background image

User’s Manual of GS-4210-16T2S_24T2S_16P2S_24P2S_48T4S 

 

 

23 

 

 

Product 

GS-4210-16P2S 

GS-4210-24P2S 

Hardware Specifications 

10/100/1000T   

Auto-MDI/MDI-X Copper ports 

16 

24 

802.3af/at PoE Injector Port 

16 

24 

SFP/mini-GBIC Slots 

Two 100/1000BASE-X SFP interfaces, supporting 100/1000Mbps dual mode 

Console 

One RS-232-to-RJ45 serial port (115200, 8, N, 1) 

Reset Button 

System factory default 

Switch Architecture 

Store-and-Forward 

Switch Fabric 

36Gbps/non-blocking 

52Gbps/non-blocking 

Switch Throughput@64 bytes 

26.7Mpps @64 bytes 

38.6Mpps @64 bytes 

MAC Address Table 

8K entries   

Shared Data Buffer 

4.1 megabits 

Flow Control 

IEEE 802.3x pause frame for full-duplex 
Back pressure for half-duplex 

Jumbo Frame 

10K bytes 

Reset Button 

> 5 sec: Factory default 

LED 

System: 

Power (

Green

10/100/1000T RJ45 Interfaces   

(Port 1 to Port 16): 
1000 LNK/ACT (

Green

),   

10/100 LNK/ACT (

Orange

),   

PoE (

Orange

100/1000Mbps SFP Interfaces   
(Port 17 to Port 18): 
1000 LNK/ACT (

Green

),   

100 LNK/ACT (

Orange

System: 

Power (

Green

10/100/1000T RJ45 Interfaces   

(Port 1 to Port 24): 
1000 LNK/ACT (

Green

),   

10/100 LNK/ACT (

Orange

),   

PoE (

Orange

100/1000Mbps SFP Interfaces   
(Port 25 to Port 26): 
1000 LNK/ACT (

Green

),   

100 LNK/ACT (

Orange

Thermal Fan 

Power Requirements 

AC 100~240V, 50/60Hz, auto-sensing. 

Power 

Consumption/Dissipation 

Max. 260 watts/886 BTU 

Max. 330 watts/1122 BTU 

Dimensions (W x D x H) 

440 x 208 x 44 mm (1U height) 

445 x 207 x 45 mm (1U height) 

Weight 

2.8kg 

ESD Protection 

Yes 

Enclosure 

Metal 

Layer 2 Functions

 

PoE Standard 

I

EEE 802.3af Power over Ethernet/PSE 

IEEE 802.3at Power over Ethernet Plus/PSE 

PoE Power Output 

Per Port 52V DC, 300mA. Max. 15.4 watts (IEEE 802.3af) 

Per Port 52V DC, 600mA. Max. 30 watts (IEEE 802.3at) 

PoE Power Budget 

300 watts 

220 watts 

Summary of Contents for GS-4210-16P2S

Page 1: ...User s Manual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 1 ...

Page 2: ...ide reasonable protection against harmful interference when the equipment is operated in a commercial environment This equipment generates uses and can radiate radio frequency energy and if not installed and used in accordance with the Instruction manual may cause harmful interference to radio communications Operation of this equipment in a residential area is likely to cause harmful interference ...

Page 3: ...D Indications 29 2 1 3 Switch Rear Panel 33 2 2 Installing the Switch 34 2 2 1 Desktop Installation 34 2 2 2 Rack Mounting 35 2 2 3 Installing the SFP transceiver 36 3 SWITCH MANAGEMENT 39 3 1 Requirements 39 3 2 Management Access Overview 40 3 3 Administration Console 41 3 4 Web Management 42 3 5 SNMP based Network Management 43 3 6 PLANET Smart Discovery Utility 44 4 WEB CONFIGURATION 46 4 1 Mai...

Page 4: ...SNMP View 73 4 2 7 4 SNMP Access Group 75 4 2 7 5 SNMP Community 77 4 2 7 6 SNMP User 78 4 2 7 7 SNMPv1 2 Notification Recipients 80 4 2 7 8 SNMPv3 Notification Recipients 83 4 2 7 9 SNMP Engine ID 85 4 2 7 10 SNMP Remote Engine ID 86 4 3 Port Management 87 4 3 1 Port Configuration 87 4 3 2 Port Counters 90 4 3 3 Bandwidth Utilization 96 4 3 4 Port Mirroring 97 4 3 5 Jumbo Frame 100 4 3 6 Port Err...

Page 5: ...44 4 5 14 1 Two separate 802 1Q VLANs 144 4 5 14 2 VLAN Trunking between two 802 1Q aware switch 147 4 6 Spanning Tree Protocol 151 4 6 1 Theory 151 4 6 2 STP Global Settings 157 4 6 3 STP Port Setting 159 4 6 4 CIST Instance Setting 162 4 6 5 CIST Port Setting 165 4 6 6 MST Instance Configuration 168 4 6 7 MST Port Setting 170 4 6 8 STP Statistics 172 4 7 Multicast 174 4 7 1 Properties 174 4 7 2 ...

Page 6: ...erties 209 4 8 2 2 QoS Port Settings 210 4 8 2 3 Queue Settings 212 4 8 2 4 CoS Mapping 213 4 8 2 5 DSCP Mapping 215 4 8 2 6 IP Precedence Mapping 217 4 8 3 QoS Basic Mode 219 4 8 3 1 Global Settings 219 4 8 3 2 Port Settings 220 4 8 4 QoS Advanced Mode 222 4 8 4 1 Global Settings 222 4 8 4 2 Class Mapping 223 4 8 4 3 Aggregate Police 224 4 8 4 4 Policy Table 225 4 8 4 5 Policy Class Maps 226 4 8 ...

Page 7: ...9 3 3 VLAN Setting 260 4 9 3 4 Port Setting 262 4 9 3 5 Statistics 264 4 9 3 6 Rate Limit 265 4 9 3 7 Option82 Global Setting 267 4 9 3 8 Option82 Port Setting 268 4 9 3 9 Option82 Circuit ID Setting 271 4 9 4 Dynamic ARP Inspection 272 4 9 4 1 Global Setting 272 4 9 4 2 VLAN Setting 273 4 9 4 3 Port Setting 274 4 9 4 4 Statistics 276 4 9 4 5 Rate Limit 277 4 9 5 IP Source Guard 278 4 9 5 1 Port S...

Page 8: ... MAC Filtering 327 4 11 3 Dynamic Address Setting 328 4 11 4 Dynamic Learned 329 4 11 5 RMA Setting 331 4 12 LLDP 332 4 12 1 Link Layer Discovery Protocol 332 4 12 2 LLDP Global Setting 332 4 12 3 LLDP Port Setting 335 4 12 4 LLDP Local Device 340 4 12 5 LLDP Remote Device 347 4 12 6 MED Network Policy 348 4 12 7 MED Port Setting 352 4 12 8 LLDP Overloading 356 4 12 9 LLDP Statistics 357 4 13 Diag...

Page 9: ...1 Factory Default 386 4 16 2 Reboot Switch 387 4 16 3 Backup Manager 388 4 16 4 Upgrade Manager 389 4 16 5 Configuation Manager 390 4 16 6 Enable Password 391 5 COMMAND LINE INTERFACE 392 5 1 Accessing the CLI 392 Logon to the Console 392 Configure IP address 393 5 2 Telnet Login 394 6 Command Line Mode 395 6 1 User Mode Commands 396 6 1 1 enable command 396 6 1 2 exit command 397 6 1 3 ping comma...

Page 10: ...05 6 2 5 debug command 405 6 2 6 delete command 406 6 2 7 disable command 406 6 2 8 end command 406 6 2 9 exit command 407 6 2 10 no command 407 6 2 11 ping command 408 6 2 12 reboot command 408 6 2 13 renew command 408 6 2 14 restore defaults command 409 6 2 15 save command 409 6 2 16 show command 409 6 2 17 ssl command 410 6 2 18 traceroute command 410 6 2 19 udld command 411 6 3 Global Config M...

Page 11: ... 23 lldp Command 418 6 3 24 logging Command 418 6 3 25 mac Command 418 6 3 26 management vlan Command 418 6 3 27 mirror Command 419 6 3 28 no Command 419 6 3 29 policy map Command 419 6 3 30 port security Command 419 6 3 31 qos Command 420 6 3 32 radius Command 420 6 3 33 rate limit Command 420 6 3 34 rmon Command 420 6 3 35 Snmp Command 421 6 3 36 sntp Command 421 6 3 37 spanning tree Command 421...

Page 12: ...7 2 Learning 424 7 3 Forwarding Filtering 424 7 4 Store and Forward 424 7 5 Auto Negotiation 426 8 POWER OVER ETHERNET OVERVIEW 427 9 TROUBLESHOOTING 429 APPENDIX A 430 A 1 Switch s RJ45 Pin Assignments 1000Mbps 1000BASE T 430 A 2 10 100Mbps 10 100BASE TX 430 ...

Page 13: ... 4210 24P2S 24 Port 10 100 1000T 802 3at PoE 2 Port 100 1000X SFP Managed Switch Managed Switch mentioned in this Guide refers to the GS 4210 16T2S GS 4210 24T2S GS 4210 16P2S GS 4210 24P2S and GS 4210 48T4S 1 1 Package Contents Open the box of the Managed Switch and carefully unpack it The box should contain the following items The Managed Switch x 1 Quick Installation Guide x 1 Rubber Feet x 4 P...

Page 14: ...witch GS 4210 16P2S and GS 4210 24P2S The PoE in line power following the IEEE 802 3at af standard makes the GS 4210 16P2S and GS 4210 24P2S able to deliver Gigabit speed data and up to 30 watts of power per port to 16 24 PoE compliant powered devices PDs with a combined power output budget of up to 240 300 watts The GS 4210 16P2S and GS 4210 24P2S provides more flexibility in power requirement fo...

Page 15: ...rce and destination IP address TCP UDP ports or defined typical network applications Its protection mechanism also comprises 802 1X port based authentication which can be deployed with RADIUS to ensure the port level security and block illegal users With the protected port function communication between edge ports can be prevented to guarantee user privacy Furthermore port security function allows...

Page 16: ...e Managed Switch by Web interface Section 5 COMMAND LINE INTERFACE The section describes how to use the Command Line interface CLI Section 6 CLI CONFIGURATION The section explains how to manage the Managed Switch by Command Line interface Section 7 SWITCH OPERATION The chapter explains how to do the switch operation of the Managed Switch Section 8 POWER OVER ETHERNET OVERVIEW The chapter introduce...

Page 17: ...Automatic address learning and address aging Supports CSMA CD protocol Power over Ethernet GS 4210 16P2S and GS 4210 24P2S Complies with IEEE 802 3at High Power over Ethernet Complies with IEEE 802 3af Power over Ethernet Up to 16 24 ports of IEEE 802 3af 802 3at devices powered Supports PoE Power up to 30 8 watts for each PoE port 240 300 watt PoE budget Auto detects powered device PD Circuit pro...

Page 18: ...ice Ingress Egress Rate Limit per port bandwidth control Traffic classification IEEE 802 1p CoS DSCP IP Precedence of IPv4 IPv6 packets Strict priority and Weighted Round Robin WRR CoS policies Multicast Supports IPv4 IGMP snooping v2 and v3 Supports IPv6 MLD snooping v1 v2 IGMP querier mode support IGMP snooping port filtering MLD snooping port filtering Security Storm Control support Broadcast U...

Page 19: ...IPv4 IPv6 Web switch management Telnet Command Line Interface SNMP v1 v2c and v3 HTTPs secure access Built in Trivial File Transfer Protocol TFTP client Static and DHCP for IP address assignment System Maintenance Firmware upload download via HTTP TFTP Configuration upload download through HTTP TFTP Hardware reset button for system reset to factory default SNTP Network Time Protocol Cable diagnost...

Page 20: ...ory default LED System Power Green 10 100 1000T RJ45 Ports Port 1 to Port 16 1000 LNK ACT Green 10 100 LNK ACT Orange 100 1000Mbps SFP Ports Port 17 to Port 18 1000 LNK ACT Green 100 LNK ACT Orange System Power Green 10 100 1000T RJ45 Ports Port 1 to Port 24 1000 LNK ACT Green 10 100 LNK ACT Orange 100 1000Mbps SFP Ports Port 25 to Port 26 1000 LNK ACT Green 100 LNK ACT Orange System PWR Power Gre...

Page 21: ...v6 IP based ACE MAC based ACE QoS 8 mapping ID to 8 level priority queues Port Number 802 1p priority DSCP IP Precedence of IPv4 IPv6 packets Traffic classification based strict priority and WRR Ingress Egress Rate Limit per port bandwidth control Security IEEE 802 1X port based authentication Built in RADIUS client to co operate with RADIUS server RADIUS TACACS authentication IP MAC port binding ...

Page 22: ... IEEE 802 3x Flow Control and Back pressure IEEE 802 3ad Port Trunk with LACP IEEE 802 1D Spanning Tree protocol IEEE 802 1w Rapid Spanning Tree protocol IEEE 802 1s Multiple Spanning Tree protocol IEEE 802 1p Class of Service IEEE 802 1Q VLAN Tagging IEEE 802 1x Port Authentication Network Control IEEE 802 1ab LLDP RFC 768 UDP RFC 793 TFTP RFC 791 IP RFC 792 ICMP RFC 2068 HTTP RFC 1112 IGMP versi...

Page 23: ...D System Power Green 10 100 1000T RJ45 Interfaces Port 1 to Port 16 1000 LNK ACT Green 10 100 LNK ACT Orange PoE Orange 100 1000Mbps SFP Interfaces Port 17 to Port 18 1000 LNK ACT Green 100 LNK ACT Orange System Power Green 10 100 1000T RJ45 Interfaces Port 1 to Port 24 1000 LNK ACT Green 10 100 LNK ACT Orange PoE Orange 100 1000Mbps SFP Interfaces Port 25 to Port 26 1000 LNK ACT Green 100 LNK ACT...

Page 24: ...PDU Guard BPDU Filtering and BPDU Forwarding IGMP Snooping IPv4 IGMP v2 v3 Snooping IGMP Querier Up to 256 multicast groups MLD Snooping IPv6 MLD v1 v2 snooping up to 256 multicast groups Access Control List IPv4 IPv6 IP based ACL MAC based ACL IPv4 IPv6 IP based ACE MAC based ACE QoS 8 mapping ID to 8 level priority queues Port Number 802 1p priority DSCP IP Precedence of IPv4 IPv6 packets Traffi...

Page 25: ...nce Regulatory Compliance FCC Part 15 Class A CE Standards Compliance IEEE 802 3 10BASE T IEEE 802 3u 100BASE TX 100BASE FX IEEE 802 3z Gigabit SX LX IEEE 802 3ab Gigabit 1000BASE T IEEE 802 3x Flow Control and Back pressure IEEE 802 3ad Port Trunk with LACP IEEE 802 1D Spanning Tree protocol IEEE 802 1w Rapid Spanning Tree protocol IEEE 802 1s Multiple Spanning Tree protocol IEEE 802 1p Class of ...

Page 26: ...er s Manual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 26 Operating Temperature 0 50 degrees C Relative Humidity 5 95 non condensing Storage Temperature 10 70 degrees C Relative Humidity 5 95 non condensing ...

Page 27: ...tors Before connecting any network device to the Managed Switch please read this chapter completely 2 1 Hardware Description 2 1 1 Switch Front Panel The front panel provides a simple interface monitoring the Managed Switch Figure 2 1 1 Figure 2 1 2 Figure 2 1 3 Figure 2 1 4 and Figure 2 1 5 show their front panels Front Panel Figure 2 1 1 GS 4210 16T2S Front Panel Front Panel Figure 2 1 2 GS 4210...

Page 28: ...stic information including IP Address setting factory reset port management link status and system setting Users can use the attached DB9 to RJ45 console cable in the package and connect to the console port on the device After the connection users can run any terminal emulation program Hyper Terminal ProComm Plus Telix Winterm and so on to enter the startup screen of the device Reset Button In the...

Page 29: ...cessfully established at 1000Mbps Blinks To indicate that the switch is actively sending or receiving data over that port 10 100 LNK ACT Orange Lights Blinks To indicate the link through that port is successfully established at 10Mbps or 100Mbps To indicate that the switch is actively sending or receiving data over that port 100 1000BASE X SFP Interfaces LED Color Function 1000 LNK ACT Green Light...

Page 30: ...k through that port is successfully established at 1000Mbps Blinks To indicate that the switch is actively sending or receiving data over that port 100 LNK ACT Orange Lights To indicate the link through that port is successfully established at 100Mbps Blinks To indicate that the switch is actively sending or receiving data over that port LED Indication Figure 2 1 8 GS 4210 48T4S LED Panel System L...

Page 31: ...gh that port is successfully established at 1000Mbps Blinks To indicate that the switch is actively sending or receiving data over that port 10 100 LNK ACT Orange Lights Blinks To indicate the link through that port is successfully established at 10Mbps or 100Mbps To indicate that the switch is actively sending or receiving data over that port PoE in Use Orange Lights To indicate the port is provi...

Page 32: ...s successfully established at 10Mbps or 100Mbps To indicate that the switch is actively sending or receiving data over that port PoE in Use Orange Lights To indicate the port is providing 52V DC in line power Off To indicate the connected device is not a PoE Powered Device PD 100 1000BASE X SFP Interfaces LED Color Function 1000 LNK ACT Green Lights To indicate the link through that port is succes...

Page 33: ...tch s power supply automatically adjusts to line power in the range of 100 240V AC and 50 60Hz Plug the female end of the power cord firmly into the receptacle on the rear panel of the Managed Switch Plug the other end of the power cord into an electrical outlet and the power will be ready Power Notice The device is a power required device which means it will not work till it is powered If your ne...

Page 34: ...witch on the desktop or the shelf near an AC power source as shown in Figure 2 1 14 Figure 2 1 14 Place the Managed Switch on the desktop Step3 Keep enough ventilation space between the Managed Switch and the surrounding objects When choosing a location please keep in mind the environmental restrictions discussed in Chapter 1 Section 4 and specifications Step 4 Connecting the Managed Switch to net...

Page 35: ...nt panel positioned towards the front side Step2 Attach the rack mount bracket to each side of the Managed Switch with supplied screws attached to the package Figure 2 1 15 shows how to attach brackets to one side of the Managed Switch Figure 2 1 15 Attach Brackets to the Managed Switch You must use the screws supplied with the mounting brackets Damage caused to the parts by using incorrect screws...

Page 36: ...twork cabling and supply power to the Managed Switch 2 2 3 Installing the SFP transceiver The sections describe how to insert an SFP transceiver into an SFP slot The SFP transceivers are hot pluggable and hot swappable You can plug in and out the transceiver to from any SFP port without having to power down the Managed Switch as the Figure 2 1 17 shows Figure 2 1 17 Plug In the SFP Transceiver ...

Page 37: ...FX SFP Port 100BASE FX Transceiver 2KM MFB F20 SFP Port 100BASE FX Transceiver 20KM MFB F40 SFP Port 100BASE FX Transceiver 40KM MFB F60 SFP Port 100BASE FX Transceiver 60KM MFB FA20 SFP Port 100BASE BX Transceiver WDM TX 1310nm 20KM MFB FB20 SFP Port 100BASE BX Transceiver WDM TX 1550nm 20KM It is recommended to use PLANET SFP on the Managed Switch If you insert an SFP transceiver that is not sup...

Page 38: ...function with some fiber NICs or Media Converters user has to set the port Link mode to 1000 Force or 100 Force Removing the Transceiver Module 1 Make sure there is no network activity anymore 2 Remove the fiber optic cable gently 3 Lift up the lever of the MGB module and turn it to a horizontal position 4 Pull out the module gently through the lever Figure 2 1 18 How to Pull Out the SFP Transceiv...

Page 39: ...Access Overview Administration Console Access Web Management Access SNMP Access Standards Protocols and Related Reading 3 1 Requirements Workstations running Windows 2000 XP 2003 Vista 7 8 10 2008 MAC OS9 or later Linux UNIX or other platforms are compatible with TCP IP protocols Workstation is installed with Ethernet NIC Network Interface Card Serial Port connect Terminal The above PC with COM Po...

Page 40: ...elnet functionality and HyperTerminal built into Windows 2000 XP 2003 Vista 7 8 10 2008 operating systems Secure Must be near the switch or use dial up connection Not convenient for remote users Modem connection may prove to be unreliable or slow Web Browser Ideal for configuring the switch remotely Compatible with all popular browsers Can be accessed from any location Most visually appealing Secu...

Page 41: ...cess The following sections describe these methods For more information about using the console refer to Chapter 5 Command Line Interface Console Management Figure 3 1 Console Management Direct Access Direct access to the administration console is achieved by directly connecting a terminal or a PC equipped with a terminal emulation program such as HyperTerminal to the Managed Switch console serial...

Page 42: ...at allow users to manage the Managed Switch from anywhere on the network through a standard browser such as Microsoft Internet Explorer After you set up your IP address for the Managed Switch you can access the Managed Switch s Web interface applications directly in your Web browser by entering the IP address of the Managed Switch Figure 3 3 Web Management You can then use your Web browser to list...

Page 43: ...nagement method requires the SNMP agent on the switch and the SNMP Network Management Station to use the same community string This management method in fact uses two community strings the get community string and the set community string If the SNMP Network management Station only knows the set community string it can read and write to the MIBs However if it only knows the get community string it...

Page 44: ...1 Download the PLANET Smart Discovery Utility from PLANET Official Website 2 Deposit the Planet Smart Discovery Utility in administrator PC 3 Run this utility as the following screen appears Figure 3 6 Planet Smart Discovery Utility Screen If there are two LAN cards or above in the same administrator PC choose a different LAN card by using the Select Adapter tool 4 Press Refresh button for the cur...

Page 45: ...re shown below Update Device use current setting on one single device Update Multi use current setting on choose multi devices Update All use current setting on whole devices in the list The same functions mentioned above also can be found in Option tools bar 3 To click the Control Packet Force Broadcast function it allows you to assign a new setting value to the Web Smart Switch under a different...

Page 46: ...ble Java Applets to use network ports The Managed Switch can be configured through an Ethernet connection making sure the manager PC must be set on the same IP subnet address as the Managed Switch For example the default IP address of the Managed Switch is 192 168 0 100 then the manager PC should be set at 192 168 0 x where x is a number between 1 and 254 except 100 and the default subnet mask is ...

Page 47: ... changed via console to login the main screen of Managed Switch The login screen in Figure 4 1 2 appears Figure 4 1 2 Login Screen Default User name admin Default Password admin The following web screen based on GS 4210 24T2S will be the same as that of GS 4210 16T2S GS 4210 48T4S GS 4210 16P2S and GS 4210 24P2S After entering the username and password the main screen appears as Figure 4 1 3 ...

Page 48: ... the web page let you access all the commands and statistics the Managed Switch provides It is recommended to use Internet Explore 8 0 or above to access Managed Switch The changed IP address takes effect immediately after clicking on the Apply button You need to use the new IP address to access the Web interface For security reason please change and memorize the new password after this first setu...

Page 49: ...h s ports The Mode can be set to display different information for the ports including Link up or Link down Clicking on the image of a port opens the Port Status page The port states are illustrated as follows State Disabled Down Link RJ45 Ports SFP Ports Main Menu Using the onboard web agent you can define system parameters manage and control the Managed Switch and all its ports or monitor networ...

Page 50: ...ch Main Functions Menu Buttons Click to save changes or reset to default Click to logout the Managed Switch Click to reboot the Managed Switch Click to refresh the page The PoE function only available on GS 4210 16P2S and GS 4210 24P2S the GS 4210 SERIES does not support this function ...

Page 51: ...ult parameter For more detailed information please refer to the chapter 4 15 1 4 1 2 Configuration Manager The system file folder contains configuration settings The screen in Figure 4 1 7 appears Figure 4 1 7 Save Button Screenshot The page includes the following fields Object Description Running Configuration Refers to the running configuration sequence use in the switch In switch the running co...

Page 52: ...nfiguration file to be startup config Backup Configuration The backup configuration is empty in FLASH please save the backup configuration first by Maintenance Backup Manager Button Click to save configuration 4 1 2 1 Saving Configuration In the Managed Switch the running configuration file stores in the RAM In the current version the running configuration sequence of running config can be saved f...

Page 53: ...al of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 53 2 Select Source File Running Configuration and Destination File Startup Configuration 3 Press the Apply button to save running configuration to startup configuration ...

Page 54: ...re new user name and password on this page Time Settings Configure SNTP on this page Log Management The switch log information is provided here SNMP Management Configure SNMP on this page 4 2 1 System Information The System Info page provides information for the current device information System Info page helps a switch administrator to identify the hardware MAC address software version and system...

Page 55: ... time the device has been operational Button Click to edit parameter 4 2 2 IP Configuration The IP Configuration includes the IP Address Subnet Mask and Gateway The Configured column is used to view or change the IP configuration Fill up the IP Address Subnet Mask and Gateway for the device The screens in Figure 4 2 2 Figure 4 2 3 appear Figure 4 2 2 IP Address Setting Page Screenshot The page inc...

Page 56: ...ystem Name as hostname to provide DNS lookup IP Address Provide the IP address of Managed Switch in dotted decimal notation Subnet Mask Provide the subnet mask of Managed Switch dotted decimal notation Gateway Provide the IP address of the router in dotted decimal notation Button Click to apply changes Figure 4 2 3 IP Information Page Screenshot The page includes the following fields Object Descri...

Page 57: ... address is in 128 bit records represented as eight fields of up to four hexadecimal digits with a colon separating each field For example fe80 215 c5ff fe03 4dc7 The symbol is a special syntax that can be used as a shorthand way of representing multiple 16 bit groups of contiguous zeros but it can only appear once It also uses the following legally IPv4 address For example 192 1 2 34 Provide the ...

Page 58: ...s Object Description Auto Configuration Display the current auto configuration state IPv6 In Use Address Display the current IPv6 in use address IPv6 In Use Router Display the current in use gateway IPv6 Static Address Display the current IPv6 static address IPv6 Static Router Display the current IPv6 static gateway DHCPv6 Client Display the current DHCPv6 client status ...

Page 59: ...he screens in Figure 4 2 6 and Figure 4 2 7 appear Figure 4 2 6 Local User Information Page Screenshot The page includes the following fields Object Description User Name The name identifying the user Maximum length 31 characters Maximum number of users 8 Password Type The password types for the user Options Clear Text Encrypted No Password Password Enter the user s new password here Range 0 30 ch...

Page 60: ...ent privilege type Modify Click to modify the local user entry Delete the current user 4 2 5 Time Settings 4 2 5 1 System Time Configure SNTP on this page SNTP is an acronym for Simple Network Time Protocol a network protocol for synchronizing the clocks of computer systems You can specify SNTP Servers and set GMT Time zone The SNTP Configuration screens in Figure 4 2 8 and Figure 4 2 9 appear Fig...

Page 61: ... for a defined Daylight Saving Time duration Select Disable to disable the Daylight Saving Time configuration Select Recurring and configure the Daylight Saving Time duration to repeat the configuration every year Select Non Recurring and configure the Daylight Saving Time duration for single time configuration Default Disabled Daylight Saving Time Offset Enter the number of minutes to add during ...

Page 62: ...e 4 2 9 Time Information Page Screenshot The page includes the following fields Object Description Current Date Time Display the current date time SNTP Display the current SNTP state Time Zone Display the current time zone Daylight Saving Time Display the current daylight saving time state Daylight Saving Time Offset Display the current daylight saving time offset state From Display the current da...

Page 63: ...ds Object Description SNTP NTP Server Address Type the IP address or domain name of the SNTP NTP server Server Port Type the port number of the server port Options 1 65535 Default 123 Button Click to apply changes Figure 4 2 11 SNTP Server Information Page Screenshot The page includes the following fields Object Description SNTP Server Address Display the current SNTP server address SNTP Server Po...

Page 64: ...only 5 Notice Normal but significant condition such as cold start 4 Warning Warning conditions e g return false unexpected return 3 Error Error conditions e g invalid input default used 2 Critical Critical conditions e g memory allocation or free memory error resource exhausted 1 Alert Immediate action needed 0 Emergency System unusable 4 2 6 1 Logging Service The Managed Switch system local log i...

Page 65: ...ged Switch system local log information is provided here The local Log screens in Figure 4 2 14 and Figure 4 2 15 appear Figure 4 2 14 Local Log Target Setting Page Screenshot The page includes the following fields Object Description Target The target of the local log entry The following target types are supported Buffered Target the buffer of the local log Flash Target the Flash of the local log ...

Page 66: ...onditions for local log Notice Notice level of the normal but significant conditions for local log Info Informational level of the informational messages for local log Debug Debug level of the debugging messages for local log Button Click to apply changes Figure 4 2 15 Local Log Setting Status Page Screenshot The page includes the following fields Object Description Status Display the current loca...

Page 67: ...mote Syslog screens in Figure 4 2 16 and Figure 4 2 17 appear Figure 4 2 16 Remote Log Target Page Screenshot The page includes the following fields Object Description Server Address Provide the remote syslog IP address of this Managed Switch Server Port Provide the port number of remote syslog server Options 1 65535 Default Port no 514 Severity The severity of the local log entry The following se...

Page 68: ...el of the informational messages for local log Debug Debug level of the debugging messages for local log Facility Local0 7 local user 0 7 Button Click to apply changes Figure 4 2 17 Remote Log Setting Status Page Screenshot The page includes the following fields Object Description Status Display the current remote syslog state Server Info Display the current remote syslog server information Severi...

Page 69: ...pes are supported Emerg Emergency level of the system unsable for log view Alert Alert level of the immediate action needed for log view Crit Critical level of the critical conditions for log view Error Error level of the error conditions for log view Warning Warning level of the warning conditions for log view Notice Notice level of the normal but significant conditions for log view Info Informat...

Page 70: ...lay the current log severity Category Display the current log category Total Entries Display the current log entries Figure 4 2 20 Logging Messages Page Screenshot The page includes the following fields Object Description No This is the number for logs Timestamp Display the time of log Category Display the category type Severity Display the severity type Message Display the log message Buttons Cli...

Page 71: ...re management information such as the number of error packets received by a network element Management information base MIB A MIB is a collection of managed objects residing in a virtual information store Collections of related managed objects are defined in specific MIB modules network management protocol A management protocol is used to convey management information between agents and NMSs SNMP ...

Page 72: ... 4 2 21 SNMP Global Setting Page Screenshot The page includes the following fields Object Description State Indicates the SNMP mode operation Possible modes are Enabled Enable SNMP mode operation Disabled Disable SNMP mode operation Button Click to apply changes Figure 4 2 22 SNMP Information Page Screenshot The page includes the following fields Object Description SNMP Display the current SNMP st...

Page 73: ...OID defining the root of the subtree to add to the named view The allowed string content is digital number or asterisk Subtree OID Mask The bitmask identifies which positions in the specified object identifier are to be regarded as wildcards for the purpose of pattern matching View Type Indicates the view type that this entry should belong to Possible view type are Included An optional flag to ind...

Page 74: ...NMP View Table Status Page Screenshot The page includes the following fields Object Description View Name Display the current SNMP view name Subtree OID Display the current SNMP subtree OID OID Mask Display the current SNMP OID mask View Type Display the current SNMP view type Action Delete the view table entry ...

Page 75: ...1 Reserved for SNMPv1 v2c Reserved for SNMPv2c V3 Reserved for SNMPv3 or User based Security Model USM Security Level Indicates the security model that this entry should belong to Possible security models are Noauth None authentication and none privacy security levels are assigned to the group auth Authentication and none privacy priv Authentication and privacy Note The Security Level applies to S...

Page 76: ...owing fields Object Description Group Name Display the current SNMP access group name Security Model Display the current security model Security Level Display the current security level Read View Name Display the current read view name Write View Name Display the current write view name Notify View Name Display the current notify view name Action Delete the access group entry ...

Page 77: ...s 0 to 16 Community Mode Indicates the SNMP community supported mode Possible versions are Basic Set SNMP community mode supported version 1 and 2c Advanced Set SNMP community mode supported version 3 Group Name A string identifying the group name that this entry should belong to The allowed string length is 1 to 16 View Name A string identifying the view name that this entry should belong to The ...

Page 78: ...ay the current view name Access Right Display the current access type Action Delete the community entry 4 2 7 6 SNMP User Configure SNMPv3 users table on this page Each SNMPv3 user is defined by a unique name Users must be configured with a specific security level and assigned to a group The SNMPv3 group restricts users to a specific read write and notify view The entry index key is User Name The ...

Page 79: ...tes the authentication protocol that this entry should belong to Possible authentication protocols are None None authentication protocol MD5 An optional flag to indicate that this user using MD5 authentication protocol SHA An optional flag to indicate that this user using SHA authentication protocol The value of security level cannot be modified if entry already exists That means you must first en...

Page 80: ...e Display the current privilege mode Authentication Protocol Display the current authentication protocol Encryption Protocol Display the current encryption protocol Access Right Display the current access right Action Delete the user entry 4 2 7 7 SNMPv1 2 Notification Recipients Configure SNMPv1 and 2 notification recipients on this page The SNMPv1 2 Notification Recipients screens in Figure 4 2 ...

Page 81: ...e community access string when send SNMP trap packet UDP Port Indicates the SNMP trap destination port SNMP Agent will send SNMP message via this port the port range is 1 65535 Time Out Indicates the SNMP trap inform timeout The allowed range is 1 to 300 Retries Indicates the SNMP trap inform retry times The allowed range is 1 to 255 Button Click to add a new SNMPv1 2 host entry Figure 4 2 32 SNMP...

Page 82: ...User s Manual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 82 Retry Displays the current retry times Action Delete the SNMPv1 2 host entry ...

Page 83: ...lows a valid IP address in dotted decimal notation x y z w It can also represent a legally valid IPv4 address For example 192 1 2 34 Notify Type Set the notify type in traps or informs User Name Indicates the user string when send SNMP trap packet UDP Port Indicates the SNMP trap destination port SNMP Agent will send SNMP message via this port the port range is 1 65535 Time Out Indicates the SNMP ...

Page 84: ...ect Description Server Address Display the current server address Notify Type Displays the current notify type User Name Display the current user name UDP Port Display the current UDP port Time Out Display the current time out Retry Displays the current retry times Action Delete the SNMPv3 host entry ...

Page 85: ...re 4 2 36 appear Figure 4 2 35 SNMPv3 Engine ID Setting Page Screenshot The page includes the following fields Object Description Engine ID An octet string identifying the engine ID that this entry should belong to The string must contain an even number between 10 and 64 hexadecimal digits but all zeros and all F s are not allowed Button Click to apply changes Figure 4 2 36 SNMPv3 Engine ID Status...

Page 86: ... Description Remote IP Address Indicates the SNMP remote engine ID address It allows a valid IP address in dotted decimal notation x y z w Engine ID An octet string identifying the engine ID that this entry should belong to Buttons Click to add a new Engine ID entry Figure 4 2 38 SNMPv3 Remote Engine ID Status Page Screenshot The page includes the following fields Object Description Remote IP Addr...

Page 87: ...le port error status Protected Ports Configures protected ports settings EEE Configures EEE settings 4 3 1 Port Configuration This page displays current port configurations and status Ports can also be configured here The table has one row for each port on the selected switch in a number of columns which are The Port Configuration screens in Figure 4 3 1 and Figure 4 3 2 appear Figure 4 3 1 Port S...

Page 88: ...mode Half Force sets Half Duplex mode Flow Control When Auto Speed is selected for a port this section indicates the flow control capability that is advertised to the link partner When a fixed speed setting is selected that is what is used Current Rx column indicates whether pause frames on the port are obeyed Current Tx column indicates whether pause frames on the port are transmitted The Rx and ...

Page 89: ...User s Manual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 89 Button Click to apply changes Figure 4 3 2 Port Status Page Screenshot ...

Page 90: ...f the port Flow Control Configuration Display the current flow control configuration of the port Flow Control Status Display the current flow control status of the port 4 3 2 Port Counters This page provides an overview of traffic and trunk statistics for all switch ports The Port Statistics screens in Figure 4 3 3 Figure 4 3 4 Figure 4 3 5 Figure 4 3 6 appear Figure 4 3 3 Port MIB Counters Settin...

Page 91: ...r of inbound packets which were chosen to be discarded even though no errors had been detected to prevent their being deliverable to a higher layer protocol One possible reason for discarding such a packet could be to free up buffer space ifOutOctets Transmit Octets The total number of octets transmitted out of the interface including framing characters ifOutUcastPkts Transmit Unicast Packets The ...

Page 92: ... layer ifInBroadcastPkts Received Broadcast Packets The number of packets delivered by this sub layer to a higher sub layer which were addressed to a broadcast address at this sub layer ifOutMulticastPkts Transmit Multicast Packets The total number of packets that higher level protocols requested betransmitted and which were addressed to a multicast address at this sub layer including those that w...

Page 93: ...ot3StatsDeferredTransmissions A count of frames for which the first transmission attempt on a particularinterface is delayed because the medium was busy dot3StatsLateCollisions The number of times that a collision is detected later than 512 bit times into the transmission of a packet dot3StatsExcessiveCollisions A count of frames for which transmission on a particular interface fails due to excess...

Page 94: ...not include multicast packets etherStatsMulticastPkts The total number of good frames received that were directed to this multicast address etherStatsCRCAlignErrors The number of CRC alignment errors FCS or alignment errors etherStatsUnderSizePkts The total number of frames received that were less than 64 octets long excluding framing bits but including FCS octets and were otherwise well formed et...

Page 95: ...Ethernet segment etherStatsPkts64Octets The total number of frames including bad packets received andtransmitted that were 64 octets in length excluding framing bits but including FCS octets etherStatsPkts65to127Octets etherStatsPkts128to255Octets etherStatsPkts256to511Octets etherStatsPkts512to1023Octets etherStatsPkts1024to1518Octets The total number of frames including bad packets received andt...

Page 96: ...sing a line graph The Bandwidth Utilization screen in Figure 4 3 7 appears To view the port utilization click on the Port Management folder and then the Bandwidth Utilization link Figure 4 3 7 Port Bandwidth Utilization Page Screenshot The page includes the following fields Object Description Refresh Period This shows the period interval between last and next refresh Options 2 sec 5 sec 10 sec IFG...

Page 97: ...rk problems selected traffic can be copied or mirrored to a mirror port where a frame analyzer can be attached to analyze the frame flow The Managed Switch can unobtrusively mirror traffic from any port to a monitor port You can then attach a protocol analyzer or RMON probe to this port to perform traffic analysis and verify connection integrity Figure 4 3 8 Port Mirror Application The traffic to ...

Page 98: ...ID Possible ID are 1 to 4 Monitor Session State Enable or disable the port mirroring function Destination Port Select the port to mirror destination port Allow Ingress Frames from ports that have either source rx or destination tx mirroring enabled are mirrored to this port Sniffer RX Ports Frames received at these ports are mirrored to the mirroring port Frames transmitted are not mirrored Sniffe...

Page 99: ... Mirroring Status Page Screenshot The page includes the following fields Object Description Session ID Display the session ID Destination Port This is the mirroring port entry Ingress State Display the ingress state Source TX Port Display the current TX ports Source RX Port Display the current RX ports ...

Page 100: ...igure 4 3 11 Jumbo Frame Setting Page Screenshot The page includes the following fields Object Description Jumbo Frame Bytes Enter the maximum frame size allowed for the switch port including FCS The allowed range is 64 bytes to 9216 bytes Button Click to apply changes Figure 4 3 12 Jumbo Frame Information Page Screenshot The page includes the following fields Object Description Jumbo Display the ...

Page 101: ...fault is 300 seconds BPDU Guard Enable or disable the port error disabled function to check status by BPDU guard Self Loop Enable or disable the port error disabled function to check status by self loop Broadcast Flood Enable or disable the port error disabled function to check status by broadcast flood Unknown Multicast Flood Enable or disable the port error disabled function to check status by u...

Page 102: ...Object Description Recovery Interval Display the current recovery interval time BPDU Guard Display the current BPDU guard status Self Loop Display the current self loop status Broadcast Flood Display the current broadcst flood status Unknown Multicast Flood Display the current unknown multicast flood status Unicast Flood Display the current unicast flood status ACL Display the current ACL status P...

Page 103: ... were disabled by some protocols such as BPDU Guard Loopback and UDLD The Port Error Disable screen in Figure 4 3 15 appears Figure 4 3 15 Port Error Disable Status Page Screenshot The displayed counters are Object Description Port Name Displays the port for error disable status Error Disabled Reason Display the error disabled reason of the port Time Left Seconds Display the time left in seconds ...

Page 104: ...d Zone DMZ are allowed to communicate with the outside world and with database servers on the inside segment but are not allowed to communicate with each other For protected port group to be applied the Managed switch must first be configured for standard VLAN operation Ports in a protected port group fall into one of these two groups Promiscuous Unprotected ports Ports from which traffic can be f...

Page 105: ... The port settings relate to the currently unit as reflected by the page header The Port Isolation Configuration screens in Figure 4 3 16 and Figure 4 3 17 appear Figure 4 3 16 Protected Ports Settings Page Screenshot The page includes the following fields Object Description Port List Select port number for this drop down list Port Type Displays protected port types Protected A single stand alone ...

Page 106: ...4S 106 Button Click to apply changes Figure 4 3 17 Protect Ports Status Page Screenshot The page includes the following fields Object Description Protected Ports Display the current protected ports Unprotected Ports Display the current unprotected ports ...

Page 107: ...for ports in auto negotiation mode where the port is negotiated to either 1G or 100 Mbit full duplex mode For ports that are not EEE capable the corresponding EEE checkboxes are grayed out and thus impossible to enable EEE for The EEE port settings relate to the currently unit as reflected by the page header When a port is powered down for saving power outgoing traffic is stored in a buffer until ...

Page 108: ...User s Manual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 108 Button Click to apply changes Figure 4 3 19 EEE Enable Status Page Screenshot ...

Page 109: ...ser s Manual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 109 The page includes the following fields Object Description Port The switch port number of the logical port EEE State Display the current EEE state ...

Page 110: ...gated Links can be assigned manually Port Trunk or automatically by enabling Link Aggregation Control Protocol LACP on the relevant links Aggregated Links are treated by the system as a single logical port Specifically the Aggregated Link has similar port attributes to a non aggregated port including auto negotiation speed Duplex setting etc The device supports the following Aggregation links Stat...

Page 111: ... link aggregation ports None of the ports in a link aggregation can be configured as a mirror source port or a mirror target port All of the ports in a link aggregation have to be treated as a whole when moved from to added or deleted from a VLAN The Spanning Tree Protocol will treat all the ports in a link aggregation as a whole Enable the link aggregation prior to connecting any cable between th...

Page 112: ...includes the following fields Object Description Load Balance Algorithm Select load balance algorithm mode MAC Address The MAC address can be used to calculate the port for the frame IP MAC Address The IP and MAC address can be used to calculate the port for the frame Button Click to apply changes Figure 4 4 3 LAG Information Page Screenshot The page includes the following fields Object Descriptio...

Page 113: ...st the available range is 1 to 8 Name Indicates per LAG name and the available range are 32 characters Type Indicates the trunk type Static Force aggregared selected ports to be a trunk group LACP LACP LAG negotiate Aggregated Port links with other LACP ports located on a different device If the other device ports are also LACP ports the devices establish a LAG between them Ports Select port numbe...

Page 114: ...ge allows setting configuration for per LAG The LAG Port setting screens in Figure 4 4 6 and Figure 4 4 7 appear Figure 4 4 6 LAG Port Setting Information Page Screenshot The page includes the following fields Object Description LAG Select Select LAG number for this drop down list Enabled Indicates the LAG Port Setting operation Possible state are Enabled Start up the LAG manually Disabled Shutdow...

Page 115: ...es on the port are obeyed Current Tx column indicates whether pause frames on the port are transmitted The Rx and Tx settings are determined by the result of the last Auto Negotiation Check the configured column to use flow control This setting is related to the setting for Configured Link Speed Possible state are Enabled Start up the Flow Control manually Disabled Shutdown the Flow Control manual...

Page 116: ...low control status 4 4 4 LACP Setting This page is used to configure the LACP system priority setting The LACP Setting screens in Figure 4 4 8 and Figure 4 4 9 appear Figure 4 4 8 LACP Setting Page Screenshot The page includes the following fields Object Description LACP Enable Disable or enable LACP function System Priority A value which is used to identify the active LACP The Managed Switch with...

Page 117: ...s used to configure the LACP port setting The LACP Port Setting screens in Figure 4 4 10 and Figure 4 4 11 appear Figure 4 4 10 LACP Port Setting Page Screenshot The page includes the following fields Object Description Port Select Select port number for this drop down list to set LACP port setting Priority The Prio controls the priority of the port If the LACP partner wants to form a larger group...

Page 118: ... LACP packets each second while Long will wait for 30 seconds before sending a LACP packet Button Click to apply changes Figure 4 4 11 LACP Port Information Page Screenshot The page includes the following fields Object Description Port Name The switch port number of the logical port Priority Display the current LACP priority parameter Timeout Display the current timeout parameter ...

Page 119: ... current trunk type Link State Display the current link state Active Member Display the current active member Standby Member Display the current standby member Figure 4 4 13 LACP Information Page Screenshot The page includes the following fields Object Description LAG Display the current LAG ID Port Display the current port number PartnerSysId The system ID of link partner This field would be upda...

Page 120: ...n state machine status of the port no PRD means the port is in no periodic state FstPRD means fast periodic state SlwPRD means slow periodic state PrdTX means periodic TX state AtState The actor state field of LACP PDU description The field from left to right describes LACP_Activity LACP_Timeout Aggregation Synchronization Collecting Distributing Defaulted and Expired The contents could be true or...

Page 121: ...cation End nodes that frequently communicate with each other are assigned to the same VLAN regardless of where they are physically on the network Logically a VLAN can be equated to a broadcast domain because broadcast packets are forwarded to only members of the VLAN on which the broadcast was initiated 1 No matter what basis is used to uniquely identify end nodes and assign these nodes VLAN membe...

Page 122: ...ical segment VLANs help to simplify network management by allowing you to move devices to a new VLAN without having to change any physical connections VLANs can be easily organized to reflect departmental groups such as Marketing or R D usage groups such as e mail or multicast groups used for multimedia applications such as videoconferencing VLANs provide greater network efficiency by reducing bro...

Page 123: ...her Type field is equal to 0x8100 the packet carries the IEEE 802 1Q 802 1p tag The tag is contained in the following two octets and consists of 3 bits of user priority 1 bit of Canonical Format Identifier CFI used for encapsulating Token Ring packets so they can be carried across Ethernet backbones and 12 bits of VLAN ID VID The 3 bits of user priority are used by 802 1p The VID is the VLAN ident...

Page 124: ...he switch will drop the packet Because of the existence of the PVID for untagged packets and the VID for tagged packets tag aware and tag unaware network devices can coexist on the same network A switch port can have only one PVID but can have as many VID as the switch has memory in its VLAN table to store them Because some devices on a network may be tag unaware a decision must be made at each po...

Page 125: ...ged VLAN ID to identify the port broadcast domain of the frame Port Overlapping Port overlapping can be used to allow access to commonly shared network resources among different VLAN groups such as file servers or printers Note that if you implement VLANs which do not overlap but still need to communicate you can connect them by enabled routing on this switch Untagged VLANs Untagged or static VLAN...

Page 126: ...current management VLAN 4 5 4 Create VLAN Create delete VLAN on this page The screens in Figure 4 5 3 and Figure 4 5 4 appear Figure 4 5 3 VLAN Setting Page Screenshot The page includes the following fields Object Description VLAN List Indicates the ID of this particular VLAN VLAN Action This column allowed users to add or delete VLAN s VLAN Name Prefix Indicates the name of this particular VLAN t...

Page 127: ...ice are tagged by the ports PVID Understand nomenclature of the Switch IEEE 802 1Q Tagged and Untagged Every port on an 802 1Q compliant switch can be configured as tagged or untagged Tagged Ports with tagging enabled will put the VID number priority and other VLAN information into the header of all packets that flow into those ports If a packet has previously been tagged the port will not alter t...

Page 128: ...s network and then stripping the tags when the frames leave the network A service provider s customers may have specific requirements for their internal VLAN IDs and number of VLANs supported VLAN ranges required by different customers in the same service provider network might easily overlap and traffic passing through the infrastructure might be mixed Assigning a unique range of VLAN IDs to each...

Page 129: ...ject Description Port Select Select port number for this drop down list to set VLAN port setting Interface VLAN Mode Set the port in hybrid access trunk tunnel mode Hybrid means the port allows the traffic of multi VLANs to pass with tag or untag mode Access indicates the port belongs to one VLAN only Trunk means the port allows traffic of multiple VLAN Tunnel configures IEEE 802 1Q tunneling for ...

Page 130: ...ded If ingress filtering is disabled frames classified to a VLAN that the port is not a member of are accepted and forwarded to the switch engine However the port will never transmit frames classified to VLANs that it is not a member of Uplink Enable disable uplink function in trunk port TPID Configure the type TPID of the protocol of switch trunk port Button Click to apply changes Figure 4 5 6 Ed...

Page 131: ...ort The switch port number of the logical port Interface VLAN Mode Display the current interface VLAN mode PVID Display the current PVID Accepted Frame Type Display the current access frame type Ingress Filtering Display the current ingress filtering Uplink Display the current uplink mode TPID Display the current TPID ...

Page 132: ... 132 4 5 6 Port to VLAN Use the VLAN Static Table to configure port members for the selected VLAN index This Page allows for adding and deleting port members of each VLAN The screen in Figure 4 5 7 appears Figure 4 5 7 Port to VLAN Setting Page Screenshot ...

Page 133: ...bidden from automatically joining the VLAN via GVRP Excluded Interface is not a member of the VLAN Packets associated with this VLAN will not be transmitted by the interface Tagged Interface is a member of the VLAN All packets transmitted by the port will be tagged that is carry a tag and therefore carry VLAN or CoS information Untagged Interface is a member of the VLAN All packets transmitted by ...

Page 134: ...4T2S_16P2S_24P2S_48T4S 134 4 5 7 Port VLAN Membership This Page provides an overview of membership status for VLAN users The VLAN Membership Status screen in Figure 4 5 8 appears Figure 4 5 8 Port VLAN Membership Table Page Screenshot ...

Page 135: ...u can configure this Managed Switch with protocol based VLANs that divide the physical network into logical VLAN groups for each required protocol When a frame is received at a port its VLAN membership can then be determined based on the protocol type being used by the inbound packets Command Usage To configure protocol based VLANs follow these steps 1 First configure VLAN groups for the protocols...

Page 136: ...y depending on the new frame type you selected Protocol Value 0x0600 0xFFFE Valid value that can be entered in this text field depends on the option selected from the the preceding Frame Type selection menu Valid values for frame type ranges from 0x0600 0xfffe Button Click to apply changes Figure 4 5 10 Protocol VLAN Group State Page Screenshot The page includes the following fields Object Descrip...

Page 137: ...nshot The page includes the following fields Object Description Port Select port for this drop down list to assign protocol VLAN port Group Select group ID for this drop down list to protocol VLAN group VLAN VLAN ID assigned to the Special Protocol VLAN Group Button Click to add protocol VLAN port entry Figure 4 5 12 Protocol VLAN Port State Page Screenshot The page includes the following fields O...

Page 138: ...bers on ports across the network VLANs are dynamically configured based on join messages issued by host devices and propagated throughout the network GVRP must be enabled to permit automatic VLAN registration and to support VLANs which extend beyond the local switch The GVRP Global Setting Information screens in Figure 4 5 13 and Figure 4 5 14 appear Figure 4 5 13 GVRP Global Setting Page Screensh...

Page 139: ...is Managed Switch Button Click to apply changes Figure 4 5 14 GVRP Information Page Screenshot The page includes the following fields Object Description GVRP Status Display the current GVRP status Join Timeout Display the current join timeout parameter Leave Timeout Display the current leave timeout parameter LeaveAll Timeout Display the current leaveall timeout parameter ...

Page 140: ...istration mode These ports use GVRP join messages from neighboring switches to prune the VLANs running across the 802 1Q trunk link If the device on the other side is not capable of sending GVRP messages or if you do not want to allow the switch to prune any of the VLANs use the Fixed mode Fixed mode ports will forward for all VLANs that exist in the switch database Ports in Forbidden mode forward...

Page 141: ...ect Description Port The switch port number of the logical port Enable State Display the current GVRP port state Registration Mode Display the current registration mode VLAN Creation State Display the current VLAN creation state 4 5 12 GVRP VLAN The GVRP VLAN Database screen in Figure 4 5 17 appears Figure 4 5 17 GVRP VLAN Database Page Screenshot ...

Page 142: ... screens in Figure 4 5 18 and Figure 4 5 19 appear Figure 4 5 18 GVRP Port Statistics Page Screenshot The page includes the following fields Object Description Port The switch port number of the logical port Join Empty Rx Tx Display the current join empty TX RX packets Empty Rx Tx Display the current empty TX RX packets Leave Empty Rx Tx Display the current leave empty TX RX packets Join In Rx Tx ...

Page 143: ...ical port Invalid Protocol ID Display the current invalid protocol ID Invalid Attribute Type Display the current invalid attribute type Invalid Attribute Value Display the current invalid attribute value Invalid Attribute Length Display the current invalid attribute length Invalid Event Display the current invalid event Buttons Click to clear the GVRP Error Statistics Click to refresh the GVRP Err...

Page 144: ...Group 3 are separated VLANs Each VLAN isolate network traffic so only members of the VLAN receive traffic from the same VLAN members The screen in Figure 4 5 20 appears and Table 4 5 2 describes the port configuration of the Managed Switches Figure 4 5 20 Two Separate VLAN Diagrams VLAN Group VID Untagged Members Tagged Members VLAN Group 1 1 Port 7 Port 8 N A VLAN Group 2 2 Port 1 Port 2 Port 3 V...

Page 145: ...a tagged packet with VLAN Tag 2 enters Port 3 PC 1 and PC 2 will received the packet through Port 1 and Port 2 2 While the packet leaves Port 1 and Port 2 it will be stripped away it tag becoming an untagged packet Untagged packet entering VLAN 3 1 While PC 4 transmit an untagged packet enters Port 4 the Managed Switch will tag it with a VLAN Tag 3 PC 5 and PC 6 will received the packet through Po...

Page 146: ...and PVID for each port Port 1 Port 2 and Port 3 VLAN Mode Hybrid PVID 2 Port 4 Port 5 and Port 6 VLAN Mode Hybrid PVID 3 3 Assign Tagged Untagged for each port VLAN ID 2 Port 1 2 Untagged Port 3 Tagged Port 4 6 Excluded VLAN ID 3 Port 4 5 Untagged Port 6 Tagged Port 1 3 Excluded ...

Page 147: ...wo 802 1Q aware switch The most cases are used for Uplink to other switches VLANs are separated at different switches but they need to access with other switches within the same VLAN group The screen in Figure 4 5 21 appears Figure 4 5 21 VLAN Trunking between two 802 1Q Aware Switch Diagrams ...

Page 148: ... 2 and 3 Add VLAN group 2 and group 3 2 Assign VLAN mode and PVID for each port Port 1 Port 2 and Port 3 VLAN Mode Hybrid PVID 2 Port 4 Port 5 and Port 6 VLAN Mode Hybrid PVID 3 Port 7 VLAN Mode Hybrid PVID 1 3 Assign Tagged Untagged for each port VLAN ID 1 Port 1 6 Untagged Port 7 Excluded ...

Page 149: ...User s Manual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 149 VLAN ID 2 Port 1 2 Untagged Port 3 7 Tagged Port 4 6 Excluded VLAN ID 3 Port 4 5 Untagged Port 6 7 Tagged Port 1 3 Excluded ...

Page 150: ...User s Manual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 150 ...

Page 151: ...s at the time of a primary link failure is also accomplished automatically without operator intervention This automatic network reconfiguration provides maximum uptime to network users However the concepts of the Spanning Tree Algorithm and protocol are a complicated and complex subject and must be fully researched and understood It is possible to cause serious degradation of the performance of th...

Page 152: ...ance connecting higher speed links to a port that has a higher number than the current root port can cause a root port change STP Port States The BPDUs take some time to pass through a network This propagation delay can result in topology changes where a port that transitioned directly from a Blocking state to a Forwarding state could create temporary data loops Ports must wait for new network top...

Page 153: ...STP Parameters STP Operation Levels The Switch allows for two levels of operation the switch level and the port level The switch level forms a spanning tree consisting of links between one or more switches The port level constructs a spanning tree consisting of groups of one or more ports The STP operates in much the same way for both levels On the switch level STP calculates the Bridge Identifier...

Page 154: ... the user configurable STP parameters for the port or port group level Variable Description Default Value Port Priority A relative priority for each port lower numbers give a higher priority and a greater chance of a given port being elected as the root port 128 Port Cost A value used by STP to evaluate paths STP calculates path costs and selects the path with the minimum cost as the active path 2...

Page 155: ...he greater the probability the port will be chosen as the Root Port Port Cost A Port Cost can be set from 0 to 200000000 The lower the number the greater the probability the port will be chosen to forward packets 3 Illustration of STP A simple illustration of three switches connected in a loop is depicted in the below diagram In this example you can anticipate some major network problems if the ST...

Page 156: ...User s Manual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 156 Figure 4 6 2 Before Applying the STA Rules In this example only the default STP values are used Figure 4 6 3 After Applying the STA Rules ...

Page 157: ...T Instance Setting Configuration each MST instance settings MST Port Setting Configuration per port MST setting STP Statistics Display the STP statistics 4 6 2 STP Global Settings This page allows you to configure STP system settings The settings are used by all STP Bridge instances in the Switch The Managed Switch support the following Spanning Tree protocols Compatiable Spanning Tree Protocol ST...

Page 158: ...ompatible RSTP Operation and MSTP Operation Configuration Name Identifier used to identify the configuration currently being used Configuration Revision Identifier used to identify the configuration currently being used The values allowed are between 0 and 65535 The default value is 0 Button Click to apply changes Figure 4 6 5 STP Information Page Screenshot The page includes the following fields ...

Page 159: ...rt as beeing set or cleared The initial operEdge state when a port is initialized BPDU Filter Control whether a port explicitly configured as Edge will transmit and receive BPDUs BPDU Guard Control whether a port explicitly configured as Edge will disable itself upon reception of a BPDU The port will enter the error disabled state and will be removed from the active topology P2P MAC Controls wheth...

Page 160: ...rnet 50 600 200 000 20 000 000 Fast Ethernet 10 60 20 000 2 000 000 Gigabit Ethernet 3 10 2 000 200 000 Table 4 6 1 Recommended STP Path Cost Range Port Type Link Type IEEE 802 1D 1998 IEEE 802 1w 2001 Ethernet Half Duplex Full Duplex Trunk 100 95 90 2 000 000 1 999 999 1 000 000 Fast Ethernet Half Duplex Full Duplex Trunk 19 18 15 200 000 100 000 50 000 Gigabit Ethernet Full Duplex Trunk 4 3 10 0...

Page 161: ... Status Page Screenshot The page includes the following fields Object Description Port The switch port number of the logical STP port Admin Enable Display the current STP port mode status External Cost Display the current external cost Edge Port Display the current edge port status ...

Page 162: ...rity Controls the bridge priority Lower numeric values have better priority The bridge priority plus the MSTI instance number concatenated with the 6 byte MAC address of the switch forms a Bridge Identifier For MSTP operation this is the priority of the CIST Otherwise this is the priority of the STP RSTP bridge Max Hops This defines the initial value of remaining Hops for MSTI information generate...

Page 163: ...ld Count The number of BPDU s a bridge port can send per second When exceeded transmission of the next BPDU will be delayed Valid values are in the range 1 to 10 BPDU s per second Hello Time The time that controls the switch to send out the BPDU packet to check STP current status Enter a value between 1 through 10 Button Click to apply changes Figure 4 6 9 CIST Instance Information Page Screenshot...

Page 164: ...ridge identifier information Designated Root Bridge Display the designed root bridge information External Root Path Cost Display the external root path cost informaiton Regional Root Bridge Display the regional root bridge information Internal Root Path Cost Display the internal root path cost information Designated Bridge Display the designated bridge information Root Port Display the root port i...

Page 165: ...ntrols the port priority This can be used to control priority of ports having identical port cost See above Default 128 Range 0 240 in steps of 16 Internal Path Cost 0 Auto Controls the path cost incurred by the port The Auto setting will set the path cost as appropriate by the physical link speed using the 802 1D recommended values Using the Specific setting a user defined value can be entered Th...

Page 166: ...User s Manual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 166 Button Click to apply changes Figure 4 6 12 CIST Port Status Page Screenshot ...

Page 167: ...l path cost oper Designated Root Bridge Display the current designated root bridge External Root Cost Display the current external root cost Regional Root Bridge Display the current regional root bridge Internal Root Cost Display the current internal root cost Designated Bridge Display the current designated bridge Internal Port Path Cost Display the current internal port path cost Edge Port Conf ...

Page 168: ... 1 4094 Allow assign VLAN list for special MSTI ID The range for the VLAN list is 1 4094 Priority Controls the bridge priority Lower numerical values have better priority The bridge priority plus the MSTI instance number concatenated with the 6 byte MAC address of the switch forms a Bridge Identifier Button Click to apply changes Figure 4 6 14 MSTI Instance Setting Information Page Screenshot The ...

Page 169: ...oot Bridge Display the current designated root bridge Internal Root Cost Display the current internal root cost Designated Bridge Display the current designated bridge Root Port Display the current root port Max Age Display the current max age Forward Delay Display the current forward delay Remaining Hops Display the current remaininging hops Last Topology Change Display the current last topology ...

Page 170: ...Figure 4 6 16 MST Port Configuration Page Screenshot The page includes the following fields Object Description MST ID Enter the special MST ID to configure path cost priority Port Select Select port number for this drop down list Priority Controls the port priority This can be used to control priority of ports having identical port cost Internal Path Cost 0 Auto Controls the path cost incurred by ...

Page 171: ...ity Port ID Display the current indentifier priority port ID Internal Path Cost Conf Oper Display the current internal path cost configuration operation Regional Root Bridge Display the current regional root bridget Internal Root Cost Display the current internal root cost Designated Bridge Display the current designated bridge Internal Path Cost Display the current internal path cost Port Role Di...

Page 172: ... s Manual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 172 4 6 8 STP Statistics This page displays STP statistics The STP statistics screen in Figure 4 6 18 appears Figure 4 6 18 STP Statistics Page Screenshot ...

Page 173: ... BPDUs Received Display the current configuration BPDUs received TCN BPDUs Received Display the current TCN BPDUs received MSTP BPDUs Received Display the current MSTP BPDUs received Configuration BPDUs Transmitted Display the configuration BPDUs transmitted TCN BPDUs Transmitted Display the current TCN BPDUs transmitted MSTP BPDUs Transmitted Display the current BPDUs transmitted ...

Page 174: ...res multicast filter 4 7 1 Properties This page provides multicast properties related configuration The multicast Properties and Information screens in Figure 4 7 1 and Figure 4 7 2 appear Figure 4 7 1 Properties Setting Page Screenshot The page includes the following fields Object Description L2 Unknow Multicast Action Action for L2 unknown multicast traffic Options are Drop or flood IP Unknown M...

Page 175: ...nshot The page includes the following fields Object Description L2 Unknow Multicast Action Display the current L2 unknown multicast action status IP Uknown Multicast Action Display the current IP unknown multicast action status IPv6 Uknown Multicast Action Display the current IPv6 unknown multicast action status Forward Method For IPv4 Display the current IPv4 multicast forward method Forward Meth...

Page 176: ...by routers that they will become members of a multicast group The Internet Group Management Protocol IGMP is used to communicate this information IGMP is also used to periodically check the multicast group for members that are no longer active In the case where there is more than one multicast router on a sub network one router is elected as the queried This router then keeps track of the membersh...

Page 177: ...User s Manual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 177 Figure 4 7 4 Multicast Flooding Figure 4 7 5 IGMP Snooping Multicast Stream Control ...

Page 178: ...lticast routers to keep track of the membership of multicast groups on their respective sub networks The following outlines what is communicated between a multicast router and a multicast group member using IGMP A host sends an IGMP report to join a group A host will never send a report when it wants to leave a group for version 1 A host will send a leave report when it wants to leave a group for ...

Page 179: ...ve multicast traffic If there is more than one router switch on the LAN performing IP multicasting one of these devices is elected querier and assumes the role of querying the LAN for group members It then propagates the service requests on to any upstream multicast switch router to ensure that it will continue to receive the multicast service Multicast routers use this information along with a mu...

Page 180: ...e includes the following fields Object Description IGMP Snooping Status Enable or disable the IGMP snooping The default value is Disabled IGMP Snooping Version Sets the IGMP Snooping operation version Possible versions are v2 Set IGMP Snooping supported IGMP version 2 v3 Set IGMP Snooping supported IGMP version 3 IGMP Snooping Report Suppression Limits the membership report traffic sent to multica...

Page 181: ... Entry No Display the current entry number VLAN ID Display the current VLAN ID IGMP Snooping Operation Status Display the current IGMP snooping operation status Router Ports Auto Learn Display the current router ports auto learning Query Robustness Display the current query robustness Query Interval sec Display the current query interval Query Max Response Interval sec Display the current query ma...

Page 182: ...ds Object Description VLAN ID Select VLAN ID for this drop down list Querier State Enable or disable the querier state The default value is Disabled Querier Version Sets the querier version for compatibility with other devices on the network Version 2 or 3 Default v2 Button Click to apply changes Figure 4 7 11 IGMP Querier Status Page Screenshot The page includes the following fields Object Descri...

Page 183: ...rts attached to participating hosts to a common VLAN and then assign the multicast service to that VLAN group Static multicast addresses are never aged out When a multicast address is assigned to an interface in a specific VLAN the corresponding traffic can only be forwarded to ports within that VLAN The IGMP Static Group configuration screens in Figure 4 7 12 and Figure 4 7 13 appear Figure 4 7 1...

Page 184: ...k to edit parameter 4 7 2 4 IGMP Group Table This page provides Multicast Database The IGMP Group Table screen in Figure 4 7 14 appears Figure 4 7 14 IGMP Group Table Page Screenshot The page includes the following fields Object Description VLAN ID Display the current VID Group IP Address Display multicast IP address for a specific multicast service Member Ports Display the current member port Typ...

Page 185: ...riate interfaces within the Managed Switch The IGMP Router Setting and Status screens in Figure 4 7 15 and Figure 4 7 16 appear Figure 4 7 15 Add Router Port Page Screenshot The page includes the following fields Object Description VLAN ID Selects the VLAN to propagate all multicast traffic coming from the attached multicast router Type Sets the Router port type The types of Router port as below S...

Page 186: ...ck to edit parameter Click to delete the group ID entry 4 7 2 6 IGMP Router Table This page provides Router Table The Dynamic Static and Forbidden Router Table screens in Figure 4 7 17 Figure 4 7 18 and Figure 4 7 19 appear Figure 4 7 17 Dynamic Router Table Page Screenshot The page includes the following fields Object Description VLAN ID Display the current VLAN ID Port Display the current dynami...

Page 187: ...age includes the following fields Object Description VLAN ID Display the current VLAN ID Port Mask Display the current port mask Figure 4 7 19 Forbidden Router Table Page Screenshot The page includes the following fields Object Description VLAN ID Display the current VLAN ID Port Mask Display the current port mask ...

Page 188: ...anual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 188 4 7 2 7 IGMP Forward All This page provides IGMP Forward All The Forward All screen in Figure 4 7 20 appears Figure 4 7 20 Forward All Setting Page Screenshot ...

Page 189: ...P membership Port The switch port number of the logical port Membership Select IGMP membership for each interface Static Interface is a member of the IGMP Forbidden Interface is forbidden from automatically joining the IGMP via MVR None Interface is not a member of the VLAN Packets associated with this VLAN will not be transmitted by the interface Button Click to apply changes ...

Page 190: ...1 appears Figure 4 7 21 Forward All Setting Page Screenshot The page includes the following fields Object Description Total RX Display current total RX Valid RX Display current valid RX Invalid RX Display current invalid RX Other RX Display current other RX Leave RX Display current leave RX Report RX Display current report RX General Query RX Display current general query RX ...

Page 191: ...group source query RX Leave TX Display current leave TX Report TX Display current report TX General Query TX Display current general query TX Special Group Query TX Display current special group query TX Special Group Source Query TX Display current special group source query TX Buttons Click to clear the IGMP Snooping Statistics Click to refresh the IGMP Snooping Statistics ...

Page 192: ...creenshot The page includes the following fields Object Description MLD Snooping Status Enable or disable the MLD snooping The default value is Disabled MLD Snooping Version Sets the MLD Snooping operation version Possible versions are v1 Set MLD Snooping supported MLD version 1 v2 Set MLD Snooping supported MLD version 2 MLD Snooping Report Suppression Limits the membership report traffic sent to...

Page 193: ...y No Display the current entry number VLAN ID Display the current VLAN ID MLD Snooping Operation Status Display the current MLD snooping operation status Router Ports Auto Learn Display the current router ports auto learning Query Robustness Display the current query robustness Query Interval sec Display the current query interval Query Max Response Interval sec Display the current query max respo...

Page 194: ... ID Select VLAN ID for this drop down list Group IP Address The IP address for a specific multicast service Member Ports Select port number for this drop down list Button Click to add IGMP router port entry Figure 4 7 26 MLD Static Groups Page Screenshot The page includes the following fields Object Description VLAN ID Display the current VLAN ID Group IPv6 Address Display the current group IPv6 a...

Page 195: ...ng on selected options Life Sec Display the current life 4 7 4 4 MLD Router Setting Depending on your network connections MLD snooping may not always be able to locate the MLD querier Therefore if the MLD querier is a known multicast router switch connected over the network to an interface port or trunk on your Managed Switch you can manually configure the interface and a specified VLAN to join al...

Page 196: ...act as router ports A router port is a port on the Ethernet switch that leads towards the Layer 3 multicast device or MLD querier Forbid Port Select Specify which ports un act as router ports Button Click to add MLD router port entry Figure 4 7 29 Router Port Status Page Screenshot The page includes the following fields Object Description VLAN ID Display the current VLAN ID Static Ports Display th...

Page 197: ...uter Table Page Screenshot The page includes the following fields Object Description VLAN ID Display the current VLAN ID Port Display the current dynamic router ports Expiry Time Sec Display the current expiry time Figure 4 7 31 Static Router Table Page Screenshot The page includes the following fields Object Description VLAN ID Display the current VLAN ID Port Mask Display the current port mask F...

Page 198: ... All Setting Page Screenshot The page includes the following fields Object Description VLAN ID Select VLAN ID for this drop down list to assign MLD membership Port The switch port number of the logical port Membership Select MLD membership for each interface Forbidden Interface is forbidden from automatically joining the MLD via MVR None Interface is not a member of the VLAN Packets associated wit...

Page 199: ...All Setting Page Screenshot The page includes the following fields Object Description Total RX Display current total RX Valid RX Display current valid RX Invalid RX Display current invalid RX Other RX Display current other RX Leave RX Display current leave RX Report RX Display current report RX General Query RX Display current general query RX Special Group Query RX Display current special group q...

Page 200: ... Display current leave TX Report TX Display current report TX General Query TX Display current general query TX Special Group Query TX Display current special group query TX Special Group Source Query TX Display current special group source query TX Buttons Click to clear the MLD Snooping Statistics Click to refresh the MLD Snooping Statistics ...

Page 201: ...lso you can set the multicast throttling number to limit the number of multicast groups an interface can join at the same time The MAX Group and Information screens in Figure 4 7 35 and Figure 4 7 36 appear Figure 4 7 35 Max Groups and Action Setting Page Screenshot The page includes the following fields Object Description IP Type Select IPv4 or IPv6 for this drop down list Port Select Select port...

Page 202: ...User s Manual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 202 Figure 4 7 36 IGMP Port Max Groups Information Page Screenshot ...

Page 203: ... 4210 16T2S_24T2S_16P2S_24P2S_48T4S 203 The page includes the following fields Object Description Port The switch port number of the logical port Max Groups Display the current Max groups Action Display the current action ...

Page 204: ...d multicast join reports received on the port are checked against the filter profile If a requested multicast group is permitted the multicast join report is forwarded as normal If a requested multicast group is denied the multicast join report is dropped When you have created a Multicast profile number you can then configure the multicast groups to filter and set the access mode Command Usage Eac...

Page 205: ...s Action Sets the access mode of the profile either permit or deny Permit Multicast join reports are processed when a multicast group falls within the controlled range Deny When the access mode is set to multicast join reports are only processed when the multicast group is not in the controlled range Button Click to add multicast profile entry Figure 4 7 38 IGMP MLD Profile Status Page Screenshot ...

Page 206: ...ect Description Port Select Select port number for this drop down list Filter Profile ID Select filter profile ID for this drop down list Button Click to apply changes Figure 4 7 40 Port Filter Status Page Screenshot The page includes the following fields Object Description Port Display the current port Filter Profile ID Display the current filter profile ID Action Click to display detail profile ...

Page 207: ...Object Description Port Select Select port number for this drop down list Filter Profile ID Select filter profile ID for this drop down list Button Click to apply changes Figure 4 7 42 Port Filter Status Page Screenshot The page includes the following fields Object Description Port Display the current port Filter Profile ID Display the current filter profile ID Action Click to display detail profi...

Page 208: ... performance for specific types of traffic and preserve performance as the amount of traffic grows Reduce the need to constantly add bandwidth to the network Manage network congestion To implement QoS on your network you need to carry out the following actions 1 Define a service level to determine the priority that will be applied to traffic 2 Apply a classifier to determine how the incoming traff...

Page 209: ...igure 4 8 1 and Figure 4 8 2 appear Figure 4 8 1 QoS Global Setting Page Screenshot The page includes the following fields Object Description QoS Mode Enable or disable QoS mode Button Click to apply changes Figure 4 8 2 QoS Information Page Screenshot The page includes the following fields Object Description QoS Mode Display the current QoS mode ...

Page 210: ...ing Page Screenshot The page includes the following fields Object Description Port Select Select port number for this drop down list CoS Value Select CoS value for this drop down list the available options are 0 to 7 Remark CoS Disable or enable remark CoS Remark DSCP Disable or enable remark DSCP Remark IP Precedence Disable or enable remark IP Precedence Button Click to apply changes ...

Page 211: ...nshot The page includes the following fields Object Description Port The switch port number of the logical port CoS Value Display the current CoS value Remark CoS Display the current remark CoS Remark DSCP Display the current remark DSCP Remark IP Precedence Display the current remark IP precedence ...

Page 212: ...ect Description Queue Display the current queue ID Strict Priority Controls whether the scheduler mode is Strict Priority on this switch port WRR Controls whether the scheduler mode is Weighted on this switch port Weight Controls the weight for this queue This value is restricted to 1 100 This parameter is only shown if Scheduler Mode is set to Weighted of WRR Bandwidth Display the current bandwit...

Page 213: ...information Information Value Display the current queue vlaue information 4 8 2 4 CoS Mapping The CoS to Queue and Queue to CoS Mapping screens in Figure 4 8 7 and Figure 4 8 8 appear Figure 4 8 7 CoS to Queue and Queue to CoS Mapping Page Screenshot The page includes the following fields Object Description Queue Select Queue value for this drop down list Class of Service Select CoS value for this...

Page 214: ...changes Figure 4 8 8 CoS Mapping Page Screenshot The page includes the following fields Object Description CoS Display the current CoS value Mapping to Queue Display the current mapping to queue Queue Display the current queue value Mapping to CoS Display the current mapping to CoS ...

Page 215: ...SCP Mapping screens in Figure 4 8 9 and Figure 4 8 10 appear Figure 4 8 9 DSCP to Queue and Queue to DSCP Mapping Page Screenshot The page includes the following fields Object Description Queue Select Queue value for this drop down list DSCP Select DSCP value for this drop down list Button Click to apply changes ...

Page 216: ...8 10 DSCP Mapping Page Screenshot The page includes the following fields Object Description DSCP Display the current CoS value Mapping to Queue Display the current mapping to queue Queue Display the current queue value Mapping to DSCP Display the current mapping to DSCP ...

Page 217: ... 8 11 and Figure 4 8 12 appear Figure 4 8 11 IP Precedence to Queue and Queue to IP Precedence Mapping Page Screenshot The page includes the following fields Object Description Queue Select Queue value for this drop down list IP Precedence Select IP Precedence value for this drop down list Button Click to apply changes Figure 4 8 12 IP Precedence Mapping Page Screenshot ...

Page 218: ...he page includes the following fields Object Description IP Precedence Display the current CoS value Mapping to Queue Display the current mapping to queue Queue Display the current queue value Mapping to IP Precedence Display the current mapping to IP Precedence ...

Page 219: ... Figure 4 8 13 Basic Mode Global Settings Page Screenshot The page includes the following fields Object Description Trust Mode Set the QoS mode the optios are shown as below Cos 802 1p Default DSCP CoS 802 1p DSCP IP Precedence None Button Click to apply changes Figure 4 8 14 QoS Information Page Screenshot The page includes the following fields Object Description Trust Mode Display the current Qo...

Page 220: ...tting and Status screens in Figure 4 8 15 and Figure 4 8 16 appear Figure 4 8 15 Basic Mode Global Settings Page Screenshot The page includes the following fields Object Description Port Select port number for this drop down list Trust Enable or disable the trust mode Button Click to apply changes ...

Page 221: ...16T2S_24T2S_16P2S_24P2S_48T4S 221 Figure 4 8 16 QoS Port Status Page Screenshot The page includes the following fields Object Description Port The switch port number of the logical port Trust Type Display the current trust type ...

Page 222: ... page includes the following fields Object Description Trust Mode Set the QoS mode the optios are shown as below Cos 802 1p Default DSCP CoS 802 1p DSCP IP Precedence Default Mode Status Set the default mode as Trusted or Not Trusted Default Button Click to apply changes Figure 4 8 18 QoS Information Page Screenshot The page includes the following fields Object Description Trust Mode Display the c...

Page 223: ...apping Page Screenshot The page includes the following fields Object Description Class Name Input the class name and 32 characters allowed Match ACL Type Choose IP MAC or IP or MAC as match ACL type IP Choose IPv4 or IPv6 MAC Choose specific MAC adrress Preferred ACL Choose IP or MAC for preferred ACL Button Click to add Class Mapping profile entry Figure 4 8 20 QoS Class Mapping Table Page Screen...

Page 224: ...22 appear Figure 4 8 21 QoS Aggregate Police Page Screenshot The page includes the following fields Object Description Aggregate Police Name Input the aggregate police name and 32 characters allowed Ingress Committed Information Rate CIR Allow input a number as ingress committed information rate Ingress Committed Burst Size CBS Allow input a number as ingress committed burst size Exceed Action Cho...

Page 225: ... Exceed Action Disaply the current exceed action information Action Disaply the current action information 4 8 4 4 Policy Table The QoS Policy table and Policy table status screens in Figure 4 8 23 and Figure 4 8 24 appear Figure 4 8 23 QoS Policy Table Page Screenshot The page includes the following fields Object Description Policy Name Input the policy name and 31 characters allowed Button Click...

Page 226: ...icy class maps status screens in Figure 4 8 25 and Figure 4 8 26 appear Figure 4 8 25 QoS Policy Class Maps Table Page Screenshot The page includes the following fields Object Description Policy Name Allow choose one specific policy name Class Name Allow choose one specific class name Action Type Provide Trust None Always Trust and Set Queue oprtions Police Type Provide None Single and Aggregate o...

Page 227: ...s Map Table Page Screenshot The page includes the following fields Object Description Policy Name Display the current policy name information Class Name Disaply the current class name information Action Type Disaply current Trust Set Attribute and Set Value information Police Type Display current policy type information Aggregate Police Name Display current Aggregate Police Name information CIR Di...

Page 228: ...dning table screens in Figure 4 8 27 and Figure 4 8 28 appear Figure 4 8 27 QoS Policy Binding Table Page Screenshot The page includes the following fields Object Description Policy Select Select policy from this drop down list Binding Port Select one specific port from this drop down list Button Click to apply changes ...

Page 229: ..._24T2S_16P2S_24P2S_48T4S 229 Figure 4 8 28 QoS Policy Binding Table Page Screenshot The page includes the following fields Object Description Port Disaply per port information Policy Name Display the current policy name information ...

Page 230: ... 8 29 Ingress Bandwidth Control Settings Page Screenshot The page includes the following fields Object Description Burst Size Allow assigning burst size and the options are 1 to 65535 Unit Bytes Port Select port number for this drop down list State Enable or disable the port rate policer The default value is Disabled Rate Kbps Configure the rate for the port policer The default value is unlimited ...

Page 231: ...of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 231 The page includes the following fields Object Description Burst Size Display current burst size information Figure 4 8 31 Ingress Bandwidth Control Status Page Screenshot ...

Page 232: ...ol Setting and Status screens in Figure 4 8 32 and Figure 4 8 33 appear Figure 4 8 32 VLAN Ingress Bandwidth Control Settings Page Screenshot The page includes the following fields Object Description VLAN Select VLAN number for this drop down list Port Select port number for this drop down list State Enable or disable the port rate policer The default value is Disabled Rate Kbps Configure the rate...

Page 233: ...dwidth preamble The Egress Bandwidth Control Setting and Status screens in Figure 4 8 34 Figure 4 8 35 and Figure 4 8 36 appear Figure 4 8 34 Egress Bandwidth Control Settings Page Screenshot The page includes the following fields Object Description Burst Size Allow assigning burst size and the options are 1 to 65535 Unit Bytes Port Select port number for this drop down list State Enable or disabl...

Page 234: ...ton Click to apply changes Figure 4 8 35 Egress Port Burst Size Configuration Page Screenshot The page includes the following fields Object Description Burst Size Display current burst size information Figure 4 8 36 Egress Bandwidth Control Status Page Screenshot ...

Page 235: ...ndwidthSettings Page Screenshot The page includes the following fields Object Description Burst Size Allow assigning burst size and the options are 1 to 65535 Unit Bytes Port Select port number for this drop down list Queue Select queue numbers for this drop down list options are 1 to 8 State Enable or disable the port rate policer The default value is Disabled CIR Kbps Configure the CIR for the p...

Page 236: ...e following fields Object Description Burst Size Display current burst size information Figure 4 8 39 Egress Queue Status Page Screenshot The page includes the following fields Object Description Queue ID Display the current queue ID Rate Limit Kbps Display the current rate limit ...

Page 237: ...ways belong to Voice VLAN when relocated physically The greatest advantage of the VLAN is the equipment can be automatically placed into Voice VLAN according to its voice traffic which will be transmitted at specified priority Meanwhile when voice equipment is physically relocated it still belongs to the Voice VLAN without any further configuration modification which is because it is based on voic...

Page 238: ...ode operation Disabled Disable Voice VLAN mode operation Voice VLAN ID Indicates the Voice VLAN ID It should be a unique VLAN ID in the system and cannot equal each port PVID It is conflict configuration if the value equal management VID MVR VID PVID etc The allowed range is 1 to 4095 Remark CoS 802 1p Select 802 1p value for this drop down list 1p remark Enable or disable 802 1p remark Aging Time...

Page 239: ... VLAN state Voice VLAN ID Display the current voice VLAN ID Remark CoS 802 1p Display the current remark CoS 802 1p 1p remark Display the current 1p remark Aging Display the current aging time 4 8 6 3 Telephony OUI MAC Setting Configure Voice VLAN OUI table on this Page The Telephony OUI MAC Setting screens in Figure 4 8 42 and Figure 4 8 43 appear Figure 4 8 42 Voice VLAN OUI MAC Setting Page Scr...

Page 240: ... input format is xx xx xx x is a hexadecimal digit Description User defined text that identifies the VoIP devices Button Click to add voice VLAN OUI setting Figure 4 8 43 Voice VLAN OUI Group Page Screenshot The page includes the following fields Object Description OUI Address Display the current OUI address Description Display the current description Modify Click to edit voice VLAN OUI group para...

Page 241: ... the IP device to the switch the IP phone should configure the voice VLAN ID correctly It should be configured through its own GUI The Telephony OUI MAC Setting screens in Figure 4 8 44 and Figure 4 8 45 appear Figure 4 8 44 Voice VLAN OUI Port Setting Page Screenshot The page includes the following fields Object Description Port Select port number for this drop down list State Enable or disable t...

Page 242: ..._24P2S_48T4S 242 Figure 4 8 45 Voice VLAN Port State Page Screenshot The page includes the following fields Object Description Port The switch port number of the logical port State Display the current state CoS Mode Display the current CoS mode ...

Page 243: ...red on this Page There is an unknown unicast storm rate control unknown multicast storm rate control and a broadcast storm rate control These only affect flooded frames i e frames with a VLAN ID DMAC pair not present on the MAC Address table 4 9 1 1 Global Setting The Storm Control Global Setting and Information screens in Figure 4 9 1 and Figure 4 9 2 appear Figure 4 9 1 Storm Control Global Sett...

Page 244: ...G 4 9 1 2 Port Setting Storm control for the switch is configured on this page There are three types of storm rate control Broadcast storm rate control Unknown Unicast storm rate control Unknow Multicast storm rate contro l The configuration indicates the permitted packet rate for unknown unicast unknown multicast or broadcast traffic across the switch The Storm Control Configuration screens in Fi...

Page 245: ... type Action Configures the action performed when storm control is over rate on a port Valid values are Shutdown or Drop Type Enable The settings in a particular row apply to the frame type listed here Broadcast Unknown Multicast Unknown Unicast Rate kbps pps Configure the rate for the storm control The default value is 10 000 and unit is 16Kbps Button Click to apply changes Figure 4 9 4 Storm Con...

Page 246: ...h port number of the logical port Port State Display the current port state Broadcast 16Kbps Display the current brocast storm control rate Unknown Multicast 16Kbps Display the current unknown multicast storm control rate Unknown Unicast 16Kbps Display the current unknown unicast storm control rate Action Display the current action ...

Page 247: ...pecial packet containing a success or failure indication Besides forwarding this decision to the supplicant the switch uses it to open up or block traffic on the switch port connected to the supplicant Overview of User Authentication It is allowed to configure the Managed Switch to authenticate users logging into the system for management access using local or remote authentication methods such as...

Page 248: ...m with Extensible Authentication Protocol EAP extensions is the only supported authentication server it is available in Cisco Secure Access Control Server version 3 0 RADIUS operates in a client server model in which secure authentication information is exchanged between the RADIUS server and one or more RADIUS clients Switch 802 1X device controls the physical access to the network based on the a...

Page 249: ...wever if during bootup the client does not receive an EAP request identity frame from the switch the client can initiate authentication by sending an EAPOL start frame which prompts the switch to request the client s identity If 802 1X is not enabled or supported on the network access device any EAPOL frames from the client are dropped If the client does not receive an EAP request identity frame a...

Page 250: ...the client initiates the authentication process by sending the EAPOL start frame When no response is received the client sends the request for a fixed number of times Because no response is received the client begins sending frames as if the port is in the authorized state If the client is successfully authenticated receives an Accept frame from the authentication server the port state changes to ...

Page 251: ...kend RADIUS servers are configured on the Security 802 1X Access Control 802 1X Setting page The IEEE802 1X standard defines port based operation but non standard variants overcome security limitations as shall be explored below The 802 1X Setting and Information screens in Figure 4 9 7 and Figure 4 9 8 appear Figure 4 9 7 802 1X Setting Page Screenshot The page includes the following fields Objec...

Page 252: ...owing modes are available No Authentication Authentication Force Unauthorized In this mode the switch will send one EAPOL Failure frame when the port link comes up and any client on the port will be disallowed network access Force Authorized In this mode the switch will send one EAPOL Success frame when the port link comes up and any client on the port will be allowed network access without authen...

Page 253: ... 65535 seconds Quiet Period Sets time to keep silent on supplicant authentication failure Supplicant Period Sets the interval for the supplicant to re transmit EAP request identify frame Maximun Request Retries The number of times that the switch transmits an EAPOL Request Identity frame without response before considering entering the Guest VLAN is adjusted with this setting The value can only be...

Page 254: ...nfigured with EAPOL Timeout If Allow Guest VLAN if EAPOL Seen is enabled the port will now be placed in the Guest VLAN If disabled the switch will first check its history to see if an EAPOL frame has previously been received on the port this history is cleared if the port link goes down or the port s Admin State is changed and if not the port will be placed in the Guest VLAN Otherwise it will not ...

Page 255: ...is drop down list Guest VLAN Enabled A Guest VLAN is a special VLAN typically with limited network access on which 802 1X unaware clients are placed after a network administrator defined timeout The switch follows a set of rules for entering and leaving the Guest VLAN as listed below The Guest VLAN Enabled checkbox provides a quick way to globally enable disable Guest VLAN functionality When check...

Page 256: ...8T4S 256 Figure 4 9 12 Guest VLAN Status Page Screenshot The page includes the following fields Object Description Port Name The switch port number of the logical port Enable State Display the current state In Guest VLAN Display the current guest VLAN ...

Page 257: ...s Figure 4 9 13 Authenticated Host Table Page Screenshot The page includes the following fields Object Description User Name Display the current user name Port Display the current port number Session Time Display the current session time Authentication Method Display the current authentication method MAC Address Display the current MAC address ...

Page 258: ...ilter DHCP messages received on a non secure interface from outside the network or firewall When DHCP snooping is enabled globally and enabled on a VLAN interface DHCP messages received on an untrusted interface from a device not listed in the DHCP snooping table will be dropped Table entries are only learned for trusted interfaces An entry is added or removed dynamically to the DHCP snooping tabl...

Page 259: ...P packet is not a recognizable type it is dropped If a DHCP packet from a client passes the filtering criteria above it will only be forwarded to trusted ports in the same VLAN If a DHCP packet is from server is received on a trusted port it will be forwarded to both trusted and untrusted ports in the same VLAN If the DHCP snooping is globally disabled all dynamic bindings are removed from the bin...

Page 260: ...enshot The page includes the following fields Object Description DHCP Snooping Display the current DHCP snooping status 4 9 3 3 VLAN Setting Command Usage When DHCP snooping is enabled globally on the switch and enabled on the specified VLAN DHCP packet filtering will be performed on any untrusted ports within the VLAN When the DHCP snooping is globally disabled DHCP snooping can still be configur...

Page 261: ...bled and possible modes are Enabled Enable DHCP snooping mode operation When enable DHCP snooping mode operation the request DHCP messages will be forwarded to trusted ports and only allowed reply packets from trusted ports Disabled Disable DHCP snooping mode operation Button Click to apply changes Figure 4 9 17 DHCP Snooping VLAN Setting Page Screenshot The page includes the following fields Obje...

Page 262: ... this port are removed Set all ports connected to DHCP servers within the local network or firewall to trusted state Set all other ports outside the local network or firewall to untrusted state The DHCP Snooping Port Setting screens in Figure 4 9 18 and Figure 4 9 19 appear Figure 4 9 18 DHCP Snooping Port Setting Page Screenshot The page includes the following fields Object Description Port Selec...

Page 263: ..._48T4S 263 Figure 4 9 19 DHCP Snooping Port Setting Page Screenshot The page includes the following fields Object Description Port The switch port number of the logical port Type Display the current type Chaddr Check Display the current chaddr check ...

Page 264: ...Statistics screen in Figure 4 9 20 appears Figure 4 9 20 DHCP Snooping Statistics Page Screenshot The page includes the following fields Object Description Port The switch port number of the logical port Forwarded Display the current forwarded Chaddr Check Dropped Display the chaddr check dropped ...

Page 265: ...ooping the switch will monitor all the DHCP messages and implement software transmission The DHCP Rate Limit Setting and Config screens in Figure 4 9 21 and Figure 4 9 22 appear Figure 4 9 21 DHCP Rate Limit Setting Page Screenshot The page includes the following fields Object Description Port Select port for this drop down list State Set default or user define Rate Limit pps Configure the rate li...

Page 266: ...2S_16P2S_24P2S_48T4S 266 Figure 4 9 22 DHCP Rate Limit Setting Page Screenshot The page includes the following fields Object Description Port Name The switch port number of the logical port Rate Limit pps Display the current rate limit ...

Page 267: ...o sub options Circuit ID option 1 Remote ID option2 The Circuit ID sub option is supposed to include information specific to which circuit the request came in on The Remote ID sub option was designed to carry information relating to the remote host end of the circuit The definition of Circuit ID in the switch is 4 bytes in length and the format is vlan_id module_id port_no The parameter of vlan_id...

Page 268: ...essing keep mode means that the system will keep the original option82 segment in the message and forward it to the server to process replace mode means that the system will replace the option 82 segment in the existing message with its own option 82 and forward the message to the server to process Option82 Port Setting screens in Figure 4 9 25 and Figure 4 9 26 appear Figure 4 9 25 Option82 Port ...

Page 269: ...User s Manual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 269 Button Click to apply changes Figure 4 9 26 Option82 Port Setting Page Screenshot ...

Page 270: ... 16T2S_24T2S_16P2S_24P2S_48T4S 270 Allow UnTrusted Display the current untrusted mode The page includes the following fields Object Description Port The switch port number of the logical port Enable Display the current status ...

Page 271: ...ID Setting Page Screenshot The page includes the following fields Object Description Port Select port for this drop down list VLAN Indicates the ID of this particular VLAN Circuit ID Set the option1 Circuit ID content of option 82 added by DHCP request packets Button Click to apply changes Figure 4 9 28 Option82 Port Circuit ID Setting Page Screenshot The page includes the following fields Object ...

Page 272: ... ARP Inspection related configuration A Dynamic ARP prevents the untrusted ARP packets based on the DHCP Snooping Database 4 9 4 1 Global Setting DAI Setting and Information screens in Figure 4 9 29 and Figure 4 9 30 appear Figure 4 9 29 DAI Setting Page Screenshot The page includes the following fields Object Description DAI Enable or disable the Dynamic ARP Inspection Button Click to apply chang...

Page 273: ...e page includes the following fields Object Description VLAN List Indicates the ID of this particular VLAN Status Enables Dynamic ARP Inspection on the specified VLAN Options Enable Disable Button Click to apply changes Figure 4 9 32 DAI VLAN Setting Page Screenshot The page includes the following fields Object Description VLAN List Display the current VLAN list Status Display the current status ...

Page 274: ...he source MAC address in the Ethernet header against the sender MAC address in the ARP body This check is performed on both ARP requests and responses When enabled packets with different MAC addresses are classified as invalid and are dropped Dst Mac Chk Enable or disable to checks the destination MAC address in the Ethernet header against the target MAC address in ARP body This check is performed...

Page 275: ...DAI Port Setting Page Screenshot The page includes the following fields Object Description Port The switch port number of the logical port Type Display the current port type Src MAC Chk Display the current Src MAC Chk status Dst MAC Chk Display the current Dst MAC Chk status ...

Page 276: ...The page includes the following fields Object Description Port The switch port number of the logical port Forwarded Display the current forwarded Source MAC Failures Display the current source MAC failures Dest MAC Failures Display the current source MAC failures SIP Validation Failures Display the current SIP Validation failures DIP Validation Failures Display the current DIP Validation failures ...

Page 277: ...he following fields Object Description Port Select port for this drop down list State Set default or user define Rate Limit pps Configure the rate limit for the port policer The default value is unlimited Button Click to apply changes Figure 4 9 37 ARP Rate Limit Setting Page Screenshot The page includes the following fields Object Description Port The switch port number of the logical port Rate L...

Page 278: ...ing attacks when a host tries to spoof and use the IP address of another host After receiving a packet the port looks up the key attributes including IP address MAC address and VLAN tag of the packet in the binding entries of the IP source guard If there is a matching entry the port will forward the packet Otherwise the port will abandon the packet IP source guard filters packets based on the foll...

Page 279: ...fing attacks when a host tries to spoof and use the IP address of another host The IP Source Guard Port Setting and Information screens in Figure 4 9 38 and Figure 4 9 39 appear Figure 4 9 38 IP Source Guard Port Setting Page Screenshot The page includes the following fields Object Description Port Select port for this drop down list Status Enable or disable the IP source guard Max Binding Entry T...

Page 280: ...rd Port Information Page Screenshot The page includes the following fields Object Description Port The switch port number of the logical port Status Display the current status Max Binding Entry Display the current max binding entry Current Binding Entry Display the current binding entry ...

Page 281: ...the ID of this particular VLAN MAC Address Sourcing MAC address is allowed IP Address Sourcing IP address is allowed Button Click to add authentication list Figure 4 9 41 IP Source Guard Binding Table Status Page Screenshot The page includes the following fields Object Description Port Display the current port VLAN ID Display the current VLAN MAC Address Display the current MAC address IP Address ...

Page 282: ...enshot The page includes the following fields Object Description Port Select Select port for this drop down list Security Enable or disable the port security Max L2 Entry The maximum number of MAC addresses that can be secured on this port If the limit is exceeded the corresponding action is taken The switch is born with a total number of MAC addresses from which all ports draw whenever a new MAC ...

Page 283: ...ed Even if the link is physically disconnected and reconnected on the port by disconnecting the cable the port will remain shut down There are three ways to re open the port 1 Disable and re enable Limit Control on the port or the switch 2 Click the Reopen button Also appears under SNMP and System log Trap Frequency sec Allow to input the seconds for trap frequency Button Click to apply changes Fi...

Page 284: ...e following fields Object Description Port Name The switch port number of the logical port Enable State Display the current per port security status L2 Entry Num Display the current L2 entry number Action Display the current aciotn Trap Frequency Display the current trap frequency ...

Page 285: ...ve data of the server Security feature refers to applications such as protocol check which is for protecting the server from attacks such as DoS The protocol check allows the user to drop matched packets based on specified conditions The security features provide several simple and effective protections against Dos attacks while acting no influence on the linear forwarding performance of the switc...

Page 286: ... mode by IPv4 ping max size IPv6 Ping Max Size Enable or disable DoS check mode by IPv6 ping max size Ping Max Size Setting Set the max size for ping Smurf Attack Enable or disable DoS check mode by smurf attack TCP Min Hdr Size Enable or disable DoS check mode by TCP min hdr size TCP SYN SPORT 1024 Enable or disable DoS check mode by TCP syn sport 1024 Null Scan Attack Enable or disable DoS check...

Page 287: ...nts Display the current ICMP fragment status IPv4 Ping Max Size Display the current IPv4 ping max size status IPv6 Ping Max Size Display the current IPv6 ping max size status Smurf Attack Display the current smurf attack status TCP Min Header Length Display the current TCP min header length TCP SYN SPORT 1024 Display the current TCP syn status Null Scan Attack Display the current null scan attack ...

Page 288: ... 4 9 46 and Figure 4 9 47 appear Figure 4 9 46 Port Security Setting Page Screenshot The page includes the following fields Object Description Port Select Select port for this drop down list DoS Protection Enable or disable per port DoS protection Gratuitous ARP Enable or disable per port Gratuitous ARP Button Click to apply changes ...

Page 289: ...e 4 9 47 Port Security Setting Page Screenshot The page includes the following fields Object Description Port The switch port number of the logical port DoS Protection Display the current DoS protection status Gratuitous ARP Display the current Gratuitous ARP status ...

Page 290: ...ch supports the following AAA features Accounting for IEEE 802 1X authenticated users that access the network through the Managed Switch Accounting for users that access management interfaces on the Managed Switch through the console and Telnet Accounting for commands that users enter at specific CLI privilege levels Authorization of users that access management interfaces on the Managed Switch th...

Page 291: ...ption List Name Defines a name for the authentication list the available length is 31 characters Method 1 4 Set the login authentication method Empty None Local TACACS RADIUS Enable Default mode is Empty Button Click to add authentication list Figure 4 9 49 Login Authentication List Screenshot The page includes the following fields Object Description List Name Display the current list name Method ...

Page 292: ...0 New Authentication List Screenshot The page includes the following fields Object Description List Name Defines a name for the authentication list the available length is 31 characters Method 1 3 Set the login authentication method Empty None Enable TACACS RADIUS Button Click to add authentication list Figure 4 9 51 Login Authentication List Screenshot The page includes the following fields Objec...

Page 293: ...s The authentication list screens in Figure 4 9 52 and Figure 4 9 53 appear Figure 4 9 52 New Accounting List Screenshot The page includes the following fields Object Description List Name Defines a name for the accounting list the available length is 31 characters Record Type Provide following record type Start Stop Default mode Stop Only Method 1 2 Set the login accounting method TACACS RADIUS B...

Page 294: ...odify Click to edit login authentication list parameter Click to delete login authentication list entry 4 9 8 4 Accounting Update This page is to accounting update parameters The authentication list screens in Figure 4 9 54 and Figure 4 9 55 appear Figure 4 9 54 Accounting Update Screenshot The page includes the following fields Object Description State Provide Disabled or Enabled this function Pr...

Page 295: ...2S_16P2S_24P2S_48T4S 295 Button Click to apply changes Figure 4 9 55 Accounting Update Screenshot The page includes the following fields Object Description State Display the current state Periodic mim Display the current periodic value ...

Page 296: ...ge Screenshot The page includes the following fields Object Description Key String The secret key up to 128 characters long shared between the TACACS server and the switch Timeout for Reply Retransmit is the number of times in the range 1 to 30 a TACACS request is retransmitted to a server that is not responding If the server has not responded after the last retransmit it is considered to be dead ...

Page 297: ...ut The number of seconds the switch waits for a reply from the server before it resends the request Range 1 30 seconds Server Priority Set the server priority Range 0 65535 Button Click to add TACACS Server setting Figure 4 9 58 Login Authentication List Page Screenshot The page includes the following fields Object Description IP Address Display the current IP address Port Display the current port...

Page 298: ...1 to 30 a RADIUS request is retransmitted to a server that is not responding If the server has not responded after the last retransmit it is considered to be dead Default is 3 Dead Time The Dead Time which can be set to a number between 0 and 2000 seconds is the period during which the switch will not send new requests to a server that has failed to respond to a previous request This will stop the...

Page 299: ...lt port 1813 is used on the RADIUS Accounting Server Range 0 65535 Key String The shared key shared between the RADIUS Authentication Server and the switch Timeout for Reply The Timeout which can be set to a number between 1 and 30 seconds is the maximum time to wait for a reply from a server If the server does not reply within this timeframe we will consider it to be dead and continue with the ne...

Page 300: ...Dead Time to a value greater than 0 zero will enable this feature but only if more than one server has been configured Range 0 2000 Usage Type Set the usage type The following modes are available Login 802 1X All Button Click to add Radius server setting Figure 4 9 61 Login Authentication List Page Screenshot The page includes the following fields Object Description IP Address Display the current ...

Page 301: ...es the following fields Object Description Login Authentication List Select login authentication list for this drop down list Enable Authentication List Select enable authentication list for this drop down list EXEC Accounting List Select EXEC accounting list for this drop down list Session Timeout Set the session timeout value Default is 10 and available range is 0 65535 minutes Password Retry Co...

Page 302: ...tion List Display the current login authentication list information Enable Authentication List Display the current enable authentication list information EXEC Accounting List Display the EXEC accounting list information Session Timeout Display the current session timeout information Password Retry Count Displays the current password retry count information Silent Time Display the current silent ti...

Page 303: ...Authentication List Select login authentication list for this drop down list Enable Authentication List Select enable authentication list for this drop down list EXEC Accounting List Select EXEC accounting list for this drop down list Session Timeout Set the session timeout value Default is 10 and available range is 0 65535 minutes Password Retry Count Set the password retry count value Default is...

Page 304: ...Authentication List Display the current login authentication list information Enable Authentication List Display the current enable authentication list information EXEC Accounting List Display the EXEC accounting list information Session Timeout Display the current session timeout information Password Retry Count Displays the current password retry count information Silent Time Display the current...

Page 305: ... Login Authentication List Select login authentication list for this drop down list Session Timeout Set the session timeout value Default is 10 and available range is 0 86400 minutes Button Click to apply changes Figure 4 9 67 HTTP Information Page Screenshot The page includes the following fields Object Description HTTP Service Display the current HTTP service information Login Authentication Lis...

Page 306: ...d Login Authentication List Select login authentication list for this drop down list Session Timeout Set the session timeout value Default is 10 and available range is 0 86400 minutes Button Click to apply changes Figure 4 9 69 HTTPs Information Page Screenshot The page includes the following fields Object Description HTTPs Service Display the current HTTPs service information Login Authentication...

Page 307: ...lar ACE ID There are three ACE frame types Ethernet Type ARP and IPv4 and two ACE actions permit and deny The ACE also contains many detailed different parameter options that are available for individual application The ACL page contains links to the following main topics MAC Based ACL Configuration MAC based ACL setting MAC Based ACE Add Edit Delete the MAC based ACE Access Control Entry setting ...

Page 308: ...10 16T2S_24T2S_16P2S_24P2S_48T4S 308 Button Click to add MAC Based ACL setting Figure 4 10 2 MAC Based ACL Table Page Screenshot The page includes the following fields Object Description Delete Click to delete ACL name entry ...

Page 309: ... 3 and Figure 4 10 4 appear Figure 4 10 3 MAC Based ACE Page Screenshot The page includes the following fields Object Description ACL Name Select ACL name for this drop down list Sequence Set the ACL sequence Action Indicates the forwarding action of the ACE Permit Frames matching the ACE may be forwarded and learned Deny Frames matching the ACE are dropped DA MAC Specify the destination MAC filte...

Page 310: ...ource MAC address with this ACE choose this value A field for entering a SA MAC value appears SA MAC Value When User Defined is selected for the SA MAC filter you can enter a specific source MAC address The legal format is xx xx xx xx xx xx A frame that hits this ACE matches this SA MAC value SA MAC Mask Specify whether frames can hit the action according to their sender hardware address field SHA...

Page 311: ...tion Destination MAC Address Display the current destination MAC address Destination Wildcard Mask Display the current destination wildcard mask Source MAC Address Display the current source MAC address Source Wildcard Mask Display the current source wildcard mask VLAN ID Display the current VLAN ID 802 1p Display the current 802 1p value 802 1p Mask Display the current 802 1p mask value Ethertype...

Page 312: ...rdware due to hardware limitations IPv4 Based ACL screens in Figure 4 10 5 and Figure 4 10 6 appear Figure 4 10 5 IPv4 based ACL Page Screenshot The page includes the following fields Object Description ACL Name Create a named IPv4 based ACL list Button Click to add IPv4 based ACL name list Figure 4 10 6 IPv4 based ACL Table Page Screenshot The page includes the following fields Object Description...

Page 313: ...4 10 4 IPv4 based ACE An ACE consists of several parameters Different parameter options are displayed depending on the frame type that you selected The IPv4 Based ACE screens in Figure 4 10 7 and Figure 4 10 8 appear Figure 4 10 7 IPv4 based ACE Page Screenshot ...

Page 314: ...address The legal format is xxx xxx xxx xxx A frame that hits this ACE matches this source IP address value Source IP Mask When User Defined is selected for the source IP filter you can enter a specific SIP mask in dotted decimal notation Destination IP Address Specify the Destination IP address filter for this ACE Any No destination IP address filter is specified User Defined If you want to filte...

Page 315: ...ation port value appears TCP Flags Urg Specify the TCP Urgent Pointer field significant URG value for this ACE Set TCP frames where the Urg field is set must be able to match this entry Unset TCP frames where the Urg field is set must not be able to match this entry Don t Care Any value is allowed don t care Ack Specify the TCP Acknowledgment field significant ACK value for this ACE Set TCP frames...

Page 316: ...hes this DSCP value IP Recedence to match If you want to filter a specific IP recedence with this ACE you can enter a specific IP recedence value A field for entering an IP recedence value appears The allowed range is 0 to 7 A frame that hits this ACE matches this IP recedence value ICMP Specify the ICMP for this ACE Any No specifc ICMP is specified destination port status is don t care Select fro...

Page 317: ...ss Wildcard Mask Display the current source IP address wildcard mask Destination IP Address Display the current destination IP address Destination IP Address Wildcard Mask Display the current destination IP address wildcard mask Source Port Range Display the current source port range Destiantion Port Range Display the current destination port range Flag Set Display the current flag set DSCP Displa...

Page 318: ...dware due to hardware limitations IPv6 Based ACL screens in Figure 4 10 9 and Figure 4 10 10 appear Figure 4 10 9 IPv6 based ACL Page Screenshot The page includes the following fields Object Description ACL Name Create a named IPv6 based ACL list Button Click to add IPv6 based ACL name list Figure 4 10 10 IPv6 based ACL Table Page Screenshot The page includes the following fields Object Descriptio...

Page 319: ...10 6 IPv6 based ACE An ACE consists of several parameters Different parameter options are displayed depending on the frame type that you selected The IPv6 Based ACE screens in Figure 4 10 11 and Figure 4 10 12 appear Figure 4 10 11 IPv6 based ACE Page Screenshot ...

Page 320: ...xx A frame that hits this ACE matches this source IP address value Source IP Prefix Length When User Defined is selected for the source IP filter you can enter a specific SIP prefix length in dotted decimal notation Destination IP Address Specify the Destination IP address filter for this ACE Any No destination IP address filter is specified User Defined If you want to filter a specific destinatio...

Page 321: ...e value A field for entering a destination port value appears TCP Flags URG Specify the TCP Urgent Pointer field significant URG value for this ACE Set TCP frames where the URG field is set must be able to match this entry Unset TCP frames where the URG field is set must not be able to match this entry Don t Care Any value is allowed don t care ACK Specify the TCP Acknowledgment field significant ...

Page 322: ... A frame that hits this ACE matches this DSCP value IP Recedence If you want to filter a specific IP recedence with this ACE you can enter a specific IP recedence value A field for entering an IP recedence value appears The allowed range is 0 to 7 A frame that hits this ACE matches this IP recedence value ICMP Specify the ICMP for this ACE Any No specifc ICMP is specified destination port status i...

Page 323: ...ss Wildcard Mask Display the current source IP address wildcard mask Destination IP Address Display the current destination IP address Destination IP Address Wildcard Mask Display the current destination IP address wildcard mask Source Port Range Display the current source port range Destination Port Range Display the current destination port range Flag Set Display the current flag set DSCP Displa...

Page 324: ...Object Description Binding Port Select port for this drop down list ACL Select Select ACL list for this drop down list Button Click to apply changes Figure 4 10 14 ACL Binding Table Page Screenshot The page includes the following fields Object Description Port The switch port number of the logical port MAC ACL Display the current MAC ACL IPv4 ACL Display the current IPv4 ACL IPv6 ACL Display the c...

Page 325: ...ess of the equipment sending the frame The SMAC address is used by the switch to automatically update the MAC table with these dynamic MAC addresses Dynamic entries are removed from the MAC table if no frames with the corresponding SMAC address have been seen after a configurable age time 4 11 1 Static MAC Setting The static entries in the MAC table are shown in this table The MAC table is sorted ...

Page 326: ...Static MAC Status Page Screenshot The page includes the following fields Object Description No This is the number for entries MAC Address The MAC address for the entry Port Display the current port VLAN The VLAN ID for the entry Delete Click to delete static MAC status entry ...

Page 327: ...g Page Screenshot The page includes the following fields Object Description MAC Address Physical address associated with this interface VLAN 1 4094 Indicates the ID of this particular VLAN Button Click to add new MAC filtering setting Figure 4 11 4 MAC Filter Information Page Screenshot The page includes the following fields Object Description No This is the number for entries MAC Address The MAC ...

Page 328: ...re 4 11 6 appear Figure 4 11 5 Dynamic Addresses Setting Page Screenshot The page includes the following fields Object Description Aging Time The time after which a learned entry is discarded Range 10 630 seconds Default 300 seconds Button Click to apply changes Figure 4 11 6 Dynamic Address Status Page Screenshot The page includes the following fields Object Description Aging Time Display the cur...

Page 329: ...7 and Figure 4 11 8 appear Figure 4 11 7 Dynamic Learned Page Screenshot The page includes the following fields Object Description Port Select port for this drop down list VLAN Select VLAN for this drop down list MAC Address Physical address associated with this interface Buttons Refreshes the displayed table starting from the Start from MAC address and VLAN input fields Flushes all dynamic entrie...

Page 330: ... VLAN The VLAN ID of the entry Type Indicates whether the entry is a static or dynamic entry Port The ports that are members of the entry Button Click to add dynamic MAC address to static MAC address Object Description MAC Address The MAC address of the entry ...

Page 331: ...and Figure 4 11 10 appear Figure 4 11 9 Reserved MAC Addresses Page Screenshot The page includes the following fields Object Description MAC Address Select MAC Address from this drop down list Action Select Peer Bridge and Discard for specific MAC address Button Click to apply changes Figure 4 11 10 Reserved MAC Addresses StatusPage Screenshot Object Description MAC Address The MAC address of the ...

Page 332: ...ore and maintain information gathered about the neighboring network nodes it discovers Link Layer Discovery Protocol Media Endpoint Discovery LLDP MED is an extension of LLDP intended for managing endpoint devices such as Voice over IP phones and network switches The LLDP MED TLVs advertise information such as network policy power inventory and device location details LLDP and LLDP MED information...

Page 333: ...od is set to Holdtime multiplied by Transmission Interval seconds Valid values are restricted to 2 10 times TTL in seconds is based on the following rule Transmission Interval Holdtime Multiplier 65536 Therefore the default TTL is 4 30 120 seconds Reinitialization Delay When a port is disabled LLDP is disabled or the switch is rebooted a LLDP shutdown frame is transmitted to the neighboring units ...

Page 334: ...DP Global Config Page Screenshot The page includes the following fields Object Description LLDP Enable Display the current LLDP status LLDP PDU Disable Action Displays the current LLDP PDU disable action Transmission Interval Display the current transmission interval informaiton Check Change Interval Display the current check change interval informaiton Reinitialization Delay Display the current r...

Page 335: ...es the following fields Object Description Port Select Select port for this drop down list State Enables LLDP messages transmit and receive modes for LLDP Protocol Data Units Options Disable Default Rx ONLY Tx ONLY TX RX Port Select Select port for this drop down list Optional TLV Select Configures the information included in the TLV field of advertised messages System Name When checked the System...

Page 336: ...802 3 MAC PHY is included in LLDP information transmitted 802 3 Link Aggregation When checked the 802 3 Link Aggregation is included in LLDP information transmitted 802 3 Maximun Frame Size When checked the 802 3 Maximun Frame Size is included in LLDP information transmitted 802 1 PVID When checked the 802 1 PVID is included in LLDP information transmitted Button Click to apply changes ...

Page 337: ...gure 4 12 4 LLDP Port Status Page Screenshot The page includes the following fields Object Description Port The switch port number of the logical port State Display the current LLDP status Selected Optional TLVs Display the current selected optional TLVs setting ...

Page 338: ...LAN TLV Status screens in Figure 4 12 5 and Figure 4 12 6 appear Figure 4 12 5 VLAN Name TLV VLAN Selection Page Screenshot The page includes the following fields Object Description Port Select Select port from this drop down list VLAN Select Select VLAN from this drop down list Button Click to apply changes ...

Page 339: ...T2S_16P2S_24P2S_48T4S 339 Figure 4 12 6 LLDP Port VLAN TLV Status Page Screenshot The page includes the following fields Object Description Port The switch port number of the logical port Selected VLAN Display the current selected VLAN ...

Page 340: ...and Figure 4 12 8 appear Figure 4 12 7 Local Device Summary Page Screenshot The page includes the following fields Object Description Chassis ID Subtype Display the current chassis ID subtype Chassis ID Display the current chassis ID System Name Display the current system name System Description Display the current system description Capabilities Supported Display the current capabilities supporte...

Page 341: ...nterface The switch port number of the logical port LLDP Status Display the current LLDP status LLDP MED Status Display the current LLDP MED Status Detail press the Detail button then the following detail LLDP Local Device Detail information appears Press Back button for back to previous Port Status screen The Global Information screen in Figure 4 12 9 appears ...

Page 342: ...he current system name System Description Display the current system description Supported System Capabilities Display the current supported system capabilities information Enabled System Capabilities Display the current enabled system capabilities information Port ID Subtype Display the current port ID Subtype information Port ID Display the current port ID information Port Description Display th...

Page 343: ...current auto neogitaion advertised capailities information Operational MAU Type Display the current operational MAU type information The 802 3 Details Information screen in Figure 4 12 11 appears Figure 4 12 11 802 3 Details Information Page Screenshot The page includes the following fields Object Description 802 3 Maximum Frame Size Display current 802 3 maximum frame size information The 802 3 L...

Page 344: ...n Capabilities Supported Display current capabilities supported information Current Capabilities Display current capabilities information Device Class Display current device class information PoE Device Type Display current PoE device type information PoE Power Source Display current PoE power source information PoE Power Priority Display current PoE power priority information PoE Power Value Disp...

Page 345: ... 4210 24P2S The 802 1 VLAN and Protocol Information screen in Figure 4 12 14 appears Figure 4 12 14 802 1 VLAN and Protocol Information Page Screenshot The page includes the following fields Object Description PVID Display current PVID information VLAN Names Display current VLAN Names information The Location Information screen in Figure 4 12 15 appears Figure 4 12 15 Location Information Page Scr...

Page 346: ...ork Policy Table Page Screenshot The page includes the following fields Object Description Application Type Display current application type information VLAN ID Display current VLAN ID information VLAN Type Display current VLAN Type information User Priority Display current user priority information DSCP Display current DSCP information ...

Page 347: ...llowing fields Object Description Sel Disaply current sel information Local Port Display the current local port Chassis ID Subtype Display the current chassis ID subtype Chassis ID The Chassis ID is the identification of the neighbor s LLDP frames Port ID Subtype Display the current port ID subtype Port ID The Remote Port ID is the identification of the neighbor port System Name System Name is the...

Page 348: ...multiple sets of application types supported on a given port The application types specifically addressed are 1 Voice 2 Guest Voice 3 Softphone Voice 4 Video Conferencing 5 Streaming Video 6 Control Signaling conditionally support a separate network policy for the media types above A large network may support multiple VoIP policies across the entire organization and different policies per applicat...

Page 349: ... dedicated IP Telephony handsets and other similar appliances supporting interactive voice services These devices are typically deployed on a separate VLAN for ease of deployment and enhanced security by isolation from data applications Voice Signaling for use in network topologies that require a different policy for the voice signaling than for the voice media This application type should not be ...

Page 350: ...topologies that require a separate policy for the video signaling than for the video media This application type should not be advertised if all the same network policies apply as those advertised in the Video Conferencing application policy VLAN ID VLAN identifier VID for the port as defined in IEEE 802 1Q 2003 The range is 1 4095 VLAN Tag Tagged indicates that the device is using the IEEE 802 1Q...

Page 351: ...e following fields Object Description Network Policy Number Display the current network policy number Application Display the current application VLAN ID Display the current VLAN ID VLAN Tag Display the current VLAN tag status L2 Priority Display the current L2 priority DSCP Value Dusplay the current DSCP value Button Click to delete LLDP MED network policy table entry ...

Page 352: ...cluded in the MED TLV field of advertised messages Network Policy This option advertises network policy configuration information aiding in the discovery and diagnosis of VLAN configuration mismatches on a port Improper network policy configurations frequently result in voice quality degradation or complete service disruption Location This option advertises location identification details Inventor...

Page 353: ... page includes the following fields Object Description Interface The switch port number of the logical port LLDP MED Status Display the current LLDP MED status Active Display the current active status Application Display the current application Location Display the current location Inventory Display the current inventory ...

Page 354: ...shot The page includes the following fields Object Description Ports Select port for this drop down list Location Coordinate A string identifying the Location Coordinate that this entry should belong to Location Civic Address A string identifying the Location Civic Address that this entry should belong to Location ESC ELIN A string identifying the Location ESC ELIN that this entry should belong to...

Page 355: ...LDP MED Port Location Table Page Screenshot The page includes the following fields Object Description Port The switch port number of the logical port Coordinate Display the current coordinate Civic Address Display the current civic address ESC ELIN Display the current ESC ELIN ...

Page 356: ...User s Manual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 356 4 12 8 LLDP Overloading The LLDP Port Overloading screen in Figure 4 12 24 appears Figure 4 12 24 LLDP Port Overloading Table Page Screenshot ...

Page 357: ...Policy Displays if the network policies packets were transmitted or overloaded MED Extended Power via MDI Displays if the extended power via MDI packets were transmitted or overloaded 802 3 TLVs Displays if the 802 3 TLVs were transmitted or overloaded Optional TLVs If the LLDP MED extended power via MDI packets were sent or if they were overloaded MED Inventory Displays if the mandatory group of ...

Page 358: ...mber of new entries added since switch reboot Deletions Shows the number of new entries deleted since switch reboot Drops Shows the number of LLDP frames dropped due to that the entry table was full Age Outs Shows the number of entries deleted due to Time To Live expiring Buttons Click to clear the statistics Click to refresh the statistics ...

Page 359: ... Port The port on which LLDP frames are received or transmitted TX Frame Total The number of LLDP frames transmitted on the port RX Frame Total The number of LLDP frames received on the port RX Frame Discarded If an LLDP frame is received on a port and the switch s internal table has run full the LLDP frame is counted and discarded This situation is known as Too Many ...

Page 360: ...nks down an LLDP shutdown frame is received or when the entry ages out RX Frame Errors The number of received LLDP frames containing some kind of error RX TLVs Discarded Each LLDP frame can contain multiple pieces of information known as TLVs TLV is short for Type Length Value If a TLV is malformed it is counted and discarded RX TLVs Unrecognized The number of well formed TLVs but with an unknown ...

Page 361: ...er 4 13 1 Cable Diagnostics The Cable Diagnostics performs tests on copper cables These functions have the ability to identify the cable length and operating conditions and to isolate a variety of common faults that can occur on the Cat5 twisted pair cabling There might be two statuses as follow If the link is established on the twisted pair interface in 1000BASE T mode the Cable Diagnostics can r...

Page 362: ...the following fields Object Description Port Select port for this drop down list Button Click to run the diagnostics Figure 4 13 2 Test Results Page Screenshot The page includes the following fields Object Description Port The port where you are requesting Cable Diagnostics Channel A D Display the current channel status Cable Length A D Display the current cable length Result Display the test resu...

Page 363: ... The system status screen in Figure 4 13 3 appears Figure 4 13 3 CPU and Memory Information Page Screenshot The page includes the following fields Object Description CPU Display the current CPU usage status MEM_USED Display the current memory usage status MEM_FREE Display the current free memory status Refresh Period Provide 5 and 10 seconds for refresh period ...

Page 364: ...are received or until a timeout occurs The ICMP Ping screen in Figure 4 13 4 appears Figure 4 13 4 IPv4 Ping Test Setting Page Screenshot The page includes the following fields Object Description IP Address The destination IP Address Count Number of echo requests to send The range is 1 5 and default is 4 Interval in sec Send interval for each ICMP packet The range is 1 5 and default is 1 Size in b...

Page 365: ...ion of a reply The page refreshes automatically until responses to all packets are received or until a timeout occurs The ICMPv6 Ping screen in Figure 4 13 5 appears Figure 4 13 5 IPv6 Ping Page Screenshot The page includes the following fields Object Description IPv6 Address The destination IPv6 Address Count Number of echo requests to send The range is 1 5 and default is 4 Interval in sec Send i...

Page 366: ...out a data packet with TTL at 2 will be sent Also the send hop may be a TTL timeout return but the procedure will carries on till the data packet is sent to its destination These procedures is for recording every source address which returned ICMP TTL timeout message so to describe a path the IP data packets traveled to reach the destination The Trace Route Setting screen in Figure 4 13 6 appears ...

Page 367: ...power socket limitation the GS 4210 16P2S and GS 4210 24P2S PoE Managed Switch makes the installation of cameras or WLAN AP more easily and efficiently Use the PoE sub menu items to configure the PoE function of the GS 4210 16P2S and GS 4210 24P2S PoE Managed Switch Under PoE sub menu the following topics are provided to configure and view the PoE Setting This section has the following items PoE G...

Page 368: ... The range is 0 300 watts and default is 300 watts GS 4210 24P2S Systsem Operation Status Display current system operation status Power Allocation Dislpay current power allocation value in watts PoE Temperature Port 1 8 Display the current PoE chipset temperature of port 1 8 PoE Temperature Port 9 16 Display the current PoE chipset temperature of port 9 16 PoE Temperature Port 17 24 Display the cu...

Page 369: ...oE Port Setting Page Screenshot Button Click to apply changes The page includes the following fields Object Description Port Select Select port from this drop down list Status Disable or enable per port PoE function Priority Select priority oprtions from this drop down list The available options are 3 Low Default 2 High 1 Critiical Power Budget Allow assign PoE Budget to per port of the PoE Manage...

Page 370: ... 370 Figure 4 14 3 PoE Port Status Page Screenshot The page includes the following fields Object Description Port The switch port number of the logical port Status Display per PoE port operation status Class Display per PoE port PD device class information ...

Page 371: ... watts Display per PoE port power consumption information Power Budget watts Display per PoE port power budget information The page includes the following fields Object Description Port The switch port number of the logical port Status Display per PoE port operation status Class Display per PoE port PD device class information ...

Page 372: ...y time and viewing per PoE port status The PoE Delay Setting screen in Figure 4 14 4 appears Figure 4 14 4 PoE Delay Setting Page Screenshot Button Click to apply changes The page includes the following fields Object Description Port Select Select port from this drop down list Delay Mode Disable or enable delay mode Delay Time Allow assign delay time to the PoE Managed Switch The range is 0 300 se...

Page 373: ...gure 4 14 5 PoE Delay Status Page Screenshot The page includes the following fields Object Description Port The switch port number of the logical port Delay Mode Display per port delay mode status Delay Time Second Display per port delay time setting information ...

Page 374: ...m restrictions due to power outlet locations which eliminate the costs for additional AC wiring and reduces the installation time 3 25 Watts High Power PoE Splitter High PoE Splitter split the PoE 52V DC over the Ethernet cable into 24 12V DC power output It frees the device deployment from restrictions due to power outlet locations which eliminate the costs for additional AC wiring and reduces th...

Page 375: ...ch subnet monitored by the Agent History Record periodical statistic samples available from Statistics Alarm Allow management console users to set any count or integer for sample intervals and alert thresholds for RMON Agent records Event A list of all events generated by RMON Agent Alarm depends on the implementation of Event Statistics and History display some current or history subnet statistic...

Page 376: ...tal number of packets received that were longer than 1518 octets etherStatsFragments The number of frames which size is less than 64 octets received with invalid CRC etherStatsJabbers The number of frames which size is larger than 64 octets received with invalid CRC etherStatsCollisions The best estimate of the total number of collisions on this Ethernet segment etherStatsPkts64Octets The total nu...

Page 377: ...the event the possible types are None The total number of octets received on the interface including framing characters Log The number of uni cast packets delivered to a higher layer protocol SNMP Trap The number of broad cast and multi cast packets delivered to a higher layer protocol Log and Trap The number of inbound packets that are discarded even the packets are normal Community Specify the c...

Page 378: ...g fields Object Description Index Display the current event index Event Type Display the current event type Community Display the current community for SNMP trap Description Display the current event description Last Sent Time Display the current last sent time Owner Display the current event owner Action Click to delete RMON event entry ...

Page 379: ...ears Figure 4 15 4 RMON Event Log Table Page Screenshot The Page includes the following fields Object Description Event Index Select index from this drop down list Index Indicates the index of the log entry Alarm Index Indicates the alarm index of the log entry Action Indicates the action of the log entry Log Time Indicates Event log time Description Indicates the Event description ...

Page 380: ...modify the index Index Indicates the index of the alarm entry The range is 1 65535 Sample Port Select port from this drop down list Sample Variable Indicates the particular variable to be sampled the possible variables are DropEvents The total number of events in which packets were dropped due to lack of resources Octets The number of received and transmitted good and bad bytes Includes FCS but ex...

Page 381: ...ollisions on this Ethernet segment Pkts64Octets The total number of frames including bad packets received andtransmitted that were 64 octets in length excluding framing bits but including FCS octets Pkts65to127Octets The total number of frames including bad packets received andtransmitted where the number of octets fall within the specified range excluding framing bits but including FCS octets Pkt...

Page 382: ...ling threshold is crossed Owner Specify an owner for the alarm Button Click to apply changes Figure 4 15 6 RMON Alarm Status Page Screenshot The Page includes the following fields Object Description Index Indicates the index of Alarm control entry Sample Port Display the current sample port Sample Variable Display the current sample variable Sample Interval Display the current interval Sample Type...

Page 383: ...reate the new index or modify the index Index Indicates the index of the history entry The range is 1 65535 Sample Port Select port from this drop down list Bucket Requested Indicates the maximum data entries associated this History control entry stored in RMON The range is from 1 to 65535 default value is 50 Interval Indicates the interval in seconds for sampling the history statistics data The r...

Page 384: ...nshot The Page includes the following fields Object Description Index Display the current index Data Source Display the current data source Bucket Requested Display the current bucket requested Interval Display the current interval Owner Display the current owner Action Click to delete RMON history entry ...

Page 385: ...RMON History Log This page provides a detail of RMON history entries screen in Figure 4 15 9 appears Figure 4 15 9 RMON History Status Page Screenshot The page includes the following fields Object Description History Index Select history index from this drop down list ...

Page 386: ...able password 4 16 1 Factory Default You can reset the configuration of the switch on this page Only the IP configuration is retained The new configuration is available immediately which means that no restart is necessary The Factory Default screen in Figure 4 16 1 appears and clicks to reset the configuration to Factory Defaults Figure 4 16 1 Factory Default Page Screenshot After the Factory butt...

Page 387: ...boot page enables the device to be rebooted from a remote location Once the Reboot button is pressed user has to re login the WEB interface about 60 seconds later The Reboot Switch screen in Figure 4 16 2 appears and clicks to reboot the system Figure 4 16 2 Reboot Switch Page Screenshot ...

Page 388: ...nagement station The Backup Manager screen in Figure 4 16 3 appears Figure 4 16 3 Backup Manager Page Screenshot The page includes the following fields Object Description Backup Method Select backup method from this drop down list The optios are TFTP and HTTP Server IP Fill in your TFTP server IP address Backup Type Select backup type Button Click to backup image configuration or log ...

Page 389: ...anager screen in Figure 4 16 4 appears Figure 4 16 4 Upgrade Manager Page Screenshot The page includes the following fields Object Description Upgrade Method Select upgrade method from this drop down list The optios are TFTP and HTTP Server IP Fill in your TFTP server IP address File Name The name of firmware image or configuration Upgrade Type Select upgrade type Button Click to upgrade image or ...

Page 390: ...guration file which is called configuration save This page also provides to save all applied changes and set the current configuration as a startup configuration or backup configuration The startup configuration file will be loaded automatically across a system reboot the configuration manager screen in Figure 4 16 5 appears Figure 4 16 5 Configuration Manager Page Screenshot The page includes the...

Page 391: ...vide 0 15 option Password Type Provide Clear Text and Encrypted options Password Allow input the new password and available range is 30 characters Retype Password Allow input the new password again for confirm Button Click to apply changes Figure 4 16 7 Local Enable Password Page Screenshot The page includes the following fields Object Description Privilege Value Display current privilege value in...

Page 392: ...GS 4210 24T2S GS 4210 48T4S and GS 4210 16P2S Logon to the Console Once the terminal is connected to the device power on the Managed Switch and the terminal will run self testing procedures Then the following message asks to login user name and password The factory default user name and password are shown as follows and the login screen in Figure 5 1 appears Username admin Password admin 1 On User...

Page 393: ...ter show ip 2 The screen displays the current IP address Subnet Mask and Gateway shown in Figure 5 2 Figure 5 2 IP Information Screen Configuration of the IP address 3 On GS 4210 24P2S prompt enter configure 4 On GS 4210 24P2S config prompt enter the following command and press Enter as shown in Figure 5 3 GS 4210 24P2S config ip address 192 168 1 100 mask 255 255 255 0 GS 4210 24P2S config ip def...

Page 394: ...immediately You can access the Web interface of Managed Switch through the new IP address If you do not familiar with console command or the related parameter enter anytime in console to get the help description 5 2 Telnet Login The Managed Switch also supports telnet for remote management The Managed Switch asks for user name and password for remote login when using telnet please use admin for us...

Page 395: ...ures the command modes the prompts visible in that mode and the exit method from that mode Command Mode Access Method Prompt Exit or Access Previous Mode User Mode This is the first level of access Perform basic tasks and list system information GS 4210 24P2S Enter exit command Privileged Mode From the User Mode enter the enable command GS 4210 24P2S To exit to the User Mode enter exit Global Conf...

Page 396: ... can issue any Exec command to enter the Global Configuration mode The command prompt shown at this level is Command Prompt GS 4210 24P2S Global Config Mode This mode permits the operator to make modifications to the running configuration General setup commands are grouped in this mode From the Global Configuration mode the operator can enter the Interface Configuration mode The command prompt at ...

Page 397: ...STNAME Host name Example GS 4210 24P2S ping 192 168 0 100 PING 192 168 0 100 192 168 0 100 56 data bytes 64 bytes from 192 168 0 100 icmp_seq 0 ttl 64 time 0 0 ms 64 bytes from 192 168 0 100 icmp_seq 1 ttl 64 time 0 0 ms 64 bytes from 192 168 0 100 icmp_seq 2 ttl 64 time 0 0 ms 64 bytes from 192 168 0 100 icmp_seq 3 ttl 64 time 0 0 ms 192 168 0 100 ping statistics 4 packets transmitted 4 packets r...

Page 398: ...p Example GS 4210 24P2S show arp Address HWtype H Waddress F lags Mask Iface 192 168 0 100 ether C8 9C DC EC D6 DD C eth0 GS 4210 24P2S show history Description List the last several history commands Syntax show history Example GS 4210 24P2S show history show info Description Show basic information Syntax show info Example GS 4210 24P2S show info ...

Page 399: ...privilege Description Show the local user privilege level Syntax show privilege Example GS 4210 24P2S show privilege Current CLI Username admin Current CLI Privilege 15 GS 4210 24P2S show version Description Show the system hardware and software status Syntax show version Example GS 4210 24P2S show version Loader Version 2011 12 41872 Loader Date May 22 2014 19 28 43 Firmware Version v1 0b140611 F...

Page 400: ...rp Description Clear entries in the ARP cache Syntax clear arp A B C D IP address to clear clear arp the entire ARP cache is cleared Example GS 4210 24P2S clear arp 192 168 0 100 GS 4210 24P2S GS 4210 24P2S clear arp GS 4210 24P2S clear gvrp Description Clear the GVRP configuration Syntax clear GVRP error statistics GVRP Error Statistics information clear GVRP statistics GVRP Statistics informatio...

Page 401: ... arp inspection interfaces GigabitEthernet 1 26 statistics Example GS 4210 24P2S clear ip arp inspection interfaces lag 1 statistics GS 4210 24P2S clear ip arp inspection interfaces GigabitEthernet 1 statistics GS 4210 24P2S clear ip dhcp Description Clear the DHCP configuration Syntax clear ip dhcp snooping database statistics clear ip dhcp snooping interfaces LAG 1 8 statistics clear ip dhcp sno...

Page 402: ...10 24P2S clear ip igmp snooping statistics GS 4210 24P2S clear ip igmp snooping vlan 1 static mac 00 30 4F 00 00 01 GS 4210 24P2S clear ipv6 Description Clear the ipv6 information Syntax clear ipv6 mld snooping groups dynamic static clear ipv6 mld snooping statistics clear ipv6 mld snooping vlan x static mac xx xx xx xx xx xx Example GS 4210 24P2S clear ipv6 mld snooping groups dynamic GS 4210 24P...

Page 403: ...S clear line ssh GS 4210 24P2S clear line telnet GS 4210 24P2S clear lldp Description Clear lldp configuration Syntax clear line lldp statistics Example GS 4210 24P2S clear lldp statistics GS 4210 24P2S clear logging Description Clear log configuration Syntax clear logging buffered flash Example GS 4210 24P2S clear logging buffered GS 4210 24P2S clear logging flash GS 4210 24P2S ...

Page 404: ...c interfaces GigabitEthernet 1 GS 4210 24P2S clear mac address table dynamic vlan 1 GS 4210 24P2S clear rmon Description Clear RMON information Syntax clear rmon interfaces lag x statistics clear rmon interfaces GigabitEthernet x statistics Example GS 4210 24P2S clear rmon interfaces lag 1 statistics GS 4210 24P2S clear rmon interfaces GigabitEthernet 1 statistics GS 4210 24P2S 6 2 2 clock command...

Page 405: ...le to another Syntax copy backup config flash running config startup config tftp running config startup config tftp Example GS 4210 24P2S copy running config startup config Success GS 4210 24P2S 6 2 5 debug command Description Debug Options Syntax debug acl all common reserve user defined Example GS 4210 24P2S debug acl all GS 4210 24P2S debug acl common GS 4210 24P2S debug acl reserve GS 4210 24P...

Page 406: ... GS 4210 24P2S delete backup config GS 4210 24P2S delete flash GS 4210 24P2S delete startup config GS 4210 24P2S delete system image 0 GS 4210 24P2S 6 2 7 disable command Description Turn off privileged mode command Syntax disable Example GS 4210 24P2S disable GS 4210 24P2S 6 2 8 end command Description End current mode and change to enable mode Syntax end Example GS 4210 24P2S config end GS 4210 ...

Page 407: ...evious mode Syntax exit Example GS 4210 24P2S exit GS 4210 24P2S 6 2 10 no command Description Negate command Syntax no debug acl all common reserve user defined Example GS 4210 24P2S no debug acl all GS 4210 24P2S no debug acl common GS 4210 24P2S no debug acl reserve GS 4210 24P2S no debug acl user defined GS 4210 24P2S ...

Page 408: ...ms 64 bytes from 192 168 0 100 icmp_seq 2 ttl 64 time 0 0 ms 64 bytes from 192 168 0 100 icmp_seq 3 ttl 64 time 0 0 ms 192 168 0 100 ping statistics 4 packets transmitted 4 packets received 0 packet loss round trip min avg max 0 0 0 0 0 0 ms GS 4210 24P2S 6 2 12 reboot command Description Halt and perform a cold restart Syntax reboot Example GS 4210 24P2S reboot Jul 03 14 22 09 System 4 System reb...

Page 409: ... 01 08 16 00 System 4 System reboot 6 2 15 save command Description Save running configuration to flash Syntax save Example GS 4210 24P2S save Success GS 4210 24P2S 6 2 16 show command Description Show running system information Syntax show specific item Example GS 4210 24P2S show version Loader Version 2011 12 41872 Loader Date May 22 2014 19 28 43 Firmware Version v1 0b140611 Firmware Date Wed J...

Page 410: ... some fields there will be a default value If you enter the field will be left blank Country Name 2 letter code AU 2 string is too short it needs to be at least 2 bytes long Country Name 2 letter code AU TW State or Province Name full name Some State TW Locality Name eg city Taipei Organization Name eg company Internet Widgits Pty Ltd PLANET Organizational Unit Name eg section GS 4210 24P2S Common...

Page 411: ...S 4210 16T2S_24T2S_16P2S_24P2S_48T4S 411 6 2 19 udld command Description Configure global UDLD setting Syntax udld reset Example GS 4210 24P2S udld reset GS 4210 24P2S Jan 01 08 16 26 UDLD 5 No ports are disabled by UDLD ...

Page 412: ...gin 6 3 2 boot Command Description Booting Operations Syntax boot host auto config boot system image0 1 6 3 3 bridge Command Description Global bridge table configuration Syntax bridge multicast reserved address xx xx xx xx xx xx bridge discard peer 6 3 4 class map Command Description Create class map and enter class map configuration mode Use no form in order to delete the class Syntax class map ...

Page 413: ...um size of IPv6 fragments ipv6 min frag size length DoS information land deny Source IP equals to destination IP nullscan deny NULL Scan Attacks pod deny Ping of Death Attacks smurf deny Smurf Attacks smurf netmask DoS information syn sportl1024 deny SYN packets with sport less than 1024 synfin deny SYN and FIN bits set in the packet synrst deny SYNC and RST bits set in the packet tcp frag off min...

Page 414: ... do Command Description To run exec commands in current mode Syntax do SEQUENCE Exec Command 6 3 9 enable Command Description Local Enable Password Syntax enable password privilege secret 6 3 10 end Command Description End current mode and change to enable mode Syntax end 6 3 11 errdisable Command Description Error Disable Syntax errdisable recovery cause interval ...

Page 415: ...s mode Syntax Exit 6 3 13 gvrp Command Description GVRP configuration Syntax gvrp time join leave leaveall 6 3 14 hostname Command Description Set system s network name Syntax hostname WORD this system s network name 6 3 15 interface Command Description Select an interface to configure Syntax Interface GigabitEthernet LAG range ...

Page 416: ...omin Name Server http HTTP server configuration https HTTPS server configuration igmp IGMP Configuration source IP Source Guard Configuration ssh SSH Secure Shell configuration telnet Telnet daemon configuration 6 3 17 ipv6 Command Description IPV6 configuration Syntax ipv6 acl This command creates an ACL which perform classification onlayer 3 fields and enters to ipv6 access configuration mode ad...

Page 417: ...nformation Syntax l2 igmp snooping unknown multicast action drop flood 6 3 20 lacp Command Description LACP Configuration Syntax lacp system priority 1 65535 LACP system priority 6 3 21 lag Command Description Link Aggregation Group Configuration Syntax lag load balance src dst mac src dst mac ip 6 3 22 line Command Description To identify a specific line for configuration Syntax line console ssh ...

Page 418: ... Configure LLDP TX delay tx interval Configure LLDP transmission interval 6 3 24 logging Command Description Log Configuration Syntax logging buffered R AM flash F lash host Remote syslog host 6 3 25 mac Command Description MAC Configuration Syntax mac acl This command enters the extended MAC ACL configuration in order to create layer 2 extended ACL address table MAC address table configuration 6 ...

Page 419: ...ace GigabitEthernet 1 26 GigabitEthernet device number 6 3 28 no Command Description Negate command Syntax no 6 3 29 policy map Command Description This command create policy map and enter policy map configuration mode Use no form to delete the policy map Syntax policy map WORD 0 32 Enter the policy map name 6 3 30 port security Command Description Port security Configuration Syntax port security ...

Page 420: ... can be applied to multiple classes within the same policy map Use the no form of the command to remove policer basic Set system QoS advance mode map C onfigure the QoS maps queue Q ueue configuration trust Configure the global trust mode Use the no form to return untrusted state 6 3 32 radius Command Description RADIUS server information Syntax radius default config host 6 3 33 rate limit Command...

Page 421: ...tocol Syntax sntp host 6 3 37 spanning tree Command Description Spanning tree configuration Syntax Spanning tree bpdu action for bpdu packet forward delay Sets the forward delay parameter hello time Sets the hello time parameter max hops Sets the max hops parameter maximum age Changes the interval between messages the spanning tree receive s from the root switch mode Spanning tree protocol type ms...

Page 422: ...ontact location S et host location name S et host name 6 3 40 tacacs Command Description TACACS server information Syntax tacacs default config TACACS server default parameters host TACACS server host 6 3 41 udld Command Description Configure global UDLD setting Syntax udld aggressive Enable UDLD protocol in aggressive mode on fiber ports except wher e locally configured enable Enable UDLD protoco...

Page 423: ...assword U se clear text password privilege Local user privilege level secret Use encrypted password 6 3 43 vlan Command Description VLAN Configuration Syntax vlan VLAN LIST V LAN List e g 3 6 8 The range of VLAN ID is 1 to 4094 protocol vlan 802 1v protocol VLAN configuration 6 3 44 voice vlan Command Description Voice VLAN Configuration Syntax voice vlan 1 4094 Specifies the Voice VLAN Identifier...

Page 424: ...f the destination address is located at the same port with this packet comes in then this packet will be filtered Thereby increasing the network throughput and availability 7 4 Store and Forward Store and Forward is one type of packet forwarding techniques A Store and Forward Ethernet Switching stores the incoming frame in an internal buffer do the complete error checking before transmission There...

Page 425: ...er s Manual of GS 4210 16T2S_24T2S_16P2S_24P2S_48T4S 425 The Switch performs Store and forward therefore no error packets occur More reliably it reduces the re transmission rate No packet loss will occur ...

Page 426: ...lly at Power On or Reset This is done by detect the modes and speeds at the second of both device is connected and capable of both 10BASE T and 100BASE TX devices can connect with the port in either Half or Full Duplex mode If attached device is 100BASE TX port will set to 10Mbps no auto negotiation 10Mbps 10Mbps with auto negotiation 10 20Mbps 10BASE T Full Duplex 100Mbps no auto negotiation 100M...

Page 427: ... Architecture The specification of PoE typically requires two devices the Powered Source Equipment PSE and the Powered Device PD The PSE is either an End Span or a Mid Span while the PD is a PoE enabled terminal such as IP Phones Wireless LAN etc Power can be delivered over data pairs or spare pairs of standard CAT 5 cabling Powered Source Equipment PSE Power sourcing equipment PSE is a device suc...

Page 428: ...igure 8 1 Power Supplied over the Spare Pins The data pairs are used Since Ethernet pairs are transformer coupled at each end it is possible to apply DC power to the center tap of the isolation transformer without upsetting the data transfer In this mode of operation the pair on pins 3 and 6 and the pair on pins 1 and 2 can be of either polarity Figure 8 2 Power Supplied over the Data Pins ...

Page 429: ...t rate of the port Why the Switch doesn t connect to the network Solution 1 Check the LNK ACT LED on the Managed Switch 2 Try another port on the Managed Switch 3 Make sure the cable is installed properly 4 Make sure the cable is the right type 5 Turn off the power After a while turn on power again 100BASE TX port link LED is lit but the traffic is irregular Solution Check that the attached device...

Page 430: ...10 100BASE TX When connecting your 10 100Mbps Ethernet Switch to another switch a bridge or a hub a straight or crossover cable is necessary Each port of the Switch supports auto MDI MDI X detection That means you can directly connect the Switch to any Ethernet devices without making a crossover cable The following table and diagram show the standard RJ45 receptacle connector and their pin assignm...

Page 431: ...ge 3 White Green 4 Blue 5 White Blue 6 Green 7 White Brown 8 Brown 1 White Orange 2 Orange 3 White Green 4 Blue 5 White Blue 6 Green 7 White Brown 8 Brown SIDE 2 Crossover Cable SIDE 1 SIDE 2 1 2 3 4 5 6 7 8 1 2 3 4 5 6 7 8 SIDE 1 1 White Orange 2 Orange 3 White Green 4 Blue 5 White Blue 6 Green 7 White Brown 8 Brown 1 White Green 2 Green 3 White Orange 4 Blue 5 White Blue 6 Orange 7 White Brown 8...

Reviews: