background image

 

 
 
 
 

VES-1616/24FA-5x Series 

VDSL Switch 

 

 
 
 
 
 
 
 

Support Notes 

 

 
 
 
 
 
 
 
 
 
 
 

Version1.0 

Apr. 2008   

 
 
 
 
 
 
 
 

   

Summary of Contents for VES-1616

Page 1: ...VES 1616 24FA 5x Series VDSL Switch Support Notes Version1 0 Apr 2008 ...

Page 2: ...LAN Overview 24 Port based VLAN 25 Port based VLAN across multiple switches 27 How to configure Port Based VLAN 28 What is IEEE 802 1Q Tag based VLAN 33 How 802 1Q VLAN works 34 Connecting Two Switches using VLAN 37 Setting up VLAN Trunking 40 VLAN Stacking Overview 44 Configuring Switch A E F and H Using the Web Configurator 46 Configuring Switch B Using the Web Configurator 46 Configuring Switch...

Page 3: ...gement 105 Introduction to SNMPc and NetAtlas 105 SNMPc Overview 106 EMS Overview 107 FAQ 114 What are the default IP parameter settings 114 What is the default login Name and Password to log into the Web Configurator 114 How to access my SWITCH through the console port 114 What is default login password for console telnet and FTP login 114 How to change the password 114 How to access the Command ...

Page 4: ...ator 1 Download and unzipped the correct model firmware to your computer 2 Click Management Maintenance in the navigator panel to display the following screen 3 Click the Click Here link for Firmware Upgrade to display the following screen 4 In the File Path field click Browse to locate the firmware file 5 Click Upgrade to start the firmware upgrade process Using the Console Port ...

Page 5: ...puter to log into switch From the command prompt type ftp Switch IP 3 Press ENTER when prompted for a user name 4 Enter the administrator login password to access the switch and display FTP prompt 5 Enter bin to set the transfer mode to binary 6 Use put to transfer the firmware from the computer to the switch for example put firmware bin ras 0 transfers the firmware on your computer firmware bin t...

Page 6: ... with a rom file extension 5 Enter ATGO to restart the switch after file transfer and the configuration restore processes are complete Using FTP 1 Download and unzipped the correct model firmware to your computer 2 Launch the FTP client on your computer to log into the switch From the command prompt type ftp Switch IP 3 Press ENTER when prompted for a user name 4 Enter the administrator login pass...

Page 7: ...link for Backup Configuration to display the following screen 3 Click Backup to display the File Download dialog Then click Save to back up the configuration text file to a location you specify on your computer Using the Console Port 1 Connect to the console port and launch a Terminal Emulation software 2 Restart the switch to enter the debug mode via the terminal 3 Enter ATTD 4 Use X modem protoc...

Page 8: ...r the administrator login password to access the switch and display FTP prompt 5 Enter bin to set the transfer mode to binary 6 Use get to transfer the configuration file from the switch to your computer for example get config config rom transfers the configuration file on the switch config to your computer and renames it config rom 7 Enter bye to log out from the switch Load Factory Defaults Usin...

Page 9: ...n the Terminal Emulation Software 2 Enter the administrator login password to log into the CLI Enter erase run to load the factory default configuration General Networking DHCP Relay Option 82 Application ISP may want to limit the number of IP address or provide some specific client IP addresses based on the switch ports VLAN ID and option 82 string They can easily achieve this with the DHCP Relay...

Page 10: ... series with a computer connected to a CPE to the first VDSL port The Option82 string is set to VES 1616FA 54 The IP address of the DHCP server IP Commander at 192 168 1 99 and it is to assign client IP addresses of 192 168 1 201 and 192 168 1 203 for VLAN ID 1 with Option82 string of VES 1616FA 54 1 Switch settings In the web configurator click Advanced Application DHCP in the navigation panel to...

Page 11: ...008 ZyXEL Communications Corporation 10 Next connect a computer to the Ethernet port of the CPE to the 1st VDSL port Refer to the previous application for more information 2 IP Commander setup Launch IP Commander and right click IP Commander and click Connect New Server ...

Page 12: ...4FA 5x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 11 Enter the IP address or domain name for the DHCP server and click OK For this example we enter 192 168 1 99 for the IP address ...

Page 13: ...XEL VES 1616 24FA 5x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 12 Enter the user name and password The default user name is administrator and password is incognito ...

Page 14: ...ES 1616 24FA 5x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 13 A screen displays Make sure that the status of your DHCP is online On the top menu click Wizard Rule Wizard ...

Page 15: ...ZyXEL VES 1616 24FA 5x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 14 Enter a name and description for the new rule ...

Page 16: ...FA 5x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 15 Specify one or a range of IP addresses for this rule In this example we configure an IP pool from 192 168 1 201 to 192 168 1 203 ...

Page 17: ...ZyXEL VES 1616 24FA 5x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 16 Next select DHCP Option in the Keywords field ...

Page 18: ...displays Select Option 82 Relay Agent Information set sub option 1and use binary data For port 1 VLAN 1 with option82 string of VES 1616FA 54 enter 0019000147532d33303132 as the key value and click OK Note that the first two bytes define the port number the second two bytes is the VLAN ID and the rest of the bytes are the Option 82 string ...

Page 19: ...ZyXEL VES 1616 24FA 5x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 18 After setting the fields you should see the following screen ...

Page 20: ...ZyXEL VES 1616 24FA 5x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 19 Click Next in the screen that displays ...

Page 21: ...ZyXEL VES 1616 24FA 5x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 20 Optionally you can create a new DHCP template with information such as gateway DNS server etc ...

Page 22: ...ZyXEL VES 1616 24FA 5x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 21 Here enter 192 168 1 1 as gateway IP address for DHCP clients ...

Page 23: ...ZyXEL VES 1616 24FA 5x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 22 You can choose to enable DDNS service on the DHCP server ...

Page 24: ...ZyXEL VES 1616 24FA 5x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 23 Click Finish to complete the rule creation ...

Page 25: ...your computer should be able to get an IP address of 192 168 1 201 when a DHCP request is sent Separating a physical network into multiple virtual networks What is Virtual LAN VLAN Overview A VLAN Virtual Local Area Network allows a physical network to be partitioned into multiple logical networks Stations on a logical network belong to a group ...

Page 26: ...ll broadcasts are confined to a specific broadcast domain There are two VLAN implementations Port based VLAN and IEEE 802 1q Tagged VLAN VES 1616F 3X supports both VLAN implementations The major difference between both VLAN implementations is that Tagged VLAN can cross Layer 2 switches but Port based VLAN cannot Port based VLAN Port based VLANs are VLANs where the packet forwarding decision is bas...

Page 27: ...here are three VLAN groups in the physical network Hosts A and B can communicate with each other since they are in the same VLAN group VLAN 1 Hosts B and C are in VLAN group 2 Hosts A D and E are in VLAN group 3 Port based VLAN definition z Egress port for port 1 port 2 port 4 port 5 z Egress port for port 2 port 1 port 3 z Egress port for port 3 port 2 z Egress port for port 4 port 1 port 5 z Egr...

Page 28: ... For Switch 3 ports 2 3 and 4 are allowed to communicate with uplink port 1 but not with other ports z Switch 3 VLAN 1 member port port 2 and port 1 z Switch 3 VLAN 2 member port port 3 and port 1 z Switch 2 VLAN 3 member port port 4 and port 1 Host A cannot communicate with Host B due to the port based VLAN implementation on Switch 2 Host C cannot communicate with Host D due to the port based VLA...

Page 29: ...municate with uplink port 4 but not with other ports z Switch 1 VLAN 1 member port port 1 and port 4 z Switch 1 VLAN 2 member port port 2 and port 4 z Switch 1 VLAN 3 member port port 3 and port 4 How to configure Port Based VLAN Port based VLANs are VLANs where the packet forwarding decision is based on the destination MAC address and its associated port ...

Page 30: ...which they were created Configuring the Switch Using the Web Configurator 1 Use an RJ 45 Ethernet cable to connect a computer to the management port on the switch 2 By default the management IP address of the switch is 192 168 0 1 24 3 Set the IP settings on your computer to 192 168 0 2 24 4 Open a web browser such as IE and enter http 192 168 0 1 as the URL 5 When prompted enter admin as the user...

Page 31: ...Type field Click Apply to save your changes 8 Next create logical partitions on the switch Click Advanced Application VLAN in the navigation panel and select the ports to belong to the VLAN For this example select ports 1 4 and 17 18 to belong to a VLAN so they can communicate with each other Although ports 5 8 are in another group both groups cannot communicate with each other Here we also define...

Page 32: ...me The configuration screen should look similar to the screen as shown 9 Finally verify the settings If you have configured the VLAN settings properly PC A can ping PC B and PC Z but not PC C or PC D and vice versa 10 For example PC A 192 168 1 4 24 PC B 192 168 1 5 24 PC C 192 168 1 6 24 PC D 192 168 1 7 24 PC Z 192 168 1 99 24 11 PING PC B from PC A successful reply messages 12 PING PC Z from PC...

Page 33: ...sole port on the switch 2 Open your Terminal program for example Hyper Terminal in Windows System 3 Make sure the console connection settings are configured as listed below Bps 9600 Data bits 8 Parity None Stop bits 1 Flow control None 4 After you can connect successfully enter the user name and password 5 Enter config to go into the configuration mode 6 Enter the following commands to configure P...

Page 34: ...e across bridges This tag is used for VLAN and QoS Quality of Service priority identification The VLANs can be created statically by an administrator or dynamically through GVRP The VLAN ID associates a frame with a specific VLAN and provides the information that switches need to process the frame across the network A tagged frame is four bytes longer than an untagged frame and contains two bytes ...

Page 35: ...be forwarded as it is to an untagged port z VID VLAN ID is the identification of the VLAN which is used by the standard 802 1Q It is 12 bits long and allows the identification of 4096 2 12 VLANs Of the 4096 possible VIDs a VID of 0 is used to identify priority frames and value 4095 FFF is reserved so the maximum possible VLAN configurations are 4 094 z Note that user priority and VLAN ID are indep...

Page 36: ...tagged frames on the port When a tagged frame is received on a port it carries a tag header that has an explicit VID Ingress Process directly passes the tagged frame to Forwarding Process An untagged frame does not carry any VID to which it belongs When an untagged frame is received Ingress Process inserts a tag contained the PVID into the untagged frame Each physical port has a default VID called...

Page 37: ... in Filtering Database have the following information 1 VID VLAN ID 2 Port The switch port number 3 Ad Control Registration administration control There are 3 types of ad control including forbidden registration fixed registration and normal registration z Forbidden registration This port is forbidden to be the egress port of the specified VID z Fixed registration While ad control is fixed registr...

Page 38: ...gress port is tagged If the value is untagged the tag will be removed before a frame leaves the egress port Connecting Two Switches using VLAN This example shows you how to configure VLAN settings on two VES 1616FA 54 switches which are connected using the Ethernet port There are five VLANs on the first switch and seven VLANs on the second switch The Ethernet port is port 17 on both switches VLANs...

Page 39: ...nts co nfiguration 02 103 10 02 103 10 figuration o figuration o opyright 2008 ns on the tw 04 105 10 04 105 on on switch A on switch B VE 8 ZyXEL Com wo switche 06 107 on n switch B A B ES 1616 24F mmunication es are as fo switch A FA 5x Series ns Corporatio ollows s Support N on Notes 38 ...

Page 40: ... VID 106 port 11 12 13 17 TAG VID 107 port 14 15 16 17 TAG In switch B add port 17 in each VLAN VID 101 port 1 2 3 17 TAG VID 102 port 4 5 6 17 TAG VID 103 port 7 8 9 17 TAG VID 104 port 10 11 12 17 TAG VID 105 port 13 14 15 16 17 TAG Clients in the same VLAN on both switches can communicate with each other PVID Set PVID on switch A Port 1 2 101 Port 3 4 102 Port 5 6 103 Port 7 8 104 Port 9 10 105...

Page 41: ...nking port ng port whi figure sho ation scree opyright 2008 5 ng oying VLAN onfigured a switch 1 c In this exa ile on VES ows the net n for switc VE 8 ZyXEL Com N trunking as the VLAN an reach P ample por S 2 port 17 twork exam ch 1 is show ES 1616 24F mmunication you can c N trunking PC 2 conne rt 17 on VE 7 is the VLA mple wn as follo FA 5x Series ns Corporatio connect tw port VLA ected to sw ES...

Page 42: ...ZyXEL VES 1616 24FA 5x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 41 The configuration screen for switch 2 is shown as follows ...

Page 43: ...ration 42 In the VES 1 we set port 1 as VLAN 2 untag In the VES 2 we set port 2 as VLAN 2 untag The switch 1 IP address 192 168 1 31 The switch 2 IP address 192 168 1 21 After the configuration you can see that PC 1 connected to port 2 on switch 1 can still ping PC 2 connected to port 6 on switch 2 ...

Page 44: ...ZyXEL VES 1616 24FA 5x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 43 ...

Page 45: ... In this example company XX and company YY both subscribe to the same ISP for Internet service Both companies have an internal VLAN group with VID 1 In order to prevent VLAN tagged packets between these two companies from transmitting to each other s network VLAN stacking is implemented in the ISP s network The ISP assigns a service provider VID for each company company XX is assigned an SP VID of...

Page 46: ...ic and the SP tag is removed during egress VLAN Stacking is enabled on a Tunnel port on switches G port 9 C and B From Switch A to Switch H Switch A Enabled VLAN VLAN1 and egress tagging on Port 17 Port 1 is connected to another access switch in a building Port 17 is connected to port 11 on Switch B Switch B Enabled VLAN Stacking and STP Port 1 is connected to port 17 on Switch A Port 2 is connect...

Page 47: ... already created for you The setting required is to make sure that port 17 is a member of VLAN 1 and that egress tagging is enabled on the port By default all the ports in VLAN 1 are untagged during Egress Configuring Switch B Using the Web Configurator 1 Use an RJ 45 Ethernet cable to connect your computer to the MGMT port on the switch 2 By default the IP address on the MGMT port is 192 168 0 1 ...

Page 48: ...ntents copyright 2008 ZyXEL Communications Corporation 47 7 First create VLAN groups for the ISP s network For this example VLAN 30 for company XX and VLAN 40 for company YY Click Advanced Application Switch Advance VLAN and click the Static VLAN link ...

Page 49: ...8 Create a VLAN with a VID of 30 Select Fixed and un select Tx Tagging for port 1 For port 25 select both Fixed and Tx Tagging 9 Create another VLAN with a VID of 40 Select Fixed and un select Tx Tagging for port 2 10 For port 12 select both Fixed and Tx Tagging The VLAN Status screen should display as shown ...

Page 50: ...ons Corporation 49 11 To configure VLAN Stacking click Advanced Application VLAN Stacking in the navigation panel to display the configuration screen 13 To enable VLAN stacking select Active Set ports 1 and 2 as the access port and enter the corresponding SPVIDs as shown in the figure above ...

Page 51: ...witch 2 By default the IP address on the MGMT port is 192 168 0 1 24 3 Set your computer to use a static IP address in the same subnet for example 192 168 0 2 24 4 Open a web browser such as IE and enter http 192 168 0 1 as the URL 5 A login screen displays Enter admin the default as the username and 1234 the default as the password 6 After you have logged in successfully the main screen displays ...

Page 52: ...ions Corporation 51 Follow the steps in the previous section to configure VLANs 30 and 40 of which ports 9 10 and 11 are members After the configuration the VLAN Status screen should look similar to the figure as shown 11 To configure VLAN Stacking click Advanced Application VLAN Stacking ...

Page 53: ...ple Configuring Switch D Using the Web Configurator 1 Use an RJ 45 Ethernet cable to connect your computer to the MGMT port on the switch 2 By default the IP address on the MGMT port is 192 168 0 1 24 3 Set your computer to use a static IP address in the same subnet for example 192 168 0 2 24 4 Open a web browser such as IE and enter http 192 168 0 1 as the URL 5 A login screen displays Enter admi...

Page 54: ...ntents copyright 2008 ZyXEL Communications Corporation 53 7 First create VLAN groups for the ISP s network For this example VLAN 30 for company XX and VLAN 40 for company YY Click Advanced Application Switch Advance VLAN and click the Static VLAN link ...

Page 55: ...ction to configure VLAN 30 of which ports 1 and 12 are members Since port 1 is an Access Port un select the Tx Tagging field After the configuration the VLAN Status screen should look similar to the figure as shown 8 To configure VLAN Stacking click Advanced Application VLAN Stacking in the navigation panel to display the configuration screen ...

Page 56: ...itch G Using the Web Configurator 1 Use an RJ 45 Ethernet cable to connect your computer to the MGMT port on the switch 2 By default the IP address on the MGMT port is 192 168 0 1 24 3 Set your computer to use a static IP address in the same subnet for example 192 168 0 2 24 4 Open a web browser such as IE and enter http 192 168 0 1 as the URL 5 A login screen displays Enter admin the default as t...

Page 57: ...ntents copyright 2008 ZyXEL Communications Corporation 56 7 First create VLAN groups for the ISP s network For this example VLAN 30 for company XX and VLAN 40 for company YY Click Advanced Application Switch Advance VLAN and click the Static VLAN link ...

Page 58: ...of which ports 1 and 12 are members Since port 12 is a TunnelPort select the Tx Tagging field For the Access Port port 1 un select the Tx Tagging field After the configuration the VLAN Status screen should look similar to the figure as shown 8 To configure VLAN Stacking click Advanced Application VLAN Stacking in the navigation panel to display the configuration screen ...

Page 59: ...ents copyright 2008 ZyXEL Communications Corporation 58 To enable VLAN stacking select Active Set port 25 as the tunnel port and leave the SPVID field to the default settings 9 You have finished setting Switch G for VLAN stacking for this network example ...

Page 60: ...port members By default VLAN1 is already created for you The setting required is to make sure that port 17 is a member of VLAN 1 and that egress tagging is enabled on the port By default all the ports in VLAN 1 are untagged during Egress 2 Connect your computer to the console port on the switch 3 Open a Terminal program for example Hyper Terminal in Windows 4 Configure the console port settings as...

Page 61: ...17 will be tagged during Egress 8 After entering the commands use the write memory command in the enable mode to save your configuration Configuring Switch B Using the CLI 1 Connect your computer to the console port on the switch 2 Open a Terminal program for example Hyper Terminal in Windows 3 Configure the console port settings as shown next Bps 9600 Data bits 8 Parity None Stop bits 1 Flow cont...

Page 62: ...e console port on the switch 2 Open a Terminal program for example Hyper Terminal in Windows 3 Configure the console port settings as shown next Bps 9600 Data bits 8 Parity None Stop bits 1 Flow control None 4 After you are connected successfully the login prompt displays Enter the administrator login username admin and password 1234 is the default 5 Enter config to go into the configuration mode ...

Page 63: ...on the switch 2 Open a Terminal program for example Hyper Terminal in Windows 3 Configure the console port settings as shown next Bps 9600 Data bits 8 Parity None Stop bits 1 Flow control None 4 After you are connected successfully the login prompt displays Enter the administrator login username admin and password 1234 is the default 5 Enter config to go into the configuration mode 6 Enter the com...

Page 64: ... VES 1616 24FA 5x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 63 6 After entering the commands use the write memory command in the enable mode to save your configuration ...

Page 65: ...passing IGMP messages After that the switch records the message s group registration information and configures the multicasting information accordingly If the multicast group information is unknown not recorded on the switch the switch discards that multicast traffic Only the registered clients that join the group will receive multicast stream from the IGMP router Thus this significantly reduces ...

Page 66: ...is example we enable the IGMP function on the GS 4024 an IGMP router to connect to a multimedia server Also we enable IGMP snooping function on the VES 1616F 3X the multimedia clients are connect to 1 In GS 4024 click the IP Application select IGMP where IGMP function can be enabled and we can select either IGMP v1 or IGMP v2 233 4 4 4 Group member Not a member Media Stream Server 233 4 4 4 GS 402...

Page 67: ...click Advanced Application Multicast Multicast Setting and then IGMP Snooping where we can enable IGMP snooping function with WEB GUI Configuration of IGMP and IGMP snooping by CLI 1 Enable IGMP function in GS 4024 In the configure mode GS 4024 config router igmp 2 Enable IGMP snooping in VDSL switch In the configure mode of CLI ...

Page 68: ...N Registration that enables a media server to transmit multicast stream in a single multicast VLAN while clients receiving multicast VLAN stream can reside in different VLANs Clients in different VLANs intending to join or leave the multicast group simply send the IGMP Join leave message to a receiver port The receiver port belonging to one of the multicast groups can receive multicast stream from...

Page 69: ...mic mode in MVR setting IGMP report message transmitted from the receiver port will be forwarded to a multicast router through its source CH1 VLAN1 CH1 VLAN2 CH1 VLAN4 CH1 VLAN5 CH1 VLAN6 CH1 VLAN3 1 multicast stream VES 1616F GS 4024 CH1 VLAN1 CH1 VLAN2 CH1 VLAN4 CH1 VLAN5 CH1 VLAN6 CH1 VLAN3 single multicast stream VES 1616F GS 4024 Figure 2 Figure 1 ...

Page 70: ... sends an IGMP leave message to the switch to leave the multicast The switch CPU sends an IGMP group specific query through the receiver port VLAN If there is another subscriber in the VLAN subscriber must respond within the max response time If there is no subscriber the switch eliminates this receiver port z Immediate Leave Operation Subscriber sends an IGMP leave message to the switch to leave ...

Page 71: ...VLAN Configuration create a new VLAN 100 Figure 4 VLAN Configuration 2 In the GS 4024 click the Advanced Application and then select the VLAN In the VLAN port Setting set the PVID of the port 10 to 100 as the multicast traffic that flows from media server to port 10 must be tagged with PVID 100 to communicate with the port in MVR VLAN 100 in VES 1616F 3X GS 4024 VES 1616F VLAN 30 VLAN 40 VLAN 50 P...

Page 72: ...616FA 54 in the Advanced Application MVR configure the MVR VLAN 100 Define port 1 port 2 and port 3 as the receiver ports for forwarding the multicast stream to the clients in different VLANs set port 17 as a source port to receive traffic from the media server Also select mode as dynamic mode The switch sends IGMP report message to multicast router through its source port ...

Page 73: ...pplication VLAN Status and check whether there is the new VLAN 100 added in the VLAN list We also create three separate VLANs 30 40 50 and assign their PVID as 30 40 and 50 respectively Open Advanced Application VLAN Static VLAN to add a new VLAN Tick the Active box type VLAN Name 30 and VLAN ID 30 in the columns Change Port 1 and Port 17 to fixed and keep port 17 tx tagging ...

Page 74: ...unications Corporation 73 Open Advanced Application VLAN Static VLAN to add a new VLAN Tick the Active box type VLAN Name 40 and VLAN ID 40 in the columns Change Port 2 and Port 17 to fixed and keep port 17 tx tagging Open Advanced Application VLAN Static VLAN to add a new VLAN Tick ...

Page 75: ...me 50 and VLAN ID 50 in the columns Change Port 3 and Port 17 to fixed and keep port 17 tx tagging Open Advanced Application VLAN VLAN Port Setting to change PVID for the ports 1 2 and 3 5 Before we start to use the MVR it is fundamental to enable the IGMP Snooping first In the VES 1616FA 54 Menu click the Multicast go to the Multicast ...

Page 76: ...so that only the clients belonging to that range of multicast group will receive the multicast traffic Configuration via CLI Step 1 On the VES 1616FA 54 in the configure mode create VLAN 100 VES 1616FA 54 config VES 1616FA 54 config vlan 100 Step 2 In the VLAN 100 set the port 17 to be fixed port VES 1616FA 54 config vlan fixed 17 Step 3 On the VES 1616FA 54 in the configure mode create VLAN 30 an...

Page 77: ...terface port channel 2 VES 1616FA 54 config interface pvid 40 VES 1616FA 54 config interface exit Step 8 On the VES 1616FA 54 set the PVID of specific VLAN 50 VES 1616FA 54 config interface port channel 3 VES 1616FA 54 config interface pvid 50 VES 1616FA 54 config interface exit Step 9 On the VES 1616FA 54 in the configure mode enable IGMP snooping VES 1616FA 54 config igmpsnooping Step 10 On the ...

Page 78: ...e tr P service V er IP over A 54 need to ena traffic flow plication check the A Multicast V VE 8 ZyXEL Com tion and more application achieve trip elow raffic flows VLAN ID 2 Ethernet t able IGMP ws are go t MVR to c Active che VLAN ID ES 1616 24F mmunication popular re n and this ple play ap with differ 203 is for P raffic and V P feature in hrough VE configure th ckbox to e FA 5x Series ns Corpor...

Page 79: ...configuration page check the VDSL port 1 to receive port and port 17 to Source port and make sure the check Tx Tagging for port 1 and port 17 3 Click the Group configuration link to configure the multicast group IP Fill in the name for MVR and the IP range start IP address is 224 1 100 20 and End Address is 224 1 100 200 ...

Page 80: ... page To avoid the unknown multicast frames flooding to all VDSL ports check the Drop to make sure the unknown multicast frames will be dropped Click Apply button to save the settings 5 Open Advanced Application VLAN and click static VLAN link to create VLAN Check the ACTIVE checkbox to enable and fill in the VLAN name VoIP and VLAN ID 201 Configure port 1 and port 17 to Fixed and check the Tx Tag...

Page 81: ...Support Notes All contents copyright 2008 ZyXEL Communications Corporation 80 Check the ACTIVE checkbox to enable and fill in the VLAN name Data and VLAN ID 203 Configure port 1 and port 17 to Fixed and check the Tx Tagging checkbox ...

Page 82: ...upport Notes All contents copyright 2008 ZyXEL Communications Corporation 81 Check the ACTIVE checkbox to enable and fill in the VLAN name IPTV and VLAN ID 3988 Configure port 1 and port 17 to Fixed and check the Tx Tagging checkbox ...

Page 83: ...ate different WAN interfaces in the VDSL modem for different traffic flows and also we need to create classification rule to identify these different traffic flows In this document we will use P 870H 51 for the configuration example The management IP address of P 870H 51 is 192 168 1 1 After logging in the first step is to create WAN Interface 1 Create WAN Interface via WEB GUI ...

Page 84: ...n to add a new interface Then check the VLAN Mux option to enable the IEEE 802 1Q VLAN on this Interface and fill in the VLAN ID Click the Enable Quality of Service option to enable QoS feature on P 870H 51 then click the next button to move to the next step In the connection type configuration page select Bridging mode and click the next button to move to the next configuration step ...

Page 85: ...o the next configuration step page The last is the confirmation page click the save button to save and finish the process of creating the WAN interface Repeat the above steps to create the other three interfaces with the VLAN ID 201 3988 and 4001 2 Create a Queue for the WAN Interface via WEB GUI Open Advance Setup Queue Config and click the Add button to open the QoS Queue configuration page ...

Page 86: ...ess of creating the WAN interfaces and Queue click the Save Reboot button on the Queue Config page to save the above settings and reboot the device for the changes to take effect 3 Configuration the QoS classification to classify traffic flow Open Advanced Setup QoS Classification page to classify traffic flow Click ADD button to add a new classification rule in this document we need create classi...

Page 87: ...er words that it would be added the VLAN ID when sent through this WAN Interface and that is why we enable the VLAN Mux For example the PPPoE 1 and PPPoE 2 need to be added the VLAN ID 203 we select the WAN interface which will add the VLAN ID 203 for these two rules Scroll down the page to configure the other parameters On this page there are two sets of the traffic parameters used to define the ...

Page 88: ...tting which will combine all traffic from the Ethernet port 4 of P 870H 51 with the VLAN ID 201 To make sure the CLI command works properly we need to make sure the order of rule for the VLAN 201 is 1 This should help us to make sure the CLI command can map to the correct WAN interface with correct VLAN ID Click the Save Apply button at the QoS classification page to save and finish all the settin...

Page 89: ...ZyXEL Communications Corporation 88 After logging in the CLI of P 870H 51 we can see the picture below showing the list of the commands and other information Type sh command to enter the CLI mode After that enter the below commands to configure the port based VLAN settings ...

Page 90: ...copyright 2008 ZyXEL Communications Corporation 89 ebtables I INPUT 1 i eth1 4 j mark set mark 0x80004 The second command is ebtables I FORWARD 1 i eth1 4 j mark set mark 0x80004 After issuing these two commands the settings are done Type exit to exit the CLI ...

Page 91: ...se P 870H 51 to classify the service flows Let s review what we done we classified the traffic for VoIP PPPoE for Internet Access and IPoE for VoD With these settings P 870H 51 can work as a home gateway to help service provider to provide VoIP service to customer at the Ethernet port 4 and Internet access and IPTV service on the remaining ports ...

Page 92: ...ct with other STP compliant devices in your network to ensure that only one path exists between any two stations on the network The redundant topology without STP will cause the following problem 1 Broadcast storm Without Spanning Tree loop avoidance mechanism each switch will endlessly flood broadcast packets to all ports This situation is called broadcast storm z When Host sends a broadcast fram...

Page 93: ...f the host on Port 2 z Switch A has not yet learned the MAC address of Router So Switch A will flood a copy of the received frame to Segment B z When the copy of the frame from Switch A arrives at Switch B Switch B will remove the first entry Host MAC address on Port 2 in Filtering Database and add a new mapping of Host MAC address on Port 1 Switch B incorrectly learn Host MAC address on Port 1 z ...

Page 94: ...ge ID Each bridge has unique bridge ID The root bridge is the bridge with the lowest bridge ID in the spanning tree network z The bridge ID includes two parts bridge priority 2 bytes and bridge MAC address 6 bytes The 802 1d default bridge priority is 32768 E g for a switch with default priority 32768 8000 hex MAC address is 00 A0 C5 12 34 56 its bridge ID is 8000 00A0 C512 3456 z On the root brid...

Page 95: ...port How STP works After STP determines the lowest cost spanning tree it enables all root ports and designated ports and disables all other ports Network packets are therefore only forwarded between root ports and designated ports eliminating any possible network loops STP aware devices exchange Bridge Protocol Data Units BPDUs periodically Whenever the bridged LAN topology changes a new spanning ...

Page 96: ...ort 1 path cost to root bridge is 19 Port 2 path cost is 119 100 Switch A Port 2 19 Switch B Port 1 For Switch B Port 1 path cost is 19 Port 2 path cost is 119 Root port Port 1 of Switch A and Switch B because it has the lowest path cost to the root bridge Switch C 3 On Segment A both Port 2 of Switch A and Switch B have the same path cost to root bridge Since Switch A has lower bridge ID than Swi...

Page 97: ...se ports thus denying network access for computers within unknown MAC addresses Without the MAC limit function any computer can access the network through a switch port The port automatically learns the computer s MAC address and stores it to the MAC address table Activate the MAC limit function on a port by entering the port security port number command in the CLI The following figure shows an ex...

Page 98: ...ZyXEL VES 1616 24FA 5x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 97 ...

Page 99: ...ink to display RADIUS configuration screen as shown Set the RADIUS server IP address UDP port and shared Secret Make sure the information you have entered is the same as the RADIUS server Then click Apply to make the settings take effect Click the 802 1x link to display the 802 1x configuration screen Select the Active check box to enable and then select the Active for a port to enable 802 1x auth...

Page 100: ... configure the same settings on the client Create User Account Click RADIUS USER ACCOUNT in the navigation panel to display the configuration screen as shown You can use the existing user accounts or create a new one by clicking the Add New User button Note that the client site MUST use the account in the RADIUS server Supplicant Setup Windows XP You can use any supplicant software such as Meeting...

Page 101: ...Area connection Properties screen and click the Authentication tab Select the Enable IEEE 802 1x authentication for this network option and select MD5 challenge in the EAP type field The following figure shows an example When 802 1x authentication process starts you are prompted to enter the user name and password The following figure shows the prompt ...

Page 102: ...e message window and a login screen displays as shown Enter your account user name and password in the fields provided After you click OK and the authentication server has verified your account you can log into the system successfully This indicates that you have configured the client for 802 1x authentication correctly ...

Page 103: ...information such as the source address destination address port number and packet format In this example we group traffic based on the packet format and set the VES 1616F 3X to apply its policy rules The following lists the three classifier rules that we will define in this example 1 Packet with a source IP address of 192 168 1 20 2 Packets on port 2 3 ARP traffic for testing Once packet classific...

Page 104: ...x Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 103 The following figures show the screen settings for each classifier rule Classifier Configuration Classifier 1 Classifier 2 Classifier 3 ...

Page 105: ...Support Notes All contents copyright 2008 ZyXEL Communications Corporation 104 Policy Rule Configuration The following figures show the screen settings for each policy rule 1 Policy rule on Classifier 1 2 Policy rule on classifier 2 ...

Page 106: ...t Notes All contents copyright 2008 ZyXEL Communications Corporation 105 3 Policy rule on classifier 3 Centralized Management Introduction to SNMPc and NetAtlas With the number of network device increasing the demand to detect and respond ...

Page 107: ...rmance management and security for all ZyXEL s Ethernet switches SNMPc is a network management software produced by Castle Rock that constantly probes the network element NE and collects information from these NE for the EMS Running in the background to provide queries for the EMS is PostgreSQL an enterprise relational database system Figure 1 System Architecture SNMPc Overview The following figur...

Page 108: ...mands z Device Panel This is a graphical device display z Device List Panel View devices in a tree structure The colors of the device indicate the status of the devices Green means the device is working properly and Red indicates no response from the device z System message Panel View the alarm and port status of the selected switch Figure 3 EMS Overview Main Button Bar Edit Button Bar View Window...

Page 109: ...yXEL Communications Corporation 108 Adding a new device in SNMPc This section shows you how to add a new device in SNMPc and access the EMS screen 1 In the edit button bar shown in Figure 4 click the Insert Device icon to create a new device node Figure 4 Adding a new Device ...

Page 110: ...n displays Enter a descriptive name in the Label field Then enter the IP address of the device in the Address field For this example we enter 192 168 0 1 as the IP address of the switch Figure 5 Map Object Properties 3 Click the Access tab to configure SNMP settings Change the value for Read Access Mode to SNMP V2c Figure 6 Read Access mode ...

Page 111: ...yright 2008 ZyXEL Communications Corporation 110 4 Change the value for Read Write Access Mode to SNMP V2c Screen settings should be similar to the one shown Figure 7 Read Write Access Mode 5 Change the value for Read Community to public Figure 8 Read Community ...

Page 112: ...ZyXEL Communications Corporation 111 6 Change the value for Read Write Community to public Click OK to save the settings and close this screen Figure 9 Read write Community 7 In the Selection tool menu click the name of the switch you have just created to manage the device ...

Page 113: ... Device Selection 8 A screen displays as shown Click Switch Manager to display the main EMS screen as shown in Figure 11 Figure 11 Device Selection 9 The device list panel on the left displays a logical hierarchy of the devices You can also see the devices added under the Rootmap in this list Figure 12 shows an example ...

Page 114: ... Series Support Notes All contents copyright 2008 ZyXEL Communications Corporation 113 Figure 12 Rootmap 10 Click on a switch icon to display the device panel and status screen as shown in Figure 13 Figure 13 Device mapping ...

Page 115: ... port COM1 COM2 or other COM port of your computer Launch a terminal emulation software configured to the follow settings Terminal emulation VT100 Baud rate 115200 bps Data bits 8 Parity none Stop bit 1 Flow control none What is default login password for console telnet and FTP login Password 1234 How to change the password You can only change the administrator login password in the web configurat...

Page 116: ...reload the factory default configuration Note that all your previous configuration will be lost 1 Connect the console cable to your computer and launch a terminal emulation software 2 Restart the switch and press any key to enter the debug mode at the Press any key to enter Debug Mode within 3 seconds prompt 3 Enter atlc 4 When the starting XMODEM upload message displays start XMODEM upload of the...

Page 117: ...creen Is Online Help available on the Web Configurator Yes You can click on the Help link in any web configurator screen to display the help content for that screen How to restart device from the Web Configurator 1 Click Management Maintenance in the navigation panel to display the screen as shown 2 Click Click Here button next to Reboot System will restart the switch How to check the current runn...

Page 118: ...operating What is Dual Personality interface on a VDSL Switch Dual Personality GbE interface means that one 1000Base T Copper port and one SFP port shares the same physical interface Only one of them can be used at a time Dual Personality interface is also known as a Combo Port Can I enable IGMP snooping on the Switch which is acting as an IGMP Router No You do not need to enable IGMP Snooping on ...

Reviews: