Draytek VigorSwitch P1085 User Manual Download Page 113

 

VigorSwitch P1085 User’s Guide 

105 

V

V

I

I

-

-

2

2

 

 

B

B

a

a

n

n

d

d

w

w

i

i

d

d

t

t

h

h

 

 

Use the bandwidth setting pages to define values that determine how much traffic the switch 
can receive and send on specific port or queue. 

V

V

I

I

-

-

2

2

-

-

1

1

 

 

I

I

n

n

g

g

r

r

e

e

s

s

s

s

 

 

R

R

a

a

t

t

e

e

 

 

L

L

i

i

m

m

i

i

t

t

 

 

This page allows a user to configure ingress port rate limit. The ingress rate limit is the 

number of bits per second that can be received from the ingress interface. Excess bandwidth 
above this limit is discarded. The configuration result for each port will be displayed on the 

table listed on the lower side of this web page. 

 

Available settings are explained as follows: 

Item Description 

Ingress Rate Limit 

Ports 

Use the drop down list to select the port profile (GE1 to GE8) 

or profiles. 

State 

 

Disable – Disable ingress bandwidth control. 

 

Enable - Enable ingress bandwidth control. 

Rate (Kbps) 

Enter the rate value,<16-1000000>,unit:16 Kbps. 

Apply 

Apply the settings to the switch. 

Modify 

- Click it to modify the settings for the selected port 

profile. 

 

Summary of Contents for VigorSwitch P1085

Page 1: ......

Page 2: ...VigorSwitch P1085 User s Guide ii VigorSwitch P1085 PoE Web Smart Gigabit Switch User s Guide Version 1 0 Firmware Version V2 5 1 For future update please visit DrayTek web site Date December 25 2019 ...

Page 3: ...lease keep your purchase receipt in a safe place as it serves as proof of date of purchase During the warranty period and upon proof of purchase should the product have indications of failure due to faulty workmanship and or materials we will at our discretion repair or replace the defective products or components without charge for either parts or labor to whatever extent we deem necessary tore s...

Page 4: ...essing Web Page of VigorSwitch 13 I 4 Dashboard 14 I 5 Status 15 I 5 1 Port Bandwidth Utilization 15 I 5 2 LLDP Statistics 15 Part II Switch LAN 17 II 1 General Setup 18 II 1 1 Management IP VLAN 18 II 2 Port Setting 20 II 2 1 General Setting 20 II 2 2 Protected Ports 22 II 3 Mirror 23 II 4 Link Aggregation 24 II 4 1 LAG Setting 24 II 4 2 LAG Management 25 II 4 3 LAG Port Setting 26 II 4 4 LACP Se...

Page 5: ...9 2 Port Setting 50 II 9 3 Bridge Setting 52 II 9 4 Port Advanced Setting 53 II 9 5 Statistics 54 II 10 MAC Address Table 55 II 10 1 Static MAC Setting 55 II 10 2 Dynamic Address Setting 56 II 10 3 Dynamic Learned 56 II 11 Blocked Port Recover 58 Part III ONVIF Surveillance 59 III 1 Topology 60 III 1 1 Status 60 III 2 2 Throughput Threshold 65 III 2 Video 67 III 3 Device Maintenance 68 III 3 1 Gen...

Page 6: ...ties 98 VI 1 1 1 QoS General Setting 98 VI 1 1 2 Trust Ports 99 VI 1 2 Port Settings 100 VI 1 3 Queue Settings 101 VI 1 4 CoS Mapping 102 VI 1 5 DSCP Mapping 103 VI 1 6 IP Precedence Mapping 104 VI 2 Bandwidth 105 VI 2 1 Ingress Rate Limit 105 VI 2 2 Egress Shaping Rate 106 VI 2 3 Egress Shaping Per Queue 107 Part VII PoE Configuration 109 VII 1 Properties 110 VII 2 Status 111 VII 3 Schedule 112 V...

Page 7: ...I 7 Time and Date 138 VIII 7 1 System Time Zone 138 VIII 7 2 Time 139 VIII 8 Backup Manager 140 VIII 9 Upgrade Manager 141 VIII 10 Account Manager 142 VIII 11 Factory Default 144 VIII 12 Reboot Switch 145 Part IX Diagnostics 147 IX 1 Device Check 148 IX 2 Cable Diagnostics 149 IX 3 Ping Test 150 IX 4 SysLog 151 IX 4 1 SysLog Explorer 151 IX 4 2 SysLog Settings 152 IX 4 2 1 SysLog Service 152 IX 4 ...

Page 8: ...figuration 243 XI 2 9 Hardware Monitor Configuration 244 XI 2 10 Ping Configuration 244 XI 2 11 Reboot Configuration 245 XI 2 12 Restore defaults Configuration 245 XI 2 13 Save Configuration 245 XI 2 14 Show Configuration 246 XI 2 15 SSL Configuration 247 XI 2 16 Terminal Configuration 247 XI 2 17 Traceroute Configuration 248 Appendix Reference 249 A 1 What s the Ethernet 249 A 2 Media Access Cont...

Page 9: ...VigorSwitch P1085 User s Guide 1 P Pa ar rt t I I I In nt tr ro od du uc ct ti io on n ...

Page 10: ...iciently save the switch power with auto detect the client idle and cable length to provide different power I I 1 1 1 1 K Ke ey y F Fe ea at tu ur re es s Below shows key features of this device Q Qo oS S The switch offers powerful QoS function This function supports 802 1p VLAN tag priority and DSCP on Layer 3 of network framework V VL LA AN N Support Port based VLAN and IEEE802 1Q Tag VLAN Suppo...

Page 11: ... button for resetting configuration to factory default by pressing over 5 seconds M Ma an na ag ge em me en nt t Supports per port traffic monitoring counters Supports a snapshot of the system Information when you login Supports port mirror function Supports the static trunk function Supports 802 1Q VLAN Supports user management and limits three users to login Maximal packet length can be up to 96...

Page 12: ...FP ports on the front panel of the switch LED display area locating on the front panel contains an ACT Power LED and ports working status of the switch L LE ED D E Ex xp pl la an na at ti io on n LED Color Explanation On Devices connected over the PoE maximum power budget Blinking More than 80 of maximum power budget is supplied for PoE device s PoE Alert for P1085 Off Devices connected within the...

Page 13: ...l be off if RST button is pressed between 5 seconds and 10 seconds Port 1 44 RJ45 Port 1 to Port 44 can be used for Ethernet connection and PoE connection depending on the device connected RJ 45 LNK ACT Port 1 8 PoE for Port 1 8 Port 1 to Port 8 can be used for Ethernet connection and PoE connection depending on the device connected Power inlet for AC input 100 240V AC 50 60Hz Note Power Output IE...

Page 14: ...the following applications C Ca as se e 1 1 A Al ll l s sw wi it tc ch h p po or rt ts s a ar re e i in n t th he e s sa am me e l lo oc ca al l a ar re ea a n ne et tw wo or rk k Every port can access each other The switch image is sample only If VLAN is enabled and configured each node in the network that can communicate each other directly is bounded in the same VLAN area C Ca as se e 2 2 T Th ...

Page 15: ... be standalone or mounted in a rack Rack mounting facilitate to an orderly installation when you are going to install series of networking devices Procedures to Rack mount the switch 1 Disconnect all the cables from the switch before continuing 2 Place the unit the right way up on a hard flat surface with the front facing you 3 Locate a mounting bracket over the mounting holes on one side of the u...

Page 16: ...ur ri in ng g t th he e M Ma an na ag ge em me en nt t A Ag ge en nt t o of f S Sw wi it tc ch h Users can monitor and configure the switch through the following procedures Configuring the Management Agent of VigorSwitch P1085 through the Ethernet Port There are several ways to configure and monitor the switch through Ethernet port includes Web UI and SNMP I I 2 2 4 4 M Ma an na ag gi in ng g V Vi...

Page 17: ... The former indicates the network where the addressed host resides and the latter indicates the individual host in the network which the address of host refers to And the host identifier must be unique in the same LAN Here the term of IP address we used is version 4 known as IPv4 Network identifier Host identifier 32 bits With the classful addressing it divides IP address into three classes class ...

Page 18: ...ow to split an IP address to the network prefix and the host address in bitwise basis It is designed to utilize IP address more efficiently and ease to manage IP network For a class B network 128 1 2 3 it may have a subnet mask 255 255 0 0 in default in which the first two bytes is with all 1s This means more than 60 thousands of nodes in flat IP address will be at the same network It s too large ...

Page 19: ...16384 16382 17 32768 32766 16 65536 65534 According to the scheme above a subnet mask 255 255 255 0 will partition a network with the class C It means there will have a maximum of 254 effective nodes existed in this sub netted network and is considered a physical network in an autonomous network So it owns a network IP address which may looks like 168 1 2 0 With the subnet mask a bigger network ca...

Page 20: ...host address to it First IP Address as shown above enter 192 168 1 224 for instance For sure an IP address such as 192 168 1 x must be set on your PC Second Subnet Mask as shown above enter 255 255 255 0 Choose a subnet mask suitable for your network Note The DHCP Setting is enabled in default Therefore if a DHCP server presented on network connected to the switch check before accessing your switc...

Page 21: ... h 1 Open any browser e g Firefox and type 192 168 1 224 as URL 2 Please type admin admin as the Username Password and click Login 3 Now the Main Screen will appear Info The DHCP Setting is enabled in default Therefore if a DHCP server presented on network connected to VigorSwitch checking before accessing VigorSwitch is essential ...

Page 22: ... User s Guide 14 I I 4 4 D Da as sh hb bo oa ar rd d Click Dashboard from the main menu on the left side of the main page A web page with default selections will be displayed on the screen Refer to the following figure ...

Page 23: ...s page offers the traffic statistics inlcuding data information and data of interframe gap for each port GE1 to GE8 In which data of interframe gap can be displayed or hidden by choose Enable Disable for IFG I I 5 5 2 2 L LL LD DP P S St ta at ti is st ti ic cs s This page offers the statistics of LLDP packets in out and error of each port GE1 to GE8 ...

Page 24: ...VigorSwitch P1085 User s Guide 16 This page is left blank ...

Page 25: ...VigorSwitch P1085 User s Guide 17 P Pa ar rt t I II I S Sw wi it tc ch h L LA AN N ...

Page 26: ... the default gateway device The gateway field specifies the IP address of the gateway next hop for outgoing traffic In additin this page allows the network administrator to change the VLAN ID of management access Management access protocols such as http https SNMP and etc are only accessible from the VLAN specified as management VLAN Info If VigorSwitch has connected to Vigor router it will use th...

Page 27: ...it to let switch automatically configure IPv6 address IPv6 Address It is available when Auto Configuration is set as Disable Enter the IPv6 address of your switch If auto configuration mode is disabled enter IPv6 address in this field Link Local Address Display link local address Gateway It is available when Auto Configuration is set as Disable Enter the IPv6 address of the router as your default ...

Page 28: ...ed with 100M ability only Auto 1000M Auto speed with 1000M ability only Auto 10 100M Auto speed with 10 100M ability 10M Force speed with 10M ability 100M Force speed with 100M ability 1000M Force speed with 1000M ability Selecting Auto auto negotiation allows one port to negotiate with a peer port automatically to obtain the connection speed and duplex mode that both ends support When auto negoti...

Page 29: ...te transmission of signals to match the bandwidth of the receiving port The switch uses IEEE802 3x flow control in full duplex mode and backpressure flow control in half duplex mode IEEE802 3x flow control is used in full duplex mode to send a pause signal to the sending port causing it to temporarily stop sending signals when the receiving port memory buffers fill Back Pressure flow control is ty...

Page 30: ...n Port List and Enable is clicked as Protected then users behind GE1 and GE3 are separated and can not communicate with each other Available settings are explained as follows Item Description Protected Ports Settings Port List Use the drop down list to select the port s GE1 to GE8 for applying the settings configured in this page Protected Click Enable to activate the protected port function Apply...

Page 31: ...n ID Select the session ID profile 1 to 4 of mirror operation you wish to configure Monitor Session State Enable Enable specified mirror session Disable Disable specified mirror session Destination Port Specify the port where you wish to observe the mirrored packets Allow Operation as Normal Port Enable The destination port is able to function as a port connecting to network communicating with oth...

Page 32: ...s to configure Load Balance Algorithm for Link Aggregation Available settings are explained as follows Item Description Load Balance Algorithm Select your Load balance algorithm MAC address Aggregated group will balance the traffic based on different MAC addresses Therefore the packets from different MAC addresses will be sent to different links IP Mac Address Aggregated group will balance the tra...

Page 33: ...y the type of the LAG Link Status Display LAG port link status Active Member Display active member ports of the LAG Standby Member Display inactive or candidate member ports of the LAG Modify It is used to edit the name type and port number for each link aggregation profile Name Enter a string as LAG name Type Use the drop down menu to specify the type for LAG Static The static aggregated port sen...

Page 34: ...0M ability only Auto 10 100M Auto speed with 10 100M ability 10M Force speed with 10M ability 100M Force speed with 100M ability 1000M Force speed with 1000M ability Selecting Auto auto negotiation allows one port to negotiate with a peer port automatically to obtain the connection speed and duplex mode that both ends support When auto negotiation is turned on a port on the switch negotiates with ...

Page 35: ...e IEEE802 3x flow control is used in full duplex mode to send a pause signal to the sending port causing it to temporarily stop sending signals when the receiving port memory buffers fill Back Pressure flow control is typically used in half duplex mode to send a collision signal to the sending port mimicking a state of packet collision causing the sending port to temporarily stop sending signals a...

Page 36: ...under LACP protocol Available settings are explained as follows Item Description Ports Use the drop down list to specify LAN Port Priority Enter a port priority number for the port Timeout The timeout option decides how local switch of LAG connection determines connection to be lost Switch would also notify the remote switch about this setting value so that remote switch can send LACP PDU in corre...

Page 37: ...ad of physically relocating devices or connections I II I 5 5 1 1 C Cr re ea at te e V VL LA AN N This page allows a user to add edit or delete VLAN settings Available settings are explained as follows Item Description Action Select which action to perform add VLANs or delete VLANs Add Create a new VLAN profile Delete Delete an existed VLAN profile VLAN ID Enter the number as VLAN ID to be created...

Page 38: ...II I 5 5 2 2 I In nt te er rf fa ac ce e S Se et tt ti in ng gs s This page allows a user to configure interface setting related to VLAN Available settings are explained as follows Item Description Port Select Select LAN ports to configure VLAN Settings Interface VLAN Mode Select the VLAN mode of the interface Hybrid Support all functions as defined in IEEE 802 1Q specification Access Accept only ...

Page 39: ...Hybrid mode All Accept frames regardless it s tagged with 802 1q or not Tag Only Accept frames only with 802 1q tagged Untag Only Accept frames untagged Ingress Filtering Enable the ingress filtering to filter out any packets not belong to any VLAN members of this port It is enabled automatically while operating in Access and Trunk mode Enabled Click it to enable the function Disabled Click it to ...

Page 40: ...bal and per interface setting of voice VLAN Available settings are explained as follows Item Description Voice VLAN State Enabled Click it to enable Voice VLAN Disabled Click it to disable Voice VLAN Voice VLAN Id Check the box of Enable first and then select Voice VLAN ID profile Remark CoS 802 1p Click Enabled Disabled to enable or disable 1p remarking If enabled qualified packets will be remark...

Page 41: ...ses Default has 8 pre defined OUI MAC Available settings are explained as follows Item Description OUI Address Type OUI address Description Enter a description of the specified MAC address to the voice VLAN OUI table Add Click it to create a new voice OUI based on the settings configured above Edit Modify OUI setting for voice VLAN Click it to remove the selected OUI entry ...

Page 42: ...S 802 1p is enabled in Voice VLAN Properties settings in this page shall be applied Otherwise this option will not take effect All Once this port is identified as Voice VLAN by frame with matched OUI remark CoS 802 1p shall tag for all ingress frame regardless of remarked frame matched with pre configured OUI or not Src Source Once this port is identified as Voice VLAN by frame with matched OUI re...

Page 43: ...s with specific MAC addresses for later binding with VLAN and Port Available settings are explained as follows Item Description Group ID It is a number for identification later while chosen to be bound with VLAN Port MAC Address Enter the MAC address you wish to be classified in this group Mask The mask is the length of matching prefix you wish to have on MAC address For example configure mask in ...

Page 44: ...s page allows the network administrator to bind the group of specified MAC addresses with VLAN and Port Available settings are explained as follows Item Description Ports Select the ports you wish to be bound with specified MAC address group Group ID Choose the group ID you have created in earlier section which specified a group of host by MAC address and its mask VLAN Enter the VLAN ID that you w...

Page 45: ...Available settings are explained as follows Item Description State Enabled Click it to enable the port settings for such VLAN Disabled Click it to disable the port settings for such VLAN VLAN ID Choose a VLAN profile created in Switch LAN VLAN Management Create Vlan as Surveillance VLAN CoS 802 1p Remarking Specify the CoS 802 1p number you wish ingress packets be tagged with so that QoS can prior...

Page 46: ...ved port into surveillance VLAN ID tagged member Manual User need add interface to VLAN ID tagged member manually QoS Policy Select port QoS Policy mode Video Packet QoS attributes are applied to packets with OUI in the source MAC address All QoS attributes are applied to packets that are classified to the Surveillance VLAN OK Apply the settings to the switch Cancel Abandon the changes and return ...

Page 47: ...e Available settings are explained as follows Item Description OUI Address Enter OUI MAC address of monitored IP camera It can t be edited in edit dialog Description Enter a description of the specified MAC address to the surveillance VLAN OUI table Add Click it to create a new voice OUI based on the settings configured above Edit Modify OUI setting for surveillance VLAN Click it to remove the sel...

Page 48: ...cient Ethernet function Available settings are explained as follows Item Description Port Select one or multiple ports to configure GE1 to GE8 Enable Enable Click it to enable the EEE function Disable Click it to disable the EEE function Apply Apply the settings to the switch Modify Click it to modify port setting status ...

Page 49: ... the multicast packets This page allows the network administrator to choose actions for processing the unknown muliticast packets and for handling known packets with MAC address IP address and VLAN ID Available settings are explained as follows Item Description Unknown Multicast Action Select an action for switch to handle with unknown multicast packet Drop Drop the unknown multicast data Flood Fl...

Page 50: ...e switch maintains a map of which links need which IP multicast streams Multicasts may be filtered from the links which do not need them and thus controls which ports receive specific multicast traffic I II I 7 7 2 2 1 1 I IG GM MP P S Se et tt ti in ng g This page allows the network administrator to enable disable IGMP function select snooping version and enable disable snooping report suppressio...

Page 51: ... used by IGMP Apply Apply the settings to the switch Modify Click it to modify IGMP settings for selected profile However if IGMP Snooping State is not set as Enable such option will be disabled IGMP Snooping State Choose Enable to enable IGMP snooping function Router Ports Auto Learn Set the enabling status of IGMP router port learning Choose Enable to learn router port by IGMP query Query Robust...

Page 52: ...ble to enable Fastleave function OK Apply the settings to the switch Cancel Close the page and return to previous page I II I 7 7 2 2 2 2 I IG GM MP P Q Qu ue er ri ie er r S Se et tt ti in ng g This page allows a user to configure querier settings on specific VLAN of IGMP Snooping Available settings are explained as follows Item Description VLAN ID Use the drop down list to specify a VLAN profile...

Page 53: ...e specified port VLAN member Available settings are explained as follows Item Description VLAN ID Use the drop down list to specify a VLAN profile as IGMP Static Group Group IP Address It is an identifier for the group member Packets sent to such address will be transferred to all interfaces defined in Member Ports Specify the IPv4 multicast address you wish to assign for the static group defined ...

Page 54: ...lable settings are explained as follows Item Description VLAN ID Display the VLAN of this multicast group belongs to Group IP Address Display the multicast address of this multicast group Member Ports Display the port s where subscribing member of this multicast group belongs to Type Display if it is dynamically learned or statically assigned Life sec Display the life time of this multicast member...

Page 55: ...his switch Available settings are explained as follows Item Description VLAN ID Use the drop down list to specify a VLAN profile created in Switch LAN VLAN Management Create Vlan that the MLD querier belongs to Port Display the static port member specified in Member Ports Expire Time sec Display the time before querier is considered no longer existed ...

Page 56: ...r ra am me e This page allows a user to configure switch port jumbo frame settings Available settings are explained as follows Item Description Jumbo Frame Bytes Enter Jumbo frame size The valid range is 1526 bytes 10000 bytes Apply Apply the settings to the switch ...

Page 57: ...ch only other layer 2 switches or bridges are listening If any loops multiple possible paths between switches are found in the network topology the switches will co operate to disable a port or ports to ensure that there are no loops that is from one device to any other device in the layer 2 network only one path can be taken I II I 9 9 1 1 P Pr ro op pe er rt ti ie es s This page allows a user to...

Page 58: ...g a frame on to a LAN through that port It is recommended to assign this value according to the speed of the bridge The slower the media the higher the cost Entering 0 means the switch will automatically assign a value Priority Specify a priority value for the switch The smaller the priority value the higher the priority and greater chance of becoming the root Edge Port In the edge mode the interf...

Page 59: ...switch by turning this port into error state and shutdown if any BPDU received from this port Check it to enable such function Apply Apply the settings to the switch After clicking it the settings configured above will be shown on the table below Ports Use the drop down to specify the interface s for applying the function of Migrate Migrate Click it to force the port s specified above to send one ...

Page 60: ...tch to be selected as the root bridge of the topology Forward Delay Specify the STP forward delay time which is the amount of time that a port remains in the Listening and Learning states before it enters the Forwarding state Its valid range is from 4 to 10 seconds Max Age Specify the time interval in seconds for a switch to wait the configuration messages without attempting to redefine its own co...

Page 61: ...signated root bridge Root Path Cost Display the operational root path cost Designated Bridge Display the identifier of next bridge on this port Edge Port Conf Oper Display if this port is configured as Edge of STP network for speed up link up P2P MAC Conf Oper Display if this port is configured as point to point link to another switch or host Port Role Display current port role on the specified po...

Page 62: ...gs are explained as follows Item Description Port Display the port number GE LAG Configure BPDUs Rx Display the counts of the received CONFIG BPDU TCN BPDUs Rx Display the counts of the received TCN BPDU Configure BPDUs Tx Display the counts of the transmitted CONFIG BPDU TCN BPDUs Rx Display the counts of the transmitted TCN BPDU ...

Page 63: ...nually assign MAC address into MAC table The configuration result will be displayed on the table listed on the lower side of this web page Available settings are explained as follows Item Description MAC Address Enter the MAC address that will be forwarded VLAN This is the VLAN group to which the MAC address belongs Port Select the port where received frame of matched destination MAC address will ...

Page 64: ... MAC address Available settings are explained as follows Item Description Aging Time Enter the Dynamic MAC address aging out value 5 32767 seconds Apply Apply the settings to the switch I II I 1 10 0 3 3 D Dy yn na am mi ic c L Le ea ar rn ne ed d This page displays the MAC address and port number automatically learned by VigorSwitch Available settings are explained as follows ...

Page 65: ...ay the VLAN group to which the MAC address belongs Type Display whether the MAC address is Dynamic learned by the Switch or Static Unicast manually entered in the Static MAC Forwarding screen Port Display the port to which this MAC address belongs Add to Static Click this button to add any port into the static MAC table ...

Page 66: ...overy Interval Broadcast Flood Enable Recover the port being blocked by broadcast flood after the time set in Recovery Interval Unknown Multicast Flood Enable Recover the port being blocked by unknown multicast flood after the time set in Recovery Interval Unicast Flood Enable Recover the port being blocked by unicast flood after the time set in Recovery Interval ACL Enable Recover the port being ...

Page 67: ...VigorSwitch P1085 User s Guide 59 P Pa ar rt t I II II I O ON NV VI IF F S Su ur rv ve ei il ll la an nc ce e ...

Page 68: ...ic detected by Vigor system I II II I 1 1 1 1 S St ta at tu us s The status including port enabled traffic downlink etc of the IP cameras and NVRs Network Video Recorders can be seen on this page Available settings are explained as follows Item Description Discovery Enable If enabled VigorSwitch will automatically detect ONVIF devices recognize third party IP cameras and NVR and integrate ONVIF de...

Page 69: ...ice s disconnected NVR Display the number of NVR device s connected to VigorSwitch The panel sketch on the screen will display which LAN port that the NVR device connected CAM Display the number of IP camera s connected to VigorSwitch The panel sketch on the screen will display which LAN port that the IP camera connected Group Information Total Group Display the total number of groups Add New Grou...

Page 70: ...lists all devices IP cameras not included by other group Select one IP device to multiple devices or select all the devices for managed by this group ONVIF Device Admin Username Password When the group members share the same username and password enter the username and password in these two field for administration Next Click it to access into next page Step 2 The second page allows you to configu...

Page 71: ... ingress threshold alert enter the ingress rate as a threshold to send mail alert GE Egress Threshold Mailalert Click Enable to set the egress limit value When the outgoing traffic packet of the GE port reaches the limit the Vigor System will send an alert email to the system administrator GE Egress Rate If enabling the egress threshold alert enter the egress rate as a threshold to send mail alert...

Page 72: ...VigorSwitch P1085 User s Guide 64 ...

Page 73: ...mail alert will be sent out Enable When the ingress rate reaches the threshold configured here Vigor system will send alert mail to specified mail address Ingress Rate Kbps Enter a value as the threshold of ingress packets Egress Threshold Mailalert Disable No mail alert will be sent out Enable When the egress rate reaches the threshold configured here Vigor system will send alert mail to specifie...

Page 74: ...VigorSwitch P1085 User s Guide 66 ...

Page 75: ...ng and displaying on this field Video Preview After authenticated with correct username and password the image of the specified IP camera supported by VigorSwitch will be shown immediately Usename Password The default username password will be input if it is configured on the Topology page However if the default input is not the correct username password enter the correct one of the IP camera inst...

Page 76: ...iguring settings for ping check of IP camera or NVR Available settings are explained as follows Item Description Device List Search Enter a string to search the IP device you want Username Password The default username password will be input if it is configured on the Topology page However if the default input is not the correct username password enter the correct one of the IP device instead Logi...

Page 77: ...layed in this field one by one with the format of x x x x x x x x x x x x Del Device Click it to remove the selected IP address Interval Time sec Set a time interval 15 30 60 120 for pinging action Retry Time Choose 1 3 or 5 for Vigor system to retry the pinging action Failure Action Configure the power behavior for each LAN port Power Cycle Once the device is offline Vigorswitch will power off th...

Page 78: ...t if it is configured on the Topology page However if the default input is not the correct username password enter the correct one of the IP device instead Login Click it to authenticate the username and password Later current network settings related to this device will be shown on the screen Mode Change the connection mode for this device Static When it is selected you have to enter value for ne...

Page 79: ...e Display the hostname of the DHCP server Zero Configuration Enable The network settings for the IP device will be configured automatically Disable The network settings for the IP devcie must be configured manually Apply Save the settings or changes to the switch ...

Page 80: ...ater current network settings related to this device will be shown on the screen HTTP Ports Current HTTP port number of the IP device is shown in this field Enable Click it to enable the HTTP port configuration and enter a port value if required Disable Disable the HTTP port configuration HTTPS Ports Current HTTPS port number of the IP device is shown in this field Enable Click it to enable the HT...

Page 81: ...VigorSwitch P1085 User s Guide 73 P Pa ar rt t I IV V S Se ec cu ur ri it ty y ...

Page 82: ... Control Available settings are explained as follows Item Description Storm Control Mode Select the mode of storm control Packet sec Storm control rate will be calculated by packet based Kbits sec Storm control rate will be calculated by octet based Preamble Inter Frame Gap Select the rate calculation with without preamble IFG 20 bytes Excluded Exclude preamble IFG 20 bytes when count ingress stor...

Page 83: ...ing Rate Check the box es to enable strom control rate limited for Broadcast Unknown Multicast and or Unknow Unicast packet Broadcast Specify the storm control rate for Broadcast packet Value of storm control rate Unit Kbps Kbits per second The range is from 16 to 1000000 Unknown Multicast Specify the storm control rate for unknown multicast packet Value of storm control rate Unit Kbps Kbits per s...

Page 84: ...e allows a user to configure DoS setting to enable disable DoS function for global setting Available settings are explained as follows Item Description Dst MAC Src MAC Drop the packets if the destination MAC address is equal to the source MAC address Disabled Disable the item function Enabled Enable the item function LAND Drop the packets if the source IP address is equal to the destination IP add...

Page 85: ...ICMPv6 ping packets The valid range is from 0 to 65535 bytes and the default value is 512 bytes Smurf Attack Avoid smurf attack The length range of the netmask is from 0 to 323 bytes and default length is 0 byte Disabled Disable the item function Enabled Enable the item function TCP Min Hdr Size Check the minimum TCP header and drops the TCP packets with the header smaller than the minimum size Th...

Page 86: ...r to configure and display the state of DoS protection for interfaces The configuration result for each port will be displayed on the table listed on the lower side of this web page Available settings are explained as follows Item Description Port Use the drop down list to select the port profile GE1 to GE8 or profiles DoS Protection Disabled Disable the function of DoS Protection Enabled Enable t...

Page 87: ...ort interface separately Available settings are explained as follows Item Description Ports Use the drop down list to select the port GE1 to GE8 LAG1 to LAG8 or ports for applying IP source guard function State Enable Check it to make the port s selected above apply the settings configured in this page Verify Source Specify the type of source IP for the packet coming from IP Only the packet with s...

Page 88: ...t is optional setting Binding Select the binding type for such feature IP MAC Port VLAN Packets will be allowed to pass through the port interface if they meet the conditions specified by IP address MAC address Port setting and VLAN ID setting IP Port VLAN Packets will be allowed to pass through the port interface if they meet the conditions specified by IP address Port setting and VLAN ID setting...

Page 89: ...it might result in conflict between different devices due to using the same IP address and cause the devices not working correctly This page allows you to prevent IP conflict by binding the port with the specified IP address Available settings are explained as follows Item Description IP Prevention Enable Click it to activate the function of IP prevention Disable Click it to deactivate the functio...

Page 90: ...VigorSwitch P1085 User s Guide 82 IP Conflict Prevention Setup Wizard Quick Start Wizard The system will guide to bind server port with an IP address step by step Step 1 Step 2 Step 3 ...

Page 91: ... address specified for the GE port will be unavailable for other network devices Apply Apply the settings to the switch Clear Remove all settings of IP source guard DHCP snooping and dynamic ARP inspection Modify Click it to modify the settings for the selected entry ...

Page 92: ...ide 84 Port Type There are four selections DHCP Client Static Binding Multiple Hosts and DHCP Server Each type will bring out different IP address es settings OK Click it to save the settings Click it to remove the selected entry ...

Page 93: ...tch detects the loop event of GE ports LAG ports automaticlly Disable VigorSwitch will not detect the loop event Transmission Time When the loop event occurred VigorSwitch will perform the action after a period of time Action When the switch detects loop situation occurred to a port it will perform the action selected in this field Log The switch will reord such event as a log Shutdown Port The sw...

Page 94: ...VigorSwitch P1085 User s Guide 86 This page is left blank ...

Page 95: ...VigorSwitch P1085 User s Guide 87 P Pa ar rt t V V A AC CL L C Co on nf fi ig gu ur ra at ti io on n ...

Page 96: ...C The function is used to show the Access Control List ACL based on Layer 2 filtering the MAC layer The ACL is composed by many Access Control Element ACE rules You can create a new ACL here then add multiple ACEs Available settings are explained as follows Item Description ACL Profile Name Enter a name for creating a new ACL profile Add Add a new ACL entry using given ACL name Action click it to ...

Page 97: ... new ACL entry using given ACL name Action click it to remove the selected entry V V 1 1 3 3 I IP Pv v6 6 The function is used to show the Access Control List ACL based on Layer 2 to Layer 4 filtering the IPv6 The ACL is composed by many Access Control Element ACE rules You may create a new ACL here then add multiple ACEs Available settings are explained as follows ...

Page 98: ...VigorSwitch P1085 User s Guide 90 Item Description ACL Profile Name Enter a name for creating a new ACL profile Add Add a new ACL entry using given ACL name Action click it to remove the selected entry ...

Page 99: ... settings are explained as follows Item Description ACL Profile Name Use the drop down list to selected one of the user defined ACL profiles Sequence Assign a sequence number to this ACE The sequence is used to identify which one of ACEs in an ACL is firstly used to match ingress packets The switch port bound with an ACL use the contained ACE rules start with the one with lower sequence number to ...

Page 100: ...gs for the selected entry click it to remove the selected entry V V 2 2 2 2 I IP Pv v4 4 This page shows ACE based on IPv4 address You may choose ACL permit and deny particular packet or frame even shutdown the port You may provide filtering matching criteria for one or more of following packet characteristic such as Protocol over the IP layer Source Destination IPv4 address Type of Service Source...

Page 101: ...packets will be filtered DSCP All IP traffic is mapped to queues based on the DSCP field in the IP header If traffic is not IP traffic it is mapped to the lowest priority queue IP Precedence All IP traffic is mapped to queues based on the IP Precedence field in the IP header If traffic is not IP traffic it is mapped to the lowest priority queue Source Port Destination Port Specify the source and d...

Page 102: ...CL is firstly used to match ingress packets The switch port bound with an ACL use the contained ACE rules start with the one with lower sequence number to match the packet first Action Select the action applied to the packet matched this ACE Permit or deny the packets into switch core or shutdown the port for stopping further transmission Permit Deny Shutdown Protocol Specify the protocol for filt...

Page 103: ...r for filtering the packets Any All packets will be filtered Single Only the packets passing through the number defined here will be filtered Range Only the packets passing through the port range defined here will be filtered ICMP Type Any All packets will be filtered Select Choose one of the type e g Destination Unreachable Echo Reply MLD Query from the drop down list Define Specify a type number...

Page 104: ...on A physical port can only be bound with one of the IPv4 and IPv6 ACL not both Available settings are explained as follows Item Description Ports Use the drop down list to select the port profiles GE1 to GE8 for binding ACL MAC ACL IPv4 ACL IPv6 ACL Select ACLs MAC IPv4 and or IPv6 to be bound on this interface port so Switch may filter packets by using it Apply Apply the settings to the switch ...

Page 105: ...VigorSwitch P1085 User s Guide 97 P Pa ar rt t V VI I Q Qo oS S C Co on nf fi ig gu ur ra at ti io on n ...

Page 106: ... the function of QoS mode Basic Enable the function of QoS mode Ingress Trust Mode Select the QoS operation mode CoS 802 1p Traffic is mapped to queues based on the CoS field in the VLAN tag or based on the per port default CoS value if there is no VLAN tag on the incoming packet DSCP All IP traffic is mapped to queues based on the DSCP field in the IP header If traffic is not IP traffic it is map...

Page 107: ...riority queue The configuration result for each port will be displayed on the table listed on the lower side of this web page Available settings are explained as follows Item Description Ports Use the drop down list to select the port profile GE1 to GE8 or profiles Trust Click Enable to make traffic follow the trust mode in general setting Enable Traffic will follow trust mode in general setting D...

Page 108: ...t given trust QoS tag 802 1q DSCP IP Precedence depending on configuration Engress Remarking Remark CoS Disable Disable CoS remarking function for outgoing packets Enable Egress traffic will be marked with CoS value according to the Queue to CoS mapping table Remark DSCP IP Precedence Disable Disable DSCP IP Precedence remarking function for outgoing packets DSCP Egress traffic will be marked with...

Page 109: ...bin WRR The number of packets sent from the queue is proportional to the weight of the queue Available settings are explained as follows Item Description Queue There are eight queue ID numbers allowed to be configured Schedule Strict Priority Click it to set queue to strict priority type WRR Click it to set queue to Weight round robin type Weight If the queue type is WRR set the queue weight for t...

Page 110: ...ser to configure mapping only Available settings are explained as follows Item Description CoS to Queue Mapping for Ingress Settings for incoming packets Class of Service Display the class of service value 0 to 7 Queue Define the queue ID level 1 to 8 for different class of service values Queue to CoS Mapping for Egress Remarking Settings for outgoing packets Queue Display the queue ID level 1 to ...

Page 111: ...s page provides settings for user to configure mapping only Available settings are explained as follows Item Description DSCP to Queue Mapping for Ingress Settings for the incoming packets DSCP Display the DSCP value 0 to 7 Queue Define the queue ID level 1 to 8 for different DSCP values Queue to DSCP Mapping for Egress Remarking Settings for outgoing packets Queue Display the queue ID level 1 to ...

Page 112: ... settings for user to configure mapping only Available settings are explained as follows Item Description IP Precedence to Queue Mapping for Ingress Settings for the incoming packets IP Precedence Display the IP Precedence value 0 to 7 Queue Define the queue ID level 1 to 8 for different IP Precedence values Queue to IP Precedence Mapping for Egress Remarking Settings for outgoing packets Queue Di...

Page 113: ...be received from the ingress interface Excess bandwidth above this limit is discarded The configuration result for each port will be displayed on the table listed on the lower side of this web page Available settings are explained as follows Item Description Ingress Rate Limit Ports Use the drop down list to select the port profile GE1 to GE8 or profiles State Disable Disable ingress bandwidth con...

Page 114: ...rface Excess bandwidth above this limit is discarded Available settings are explained as follows Item Description Egress Shapping Rate Ports Use the drop down list to select the port profile GE1 to GE8 or profiles State Disable Disable egress bandwidth control Enable Enable egress bandwidth control CIR Kbps Enter the rate value 16 1000000 unit 16 Kbps Apply Apply the settings to the switch Modify ...

Page 115: ...ed on the table listed on the lower side of this web page Available settings are explained as follows Item Description Egress Shapping Per Queue Port Use the drop down list to select the port profile GE1 to GE8 or profiles Queue Use the drop down list to select queue number 1 to 8 for the selected GE port State Disable Disable egress bandwidth control Enable Enable egress bandwidth control CIR Kbp...

Page 116: ...VigorSwitch P1085 User s Guide 108 This page is left blank ...

Page 117: ...VigorSwitch P1085 User s Guide 109 P Pa ar rt t V VI II I P Po oE E C Co on nf fi ig gu ur ra at ti io on n ...

Page 118: ...tion Auto Provides plug and play PoE function PoE schedule and Power Limit are disabled in this mode Manual Before using PoE Schedule set Manual as PoE mode Ports Use the drop down list to select the port GE1 to GE8 or ports for applying PoE configuration Enable Enable Make the selected ports be applied with PoE mode Disable Make the selected ports be not applied with PoE mode Priority Select Prio...

Page 119: ...de Display the PoE Mode Manual Auto or Disable selected for the LAN port Power Budget W Display the maximum power this switch can supply over PoE Consuming Power W Display current power being consumed by all devices over PoE Remaining Power W Display remaining power that can be supplied to additional devices over PoE Power Cycle Apply If PoE device connects to VigorSwitch such button will be avaib...

Page 120: ...s configured Description Enter a brief comment for such schedule Start Date Specify the starting date of the schedule by choosing from a drop down calendar Start Time Specify the starting time of the schedule by using the drop down list to specify the starting time hours and minutes Duration Time Define the time duration hours and minutes Action Specify which action should perform during the perio...

Page 121: ...page allows the network administrator to specify the PoE port for applying the schedule The configuration result for each port will be displayed on the table listed on the lower side of this web page Note that the schedule profile is only available in PoE Manual mode Available settings are explained as follows Item Description Ports Select the port or ports for applying the schedule Schedule Index...

Page 122: ...VigorSwitch P1085 User s Guide 114 This page is left blank ...

Page 123: ...VigorSwitch P1085 User s Guide 115 P Pa ar rt t V VI II II I S Sy ys st te em m M Ma ai in nt te en na an nc ce e ...

Page 124: ...u want to link Last Inform Display the time that VigorACS server makes a response while receiving Inform message from CPE last time Test Inform Click Test With Inform to send a message to test if such CPE is able to communicate with VigorACS server CPE Settings CPE Client Choose HTTP or HTTPS for connecting with VigorACS URL Display the URL of VigorSwitch Port Type the username and password that V...

Page 125: ...t setting is 60 seconds Maximum Keep Alive Period If STUN is enabled the switch must send binding request to the server for the purpose of maintaining the binding in the Gateway Please type a number as the maximum period A value of 1 indicates that no maximum period is specified Health Check Vigor system will check the health status of LAN ports including link up down speed change or PoE power dis...

Page 126: ...lained as follows Item Description Remote Management Enable Click it to enable OpenVPN tunnel between VigorSwitch with the remote end Disable Click it to disable OpenVPN tunnel Config File As a VPN client please import the OpenVPN config file coming from OpenVPN server Apply Save and apply the settings to the switch Status Display current OpenVPN status Disabled Connecting or Success and configura...

Page 127: ...itted to the specified URL Disable Click it to disable the webhook service URL Specify the destination to receive the real time data by entering the URL Please get the URL from the client who wants to obtain the newest and available data automatically from the switch Report Period Set the transmission interval unit is minute Keep my settings while rest default Check the box to keep the webhook con...

Page 128: ...switch LLDP PDU Disable Action It is available when LLDP State is disabled Specify the action for VigorSwitch to execute Filtering Packets will be dropped Bridging Packets will be transmitted to the device within the same VLAN Flooding Packets will be transmitted to all ports Transmission Interval Select the interval at which frames are transmitted The default is 30 seconds and the valid range is ...

Page 129: ...ithin data communication protocols optional information may be encoded as a type length value or TLV element inside a protocol TLV is also known as tag length value The type and length are fixed in size typically 1 4 bytes and the value field is of variable size Select the LLDP optional TLVs to be carried multiple selection is allowed Available items include System Name Port Description System Des...

Page 130: ...VigorSwitch P1085 User s Guide 122 ...

Page 131: ...ess the MAC address of the switch is displayed System Name Display model name of switch System Description Display description of switch Capabilities Supported Display the primary functions of the device such as Bridge WLAN AP or Router Capabilities Enabled Primary enabled functions of the device Port ID Subtype Display the type of the port identifier that is shown Port Details Display detailed in...

Page 132: ...nected Chassis ID Subtype Display the type of chassis ID for example MAC address Chassis ID Display the identifier of the 802 LAN neighboring device s chassis Port ID Subtype Display the type of port identifier Port ID Display the number of port identifier System Name Display the name of the switch Time to Live Display the time interval in seconds after which the information for remote device will...

Page 133: ...lay the name of the port Total Bytes Display the total number of bytes of LLDP information in each packet Left to Send Bytes Display the total number of available bytes left for additional LLDP information in each packet Status Display if LLDP TLVs has overloaded the PDU maximum size or not Mandatory TLVs Display how many bytes used by mandatory TLVs 802 3 TLVs Display how many bytes used by 802 3...

Page 134: ...managed devices Network management station NMS software which runs on the manager A managed device is a network node that implements an SNMP interface that allows unidirectional read only or bidirectional read and write access to node specific information Managed devices exchange node specific information with the NMSs Sometimes called network elements the managed devices can be any type of device...

Page 135: ...nformation base and then include or exclude OID Object Identifier in a view Available settings are explained as follows Item Description View Name Enter a name of the MIB view OID Subtree Enter an OID string to be included or excluded from the MIB view Type Determine to include or exclude the selected MIBs Apply Apply the settings to the switch ...

Page 136: ...View Enabled Users of this group have the right to read the selected MIB view Use the drop down list to select one of the views The default is all which means the group user can read all MIB views Write View Enabled Users of this group have the right to write the selected MIB view Use the drop down list to select one of the views The default is all which means the group user can write all MIB view...

Page 137: ...ecified for such SNMP community profile Advanced Specify one of the SNMP groups for such SNMP community profile View Simply specify one of the view profiles created in SNMP View from the drop down list Access Right Read Only It allows unidirectional access to node specific information Read Write It allows bidirectional access to node specific information Group Specify the SNMP group configured by ...

Page 138: ... Authentication Method Method You can change the methods None MD5 SHA for the selected SNMPv3 group If no method is available for you to select that means the selected SNMPv3 group is set with No Security Password Enter a string as the password for authentication Privacy Method You can change the methods None DES for the selected SNMPv3 group If no method is available for you to select that means ...

Page 139: ...VigorSwitch P1085 User s Guide 131 However if there is no SNMPv3 group ready for use the following pages will appear instead Refer to VIII 5 2 Group to create a SNMPv3 group first ...

Page 140: ...al engine ID Available settings are explained as follows Item Description Engine ID The user defined engine ID is range 10 to 64 hexadecimal characters and the hexadecimal number must be divided by 2 User Defined If it is checked the local engine ID will be configured manually If not the default Engine ID which is made up of MAC and Enterprise ID will be used instead Apply Apply the settings to th...

Page 141: ... Type Specify the address type for entering hostname or IPv4 IPv6 address Server Address Enter the IP address or the host name of the SNMP server Engine ID Specify the engine ID for remote SNMP server The engine ID is range10 to 64 hexadecimal characters and the hexadecimal number must be divided by 2 Add Click it to create a new profile Edit click it to modify the settings for the selected server...

Page 142: ...tion Authentication Failure Enable VigorSwtich will reboot when encountering authentication failure including community not match or user password not match Link Up Down Enable VigorSwtich will reboot while encountering port link up or down trap Cold Start Enable VigorSwtich will reboot while encountering user trap Warm Start Enable VigorSwtich will reboot while encountering power down trap Apply ...

Page 143: ...orms to the host If it is used Timeout and Retry also shall be defined Community user Use the drop down list to choose one of the community profiles Security Level Specify SNMP security level for SNMP notification packet It is available when SNMPv3 is selected No Security No authentication Authentication Authentication without encryption will be performed for packets Authentication and Privacy Aut...

Page 144: ...t is available when Inform is selected as Type Use Default If it is checked the default number 3 will be used automaticallty Add Click it to create a new notification profile Edit Click it to modify the settings for the selected server profile Click it to remove the selected entry ...

Page 145: ... Management Enabled Users will be forced to access into the web user interface of VigorSwitch by HTTPS protocol TLS Minimum Protocol Version TLS1 2 TLS 1 3 VigorSwitch supports TLS1 2 and TLS 1 3 protocols for web broswsing Select one of the versions as a protocol for having higher connection security Telnet Service Telnet is the TCP IP standard protocol for remote terminal service TELNET allows a...

Page 146: ...sing recurring mode of daylight saving time Non Recurring Using non recurring mode of daylight saving time USA Using daylight saving time in the United States that starts on the second Sunday of March and ends on the first Sunday of November European Using daylight saving time in the Europe that starts on the last Sunday Daylight Saving Time Offset It is available when Recurring is selected as Day...

Page 147: ... im me e This page allows a user to specify time and activate SNTP server manually Available settings are explained as follows Item Description Manual Time Specify static time year month day hours miniutes and seconds manually Enable SNTP Enable Click it to enable SNTP time server Disable Click to disable the time server SNTP NTP Server Address Enter the web site of the time server or the IP addre...

Page 148: ...through HTTP protocol Available settings are explained as follows Item Description Backup Method Select Backup method TFTP Using TFTP to backup firmware HTTP Using WEB browser to ubackup firmware Server IP It is available when TFTP is selected as Backup Method Enter the IPv4 IPv6 address for the TFTP server Backup Type Configuration Make a backup copy for the configurations for VigorSwitch Apply A...

Page 149: ...rmware HTTP Using WEB browser to upgrade firmware Server IP It is available when TFTP is selected as Upgrade Method Enter the IPv4 IPv6 address for the TFTP server File Name It is available when TFTP is selected as Upgrade Method Enter the firmware image or configuration file name on the TFTP server File Path It is available when HTTP is selected as Upgrade Method Choose the firmware file located ...

Page 150: ...ssword and choose privilege level After clicking Apply the existed user name will be modified with different values Password Enter a password for new account Password Strength Display the strength weak medium or strong of the password entered above Retype Password Retype password to make sure the password is exactly you typed before in Password field Privilege Level Use the drop down list to selec...

Page 151: ...VigorSwitch P1085 User s Guide 143 ...

Page 152: ... I 1 11 1 F Fa ac ct to or ry y D De ef fa au ul lt t Click Apply to return to factory default settings for VigorSwitch If Keep my current IPv4 address settings is checked after clicking Apply the original configuration for IP address will be kept ...

Page 153: ...VigorSwitch P1085 User s Guide 145 V VI II II I 1 12 2 R Re eb bo oo ot t S Sw wi it tc ch h Click Apply to reboot VigorSwitch with current settings ...

Page 154: ...VigorSwitch P1085 User s Guide 146 This page is left blank ...

Page 155: ...VigorSwitch P1085 User s Guide 147 P Pa ar rt t I IX X D Di ia ag gn no os st ti ic cs s ...

Page 156: ... No PoE function for the selected GE port Enable PoE function will be enabled for the selected GE port Ping IP Address Enter the IP address of the PoE device for check Interval Time sec The ping check will be performed every 10 30 60 or 120 seconds for the selected port PoE device Retry Time The system will perform the ping check the selected port PoE device for 1 3 or 5 times Failure Action Speci...

Page 157: ... cs s After finished copper test the results will be shown on the lower side of this web page Available settings are explained as follows Item Description Port Use the drop down list to select the port GE1 to GE8 or ports for performing cable diagnostics Start Perform the copper test action ...

Page 158: ...pecify IP address for sending ping to check if network path is ok Host Enter the IP address of SNMP server based on the protocol selected above Count It means how many times to send ping request packet Enter a number between 1 and 5 as the count and the default configuration is 4 Interval sec Define the interval to perform ping action For example 1 means the ping action will be performed per secon...

Page 159: ... known as Flash Severity Select severity emerg alert crit error warning notice info and debug of log messages which you wish to filter out for review Category Select the categories related features of logs you wish to review Category contains AAA ACL AUTHMGR CABLE_DIAG DAI DHCP_SNOOPING GVRP IGMP_SNOOPING IPSG L2 LLDP Mac based VLAN Mirror MLD_SNOOPING Platform PM Port PORT_SECURITY QoS Rate SNMP ...

Page 160: ...Se er rv vi ic ce e This page allows user to enable system logging into local syslog and specific remote syslog server for storage Available settings are explained as follows Item Description SysLog Service Enable Click it to activate function of syslog Disable Click it to inactivate the function Apply Apply the settings to the switch ...

Page 161: ... off Non Volatile Memory Select the non volatile memory for saving If you want to modify Volatile Memory Non Volatile Memory select Volatile Memory Non Volatile Memory in this field Then use the drop down list of severity to specify type of log message After clicking Apply the Volatile Memory Non Volatile Memory will be modified with new configured severity level Severity Select severity emerg ale...

Page 162: ...ddress Enter the IP address of Syslog server Server Port Specify the port that syslog should be sent to Severity Select severity emerg alert crit error warning notice info and debug of log messages which will be stored Facility One device supports multiple facilities represented with facility ID local0 to local7 of remote Syslog server For each facility ID contains different syslog server configur...

Page 163: ...Syslog Mail Disable Disable the function of Syslog Mail Category Vigor sytem will send the e mail related to the selected feature s to the recipient SMTP Server Enter IP address or URL of the SMTP server SMTP Port Enter the port number for the SMTP server Authentication Enable Click it to enable authentication mechanism Username Enter a user name for authentication Password Enter a password for au...

Page 164: ... out will not be encrypted Sender Enter the email address which will send the syslog mail out Email Address Enter the email address which will receive the syslog mail Apply Apply the settings to the switch Send test mail After clicking this button VigorSwitch system will send a test mail to the recipient ...

Page 165: ...VigorSwitch P1085 User s Guide 157 P Pa ar rt t X X M Ma ai il l A Al le er rt t ...

Page 166: ...hanism User Name Enter a user name for authentication Password Enter a password for authentication Encryption After enabling Authentication choose one of the encryption servers for data encryption StartTLS The mail will be encrypted with StartTLS SSL TLS The mail will be encrypted with SSL TLS Disable The mail sent out will not be encrypted Sender Enter the email address which will send the alert ...

Page 167: ...P1085 User s Guide 159 IP Conflict Device Check ONVIF Throughput Threshold Apply Apply the settings to the switch Send test mail After clicking this button VigorSwitch system will send a test mail to the recipient ...

Page 168: ...VigorSwitch P1085 User s Guide 160 This page is left blank ...

Page 169: ...VigorSwitch P1085 User s Guide 161 P Pa ar rt t X XI I T Te el ln ne et t C Co om mm ma an nd ds s ...

Page 170: ...his manual Info For Windows 7 user please make sure the Windows Features of Telnet Client has been turned on under Control Panel Programs Type cmd and press Enter The Telnet terminal will be open later In the following window type Telnet 192 168 1 224 as below and press Enter Note that the IP address in the example is the default address of the router If you have changed the default enter the curr...

Page 171: ...VigorSwitch P1085 User s Guide 163 For users using previous Windows system e g XP simply click Start Run and type Telnet 192 168 1 224 in the Open box Next enter admin admin for Account Password ...

Page 172: ...o check if there are subcommands under current command X XI I 2 2 1 1 C Cl le ea ar r C Co on nf fi ig gu ur ra at ti io on n This command allows resetting the functions of ARP interface IP IPv6 LACP Line LLDP Logging MAC and Spanning Tree T Te el ln ne et t C Co om mm ma an nd d c cl le ea ar r a ar rp p Use this command to clear entries in the ARP cache S Sy yn nt ta ax x I It te em ms s clear a...

Page 173: ...nterface for clearing statistics counters on that port 1 8 Enter the number 1 to 8 of LAG interface IEEE 802 3 Link Aggregation Interface Related Syntax clear interfaces LAG 1 8 counters E Ex xa am mp pl le e P1085 clear interfaces gigabitethernet 3 counters P1085 clear interfaces P1085 clear interfaces lag 2 counters P1085 T Te el ln ne et t C Co om mm ma an nd d c cl le ea ar r i ip p Use this c...

Page 174: ...atic snooping groups of MLD Related Syntax clear ipv6 mld snooping groups dynamic clear ipv6 mld snooping groups static E Ex xa am mp pl le e P1085 clear ipv6 P1085 clear ipv6 mld snooping groups dynamic P1085 clear ipv6 mld snooping groups dynamic cr P1085 clear ipv6 mld snooping groups static T Te el ln ne et t C Co om mm ma an nd d c cl le ea ar r l la ac cp p Use this command to clear LACP con...

Page 175: ... Syntax clear line ssh slear line telnet Clear SSH Telnet configuration for line connection Related Syntax clear line telnet E Ex xa am mp pl le e P1085 clear line ssh P1085 clear line telnet T Te el ln ne et t C Co om mm ma an nd d c cl le ea ar r l ll ld dp p Use this command to clear LLDP statistics or reset LLDP information S Sy yn nt ta ax x I It te em ms s clear lldp global clear lldp interf...

Page 176: ...le D De es sc cr ri ip pt ti io on n Syntax Items Description clear logging buffered Clear the log stored in RAM Related Syntax clear logging buffered clear logging file Clear the log stored in flash Related Syntax clear logging file E Ex xa am mp pl le e P1085 clear logging buffered P1085 clear logging file P1085 T Te el ln ne et t C Co om mm ma an nd d c cl le ea ar r m ma ac c Use this command ...

Page 177: ...tion S Sy yn nt ta ax x I It te em ms s clear spanning tree D De es sc cr ri ip pt ti io on n Syntax Items Description clear spanning tree interfaces Specify a LAN interface for clearing its running information 1 8 Enter the number 1 to 8 of LAN port 1 8 Enter the number 1 to 8 of LAG interface IEEE 802 3 Link Aggregation Interface Related Syntax clear spanning tree interfaces GigabitEthernet 1 8 ...

Page 178: ...ti io on n Syntax Items Description clock set Set current by entering hours minutes seconds month date and year with the format listed below HH MM SS Hour minute second e g 08 10 30 Jan January feb February mar March apr April may May jun June jul July aug August sep September oct October nov November dec December 1 31 Date 1 to 31 2000 2035 Year of 2000 to 2035 Related Syntax clock set HH MM SS j...

Page 179: ...d external time source for the system clock S Sy yn nt ta ax x I It te em ms s clock auto timezone clock source local clock source sntp clock summer time clock timezone D De es sc cr ri ip pt ti io on n Syntax Items Description clock auto timezone VigorSwitch sets the time zone automatically clock source local Configure an external time source for the system clock local means to use static time It...

Page 180: ...2037 HH MM jan feb mar apr may jun jul aug sep oct nov dec 1 31 2000 2037 HH MM config clock summer time ACRONYM recurring eu 1 1440 config clock summer time ACRONYM recurring usa 1 1440 config clock summer time ACRONYM recurring first sun mon tue wed thu fri sat jan feb mar apr may jun jul aug sep oct nov dec HH MM first last sun mon tue wed thu fri sat jan feb mar apr may jun jul aug sep oct nov...

Page 181: ... P1085 configure P1085 config clock summer time ACRONYM recurring eu 1200 P1085 config clock summer time ACRONYM recurring first mon jan 10 10 first sun feb 10 10 1000 P1085 config exit P1085 show clock detail 2019 01 05 11 37 18 UTC 8 Time source is sntp Time zone Acronym is Offset is UTC 8 Summertime Acronym is ACRONYM Recurring every year Begins at 1 1 1 10 10 Ends at 1 0 2 10 10 Offset is 1000...

Page 182: ... dos xma deny D De es sc cr ri ip pt ti io on n Syntax Items Description dos daeqsa deny Drop the packets if the destination MAC address equals to the source MAC address Related Syntax config dos daeqsa deny dos icmp frag pkts deny Drop the fragmented ICMP packets Related Syntax config dos icmp frag pkts deny dos icmp ping max length Set the maximum packet size for ICMPv4 ICMPv6 ping operation 0 6...

Page 183: ...the smurf attack size 0 32 Enter a number as smurf attacks size Related Syntax config dos smurf netmask 0 32 dos syn sportl1024 deny Drop SYN packets with sport less than 1024 Related Syntax config dos syn sportl1024 deny dos synfin deny Drop the packets with SYN and FIN bits set Related Syntax config dos synfin deny dos synrst deny Drop the packets with SYNC and RST bits set Related Syntax config...

Page 184: ..._surveillence set D De es sc cr ri ip pt ti io on n Syntax Items Description dray_surveillence add Add an IP device for surveillance WORD 36 36 Enter the UUID string of the IP camera or IP based device Related Syntax config dray_surveillence add device uuid WORD 36 36 config dray_surveillence add group uuid WORD 36 36 dray_surveillence direct add WORD 36 36 Enter the UUID string of the IP camera o...

Page 185: ...0 Loader Date Sep 05 2019 16 55 13 Firmware Version 2 5 1_RC5 Firmware Date Nov 28 2019 17 15 54 Firmware Revision 1688 System Object ID 1 3 6 1 4 1 7367 System Up Time 1 days 21 hours 51 mins 1 secs PoE SW Version 260 P1085 config T Te el ln ne et t C Co om mm ma an nd d e en na ab bl le e Use this command to configure local password with encrypted string or not S Sy yn nt ta ax x I It te em ms s...

Page 186: ...ui table 00 E0 BB 3COM voice vlan oui table 00 03 6B Cisco voice vlan oui table 00 E0 75 Veritel voice vlan oui table 00 D0 1E Pingtel voice vlan oui table 00 01 E3 Siemens voice vlan oui table 00 60 B9 NEC Philips voice vlan oui table 00 0F E2 H3C voice vlan oui table 00 09 6E Avaya vlan mac vlan group 1 14 49 BC 00 04 C9 mask 9 T Te el ln ne et t C Co om mm ma an nd d e en nd d Use this command ...

Page 187: ...default value is 300 seconds Related Syntax config errdisable recovery interval 30 86400 E Ex xa am mp pl le e P1085 configure P1085 config P1085 config errdisable recovery interval 600 P1085 config T Te el ln ne et t C Co om mm ma an nd d e ex xi it t Use this command to exit current mode and return to previous mode phase S Sy yn nt ta ax x I It te em ms s exit E Ex xa am mp pl le e P1085 configu...

Page 188: ...ri ip pt ti io on n Syntax Items Description interface GigabitEthernet 1 8 Specify the number of Ethernet LAN port Related Syntax config interface GigabitEthernet 1 8 interface LAG 1 8 Specify the number of LAG interface Related Syntax config interface LAG 1 8 Interface range Specify an interface ranges for configuring detailed settings Related Syntax config interface range GigabitEthernet 1 8 con...

Page 189: ...he custom module configuration for the specified interface Ethernet port LAG port Related Syntax config if custom enable description Write a description for the specified interface Ethernet port LAG port WORD Enter a description up to 32 characters Related Syntax config if descripton WORD device check Perform a device check the specified interface Ethernet port LAG port ip address A B C D Enter th...

Page 190: ...trol auto off on ip Apply IP configuration to the specified interface Ethernet port LAG port acl NAME Specify an ACL for packets Enter the name of the ACL conflict prevention bind ip A B C D conflict prevention port type DHCP Client conflict prevention port type DHCP Client has server conflict prevention port type DHCP Server conflict prevention port type DHCP Server has server conflict prevention...

Page 191: ...p number action deny replace Define the action to be performed when excessing the maximum group Related Syntax config if ipv6 acl NAME config if ipv6 mld filter config if ipv6 mld max groups 0 256 config if ipv6 mld max groups action deny replace lacp Apply LACP Configuration to the specified interface Ethernet port LAG port 1 65535 Set a number for IEEE 802 3 link aggregation port priority long s...

Page 192: ...E device discovery protocol and apply the power to the devcie inline never Turn off the PoE device power power limit 15 4w 30w MW Set the power limit for the PoE device priority 1 3 critical high low Set the priority of power application for the PoE device schedule index Specify the index number of the schedule profile Related Syntax config if power inline auto config if power inline never config ...

Page 193: ...d Syntax config if shutdown spanning tree Configure spanning tree settings bpdu filter Set the BPDU Filter for specified port bpdu guard Set the BPDU Guard for specified port edge Set the edge port for specified port cost Change an interface s spanning tree path cost link type Specify a link type for spanning tree protocol use mcheck Set the mcheck for specified port to migrate mst Set spanning tr...

Page 194: ... VLAN automatically manual The administrator manually makes surveillance member port join voice VLAN Related Syntax config if surveillance vlan cos all src config if surveillance vlan mode auto manual switchport Set switching mode characteristics access vlan Use it to set a native VLAN on the interface default vlan tagged Use it to make the selected port interface to become the default VLAN tagged...

Page 195: ...plink config if switchport trunk allowed vlan add remove 1 4094 all config if switchport trunk native 1 4094 vlan mac vlan group Set a MAC based VLAN configuration protocol vlan group Set a protocol based VLAN configuration 1 2147483647 Specify a group ID to map 1 4094 Specify a VLAN ID Related Syntax config if vlan mac vlan group 1 2147483647 vlan 1 4094 config if vlan protocol vlan group 1 21474...

Page 196: ...acl sequence config ip acl show ip acl Use the deny command to create deny rules for the IPv4 access list 0 255 egp hmp icmp igp ipinip ipv6 ipv6 frag ipv6 icmp ipv6 rout ip l2tp ospf pim rdp rsvp tcp udp Specify the IP protocol number or enter the name of the protocol A B C D A B C D A B C D A B C D Specify the source and destination IPv4 addresses and subnet masks dscp 0 63 Set the DSCP filterin...

Page 197: ...p acl no sequence 1 2147483647 Use the permit command to create permit rules which bypass the packets meet the rule 0 255 egp hmp icmp igp ipinip ipv6 ipv6 frag ipv6 icmp ipv6 rout ip l2tp ospf pim rdp rsvp tcp udp Specify the IP protocol number or enter the name of the protocol A B C D A B C D A B C D A B C D Specify the source and destination IPv4 addresses and subnet masks dscp 0 63 Set the DSC...

Page 198: ...C D mask A B C D ip conflict Use this command to do IP conflict prevention lag Enable disable the function A B C D Specify the IPv4 addresses 1 8 Specify a physical port 1 8 Specify a LAG port Related Syntax config ip conflict lag config ip conflict prevention config ip conflict prevention clear config ip conflict prevention server ip A B C D interface GigabitEthernet 1 8 config ip conflict preven...

Page 199: ...config ip https login authentication LISTNAME config ip https session timeout 0 86400 ip igmp Use this command to set IGMP profile and enable IGMP snooping function Profile Set IGMP profile 1 128 Enter the index number of IGMP profile to access into next phase for configuring detailed settings A B C D A B C D Specify the source and destination IPv4 addresses action deny permit Speicfy the rule den...

Page 200: ...ed Syntax config ip telnet E Ex xa am mp pl le e P1085 configure P1085 config ip acl market_1 P1085 config ip acl P1085 config ip acl deny 20 192 168 2 55 255 255 255 0 192 168 2 85 255 P1085 config T Te el ln ne et t C Co om mm ma an nd d i ip pv v6 6 Use this command to create an IPv6 access list ACL S Sy yn nt ta ax x I It te em ms s ipv6 acl ipv6 address ipv6 autoconfig ipv6 default gateway ip...

Page 201: ... additional flags one after another without a space example syn ack 0 65535 PORT_RANGE any bootpc bootps discard domain echo nameserver netbios ns ntp rip snmp snmptrap sunrpc syslog talk tftp time who X X X X 0 128 0 65535 PORT_RANGE any bootpc bootps discard domain echo nameserver netbios ns ntp rip snmp snmptrap sunrpc syslog talk tftp time who Set UDP port Related Syntax config ipv6 acl deny 0...

Page 202: ...ny destination unreachable echo reply echo request nd na nd ns packet too big parameter problem router advertisement router solicitation time exceeded 0 255 any dscp 0 63 shutdown config ipv6 acl deny icmp X X X X 0 128 any 0 255 any destination unreachable echo reply echo request nd na nd ns packet too big parameter problem router advertisement router solicitation time exceeded 0 255 any preceden...

Page 203: ...p ftp data hostname klogin kshell pop2 pop3 smtp sunrpc syslog talk telnet time whois www X X X X 0 128 0 65535 PORT_RANGE any daytime discard domain drip echo ftp ftp data hostname klogin kshell pop2 pop3 smtp sunrpc syslog talk telnet time whois www dscp 0 63 config ipv6 acl deny tcp X X X X 0 128 0 65535 PORT_RANGE any daytime discard domain drip echo ftp ftp data hostname klogin kshell pop2 po...

Page 204: ...p echo ftp ftp data hostname klogin kshell pop2 pop3 smtp sunrpc syslog talk telnet time whois www precedence 0 7 config ipv6 acl deny tcp X X X X 0 128 0 65535 PORT_RANGE any daytime discard domain drip echo ftp ftp data hostname klogin kshell pop2 pop3 smtp sunrpc syslog talk telnet time whois www X X X X 0 128 0 65535 PORT_RANGE any daytime discard domain drip echo ftp ftp data hostname klogin ...

Page 205: ...ted Syntax config ipv6 acl do SEQUENCE Use the end command to finish current mode Any changes in current mode will be saved Related Syntax config ipv6 acl end Use the exit command to close the current CLI session or return to the previous mode without saving the settings Related Syntax config ipv6 acl exit Use the no sequence command to delete any entry in management ACL 1 2147483647 Specify an in...

Page 206: ... ipv6 acl permit 0 255 X X X X 0 128 any precedence 0 7 config ipv6 acl permit 0 255 X X X X 0 128 any precedence 0 7 shutdown config ipv6 acl permit 0 255 X X X X 0 128 any shutdown config ipv6 acl permit icmp X X X X 0 128 X X X X 0 128 0 255 any destination unreachable echo reply echo request nd na nd ns packet too big parameter problem router advertisement router solicitation time exceeded 0 2...

Page 207: ...ertisement router solicitation time exceeded 0 255 any shutdown config ipv6 acl permit ipv6 X X X X 0 128 X X X X 0 128 config ipv6 acl permit ipv6 X X X X 0 128 X X X X 0 128 dscp 0 63 config ipv6 acl permit ipv6 X X X X 0 128 X X X X 0 128 dscp 0 63 shutdown config ipv6 acl permit ipv6 X X X X 0 128 X X X X 0 128 precedence 0 7 config ipv6 acl permit ipv6 X X X X 0 128 X X X X 0 128 precedence 0...

Page 208: ... drip echo ftp ftp data hostname klogin kshell pop2 pop3 smtp sunrpc syslog talk telnet time whois www X X X X 0 128 0 65535 PORT_RANGE any daytime discard domain drip echo ftp ftp data hostname klogin kshell pop2 pop3 smtp sunrpc syslog talk telnet time whois www match all TCP_FLAG dscp 0 63 config ipv6 acl permit tcp X X X X 0 128 0 65535 PORT_RANGE any daytime discard domain drip echo ftp ftp d...

Page 209: ... whois www shutdown config ipv6 acl permit udp X X X X 0 128 0 65535 PORT_RANGE any bootpc bootps discard domain echo nameserver netbios ns ntp rip snmp snmptrap sunrpc syslog talk tftp time who X X X X 0 128 0 65535 PORT_RANGE any bootpc bootps discard domain echo nameserver netbios ns ntp rip snmp snmptrap sunrpc syslog talk tftp time who config ipv6 acl permit udp X X X X 0 128 0 65535 PORT_RAN...

Page 210: ... X X ipv6 dhcp Use this command to enable DHCPv6 client to get IP address from remote DHCPv6 server ipv6 mld Use this command to set MLD configuration profile 1 128 Use it to enter profile configuration snooping Use it to enable MLD snooping function forward method dip mac report suppression Use it to enable MLD snooping report suppression function unknown multicast action drop flood router port U...

Page 211: ...it config mld profile profile range ipv6 X X X X action deny permit config mld profile profile range ipv6 X X X X X X X X config mld profile profile range ipv6 X X X X X X X X action deny permit config mld profile show config ipv6 mld snooping config ipv6 mld snooping forward method dip mac config ipv6 mld snooping report suppression config ipv6 mld snooping unknown multicast action drop flood rou...

Page 212: ...085 config ipv6 acl CA_v6 P1085 config ipv6 acl deny 3 00 50 32 ff 24 00 50 78 aa 32 T Te el ln ne et t C Co om mm ma an nd d j ju um mb bo o f fr ra am me e Use this command to modify the maximum frame size of jumbo frame S Sy yn nt ta ax x I It te em ms s jumbo frame D De es sc cr ri ip pt ti io on n Syntax Items Description jumbo frame Enable the function of jumbo frame Set the maximum frame si...

Page 213: ...can transmit packets to all ports for balancing the traffic loading Use this command to change the load balance algorithm to src dst mac or src dst mac ip as the Load Balance policy S Sy yn nt ta ax x I It te em ms s lag load balance D De es sc cr ri ip pt ti io on n Syntax Items Description lag load balance LAG load balancing is based on source and destination MAC address and or IP address Relate...

Page 214: ...hen available sub commands are config line do config line end config line exec timeout config line exit config line password thresh config line silent time do Use the do command to run execution command in current mode SEQUENCE Related Syntax config line do SEQUENCE exec timeout Use the exec timeout to set the session timeout configuration 0 65535 Enter the number Related Syntax config line exec t...

Page 215: ... te em ms s lldp lldp holdtime multiplier lldp lldpdu lldp reinit delay lldp tx delay lldp tx interval D De es sc cr ri ip pt ti io on n Syntax Items Description lldp Enable the function of LLDP lldp holdtime multiplier Set the multiplier used for calculating the LLDP discovery packet hold time 2 10 Set the LLDP hold time multiplier Related Syntax config lldp holdtime multiplier 2 10 lldp lldpdu b...

Page 216: ...transmissions 1 8191 Enter the number of delay time Note that both tx interval and tx delay will affect the LLDP PDU TX time Related Syntax config lldp tx delay 1 8191 lldp tx interval Set the LLDP TX interval 5 32767 Enter the interval in unit of second Related Syntax config lldp tx interval 5 32767 E Ex xa am mp pl le e P1085 configure P1085 config P1085 config lldp tx interval 500 P1085 config ...

Page 217: ...ging host Define the logging server host A B C D Enter an IP address of the remote or local server facility local0 local7 Specify the facility parameter for the syslog message port 1 65535 Enter a number for the remote server Default is 514 severity 0 7 Specify the logging level by entering a number from EMEGR DEBUG HOSTNAME Define a name as the host Related Syntax config logging host A B C D faci...

Page 218: ...ems Description logmail active disable enable Enable or disable the function of log mail Related Syntax config logmail active disable enable logmail auth disable enable Enable or disable the function of SMTP server authentication Related Syntax config logmail auth disable enable logmail category AAA ACL AUTHMGR CABLE_DIAG DAI DHCP_SNOOPING GVRP IGMP_SNOOPING IPSG L2 LLDP Mac based Mirror MLD_SNOOP...

Page 219: ...by STMP server Related Syntax config logmail username NAME E Ex xa am mp pl le e P1085 configure P1085 config P1085 config logmail receiver carrie_ni draytek com P1085 config T Te el ln ne et t C Co om mm ma an nd d l lo oo op p p pr ro ot te ec ct ti io on n Use this command to set loop protection S Sy yn nt ta ax x I It te em ms s loop protection action loop protection periodicTime loop protecti...

Page 220: ...o add deny rules for the MAC access list A B C D E F A B C D E F A B C D E F A B C D E F Specify the source and destination MAC addresses and subnet masks cos 0 7 0 7 Set the cos value and the cos mask for a packet 0x0600 0xFFFF Set the EtherType of the packet Shutdown Disable the Ethernet interface vlan 1 4094 Specify the VLAN ID of the packet any Any MAC address Related Syntax config mac acl den...

Page 221: ...4 cos 0 7 0 7 config mac acl deny any any vlan 1 4094 cos 0 7 0 7 ethtype 0x0600 0xFFFF config mac acl deny any any vlan 1 4094 cos 0 7 0 7 ethtype 0x0600 0xFFFF shutdown config mac acl deny any any vlan 1 4094 ethtype 0x0600 0xFFFF config mac acl deny any any vlan 1 4094 ethtype 0x0600 0xFFFF shutdown config mac acl deny any any vlan 1 4094 shutdown Use the do command to run execution command in ...

Page 222: ...lan 1 4094 cos 0 7 0 7 ethtype 0x0600 0xFFFF config mac acl permit any A B C D E F A B C D E F vlan 1 4094 ethtype 0x0600 0xFFFF Use the sequence command to deny or permit the ACL 1 2147483647 Enter the sequence index ACE The sequence represents the priority of the ACE in the ACL A B C D E F A B C D E F Specify the source and destination MAC addresses and subnet masks cos 0 7 0 7 Set the cos value...

Page 223: ...sequence 1 2147483647 deny any any shutdown config mac acl sequence 1 2147483647 deny any any vlan 1 4094 config mac acl sequence 1 2147483647 deny any any vlan 1 4094 cos 0 7 0 7 config mac acl sequence 1 2147483647 deny any any vlan 1 4094 cos 0 7 0 7 ethtype 0x0600 0xFFFF config mac acl sequence 1 2147483647 deny any any vlan 1 4094 cos 0 7 0 7 ethtype 0x0600 0xFFFF shutdown config mac acl sequ...

Page 224: ...an 1 4094 cos 0 7 0 7 config mac acl sequence 1 2147483647 permit any any vlan 1 4094 cos 0 7 0 7 ethtype 0x0600 0xFFFF config mac acl sequence 1 2147483647 permit any any vlan 1 4094 ethtype 0x0600 0xFFFF mac address table aging time 10 630 Set the aging time for an entry remains in the MAC address table address table static Add a static address to the MAC address table to drop the packets with t...

Page 225: ...auth disable enable Enable or disable the function of SMTP server authentication Related Syntax config mailalert auth disable enable mailalert devicecheck disable enable Enable or disable the function of sending a mail alert when encountering a device check error Related Syntax config mailalert devicecheck disable enable mailalert encry Specify the encryption type for mail alert disable ssltls sta...

Page 226: ...ver Related Syntax config mailalert receiver ADDRESS mailalert sender Specify an address which sends out the alert mail ADDRESS Enter the email address of the sender Related Syntax config mailalert sender ADDRESS mailalert server Set the IP address of the server ADDRESS Enter the IP address of the SMTP server Related Syntax config mailalert server ADDRESS mailalert sysrestart disable enable Enable...

Page 227: ... ri ip pt ti io on n Syntax Items Description mirror session Set the destination interface of a port mirror session 1 4 Specify the mirror session ID number GigabitEthernet 1 8 Specify a physical port as the SPAN destination allow ingress Enable the ingress traffic forwarding both rx tx Specify the mirror direction TX only RX only or TX and RX Related Syntax config mirror session 1 4 destination i...

Page 228: ... pt ti io on n Syntax Items Description enable Enable the OpenVPN tunnel disable Disable the OpenVPN tunnel filename NAME Define a name for OpenVPN configuration Related Syntax config openvpn filename NAME E Ex xa am mp pl le e P1085 configure P1085 config P1085 config T Te el ln ne et t C Co om mm ma an nd d p po oe e Use this command configure settings for PoE device S Sy yn nt ta ax x I It te e...

Page 229: ... cr ri ip pt ti io on n Syntax Items Description qos Enable the quality of service based on basic trust type to assign the queue for packets Related Syntax config qos qos map map cos queue Set the CoS to queue map map dscp queue Set the DSCP to queue map map precedence queue Set the IP Precedence to queue map map queue cos Modify the queue to CoS map map queue dscp Modify the queue to DSCP map map...

Page 230: ...fig P1085 config qos map cos queue SEQUENCE to 3 P1085 config T Te el ln ne et t C Co om mm ma an nd d s sc ch he ed du ul le e Use this command to set schedule S Sy yn nt ta ax x I It te em ms s schedule index D De es sc cr ri ip pt ti io on n Syntax Items Description schedule index Specify an index number for configuring detailed settings of a schedule profile 1 15 Enter a number to select a sch...

Page 231: ...ion on off config schedule index 1 15 how often weekdays sun mon tue wed thu fri sat start date apr aug dec feb jan jul jun mar may nov oct sep 1 31 2000 2035 start time HH MM duration HH MM action on off E Ex xa am mp pl le e P1085 configure P1085 config P1085 config schedule index 1 how often cycle days 3 start date jan 1 2019 start time 08 01 duraton 17 30 action on P1085 config schedule index ...

Page 232: ...thentication mode auth means to perform packet authentication without encryption It is applicable for SNMPv3 only noauth means no packet authentication performed priv means to perform packet authentication with encryption and also it is applicable for SNMPv3 only read view NAME Set the view name to enable agent configuration notify view NAME Set the view name to send only trap included in SNMP vie...

Page 233: ...ME timeout 1 300 retries 1 255 config snmp host A B C D informs version 1 2c 3 NAME udp port 1 65535 config snmp host A B C D informs version 1 2c 3 NAME udp port 1 65535 retries 1 255 config snmp host A B C D informs version 1 2c 3 NAME udp port 1 65535 timeout 1 300 config snmp host A B C D informs version 1 2c 3 NAME udp port 1 65535 timeout 1 300 retries 1 255 Set a host to receive SNMP notifi...

Page 234: ...ms NAME retries 1 255 config snmp host HOSTNAME informs NAME timeout 1 300 config snmp host HOSTNAME informs NAME retries 1 255 timeout 1 300 retries 1 255 config snmp host HOSTNAME informs NAME udp port 1 65535 config snmp host HOSTNAME informs NAME udp port 1 65535 retries 1 255 config snmp host HOSTNAME informs NAME udp port 1 65535 timeout 1 300 config snmp host HOSTNAME informs NAME udp port ...

Page 235: ...meout 1 300 config snmp host X X X X NAME retries 1 255 timeout 1 300 retries 1 255 config snmp host X X X X NAME udp port 1 65535 config snmp host X X X X NAME udp port 1 65535 retries 1 255 config snmp host X X X X NAME udp port 1 65535 timeout 1 300 config snmp host X X X X NAME udp port 1 65535 timeout 1 300 retries 1 255 config snmp host X X X X informs NAME config snmp host X X X X informs N...

Page 236: ...he SNMP port security trap Warm start Enable the SNMP warm startup failure trap Related Syntax config snmp trap auth cold start linkUpDown port security warm start snmp user snmp user Set SNMP user account username Specify a name of SNMP user groupNAME Sepcify a name of SNMP group auth md5 sha Specify the authentication mode md5 or sha AUTHPASSWD Enter the password for the md5 sha mode Pri PRIVPAS...

Page 237: ...1085 config snmp view CAR_community subtree 10 oid mask 9 viewtype included P1085 config T Te el ln ne et t C Co om mm ma an nd d s sn nt tp p Use this command to configure settings for remote SNTP server S Sy yn nt ta ax x I It te em ms s sntp host D De es sc cr ri ip pt ti io on n Syntax Items Description sntp host Set the remote SNTP server by specifying IP address or hostname HOSTNAME Enter th...

Page 238: ...fault value is 2 seconds Related Syntax config spanning tree hello time 1 10 spanning tree maximum age Set the time interval for VigorSwitch to wait without receiving the configuration message 6 40 Default value is 20 seconds Related Syntax config spanning tree maximum age 6 40 spanning tree pathcost Set the path cost method for spanning tree long short Long means the path cost ranging from 1 to 2...

Page 239: ... this command to configure settings for Storm Control S Sy yn nt ta ax x I It te em ms s storm control ifg exclude storm control ifg include storm control unit bps storm control unit pps D De es sc cr ri ip pt ti io on n Syntax Items Description storm control ifg exclude Exclude the preamble and IFG inter frame gap into the calculating Related Syntax config storm control ifg exclude storm control ...

Page 240: ...lance VLAN on VigorSwitch Related Syntax config surveillance vlan surveillance vlan aging time Set the aging time for surveillance VLAN 30 65536 Enter a value as aging time Related Syntax config surveillance vlan aging time 30 65536 surveillance vlan cos Set the class of service 0 7 for surveillance VLAN 0 7 Enter a number Related Syntax config surveillance vlan cos 0 7 remark surveillance vlan ou...

Page 241: ...lated Syntax config system contact CONTACT system location LOCATION Specify the location of the host Related Syntax config system location LOCATION system name NAME Change the name of the system The default name is P1085 Related Syntax config system name NAME E Ex xa am mp pl le e P1085 configure P1085 config P1085 config system contact callMIS P1085 config P1085 config system location DrayTek P10...

Page 242: ... Enable for VigorACS controlling such CPE through the Internet Related Syntax config tr069 cpeEnable disable enable tr069 cpePwd PASSWORD Enter the password that VigorACS server can use it to authenticate and control the CPE device Related Syntax config tr069 cpePwd PASSWORD tr069 cpeUsername NAME Enter the username that VigorACS server can use it to authenticate and control the CPE device Related...

Page 243: ...e enable tr069 stun disable enable Enter Enable to enable CPE management protocol with STUN server Related Syntax config tr069 stun disable enable tr069 stunMAXkeepalive Set the maximum time period for CPE to send the binding request to VigorACS server 0 65535 Enter a number Related Syntax config tr069 stunMAXkeepalive 0 65535 tr069 stunMINkeepalive Set the minimum time period for CPE to send the ...

Page 244: ... level to be admin privilege 15 user privilege 1 PASSWORD Enter a string as the password for the local user Related Syntax config username WORD privilege admin user secret PASSWORD config username WORD secret PASSWORD config username WORD secret encrypted PASSWORD E Ex xa am mp pl le e P1085 configure P1085 config P1085 config username carrie_1 privilege admin secret md123456 P1085 config P1085 co...

Page 245: ...mode without saving the settings Related Syntax config macl exit vlan Use the name command to add a VLAN profile string Enter the name of the VLAN profile Related Syntax config vlan name string vlan mac vlan group Create a MAC vlan group 1 2147483647 Specify a group ID A B C D E F Enter the MAC address to be mapped 9 48 Enter a number representing the subnet mask Related Syntax config vlan mac vla...

Page 246: ... from the OUI table In default there are 8 OUI addresses A B C Enter the OUI address DESCRIPTION Enter a brief description for the specified MAC address to the voice VLAN OUI table Related Syntax config voice vlan cos 0 7 remark voice vlan vlan Set the VLAN identifier of the voice VLAN 2 4094 Enter the number of VLAN ID Related Syntax config voice vlan vlan 2 4094 E Ex xa am mp pl le e P1085 confi...

Page 247: ...r the IP address of the destination path PATH Enter the path string part of the composition of the URL of the destination port number Enter a port number service http https Specify the protocol http or https of the destination url domain name Enter the domain name e g draytek com of the destination Note that it is not necessary to enter this information if IP address has been set first Related Syn...

Page 248: ...40 E Ex xa am mp pl le e P1085 configure P1085 config webhook host service https P1085 config webhook host url www demo com P1085 config webhook host path Draytek demo P1085 config webhook host port 443 P1085 config webhook interval 2 ...

Page 249: ...erver with a filename Related Syntax copy running config startup config copy running config tftp copy startup config running config Copy the startup configuration file to the running configuration tftp Copy the startup configuration file to remote TFTP server with a filename Related Syntax copy startup config running config copy startup config tftp copy tftp running config Get the running configur...

Page 250: ... default settings of VigorSwitch Related Syntax delete startup config E Ex xa am mp pl le e P1085 delet flash startup config Delete flash startup config y n y Do you want to reload the system to take effect y n y X XI I 2 2 6 6 D Di is sa ab bl le e C Co on nf fi ig gu ur ra at ti io on n All commands used will be divided into EXEC mode and Privileged EXEC mode This command is to turn off privileg...

Page 251: ... current mode S Sy yn nt ta ax x I It te em ms s end E Ex xa am mp pl le e P1085 config interface GigabitEthernet 3 P1085 config if end P1085 X XI I 2 2 8 8 E Ex xi it t C Co on nf fi ig gu ur ra at ti io on n Use this command to close current CLI session or return to previous mode S Sy yn nt ta ax x I It te em ms s exit E Ex xa am mp pl le e P1085 config interface GigabitEthernet 3 P1085 config i...

Page 252: ...I It te em ms s ping D De es sc cr ri ip pt ti io on n Syntax Items Description ping HOSTNAME Enter an IPv4 IPv6 address or a domain name to ping count 1 999999999 Specify the number of repetitions of ping operation Related Syntax ping HOSTNAME count 1 999999999 E Ex xa am mp pl le e P1085 ping 192 168 1 11 count 3 PING 192 168 1 11 192 168 1 11 56 data bytes 64 bytes from 192 168 1 11 icmp_seq 0 ...

Page 253: ...c cr ri ip pt ti io on n Syntax Items Description restore defaults 1 8 Enter the number 1 to 8 of LAN port 1 8 Enter the number of LAG port Related Syntax restore defaults restore defaults interfaces GigabitEthernet 1 8 restore defaults interfaces LAG 1 8 E Ex xa am mp pl le e P1085 restore defaults interfaces gigabitethernet 3 Interface gi3 restore factory defaults P1085 P1085 restore default Sys...

Page 254: ...sys usage 256 Type IPSG usage 128 Type Auth usage 128 P1085 P1085 P1085 show arp Address HWtype HWaddress Flags Mask Iface 192 168 1 55 ether 00 1D AA F0 26 08 C eth0 192 168 1 10 ether 00 05 5D E4 D8 EE C eth0 P1085 show voice vlan interfaces gigabitethernet 3 Voice VLAN Aging 1440 minutes Voice VLAN CoS 6 Voice VLAN 1p Remark disabled OUI table OUI MAC Description 00 E0 BB 3COM 00 03 6B Cisco 00...

Page 255: ... fields but you can leave some blank For some fields there will be a default value If you enter the field will be left blank Country Name 2 letter code AU tw State or Province Name full name Some State hs Locality Name eg city hschu Organization Name eg company Internet Widgits Pty Ltd draytek Organizational Unit Name eg section marketing Common Name e g server FQDN or YOUR name draytek Email Addr...

Page 256: ...nt ta ax x I It te em ms s traceroute S Sy yn nt ta ax x D De es sc cr ri ip pt ti io on n Syntax Items Description traceroute HOSTNAME Enter the IP address or the hostname of the device for VigorSwitch to perform traceroute diagnostic Related Syntax traceroute HOSTNAME E Ex xa am mp pl le e P1085 traceroute 192 168 1 224 traceroute to 192 168 1 224 192 168 1 224 30 hops max 40 byte packets 1 192 ...

Page 257: ...he same frame format CSMA CD software interface In 1998 Gigabit Ethernet was rolled out and provided 1000Mbps Now 10G s Ethernet is under approving Although these Ethernet have different speed they still use the same basic functions So they are compatible in software and can connect each other almost without limitation The transmission media may be the only problem In the above figure we can see t...

Page 258: ...work layer which is nothing to do with the nature of the LAN So it can operate over other different LAN technology such as Token Ring FDDI and so on Likewise for the interface to the MAC layer LLC defines the services with the interface independent of the medium access technology and with some of the nature of the medium itself The table above is the format of LLC PDU It comprises four fields DSAP...

Page 259: ...ess service LLC type 2 connection oriented service and LLC type 3 acknowledge connectionless service are three types of LLC frame for all classes of service In Fig 3 2 it shows the format of Service Access Point SAP Please refer to IEEE802 2 for more details ...

Page 260: ... group 1 So the 48 bit address space is divided into two portions Unicast and Multicast The second bit is for global unique 0 or locally unique address The former is assigned by the device manufacturer and the later is usually assigned by the administrator In practice global unique addresses are always applied A unicast address is identified with a single network interface With this nature of MAC ...

Page 261: ... it means the Length Type acts as Type Different type value means the frames with different protocols running over Ethernet being sent or received For example 0x0800 IP datagram 0x0806 ARP 0x0835 RARP 0x8137 IPX datagram 0x86DD IPv6 Data Less than or equal to 1500 bytes and greater or equal to 46 bytes If data is less than 46 bytes the MAC will automatically extend the padding bits and have the pa...

Page 262: ...hernet MAC transmits frames in half duplex and full duplex ways In halfduplex operation mode the MAC can either transmit or receive frame at a moment but cannot do both jobs at the same time As the transmission of a MAC frame with the half duplex operation exists only in the same collision domain the carrier signal needs to spend time to travel to reach the targeted device For two most distant dev...

Page 263: ...mitting and receiving frames are processed simultaneously This doubles the total bandwidth Full duplex is much easier than half duplex because it does not involve media contention collision retransmission schedule padding bits for short frame The rest functions follow the specification of IEEE802 3 For example it must meet the requirement of minimum inter frame gap between successive frames and fr...

Page 264: ...ll as to have the jobs ready such as adjusting buffer counter updating counter and so on in the receiver site Once the inter frame gap time expires after the de assertion of carrier sense the MAC transmits data In IEEE802 3 specification this is 96 bit time or more C Co ol ll li is si io on n Collision happens only in half duplex operation When two or more network nodes transmit frames at approxim...

Page 265: ...CS is invalid If there is any extra bits existed which must meet the specification of IEEE802 3 When both FCS and extra bits are valid the received frame will be accepted otherwise discards the received frame and reports frameCheckError if no extra bits appended or alignmentError if extra bits appended 5 If the length type is valid If not discards the packet and reports lengthError 6 If all five p...

Page 266: ...ower speeds is inadequate to accommodate network topologies of the desired physical extent Carrier Extension provides a means by which the slotTime can be increased to a sufficient value for the desired topologies without increasing the minFrameSize parameter as this would have deleterious effects Nondata bits referred to as extension bits are appended to frames that are less than slotTime bits in...

Page 267: ...4 G General 88 91 96 98 General Setup 18 I Ingress Rate Limit 105 Installation for VigorAPM 6 L License Agreement 20 License Information 23 24 29 40 41 48 49 55 Limiting Rate 75 P PoE Configuration 109 Preamble 74 Properties 76 Q QoS Configuration 87 97 S Security 59 73 SNMP 126 SNMP Community 129 130 132 Storm Control 75 Storm Control 60 74 Storm Control 79 Stric Priority Queue 101 System Configu...

Reviews: