background image

 

www.zyxel.com

ONU-2024 Series

User’s Guide

Version 1
11/2008
Edition 1

DEFAULT LOGIN

IP Address

http://192.168.1.1

User Name

admin

Password

1234

Summary of Contents for ONU-2024 Series

Page 1: ...www zyxel com ONU 2024 Series User s Guide Version 1 11 2008 Edition 1 DEFAULT LOGIN IP Address http 192 168 1 1 User Name admin Password 1234...

Page 2: ......

Page 3: ...topology Related Documentation Quick Start Guide The Quick Start Guide contains information on setting up your hardware Web Configurator Online Help Embedded web help for descriptions of individual s...

Page 4: ...d uppercase text for example ENTER means the enter or return key on your keyboard Enter means for you to type one or more characters and then press the ENTER key Select or choose means for you to use...

Page 5: ...Guide 5 Icons Used in Figures Figures in this User s Guide may use the following generic icons The ONU icon is not an exact representation of your device ONU Computer Notebook computer Server DSLAM F...

Page 6: ...rrect ports Place connecting cables carefully so that no one will step on them or stumble over them Always disconnect all cables from this device before servicing or disassembling Use ONLY an appropri...

Page 7: ...Safety Warnings ONU User s Guide 7 This product is recyclable Dispose of it properly...

Page 8: ...Safety Warnings ONU User s Guide 8...

Page 9: ...Basic Setting 65 Advanced Setup 77 VLAN 79 Static MAC Forward Setup 91 Filtering 93 Spanning Tree Protocol 95 Bandwidth Control 109 Broadcast Storm Control 111 Mirroring 113 Link Aggregation 115 Port...

Page 10: ...Contents Overview ONU User s Guide 10 Syslog 219 Cluster Management 223 MAC Table 229 ARP Table 231 Configure Clone 233 Appendices and Index 235...

Page 11: ...ging Example 32 1 1 3 High Performance Switching Example 32 1 1 4 IEEE 802 1Q VLAN Application Examples 33 1 2 Ways to Manage the ONU 34 1 3 Good Habits for Managing the ONU 34 Chapter 2 Hardware Inst...

Page 12: ...onfiguration 53 4 5 ONU Lockout 53 4 6 Resetting the ONU 53 4 6 1 Reload the Configuration File 54 4 7 Logging Out of the Web Configurator 54 4 8 Help 54 Chapter 5 Initial Setup Example 55 5 1 Overvie...

Page 13: ...Screens 79 8 1 2 What You Need to Know About the VLAN Screen 79 8 2 Select the VLAN Type 82 8 3 Static VLAN Status 82 8 3 1 Static VLAN Details 83 8 3 2 Configure a Static VLAN 84 8 3 3 Configure VLAN...

Page 14: ...13 2 Broadcast Storm Control Setup 111 Chapter 14 Mirroring 113 14 1 Overview 113 14 2 Port Mirroring Setup 113 Chapter 15 Link Aggregation 115 15 1 Overview 115 15 1 1 What You Can Do in the Link Agg...

Page 15: ...IGMP Filtering Profile 136 19 6 MVR Overview 137 19 6 1 Types of MVR Ports 138 19 6 2 MVR Modes 138 19 6 3 How MVR Works 138 19 7 General MVR Configuration 139 19 8 MVR Group Configuration 141 19 8 1...

Page 16: ...Guard Screen 169 22 1 2 What You Need to Know About the Loop Guard Screens 170 22 2 Loop Guard Setup 172 Part IV IP Application 175 Chapter 23 Static Route 177 23 1 Overview 177 23 2 Configuring Stati...

Page 17: ...ilename Conventions 197 26 9 2 FTP Command Line Procedure 198 26 9 3 GUI based FTP Clients 198 26 9 4 FTP Restrictions 198 Chapter 27 Access Control 199 27 1 Overview 199 27 1 1 What You Can Do in the...

Page 18: ...ent 223 30 1 Overview 223 30 1 1 What You Can Do in these Screens 224 30 2 Cluster Management Status 224 30 2 1 Cluster Member Switch Management 225 30 3 Clustering Management Configuration 227 Chapte...

Page 19: ...Table of Contents ONU User s Guide 19 Appendix A Product Specifications 237 Appendix B IP Addresses and Subnetting 243 Appendix C Legal Information 251 Appendix D Customer Support 255 Index 261...

Page 20: ...Table of Contents ONU User s Guide 20...

Page 21: ...Logout Screen 54 Figure 19 Initial Setup Network Example VLAN 56 Figure 20 Initial Setup Network Example Port VID 57 Figure 21 Initial Setup Example Management IP Address 58 Figure 22 Status 59 Figur...

Page 22: ...cation 122 Figure 58 Advanced Application Port Authentication 802 1x 123 Figure 59 Advanced Application Port Security 126 Figure 60 Port Security Example 127 Figure 61 Advanced Application Queuing Met...

Page 23: ...IP Application DHCP VLAN 189 Figure 103 DHCP Relay for Two VLANs 190 Figure 104 DHCP Relay for Two VLANs Configuration Example 190 Figure 105 Management Maintenance 193 Figure 106 Load Factory Defaul...

Page 24: ...Screen 225 Figure 129 Example Uploading Firmware to a Cluster Member Switch 226 Figure 130 Management Clustering Management Configuration 227 Figure 131 MAC Table Flowchart 229 Figure 132 Management M...

Page 25: ...arding 92 Table 20 Advanced Application Filtering 93 Table 21 STP Path Costs 96 Table 22 STP Port States 97 Table 23 Advanced Application Spanning Tree Protocol RSTP 101 Table 24 Advanced Application...

Page 26: ...ia Telnet SSH 156 Table 54 RADIUS Attributes Exec Events via Console 156 Table 55 IP Source Guard 161 Table 56 IP Source Guard Static Binding 162 Table 57 ARP Inspection Status 163 Table 58 ARP Inspec...

Page 27: ...r Member Example 226 Table 93 Management Clustering Management Configuration 227 Table 94 Management MAC Table 230 Table 95 Management ARP Table 232 Table 96 Management Configure Clone 234 Table 97 Ha...

Page 28: ...List of Tables ONU User s Guide 28...

Page 29: ...29 PART I Introduction Getting to Know Your Device 31 Hardware Installation and Connection 35 Hardware Connections 39...

Page 30: ...30...

Page 31: ...its built in web configurator managing and configuring the ONU is easy In addition it can also be managed via Telnet SSH Secure SHell any terminal emulator program on the console port or third party...

Page 32: ...ork managers to centralize multiple servers at a single location Figure 2 Bridging Application 1 1 3 High Performance Switching Example The ONU is ideal for connecting two networks that need high band...

Page 33: ...re not in the same group s unless such traffic first goes through a router For more information on VLANs refer to Chapter 8 on page 79 Ports in the same VLAN group share the same frame broadcast domai...

Page 34: ...red and or managed by an SNMP manager See Section 27 3 on page 200 1 3 Good Habits for Managing the ONU Do the following things regularly to make the ONU more secure and to manage it more effectively...

Page 35: ...the weight of the ONU and the connected cables Make sure there is a power outlet nearby 3 Make sure there is enough clearance around the ONU to allow air circulation and the attachment of cables and t...

Page 36: ...ements Two mounting brackets Eight M3 flat head screws and a 2 Philips screwdriver Four M5 flat head screws and a 2 Philips screwdriver Failure to use the proper screws may damage the unit 2 3 1 1 Pre...

Page 37: ...ONU on a rack Proceed to the next section 2 3 3 Mounting the ONU on a Rack 1 Position a mounting bracket that is already attached to the ONU on one side of the rack lining up the two screw holes on th...

Page 38: ...Chapter 2 Hardware Installation and Connection ONU User s Guide 38...

Page 39: ...u want to configure the ONU using the command line interface CLI via the console port 24 10 100 Mbps RJ 45 Ethernet Ports Connect these ports to a computer a hub an Ethernet switch or router Gigabit E...

Page 40: ...ps and the duplex mode can be half duplex at 100 Mbps or full duplex An auto negotiating port can detect and adjust to the optimum Ethernet speed 10 100 Mbps and duplex mode full duplex or half duplex...

Page 41: ...g down Figure 9 Transceiver Installation Example 2 Press the transceiver firmly until it clicks into place 3 The ONU automatically detects the installed transceiver Check the LEDs to verify that it is...

Page 42: ...PON uplink port s connector Figure 13 The GEPON Uplink Port 3 3 Rear Panel The following figure shows the rear panel of the ONU The power connector is here Figure 14 Rear Panel 3 3 1 Power Connector M...

Page 43: ...t is negotiating in full duplex mode Off The Ethernet port is negotiating in half duplex mode and no collisions are occurring Gigabit Port 100 1000 Green On The link to a 1000 Mbps Ethernet network is...

Page 44: ...Chapter 3 Hardware Connections ONU User s Guide 44...

Page 45: ...45 PART II Basic Configuration The Web Configurator 47 Initial Setup Example 55 System Status and Port Statistics 59 Basic Setting 65...

Page 46: ...46...

Page 47: ...om your device Web pop up blocking is enabled by default in Windows XP SP Service Pack 2 JavaScript enabled by default Java permissions enabled by default 4 2 System Login 1 Start your web browser 2 T...

Page 48: ...low you to perform certain tasks no matter which screen you are currently working in B Click this link to save your configuration into the ONU s nonvolatile memory Nonvolatile memory is saved in the c...

Page 49: ...panel click a main link to reveal a list of submenu links These settings in the Web Configurator can only be configured for the Ethernet ports not the GEPON port Table 3 Navigation Panel Sub links Ov...

Page 50: ...Queuing Method Multicast Status Multicast Setting IGMP Snooping VLAN IGMP Filtering Profile MVR Group Configuration Authentication and Accounting RADIUS Server Setup TACACS Server Setup Auth and Acct...

Page 51: ...to screens where you can cap the maximum bandwidth allowed from specified source s to specified destination s Broadcast Storm Control This link takes you to a screen to set up broadcast filters Mirro...

Page 52: ...can perform firmware and configuration file maintenance as well as reboot the system Access Control This link takes you to screens where you can change the system login password and configure SNMP and...

Page 53: ...ld block yourself and all others from using in band management managing through the data ports if you do one of the following 1 Delete the management VLAN default is VLAN 1 2 Delete all port based VLA...

Page 54: ...ill see the initial screen 3 When you see the message Press any key to enter Debug Mode within 3 seconds press any key to enter debug mode 4 Type atlc after the Enter Debug Mode message 5 Wait for the...

Page 55: ...ate a VLAN Set port VLAN ID Configure the ONU IP management address 5 1 2 Before You Begin Before you begin you should log into the web configurator 1 Connect your computer to any Ethernet port on the...

Page 56: ...ple you want to configure port 10 as a member of VLAN 2 Figure 19 Initial Setup Network Example VLAN 1 Click Advanced Application and VLAN in the navigation panel and click the Static VLAN link 2 In t...

Page 57: ...Save button to save the settings 5 1 4 Setting Port VID Use PVID to add a tag to incoming untagged frames received on that port so that the frames are forwarded to the VLAN group that the tag defines...

Page 58: ...s an example Figure 21 Initial Setup Example Management IP Address 1 Click Basic Setting and IP Setup in the navigation panel 2 Configure the related fields in the IP Setup screen For the VLAN2 networ...

Page 59: ...for the entire device Section 6 2 on page 59 The Port Details screen lets you view statistics for one port Section 6 2 1 on page 61 6 2 Port Status Summary To view the port statistics click Status in...

Page 60: ...nk Aggregation Control Protocol has been enabled on the port This field displays N A for the GEPON uplink port TxPkts This field shows the number of transmitted frames on this port RxPkts This field s...

Page 61: ...SCRIPTION Port Info Port NO This field displays the port number you are viewing Name This field displays the name of the port Link This field displays the speed either 10M for 10Mbps 100M for 100Mbps...

Page 62: ...iled information about packets received RX Packets This field shows the number of good packets unicast multicast and broadcast received This field displays 0 for the GEPON uplink port Multicast This f...

Page 63: ...ckets including bad packets received that were between 65 and 127 octets in length 128 255 This field shows the number of packets including bad packets received that were between 128 and 255 octets in...

Page 64: ...Chapter 6 System Status and Port Statistics ONU User s Guide 64...

Page 65: ...ting domain subnet mask s and DNS domain name server for management purposes Section 7 6 on page 72 7 1 2 What You Need to Know About the Basic Setting Screens The following terms and concepts may hel...

Page 66: ...s ONUs FTTx Fiber To The x FTTx refers to networking infrastructure that extends from a service provider to the x where x can one of many locations Office FTTO Home FTTH Desk FTTD Building FTTB or eve...

Page 67: ...l Setup Use this screen to configure general settings such as the system name and time Click Basic Setting and General Setup in the navigation panel to display the screen as shown Figure 25 Basic Sett...

Page 68: ...or 60 seconds Please wait Current Time This field displays the time you open this menu or refresh the menu New Time hh min ss Enter the new time in hour minute and second format The new time then appe...

Page 69: ...apter 8 on page 79 for information on port based and 802 1Q tagged VLANs End Date Configure the day and time when Daylight Saving Time ends if you selected Daylight Saving Time The time field uses the...

Page 70: ...dresses remain in the MAC address table before they age out and must be relearned GARP Timer Switches join VLANs by making a declaration A declaration is made by issuing a Join message using GARP Decl...

Page 71: ...e traffic that is especially sensitive to jitter jitter is the variations in delay Level 5 Typically used for video that consumes high bandwidth and is sensitive to jitter Level 4 Typically used for c...

Page 72: ...igure IP addresses for accessing and managing the ONU from the ports belonging to the pre defined VLAN s See Table 99 on page 239 for how many IP addresses you can configure Figure 27 Basic Setting IP...

Page 73: ...ink on the top navigation panel to save your changes to the non volatile memory when you are done configuring Cancel Click Cancel to reset the fields to your previous configuration Management IP Addre...

Page 74: ...ake some settings the same for all ports Use this row first to set the common settings and then make adjustments on a port by port basis Note Changes in this row are copied to all the ports as soon as...

Page 75: ...fer memory causing packet discards and frame losses Flow Control is used to regulate transmission of signals to match the bandwidth of the receiving port The ONU uses IEEE 802 3x flow control in full...

Page 76: ...Chapter 7 Basic Setting ONU User s Guide 76...

Page 77: ...Broadcast Storm Control 111 Mirroring 113 Link Aggregation 115 Port Authentication 121 Port Security 125 Queuing Method 129 Multicast 131 Authentication Accounting 145 IP Source Guard 159 Loop Guard 1...

Page 78: ...78...

Page 79: ...r IIEEE 802 1Q Tagged VLANs A tagged VLAN uses an explicit tag VLAN ID in the MAC header to identify the VLAN membership of a frame across bridges they are not confined to the switch on which they wer...

Page 80: ...to a specific domain Automatic VLAN Registration GARP and GVRP are the protocols used to automatically register VLAN membership across switches GARP GARP Generic Attribute Registration Protocol allow...

Page 81: ...are unknown to those switches to pass through their VLAN trunking port s Figure 29 Port VLAN Trunking VLAN Administrative Control Registration Fixed Fixed registration ports are permanent VLAN member...

Page 82: ...h the specified VID See Section on page 79 for more information on Static VLAN Click Advanced Application VLAN from the navigation panel to display the VLAN Status screen Figure 31 Advanced Applicatio...

Page 83: ...if all status information cannot be seen in one screen Table 14 Advanced Application VLAN VLAN Status continued LABEL DESCRIPTION Table 15 Advanced Application VLAN VLAN Detail LABEL DESCRIPTION VLAN...

Page 84: ...entification purposes This name consists of up to 64 printable characters spaces are allowed VLAN Group ID Enter the VLAN ID for this static entry the valid range is between 1 and 4094 Port The port n...

Page 85: ...nges if it is turned off or loses power so use the Save link on the top navigation panel to save your changes to the non volatile memory when you are done configuring Cancel Click Cancel to begin conf...

Page 86: ...s row first to set the common settings and then make adjustments on a port by port basis Note Changes in this row are copied to all the ports as soon as you make them PVID Enter a number between 1and...

Page 87: ...r for example between conference rooms in a hotel you must define the egress an egress port is an outgoing port that is a port through which a data packet leaves for both ports Port based VLANs are sp...

Page 88: ...1 Configure a Port based VLAN Select Port Based as the VLAN Type in the Switch Setup screen and then click VLAN from the navigation panel to display the next screen Figure 35 Advanced Application VLA...

Page 89: ...Chapter 8 VLAN ONU User s Guide 89 Figure 36 Advanced Application VLAN Port Based VLAN Setup Port Isolation...

Page 90: ...that is a port through which a data packet enters If you wish to allow two subscriber ports to talk to each other you must define the ingress port for both ports The numbers in the top row denote the...

Page 91: ...ysical layer interface where it is transmitted as a stream of bits Static MAC Forwarding A static MAC address entry is an address that you manually enter into the MAC address learning table Static MAC...

Page 92: ...f it is turned off or loses power so use the Save link on the top navigation panel to save your changes to the non volatile memory when you are done configuring Cancel Click Cancel to begin configurin...

Page 93: ...ced Application Filtering The following table describes the related labels in this screen Table 20 Advanced Application Filtering LABEL DESCRIPTION Active Make sure to select this check box to activat...

Page 94: ...he rule Click an index number to change the settings Active This field displays Yes when the rule is activated and No when is it deactivated Name This field displays the descriptive name for this rule...

Page 95: ...wards compatible with STP only aware bridges In RSTP topology change information is directly propagated throughout the network from the device that generates the topology change In STP a longer delay...

Page 96: ...tree with STP it enables the root port and the ports that are the designated ports for connected LANs and disables all other ports that participate in STP Network packets are therefore only forwarded...

Page 97: ...ingle bridge on the network A VLAN can be mapped to a specific Multiple Spanning Tree Instance MSTI MSTI allows multiple VLANs to use the same spanning tree Load balancing is possible as traffic from...

Page 98: ...nt spanning trees in the network Thus traffic from the two VLANs travel on different paths The following figure shows the network example using MSTP Figure 40 MSTP Network Example MST Region An MST re...

Page 99: ...region Thus an MSTI does not span across MST regions The following figure shows an example where there are two MST regions Regions 1 and 2 have 2 spanning tree instances Figure 41 MSTIs in Different...

Page 100: ...nced Application Spanning Tree Protocol Configuration Figure 43 Advanced Application Spanning Tree Protocol Select the STP mode you want to configure on the ONU 11 3 Configure Rapid Spanning Tree Prot...

Page 101: ...Forwarding Delay This is the maximum time in seconds a switch will wait before changing states This delay is required because every switch must receive information about topology changes before it sta...

Page 102: ...dge if the ONU is the root switch Hello Time second This is the time interval in seconds at which the root switch transmits a configuration message The root bridge determines Hello Time Max Age and Fo...

Page 103: ...103 11 5 Configure Multiple Spanning Tree Protocol To configure MSTP click MSTP in the Advanced Application Spanning Tree Protocol screen See Section on page 97 for more information on MSTP Figure 46...

Page 104: ...5 in an MSTP region before the BPDU is discarded and the port information is aged Configuration Name Enter a descriptive name up to 32 characters of an MST region Revision Number Enter a number to ide...

Page 105: ...on to a LAN through that port It is recommended to assign this value according to the speed of the bridge The slower the media the higher the cost see Table 21 on page 96 for more information Add Cli...

Page 106: ...he ONU Figure 47 Advanced Application Spanning Tree Protocol Status MSTP The following table describes the labels in this screen Table 26 Advanced Application Spanning Tree Protocol Status MSTP LABEL...

Page 107: ...generated from the VLAN MSTI mapping information This field displays the 16 octet signature that is included in an MSTP BPDU This field displays the digest when MSTP is activated on the system Topolo...

Page 108: ...Chapter 11 Spanning Tree Protocol ONU User s Guide 108...

Page 109: ...the Bandwidth Control screen 12 2 Bandwidth Control Setup Bandwidth control means defining a maximum allowable bandwidth for incoming and or out going traffic flows on a port Click Advanced Applicati...

Page 110: ...er a number between 2000 and 103999 the ONU rounds the number down to the nearest multiple of 1000 On a Gigabit Ethernet Mini GBIC port the ONU rounds a number down to the nearest multiple of 8000 for...

Page 111: ...F packets the ONU receives per second on the ports When the maximum number of allowable broadcast multicast and or DLF packets is reached per second the subsequent packets are discarded Enable this fe...

Page 112: ...control on the port Clear this check box to disable the feature Rate Specify the traffic a port receives in Kilobits per second Kbps If you enter a number between 64 and 1728 the ONU automatically rou...

Page 113: ...flow to a monitor port the port you copy the traffic to in order that you can examine the traffic from the monitor port without interference Click Advanced Application Mirroring in the navigation pane...

Page 114: ...ress Select All to copy all outgoing traffic from the mirrored port s Select Destination MAC to copy outgoing traffic to a specified MAC address on the mirrored port s Enter the destination MAC addres...

Page 115: ...beginning port of each trunk group must be physically connected to form a trunk group The ONU supports both static and dynamic link aggregation In a properly planned network it is recommended to impl...

Page 116: ...to point to the same Ethernet switch and configure the ports for LACP trunking LACP only works on full duplex links All ports in the same trunk group must have the same media type speed duplex mode a...

Page 117: ...ify a trunk group that is one logical link containing multiple ports Enabled Ports These are the ports you have configured in the Link Aggregation screen to be in the trunk group Synchronized Ports Th...

Page 118: ...egation Link Aggregation Setting LABEL DESCRIPTION Link Aggregation Setting Group ID The field identifies the link aggregation group that is one logical link containing multiple ports Active Select th...

Page 119: ...ption to enable LACP for a trunk Port This field displays the port number Settings in this row apply to all ports Use this row only if you want to make some settings the same for all ports Use this ro...

Page 120: ...e trunk group are connected to the same destination The following figure shows ports 2 5 on switch A connected to switch B Figure 54 Trunking Example Physical Connections 2 Configure static trunking C...

Page 121: ...16 1 1 What You Can Do in the Port Authentication Screens The Port Authentication screen lets you choose and active an authentication method Section 16 2 on page 122 The 802 1x screen lets you activa...

Page 122: ...u want to use both on the ONU and the port s then configure the RADIUS server settings in the Auth and Acct Radius Server Setup screen Click Advanced Application Port Authentication in the navigation...

Page 123: ...it on each port Port This field displays a port number Settings in this row apply to all ports Use this row only if you want to make some settings the same for all ports Use this row first to set the...

Page 124: ...loses these changes if it is turned off or loses power so use the Save link on the top navigation panel to save your changes to the non volatile memory when you are done configuring Cancel Click Canc...

Page 125: ...s learning and configure static MAC address es for a port By default MAC address learning is still enabled even though the port security is not activated Functionally the ONU allows for three possible...

Page 126: ...e same for all ports Use this row first to set the common settings and then make adjustments on a port by port basis Note Changes in this row are copied to all the ports as soon as you make them Activ...

Page 127: ...dress Use this field to limit the number of dynamic MAC addresses that may be learned on a port For example if you set this field to 5 on port 2 then only the devices with these five learned MAC addre...

Page 128: ...NG LIMIT NO OF LEARNED MAC ADDRESSES 1 X 0 disables limits Forward all packets learn all MAC addresses 2 X X 0 disables limits Forward all packets learn all MAC addresses 3 X 0 disables limits Drop al...

Page 129: ...As traffic comes into the ONU traffic on the highest priority queue Q7 is transmitted first When that queue empties traffic on the next highest priority queue Q6 is transmitted until Q6 empties and t...

Page 130: ...Strict Priority Queuing SPQ services queues based on priority only When the highest priority queue empties traffic on the next highest priority queue begins Q3 has the highest priority and Q0 the lowe...

Page 131: ...LAN screen lets you configure the ONU to automatically locate VLANS connected to its network Section 19 4 on page 135 The IGMP Filtering Profile screen lets you specify a range of multicast groups tha...

Page 132: ...group IGMP snooping generates no additional network traffic allowing you to significantly reduce multicast traffic passing through your ONU IGMP Snooping and VLANs The ONU can perform IGMP snooping on...

Page 133: ...enable IGMP Snooping to forward group multicast traffic only to ports that are members of that group Host Timeout Specify the time from 1 to 16 711 450 in seconds that elapses before the ONU removes...

Page 134: ...ce a port is registered in the specified number of multicast groups any new IGMP join report frame s is dropped on this port IGMP Filtering Profile Select the name of the IGMP filtering profile to use...

Page 135: ...n learn up to 16 VLANs including up to three VLANs you configured in the MVR screen For example if you have configured one multicast VLAN in the MVR screen you can only specify up to 15 VLANs in this...

Page 136: ...Multicast Setting IGMP Filtering Profile Add Click Add to insert the entry in the summary table below and save your changes to the ONU s run time memory The ONU loses these changes if it is turned off...

Page 137: ...purposes To configure additional rule s for a profile that you have already added enter the profile name and specify a different IP multicast address range Start Address Type the starting multicast IP...

Page 138: ...s The following figure shows a multicast television example where a subscriber device such as a computer in VLAN 1 receives multicast traffic from the streaming media server S via the ONU Multiple sub...

Page 139: ...select the receiver port s and a source port for each multicast VLAN Click Advanced Applications Multicast Multicast Setting MVR link to display the screen as shown next You can create up to three mul...

Page 140: ...4 of the multicast VLAN 802 1p Priority Select a priority level 0 7 with which the ONU replaces the priority in outgoing IGMP control packets belonging to this multicast VLAN Mode Specify the MVR mode...

Page 141: ...t this checkbox if you want the port to tag the VLAN ID in all outgoing frames transmitted Add Click Add to save your changes to the ONU s run time memory The ONU loses these changes if it is turned o...

Page 142: ...Enter the same IP address as the Start Address field if you want to configure only one IP address for a multicast group Refer to Section on page 131 for more information on IP multicast addresses Add...

Page 143: ...ngs to the multicast group with VID 200 to receive multicast traffic the News and Movie channels from the remote streaming media server S Computers A B and C in VLAN 1 are able to receive the traffic...

Page 144: ...to the subscribers configure multicast group settings in the Group Configuration screen The following figure shows an example where two multicast groups News and Movie are configured for the multicas...

Page 145: ...users Accounting is the process of recording what a user is doing The ONU can use an external server to track when users log in log out execute commands and so on Accounting can also record system re...

Page 146: ...memory capacity of the device In essence RADIUS and TACACS authentication both allow you to validate an unlimited number of users from a central location The following table describes some key differe...

Page 147: ...e multiple RADIUS servers Select index priority and the ONU tries to authenticate with the first configured RADIUS server if the RADIUS server does not respond then the ONU tries to authenticate with...

Page 148: ...ut Specify the amount of time in seconds that the ONU waits for an accounting request response from the RADIUS accounting server Index This is a read only number representing a RADIUS accounting serve...

Page 149: ...e multiple TACACS servers Select index priority and the ONU tries to authenticate with the first configured TACACS server if the TACACS server does not respond then the ONU tries to authenticate with...

Page 150: ...ngs Timeout Specify the amount of time in seconds that the ONU waits for an accounting request response from the TACACS server Index This is a read only number representing a TACACS accounting server...

Page 151: ...te access privilege level for administrator accounts users for ONU management Configure the access privilege of accounts via commands see the CLI Reference Guide for local authentication The TACACS an...

Page 152: ...system shuts down system accounting is enabled system accounting is disabled Exec Configure the ONU to send information when an administrator logs in and logs out via the console port Telnet or SSH Do...

Page 153: ...company by the IANA Internet Assigned Numbers Authority Vendor Type A vendor specified attribute identifying the setting you want to modify Vendor data A value you want to assign to the setting Refer...

Page 154: ...hentication Refer to RFC 2866 and RFC 2869 for RADIUS attributes used for accounting This appendix lists the attributes used by authentication and accounting functions on the ONU In cases where the at...

Page 155: ...S IP Address 20 2 1 3 Attributes Used by the IEEE 802 1x Authentication User Name NAS Identifier NAS IP Address NAS Port NAS Port Type This value is set to Ethernet 15 on the ONU Calling Station Id Fr...

Page 156: ...TE STOP User Name Y Y Y NAS Identifier Y Y Y NAS IP Address Y Y Y Service Type Y Y Y Acct Status Type Y Y Y Acct Delay Time Y Y Y Acct Session Id Y Y Y Acct Authentic Y Y Y Acct Session Time Y Y Acct...

Page 157: ...ct Session Id Y Y Y Acct Authentic Y Y Y Acct Input Octets Y Y Acct Output Octets Y Y Acct Session Time Y Y Acct Input Packets Y Y Acct Output Packets Y Y Acct Terminate Cause Y Acct Input Gigawords Y...

Page 158: ...Chapter 20 Authentication Accounting ONU User s Guide 158...

Page 159: ...ARP inspection Use this to filter unauthorized ARP packets on the network 21 1 1 What You Can Do in the IP Source Guard Screens The IP Source Guard screen lets you look at the current bindings for ARP...

Page 160: ...quest for computer A Then computer X does the following things It pretends to be computer A and responds to computer B It pretends to be computer B and sends a message to computer A As a result all th...

Page 161: ...ch port can receive per second 21 2 IP Source Guard Use this screen to look at the current bindings for ARP inspection Bindings are used by ARP inspection to distinguish between authorized and unautho...

Page 162: ...nding Port This field displays the port number in the binding If this field is blank the binding applies to all ports Table 55 IP Source Guard continued LABEL DESCRIPTION Table 56 IP Source Guard Stat...

Page 163: ...he binding static This binding was learned from information provided manually by an administrator VLAN This field displays the source VLAN ID in the binding Port This field displays the port number in...

Page 164: ...ARP Inspection Log Status LABEL DESCRIPTION Clearing log status table Click Apply to remove all the log messages that were generated by ARP packets and that have not been sent to the syslog server yet...

Page 165: ...e was generated static deny An ARP packet was discarded because it violated a static binding with the same MAC address and VLAN ID deny An ARP packet was discarded because there were no bindings with...

Page 166: ...e log and reset this counter See Section 21 4 1 on page 164 Syslog rate Enter the maximum number of syslog messages the ONU can send to the syslog server in one batch This number is expressed as a rat...

Page 167: ...t the settings are applied to all of the ports Trusted State Select whether this port is a trusted port Trusted or an untrusted port Untrusted The ONU does not discard ARP packets on trusted ports for...

Page 168: ...displays the VLAN ID of each VLAN in the range specified above If you configure the VLAN the settings are applied to all VLANs Enabled Select Yes to enable ARP inspection on the VLAN Select No to dis...

Page 169: ...t out on that port loop back to the ONU While you can use Spanning Tree Protocol STP to prevent loops in the core of your network STP cannot prevent loops that occur on the edge of your network Figure...

Page 170: ...switch in loop state It will receive its own broadcast messages that it sends out as they loop back It will then re broadcast those messages again The following figure shows port N on switch A connec...

Page 171: ...three switches forming a loop A sample path of the loop guard probe packet is also shown In this example the probe packet is sent from port N and returns on another port As long as loop guard is enabl...

Page 172: ...ESCRIPTION Active Select this option to enable loop guard on the ONU The ONU generates syslog internal log messages as well as SNMP traps when it shuts down a port via the loop guard feature Port This...

Page 173: ...ONU loses these changes if it is turned off or loses power so use the Save link on the top navigation panel to save your changes to the non volatile memory when you are done configuring Cancel Click C...

Page 174: ...Chapter 22 Loop Guard ONU User s Guide 174...

Page 175: ...175 PART IV IP Application Static Route 177 Differentiated Services 181 DHCP 185...

Page 176: ...176...

Page 177: ...use static routes to send data to a server or device that is not reachable through the default gateway for example when sending SNMP traps or using ping to test IP connectivity This figure shows a Te...

Page 178: ...ighbor of your ONU that will forward the packet to the destination The gateway must be a router on the same segment as your ONU Metric The metric represents the cost of transmission for routing purpos...

Page 179: ...ess This field displays the IP address of the gateway The gateway is an immediate neighbor of your ONU that will forward the packet to the destination Metric This field displays the cost of transmissi...

Page 180: ...Chapter 23 Static Route ONU User s Guide 180...

Page 181: ...dvanced notice of where the traffic is going 24 1 1 What You Can Do in the DiffServ Screen The DiffServ screen lets you apply marking rules or IEEE 802 1p priority mapping on a selected port Section 2...

Page 182: ...v compliant network devices The boundary node A in Figure 95 in a DiffServ network classifies marks with a DSCP value the incoming packets into different traffic flows Platinum Gold Silver Bronze base...

Page 183: ...umber of a port on the ONU Settings in this row apply to all ports Use this row only if you want to make some settings the same for all ports Use this row first to set the common settings and then mak...

Page 184: ...g table describes the labels in this screen Table 65 Default DSCP IEEE 802 1p Mapping DSCP VALUE 0 7 8 15 16 23 24 31 32 39 40 47 48 55 56 63 IEEE 802 1p 0 1 2 3 4 5 6 7 Table 66 IP Application DiffSe...

Page 185: ...e VLAN Setting screen lets you configure your DHCP settings based on the VLAN domain of the DHCP clients Section 25 4 on page 188 25 1 2 What You Need to Know About the DHCP Screen The following terms...

Page 186: ...ership of the DHCP clients 25 3 1 DHCP Relay Agent Information The ONU can add information about the source of client DHCP requests that it relays to a DHCP server by adding Relay Agent Information Th...

Page 187: ...is is the VLAN that the port belongs to Information up to 32 bytes This optional read only field is set according to system name set in Basic Settings General Setup Table 69 IP Application DHCP Global...

Page 188: ...te IP address according to the VLAN ID Figure 101 DHCP Relay Configuration Example 25 4 Configuring DHCP VLAN Settings Use this screen to configure your DHCP settings based on the VLAN domain of the D...

Page 189: ...ct the check box for the ONU to add the system name to the client DHCP requests that it relays to a DHCP server Add Click Add to save your changes to the ONU s run time memory The ONU loses these chan...

Page 190: ...rd DHCP requests from the dormitory rooms VLAN 1 to the DHCP server with an IP address of 192 168 1 100 Requests from the academic buildings VLAN 2 are sent to the other DHCP server with an IP address...

Page 191: ...191 PART V Management Maintenance 193 Access Control 199 Diagnostic 217 Syslog 219 Cluster Management 223 MAC Table 229 ARP Table 231 Configure Clone 233...

Page 192: ...192...

Page 193: ...irmware Upgrade screen lets you upload and install new firmware on your ONU Section 26 6 on page 195 The Restore Configuration screen lets you restore a previously saved configuration file Section 26...

Page 194: ...e current configuration settings permanently to Configuration 1 on the ONU Alternatively click Save on the top right hand corner in any screen to save the configuration changes to the current configur...

Page 195: ...Reboot System to reboot and load configuration one The following screen displays Figure 107 Reboot System Confirmation 2 Click OK again and then wait for the ONU to restart This takes up to two minute...

Page 196: ...109 Management Maintenance Restore Configuration Type the path and file name of the configuration file you wish to restore in the File Path text box or click Browse to display the Choose File screen b...

Page 197: ...tp put firmware bin ras This is a sample FTP session showing the transfer of the computer file firmware bin to the ONU ftp get config config cfg This is a sample FTP session saving the current configu...

Page 198: ...based FTP Clients The following table describes some of the commands that you may see in GUI based FTP clients 26 9 4 FTP Restrictions FTP will not work when FTP service is disabled in the Service Ac...

Page 199: ...ontrol options Section 27 2 on page 200 The SNMP screen lets you configure SNMP settings and traps Section 27 3 on page 200 The Trap Group screen lets you specify the types of SNMP traps that should b...

Page 200: ...if TCP IP is configured Figure 112 SNMP Management Model An SNMP managed network consists of two main components agents and a manager An agent is a management software module that resides in a manage...

Page 201: ...mance The ONU supports the following MIBs SNMP MIB II RFC 1213 RFC 1157 SNMP v1 RFC 1493 Bridge MIBs RFC 1643 Ethernet MIBs RFC 1155 SMI RFC 2674 SNMPv2 SNMPv2c RFC 1757 RMON SNMPv2 SNMPv2c or later v...

Page 202: ...ve or below the normal operating range VoltageEventClear 1 3 6 1 4 1 890 1 5 8 27 27 2 2 This trap is sent when the voltage returns to the normal operating range reset UncontrolledResetEventOn 1 3 6 1...

Page 203: ...sent when authentication fails due to incorrect user name and or password AuthenticationFailureEvent On 1 3 6 1 4 1 890 1 5 8 16 27 2 1 1 3 6 1 4 1 890 1 5 8 27 27 2 1 This trap is sent when authentic...

Page 204: ...root switch changes STPTopologyChange 1 3 6 1 2 1 17 0 2 This trap is sent when the STP topology changes MSTPTopologyChange 1 3 6 1 4 1 890 1 5 8 16 107 7 0 2 1 3 6 1 4 1 890 1 5 8 27 107 7 0 2 This t...

Page 205: ...sion 3 v3 or both v3v2c Note SNMP version 2c is backwards compatible with SNMP version 1 Get Community Enter the Get Community string which is the password for the incoming Get and GetNext requests fr...

Page 206: ...implement an authentication algorithm for SNMP messages sent by this user priv to implement authentication and encryption for SNMP messages sent by this user This is the highest security level Note Th...

Page 207: ...nagers You must first configure a trap destination IP address in the SNMP Setting screen Use the rest of the screen to select which traps the ONU sends to that SNMP manager Type Select the categories...

Page 208: ...e admin user name You cannot change the default administrator user name Only the administrator has read write access Old Password Type the existing system password 1234 is the default password when sh...

Page 209: ...ween two hosts over an unsecured network Figure 116 SSH Communication Example Apply Click Apply to save your changes to the ONU s run time memory The ONU loses these changes if it is turned off or los...

Page 210: ...result back to the server The client automatically saves any new server public keys In subsequent connections the server public key is checked against the saved version on the client computer 2 Encry...

Page 211: ...that enables secure transactions of data by ensuring confidentiality an unauthorized party cannot read the transferred data authentication one party can identify the other party and data integrity yo...

Page 212: ...address or domain name of the ONU you wish to access 27 8 1 Internet Explorer Warning Messages When you attempt to access the ONU HTTPS server a Windows dialog box pops up asking if you trust the serv...

Page 213: ...ain Screen After you accept the certificate and enter the login username and password the ONU main screen appears The lock displayed in the bottom right of the browser status bar denotes a secure conn...

Page 214: ...that you want to allow to access the ONU Service Port For Telnet SSH FTP HTTP or HTTPS services you may change the default service port by typing the new port number in the Server Port field If you c...

Page 215: ...ive Select this check box to activate this secured client set Clear the check box if you wish to temporarily disable the set without deleting it Start Address End Address Configure the IP address rang...

Page 216: ...Chapter 27 Access Control ONU User s Guide 216...

Page 217: ...verview This chapter explains the Diagnostic screen 28 2 Diagnostic Click Management Diagnostic in the navigation panel to open this screen Use this screen to check system logs ping IP addresses or pe...

Page 218: ...in the multi line text box Click Clear to empty the text box and reset the syslog entry IP Ping Type the IP address of a device that you want to ping in order to test a connection Click Ping to have...

Page 219: ...he following table describes the syslog severity levels 29 1 1 What You Can Do in the Syslog Screens The Syslog Setup screen lets you configure the ONU to send logs to an external syslog server Sectio...

Page 220: ...ting Logging Type This column displays the names of the categories of logs that the device can generate Active Select this option to set the device to generate logs for the corresponding category Faci...

Page 221: ...re critical the logs are Add Click Add to save your changes to the ONU s run time memory The ONU loses these changes if it is turned off or loses power so use the Save link on the top navigation panel...

Page 222: ...Chapter 29 Syslog ONU User s Guide 222...

Page 223: ...g example switch A in the basement is the cluster manager and the other switches on the upper floors of the building are cluster members Figure 126 Clustering Application Example Table 90 Clustering M...

Page 224: ...nt Cluster Management LABEL DESCRIPTION Status This field displays the role of this ONU within the cluster Manager Member you see this if you access this screen in the cluster member switch directly a...

Page 225: ...see if you accessed it directly are different Figure 128 Cluster Management Cluster Member Web Configurator Screen Model This field displays the model name Status This field displays Online the clust...

Page 226: ...01 23 46 rw rw rw 1 owner group 0 Jul 01 12 00 config 00 a0 c5 01 23 46 226 File sent OK ftp 297 bytes received in 0 00Seconds 297000 00Kbytes sec ftp bin 200 Type I OK ftp put 370lt0 bin fw 00 a0 c5...

Page 227: ...ESCRIPTION Clustering Manager Active Select Active to have this ONU become the cluster manager switch A cluster can only have one manager Other directly connected switches that are set to be cluster m...

Page 228: ...lustering Candidate list and then enter its web configurator password If that switch administrator changes the web configurator password afterwards then it cannot be managed from the Cluster Manager I...

Page 229: ...the following figure 1 The ONU examines a received frame and learns the port on which this source MAC address came 2 The ONU checks to see if the frame s destination MAC address matches a source MAC...

Page 230: ...ry table below MAC Click this button to display and arrange the data according to MAC address VID Click this button to display and arrange the data according to VLAN group Port Click this button to di...

Page 231: ...Works When an incoming packet destined for a host device on a local area network arrives at the ONU the ONU s ARP program looks in the ARP Table and if it finds the address sends it to the device If...

Page 232: ...scribes the labels in this screen Table 95 Management ARP Table LABEL DESCRIPTION Index This is the ARP Table entry number IP Address This is the learned IP address of a device connected to a ONU port...

Page 233: ...w you can copy the settings of one port onto other ports 33 2 Configure Clone Cloning allows you to copy the basic and advanced settings from a source port to a destination port or ports Click Managem...

Page 234: ...4 and 6 are the destination ports 2 6 indicates that ports 2 through 6 are the destination ports Note The GEPON uplink port is 26 and cannot be cloned Basic Setting Select which port settings you conf...

Page 235: ...235 PART VI Appendices and Index Product Specifications 237 IP Addresses and Subnetting 243 Legal Information 251 Customer Support 255 Index 261...

Page 236: ...236...

Page 237: ...rnet cable connector Auto negotiation Auto MDI MDI X Compliant with 802 3 802 3u Back pressure flow control in half duplex mode 802 3x flow control in full duplex mode Power budget management Gigabit...

Page 238: ...you copy the traffic to without interference Static Route Static routes tell the ONU how to forward IP traffic when you configure the TCP IP parameters manually Multicast VLAN Registration MVR Multica...

Page 239: ...VLAN group so as to be able to communicate with one another Table 99 Firmware Specifications FEATURE SPECIFICATION Default IP Address 192 168 1 1 Number of IP Addresses Configurable 64 Default Subnet...

Page 240: ...RADIUS authentication Multiple RADIUS servers Multiple TACACS servers 802 1X VLAN and bandwidth assignment Login authentication by RADIUS Login authentication by TACACS IP source guard Static IP MAC b...

Page 241: ...Standards Supported STANDARD DESCRIPTION RFC 826 Address Resolution Protocol ARP RFC 867 Daytime Protocol RFC 868 Time Protocol RFC 894 Ethernet II Encapsulation RFC 1112 Internet Group Management Pro...

Page 242: ...te IEEE 802 1x Port Based Network Access Control IEEE 802 1d MAC Bridges IEEE 802 1p Traffic Types Packet Priority IEEE 802 1q Tagged VLAN IEEE 802 1w Rapid Spanning Tree Protocol RSTP IEEE 802 1s Mul...

Page 243: ...a common street name the hosts on a network share a common network number Similarly as each house has its own house number each host on the network has its own unique identifying number the host ID R...

Page 244: ...rt of the host ID The following example shows a subnet mask identifying the network number in bold text and host ID of an IP address 192 168 1 2 in decimal By convention subnet masks always consist of...

Page 245: ...a continuous number of zeros for the remainder of the 32 bit mask you can simply specify the number of ones instead of writing the value of each octet This is usually specified by writing a followed b...

Page 246: ...the company network before subnetting Figure 136 Subnetting Example Before Subnetting You can borrow one of the host ID bits to divide the network 192 168 1 0 into two separate sub networks The subnet...

Page 247: ...254 Example Four Subnets The previous example illustrated using a 25 bit subnet mask to divide a 24 bit address into two subnets Similarly to divide a 24 bit address into four subnets you need to borr...

Page 248: ...3 IP SUBNET MASK NETWORK NUMBER LAST OCTET BIT VALUE IP Address 192 168 1 128 IP Address Binary 11000000 10101000 00000001 10000000 Subnet Mask Binary 11111111 11111111 11111111 11000000 Subnet Addre...

Page 249: ...TS SUBNET MASK NO SUBNETS NO HOSTS PER SUBNET 1 255 255 255 128 25 2 126 2 255 255 255 192 26 4 62 3 255 255 255 224 27 8 30 4 255 255 255 240 28 16 14 5 255 255 255 248 29 32 6 6 255 255 255 252 30 6...

Page 250: ...on t need to change the subnet mask computed by the ONU unless you are instructed to do otherwise Private IP Addresses Every machine on the Internet must have a unique address If your networks are iso...

Page 251: ...are described herein Neither does it convey any license under its patent rights nor the patent rights of others ZyXEL further reserves the right to make changes in any products described herein withou...

Page 252: ...ressly approved by the party responsible for compliance could void the user s authority to operate the equipment This Class A digital apparatus complies with Canadian ICES 003 Cet appareil num rique d...

Page 253: ...ct or consequential damages of any kind to the purchaser To obtain the services of this warranty contact ZyXEL s Service Center for your Return Material Authorization number RMA Products must be retur...

Page 254: ...Appendix C Legal Information ONU User s Guide 254...

Page 255: ...l support zyxel com tw Sales E mail sales zyxel com tw Telephone 886 3 578 3942 Fax 886 3 578 2439 Web www zyxel com www europe zyxel com FTP ftp zyxel com ftp europe zyxel com Regular Mail ZyXEL Comm...

Page 256: ...Web www zyxel fi Regular Mail ZyXEL Communications Oy Malminkaari 10 00700 Helsinki Finland France E mail info zyxel fr Telephone 33 4 72 52 97 97 Fax 33 4 72 52 19 20 Web www zyxel fr Regular Mail Zy...

Page 257: ...a ku Tokyo 141 0022 Japan Kazakhstan Support http zyxel kz support Sales E mail sales zyxel kz Telephone 7 3272 590 698 Fax 7 3272 590 689 Web www zyxel kz Regular Mail ZyXEL Kazakhstan 43 Dostyk Ave...

Page 258: ...i 1A 03 715 Warszawa Poland Russia Support http zyxel ru support Sales E mail sales zyxel ru Telephone 7 095 542 89 29 Fax 7 095 542 89 25 Web www zyxel ru Regular Mail ZyXEL Russia Ostrovityanova 37a...

Page 259: ...yXEL Thailand Co Ltd 1 1 Moo 2 Ratchaphruk Road Bangrak Noi Muang Nonthaburi 11000 Thailand Ukraine Support E mail support ua zyxel com Sales E mail sales ua zyxel com Telephone 380 44 247 69 78 Fax 3...

Page 260: ...Appendix D Customer Support ONU User s Guide 260...

Page 261: ...uto negotiating 40 B back up configuration file 196 bandwidth control egress rate 110 ingress rate 110 basic settings 65 binding 159 binding table 159 building 159 BPDUs Bridge Protocol Data Units 96...

Page 262: ...mapping 184 service level 181 what it does 182 DSCP DiffServ Code Point 181 dual personality port 40 dynamic link aggregation 116 E egress port 90 Ethernet broadcast address 231 Ethernet port 40 auto...

Page 263: ...snooping 132 MVR 137 ingress check 86 ingress port 90 Internet Assigned Numbers Authority See IANA 250 introduction 31 IP interface 72 setup 72 IP address definition 66 IP source guard 159 ARP inspect...

Page 264: ...ge 104 max hops 104 MST region 98 network example 98 path cost 105 port priority 105 revision level 104 MSTP Multiple Spanning Tree Protocol 95 MTU Multi Tenant Unit 69 multicast 131 802 1 priority 13...

Page 265: ...computers 215 resetting 53 194 to factory default settings 194 restoring configuration 53 196 RFC 3164 219 RSTP 95 S safety warnings 6 save configuration 53 194 screen summary 50 Secure Shell See SSH...

Page 266: ...9 TACACS Terminal Access Controller Access Control System Plus 145 tagged VLAN 79 temperature 237 time current 68 time zone 68 Time RFC 868 68 time server 68 time service protocol 68 format 68 tradema...

Page 267: ...6 type 70 82 VLAN Virtual Local Area Network 69 VSA 153 W warranty 252 note 253 web configurator 34 47 getting help 54 home 48 login 47 logout 54 navigation panel 49 screen summary 50 Weighted Round R...

Page 268: ...Index ONU User s Guide 268...

Reviews: