E3Switch DS3 Operating Information Manual Download Page 9

Chapter 4: Remote Management HTTP and SNMP

The following methods may be used to determine a gateway's IP address if lost or forgotten.  Note that once 
determined, management communication with the unit may only be possible from a host configured to the 
same IP subnet address if the unit's default router address is invalid.

To manually discover a unit's IP address, unplug all LAN and BNC cables from the gateway and power 
cycle the unit.  30 seconds after powerup, the gateway will begin blinking out its IP address on the leftmost 
LED.  Each digit is counted up as an orange blink with a pause between digits and a short blink for a 0.  A 
decimal in the IP address is indicated with a green blink.  For example, <orange><orange><pause><short-
orange><pause><green>... would be an IP address that begins “20.”

For those with access to packet sniffers, upon power-up, the gateway will broadcast several gratuitous ARP 
packets on its network ports which can be examined with a sniffer or packet monitoring software to 
determine a unit's IP address.  The source Ethernet MAC address of such packets and E3Switch gateways is 
00:50:C2:6F:xx:xx.  Tcpdump or Wireshark are two readily available software packages to examine 
network packets.

Additionally, examination of the MAC address table of an attached LAN switch or router may provide the 
IP address if the E3Switch MAC address prefix (00:50:C2:6F:xx:xx) can be located.

Management Passwords

The HTTP management statistics page is initially accessible without a password.  The HTTP settings page 
is initially modifiable within the first several minutes after powerup with username 

admin

 and no password. 

If the unit has not had its default password changed, after several minutes the settings page will be locked 
for security reasons.  It is desirable to change the default password of the unit.  For security reasons, 
changing the default password of the unit must be done within the first several minutes of any powerup.  If 
the HTTP management password is lost or forgotten, it may be reset by accessing the HTTP management 
settings within the first minute after powerup and with no BNC cables attached to the unit.

SNMP statistics may initially be accessed using the read-only community name 

public

.  Write-community 

names and variable access authorization may be set through the HTTP management interface.

Security

Please also refer to the password section above.

HTTP Interface Security

Access to the HTTP management interface statistics and settings pages can be selectively limited to users 
knowing the HTTP management password, which is transmitted securely on the network using MD5 
encoding.  New values of management settings, or modifications of the administrator password are not 
encrypted and are visible to users monitoring network packets, as is statistical data requested by an MD5 
authorized user or any information visible on a HTTP page.

When logging out from any secure webpage, the browser window should always be closed!

  Browsers 

typically continue to send administrator credentials continuously even after apparent logout.

SNMP Security

The gateway implements SNMPv2c, which is inherently an insecure protocol; however, the gateway 
enhances security by implementing view-based access management (VACM), which can restrict read or 
write access to specific management settings and statistics.  When shipped, the gateway allows read access 
to “safe” SNMP statistics and prohibits read and write access to statistics and settings which could allow 
determination of network topology or interfere with normal link traffic.  The VACM configuration can be 
updated through the HTTP management interface to meet the user's needs, and most SNMP variables can 
also be set through the HTTP management interface in a more secure manner than SNMP allows.

9

Summary of Contents for DS3

Page 1: ...DS3 E3 over Ethernet Pseudowire Gateway V5 4 November 11th 2010 Operating Information...

Page 2: ...Coronado Ave San Carlos CA 94070 U S A http www ds3switch com support ds3switch com TEL 1 650 598 0366 FCC STATEMENT This device complies with Part 15 of the FCC Rules Operation is subject to the foll...

Page 3: ...quipment were derived for commercial and industrial environments to provide reasonable protection against interference with licensed communication equipment Attention This is a Class A product In a do...

Page 4: ...ACKET FLOW 12 Packet Order 12 Receive Jitter Buffer Depth and Latency 12 TDM Frames per Packet and Latency 12 PORT TO PORT PACKET FLOW 13 LAN to LAN 13 Loopback 13 LAN PORT SETTINGS 13 LAN Port Speed...

Page 5: ...E 18 INTEROPERABILITY 18 PINGING 18 STEP BY STEP DIAGNOSIS 18 CHAPTER 11 THIRD PARTY COPYRIGHT NOTICES 19 ECOS LICENSE 19 THE FREEBSD COPYRIGHT 19 THE NET SNMP COPYRIGHT 19 THE APACHE LICENSE 21 THE S...

Page 6: ...ways is possible either in or out of band through either the copper or SFP LAN port An SFP transceiver is required to use the SFP LAN port Remote firmware upgrade to a gateway is possible through the...

Page 7: ...ablished between the two gateways with no TDM alarms at either end Further HTTP management of the gateway via LAN is required in the following situations if using fractional rather than full speed E3...

Page 8: ...ement interface must be in xxx xxx xxx xxx numeric format rather than a human readable DNS resolvable hostname Automatic Link Local IP Address E3Switch products are shipped with an initial IP address...

Page 9: ...e default password of the unit For security reasons changing the default password of the unit must be done within the first several minutes of any powerup If the HTTP management password is lost or fo...

Page 10: ...n be modified via SNMP can also be set through the HTTP interface in a more user friendly manner Refer to the configuration section of this document for guidance on specific settings Event Log File A...

Page 11: ...performing the TFTP transfer are included with all firmware shipments The most common source of problems when performing upgrades is attempting a TFTP transfer in ASCII or text mode rather than binary...

Page 12: ...the following discussion if the incoming TDM is unframed the term frame simply refers to the number of TDM bits that would constitute a frame if framing were in effect Each LAN packet requires approx...

Page 13: ...ached equipment This requirement is necessary to fulfill 802 3 standards which mandate a fallback to half duplex operation if an autonegotiation mismatch exists The gateways require full duplex LAN co...

Page 14: ...munication with the gateway s management entity As shipped the unit will accept management packets with any VLAN tags and attempt to respond to the same For more robust performance specific VLAN tag s...

Page 15: ...understanding the gateway s autonegotiation advertisement of strictly full duplex capability It is highly desirable to leave autonegotiation enabled so that changing attached LAN equipment does not re...

Page 16: ...or lengths over 135 meters testing in field should be used to determine whether bit error rates are acceptable Long cable lengths also require careful selection of cable type and attention to sources...

Page 17: ...actional TDM is desired Transport Layer Depending upon the model purchased LAN packets may be configured with simple MAC Layer 2 addressing or more sophisticated IP UDP or MPLS headers Chapter 10 Trou...

Page 18: ...command ping followed by the destination machine s IP address or hostname is all that is required to be typed at the source machine s command line The default ping generates approximately one 64 byte...

Page 19: ...and received Free public domain programs such as Wireshark are readily available Chapter 11 Third Party Copyright Notices E3Switch is grateful for and contributes to open source software development w...

Page 20: ...AIMED IN NO EVENT SHALL THE COPYRIGHT HOLDERS OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT INDIRECT INCIDENTAL SPECIAL EXEMPLARY OR CONSEQUENTIAL DAMAGES INCLUDING BUT NOT LIMITED TO PROCUREMENT OF SUBSTI...

Page 21: ...bmitted to Licensor for inclusion in the Work by the copyright owner or by an individual or Legal Entity authorized to submit on behalf of the copyright owner For the purposes of this definition submi...

Page 22: ...sibility of such damages 9 Accepting Warranty or Additional Liability While redistributing the Work or Derivative Works thereof You may choose to offer and charge a fee for acceptance of support warra...

Page 23: ...Chapter 12 Technical Specifications and Standards Chapter 12 Technical Specifications and Standards Please see separate specification datasheet 23...

Reviews: