background image

 

 

ZXR10 2920/2928/2952

Access Switch

User Manual(Volume I)

Version 1.0

ZTE CORPORATION 
ZTE Plaza,  Keji Road South,  
Hi-Tech Industrial Park,  
Nanshan District,  Shenzhen,  
P.   R.   China 
518057 
Tel: (86) 755 26771900    800-9830-9830 
Fax: (86) 755 26772236 
URL: http://support.  zte.  com.  cn 

E-mail: doc@zte.  com.  cn 

Summary of Contents for ZXR10 2920

Page 1: ... Manual Volume I Version 1 0 ZTE CORPORATION ZTE Plaza Keji Road South Hi Tech Industrial Park Nanshan District Shenzhen P R China 518057 Tel 86 755 26771900 800 9830 9830 Fax 86 755 26772236 URL http support zte com cn E mail doc zte com cn ...

Page 2: ...y of merchantability fitness for a particular purpose title or non infringement ZTE CORPORATION and its licensors shall not be liable for damages resulting from the use of or reliance on the information contained herein ZTE CORPORATION or its licensors may have current or pending intellectual property rights or applications covering the subject matter of this document Except as expressly provided ...

Page 3: ...echnical Accuracy Content Good Fair Average Poor Bad N A Your suggestions for improvement of this documentation Please check the suggestions which you feel can improve this documentation Improve the overview introduction Make it more concise brief Improve the Contents Add more step by step procedures tutorials Improve the organization Add more troubleshooting information Include more figures Make ...

Page 4: ...This page is intentionally blank ...

Page 5: ...ty Instruction 1 Overview 1 Safety Instructions 1 Chapter 2 3 System Overview 3 Overview 3 Product Overview 3 Switching Capability 4 Reliability and characteristics 4 Particular function 4 Security Controls 5 QoS Guarantee 5 Management 6 Functions 6 Technical Features and Parameters 7 Chapter 3 9 Structure and Principle 9 Overview 9 Working Principle 9 Hardware Structure 10 ...

Page 6: ... Cable Lightning Protection Requirements 32 Chapter 5 35 Usage and Operation 35 Overview 35 Configuration Modes 36 Configuration through Console Port Connection 36 Configuring through Telnet 37 Simple Network Management Protocol SNMP 38 Configuring through WEB Connection 39 Command Modes 40 Configuring User Mode 40 Configuring Global Mode 41 Configuring SNMP Mode 42 Configuring Layer 3 Mode 42 Con...

Page 7: ...nformation 57 Upgrading Version at Normality 57 Upgrading Version at Abnormality 59 Chapter 7 65 Service Configuration 65 Overview 65 Configuring Basic Port Parameters 68 Displaying Port Information 74 Port Mirroring 75 Configuring Port Mirroring 75 VLAN 77 Configuring VLAN 78 Introduction to FDB 83 MAC Table Operations 83 Configuring FDB 84 LACP Overview 86 Configuring LACP 87 IGMP Snooping 91 Co...

Page 8: ...LAN Overview 145 Configuring PVLAN 146 802 1x Transparent Transmission 149 Configuring 802 1x Transparent Transmission 150 Layer 3 Configuration 150 Configuring IP Port 151 Static Route Configuration 153 Configuring ARP Table Entry 154 Chapter 8 159 Access Service 159 Configuring 802 1x 163 Configuring Protocol Parameters of 802 1x 166 Configuring RADIUS 169 QinQ Overview 177 Configuring QinQ 178 ...

Page 9: ...verview 221 Configuring SSH 222 Configuring SSH v2 0 223 SNMP Overview 226 Configuring SNMP 227 RMON Overview 233 Configuring RMON 234 Cluster Management Overview 241 Configuring a ZDP 243 Configuring ZTP 245 Configuring Cluster 249 Configuring a Cluster Member 250 Configuring Cluster Parameters 251 Configuring Access and Control Cluster Members 253 Displaying Cluster Configuration 255 Web Managem...

Page 10: ...intenance 292 Maintenance Period 293 Single Loop Test Method 294 Configuring Single Port Loop Test 294 Virtual Circuit Test 297 Common Troubleshooting 298 Troubleshooting through Console Port 298 Troubleshooting through Telnet 299 Troubleshooting a Telnet connection with switch 299 Troubleshooting the browser 300 Troubleshooting the Switch through Web 300 Troubleshooting the User Name Password 301...

Page 11: ...er 2 Switches and protocols This is Volume 1 and the Volume 2 is based on Commands Familiarity with the following is helpful Virtual Local Area Network Link Aggregation Control Protocol Spanning Tree Protocol Access Control List What Is in This Manual This manual contains the following chapters TAB L E 1 CH AP T E R SUM M AR Y Chapter Summary Chapter 1 Safety Instruction This chapter introduces th...

Page 12: ...view of configuration methods for various services of ZXR10 2920 2928 2952 Chapter 8 Network Management This chapter provides and overview of network management functions of the ZXR10 2920 2928 2952 such as Remote Access SSH SNMP RMON and cluster management Chapter 9 Maintenance This chapter provides routine maintenance common test methods and troubleshooting of ZXR10 2920 2928 2952 Conventions ZT...

Page 13: ... on how to obtain support for the documentation and the software If you have problems questions comments or suggestions regarding your product contact us by e mail at support zte com cn You can also call our customer support center at 86 755 26771900 and 86 800 9830 9830 ZTE welcomes your comments and suggestions on the quality and usefulness of this document For further questions comments or sugg...

Page 14: ...iv Confidential and Proprietary Information of ZTE CORPORATION This Page is intentionally blank ...

Page 15: ...and maintained by professional user Please observe local safety specifications and relevant operating procedures in equipment installation operation and maintenance Otherwise personal injury or equipment damage may occur Safety precautions introduced in this manual are only supplementary to local safety codes ZTE shall not bear any liabilities incurred by violation of the universal safety operatio...

Page 16: ...2 Confidential and Proprietary Information of ZTE CORPORATION This page is intentionally blank ...

Page 17: ...cs 4 Security Controls 5 QoS Guarantee 5 Management 6 Functions 6 Technical Features and Parameters 7 Product Overview ZXR10 2920 2928 2952 series products are megabit L2 Ethernet switch providing gigabit upward Ethernet ports They can provide different quantity of interface types of Ethernet port mainly located at megabit access converge to provide fast efficient and cost effective access and con...

Page 18: ...e link redundancy backup through STP RSTP MSTP RSTP switching that is based on IEEE 802 1w ensures the usability of the network These switches support the LACP function of 802 3ad function and it supplies the load equalization backup and the link Switches support Ethernet ring network mode through ZESR High switching capability ensures that the operation do not be interrupted Particular function T...

Page 19: ...NMPv3 protocol supplies network management security Multilevel security of console can prevent unauthenticated users changing the switch configuration RADIUS authentication may carry on the common control to the switchboard The following are the network security control ACL based on port or Trunk makes it possible for users to apply security strategy to the ports of switches or Trunk Binding MAC a...

Page 20: ...pports layer 2 switching at wire speed Full wire speed switching is implemented at all ports ZXR10 2920 2928 2952 has the following functions Megabit ports support port 10 100 1000M self adapting and MDI MDIX self adapting Kilomega ports support port 10 100 1000M self adapting and MDI MDIX self adapting Support 802 3x compliant flow control full duplex and back pressure flow control half duplex VC...

Page 21: ...2 1p standard the ports support 4 PRI queue Ingress supports CAR The queue attempering supports SP combination SP WRR attempering method Egress is based on the queue and discarding the toned tail Port based speed control includes input speed limit and output speed limit Input speed limit strategy includes unicast unknown unicast broadcast and groupcast Input speed limit is based on stream and outp...

Page 22: ...L E 6 TE C H N I C AL FE AT U R E S AN D PAR AM E T ER S model item ZXR10 2920 ZXR10 2928 ZXR10 2952 Dimensions HxWxD mm 43 6 436 200 43 6 436 200 43 6 442 280 Weigh Fully equipped kg 2 2 2 5 Maximum power consumption W 16 20 27 Power supply AC power supply 100V 240V 48Hz 62Hz Wave shape distortion 5 DC power supply 57V to 40V ...

Page 23: ...ardware Structure 10 ZXR10 2920 11 ZXR10 2928 12 ZXR10 2952 13 ZXR10 2928 FI 14 Power Supply Module 17 Working Principle ZXR10 2920 2928 2952 series are important parts of ZXR10 Ethernet switches that are launched by ZTE They define a pure megabit L2 user Ethernet switch They are intended for gigabit upward access and used widely in large scale enterprise network and top grade industry This series...

Page 24: ...boards to accomplish the external user connection and transceivers packets The interface module switching module are interlinked by standard interface Power module adopts the 220 VAC or 48 VDC for power supply to offer required power supply for other parts of the system FI G U R E 1 ZXR10 2920 2928 2952FI WO R K I N G PRI N CI P L E ZXR10 2920 2928 2952 uses the 19 inch su brack that is in complia...

Page 25: ...function VCT auto test Two fixed 10 100 1000BASE T interface One expand slot expansile dual channel 1000M optical interface double 1000M electrical interface 1000M one optical one electrical upward subboard One Console port is to realize the management and configuration of various services There are 32 indicators on the front panel of the ZXR10 2920 indicating the status of the 16 10 100Base T por...

Page 26: ... that the LINK is normal When the other indicator is on it indicates that the LINK is normal If the indicator is flashing it indicates that data sending or receiving is under way ZXR10 2928 Front panel of the ZXR10 2928 is shown in Figure 3 FI G U R E 3 FR ON T PAN E L OF ZXR10 2928 Ethernet switching main board of ZXR10 2928 is KEBT ZXR10 2928 provides the following types of access ports Twenty f...

Page 27: ...lduplex indicator the other is link activation indicator f Semiduplex fullduplex indicator is on in the condition of fullduplex is off in the condition of semiduplex is flashing in the condition of collision f Link activation indicator is flashing when the link is activated 4 interface indicators correspond to the 2 10 100 1000 Base T interfaces Every interface has two indicators When one of the i...

Page 28: ... PWR is flashing it indicates that the switch is the main or standby role of the stack system Flashing in the same frequency with RUN shows it is the main equipment Flashing in the half frequency with RUN shows it is the standby equipment 48 indicators respond to 48 10 100 Base T port Every port has 1 indicator indicating LNK ACT If the link indicator is on it indicates that the LINK is normal If ...

Page 29: ...rs one is link activation indicator the other one is link status indicator If the link activation indicator is flashing it indicates that data sending or receiving is underway When link status indicator is on it indicates that the LINK is normal FGFI subboard offer two gigabit Ethernet up go light port the type is SF 2GE 2SFP as shown in Figure 6 Subboard Type Function FGEI SF 2GE 2RJ45 2 gigabit ...

Page 30: ...ctrical port the type is SF 2GE SFPRJ45 as shown in figure 7 F I G U R E 7 SF 2GE SFPRJ45S U B B O AR D FGFE There are 3 indicators on the FGFIpanel The gigabit Ethernet up go light port has an indicator ACT When the indicator is on it indicates that LINKis normal if the indicator is flashing it indicates that data sending or receiving is underway The gigabit Ethernet up go electrical port has two...

Page 31: ...is adopted use 48V DC power cables When the AC power supply is adopted use AC power cables Both of the two modes support a backup power supply of 12v DC power supply FIGURE 8 and FIGURE 9 respectively show rear panel of the switch when the 48V DC power supply and 110V 220V AC power supply are adopted FIGURE 8 ZXR10 2920 2928 2952 B AC K P AN E L DC P O W E R OFF ON PGND 48VRTN 48V FIGURE 9 ZXR10 2...

Page 32: ...ZXR10 2920 2928 2952 V1 0 Access Switch User Manual Volume I 18 Confidential and Proprietary Information of ZTE CORPORATION This page is intentionally blank ...

Page 33: ...pics Page No Equipment 19 Switch Installation on Desktop 20 Switch Installation onto a Cabinet 20 Cable 23 Power Cables 24 Console Cable 25 Network Cable 26 Optical Fiber 28 Labels 29 Cable Lightning Protection Requirements 32 Equipment Installation ZXR10 2920 2928 2952 can be placed on desktop and can be installed on a 19 inch standard cabinet 19 inch standard cabinet can be provided by customer ...

Page 34: ... accessories on bottom plate of switch Four pads support switch and form a lower ventilation channel for power to cool down It is shown in Figure 8 FI G U R E 8 IN ST AL L I N G PL AS T I C PAD S 1 2 2 1 1 2 1 Case 2 Pad Switch Installation onto a Cabinet To install the switch into the 19 inch cabinet install a flange to each of the two sides of the switch shell the flange and screws are part of t...

Page 35: ...tial and Proprietary Information of ZTE CORPORATION 21 FI G U R E 9 IN ST AL L I N G FL AN G E S 3 2 1 2 3 1 1 Case 2 Flange 3 Screw Install two symmetrical brackets at both sides of the 19 inch cabinet to support the switch as shown in Figure 10 ...

Page 36: ...me I 22 Confidential and Proprietary Information of ZTE CORPORATION FI G U R E 10 INS T AL L I N G BR AC K E T S 2 1 3 1 Holder 2 Cabinet 3 Screw After installation push switch along with bracket and fix flanges with screws onto cabinet as shown in Figure 11 ...

Page 37: ...fidential and Proprietary Information of ZTE CORPORATION 23 FI G U R E 11 FIX I N G T H E SW IT C H 1 3 1 2 3 2 3 1 2 1 Cabinet 2 Box 3 Screw Cable Types ZXR10 2920 2928 2952 consists of Power cables Console cables Network cables Fiber optics ...

Page 38: ...r cable as shown in Figure 12 FI G U R E 12 AC PO W E R CAB L E One end of the AC power cable connects the AC power socket of the ZXR10 2920 2928 2952 power module and the other end connects the 220 VAC power socket Appearance and description of 48V power socket on DC power supply module of ZXR10 2920 2928 2952 is shown in Figure 13 FI G U R E 13 48 PO W E R SO CK E T D 48VGND 48V GNDP DC power ca...

Page 39: ...g terminal of 48V DC power supply There is a grounding screw on the back of ZXR10 2920 2928 2952 figuring by When connecting with kelly protect cable one end of the cable is connected to the grouding screw and the other end to the grouding protect of the cabinet of the ZXR10 2920 2928 2952 Grounding protect cable shape is shown in Figure 17 FI G U R E 17 GR O U N D I N G P RO T E C T C AB L E Cons...

Page 40: ...n in TABLE 10 FIGURE 18 CO N S O L E CAB L E IN S T AL L AT I O N TABLE 10 LI N E AR OR D E R I N G OF SE R I AL PO R T CO NS OL E CAB L E Side A Color Side B 2 White 3 3 Blue 6 White 4 5 Orange 5 4 White 7 6 Green 2 7 White 8 8 Brown 1 Network Cable Installation Both ends of network cable are crimped with RJ45 connectors as shown in FIGURE 19 Name of the cable connector 8P8C straight crimping cab...

Page 41: ...orrespondence Specific pin outs are shown in Table 10 TAB L E 10 STR AI G H T TH R O U G H NE T W O RK CAB L E RJ45 LI N E AR OR D E R I N G End A Cable Color End B 1 White orange 1 2 Orange 2 3 White green 3 6 Green 6 4 Blue 4 5 White blue 5 7 White brown 7 8 Brown 8 Crossover RJ45J cable with two twisted pairs at both ends corresponding to each other in crossover mode The specific connection rel...

Page 42: ...bers are available for configuration as shown in Table 12 TAB L E 12 FI BE R TY P E S Mode Type of Connector to Switch Type of Connector on the Peer End FC PC connector SC PC connector ST PC connector Single mode fiber SC PC connector square flat connector LC PC connector FC PC connector SC PC connector ST PC connector Multi mode fiber SC PC connector square flat connector LC PC connector For fibe...

Page 43: ... Labels Pattern and meanings of the labels attached to the connector Label attached to the connector is called transverse English label on panels and connectors Structure and dimensions of the label is shown in FIGURE 20 FIGURE 20 TR AN S V E R S E EN G L I S H LAB E L ON PAN E L S AN D CO N N E C T O R S These contents are described in the following section ...

Page 44: ... E R LAS E R PR I N T LAB E L MO D E L II Transparent area Printable area Transparent area HD182 Port B 1 30m 1 L5 DTI1 D25 32 Contents of the label in the above figure have same meanings as those in FIGURE 20 These two types of labels are used in different places Transverse English label on panels and connectors is only applicable to the connectors where the attachment area is larger than the lab...

Page 45: ...n No The side marked with L must be filled in The side marked with R must be filled in Two sides of the engineering label on the optical fiber are marked L and R with the specific meanings given as follows When label is pasted on fiber at ZXR10 2920 2928 2952 side row and column number of cabinet at side of connected remote optical interface device as well as the layer No of the fiber in the cabin...

Page 46: ...or to avoid the direct sunshine rains and lightning Ensure that all subscriber lines are distributed inside building to avoid lightning induction Uplink downlink and cascading lines are distributed outside Cabling of Ethernet switch in a four floor building with three units is shown in Figure 17 FI G U R E 17 CAB L I N G OF TH E ET H E R N E T SW I T C H IN A BU I L D I N G Switch Switch Switch Sw...

Page 47: ...are connected to ground through shell Rest of subscriber lines are distributed inside building FI G U R E 18 CAB L I N G OF A CO N V E R G E N C E SW I T C H Uplink cable optical interface Uplink cable or cascading cable Shell ground Subscriber line Less than 30 cm Lightning protection bar Ethernet switch Explanations are as follows Grounding system with good ground grid is preferred for switch Ma...

Page 48: ...ion index than that for port cable Note Ethernet switch suffers lightning strike due to grounding power supply and wiring Lightning strike lead in mechanism also varies a lot Taking one measure does not prevent lightning strike Therefore several measures must be implemented at same time Proper grounding appropriate power supply reasonable wiring and suitable lightning protection measures will defi...

Page 49: ...rough Console Port Connection 36 Configuring through Telnet 37 Simple Network Management Protocol SNMP 38 Configuring through WEB Connection 39 Command Modes 40 Configuring User Mode 40 Configuring Global Mode 41 Configuring SNMP Mode 42 Configuring Layer 3 Mode 42 Configuring File System Mode 42 Configuring NAS Mode 43 Configuring Cluster Management 43 Configuring Basic ACL 44 Configuring Extende...

Page 50: ... connected network as shown in Figure 19 Configuration through serial port connection Configuration through TELNET session Configuration through SNMP connection Configuration through WEB connection FI G U R E 19 ZXR10 2920 2928 2952 CO NF I G U R AT I O N MO D E S Configuration through Console Port Connection Configuration through console port connection is the main configuration mode of the ZXR10...

Page 51: ...hat local computer can ping the IP address of the layer 3 port in the switch Layer 3 port address configuration refers to section 7 13 Create a new user using command create user name admin guest Set login password using command set user local name login password string Note by default the username password is admin zhongxing To configure through telnet perform the following steps 1 Run the telnet...

Page 52: ...anagement Protocol SNMP is one of the most popular network protocols An NM server can manage all devices on the network through this protocol SNMP adopts the management based on the server and client Background NM server serves as SNMP server and the foreground network device ZXR10 2920 2928 2952 serves as the SNMP client Foreground and background share one MIB management database and the SNMP is ...

Page 53: ... M M AN D Format Mode Function create user name admin guest config This creates user Result This creates user 2 To configure user password use command set user local name login password string in global configuration mode This is shown in Table 15 TAB L E 15 US E R PAS S W O R D CO M M AN D Format Mode Function set user local name login password string config This configures user password Result T...

Page 54: ...ement is completed successfully Command Modes ZXR10 2920 2928 2952 allocates the commands to various modes based on the function In order to authorize the facilitation to user s configuration and management for the switch only one command can be executed in the special mode only ZXR10 2920 2928 2952 command modes include User mode Global configuration mode SNMP configuration mode Layer 3 configura...

Page 55: ...executed in any mode END OF STEPS User mode has been configured Configuring Global Mode This topic describes the global configuration mode For the configuration of global mode perform the following steps 1 In user mode enter the enable command and the corresponding password to enter the global configuration mode as follows zte enable Password zte cfg 2 In the global configuration mode various func...

Page 56: ...has been configured Configuring Layer 3 Mode This topic describes the Layer 3 configuration mode For the configuration of Layer 3 mode perform the following steps 1 In the global configuration mode execute the command config router to enter the Layer 3 configuration mode as shown in the following example zte cfg config router zte cfg router Note In the Layer 3 configuration mode you can configure ...

Page 57: ...nfigured Configuring NAS Mode This topic describes the NAS configuration mode For the configuration of NAS mode perform the following steps 1 In the global configuration mode execute the command config nas to enter into NAS configuration mode as shown below zte cfg config nas zte cfg nas Note In the NAS configuration mode configuration of switch access service including user access authentication ...

Page 58: ...config acl basic number 10 zte basic acl group Note In the basic ACL configuration mode it is possible to add delete move the ACL rule for the specified ACL id 2 To return to the global configuration mode from basic ACL configuration mode use command exit or press Ctrl Z END OF STEPS Basic ACL is configured Configuring Extended ACL This topic describes the extended ACL configuration mode For the c...

Page 59: ...brid ACL Mode This topic describes the Hybrid ACL configuration mode For the configuration of Hybrid ACL perform the following steps 1 In the global configuration mode execute command config acl hybrid number 300 349 to enter into Hybrid ACL configuration mode as shown in zte cfg config acl hybrid number 333 zte hybrid acl group Note Hybrid ACL configuration mode includes configuring ACL parameter...

Page 60: ...aracter or character string Result This will view the list of commands or keywords beginning with that character or character string Example An example given below shows the character string zte cfg c config clear create zte cfg c 3 Input behind the command keyword and parameter Result It shows the keyword or parameter to be input next and its brief explanation Example An example is given below zt...

Page 61: ... command help has been configured Command Abbreviations In ZXR10 2920 2928 2952 a command or keyword can be shortened into a character or string that can uniquely identify this command or keyword For example the command exit can be shortened as ex and the command show port shortened as sh po History Commands Input command can be recorded in the user interface up to 10 history commands can be recor...

Page 62: ...Å Move left in the command line currently indicated by the prompt Ctrl F or Æ Move right in the command line where the prompt is currently located Tab Display commands starting with the character or string If there is only one command make this command a complete one Ctrl A Skip to the beginning of the command line Ctrl E Skip to the end of the command line Ctrl K Delete the characters from the cu...

Page 63: ...m 50 Configuring Imports and Exports 54 Setting File Backup and Recovery 55 Software Version Upgrade 56 Viewing System Information 57 Upgrading Version at Normality 57 Upgrading Version at Abnormality 59 File System In ZXR10 2920 2928 2952 Flash is the major storage device on the main control board Software version file and configuration file of the ZXR10 2920 2928 2952 are saved in the Flash memo...

Page 64: ...ons For file system operation perform the following steps 1 To enter the file system configuration mode use command config tffs in global configuration mode This is shown in Table 21 TAB L E 21 CO N F I G TF F S COM M AN D Format Mode Function config tffs config This enters into the file system configuration mode Result This enters into the file system configuration mode 2 To create new directory ...

Page 65: ...M M AN D Format Mode Function cd directory name File system config This modifies the current directory Result This modifies the current directory 6 To displays the current directory list use command ls in file system configuration mode This is shown in Table 26 TAB L E 26 LS CO M M AN D Format Mode Function ls File system config This displays the current directory Result This displays the current ...

Page 66: ...B L E 29 FO R M AT CO M M AN D Format Mode Function format File system config This formats the FLASH memory Result This formats the FLASH memory END OF STEPS File system operation of ZXR10 2920 2928 2952 is configured Configuring ZXR10 2920 2928 2952 as an TFTP Client This topic describes the background TFTP server configuration To configure background TFTP server meet the following requirements S...

Page 67: ... R FAC E 2 Select Tftpd Configure click Browse on the popup dialog box and select a directory to store the version configuration file such as D IMG The following dialog box will appear as shown in Figure 23 FI G U R E 23 CO N F I G U R E DI AL O G BO X 3 Click OK in Figure 23 to finish the settings END OF STEPS Result ...

Page 68: ...itch can not find running cfg file it will check whether the config txt file exists and when file exists switch will use it to recover configurations Config txt file is used for version update When the span between new version and old one is big using running cfg file of the primary version may cause mistakes after version update Consider the following recommendations f Create config txt file befo...

Page 69: ...backup and recovery perform the following steps 1 Use command saveconfig in global configuration mode This is shown in Table 30 Note When a command is used to modify the switch configuration data is running in the memory of the switch When the switch is restarted all the contents newly configured will be lost In order to save the current configuration into the FLASH memory TAB L E 30 SAV E C O N F...

Page 70: ...e foreground version file to the background TFTP server Example This example shows the upload of the foreground version file to the background TFTP server Zte cfg tffs tftp 192 168 1 102 upload kernel z 4 Version file recovery is used to retransmit the background backup version file to the foreground through TFTP Recovery is very important in the case of upgrading failure The version recovery oper...

Page 71: ...software and hardware of system Result This shows the running software and hardware information of system Example The following information is displayed after carrying out show version command zte cfg version The System s Hardware Info Switch s Mac Address 00 d0 d0 f0 11 22 Module 0 ZXR10 5124 fasteth 0 gbit 24 The System s Software Info Version number V1 1 11 b Version make date Jun 16 2006 Versi...

Page 72: ...eps 1 View the information about the currently running image by using show version command in privileged mode as shown in Table 32 TAB L E 32 SHO W VE R S I O N CO M M AN D WIN D O W Format Mode Function Show version Privileged mode This indicated software version flash and image file present in directory Result This indicates new image file present in directory 2 To delete the old version file in...

Page 73: ...ig span with the new one use config txt file to recover configuration After upadate check the recovered configurations are of same primary configurations or not If they are not the same configure according to facts and avoid the mistakes caused by update Upgrading Version at Abnormality This topic describes the procedure of software version upgrade for ZXR10 2920 2928 2952 if it fails to start Con...

Page 74: ... Co Ltd System Booting CPU DB 88E6218 Version VxWorks5 5 1 BSP version 1 2 6 b Creation date Aug 1 2006 09 40 27 Press any key to stop auto boot 7 ZxR10 Boot 2 Enter c in the ZxR10 Boot state and press Enter to enter the parameter modification status Set the IP addresses of the Ethernet port and the TFTP server Generally these two addresses are set to the same network segment ...

Page 75: ...eway inet g 10 40 89 78 Use the default value user u Use the default value ftp password pw blank use rsh Use the default value flags f 0x80 Use the default value target name tn Use the default value startup script s Use the default value other o Use the default value ZxR10 Boot 3 Set the IP address of the background host as the same with the IP address of the above TFTP server 4 Start the TFTP ser...

Page 76: ...ing no netmask specified Attaching network interface lo0 done Attaching to TFFS test flash passed perfectly Welcome to boot manager Type for help BootManager ls Display the current directory list pwd Display the current absolution path devs Display the FLASH information show Display the switch type and mac address reboot Restart the switch format Format the FLASH del file_name Delete the specified...

Page 77: ...e BootManager ls snmpboots v3 35 startcfg txt 1378 running cfg 231916 kernel z 1311339 BootManager 7 In the BootManager state execute the command reboot to restart the switch by using the new version If the switch is started normally use the command version to check whether the new version is running in the memory When the switch is not started normally it indicates the version upgrade fails In th...

Page 78: ...ZXR10 2920 2928 2952 V1 0 Access Switch User Manual Volume I 64 Confidential and Proprietary Information of ZTE CORPORATION This page is intentionally blank ...

Page 79: ...eters 68 Displaying Port Information 74 Port Mirroring 75 Configuring Port Mirroring 75 VLAN 77 Configuring VLAN 78 Introduction to FDB 83 MAC Table Operations 83 Configuring FDB 84 LACP Overview 86 Configuring LACP 87 IGMP Snooping 91 Configuring IGMP Snooping 91 Internet Protocol Television 101 Configuring IPTV Global Parameters 102 Configuring IPTV Channels 103 Configuring Channel Access Contro...

Page 80: ...pe IEEE ACL 124 Configuring Basic ACL 126 Configuring Extended ACL 127 Configuring L2 ACL 128 Configuring Hybrid ACL 128 Configuring Hybrid ACL 128 Configuring Global ACL 129 Configuring Time Range 131 Configuring ACL to a Physical Port 131 Quality of Service QoS 132 Configuring QoS 133 Private Virtual LAN Overview 145 Configuring PVLAN 146 802 1x Transparent Transmission 149 Configuring 802 1x Tr...

Page 81: ... 185 Configuring Syslog 186 Configuring NTP 187 GARP GVRP Overview 189 Configuring GARP 190 Configuring GVRP 191 DHCP Snooping Option82 194 Configuring Global DHCP 195 Configuring DHCP Snooping 197 Configuring IP Source Guard 198 Configuring DHCP Option82 199 VBAS Overview 204 Configuring VBAS 205 sFlow Monitoring Overview 207 Configuring sFlow 207 ZESR Overview 210 Configuring ZESR 211 ...

Page 82: ... port name statistics data Result This clear port name statistics data 2 To create port description name use command create port portname name name in global configuration mode This is shown in Table 35 TAB L E 35 AU T O SE N S I N G CO M M AN D Format Mode Function clear port portlist name statistics descripti on Global config This creates port description name Result This creates port descriptio...

Page 83: ...rtise maxspeed speed10 speed100 speed1000 Global config This sets speed of the port Result This sets speed of the port 6 To set the working manner of the port use command set port portlist duplex full half Format Mode Function set port portlist duplex full half Global config This sets the working manner of the port 7 To set the speed of the port use command set port portlist speed 10 100 1000 Tabl...

Page 84: ...address 8 To set the priority of the source VLAN use command set port portlist vlan priority enable disable TAB L E 42 QU E U E SC H E D U LE COM M AN D Format Mode Function set port portlist vlan priority enable disable Global config This sets port s priority of the source VLAN Result This sets port s queue schedule profile 9 To set the priority of a port use command set port portlist default pri...

Page 85: ...le or disable the port unit statistics use command set port portlist unit statistics enable disable in global configuration mode This is shown in Table 46 TAB L E 46 RAT E AD V E R T I S E M E N T COM M AN D Format Mode Function set port portlist unit statistics enable disable Global config This sets the port unit statistics Result This sets the port unit statistics 15 To set the multicast filter ...

Page 86: ... config This sets port s macaddress Result This sets port s macaddress 18 To set the ACL info use command set port portlist acl acl number enable disable in global configuration mode This is shown in Table 50 TAB L E 50 CR E AT E PO R T CO M M AN D Format Mode Function set port portlist acl acl number enable disable Global config This sets the ACL info Result This sets the ACL info 19 To set port ...

Page 87: ...nverts it to the corresponding UP The flow is as follows When the IP message enterS from port A that trusts in DSCP firstly we get the default priority def 2 0 0 7 aggregately 3 bits Then mapping the global DSCP TC table according to DSCP value of the message we can get the initial TC value TC 1 0 0 3 aggregately 2 bits of the message We adopt TC 1 0 as the 2 1 digit of UP the last digit of port d...

Page 88: ...l configuration mode This is shown in Table 55 TAB L E 55 SHO W PO R T VL AN COM M AN D Format Mode Function show port portlist vlan Global config This displays Vlan information of the port Result This displays Vlan information of the port 3 To display statistics information of the port in unit time use command show port portlist statistics 1min_unit 5min_unit in global configuration mode This is ...

Page 89: ...ress destination port ingress monitoring port or mirror the data packets of the switch port egress mirroring port to an egress destination port egress monitoring port Through mirroring data packets flowing in or out of a certain port can be monitored Port mirroring provides an effective tool for the maintenance and monitoring of the switch Switch can be configured with only one ingress monitoring ...

Page 90: ...de This is shown in Table 60 TAB L E 60 DE L E T E MI R R O RI NG PO R T COM MAN D Format Mode Function set mirror delete source port portlist ingress egress Global config This deletes mirroring port Result This deletes mirroring port 3 To set a monitoring port use command set mirror add dest port portname ingress egress in global configuration mode This is shown in Table 61 TAB L E 61 SE T MI R R...

Page 91: ...S Port mirroring is configured on ZXR10 2920 2928 2952 To mirror data packets received by port 1 and port 16 onto the monitoring port 10 configuration is as follows zte cfg set mirror add dest port 10 ingress zte cfg set mirror add source port 1 16 ingress Use the command show mirror to view the port mirroring configuration zte cfg show mirror ingress mirror infomation source port 1 16 dest port 1...

Page 92: ... the universal work mode In this mode VLAN partition is based on port s VLAN info PVID port VLAN ID or the information in VLAN lable VLAN provides the following advantages Lower broadcast traffic on the network Enhanced network security Streamlined network management Configuring VLAN This topic describes the configuration of VLAN on ZXR10 2920 2928 2952 For configuration of VLAN perform the follow...

Page 93: ... Mode Function set trunk trunklist pvid 1 4094 Global config This sets trunk PVID Result This sets trunk PVID 5 To Enable Disable the VLAN use command set vlan vlanlist enable disable in global configuration mode This is shown in Table 68 TAB L E 68 SE T VL AN CO M M AN D Format Mode Function set vlan vlanlist enable disable Global config This Enable Disable the VLAN Result This Enable Disable the...

Page 94: ...PO R T COM M AN D Format Mode Function set vlan vlanlist delete port portlist Global config This deletes a specified port to the VLAN Result This deletes a specified port to the VLAN 9 To delete a specified trunk to the VLAN use command set vlan vlanlist delete trunk trunklist in global configuration mode This is shown in Table 72 TAB L E 72 SE T VL AN DE L E T E TR U N K COM M AN D Format Mode Fu...

Page 95: ... I D TR U N K COM M AN D Format Mode Function set vlan vlanlist forbid trunk trunklist Global config This forbids trunk on VLAN Result This forbids trunk on VLAN 13 To permit trunk on VLAN use command set vlan vlanlist permit trunk trunklist in global configuration mode This is shown in Table 76 TAB L E 76 SE T VL AN PE R M I T TR U N K COM M AN D Format Mode Function set vlan vlanlist permit trun...

Page 96: ...8 tag zte cfg set port 1 2 pvid 100 zte cfg set vlan 100 enable zte cfg show vlan 100 VlanId 100 Fid 100 Priority off VlanStatus enabled VlanName Tagged ports 7 8 Untagged ports 1 2 zte cfg Configuration of VLAN transparent transmission This example describes how Switch A is connected to switch B through port 16 Port 1 of switch A and port 2 of switch B belong to VLAN2 and port 3 of switch A and p...

Page 97: ...ding Each switch maintains a MAC address table called forwarding database FDB FDB records one to one mapping relationship between MAC addresses and switch ports Upon receiving a data frame the switch decides whether to drop it or forward it to the proper port based on this table The FDB is the basis and prerequisite for fast forwarding MAC Table Operations MAC table operations include the configur...

Page 98: ...tid trunk trunkid in global configuration mode This is shown in Table 78 TAB L E 78 SE T FD B AD D VL AN COM M AN D Format Mode Function set fdb add xx xx xx xx xx xx vlan 1 4094 port portid trunk trunkid Global config This adds the static binding address to the address table Result This adds the static binding address to the address table 2 To set the aging time of MAC address use command set fdb...

Page 99: ... This sets the filter address of fdb 5 To display fdb information use command show fdb static dynamic filter detail in global configuration mode This is shown in Table 82 TAB L E 82 SHO W FD B COM M AN D Format Mode Function show fdb static dynamic filter detail Global config This displays fdb information Result This displays fdb information 6 To display the aging time of fdb address use command s...

Page 100: ...lays the port based fdb information 9 To display Trunk fdb information use command show fdb trunk trunkname detail in global configuration mode This is shown in Table 86 TAB L E 86 SHO W FD B TR U NK COM M AN D Format Mode Function show fdb trunk trunkname detail Global config This displays Trunk fdb information Result This displays Trunk fdb information 10 To display the VLAN based fdb informatio...

Page 101: ...on groups In each aggregation group number of links participating in aggregation does not exceed eight Links participating in the aggregation must have same transmission media type and same transmission rate Configuring LACP This topic describes the configuration of link aggregation For configuration of link aggregation perform the following steps 1 To Enable Disable the LACP function use command ...

Page 102: ...onfiguration mode This is shown in Table 91 TAB L E 91 SE T LAC P AG G R E G AT O R MO D E CO M M AN D Format Mode Function set lacp aggregator trunkid mode dynamic static mixed Global config This sets aggregation mode of the aggregation group Result This sets aggregation mode of the aggregation group 5 To set the mode used by the port to participate in the aggregation use command set lacp port po...

Page 103: ...he LACP configuration information use command show lacp in global configuration mode This is shown in Table 95 TAB L E 95 SHO W LACP CO M M AN D Format Mode Function show lacp Global config This displays the LACP configuration information Result This displays the LACP configuration information 7 To display the aggregation information about the LACP aggregation group use command show lacp aggregato...

Page 104: ...ding MAC address and so on This example describes that switch A and switch B are connected through aggregation port binding the port 15 and port 16 Port 1 of switch A and port 2 of switch B belong to VLAN2 Port 3 of switch A and port 4 of switch B belong to VLAN2 Members of same VLAN can communicate with each other This is shown in Figure 25 FI G U R E 25 LAC P CO N F I G U RAT I O N p1 p3 Switch ...

Page 105: ...f the network thus causing a great waste of network bandwidth resource With IGMP Snooping function IGMP communication between host and router is snooped so that multicast packets are sent to the ports in the multicast forwarding table instead of all ports This restricts the wide spread of multicast messages in the LAN switch reduces the waste of network bandwidth and improves the utilization rate ...

Page 106: ...s is shown in Table 100 TAB L E 99 SE T IGM P SN O O P IN G DE L E T E VLAN CO M M AN D Format Mode Function set igmp snooping delete vlan vlanlist Global config This deletes the IGMP Snooping function for the specified VLAN Result This sets crossvlan monitor 4 To delete the IGMP Snooping function for the specified VLAN use command set igmp snooping delete vlan vlanlist in global configuration mod...

Page 107: ...G QU E R Y VLAN CO M M AN D Format Mode Function set igmp snooping query vlan vlanlist enable disable Global config This Enable Disable the IGMP Snooping function for the specified VLAN Result This Enable Disable the IGMP Snooping function for the specified VLAN 8 To set the snooping interval use command set igmp snooping query interval 10 2147483647 in global configuration mode This is shown in T...

Page 108: ...multicast group to ports on Vlan use command set igmp snooping vlan 1 4094 add group A B C D port portlist trunk trunklist in global configuration mode This is shown in Table 105 TAB L E 105 STAT I C MU L T I C AS T GR O U P TO PO R T S COM M AN D Format Mode Function set igmp snooping vlan 1 4094 add group A B C D port portlist trunk trunklist Global config This binds static multicast group to po...

Page 109: ...roup A B C D port portlist trunk trunklist in global configuration mode This is shown in Table 108 TAB L E 108 SET IGM P SN O O PI N G VL AN DE L E T E GR O U P PO R T COM M AN D Format Mode Function set igmp snooping vlan 1 4094 delete group A B C D port portlist trunk trunklist Global config This unbinds static multicast group from ports Result This unbinds static multicast group from ports 15 T...

Page 110: ...e This is shown in Table 111 TAB L E 111 SET IGM P SN O O PI N G AD D MAX N U M VL AN CO M M AN D Format Mode Function set igmp snooping add maxnum 1 256 vlan vlanlist Global config This adds maximum multicast group numbers to Vlan Result This adds maximum multicast group numbers to Vlan 18 To delete maximum multicast group number from Vlan use command set igmp snooping delete maxnum vlan vlanlist...

Page 111: ...6 To delete source Ip of Vlan from filter use command set igmp filter delete groupip A B C D vlan vlanlist in global configuration mode This is shown in Table 115 TAB L E 115 SET IGM P FI LT E R DE L E T E GR OU P I P VL AN CO M M AN D Format Mode Function set igmp filter delete groupip A B C D vlan vlanlist Global config This deletes source Ip of Vlan from filter Result This deletes source Ip of ...

Page 112: ... in Table 118 TAB L E 118 SH O W IGM P SNO O P I N G COM M AN D Format Mode Function show igmp snooping Global config This displays the configuration of IGMP snooping Result This displays the configuration of IGMP snooping 10 To display the configuration of IGMP snooping result use command show igmp snooping vlan vlanname host router in global configuration mode This is shown in Table 119 TAB L E ...

Page 113: ...s the multicast snooping results Result This displays the multicast snooping results END OF STEPS IGMP snooping has been configured This example describes IGMP snooping function Ports 1 3 and 5 are connected to the host Port 10 is connected to the router The one to multiple communication mode is implemented That is port 10 can communicate with ports 1 3 and 5 but ports 1 3 and 5 cannot communicate...

Page 114: ...icast snooping result zte cfg show igmp snooping vlan Num VlanId Group Last_Report PortMember 1 210 224 1 1 1 192 168 1 1 1 2 230 224 1 1 1 192 168 1 2 3 3 250 224 1 1 1 192 168 1 3 5 Enable multi VLAN IGMP snooping function of the switch and display the snooping results zte cfg set igmp snooping crossvlan enable zte cfg show igmp snooping vlan Num VlanId Group Last_Report PortMember 1 210 224 1 1...

Page 115: ...um VlanId Group Last_Report PortMember 1 200 230 44 45 157 192 168 1 1 1 3 5 10 zte cfg sho igmp filter IGMP Filter enabled Index FilterIpAddress Vlan Port Type 1 230 44 45 167 200 Groupip zte cfg show igmp filter vlan 200 Maximal group number 256 Current group number 0 The filter address list of this vlan Index FilterIpAddress Vlan Type 1 230 44 45 167 200 Groupip Internet Protocol Television Int...

Page 116: ...as config mode This sets the least view time Result This sets the least view time 2 To set the max preview counts on global use command iptv control prvcount count in nas config mode This is shown in Table 123 TAB L E 123 IPT V CO N T R O L PR V C O U N T COU N T COM M AN D Format Mode Function iptv control prvcount count nas config mode This sets the max preview counts on global Result This sets ...

Page 117: ... reset preview counts Result This sets the period of global reset preview counts 6 To enable disable IPTV use command iptv control enable disable in nas config mode This is shown in Table 127 TAB L E 127 IPT V CO N T R O L CO M M AN D Format Mode Function iptv control enable disable nas config mode This enable disable IPTV Result This enable disable IPTV END OF STEPS IPTV has been configured Confi...

Page 118: ...llist mvlan in nas config mode This is shown in Table 130 TAB L E 130 IPTV CH AN N E L MV L AN CO M M AN D Format Mode Function iptv channel channellist mvlan Nas config mode This sets a channel belonging to a multicast Vlan Result This sets a channel belonging to a multicast Vlan 4 To delete a channel use command clear iptv channel channellist in nas config mode This is shown in Table 131 TAB L E...

Page 119: ... This sets the name of CAC rule 3 To set maximum preview counts of rules use command iptv cac rule rulelist prvcount in nas config mode This is shown in Table 134 TAB L E 134 IPTV CAC RU L E PR V C O U N T CO M M AN D Format Mode Function iptv cac rule rulelist prvcount Nas config mode This sets maximum preview count of rules Result The sets maximum preview count of rules 4 To set maximum preview ...

Page 120: ...Result This sets the right rule to channel 7 To delete rules use command clear iptv cac rule rulelist in nas config mode This is shown in Table 138 TAB L E 138 CLE AR IP T V CAC RU L E COM M AN D Format Mode Function clear iptv cac rule rulelist Nas config mode This deletes the rules Result This deletes the rules END OF STEPS CAC has been configured Configuring Administrative Command of IPTV Users...

Page 121: ...ast group 224 1 1 1 Max preview time is 2 minutes Least preview interval is for 20 seconds Max preview counts are 10 Vlan ID of multicast group is 100 Configuration is shown below ZXR10 config nas iptv control enable ZXR10 config nas create iptv channel special 1 address 224 1 1 1 ZXR10 config nas iptv channel 1 mvlan 100 ZXR10 config nas iptv channel 1 name cctv1 ZXR10 config nas create iptv cac ...

Page 122: ...isplay the global configuration information of IPTV use command show iptv control in privileged mode This is shown in Table 140 TAB L E 140 SH O W IPTV CON T R O L C OM M AN D Format Mode Function show iptv control privileged mode This displays the global configuration information of IPTV Result This displays the global configuration information of IPTV 2 To display the channel information of IPTV...

Page 123: ...ileged mode This is shown in Table 144 TAB L E 144 SH O W IP T V CAC RU L E ST AT I S T I C S COM M AN D Format Mode Function show iptv cac rule statistics privileged mode This displays CAC rule statistics Result This displays CAC rule statistics 6 To display online users of IPTV use command show iptv client in privileged mode This is shown in Table 145 TAB L E 145 SH O W IPTV CL IE N T COM M AN D...

Page 124: ...creases the topology convergence speed Multiple Spanning Tree Protocol MSTP is on the basis of RSTP and STP added with the forwarding processing of frames with VLAN ID The whole network topology structure can be planned into a Common and Internal Spanning Tree CIST which is divided into Common Spanning Tree CST and Internal Spanning Tree IST as shown in Figure 27 FI G U R E 27 MSTP TO P O L OG I C...

Page 125: ...rbulent the state can switch fast According to port role the state after the calculation being steady is shown in TABLE147 TABLE147 PO R T R O L E PO R T S T AT E Port role Port state Master Forward Root Forward Designated Forward Backup Discard Alternate Discard Edged Forward Spanning Tree Protocol STP is applicable to a loop network It blocks some redundant paths with certain algorithms so that ...

Page 126: ... the port to blocking state When configuring one port you can configure only one of the three protection BPDU protection root protection loop protection Configuring STP This topic describes the STP configuration In the default configuration MSTP only has the instance with ins_id as 0 This instance always exists and cannot be manually deleted This instance is mapped with VLANs 1 to 4094 For the con...

Page 127: ...mat Mode Function clear stp name 0 15 Global config This clear the STP name Result This clears the STP name 5 To Enable Disable the STP use command set stp enable disable in global configuration mode This is shown in Table 151 TAB L E 151 SET ST P COM M AN D Format Mode Function set stp enable disable Global config This enable disable the STP Result This is used to enable disable the STP 6 To set ...

Page 128: ...me use command set stp forwarddelay 4 30 in global configuration mode This is shown in Table 155 TAB L E 155 SET ST P FO R W AR D DE L AY CO M M AN D Format Mode Function set stp forwarddelay 4 30 Global config This sets STP forwarding delay time Result This sets STP forwarding delay time 10 To set STP hello time use command set stp hellotime 1 10 in global configuration mode This is shown in Tabl...

Page 129: ...erminal of MST Result This sets the maximum number of hop between any two terminals of MST 18 To set the bridge priority use command set stp instance 0 15 priority 0 61440 in global configuration mode This is shown in Table 160 TAB L E 160 SET ST P IN S T AN C E BR I D G E PRI O R I T Y COM M AN D Format Mode Function set stp instance 0 15 priority 0 61440 Global config This sets the bridge priori...

Page 130: ...t portname root guard enable disable Global config This sets port root guard for STP instance Result This sets port root guard for STP instance 18 To set port loop guard for STP instance use command set stp instance 0 15 port portname loop guard enable disable in global configuration mode This is shown in Table 163 TAB L E 164 SET ST P IN S T AN C E PO R T LO OP GU AR D CO M M AN D Format Mode Fun...

Page 131: ...tion mode This is shown in Table 167 TAB L E 167 SET ST P IN S T AN C E TR U N K ROO T GU AR D CO M M AN D Format Mode Function set stp instance 0 15 trunk trunkname root guard enable disable Global config This sets trunk root guard of the instance Result This sets trunk root guard of the instance 22 To set trunk loop of the instance use command set stp instance 0 15 trunk trunkname loop guard ena...

Page 132: ...ble STP port use command set stp port portlist enable disable in global configuration mode This is shown in Table 171 TAB L E 171 SET ST P PO R T CO M M AN D Format Mode Function set stp port portlist enable disable Global config This enable disable stp port Result This enable disable STP port 26 To set port s link type of the instance use command set stp port portlist linktype point point shared ...

Page 133: ...type Result This checks STP port protocol type 29 To set BPDU guard use command set stp port portlist bpdu guard enable disable in global configuration mode This is shown in Table 175 TAB L E 175 SET ST P PO R T BP D U GU AR D CO M M AN D Format Mode Function set stp port portlist bpdu guard enable disable Global config This sets BPDU guard Result This sets BPDU guard 30 To set STP BPDU guard inte...

Page 134: ...runk trunklist enable disable in global configuration mode This is shown in Table 179 TAB L E 179 SET ST P TR U NK CO M M AN D Format Mode Function set stp trunk trunklist enable disable Global config This enable disable stp trunk Result This enable disable STP trunk 34 To set trunk s link type of the instance use command set stp trunk trunklist linktype point point shared in global configuration ...

Page 135: ...ion Result This displays stp information ii To display stp instance information use command show stp instance 0 15 in global configuration mode This is shown in Table 183 TAB L E 183 SH O W ST P IN S TAN C E CO M M AN D Format Mode Function show stp instance 0 15 Global config This displays stp instance information Result This displays stp instance information iii To display stp port information u...

Page 136: ...lt This displays stp relay information END OF STEPS STP has been configured The following is an example of MSTP configuration Create instance 1 set up mapping relations with VLANs 10 to 20 and set the name as zte The MST version is 10 zte cfg set stp instance 1 add vlan 10 20 zte cfg set stp name zte zte cfg set stp revision 10 zte cfg show stp The spanning_tree protocol is enabled The STP ForceVe...

Page 137: ...dgeID Priority 32768 Address 00 d0 d0 ff ff 0a HelloTime s 2 MaxAge s 20 ForwardDelay s 15 MaxHops 20 Interface PortId Cost Status Role Bound GuardStatus 2 128 2 200000 Discard Designated MSTP None zte cfg show stp instance 1 RootID Priority 1 Address 00 d0 d0 ff ff 0a HelloTime s 2 MaxAge s 20 ForwardDelay s 15 RemainHops 20 BridgeID Priority 1 Address 00 d0 d0 ff ff 0a HelloTime s 2 MaxAge s 20 ...

Page 138: ... in an access list one by one The first match determines whether the switch accepts or rejects the packets because the switch stops testing conditions after the first match The order of conditions in the list is critical If no conditions match the switch rejects the packets If there are no restrictions the switch forwards the packet otherwise the switch drops the packet Packet matching rules defin...

Page 139: ...ort number TCP destination port number UDP source port number UDP destination port number ICMP type ICMP Code DiffServ Code Point DSCP ToS and Precedence L2 ACL Match source MAC address destination MAC address source VLAN ID L2 Ethernet protocol type and 802 1p priority value Hybrid ACL Match the following items f source IP address destination IP address IP protocol type TCP source port number TCP...

Page 140: ...g steps 1 To enter into basic ACL configuration use command config acl basic number acl number in global configuration mode This is shown in Table 188 TAB L E 188 ACL BAS I C NU M B E R COM M AN D Format Mode Function config acl basic number acl number global config This enters into basic ACL configuration mode Result This enters into basic ACL configuration mode 2 To configure the rules of ACL us...

Page 141: ...s configures extended ACL 2 To configure the rules of ACL use command rule rule_id permit deny ip protocol ip tcp udp icmp arp source ipaddr wildcard any source port sourceport mask destination ipaddr wildcard any dest port destport mask established esblishing icmp type icmp code dscp fragment in ACL config mode This is shown in Table 191 TAB L E 191 RU L E COM M AN D Format Mode Function rule rul...

Page 142: ...nters into L2 ACL configuration mode 2 To configure the rules of ACL use command rule rule id permit deny ip arp other any ether type protocol number dsap ssap cos source vlanid source mac wildcard any destination mac wildcard any in ACL config mode This is shown in Table 193 TAB L E 193 RU L E COM M AN D Format Mode Function rule rule id permit deny ip arp other any ether type protocol number dsa...

Page 143: ...sourceport mask destination ipaddr wildcard any dest port destport mask dscp fragment ether type proto number cos source vlanId source mac wildcard any destination mac wildcard any in ACL config mode This is shown in TAB L E 195 RU L E COM M AN D Format Mode Function rule rule id permit deny ip protocol ip tcp udp arp source ipaddr wildcard any source port sourceport mask destination ipaddr wildca...

Page 144: ...ort port id any ip protocol ip tcp udp arp any source ipaddr wildcard any source port sourceport mask destination ipaddr wildcard any dest port destport mask dscp fragment ether type proto number cos source vlanId source mac wildcard any destination mac wildcard any in ACL config mode This is shown in Table 197 TAB L E 197 RU L E COM M AN D Format Mode Function rule rule id permit deny port port i...

Page 145: ...solute start time to end time daily day off day working monday tuesday wednesday thursday friday saturday sunday global config This configures time range Result This configures time range f Configuration of time range per day Specify the start time and end time per day f Configuration of period range Specify the period as a date every week f Configuration of date range Specify the start time and e...

Page 146: ...rrent bound when you want to bind a new one in the case that an old one has applied to the physical port otherwise a false message will return END OF STEPS ACL has been configured to a physical port Quality of Service QoS ZXR10 2920 2928 2952 provides QoS function and priority control function Priority of the data packets can be determined by source MAC address priority of the data packets VLAN pr...

Page 147: ...ured if the switch receives the data frames the data frames with higher priority can be transmitted first to ensure the key applications Configuring QoS This topic describes the configuration of QoS including the data packet priority For the configuration of QoS perform the following steps 1 To set the mapping of the user priority to traffic class use command set qos priority map user priority 0 7...

Page 148: ...res global queue schedule profile 4 To configure the parameters of the flux monitor use command set qos policer counter mode L1 L2 L3 in global configuration mode This is shown in Table 203 TAB L E 203 SET QO S PO L I C ER PAR AM E T E R S COM M AN D Format Mode Function set qos policer counter mode L1 L2 L3 global config This configures the parameters of flux monitor Result This configures the pa...

Page 149: ...t Mode Function set qos policer 0 255 counter 0 15 enable disable global config This configures the overspeed disposol of flux monitor Result This configures the overspeed disposal of flux monitor 8 To configure the ingress session rate of the flux monitor use command set bandwidth feport portlist ingress session 0 3 rate 64 100000 in global configuration mode This is shown in Table 203 TAB L E 20...

Page 150: ...itor use command set bandwidth feport portlist ingress session 0 3 packet type unknowmulticast broadcast unicast multicast MGMT ARP tcp control tcp data udp non tcpudp enable disable in global configuration mode This is shown in Table 203 TAB L E 209 SET QO S PO L I C ER PAR AM E T E R S COM M AN D Format Mode Function set bandwidth feport portlist ingress session 0 3 queue priority queuelist enab...

Page 151: ...OM M AN D Format Mode Function set bandwidth feport portlist ingress session 0 3 enable disable global config This configures the ingress session mgmt no ratelimit Result This configures the ingress session of flux monitor 13 To configure the egress session of the flux monitor use command set bandwidth feport portlist egress on rate 64 1000000 off in global configuration mode This is shown in Tabl...

Page 152: ...rtlist ingress on rate 2000 1000000 off global config This configures the geport ingress session Result This configures the geport ingress session of flux monitor 15 To configure the geport egress session of the flux monitor use command set bandwidth geport portlist egress on rate 281 1000000 burstsize 4 16380 off in global configuration mode This is shown in Table 203 TAB L E 215 SET QO S PO L I ...

Page 153: ...7 SET PO L I C Y VL AN REM AR K CO M M AN D Format Mode Function set policy vlan remark in acl 1 349 rule 1 500 1 4094 untagged tagged all nested replaced global config This remarks the VLAN Result This remarks the VLAN 18 To bind the rule of flux monitor use command set policy policing in acl 1 350 rule 1 500 policer 0 255 in global configuration mode This is shown in TAB L E 218 SET PO L I C Y P...

Page 154: ... E 220 SET PO L I C Y RE DI R E C T COM M AN D Format Mode Function set policy redirect in acl 1 349 rule 1 500 cpu port portname global config This redirects the data flow Result This redirects the data flow 21 To set policy statistics use command set policy statistics in acl 1 349 rule 1 500 counter 0 31 in global configuration mode This is shown in Table 222 TAB L E 221 SET PO L I C Y QO S RE M...

Page 155: ...affic use command clear policy mirror in acl 1 349 rule 1 100 in global configuration mode This is shown in Table 224 TAB L E 224 CLE AR PO L I C Y MI R R O R COM M AN D Format Mode Function clear policy mirror in acl 1 349 rule 1 100 global config This deletes mirror for the traffic Result This deletes mirror for the traffic 25 To delete Vlan remark for the traffic use command clear policy vlan r...

Page 156: ...28 To clear statistics for the traffic use command clear policy statistics in acl 1 349 rule 1 100 in global configuration mode This is shown in Table 228 TAB L E 228 CLE AR PO L I C Y ST AT I S T I C S COM M AN D Format Mode Function clear policy statistics in acl 1 349 rule 1 100 global config This clears statistics for the traffic Result This clears statistics for the traffic 29 To clear redire...

Page 157: ...iews queue schedule profile Result This views user priority to the QoS profiles mapping session 5 To view qos queue schedule use command show qos queue schedule wrr0 sp wrr1 sp wrr2 sp in global configuration mode This is shown in Table 233 TAB L E 232 SH O W QO S PO LI C E R COM M AN D Format Mode Function show qos queue schedule wrr0 sp wrr1 sp wrr2 sp global config This views qos policer Result...

Page 158: ...N D Format Mode Function show policy mirror redirect qos remark vlan remark statistic policing 0 255 global config This views policy for traffic Result This views policy for traffic END OF STEPS QoS including data packet priority has been configured This example shows overall situation of QoS profile Value is TC 5 DP 1 UP 5 DSCP 33 zte cfg set qos profile 66 tc 5 dp 1 up 5 dsc 33 zte cfg show qos ...

Page 159: ... sdwrr 1 15 7 sdwrr 1 20 Private Virtual LAN Overview Packets of different users are separated to improve network security A VLAN can be allocated to each user This has its limits Current IEEE 802 1Q standard supports up to 4094 VLANs which restrict the user capacity and network expansion Each VLAN corresponds to an IP subnet which leads to waste of IP address resources Planning and management of ...

Page 160: ... 1 4 add promiscuous port portid trunk trunkid isolate port portlist trunk trunklist in global configuration mode This is shown in Table 236 TAB L E 236 SE T PVLAN SE S S I O N COM M AN D Format Mode Function set pvlan session 1 4 add promiscuous port portid trunk trunkid isolate port portlist trunk trunklist global config This configures isolate ports and promiscuous ports of PVLAN Result This co...

Page 161: ...rts trunk in the PVLAN 4 To clear PVLAN session use command set pvlan session 1 4 clear config in global configuration mode This is shown in Table 239 TAB L E 239 SET PVLAN SE S S I O N CL E AR CO M M AN D Format Mode Function set pvlan session 1 4 clear config global config This clears PVLAN session Result This clears PVLAN session 5 To view PVLAN use command show pvlan in global configuration mo...

Page 162: ...tion zte cfg set pvlan session 1 add promis port 16 isolate port 1 3 zte cfg show pvlan pvlan session 1 promiscuous port 16 isolated port 1 3 isolated trunk pvlan session 2 promiscuous port isolated port isolated trunk pvlan session 3 promiscuous port isolated port isolated trunk pvlan session 4 promiscuous port isolated port isolated trunk zte cfg In PLVAN 2 session add trunk 16 with isolation po...

Page 163: ...vlan session 4 promiscuous port isolated port isolated trunk zte cfg 802 1x Transparent Transmission IEEE 802 1x is a port based network access control protocol Port based network access control is a way to authenticate and authorize the users connected to the LAN equipment This type of authentication provides a point to pint subscriber identification method in the LAN ZXR10 2920 2928 2952 provide...

Page 164: ...the 802 1x transparent transmission function Result This enable disable the 802 1x transparent transmission function 2 To display the configuration of 802 1x transparent transmission use command show 802 1xrelay in global configuration mode This is shown in Table 242 TAB L E 242 SH O W 802 1X RE L AY CO M M AN D Format Mode Function show 802 1xrelay global config This displays the configuration of...

Page 165: ...rk and MAC address When sending IP packets switch first checks whether destination IP address is in the same network segment If yes switch checks whether there is a peer end IP address and MAC address mapping entry in ARP table If yes switch directly sends the IP packets to this MAC address If MAC address corresponding to peer end IP address cannot be found in ARP table an ARP Request broadcast pa...

Page 166: ...ss of layer 3 port use command set ipport 0 63 mac xx xx xx xx xx xx in router config mode This is shown in Table 245 TAB L E 245 SET IP P O R T MAC C OM M AN D Format Mode Function set ipport 0 63 mac xx xx xx xx xx xx router config This sets the MAC address of layer 3 port Result This sets the MAC address of layer 3 port 4 To enable disable the layer 3 port use command set ipport 0 63 enable dis...

Page 167: ...er set ipport 1 ipaddress 192 1 1 1 24 zte cfg router set ipport 1 vlan 100 zte cfg router set ipport 1 enable zte cfg router exit zte cfg After the configuration is completed use command show ippor to view the IP port configuration Static Route Configuration After an IP port is configured if the remote user to be connected is not in the network segment of the interface use command iproute A B C D...

Page 168: ...the result zte cfg router show iproute Type IpAddress Mask Gateway Metric IPport direct 192 1 1 0 255 255 252 0 192 1 1 1 0 0 static 192 1 2 0 255 255 255 0 192 1 1 2 0 0 Total 2 Use command clear iproute to delete one or more static routes Configuring ARP Table Entry This topic describes the configuration of ARP table entry For the configuration of ARP table entry perform the following steps 1 To...

Page 169: ...letes static ARP table entry 4 To delete the ipport configuration use command clear ipport 0 63 mac ipaddress A B C D M A B C D A B C D vlan vlanname in router config mode This is shown in Table 250 TAB L E 250 AR P IP P O R T TIM E O UT COM M AN D Format Mode Function arp ipport 0 63 timeout 1 1000 router config This sets ARP table entry aging time of the IP port Result This deletes the ipport co...

Page 170: ... AN D Format Mode Function show arp static dynamic invalid ipport 0 63 static dynamic invalid ipaddress A B C D router config This views ARP table entries Result This views ARP table entries 8 To view ARP info use command show arp static dynamic invalid ipport 0 63 static dynamic invalid ipaddress A B C D in router config mode This is shown in Table 253 TAB L E 254 SH O W AR P CO M M AN D Format M...

Page 171: ...0 To view ARP info use command show arp iproute in router config mode This is shown in Table 253 TAB L E 256 SH O W AR P CO M M AN D Format Mode Function show arp iproute router config This views ARP table entries Result This views ARP iproute END OF STEPS ARP table entry has been configured Result ...

Page 172: ...ZXR10 2920 2928 2952 V1 0 Access Switch User Manual Volume I 158 Confidential and Proprietary Information of ZTE CORPORATION This page is intentionally blank ...

Page 173: ...ugh this client software To support the port based network access control client system must support Extensible Authentication Protocol Over LAN EAPOL Authentication system is generally network equipment that supports IEEE802 1x protocol for example switch Corresponding to ports of different subscribers ports could be physical ports or MAC address VLAN or IP address of user equipment Authenticatio...

Page 174: ...urned by the server Radius Authentication Server is responsible for receiving subscriber connection request verifying the subscriber identity and returning the configuration information required by the customer A Radius Authentication Server can serve as a RADIUS customer proxy to connect to another Radius Authentication Server Radius Accounting Server is responsible for receiving the subscriber b...

Page 175: ...ection setup Successful access RADIUS server CHAP is an encrypted authentication mode and avoids transmission of user s real password upon the setup of connection NAS sends a randomly generated Challenge string to user User encrypts Challenge string by using own password and MD5 algorithm and returns username and encrypted Challenge string encrypted password Server uses user password it stores and...

Page 176: ...hat transparently transmits EAP packets It includes EAP MD5 and PEAP The following example explains EAP MD5 EAP MD5 is a CHAP identity authentication mechanism used in the EAP framework structure Process of using the EAP MD5 mode for identity authentication is shown in FI G U R E 32 USI N G EAP M D 5 MO D E FO R IDE N T I T Y AU T H E N T I C AT I O N EAPOL RADIUS EAPOL Start EAP Request Identity ...

Page 177: ...ed in nas config mode This is shown in Table 258 TAB L E 258 AAA CO N T R O L PO R T MO DE CO M M AN D Format Mode Function aaa control port portlist port mode auto force unauthorized force authorized nas config This configures the authentication control mode of the port Result This configures the authentication control mode of the port Note The available modes include f Auto Subscriber access fro...

Page 178: ... config This set the maximum number of subscribers connected through port Result This sets the maximum number of subscribers connected through port Note A port can allow access of multiple subscribers and each subscriber has own independent authentication and billing processes The aaa control port max hosts command is valid only when the port allows access of multiple subscribers 5 To enable disab...

Page 179: ...own in Table 263 TAB L E 263 AAA CO N T R O L P O R T KE E P AL I V E C OM M AN D Format Mode Function aaa control port portlist keepalive enable disable nas config This enable disable abnormal off line detection mechanism of the port Result This enable disable abnormal off line detection mechanism of the port 8 To set the abnormal off line detection period of the port use command aaa control port...

Page 180: ...265 AAA CO N T R O L PR O T O C O L CO M M AN D Format Mode Function aaa control port portlist protocol pap chap eap nas config This sets authentication mode for the port Result This sets authentication mode for port Note During the subscriber access authentication there are three subscriber identity authentication methods between the authentication server and the authentication system PAP CHAP an...

Page 181: ... period 0 65535 nas config This set time that authentication system needs to wait before it can resend EAPOL data packet Result This set time that authentication system needs to wait before it can resend EAPOL data packet 3 To set timeout time for authentication system to receive data packets from authentication client system use command dot1x supplicant timeout 1 65535 in nas config mode This is ...

Page 182: ... receives Challenge response from client Result This set maximum time of request resending when timer expires before authentication system receives Challenge response from client Note 802 1x realizes the access control by exchanging EAPOL data packets between client system and authentication system and RADIUS data packets between authentication system and authentication server During exchange of d...

Page 183: ... 802 1x protocol parameters use command show dot1x in nas config mode This is shown in Table 272 TAB L E 272 SH O W DO T 1X CO M M AN D Format Mode Function show dot1x nas config This displays the 802 1x protocol parameters Result This displays the 802 1x protocol parameters END OF STEPS Protocol parameters or 802 1x has been configured on ZXR10 2920 2928 2952 Configuring RADIUS This topic describ...

Page 184: ... AT I O N CO M M AN D Format Mode Function radius isp ispname add authentication A B C D 0 65535 nas config This add authentication server to domain Result This add authentication server to domain 3 To delete the authentication server from domain use command radius isp ispname delete authentication A B C D in nas config mode This is shown in Table 275 TAB L E 275 RAD I U S IS P DEL E T E AU T H E ...

Page 185: ... accounting server from the domain Note A domain can be configured with up to three accounting servers Priority of the server is determined by configuration order First server configured enjoys highest priority and last server has lowest priority When a server is deleted priorities of the related servers rise in sequence 6 To set the IP address of the client in the domain use command radius isp is...

Page 186: ...t domain Result This specifies a default domain Note Only one domain can be specified as default domain in system System will send subscriber authentication requests without domain name specified on RADIUS authentication server in default domain 9 To set full account of domain use command radius isp ispname fullaccount enable disable in nas config mode This is shown in Table 281 TAB L E 281 RAD I ...

Page 187: ...i To set number of retransmissions upon server response timeout use command radius retransmit 1 255 in nas config mode This is shown in Table 284 TAB L E 284 RAD I U S RE T R AN S M I T COM M AN D Format Mode Function radius retransmit 1 255 nas config This sets number of retransmission upon server response timeout Result This sets number of retransmission upon server response timeout iii To set N...

Page 188: ...ession id session id user name user name isp name isp name server ip A B C D nas config This deletes accounting of packet Result This deletes accounting of packet 14 To display RADIUS configuration use command show radius ispName ispname accounting stop session id session id user name user name isp name isp name server ip A B C D in nas config mode This is shown in Table 288 TAB L E 288 SH O W RAD...

Page 189: ...as dot1x server timeout 30 zte cfg nas aaa control port 1 keepalive enable zte cfg nas aaa control port 1 keepalive period 10 zte cfg nas show aaa control 1 PortId 1 PortControl auto Dot1x enabled AuthenticationProtocol eap KeepAlive enabled KeepAlivePeriod 10 Accounting disabled MultipleHosts disabled MaxHosts 0 HistoryHostsTotal 0 OnlineHosts 0 zte cfg nas show dot1x TxPeriod 30 QuietPeriod 60 S...

Page 190: ...imum number of subscriber accessed is 5 zte cfg nas aaa control port 1 port mode auto zte cfg nas aaa control port 1 protocol chap zte cfg nas aaa control port 1 multiple hosts enable zte cfg nas aaa control port 1 max hosts 5 zte cfg nas show aaa control 1 PortId 1 PortControl auto Dot1x enabled AuthenticationProtocol chap KeepAlive enabled KeepAlivePeriod 10 Accounting disabled MultipleHosts ena...

Page 191: ...56 Authentication servers Auth port 10 40 92 212 1812 10 40 92 215 1812 Accounting servers Acct port 10 40 92 215 1813 10 40 92 212 1813 zte cfg nas QinQ Overview QinQ is IEEE 802 1Q tunneling protocol and is also called VLAN stacking QinQ technology is the addition of one more VLAN tag outer tag to the original VLAN tag inner tag Outer tag can shield the inner tag QinQ does not need protocol supp...

Page 192: ... VLAN tag or not Packet is forwarded by VLAN 10 which is determined by the PVID Uplink port of switch A inserts outer tag VLAN ID 10 when forwarding data packet received from customer port Tpid of this tag can be configured on switch Inside ISP network packet is broadcast along port of VLAN 10 until it reaches switch B Switch B finds out that port connected to user network 2 is a customer port Thu...

Page 193: ...qinq tpid tpid in global configuration mode This is shown in Table 291 TAB L E 291 SET QI N Q TP I D CO M M AN D Format Mode Function set qinq tpid tpid global config This set tpid of the outer tag Result This set tpid of the outer tag 4 To display QinQ configuration use command show qinq in global configuration mode This is shown in Table 292 TAB L E 292 SH O W QI N Q CO M M AN D Format Mode Func...

Page 194: ...ifferent Service Provider s VLAN tags for packets Packets are transmitted in Service Provider Network Vlan Tags of Service Provider would be strip off when packets leave Service Provider Vlan SQinQ configuration is determined as per following conditions Normally a set of Customer Vlans is set in one Uplink Port Several sets of Customer Vlans can be in one Uplink Port when it is confirmed that all ...

Page 195: ...use command set sqinq session 1 256 customer vlan vlanlist uplink vlan 1 4094 in global configuration mode This is shown in Table 293 TAB L E 293 SET SQI N Q SE SS I O N COM M AN D Format Mode Function set sqinq session 1 256 customer vlan vlanlist uplink vlan 1 4094 global config This configures SQinQ session Result This configures SQinQ session 2 To set Qos remark use command set policy qos rema...

Page 196: ...ode Function set policy policing in sqinq session 1 256 policer 0 255 global config This monitors traffic Result This monitors traffic 5 To clear traffic monitor use command clear policy policing in sqinq session 1 256 in global configuration mode This is shown in Table 297 TAB L E 297 CLE AR PO L I C Y PO L I C I N G COM M AN D Format Mode Function clear policy policing in sqinq session 1 256 glo...

Page 197: ...atistics in sqinq session 1 256 counter 0 31 global config This sets policy of statistics Result This sets policy of statistics 9 To clear policy of statistics use command clear policy statistics in sqinq session 1 256 in global configuration mode This is shown in Table 301 TAB L E 301 CLE AR PO L I C Y ST AT I S T I C S COM M AN D Format Mode Function clear policy statistics in sqinq session 1 25...

Page 198: ...nQ strategy policy has been configured This example describes that there are two switches of ZXR10 5124 Switch A and Switch B in Service Provider Network Port 24 of Switch A is connected to port 24 of Switch B Vlan1 200 is in port 1 through 6 of Switch A which communicate with port 1 through 3 of Switch B in which Uplink vlanid assigned as 100 Vlan201 4094 is in port 1 through 6 of Switch A which ...

Page 199: ...rnet switch It is the information center of system software module Syslog manages and classify most output information so that the information can be filtered effectively to support network manager and developer monitoring network running circumstance and diagnosing network fault Syslog log system classifies log information to eight levels according to the Levels This is shown in Table 324 TAB L E...

Page 200: ...iguration mode This is shown in Table 307 TAB L E 307 SET SY S L O G LE VE L COM M AN D Format Mode Function set syslog level global config This defines syslog information level Result This defines syslog information level Note Default level of syslog information is informational If level of syslog information is configured to emergencies the information will be sent firstly 3 To setup syslog info...

Page 201: ...gured on ZXR10 2920 2928 2952 In this example syslog in switch is enabled level of information is informational and all functional modules are enabled IP address of server is 192 168 1 1 and name of server is Srv1 Configuration zte cfg set syslog level informational zte cfg set syslog add server 1 ipaddress 192 168 1 1 name Srv1 zte cfg set syslog module all enable zte cfg set syslog enable zte cf...

Page 202: ...p server in global configuration mode This is shown in Table 312 TAB L E 312 SET NT P SER V E R CO M M AN D Format Mode Function set ntp server global config This setups NTP server IP address Result This setups NTP server IP address Note At present only one NTP server can be configured If several NTP servers are configured the latter will cover the former 3 To configure source IP address which is ...

Page 203: ...g show ntp ntp protocol is enable ntp protocol version 3 ntp server address 202 10 10 10 ntp source address None ntp is_synchronized No ntp rcv stratum 16 no reference clock zte cfg In the output ntp is_synchronized represents whether switch has synchronized time with NTP server GARP GVRP Overview GARP Generic Attribute Registration Protocol uses different protocols to dynamically distribute attri...

Page 204: ...mmand set garp timer hold join leave leaveall timer_value in global configuration mode This is shown in Table 316 TAB L E 316 SET GAR P TI M E R CO M M AN D Format Mode Function set garp timer hold join leave leaveall timer_value global config This sets timer of GARP Result This sets timer of GARP Note There are four kinds of timer including hold timer join timer leave timer and leave all timer 3 ...

Page 205: ...V R P PO R T CO M M AN D Format Mode Function set gvrp port portlist enable disable global config This enable disable GVRP in port Result This enable disable GVRP in port Note By default GVRP in port is disabled After enabling GVRP in port the port can receive packets of GVRP protocol 3 To configure type of GVRP registration in port use command set gvrp port portlist registration normal fixed forb...

Page 206: ...et gvrp trunk trunklist enable disable global config This enable disable GVRP in trunk port Result This enable disable GVRP in trunk port Note By default GVRP in trunk port is disabled After enabling GVRP in trunk port the port can receive packets of GVRP protocol 5 To configure trunk port and GVRP registration type use command set gvrp trunk trunklist registration normal fixed forbidden in global...

Page 207: ...e cfg set garp timer leaveall 10000 In this example show GARP configuration status zte cfg show garp GARP is enabled GARP Timers Hold Timeout 100 millisecond Join Timeout 200 millisecond Leave Timeout 600 millisecond LeaveAll Timeout 10000 millisecond In this example enable disable GVRP enable disable GVRP in port and configure type of registration in port zte cfg set gvrp enable zte cfg set gvrp ...

Page 208: ...s interact in broadcasting way and course is transparent There is no authentication between DHCP server and client There may be DHCP servers that establish a private and illegal way which causes confusion to part of the hosts of their address distribution gateway and DNS parameters and make it impossible for the hosts to connect to the external network There will be IP deceiving MAC address deceiv...

Page 209: ...tion and request DHCP packets sent by users will add Option82 according to user configurations It makes it possible for hosts to interact with more special information with DHCP Server Using Circuit ID sub option switch provides user access link information which is good for server to distribute and manage address Server limits the amount of user IP address that distributed to each Remote ID label...

Page 210: ...onfigures DHCP attribute of port Result This configures DHCP attribute of port Important There are three kinds of attributes of the port server port connecting to DHCP server cascade cascade connecting port client port connecting to client Attribute is client by default 3 To display DHCP information and attribute of the ports use command show dhcp in global configuration mode This is shown in Tabl...

Page 211: ...ction based on port Note DHCP snooping function is disabled by default This command is to enable or disable DHCP Snooping function on port Only in the condition that the global DHCP function is enabled can this function be enabled DHCP function on the ports connecting to user and that connecting to server should be enabled at same time 2 To display DHCP Snooping configurations use command show dhc...

Page 212: ...E AR DH C P SNP BI N D COM M AN D Format Mode Function clear dhcp snp bind entry all port portname mac xx xx xx xx xx xx global config This clears information of DHCP Snooping dynamic binding table item Result This clears information of DHCP Snooping dynamic binding table item Important There are three kinds of modes to clear information of DHCP Snooping dynamic binding table item clear all based ...

Page 213: ...H O W DH C P IP SO U R C E GU AR D COM M AN D Format Mode Function show dhcp ip source guard global config This displays IP source guard configuration Result This displays IP source guard configuration END OF STEPS IP source guard has been configured on ZXR10 2920 2928 2952 Configuring DHCP Option82 This topic describes the Option82 configuration on ZXR10 2920 2928 2952 For the configuration of Op...

Page 214: ...is is shown in Table 335 TAB L E 335 SET DH C P OP T I ON 82 SU B OP T IO N COM M AN D Format Mode Function set dhcp option82 sub option port portname circuit ID on cisco china tel dsl forum off global config This enable disable DHCP Option82 Circuit_ID sub option based on port Result This enable disable DHCP Option82 Circuit_ID sub option based on port Important ZXR10 2920 2928 2952 supports thre...

Page 215: ...s three forms Remote_ID is enabled by default and does not need to configure it Besides switches support a sub option which uses in expanding 6 To display DHCP Option82 configuration information use command show dhcp Option82 in global configuration mode This is shown in Table 338 TAB L E 338 SH O W DH C P OPT I O N 82 COM M AN D Format Mode Function show dhcp Option82 global config This displays ...

Page 216: ...iguration mode This is shown in Table 341 TAB L E 341 CLE AR DH C P OP T I O N 82 AN I CO M M AN D Format Mode Function clear dhcp Option82 ani global config This clears configuration of DHCP Option82 access node identifier Result This clears configuration of DHCP Option82 access node identifier END OF STEPS Option82 has been configured on ZXR10 2920 2928 2952 This example shows the following inst...

Page 217: ...nt 7 Client 8 Client 24 Cascade zte cfg The following instance shows DHCP Option82 configuration zte cfg set dhcp option82 add port 1 8 24 zte cfg set dhcp option82 delete port 5 zte cfg set dhcp option82 ani nanjing68 zte cfg set dhcp option82 sub option port 7 circuit ID on china tel zte cfg set dhcp option82 sub option port 7 subscriber ID on yuhuatai The following instance shows DHCP Option82 ...

Page 218: ...ot physical equipment is a standard protocol which is developed by Guangdong Institute of China Telecom VBAS is to solve the problem of wideband user identifier When BAS gets user identifier by inquiring correspondence relationship of users MAC dialing to the switch and port then sends user name password and identifier information to RADIUS it can realize the position of the user Layer 2 communica...

Page 219: ...ion mode This is shown in Table 342 TAB L E 342 SET VB AS CO M M AN D Format Mode Function set vbas enable disable global config This enable disable global VBAS function Result This enable disable global VBAS function Note VBAS function is disabled by default This command is to enable disable VBAS globally 2 To enable disable trust port VBAS function use command set vbas trust port portlist enable...

Page 220: ...splay VBAS configuration use command show vbas in global configuration mode This is shown in Table 345 TAB L E 345 SH O W VB AS CO M M AN D Format Mode Function show vbas global config This displays VBAS configuration Result This displays VBAS configuration END OF STEPS VBAS has been configured This example describes how to trust port of switch A is port 1 cascade port is port 2 and trust port of ...

Page 221: ...ets information of current network Configuring sFlow This topic describes the configuration of sFlow on ZXR10 2920 2928 2952 5116 FI 5124 FI For the configuration of sFlow perform the following steps 1 To set proxy IP address of sFlow use command set sflow agent address A B C D in global configuration mode This is shown in Table 346 TAB L E 346 SET S FL O W AG E N T AD D R E S S CO M M AN D Format...

Page 222: ...000000 global config This enables sample flow function on port Result This enables sample function on port 4 To set ingress sample mode of sFlow function use command set sflow ingress sample mode forward good in global configuration mode This is shown in Table 349 TAB L E 349 SET S FL O W IN G RE S S COM M AN D Format Mode Function set sflow ingress sample mode forward good global config This sets...

Page 223: ... SET S FL O W CL EAR CO N F I G CO M M AN D Format Mode Function set sflow clear config global config This clear sFlow configurations Result This clears sFlow configurations END OF STEPS sFlow has been configured on ZXR10 2920 2928 2952 5116 FI 5124 FI In the following instance it shows configurations of IP addresses of sFlow proxy and collector and it enables the sample flow function on port 1 zt...

Page 224: ...nly needs to block a port in ring to avoid loop When link trouble occurs free the port from blocked to protect the service flow ZTE Ethernet Switching Ring supports fast convergence well when the topology of ring Ethernet link changes ZESR is a master switch in an annular network and others are transits Each switch has two port connected into ring and one of the port is designated as primary port ...

Page 225: ... L E 352 SET ZE S R DOM AI N COM M AN D Format Mode Function set zesr domain domainId mode master transit global config This sets node equipment mode n ZESR domain Result This sets node equipment mode in ZESR domain 2 To set primary port in ZESR domain use command set zesr domain domainId primary port portname in global configuration mode This is shown in Table 353 TAB L E 353 SET ZE S R DOM AI N ...

Page 226: ...R IM AR Y TR U N K COM M AN D Format Mode Function set zesr domain domainId primary trunk trunkname global config This sets primary trunk port in ZESR domain Result This sets primary trunk port in ZESR domain Note Set trunk port as primary port on switches in ZESR domain 5 To set secondary trunk port in ZESR domain use command set zesr domain domainId secondary trunk trunkname in global configurat...

Page 227: ...E 358 SET ZE S R DOM AI N AD D PR O T EC T VL AN CO M M AN D Format Mode Function set zesr domain domainId add protect_vlan vlanlist global config This add protect VLAN in ZESR domain Result This add protect VLAN in ZESR domain Note Add protect VLAN in ZESR domain Protect VLAN is the user data VLAN in the domains 8 To delete control VLAN in ZESR domain use command set zesr domain domainId delete c...

Page 228: ...ESR domains is disabled by default When enabling ZESR function parameters in domains should be set actually ZESR function can not be enabled if parameter is not integrated meanwhile ZESR control VLAN should be enabled by users and add ports in the ring as Tagged ports into control VLAN To distinguish with STP function ports in ZESR ring are not managed by STP Before ZESR function is enabled STP fu...

Page 229: ...ion in all ZESR domains Note This command displays configuration in all ZESR domains END OF STEPS ZESR has been configured This example describes instance configuration in ZESR domain zte cfg set zesr domain 2 mode transit zte cfg set zesr domain 2 primary port 5 zte cfg set zesr domain 2 secondary port 6 zte cfg set zesr domain 2 add control_vlan 100 zte cfg set zesr domain 2 add protect_vlan 110...

Page 230: ...port T1 Port state Forward Secondary port T2 Port state Forward ZESR Domain Control Vlan 100 ZESR Domain protected vlan 110 115 In the following instance it shows the information of the enabled transit zte cfg show zesr domain 1 ZESR domains 1 Ring state Down Domain enabled Yes Node mode Transit Primary port 3 Port state Forward Secondary port 4 Port state Forward ZESR Domain Control Vlan 10 ZESR ...

Page 231: ...Configuring Remote Access 219 Remote Access Configuration Examples 220 SSH Overview 221 Configuring SSH 222 Configuring SSH v2 0 223 SNMP Overview 226 Configuring SNMP 227 RMON Overview 233 Configuring RMON 234 Cluster Management Overview 241 Configuring a ZDP 243 Configuring ZTP 245 Configuring Cluster 249 Configuring a Cluster Member 250 Configuring Cluster Parameters 251 Configuring Access and ...

Page 232: ... System 264 Configuring Port and Parameters 265 Configuring Vlan Management 270 Configuring PVLAN 273 Configuring Mirroring Management 275 Configuring LACP Management 278 Configuring Terminal Record 281 Configuring Port Statistics 282 Configuring 283 Saving Configuration 284 Rebooting an Equipment 285 Uploading a File 286 Configuring User Management 288 ...

Page 233: ...wing steps 1 To enable disable restrictive remote access use command set remote access any specific in global configuration mode This is shown in Table 365 TAB L E 365 SET REM O T E AC C E S S COM M AN D Format Mode Function set remote access any specific global config This enable disable restrictive remote access Result This enable disable restrictive remote access Note By default restrictive acc...

Page 234: ...AD D R E S S COM M AN D Format Mode Function clear remote access ipaddress A B C D A B C D global config This deletes an IP address that allows remote access Result This deletes an IP address that allows remote access 5 To display Remote Access configuration information use command show remote access in global configuration mode This is shown in Table 369 TAB L E 369 SH O W REM O T E AC C E S S CO...

Page 235: ...k management user to access switch from any IP address through Telnet zte cfg set remote access any zte cfg show remote access Whether check remote manage address NO Allowable remote manage address list none zte cfg SSH Overview Secure shell SSH is a protocol created by Network Working Group of the IETF offers secure remote access and other secure network services over an insecure network Purpose ...

Page 236: ... shall be configured on the switch and the local host shall be able to ping the IP port address on the switch normally f This switch only supports SSH login of a single user allowing for three login attempts After three login attempts connection with the user is automatically terminated After user login set ssh disable command is to terminate connection with user and prohibit user from logging in ...

Page 237: ...figuration of the switch is as follows zte cfg creat user zte guest zte cfg loginpass zte zte cfg set ssh enable Configuring SSH v2 0 This topic describes the client using SSH v2 0 can configure free software Putty developed by Simon Tatham to access the switch For the configuration of SSH v2 0 perform the following steps 1 Set the IP address and port number of SSH Server as shown in Figure 38 Set...

Page 238: ...ccess Switch User Manual Volume I 224 Confidential and Proprietary Information of ZTE CORPORATION FI G U R E 38 SET T I N G IP AD D R E S S AN D PO R T NUM B E R OF SSH SE R V ER 2 Set the SSH version number as shown in Figure 39 ...

Page 239: ...ary Information of ZTE CORPORATION 225 FI G U R E 39 SET T I N G SSH VER S I O N NUM B ER 3 For the first time to log in user confirmation is needed as shown in Figure 40 FI G U R E 40 PUT T Y SE C U RI T Y AL E R T 4 SSH login result is shown in Figure 41 ...

Page 240: ...es devices to report problems and errors to network management stations Any network administrator can use SNMP to manage switches SNMP adopts the Management process Agent process model to monitor and control all types of managed network devices The SNMP network management needs three key elements Managed devices can communicate over the Internet Each device contains an agent The network management...

Page 241: ...rity use command create community in SNMP config mode This is shown in Table 372 TAB L E 372 CR E AT E CO M M UN I T Y COM M AN D Format Mode Function create community SNMP config This creates communication name and set access authority Result This creates communication name and set access authority f Community string offers a user confirmation mechanism for remote network administrators to config...

Page 242: ...correspond to one view but one view can correspond to multiple communities 4 To set group name and its security level use command set group in SNMP config mode This is shown in Table 375 TAB L E 375 SET GR O U P COM M AN D Format Mode Function set group SNMP config This sets group name and its security level Result This sets group name and its security level f There are three levels of group no au...

Page 243: ...t is changed configurations of primary engineID don t work any longer 7 To set the address community name and version of trap or inform host use command set host in SNMP config mode This is shown in Table 378 TAB L E 378 SET HO S T COM M AN D Format Mode Function set host SNMP config This sets address Result This set address community name and version of trap or inform host f Host is destination I...

Page 244: ...E AR VI E W COM M AN D Format Mode Function clear view SNMP config This deletes a view name Result This deletes a view name 11 To delete a group name use command clear group in SNMP config mode This is shown in Table 382 TAB L E 382 CLE AR GR O U P CO M M AN D Format Mode Function clear group SNMP config This deletes a group name Result This deletes a group name 12 To delete a user name use comman...

Page 245: ...his views SNMP configuration END OF STEPS SNMP has been configured This example describes basic configuration of SNMPv1 and SNMPv2c Suppose that IP address of network management server is 10 40 92 105 switch has a layer 3 port with IP address of 10 40 92 200 and switch is managed through network management server Create a community named zte with read write authority and view named vvv and then as...

Page 246: ... Level ViewName zte private vvv zte cfg snmp show snmp view ViewName Exc Inc MibFamily vvv Include 1 3 6 1 zte cfg snmp show snmp host HostIpAddress Comm User Version type SecurityLevel 10 40 92 77 zte Ver 1 Trap zte cfg snmp This example describes basic configuration of SNMPv3 Suppose that IP address of network management server is 10 40 92 77 switch has a layer 3 port with IP address of 10 40 92...

Page 247: ...nform v3 zteuser priv zte cfg snmp show snmp group groupName ztegroup secModel v3 readView zteView secLevel AuthAndPriv writeView zteView rowStatus Active notifyView zteView zte cfg snmp show snmp user UserName zteuser GroupName ztegroup v3 EngineID 830900020300010289d64401 AuthType Md5 StorageType NonVolatile EncryptType Des_Cbc RowStatus Active zte cfg snmp show snmp host HostIpAddress Comm User...

Page 248: ...hese data can be obtained through MIB browser RMON control information can be configured through MIB browser and a HyperTerminal or remote Telnet command line RMON sampling information and statistics are obtained through MIB browser Configuring RMON This topic describes the configuration of RMON through a HyperTerminal or remote Telnet For the configuration of RMON perform the following steps 1 To...

Page 249: ...r the port number 16 directly f historyControlBucketsRequested By default it is 50 f historyControlOwner f historyControlInterval By default it is 1 800 seconds f historyControlStatus It can be valid underCreation createRequest and invalid When it is set to invalid the instance is deleted The control status can be set to valid only when the data source is specified 3 To create configure instances ...

Page 250: ... type none log snmptrap logandtrap owner string community string status valid underCreation createRequest invalid SNMP config These create configure instances of the event group Result These create configure instances of the event group Command line configuration of event group is to configure eventTable in event group The configuration involves f eventDescription f eventType It can be none 1 log ...

Page 251: ...pled in the local mib for example for sampling the etherHistoryBroadcastPkts the variable value shall be 1 3 6 1 2 1 16 2 2 1 7 x x where x x indicates the sampling bucket of an instance of the history group f alarmSampleType The absolute indicates the absolute value and delta indicates the relative value f alarmStartupAlarm It can be risingAlarm 1 fallingAlarm 2 and risingOrFallingAlarm 3 which i...

Page 252: ... displays configuration information about history group show statistic SNMP config This displays configuration information about statistic group show event SNMP config This display configuration information about event group show alarm SNMP config This display configuration information about alarm group Result This displays RMON status history group statistics group event group and alarm group END...

Page 253: ...te cfg snmp set alarm 2 interval 10 zte cfg snmp set alarm 2 variable 1 3 6 1 2 1 16 2 2 1 6 2 1 zte cfg snmp set alarm 2 sample absolute zte cfg snmp set alarm 2 startup rising zte cfg snmp set alarm 2 threshold 8 eventindex 2 rising zte cfg snmp set alarm 2 threshold 15 eventindex 2 falling zte cfg snmp set alarm 2 owner zteNj zte cfg snmp set alarm 2 status valid zte cfg snmp set statistics 1 d...

Page 254: ...er zteNj zte cfg snmp Query configuration information about statistics 1 zte cfg snmp show statistics 1 StatsIndex 1 DropEvents 0 BroadcastPkts 0 Octets 0 MulticastPkts 0 Pkts 0 Pkts64Octets 0 Fragments 0 Pkts65to127Octets 0 Jabbers 0 Pkts128to255Octets 0 Collisions 0 Pkts256to511Octets 0 CRCAlignErrors 0 Pkts512to1023Octets 0 UndersizePkts 0 Pkts1024to1518Octets 0 OversizePkts 0 DataSource port 1...

Page 255: ...ber switches form a cluster private network It is recommended to isolate broadcast domain between public network and private network on the command switch and shield direct access to private address Command switch provides an external management and maintenance channel to manage cluster in a centralized manner In general broadcast domain where a cluster is located consists of switches in these rol...

Page 256: ...NT NE T W OR K Public network Independent switch Candidate switch NM console 110 1 1 1 TFTP Server 110 1 1 2 Command switch 100 1 1 10 Cluster internal network Member switch Member switch Member switch Member switch Member switch Outside the cluster Cluster internal address pool 192 168 1 0 24 Changeover rule of four roles of switches within a cluster is shown in ...

Page 257: ...ing adjacent device ID device type version and port information This protocol supports the refreshing and aging of neighbor device information table To configure cluster management function meet the following requirement To configure cluster management function use command config group to enter into cluster management configuration mode For the configuration of ZDP perform the following steps 1 To...

Page 258: ... ZDP function Important By default ZDP functions of all ports trunks are enabled When ZDP function of a port trunk is disabled contents of neighbor device information table of port trunk are cleared and ZDP packets processing is suspended Note A port trunk can collect and send ZDP information normally only when both ZDP function of port trunk and system ZDP function are enabled 4 To set time inter...

Page 259: ...our detail group config This displays neighbor device information table Result This displays neighbor device information table END OF STEPS ZDP has been configured Configuring ZTP Topology protocol ZTP is a protocol used to collect network topology information With neighbor device information table collected through ZDP ZTP sends and forwards ZTP topology collection packets through the relevant po...

Page 260: ...ction set ztp port portlist enable disable group config This enable disable port ZTP function Result This enable disable port ZTP function 3 To enable disable trunk ZTP function use command set ztp trunk trunklist enable disable in group config mode This is shown in Table 401 TAB L E 401 SET ZT P TR U N K CO M M AN D Format Mode Function set ztp trunk trunklist enable disable group config This ena...

Page 261: ... VLAN for collecting topology information is VLAN 1 and topology collecting range is four hops By default time interval for collecting topology information is 0 minute that is topology information is not collected periodically f When switch is configured to be a command switch VLAN for collecting topology information serves as management VLAN of command switch In this case it is not allowed to cha...

Page 262: ...mac in group config mode This is shown in Table 405 TAB L E 405 ZT P MAC CO M M AN D Format Mode Function show ztp mac group config This displays detail of specified device according to MAC address Result This displays detail of specified device according to MAC address 8 To display topology information table use command show ztp device idlist in group config mode This is shown in Table 406 TAB L ...

Page 263: ... in group config mode This is shown in Table 408 TAB L E 408 SET GR O U P IN D EP E N D E N T COM M AN D Format Mode Function set group independent group config This sets independent switches Result This sets independent switches 3 To set a command switch specify a layer 3 port number for cluster management and set IP address pool for user cluster management use command set group commander ipport ...

Page 264: ...he configuration of cluster member to add delete For the configuration of cluster member perform the following steps 1 To add a member based on device MAC address use command set group add mac xx xx xx in group config mode This is shown in Table 410 TAB L E 410 SET GR O U P AD D MAC CO M M AN D Format Mode Function set group add mac xx xx xx group config This adds a member based on device MAC addr...

Page 265: ...r idlist in group config mode This is shown in Table 413 TAB L E 413 SET GR O U P DE LE T E MEM B E R CO M M AN D Format Mode Function set group delete member idlist group config This deleted a device with specified member ID from cluster Result This deletes a device with specified member ID from cluster END OF STEPS Cluster member has been add delet When a device is added to cluster but member ID...

Page 266: ...r use command set group holdtime 1 300 in group config mode This is shown in Table 416 TAB L E 416 SET GR O U P HO LD T IM E COM M AN D Format Mode Function set group holdtime 1 300 group config This sets effective holding time of information about switches in cluster Result This sets effective holding time of information about switches in cluster 4 To set IP address of internal public SYSLOG Serv...

Page 267: ...ered after effective holding time command switch displays that member is in DOWN state After communication is recovered member is added to cluster automatically and is displayed in UP status If IP address of TFTP Server of cluster is configured member switch can access TFTP Server by directly accessing command switch Configuring Access and Control Cluster Members This topic describes the configura...

Page 268: ...P COM M AN D E R COM M AN D Format Mode Function tftp commander download upload name privileged mode This download upload version through TFTP on command switch Result This download upload version through TFTP on command switch 4 To save configuration of specified member switch use command save member idlist all in privileged mode This is shown in Table 422 TAB L E 422 SAV E ME M B E R CO M M AN D...

Page 269: ...iguration This topic describes the display of cluster configuration and cluster member information For the display of cluster configuration perform the following steps 1 To display cluster configuration information use command show group in global config mode This is shown in Table 425 TAB L E 425 SH O W GR O U P CO M M AN D Format Mode Function show group global config This displays cluster confi...

Page 270: ...ation has been displayed This example describes the initial configuration of switches is default configuration Set the VLAN where public network IP address of command switch in cluster is located to 2525 IP address to 100 1 1 10 24 gateway address to 100 1 1 1 cluster management VLAN to 4000 private address pool to 192 168 1 0 24 and IP address of TFTP Server of whole cluster to 110 1 1 2 This is ...

Page 271: ...Chapter 9 Network Management Confidential and Proprietary Information of ZTE CORPORATION 257 Create a cluster on layer 3 port 1 of command switch and VLAN 1 default VLAN ...

Page 272: ... candi ZXR10 5116 FI 3 00 d0 d0 fc 08 fa 1 candi ZXR10 5116 4 00 d0 d0 fc 08 d5 1 candi ZXR10 2928 FI 5 00 d0 d0 fc 09 3a 1 candi ZXR10 2818S Cmdr WYXX cfg group set group add device 1 5 Adding device id 1 Successed to add member Adding device id 2 Successed to add member Adding device id 3 Successed to add member Adding device id 4 Successed to add member Adding device id 5 Successed to add membe...

Page 273: ...r 4 Trying Open Connecting Membr_4 zte enable Membr_4 zte cfg set vlan 4000 enable Membr_4 zte cfg set vlan 4000 add port 1 16 tag Delete cluster created on VLAN 1 Cmdr WYXX cfg group set group delete member 1 5 Deleting member id 1 Successed to del member Deleting member id 2 Successed to del member Deleting member id 3 Successed to del member Deleting member id 4 Successed to del member Deleting...

Page 274: ...ZXR10 2920 2928 2952 V1 0 Access Switch User Manual Volume I 260 Confidential and Proprietary Information of ZTE CORPORATION Create a cluster on VLAN 4000 ...

Page 275: ...R10 5116 FI 3 00 d0 d0 fc 08 fa 1 candi ZXR10 5116 4 00 d0 d0 fc 08 d5 1 candi ZXR10 2928 FI 5 00 d0 d0 fc 09 3a 1 candi ZXR10 2818S Cmdr WYXX cfg group set group add device 1 5 Adding device id 1 Successed to add member Adding device id 2 Successed to add member Adding device id 3 Successed to add member Adding device id 4 Successed to add member Adding device id 5 Successed to add member Cmdr WY...

Page 276: ...switch remotely using a standard WEB browser give the advice that the browser version should be above IE 4 0 with a distinguish rate of 1024 768 through the network Logging On Using Web Management This topic describes procedure to login web management of ZXR10 2920 2928 2952 To login to web management meet the following requirements Enable the web through hyper terminal ZXR10 2609 2818S 2826S 2852...

Page 277: ...ame and login Password By default username is admin and password is zhongxing 3 Select User Role It could be Admin User or Normal User In Normal User there is no need of Admin Password Without Admin Password admin user is not accessible 4 Click Login button and log in the main system Result Ethernet switch is displayed as shown in Figure 45 ...

Page 278: ...ing Web management is implemented Configuring a System This topic describes the structure of switch configuration For system configuration perform the following steps 1 Click the catalog tree in the left of the system main page Configuration System to open system information page Result System configuration is displayed showing all the parameters as shown in Figure 46 Result Purpose Steps ...

Page 279: ...ersion Make Time When version is made Mac Address Hardware address of the switch Host Name System name Sys Location System location Sys Up Time Time the system has run since its start up 2 Host name and Sys location is change by clicking on it Name and address is typed in columns 3 Click Apply Result Host name and address is changed END OF STEPS Structure of switch has been configured Configuring ...

Page 280: ...lume I 266 Confidential and Proprietary Information of ZTE CORPORATION 1 Click on Configuration Port Port State from configuration mode as show in Figure 47 FI G U R E 47 POR T ST AT E AN D PAR AM E T E R S Result Port status appears as shown in Figure 48 ...

Page 281: ... PAR AM E T E R S DE T AI L Parameters Description Port Class Ethernet standard Link State Link state linkup or linkdown of port Duplex Working duplex state of port Speed Working speed of port Note When port state is linkdown the items Duplex and Speed are meaningless 2 Click catalog tree in the left of system main page Configuration Port Port Parameter to open the port configuration information p...

Page 282: ... Work mode of the port Auto Neg Work mode of the port that is work speed and duplex PVID VLAN ID is default on the port Flow Control Flow control enable on the port Multi Filter Multicast filtration enable on the port Mac Limit Limit the MAC address learning on the port Security Security enable on the port Speed Advertise Speed advertise on the port 3 For single port configuration click Config but...

Page 283: ...on of selected port is accessible Note When security is enabling Mac Limit is not supported Important Ensure that changes made to a port is not web management terminal this can effect in terminating web management session 5 For batch ports configuration select some ports in the port configuration information page list and at the same time user can choose Select All for all ports to be selected the...

Page 284: ... END OF STEPS Result Batch Ports are accessible Configuring Vlan Management This topic describes the configuration of Vlan management For the configuration Vlan management perform the following steps 1 Click the catalog tree in the left of system main page Configuration VLAN Vlan Overview to open VLAN information page This shows recent operated VLAN information If there is on operation on the VLAN...

Page 285: ... Select ports which are to be untagged trunk 2 To show specified VLAN information select the radio box Input in the VLAN information page then input the wanted VLAN number in text column such as 1 3 5 or select the radio box All Click Apply button to submit Result Vlan information is displayed Important When there are more than 20 items it will show them page by page with the page number on the le...

Page 286: ...E R IN P U T 4 Input the VLAN number format is like 1 3 5 in the VLAN number input page and click Apply button to enter single VLAN or batch VLANs configuration page 5 Single VLAN configuration page is shown in Figure 54 FI G U R E 54 SIN G L E VL AN 6 After configuring some attributes of the Vlan click Apply button to submit Result Vlan is configured ...

Page 287: ...Ns configuration page is shown in Figure 55 FI G U R E 55 BAT C H VL AN 8 Select and configure some attributes of the Vlan in the page then click Apply button to submit Result Batch Vlan is configured END OF STEPS VLAN has been configured Configuring PVLAN This topic describes the configuration of PVLAN For the configuration PVLAN perform the following steps 1 Click the catalog tree in the left of...

Page 288: ...s parameters shown in Figure 56 TAB L E 431 PVLAN PAR AM E T E R S DE S C R IP T I O N Parameters Description PVlan Session Pvlan session Promiscuous Port Prmoiscuous port Isolated Port Isolated port Isolated Trunk Isolated trunk 2 Click the catalog tree in the left of the system main page Configuration PVLAN Pvlan Configure to open the PVLAN configuration page as shown in Figure 57 ...

Page 289: ...page click Apply button to submit END OF STEPS PVLAN has been configured Configuring Mirroring Management This topic describes the port mirroring management For the port mirroring management perform the following steps 1 Click the catalog tree in the left of the system main page configuration mirror to open mirror information page as shown in Figure 58 Result Purpose Steps ...

Page 290: ...he page shows the following information of port mirror including ingress and egress as shown in Table 432 TAB L E 432 PO R T MI R R O R DE T AI L Parameters Description Source port Source port of the mirror Destination port Destination port of the mirror 2 Click Config link on the right of Ingress column to open the ingress port mirror configuration page as shown in Figure 59 ...

Page 291: ... R 3 Configure destination and source port of ingress port mirror then click Apply button to submit Result This configures destination and source port of ingress port mirror 4 Click Config link on the right of Egress column to open the egress port mirror configuration page as shown in Figure 60 FI G U R E 60 EGR E S S PO R T MIR R O R ...

Page 292: ...ic describes the configuration of LACP management For the configuration of LACP management perform the following steps 1 Click catalog tree in the left of the system main page Configuration Lacp Lacp Port to open LACP basic attributes page as shown in Figure 61 FI G U R E 61 LACP BAS I C AT T R I B U T E f This page includes LACP basic information as shown in Table 433 TAB L E 433 LACP BAS I C IN ...

Page 293: ...sembling port in the page 3 After configuration click Apply button to submit Result This configures basic attribute of LACP 4 To configure batch assembling port attributes select the check boxes of assembling ports Select All all ports are selected then click Set button to open batch assembling ports configuration page as shown in Figure 62 FI G U R E 62 BAT C H AS S E M B L I N G PO R T S CON F I...

Page 294: ... information of assembling group as shown in Table 435 TAB L E 435 AS S E M BL I N G GR O U P DE T AI L Parameters Description Attached Ports Attached ports in the assembling group Active Ports Active ports in the assembling group GroupMode Assembling mode of the assembling group 7 Click on Config button on the right to open the corresponding assembling group configuration page as shown in Figure ...

Page 295: ...LACP management has been configured Only ports with same attributes can be binded to same assembling group Number of ports binded to assembling group is up to 8 Avoid binding port connected to network management host to assembling group Otherwise the network management will be interrupted Configuring Terminal Record This topic describes the configuration of terminal record For the configuration of...

Page 296: ...date the terminal log information END OF STEPS Terminal log information is accessible Configuring Port Statistics This topic describes the configuration of port statistics For the configuration of port statistics perform the following steps 1 Click the catalog tree in the left of the system main page Monitoring Port Statistics to open the port statistics information page as shown in Figure 66 Resu...

Page 297: ...the PortNumber column to get the statistics data on the port END OF STEPS This shows statistics data on the port Configuring Information This topic describes to open the configuration of information For the opening of configuration of information perform the following step 1 Click the catalog tree in the left of the system main page Monitoring Running config to open the configuration information p...

Page 298: ... END OF STEPS The page shows the configuration information of the switch Saving Configuration This topic describes the configuration saving reminder page For the configuration of saving perform the following steps 1 Click the catalog tree in the left of the system main page Maintenance Save to open the configuration saving reminder page as shown in Figure 68 Result Purpose Steps ...

Page 299: ...s saves the configuration Saving the configuration will cover the primary configuration files please be sure to cover the files before clicking OK Rebooting an Equipment This topic describes the rebooting of equipment For the configuration of rebooting equipment perform the following steps 1 Click the catalog tree in the left of the system main page Maintenance Reboot to open the reboot page as sh...

Page 300: ...olumn then click OK to reboot the switch or click Cancel to give up rebooting END OF STEPS This reboots the switch Uploading a File This topic describes the uploading of file For the configuration of file uploading perform the following steps 1 Click the catalog tree in the left of the system main page Maintenance Upload to open the file upload page as shown in Figure 70 Result Purpose Steps ...

Page 301: ...on of ZTE CORPORATION 287 FI G U R E 70 FIL E UP L O AD 2 Click Browse to browse and select the file need uploading as shown in Figure 71 then click OK to upload the file FI G U R E 71 BRO W S E AN D S E L E C T FI L E END OF STEPS The file uploaded successfully Result ...

Page 302: ...n Configuring User Management This topic describes the configuration of user management For the configuration of user management perform the following steps 1 Click the catalog tree in the left of the system main page Maintenance User Manager to open the user management page as shown in Figure 72 FI G U R E 72 USE R MAN AG E M E N T 2 Click Apply to submit Note Page is user modification page by de...

Page 303: ...e management password of the current user and add and confirm the information of added user then click Apply to submit 5 Click Delete in the user management page to open deleting user page as shown in Figure 74 FI G U R E 74 DEL E T I N G US E R 6 Input the management password and select the user to be deleted then click Apply to submit ...

Page 304: ...2952 V1 0 Access Switch User Manual Volume I 290 Confidential and Proprietary Information of ZTE CORPORATION END OF STEPS User management tool has been configured and now it is possible to add and delete a user Result ...

Page 305: ... Page No Routine Maintenance 292 Daily Routine Maintenance 292 Monthly Maintenance 292 Maintenance Period 293 Single Loop Test Method 294 Configuring Single Port Loop Test 294 Virtual Circuit Test 297 Common Troubleshooting 298 Troubleshooting through Console Port 298 Troubleshooting through Telnet 299 Troubleshooting a Telnet 299 Troubleshooting 300 Troubleshooting the Switch through Web 300 Trou...

Page 306: ...ment room 5 Check system alarm information 6 Check the communication status between the switch and each connected device by logging into switch through a HyperTerminal or Telnet and then use the ping command to test different network segments and check the connectivity Result This checks the communication status between switch and the other device connected to 7 Check whether the switch related se...

Page 307: ...stic data and configuration data END OF STEPS This checks the monthly maintenance of switch Maintenance Period Maintenance and test period of the Ethernet switch system for the reference of the maintenance personnel is shown in Table 436 TAB L E 436 MAI N T E N AN C E AN D TE S T PE R I O D OF ET HER N E T SW IT C H No Maintenance Test Item Test Period 1 Check the running status of the switch Dail...

Page 308: ...wing three parameters It indicates the MAC address of the switch The MAC address of each switch is unique Port numbers correspond to the numbers of the ports on the switch one by one For each switch the digital signature of each port is different When three parameters in the test packet sent through port are same as those in the test packet received through the port a port loop absolutely exists C...

Page 309: ... config mode This is shown in Table 439 TAB L E 439 SET LO O P DE T EC T TR U N K COM M AN D Format Mode Function set loopdetect trunk trunklist enable disable global config This enable disable loop test function of a trunk Result This enable disable loop test function of a trunk Note By default loop test function of a trunk is disabled 4 To enable disable loop test function of a trunk on a design...

Page 310: ...DE T EC T TR U N K PRO T E C T COM M AN D Format Mode Function set loopdetect trunk trunklist protect enable disable global config This enable disable loop test protection function of a trunk Result This enable disable loop test protection function of a trunk 7 To set time for blocking port with loop use command set loopdetect blockdelay 1 1080 in global config mode This is shown in Table 443 TAB ...

Page 311: ...fig This displays port loop test configuration and port detection status Result This displays port loop test configuration and port detection status Note When the port cannot work normally configure show loopdetect to observe whether a port loop exists If no loop is detected and the spanning tree of the port is enabled eliminate fault according to status of spanning status END OF STEPS Single Port...

Page 312: ...sole port To troubleshoot through console port meet the following requirements Check the configuration cable Check the serial port of the HyperTerminal Check console port of the switch For troubleshooting through console port perform the following steps 1 Use proper configuration cables For the connections of configuration cables see Console Cable 2 Check the settings of serial port attributes of ...

Page 313: ...e consistent with the related VLAN ID 2 Enable the port 3 Enable the VLAN bound with the IP port 4 Configure a valid IP address subnet mask and default gateway for the switch 5 Modify the IP address of the switch or that of the other device to eliminate the IP address conflict END OF STEPS This troubleshoots through Telnet connection Troubleshooting a Telnet connection with switch This topic descr...

Page 314: ...llowing steps 1 Update the browser version The version should be above 4 0 2 Examine the configuration of the host to get the right IP address and port number 3 Examine the connection between the host and the equipment to make sure that the communication is normal 4 Set the right management port on the switch and the right IP address 5 Enable web management function of the switch and set the port ...

Page 315: ...nistrator can find original user name and password If the user name and password cannot be found restart the switch and delete the configuration file f Restart the switch and press any key according to the prompt to enter the boot status in the HyperTerminal Welcome to use ZTE eCarrier Copyright c 2004 2006 ZTE Co Ltd System Booting CPU DB 88E6218 Version VxWorks5 5 1 BSP version 1 2 6 b Creation ...

Page 316: ...pw 5124 flags f 0x0 other o MAC0 00 32 45 67 89 ab Attached TCP IP interface to marfec0 Warning no netmask specified Attaching network interface lo0 done Attaching to TFFS test flash passed perfectly MarvellDx has been initialized Welcome to boot manager Type for help BootManager f Run del command to delete the configuration file and then restart the switch BootManager ls KERNEL RUNNING CFG config...

Page 317: ...enabled Troubleshooting a Device Connection This topic describes how to troubleshoot the interconnection of two devices so that they can be connected to two switch ports in a same VLAN To troubleshoot the interconnection of two devices in the same VLAN meet the following requirements PVID of the port is configured incorrectly Port is disabled VLAN is disabled IP address is not set on the equipment...

Page 318: ...al Volume I 304 Confidential and Proprietary Information of ZTE CORPORATION 3 Enable the VLAN 4 Add the port to the VLAN and select untag 5 Set correct IP address on equipment END OF STEPS Interconnect of two devices in same VLAN is configured Result ...

Page 319: ...ASBR Autonomous System Border Router ASN Abstract Syntax Notation ATM Asynchronous Transfer Mode BGP Border Gateway Protocol BOOTP Bootstrap Protocol BDR Backup Designate Router CHAP Challenge Handshake Authentication Protocol CIDR Classless Inter Domain Routing CLNP Connectionless Network Protocol CLNS Connectionless Network Service COS Class of Service CRC Cyclic Redundancy Check CRLDP Constrain...

Page 320: ... Protocol GBIC Gigabit Interface Converter GRE General Routing Encapsulation ICMP Internet Control Message Protocol IETF Internet Engineering Task Force IGMP Internet Group Management Protocol IGP Interior Gateway Protocol IP Internet Protocol ISO International Organization for Standardization ISP Internet Service Provider LAN Local Area Network LAPB Link Access Procedure Balanced LCP Link Control...

Page 321: ...on OSPF Open Shortest Path First PAP Password Authentication Protocol PAT Port Address Translation PCB Process Control Block PCM Pulse Code Modulation PDU Protocol Data Unit POS Packet over SDH PPP Point to Point Protocol PSNP Partial Sequence Num PDU PRT Process Registry Table QOS Quality of Service RARP Reverse Address Resolution Protocol RADIUS Remote Authentication Dial In User Service RFC Req...

Page 322: ...NP Sequence Num PDU SPF Shortest Path First TCP Transmission Control Protocol TFTP Trivial File Transfer Protocol TOS Type Of Service TELNET Telecommunication Network Protocol TTL Time To Live UDP User Datagram Protocol VLSM Variable Length Subnet Mask VPN Virtual Private Network VRF Virtual Routing Forwarding VRRP Virtual Router Redundancy Protocol WAN Wide Area Network WWW World Wide Web ...

Page 323: ... 14 DC Power Cable 25 Figure 15 Transverse English Type I Label 31 Figure 16 Pattern And Meanings Of Engineering Label On Optical Fiber 31 Figure 17 Cabling Of The Ethernet Switch In A Building 32 Figure 18 Cabling Of A Convergence Switch 33 Figure 19 ZXR10 2920 2928 2952 Configuration Modes 36 Figure 20 Run Telnet 37 Figure 21 Telnet Login 38 Figure 22 TFTPD Interface 53 Figure 23 Configure Dialo...

Page 324: ...igure 45 System Interface 264 Figure 46 System Configuration 265 Figure 47 Port State And Parameters 266 Figure 48 Port State Information 267 Figure 49 Port Configuration Information 268 Figure 50 Single Port Configuration 269 Figure 51 Batch Port Configuration 270 Figure 52 Vlan Information 271 Figure 53 Vlan Number Input 272 Figure 54 Single Vlan 272 Figure 55 Batch Vlan 273 Figure 56 PVLAN Info...

Page 325: ...rmation of ZTE CORPORATION 311 Figure 68 Configuration Saving Reminder 285 Figure 69 Reboot 286 Figure 70 File Upload 287 Figure 71 Browse And select File 287 Figure 72 User Management 288 Figure 73 Adding user 289 Figure 74 Deleting User 289 ...

Page 326: ...ZXR10 2920 2928 2952 V1 00 Access Switch User Manual Volume I 312 Confidential and Proprietary Information of ZTE CORPORATION This page is intentionally blank ...

Page 327: ...t Through Network Cable RJ45 Linear Ordering 27 Table 11 Crossover Cable RJ45J S Linear Ordering 28 Table 12 Fiber Types 28 Table 13 Topics In Chapter 5 35 Table 14 Create User Command 39 Table 15 User Password Command 39 Table 16 Admin Password 39 Table 17 Web Commands 40 Table 18 Invoking a Command 47 Table 19 Functional Keys 48 Table 20 Topics In Chapter 6 49 Table 21 Config Tffs Command 50 Tab...

Page 328: ...y Command 70 Table 44 Set Port Security Command 70 Table 45 Multicast Filter Command 71 Table 46 Rate Advertisement Command 71 Table 47 Mac Address Command 71 Table 48 Protocol Vlan Command 72 Table 49 Port jumbo Command 72 Table 50 Create Port Command 72 Table 51 Port Description Command 72 Table 52 Port Description Command 73 Table 53 Port Description Command 73 Table 54 Show Port Command 74 Tab...

Page 329: ...nd 84 Table 81 Set Fdb Filter Command 85 Table 82 Show Fdb Command 85 Table 83 Show Fdb Agingtime Command 85 Table 84 Show Fdb Mac Command 86 Table 85 Show Fdb Port Command 86 Table 86 Show Fdb Trunk Command 86 Table 87 Show Fdb Vlan Command 86 Table 88 Set Lacp Command 87 Table 89 Set Lacp Aggregator Command 87 Table 90 Set Lacp Aggregator Delete Command 88 Table 91 Set Lacp Aggregator Mode Comma...

Page 330: ...upip Vlan Command 97 Table 115 Set Igmp Filter Delete Groupip Vlan Command 97 Table 116 Set Igmp Filter Add Sourceip Vlan Command 97 Table 117 Set Igmp Filter Delete Sourceip Vlan Command 98 Table 118 Show Igmp Snooping Command 98 Table 119 Show Igmp Snooping Vlan Command 98 Table 120 Show Igmp Filter command 98 Table 121 Show Igmp Filter Vlan Command 99 Table 122 IPTV Control Log Time Command 102...

Page 331: ...ort Command 114 Table 154 Set Stp Forceversion Command 114 Table 155 Set Stp Forward Delay Command 114 Table 156 Set Stp Hellotime Command 114 Table 157 Set Stp Hmd5 Digest Command 114 Table 158 Set Stp Hmd5 Key Port Command 115 Table 159 Set Stp Hopmax Command 115 Table 160 Set Stp Instance Bridge Priority Command 115 Table 161 Set Stp Instance Port cost Command 115 Table 162 Set Stp Instance Por...

Page 332: ...Show Stp Relay Command 122 Table 187 ACL Description 126 Table 188 ACL Basic Number Command 126 Table 189 Rule Command 126 Table 190 Config ACL Extend Command 127 Table 191 Rule Command 127 Table 192 Config ACL Link Command 128 Table 193 Rule Command 128 Table 194 Config ACL Hybrid Command 129 Table 195 Rule Command 129 Table 196 Config ACL Global Command 130 Table 197 Rule Command 130 Table 198 S...

Page 333: ...mand 141 Table 223 Clear Qos Policy Counter Command 141 Table 224 Clear Policy Mirror Command 141 Table 225 Clear Policy Vlan Command 141 Table 226 Clear Policy Policing Command 142 Table 227 Clear Policy Qos Remark Command 142 Table 228 Clear Policy Statistics Command 142 Table 229 Clear Policy Redirect Command 142 Table 230 Show Qos Dscp Command 143 Table 231 Show Qos Queue Profile command 143 T...

Page 334: ...rt Max Hosts Command 164 Table 261 Dot1x Re authentication Command 164 Table 262 Dot1x Re Authentication Period Command 165 Table 263 AAA Control port Keepalive command 165 Table 264 AAA Control Port Keepalive Period 165 Table 265 AAA Control Protocol Command 166 Table 266 Dot1x Quiet Period Command 167 Table 267 Dot1x Quiet Period Command 167 Table 268 Dot1x Supplicant Timeout Command 167 Table 2...

Page 335: ...ar Policy Qos Command 182 Table 296 Set Policy Policing Command 182 Table 297 Clear Policy Policing Command 182 Table 298 Set Policy Redirect Command 182 Table 299 Clear Policy Redirect Command 183 Table 300 Set Policy Statistics Command 183 Table 301 Clear Policy Statistics Command 183 Table 302 Set Port SQinQ Session Command 183 Table 303 Clear SQinQ Session Command 184 Table 304 Show SQinQ Sess...

Page 336: ...199 Table 332 Show Dhcp Ip Source Guard Command 199 Table 333 Set Dhcp Option82 Command 199 Table 334 Set Dhcp Option82 Command 200 Table 335 Set Dhcp Option82 Sub Option Command 200 Table 336 Set Dhcp Option82 Command 200 Table 337 Set Dhcp Option82 Sub Option Port Command 201 Table 338 Show Dhcp Option82 Command 201 Table 339 Show Dhcp Option82 Ani Command 201 Table 340 Show Dhcp Option82 Port C...

Page 337: ...ccess Command 219 Table 366 Set Remote Access Ipaddress Command 219 Table 367 Clear Remote Access All Command 220 Table 368 Clear Remote Access Ipaddress Command 220 Table 369 Show Remote Access Command 220 Table 370 Set Ssh Command 222 Table 371 Show Ssh Command 222 Table 372 Create Community Command 227 Table 373 Create View Command 227 Table 374 Set Community View Command 228 Table 375 Set Grou...

Page 338: ...rt Command 247 Table 404 Show Start Command 248 Table 405 Ztp Mac Command 248 Table 406 Show Ztp Device Command 248 Table 407 Set Group Candidate Command 249 Table 408 Set Group Independent Command 249 Table 409 Set Group Command 249 Table 410 Set Group Add Mac Command 250 Table 411 Set Group Add Mac Command 250 Table 412 Set Group Add Device Command 251 Table 413 Set Group Delete Member Command 2...

Page 339: ...ion Detail 278 Table 434 Assembling Port Information 279 Table 435 Assembling Group Detail 280 Table 436 Maintenance And Test Period Of Ethernet Switch 293 Table 437 Set Loop Detect Port Command 294 Table 438 Set Loop Detect Port Vlan Command 295 Table 439 Set Loop Detect Trunk Command 295 Table 440 Set Loop Detect Trunk Vlan Command 295 Table 441 Set Loop Detect Port Protect Command 296 Table 442...

Page 340: ...326 Confidential and Proprietary Information of ZTE CORPORATION This Page is intentionally blank ...

Page 341: ...IMG 55 Internet Protocol television IPTV 103 IP address 37 127 147 Isolated port 147 148 local safety 1 Media Access Control MAC 85 NMS 309 Power Module 10 Promiscuous port 147 PVLAN 147 148 152 QoS 5 126 RMON 6 safety instructions i 1 security control 5 Simple Network Management Protocol SNMP 38 Straight through RJ45 27 Switching module 10 Telnet 37 38 39 40 52 53 54 57 TFTP server 54 56 57 VLAN ...

Reviews: