Moxa Technologies EDS-510E Series User Manual Download Page 91

 

 

Moxa Managed Ethernet Switch (UI_2.0_FW_5.x)  User Manual 

91

 

Port Access Control Table 

 

The port status will be indicated  as 

authorized

 or 

unauthorized

Broadcast Storm Protection 

Broadcast Storm Protection is only supported by the EDS-G508E, EDS-G512E-4GSFP, EDS-G516E-4GSFP, 
IKS-6726A/6728A/6728A-8PoE, EDS-G512E-8PoE,  EDS-518E, EDS-528E, and EDS-P506E  Series. 

 

Broadcast Storm Protection 

Setting 

Description 

Factory Default 

Unchecked 

Broadcast storm protection is not activated. 

Checked 

Checked 

Broadcast storm protection is activated. In this case, you may 
check either one or both of Include Multicast Packet and 
Include Unknown Unicast Packet. 

Include Multicast Packet 

When checked, the switch will discard Multicast packets if the Multicast traffic is over the Multicast packet 
limit. 

 

NOTE 

 

For IKS-6726A/6728A/6728A-8PoE, EDS-518E, EDS-528E, and EDS-P506E  Series, only ‘Known Multicast 
Packet’ can be discarded if the ‘Include  Multicast  Packet’ feature is checked and traffic exceeds the limit. 

 

Summary of Contents for EDS-510E Series

Page 1: ...this user manual only applies to products using firmware version 5 0 or higher EDS 510E EDS 518E EDS 528E EDS G508E EDS G512E EDS G516E EDS P506E 4PoE EDS G512E 8PoE IKS 6726A IKS 6728A IKS 6728A 8PoE...

Page 2: ...ent as is without warranty of any kind either expressed or implied including but not limited to its particular purpose Moxa reserves the right to make improvements and or changes to this manual or to...

Page 3: ...ual LAN VLAN Concept 49 Sample Applications of VLANs Using Moxa Switches 51 Configuring a Virtual LAN 52 VLAN Name Setting 54 QinQ Settings 55 VLAN Table 55 Port 56 Port Settings 56 Port Status 57 Lin...

Page 4: ...2 SNMP Read Write Settings 103 Trap Settings 104 Industrial Protocols 108 Diagnostics 108 LLDP 108 Ping 109 Port Mirroring 110 Monitoring 111 CPU Memory Utilization 111 Statistics 112 Fiber Digital Di...

Page 5: ...initial installation process for a Moxa switch Moxa switches provide three interfaces to access the configuration settings USB console interface command line interface and web console interface Chapt...

Page 6: ...he Internet USB Console Configuration 115200 None 8 1 VT100 NOTE A Moxa switch allows multi session connections up to 6 by connecting to the web console and another console serial or Telnet at the sam...

Page 7: ...r Ports select the COM port that is being used for the console connection Set the other fields as follows 115200 for Baud Rate 8 for Data Bits None for Parity and 1 for Stop Bits 4 On the Terminal tab...

Page 8: ...fault the password assigned to the Moxa switch is moxa Be sure to change the default password after you first log in to help keep your system secure 7 The Main Menu of the Moxa switch s USB console sh...

Page 9: ...onsole your PC host and the Moxa switch must be on the same logical subnet NOTE When connecting to the Moxa switch s Telnet or web console first connect one of the Moxa switch s Ethernet ports to your...

Page 10: ...field blank and press Enter 4 The Main Menu of the Moxa switch s Telnet console should appear 5 In the terminal window select Preferences from the Terminal menu on the menu bar 6 The Terminal Preferen...

Page 11: ...a switch s Telnet or web console first connect one of the Moxa switch s Ethernet ports to your Ethernet LAN or directly to your PC s Ethernet port You may use either a straight through or cross over E...

Page 12: ...ppear Use the folders in the left navigation panel to navigate between different pages of configuration options Disabling Telnet and Browser Access If you are connecting the Moxa switch to a public ne...

Page 13: ...The Telnet and web consoles can be opened over an Ethernet LAN or the Internet The web console is the most user friendly interface for configuring a Moxa switch In this chapter we use the web console...

Page 14: ...pplications of different units Example factorySwitch1 none NOTE The Switch Name field follows the PROFINET I O naming rule The name can only include any of these characters a z A Z 0 9 and the name ca...

Page 15: ...nts including establishing activating modifying disabling and removing accounts There are two levels of configuration access admin and user Accounts with admin authority have read write access of all...

Page 16: ...e Setting Description Factory Default User Name Max of 30 characters User Name None Password Password for the user account between 4 and 16 characters None Modifying an Existing Account Select an exis...

Page 17: ...sword is entered The account password policy requires passwords to be of a minimum length and complexity with a strength check If Account Login Failure Lockout is enabled you will need to configure th...

Page 18: ...twork with multiple segments the switch must be configured with a Global Unicast address Get IP From Setting Description Factory Default DHCP The Moxa switch s IP address will be assigned automaticall...

Page 19: ...mal values One double colon may be used in the address to indicate the appropriate number of zeros required to fill the undefined fields None IPv6 Global Unicast Address Setting Description Factory De...

Page 20: ...rmat None Time Zone Setting Description Factory Default Time zone Specifies the time zone which is used to determine the local time offset from GMT Greenwich Mean Time GMT Greenwich Mean Time Daylight...

Page 21: ...tween the NTP client and NTP server NTP Authentication Settings Setting Description Factory Default Checked Enable NTP Authentication Unchecked Unchecked Disable NTP Authentication Authentication Key...

Page 22: ...y ID that is used to be authorized Null Clock Source is from SNTP SNTP Client Settings Setting Description Factory Default 1st Time Server The IP or domain address e g 192 168 1 1 time stdtime gov tw...

Page 23: ...t http ieee1588 nist gov switch htm An Ethernet switch potentially introduces multi microsecond fluctuations in the latency between the 1588 grandmaster clock and a 1588 slave clock Uncorrected these...

Page 24: ...P2P BC Operates as a peer to peer IEEE 1588 v2 boundary clock SyncInterval sets the synchronization message time interval Setting Description Factory Default 0 1 2 3 or 4 0 1 s 1 2 s 2 4 s 3 8 s or 4...

Page 25: ...S 6700A and EDS P506E Series do not support the 802 3 setting Role Setting Description Factory Default Member or Master Set this switch to be the Member or Grand Master Member PTP Status Indicates the...

Page 26: ...Start Power is cut off and then reconnected Warm Start The Moxa switch is rebooted such as when network parameters are changed IP address subnet mask etc Configuration Change Any configuration item h...

Page 27: ...en changed Configuration is Imported When the configuration is successfully imported SSL Certification is Imported When SSL Certification is successfully imported Fiber Check Warning If the correspond...

Page 28: ...on Trap The EDS E series will send a notification to the trap server when an event is triggered E Mail The EDS E series will send a notification to the email server defined in the Email Setting Syslog...

Page 29: ...size Action Setting Description Factory Default Overwrite The Oldest Event Log The oldest event log will be overwritten when the event log exceeds 1000 records Overwrite The Oldest Event Log Stop Reco...

Page 30: ...mplete the email settings you should first click Apply to activate those settings and then press the Test button to verify that the settings are correct NOTE Auto warning e mail messages will be sent...

Page 31: ...tart Configuration change activated Power 1 or 2 transition Off to On or On to Off Authentication fail Password change Redundancy protocol topology change Master setting mismatch ABC 02 status Web log...

Page 32: ...ss groups which are selected from the drop down list Drop Down List ALL Select this item to show all of the Moxa switch s MAC addresses ALL Learned Select this item to show all of the Moxa switch s Le...

Page 33: ...moxa com 2 Browse for the rom file and then click the Upgrade button TFTP Server 1 Enter the TFTP Server s IP address 2 Input the firmware file name rom and click the Upgrade button Auto Backup Confi...

Page 34: ...ick the Backup Restore button Auto Backup Configurator ABC 02 1 Click Backup to save the configuration file to the ABC 02 The file will be saved in the ABC 02 s Moxa folder as a ini file e g Sys ini N...

Page 35: ...02 when configuration change checkbox and then click Apply This function is disabled by default The ABC 02 is capable of backing up switch configuration files automatically While the ABC 02 is plugge...

Page 36: ...es the following information Index An event index assigned to identify the event sequence Bootup Number This field shows how many times the Moxa switch has been rebooted or cold started Date The date...

Page 37: ...led Turbo Ring v2 protocol will be enabled when the DIP switch is moved to the ON position NOTE If the 4th DIP switch Turbo Ring is configured to ON you will not be able to disable the Turbo Ring DIP...

Page 38: ...rge part to the reliability provided by PoE Ethernet switches that supply the power to Powered Devices PD when AC power is not available or is too expensive to provide locally Power over Ethernet can...

Page 39: ...rface gives users control over the system s PoE power output PoE power threshold PoE port configuration and PD failure check The PoE settings page is divided into three parts PoE System Configuration...

Page 40: ...oE power transmission to a PD Enable Disable Disables PoE power transmission to a PD PoE power management Mode Setting Description Factory Default Allocated Power If a powered device is connected that...

Page 41: ...tance range is 17 k to 29 k and the power allocation of the port is automatically set to 36 W Force 2 Pair Force 36W only for EDS P506E 4PoE Provides power output to non 802 3 af at PDs The acceptable...

Page 42: ...s When the PoE measured power exceeds the assigned limit the switch will disable the PoE port with the lowest priority Setting Description Factory Default 1 to number of PoE ports The smaller the numb...

Page 43: ...Checked Select those days on which you would like the port to be enabled you will then be able to modify the StartTime and EndTime Disable Unchecked The port will not provide PoE power on days that a...

Page 44: ...its 802 3 af 350 mA 802 3 at 600 mA High Power 720 mA Force 600 mA PoE PD Failure Check When the switch does not receive a PD response after the defined period Over Measured Power Limitation When the...

Page 45: ...f 802 3 at or legacy 2 pair PD 4 Pair 60W A 4 Pair PD that uses all 8 pins of the RJ 45 connector to receive PoE output Classification Item Description N A The port is not classified 0 to 4 Class 0 to...

Page 46: ...4 Pair PD the system suggests selecting 4 Pair High Power 60W mode Select 2 Pair Force Mode or 4 Pair Force Mode When configuring at 4 Pair PoE Mode and detecting higher lower resistance or higher ca...

Page 47: ...a legacy PD Potential Legacy PD In 802 3af at or High Power mode the system has detected a potential legacy PD PoE power is not being provided Port Description Item Description Status Indicates if th...

Page 48: ...er Status shows a graph of Sum of measured power Sum of allocated power and Max of allocated power Sum of measured power in green shows the total measured power of all PDs Sum of allocated power in bl...

Page 49: ...flexible than traditional networks Using VLANs also provides you with three other benefits VLANs ease the relocation of devices on networks With traditional networks network administrators spend much...

Page 50: ...a single VLAN it can be an untagged member but if the port needs to be a member of multiple VLANs a tagged membership must be defined A typical host e g clients will be an untagged member of one VLAN...

Page 51: ...it should be configured as an Access Port with PVID 5 Port 7 connects a single untagged device and assigns it to VLAN 4 it should be configured as an Access Port with PVID 4 After the application is p...

Page 52: ...sed to configure the settings for individual ports Quick Setting Panel The EDS E series provides a Quick Setting Panel that administrators can use to quickly configure VLAN settings for single ports o...

Page 53: ...PVID Setting Description Factory Default 1 to 4094 Sets the default VLAN ID for untagged devices connected to the port 1 Tagged VLAN Setting Description Factory Default 1 to 4094 This field will be ac...

Page 54: ...ximum VLAN ID equals the number of switch ports In the following example all of the ports are assigned to VLAN 1 NOTE Port Based VLAN is supported by EDS series switches not including the EDS 728 828...

Page 55: ...ws users to tag double VLAN headers into a single Ethernet frame TPID Setting Description Factory Default 8100 to FFFF Assign the TPID of the second VLAN tag 8100 QinQ Enable Setting Description Facto...

Page 56: ...type Displays the media type for each module s port N A Description Setting Description Factory Default Max 63 characters Specifies an alias for the port to help administrators differentiate between...

Page 57: ...net device has trouble auto negotiating for port type MDIX NOTE For the Gigabit ports MDI MDIX is only Auto mode Port Status The following table shows the status of each port including the media type...

Page 58: ...ured as 100BaseTX and they are operating in full duplex mode the potential bandwidth of the connection will be up to 1 6 Gbps This means that users can double triple or quadruple the bandwidth of the...

Page 59: ...ol Protocol Static NOTE Trunk groups could also be selected as the redundant ports for Turbo Ring V2 or Turbo Chain Trunking Status The Trunking Status table shows the Trunk Group configuration status...

Page 60: ...acket has a multicast group address in the destination address field of the packet s IP header Benefits of Multicast The benefits of using IP multicast are It uses the most efficient sensible method t...

Page 61: ...onging to the same group Multicast Filtering and Moxa s Industrial Rackmount Switches There are three ways to achieve multicast filtering with a Moxa switch IGMP Internet Group Management Protocol Sno...

Page 62: ...ffic for the multicast groups When the router forwards traffic for the multicast group to the LAN or VLAN the switches only forward the traffic to ports that received a report packet IGMP version 3 su...

Page 63: ...LAN is enabled IGMP Snooping Setting Enable IGMP Snooping Global Setting Description Factory Default Enable Disable Select the Enable IGMP Snooping checkbox near the top of the window to enable the IG...

Page 64: ...l connect to the multicast routers These ports will receive all multicast packets from the source This option is only active when IGMP Snooping is enabled Disabled NOTE If a router or layer 3 switch i...

Page 65: ...eives the multicast stream or the port the multicast stream is forwarded to Version Displays the IGMP Snooping version Filter Mode Indicates that the multicast source address is included or excluded D...

Page 66: ...y Default Integer Type the MAC address in the MAC Address field to specify a static multicast address None Member Port Setting Description Factory Default Select Deselect Select the appropriate checkb...

Page 67: ...rt This multicast address is learned by GMRP Multicast Filtering Behavior Multicast Filtering Behavior supports two options Forward Unknown and Filter Unknown Note Only supported by the EDS 518E EDS 5...

Page 68: ...al applications Provide predictable throughput for multimedia applications such as video conferencing or voice over IP and minimize traffic delay and jitter Improve network performance as the amount o...

Page 69: ...d consequently traffic will only contain 802 1p priority markings if the network is configured with VLANs and VLAN tagging The traffic flow through the switch is as follows A packet received by the Mo...

Page 70: ...lied to the four priorities This approach prevents the lower priority frames from being starved of opportunity for transmission with only a slight delay to the higher priority frames Weight Fair Stric...

Page 71: ...er can enable these classifications individually or in combination For instance if a hot higher priority port is required for a network design TOS DSCP Inspection and Cos Inspection can be disabled Th...

Page 72: ...User Manual 72 Priority Mapping Type 2 CoS Value and Priority Queues Setting Description Factory Default 0 to 7 Maps different CoS values to 8 different egress queues CoS 0 0 CoS 1 1 CoS 2 2 CoS 3 3 C...

Page 73: ...y unpredictable faults Traffic Rate Limiting Settings There are four types of bandwidth management settings depending on which model of switch you are using Type Model Type 1 EDS 510E Type 2 EDS G508E...

Page 74: ...of max throughput for all packets from the following options Not Limited 3 5 10 15 25 35 50 65 85 Unlimited Rate Limiting Port Disable Setting Description Factory Default Port disable duration 1 6553...

Page 75: ...s packets Drop Packet Port Disable When the ingress packets exceed the ingress rate limit the port will be disabled for a certain period During this period all packets from this port will be discarded...

Page 76: ...ng Description Factory Default Drop Packet Set the max ingress egress rate limit for ingress egress packets Drop Packet Port Disable When the ingress packets exceed the ingress rate limit the port wil...

Page 77: ...464 7441 14881 22322 37203 52084 74405 Unlimited NOTE The Port Disable function of Rate Limiting is for multicast packets and broadcast packets Type 4 For Type 4 the Control Mode setting on the Rate L...

Page 78: ...ons Unlimited 128K 256K 512K 1M 2M 4M 8M 10 100Mbps 15 150Mbps 25 250Mbps 35 350Mbps 50 500Mbps 65 650Mbps 85 850Mbps Limit Broadcast 8M Limit Broadcast Multicast Flooded Unicast Limit Broadcast Multi...

Page 79: ...ted 4464 7441 14881 22322 37203 52084 74405 Unlimited Security Security can be categorized into two levels the user name password level and the port access level Moxa switches provide many kinds of se...

Page 80: ...the appropriate checkboxes to enable Moxa Service NOTE Moxa Service is only for Moxa network management software suite TCP Port 4000 UDP Port 4000 Enable Moxa Service Encrypted Setting Description Fa...

Page 81: ...o 192 168 1 1 only Grant access to any host on a specific subnetwork For example enter IP address 192 168 1 0 with netmask 255 255 255 0 to allow access to all IPs on the subnet defined by this IP add...

Page 82: ...rd PKCS 12 certificate file 2 Enter the Import Password and click Import 3 The SSL certificate is updated Regenerate SSL Certificate Setting Description Factory Default Select Deselect Enable the SSL...

Page 83: ...local database 2 RADIUS Local Check RADIUS database first If the RADIUS server is not reachable then the switch will check the local database 3 TACACS Only check TACACS database 4 RADIUS Only check th...

Page 84: ...and responds to the requests from the switch Authentication Server The server that performs the actual authentication of the supplicant Authenticator Edge switch or wireless access point that acts as...

Page 85: ...ase as the authentication database Re Auth Global Setting Description Factory Default Enable Disable Select enable to require re authentication of the client after a preset time period of no activity...

Page 86: ...AC Authentication Bypass with the Local database None Description Max of 30 characters Description for the Local User Database None NOTE The user name for the IEEE 802 1X Local Database is not case se...

Page 87: ...thentication Bypass column to enable MAC Authentication Bypass for one or more ports Deselect NOTE If RADIUS Server is case sensitive use lower case characters for the username and password NOTE MAC A...

Page 88: ...to access a port after the maximum number of MAC addresses have already been learned The total number of allowed MAC addresses cannot exceed 1024 NOTE The whitelist or blacklist of the EDS G500E Seri...

Page 89: ...limit is reached and the port receives a packet with an unknown MAC address unlearned by the port the packet will be discarded Disable Enable When the port limit is reached and the port receives a pa...

Page 90: ...None MAC Address Sticky Port Number Setting Description Factory Default Port Number Associates the static address to a dedicated port None VID Setting Description Factory Default VLAN ID Associates th...

Page 91: ...escription Factory Default Unchecked Broadcast storm protection is not activated Checked Checked Broadcast storm protection is activated In this case you may check either one or both of Include Multic...

Page 92: ...wing layer 2 switches EDS 518E EDS 528E EDS G508E EDS G512E EDS G516E EDS G512E 8PoE the IKS Series and the ICS Series Layer 2 switches only support Ingress ACL Access control lists ACLs increase the...

Page 93: ...ules In other words Access Control Lists have Priority Index as an attribute to define the priority in the web configuration console There are two types of settings for an ACL list settings and rule s...

Page 94: ...d Note that the ACL ID is not unique with respect to the profile name The ID changes when swapping the priority of different access control profiles The maximum Priority Index number is 16 Name You ca...

Page 95: ...you would like to edit based on the ACL ID and then set up the rule content and ingress egress ports After configuring click the Add button to add the rule to the list Finally click Apply to activate...

Page 96: ...ranges to filter It allows checking the source or destination of the packet Choose Any if you do not need to use this criteria IP Protocol Select the type of protocols to be filtered Moxa provides IC...

Page 97: ...Moxa Managed Ethernet Switch UI_2 0_FW_5 x User Manual 97 MAC Based Layer 2 Device NOTE MAC based ACL is not available on the EDS 510E Series...

Page 98: ...ific MAC address ranges to filter It allows checking the source or destination of the packet Choose Any if you do not need to use this criterion Ethernet Type Select the type of Ethernet protocol to f...

Page 99: ...select Port or ACL ID and all the rules will be displayed in the table DHCP IP Port Binding Designated IP Address Setting Description Factory Default IP Address Set the desired IP of connected devices...

Page 100: ...ons Circuit ID and Remote ID which define the relationship between the end device IP and the DHCP Option 82 server The Circuit ID is a 4 byte number generated by the Ethernet switch a combination of p...

Page 101: ...tion 82 function Disable Assign Remote ID by Setting Description Factory Default IP Uses the switch s IP address as the remote ID sub IP MAC Uses the switch s MAC address as the remote ID sub IP Clien...

Page 102: ...hentication V1 V2c Write Read Community Community string No Uses a community string match for authentication SNMP V3 No Auth No No Uses an account with admin or user to access objects MD5 or SHA Authe...

Page 103: ...ccount to access objects without authentication No MD5 Auth Authentication will be based on the HMAC MD5 algorithms 8 character passwords are the minimum requirement for authentication No SHA Auth Aut...

Page 104: ...MP Trap V1 Trap V2c Host IP Address 1 Setting Description Factory Default IP or name Specifies the IP address or name of the primary trap server used by your network None 1st Trap Community Setting De...

Page 105: ...on the HMAC MD5 algorithms 8 character passwords are the minimum requirement for authentication SHA Auth Authentication will be based on the HMAC SHA algorithms 8 character passwords are the minimum r...

Page 106: ...Factory Default IP or name Specifies the IP address or name of the primary trap server used by your network NA 1st Trap Community Setting Description Factory Default Max 30 characters Specifies the co...

Page 107: ...on the HMAC MD5 algorithms 8 character passwords are the minimum requirement for authentication SHA Auth Authentication will be based on the HMAC SHA algorithms 8 character passwords are the minimum r...

Page 108: ...t tools for administrators to diagnose network systems LLDP Ping and Port Mirror LLDP Overview LLDP is an OSI Layer 2 protocol defined by IEEE 802 11AB LLDP standardizes the self identification advert...

Page 109: ...vice Neighbor Port The port number of the neighbor device Neighbor Port Description A textual description of the neighbor device s interface Neighbor System Hostname of the neighbor device Ping The Pi...

Page 110: ...EDS 510E EDS 518E EDS 528E EDS P506E 4PoE IKS 6726A IKS 6728A IKS 6728A 8PoE IKS G6524A IKS G6824A ICS G7526A ICS G7826A ICS G7528A ICS G7828A ICS G7748A ICS G7848A ICS G7750A ICS G7850A ICS G7752A I...

Page 111: ...itor only those data packets being sent out through Moxa s switch TX RX Select this option to monitor data packets both coming in and being sent out through Moxa s switch Mirror Port Select the number...

Page 112: ...mbined data transmission activity of all of the Moxa switch s 18 ports Click one of the four options Total Packets TX Packets RX Packets or Error Packets to view transmission activity of specific type...

Page 113: ...ical display of the individual port activity that can be viewed with the Console Monitor function discussed above The All Ports option shows three vertical bars for each port The height of the bar rep...

Page 114: ...ugging Two different categories of Moxa switches support Fiber Digital Diagnostics Monitoring functions SFP DDM and Fiber Check Type Models Supported SFP DDM IKS 6726A IKS 6728A IKS 6728A 8PoE IKS G65...

Page 115: ...shold of light being transmitted into the fiber optic cable Tx power dBm Min The Min threshold of light being transmitted into the fiber optic cable Rx power dBm Current The current amount of light be...

Page 116: ...rtain tolerances exist between real data and measured data Event Log The Event Log Table displays the following information Index Event index assigned to identify the event sequence Bootup Number This...

Page 117: ...and the availability of a host by pinging it The status of tracking up down is the result of the monitored target The tracking function can bind a tracking entry and perform a specific action accordi...

Page 118: ...interface 1 000 ms Up Delay ms Setting Description Factory Default 0 to 100 000 ms The threshold that the status of interface tracking changes from down to up when the status of the monitored port or...

Page 119: ...cking ID of ping tracking No NOTE The tracking ID has to be unique IP Address Setting Description Factory Default Valid IP address The monitored IP address No Interval ms Setting Description Factory D...

Page 120: ...f the logic tracking entry is up Otherwise the status of the logic tracking entry is down With operator OR if all the statuses of the entries in the Logical List are down the status of the logic track...

Page 121: ...acking Select this item to show all the interface tracking information Ping Tracking Select this item to show the ping tracking information Logical Tracking Select this item to show the logical tracki...

Page 122: ...s follows MIB II 1 System Group sysORTable MIB II 2 Interfaces Group ifTable MIB II 4 IP Group ipAddrTable ipNetToMediaTable IpGroup IpBasicStatsGroup IpStatsGroup MIB II 5 ICMP Group IcmpGroup IcmpIn...

Page 123: ...tic dot1qStaticUnicastTable dot1qStaticMulticastTable dot1qVlan dot1qVlanCurrentTable dot1qVlanStaticTable dot1qPortVlanTable The private MIB file can be downloaded from Moxa s website www moxa com Pu...

Reviews: