background image

Chapter

 

3: Web Management 

Security - Network - IP Source Guard - Static Table 

 

  NGSME24G4S User Manual | 100 

3.1.4.13.2. Security - Network - IP Source Guard - Static Table

 

 

Delete 

Check to delete the entry. It will be deleted during the next save. 

Port 

The logical port for the settings. 

VLAN ID 

The vlan id for the settings. 

IP Address 

Allowed Source IP address. 

IP Mask 

It can be used for calculating the allowed network with IP address. 

Buttons 

 

Add New Entry:

 Click to add a new entry to the Static IP Source Guard table. 

 

Save:

 Click to save changes. 

 

Reset:

 Click to undo any changes made locally and revert to previously saved 

values. 

 

Summary of Contents for NGSME24G4S

Page 1: ...Version 2 0 Niveo NGSME24G4S 24 Port 10 100 1000Base T 4 Port 10G SFP Full Management Stackable High Power PoE Switch User Manual...

Page 2: ...interference will not occur in a particular installation If this equipment does cause harmful interference to radio or television reception which can be determined by turning the equipment off and on...

Page 3: ...ment 27 3 1 Web Management Configure 28 3 1 1 Configuration System 30 3 1 1 1 System Information 30 3 1 1 2 System IP 31 3 1 1 3 System IPv6 32 3 1 1 4 System NTP 33 3 1 1 5 System Time 34 3 1 1 6 Sys...

Page 4: ...ty Network DHCP 96 3 1 4 12 1 Security Network DHCP Snooping 96 3 1 4 12 2 Security Network DHCP Relay 97 3 1 4 13 Security Network IP Source Guard 99 3 1 4 13 1 Security Network IP Source Guard Confi...

Page 5: ...13 1 VLANs VLAN Membership 152 3 1 13 2 VLANs Ports 154 3 1 14 Configuration Private VLAN 156 3 1 14 1 Private VLAN Port Isolation 156 3 1 15 Configuration VCL 157 3 1 15 1 VCL MAC based VLAN 157 3 1...

Page 6: ...ity Access Management Statistics 211 3 2 3 2 Security Network 212 3 2 3 2 1 Security Network Port Security Switch 212 3 2 3 2 2 Security Network Port Security Port 215 3 2 3 2 3 Security Network NAS S...

Page 7: ...258 3 2 8 1 2 IPMC IGMP Snooping Groups Information 260 3 2 8 1 3 IPMC IGMP Snooping IPv4 SFM Information 261 3 2 8 2 IPMC MLD Snooping 263 3 2 8 2 1 IPMC MLD Snooping Status 263 3 2 8 2 2 IPMC MLD S...

Page 8: ...4 CLI Management Port 311 4 5 CLI Management MAC 314 4 6 CLI Management VLAN 315 4 7 CLI Management PVLAN Private VLAN 316 4 8 CLI Management Security 317 4 9 CLI Management STP 334 4 10 CLI Manageme...

Page 9: ...Table of Contents NGSME24G4S User Manual 9 Appendix A Product Safety 368 Appendix B IP Configuration for Your PC 369 Appendix C Glossary 372...

Page 10: ...NGSME24G4S User Manual 10 Before Starting In Before Starting This section contains introductory information which includes Intended Readers Icons for Note Caution and Warning Product Package Contents...

Page 11: ...g management and terminologies Icons for Note Caution and Warning To install configure use and maintain this product properly please pay attention when you see these icons in this manual A Note icon i...

Page 12: ...check and verify the contents of the product package which should include the following items One Network Switch One Power Cord One User Manual CD One pair Rack mount kit 8 Screws Note If any item li...

Page 13: ...Overview In Product Overview This section will give you an overview of this product including its feature functions and hardware software specifications Product Brief Description Product Specification...

Page 14: ...slots as the uplink ports the 10G uplink design provides an excellent solution for expanding your network from 1G to 10G By 10G speed this product provides high flexibility and high bandwidth connecti...

Page 15: ...ternal Power Power Feeding Detecting Capability on PD PD Alive Check PD Classification Power Management per port Enable Disable PoE Per Port Priority Setting Per Port Power Level Setting Per Port Over...

Page 16: ...horization Accounting TACACS HTTP SSL Secure Web SSH v2 0 Secured Telnet Session MAC IP Filter Management Command Line Interface CLI Web Based Management Telnet Access Management Filtering SNMP WEB SS...

Page 17: ...net PoE IEEE 802 3at Power over Ethernet PoE IEEE 802 3az Energy Efficient Ethernet EEE IEEE 802 3x Flow Control IEEE 802 1Q VLAN IEEE802 1v Protocol VLAN IEEE 802 1p Class of Service IEEE 802 1D Span...

Page 18: ...rts The LED Indicators are also located on the front panel LED Indicators The LED Indicators present real time information of systematic operation status The following table provides description of LE...

Page 19: ...00 ohm Max 100m 100 Base TX 2 pair UTP STP CAT 5 cable EIA TIA 568 100 ohm Max 100m 1000 Base T 4 pair UTP STP CAT 5 cable EIA TIA 568 100 ohm Max 100m PoE To delivery power properly it is recommended...

Page 20: ...n configure the switch via RS232 console cable without having the switch or your PC connecting to a network Out of band management provides a dedicated and secure way for switch management In Band Man...

Page 21: ...To access this switch s out of band management CLI Command Line Interface your PC must have terminal emulator software such as HyperTerminal or PuTTY installed Some operating systems such as Microsof...

Page 22: ...ial Console NGSME24G4S User Manual 22 4 Set the serial port settings as Baud Rate 115200 Data Bit 8 Parity None Stop Bit 1 Row Control None 5 The system will prompt you to login the out of band manage...

Page 23: ...ur PC properly 1 Verify that the network interface card NIC of your PC is operational and properly installed and that your operating system supports TCP IP protocol 2 Connect your PC with the switch v...

Page 24: ...on for Web Interface NGSME24G4S User Manual 24 6 The web browser will prompt you to sign in The default username password for the configuration web page is admin admin For more information please refe...

Page 25: ...s telnet SSH management CLI please set your PC s network environment according to the previous chapter 2 2 Preparation for Web Interface Telnet interface can be accessed via Microsoft CMD command Howe...

Page 26: ...the switch via SSH for the first time a PuTTY Security Alert window will pop up Please press Yes to continue This window won t pop up if you re using telnet to connect to the in band management CLI 4...

Page 27: ...agement interface You can make all settings and monitor system status with this management web page Configuration Monitor options included in the management web page can be divided into the following...

Page 28: ...and provide redundant links that serve as automatic backup paths if an active link fails This switch supports STP RSTP Rapid STP and MSTP Multiple STP MVR MVR stands for Multiple VLAN Registration a p...

Page 29: ...ed received to from a port or multiple ports to a designated port UPnP UPnP stands for Universal Plug and Play a protocol that allows all the devices on the same network can discover each other and es...

Page 30: ...or this switch By convention this is the switch s fully qualified domain name A domain name is a text string drawn from the alphabet A Z a z digits 0 9 minus sign No space characters are permitted as...

Page 31: ...he configured System Name as hostname for DNS lookup IP Address Provide the IP address of this switch in dotted decimal notation IP Mask Provide the IP mask of this switch dotted decimal notation IP R...

Page 32: ...le fe80 215 c5ff fe03 4dc7 The symbol is a special syntax that can be used as a shorthand way of representing multiple 16 bit groups of contiguous zeros but it can appear only once It can also represe...

Page 33: ...ver IPv6 address is in 128 bit records represented as eight fields of up to four hexadecimal digits with a colon separating each field For example fe80 215 c5ff fe03 4dc7 The symbol is a special synta...

Page 34: ...able acronym to identify the time zone You can use up to 16 alphanumeric characters and punctuations such as _ and Daylight Saving Time Configuration When enabled the switch will set the clock forward...

Page 35: ...Select the starting minute End time settings Week Select the ending week number Day Select the ending day Month Select the ending month Hours Select the ending hour Minutes Select the ending minute O...

Page 36: ...knowledgments The system log packet will always send out even if the system log server does not exist Possible modes are Enabled Enable server mode operation Disabled Disable server mode operation Ser...

Page 37: ...the value of the wakeup time in order to make sure that both the receiving and transmitting device has all circuits powered up when traffic is transmitted The devices can exchange wakeup time informa...

Page 38: ...operation Auto Cu port auto negotiating speed with the link partner and selects the highest speed that is compatible with the link partner 10Mbps HDX Forces the cu port in 10Mbps half duplex mode 10M...

Page 39: ...start backoff algorithm after 16 collisions Power Control The Usage column shows the current percentage of the power consumption per port The Configured column allows for changing the power savings mo...

Page 40: ...r You can also click on the link to configure user account Privilege Level The privilege level of the user The allowed range is 1 to 15 If the privilege level value is 15 it can access all groups i e...

Page 41: ...up privilege level User s privilege should be same or greater than the group privilege level to have the access of that group By default setting most groups privilege level 5 has the read only access...

Page 42: ...he following description defines these privilege level groups in details System Contact Name Location Timezone Daylight Saving Time Log Security Authentication System Access Management Port contains D...

Page 43: ...ng sub groups configuration read only configuration execute read write status statistics read only status statistics read write e g for clearing of statistics User Privilege should be same or greater...

Page 44: ...s None authentication is disabled and login is not possible Local use the local user database on the stack for authentication RADIUS use a remote RADIUS server for authentication TACACS use a remote T...

Page 45: ...ty Switch SSH Configure SSH on this page Mode Indicates the SSH mode operation Possible modes are Enabled Enable SSH mode operation Disabled Disable SSH mode operation Buttons Save Click to save chang...

Page 46: ...tion Possible modes are Enabled Enable HTTPS mode operation Disabled Disable HTTPS mode operation Automatic Redirect Indicates the HTTPS redirect mode operation Automatically redirects web browser to...

Page 47: ...s Indicates the start IP address for the access management entry End IP address Indicates the end IP address for the access management entry HTTP HTTPS Indicates that the host can access the switch fr...

Page 48: ...hen SNMP version is SNMPv1 or SNMPv2c If SNMP version is SNMPv3 the community string will be associated with SNMPv3 communities table It provides more flexibility to configure security name than a SNM...

Page 49: ...cates the SNMP trap supported version Possible versions are SNMP v1 Set SNMP trap supported version 1 SNMP v2c Set SNMP trap supported version 2c SNMP v3 Set SNMP trap supported version 3 Trap Communi...

Page 50: ...led Disable SNMP trap link up and link down mode operation Trap Inform Mode Indicates the SNMP trap inform mode operation Possible modes are Enabled Enable SNMP trap inform mode operation Disabled Dis...

Page 51: ...ame Indicates the SNMP trap security name SNMPv3 traps and informs using USM for authentication and privacy A unique security name is needed when traps and informs are enabled Buttons Save Click to sa...

Page 52: ...string length is 1 to 32 and the allowed content is ASCII characters from 33 to 126 The community string will be treated as security name and map a SNMPv1 or SNMPv2c community string Source IP Indica...

Page 53: ...eID and usmUserName are the entry s keys In a simple agent usmUserEngineID is always that agent s own snmpEngineID value The value can also take the value of the snmpEngineID of a remote SNMP engine w...

Page 54: ...ng the authentication password phrase For MD5 authentication protocol the allowed string length is 8 to 32 For SHA authentication protocol the allowed string length is 8 to 40 The allowed content is A...

Page 55: ...d for SNMPv2c usm User based Security Model USM Security Name A string identifying the security name that this entry should belong to The allowed string length is 1 to 32 and the allowed content is AS...

Page 56: ...elong to Possible view types are included An optional flag to indicate that this view subtree should be included excluded An optional flag to indicate that this view subtree should be excluded In gene...

Page 57: ...USM Security Level Indicates the security model that this entry should belong to Possible security models are NoAuth NoPriv No authentication and no privacy Auth NoPriv Authentication and no privacy...

Page 58: ...ry It will be deleted during the next save ID Indicates the index of the entry The range is from 1 to 65535 Data Source Indicates the port ID which wants to be monitored If in stacking switch the valu...

Page 59: ...he value must add 1000 switch ID 1 for example if the port is switch 3 port 5 the value is 2005 Interval Indicates the interval in seconds for sampling the history statistics data The range is from 1...

Page 60: ...stPkts The number of broad cast and multi cast packets delivered to a higher layer protocol InDiscards The number of inbound packets that are discarded even the packets are normal InErrors The number...

Page 61: ...resholds possible sample types are RisingTrigger alarm when the first value is larger than the rising threshold FallingTrigger alarm when the first value is less than the falling threshold RisingOrFal...

Page 62: ...r of octets received on the interface including framing characters Log The number of uni cast packets delivered to a higher layer protocol snmptrap The number of broad cast and multi cast packets deli...

Page 63: ...e maximum number of users on the port If this number is exceeded an action is taken The action can be one of the four different actions as described below The Limit Control module utilizes a lower lay...

Page 64: ...situation enable aging With aging enabled a timer is started once the end host gets secured When the timer expires the switch starts looking for frames from the end host and if such frames are not se...

Page 65: ...wn If Limit 1 MAC addresses is seen on the port both the Trap and the Shutdown actions described above will be taken State This column shows the current state of the port as seen from the Limit Contro...

Page 66: ...xplored below MAC based authentication allows for authentication of more than one user on the same port and doesn t require the user to have special 802 1X supplicant software installed on his system...

Page 67: ...C addresses the Port Security module needs to check for activity on the MAC address in question at regular intervals and free resources if no activity is seen within a given period of time This parame...

Page 68: ...ll ports RADIUS Assigned VLAN Enabled RADIUS assigned VLAN provides a means to centrally control the VLAN on which a successfully authenticated supplicant is placed on the switch Incoming traffic will...

Page 69: ...nged if the Guest VLAN option is globally enabled Valid values are in the range 1 255 Allow Guest VLAN if EAPOL Seen The switch remembers if an EAPOL frame has been received on the port for the life t...

Page 70: ...d In this mode the switch will send one EAPOL Success frame when the port link comes up and any client on the port will be allowed network access without authentication Force Unauthorized In this mode...

Page 71: ...uppose that the first server in the list is currently down but not considered dead Now if the supplicant retransmits EAPOL Start frames at a rate faster than X seconds then it will never get authentic...

Page 72: ...ched In this case the switch sends EAPOL Request Identity frames using the BPDU multicast MAC address as destination to wake up any supplicants that might be on the port The maximum number of supplica...

Page 73: ...ent on the port the port s QoS Class is immediately reverted to the original QoS Class which may be changed by the administrator in the meanwhile without affecting the RADIUS assigned This option is o...

Page 74: ...nel Type and Tunnel Private Group ID attributes must all be present at least once in the Access Accept packet The switch looks for the first set of these attributes that have the same Tag value and fu...

Page 75: ...cess on this VLAN The switch will not transmit an EAPOL Success frame when entering the Guest VLAN While in the Guest VLAN the switch monitors the link for EAPOL frames and if one such frame is receiv...

Page 76: ...only has effect for successfully authenticated clients on the port and will not cause the clients to get temporarily unauthorized Reinitialize Forces a reinitialization of the clients on the port and...

Page 77: ...l port for the settings contained in the same row Policy ID Select the policy to apply to this port The allowed values are 0 through 255 The default value is 0 Action Select whether forwarding is perm...

Page 78: ...s received on the port the port will be disabled Disabled Port shut down is disabled The default value is Disabled State Specify the port state of this port The allowed values are Enabled To reopen po...

Page 79: ...ACL Rate Limiter Configure the rate limiter for the ACL of the switch Rate Limiter ID The rate limiter ID for the settings contained in the same row Rate The allowed values are 0 131071 in pps Button...

Page 80: ...mask Indicates the policy number and bitmask of the ACE Frame Type Indicates the frame type of the ACE Possible values are Any The ACE will match any frame type EType The ACE will match Ethernet Type...

Page 81: ...he ACE was hit by a frame Modification Buttons You can modify each ACE Access Control Entry in the table using the following buttons Inserts a new ACE before the current row Edits the ACE row Moves th...

Page 82: ...The ACE applies to this port number where n is the number of the switch port Policy Filter Specify the policy number filter for this ACE Any No policy filter is specified policy filter status is don t...

Page 83: ...or the ACE operation Deny The frame that hits this ACE is dropped Rate Limiter Specify the rate limiter in number of base units The allowed range is 1 to 16 Disabled indicates that the rate limiter op...

Page 84: ...at is xx xx xx xx xx xx or xx xx xx xx xx xx or xxxxxxxxxxxx x is a hexadecimal digit A frame that hits this ACE matches this SMAC value DMAC Filter Specify the destination MAC filter for this ACE Any...

Page 85: ...D with this ACE choose this value A field for entering a VLAN ID number appears VLAN ID When Specific is selected for the VLAN ID filter you can enter a specific VLAN ID number The allowed range is 1...

Page 86: ...quest Frame must have ARP Request or RARP Request OP flag set Reply Frame must have ARP Reply or RARP Reply OP flag Sender IP Filter Specify the sender IP filter for this ACE Any No sender IP filter i...

Page 87: ...decimal notation ARP Sender MAC Match Specify whether frames can hit the action according to their sender hardware address field SHA settings 0 ARP frames where SHA is not equal to the SMAC address 1...

Page 88: ...RARP frames where the HLD is not equal to Ethernet 1 1 ARP RARP frames where the HLD is equal to Ethernet 1 Any Any value is allowed don t care Ethernet Specify whether frames can hit the action acco...

Page 89: ...d later in this help file TCP Select TCP to filter IPv4 TCP protocol frames Extra fields for defining TCP parameters will appear These fields are explained later in this help file IP Protocol Value Wh...

Page 90: ...e source IP address and source IP mask in the SIP Address and SIP Mask fields that appear SIP Address When Host or Network is selected for the source IP filter you can enter a specific SIP address in...

Page 91: ...he ICMP filter you can enter a specific ICMP value The allowed range is 0 to 255 A frame that hits this ACE matches this ICMP value ICMP Code Filter Specify the ICMP code filter for this ACE Any No IC...

Page 92: ...s ACE you can enter a specific TCP UDP source range value A field for entering a TCP UDP source value appears TCP UDP Source No When Specific is selected for the TCP UDP source filter you can enter a...

Page 93: ...35 A frame that hits this ACE matches this TCP UDP destination value TCP FIN Specify the TCP No more data from sender FIN value for this ACE 0 TCP frames where the FIN field is set must not be able to...

Page 94: ...must not be able to match this entry 1 TCP frames where the ACK field is set must be able to match this entry Any Any value is allowed don t care TCP URG Specify the TCP Urgent Pointer field significa...

Page 95: ...ou want to filter a specific EtherType filter with this ACE you can enter a specific EtherType value A field for entering a EtherType value appears Ethernet Type Value When Specific is selected for th...

Page 96: ...ing mode operation is enabled the DHCP request messages will be forwarded to trusted ports and only allow reply packets from trusted ports Disabled Disable DHCP snooping mode operation Port Mode Confi...

Page 97: ...subnet domain Relay Information Mode Indicates the DHCP relay information mode option operation The option 82 circuit ID format as vlan_id module_id port_no The first four characters represent the VLA...

Page 98: ...licy The Replace option is invalid when relay information mode is disabled Possible policies are Replace Replace the original relay information when a DHCP message that already contains it is received...

Page 99: ...uard is enabled on which ports Only when both Global Mode and Port Mode on a given port are enabled IP Source Guard is enabled on this given port Max Dynamic Clients Specify the maximum number of dyna...

Page 100: ...ed during the next save Port The logical port for the settings VLAN ID The vlan id for the settings IP Address Allowed Source IP address IP Mask It can be used for calculating the allowed network with...

Page 101: ...Configuration Enable the Global ARP Inspection or disable the Global ARP Inspection Port Mode Configuration Specify ARP Inspection is enabled on which ports Only when both Global Mode and Port Mode o...

Page 102: ...ing the next save Port The logical port for the settings VLAN ID The vlan id for the settings MAC Address Allowed Source MAC address in ARP request packets IP Address Allowed Source IP address in ARP...

Page 103: ...cope with lost frames the timeout interval is divided into 3 subintervals of equal length If a reply is not received within the subinterval the request is transmitted again This algorithm causes the...

Page 104: ...w applies Enabled Enable the RADIUS Authentication Server by checking this box IP Address Hostname The IP address or hostname of the RADIUS Authentication Server IP address is expressed in dotted deci...

Page 105: ...below applies Enabled Enable the RADIUS Accounting Server by checking this box IP Address Hostname The IP address or hostname of the RADIUS Accounting Server IP address is expressed in dotted decimal...

Page 106: ...by checking this box IP Address Hostname The IP address or hostname of the TACACS Authentication Server IP address is expressed in dotted decimal notation Port The TCP port to use on the TACACS Authen...

Page 107: ...Source MAC address or uncheck to disable By default Source MAC Address is enabled Destination MAC Address The Destination MAC Address can be used to calculate the destination port for the frame Check...

Page 108: ...embers Group ID Indicates the group ID for the settings contained in the same row Group ID Normal indicates there is no aggregation Only one group ID is valid per port Port Members Each switch port is...

Page 109: ...tion when 2 or more ports are connected to the same partner LACP can form max 12 LLAGs per switch and 2 GLAGs per stack Key The Key value incurred by the port range 1 65535 The Auto setting will set t...

Page 110: ...before sending a LACP packet Prio The Prio controls the priority of the port If the LACP partner wants to form a larger group than is supported by this device then this parameter will control which p...

Page 111: ...Protection Controls whether loop protections is enabled as a whole Transmission Time The interval between each loop protection PDU sent on each port valid values are 1 to 10 seconds Shutdown Time The...

Page 112: ...rt Action Configures the action performed when a loop is detected on a port Valid values are Shutdown Port Shutdown Port and Log or Log Only Tx Mode Controls whether the port is actively generating lo...

Page 113: ...ority Lower numeric values have better priority The bridge priority plus the MSTI instance number concatenated with the 6 byte MAC address of the switch forms a Bridge Identifier For MSTP operation th...

Page 114: ...tly configured as Edge will transmit and receive BPDUs Edge Port BPDU Guard Control whether a port explicitly configured as Edge will disable itself upon reception of a BPDU The port will enter the er...

Page 115: ...The name identifying the VLAN to MSTI mapping Bridges must share the name and revision see below as well as the VLAN to MSTI mapping configuration in order to share spanning trees for MSTI s Intra re...

Page 116: ...xx xx being between 1 and 4094 VLAN or a range xx yy each of which must be separated with comma and or space A VLAN can only be mapped to one MSTI An unused MSTI should just be left empty I e not hav...

Page 117: ...change them as well MSTI The bridge instance The CIST is the default instance which is always active Priority Controls the bridge priority Lower numeric values have better priority The bridge priorit...

Page 118: ...ort configurations and possibly change them as well This page contains settings for physical and aggregated ports The aggregation settings are stack global The STP port settings relate to the currentl...

Page 119: ...utoEdge Controls whether the bridge should enable automatic edge detection on the bridge port This allows operEdge to be derived from whether BPDU s are received on the port or not Restricted Role If...

Page 120: ...abled state due to this setting is subject to the bridge Port Error Recovery setting as well Point to Point Controls whether the port connects to a point to point LAN rather than to a shared medium Th...

Page 121: ...inspect the current STP MSTI port configurations and possibly change them as well An MSTI port is a virtual port which is instantiated separately for each active CIST physical port for each MSTI inst...

Page 122: ...ting will set the path cost as appropriate by the physical link speed using the 802 1D recommended values Using the Specific setting a user defined value can be entered The path cost is used when esta...

Page 123: ...hannel the set top box or PC sends an IGMP MLD report message to Switch A to join the appropriate multicast group address Uplink ports that send and receive multicast data to and from the multicast VL...

Page 124: ...for IGMP MLD report memberships on a receiver port before removing the port from multicast group membership The value is in units of tenths of a seconds The range is from 0 to 31744 The default LLQI i...

Page 125: ...ts Select the port role by clicking the Role symbol to switch the setting Immediate Leave Enable the fast leave on the port Buttons Add New NVR VLAN Click to add new MVR VLAN Specify the VID and confi...

Page 126: ...ame of the Channel of the specific Multicast VLAN Maximum length of the Channel Name string is 32 Channel Name can only contain alphabets or numbers Channel name should contain at least one alphabet C...

Page 127: ...o the currently selected stack unit as reflected by the page header Snooping Enabled Enable the Global IGMP Snooping Unregistered IPMCv4 Flooding Enabled Enable unregistered IPMCv4 traffic flooding Th...

Page 128: ...the router side Router Port Specify which ports act as router ports A router port is a port on the Ethernet switch that leads towards the Layer 3 multicast device or IGMP querier If an aggregation me...

Page 129: ...st VLAN Table match The will use the last entry of the currently displayed entry as a basis for the next lookup When the end is reached the text No more entries is shown in the displayed table Use the...

Page 130: ...by the Last Member Query Interval multiplied by the Last Member Query Count The allowed range is 0 to 31744 in tenths of seconds default last member query interval is 10 in tenths of seconds 1 second...

Page 131: ...e settings Filtering Groups The IP Multicast Group that will be filtered Add New Filtering Group Click Add New Filtering Group button to add a new entry to the Group Filtering table Specify the Port a...

Page 132: ...Enabled Enable unregistered IPMCv6 traffic flooding The flooding control takes effect only when MLD Snooping is enabled When MLD Snooping is disabled unregistered IPMCv6 traffic flooding is always act...

Page 133: ...the Layer 3 multicast device or MLD querier If an aggregation member port is selected as a router port the whole aggregation will act as a router port Fast Leave Enable the fast leave on the port Thr...

Page 134: ...entry as a basis for the next lookup When the end is reached the text No more entries is shown in the displayed table Use the button to start over MLD Snooping VLAN Table Columns Delete Check to dele...

Page 135: ...ate the Maximum Response Code inserted into Multicast Address and Source Specific Query messages The allowed range is 0 to 31744 in tenths of seconds default last listener query interval is 10 in tent...

Page 136: ...settings Filtering Groups The IP Multicast Group that will be filtered Add New Filtering Group Click Add New Filtering Group button to add a new entry to the Group Filtering table Specify the Port an...

Page 137: ...nterval value Valid values are restricted to 5 32768 seconds Tx Hold Each LLDP frame contains information about how long the information in the LLDP frame shall be considered valid The LLDP informatio...

Page 138: ...neighbors but will send out LLDP information Disabled The switch will not send out LLDP information and will drop LLDP information received from neighbors Enabled The switch will send out LLDP inform...

Page 139: ...switch Note When CDP awareness on a port is disabled the CDP information isn t removed immediately but gets removed when the hold time is exceeded Port Descr Optional TLV When checked the port descrip...

Page 140: ...t can come with inappropriate knowledge of the network policy With this in mind LLDP MED defines an LLDP MED Fast Start interaction between the protocol and the application layers on top of the protoc...

Page 141: ...degrees with a maximum of 4 digits It is possible to specify the direction to either East of the prime meridian or West of the prime meridian Altitude Altitude SHOULD be normalized to within 32767 to...

Page 142: ...E or US State National subdivisions state canton region province prefecture County County parish gun Japan district City City township shi Japan Example Copenhagen City district City division borough...

Page 143: ...1 and others such as defined by TIA or NENA Emergency Call Service Emergency Call Service ELIN identifier data format is defined to carry the ELIN identifier as used during emergency call setup to a t...

Page 144: ...ion type LLDP MED allows multiple policies to be advertised per port each corresponding to a different application type Different ports on the same Network Connectivity Device may advertise different...

Page 145: ...ty field is ignored and only the DSCP value has relevance 6 Video Conferencing for use by dedicated Video Conferencing equipment and other similar appliances supporting real time interactive video aud...

Page 146: ...e point values 0 through 63 A value of 0 represents use of the default DSCP value as defined in RFC 2475 Adding a new policy Click Add New Policy to add a new policy Specify the Application type Tag V...

Page 147: ...port automatically determines how much power to reserve according to the class the connected PD belongs to and reserves the power accordingly Four different port classes exist and one for 4 7 15 4 or...

Page 148: ...available from the power supply Power Supply Configuration Primary and Backup Power Source Some switches support having two PoE power supplies One is used as primary power source and one as backup pow...

Page 149: ...er than the power supply can deliver In this case the port with the lowest priority will be turn off starting from the port with the highest port number Maximum Power The Maximum Power value contains...

Page 150: ...time by entering a value here in seconds The allowed range is 10 to 1000000 seconds Disable the automatic aging of dynamic entries by checking the Disable automatic aging checkbox MAC Table Learning I...

Page 151: ...AC table can contain 64 entries The maximum of 64 entries is for the whole stack and not per switch The MAC table is sorted first by VLAN ID and then by MAC address Delete Check to delete the entry It...

Page 152: ...in the VLAN Table Clicking the Refresh button will update the displayed table starting from that or the closest next VLAN Table match The will use the last entry of the currently displayed VLAN entry...

Page 153: ...needed Legal values for a VLAN ID are 1 through 4095 The VLAN is enabled on the selected stack switch unit when you click on Save The VLAN is thereafter present on the other stack switch units but wi...

Page 154: ...tering Enable ingress filtering on a port by checking the box This parameter affects VLAN ingress processing If ingress filtering is enabled and the ingress port is not a member of the classified VLAN...

Page 155: ...different from the Port VLAN ID a VLAN tag with the classified VLAN ID is inserted in the frame Port VLAN ID Configures the VLAN identifier for the port The allowed values are from 1 through 4095 The...

Page 156: ...k unit as reflected by the page header This feature works across the stack Configuration Port Members A check box is provided for each port of a private VLAN When checked port isolation is enabled on...

Page 157: ...sed VLAN check the box To remove or exclude the port from the MAC based VLAN make sure the box is unchecked By default no ports are members and all boxes are unchecked Adding a New MAC based VLAN Clic...

Page 158: ...ly and revert to previously saved values Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh the page immediately Updates th...

Page 159: ...e you selected Value Valid value that can be entered in this text field depends on the option selected from the the preceding Frame Type selection menu Below is the criteria for three different Frame...

Page 160: ...sists of a combination of alphabets a z or A Z and integers 0 9 Note special character and underscore _ are not allowed Adding a New Group to VLAN mapping entry Click Add New Entry to add a new entry...

Page 161: ...ed A valid VLAN ID ranges from 1 4095 Port Members A row of check boxes for each port is displayed for each Group Name to VLAN ID mapping To include a port in a mapping check the box To remove or excl...

Page 162: ...twork mask length VLAN ID Indicates the VLAN ID VLAN ID can be changed for the existing entries Port Members A row of check boxes for each port is displayed for each IP subnet based VLAN entry To incl...

Page 163: ...nual 163 Buttons Save Click to save changes Reset Click to undo any changes made locally and revert to previously saved values Auto refresh Check this box to refresh the page automatically Automatic r...

Page 164: ...ice VLAN It can avoid the conflict of ingress filtering Possible modes are Enabled Enable Voice VLAN mode operation Disabled Disable Voice VLAN mode operation VLAN ID Indicates the Voice VLAN ID It sh...

Page 165: ...will be blocked for 10 seconds Possible port modes are Enabled Enable Voice VLAN security mode operation Disabled Disable Voice VLAN security mode operation Port Discovery Protocol Indicates the Voice...

Page 166: ...e Telephony OUI A telephony OUI address is a globally unique identifier assigned to a vendor by IEEE It must be 6 characters long and the input format is xx xx xx x is a hexadecimal digit Description...

Page 167: ...All frames are classified to a QoS class There is a one to one mapping between QoS class queue and priority A QoS class of 0 zero has the lowest priority If the port is VLAN aware and the frame is tag...

Page 168: ...frame is tagged then the frame is classified to a DP level that is equal to the DEI value in the tag Otherwise the frame is classified to the default DP level The classified DP level can be overruled...

Page 169: ...on this switch port Rate Controls the rate for the policer The default value is 500 This value is restricted to 100 1000000 when the Unit is kbps or fps and it is restricted to 1 13200 when the Unit...

Page 170: ...ss Port Schedulers for all switch ports The ports belong to the currently selected stack unit as reflected by the page header Port The logical port for the settings contained in the same row Click on...

Page 171: ...r this queue on this switch port Queue Shaper Rate Controls the rate for the queue shaper The default value is 500 This value is restricted to 100 1000000 when the Unit is kbps and it is restricted to...

Page 172: ...per Rate Controls the rate for the port shaper The default value is 500 This value is restricted to 100 1000000 when the Unit is kbps and it is restricted to 1 13200 when the Unit is Mbps Port Shaper...

Page 173: ...r this queue on this switch port Queue Shaper Rate Controls the rate for the queue shaper The default value is 500 This value is restricted to 100 1000000 when the Unit is kbps and it is restricted to...

Page 174: ...per Rate Controls the rate for the port shaper The default value is 500 This value is restricted to 100 1000000 when the Unit is kbps and it is restricted to 1 13200 when the Unit is Mbps Port Shaper...

Page 175: ...s for all switch ports The ports belong to the currently selected stack unit as reflected by the page header Port The logical port for the settings contained in the same row Click on the port number i...

Page 176: ...this queue on this switch port Queue Shaper Rate Controls the rate for the queue shaper The default value is 500 This value is restricted to 100 1000000 when the Unit is kbps and it is restricted to...

Page 177: ...er Rate Controls the rate for the port shaper The default value is 500 This value is restricted to 100 1000000 when the Unit is kbps and it is restricted to 1 13200 when the Unit is Mbps Port Shaper U...

Page 178: ...this queue on this switch port Queue Shaper Rate Controls the rate for the queue shaper The default value is 500 This value is restricted to 100 1000000 when the Unit is kbps and it is restricted to...

Page 179: ...er Rate Controls the rate for the port shaper The default value is 500 This value is restricted to 100 1000000 when the Unit is kbps and it is restricted to 1 13200 when the Unit is Mbps Port Shaper U...

Page 180: ...s The ports belong to the currently selected stack unit as reflected by the page header Port The logical port for the settings contained in the same row Click on the port number in order to configure...

Page 181: ...cific port are configured on this page Mode Controls the tag remarking mode for this port Classified Use classified PCP DEI values Default Use default PCP DEI values Mapped Use mapped versions of QoS...

Page 182: ...sified DP level to a 1 bit DP level used in the QoS class DP level to PCP DEI mapping process QoS class DP level to PCP DEI Mapping Controls the mapping of the classified QoS class DP level to PCP DEI...

Page 183: ...gs Ingress In Ingress settings you can change ingress translation and classification settings for individual ports There are two configuration parameters available in Ingress 1 Translate 2 Classify 1...

Page 184: ...iting can be one of Disable No Egress rewrite Enable Rewrite enabled without remapping Remap DSCP from analyzer is remapped and frame is remarked with remapped DSCP value Buttons Save Click to save ch...

Page 185: ...pported DSCP values are 64 Trust Controls whether a specific DSCP value is trusted Only frames with trusted DSCP values are mapped to a specific QoS class and Drop Precedence Level Frames with untrust...

Page 186: ...lated to new DSCP before using the DSCP for QoS class and DPL map There are two configuration parameters for DSCP Translation 1 Translate 2 Classify 1 Translate DSCP at Ingress side can be translated...

Page 187: ...to configure the mapping of QoS class to DSCP value The settings relate to the currently selected stack unit as reflected by the page header QoS Class Actual QoS class DSCP Select the classified DSCP...

Page 188: ...t The port number for which the configuration below applies Enabled Controls whether the storm control is enabled on this switch port Rate Controls the rate for the storm control The default value is...

Page 189: ...s whether RED is enabled for this queue Min Threshold Controls the lower RED threshold If the average queue filling level is below this threshold the drop probability is zero This value is restricted...

Page 190: ...level is 100 Frames marked with Drop Precedence Level 0 are never dropped Min Threshold is the average queue filling level where the queues randomly start dropping frames The drop probability for fram...

Page 191: ...t also known as ingress or source mirroring All frames transmitted on a given port also known as egress or destination mirroring Port to mirror to Port to mirror also known as the mirror port Frames f...

Page 192: ...ived are not mirrored Disabled Neither frames transmitted nor frames received are mirrored Enabled Frames received and frames transmitted are mirrored on the mirror port Note For a given port a frame...

Page 193: ...ation carried in SSDP packets is used to inform a control point or control points how often it or they should receive an SSDP advertisement message from this switch If a control point does not receive...

Page 194: ...The Switch ID 1 16 assigned to a switch For more information see description of Switch IDs Master Capable Indicates whether a switch is capable of being master An unmanaged switch for example will no...

Page 195: ...on page If the configuration of the switch is not to be transferred to another switch then the configuration may be deleted by choosing Delete followed by Save Replacing a Switch If a switch is to be...

Page 196: ...e been master for more than 30 seconds then that switch will become master 2 If multiple switches claim to have been master for more than 30 seconds then the switch which has been master for the longe...

Page 197: ...using the Web or CLI interface or through SNMP This read only field shows the owner of the current sFlow configuration and assumes values as follows If sFlow is currently unconfigured unclaimed Owner...

Page 198: ...lue that avoids fragmentation of the sFlow datagrams Valid range is 200 to 1468 bytes with default being 1400 bytes Port Configuration Port The port number for which the configuration below applies Fl...

Page 199: ...terval in seconds between counter poller samples Buttons Release See description under Owner Refresh Click to refresh the page Note that unsaved changes will be lost Save Click to save changes Note th...

Page 200: ...nfigured in Configuration System Information System Contact Name The system name configured in Configuration System Information System Name Location The system location configured in Configuration Sys...

Page 201: ...ation NGSME24G4S User Manual 201 Software Date The date when the switch software was produced Buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 sec...

Page 202: ...20 samples are graphed and the last numbers are displayed as text as well In order to display the SVG graph your browser must support the SVG format Consult the SVG Wiki for more information on browse...

Page 203: ...e of the system log entry Message The message of the system log entry Buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Updates the...

Page 204: ...stem log entry Message The detailed message of the system log entry Buttons Refresh Updates the system log entry to the current entry ID Updates the system log entry to the first available entry ID Up...

Page 205: ...is page provides an overview of the current switch port states The port states are illustrated as follows Status Disabled Down Link RJ45 ports SFP ports X2 ports Buttons Auto refresh Check this box to...

Page 206: ...umber of received and transmitted packets per port Bytes The number of received and transmitted bytes per port Errors The number of frames received in error and the number of incomplete transmissions...

Page 207: ...nit as reflected by the page header Port The logical port for the settings contained in the same row Qn There are 8 QoS queues per port Q0 is the lowest priority queue Rx Tx The number of received and...

Page 208: ...ive and transmit the size counters for receive and transmit and the error counters for receive and transmit Receive Total and Transmit Total Rx and Tx Packets The number of received and transmitted go...

Page 209: ...egress congestion Rx CRC Alignment The number of frames received with CRC or alignment errors Rx Undersize The number of short 1 frames received with valid CRC Rx Oversize The number of long 2 frames...

Page 210: ...ns Refresh Click to refresh the page immediately Clear Clears the counters for the selected port Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds...

Page 211: ...Received Packets Number of received packets from the interface when access management mode is enabled Allowed Packets Number of allowed packets from the interface when access management mode is enabl...

Page 212: ...resses are passed on to the port security module which in turn asks all user modules whether to allow this new MAC address to forward or block it For a MAC address to be set in the forwarding state al...

Page 213: ...sing the Port Security service Ready The Port Security service is in use by at least one user module and is awaiting frames from unknown MAC addresses to arrive Limit Reached The Port Security service...

Page 214: ...t Security Network Port Security Switch NGSME24G4S User Manual 214 Buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refre...

Page 215: ...port If no MAC addresses are learned a single row stating No MAC addresses attached is displayed State Indicates whether the corresponding MAC address is blocked or forwarding In the blocked state it...

Page 216: ...on of possible values Port State The current state of the port Refer to NAS Port State for a description of the individual states Last Source The source MAC address carried in the most recently receiv...

Page 217: ...Port VLAN ID is not overridden by NAS If the VLAN ID is assigned by the RADIUS server RADIUS assigned is appended to the VLAN ID Read more about RADIUS assigned VLANs here If the port is moved to the...

Page 218: ...r Port State Admin State The port s current administrative state Refer to NAS Admin State for a description of possible values Port State The current state of the port Refer to NAS Port State for a de...

Page 219: ...work NAS Port NGSME24G4S User Manual 219 Port Counters EAPOL Counters These supplicant frame counters are available for the following administrative states Force Authorized Force Unauthorized Port bas...

Page 220: ...ecurity Network NAS Port NGSME24G4S User Manual 220 Backend Server Counters These backend RADIUS frame counters are available for the following administrative states Port based 802 1X Single 802 1X Mu...

Page 221: ...llowing administrative states Multi 802 1X MAC based Auth The table is identical to and is placed next to the Port Counters table and will be empty if no MAC address is currently selected To populate...

Page 222: ...successfully authenticated the client it is unauthenticated If an authentication fails for one or the other reason the client will remain in the unauthenticated state for Hold Time seconds Last Authe...

Page 223: ...ll match any frame type EType The ACE will match Ethernet Type frames Note that an Ethernet Type based ACE will not get matched by IP and ARP frames ARP The ACE will match ARP RARP frames IPv4 The ACE...

Page 224: ...nter indicates the number of times the ACE was hit by a frame Conflict Indicates the hardware status of the specific ACE The specific ACE is not applied to the hardware due to hardware limitations But...

Page 225: ...equest option 53 with value 3 packets received and transmitted Rx and Tx Decline The number of decline option 53 with value 4 packets received and transmitted Rx and Tx ACK The number of ACK option 53...

Page 226: ...transmitted Rx and Tx Lease Active The number of lease active option 53 with value 13 packets received and transmitted Buttons The port select box determines which port is affected by clicking the bu...

Page 227: ...n options Receive Missing Circuit ID The number of packets received with the Circuit ID option missing Receive Missing Remote ID The number of packets received with the Remote ID option missing Receiv...

Page 228: ...mation option Keep Agent Option The number of packets whose relay agent information was retained Drop Agent Option The number of packets that were dropped which were received with relay agent informat...

Page 229: ...AN MAC address and IP address input fields allow the user to select the starting point in the Dynamic ARP Inspection Table Clicking the Refresh button will update the displayed table starting from tha...

Page 230: ...he page automatically Automatic refresh occurs every 3 seconds Refresh Refreshes the displayed table starting from the input fields Clear Flushes all dynamic entries Updates the table starting from th...

Page 231: ...c IP Source Guard Table Clicking the Refresh button will update the displayed table starting from that or the closest next Dynamic IP Source Guard Table match In addition the two input fields will upo...

Page 232: ...P Source Guard NGSME24G4S User Manual 232 Clear Flushes all dynamic entries Updates the table starting from the first entry in the Dynamic IP Source Guard Table Updates the table starting with the ent...

Page 233: ...ld takes one of the following values Disabled The server is disabled Not Ready The server is enabled but IP communication is not yet up and running Ready The server is enabled IP communication is up a...

Page 234: ...P communication is up and running and the RADIUS module is ready to accept accounting attempts Dead X seconds left Accounting attempts were made to this server but it did not reply within the configur...

Page 235: ...ics for a particular RADIUS server RADIUS Authentication Statistics The statistics map closely to those specified in RFC4668 RADIUS Authentication Client MIB Use the server select box to switch betwee...

Page 236: ...Chapter 3 Web Management Security AAA RADIUS Details NGSME24G4S User Manual 236...

Page 237: ...he server and the latest round trip time RADIUS Accounting Statistics The statistics map closely to those specified in RFC4670 RADIUS Accounting Client MIB Use the server select box to switch between...

Page 238: ...ound trip time Buttons The server select box determines which server is affected by clicking the buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3...

Page 239: ...ayed table starting from that or the next closest Statistics table match The button will use the last entry of the currently displayed entry as a basis for the next lookup When the end is reached the...

Page 240: ...CRC Jabb The number of frames which size is larger than 64 octets received with invalid CRC Coll The best estimate of the total number of collisions on this Ethernet segment 64 The total number of pac...

Page 241: ...s box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh the page immediately Updates the table starting from the first entry in the Statistics table i...

Page 242: ...h The will use the last entry of the currently displayed entry as a basis for the next lookup When the end is reached the text No more entries is shown in the displayed table Use the button to start o...

Page 243: ...of frames which size is less than 64 octets received with invalid CRC Jabb The number of frames which size is larger than 64 octets received with invalid CRC Coll The best estimate of the total numbe...

Page 244: ...ayed table starting from that or the next closest Alarm table match The will use the last entry of the currently displayed entry as a basis for the next lookup When the end is reached the text No more...

Page 245: ...t index Buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to refresh the page immediately Updates the table starting from the...

Page 246: ...tton will update the displayed table starting from that or the next closest Event table match The will use the last entry of the currently displayed entry as a basis for the next lookup When the end i...

Page 247: ...id and for GLAGs as aggr id Partner System ID The system ID MAC address of the aggregation partner Partner Key The Key that the partner has assigned to this aggregation ID Last changed The time since...

Page 248: ...up but will join if other port leaves Meanwhile it s LACP status is disabled Key The key assigned to this port Only ports with the same key can aggregate together Aggr ID The Aggregation ID assigned t...

Page 249: ...umber LACP Received Shows how many LACP frames have been received at each port LACP Transmitted Shows how many LACP frames have been sent from each port Discarded Shows how many unknown or illegal LAC...

Page 250: ...n The currently configured port action Transmit The currently configured port transmit mode Loops The number of loops detected on this port Status The current loop protection status of the port Loop W...

Page 251: ...The Bridge ID of this Bridge instance Root ID The Bridge ID of the currently elected root bridge Root Port The switch port currently assigned the root port role Root Cost Root Path Cost For the Root B...

Page 252: ...ansmitted on the port STP The number of legacy STP Configuration BPDU s received transmitted on the port TCN The number of legacy Topology Change Notification BPDU s received transmitted on the port D...

Page 253: ...d transmitted on the port STP The number of legacy STP Configuration BPDU s received transmitted on the port TCN The number of legacy Topology Change Notification BPDU s received transmitted on the po...

Page 254: ...number of Transmitted Queries for IGMP and MLD respectively IGMPv1 Joins Received The number of Received IGMPv1 Join s IGMPv2 MLDv1 Report s Received The number of Received IGMPv2 Join s and MLDv1 Rep...

Page 255: ...ll update the displayed table starting from that or the closest next MVR Channels Groups Information Table match In addition the two input fields will upon a Refresh button click assume the value of t...

Page 256: ...ess input fields allow the user to select the starting point in the MVR SFM Information Table Clicking the Refresh button will update the displayed table starting from that or the closest next MVR SFM...

Page 257: ...rdware Filter Switch Indicates whether data plane destined to the specific group address from the source IPv4 IPv6 address could be handled by chip or not Buttons Auto refresh Automatic refresh occurs...

Page 258: ...Version Working Querier Version currently Host Version Working Host Version currently Querier Status Shows the Querier status is ACTIVE or IDLE DISABLE denotes the specific interface is administrativ...

Page 259: ...er Static denotes the specific port is configured to be a router port Dynamic denotes the specific port is learnt to be a router port Both denote the specific port is configured or learnt to be a rout...

Page 260: ...he displayed table starting from that or the closest next IGMP Group Table match In addition the two input fields will upon a Refresh button click assume the value of the first displayed entry allowin...

Page 261: ...d group input fields allow the user to select the starting point in the IGMP SFM Information Table Clicking the Refresh button will update the displayed table starting from that or the closest next IG...

Page 262: ...e destined to the specific group address from the source IPv4 address could be handled by chip or not Buttons Auto refresh Automatic refresh occurs every 3 seconds Refresh Refreshes the displayed tabl...

Page 263: ...st Version currently Querier Status Shows the Querier status is ACTIVE or IDLE DISABLE denotes the specific interface is administratively disabled Queries Transmitted The number of Transmitted Queries...

Page 264: ...tes the specific port is learnt to be a router port Both denote the specific port is configured or learnt to be a router port Port Switch port number Status Indicate whether specific port is a router...

Page 265: ...displayed table starting from that or the closest next MLD Group Table match In addition the two input fields will upon a Refresh button click assume the value of the first displayed entry allowing f...

Page 266: ...eginning of the MLD SFM Information Table The Start from VLAN and group input fields allow the user to select the starting point in the MLD SFM Information Table Clicking the Refresh button will updat...

Page 267: ...Allow or Deny Hardware Filter Switch Indicates whether data plane destined to the specific group address from the source IPv6 address could be handled by chip or not Buttons Auto refresh Automatic re...

Page 268: ...n of the neighbour s LLDP frames Port ID The Port ID is the identification of the neighbour port Port Description Port Description is the port description advertised by the neighbour unit System Name...

Page 269: ...neighbour unit s address that is used for higher layer entities to assist discovery by the network management This could for instance hold the neighbour s IP address Buttons Auto refresh Check this b...

Page 270: ...Bridge 3 IEEE 802 3 Repeater included for historical reasons 4 IEEE 802 11 Wireless Access Point 5 Any device that supports the IEEE 802 1AB and MED extensions defined by TIA 1057 and can relay IEEE...

Page 271: ...ategories expected to adhere to this class include but are not limited to Voice Media Gateways Conference Bridges Media Servers and similar Discovery services defined in this class include media type...

Page 272: ...ice services 4 Guest Voice Signaling for use in network topologies that require a different policy for the guest voice Signaling than for the guest voice media 5 Softphone Voice for use by softphone a...

Page 273: ...ority Priority is the Layer 2 priority to be used for the specified application type One of the eight priority levels 0 through 7 DSCP DSCP is the DSCP value to be used to provide Diffserv node behavi...

Page 274: ...Source or its Backup Power Source it is indicated as Unknown If the device is a PD device it can either run on its local power supply or it can use the PSE as power source It can also use both its lo...

Page 275: ...nagement LLDP PoE NGSME24G4S User Manual 275 is represented as reserved Buttons Auto refresh Check this box to refresh the page automatically Automatic refresh occurs every 3 seconds Refresh Click to...

Page 276: ...ke the transmitter to hold off to allow time for the receiver to wake from sleep Fallback Receive Tw The link partner s fallback receive Tw A receiving link partner may inform the transmitter of an al...

Page 277: ...resolved Rx Tw for this link Note NOT the link partner The resolved value that is the actual tx wakeup time used for this link based on EEE information exchanged via LLDP EEE in Sync Shows whether the...

Page 278: ...dded Shows the number of new entries added since switch reboot Total Neighbours Entries Deleted Shows the number of new entries deleted since switch reboot Total Neighbours Entries Dropped Shows the n...

Page 279: ...rame can contain multiple pieces of information known as TLVs TLV is short for Type Length Value If a TLV is malformed it is counted and discarded TLVs Unrecognized The number of well formed TLVs but...

Page 280: ...lass shows the PDs class Five Classes are defined Class 0 Max power 15 4 W Class 1 Max power 4 0 W Class 2 Max power 7 0 W Class 3 Max power 15 4 W Class 4 Max power 30 0 W Power Requested The Power R...

Page 281: ...d OFF Power budget exceeded The total requested or used power by the PDs exceeds the maximum power the Power Supply can deliver and port s with the lowest priority is are powered down No PD detected N...

Page 282: ...address and VLAN input fields allow the user to select the starting point in the MAC Table Clicking the Refresh button will update the displayed table starting from that or the closest next MAC Table...

Page 283: ...occurs every 3 seconds Refresh Refreshes the displayed table starting from the Start from MAC address and VLAN input fields Clear Flushes all dynamic entries Updates the table starting from the first...

Page 284: ...VLAN ID If a port is included in a VLAN the following image will be displayed If a port is in the forbidden port list the following image will be displayed If a port is in the forbidden port list and...

Page 285: ...eached the text No data exists for the selected user is shown in the table Use the button to start over Buttons Select VLAN Users from this drop down list Auto refresh Check this box to refresh the pa...

Page 286: ...s port based authentication which involves communications between a Supplicant Authenticator and an Authentication Server Voice VLAN Voice VLAN is a VLAN configured specially for voice traffic typical...

Page 287: ...ll frames or only tagged frames This parameter affects VLAN ingress processing If the port only accepts tagged frames untagged frames received on that port are discarded Tx Tag Shows egress filtering...

Page 288: ...lds described below apply Stack Topology State Shows the current stacking state and whether a reboot is required due to changed stack ports or stacking state on the stack configuration page Topology S...

Page 289: ...value Yes For details about the master election algorithm see Stack Configuration Help Master Forwarding Table As the heading suggests the information in the table is as seen from the master view For...

Page 290: ...e referred to as static NAS NAS provides port based authentication which involves communications between a Supplicant Authenticator and an Authentication Server MAC Address Indicates the MAC address V...

Page 291: ...local management If sFlow is currently configured through SNMP Owner contains a string identifying the sFlow receiver IP Address Hostname The IP address or hostname of the sFlow receiver Timeout The...

Page 292: ...divided into Rx and Tx flow samples where Rx flow samples contains the number of packets that were sampled upon reception ingress on the port and Tx flow samples contains the number of packets that we...

Page 293: ...P header The page refreshes automatically until responses to all packets are received or until a timeout occurs PING server 10 10 132 20 56 bytes of data 64 bytes from 10 10 132 20 icmp_seq 0 time 0ms...

Page 294: ...Chapter 3 Web Management Diagnostics Ping NGSME24G4S User Manual 294 Buttons Start Click to start transmitting ICMP packets New Ping Click to re start diagnostics with PING...

Page 295: ...icmp_seq 0 time 0ms 64 bytes from 10 10 132 20 icmp_seq 1 time 0ms 64 bytes from 10 10 132 20 icmp_seq 2 time 0ms 64 bytes from 10 10 132 20 icmp_seq 3 time 0ms 64 bytes from 10 10 132 20 icmp_seq 4 t...

Page 296: ...wn while running VeriPHY Therefore running VeriPHY on a 10 or 100 Mbps management port will cause the switch to stop responding until VeriPHY is complete The ports belong to the currently selected sta...

Page 297: ...Chapter 3 Web Management Diagnostics VeriPHY NGSME24G4S User Manual 297 Length The length in meters of the cable pair The resolution is 3 meters...

Page 298: ...g the PoE switch reset all settings except Switch s IP address back to default value updating switch firmware or upload download all system settings 3 4 1 Maintenance Restart Device You can restart th...

Page 299: ...restart is necessary Buttons Yes Click to reset the configuration to Factory Defaults No Click to return to the Port State page without resetting the configuration Note Restoring factory default can...

Page 300: ...button to choose the firmware file Update Click this button to start upload the firmware The system will inform you when the new firmware is uploaded to the switch After updating the firmware the swit...

Page 301: ...uration Save NGSME24G4S User Manual 301 3 4 3 Maintenance Configuration 3 4 3 1 Configuration Save You can save all the current setting values as a file in XML format Buttons Save Configuration Click...

Page 302: ...nagement Configuration Load NGSME24G4S User Manual 302 3 4 3 2 Configuration Load Buttons Choose File Click this button to choose the configuration file that you ve saved Upload Click to upload the co...

Page 303: ...rface This switch provides a CLI Command Line Interface management interface You can make all settings and monitor system status with this management CLI You can access the CLI via serial console teln...

Page 304: ...itch You can view system information status and configure the switch via command inputting As shown in the figure above a command prompt will available prompting you to input the command You can input...

Page 305: ...Name name Parameters name System name string 1 255 Example Contact Name Orwell System contact Orwell System Name Syntax System Name name Parameters name System name string 1 255 Example Contact Name...

Page 306: ...ip_router vid Example IP 192 168 2 2 Mask 255 255 255 0 Gateway 192 168 2 254 VID 1 switch IP setup 192 168 2 2 255 255 255 0 192 168 2 254 1 NTP Enable NTP Mode by below command switch IP ntp mode en...

Page 307: ...tate ipv6_addr enable disable IP IPv6 Ping6 ipv6_addr Length ping_length Count ping_count Interval ping_interval Auto Configuration Syntax IP IPv6 AUTOCONFIG enable disable Example switch IP ipv6 auto...

Page 308: ...NTP Setting Status Check the NTP Server settings by below command switch IP ntp conf IP NTP Configuration NTP Mode Enabled Idx Server IP host address a b c d or a host name string 1 192 168 100 1 2 1...

Page 309: ...witch System log level err Clear Syslog Syntax System Log Clear all info warning error switch System log clear all System Log Configuration switch System log conf System Log Configuration System Log S...

Page 310: ...mmand Line Stack List System Group Description Show the list of switches in stack Syntax Stack List detailed productinfo Parameters detailed productinfo Show product information System Contact Syntax...

Page 311: ...e 1 en Port state 1 dis Link Speed and Duplex Syntax Port Mode port_list auto 10hdx 10fdx 100hdx 100fdx 1000fdx sfp_auto_ams 100 0x_ams 100fx_ams 1000x 100fx Example Port mode 2 1000fdx Configure port...

Page 312: ...9600 Disabled Discard 1Gfdx Port Mode Port mode 2 Port Mode Link 2 Auto 1Gfdx Port Status All Information switch Port config Port Configuration Port State Mode Flow Control MaxFrame Power Excessive Li...

Page 313: ...Management Port NGSME24G4S User Manual 313 2 Enabled Auto Disabled 9600 Disabled Discard 1Gfdx Port Statistic switch Port statistic 1 Port 1 Statistics Rx Packets 0 Tx Packets 0 Rx Octets 0 Tx Octets...

Page 314: ...ing time range is 10 1000000 MAC age 0 0 Disable Aging time MAC Learning Configuration Syntax MAC Learning port_list auto disable secure Example MAC lear 1 8 sec MAC lear 9 12 dis MAC learn 1 12 auto...

Page 315: ...Example VLAN add 3 5 8 Add port 5 8 to VLAN 3 VLAN name add vlan3 3 vlan3 is the name of VLAN 3 Port Configuration Syntax VLAN FrameType port_list all tagged untagged VLAN IngressFilter port_list enab...

Page 316: ...Configuration PVLAN Configuration Syntax PVLAN Configuration port_list PVLAN Add pvlan_id port_list PVLAN Delete pvlan_id PVLAN Lookup pvlan_id PVLAN Isolate port_list enable disable Example PVLAN add...

Page 317: ...Hypertext Transfer Protocol over Secure Socket Layer Security Switch Access Access management Security Switch SNMP Simple Network Management Protocol Security Switch RMON Remote Network Monitoring Use...

Page 318: ...5 Privilege Level Syntax Security Switch Privilege Level Group group_name cro crw sro srw cro Configuration Read Only crw Configuration Excute Read Write sro Status Statistics Read Only srw Status Sta...

Page 319: ...t radius en Authentication Configuration Security Switch auth conf Auth Configuration Client Authentication Method Local Authentication Fallback console local Disabled telnet local Disabled ssh local...

Page 320: ...e IP range from the 192 168 2 1 to 192 168 2 10 can access the web UI Security Switch access add 1 192 168 2 1 192 168 2 10 web SNMP System Configuration Mode Version Read Write Community Syntax Secur...

Page 321: ...00 255 255 255 0 SNMP Trap Server Setting Enter the SNMP Trap Configuration Group Security Switch SNMP trap Type up to move up one level or to go to root level Security Switch SNMP Trap Syntax Securit...

Page 322: ...itch SNMP Trap Inform Retry Times retries Example Security Switch SNMP trap auth fai en Security Switch SNMP trap link up en Security Switch SNMP trap info mode en Security Switch SNMP trap info time...

Page 323: ...ity Switch RMON Statistics Add stats_id data_source Security Switch RMON Statistics Delete stats_id Security Switch RMON Statistics Lookup stats_id Histroy Security Switch RMON History Add history_id...

Page 324: ...ing enable disable Security Network Limit Agetime age_time Example Security Network limit mode enable Security Network limit agin enable Security Network limit agetim 1000 Result Port Security Limit C...

Page 325: ...Holdtime hold_time Radius Assigned Security Network NAS RADIUS_QoS global port_list enable disable Security Network NAS RADIUS_VLAN global port_list enable disable Guest VLAN Security Network NAS Gues...

Page 326: ...lt All ports permit Permit forwarding default deny Deny forwarding rate_limiter Rate limiter number 1 15 or disable port_redirect Port list for copy of frames or disable mirror Mirror of frames enable...

Page 327: ...er Rate 9 1 PPS 10 300 KBPS ACL Policy Syntax Security Network ACL Policy port_list policy Example Security Network ACL policy 1 2 Access Control List Syntax Security Network ACL Add ace_id ace_id_nex...

Page 328: ...00 0xFFFF or any but excluding 0x800 IPv4 0x806 ARP and 0x86DD IPv6 smac Source MAC address xx xx xx xx xx xx or xx xx xx xx xx xx or xxxxxxxxxxxx x is a hexadecimal digit or any dmac Destination MAC...

Page 329: ...og_disable shutdown Shut down ingress port shut shut_disable Example Add one ACE Security Network ACL add 2 port 6 10 policy 3 8 ip ACE ID 2 added last Edit one ACE Security Network ACL add 1 port 1 5...

Page 330: ...dhcp relay mode en Assign one Server IP before enable the Relay mode Security Network dhcp rel info mode en Security Network dhcp rel info policy keep IP Source Guard IP Source Guard Configuration Syn...

Page 331: ...1 1 192 168 2 10 11 22 33 44 55 66 Static 5 2 192 168 2 101 00 0b 16 21 2c 37 ARP Inspection ARP Inspection Syntax Security Network ARP Inspection Configuration Security Network ARP Inspection Mode e...

Page 332: ...Server Syntax Security AAA RADIUS server_index enable disable ip_addr_string secret server_port Example Security aaa radi 1 en 192 168 2 200 password 1812 RADIUS Accounting Server Syntax Security AAA...

Page 333: ...192 168 2 200 1812 2 Disabled 1812 3 Disabled 1812 4 Disabled 1812 5 Disabled 1812 RADIUS Accounting Server Configuration Server Mode IP Address Secret Port 1 Enabled 192 168 2 200 1813 2 Disabled 181...

Page 334: ...ity Example STP msti pri MSTI Bridge Priority CIST 32768 STP msti pri 4096 The available priority parameter includes 0 4096 8192 12288 16384 20480 24576 28672 32768 36864 40960 45056 49152 53248 57344...

Page 335: ...P Msti Add msti vid range Example STP mst add 1 100 Add VLAN 100 to MSTI1 STP mst map MSTI VLANs mapped to MSTI MSTI1 100 MSTI2 No VLANs mapped MSTI3 No VLANs mapped MSTI4 No VLANs mapped MSTI5 No VLA...

Page 336: ...t Port list or all Port zero means aggregations path_cost STP port path cost 1 200000000 or auto Example Configure CIST 0 Port Path Cost STP msti port cost 0 all auto Path cost auto STP msti port cost...

Page 337: ...ontributors Syntax Aggr Mode smac dmac ip port enable disable smac Source MAC Address dmac Destination MAC Address ip IP Address port TCP UDP Port Number Example Only the Source MAC Hash is enabled Th...

Page 338: ...Chapter 4 CLI Management CLI Management Aggr NGSME24G4S User Manual 338 Example Configure port 5 8 to a LACP group lacp mode 5 8 en Mode Enable lacp key 5 8 100 Key 100 lacp role 5 8 act Role Enable...

Page 339: ...lt All ports Mode Description Set or show LACP mode Syntax LACP Mode port_list enable disable Parameters port_list Port list or all default All ports enable Enable LACP protocol disable Disable LACP p...

Page 340: ...System Prio 0 65535 Role Description Set or show the LACP role Syntax LACP Role port_list active passive Parameters port_list Port list or all default All ports active Initiate LACP negotiation passiv...

Page 341: ...default All ports clear Clear LACP statistics Timeout Description Set or show the LACP timeout Syntax LACP Timeout port_list fast slow Parameters port_list Port list or all default All ports fast Fast...

Page 342: ...rx tx rx RX Only tx TX Only Example Enable LLDP on Ports LLDP mode 1 10 en Port 1 10 are enabled LLDP mode 1 26 en Port 1 26 are enabled CDP aware Syntax LLDP cdp_aware port_list enable disable Exampl...

Page 343: ...ration Syntax LLDPMED Configuration port_list Parameters port_list Port list or all default All ports Civic Description Set or show LLDP MED Civic Address Location Syntax LLDPMED Civic country state c...

Page 344: ...Landmark or vanity address additional_info Additional location informationname Name residence and office occupant zip_code Postal zip code building Building structure apartment Unit apartment suite f...

Page 345: ...her similar appliances supporting interactive voice services These devices are typically deployed on a separate VLAN for ease of deployment and enhanced security by isolation from data applications vo...

Page 346: ...ion and other similar applications supporting streaming video services that require specific network policy treatment Video applications relying on TCP with buffering would not be an intended use of t...

Page 347: ...disable Parameters port_list Port list or all default All ports enable Enable EEE disable Disable EEE Example Enable Port 1 5 EEE mode 1 5 en Urgent Queue of Port Syntax EEE Urgent_queues port_list q...

Page 348: ...onfiguration Warning The default value is for reference only If the value is not comfort to your product specification please give the correct value before you start using PoE function Syntax PoE Maxi...

Page 349: ...2 3at Class 4 limited to 30W default Show PoE s mode Example Set Port 1 24 ro PoE mode PoE mode 1 24 poe PoE Status Primary Power Supply PoE prim Primary Power Supply 200 W Port Status PoE sta Port PD...

Page 350: ...disable Range of the Value class QoS class 0 7 dpl Drop Precedence Level 0 1 pcp Priority Code Point 0 7 dei Drop Eligible Indicator 0 1 Example QoS Port Classification clas 1 2 7 QoS Port Classificat...

Page 351: ...er Mode port_list strict weighted Example QoS Port Scheduler mode 1 2 stric Strict Priority QoS Port Scheduler mode 1 2 wei Weighted QoS Egress Port Scheduler and Shapers QoS Port Scheduler wei 1 2 1...

Page 352: ...nable disable QoS Port DSCP Classification port_list none zero selected all QoS Port DSCP EgressRemark port_list disable enable remap_dp_unaware remap_dp_aware Note DSCP is an advanced QoS setting ple...

Page 353: ...mand Line Mirroring Configuration Mirror Configuration Syntax Mirror Port port disable Mirror Mode port_cpu_list enable disable rx tx Example Mirror port 5 Mirror mode 6 8 en Result Mirror Configurati...

Page 354: ...Syntax Config Save ip_server file_name Parameters ip_server TFTP server IPv4 address a b c d file_name Configuration file name Load Description Load configuration from TFTP server Syntax Config Load...

Page 355: ...ring file_name Parameters ip_addr_string IP host address a b c d or a host name string file_name Firmware file name IPv6 Load Description Load new firmware from IPv6 TFTP server Syntax Firmware IPv6 L...

Page 356: ...Command Line UPnP Configuration UPnp Configuration Syntax UPnP Configuration UPnP Mode enable disable UPnP TTL ttl UPnP AdvertisingDuration duration Example UPnP mode en UPnP ttl 5 Default 4 UPnP adv...

Page 357: ...me port_list source receiver inactive Example Port 2 Source Port Port 6 7 Receiver Port MVR vlan port 2 2 source MVR vlan port 2 6 7 rec Immediately Leave Syntax MVR Immediate Leave port_list enable d...

Page 358: ...nt CLI Management MVR NGSME24G4S User Manual 358 MVR Immediate Leave Setting Port Immediate Leave 1 Enabled 2 Enabled 3 Enabled 4 Enabled 5 Enabled 6 Enabled 7 Enabled 8 Enabled 9 Enabled 10 Enabled 1...

Page 359: ...vlan age 86400 Voice vlan traff class 7 Result Voice VLAN Configuration Voice VLAN Mode Enabled Voice VLAN VLAN ID 100 Voice VLAN Age Time seconds 86400 Voice VLAN Traffic Class 7 Port Configuration...

Page 360: ...Voice VLAN OUI Delete oui_addr Voice VLAN OUI Clear Voice VLAN OUI Lookup oui_addr Example Voice VLAN oui add 00 12 08 hello Result Voice VLAN oui lookup Voice VLAN OUI Table Telephony OUI Descriptio...

Page 361: ...n time Example loop protect mode en Transmission Time loop protect trans 10 10 seconds Shutdown Time loop protect shut 200 200 seconds Port Configuration Loop Protection Port Configuration Syntax Loop...

Page 362: ...ve Proxy Enable Syntax IPMC Leave Proxy mld igmp enable disable Example IPMC leave proxy igmp en Enable IPMC leave proxy igmp dis Disable Proxy Enable Syntax IPMC Proxy mld igmp enable disable Example...

Page 363: ...Parameter LLQI mld igmp vid ipmc_param_llqi IPMC Parameter URI mld igmp vid ipmc_param_uri Example IPMC state igmp 2 en Enable IGMP Snooping on VLAN 2 IPMC quer igmp 2 en Enable IGMP Querier on VLAN...

Page 364: ...168 2 100 UDP Port 6343 Max Datagram 1400 bytes Time left 0 seconds Receiver Release sFlow receiver Port Configuration Syntax sFlow Receiver release timeout ip_addr_host udp_port datagram_size sFlow F...

Page 365: ...Chapter 4 CLI Management CLI Management sFlow NGSME24G4S User Manual 365 Per Port Statistics Port Rx Flow Samples Tx Flow Samples Counter Samples 1 0 0 0 2 0 0 0...

Page 366: ...c 37 10 1 4 Protocol based VLAN Configuration Protocol to Group Syntax VCL ProtoVlan Protocol Add Eth2 ether_type arp ip ipx at group_id Example VCL ProtoVlan protocol add Eth2 0x0808 E4 Group to VLAN...

Page 367: ...ation Syntax VCL IPVlan Add vce_id ip_addr_mask vid port_list Parameters vce_id Unique VCE ID for each VCL entry ip_addr_mask Source IP address and mask Format a b c d n vid VLAN ID 1 4095 port_list P...

Page 368: ...e changes even within the product s operating temperature range may cause malfunctions DO NOT install this product in a location near any sources of water or liquid DO NOT stack this product with othe...

Page 369: ...ng section will guide you to set the IP address properly in a Microsoft Windows 8 environment Setting IP address in other Microsoft operating system such as Windows Vista or Windows 7 is quite the sam...

Page 370: ...ME24G4S User Manual 370 3 An Ethernet Status window will pop up Please click on the Properties button as shown in the figure down below 4 An Ethernet Properties window will pop up Please double click...

Page 371: ...hown in the figure down below By default your product s IP address should be 192 168 2 1 You can set any IP address as long as it s not the same with your product s IP address and is in the same netwo...

Page 372: ...prioritized for the various situation In networking the ACL refers to a list of service ports or network services that are available on a host or server each with a list of hosts or servers permitted...

Page 373: ...ion Using multiple ports in parallel to increase the link speed beyond the limits of a port and to increase the redundancy for higher availability ARP ARP is an acronym for Address Resolution Protocol...

Page 374: ...CP server ensures that all IP addresses are unique for example no IP address is assigned to a second client while the first client s assignment is valid its lease has not expired Therefore IP address...

Page 375: ...legitimate conversation between the DHCP client and server DNS DNS is an acronym for Domain Name System It stores and associates many types of information with domain names Most importantly DNS transl...

Page 376: ...sing applies to IGMP and MLD H HTTP HTTP is an acronym for Hypertext Transfer Protocol It is a protocol that used to transfer or convey information on the World Wide Web WWW HTTP defines how messages...

Page 377: ...or simple exchanges such as time stamp or echo transactions For example the PING command uses ICMP to test an Internet connection IEEE 802 1X IEEE 802 1X is an IEEE standard for port based Network Acc...

Page 378: ...et network IP is a best effort system which means that no packet of information sent over is assured to reach its destination in the same condition it was sent Each device connected to a Local Area Ne...

Page 379: ...standard protocol The Link Layer Discovery Protocol LLDP specified in this standard allows stations attached to an IEEE 802 LAN to advertise to other stations attached to the same IEEE 802 LAN the ma...

Page 380: ...C table with these dynamic MAC addresses Dynamic entries are removed from the MAC table if no frame with the corresponding SMAC address has been seen after a configurable age time Mirroring For debugg...

Page 381: ...le if the switch shall include the TLV in the LLDP frame These TLVs are known as optional TLVs If an optional TLVs is disabled the corresponding information is not included in the LLDP frame OUI OUI i...

Page 382: ...used for powering IP telephones wireless LAN access points and other equipment where it would be difficult or expensive to connect the equipment to main power supply Policer A policer can limit the ba...

Page 383: ...vide secure predictable measurable and sometimes guaranteed services Achieving the required QoS becomes the secret to a successful end to end business solution Therefore QoS is the set of techniques t...

Page 384: ...rotocol It is a text based protocol that uses the Transmission Control Protocol TCP and provides a mail service modeled on the FTP file transfer service SMTP transfers mail messages between systems an...

Page 385: ...r Terminal Acess Controller Access Control System Plus It is a networking protocol which provides access control for routers network access servers and other networked computing devices via one or mor...

Page 386: ...otocol UDP and provides file writing and reading but it does not provide directory service and security features ToS ToS is an acronym for Type of Service It is implemented as the IPv4 ToS priority co...

Page 387: ...it field storing the priority level for the 802 1Q frame It is also known as PCP V VLAN Virtual LAN A method to restrict communication between switch ports VLANs can be used for the following applicat...

Page 388: ...a 12 bit field specifying the VLAN to which the frame belongs Voice VLAN Voice VLAN is VLAN configured specially for voice traffic By adding the ports with voice devices attached to voice VLAN we can...

Reviews: