background image

 

 

 

 

 

SISGM-CHAS L2/L3 

Modular Rackmount Hardened 

Switch 

 

 

 

 

 

 

User Guide 

33625 Rev. B

 

 

 

Summary of Contents for SISGM-CHAS L2

Page 1: ...SISGM CHAS L2 L3 Modular Rackmount Hardened Switch User Guide 33625 Rev B...

Page 2: ...Descriptions 12 2 4 Front Panel 14 2 1 1 Ports and Connectors 14 2 1 2 LEDs 15 2 5 Rear Panel 16 3 Hardware Installation 17 2 1 Rack mount Installation 17 3 2 Module Installation 19 3 2 1 RJ 45 Modul...

Page 3: ...37 4 4 2 MSTP 42 4 4 3 CIST 46 4 5 Fast Recovery 48 5 Management 49 5 1 Basic Settings 51 5 1 1 System Information 51 5 1 2 System Password 52 5 1 3 Authentication 53 5 1 4 IP Setting 54 5 1 5 IP Stat...

Page 4: ...104 5 5 4 SNMP User Configurations 105 5 5 5 SNMP Group Configurations 107 5 5 6 SNMP View Configurations 108 5 5 7 SNMP Access Configurations 109 5 6 Traffic Prioritization 110 5 6 1 Storm Control 1...

Page 5: ...rning Alerts 169 5 9 1 Fault Alarm 169 5 10 Monitor and Diag 173 5 10 1 MAC Table 173 5 10 2 Port Statistic 177 5 10 3 Port Monitor Mirror Configuration 180 5 10 4 System Log Information 181 5 10 5 Ca...

Page 6: ...mmands 209 Security Network NAS Commands 209 Security Network ACL Commands 209 Security Network DHCP Commands 210 Security Network AAA Commands 210 STP Commands 211 Aggregation Commands 212 LLDP Comma...

Page 7: ...Troubleshooting 225 Recording Model and System Information 226 Serial Label on SISGM Bottom 227 9 Service Warranty and Tech Support 228 Warranty 228 Return Authorization 228 Contact Us 228 Return Ins...

Page 8: ...protect your mission critical applications from network interruptions with its fast recovery technology Supporting a wide operating temperature from 40 C to 65 C with 1GB SFP modules the switch is sui...

Page 9: ...edundancy Protocol MRP Multiple Registration Protocol IEEE 1588v2 PTP Clock Synchronization IPv4 IPv6 internet protocols 8K MAC Table HTTPS SSH network security SMTP client IP based Bandwidth manageme...

Page 10: ...17 32 inches 440 mm Depth 12 8 inches 325 mm Height 1 73 inches 44 mm 19 Rack Mountable 1U For adequate air circulation for cooling open space in the rack above and below the chassis is required Power...

Page 11: ...rranty 1 5 Package Contents Contact your sales representative if you did not receive the following One L2 or L3 Switch One Power Cord country specific One Power Cable Adapter for SISGM PWR HVC only On...

Page 12: ...rt 100 1000 modules one half size bay to house either a 2 or 4 port 1000 10Gb SFP module and two power supply bays 2 2 Power Supply Modules The SISGM supports one or two power supply modules The chass...

Page 13: ...tch User Guide 33625 Rev B https www transition com Page 12 of 234 SISGM PWR HVC Power Supply 100 240VAC With Fan 2 3 Port Module Descriptions Photo Description SISGM 2P 10G SFP 2 Port 10GB SFP Module...

Page 14: ...Transition Networks SISGM CHAS L2 L3 Switch User Guide 33625 Rev B https www transition com Page 13 of 234 SISGM 8P 1G SFP 8 Port 1GB SFP Module SISGM 8P 1G TX 8 Port 1GB TX Module...

Page 15: ...ur application For applications requiring long distance data transmission the SISGM also provides several fiber transceivers to meet your needs See Model Numbers above for the list of available module...

Page 16: ...ule 1 activated PW2 Green On Power module 2 activated R M Green On Ring Master Ring Green On Ring enabled Blinking Ring structure is broken Fault Amber On Errors power failure or port malfunctioning D...

Page 17: ...33625 Rev B https www transition com Page 16 of 234 2 5 Rear Panel The rear panel of the switch has two panel module bays and one terminal block The terminal block includes two power pairs for redund...

Page 18: ...ch to a rack in any environment Follow the steps below to install the switch to a rack Step 1 Install left and right front mounting brackets to the switch using the four M3 screws on each side provide...

Page 19: ...space for front panel cabling is limited Remember When installing the brackets on the front sides use the four screw holes at the top and bottom When installing the brackets on the back sides use the...

Page 20: ...r the edge connectors on the back Carefully remove the protective edge cover before installing the module Retain the protective edge covers for future use and replace them when storing or transporting...

Page 21: ...com Page 20 of 234 3 2 1 RJ 45 Module The SISGM switch supports up to three RJ 45 modules giving you a total of 24 RJ 45 ports Follow the steps below for installation Step 1 Turn the switch power off...

Page 22: ...maximum three SFP modules giving you a total of 24 SFP ports Follow the steps below for installation Step 1 Turn the switch power off Step 2 Insert the SFP modules in Bays 1 2 and 3 respectively Step...

Page 23: ...module can be plugged into the 10 Gigabit Ethernet bay of the switch and connected to fiber optic networks Follow the steps below for installation Step 1 Turn the switch power off Step 2 Insert the 1...

Page 24: ...Insert the modules in Power 1 and or Power 2 bays respectively Step 3 Turn the switch power on Power Cable Adapter for SISGM PWR HVC only The SISGM PWR HVC ships with a power cable adapter that has a...

Page 25: ...eparate paths to route wiring for power and devices If power wiring and device wiring paths must cross make sure the wires are perpendicular at the intersection point 5 Do not run signal or communicat...

Page 26: ...f the 2 pin terminal block connector will respond to your configured events according to the wiring 3 3 3 Redundant Power Inputs The SISGM series support dual redundant power supplies Power Supply 1 P...

Page 27: ...following table for cable specifications Cable Type Max Length Connector 10BASE T Cat 3 4 5 100 ohm UTP 100 m 328 ft RJ 45 100BASE TX Cat 5 100 ohm UTP UTP 100 m 328 ft RJ 45 1000BASE T Cat 5 Cat 5e...

Page 28: ...ase T X MDI MDI X Pin Assignments Pin Number MDI port MDI X port 1 TD transmit RD receive 2 TD transmit RD receive 3 RD receive TD transmit 4 Not used Not used 5 Not used Not used 6 RD receive TD tran...

Page 29: ...of the RS 232 cable should be connected the PC while the other end of the cable RJ 45 connector should be connected to the Console port of the switch PC pin out male assignment RS 232 with DB9 female...

Page 30: ...ork redundancy capabilities via these steps 1 Connect each switch to form a daisy chain using an Ethernet cable 2 Set one of the connected switches to be the master and make sure the port setting of e...

Page 31: ...Ring 1 and switch C and D from Ring 2 Decide which port on each switch to be used as the coupling port and then link them together e g port 1 of switch A to port 2 of switch C and port 1 of switch B t...

Page 32: ...ology to a RSTP network environment you can use dual homing Choose two switches Switch A B from the ring for connecting to the switches in the RSTP network backbone switches The connection of one of t...

Page 33: ...ng these steps 1 Select two switches from the chain Switch A B that you want to connect to the Redundant Rings and connect them to the switches in the ring Switch C D 2 In correspondence to the ports...

Page 34: ...Redundant Ring Technology 4 1 1 Introduction The switch provides redundant ring technology with recovery time of less than 30 milliseconds in full duplex Gigabit operation or 10 milliseconds in full d...

Page 35: ...to enable Coupling Ring Coupling Ring can divide a big ring into two smaller rings to avoid network topology changes affecting all switches It is a good method for connecting two rings Coupling Port P...

Page 36: ...etwork redundancy topologies The self healing Ethernet technology designed for distributed and complex industrial networks enables the network to recover in less than 30 milliseconds in full duplex Gi...

Page 37: ...tiple Ring enabled Label Description Enable Check to enable the Multiple Ring function 1st Ring Port The first port connecting to the ring 2nd Ring Port The second port connecting to the ring Edge Por...

Page 38: ...Compared to STP which recovers a link in 30 to 50 seconds RSTP can shorten the time to 5 to 6 seconds STP Bridge Status This page shows the status for all STP bridge instances The STP Bridges paramet...

Page 39: ...t number to which the following settings will be applied CIST Role The current STP port role of the CIST port The values include AlternatePort BackupPort RootPort and DesignatedPort CIST State The cur...

Page 40: ...transmitted on the port RSTP The number of RSTP configuration BPDUs received transmitted on the port STP The number of legacy STP configuration BPDUs received transmitted on the port TCN The number o...

Page 41: ...switch forms a Bridge Identifier For MSTP operation this is the priority of the CIST Otherwise this is the priority of the STP RSTP bridge Forward Delay The delay used by STP bridges to transit root...

Page 42: ...plicitly configured as Edge will disable itself upon reception of a BPDU The port will enter the error disabled state and will be removed from the active topology Port Error Recovery Controls whether...

Page 43: ...e or more MSTP switches with the same VLANs at least one MST instance and the same MST region name Therefore switches can use different paths in the network to effectively balance loads Port Settings...

Page 44: ...to will set the path cost according to the physical link speed by using the 802 1D recommended values Specific allows you to enter a user defined value The path cost is used when establishing an activ...

Page 45: ...configurations in order to share spanning trees for MSTIs intra region The name must not exceed 32 characters Configuration Revision Revision of the MSTI configuration named above This must be an int...

Page 46: ...iority Configuration parameters are described below Label Description MSTI The bridge instance CIST is the default instance which is always active Priority Indicates bridge priority The lower the valu...

Page 47: ...hange them as well This page contains settings for physical and aggregated ports The aggregation settings are stack global The STP CIST Port Configuration parameters are described below Label Descript...

Page 48: ...d topology change notifications and topology changes to other ports If set it will cause temporary disconnection after changes in an active spanning trees topology as a result of persistent incorrectl...

Page 49: ...he active port and the other ports with different priorities will be backup ports The Fast Recovery function is for port redundancy The port that has the highest recovery priority the lowest number wi...

Page 50: ...duces network bandwidth consumption but also enhances access speed and provides a user friendly viewing screen Preparing for Web Management You can access the management page of the switch via the fol...

Page 51: ...0 of 234 After logging in the Information Message page displays as shown below The left side of the management interface shows links to various settings You can click on the links to access the config...

Page 52: ...9 and minus sign Space is not allowed to be part of the name The first character must be an alpha character and the first or last character must not be a minus sign The allowed string length is 0 to...

Page 53: ...log in from CLI Label Description Old User Name The existing User Name If this is incorrect you can set the new password Old Password The existing password If this is incorrect you cannot set the new...

Page 54: ...ible local Use the local user database on the switch stack for authentication radius Use remote RADIUS server s for authentication tacacs Use remote TACACS server s for authentication Methods that inv...

Page 55: ...be able to access the IP interface This field is only available for input when creating an new interface IPv4 DHCP Enable Enable the DHCP client by checking this box If this option is enabled the syst...

Page 56: ...an also represent a legally valid IPv4 address For example 192 1 2 34 The field may be left blank if IPv6 operation on the interface is not desired IPv6 Mask Length The IPv6 network mask in number of...

Page 57: ...ute AKA gateway of last resort is the network route used by a router when no other known route exists for an IP packet s destination address Network 0 0 0 0 Mask Length 0 Gateway 10 0 1 1 as shown abo...

Page 58: ...type of the entry This may be LINK or IPv4 Address The current address of the interface of the given type Status The status flags of the interface and or address IP Routes Network The destination IP n...

Page 59: ...e acronym to identify the time zone Range up to 16 characters Daylight Saving Time Configuration This is used to set the clock forward or backward according to the configurations set below for a defin...

Page 60: ...set Enter the number of minutes to add during Daylight Saving Time Range 1 1440 minutes Save Click to save changes Reset Click to undo any changes made locally and revert to previously saved values 5...

Page 61: ...cting as a group The default gateway of a participating host is assigned to the virtual router instead of a physical router If the physical router that is routing packets on behalf of the virtual rout...

Page 62: ...e following page Label Description Mode Indicates the selected HTTPS mode When the current connection is HTTPS disabling HTTPS will automatically redirect web browser to an HTTP connection The modes a...

Page 63: ...Page 62 of 234 5 1 10 SSH You can configure SSH settings on the following page Label Description Mode Indicates the selected SSH mode either Enabled enable SSH Disabled disable SSH Save Click to save...

Page 64: ...Interval value Valid values are 5 32768 seconds Port The switch port number to which the following settings will be applied Mode Indicates the selected LLDP mode Rx only the switch will not send out L...

Page 65: ...on of the neighbor port System Name The name advertised by the neighbor Port Description The description of the port advertised by the neighbor System Capabilities Description of the neighbor s capabi...

Page 66: ...en the last entry was deleted or added Total Neighbors Entries Added Shows the number of new entries added since switch reboot Total Neighbors Entries Deleted Shows the number of new entries deleted s...

Page 67: ...ntry ages out TLVs Discarded Each LLDP frame can contain multiple pieces of information known as TLVs Type Length Value If a TLV is malformed it will be counted and discarded TLVs Unrecognized The num...

Page 68: ...witch User Guide 33625 Rev B https www transition com Page 67 of 234 5 1 12 Backup Save Configurations You can save or view switch configurations The configuration file is in XML format An example of...

Page 69: ...SISGM CHAS L2 L3 Switch User Guide 33625 Rev B https www transition com Page 68 of 234 5 1 13 Restore Configuration You can load the switch configuration The configuration file is in XML format with...

Page 70: ...ted After about a minute the firmware is updated and the switch restarts Note The Layer 2 switch is NOT upgradeable to Layer 3 Warning While the firmware is being updated Web access appears to be defu...

Page 71: ...up DHCP settings for the switch You can check the Enabled checkbox to activate the function Once the box is checked you can enter information in each field Label Description Enabled Enable Disable DH...

Page 72: ...ng table A DHCP server can automatically assign an IP address to a DHCP client Label Description No Client list number Select Check to select device Type The type of client Dynamic or Static MAC Addre...

Page 73: ...ously been assigned to the connected device Label Description MAC Address Enter the MAC Address of client IP Address Enter the IP address of client No The instance number for this line Select Select d...

Page 74: ...m flooding for security considerations Disabled disable DHCP relay Relay Server Indicates the DHCP relay server IP address A DHCP relay agent is used to forward and transfer DHCP messages between the...

Page 75: ...hat already contains relay agent information it will enforce the policy The Replace option is invalid when relay information mode is disabled The policies includes Replace replace the original relay i...

Page 76: ...wn Remote ID DHCP Client Statistics Label Description Transmit to Client The number of packets relayed from the server to the client Transmit Error The number of packets with errors when being sent to...

Page 77: ...Indicates the current link speed of the port Configured Link Speed Select an available link speed for the switch port Only speeds supported by the specific port are shown Selections are Disabled Disab...

Page 78: ...sition com Page 77 of 234 Excessive Collision Mode Select Discard or Reset on too many collisions Save Click to save changes Reset Click to undo any changes made locally and revert to previously saved...

Page 79: ...sable By default Source MAC Address is enabled Destination MAC Address Calculates the destination port of the frame You can check this box to enable the destination MAC address or uncheck to disable B...

Page 80: ...group Normal means no aggregation Only one group ID is valid per port Port Members Lists each switch port for each group ID Select a radio button to include a port in an aggregation or clear the radi...

Page 81: ...er port LACP Enabled Lists each switch port for each group ID Check to include a port in an aggregation or clear the box to remove the port from the aggregation By default no ports belong to any aggre...

Page 82: ...ed values LACP System Status This page provides a status overview for all LACP instances Label Description Aggr ID The aggregation ID is associated with the aggregation instance For LLAG the ID is sho...

Page 83: ...he port cannot join in the aggregation group unless other ports are removed The LACP status is disabled Key The key assigned to the port Only ports with the same key can be aggregated Aggr ID The aggr...

Page 84: ...on Port Switch port number LACP Received The number of LACP frames received at each port LACP Transmitted The number of LACP frames sent from each port Discarded The number of unknown or illegal LACP...

Page 85: ...each loop protection PDU sent on each port The valid value is 1 to 10 seconds Shutdown Time The period in seconds for which a port will be kept disabled when a loop is detected shutting down the port...

Page 86: ...oop protection port parameters are described below Label Description Port The switch port number of the logical port Action The currently configured port action Transmit The currently configured port...

Page 87: ...e The VLAN input fields let you select the starting point in the VLAN Table Clicking the Refresh button will update the displayed table starting from that or the closest next VLAN Table match The butt...

Page 88: ...he port from the VLAN make sure the unchecked checkbox is shown By default no ports are members and for every new VLAN entry all boxes are unchecked Add New VLAN Click to add a new VLAN ID An empty ro...

Page 89: ...below Ingress Filtering Enable ingress filtering on a port by checking the box This parameter affects VLAN ingress processing If ingress filtering is enabled and the ingress port is not a member of th...

Page 90: ...ANs except the configured PVID will be tagged Tag_all all VLANs are tagged Untag_all all VLANs are untagged Introduction to Port Types Each port type Unaware C port S port and S custom port is describ...

Page 91: ...arded 2 If the TPID of tagged frame is not 0x88A8 ex 0x8100 it will be discarded The TPID of a frame transmitted by S port will be set to 0x88A8 S custom port When the port receives untagged frames an...

Page 92: ...Transition Networks SISGM CHAS L2 L3 Switch User Guide 33625 Rev B https www transition com Page 91 of 234 SISGM Series Switch SISGM Series Switch Unaware top C Port bottom...

Page 93: ...User Guide 33625 Rev B https www transition com Page 92 of 234 S Custom port is used for user defined TPID while Ethertype for Custom S Ports is configured to 8123 outgoing packets will bring with TP...

Page 94: ...https www transition com Page 93 of 234 Examples of VLAN Settings VLAN Access Mode SISGM Series Switch A SISGM Series Switch B SISGM Series Switch C Switch A Port 7 is VLAN Access mode Untagged 20 Po...

Page 95: ...e 33625 Rev B https www transition com Page 94 of 234 VLAN 1Q Trunk Mode SISGM Series Switch A SISGM Series Switch B SISGM Series Switch C Switch B Port 1 VLAN 1Qtrunk mode tagged 10 20 Port 2 VLAN 1Q...

Page 96: ...ransition Networks SISGM CHAS L2 L3 Switch User Guide 33625 Rev B https www transition com Page 95 of 234 VLAN Hybrid Mode Port 1 VLAN Hybrid mode untagged 10 Tagged 10 20 Below are the switch setting...

Page 97: ...3625 Rev B https www transition com Page 96 of 234 VLAN QinQ Mode VLAN QinQ mode is usually used when there are unknown VLANs as shown in the figure below where VLAN X Unknown VLAN not configured loca...

Page 98: ...re Private VLANs can be added or deleted here Port members of each private VLAN can be added or removed here Private VLANs are based on the source port mask and there are no connections to VLANs This...

Page 99: ...ove or exclude the port from the private VLAN make sure the box is unchecked By default no ports are members and all boxes are unchecked Adding a New Static Entry Click Add New Private LAN to add a ne...

Page 100: ...e VLAN Label Description Port Members A check box is provided for each port of a private VLAN When checked port isolation is enabled for that port When unchecked port isolation is disabled for that po...

Page 101: ...haracters and only ASCII characters 33 126 are allowed The field only suits to SNMPv1 and SNMPv2c SNMPv3 uses USM for authentication and privacy and the community string will be associated with SNMPv3...

Page 102: ...ity access string when sending SNMP trap packets The allowed string length is 0 255 characters and only ASCII characters 33 126 are allowed Trap Destination Address Indicates the SNMP trap destination...

Page 103: ...ecurity engine ID SNMPv3 sends traps and informs using USM for authentication and privacy A unique engine ID for these traps and informs is needed When Trap Probe Security Engine ID is enabled the ID...

Page 104: ...group s traps Possible traps are Indicates that the SNMP entity is permitted to generate authentication failure traps Possible modes are Warm Start Enable SNMP trap authentication failure Link Up Ena...

Page 105: ...table The entry index key is Community Label Description Delete Check to delete the entry It will be deleted during the next save Community Indicates the community access string to permit access to SN...

Page 106: ...ineID and usmUserName are the entry keys In a simple agent usmUserEngineID is always that agent s own snmpEngineID value The value can also take the value of the snmpEngineID of a remote SNMP engine w...

Page 107: ...ists which means the value must be set correctly at the time of entry creation Authentication Password A string identifying the authentication pass phrase For MD5 authentication protocol the allowed s...

Page 108: ...e Security Model Indicates the security model that this entry should belong to Possible security models included v1 Reserved for SNMPv1 v2c Reserved for SNMPv2c usm User based Security Model USM Secur...

Page 109: ...haracters and only ASCII characters 33 126 are allowed View Type Indicates the view type that this entry should belong to Possible view types include Included an optional flag to indicate that this vi...

Page 110: ...ble security models include any Accepted any security model v1 v2c usm v1 Reserved for SNMPv1 v2c Reserved for SNMPv2c usm User based Security Model USM Security Level Indicates the security model tha...

Page 111: ...oadcast traffic across the switch Note frames sent to the CPU of the switch are always limited to approximately 4 kpps For example broadcasts in the Management VLAN are limited to this rate The manage...

Page 112: ...ty A QoS class of 0 zero has the lowest priority If the port is VLAN aware and the frame is tagged then the frame is classified to a QoS class that is based on the PCP value in the tag as shown below...

Page 113: ...re classified to a PCP value If the port is VLAN aware and the frame is tagged then the frame is classified to the PCP value in the tag Otherwise the frame is classified to the default PCP value DEI C...

Page 114: ...l switch ports The QoS Egress Port Tag Remarking parameters are described below Label Description Port The switch port number to which the following settings will be applied Click on the port number t...

Page 115: ...Translate Check to enable ingress translation Ingress Classify Classification can have one of these four values Disable no Ingress DSCP classification DSCP 0 classify if incoming or translated if ena...

Page 116: ...olicing This page allows you to configure Policer settings for all switch ports Label Description Port The port number for which the configuration below applies Enabled Check to enable the policer for...

Page 117: ...ion below applies E Enabled Check to enable queue policer for individual switch ports Rate Configures the rate of each queue policer The default value is 500 This value is restricted to 100 to 1000000...

Page 118: ...Scheduler and Shapers for a specific port From the default QoS Egress Port Schedulers page see above click a linked number in the Port column to display the default QoS Egress Port Scheduler and Shape...

Page 119: ...is kbps and it is restricted to 1 to 3300 when the Unit is Mbps Queues Shaper Unit Configures the rate for each queue shaper The default value is 500 This value is restricted to 100 to 1000000 when t...

Page 120: ...t Queue Shaper Enable Check to enable queue shaper for individual switch ports Queue Shaper Rate Configures the rate of each queue shaper The default value is 500 This value is restricted to 100 to 10...

Page 121: ...tricted to 1 to 3300 when the Unit is Mbps Port Shaper Unit Configures the unit of measurement for each port shaper rate as kbps or Mbps The default value is kbps 5 6 8 Port Scheduler This page provid...

Page 122: ...Classification settings for all switches Label Description DSCP Maximum number of supported DSCP values is 64 Trust Check to trust a specific DSCP value Only frames with trusted DSCP values are mapped...

Page 123: ...ted to new DSCP before using the DSCP for QoS class and DPL map There are two configuration parameters for DSCP Translation 1 Translate DSCP can be translated to any of 0 63 DSCP values 2 Classify che...

Page 124: ...transition com Page 123 of 234 5 6 12 DSCP Classification This page allows you to configure the mapping of QoS class and Drop Precedence Level to DSCP value Label Description QoS Class Actual QoS clas...

Page 125: ...E Configuration page displays Label Description Port Members Check to include the port in the QCL entry By default all ports are included Key Parameters Key configurations include Tag value of tag can...

Page 126: ...ny Source IP specific Source IP address in value mask format or Any IP and mask are in the format of x y z w where x y z and w are decimal numbers between 0 and 255 When the mask is converted to a 32...

Page 127: ...port 0 65535 or Any specific value or port range applicable for IP protocol UDP TCP Action Parameters Class QoS class 0 7 or Default Valid Drop Precedence Level value can be 0 1 or Default Valid DSCP...

Page 128: ...tics Queuing Counters This page provides the statistics of individual queues for all switch ports Label Description Port The switch port number to which the following settings will be applied Qn There...

Page 129: ...s IPv6 the QCE will match only IPV6 frames Port Indicates the list of ports configured with the QCE Action Indicates the classification action taken on ingress frame if parameters configured are match...

Page 130: ...nable global IGMP snooping Unregistered IPMCv4Flooding Enabled Check to enable unregistered IPMC traffic flooding Port The port number being configured on this line Router Port Specifies which ports a...

Page 131: ...layed entry as a basis for the next lookup When the end is reached the text No more entries is shown in the displayed table Use the button to start over Label Description Delete Check to delete the en...

Page 132: ...of received V1 reports V2 Reports Received The number of received V2 reports V3 Reports Received The number of received V3 reports V2 Leave Received The number of received V2 leave packets Router Por...

Page 133: ...and group input fields allow the user to select the starting point in the IGMP Group Table Clicking the Refresh button will update the displayed table starting from that or the closest next IGMP Grou...

Page 134: ...a policy to the port The allowed values are 1 8 The default value is 1 Action Select to Permit to permit or Deny to deny forwarding The default value is Permit Rate Limiter ID Select a rate limiter fo...

Page 135: ...the port will be disabled Disabled port shut down is disabled The default value is Disabled State Specify the port state of this port The allowed values are Enabled To reopen ports by changing the vol...

Page 136: ...ansition com Page 135 of 234 Rate Limit This page lets you configure the rate limiter for the ACL of the switch Label Description Rate Limiter ID The rate limiter ID for the settings contained in the...

Page 137: ...ing to the frame type you selected A frame matching the ACE can be configured here The default Access Control List Configuration page is shown below From the default page click the Add icon in the low...

Page 138: ...Specifies the rate limiter in number of base units The allowed range is 1 to 15 Disabled means the rate limiter operation is disabled Port Redirect Frames that hit the ACE are redirected to the port...

Page 139: ...d for the SMAC filter you can enter a specific source MAC address The legal format is xx xx xx xx xx xx Frames matching the ACE will use this SMAC value DMAC Filter Specifies the destination MAC filte...

Page 140: ...filter a specific VLAN ID with the ACE choose this value A field for entering a VLAN ID number appears VLAN ID When Specific is selected for the VLAN ID filter you can enter a specific VLAN ID number...

Page 141: ...se refer to the help file TCP selects TCP to filter IPv4 TCP protocol frames Extra fields for defining TCP parameters will appear For more details of these fields please refer to the help file IP Prot...

Page 142: ...ress and source IP mask in the SIP Address and SIP Mask fields that appear SIP Address When Host or Network is selected for the source IP filter you can enter a specific SIP address in dotted decimal...

Page 143: ...is set to Host Specify the sender IP address in the SIP Address field that appears Network sender IP filter is set to Network Specify the sender IP address and sender IP mask in the SIP Address and SI...

Page 144: ...rnet Length Specifies whether frames will meet the action according to their ARP RARP hardware address length HLN and protocol address length PLN settings 0 ARP RARP frames where the HLN is equal to E...

Page 145: ...is selected for the ICMP filter you can enter a specific ICMP value The allowed range is 0 to 255 A frame matching the ACE will use this ICMP value ICMP Code Filter Specifies the ICMP code filter for...

Page 146: ...ng a TCP UDP source value appears Range if you want to filter a specific TCP UDP source range filter with the ACE you can enter a specific TCP UDP source range A field for entering a TCP UDP source va...

Page 147: ...he ACE will use this TCP UDP destination value TCP UDP Destination Range When Range is selected for the TCP UDP destination filter you can enter a specific TCP UDP destination range value The allowed...

Page 148: ...is set must not be able to match this entry 1 TCP frames where the ACK field is set must be able to match this entry Any any value is allowed don t care TCP URG Specifies the TCP URG urgent pointer f...

Page 149: ...t The ACE will match a specific ingress port Frame Type Indicates the frame type of the ACE Possible values are Any The ACE will match any frame type EType The ACE will match Ethernet Type frames Note...

Page 150: ...n Disabled is displayed the rate limiter operation is disabled CPU Forward packet that matched the specific ACE to CPU CPU Once Forward first packet that matched the specific ACE to CPU Counter The co...

Page 151: ...ill stop the switch from continually trying to contact a server that it has already determined as dead Deadtime can be set to a number between 0 to 1440 minutes Setting the Deadtime to a value greater...

Page 152: ...ort to use on the RADIUS server for accounting Timeout This optional setting overrides the global timeout value Leaving it blank will use the global timeout value Retransmit This optional setting over...

Page 153: ...s The current status of the server This field takes one of the following values Disabled The server is disabled Not Ready The server is enabled but IP communication is not yet up and running Ready The...

Page 154: ...r Status The current status of the server This field takes one of the following values Disabled The server is disabled Not Ready The server is enabled but IP communication is not yet up and running Re...

Page 155: ...he statistics map closely to those specified in RFC4668 RADIUS Authentication Client MIB Use the server drop down list to switch between the backend servers to show related details RADIUS Authenticati...

Page 156: ...ion Networks SISGM CHAS L2 L3 Switch User Guide 33625 Rev B https www transition com Page 155 of 234 Other Info This section contains information about the state of the server and the latest round tri...

Page 157: ...m Page 156 of 234 RADIUS Accounting Statistics for Server x Label Description Packet Counters RADIUS accounting server packet counters There are five receive and four transmit counters Other Info This...

Page 158: ...m a TACACS server before it is considered to be dead Deadtime Deadtime which can be set to a number between 0 to 1440 minutes is the period during which the switch will not send new requests to a serv...

Page 159: ...the TACACS server Port The TCP port to use on the TACACS server for authentication Timeout This optional setting overrides the global timeout value Leaving it blank will use the global timeout value K...

Page 160: ...authentication server Frames sent between the supplicant and the switch are special 802 1X frames known as EAPOL EAP Over LANs frames which encapsulate EAP PDUs RFC3748 Frames sent between the switch...

Page 161: ...ADIUS server The 6 byte MAC address is converted to a string in the following form xx xx xx xx xx xx that is a dash is used as separator between the lower cased hexadecimal digits The switch only supp...

Page 162: ...ication for 802 1X enabled ports can be used to detect if a new device is plugged into a switch port For MAC based ports reauthentication is only useful if the RADIUS server configuration has changed...

Page 163: ...e client is put on hold in Unauthorized state The hold timer does not count during an on going authentication The switch will ignore new frames coming from the client during the hold time The hold tim...

Page 164: ...frame from the supplicant Since the server has not failed because the X seconds have not expired the same server will be contacted when the next backend authentication server request from the switch...

Page 165: ...ined from the first EAPOL Start or EAPOL Response Identity frame sent by the supplicant An exception to this is when no supplicants are attached In this case the switch sends EAPOL Request Identity fr...

Page 166: ...the following values Globally Disabled NAS is globally disabled Link Down NAS is globally enabled but there is no link on the port Authorized the port is in Force Authorized or a single supplicant mo...

Page 167: ...tails regarding each value Port State The current state of the port Refer to NAS Port State for more details regarding each value Last Source The source MAC address carried in the most recently receiv...

Page 168: ...uthentication Server statistics is showed Use the port drop down list to select which port details to be displayed Label Description Admin State The port s current administrative state Refer to NAS Ad...

Page 169: ...er Counters These backend RADIUS frame counters are available for the following administrative states 802 1X MAC based Auth Last Supplicant Clien t Info Information about the last supplicant client th...

Page 170: ...witch panel lights and the electric relay will signal at the same time When any selected fault event occurs the Fault LED in switch panel will be illuminated and the electric relay will be energized a...

Page 171: ...ed the syslog message will be sent to syslog server The syslog protocol is based on UDP communications and received on UDP port 514 and the syslog server will not send acknowledgments back to the send...

Page 172: ...821 Simple Mail Transfer Protocol Label Description E mail Alert Enable or Disable transmission of system warnings by e mail Sender E mail Address The SMTP server IP address Mail Subject Subject of th...

Page 173: ...ecked when SYSLOG or SMTP is disabled Label Description System Start Sends out alerts when the system is restarted Power Status Sends out alerts when power is up or down SNMP Authentication Failure Se...

Page 174: ...You can set timeouts for entries in the dynamic MAC table and configure the static MAC table here MAC Address Table Configuration Aging Configuration By default dynamic entries are removed from the M...

Page 175: ...the port to dynamically learn the MAC address based on these settings Label Description Auto Learning is done automatically as soon as a frame with an unknown SMAC is received Disable No learning is...

Page 176: ...orted first by VLAN ID and then by MAC address Label Description Delete Check to delete an entry It will be deleted during the next save VLAN ID The VLAN ID for the entry MAC Address The MAC address f...

Page 177: ...oint in the MAC table Clicking the Refresh button will update the displayed table starting from that or the closest next MAC table match In addition the two input fields will upon clicking Refresh ass...

Page 178: ...of received and transmitted packets per port Bytes The number of received and transmitted bytes per port Errors The number of frames received in error and the number of incomplete transmissions per p...

Page 179: ...Rx and Tx Unicast The number of received and transmitted good and bad unicast packets Rx and Tx Multicast The number of received and transmitted good and bad multicast packets Rx and Tx Broadcast The...

Page 180: ...ceived frames filtered by the forwarding process Tx Drops The number of frames dropped due to output buffer congestion Tx Late Exc Coll The number of frames dropped due to excessive or late collisions...

Page 181: ...s from ports that have either source rx or destination tx mirroring enabled are mirrored to this port Disabled option disables mirroring Label Description Port The switch port number to which the foll...

Page 182: ...or provides error message All enables all levels Time The time of the system log entry Message The MAC address of the switch Auto refresh Check this box to enable an automatic refresh of the page at r...

Page 183: ...matically and you can view the cable diagnostics results in the cable status table Note that VeriPHY diagnostics is only accurate for cables 7 140 meters long The 10 and 100 Mbps ports will be disconn...

Page 184: ...t number that this line monitors reports Temperature C The SFP temperature in degrees Celsius Vcc V The SFP voltage measured in Volts TX Bias mA The SFP transmit Bias measured in mA milliAmps TX Power...

Page 185: ...10 10 132 20 56 bytes of data 64 bytes from 10 10 132 20 icmp_seq 0 time 0ms 64 bytes from 10 10 132 20 icmp_seq 1 time 0ms 64 bytes from 10 10 132 20 icmp_seq 2 time 0ms 64 bytes from 10 10 132 20 ic...

Page 186: ...ms 64 bytes from fe80 215 58ff feed 69dd icmp_seq 2 time 0ms 64 bytes from fe80 219 5bff fe2f b47 icmp_seq 3 time 0ms 64 bytes from fe80 215 58ff feed 69dd icmp_seq 3 time 0ms 64 bytes from fe80 219 5...

Page 187: ...etworks SISGM CHAS L2 L3 Switch User Guide 33625 Rev B https www transition com Page 186 of 234 Do not specify egress interface for loopback address Do specify egress interface for link local or multi...

Page 188: ...you to select One_pps_mode configurations The values are Output enable the 1 pps clock output Input enable the 1 pps clock input Disable disable the 1 pps clock in out put External Enable The box allo...

Page 189: ...Instance 2 Step Flag Static member defined by the system true if two step Sync events and Pdelay_Resp events are used Clock Identity Shows a unique clock identifier One Way If true one way measuremen...

Page 190: ...view the current PTP clock settings PTP External Clock Parameters Label Description One_pps_mode The box displays One_pps_mode configurations The values are Output enable the 1 pps clock output Input...

Page 191: ...pe is Peer to Peer Transparent Clock E2e Transp Clock s Device Type is End to End Transparent Clock Master Only Clock s Device Type is Master Only Slave Only Clock s Device Type is Slave Only Port Lis...

Page 192: ...pe is Master Only 5 Slave Only Clock s Device Type is Slave Only 2 Step Flag Static member defined by the system true if two step Sync events and Pdelay_Resp events are used Ports The total number of...

Page 193: ...ock is not a slave the value is the clock s own ID Port Port Id for the parent master port PStat Parents Stats always false Var It is observed parent offset scaled log variance Change Rate Observed Pa...

Page 194: ...I constant 1 10000 see above D constant 1 10000 see above Filter Parameters The default delay filter is a low pass filter with a time constant of 2 DelayFilter DelayRequestRate The default offset fil...

Page 195: ...sent with timestamps and the received packets have the timestamps read so the timing and thus frequency can be derived Network timing is hierarchical in nature such that there is one master that trans...

Page 196: ...to output b Generate 1 PPS one pulse per second to measure the 1588 time c First a PTP Clock instance must be created Select PTP in the Configuration menu and click the Add New PTP Clock button Step...

Page 197: ...he linked 0 in the Clock Instance column to display the Clock instance Configuration page Step 4 a Configure Clock parameters Note Only parameters different from default are listed below Clock Default...

Page 198: ...tch User Guide 33625 Rev B https www transition com Page 197 of 234 b Click the Save button then click the linked Port Configuration to enter port specific parameters Step 5 Check the ports Stat lstn...

Page 199: ...Transition Networks SISGM CHAS L2 L3 Switch User Guide 33625 Rev B https www transition com Page 198 of 234 II Resulting Configuration...

Page 200: ...performed by making a physical loopback between port 1 and port 2 within the first minute from switch reboot In the first minute after boot loopback packets will be transmitted at port 1 If a loopbac...

Page 201: ...tps www transition com Page 200 of 234 5 12 2 System Reboot Restart Device You can restart the switch on this page After restart the switch will boot normally Label Description Yes Click to restart th...

Page 202: ...itch by CLI CLI Management by RS 232 Serial Console 115200 8 none 1 none Before configuring RS 232 serial console connect the RS 232 port of the switch to your PC Com port using a RJ45 to DB9 F cable...

Page 203: ...er Guide 33625 Rev B https www transition com Page 202 of 234 Step 3 Select a COM port in the drop down list Step 4 A pop up window displays that indicates COM port properties including bits per secon...

Page 204: ...S L2 L3 Switch User Guide 33625 Rev B https www transition com Page 203 of 234 Step 5 The console login screen will appear Use the keyboard to enter the Username and Password same as the password for...

Page 205: ...168 1 77 Subnet Mask 255 255 255 0 Default Gateway 192 168 1 254 User Name root Password root Follow the steps below to access console via Telnet Step 1 Telnet to the IP address of the switch from th...

Page 206: ...ition com Page 205 of 234 Command Groups System Commands System Configuration all port_list Reboot Restore Default keep_ip Contact contact Name name Location location Description description Password...

Page 207: ...10hdx 10fdx 100hdx 100fdx 1000fdx sfp_auto_ams Flow Control port_list enable disable State port_list enable disable MaxFrame port_list max_frame Power port_list enable disable actiphy dynamic Excessi...

Page 208: ...ype Add vid name ports_list Forbidden Add vid name port_list Delete vid name Forbidden Delete vid name Forbidden Lookup vid name name Lookup vid name name combined static nas all Name Add name vid Nam...

Page 209: ...ble disable Security Switch SSH Commands Security switch ssh Configuration Mode enable disable Security Switch HTTPS Commands Security switch ssh Configuration Mode enable disable Security Switch RMON...

Page 210: ...t Mode enable disable State port_list auto authorized unauthorized macbased Reauthentication enable disable ReauthPeriod reauth_period EapolTimeout eapol_timeout Agetime age_time Holdtime hold_time Au...

Page 211: ...Status combined static loop_protect dhcp ptp ipmc conflicts Port State port_list enable disable Security Network DHCP Commands Security Network DHCP Configuration Mode enable disable Server ip_addr I...

Page 212: ...sti port_list Msti Priority msti priority Msti Map msti clear Msti Add msti vid Port Configuration port_list Port Mode port_list enable disable Port Edge port_list enable disable Port AutoEdge port_li...

Page 213: ...st aggr_id Delete aggr_id Lookup aggr_id Mode smac dmac ip port enable disable LACP Commands LACP Configuration port_list Mode port_list enable disable Key port_list key Role port_list active passive...

Page 214: ...Map class_list dpl_list dscp DSCP EgressRemap dscp_list dpl_list dscp Storm Unicast enable disable packet_rate Storm Multicast enable disable packet_rate Storm Broadcast enable disable packet_rate QCL...

Page 215: ...t_list macbased auto authorized unauthorized Authenticate port_list now Reauthentication enable disable Period reauth_period Timeout eapol_timeout Statistics port_list clear eapol radius Clients port_...

Page 216: ...ort policy policy vid tag_prio dmac_type etype etype smac dmac arp sip dip smac arp_opcode arp_flags ip sip dip protocol ip_flags icmp sip dip icmp_type icmp_code ip_flags udp sip dip sport dport ip_f...

Page 217: ...ommunity Add community ip_addr ip_mask Community Delete index Community Lookup index User Add engineid user_name MD5 SHA auth_password DES priv_password User Delete index User Changekey engineid user_...

Page 218: ...fset valid leap59 leap61 timetrac freqtrac ptptimescale timesource PTP PortDataSet clockinst port_list announceintv announceto syncintv delaymech minpdelayreqintv delayasymmetry ingressLatency LocalCl...

Page 219: ...uration port_list Port Mode port_list enable disable Port Action port_list shutdown shut_log log Port Transmit port_list enable disable Status port_list IPMC Commands IPMC Configuration igmp Mode igmp...

Page 220: ...PowerStatus enable disable SMTP SnmpAuthenticationFailure enable disable SMTP RingTopologyChange enable disable SMTP Port port_list disable linkup linkdown both DHCPServer Commands DHCPServer Mode ena...

Page 221: ...Mode enable disable Port port_list fr_priority SFP Commands SFP syslog enable disable temp temperature Info MRP Commands MRP Configuration Mode enable disable Manager enable disable React enable disa...

Page 222: ...Protocol IEEE 802 1s for MSTP Multiple Spanning Tree Protocol IEEE 802 1x for Authentication IEEE 802 1AB for LLDP Link Layer Discovery Protocol MAC Table 8k Priority Queues 8 Processing Store and Fo...

Page 223: ...management DOS DDOS auto prevention Port configuration status statistics monitoring security DHCP Server Client DHCP Relay Modbus TCP DNS client proxy SMTP Client Network Redundancy Redundant Rings O...

Page 224: ...s Enclosure 19 inches rack mountable Weight g 6450g SISGM LV 6600g SISGM HV SISGM 4P 10G SFP 1882120 6278 hours SISGM 8P 1G SFP MTBF 3712062 3901 hours MTBF SISGM CHAS L2 L3 Chassis with SISGM PWR HVC...

Page 225: ...Transition Networks SISGM CHAS L2 L3 Switch User Guide 33625 Rev B https www transition com Page 224 of 234 Dimensions Warranty Chassis and Port Modules 5 Year Limited Warranty...

Page 226: ...Is the Green port Link Act LED or the Amber Link LED lit NO Verify that the copper and fiber cable requirements are met See the Connection section on page 26 YES Verify that the feature you are config...

Page 227: ..._________ Your Transition Networks service contract number _______________________________ A description of the failure __________________________________________________ _____________________________...

Page 228: ...Transition Networks SISGM CHAS L2 L3 Switch User Guide 33625 Rev B https www transition com Page 227 of 234 Serial Label on SISGM Bottom...

Page 229: ...e original factory shipment date Any warranty hereunder is extended to the original consumer or purchaser and is not assignable Transition Networks makes no express or implied warranties including but...

Page 230: ...will pay for the shipping of the repaired or replaced in warranty product s back to the customer any and all customs charges tariffs or and taxes are the customer s responsibility Before making any no...

Page 231: ...etrieb dieses Ger tes Rundfunkst rungen auftreten In diesem F ll ist der Benutzer f r Gegenma nahmen verantwortlich Attention Ceci est un produit de Classe A Dans un environment domestique ce produit...

Page 232: ...seitigen Anerkennung ihrer Konformit t Safety Warnings and Cautions These products are not intended for use in life support products where failure of a product could reasonably be expected to result i...

Page 233: ...eidsvoorschriften worden ge nstalleerd S curit lectrique IMPORTANT Cet quipement doit tre utilis conform ment aux instructions de s curit S hk turvallisuus T RKE T m laite on asennettava turvaohjeiden...

Page 234: ...ce names used in this publication are for identification purposes only and may be trademarks or registered trademarks of their respective companies All other trademarks or registered trademarks mentio...

Page 235: ...Page 234 of 234 Transition Networks 10900 Red Circle Drive Minnetonka MN 55343 USA Tel 952 941 7600 or 1 800 526 9267 Fax 952 941 2322 Copyright 2015 2017 Transition Networks All rights reserved Print...

Reviews: