background image

GS-3012F User’s Guide 

ii 

Copyright 

Copyright 

Copyright © 2004 by ZyXEL Communications Corporation 

The contents of this publication may not be reproduced in any part or as a whole, transcribed, stored in a retrieval 
system, translated into any language, or transmitted in any form or by any means, electronic, mechanical, 
magnetic, optical, chemical, photocopying, manual, or otherwise, without the prior written permission of ZyXEL 
Communications Corporation. 

Published by ZyXEL Communications Corporation. All rights reserved. 

Disclaimer 

ZyXEL does not assume any liability arising out of the application or use of any products, or software described 
herein. Neither does it convey any license under its patent rights nor the patents rights of others. ZyXEL further 
reserves the right to make changes in any products described herein without notice. This publication is subject to 
change without notice. 

Trademarks 

Trademarks mentioned in this publication are used for identification purposes only and may be properties of their 
respective owners.  

Summary of Contents for Dimension GS-3012F

Page 1: ...Dimension GS 3012F Gigabit Ethernet Switch Version 3 60 LR 0 5 2005 User s Guide...

Page 2: ...yXEL Communications Corporation Published by ZyXEL Communications Corporation All rights reserved Disclaimer ZyXEL does not assume any liability arising out of the application or use of any products o...

Page 3: ...y an act of God or subjected to abnormal working conditions Note Repair or replacement as provided under this warranty is the exclusive remedy of the purchaser This warranty is in lieu of all other wa...

Page 4: ...and if not installed and used in accordance with the instruction manual may cause harmful interference to radio communications Operation of this equipment in a residential area is likely to cause har...

Page 5: ......

Page 6: ...xel com ZyXEL Communications Inc 1130 N Miller St Anaheim CA 92806 2001 U S A support zyxel de 49 2405 6909 0 www zyxel de GERMANY sales zyxel de 49 2405 6909 99 ZyXEL Deutschland GmbH Adenauerstr 20...

Page 7: ...rt II II Chapter 2 Hardware Installation 2 1 2 1 Installation Scenarios 2 1 Chapter 3 Hardware Connections 3 1 3 1 Safety Warnings 3 1 3 2 Front Panel 3 1 3 3 Rear Panel 3 5 3 4 Front Panel LEDs 3 5 3...

Page 8: ...Setup 8 1 8 1 Introduction to Static MAC Forward Setup 8 1 8 2 Configuring Static MAC Forwarding 8 1 8 3 Viewing and Editing Static MAC Forwarding Rules 8 2 Chapter 9 Filtering 9 1 9 1 Introduction t...

Page 9: ...6 2 Port Security Setup 16 1 Chapter 17 Access Control 17 1 17 1 About Access Control 17 1 17 2 Access Control Overview 17 1 17 3 About SNMP 17 2 17 4 SSH Overview 17 6 17 5 How SSH works 17 6 17 6 SS...

Page 10: ...ration File 23 2 23 4 Backing Up a Configuration File 23 2 23 5 Load Factory Defaults 23 3 23 6 Reboot System 23 3 23 7 Command Line FTP 23 3 Chapter 24 Diagnostic 24 1 24 1 Diagnostic 24 1 Chapter 25...

Page 11: ...ommands 29 1 29 3 ping 29 4 29 4 traceroute 29 4 29 5 Enabling RSTP 29 5 29 6 Configuration File Maintenance 29 5 29 7 Example no Commands 29 7 29 8 interface Commands 29 10 Chapter 30 IEEE 802 1Q Tag...

Page 12: ......

Page 13: ...1 Figure 4 2 Web Configurator Home Screen Status 4 2 Figure 4 3 Web Configurator Change Password at Login 4 6 Figure 4 4 Resetting the Switch Via Console Port 4 7 Figure 4 5 Web Configurator Logout Sc...

Page 14: ...net Explorer 17 8 Figure 17 10 Security Certificate 1 Netscape 17 9 Figure 17 11 Security Certificate 2 Netscape 17 9 Figure 17 12 Main Screen Internet Explorer 17 10 Figure 17 13 Main Screen Netscape...

Page 15: ...e 29 6 show mac address table Command Example 29 4 Figure 29 7 ping Command Example 29 4 Figure 29 8 traceroute Command Example 29 5 Figure 29 9 Enable RSTP Command Example 29 5 Figure 29 10 CLI Backu...

Page 16: ...ion and Activation Example 30 2 Figure 30 2 CPU VLAN Configuration and Activation Example 30 2 Figure 30 3 GARP STATUS Command Example 30 3 Figure 30 4 garp status Command Example 30 4 Figure 30 5 vla...

Page 17: ...Static MAC Forwarding Summary Table 8 2 Table 9 1 Filtering 9 1 Table 9 2 Filtering Summary Table 9 2 Table 10 1 STP Path Costs 10 1 Table 10 2 STP Port States 10 2 Table 10 3 Spanning Tree Protocol S...

Page 18: ...onventions 23 4 Table 23 2 General Commands for GUI based FTP Clients 23 5 Table 24 1 Diagnostic 24 1 Table 25 1 ZyXEL Clustering Management Specifications 25 1 Table 25 2 Cluster Management Status 25...

Page 19: ...ps data service over Category 5 wiring to each customer General Syntax Conventions This guide shows you how to configure the switch using the web configurator and CLI commands See the online HTML help...

Page 20: ...TML help The online HTML help shows you how to use the web configurator to configure individual screens More background information can be found in this UG ZyXEL Web Site The ZyXEL download library at...

Page 21: ...Features and Applications I Part I Features and Applications This part acquaints you with the features and applications of the GS 3012F...

Page 22: ......

Page 23: ...the console port or third party SNMP management 1 2 Features The next two sections describe the hardware and firmware features of the GS 3012F 1 2 1 Hardware Features Power The GS 3012F DC model requi...

Page 24: ...g SNMP for management SNMP MIB II RFC 1213 SNMP v1 RFC 1157 Ethernet MIBs RFC 1643 Bridge MIBs RFC 1493 SMI RFC 1155 RMON RFC 1757 SNMPv2 or SNMPv2c Bridge extension MIBs RFC 2674 Interface MIB RFC 28...

Page 25: ...c shaping STP Spanning Tree Protocol RSTP Rapid STP R STP detects and breaks network loops and provides backup links between switches bridges or routers It allows a switch to interact with other R STP...

Page 26: ...ent company departments to connect to the corporate backbone It can alleviate bandwidth contention and eliminate server and network bottlenecks All users that need high bandwidth can connect to high s...

Page 27: ...or connecting two power workgroups that need high bandwidth In the following example use trunking to connect these two power workgroups Switching to higher speed LANs such as FDDI or ATM is not feasib...

Page 28: ...ork allows a physical network to be partitioned into multiple logical networks Stations on a logical network belong to one group A station can belong to more than one group With VLAN a station cannot...

Page 29: ...ication VLAN Shared Server Example Shared resources such as a server can be used by all ports in the same VLAN as the server as shown in the following example In this example only ports that need acce...

Page 30: ...GS 3012F User s Guide 1 8 Getting to Know the GS 3012F Figure 1 5 Shared Server Using VLAN Example...

Page 31: ...and Connections II Part II Hardware Installation and Connections This part acquaints you with installation scenarios of the GS 3012F instructs you on how to make the hardware connections and explains...

Page 32: ......

Page 33: ...ons 2 1 1 Desktop Installation Procedure 1 Make sure the switch is clean and dry 2 Set the switch on a smooth level surface strong enough to support the weight of the switch and the connected cables M...

Page 34: ...ack mounting kit 1 Align one bracket with the holes on one side of the switch and secure it with the bracket screws smaller than the rack mounting screws 2 Attach the other bracket in a similar fashio...

Page 35: ...GS 3012F User s Guide Hardware Installation 2 3 Figure 2 3 Mounting the ES to an EIA standard 19 inch rack...

Page 36: ......

Page 37: ...nd management port for local management Figure 3 1 GS 3012F Front Panel Table 3 1 GS 3012F Front Panel CONNECTOR DESCRIPTION 12 Mini GBIC Ports Use mini GBIC transceivers in these slots for fiber opti...

Page 38: ...r each pair for a total of four possible Gigabit connections one from each of the four pairs The mini GBIC ports have priority over the Gigabit ports This means that if a mini GBIC port and the corres...

Page 39: ...nstallation Use the following steps to install a mini GBIC transceiver SFP module 1 Insert the transceiver into the slot with the exposed section of PCB board facing down 2 Press the transceiver firml...

Page 40: ...eiver out of the slot Figure 3 4 Opening the Transceiver s Latch Example Figure 3 5 Transceiver Removal Example 3 2 4 Management Port The MGNT management port is used for local management Connect dire...

Page 41: ...airflow of the fans located on the side of the unit The GS 3012F DC unit requires DC power supply input of 48 VDC to 60 VDC 1 2A Max To connect the power to the unit insert the one end of the supplied...

Page 42: ...tests On The system is on and functioning properly Off The power is off or the system is not ready malfunctioning ALM Red On There is a hardware failure Off The system is functioning normally GBIC Slo...

Page 43: ...nected at 100Mbps or to an Ethernet device 3 5 Configuring the GS 3012F You may use the embedded web configurator or command line interface to configure the switch If you re using the web configurator...

Page 44: ......

Page 45: ...Getting Started III Part III Getting Started This part introduces you to the web configurator describes the Status and Port Details screens and shows you how to configure the Basic Setting screens...

Page 46: ......

Page 47: ...xplorer or Netscape Navigator web browser 2 Type http and the IP address of the switch for example the default is 192 168 1 1 in the Location or Address field Press Enter 3 The login screen appears Th...

Page 48: ...in link to reveal a list of submenu links Table 4 1 Navigation Panel Sub links Overview BASIC SETTING ADVANCED APPLICATION ROUTING PROTOCOL MANAGEMENT Navigation Panel Click on a tab to display relate...

Page 49: ...etup Port Setup VLAN Status VLAN Port Setting Static VLAN Static MAC Forwarding Filtering Spanning Tree Protocol Status Spanning Tree Protocol Configuration Bandwidth Control Broadcast Storm Control M...

Page 50: ...u can configure the IP address subnet mask necessary for switch management and DNS domain name server Port Setup This link takes you to screens where you can configure settings for individual switch p...

Page 51: ...Rule This link takes you to a screen where you can configure policy rules DHCP Relay This link takes you to a screen where you can configure DHCP relay information Routing Protocol Static Routing Thi...

Page 52: ...gement port of the switch 3 Filtering all traffic to the CPU port 4 Disabling all ports 5 Assigning minimum bandwidth to the CPU port If you limit bandwidth to the CPU port you may find that the switc...

Page 53: ...DEM upload message before activating XMODEM upload on your terminal 6 After a successful configuration file upload type atgo to restart the switch Figure 4 4 Resetting the Switch Via Console Port The...

Page 54: ...e Web Configurator 4 5 2 Help The web configurator s online help has descriptions of individual screens and some supplementary information Click the Help link from a web configurator screen to view an...

Page 55: ...web configurator displays a port statistical summary with links to each port showing statistical details 5 2 Port Status Summary To view the port statistics click Status in all web configurator screen...

Page 56: ...s This field shows the number of received errors on this port Tx KB s This field shows the number of kilobytes per second transmitted on this port Rx KB s This field shows the number of kilobytes per...

Page 57: ...t connection is down and the speed duplex mode Status This field shows the training state of the ports The states are FORWARDING forwarding which means the link is functioning normally or STOP the por...

Page 58: ...lticast frames received Broadcast This field shows the number of good broadcast frames received Pause This field shows the number of 802 3x Pause frames received Control This field shows the number of...

Page 59: ...ts in length 128 255 This field shows the number of packets including bad packets received that were between 128 and 255 octets in length 256 511 This field shows the number of packets including bad p...

Page 60: ......

Page 61: ...ws you to set the system time manually or get the current time and date from an external server when you turn on your switch The real time is then displayed in the switch logs The Switch Setup screen...

Page 62: ...displays Normal for temperatures below the threshold and Error for those above Fan speed RPM A properly functioning fan is an essential component along with a sufficiently ventilated cool operating en...

Page 63: ...splays how often in seconds this screen refreshes You may change the refresh interval by typing a new number in the text box and then clicking Set Interval Stop Click Stop to halt statistic polling 6...

Page 64: ...ll timeservers support all protocols so you may have to use trial and error to find a protocol that works The main differences between them are the time format Daytime RFC 867 format is day month year...

Page 65: ...ectional it only governs outgoing traffic See the VLAN chapter for information on port based and 802 1Q tagged VLANs 6 5 IGMP Snooping IGMP Internet Group Multicast Protocol is a network layer protoco...

Page 66: ...IGMP Snooping Select Active to enable IGMP snooping See Section 6 5 for more information on IGMP snooping Bridge Control Protocol Transparency Select Active to allow the switch to handle bridging con...

Page 67: ...fine class of service Frames without an explicit priority tag are given the default priority of the ingress port Use the next two fields to configure the priority level to physical queue mapping The s...

Page 68: ...specifies the IP address of the default gateway next hop for outgoing traffic Figure 6 4 IP Setup The following table describes the labels in this screen Table 6 4 IP Setup LABEL DESCRIPTION Domain Na...

Page 69: ...teway Enter the IP address of the default outgoing gateway in dotted decimal notation for example 192 168 1 254 VID Enter the VLAN identification number associated with the switch IP address This is t...

Page 70: ...ration Index This field displays the index number of the rule Click an index number to edit the rule IP Address This field displays the IP address IP Subnet Mask This field displays the subnet mask VI...

Page 71: ...C ports select Auto or 1000M Full Duplex For mini GBIC Gigabit Ethernet combo ports select Auto 10M Half Duplex 10M Full Duplex 100M Half Duplex 100M Full Duplex or 1000M Full Duplex Selecting Auto au...

Page 72: ...state of packet collision causing the sending port to temporarily stop sending signals and resend later Select this option to enable flow control 802 1P Priority This priority value is added to incom...

Page 73: ...Advanced Application 1 IV Part IV Advanced Application 1 This part shows you how to configure the VLAN Static MAC Forwarding Filtering STP and Bandwidth Control Advanced Application screens...

Page 74: ......

Page 75: ...I set to 1 then that frame should not be forwarded as it is to an untagged port The remaining twelve bits define the VLAN ID giving a possible maximum number of 4 096 212 VLANs Note that user priority...

Page 76: ...to the following table for common GARP terminology Table 7 1 GARP Terminology VLAN PARAMETER TERM DESCRIPTION VLAN Type Permanent VLAN This is a static VLAN created manually Dynamic VLAN This is a VLA...

Page 77: ...C D and E otherwise they will drop frames with unknown VLAN group tags However with VLAN Trunking enabled on a port s in each intermediary switch you only need to create VLAN groups in the end device...

Page 78: ...s column displays the ports that are participating in a VLAN A tagged port is marked as T an untagged port is marked as U and ports not participating in a VLAN in marked as Elapsed Time This field sho...

Page 79: ...802 1Q VLAN Port Settings LABEL DESCRIPTION GVRP GVRP GARP VLAN Registration Protocol is a registration protocol that defines a way for switches to dynamically register necessary VLAN members on ports...

Page 80: ...tocol that defines a way for switches to register necessary VLAN members on ports across the network Acceptable Frame Type Specify the type of frames allowed on a port Choices are All and Tag Only Sel...

Page 81: ...between 1 and 4094 Port The port number identifies the port you are configuring Control Select Normal for the port to dynamically join this VLAN group using GVRP This is the default selection Select...

Page 82: ...of a rule click a number in the VID field Figure 7 6 Static VLAN Summary Table The following table describes the labels in this screen Table 7 5 Static VLAN Summary Table LABEL DESCRIPTION VID This f...

Page 83: ...s to talk to each other for example between conference rooms in a hotel you must define the egress an egress port is an outgoing port that is a port through which a data packet leaves for both ports P...

Page 84: ...GS 3012F User s Guide 7 10 VLAN Figure 7 8 Port Based VLAN Setup All Connected...

Page 85: ...Figure 7 9 This option is the most limiting but also the most secure After you make your selection click Apply top right of screen to display the screens as mentioned above You can still customize th...

Page 86: ...to allow two subscriber ports to talk to each other you must define the egress port for both ports CPU refers to the switch management port By default it forms a VLAN with all Gigabit ports If it does...

Page 87: ...ceive traffic on other ports This may reduce unicast flooding 8 2 Configuring Static MAC Forwarding Click Static MAC Forwarding to display the configuration screen as shown Figure 8 1 Static MAC Forwa...

Page 88: ...tic MAC Forwarding Summary Table The following table describes the labels in this screen Table 8 2 Static MAC Forwarding Summary Table LABEL DESCRIPTION Index Click an index number to modify a static...

Page 89: ...D 9 2 Configuring a Filtering Rule Click Advanced Application and Filtering to display the screen as shown next Figure 9 1 Filtering The following table describes the related labels in this screen Tab...

Page 90: ...bottom of the screen Cancel Click Cancel to reset the fields to your previous configuration Clear Click Clear to clear the fields to the factory defaults 9 3 Viewing and Editing Filter Rules To view a...

Page 91: ...g Summary Table LABEL DESCRIPTION Action This field displays the filter action Delete Check the rule s that you want to remove in the Delete column and then click the Delete button Cancel Click Cancel...

Page 92: ......

Page 93: ...to 65535 Path Cost 10Mbps 100 50 to 600 1 to 65535 Path Cost 16Mbps 62 40 to 400 1 to 65535 Path Cost 100Mbps 19 10 to 60 1 to 65535 Path Cost 1Gbps 4 3 to 10 1 to 65535 Path Cost 10Gbps 2 1 to 5 1 to...

Page 94: ...to eliminate packet looping A bridge port is not allowed to go directly from blocking state to forwarding state so as to eliminate transient loops Table 10 2 STP Port States PORT STATE DESCRIPTION Di...

Page 95: ...ridge consisting of bridge priority plus MAC address This ID is the same for Root and Our Bridge if the switch is the root switch Hello Time second This is the time interval in seconds at which the ro...

Page 96: ...Time Since Last Change This is the time since the spanning tree was last reconfigured Poll Interval s The text box displays how often in seconds this screen refreshes You may change the refresh interv...

Page 97: ...d port for the attached LAN If it is a root port a new root port is selected from among the switch ports attached to the network The allowed range is 6 to 40 seconds Forwarding Delay This is the maxim...

Page 98: ......

Page 99: ...ing and or out going traffic flows on a port Click Advanced Application and then Bandwidth Control in the navigation panel to bring up the screen as shown next Figure 11 1 Bandwidth Control The follow...

Page 100: ...per second Mbps for the incoming traffic flow on a port Enter a number between 1 and 1000 Egress Rate Specify the maximum bandwidth allowed in megabits per second Mbps for the out going traffic flow...

Page 101: ...V Part V Advanced Application 2 This part shows you how to configure the Broadcast Storm Control Mirroring Link Aggregation Port Authentication Port Security Access Control and Queuing Method Advance...

Page 102: ......

Page 103: ...er of allowable broadcast multicast and or DLF packets is reached per second the subsequent packets are discarded Enable this feature to reduce broadcast multicast and or DLF packets in your network Y...

Page 104: ...kt s Select this option and specify how many broadcast packets the port receives per second Multicast pkt s Select this option and specify how many multicast packets the port receives per second DLF p...

Page 105: ...ic from the monitor port the port you copy the traffic to without interference 13 2Port Mirroring Configuration Click Advanced Application Mirroring in the navigation panel to display the Mirroring sc...

Page 106: ...xamine it in more detail without interfering with the traffic flow on the original port s Select this port from this drop down list box Port This field displays the port number Mirrored Select this op...

Page 107: ...supports the link aggregation IEEE802 3ad standard This standard describes the Link Aggregate Control Protocol LACP which is a protocol that dynamically creates and manages trunk groups When you enabl...

Page 108: ...witch 0000 00 00 00 00 00 0000 00 0000 System priority MAC address Key Port Priority1 Port Number1 Figure 14 1 Aggregation ID 14 2Link Aggregation Protocol Status Click Advanced Application Link Aggre...

Page 109: ...the Link Aggregation screen to be in the trunk group Synchronized Ports These are the ports that are currently transmitting data as one logical link in this trunk group Poll Interval s The text box di...

Page 110: ...P system priority is a number between 1 and 65 535 The switch with the lowest system priority and lowest port number if system priority is the same becomes the LACP server The LACP server controls the...

Page 111: ...the individual port exchanges of LACP packets in order to check that the peer port in the trunk group is still up If a port does not respond after three tries then it is deemed to be down and is remov...

Page 112: ......

Page 113: ...that is limited to the memory capacity of the device In essence RADIUS authentication allows you to validate an unlimited number of users from a central location Figure 15 1 RADIUS Server 15 2Configu...

Page 114: ...Port The default port of the RADIUS server for authentication is 1812 You need not change this value unless your network administrator instructs you to do so Shared Secret Specify a password up to 31...

Page 115: ...field displays a port number Active Select this checkbox to permit 802 1x authentication on this port You must first allow 802 1x authentication on the switch before configuring it on each port Reaut...

Page 116: ......

Page 117: ...ports other than the sum cannot exceed 16K For maximum port security enable this feature disable MAC address learning and configure static MAC address es for a port It is not recommended you disable...

Page 118: ...f dynamic MAC addresses that may be learned on a port For example if you set this field to 5 on port 2 then only the devices with these five learned MAC addresses may access port 2 at any one time A s...

Page 119: ...ion and Telnet access control session cannot coexist The console port has higher priority If you telnet to the switch and someone is already logged in from the console port then you will see the follo...

Page 120: ...network management functions It executes applications that control and monitor managed devices The managed devices contain object variables managed objects that define each piece of information to be...

Page 121: ...2674 17 3 2 SNMP Traps The GS 3012F sends traps to an SNMP manager when an event occurs SNMP traps supported are outlined in the following table Table 17 3 SNMP Traps GENERIC TRAP SPECIFIC TRAP DESCR...

Page 122: ...o four stations to send your SNMP traps to Apply Click Apply to save your changes back to the switch Cancel Click Cancel to begin configuring this screen afresh 17 3 4 Setting Up Login Accounts Up to...

Page 123: ...Password Type the existing system password 1234 is the default password when shipped New Password Enter your new system password Retype to confirm Retype your new system password for confirmation Edit...

Page 124: ...lic key is checked against the saved version on the client computer 2 Encryption Method Once the identification is verified both the client and server must agree on the type of encryption method to us...

Page 125: ...tch whereas the SSL client only should authenticate itself when the SSL server requires it to do so Please refer to the following figure 1 HTTPS connection requests from an SSL aware web browser go to...

Page 126: ...screen if you select No then web configurator access is blocked Figure 17 9 Security Alert Dialog Box Internet Explorer 17 7 3 Netscape Navigator Warning Messages When you attempt to access the switc...

Page 127: ...ty Certificate 1 Netscape Figure 17 11 Security Certificate 2 Netscape 17 7 4 Login Screen After you accept the certificate and login in the switch main screen appears The lock displayed in the bottom...

Page 128: ...8Service Access Control Service Access Control allows you to decide what services you may use to access the GS 3012F You may also change the default service port and configure trusted computer s for...

Page 129: ...t people who wish to use the service know the new port number for that service Timeout Type how many minutes a management session via the web configurator can be left idle before the session times out...

Page 130: ...k box if you wish to temporarily disable the set without deleting it Start Address End Address Configure the IP address range of trusted computers fro which you can manage this switch The switch check...

Page 131: ...t Q6 7 Q5 6 Q4 5 Q3 4 Q2 3 Q1 2 Q0 1 lowest 18 1 1 Strict Priority Queuing SPQ Strict Priority Queuing SPQ services queues based on priority only As traffic comes into the switch traffic on the highes...

Page 132: ...e 18 1 rather than a fixed amount of bandwidth WRR is activated only when a port has more traffic than it can handle Queues with larger weights get more service than queues with smaller weights This q...

Page 133: ...ghest priority and Q0 the lowest WRR services queues on a rotating basis based on their queue weight the number you configure in the queue Weight field Queues with larger weights get more service than...

Page 134: ......

Page 135: ...ress source port number destination port number or incoming port number For example you can configure a classifier to select traffic from the same protocol port such as Telnet to form a flow Configure...

Page 136: ...r Figure 19 1 Classifier The following table describes the labels in this screen Table 19 1 Classifier LABEL DESCRIPTION Active Select this option to enable this rule Name Enter a descriptive name for...

Page 137: ...a source select the second choice and type a MAC address in valid MAC address format six hexadecimal character pairs Port Select the port to which the rule should be applied You may choose one port o...

Page 138: ...To view a summary of the classifier configuration scroll down to the summary table at the bottom of the Classifier screen To change the settings of a rule click a number in the Index field When two r...

Page 139: ...X 25 Level 3 0805 XNS Compat 0807 Banyan Systems 0BAD BBN Simnet 5208 IBM SNA 80D5 AppleTalk AARP 80F3 Some of the most common IP ports are Table 19 4 Common IP Ports PORT NUMBER PORT NAME 21 FTP 23 T...

Page 140: ...GS 3012F User s Guide 19 6 Classifier Figure 19 3 Classifier Example...

Page 141: ...equest a particular service or give advanced notice of where the traffic is going 20 1 2 DSCP and Per Hop Behavior DiffServ defines a new DS Differentiated Services field to replace the Type of Servic...

Page 142: ...GS 3012F User s Guide 20 2 Policy Rule Figure 20 1 Policy The following table describes the labels in this screen...

Page 143: ...Metering You can configure the desired bandwidth available to a traffic flow Traffic that exceeds the maximum bandwidth allocated in cases where the network is congested is called out of profile traf...

Page 144: ...the packet with the value you configure in the VLANID field Metering Select Enable to activate bandwidth limitation on the traffic flow s then set the actions to be taken on out of profile packets Ou...

Page 145: ...policy This is for identification purposes only Classifier s This field displays the name s of the classifier to which this policy applies Delete Click Delete to remove the selected entry from the sum...

Page 146: ...GS 3012F User s Guide 20 6 Policy Rule Figure 20 3 Policy Example...

Page 147: ...of the requests You can also specify additional information for the switch to add to the client TCP IP configuration requests that it relays to the DHCP server Please refer to RFC 3046 for more detai...

Page 148: ...ecimal notation Relay Agent Information Select the Option 82 check box to have the switch add the port numbers to client TCP IP configuration requests that it relays to a DHCP server Information Selec...

Page 149: ...Routing Protocol and Management VI Part VI Routing Protocol and Management This part describes the Routing Protocol and Management screens...

Page 150: ......

Page 151: ...field allows you to activate deactivate this static route Name Enter a descriptive name for this route This is for identification purpose only Destination IP Address This parameter specifies the IP ne...

Page 152: ...mmary Table The following table describes the labels in the summary table Table 22 2 Static Routing Summary Table LABEL DESCRIPTION Index This field displays the index number of the route Click a numb...

Page 153: ...ce screen if you want to upgrade your switch firmware See the System Info screen to verify your current firmware version number Make sure you have downloaded and unzipped the correct model firmware an...

Page 154: ...file is automatically renamed when you restore using this screen 23 4Backing Up a Configuration File Backing up your switch configurations allows you to create various snap shots of your device from...

Page 155: ...cess the switch web configurator again you may need to change the IP address of your computer to be in the same subnet as that of the default switch IP address 192 168 1 1 23 6Reboot System Reboot Sys...

Page 156: ...as This is a sample FTP session showing the transfer of the computer file firmware bin to the switch ftp get config config cfg This is a sample FTP session saving the current configuration to a file c...

Page 157: ...ord is automatically supplied to the server for anonymous access Anonymous logins will work only if your ISP or service administrator has enabled this option Normal The server requires a unique User I...

Page 158: ......

Page 159: ...llowing table describes the labels in this screen Table 24 1 Diagnostic LABEL DESCRIPTION System Log Click Display to display a log of events in the multi line text box Click Clear to empty the text b...

Page 160: ......

Page 161: ...ustering Management Specifications Maximum number of cluster members 24 Cluster Member Models Must be compatible with ZyXEL cluster management implementation Cluster Manager The switch through which y...

Page 162: ...e cluster member switch directly and not via the cluster manager o None neither a manager nor a member of a cluster Manager This field displays the cluster manager switch s hardware MAC Address The Nu...

Page 163: ...25 2 1 Cluster Member Switch Management Go to the Clustering Management Status screen of the cluster manager switch and then select an Index hyperlink from the list of members to go to that cluster me...

Page 164: ...1 5d The cluster member switch s configuration file name as seen in the cluster manager switch 25 3Configuring Cluster Management Click Configuration from the Cluster Management screen to display the...

Page 165: ...is later set to become a cluster manager then its Status is displayed as Error in the Cluster Management Status screen and a warning icon appears in the member summary list below Name Type a name to...

Page 166: ...sword afterwards then it cannot be managed from the Cluster Manager Its Status is displayed as Error in the Cluster Management Status screen and a warning icon appears in the member summary list below...

Page 167: ...following figure 1 The switch examines a received frame and learns the port on which this source MAC address came 2 The switch checks to see if the frame s destination MAC address matches a source MAC...

Page 168: ...ed in the summary table below MAC Click this button to display and arrange the data according to MAC address VID Click this button to display and arrange the data according to VLAN group Port Click th...

Page 169: ...ends it to the device If no entry is found for the IP address ARP broadcasts the request to all the devices on the LAN The switch fills in its own MAC and IP address in the sender address fields and p...

Page 170: ...is is the ARP Table entry number IP Address This is the learned IP address of a device connected to a switch port with corresponding MAC address below MAC Address This is the MAC address of the device...

Page 171: ...CLI Commands VII Part VII Commands This part gives information on the Command Line Interface CLI...

Page 172: ......

Page 173: ...our network Restore switch configuration Use the same configuration file to set all switches of the same model in your network to the same settings You may also edit a configuration file using a text...

Page 174: ...For local management connect your computer to the RJ 45 management port labeled MGMT on the switch 2 Make sure your computer IP address and the switch IP address are on the same subnet In Windows cli...

Page 175: ...the up y or down z arrow key to scroll through the command history list The CLI does not accept partial or incomplete commands You may enter a unique part of a command and press TAB to have the switc...

Page 176: ...help Description of the interactive help system history Show a list of previously run commands logout Exit from the EXEC ping Exec ping show Show system information ssh SSH client traceroute Exec tra...

Page 177: ...ollowed by a port number For example interface 10 Enter exit or logout to quit from the current mode or log out from the CLI 28 7Using Command History The switch keeps a list of up to 256 commands s y...

Page 178: ...istory Displays a list of previously command s that you have executed The switch stores up to 256 commands in history enable Accesses Enable or privileged mode show hardware monitor C F Displays curre...

Page 179: ...information ip arp Displays the ARP table ip route Displays IP routing information ip route static Displays IP static route information hardware monitor C F Displays current hardware monitor informati...

Page 180: ...all classifier related information name Displays specified classifier related information policy Displays all policy related information name Displays specified policy related information interface po...

Page 181: ...mber mac mac addr Displays the MAC address of the cluster member s member Displays the status of the cluster member s members config Displays the configuration of the cluster member s mac flush Clears...

Page 182: ...ines the path a packet takes to a device ssh 1 2 user dest ip Connects to an SSH server with the specified SSH version 28 9 3 Configure Mode The following table lists the commands in Configuration or...

Page 183: ...ables port mirroring on the switch lacp Disables the link aggregation control protocol dynamic trunking on the switch trunk T1 T2 T3 T4 T5 T6 lacp Disables LACP in the specified trunk group T1 T2 T3 T...

Page 184: ...h http Disables web browser control to the switch ssh Disables SSH Secure Shell server access to the switch https Disables secure web browser access to the switch icmp Disables ICMP access to the swit...

Page 185: ...ssh rsa ssh dsa Removes remote known hosts with the specified public key 1024 bit RSA1 RSA or DSA https timeout Resets the session timeout to the default of 300 seconds multi login Disables another a...

Page 186: ...nables port mirroring on a specified port lacp Enables Link Aggregation Control Protocol LACP system priority 1 65535 Sets the priority of an active port using LACP trunk interface port list timeout l...

Page 187: ...ac addr source port port num destination mac dest mac addr dscp 0 63 ip protocol protocol num tcp udp icmp eg p ospf rsvp igmp igp pim ipsec establish only source ip src ip addr mask bits mask bits so...

Page 188: ...ff replace priority diff set dscp outgoing mirror outgoing eport outgoing non unicast eport outgoing set vlan metering out of profile action change dscp drop forward inactive Configures a policy A cla...

Page 189: ...y be learned on a port vlan1q gvrp Allows VLAN groups beyond the local switch port isolation Enables port isolation garp join 100 65535 leave msec leaveall msec Configures GARP time settings spanning...

Page 190: ...me 10 3000 Sets learned MAC aging time snmp server contact system contact location system location Sets the geographic location and the name of the person in charge of this switch get community proper...

Page 191: ...nown hosts host ip 1024 ssh rsa ssh dsa key Adds a remote host to which the switch can access using SSH service https cert regeneration rsa dsa Re generates a certificate timeout 0 65535 Sets the HTTP...

Page 192: ...want to tag all outgoing frames transmitted with this VLAN Group ID inactive Enables the specified VLAN ip address inband default dhcp bootp Sets the default in band interface to use a static IP addr...

Page 193: ...configuration bandwidth limit Enables bandwidth limit on the switch bandwidth limit egress Mbps Sets the maximum bandwidth allowed for outgoing traffic on the switch bandwidth limit ingress Mbps Sets...

Page 194: ...ccept both tagged and untagged incoming frames or just tagged incoming frames on a port name port name string Sets a name for your interface Enter a descriptive name up to nine printable ASCII charact...

Page 195: ...check Incoming traffic is not checked for VLAN tags no gvrp Disables GVRP on the switch no flow control Disables flow control on the switch no vlan trunking Disables VLAN trunking on the switch no mi...

Page 196: ......

Page 197: ...the firmware version and system up time An example is shown next Figure 29 1 show system information Command Example 29 2 2 show hardware monitor Syntax show hardware monitor c f This command display...

Page 198: ...55 255 255 0 VID 0 VPS01 Device Type Switch Idle Timeout disable MGMT VPS CNTL VPS Number of Interface 2 cmif0 IP 127 0 0 1 Netmask 255 0 0 0 VID 1 swif0 IP 192 168 1 1 Netmask 255 255 255 0 VID 1 GS...

Page 199: ...icast 0 Broadcast 4 Pause 0 Control 0 TX Collison Single 0 Multiple 0 Excessive 0 Late 0 Error Packet RX CRC 0 Length 0 Runt 0 Distribution 64 4 65 to 127 74 128 to 255 18 256 to 511 0 512 to 1023 0 1...

Page 200: ...he Ethernet device belongs out of band refers the management port while in band means the other ports on the switch size 0 8024 Specifies the packet size to send t Sends Ping packets to the Ethernet d...

Page 201: ...oute information to an Ethernet device with an IP address of 192 168 1 100 Figure 29 8 traceroute Command Example 29 5Enabling RSTP To enable RSTP on a port Enter spanning tree followed by the port nu...

Page 202: ...oads the configuration file test cfg from the TFTP server 172 23 19 96 to the switch Figure 29 11 CLI Restore Configuration Example 29 6 3 Using a Different Configuration File You can store up to two...

Page 203: ...t the switch back to the factory defaults 1 Enter erase running config to reset the current running configuration 2 Enter write memory to save the changes to the current configuration file If you want...

Page 204: ...3 no trunk Syntax no trunk T1 T2 T3 T4 T5 T6 no trunk T1 T2 T3 T4 T5 T6 lacp no trunk T1 T2 T3 T4 T5 T6 interface port list where T1 T2 T3 T4 T 5 T6 Disables the trunk group T1 T2 T3 T4 T 5 T6 lacp D...

Page 205: ...ts one three four and five Disable authentication on ports one six and seven Figure 29 18 no port access authenticator Command Example 29 7 5 no ssh Syntax no ssh key rsa1 rsa dsa no ssh known hosts h...

Page 206: ...terface group of commands 29 8 1 interface Syntax interface Each interface refers to an Ethernet port on the switch Commands configured after the interface command correspond to those ports Type multi...

Page 207: ...ntrol Command Example 29 8 3 broadcast limit Syntax broadcast limit broadcast limit pkt s where Enables broadcast storm control limit on the switch pkt s Sets how many broadcast packets the interface...

Page 208: ...Port mirroring copies traffic from one or all ports to another or all ports for external analysis An example is shown next Enable port mirroring Enable the monitor port three Enable ports one four fiv...

Page 209: ...n Enable GVRP on the interface Figure 29 25 gvrp Command Example 29 8 7 ingress check Syntax ingress check Enables the device to discard incoming frames for VLANs that are not included in a port membe...

Page 210: ...to other switches or routers but not ports directly connected to end users to allow frames belonging to unknown VLAN groups to pass through the switch An example is shown next Enable ports one three f...

Page 211: ...re 29 30 wrr Command Example 29 8 12 egress set Syntax egress set port list where port list Sets the outgoing traffic port list for a port based VLAN An example is shown next Enable port based VLAN ta...

Page 212: ...e 29 32 qos priority Command Example 29 8 14 name Syntax name port name string where port name string Sets a name for your port interface s An example is shown next Enable ports one three four and fiv...

Page 213: ...Selecting auto auto negotiation makes one port able to negotiate with a peer automatically to obtain the connection speed and duplex mode that both ends support An example is shown next Enable ports...

Page 214: ......

Page 215: ...s enabled for the VID of a frame then the frame is transmitted as a tagged frame otherwise it is transmitted as an untagged frame 30 2VLAN Databases A VLAN database stores and organizes VLAN registrat...

Page 216: ...command to deactivate the VLAN s Example Figure 30 1 Tagged VLAN Configuration and Activation Example 4 Configure your management VLAN Use the vlan vlan id command to create a VLAN VID 3 in this examp...

Page 217: ...e default is 600 milliseconds leaveall msec This sets the duration of the Leave All Period timer for GVRP in milliseconds Each port has a single Leave All Period timer Leave All Timer must be larger t...

Page 218: ...VRP so that the switch does not propagate VLAN information to other switches 30 5Port VLAN Commands You must configure the switch port VLAN settings in config interface mode 30 5 1 Set Port VID Syntax...

Page 219: ...ample 30 5 3 Enable or Disable Port GVRP Use the gvrp command to enable GVRP on the port s Use the no gvrp command to disable GVRP The following example turns off GVRP for ports 1 to 5 Figure 30 7 no...

Page 220: ...s temporary VIDs to untagged frames 2 The switch then checks the VID in a frame s tag against the SVLAN table 3 The switch notes what the SVLAN table says that is the SVLAN tells the switch whether or...

Page 221: ...an Command Example 30 6 Enable VLAN Syntax vlan vlan id This command enables the specified VLAN ID in the SVLAN Static VLAN table 30 7Disable VLAN Syntax vlan vlan id inactive This command disables th...

Page 222: ...gged port Figure 30 10 show vlan Command Example GS 3012F show vlan 802 1Q VLAN Static Entry idx Name VID Active AdCtl TagCtl 0 1 1 active FFFFFFFFFFFFFFFFFFFFFFFFFFFF UUUUUUUUUUUUUUUUUUUUUUUUUUUU 1 u...

Page 223: ...Appendices and Index VIII Part VIII Appendices and Index This part contains an appendix and an index...

Page 224: ......

Page 225: ...Four 100 1000BASE T Gigabit ports One console port One RJ 45 management port Data Transfer Rate Fast Ethernet 100Mbps half duplex 200Mbps full duplex Gigabit 1000Mbps half duplex 2000Mbps full duplex...

Page 226: ...trunking IEEE802 3ad dynamic port trunking Port Security Static MAC address filtering MAC address learning limit Multicasting Support IGMP snooping Broadcast Storm Support broadcast storm control Por...

Page 227: ...U height Power Supply AC Unit 100 240VAC 50 60Hz 1 5A max internal universal power supply Power Supply DC Unit DC input of 48VDC 60VDC 1 2A Max Power Consumption AC 36W maximum DC 30W maximum Fuse Ra...

Page 228: ......

Page 229: ...rol 1 3 Broadcast Storm Control 12 1 C Calssifier View summary 19 4 Canonical Format Indicator 7 1 CE iv Certification iv CFI See Canonical Format Indicator Change Login Password 4 5 CI Commands 28 3...

Page 230: ...ications Commission FCC Interference Statement iv File Transfer using FTP 23 3 command example 23 4 GUI based 23 5 procedure 23 4 restrictions over WAN 23 5 Filename Conventions 23 4 Filter Setup 9 1...

Page 231: ...25 1 J Join Timer 6 7 L LACP Timeout 14 5 LACP Status 14 2 Leave All Timer 6 7 Leave Timer 6 7 LED Descriptions 3 6 Link Aggregate Control Protocol LACP 14 1 Link aggregation 14 1 Link Aggregation ID...

Page 232: ...ring 1 2 13 1 28 22 29 12 Port Security 16 1 Port Setup 6 10 6 11 Port Statistics See Port Details Port Status 5 1 See Port Details Port Link Aggregation 1 3 Port VID 7 2 Default for all ports 7 1 28...

Page 233: ...SSH 17 6 SSH Implementation 17 6 1 1 standard browser 4 1 Standards A 1 Static MAC Forward Setup 8 1 Static MAC Forwarding 8 1 Static Route Setup 22 1 Summary table 22 2 Static VLAN 7 6 Control 7 7 S...

Page 234: ...it Tagging 30 1 Forwarding 7 1 ID VID 30 1 Implicit Tagging 30 1 Introduction 6 5 Port based 7 9 Priority frame 7 1 Registration Information 30 1 Tagged VLAN 7 1 VLAN Virtual Local Area Network 6 5 VL...

Page 235: ...GS 3012F User s Guide Index B 7 ZyXEL Limited Warranty iii Note iii ZyXEL Web Site xvi...

Reviews: