background image

                                                               

 

 

37

4.4.3 ACL 

In the navigation bar to select

“fault/safety>ACL”

,Can be applied to port ACL rules and 

Settings to take effect in time 

 

 
 

instruction

 

  The ACL rules are sequenced, row in front of the match will be priority rule. Many, if the 
strategy items operating time is relatively longer.   
Basic principles:   
1, according to the order, as long as there is a meet, will not continue to find   
2,  implied  refused,  if  don't  match,  so  must  match  the  final  implied  refused  entry,  cisco 
default   
3, any only under the condition of the minimum permissions to the user can satisfy their 
demand   
4, don't forget to apply the ACL to the port   
 
 

Configuration example

 

such as: test time is every Monday to Friday 9 to 18 points, set port 1-8 cannot access the 
network   
steps: building ACL time - building ACL rules - is applied to the port   

Summary of Contents for SW-MNG-24GE2GSFP

Page 1: ...SW MNG 24GE2GSFP 24 Port 10 100 1000Mbps 2 Port Gigabit SFP Managed Ethernet Switch User Manual Version 1 1 10 22 2016...

Page 2: ...Switch 10 Chapter 3 How to Login the Switch 11 3 1 Switch to End Node 11 3 2 How to Login the Switch 11 Chapter 4 Switch Configuration 13 4 1 Quickly setting 13 4 2 PORT 16 4 2 1 Basic config 16 4 2...

Page 3: ...2 Mac study and laging 54 4 8 3 Mac address filtering 55 4 9 Snmp config 56 4 9 1 Snmp config 56 4 9 1 1 Snmp config 56 4 9 1 2 Community config 57 4 9 1 3 View config 58 4 9 1 4 Group config 59 4 9 1...

Page 4: ...3 4 10 3 2 Configuration backup 77 4 10 3 3 Restore factory configuration 78 4 10 4 Config save 79 4 10 5 Administrator privileges 80 4 10 6 Info collect 80 Appendix Technical Specifications 82...

Page 5: ...lping solve network bottlenecks that frequently develop as more advanced computer users and newer applications continue to demand greater network resources The switch is easy to install and use It req...

Page 6: ...LED SFP ports SFP1 SFP2 Designed to install the SFP module and connect to the device with a bandwidth of 1000Mbps Each has a corresponding 1000Mbps LED Console port Console Designed to connect with t...

Page 7: ...FP1 SFP2 Green On A device is connected to the port Off A device is disconnected to the port Flashing Sending or receiving data 1 3 2 Rear Panel The rear panel of the Switch contains AC power connecto...

Page 8: ...ist listed OK If any part is lost and damaged please contact your local agent immediately In addition make sure that you have the tools install switches and cables by your hands One Web Smart Ethernet...

Page 9: ...matches the voltage labeled on the Switch To keep the Switch free from lightning do not open the Switch s shell even in power failure Make sure that there is proper heat dissipation from and adequate...

Page 10: ...the equipment rack to mount the Switch on the rack and tighten it Figure 6 Rack Installation 2 1 3 Power on the Switch The Switch is powered on by the AC 100 240V 50 60Hz internal high performance pow...

Page 11: ...o the computer after installing network card driver please connect one end of the twisted pair to RJ 45 jack of your computer the other end will be connected to any RJ 45 port of the Switch the distan...

Page 12: ...d management login you can configure your computer s IP address manually to log on to the Switch The default settings of the Switch are shown below Parameter Default Value Default IP address 192 168 2...

Page 13: ...Login Windows 5 Switching language to english Enter the Username and Password The factory default Username is admin and Password is admin and then click login to log in to the Switch configuration win...

Page 14: ...ormation for switch system such as memory software version The middle shows the switch s current link status Green squares indicate the port link is up while black squares indicate the port link is do...

Page 15: ...sage on the interface is considered belongs to the VLAN Obviously the interface of the default VLAN ID PVID in the IEEE 802 1 Q VLAN ID is the Native VLAN At the same time send belong to Native VLAN f...

Page 16: ...tep button into other settings such as manage ip address set as 192 168 2 11 device name set as switch 123 default gateway with the dns server set as 172 16 1 241 Use 192 168 2 11 to log in set a new...

Page 17: ...the navigation bar to select PORT basic config For panel port to port described port speed port status working mode flow control cross line order configuration the following picture parameter descrip...

Page 18: ...ntrol should be negotiated will close negotiated close is to set port speed rate and working mode Set the port rate more than actual rate of port the port will be up Configuration example Such as The...

Page 19: ...ur own port and with members of other groups instructions Open the port of the ARP check function the port of the important device ARP the port of the VLAN MAC function and the monitor port in the por...

Page 20: ...he following picture parameter description parameter description Source port To monitor the port in and out of flow Destination port Set destination port All packets on the source port are copied and...

Page 21: ...the navigation bar to select PORT port rate limit To port output input speed limit the following picture parameter description parameter description Input speed limit Set port input speed Output speed...

Page 22: ...to 3200 KB s 4 2 5 Storm control In the navigation bar to select PORT Storm control To port storm control config the following ficture parameter description parameter description Broadcast suppressio...

Page 23: ...ion example Such as should be forwarded to the port 1 8 of all kinds of packet forwarding rate is 5000 KB s 4 2 6 Port isolation In the navigation bar to select PORT port isolation ports are isolated...

Page 24: ...solated Ports that have been added to the aggregate port aren t also capable of being a destination port and source port destination port and source port cannot be the same Configuration example Such...

Page 25: ...arameter description VLAN ID VLAN number 24GE default VLAN 1 VLAN name VLAN mark VLAN IP address Manage switch ip address instructions Management VLAN the default VLAN cannot be deleted Add ports to a...

Page 26: ...n the interface is considered belongs to the VLAN Obviously the interface of the default VLAN ID PVID in the IEEE 802 1 Q VLAN ID is the Native VLAN At the same time send belong to Native VLAN frame o...

Page 27: ...udge whether there is a VLAN information if there is no play in port PVID exchanged and forwarding if have whether the Hybrid port allows the VLAN data into if can be forwarded or discarded untag on p...

Page 28: ...ed 10 then switches at this time to remove packet VLAN10 tag in the form of ordinary package sent to pc2 pc1 p2 is VLAN10 walking at this time Again to analyze pc2 gave pc1 package process data from t...

Page 29: ...kets ban kangaroo DHCP server the following picture instructions DHCP trusted port configuration select the port as a trusted port Prohibit DHCP for address select the port and save you can disable th...

Page 30: ...29 Set the connection router 10 ports for trust then 12 port is set to the prohibit 3 Verify source mac F0 DE F1 12 98 D2 set server ip address to 192 168 2 1 4 Set option82 information...

Page 31: ...avigation bar to select fault safety anti attack anti dhcp attack Open the anti DOS attack function intercept Land attack packets illegal TCP packets to ensure that the device or server to provide nor...

Page 32: ...t fault safety anti attack ip source guard Through the source port security is enabled on port forwarding the packet filter control prevent illegal message through the port thereby limiting the illega...

Page 33: ...n the navigation bar to select fault safety anti attack anti three bind Automatically detect the port based IP address MAC address of the mapping relationship and then realize the function of a key bi...

Page 34: ...ing to enable the switch to open And if you want to access shall be binding and switch the IP address of the same network segment Configuration example Such as the binding to make first can open must...

Page 35: ...host whether to arrive The following picture parameter description parameter description destination IP address Fill in the IP address of the need to detect Timeout period Range of 1 to 10 Repeat num...

Page 36: ...ect to the destination through the following picture parameter description instruction the function is used to detect more is up to and reach the destination path If a destination unreachable diagnose...

Page 37: ...as PING connect the IP address of the PC 4 4 2 3 Cable testing In the navigation bar to select fault safety channel detection cable tracert testing Can detect connection device status the following p...

Page 38: ...s 1 according to the order as long as there is a meet will not continue to find 2 implied refused if don t match so must match the final implied refused entry cisco default 3 any only under the condit...

Page 39: ...38...

Page 40: ...er description parameter description Region name Configure the region name Revision level Parameter configuration revision level Instance ID Select configuration instance ID VLAN ID Mapping of the VLA...

Page 41: ...40 4 5 2 MSTP bridge In the navigation bar to select MSTP MSTP bridge Can be related to bridge port configuration the following picture parameter description...

Page 42: ...faults to 128 you must enter multiple of 16 the range of 0 240 Path cost Configure port costs Port fast Select configuration state Auto ege Select configuration state Point to point Select configurati...

Page 43: ...port configuration select the created instance set priority port configuration is not online on line configuration will only take effect can click on the view the current configuration button to view...

Page 44: ...ar to select DHCP relay you can set to the DHCP relay and option82 4 6 1 DHCP relay In the navigation bar to select DHCP relay Open the DHCP relay function set up and view the relay server IP address...

Page 45: ...HCP message to be delivered in the form of unicast to configure on the server The DHCP server to IP and switches in the same network segment will only take effect Configuration example Such as setting...

Page 46: ...tring length is 3 63 Proxy remote Configuration ASCII remote id string value the length of the range of 1 63 IP address Decimal IP address instruction Switches relay information to the DHCP server wil...

Page 47: ...ation bar to select QoS you can set to the Remark queue config and mapping the queue 4 7 1 Remark In the navigation bar to select QoS Remark According to the rules for port traffic bag tag or queue ma...

Page 48: ...as choice goal Mac just check the data destination Mac address is in accordance with the rules value Set the value of matching such as choice goal Mac for HH HH HH HH HH HH Choose port to config The a...

Page 49: ...he navigation bar to select QoS queue config Can be set up queue scheduling policy the following picture parameter description parameter description Scheduling strategy Can choose four kinds of modes...

Page 50: ...e Such as set the scheduling strategy for WRR weight value respectively 10 11 12 12 14 15 16 17 4 7 3 Mapping the queue 4 7 3 1 Service class queue mapping In the navigation bar to select QoS mapping...

Page 51: ...Differential service can be mapped to the corresponding service categories the following picture parameter description parameter description Server list DSCP field has seven 0 63 is divided into four...

Page 52: ...s mapping Port can be mapped to the corresponding service categories the following picture parameter description parameter description Port Select the port number 0 24 Service ID Mapped to the service...

Page 53: ...52 Such as port 4 5 6 respectively cos4 cos5 cos6 4 8 Address table In the navigation bar to select Address table you can set to MAC add and delete MACstudy and aging and MAC address filtering...

Page 54: ...iption parameter description Clear Mac Can choose to clear the multicast Mac address clear dynamic unicast Mac address clear static unicast Mac address clear the specified Mac address Mac address tabl...

Page 55: ...static Mac 2 clear port 6 static Mac addresses 4 8 2 Mac study and laging In the navigation bar to select address table Mac study and laging Can be set up port Mac address study limit and Mac address...

Page 56: ...c address of the port equipment after 2 minutes disappear automatically from the Mac address table 4 8 3 Mac address filtering In the navigation bar to select address table Mac address table Can be fi...

Page 57: ...e filter in the table 4 9 Snmp config In the navigation bar to select Snmp you can set to the Snmp config and Rmon config 4 9 1 Snmp config 4 9 1 1 Snmp config In the navigation bar to select Snmp Snm...

Page 58: ...lowing picture parameter description parameter description group Community string is equal to the NMS and Snmp agent communication between the password Access authority Read only specify the NMS Snmp...

Page 59: ...w name Wiew mane include Indicate the MIB object number contained within the view exclude Indicate the MIB object son number was left out of view MIB subtree OID View the associated MIB object is a nu...

Page 60: ...al No authentication encryption this group of users messages don t need to verify data transmission also does not need to be kept secret Both authentication and encryption this group of users need to...

Page 61: ...he data don t need to confidential No authentication encryption this group of users messages don t need to verify data transmission also does not need to be kept secret Both authentication and encrypt...

Page 62: ...o groups of users the user will be used for Snmpv3 connection Configuration example Such as new view 123 the newly built group group1 new users user1 4 9 1 6 Trap In the navigation bar to select Snmp...

Page 63: ...LinkDown equipment of cold start restart when power supply drop warm start a warm restart and Rmon set port port statistical fluctuation threshold Configuration example Such as setting hoset 192 168 2...

Page 64: ...aracters of a string instruction At the time of configuration Rmon Snmp functions must be open otherwise the prompt dialog box will appear Configuration example Such as set up monitoring Ethernet port...

Page 65: ...s in seconds owner Set the table creator range 1 30 characters of a string instruction At the time of configuration Rmon Snmp functions must be open otherwise the prompt dialog box will appear Configu...

Page 66: ...lect Snmp Rmon config alarm group define alarm group the following picture parameter description parameter description index The alarm list items index number value range is 1 65535 Static table Stati...

Page 67: ...ues The alarm threshold lower limit Set the lower limit parameter values Above below the threshold limit of events Upper lower limit reached for each event owner Set the table creator ownername for 1...

Page 68: ...bar to select SYSTEM system config System settings Basic information set switch the following picture parameter description parameter description Device name switch name Manage VLAN Switches use VLAN...

Page 69: ...agement VLAN should first created vlan 2 the VLAN Settings and set a free port in the VLAN 2 2 insert the PC interface 9 or 10 ports set up the management IP for 192 168 2 12 device name is yoyo timeo...

Page 70: ...69 3 use 192 168 1 12 logging in sets the system time 4 10 1 2 System restart In the navigation bar to select SYSTEM system config system restart equipment can be restarted the following picture...

Page 71: ...ease wait patiently The page will be refreshed automatically after device restart Configuration example Such as click restart button 4 10 1 3 Password change In the navigation bar to select SYSTEM sys...

Page 72: ...be reset in the console switch config password admin New Password 3456 Confirm Password 3456 Configuration example Such as amend the password to 1234 4 10 1 4 SSH login In the navigation bar to selec...

Page 73: ...cture instruction Configure the user to be able to switch through the Telnet login device Configuration example Such as Telnet open PC Telnet functiono open you can log in 4 10 1 6 System log In the n...

Page 74: ...Enter the required query of characters instruction Open log switch set up the syslog server system log will automatically be pushed to the server Configuration example Such as 1 the error log informat...

Page 75: ...he following picture instruction 1 please confirm that the upgraded version of the same model and the same model 2 in the upgrade process you may encounter flash to make the page is temporarily unable...

Page 76: ...g picture instruction Import process can not be closed or refresh the page or import will fail After the introduction of configuration to enable the new configuration please in this page Restart devic...

Page 77: ...76 2 import configuration 3 backup...

Page 78: ...r to select SYSTEM config management configuration backup you can configure backup file the following picture instruction Operating this page should be in the current configuration page first the back...

Page 79: ...e factory configuration the following picture instruction Restore the factory configuration will delete all the current configuration If you have any useful configuration the current system can lead t...

Page 80: ...ave you can save current configuration the following picture instruction Save settings will delete all default configurations If there are useful configurations clickbackup Configurationsbefore save t...

Page 81: ...s page is used to manage users and visitors The user can log in the Web management system of equipment for routine maintenance In addition to the admin and user can add up to five users Ordinary users...

Page 82: ...81 instruction collect useful infomation it may take a few moment Configuration example Such as click on collect button...

Page 83: ...10 100 1000Mbps Auto Negotiation ports 2 x SFP ports 1 x Console port Transfer Method Store and Forward Switching Capacity 52G MAC Address Learning Automatically learning automatically update 8K Table...

Page 84: ...83 www morrelltelecom com sales morrelltelecom com morrelltelecom...

Reviews: