background image

 

108 

 

 

Chapter 4 

Web Configuration & Operation 

 

4.15.2 Ports Configuration 

 

 

 

Ethertype for Custom S-ports: 

Specify ether type used for customer s-ports. 

 

VLAN Port Configuration 

 

Port:

 The port number. “All” settings apply to all ports. 

 
Port  Type:

 There are four port  types available. Each port  type’s ingress and  egress action is described in the following 

table. 
 

                 Action  
Port Type 

Ingress Action 

Egress Action 

Unaware 

When a tagged frame is received on a port,  
1.

 

If  the  tagged  frame  with  TPID=0x8100,  it 
becomes  a  double-tag  frame  and  is 

forwarded. 

2.

 

If  the  TPID  of  tagged  frame  is  not  0x8100 
(ex. 0x88A8), it will be discarded. 

The  TPID  of  frame  transmitted  by 
Unaware port  will be  set  to 0x8100. 
The  final  status  of  the  frame  after 

egressing are also affected by egress 
rule. 

When an untagged frame is received on a port, 
a tag (PVID) is attached and then forwarded. 

C-port 

When a tagged frame is received on a port, 
1.

 

If  a  tagged  frame  with  TIPID=0x8100,  it  is 
forwarded. 

2.

 

If  the  TPID  of  tagged  frame  is  not  0x8100 
(ex. 0x88A8), it will be discarded. 

The TPID of frame transmitted by C-
port will be set to 0x8100. 

When an untagged frame is received on a port, 
a tag (PVID) is attached and then forwarded. 

S-port 

When a tagged frame is received on a port, 
1.

 

If  a  tagged  frame  with  TPID=0x88AA,  it  is 
forwarded. 

2.

 

If  the  TPID  of  tagged  frame  is  not  0x88A8 
(ex. 0x8810), it will be discarded. 

The TPID of frame transmitted by S-
port will be set to 0x88A8 

When an untagged frame is received on a port, 

a tag (PVID) is attached and then forwarded. 

S-custom port 

When a tagged frame is received on a port, 
1.

 

If  a  tagged  frame  with  TPID=0x88AA,  it  is 
forwarded. 

2.

 

If  the  TPID  of  tagged  frame  is  not  0x88A8 
(ex. 0x8810), it will be discarded. 

The TIPID of frame transmitted by S-
custom-port  will  be  set  to  an  self-
customized  value,  which  can  be  set 

by  the  user  using  the  column  of 
Ethertype for Custom S-ports. 

When an untagged frame is received on a port, 
a tag (PVID) is attached and then forwarded. 

 

Summary of Contents for GSW-3208M2

Page 1: ...1 GSW 3208M2 Managed Gigabit Ethernet Switch ...

Page 2: ...and can radiate radio frequency energy and if not installed and used in accordance with the instructions may cause harmful interference to radio communications However there is no guarantee that interference will not occur in a particular installation If this equipment does cause harmful interference to radio or television reception which can be determined by turning the equipment off and on the u...

Page 3: ...l Version 1 0 August 2015 This document is the current official release manual Please check CTC Union s website for any updated manual or contact us by E mail at sales ctcu com Please address any comments for improving this manual or to point out omissions or errors to marketing ctcu com Thank you 2015 CTC Union Technologies Co Ltd All Rights Reserved The contents of this document are subject to c...

Page 4: ...3 4 2 3 DNS Server 15 3 4 2 4 Display TCP IP Settings 15 3 4 3 Factory Default 16 3 4 4 Reboot Device 16 3 4 5 Admin Password 16 3 4 6 Logout 16 CHAPTER 4 WEB CONFIGURATION OPERATION 17 4 1 HOME PAGE 17 4 1 1 Login 17 4 1 2 Port Status 17 4 1 3 Refresh 18 4 1 4 Help System 18 4 1 5 Logout 18 4 2 SYSTEM 18 4 2 1 System Configuration 19 4 2 2 System Information 19 4 2 3 System IP 19 4 2 4 System IPv...

Page 5: ...ation 45 4 6 1 8 2 RMON History Configuration 45 4 6 1 8 3 RMON Alarm Configuration 46 4 6 1 8 4 RMON Event Configuration 47 4 6 1 8 5 RMON Statistics Overview 47 4 6 1 8 6 RMON History Overview 48 4 6 1 8 7 RMON Alarm Overview 49 4 6 1 8 8 RMON Event Overview 49 4 6 2 Network 50 4 6 2 1 Port Security 50 4 6 2 1 1 Limit Control 50 4 6 2 1 2 Switch Status 52 4 6 2 1 3 Port Status 53 4 6 2 2 NAS 53 ...

Page 6: ... IGMP Snooping 89 4 11 1 1 Basic Configuration 90 4 11 1 2 VLAN Configuration 91 4 11 1 3 Port Group Filtering 92 4 11 1 4 Status 92 4 11 1 5 Groups Information 93 4 11 1 6 IPv4 SFM Information 93 4 11 2 MLD Snooping 94 4 11 2 1 Basic Configuration 94 4 11 2 2 VLAN Configuration 95 4 11 2 3 Port Group Filtering 96 4 11 2 4 Status 96 4 11 2 5 Groups Information 97 4 11 2 6 IPv6 SFM Information 97 4...

Page 7: ...ification 117 4 19 2 Port Policing 118 4 19 3 Port Scheduler 118 4 19 4 Port Shaping 120 4 19 5 Port Tag Remarking 120 4 19 6 Port DSCP 121 4 19 7 DSCP Based QoS 122 4 19 8 DSCP Translation 123 4 19 9 DSCP Classification 123 4 19 10 QoS Control List 124 4 19 11 Storm Control 127 4 20 MIRRORING 127 4 21 UPNP 128 4 22 DIAGNOSTICS 128 4 22 1 Ping 128 4 22 2 Ping6 129 4 22 3 VeriPHY 129 4 23 MAINTENAN...

Page 8: ... T twisted pair to the RJ 45 ports of the CPE switch No Ethernet crossover cables are required and link status can be easily monitored from the comprehensive LED display When GSW 3208M2 is deployed as a stand alone solution it incorporates an easy to use Web user interface for operation administration and maintenance both local and remotely All of the enabled Layer 2 features and functions of GSW ...

Page 9: ...LAN Groups up to 4096 Switching Fabric 20Gbps Data Processing Store and Forward Flow Control IEEE 802 3x for full duplex mode back pressure for half duplex mode MTU 9K Bytes Jumbo Frames MAC Table 8K Connectors LAN 8 x RJ 45 10 100 1000BaseT X auto detect speed auto negotiate duplex auto MDI MDI X function Full Half duplex Fiber 2 X 100 1000Base X dual speed mode SFP slot supporting DDMI Ethernet ...

Page 10: ... the front panel to provide real time indications of link status See below for detailed descriptions 2 1 Overview for Front Panel 1 2 3 4 3 2 5 6 8 4 8 7 5 Figure 1 Front Panel for GSW 3208M2 with AC Power Figure 2 Front Panel for GSW 3208M2 with DC Power 1 1 2 1 3 4 8 x RJ 45 LAN Ports 2 x SFP Cages Console Port Reset Push Button 5 6 7 8 LED Indicators AC Power Port DC Power Connection Earth Grou...

Page 11: ...tor are illustrated below 2 1 4 Reset Push Button There is a recessed push button switch used to reset GSW 3208M2 or to return it to factory defaults Pressing the reset momentarily once will warm boot the switch Pressing and holding the pushbutton switch for more than 3 seconds and then releasing will set the running configuration to the original factory default settings including the original fac...

Page 12: ...t panel of the unit Each port has a corresponding LED indicator that provides a visual and real time indication of the current operating state A description of these LED indicators is provided below LED Color Status Meaning PWR Green On The switch is receiving power Off The switch does not receive power or is in standby mode Fiber 1 Fiber 2 Orange On The fiber port link is up and operating at 1000...

Page 13: ...ocol SNMP The operator will use SNMP management software to manage and monitor the GSW 3208M2 switches on a network This requires some configuration of the device to allow SNMP management In addition the network management platform will need to import and compile the proprietary MIB management information base file so that the management software knows how to manage the GSW 3208M2 3 2 Console Oper...

Page 14: ...Ping Auto Provision Auto Provision configuration Port Port management MAC MAC address table VLAN Virtual LAN PVLAN Private VLAN Security Security management STP Spanning Tree Protocol Aggr Link Aggregation LACP Link Aggregation Control Protocol LLDP Link Layer Discovery Protocol LLDPMED Link Layer Discovery Protocol Media EEE Energy Efficient Ethernet Thermal Thermal Protection Led_power LED power...

Page 15: ...Note The dns_source parameter points to the static DNS server for the network 3 4 2 4 Display TCP IP Settings syntax IP Configuration ip setup 192 168 0 251 255 255 255 0 192 168 0 10 1 ip dns 192 168 0 1 ip configuration IP Configuration DHCP Client Disabled DHCP Option 60 GSW 3208M2 IP Address 192 168 0 1 IP Mask 255 255 255 0 IP Router 0 0 0 0 DNS Server 0 0 0 0 VLAN ID 1 DNS Proxy Disabled IPv...

Page 16: ...y Switch Users Add username password privilege_level Note Sets the password secret for the admin user Admin user has the highest privilege level of 15 To clear admin password use a pair of double quotes to enter a null password 3 4 6 Logout Syntax Logout Note After the logout command is issued the Username login prompt will again be displayed system restore default system reboot security switch ad...

Page 17: ... type of browser used The example below is with Firefox browser The GSW 3208M2 factory default is username admin with no password 4 1 2 Port Status The initial page when logged in displays a graphical overview of the port status for the electrical and optical ports The Green LAN port indicates a LAN connection with a speed of 10M or 100M The Orange colored LAN port indicates a connection speed of ...

Page 18: ...ge is accompanied by a specific help for that functional page The user can display this help pop up at any time by clicking the help icon 4 1 5 Logout After completing configuration we recommend logging out of the web GUI This is easily accomplished by clicking the logout icon After clicking the logout icon a confirmation screen will be displayed Click OK to finish logging out or click Cancel to r...

Page 19: ...en will display the configuration information the hardware MAC address and version the system time the system uptime and the software version and build date 4 2 3 System IP Setup the IP configuration interface and routes DHCP Client Enable the DHCP client by checking this box If DHCP fails and the configured IP address is zero DHCP will retry If DHCP server does not respond around 35 seconds and t...

Page 20: ...sed to show the active IPv6 configuration Auto Configuration Enable IPv6 auto configuration by checking this box If system cannot obtain the stateless address in time the configured IPv6 settings will be used The router may delay responding to a router solicitation for a few seconds the total time needed to complete auto configuration can be significantly longer Address Provides the IPv6 address o...

Page 21: ...abled this username is used as the ID when logging into HTTP or FTP server The allowed string length is 0 to 20 HTTP FTP Password If both Auto Provision Mode and HTTP FTP Login are enabled this password is used as the secret when logging into HTTP or FTP server The allowed string length is 0 to 20 4 2 6 System NTP Configuration Configure NTP Network Time Protocol on this page Mode Indicates the NT...

Page 22: ...tup Daylight Saving Time Configuration Daylight Saving Time This is used to set the clock forward or backward according to the configurations set below for a defined Daylight Saving Time duration Select Disable to disable the Daylight Saving Time configuration Select Recurring and configure the Daylight Saving Time duration to repeat the configuration every year Select Non Recurring and configure ...

Page 23: ...log server does not exist When the mode of operation is disabled no syslog packets are sent out Server Address This sets the IPv4 host address of syslog server If the switch provides DNS feature it also can be a host name Syslog Level This sets what kind of messages will send to syslog server Possible levels are Info Send information warnings and errors Warning Send warnings and errors Error Send ...

Page 24: ...nge If you want to turn off this function uncheck all ports 4 2 12 System CPU Load This page displays the CPU load using an SVG graph The load is measured as averaged over the last 100ms 1sec and 10 seconds intervals The last 120 samples are graphed and the last numbers are displayed as text as well In order to display the SVG graph your browser must support the SVG format Automatic refresh occurs...

Page 25: ...to power up the circuits is called wakeup time The default wakeup time is 17 us for 1Gbit links and 30 us for other link speeds EEE devices must agree upon the value of the wakeup time in order to make sure that both the receiving and transmitting device has all circuits powered up when traffic is transmitted The devices can exchange wakeup time information using the LLDP Link Layer Discovery Prot...

Page 26: ...reduced to the wakeup time Queues set will activate transmission of frames as soon as data is available Otherwise the queue will postpone transmission until a burst of frames can be transmitted 4 4 Thermal Protection This page allows the user to inspect and configure the current setting for controlling thermal protection Thermal protection is used to protect the chip from getting overheated When t...

Page 27: ... Temperature Display the current temperature on a certain port Port status Display the current port status 4 5 Ports Configurations related to the fiber and electrical ports are performed under the Ports menu 4 5 1 Ports Configuration This page displays current port configurations and allows some configuration here Port This device is managed Gigabit switches with 8 electrical LAN ports numbered 1...

Page 28: ...isables the switch port operation Auto nego Port auto negotiating speed with the link partner selecting the highest speed that is compatible with the link partner Detection There is no standardized way to do SFP auto detect so here it is done by reading the SFP rom Due to the missing standardized way of doing SFP auto detect some SFP s speed might not be detectable 100Mbps FDX Forces the fiber por...

Page 29: ...s Tx laser power turn OFF The allowed range is 10 to 50 in tenths of a second The default period is 30 in tenths of a second 3 second 4 5 3 Ports State Display an overview graphic of the switch This is the same graphic overview shown when first logging into the switch for management Green colored ports indicate a 10M or 100M linked state while Orange colored ports indicate a 1000M linked state Gre...

Page 30: ...ehensive overview of traffic on all ports Port The logical port 1 10 for the data contained in the same row Packets The number of received and transmitted packets per port Bytes The number of received and transmitted bytes per port Errors The number of frames received in error and the number of incomplete transmissions per port Drops The number of frames discarded due to ingress or egress congesti...

Page 31: ...e Indicates the type of frame to look for incoming frames Possible frame types are Any The QCE will match all frame type Ethernet Only Ethernet frames with Ether Type 0x600 0xFFFF are allowed LLC Only LLC frames are allowed SNAP Only SNAP frames are allowed IPv4 The QCE will match only IPV4 frames IPv6 The QCE will match only IPV6 frames Port Indicates the list of ports configured with the QCE Act...

Page 32: ...Tx Packets The number of received and transmitted good and bad packets Rx and Tx Octets The number of received and transmitted good and bad bytes Includes FCS but excludes framing bits Rx and Tx Unicast The number of received and transmitted good and bad unicast packets Rx and Tx Multicast The number of received and transmitted good and bad multicast packets Rx and Tx Broadcast The number of recei...

Page 33: ... length for this port Transmit Error Counters Tx Drops The number of frames dropped due to output buffer congestion Tx Late Exc Coll The number of frames dropped due to excessive or late collisions 4 6 Security Under the security heading are three major icons switch network and AAA Authentication and Accounting 4 6 1 Switch 4 6 1 1 Users This page provides an overview of the current users Currentl...

Page 34: ...values need to refer to each group privilege level User s privilege should be same or greater than the group privilege level to have the access of that group By default setting most groups privilege level 5 has the read only access and privilege level 10 has the read write access And the system maintenance software upload factory defaults and etc need user privilege level 15 Generally the privileg...

Page 35: ...rivilege Levels and everything in Maintenance Debug Only present in CLI Privilege Levels Every group has an authorization Privilege level for the following sub groups configuration read only configuration execute read write status statistics read only status statistics read write e g for clearing of statistics User Privilege should be the same or greater than the authorization Privilege level to h...

Page 36: ...nction is only available when Radius or Tacacs option is selected in authentication method field 4 6 1 4 SSH Configure SSH on this page Mode Indicates the SSH mode operation Possible modes are Enabled Enable SSH mode operation By default it is enabled Disabled Disable SSH mode operation Note SSH is preferred to Telnet unless the management network is trusted Telnet passes authentication credential...

Page 37: ...gth is 0 to 60 4 6 1 6 Access Management 4 6 1 6 1 Configuration Configure the access management table on this page The maximum number of entries is 16 If the application s type matches any one of the access management entries it will be allowed access to the switch Access Management Protocol Configuration Mode Indicates the access management mode operation Possible modes are Enabled Enable access...

Page 38: ...ment ports mode operation Disabled Disable access management ports mode operation Port The switch port number of the logical port Allowed Indicates that the host can access the switch from this port Click the Save button to save settings or changes Click the Reset button to restore changed settings to the default settings 4 6 1 6 2 Access Management Statistics This page provides statistics for acc...

Page 39: ... from 0x21 to 0x7E Write Community Indicates the community write access string to permit access to the SNMP agent The allowed string length is 0 to 255 and the allowed content is the ASCII characters from 0x21 to 0x7E These two fields are applicable only for SNMP version v1 or v2c If SNMP version is v3 the community string will be associated with SNMPv3 communities table SNMPv3 provides more flexi...

Page 40: ... The first character must be an alpha character and the first and last characters cannot be a dot or a dash Trap Destination IPv6 Address Indicates the SNMP trap destination IPv6 address IPv6 address is in 128 bit records represented as eight fields of up to four hexadecimal digits with a colon separating each field For example fe80 215 c5ff fe03 4dc7 The symbol is a special syntax that can be use...

Page 41: ...ame Indicates the SNMP trap security name SNMPv3 traps and informs use USM for authentication and privacy A unique security name is needed when traps and informs are enabled 4 6 1 7 2 SNMPv3 Community Configuration Configure SNMPv3 community table on this page The entry index key is Community Community Indicates the community access string to permit access to SNMPv3 agent The allowed string length...

Page 42: ...ntication protocol SHA An optional flag to indicate that this user uses SHA authentication protocol The value of security level cannot be modified if entry already exists That means it must first be ensured that the value is set correctly Authentication Password A string identifying the authentication password phrase For MD5 authentication protocol the allowed string length is 8 to 32 characters F...

Page 43: ...emove a saved entry during the next save Click the Save button to save settings or changes Click the Reset button to restore changed settings to the default settings 4 6 1 7 5 SNMPv3 View Configuration Configure SNMPv3 view table on this page The entry index keys are View Name and OID Subtree View Name A string identifying the view name that this entry should belong to The allowed string length is...

Page 44: ...cates the security model that this entry should belong to Possible security models are any Any security model accepted v1 v2c usm v1 Reserved for SNMPv1 v2c Reserved for SNMPv2c usm User based Security Model USM for SNMPv3 Security Level Indicates the security model that this entry should belong to Possible security models are NoAuth NoPriv No authentication and no privacy Auth NoPriv Authenticati...

Page 45: ...ettings 4 6 1 8 2 RMON History Configuration RMON History Configuration is to collect statistics on a physical interface to monitor network utilization packet types and errors A RMON historical record can also be used to monitor intermittent problems ID Indicates the index of the entry The range is from 1 to 65535 Data Source Indicates the port ID which wants to be monitored If in stacking switch ...

Page 46: ... than the rising threshold or less than the falling threshold Rising Trigger alarm when the first value is larger than the rising threshold Falling Trigger alarm when the first value is less than the falling threshold Rising Threshold If the current value is greater than the rising threshold and the last sample value is less than this threshold then an alarm will be triggered After a rising event ...

Page 47: ...ere The allowed characters are 0 127 Event Last Time The value of sysUpTime when an event was last generated for this entry Click the Add New Entry button to insert a new entry to the list Click the Delete button to remove a newly inserted entry or select the checkbox to remove a saved entry during the next save Click the Save button to save settings or changes Click the Reset button to restore ch...

Page 48: ...tory control entry Sample Index Displays Index of the data entry associated with the control entry Sample Start The time at which this sample started expressed in seconds since the switch booted up Drop The total number of dropped packets due to lack of resources Octets The total number of octets of data received Pkts The total number of packets including bad packets broadcast packets received Bro...

Page 49: ...old If the current value is greater than the rising threshold and the last sample value was less than this threshold then an alarm will be generated Rising Index The index of the event to use if an alarm is triggered by monitored variables crossing above the rising threshold Falling Threshold If the current value is less than the falling threshold and the last sample value was greater than this th...

Page 50: ...n immediately System Configuration Mode Enable or disable port security limit control globally If globally disabled other modules may still use the underlying functionality but limit checks and corresponding actions are disabled Aging Enabled If enabled secured MAC addresses are subject to aging as discussed under Aging Period With aging enabled a timer is started once the end host gets secured Wh...

Page 51: ...ill be learned Even if the link is physically disconnected and reconnected on the port by disconnecting the cable the port will remain shut down There are three ways to re open the port Boot the switch Disable and re enable Limit Control on the port or the switch Click the Reopen button Trap Shutdown If Limit 1 MAC addresses is seen on the port both the Trap and the Shutdown actions described abov...

Page 52: ...Ready The Port Security service is in use by at least one user module and is awaiting frames from unknown MAC addresses to arrive Limit Reached The Port Security service is enabled by at least the Limit Control user module and that module has indicated that the limit is reached and no more MAC addresses should be taken in Shutdown The Port Security service is enabled by at least the Limit Control ...

Page 53: ... and no frames have been seen the MAC address will be removed from the MAC table Otherwise a new age period will begin If aging is disabled or a user module has decided to hold the MAC address indefinitely a dash will be shown 4 6 2 2 NAS Network Access Server configuration is useful to the networking environment that wants to authenticate clients supplicants before they can access resources on th...

Page 54: ...conds Hold Time The time after an EAP Failure indication or RADIUS timeout that a client is not allowed access This setting applies to ports running Single 802 1X Multi 802 1X or MAC based authentication By default hold time is set to 10 seconds The allowed range is 10 1000000 seconds Radius Assigned QoS Enabled Select the checkbox to globally enable RADIUS assigned QoS Radius Assigned VLAN Enable...

Page 55: ...nts that are not dot1x aware will be denied access Single 802 1X In Single 802 1X at most one supplicant can get authenticated on the port at a time Normal EAPOL frames are used in the communication between the supplicant and the switch If more than one supplicant is connected to a port the one that comes first when the port s link comes up will be the first one considered If that supplicant doesn...

Page 56: ...iet period of the port runs out EAPOL based authentication For MAC based authentication reauthentication will be attempted immediately The button only has effect for successfully authenticated clients on the port and will not cause the clients to get temporarily unauthorized Reinitialize This forces the reinitialization of the clients on the port and thereby a reauthentication immediately The clie...

Page 57: ...EAPOL response frames other than Response Identity frames that have been received by the switch Requests The number of valid EAPOL request frames other than Request Identity frames that have been transmitted by the switch Start The number of EAPOL Start frames that have been received by the switch Logoff The number of valid EAPOL Logoff frames that have been received by the switch Invalid Type The...

Page 58: ...ing frames are redirected Mirror Enable or disable mirroring feature When enabled a copy of matched frames will be mirrored to the destination port specified in Mirror configuration page ACL based port mirroring set by this parameter and port mirroring set on the general Mirror Configuration page are implemented independently To use ACL based mirroring enable the Mirror parameter on the ACL Ports ...

Page 59: ...0 300 1000000 kbps Unit Select the unit of measure used in rate 4 6 2 3 3 Access Control List Click on the to insert a new ACE entry You can modify each ACE Access Control Entry in the table using the following buttons Inserts a new ACE before the current row Edits the ACE row Moves the ACE up the list Moves the ACE down the list Deletes the ACE The lowest plus sign adds a new entry at the bottom ...

Page 60: ...type either to permit or deny Rate Limiter Enable or disable the rate limiter when matched frames are found Mirror Enable or disable mirror function Logging Enable or disable logging when a frame is matched Shutdown Enable or disable shutdown a port when a frame is matched Counter Display the number of frames that have matched any of the rules defined for this ACL VLAN Parameters 802 1Q Tagged Sel...

Page 61: ...Type value ARP Parameter ARP RARP Specify the type of ARP packet Any No ARP RARP opcode flag is specified ARP The frame must have ARP RARP opcode set to ARP RARP The frame must have ARP RARP opcode set to RARP Other The frame has unknown ARP RARP opcode flag Request Reply Specify whether the packet is an ARP request reply or either type Any No ARP RARP opcode flag is specified Request The frame mu...

Page 62: ...ardware Address Space field is equal to Ethernet 1 Select Any to indicate a match and not a match IP Parameters IP Protocol Filter Select Any ICMP UDP TCP or Other protocol from the pull down menu for IP Protocol filtering IP TTL Select Zero to indicate that the TTL filed in IPv4 header is 0 If the value in TTL field is not 0 use Non Zero to indicate that You can also select any to denote the valu...

Page 63: ...l IPv4 TCP The ACE will match IPv4 frames with TCP protocol IPv4 Other The ACE will match IPv4 frames which are not ICMP UDP TCP Action Display the forwarding action of the ACE Permit Frames matching the ACE may be forwarded and learned Deny Frames matching the ACE may be forwarded and learned Filtered Frames matching the ACE are filtered Rate Limiter Indicates the rate limiter number of the ACE T...

Page 64: ...esses assigned to connected clients on insecure ports can be carefully controlled by either using the dynamic binding registered with DHCP Snooping or using the static binding configured with IP Source Guard 4 6 2 4 1 DHCP Snooping Configuration DHCP Snooping Configuration Snooping Mode Enable or disable DHCP Snooping function globally When DHCP snooping mode operation is enabled the DHCP request ...

Page 65: ...quest The number of request option 53 with value 3 packets received and transmitted Rx and Tx Decline The number of decline option 53 with value 4 packets received and transmitted Rx and Tx ACK The number of ACK option 53 with value 5 packets received and transmitted Rx and Tx NAK The number of NAK option 53 with value 6 packets received and transmitted Rx and Tx Release The number of release opti...

Page 66: ...eive Bad Circuit ID The number of packets whose Circuit ID option did not match known circuit ID Receive Bad Remote ID The number of packets whose Remote ID option did not match known Remote ID Client Statistics Transmit to Client The number of relayed packets from server to client Transmit Error The number of packets that resulted in error while being sent to servers Receive from Client The numbe...

Page 67: ... work both global mode and port mode must be enabled Max Dynamic Clients Select the maximum number of dynamic clients that can be learned on a port The available options are 0 1 2 unlimited If the port mode is enabled and the maximum number of dynamic clients is equal 0 the switch will only forward IP packets that are matched in static entries for a given port 4 6 2 5 2 Static Table Port Select a ...

Page 68: ...le shows entries sorted by port VLAN ID IP address and MAC address By default each page displays 20 entries However it can display 999 entries by entering the number in entries per page input field 4 6 2 6 ARP Inspection 4 6 2 6 1 Configuration ARP Inspection Configuration Mode Enable or disable ARP inspection function globally Port Mode Configuration Port The port number Port All rules apply to a...

Page 69: ...the Add New Entry button to insert a new entry to the list Click the Delete button to remove a newly inserted entry or select the checkbox to remove a saved entry during the next save Click the Save button to save settings or changes Click the Reset button to restore changed settings to the default settings 4 6 2 6 3 Dynamic Table Port The port number of this entry VLAN ID VLAN ID in which the ARP...

Page 70: ...utes RADIUS Authentication Server Configuration Enabled Select the checkbox to enable this authentication server configuration Hostname The hostname or IP address for the RADIUS authentication server Port The UDP port to be used on the RADIUS server for authentication Key Specify the secret key up to 63 characters This is shared between the RADIUS sever and the switch RADIUS Accounting Server Conf...

Page 71: ...Authentication Accounting Server Status Overview IP Address The configured IP address and UPD port number Status The current state of RADIUS authentication server Displayed states include the following Disabled This server is disabled Not Ready The server is ready but IP communication is not yet up and running Ready The server is ready and IP communication is not yet up and running The RADIUS serv...

Page 72: ...authentication port and dropped Packets Dropped The number of RADIUS packets that were received from the server on the authentication port and dropped for some other reason Access Requests The number of RADIUS Access Request packets sent to the server This does not include retransmissions Access Retransmissions The number of RADIUS Access Request packets retransmitted to the RADIUS authentication ...

Page 73: ...es that were received from the server on the accounting port Packets Dropped The number of RADIUS packets that were received from the server on the accounting port and dropped for some other reason Requests The number of RADIUS packets sent to the server This does not include retransmissions Retransmissions The number of RADIUS packets retransmitted to the RADIUS accounting server Pending Requests...

Page 74: ...egation that are available namely Static and LACP Under the Aggregation heading are two major icons static and LACP 4 7 1 Static Aggregation Mode Configuration Source MAC Address All traffic from the same Source MAC address is output on the same link in a trunk Destination MAC Address All traffic with the same Destination MAC address is output on the same link in a trunk IP Address All traffic wit...

Page 75: ...e the same LACP port Key In order to allow a port to join an aggregated group the port Key must be set to the same value Role The user can select either Active or Passive role depending on the device s capability of negotiating and sending LACP control packets Ports that are designated as Active are able to process and send LACP control frames Hence this allows LACP compliant devices to negotiate ...

Page 76: ...Ports The local ports that are a port of this LAG 4 7 2 3 Port Status Port The port number LACP Show LACP status on a port Yes LACP is enabled and the port link is up No LACP is not enabled or the port link is down Backup The port is in a backup role When other ports leave LAG group this port will join LAG Key The aggregation key value on a port Aggr ID Display the aggregation ID active on a port ...

Page 77: ...er connecting hardware problem or faulty protocol settings When loops are seen in a switched network they consume switch resources and thus downgrade switch performance Loop Protection feature is provided in this switch and can be enabled globally or on a per port basis Using loop protection enables the switch to automatically detect loops on a network Once loops are detected ports received the lo...

Page 78: ...propriate actions Actions will be taken include Shutdown Port Shutdown Port and Log or Log Only Shutdown Port A loop detected port is shutdown for a period of time configured in Shutdown Time Shutdown Port and Log A loop detected port is shutdown for a period of time configured in Shutdown Time and the event is logged Log Only The event is logged and the port remains enable Tx Mode Enable or disab...

Page 79: ...f connected layer 2 bridges typically Ethernet switches and disable the links which are not part of that tree leaving a single active path between any two network nodes To provide faster spanning tree convergence after a topology change an evolution of the Spanning Tree Protocol Rapid Spanning Tree Protocol RSTP is introduced by IEEE 802 1w RSTP is a refinement of STP therefore it shares most of i...

Page 80: ...nt is 1 to 10 Please note that increasing this value might have a significant impact on CPU utilization and decreasing this value might slow down convergence It is recommended to remain Transmit Hold Count to the default setting Advanced Settings Edge Port BPDU Filtering The purpose of Port BPDU Filtering is to prevent the switch from sending BPDU frames on ports that are connected to end devices ...

Page 81: ...r MSTI bridges must have the same configuration name and revision value Configuration Revision The revision number for this MSTI The allowed range is 0 65535 MSTI Mapping MSTI MSTI instance number VLAN Mapped Specify VLANs mapped to a certain MSTI Both a single VLAN and a range of VLANs are allowed Separate VLANs with a comma and use hyphen to denote a range of VLANs Example 2 5 20 40 Leave the fi...

Page 82: ...ecific if you want to use user defined value Valid values are 1 to 200000000 Please note that path cost takes precedence over port priority Priority Select port priority Admin Edge If an interface is attached to end nodes you can set it to Edge Auto Edge Select the checkbox to enable this feature When enabled a port is automatically determined to be at the edge of the network when it receives no B...

Page 83: ...dge Status STP Bridge MSTI The bridge instance Click this instance to view STP detailed bridge status Bridge ID The unique bridge ID for this instance consisting a priority value and MAC address of the bridge switch Root ID Display the root device s priority value and MAC address Root Port The number of the port on this switch that is closest to the root This switch communicates with the root devi...

Page 84: ... this port If there is no root port then this switch has been accepted as the root device of the Spanning Tree network Regional Root The Bridge ID of the currently elected regional root bridge inside the MSTP region of this bridge This parameter only applies to the CIST instance Internal Root Cost The Regional Root Path Cost For the Regional Root Bridge the cost is zero For all other CIST instance...

Page 85: ...figured Uptime The time since the bridge port was last initialized 4 9 7 Port Status Port The port number CIST Role The role assigned by Spanning Tree Algorithm Roles can be Designated Port Backup Port Root Port or Non STP CIST State Display the current state of a port The CIST state must be one of the following Discarding Ports only receive BPDU messages but do not forward them Learning Port has ...

Page 86: ...ovide data security by VLAN segregation that allows only multicast traffic into other VLANs to which the subscribers belong Even though common multicast streams are passed onto different VLAN groups from the MVR VLAN users in different IEEE 802 1Q or private VLANs cannot exchange any information except through upper level routing services The MVR menu contains the following sub menus 4 10 1 Config...

Page 87: ...le status Inactive I By default all ports are set to inactive Inactive ports do not participate in MVR operations Source S Set a port uplink ports to source port Source ports will receive and send multicast data Subscribers can not directly be connected to source ports Please also note that source ports cannot be management ports at the same time Receiver R Set a port to receiver port Client or su...

Page 88: ...lick the Save button to save settings or changes Click the Reset button to restore changed settings to the default settings 4 10 2 Statistics This page displays MVR statistics information on queries joins reports and leaves messages VLAN ID Display VLAN ID that is used for processing multicast traffic IGMP MLD Queries Received The number of received queries for IGMP and MLD IGMP MLD Queries Transm...

Page 89: ...ast group memberships It can be used more efficiently when supporting activities such as online streaming video and gaming IGMP Snooping is the process of listening to IGMP traffic IGMP snooping as implied by the name is a feature that allows the switch to listen in on the IGMP conversation between hosts and routers by processing the layer 3 packets that IGMP packets sent in a multicast network Wh...

Page 90: ...resses all unnecessary IGMP leave messages so that a non querier switch forwards an IGMP leave packet only when the last dynamic member port leaves a multicast group Proxy Enabled When enabled the switch performs like IGMP Snooping with Proxy Reporting as defined in DSL Forum TR 101 April 2006 Port Related Configuration Port The port number All rules apply to all ports Router Port Select the check...

Page 91: ...e RV allows tuning for the expected packet loss on a subnet If a subnet is susceptible to packet loss this value can be increased The RV value must not be zero and should not be one The value should be 2 or greater By default it is set to 2 QI sec The Query Interval is the interval between IGMP General Query messages sent by the Querier The default Querier Interval is 125 seconds QRI The Query Res...

Page 92: ...nsert a new entry to the list Click the Delete button to remove a newly inserted entry or select the checkbox to remove a saved entry during the next save Click the Save button to save settings or changes Click the Reset button to restore changed settings to the default settings 4 11 1 4 Status Statistics VLAN ID The VLAN ID of this entry Querier Version The current working Querier version Host Ve...

Page 93: ... address Port Members Ports that belong to this group 4 11 1 6 IPv4 SFM Information VLAN ID Display the VLAN ID of the group Groups Display the IP address of a multicast group Port The switch port number Mode The filtering mode maintained per VLAN ID port number and group address Source Address The source IP address available for filtering Type Display either Allow or Deny type Hardware Filter Swi...

Page 94: ...it picks out the group registration information and configures the multicast filters accordingly Unregistered IPMCv6 Flooding Enabled Set forwarding mode for unregistered not joined IP multicast traffic Select the checkbox to flood traffic MLD SSM Range SSM Source Specific Multicast Range allows the SSM aware hosts and routers run the SSM service model for the groups in the address range Leave Pro...

Page 95: ...t becomes querier it will be responsible for asking hosts periodically if they want to receive multicast traffic When disabled it will act as an IGMP non querier Compatibility This configures how hosts and routers take actions within a network depending on MLD version selected Available options are MLD Auto Forced MLDv1 and Forced MLDv2 By default MLD Auto is used RV The robustness variable RV all...

Page 96: ... filtering on a port When a certain multicast group is specified on a port MLD join reports received on a port will be dropped 4 11 2 4 Status Statistics VLAN ID The VLAN ID of this entry Querier Version The current working Querier version Host Version The current host version Querier Status Show the Querier status that is either ACTIVE or IDLE DISABLE denotes the specific interface is administrat...

Page 97: ...de The filtering mode maintained per VLAN ID port number and group address Source Address The source IP address available for filtering Type Display either Allow or Deny type Hardware Filter Switch Indicates whether the data plane destined to the specific group address from the source IPv4 address can be handled by the chip or not 4 12 LLDP LLDP Link Layer Discovery Protocol runs over data link la...

Page 98: ...range is 2 10 times The default is 4 Tx Delay Specify a delay between the LLDP frames that contain changed configurations Tx Delay cannot be larger than 1 4 of the Tx interval value The valid values are 1 8192 seconds Tx Reinit Specify a delay between the shutdown frame and a new LLDP initialization The valid values are 1 10 seconds LLDP Port Configuration Port The port number All settings apply t...

Page 99: ...ork policy to permitted voice capable devices both in order to conserve the limited LLDPU space and to reduce security and system integrity issues that can come with inappropriate knowledge of the network policy With this in mind LLDP MED defines an LLDP MED Fast Start interaction between the protocol and the application layers on top of the protocol in order to achieve these related properties Wi...

Page 100: ...um is Mean Lower Low Water MLLW This datum pair is to be used when referencing locations on water sea ocean Civic Address Location IETF Geopriv Civic Address based Location Configuration Information Civic Address LCI Country Code The two letter ISO 3166 country code in capital ASCII letters Example DK DE or US State National subdivisions state canton region province prefecture County County parish...

Page 101: ...n to remove a newly inserted entry or select the checkbox to remove a saved entry during the next save Click the Save button to save settings or changes Click the Reset button to restore changed settings to the default settings 4 12 3 Neighbours Local Port The local port that a remote LLDP capable device is attached Chassis ID An ID indicating the particular chassis in this system Remote Port ID A...

Page 102: ...s the local link partners reflection echo of the remote link partners respective values When a local link partner receives its echoed values from the remote link partner it can determine whether or not the remote link partner has received registered and processed its most recent values For example if the local link partner receives echoed parameters that do not match the values in its local MIB th...

Page 103: ...cal Counters Local Port The port number Tx Frames The number of LLDP PDUs transmitted Rx Frames The number of LLDP PDUs received Rx Errors The number of received LLDP frames with some kind of error Frames Discarded The number of frames discarded because they did not conform to the general validation rules as well as any specific usage rules defined for the particular Type Length Value TLV TLVs Dis...

Page 104: ...n Secure Only static MAC entries listed in Static MAC Table Configuration are learned Others will be dropped Note Make sure that the link used for managing the switch is added to the Static Mac Table before changing to secure learning mode otherwise the management link is lost and can only be restored by using another non secure port or by connecting to the switch via the serial interface Static M...

Page 105: ...s learned on CPU or certain ports Port Members Ports associated with this entry 4 14 VLAN Translation VLAN Translation is especially useful for users who want to translate the original VLAN ID to a new VLAN ID so as to exchange data across different VLANs and improve VLAN scaling VLAN translation replaces an incoming C VLAN tag with an S VLAN tag instead of adding an additional tag When configurin...

Page 106: ...ntry or select the checkbox to remove a saved entry during the next save Click the Save button to save settings or changes Click the Reset button to restore changed settings to the default settings 4 15 VLANs IEEE 802 1Q VLAN Virtual Local Area Network is a popular and cost effectively way to segment your networking deployment by logically grouping devices with similar attributes irrespective of t...

Page 107: ...mbership information shown on this page by using Start from VLAN ___ with ____ entries per page setting Up to 4096 VLANs are supported on this Switch By default all ports belong to default VLAN with VLAN ID 1 VLAN ID Specify the VLAN ID Valid values are 1 to 4095 VLAN Name Provide a description or a name for this VLAN This field can be left blank Both alphabets and numbers are allowed However if y...

Page 108: ... is received on a port 1 If a tagged frame with TIPID 0x8100 it is forwarded 2 If the TPID of tagged frame is not 0x8100 ex 0x88A8 it will be discarded The TPID of frame transmitted by C port will be set to 0x8100 When an untagged frame is received on a port a tag PVID is attached and then forwarded S port When a tagged frame is received on a port 1 If a tagged frame with TPID 0x88AA it is forward...

Page 109: ...e a member of the same VLAN as the Port VLAN ID Tx Tag Determines egress tagging of a port Untag_pvid All VLANs except the configured PVID will be tagged Tag_all All VLANs are tagged Untag_all All VLANs are untagged 4 15 3 Membership Status This page shows the current VLAN membership saved on the Switch VLAN ID VLANs that are already created Port members Display member ports on the configured VLAN...

Page 110: ...rce port mask and there are no connections to VLANs which means that VLAN IDs and Private VLAN IDs can be identical A port must be a member of both a VLAN and a Private VLAN to be able to forward packets By default all ports are VLAN unaware and members of VLAN 1 and Private VLAN 1 A VLAN unaware port can only be a member of one VLAN but it can be a member of multiple Private VLANs PVLAN ID Specif...

Page 111: ... up VLANs based on source MAC addresses When ingress untagged frames are received by a port source MAC address is processed to decide which VLAN these untagged frames belong When source MAC addresses does not match the rules created untagged frames are assigned to the receiving port s native VLAN ID PVID 4 17 1 1 Membership Configuration MAC Address Indicate the source MAC address Please note that...

Page 112: ...rder to encompass all the devices participating in a specific protocol This kind of configuration deprives users of the basic benefits of VLANs including security and easy accessibility To avoid these problems you can configure this switch with protocol based VLANs that divide the physical network into logical VLAN groups for each required protocol When a frame is received at a port its VLAN membe...

Page 113: ...n Service Access Point and SSAP Source Service Access Point values By default the value is 0xff Valid range is 0x00 to 0xff Group Name Indicate the descriptive name for this entry This field only allows 16 alphabet characters a z A Z or integers 0 9 Click the Add New Entry button to insert a new entry to the list Click the Delete button to remove a newly inserted entry or select the checkbox to re...

Page 114: ...ings or changes Click the Reset button to restore changed settings to the default settings 4 18 Voice VLAN Nowadays in the enterprise network VoIP devices are commonly deployed to save operational cost due to its easy to setup feature and convenience However while deploying VoIP devices it is recommended that VoIP traffic is separated from data traffic By isolating traffic VoIP traffic can be assi...

Page 115: ...fault the aging time is set to 86400 seconds The allowed aging time is 10 10 000 000 seconds Traffic Class Select the traffic class value which defines a service priority for traffic on the Voice VLAN The priority of any received VoIP packet is overwritten with the new traffic class when the Voice VLAN feature is active on a port By default 7 Highest priority is used The allowed range is 0 Lowest ...

Page 116: ...device MAC address MAC address OUI numbers must be configured in the Telephony OUI list so that the switch recognizes the traffic as being from a VoIP device LLDP Use LLDP IEEE 802 1ab to discover VoIP devices attached to a port LLDP checks that the telephone bit in the system capability TLV is turned on or not Both Use both OUI table and LLDP to detect VoIP traffic on a port 4 18 2 OUI Telephony ...

Page 117: ...itch go to Port Classification page The QoS menu contains the following sub menus 4 19 1 Port Classification Port The port number All rules will apply to all ports QoS class Indicate the default QoS class A QoS class of 0 has the lowest priority By Default 0 is used DP Level Select the default Drop Precedence Level PCP Select the appropriate value for the default Priority Code Point or User Priori...

Page 118: ...fault 500kbps is used The allowed range for kbps and fps is 100 to 1000000 The allowed range for Mbps and kfps is 1 to 3300Mbps Unit Select the unit of measure for the policer Flow Control If flow control is enabled and the port is in flow control mode then pause frames are sent instead of discarding frames 4 19 3 Port Scheduler Port Click the port to set up detailed settings for port scheduler Mo...

Page 119: ...the queue shaper By default 500kbps is used Allowed range for kbps is 100 to 1000000 Allowed range for Mbps is 1 to 3300Mbps Unit Select he unit of measure for the queue shaper Excess Select the checkbox to allow excess bandwidth Queue Schedule Queue Scheduler When Scheduler Mode is set to Weighted the user needs to indicate a relative weight for each queue DWRR uses a predefined relative weight f...

Page 120: ...ate Click the port number to modify or reset queue shaper and port shaper s rates See Port Scheduler for detailed explanation on each configuration option 4 19 5 Port Tag Remarking Click the port number that you want change settings Tag Remarking Mode Select the appropriate remarking mode used by this port Classified Use classified PCP DEI values Default Use default PCP DEI values Default PCP 0 De...

Page 121: ...ault 0 4 19 6 Port DSCP Port List the number of each All settings apply to all ports Ingress Translate Select the checkbox to enable ingress translation of DSCP values based on the selected classification method Ingress Classify Select the appropriate classification method Disable No ingress DSCP classification is performed DSCP 0 Classify if incoming DSCP is 0 Selected Classify only selected DSCP...

Page 122: ...he remapped DSCP value is always taken from the DSCP Translation table Egress Remap DP0 field 4 19 7 DSCP Based QoS DSCP DSCP value in ingress packet DSCP range is from 0 to 63 Trust Select the checkbox to indicate that DSCP value is trusted Only trusted DSCP values are mapped to a specific QoS class and drop precedence level DPL Frames with untrusted DSCP values are treated as non IP frames QoS C...

Page 123: ...fication method Ingress Classify Enable classification at ingress side as defined in the QoS port DSCP Configuration Table Egress Remap DP0 Remap DP0 value to the selected DSCP value DP0 indicates a drop precedence with a low priority Egress Remap DP1 Remap DP1 value to the selected DSCP value DP1 indicates a drop precedence with a high priority 4 19 9 DSCP Classification Map DSCP values to QoS cl...

Page 124: ... the port number that uses this QCL Frame Type Display the frame type to look for in incoming frames Possible frame types are Any Ethernet LLC SNAP IPv4 IPv6 SMAC Source MAC address DMAC Destination MAC address Possible values are Any Broadcast Multicast Unicast VID Display VLAN ID 1 4095 PCP Display PCP value DEI Display DEI value Action Display the classification action taken on ingress frames w...

Page 125: ...or OUI DMAC Type Select destination MAC address type By default any is used Other options available are UC for unicast MC for multicast and BC for broadcast Frame Type The frame types can be selected are listed below Any By default any is used which means that all types of frames are allowed Ethernet This option can only be used to filter Ethernet II formatted packets Options Any Specific 600 ffff...

Page 126: ...ormat x y z w where x y z and w are decimal numbers between 0 and 255 When the mask is converted to a 32 bit binary string and read from left to right all bits following the first zero must also be zero IP Fragment By default any is used Datagrams sometimes may be fragmented to ensure they can pass through a network device that uses a maximum transfer unit smaller than the original packet s size D...

Page 127: ...specified threshold will then be dropped Enable Enable Unicast storm Multicast storm or Broadcast storm protection Rate pps Select the packet threshold The packets received exceed the selected value will be dropped 4 20 Mirroring Port to mirror Select the mirror port to which either source rx or destination tx traffic will be mirrored Or disable port mirroring function Port The port number All rul...

Page 128: ... message from the switch By default the advertising duration is set to 100 seconds However due to the unreliable nature of UDP it is recommended to set to the shorter duration since the shorter the duration the fresher is UPnP status 4 22 Diagnostics The Diagnostics menu provides ping function to test the connectivity of a certain IP and VeriPHY cable diagnostics 4 22 1 Ping This Ping function is ...

Page 129: ...ostics page is used to perform cable diagnostics for all ports or selected ports to diagnose any cable faults short open etc and report the cable length Port Select All all ports or a port to perform cable diagnostics Start Click the Start button to begin the diagnostics Cable Status Port The port number Pair A B C D The status of cable pair OK Correctly terminated pair Open Open pair Short Shorte...

Page 130: ...HY is only accurate for cables of length 7 140 meters 3 10 and 100 Mbps ports will be linked down while running VeriPHY Therefore running VeriPHY on a 10 or 100 Mbps management port will cause the switch to stop responding until VeriPHY is complete 4 The EEE must be disabled at link partner 4 23 Maintenance The Maintenance menu contains several sub menus Select the appropriate sub menu to restart ...

Page 131: ...ating 4 23 3 2 Image Select Select the image file to be used in this device 4 23 4 Configuration 4 23 4 1 Save Save the current running configurations in XML format in your local device The user can also change setting using this file but only changed configurations will be taken effect in your device 4 23 4 2 Upload Upload a configuration file to restore the previously saved settings ...

Page 132: ...upporting both copper cu and fiber SFP cables AMS automatically determines if a SFP or a CU cable is inserted and switches to the corresponding media If both SFP and cu cables are inserted the port will select the preferred media APS APS is an acronym for Automatic Protection Switching This protocol is used to secure that switching is done bidirectional in the two ends of a protection group as def...

Page 133: ...eld in the Ethernet MAC header defined by the Ethernet networking standard It is used to indicate which protocol is being transported in an Ethernet frame FTP FTP is an acronym for File Transfer Protocol It is a transfer protocol that uses the Transmission Control Protocol TCP and provides file writing and reading It also provides directory service and security features Fast Leave Multicast snoopi...

Page 134: ...ows more efficient use of resources when supporting these uses IGMP Querier A router sends IGMP Query messages onto a particular link This router is called the Querier There will be only one IGMP Querier that wins Querier election on a particular link IMAP IMAP is an acronym for Internet Message Access Protocol It is a protocol for email clients to retrieve email messages from a mail server IMAP i...

Page 135: ...se MIB making it possible for the information to be accessed by a Network Management System NMS using a management protocol such as the Simple Network Management Protocol SNMP LLDP MED LLDP MED is an extension of IEEE 802 1ab and is defined by the telecommunication industry association TIA 1057 LLQI LLQI Last Listener Query Interval is the maximum response time used to calculate the Maximum Respon...

Page 136: ...ed it them Wikipedia NAS NAS is an acronym for Network Access Server The NAS is meant to act as a gateway to guard access to a protected source A client connects to the NAS and the NAS connects to another resource asking whether the client s supplied credentials are valid Based on the answer the NAS then allows or disallows access to the protected resource An example of a NAS implementation is IEE...

Page 137: ...ackets The PING Request is the packet from the origin computer and the PING Reply is the packet response from the target PoE PoE is an acronym for Power Over Ethernet Power over Ethernet is used to transmit electrical power to remote devices over standard Ethernet cable It could for example be used for powering IP telephones wireless LAN Access Points AP IP cameras and other equipment where it wou...

Page 138: ... this is the Quality Level of a given clock source This is received on a port in a SSM indicating the quality of the clock received in the port QoS QoS is an acronym for Quality of Service It is a method to guarantee a bandwidth relationship between individual applications or protocols A communications network transports a multitude of applications and data including high quality video and delay s...

Page 139: ...re sent as sFlow UDP datagrams to a central network traffic monitoring server This central server is called an sFlow receiver or sFlow collector Additional information can be found at http sflow org SHA SHA is an acronym for Secure Hash Algorithm It designed by the National Security Agency NSA and published by the NIST as a U S Federal Information Processing Standard Hash algorithms compute a fixe...

Page 140: ...he switch and is used widely in the web pages as well as in the CLI commands SyncE SyncE Is an abbreviation for Synchronous Ethernet This functionality is used to make a network clock frequency synchronized Not to be confused with real time clock synchronized IEEE 1588 TACACS TACACS is an acronym for Terminal Access Controller Access Control System Plus It is a networking protocol which provides a...

Page 141: ...algorithm TKIP comprises the same encryption engine and RC4 algorithm defined for WEP The key used for encryption in TKIP is 128 bits and changes the key used for each packet UDP UDP is an acronym for User Datagram Protocol It is a communications protocol that uses the Internet Protocol IP to exchange the messages between computers UDP is an alternative to the Transmission Control Protocol TCP tha...

Page 142: ...ired network Wikipedia WiFi WiFi is an acronym for Wireless Fidelity It is meant to be used generically when referring of any type of 802 11 network whether 802 11b 802 11a dual band etc The term is promulgated by the Wi Fi Alliance WPA WPA is an acronym for Wi Fi Protected Access It was created in response to several serious weaknesses researchers had found in the previous system Wired Equivalent...

Page 143: ...ed Random Early Detection It is an active queue management mechanism that provides preferential treatment of higher priority frames when traffic builds up within a queue A frame s DP level is used as input to WRED A higher DP level assigned to a frame results in a higher probability that the frame is dropped during times of congestion WTR WTR is an acronym for Wait To Restore This is the time a fa...

Page 144: ...This page is intentionally left blank Date Version Description 2015 8 26 0 9 Preliminary version ...

Page 145: ......

Reviews: