background image

-50-

4.9.2 802.1X Re-authentication Parameters

Configuration

Description

Reauthentication Enabled

Check to enable periodical re-authentication for all ports

Reauthentication Period

The period of time after which the connected radius clients must be
re-authenticated (unit: second), Value: 1- 3600

EAP timeout

The period of time the switch waits for a supplicant response to an
EAP request (unit: second), Value: 1 - 255

[Apply]

Click to apply the configuration change

[Refresh]

Click to refresh current configuration

Summary of Contents for KGD-600-B

Page 1: ... 1 KGD 600 B Industrial Web Smart 6 Port Gigabit Ethernet Switch with Fiber Connectivity Installation Guide DOC 120606 ...

Page 2: ...rves the right to revise this documentation and to make changes in content from time to time without obligation on the part of KTI Networks Inc to provide notification of such revision or change For more information contact United States KTI Networks Inc P O BOX 631008 Houston Texas 77263 1008 Phone 713 2663891 Fax 713 2663893 E mail kti ktinet com URL http www ktinet com International Fax 886 2 2...

Page 3: ...or compliance could void the user s authority to operate the equipment 2 Shielded interface cables and AC power cord if any must be used in order to comply with the emission limits CISPR A COMPLIANCE This device complies with EMC directive of the European Community and meets or exceeds the following technical standard EN 55022 Limits and Methods of Measurement of Radio Interference Characteristics...

Page 4: ...breviation 19 3 2 QoS Function 20 3 2 1 Packet Priority Classification 21 3 2 2 Priority Class Queues 21 3 2 3 Egress Service Policy 21 3 3 VLAN Function 22 3 3 1 VLAN Operation 22 3 3 2 Ingress Rules 22 3 3 2 1 802 1Q Tag Aware Per port setting 22 3 3 2 2 Keep Tag Per port setting 22 3 3 2 3 Drop Untag Per Port Setting 23 3 3 2 4 Drop Tag Per Port Setting 23 3 3 3 Ingress Default Tag Per Port Set...

Page 5: ...for VLAN Configuration 44 4 7 LACP 45 4 8 RSTP 46 4 9 802 1X Configuration 47 4 9 1 802 1X Statistics 49 4 9 2 802 1X Re authentication Parameters 50 4 10 IGMP Snooping 51 4 11 Mirroring 52 4 12 Quality of Service 53 4 12 1 802 1p Mapping 54 4 12 2 DSCP Mapping 55 4 12 3 QoS Service Policy 56 4 13 Storm Control 57 4 14 Statistics Overview 58 4 15 Detailed Statistics 59 4 16 LACP Status 60 4 17 RST...

Page 6: ...es used Fiber Connectivity The mini GBIC SFP port can be installed with an optional SFP optical fiber transceiver to support one Gigabit fiber connection when needed Web Management The switch is embedded with an Http server which provides management functions for advanced network functions including Port Control Quality of Service and Virtual LAN functions The manage ment can be performed via Web ...

Page 7: ...s in band web based management interface All copper ports support auto negotiation and auto MDI MDI X detection Provides full wire speed forwarding Supports 802 3x flow control for full duplex and backpressure for half duplex Provides port status statistic monitoring and control function Supports port based and 802 1Q Tag based VLAN Provides QoS function Provides port mirroring function Management...

Page 8: ... 8 1 2 Product Panels The following figure illustrates the faces of the switch ...

Page 9: ... Duplex support Full Half duplex Network cable Cat 5 UTP 1000Mbps Mini GBIC Fiber Port Compliance IEEE 802 3z 1000Base SX LX mini GBIC Connectors SFP for optional SFP type fiber transceivers Configuration Auto Forced 1000Mbps Full duplex Transmission rate 1000Mbps Network cables MMF 50 125 60 125 SMF 9 125 Eye safety IEC 825 compliant Switch Functions MAC Addresses Table 8K entries Forwarding filt...

Page 10: ...put Interfaces DC IN Jack D 6 3mm D 2 0mm DC IN Terminal Block screw type Operating Input Voltages 6 5 32VDC Power Consumption 5W max 7 5V Mechanical Dimension base 144 x 104 5 x 26 mm Housing Enclosed metal with no fan Mounting Support Din rail mounting Panel mounting Wall mounting Desktop mounting Environmental Operating Temperature Typical 40o C 70o C Storage Temperature 40o C 85o C Relative Hu...

Page 11: ... cable extension cable or plug is damaged An object has fallen into the product The product has been exposed to water The product has been dropped or damaged The product does not operate correctly when you follow the operating instructions Do not push any objects into the openings of your system Doing so can cause fire or electric shock by shorting out interior components Operate the product only ...

Page 12: ...Mounting The steps to mount the switch on aDin rail are One Din rail mounting bracket is provided in the product package as shown below Install the bracket on the bottom of the switch unit Mount the device on a Din rail ...

Page 13: ...anel Mounting One optional panel mounting bracket is available for purchase as shown below Install the bracket on the bottom of the switch unit The final dimension after panel bracket is installed is shown below ...

Page 14: ...upply system Using Terminal Blocks Three terminal contacts are provided Vdc Positive terminal Vdc Negative terminal Chassis ground Vdc 6 5V 32VDC One 3P terminal plugs are provided together with the switch The plug is shown below Power wires 24 12AWG IEC 0 5 2 5mm2 Install the power source wires with the plug properly Then plug in the terminal block socket ...

Page 15: ... to supply the DC power for the unit should have the AC voltage matching the commercial power voltage in your area 2 7 Reset Button The reset button is used to perform a reset to the switch It is not used in normal cases and can be used for diagnostic purpose If any network hanging problem is suspected it is useful to push the button to reset the switch without turning off the power Check whether ...

Page 16: ... to MDI X connection It simplifies the cable installation Auto negotiation Function The ports are featured with auto negotiation function and full capability to support connection to any Ethernet devices The port performs a negotiation process for the speed and duplex configuration with the connected device automatically when each time a link is being established If the connected device is also au...

Page 17: ...into the mini GBIC port Normally a bail is provided for every SFP transceiver Hold the bail and make insertion 3 Until the SFP transceiver is seated securely in the slot place the bail in lock position Connecting Fiber Cables LC connectors are commonly equipped on most SFP transceiver modules Identify TX and RX connector before making cable connection The following figure illustrates a connection ...

Page 18: ... 6 link is down P6 OL Port6 optical link ON Optical signal is detected on Port 6 OFF No optical signal is detected on Port 6 2 11 Configuring IP Address and Password for the Switch The switch is shipped with the following factory default settings for software management Default IP address of the switch 192 168 0 2 255 255 255 0 The IP Address is an identification of the switch in a TCP IP network ...

Page 19: ...rd Ethernet frame with no VLAN Tag field Priority tagged packet An IEEE 802 1Q packet which VID filed value is zero VID 0 VLAN Tagged packet An IEEE 802 1Q packet which VID filed value is not zero VID 0 PVID Port VID PVID is the default VID of an ingress port It is often used in VLAN classification for untagged packets It is also often used for egress tagging operation DSCP Differentiated Service ...

Page 20: ...on to guide the packet forwarding in four priority classes The versatile classification methods can meet most of the application needs The following figure illustrates the QoS operation flow when a packet received on the ingress port until it is transmitted out from the egress port ...

Page 21: ... to an egress port 3 2 2 Priority Class Queues Each egress port in the switch is equipped with four priority class egress queues to store the packets for transmission A packet is stored into the class queue which is associated to the classified priority class For example a packet is stored into Class 3 egress queue if it is classified as priority Class 3 3 2 3 Egress Service Policy Each port can b...

Page 22: ...ring and packet tag removal The related Ingress port settings are 3 3 2 1 802 1Q Tag Aware Per port setting Tag aware 802 1Q Tag Aware mode is used The switch examines the tag content of every received packets For a VLAN tagged packet the packet VLAN tag data is retrieved as packet tag information for VLAN classification and egress tagging operation For untagged packet and priority tagged packet p...

Page 23: ...en Ingress port default tag is used it is copied as packet associated Packet Tag Information for VLAN classification The PVID is used as index to one VLAN group in VLAN group table 3 3 4 Packet Tag Information Under VLAN process every packet is associated with one Packet Tag information in packet forward ing operation The tag information includes VID CFI and User Priority data and is used for two ...

Page 24: ...ropped Refer to section 3 2 4 for details about how the Packet Tag information is generated The member ports specified in the matched VLAN group are the admitted egress port range for the packet The packet will never be forwarded to other ports which are not in the member ports The Source Port Check setting of the matched VLAN group is also referred If it is enabled the ingress port will be checke...

Page 25: ...agged VID configured in next setting even Insert Tag is enabled Disable This rule is not applied 3 3 9 Summary of VLAN Function VLAN Modes Port based VLAN Mode simple port based 2 VLAN groups mode Port based VLAN ISP Mode simple port based 5 VLAN groups mode Advanced VLAN Mode Full VLAN configuration for port based and Tag based VLAN Advanced VLAN Mode Egress Settings per port Tag Aware Keep Tag D...

Page 26: ...now if services should be granted The 802 1X authenticator operates as a go between with the supplicant and the authentication server to provide services to the network When a switch is configured as an authenticator the ports of the switch must then be configured for authorization In an authenticator initiated port authorization a client is powered up or plugs into the port and the authenticator ...

Page 27: ...nd enter the IP address of the switch unit to which you want to connect The IP address is used as URL for the browser software to search the device URL http xxx xxx xxx xxx Factory default IP address 192 168 0 2 4 2 Login to the Switch Unit When browser software connects to the switch unit successfully a Login screen is provided for you to login to the device as follows The switch will accept only...

Page 28: ...elated configuration LACP LACP confguration for port link aggregation RSTP RSTP Rapid spanning tree protocol related configuration 802 1X 802 1X authentication related configuration IGMP Snooping IGMP snooping configuration Mirroring Port mirroring related configuration QoS Quality of Service related configuration Storm Control Packet Storm protection control configuration Monitoring Statistics Ov...

Page 29: ...tus Ping Ping command from the switch to other IP devices Maintenance Reboot System Command to reboot the switch Restore Default Command to restore the switch with factory default settings Update Firmware Command to update the switch firmware ConrfigurationFileTransfer Upload and save configuration file Logout Command to logout from the switch management ...

Page 30: ... 30 4 4 System ...

Page 31: ...lbackGateway Default gateway IP address used when DHCP mode is not enabled Management VLAN Set management VLAN information VID VLAN ID configured for web management to the switch CFI CFI value for web reply packets from the switch User priority Priority value for web reply packets from the switch Name Set the system name for this switch unit Password Set new password Inactivity Timeout secs Set ti...

Page 32: ...gs is not zero The switch web http server only accepts tagged management packets matched Management VLAN VID and replies tagged packets with tag composed of Management VLAN VID CFI and User Priority settings to the manage ment host The egress port will also be limited in the member ports of the matched VLAN group Summary of the rules VLAN Function Management VID Switch Embedded Web Server operatio...

Page 33: ...jumbo frame support Power Saving Mode Full all the time Link up saving when link up Link dwon saving when link down Disable disable power saving Port The port number Link Speed and duplex status with green background port is link on Down with red background port is link down ...

Page 34: ...sable 10M Full 100 Half Disable 100M Half 100 Full Disable 100M Full 1000 Full Enable 1000M Full Port 6 Mode Auto negotiation Speed capability Duplex capability Auto speed Enable 1000M Full 1000 Full Disable 1000M Full Flow Control Set port flow control function v set to enable 802 3x pause flow control for ingress and egress Apply Click to apply the configuration change Refresh Click to refresh c...

Page 35: ...freely with no VLAN limitation Port based VLAN Mode Simple configuration for 2 port based VLAN groups Port based VLAN ISP Mode Simple configuration for 5 port based VLAN groups Advance VLAN Mode Full VLAN configuration for port based and Tag based VLAN Apply Click to apply the configuration change Refresh Click to refresh current configuration ...

Page 36: ...n change Refresh Click to refresh current configuration Back Click to go back to upper menu Operation in this mode 1 The member ports of two groups are allowed to overlap 2 The member ports in same group can communicate with other members only 3 No packet tag is examined 4 Areceived packet will not be modified i e tagging or untagging through VLAN operation till it is transmitted ...

Page 37: ...ased VLAN groups are configured as follows auto matically Group 1 member Port 1 Port 6 Group 2 member Port 2 Port 6 Group 3 member Port 3 Port 6 Group 4 member Port 4 Port 6 Group 5 member Port 5 Port 6 Mode Operation 1 The joint port is the shared member port for all groups 2 Two member ports are configured in each group 3 The member ports in same group can communicate with other only 4 No packet...

Page 38: ...tion Ingress Default Tag Click to configure per port Ingress Default Tag settings Ingress Settings Click to configure per port ingress settings Egress Settings Click to configure per port egress settings VLAN Groups Click to configure VLAN group table ...

Page 39: ...ID is used as index for VLAN classification VLAN group table lookup in one of the following conditions 1 Ingress port Tag Aware setting Tag ignore 2 Ingress port Tag Aware setting Tag aware and the received packet is untagged or priority tagged PVID CFI User Priority Ingress Default Tag for the ingress port It is used as the tag for insertion in egress tagging operation in one of the following con...

Page 40: ...xists Enable set to activate tag removal for VLAN tagged packets Disable set to disable tag removal function Drop Untag Drop all untagged packets and priority tagged packets Enable drop untagged packets and priority tagged packets Disable admit untagged packets and priority tagged packets Drop Tag Drop all VLAN tagged packets Enable drop VLAN tagged packets Disable admit VLAN tagged packets Apply ...

Page 41: ... VLAN classification VLAN table lookup The following table lists the index used Ingress Tag Aware setting Received packet type Tag ignore Tag aware Untagged PVID PVID Priority tagged VID 0 PVID PVID VLAN tagged VID 0 PVID Packet tag VID 3 Both Drop Untag and Drop Tag are set to Disable to admit all packets 4 6 3 3 Egress Settings ...

Page 42: ...e this function Untagged VID VID for Untagging Specific VID setting 1 4095 decimal 12 bit VID value Apply Click to apply the configuration change Refresh Click to refresh current configuration Back Click to go back to upper menu The inserted tag sources when Insert Tag Enable are listed as follows Received packet type Tag Aware Tag ignore Tag Aware Tag aware Untagged Ingress Default Tag Ingress De...

Page 43: ...for the packets belong to the VLAN Port 1 6 click to select Source Port Check Check whether the ingress port is the member port of the VLAN Enable set to enable this check the packet is dropped if ingress port is not member port of the VLAN Disable set to disable this check Apply Click to apply the configuration change Refresh Click to refresh current configuration Back Click to go back to upper m...

Page 44: ... group are configured with same VLAN configuration and are in same VLAN group 3 Double Tagged in Advanced VLAN Mode For a received packet Ingress port Keep Tag setting and Egress port Insert Tag setting are enabled at the same time It will cause the packet double tagged when egress Although it is often applied in Q in Q provider bridging application However such condition should be avoided in norm...

Page 45: ... link aggregate Set same value to the ports in same LACP link aggregate Value 1 255 Auto key value is assigned by the system Apply Click to apply the configuration change Refresh Click to refresh current configuration Notes 1 This configuration is used to configure LACP aggregate groups 2 The ports with same key value are in same LACP aggregate group 3 The ports with Auto key are in same LACP aggr...

Page 46: ...w long a bridge should send this message to other bridge to tell I am alive Max Age When the switch is the root bridge the whole LAN will apply this setting as their maximum age time Forward Delay This figure is set by Root Bridge only The forward delay time is defined as the time spent from Listening state moved to Learning state and also from Learning state moved to Forwarding state of a port in...

Page 47: ... listening and learning state because the edge ports cannot create bridging loops in the network Port Path Cost Specifies the path cost of the port that switch uses to determine which port are the forwarding ports the lowest number is forwarding ports the rage is 1 200 000 000 and Auto Auto means a default cost is automatically calculated in RSTP operation based on the port link speed The default ...

Page 48: ...e Unauthorized the port is forced to be in unauthorized state Port State Port 802 1X state 802 1X Disabled the port is in 802 1X disabled state Link Down the port is in link down state Authorized green color the port is in 802 1X authorized state Unauthorized red color the port is in 802 1X unauthorized state Re authenticate Click to perform a manual authentication for the port Force Reinitialize ...

Page 49: ... 49 4 9 1 802 1X Statistics Configuration Description Port X Click to select Port X for the statistics Refresh Click to refresh current counters ...

Page 50: ...l ports Reauthentication Period The period of time after which the connected radius clients must be re authenticated unit second Value 1 3600 EAPtimeout The period of time the switch waits for a supplicant response to an EAP request unit second Value 1 255 Apply Click to apply the configuration change Refresh Click to refresh current configuration ...

Page 51: ...IPMC packets unconditionally Unregistered IPMC Flooding Enable to flooding unregistered IPMC VLAN ID The VID of an existing VLAN IGMPSnooping Enabled Check to enable IGMP snooping function on the associated VID IGMPQuerying Enabled Check to enable IGMP querying function on the associated VID Apply Click to apply the configuration change Refresh Click to refresh current configuration ...

Page 52: ...ort The port is forwarded all packets received on the mirrored ports Mirror Source Select the ports which will be mirrored all received packets to the mirror port Apply Click to apply the configuration change Refresh Click to refresh current configuration ...

Page 53: ...ns are disabled It is also used as default priority class for the received packet when both 802 1p and DSCP classifi cation failed in classification Class 3 Class 0 priority class 802 1p Mapping Click to configure 802 1p mapping tables DSCP Mapping Click to configureDSCP mapping table Service Policy Click to configure per port egress service policy mode Apply Click to apply the configuration chang...

Page 54: ...ty class Mapped priority class for tag m on Port n Class 3 Class 0 Apply Click to apply the configuration change Refresh Click to refresh current configuration Back Click to go back to upper menu Every ingress port has its own 802 1p mapping table The table is referred in 802 1p priority classifica tion for the received packet ...

Page 55: ... user defined DSCP value Class 3 Class 0 All others The other DSCP values not in the seven user defined values are assigned a default priority class Class 3 Class 0 Apply Click to apply the configuration change Refresh Click to refresh current configuration Back Click to go back to upper menu Only one DSCP mapping table is configured and applied to all ports The table is referred in DSCP priority ...

Page 56: ...o 5 3 1 1 Weighted ratio priority Class 3 2 1 0 1 1 1 1 weighted ratio 1 1 1 1 Apply Click to apply the configuration change Refresh Click to refresh current configuration Back Click to go back to upper menu Notes 1 Queue with higher class number has higher priority than queue with lower class number That means Class 3 Class 2 Class 1 Class 0 by default 2 In weighted ratio policies a weighted fair...

Page 57: ...a port Flooded Unicast Rate The rate limit of the flooded unicast packets transmitted on a port The flooded unicast packets are those unicast packets whose destination address is not learned in the MAC address table Apply Click to apply the configuration change Refresh Click to refresh current configuration Notes 1 The unit of the rates is pps packets per second 2 No Limit no protection control ...

Page 58: ...frames transmitted on the port Rx Bytes Total of bytes received on the port Rx Frames Total of packet frames received on the port Tx Errors Total of error packet frames transmitted on the port Rx Errors Total of error packet frames received on the port Clear Click to reset all statistic counters Refresh Click to refresh all statistic counters ...

Page 59: ...59 4 15 Detailed Statistics Button Description Port Click to display the detailed statistics of Port Clear Click to reset all statistic counters Refresh Click to refresh the displayed statistic counters ...

Page 60: ...artner Learning the port is learning by RSTP Forwarding the port is link up and forwarding frames Forwarding the port is link up and forwarding frames and the is the port number of LACP link partner Partner MAC address The MAC address of the link partner at the other end of the LACP aggregate Local Port Aggregated The ports at local end which are aggregated in same LACP group Refresh Click to refr...

Page 61: ...mber Protocol Active yes the port is link up and in LACP operation no the port is link down or not in LACP operation Partner Port Number The port number of the remote link partner Operation Port Key The operation key generated by the system ...

Page 62: ...to tell I am alive Max Age When the switch is the root bridge the whole LAN will apply this setting as their maximum age time Forward Delay This figure is set by Root Bridge only The forward delay time is defined as the time spent from Listening state moved to Learning state and also from Learning state moved to Forwarding state of a port in bridge Topology The current state of the Topology Change...

Page 63: ...omatically computed or explicitly configured Each Edge Port transits directly to the Forwarding Port State since there is no possibility of it participating in a loop P2P Port The current STP port point to point flag A point to point port connects to a non shared LAN media The flag may be automatically computed or explicitly configured The point to point properties of a port affect how fast it can...

Page 64: ...ved The number of Received Querier v1 Reports The number of received v1 reports v2 Reports The number of received v2 reports v3 Reports The number of received v3 reports v2 Leaves The number of received v2 Leave s Refresh Click to refresh the current status VLAN ID The VLAN where the multicast group is found Groups The IP multicast group found Port Members The port members of the IP multicast grou...

Page 65: ... ping commands generated Time Out in secs The time out for a reply in seconds Apply Start the ping command Status The command status Received replies The number of replies received by the system Request time outs The number of requests time out Average Response Time The average reponse time of a ping request in mini seconds ...

Page 66: ...witch and make your current http connection lost 4 22 Update Firmware This page facilitates an update of the firmware controlling the switch Enter the path and file name of a software image file for uploading Browse Click to the location of a software image Upload Click to start uploading After the software image is uploaded a page announces that the firmware update is initiated After about a minu...

Page 67: ...uration file for uploading Browse Click to the location of a configuration file Upload Click to start uploading configuration Download Click to start download of the configuration 4 24 Logout Logout menu is used to perform a logout from the switch management immediately For convenience a login page to the same switch is prompted ...

Page 68: ...rotocol SNMP RFC 1907 Management Information Base for Version 2 of the Simple Network Management Protocol SNMPv2 RFC 1213 Management Information Base for Network Manage ment of TCP IP based internets MIB II RFC 1158 Management Information Base for network manage ment of TCP IP based internets MIB II RFC 1493 Definitions of Managed Objects for Bridges RFC 2863 The Interfaces Group MIB RFC 1573 Evol...

Page 69: ...abled SNMPTrap destination 0 0 0 0 SNMP Read community public SNMPWrite community private SNMPTrap community public Ports Configuration Enable Jumbo Frames Not select disabled Power Saving Mode Full Port Mode Auto for all ports Flow Control v Enable for all ports VLAN Configuration Main Mode VLAN Disable Port based VLAN Mode setting Member Ports Port 1 2 3 4 5 6 for Group 1 None for Group 2 Port b...

Page 70: ...2 VLAN Group 2 Member Ports None VLAN Group 2 Source Port Check Disable VLAN Group 3 VID 3 VLAN Group 3 Member Ports None VLAN Group 3 Source Port Check Disable VLAN Group 4 VID 4 VLAN Group 4 Member Ports None VLAN Group 4 Source Port Check Disable VLAN Group 5 VID 5 VLAN Group 5 Member Ports None VLAN Group 5 Source Port Check Disable VLAN Group 6 VID 6 VLAN Group 6 Member Ports None VLAN Group ...

Page 71: ...0 0 0 0 RADIUS UDP Port 1812 RADIUS Secret None Admin State Force Authorized for all ports Reauthentication Enabled No Reauthentication Period 3600 EAPTimeout 30 Port 1 Port 6 tag 1 Class 0 Port 1 Port 6 tag 2 Class 1 Port 1 Port 6 tag 3 Class 1 Port 1 Port 6 tag 4 Class 2 Port 1 Port 6 tag 5 Class 2 Port 1 Port 6 tag 6 Class 3 Port 1 Port 6 tag 7 Class 3 IGMP Snooping Configuration IGMP Snooping ...

Page 72: ...s 0 Port 1 Port 6 tag 2 Class 1 Port 1 Port 6 tag 3 Class 1 Port 1 Port 6 tag 4 Class 2 Port 1 Port 6 tag 5 Class 2 Port 1 Port 6 tag 6 Class 3 Port 1 Port 6 tag 7 Class 3 QoS DSCP Mapping DSCP 1 Priority 0 Class 0 DSCP 2 Priority 0 Class 0 DSCP 3 Priority 0 Class 0 DSCP 4 Priority 0 Class 0 DSCP 5 Priority 0 Class 0 DSCP 6 Priority 0 Class 0 DSCP 7 Priority 0 Class 0 All others DSCP Class 0 QoS S...

Page 73: ...lass 0 DSCP 6 Priority 0 Class 0 DSCP 7 Priority 0 Class 0 All others DSCP Class 0 QoS Service Policy Port 1 Strict priority Port 2 Strict priority Port 3 Strict priority Port 4 Strict priority Port 5 Strict priority Port 6 Strict priority Storm Control Configuration Broadcast Rate No limit Multicast Rate No limit Flooded Unicast Rate No limit ...

Reviews:

Related manuals for KGD-600-B