background image

User Manual

•  LPB5028A has (20) 10/100/1000BASE-T access ports, (4) 100/1G copper/

fiber combo ports with dual-speed SFP slots, and (4) 10 Gigabit SFP+ 
uplink ports with dual-speed (1G/10G).

•  LPB5052A has (48) 10/100/1000BASE-T access ports, and (4) 10 Gigabit 

SFP+ uplink ports with dual-speed (1G/10G).

Gigabit PoE+ Ethernet Managed Switch Eco

LPB5028A

LPB5052A

Order toll-free in the U.S.: Call 877-877-BBOX (outside U.S. call 724-746-5500)

FREE technical support 24 hours a day, 7 days a week: Call 724-746-5500 or fax 724-746-0746

Mailing address: Black Box Corporation, 1000 Park Drive, Lawrence, PA 15055-1018

Web site: www.blackbox.com   •   E-mail: [email protected]

Customer 

Support 

Information

Summary of Contents for LPB5028A

Page 1: ...0 Gigabit SFP uplink ports with dual speed 1G 10G Gigabit PoE Ethernet Managed Switch Eco LPB5028A LPB5052A Order toll free in the U S Call 877 877 BBOX outside U S call 724 746 5500 FREE technical su...

Page 2: ...is Manual Black Box and the Double Diamond logo are registered trademarks of BB Technologies Inc Any other trademarks mentioned in this manual are acknowledged to be the property of the trademark owne...

Page 3: ...en the equipment is operated in a commercial environment Operation of this equipment in a residential area is likely to cause interference in which case the user at his own expense will be required to...

Page 4: ...n el flujo de aire por los orificios de ventilaci n 10 El equipo el ctrico deber ser situado fuera del alcance de fuentes de calor como radiadores registros de calor estufas u otros aparatos incluyend...

Page 5: ...al charge To protect your device always Touch the metal chassis of your computer to ground the static electrical charge before you pick up the circuit device Pick up the device by holding it on the le...

Page 6: ...ting to PCs Servers Hubs and Switches 19 3 3 Network Wiring Connections 19 4 System 21 4 1 System Information 21 4 1 1 Information 21 4 1 2 Configuration 22 4 1 3 CPU Load 23 4 2 Time 24 4 2 1 Manual...

Page 7: ...Status 83 5 5 5 Group Information 84 5 5 6 IPv4 SSM Information 85 5 6 MLD Snooping 87 5 6 1 Basic Configuration 87 5 6 2 VLAN Configuration 89 5 6 3 Port Group Filtering 90 5 6 4 Status 91 5 6 5 Grou...

Page 8: ...CP based QoS 157 5 15 8 DSCP Translation 159 5 15 9 DSCP Classification 161 5 15 10 QoS Control List Configuration 162 5 15 11 QCL Status 165 5 15 12 Storm Control 167 5 15 13 WRED 168 5 16 s Flow Age...

Page 9: ...6 7 3 Port Status 215 6 8 Access Managment 216 6 8 1 Configuration 216 6 8 2 Statistics 217 6 9 SSH 218 6 10 HTTPs 218 6 11 Auth Method 219 7 Maintenance 221 7 1 Restart Device 221 7 2 Firmware 221 7...

Page 10: ...ess ports 4 10 Gigabit SFP uplink slots with dual speed 1G 10G 1 DB9 console port Switching Database 32K MAC address entries Connectors LPB5028A 24 RJ 45 4 SFP slots 4 SFP slots 1 DB9 LPB5052A 48 RJ 4...

Page 11: ...802 3u 100Base TX Ethernet Twisted pair Copper IEEE 802 3ab 1000Base TX Ethernet Twisted pair Copper IEEE 802 3z 1000Base X Ethernet IEEE 802 3x Flow Control Capability ANSI IEEE 802 3 Auto negotiati...

Page 12: ...4 10 Gigabit SFP uplink slots with dual speed 1G 10G Unlike other entry level network switching solutions that provide advance managed network capabilities only in the costliest models the Gigabit Po...

Page 13: ...combo ports with dual speed SFP slots and the LPB5052A switch has 48 1000BASE T RJ 45 ports All RJ 45 ports support automatic MDI MDI X operation auto negotiation and IEEE 802 3x auto negotiation of f...

Page 14: ...rnet Managed Switch Eco switch includes a display panel for system and port indications that simplify installation and network troubleshooting The LEDs are located on left hand side of the front panel...

Page 15: ...ach connection For maximum data integrity the switch uses store and forward technology With this technology the entire packet is received into a buffer and checked for validity before it is forwarded...

Page 16: ...the login menu you have to input the complete username and password respectively the LPB5028A will not give you a shortcut to username automatically This looks inconvenient but is safer This supports...

Page 17: ...ter 3 Operation of Web based Management Figure 3 1 The login page NOTE If you need to configure a function or parameter follow the instructions in this User s Guide Or you can access the Switch s help...

Page 18: ...724 746 5500 blackbox com Page 18 Chapter 3 Operation of Web based Management Figure 3 2 Web help screen...

Page 19: ...3 Making twisted pair connections STEP 2 If the device is a network card and the switch is in the wiring closet attach the other end of the cable segment to a modular wall outlet that is connected to...

Page 20: ...5500 blackbox com Page 20 Chapter 3 Operation of Web based Management STEP 3 Label the cables to simplify future troubleshooting See Cable Labeling and Connection Records Figure 3 4 Network Wiring Con...

Page 21: ...ze and Flash Size With this information you will know the software version used MAC address serial number how many ports are good and so on 4 1 1 Information The switch system information is provided...

Page 22: ...address of the management agent in this switch Subnet Mask Displays the IP subnet mask assigned to the device Gateway IP Address Displays the default gateway IP address assigned to the device Host MA...

Page 23: ...node e g telephone closet 3rd floor The allowed string length is 0 to 255 and the allowed content is the ASCII characters from 32 to 126 4 1 3 CPU Load This page displays the CPU load using an SVG gr...

Page 24: ...d in each item Web Interface To configure Time in the Web interface 1 Click Time Manual 2 Specify the Time parameter in manual parameters 3 Click Apply Figure 4 4 Time configuration screen Parameter d...

Page 25: ...the Daylight savings type selection You can select By Dates or Recurring two type for Daylight saving type From To configure date and time when Daylight savings starts the format is YYYYMM DD HH MM T...

Page 26: ...t In this function only the administrator can create modify or delete the username and password The administrator can modify other guest identities password without confirming the password but must mo...

Page 27: ...ccess to that group By default most groups privilege level 5 has read only access and privilege level 10 has read write access And the system maintenance software upload factory defaults and etc need...

Page 28: ...ter description Group Name The name identifying the privilege group In most cases a privilege level group consists of a single module e g LACP RSTP or QoS but a few of them contain more than one The f...

Page 29: ...s IP address is used to identify the device uniquely among all other devices connected to the extended network The current version of the Internet protocol is IPv4 which has 32 bit Internet Protocol a...

Page 30: ...erver in dotted decimal notation DNS Server Provide the IP address of the DNS Server in dotted decimal notation VLAN ID Provide the managed VLAN ID The allowed range is 1 to 4095 DNS Proxy When DNS pr...

Page 31: ...is switch IPv6 address is in 128 bit records represented as eight fields of up to four hexadecimal digits with a colon separating each field For example fe80 215 c5ff fe03 4dc7 The symbol is a special...

Page 32: ...f the syslog server does not exist Possible modes are Enabled Enable server mode operation Disabled Disable server mode operation Server Address 1 and 2 Indicates the IPv4 host address of syslog serve...

Page 33: ...try Upper right icon Refresh clear You can click this to refresh the system log or clear it manually Click on the arrow icons to go go to the next up page or entry 4 5 3 Detailed Log This section desc...

Page 34: ...rap Host IP Address Trap and all MIB counters will be ignored 4 6 1 System This section describes how to configure an SNMP System on the switch This function is used to configure SNMP settings com mun...

Page 35: ...ure 4 14 The SNMP Configuration menu 4 6 3 Communities The function is used to configure SNMPv3 communities The Community and UserName is unique To create a new community account check Add new communi...

Page 36: ...ndicates the SNMP access source address mask 4 6 4 Users This function is used to configure SNMPv3 user The Entry index key is UserName To create a new UserName account check Add new user button and e...

Page 37: ...gth is 8 to 32 For SHA authentication protocol the allowed string length is 8 to 40 The allowed content is ASCII characters from 33 to 126 Privacy Protocol Indicates the privacy protocol that this ent...

Page 38: ...hat this entry should belong to The allowed string length is 1 to 32 and the allowed content is ASCII characters from 33 to 126 4 6 6 Views The function is used to configure SNMPv3 view The Entry inde...

Page 39: ...btree The OID defining the root of the subtree to add to the named view The allowed OID length is 1 to 128 The allowed string content is a digital number or asterisk Apply Click the apply icon to appl...

Page 40: ...Authentication and privacy Read View Name The name of the MIB view defining the MIB objects for which this request may request the current values Th e allowed string length is 1 to 32 and the allowed...

Page 41: ...umber Default 162 Community Security Name The length of the Community Security Name string is restricted to 1 32 Security Level Indicates what kind of message will send to Security Level Possible mode...

Page 42: ...Password The length of MD5 Authentication Password is restricted to 8 32 The length of SHA Authentication Password is restricted to 8 40 Privacy Protocol You can set DES encryption for UserName Priva...

Page 43: ...s and monitor its content or status 5 1 1 Configuration This chapter describes how to view the current port configuration and how to configure ports to non default settings including Linkup Linkdown S...

Page 44: ...elected on a port it indicates the flow control capability that is advertised to the link partner When a fixed speed setting is selected that is what is used The Current Rx column indicates whether pa...

Page 45: ...an click this icon to refresh the Port link Status manually 5 1 2 Port Description The section describes how to configure the port s alias or any descriptions for the Port Identity Enter an alphanumer...

Page 46: ...uto refresh then you need to select Auto refresh 3 Click Refresh to refresh the port statistics or click Clear to clear all information Figure 5 3 The Port Statistics Overview screen Parameter descrip...

Page 47: ...for receive and transmit Web Interface To display the per Port Port detailed Statistics Overview in the web interface 1 Click Configuration Port then Detailed Port Statistics 2 Scroll the Port Index t...

Page 48: ...ved with CRC or alignment errors Rx Undersize The number of short 1 frames received with valid CRC Rx Oversize The number of long 2 frames received with valid CRC Rx Fragments The number of short 1 fr...

Page 49: ...refresh Select auto refresh to refresh the Queuing Counters automatically Upper right icon Refresh clear Click on these icons to refresh the Queuing Counters or clear them manually 5 1 6 SFP Informat...

Page 50: ...e 10 M 100 M 1 G and so on Vendor OUI Display the manufacturer s OUI code which is assigned by IEEE Vendor Name Display the company name of the module manufacturer Vendor P N Display the product name...

Page 51: ...This makes it very easy to determine what type of ACL policy you will be working with 5 2 1 Ports The section describes how to configure the ACL parameters ACE of each switch port These parameters wil...

Page 52: ...e System Log Disabled Frames received on the port are not logged The default value is Disabled NOTE The System Log memory size and logging rate are limited Shutdown Specify the port shut down operatio...

Page 53: ...vert to previously saved values 5 2 3 Access Control List The section describes how to configure Access Control List rule An Access Control List ACL is a sequential list of permit or deny conditions t...

Page 54: ...to specify the editing action i e edit delete or moving the relative position of entry in the list 3 To specific the parameter of the ACE 4 Click on Apply to save the setting 5 To cancel the setting c...

Page 55: ...rmission for the ACE operation Deny The frame that hits this ACE is dropped Rate Limiter Specify the rate limiter in number of base units The allowed range is 1 to 16 Disabled indicates that the rate...

Page 56: ...Priority Specify the tag priority for this ACE A frame that hits this ACE matches this tag priority The allowed number range is 0 to 7 Any means that no tag priority is specified tag priority is don...

Page 57: ...are address field THA settings 0 RARP frames where THA is not equal to the DMAC address 1 RARP frames where THA is equal to the DMAC address Any Any value is allowed don t care IP Ethernet Length Spec...

Page 58: ...match this entry Any Any value is allowed don t care IP Option Specify the options flag setting for this ACE No IPv4 frames where the options flag is set must not be able to match this entry Yes IPv4...

Page 59: ...pears TCP UDP Source No When Specific is selected for the TCP UDP source filter you can enter a specific TCP UDP source value The allowed range is 0 to 65535 A frame that hits this ACE matches this TC...

Page 60: ...t URG value for this ACE 0 TCP frames where the URG field is set must not be able to match this entry 1 TCP frames where the URG field is set must be able to match this entry Any Any value is allowed...

Page 61: ...Type frames NOTE An Ethernet Type based ACE will not get matched by IP and ARP frames ARP The ACE will match ARP RARP frames IPv4 The ACE will match all IPv4 frames IPv4 ICMP The ACE will match IPv4 f...

Page 62: ...the settings of Link Aggregation You can bundle more than one port with the same speed full duplex and the same MAC to be a single logical port thus the logical port aggregates the bandwidth of these...

Page 63: ...Address or uncheck to disable By default IP Address is enabled TCP UDP Port Number The TCP UDP port number can be used to calculate the destination port for the frame Check to enable the use of the TC...

Page 64: ...nfigurations and possibly change them as well An LACP trunk group with more than one ready member ports is a real trunked group An LACP trunk group with only one or less than one ready member ports is...

Page 65: ...ert to previously saved values System Status This section describes that when you complete to set LACP function on the switch then it provides a status overview for all LACP instances Web Interface To...

Page 66: ...switch then it provides a Port Status overview for all LACP instances Web Interface To display the LACP Port status in the web interface 1 Click Configuration LACP Port Status 2 If you want to auto r...

Page 67: ...n group IDs 1 and 2 are GLAGs while IDs 3 14 are LLAGs Partner System ID The partner s System ID MAC address Partner Port The partner s port number connected to this port Auto refresh Select auto refr...

Page 68: ...to refresh the information automatically Upper right icon Refresh Clear Click on these icons to refresh the LACP port statistics information or clear them manually 5 4 Spanning Tree The Spanning Tree...

Page 69: ...g Tree example Once a stable network topology has been established all bridges listen for Hello BPDUs Bridge Protocol Data Units transmitted from the Root Bridge If a bridge does not get a Hello BPDU...

Page 70: ...e must be FwdDelay 1 2 Maximum Hop Count This defines the initial value of remaining Hops for MSTI information generated at the boundary of an MSTI region It defines how many bridges a root bridge can...

Page 71: ...ust set VLANs mapped to the MSTI The VLANs must be separated with a comma and or space A VLAN can only be mapped to one MSTI An unused MSTI should just be left empty I e not having any VLANs mapped to...

Page 72: ...I should just be left empty I e not have any VLANs Buttons Apply Click to apply changes Reset Click to undo any changes made locally and revert to previously saved values 5 4 3 MSTI Priorities When yo...

Page 73: ...to previously saved values 5 4 4 CIST Ports When you implement an Spanning Tree protocol on the switch you need to configure the CIST Ports The section describes how to inspect the current STP CIST p...

Page 74: ...uto setting will set the path cost as appropriate by the physical link speed using the 802 1D recommended values Using the Specific setting a user defined value can be entered The path cost is used wh...

Page 75: ...a network administrator to prevent bridges external to a core region of the network from bridging causing address flushing in that region possibly because those bridges are not under the full control...

Page 76: ...802 1D recommended values Using the Specific setting a user defined value can be entered The path cost is used when establishing the active topology of the network Lower path cost ports are chosen as...

Page 77: ...ently selected root bridge Root Port The switch port currently assigned to the root port role Root Cost Root Path Cost For the Root Bridge it is zero For all other Bridges it is the sum of the Port Pa...

Page 78: ...time since the bridge port was last initialized Auto refresh Select auto refresh to refresh the information automatically Upper right icon Refresh Click on these icons to refresh the STP Port status i...

Page 79: ...ing the multicast packet forwarding function forwards the broadcast packets The switch supports IGMP Snooping This includes query report and leave which is a type of packet exchanged between an IP Mul...

Page 80: ...croll to set the Throttling parameter 5 Click Apply to save the setting 6 To cancel the setting click the Reset button The switch will revert to previously saved values Figure 5 25 IGMP Snooping Confi...

Page 81: ...o any changes made locally and revert to previously saved values 5 5 2 VLAN Configuration The section describes the VLAN configuration setting process integrated with the IGMP Snooping function Each s...

Page 82: ...ult unsolicited report interval is 1 second Buttons Apply Click to apply changes Reset Click to undo any changes made locally and revert to previously saved values Upper right icon Refresh Click the R...

Page 83: ...P Multicast Group that will be filtered Adding New Filtering Group Click Adding New Filtering Group to add a new entry to the Group Filtering table Specify the Port and Filtering Group of the new entr...

Page 84: ...ived The number of Received V3 Reports V2 Leaves Received The number of Received V2 Leaves Auto refresh Select auto refresh icon and the device will refresh the log automatically Upper right icon Refr...

Page 85: ...Status manually click on the other icons for next up page or entry 5 5 6 IPv4 SSM information Source Specific Multicast SSM is a datagram delivery model that best supports one to many applications als...

Page 86: ...tarting from that or the closest next IGMP SFM Information Table match In addition the two input fields will when you click the Refresh button assume the value of the first displayed entry allowing fo...

Page 87: ...ticast address to use NOTE This is a function of the application software not of MLD When MLD snooping is enabled on a VLAN the switch acts to minimize unnecessary multicast traffic If the switch rece...

Page 88: ...Snooping Basic Configuration screen Parameter description Snooping Enabled Enable the Global MLD Snooping Unregistered IPMCv6 Flooding enabled Enable unregistered IPMCv6 traffic flooding NOTE Disablin...

Page 89: ...AN the switch acts to minimize unnecessary multicast traffic If the switch receives multicast traffic destined for a given multicast address it forwards that traffic only to ports on the VLAN that hav...

Page 90: ...sion 1 Multicast Listener Done messages It is also the Maximum Response Delay used to calculate the Maximum Response Code inserted into Multicast Address and Source Specific Query messages The allowed...

Page 91: ...ll be filtered Buttons Apply Click to apply changes Reset Click to undo any changes made locally and revert to previously saved values Publication date July 2013 5 6 4 Status The section describes how...

Page 92: ...is ACTIVE or IDLE Queries Transmitted The number of Transmitted Queries Queries Received The number of Received Queries V1 Reports Received The number of Received V1 Reports V2 Reports Received The nu...

Page 93: ...rst 20 entries from the beginning of the MLD Group Table The Start from VLAN and group input fields allow the user to select the starting point in the MLD Group Table Clicking the button will update t...

Page 94: ...the filtering mode maintained per VLAN ID port number Group Address basis It can be either Include or Exclude Source Address IP Address of the source Currently system limits the total number of IP so...

Page 95: ...ues Figure 5 39 The MVR Configuration Parameter description MVR Mode Enable Disable the Global MVR VLAN ID Specify the Multicast VLAN ID Mode Enable MVR on the port Type Specify the MVR port type on t...

Page 96: ...he configuration of MVR Port Group Allow Table Figure 5 40 MVR Groups Information screen Parameter description Delete Check to delete the entry It will be deleted during the next apply Port The logica...

Page 97: ...Ports under this group Auto refresh Select the auto refresh icon and the device will refresh the information automatically Upper right icon Refresh Click on these icons to manually refresh the MVR Gro...

Page 98: ...adjacent devices and to learn about adjacent LLDP devices The Link Layer Discovery Protocol LLDP is a vendor neutral Link Layer protocol in the Internet Protocol Suite used by network devices for adve...

Page 99: ...valid period is set to Tx Hold multiplied by Tx Interval seconds Valid values are restricted to 2 10 times Tx Delay If some configuration is changed e g the IP address a new LLDP frame is transmitted...

Page 100: ...t address is shown in the LLDP neighbors table CDP TLV Port ID is mapped to the LLDP Port ID field CDP TLV Version and Platform is mapped to the LLDP System Description field Both the CDP and LLDP sup...

Page 101: ...on is the port description advertised by the neighbor unit System Capabilities System Capabilities describes the neighbor unit s capabilities The possible capabilities are 1 Other 2 Repeater 3 Bridge...

Page 102: ...ed power management of Power over Ethernet PoE end points Inventory management allowing network administrators to track their network devices and determine their characteristics manufacturer software...

Page 103: ...724 746 5500 blackbox com Page 103 Chapter 5 Configuration Figure 5 45 LLDP MED Configuration screen part 1...

Page 104: ...724 746 5500 blackbox com Page 104 Chapter 5 Configuration Figure 5 46 LLDP MED Configuration screen part 2...

Page 105: ...st Start mechanism is only intended to run on links between LLDP MED Network Connectivity Devices and Endpoint Devices and as such does not apply to links between LAN infrastructure elements including...

Page 106: ...450F Place type Place type Example Office Postal community name Postal community name Example Leonia P O Box Post office box P O BOX Example 12345 Additional code Additional code Example 1320300003 Em...

Page 107: ...nded use of the application types 1 Voice for use by dedicated IP Telephony handsets and other similar appliances supporting interactive voice services These devices are typically deployed on a separa...

Page 108: ...riority is the Layer 2 priority to be used for the specified application type L2 Priority may specify one of eight priority levels 0 through 7 as defined by IEEE 802 1D 2004 A value of 0 represents us...

Page 109: ...twork edge and participate in IP communication service using the LLDP MED framework Within the LLDP MED Endpoint Device category the LLDP MED scheme is broken into further Endpoint Device Classes as d...

Page 110: ...he neighborhood unit s LLDP MED capabilities The possible capabilities are 1 LLDP MED capabilities 2 Network Policy 3 Location Identification 4 Extended Power via MDI PSE 5 Extended Power via MDI PD 6...

Page 111: ...4 is used to define a valid VLAN ID A value of 0 Priority Tagged is used if the device is using priority tagged frames as defined by IEEE 802 1Q 2003 meaning that only the IEEE 802 1D priority level i...

Page 112: ...ries added since switch reboot Total Neighbors Entries Deleted Shows the number of new entries deleted since switch reboot Total Neighbors Entries Dropped Shows the number of LLDP frames dropped due t...

Page 113: ...contains information about how long time the LLDP information is valid age out time If no new LLDP frame is received within the age out time the LLDP information is removed and the Age Out counter is...

Page 114: ...d by Power over Ethernet PoE To determine the amount of power the Powered Device PD may use the amount of power the power sources can deliver must be defined Retry Time The period in seconds that the...

Page 115: ...port number Maximum Power The Maximum Power value contains a numerical value that indicates the maximum power in watts that can be delivered to a remote device NOTE If you want to set the port to sup...

Page 116: ...er the PD currently is using Current Used The Power Used shows how much current the PD currently is using Priority The Priority shows the port s priority configured by the user Port Status The Port St...

Page 117: ...delay time Button Apply Click Apply to apply the change 5 9 4 Auto Checking This page allows the user to specify the auto detection parameters to check the linking status between PoE ports and PDs Whe...

Page 118: ...e system should ping Interval Time sec Device will send checking message to PD each interval time Retry Time When a PoE port can t ping the PD it will retry to send detection again The third time it w...

Page 119: ...in the web interface 1 Click Configuration PoE and Scheduling 2 Select the local port and enable 3 Select time and day to supply power 4 Click Apply to apply the change Figure 5 53 POE Scheduling scre...

Page 120: ...a MAC address SMAC address which shows the MAC address of the equipment sending the frame The SMAC address is used by the switch to automatically update the MAC table with these dynamic MAC addresses...

Page 121: ...changed by the user An example of such a module is the MAC Based Authentication under 802 1X Each port can do learning based upon the following settings Auto Learning is done automatically as soon as...

Page 122: ...MAC table Specify the VLAN ID MAC address and port members for the new entry Click Apply Buttons Apply Click to apply changes Reset Click to undo any changes made locally and revert to previously sav...

Page 123: ...address for IPv6 global IP FF FF FF FF FF FF for Broadcast 5 11 VLAN The management VLAN is used to establish an IP connection to the switch from a workstation connected to a port in the VLAN This co...

Page 124: ...the box To remove or exclude the port from the VLAN make sure the box is unchecked By default no ports are members and all boxes are unchecked Adding a New VLAN Click to add a new VLAN ID An empty ro...

Page 125: ...ring rules that can be applied to the switch The Ingress Filtering Rule 1 is forward only packets with VID matching this port s configured VID The Ingress Filtering Rule 2 is drop untagged frame You c...

Page 126: ...ort only accepts tagged frames untagged frames received on the port are discarded By default the field is set to All Egress Rule Configures the Port Egress Rule The allowed values are Hybric Trunk or...

Page 127: ...hannels is sent only on a single multicast VLAN MSTP The 802 1s Multiple Spanning Tree protocol MSTP uses VLANs to create multiple spanning trees in a network which significantly improves network reso...

Page 128: ...GVRP Combined 3 Display Port Status information Figure 5 59 The VLAN Port Status for Static user Parameter description Port The logical port for the settings contained in the same row PVID Shows the...

Page 129: ...ormation automatically Upper right icon Refresh Click to refresh the VLAN Port Status information manually 5 11 5 Private VLANs In a private VLAN communication between ports in that private VLAN is no...

Page 130: ...Port Isolation Port Isolation provides for an apparatus and method to isolate ports on layer 2 switches on the same VLAN to restrict traffic flow The apparatus comprises a switch with multiple ports...

Page 131: ...ort A this time but through Port B the next time If Port A and Port B belong to different VLANs the device will be assigned to a different VLAN the next time it accesses the network As a result it wil...

Page 132: ...be configured as needed Any unicast MAC address can be configured for the MAC based VLAN entry No broadcast or multicast MAC addresses are allowed Legal values for a VLAN ID are 1 through 4095 The MA...

Page 133: ...protocols IP IPX Decnet and Appletalk to coexist within a multipoint network and to be transported over the same network media and can also provide flow control and automatic repeat request ARQ error...

Page 134: ...ue that can be entered in this text field depends on the option selected from the the preceding Frame Type selection menu Below is the criteria for three different Frame Types 1 For Ethernet Values in...

Page 135: ...d integers 0 9 NOTE Special characters and underscore _ are not allowed Adding a New Group to a VLAN mapping entry Click to add a new entry in mapping table An empty row is added to the table Frame Ty...

Page 136: ...needed Legal values for a VLAN ID are 1 through 4095 The button can be used to undo the addition of new entry Buttons Apply Click to save changes Reset Click to undo any changes made locally and rever...

Page 137: ...ice VLAN mode operation VLAN ID Indicates the Voice VLAN ID It should be a unique VLAN ID in the system and cannot equal each port PVID It is a conflict in configuration if the value equals management...

Page 138: ...abled Enable Voice VLAN security mode operation Disabled Disable Voice VLAN security mode operation Port Discovery Protocol Indicates the Voice VLAN port discovery protocol It will only work when auto...

Page 139: ...The Generic Attribute Registration Protocol GARP provides a generic framework in which devices in a bridged LAN e g end stations and switches can register and de register attribute values such as VLA...

Page 140: ...en Parameter description Port The Port column shows the list of ports for which you can configure GARP settings There are two types of configuration settings that can be configured on per port bases T...

Page 141: ...chine will operate normally in GARP protocol exchanges non participant In this mode the Applicant state machine will not participate in the protocol operation The default configuration is normal parti...

Page 142: ...oup membership information of the VLANs The GVRP offers the function providing the VLAN registration service through a GARP application It makes use of GARP Information Declaration GID to maintain the...

Page 143: ...P globally select Enable from the menu and to disable GVRP globally select Disable Port The Port coulmn shows the list of ports for which you can configure per port GVRP settings There are three confi...

Page 144: ...ick on this icon to refresh the GVRP Global configuration information manually Buttons Apply Click to save changes Reset Click to undo any changes made locally and revert to previously saved values 5...

Page 145: ...r weighted fair queuing scheduling It supports QoS Control Lists QCL for advance programmable QoS classification based on IEEE 802 1p Ethertype VID IPv4 IPv6 DSCP and UDP TCP ports and ranges Cassific...

Page 146: ...ngs relate to the currently selected unit as reflected by the page header Web Interface To configure the QoS Port Classification parameters in the web interface 1 Click Configuration QoS Port Classifi...

Page 147: ...g Actual PCP is Pri column in Vlan tag packet DEI is cfi column PCP value from 0 7 it can be used for priority definition DEI value can be set to 0 or 1 map to DP value is 0 or 1 When ingress Qos clas...

Page 148: ...Unit Scroll to select what unit of rate includes kbps Mbps fps and kfps The default is kbps Flow Control Select enable or disable flow control on a port Buttons Apply Click to Apply changes Reset Cli...

Page 149: ...724 746 5500 blackbox com Page 149 Chapter 5 Configuration Figure 5 74 QoS Egress Port Schedules screen 1...

Page 150: ...ls the rate for the queue shaper The default value is kbps This value is restricted to 1 1000000 when the Unit is kbps and it is restricted to 1 10000 when the Unit is Mbps Queue Shaper Unit Controls...

Page 151: ...he default value is kbps Buttons Apply Click to apply changes Reset Click to undo any changes made locally and revert to previously saved values 5 15 4 Port Shaping This section provides an overview o...

Page 152: ...724 746 5500 blackbox com Page 152 Chapter 5 Configuration Figure 5 76 QoS Egress Port Shapers screen 1...

Page 153: ...rt Queue Shaper Rate Controls the rate for the queue shaper The default value is kbps This value is restricted to 1 1000000 when the Unit is kbps and it is restricted to 1 10000 when the Unit is Mbps...

Page 154: ...ally and revert to previously saved values 5 15 5 Port Tag Remarking The section provides user to get an overview of QoS Egress Port Tag Remarking for all switch ports Others the ports belong to the c...

Page 155: ...values Cancel Click to cancel the changes 5 15 6 Port DSCP The section will explain how to set the QoS Port DSCP configuration to configure the basic QoS Port DSCP Configuration settings for all switc...

Page 156: ...n and classification settings for individual ports There are two configuration parameters available in Ingress 1 Translate To Enable the Ingress Translation click the checkbox 2 Classify Classificatio...

Page 157: ...rt to previously saved values 5 15 7 DSCP Based QoS The section explains how to configure the basic QoS DSCP based QoS Ingress Classification settings for all switches Web Interface To configure the D...

Page 158: ...724 746 5500 blackbox com Page 158 Chapter 5 Configuration Figure 5 80 DSCP Based QoS Ingress Classification Configuration screen...

Page 159: ...to previously saved values 5 15 8 DSCP Translation The section describes how o configure the basic QoS DSCP Translation settings for all switches DSCP translation can be done in Ingress or Egress Web...

Page 160: ...724 746 5500 blackbox com Page 160 Chapter 5 Configuration Figure 5 81 DSCP Translation Configuration screen...

Page 161: ...1 Select the DSCP value from select menu to which you want to remap DSCP value ranges from 0 to 63 There are also these configurable parameters for Egress side Remap Select the DSCP value from select...

Page 162: ...anges made locally and revert to previously saved values 5 15 10 QoS Control List Configuration The section shows the QoS Control List QCL which is made up of the QCEs Each row describes a QCE that is...

Page 163: ...ll match all frame type Ethernet Only Ethernet frames with Ether Type 0x600 0xFFFF are allowed LLC Only LLC frames are allowed SNAP Only SNAP frames are allowed IPv4 The QCE will match only IPV4 frame...

Page 164: ...ication Buttons You can modify each QCE QoS Control Entry in the table using the following buttons button Inserts a new QCE before the current row e button Edits the QCE Up arrow button Moves the QCE...

Page 165: ...CS7 EF or AF11 AF43 IP Fragment IPv4 frame fragmented option yes no any Sport Source TCP UDP port 0 65535 or Any specific or port range applicable for IP protocol UDP TCP Dport Destination TCP UDP po...

Page 166: ...nly IPV6 frames Port Indicates the list of ports configured with the QCE Action Indicates the classification action taken on ingress frame if parameters configured are matched with the frame s content...

Page 167: ...AC Address table The configuration indicates the permitted packet rate for unicast multicast or broadcast traffic across the switch Web Interface To configure the Storm Control Configuration parameter...

Page 168: ...values 5 15 13 WRED The section allows user to configure the WRED function for the switch This page allows you to configure the Random Early Detection RED settings for queue 0 to 5 RED cannot be appli...

Page 169: ...unction with associated parameters Figure 5 87 RED Drop Probability Function NOTE Max DP 1 3 is the drop probability when the average queue filling level is 100 Frames marked with Drop Precedence Leve...

Page 170: ...w Agent our switch By default the IP is set to 0 0 0 0 and a new entry has to be added to it Port A port to listen to the sFlow Agent has to be configured for the Collector The value of the port numbe...

Page 171: ...e a 100 accurate result but it does provide a result with quantifiable accuracy Web Interface To configure the sFlow Agent in the web interface 1 Click Configuration sFlow Agent sampler 2 Click to edi...

Page 172: ...t to previously saved values Cancel Click to cancel to clear up what your setting Auto refresh Select the auto refresh icon and the device will refresh the information automatically Upper right icon R...

Page 173: ...Transmission Time The interval between each loop protection PDU sent on each port Valid values are 1 to 10 seconds Shutdown Time The period in seconds for which a port will be kept disabled if a loop...

Page 174: ...otection PDU s or whether it is just passively looking for looped PDU s Buttons Apply Click to apply changes Reset Click to undo any changes made locally and revert to previously saved values 5 17 2 S...

Page 175: ...up to 32 switches and is not limited to specific models distance barriers specialized cables and stacking methods 5 18 1 Configuration Each single IP group consists of one master switch and up to 32...

Page 176: ...Parameter description Index The ID of the active slave switch Model Name Displays the model name of the slave switch MAC Address Displays the Ethernet MAC address of the slave switch Buttons Refresh U...

Page 177: ...Type the port number into the text box Traffic Class Scroll to select the traffic class for the data stream priority The available value ranges from 0 Low to 7 High To set the voice to high priority...

Page 178: ...the traffic on the network For example we assume that Port A and Port B are Monitoring Port and Monitored Port respectively thus the traffic received by Port B will be copied to Port A for monitoring...

Page 179: ...this port Disabled disables mirroring Mirror Port Configuration The following table is used to enable Rx and Tx Port The logical port for the settings contained in the same row Mode Select mirror mod...

Page 180: ...ny changes made locally and revert to previously saved values 5 21 Trap Event Severity This function is used to set an Alarm trap and get the Event log The Trap Events Configuration function is used t...

Page 181: ...screen Parameter description Group Name This field describes the Trap Event Severity Level To scroll to select the event type with Emerg Alert Crit Error Warming Notice Info and Debug Buttons Apply C...

Page 182: ...he setting then you need to click the Reset button It will revert to previously saved values Figure 5 97 SMTP Configuration screen Parameter description These parameters are displayed on the SMTP Conf...

Page 183: ...mode operation Disabled Disable UPnP mode operation When the mode is enabled two ACEs are added automatically to trap UPNP related packets to CPU The ACEs are automatically removed when the mode is d...

Page 184: ...ld use the IP Source Guard config ure to enable or disable with the Port of the switch 6 1 1 Configuration This section describes how to configure IP Source Guard setting including Mode Enabled and Di...

Page 185: ...iguration Mode Specify IP Source Guard as enabled on ports Only when both Global Mode and Port Mode on a given port are enabled IP Source Guard will be enabled on this given port Max Dynamic Clients S...

Page 186: ...VLAN ID IP Address and MAC address in the entry 3 Click Apply Figure 6 2 Static IP Source Guard Table Parameter description Delete Check to delete the entry It will be deleted during the next save Por...

Page 187: ...of the entry MAC Address Source MAC address Auto refresh Select the auto refresh icon and the device will refresh the information automatically Upper right icon Refresh Click the refresh icon to refre...

Page 188: ...tion Mode Enable or disable Global ARP Inspection Port Mode Configuration Enable ARP Inspection on specific ports Only when both Global Mode and Port Mode on a given port are enabled ARP Inspection is...

Page 189: ...3 Click Apply Figure 6 5 Static ARP Inspection Table Parameter description Delete Check to delete the entry It will be deleted during the next save Port The logical port for the settings VLAN ID The...

Page 190: ...ress User MAC address of the entry IP Address User IP address of the entry Auto refresh Select the auto refresh icon and the device will refresh the information automatically Upper right icon Refresh...

Page 191: ...mode operation When DHCP snooping mode operation is enabled the DHCP request messages will be forwarded to trusted ports and only allow reply packets from trusted ports Disabled Disable DHCP snooping...

Page 192: ...mitted Rx and Tx Decline The number of decline option 53 with value 4 packets received and transmitted Rx and Tx ACK The number of ACK option 53 with value 5 packets received and transmitted Rx and Tx...

Page 193: ...scription Relay Mode Indicates the DHCP relay mode operation Possible modes are Enabled Enable DHCP relay mode operation When DHCP relay mode operation is enabled the agent forwards and transfers DHCP...

Page 194: ...switch The statistics show both Server and Client packet counters when DHCP Relay mode is enabled Web Interface To configure a DHCP Snooping Statistics Configuration in the web interface 1 Check Auto...

Page 195: ...of the switch The NAS server can be used to connect users to a variety of resources including Internet access conference calls printing documents on shared printers or by simply logging on to the Inte...

Page 196: ...724 746 5500 blackbox com Page 196 Chapter 6 Security Figure 6 11 Network Access Server Configuration screen Figure 6 12 Port configuration screen...

Page 197: ...if no activity is seen within a given period of time This parameter controls exactly this period and can be set to a number between 10 and 1000000 seconds If reauthentication is enabled and the port...

Page 198: ...move to the Guest VLAN is disabled on all ports Guest VLAN ID This is the value that a port s Port VLAN ID is set to if a port is moved into the Guest VLAN You can only change it if the Guest VLAN op...

Page 199: ...t for instance through a hub to piggyback on the successfully authenticated client and get network access even though they really aren t authenticated To overcome this security breach use the Single 8...

Page 200: ...port the switch reacts to QoS Class information carried in the RADIUS Access Accept packet transmitted by the RADIUS server when a supplicant is successfully authenticated If present and valid traffic...

Page 201: ...AN configuration Guest VLAN Operation When a Guest VLAN enabled port s link comes up the switch starts transmitting EAPOL Request Identity frames If the number of transmissions of such frames exceeds...

Page 202: ...ed authentication reauthentication will be attempted immediately The button only has effect for successfully authenticated clients on the port and will not cause the clients to get temporarily unautho...

Page 203: ...A Cbased authentication Last ID The user name supplicant identity carried in the most recently received Response Identity EAPOL frame for EAPOL based authentication and the source MAC address from the...

Page 204: ...r to NAS Port State for a description of the individual states QoS Class The QoS class assigned by the RADIUS server The field is blank if no QoS class is assigned Port VLAN ID The VLAN ID that NAS ha...

Page 205: ...lable for MAC based Auth MAC Address For Multi 802 1X this column holds the MAC address of the attached supplicant For MACbased Auth this column holds the MAC address of the attached client Clicking t...

Page 206: ...2 Select Enabled in the Failback to Local Authorization 3 Select Enabled in the Account To configure a RADIUS Authentication Server Configuration of AAA in the web interface 1 Check Enabled 2 Specify...

Page 207: ...com Page 207 Chapter 6 Security Figure 6 16 TACACS Accounting Configuration screen Figure 6 17 RADIUS Configuration screen Figure 6 18 RADIUS Accounting Configuration screen Figure 6 19 TACACS Authent...

Page 208: ...ox IP Address Hostname The IP address or hostname of the RADIUS Authentication Server IP address is expressed in dotted decimal notation Port The UDP port to use on the RADIUS Authentication Server If...

Page 209: ...server This field takes one of the following values Disabled The server is disabled Not Ready The server is enabled but IP communication is not yet up and running Ready The server is enabled IP commu...

Page 210: ...n and Accounting servers The statistics map closely to those specified in RFC4668 RADIUS Authentication Client MIB Web Interface To configure a RADIUS Details Configuration in the web interface 1 Spec...

Page 211: ...ntrol in the web interface 1 Select Enabled in the Port Configuration Mode 2 Specify the maximum number of MAC addresses in the Limit of Port Configuration 3 Set Action Trap Shutdown Trap Shutdown 4 C...

Page 212: ...underlying port security features without enabling Limit Control on a given port Limit The maximum number of MAC addresses that can be secured on this port This number cannot exceed 1024 If the limit...

Page 213: ...Status This section shows the Port Security status Port Security is a module with no direct configuration Configuration comes indirectly from other modules the user modules When a user module has ena...

Page 214: ...er of columns which are Port The port number for which the status applies Click the port number to see the status for this particular port Users Each of the user modules has a column that shows whethe...

Page 215: ...t Security Switch Status information manually 6 7 3 Port Status This section shows the MAC addresses secured by the Port Security module Port Security is a module with no direct configuration Configur...

Page 216: ...fresh the information automatically Upper right icon Refresh Click to refresh the Port Security Port Status information manually 6 8 Access Management This section shows you to configure access manage...

Page 217: ...ss the switch from TELNET SSH interface if the host IP address matches the IP address range provided in the entry Buttons Apply Click to apply changes Reset Click to undo any changes made locally and...

Page 218: ...SSH Configuration screen Parameter description Mode Indicates the SSH mode operation Possible modes are Enabled Enable SSH mode operation Disabled Disable SSH mode operation Buttons Apply Click to app...

Page 219: ...e 1 Specify the Client console telent ssh web that you want to monitor 2 Specify the Authentication Method none local radius tacacs 3 Check Fallback 4 Click Apply Figure 6 28 HTTPS Configuration scree...

Page 220: ...724 746 5500 blackbox com Page 220 Chapter 6 Security Buttons Apply Click to apply changes Reset Click to undo any changes made locally and revert to previously saved values...

Page 221: ...ice Configuration in the web interface 1 Chick Restart Device 2 Click Yes Figure 7 1 Restart Device screen Parameter description Restart Device You can restart the switch on this page After restart th...

Page 222: ...is updated and all managed switches restart The switch restarts WARNING While the firmware is being updated Web access appears to be defunct The front LED flashes Green Off with a frequency of 10 Hz w...

Page 223: ...e image is named image bk Version The version of the firmware image Date The date where the firmware was produced NOTE 1 If the active firmware image is the alternate image only the Active Image table...

Page 224: ...Interface To configure a Factory Defaults Configuration in the web interface 1 Click Factory Defaults 2 Click Yes Figure 7 4 Factory Defaults screen Parameter description Buttons Yes Click the Yes bu...

Page 225: ...ck Yes Figure 7 6 Save as Backup Configuration screen Parameter description Buttons Save Click the Save button to save the current setting as Backup Configuration 7 3 4 Restore User This section descr...

Page 226: ...This section describes how to export the Switch Configuration for maintenance needs Any current configuration files will be exported as XML format Web Interface To configure an Export Config Configura...

Page 227: ...he config file in your device 2 Click Upload Figure 7 9 Import Config screen Parameter description Browse Click the Browse button to search the Configuration URL and filename Upload Click the Upload b...

Page 228: ...nds to 30 seconds Start This page allows you to issue ICMP PING packets to troubleshoot IPv6 connectivity issues After you press start ICMP packets are transmitted and the sequence number and roundtri...

Page 229: ...ime 0ms 64 bytes from 10 10 132 20 icmp_seq 1 time 0ms 64 bytes from 10 10 132 20 icmp_seq 2 time 0ms 64 bytes from 10 10 132 20 icmp_seq 3 time 0ms 64 bytes from 10 10 132 20 icmp_seq 4 time 0ms Sent...

Page 230: ...7 Maintenance Figure 7 12 VeriPHY screen Parameter description Port The port for which you are requesting VeriPHY Cable Diagnostics Cable Status Port Port number Pair The status of the cable pair Len...

Page 231: ...number of ACEs is 64 ACL Ports The ACL Ports configuration is used to assign a Policy ID to an ingress port This is useful to group ports to obey the same traffic rules Traffic Policy is created unde...

Page 232: ...efore IP address pool management is done by the server and not by a human network administrator Dynamic addressing simplifies network administration because the software keeps track of IP addresses ra...

Page 233: ...the Ethernet networking standard It is used to indicate which protocol is being transported in an Ethernet frame FTP FTP is an acronym for File Transfer Protocol It is a transfer protocol that uses th...

Page 234: ...is a protocol for email clients to retrieve email messages from a mail server IMAP is the protocol that IMAP clients use to communicate with the servers and SMTP is the protocol used to transport mai...

Page 235: ...r if the administrator wants to do a fixed mapping between the DMAC address and switch ports The frames also contain a MAC address SMAC address which shows the MAC address of the equipment sending the...

Page 236: ...responding information is not included in the LLDP frame OUI OUI is the organizationally unique identifier An OUI address is a globally unique identifier assigned to a vendor by IEEE You can determine...

Page 237: ...nt QoS classes Low Normal Medium and High for individual application QCL QCL is an acronym for QoS Control List It is the list table of QCEs containing QoS control entries that classify to a specific...

Page 238: ...ogy changes within a stack as well as election of a master switch SPROUT also calculates parameters for setting up each switch to perform shortest path forwarding within the stack SSID Service Set Ide...

Page 239: ...sibilities and the singular code that results is compared against the corresponding bit in the IPv4 ToS priority control bit 0 63 TLV TLV is an acronym for Type Length Value A LLDP frame can contain m...

Page 240: ...in the previous system Wired Equivalent Privacy WEP WPA implements the majority of the IEEE 802 11i standard and was intended as an intermediate measure to take the place of WEP while 802 11i was prep...

Page 241: ...724 746 5500 blackbox com Page 241 NOTES...

Page 242: ...724 746 5500 blackbox com Page 242 NOTES...

Page 243: ...724 746 5500 blackbox com Page 243 NOTES...

Page 244: ...Tech support available in 60 seconds or less Copyright 2015 Black Box Corporation All rights reserved Black Box and the Double Diamond logo are registered trademarks of BB Technologies Inc Any third...

Reviews: