Address The IP address and UDP port number in IP Address UDP Port notation of this server State The current state...

Page 259: ...rver number Click to navigate to detailed statistics for this server IP Address The IP address and UDP port number in IP Address UDP Port notation of this server State The current state of the server This field takes one of the following values Disabled The server is disabled Not Ready The server is enabled but IP communication is not yet up and running Ready The server is enabled IP communication...

Page 260: ...eb Interface To configure a RADIUS Details Configuration in the web interface 1 Specify the Port that you want to check 2 Click Security AAA then RADIUS Overview 3 Check Auto refresh 4 Click Refresh to refresh the port detailed statistics or clear all information when you click Clear Figure 3 5 3 2 The RADIUS Authentication Statistics Server ...

Page 261: ...uthClientExtMalforme dAccessResponses The number of malformed RADIUS Access Response packets received from the server Malformed packets include packets with an invalid length Bad authenticators or Message Authenticator attributes or unknown types are not included as malformed access responses Rx Bad Authenticators radiusAuthClientExtBadAuthe nticators The number of RADIUS Access Response packets c...

Page 262: ...Ready The server is enabled IP communication is up and running and the RADIUS module is ready to accept access attempts Dead X seconds left Access attempts were made to this server but it did not reply within the configured timeout The server has temporarily been disabled but will get re enabled when the dead time expires The number of seconds left before this occurs is displayed in parentheses Th...

Page 263: ...or retransmission Tx Timeouts radiusAccClientExtTimeouts The number of accounting timeouts to the server After a timeout the client may retry to the same server send to a different server or give up A retry to the same server is counted as a retransmit as well as a timeout A send to a different server is counted as a Request as well as a timeout Other Info This section contains information about t...

Page 264: ...indicates that there hasn t been round trip communication with the server yet Buttons Auto refresh Check this box to enable an automatic refresh of the page at regular intervals Refresh Click to refresh the page immediately Clear Clears the counters for the selected server The Pending Requests counter will not be cleared by this operation ...

Page 265: ...l use the last entry of the currently displayed entry as a basis for the next lookup When the end is reached the text No more entries is shown in the displayed table Use the button to start over Web Interface To configure a RMON Statistics in the web interface 1 Specify the Port you want to check 2 Click Security Switch RMON then Statistics 3 Check Auto refresh 4 Click Refresh to refresh the port ...

Page 266: ...octets received with invalid CRC Coll The best estimate of the total number of collisions on this Ethernet segment 64 The total number of packets including bad packets received that were 64 octets in length 65 127 The total number of packets including bad packets received that were between 65 to 127 octets in length 128 255 The total number of packets including bad packets received that were betwe...

Page 267: ...Publication date Sept 2015 Revision A1 255 Updates the table starting with the entry after the last entry currently displayed ...

Page 268: ... displayed entry as a basis for the next lookup When the end is reached the text No more entries is shown in the displayed table Use the button to start over Web Interface To configure a RMON history Configuration in the web interface 1 Specify the Port that you want to check 2 Click Security Switch RMON then History 3 Check Auto refresh 4 Click Refresh to refresh the port detailed statistics or c...

Page 269: ...he total number of packets received that were longer than 1518 octets Frag The number of frames with size less than 64 octets received with invalid CRC Jabb The number of frames with size larger than 64 octets received with invalid CRC Coll The best estimate of the total number of collisions on this Ethernet segment Utilization The best estimate of the mean physical layer network utilization on th...

Page 270: ...asis for the next lookup When the end is reached the text No more entries is shown in the displayed table Use the button to start over Web Interface To configure a RMON Alarm Overview in the web interface 1 Specify Port that you want to check 2 Click Security Switch RMON then Alarm 3 Check Auto refresh 4 Click Refresh to refresh the port detailed statistics Figure 3 5 4 1 3 RMON Alarm Overview Par...

Page 271: ... Index Falling event index Buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh the page immediately Updates the table starting from the first entry in the Alarm Table i e the entry with the lowest ID Updates the table starting with the entry after the last entry currently displayed ...

Page 272: ...isplayed entry as a basis for the next lookup When the end is reached the text No more entries is shown in the displayed table Use the button to start over Web Interface To configure a RMON Event Overview in the web interface 1 Click Security Switch RMON then Event 2 Check Auto refresh 3 Click Refresh to refresh the port detailed statistics 4 Specify the Port that you want to check Figure 3 5 4 1 ...

Page 273: ...Publication date Sept 2015 Revision A1 261 Updates the table starting with the entry after the last entry currently displayed ...

Page 274: ...ggr ID The Aggregation ID associated with this aggregation instance For LLAG the id is shown as isid aggr id and for GLAGs as aggr id Partner System ID The system ID MAC address of the aggregation partner Partner Key The Key that the partner has assigned to this aggregation ID Last changed The time since this aggregation changed Local Ports Shows which ports are part of this aggregation for this s...

Page 275: ...mber LACP Yes means that LACP is enabled and the port link is up No means that LACP is not enabled or that the port link is down Backup means that the port could not join the aggregation group but will join if other port leaves Meanwhile its LACP status is disabled Key The key assigned to this port Only ports with the same key can aggregate together Aggr ID The Aggregation ID assigned to this aggr...

Page 276: ...Publication date Sept 2015 Revision A1 264 Buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh the page ...

Page 277: ... 3 3 Click Refresh to refresh the LACP Statistics Figure 3 6 3 The LACP Statistics Parameter description Port The switch port number LACP Received Shows how many LACP frames have been received at each port LACP Transmitted Shows how many LACP frames have been sent from each port Discarded Shows how many unknown or illegal LACP frames have been discarded at each port Buttons Auto refresh Check this...

Page 278: ...Publication date Sept 2015 Revision A1 266 Refresh Click to refresh the page ...

Page 279: ...Statistics Figure 3 7 Loop Protection Status Parameter description Port The switch port number of the logical port Action The currently configured port action Transmit The currently configured port transmit mode Loops The number of loops detected on this port Status The current loop protection status of the port Loop Whether a loop is currently detected on the port Time of Last Loop The time of th...

Page 280: ...e next page STP Detailed Bridge Status Figure 3 8 1 The STP Bridges status Parameter description MSTI The Bridge Instance This is also a link to the STP Detailed Bridge Status Bridge ID The Bridge ID of this Bridge instance Root ID The Bridge ID of the currently elected root bridge Root Port The switch port currently assigned the root port role Root Cost Root Path Cost For the Root Bridge it is ze...

Page 281: ... 3 Click Refresh to refresh the STP Bridges Figure 3 8 2 The STP Port status Parameter description Port The switch port number of the logical STP port CIST Role The current STP port role of the CIST port The port role can be one of the following values AlternatePort Backup Port RootPort DesignatedPort Disabled CIST State The current STP port state of the CIST port The port state can be one of the ...

Page 282: ...itch port number of the logical STP port MSTP The number of MSTP Configuration BPDUs received transmitted on the port RSTP The number of RSTP Configuration BPDUs received transmitted on the port STP The number of legacy STP Configuration BPDUs received transmitted on the port TCN The number of legacy Topology Change Notification BPDUs received transmitted on the port Discarded Unknown The number o...

Page 283: ...he Multicast VLAN ID IGMP MLD Queries Received The number of Received Queries for IGMP and MLD respectively IGMP MLD Queries Transmitted The number of Transmitted Queries for IGMP and MLD respectively IGMPv1 Joins Received The number of Received IGMPv1 Join s IGMPv2 MLDv1 Report s Received The number of Received IGMPv2 Join s and MLDv1 Report s respectively IGMPv3 MLDv2 Report s Received The numbe...

Page 284: ...ough the entries per page input field When first visited the web page will show the first 20 entries from the beginning of the MVR Channels Groups Information Table The Start from VLAN and Group Address input fields allow the user to select the starting point in the MVR Channels Groups Information Table Clicking the button will update the displayed table starting from that or the closest next MVR ...

Page 285: ...fresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh the page Updates the system log entries to the first available entry ID Updates the system log entry to the next available entry ID ...

Page 286: ...tries from the MVR SFM Information Table default is 20 selected through the entries per page input field When first visited the web page will show the first 20 entries from the beginning of the MVR SFM Information Table The Start from VLAN and Group Address input fields allow the user to select the starting point in the MVR SFM Information Table Clicking the button will update the displayed table ...

Page 287: ... address the text None is shown in the Source Address field Type Indicates the Type It can be either Allow or Deny Hardware Filter Switch Indicates whether data destined to the specific group address from the source IPv4 IPv6 address can be handled by chip or not Buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh ...

Page 288: ... IGMP Snooping status in the web interface 1 Click Monitor IGMP Snooping Status 2 To auto refresh the information then you need to select Auto refresh 3 Click Refresh to refresh the IGMP Snooping Status 4 Click Clear to clear the IGMP Snooping Status Figure 3 10 1 1 The IGMP Snooping Status Parameter description VLAN ID The VLAN ID of the entry Querier Version Working Querier Version currently Hos...

Page 289: ...t Displays which ports act as router ports A router port is a port on the Ethernet switch that leads towards the Layer 3 multicast device or IGMP querier Static denotes the specific port is configured to be a router port Dynamic denotes the specific port is learned to be a router port Both denote the specific port is configured or learned to be a router port Port Switch port number Status Indicate...

Page 290: ...ups Information Parameter description Navigating the IGMP Group Table Each page shows up to 99 entries from the IGMP Group table default is 20 selected through the entries per page input field When first visited the web page will show the first 20 entries from the beginning of the IGMP Group Table The Start from VLAN and group input fields allow the user to select the starting point in the IGMP Gr...

Page 291: ...fresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh the page Updates the system log entries to the first available entry ID Updates the system log entry to the next available entry ID ...

Page 292: ... Table Each page shows up to 99 entries from the IGMP SFM Information table default is 20 selected through the entries per page input field When first visited the web page will show the first 20 entries from the beginning of the IGMP SFM Information Table The Start from VLAN and group input fields allow the user to select the starting point in the IGMP SFM Information Table Clicking the button wil...

Page 293: ...ltering to be 128 Type Indicates the Type It can be either Allow or Deny Hardware Filter Switch Indicates whether data destined to the specific group address from the source IPv4 address can be handled by chip or not Buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh the page Updates the system log entries to the ...

Page 294: ... 1 Click Monitor MLD Snooping Status 2 To auto refresh the information select Auto refresh 3 Click Refresh to refresh an entry of the MLD Snooping Status Information 4 Click Clear to clear the MLD Snooping Status Figure 3 10 2 1 The MLD Snooping Status Parameter description VLAN ID The VLAN ID of the entry Querier Version The current working Querier Version Host Version The current working Host Ve...

Page 295: ...a port on the Ethernet switch that leads to the Layer 3 multicast device or MLD querier Static denotes the specific port is configured to be a router port Dynamic denotes the specific port is learned to be a router port Both denote the specific port is configured or learned to be a router port Port Switch port number Status Indicate whether a specific port is a router port or not Buttons Auto refr...

Page 296: ...om the MLD Group table default is 20 selected through the entries per page input field When first visited the web page will show the first 20 entries from the beginning of the MLD Group Table The Start from VLAN and group input fields allow the user to select the starting point in the MLD Group Table Clicking the button will update the displayed table starting from that or the closest next MLD Gro...

Page 297: ...o refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh the page Updates the system log entries to the first available entry ID Updates the system log entry to the next available entry ID ...

Page 298: ... Information Table Each page shows up to 99 entries from the MLD SFM Information table default is 20 selected through the entries per page input field When first visited the web page will show the first 20 entries from the beginning of the MLD SFM Information Table The Start from VLAN and group input fields allow the user to select the starting point in the MLD SFM Information Table Clicking the b...

Page 299: ...to be 128 Type Indicates the Type It can be either Allow or Deny Hardware Filter Switch Indicates whether data destined to go to the specific group address from the source IPv6 address can be handled by the chip or not Buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh the page Updates the system log entries to th...

Page 300: ...on NOTE If your network without any device supports LLDP then the table will show No LLDP neighbour information found Parameter description Local Port The port on which the LLDP frame was received Chassis ID The Chassis ID is the identification of the neighbor s LLDP frames Port ID The Remote Port ID is the identification of the neighbor port Port Description Port Description is the port descripti...

Page 301: ...bled the capability is followed by Management Address Management Address is the neighbor unit s address that is used for higher layer entities to assist discovery by the network management This could for instance hold the neighbor s IP address Buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh the page ...

Page 302: ...D Network Connectivity Devices as defined in TIA 1057 provide access to the IEEE 802 based LAN infrastructure for LLDP MED Endpoint Devices An LLDP MED Network Connectivity Device is a LAN access device based on any of the following technologies 1 LAN Switch Router 2 IEEE 802 1 Bridge 3 IEEE 802 3 Repeater included for historical reasons 4 IEEE 802 11 Wireless Access Point 5 Any device that suppor...

Page 303: ...MED Communication Endpoint Class III definition is applicable to all endpoint products that act as end user communication appliances supporting IP media Capabilities include all of the capabilities defined for the previous Generic Endpoint Class I and Media Endpoint Class II classes and are extended to include aspects related to end user devices Example product categories expected to adhere to thi...

Page 304: ... application type is using a tagged or an untagged VLAN Can be Tagged or Untagged Untagged The device is using an untagged frame format and as such does not include a tag header as defined by IEEE 802 1Q 2003 Tagged The device is using the IEEE 802 1Q tagged frame format VLAN ID VLAN ID is the VLAN identifier VID for the port as defined in IEEE 802 1Q 2003 A value of 1 through 4094 is used to defi...

Page 305: ...s the power source used by a PSE or PD device If the device is a PSE device it can either run on its Primary Power Source or its Backup Power Source If it is unknown whether the PSE device is using its Primary Power Source or its Backup Power Source it is indicated as Unknown If the device is a PD device it can either run on its local power supply or it can use the PSE as power source It can also ...

Page 306: ... its current configuration The maximum allowed value is 102 3 W If the device indicates a value higher than 102 3 W it is represented as reserved Buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh the page ...

Page 307: ...mitted Tx Tw The link partner s maximum time that the transmit path can hold off sending data after reassertion of LPI Rx Tw The link partner s time that the receiver would like the transmitter to holdoff to allow time for the receiver to wake from sleep Fallback Receive Tw The link partner s fallback receive Tw A receiving link partner may inform the transmitter of an alternate desired Tw_sys_tx ...

Page 308: ...ia LLDP Resolved Rx Tw The resolved Rx Tw for this link Note NOT the link partner The resolved value that is the actual tx wakeup time used for this link based on EEE information exchanged via LLDP EEE in Sync Shows whether the switch and the link partner have agreed on wake times Red Switch and link partner have not agreed on wakeup times Green Switch and link partner have agreed on wakeup times ...

Page 309: ...date the web screen 3 Click Auto refresh to auto update the web screen 4 Click Clear to clear all counters Figure 3 11 5 The LLDP Port Statistics information Parameter description Global Counters Neighbor entries were last changed at It also shows the time when the last entry was last deleted or added It also shows the time elapsed since the last change was detected Total Neighbors Entries Added S...

Page 310: ...rames require a new entry in the table when the Chassis ID or Remote Port ID is not already contained within the table Entries are removed from the table when a given port s link is down an LLDP shutdown frame is received or when the entry ages out TLVs Discarded Each LLDP frame can contain multiple pieces of information known as TLVs TLV is short for Type Length Value If a TLV is malformed it is ...

Page 311: ...al port number for this row PD Class Each PD is classified according to a class that defines the maximum power the PD will use The PD Class shows the PDs class Five Classes are defined Class 0 Max power 15 4 W Class 1 Max power 4 0 W Class 2 Max power 7 0 W Class 3 Max power 15 4 W Class 4 Max power 30 0 W Power Requested The Power Requested shows the requested amount of power the PD wants to be r...

Page 312: ...is disabled by user PoE turned OFF Power budget exceeded The total requested or used power by the PDs exceeds the maximum power the Power Supply can deliver and port s with the lowest priority is are powered down No PD detected No PD detected for the port PoE turned OFF PD overload The PD has requested or used more power than the port can deliver and is powered down PoE turned OFF PD is off Invali...

Page 313: ...irst displayed will be the one with the lowest VLAN ID and the lowest MAC address found in the MAC Table The Start from MAC address and VLAN input fields allow the user to select the starting point in the MAC Table Clicking the Refresh button will update the displayed table starting from that or the closest next MAC Table match In addition the two input fields will upon a Refresh button click assu...

Page 314: ...efresh the page Updates the system log entries to the first available entry ID Updates the system log entry to the next available entry ID NOTE 00 40 C7 73 01 29 your switch MAC address for IPv4 33 33 00 00 00 01 Destination MAC for IPv6 Router Advertisement reference IPv6 RA JPG 33 33 00 00 00 02 Destination MAC for IPv6 Router Solicitation reference IPv6 RS JPG 33 33 FF 73 01 29 Destination MAC ...

Page 315: ...icator and an Authentication Server MVRP Multiple VLAN Registration Protocol MVRP allows dynamic registration and deregistration of VLANs on ports on a VLAN bridged network Voice VLAN Voice VLAN is a VLAN configured specially for voice traffic typically originating from IP phones MVR MVR is used to eliminate the need to duplicate multicast traffic for subscribers in each VLAN Multicast traffic for...

Page 316: ... entries per page input field When first visited the web page will show the first 20 entries from the beginning of the VLAN Table The first displayed will be the one with the lowest VLAN ID found in the VLAN Table The VLAN input fields allow the user to select the starting point in the VLAN Table Clicking the Refresh button will update the displayed table starting from that or the closest next VLA...

Page 317: ...uration such as PVID UVID Currently we support the following VLAN User types CLI Web SNMP These are referred to as static NAS NAS provides port based authentication which involves communications between a Supplicant Authenticator and an Authentication Server Voice VLAN Voice VLAN is a VLAN configured specially for voice traffic typically originating from IP phones MVR MVR is used to eliminate the ...

Page 318: ...rocessing If the port only accepts tagged frames untagged frames received on that port are discarded Port VLAN ID Shows the Port VLAN ID PVID that a given user wants the port to have The field is empty if not overridden by the selected user Tx Tag Shows egress filtering frame status whether tagged or untagged UVID Shows UVID untagged VLAN ID Port s UVID determines the packet s behavior at the egre...

Page 319: ...nd an Authentication Server Web Interface To Display MAC based VLAN configuration in the web interface 1 Click Monitor MAC based VLAN Status 2 Specify the Static NAS Combined 3 Display MAC based information Figure 3 15 1 The MAC based VLAN Membership Status for User Static Parameter description MAC Address Indicates the MAC address VLAN ID Indicates the VLAN ID Port Members Port members of the MAC...

Page 320: ...ary depending on the new frame type you selected Value Valid value that can be entered in this text field depends on the option selected from the preceding Frame Type selection menu Below are the criteria for three different Frame Types 1 For Ethernet Values in the text field when Ethernet is selected as a Frame Type is called etype Valid values for etype ranges from 0x0600 0xffff 2 For LLC Valid ...

Page 321: ...of PID will be etype 0x0600 0xffff and if value of OUI is other than 00 00 00 then valid value of PID will be any value from 0x0000 to 0xffff Group Name A valid Group Name is a unique 16 character long string for every entry which consists of a combination of alphabets a z or A Z and integers 0 9 NOTE special character and underscore _ are not allowed Buttons Auto refresh Check this box to refresh...

Page 322: ...nd integers 0 9 no special characters are allowed The Group name you try to map to a VLAN must be present in Protocol to Group mapping table and must not be pre used by any other existing mapping entry on this page VLAN ID Indicates the ID to which Group Name will be mapped A valid VLAN ID ranges from 1 4095 Port Members A row of check boxes for each port is displayed for each Group Name to VLAN I...

Page 323: ...is 0 the application will auto generate the VCE ID for that entry Deletion and lookup of IP subnet based VLAN are based on VCE ID IP Address Indicates the IP address Mask Length Indicates the network mask length VLAN ID Indicates the VLAN ID VLAN ID can be changed for the existing entries Port Members A row of check boxes for each port is displayed for each IP subnet based VLAN entry To include a ...

Page 324: ...on Figure 3 16 The sFlow Statistics Parameter description Owner This field shows the current owner of the sFlow configuration It assumes one of three values as follows If sFlow is currently unconfigured unclaimed Owner contains none If sFlow is currently configured through Web or CLI Owner contains Configured through local management If sFlow is currently configured through SNMP Owner contains a s...

Page 325: ...umber of counter samples sent to the sFlow receiver Port Statistics Port The port number for which the following statistics applies Rx and Tx Flow Samples The number of flow samples sent to the sFlow receiver originating from this port Here flow samples are divided into Rx and Tx flow samples where Rx flow samples contains the number of packets that were sampled upon reception ingress on the port ...

Page 326: ...t IPv6 connectivity issues Web Interface To configure an ICMP PING Configuration in the web interface 1 Specify ICMP PING IP Address 2 Specify ICMP PING Size 3 Click Start Figure 4 1 The ICMP Ping Parameter description IP Address To set the IP Address of device as what you want to ping Ping Length The payload size of the ICMP packet Values range from 2 bytes to 1452 bytes Ping Count The count of t...

Page 327: ...address Start Click the Start button then the switch will start to ping the device using the ICMP packet size set on the switch After you press Start 5 ICMP packets are transmitted and the sequence number and round trip time are displayed when the switch receives a reply The page refreshes automatically until responses to all packets are received or until a timeout occurs PING6 server 10 10 132 20...

Page 328: ...to 30 seconds Egress Interface Only for IPv6 The VLAN ID VID of the specific egress IPv6 interface where the ICMP packet goes The given VID ranges from 1 to 4094 and will be effective only when the corresponding IPv6 interface is valid When the egress interface is not given PING6 finds the best matched interface for the destination Do not specify egress interface for loopback address Do specify eg...

Page 329: ...64 bytes from 10 10 132 20 icmp_seq 1 time 0ms 64 bytes from 10 10 132 20 icmp_seq 2 time 0ms 64 bytes from 10 10 132 20 icmp_seq 3 time 0ms 64 bytes from 10 10 132 20 icmp_seq 4 time 0ms Sent 5 packets received 5 OK 0 bad You can configure the following properties of the issued ICMP packets ...

Page 330: ...ccurate for cables of length 7 140 meters 10 and 100 Mbps ports will be linked down while running VeriPHY Therefore running VeriPHY on a 10 or 100 Mbps management port will cause the switch to stop responding until VeriPHY is complete Web Interface To configure a VeriPHY Cable Diagnostics Configuration in the web interface 1 Specify the Port that you want to check 2 Click Start Figure 4 3 The Veri...

Page 331: ... Parameter description Protocol The protocol ICMP UDP TCP packets to send IP Address The destination IP Address Wait Time Set the time in seconds to wait for a response to a probe default 5 0 sec Values range from 1 to 60 The payload size of the ICMP packet values range from 2 bytes to 1452 bytes Max TTL Specifies the maximum number of hops max time to live value traceroute will probe Values range...

Page 332: ...to restart the switch for any maintenance needs Any configuration files or scripts that you saved in the switch should still be available afterwards Web Interface To configure a Restart Device Configuration in the web interface 1 Chick Restart Device 2 Click Yes Figure 5 1 Restart Device Parameter description Restart Device You can restart the switch on this page After restart the switch will boot...

Page 333: ...pts will recover to factory default values Web Interface To configure a Factory Defaults Configuration in the web interface 1 Click Factory Defaults 2 Click Yes Figure 5 3 1 The Factory Defaults Parameter description Buttons Yes Click the Yes button to reset the configuration to Factory Defaults No Click No to return to the Port State page without resetting the configuration ...

Page 334: ...wse Click the Browse button to search the Firmware URL and filename NOTE This page facilitates an update of the firmware controlling the switch Uploading software will update all managed switches to the location of a software image and click After the software image is uploaded a page announces that the firmware update is initiated After about a minute the firmware is updated and all managed switc...

Page 335: ... this case the Activate Alternate Image button is also disabled 2 If the alternate image is active due to a corruption of the primary image or by manual intervention uploading a new firmware image to the device will automatically use the primary image slot and activate this 3 The firmware version and date information may be empty for older firmware releases This does not constitute an error Web In...

Page 336: ...age the alternate image is named image bk Version The version of the firmware image Date The date when the firmware was produced Buttons Activate Alternate Image Click to use the Activate Alternate Image This button may be disabled depending on system state Cancel Cancel activating the backup image Navigates away from this page ...

Page 337: ...system is restored to default settings It is also possible to store up to two other files and apply them to running config thereby switching configuration 5 4 1 Save startup config This copies running config to startup config thereby ensuring that the currently active configuration will be used at the next reboot Web Interface To save running configuration in the web interface 1 Chick Browser to s...

Page 338: ...k upload Select Figure 5 4 2 Configuration upload There are three system files 1 running config A virtual file that represents the currently active configuration on the switch This file is volatile 2 startup config The startup configuration for the switch read at boot time 3 default config A read only file with vendor specific configuration This file is read when the system is restored to default ...

Page 339: ...ly replaced with the configuration in the downloaded file Merge mode The downloaded file is merged into running config If the file system is full i e contains the three system files mentioned above plus two other files it is not possible to create new files but an existing file must be overwritten or another deleted first Web Interface To download the configuration in the web interface 3 Click Bro...

Page 340: ...configuration in the web interface 1 Click Browser to select Maintenance Configuration in your device 2 Click Activate Select Figure 5 4 4 Configuration Activation There are two system files 1 default config A read only file with vendor specific configuration This file is read when the system is restored to default settings 2 startup config The startup configuration for the switch read at boot tim...

Page 341: ...switch to the default configuration Web Interface To delete the configuration in the web interface 1 Click Browser to select Maintenance Configuration in your device 2 Click Delete Select Figure 5 4 5 Delete Configuration There is one system file 1 startup config The startup configuration for the switch read at boot time Parameter description Buttons Delete Configuration Click the Delete button an...

Page 342: ...e Information page shows general system information for the PoE DMS Switch including its DMS software version the maximum number of devices the switch can manage MAC Address and IP Address for the Switch Web interface To configure DMS Information in the web interface 1 Click Management and Information 2 Select Enabled or Disabled for the DMS state 3 Specify the IP Setting 4 Select Enabled or Disab...

Page 343: ... number Total Device Displays the number of devices in the topology MAC Address The MAC Address of this switch Current IP Address The current address IPv4 DMS uses switch interface VLAN1 DMS State Enabled or Disabled DMS IP Address The IPv4 address of the interface VLAN1 System name The IPv4 network mask of the interface VLAN1 ...

Page 344: ... Click to refresh Devices List 3 Select and the device will refresh the information automatically 4 Click to edit the Device Name and Http Port 5 Select Off Line device to remove 6 Click to save changes Figure 6 2 Device List Parameter description Remove Off Line devices removed from selected device Status Device link state On Off Line Model Name Device model name Device Name Device name Edit Devi...

Page 345: ...Publication date Sept 2015 Revision A1 333 IP Address Device IP address hyperlink re direct to device website Version Device firmware version ...

Page 346: ...logy View In this page you can see a visual view of the topology in a cluster of networks Web interface To configure DMS Topology View in the web interface 1 Click Graphical Monitoring and Topology View 2 Click to select the display information in Topology View Figure 7 1 Topology View ...

Page 347: ... cabinet Reboot Device Reboot the PD device Device Type Select Device Type for PC IP phone IP cam AP or other device Click to refresh the Topology View Click to rescan the Topology View Use the directional pad to scroll up down left or right Use the slider to zoom in out Alternatively you can use the mouse to navigate by clicking and dragging the left mouse button Use the mouse wheel to zoom in ou...

Page 348: ...Publication date Sept 2015 Revision A1 336 Select the device category Search for device by typing IP MAC address or Model Device name ...

Page 349: ...Floor View in the web interface 1 Click DMS Graphic Monitoring Floor Plan and Floor View Figure 7 2 Floor View Use the directional pad to scroll up down left or right Use the slider to zoom in out Alternatively you can use the mouse to navigate by clicking and dragging the left mouse button Use the mouse wheel to zoom in out Save the whole View to SVG PNG or PDF Select the device category Search f...

Page 350: ...e page or show a list of devices Web interface To configure DMS Map View in the web interface 1 Click DMS Graphic Monitoring and Map View Figure 7 3 Map View Use the directional pad to scroll up down left or right Use the slider to zoom in out Alternatively you can use the mouse to navigate by clicking and dragging the left mouse button Use the mouse wheel to zoom in out Select the device category...

Page 351: ...Floor Image In this page an administrator can add or delete a custom map or floor image Web interface To configure DMS Information in the web interface 1 Click Maintenance and Floor Image 2 Click Browse to select Floor image in your device 3 Click Add Figure 8 1 Floor Image ...

Page 352: ...test the link route between the switch and the device A troubleshooting solution is provided by the system so that administrators can detect where the problem lies Note that the topology of network needs to be saved for this function to work properly Web interface To configure DMS Information in the web interface 1 Click DMS Diagnostics and Device Status 2 Select device to start the recover Mechan...

Page 353: ...isual chart of network traffic of all the devices managed by the PoE DMS switch Web interface To configure DMS Information in the web interface 1 Click DMS Monitor and Traffic 2 Specify the DMS state longitude and latitude IP address Subnet Mask 3 Click Apply Figure 8 3 Traffic Chart ...

Page 354: ...nto has three transmitters set one transmitter to rotary switch setting 0 the next transmiter to rotary switch setting 1 and the last transmitter to rotary switch setting 2 9 1 Obtaining Your Media Controller License Key Case 1 You order a MediaCento controller license for a new switch Black Box installs the key on the switch and sends you an email with the license key for your receiving records C...

Page 355: ...ty code serial number to your Black Box contact so an authentication code can be created 4 Black Box will send you an email certificate with the Authentication Code 5 Log into the CLI Then run the command media controller Authentication Code enable disable Paste the Authentication Code you received into the command where you see the Authentication Code The image on the next page shows how the comm...

Page 356: ...Page 344 Figure 9 3 Enable the Media Controller Function 6 Exit out of the CLI Figure 9 4 Log out of the CLI 7 Log into the GUI and go to DMS to check if the Media Controller function is present ...

Page 357: ...troller function present on the GUI 9 3 Media Controller Options The 4th option under the DMS tab on the System Information screen is the Media Controller menu as shown below Figure 9 6 Media Controller Menu option on the DMS menu ...

Page 358: ...Page 346 When you click on the Media Controller option the expanded Media Controller Menu pops up Figure 9 7 Media Controller Menu Expanded Click on the Hardware tab Figure 9 8 Blank Hardware screen ...

Page 359: ...ch will detect all Media Cento units on the Network They will be grouped as Transmitters and Receivers Figure 9 9 Populated hardware screen You can highlight the different units and name them to make them easier to identify Figure 9 10 Hardware screen with units identified by name ...

Page 360: ...e Media Controller menu to switch which receivers are connected to which transmitters The Units are setup in a grid display Transmitters are listed across the top and receivers are listed down the side Just click the box across from a receiver to attach it to the selected transmitter then click the switch button to activate Figure 9 12 Custom Display screen You can also use the grid to setup Prese...

Page 361: ...e for preset Click on the Dashboard option in the Media Controller menu Figure 9 14 Dashboard screen Use the dropdown Preset box to choose presets to switch to Once you choose a Preset click the Publish button for it to take effect ...

Page 362: ... as a group between Transmitters Once you have moved the Receivers you wanted from the left box to the Right box fill in the Title to give the group a name then press the save Group button Figure 9 16 Groups menu Group switching will be done from the Custom Menu Groups will be added under the list of receivers and you choose which transmitter the group will be connected to then click the switch bu...

Page 363: ...ion of the current configuration including which transmitters each receiver is connected to Figure 9 18 Dashboard option The Preset drop down box on the Dashboard can be used to do switching Select the preset and click on the Publish button The Dashboard will show the changed configuration ...

Page 364: ...m the current configuration of the Media Controller info These files can be used to quickly configure another switch or recover a switch that has issues Figure 9 20 Save Configuration option Use the Restore Configuration option on the Media Controller menu to upload config files to switches ...

Page 365: ...Page 353 Figure 9 21 Restore Configuration option ...

Page 366: ... the example above r is rx1 t transmitter name or IP address in the example above t is 169 254 4 36 10 3 Switch Group http bbox local net bbapi v1 apiuser switchgroup u apiuser p apipass2015 t 169 254 4 36 g g4 where bbox local net switch web management IP address switchgroup is the command name u user in the example above user name is apiuser p password in the example above password is apipass201...

Page 367: ...7 Tech support available in 60 seconds or less Copyright 2016 Black Box Corporation All rights reserved Black Box and the Double Diamond logo are registered trademarks of BB Technologies Inc Any third party trademarks appearing in this manual are acknowledged to be the property of their respective owners Black Box Tech Support FREE Live 24 7 Tech support the way it should be Great tech support is ...

Reviews: