background image

 

Default Login Details

User’s Guide

XGS1930 Series

24/48-port GbE Smart Managed Switch

Copyright © 2021 Zyxel Communications Corporation

LAN IP Address

http://DHCP-assigned

IP or 192.168.1.1

User Name

admin

Password

1234

Version 4.70 Edition 1, 01/2021

Summary of Contents for XGS1930-28HP

Page 1: ...ser s Guide XGS1930 Series 24 48 port GbE Smart Managed Switch Copyright 2021 Zyxel Communications Corporation LAN IP Address http DHCP assigned IP or 192 168 1 1 User Name admin Password 1234 Version...

Page 2: ...ery effort has been made to ensure that the information in this manual is accurate Related Documentation Quick Start Guide The Quick Start Guide shows how to connect the Switch Online Help Click the h...

Page 3: ...field labels and field choices are all in bold font A right angle bracket within a screen name denotes a mouse click For example Basic Setting IP Setup IP Configuration Network Proxy Configuration me...

Page 4: ...MAC Forwarding 130 Static Multicast Forwarding 132 Filtering 135 Spanning Tree Protocol 137 Bandwidth Control 152 Broadcast Storm Control 154 Mirroring 156 Link Aggregation 158 Port Authentication 166...

Page 5: ...ntrol 302 Diagnostic 323 System Log 326 Syslog Setup 327 Cluster Management 330 MAC Table 336 IP Table 339 ARP Table 341 Routing Table 343 Path MTU Table 345 Configure Clone 346 IPv6 Neighbor Table 34...

Page 6: ...g Example 24 1 2 4 IEEE 802 1Q VLAN Application Examples 25 1 3 Ways to Manage the Switch 26 1 4 Good Habits for Managing the Switch 26 Chapter 2 Hardware Installation and Connection 27 2 1 Installati...

Page 7: ...48 4 4 1 Basic 48 4 4 2 VLAN 55 4 4 3 QoS 56 4 5 Web Configurator Layout 57 4 5 1 Change Your Password 61 4 6 Save Your Configuration 62 4 7 Switch Lockout 62 4 8 Reset the Switch 63 4 8 1 Restore But...

Page 8: ...ANs 84 8 5 Switch Setup 85 8 6 IP Setup 86 8 6 1 IP Interfaces 86 8 6 2 IP Status 87 8 6 3 IP Status Details 87 8 6 4 IP Configuration 88 8 6 5 Network Proxy Configuration 90 8 7 Port Setup 91 8 8 PoE...

Page 9: ...9 5 Configure a Static VLAN 120 9 6 Configure VLAN Port Settings 122 9 7 Voice VLAN 123 9 8 Vendor ID Based VLAN 125 9 9 Port Based VLAN Setup 127 9 9 1 Configure a Port Based VLAN 127 Chapter 10 Sta...

Page 10: ...ST Region 150 13 8 3 MST Instance 151 13 8 4 Common and Internal Spanning Tree CIST 151 Chapter 14 Bandwidth Control 152 14 1 Bandwidth Control Overview 152 14 1 1 What You Can Do 152 14 2 Bandwidth C...

Page 11: ...Chapter 20 Time Range 176 20 1 Time Range Overview 176 20 1 1 What You Can Do 176 20 2 Configuring Time Range 176 Chapter 21 Classifier 178 21 1 Classifier Overview 178 21 1 1 What You Can Do 178 21...

Page 12: ...02 25 1 1 What You Can Do 202 25 1 2 What You Need to Know 202 25 2 AAA Screens 203 25 3 RADIUS Server Setup 203 25 4 AAA Setup 205 25 5 Technical Reference 207 25 5 1 Vendor Specific Attribute 207 25...

Page 13: ...oE Intermediate Agent 231 29 3 1 PPPoE IA Per Port 232 29 3 2 PPPoE IA Per Port Per VLAN 233 29 3 3 PPPoE IA for VLAN 234 Chapter 30 Error Disable 236 30 1 Error Disable Overview 236 30 1 1 CPU Protec...

Page 14: ...267 33 2 Static Routing 268 33 3 IPv4 Static Route 268 33 4 IPv6 Static Route 269 Chapter 34 DHCP 271 34 1 DHCP Overview 271 34 1 1 What You Can Do 271 34 1 2 What You Need to Know 271 34 2 DHCP Confi...

Page 15: ...nload 297 36 7 Certificates 297 36 7 1 HTTPS Certificates 298 36 8 Technical Reference 299 36 8 1 FTP Command Line 299 36 8 2 Filename Conventions 299 36 8 3 FTP Command Line Procedure 300 36 8 4 GUI...

Page 16: ...Syslog Setup 327 Chapter 41 Cluster Management 330 41 1 Cluster Management Overview 330 41 1 1 What You Can Do 331 41 2 Cluster Management Status 331 41 3 Clustering Management Configuration 332 41 4...

Page 17: ...view 345 46 2 Viewing the Path MTU Table 345 Chapter 47 Configure Clone 346 47 1 Overview 346 47 2 Configure Clone 346 Chapter 48 IPv6 Neighbor Table 349 48 1 IPv6 Neighbor Table Overview 349 48 2 Vie...

Page 18: ...ble of Contents XGS1930 Series User s Guide 18 50 3 Switch Configuration 363 Appendix A Customer Support 364 Appendix B Common Services 370 Appendix C IPv6 373 Appendix D Legal Information 382 Index 3...

Page 19: ...19 PART I User s Guide...

Page 20: ...her standalone or Nebula cloud management mode When the Switch is in standalone mode it can be configured and managed by the web configurator When the Switch is in Nebula cloud management mode it can...

Page 21: ...tten with what you have configured in Nebula Note If you change the Switch s management mode from Nebula managed mode to standalone mode the Switch will reset to its factory default settings From Stan...

Page 22: ...just remove unregister the Switch from the organization or site in the Nebula web portal The Switch will reboot and restore the factory default settings 1 1 3 ZON Utility With its built in Web Configu...

Page 23: ...an example Switch and not your actual Switch 1 2 1 Backbone Example Application The Switch is an ideal solution for small networks where rapid growth can be expected in the near future The Switch can...

Page 24: ...ndwidth can connect to high speed department servers through the Switch You can provide a super fast uplink connection by using a Gigabit Ethernet or SFP port on the Switch Moreover the Switch eases s...

Page 25: ...AN Virtual Local Area Network allows a physical network to be partitioned into multiple logical networks Stations on a logical network belong to one or more groups With VLAN a station cannot directly...

Page 26: ...e 312 Cluster Management Cluster Management allows you to manage multiple switches through one switch called the cluster manager See Chapter 41 on page 330 ZON Utility ZON Utility is a program designe...

Page 27: ...d at least 5 cm of clearance on all four sides of the Switch This allows air circulation for cooling Do NOT block the ventilation holes nor store cables or power cords on the Switch Allow clearance fo...

Page 28: ...ce for air circulation 2 4 Mounting the Switch on a Rack The Switch can be mounted on an EIA standard size 19 inch rack or in a wiring closet with other equipment Follow the steps below to mount your...

Page 29: ...a 2 Philips screwdriver install the M3 flat head screws through the mounting bracket holes into the Switch 3 Repeat steps 1 and 2 to install the second mounting bracket on the other side of the Switch...

Page 30: ...a 2 Philips screwdriver install the M5 flat head screws through the mounting bracket holes into the rack Note Make sure you tighten all the four screws to prevent the Switch from getting slanted 3 Rep...

Page 31: ...10 Front Panel XGS1930 52 Figure 11 Front Panel XGS1930 52HP 3 1 1 Ethernet Ports The Switch has 1000Base T auto negotiating auto crossover Ethernet ports In 10 100 1000 Mbps Gigabit Ethernet the spe...

Page 32: ...28HP and XGS1930 52HP The Switch supports both the IEEE 802 3af Power over Ethernet PoE and IEEE 802 3at Power over Ethernet PoE plus standards The Switch is a Power Sourcing Equipment PSE because it...

Page 33: ...nsert the transceiver into the slot with the exposed section of PCB board facing down 4 Press the transceiver firmly until it clicks into place 5 The Switch automatically detects the installed transce...

Page 34: ...Note Do NOT pull the transceiver out by force You could damage it If the transceiver will not slide out grasp the tabs on both sides of the transceiver with a slight up or down motion and carefully s...

Page 35: ...on of Ethernet cables must be separate from AC power lines To avoid electric surge and electromagnetic interference use a different electrical conduit or raceway tube trough or enclosed conduit for pr...

Page 36: ...he grounding terminal of the server rack or on site grounding terminal must also be grounded and connected to the building s main grounding electrode Make sure the grounding terminal is connected to t...

Page 37: ...tings Amber On The Switch is returning to its factory default configuration settings Off The Switch is not receiving power from the power module in the power slot SYS Green On The Switch is on and fun...

Page 38: ...Amber On The link to a 10 Mbps or a 100 Mbps Ethernet network is up Blinking The Switch is transmitting or receiving to or from a 10 Mbps or a 100 Mbps Ethernet network Off The link to an Ethernet ne...

Page 39: ...39 PART II Technical Reference...

Page 40: ...p up windows from your device JavaScript enabled by default Java permissions enabled by default 4 2 System Login 1 Start your web browser 2 The Switch is a DHCP client by default Type http DHCP assign...

Page 41: ...e Section 4 4 on page 48 for more information on the Setup Wizard screen When you finish configuring the settings you can click the Apply Save button to make the settings take effect and save your con...

Page 42: ...rd Mode Click Password SNMP to open a screen where you can change the administrator password and SNMP community string simultaneously Otherwise click Ignore to close it If you log into the Web Configu...

Page 43: ...e SNMP version 2c v2c SNMP version 3 v3 or both v3v2c Note SNMP version 2c is backwards compatible with SNMP version 1 Get Community Enter the Get Community string which is the password for the incomi...

Page 44: ...xel com and install it in a computer Windows operating system 4 3 1 Requirements Before installing the ZON Utility in your computer please make sure it meets the requirements listed below Operating Sy...

Page 45: ...rmware versions later you can click the Show information about ZON icon in the upper right of the screen Then select the Supported model and firmware version link If your device is not listed here see...

Page 46: ...over all supported devices in your network Figure 32 Discovery 5 The ZON Utility screen shows the devices discovered Figure 33 ZON Utility Screen 6 Select a device and then use the icons to perform ac...

Page 47: ...unzipped it in advance 8 Change Password Use this icon to change the admin password of the selected device You must know the current admin password before changing to a new one 9 Configure NCC Discov...

Page 48: ...eived a ZDP discovery request from the ZON Utility System Name This field displays the system name of the discovered device Location This field displays where the discovered device is Status This fiel...

Page 49: ...ddress when the Switch is NOT connected to a router or you want to assign it a fixed IP address VID This field displays the VLAN ID IP Address The Switch needs an IP address for it to be managed over...

Page 50: ...r station to manage and monitor the Switch through the network Select Disabled to turn this feature off Version Select the SNMP version for the Switch The SNMP version on the Switch must match the ver...

Page 51: ...Previous to show the previous screen Next Click Next to show the next screen Cancel Click Cancel to exit this screen without saving Table 10 Wizard Basic Step 3 Link Aggregation LABEL DESCRIPTION Lin...

Page 52: ...of the default outgoing gateway in dotted decimal notation for example 192 168 1 254 DNS Server DNS Domain Name System is for mapping a domain name to its corresponding IP address and vice versa Ente...

Page 53: ...revious Click Previous to show the previous screen Finish Review the information and click Finish to create the task Cancel Click Cancel to exit this screen without saving Table 12 Wizard Protection S...

Page 54: ...Wizard Protection Step 2 Broadcast Storm Control LABEL DESCRIPTION Broadcast Storm Control Select all ports Select all ports to apply settings on all ports You can select a port by clicking it Broadca...

Page 55: ...tep 3 Summary LABEL DESCRIPTION Summary Loop Guard If the loop guard feature is enabled on a port the Switch will prevent loops on this port Broadcast Storm Control If the broadcast storm control feat...

Page 56: ...SCRIPTION VLAN Setting Default VLAN 1 Access Untagged port After you create a VLAN and select the VLAN ID from the drop down list box select ports and use the right arrow to add them as the untagged p...

Page 57: ...on so they will have high priority The port s IEEE 802 1p priority level will be set to 5 Use the Basic Setting Port Setup screen to adjust the value Medium Select ports and click the Medium button an...

Page 58: ...the Switch s non volatile memory Non volatile memory is the configuration of your Switch that stays the same even if the Switch s power is turned off D Click this link to go to the status page of the...

Page 59: ...ement and set up to 64 IP routing domains Port Setup This link takes you to a screen where you can configure settings for individual Switch ports PoE Setup For PoE models This link takes you to a scre...

Page 60: ...n on a port Time Range This link takes you to a screen where you can define different schedules Classifier This link takes you to screens where you can configure the Switch to group packets based on t...

Page 61: ...n where you can view system logs Syslog Setup This link takes you to a screen where you can setup system logs and a system log server Cluster Management This link takes you to screens where you can co...

Page 62: ...efers to the Switch s storage that remains even if the Switch s power is turned off Note Use the Save link when you are done with a configuration session 4 7 Switch Lockout You could block yourself an...

Page 63: ...m Default Press the RESTORE button for 3 to 6 seconds to have the Switch automatically reboot and restore the last saved custom default file See Section 3 3 on page 37 for more information about the L...

Page 64: ...igure Switch Management IP Address 5 1 1 Create a VLAN VLANs confine broadcast frames to the VLAN group in which the ports belongs You can do this with port based VLAN or tagged static VLAN with fixed...

Page 65: ...the VID field in the IP Setup screen refer to the same VLAN ID 3 Since the VLAN2 network is connected to port 1 on the Switch select Fixed to configure port 1 to be a permanent member of the VLAN only...

Page 66: ...Port VID 1 Click Advanced Applications VLAN VLAN Configuration in the navigation panel Then click the VLAN Port Setup link 2 Enter 2 in the PVID field for port 1 and click Apply to save your changes b...

Page 67: ...e same subnet as the Switch 2 Open your web browser and enter 192 168 1 1 the default IP address in the address bar to access the Web Configurator See Section 4 2 on page 40 for more information 3 Cli...

Page 68: ...group to which you want this management IP address to belong This is the same as the VLAN ID you configure in the Static VLAN screen 7 Click Add to save your changes back to the run time memory Setti...

Page 69: ...CP server can then assign a specific IP address based on the information in the DHCP requests 6 2 1 DHCP Relay Tutorial Introduction In this example you have configured your DHCP server 192 168 2 3 an...

Page 70: ...tion Static VLAN Setup 4 In the Static VLAN screen select ACTIVE enter a descriptive name VLAN 102 for example in the Name field and enter 102 in the VLAN Group ID field 5 Select Fixed to configure po...

Page 71: ...and then the VLAN Port Setup link in the VLAN Configuration screen Figure 52 Tutorial Click the VLAN Port Setting Link 9 Enter 102 in the PVID field for port 2 to add a tag to incoming untagged frames...

Page 72: ...1 Click IP Application DHCP DHCPv4 and then the Global link to open the DHCP Relay screen 2 Select the Active check box 3 Enter the DHCP server s IP address 192 168 2 3 in this example in the Remote...

Page 73: ...did not receive the IP address 172 16 1 18 make sure 1 Client A is connected to the Switch s port 2 in VLAN 102 2 You configured the correct VLAN ID port number and system name for DHCP relay on both...

Page 74: ...can also display other status screens for more information Use the Neighbor screen Section 7 2 1 on page 76 to view a summary and manage Switch s neighbor devices Use the Neighbor Detail screen Secti...

Page 75: ...the generation number of the Switch series and the decimal is the version of the hardware change For example V1 0 is a hardware version for the Switch where 1 identifies the first generation of the S...

Page 76: ...cted PoE enabled devices and the total power the Switch can provide to the connected PDs It also shows the percentage of PoE power usage When PoE usage reaches 100 the Switch will shut down PDs one by...

Page 77: ...This shows the IPv6 address of the neighbor device The IPv6 address is a hyper link that you can click to log into and manage the neighbor device through its Web Configurator PWR Cycle Click the Cycl...

Page 78: ...l The following table describes the fields in the above screen Table 21 Status Neighbor Neighbor Detail LABEL DESCRIPTION Local Port This shows the port of the Switch on which the neighboring device i...

Page 79: ...device through its Web Configurator Port This show the number of the neighbor device s port which is connected to the Switch Desc This shows the description of the neighbor device s port which is conn...

Page 80: ...ess default gateway device management VLAN ID and proxy server Use the Port Setup screen Section 8 7 on page 91 to configure Switch port settings Use the PoE Setup screens Section 8 8 on page 93 to vi...

Page 81: ...ontrol address of the Switch CPU Utilization CPU utilization quantifies how busy the system is Current displays the current percentage of CPU utilization Memory Utilization Memory utilization shows ho...

Page 82: ...an speed falls below the threshold shown Current This field displays this fan s current speed in Revolutions Per Minute RPM MAX This field displays this fan s maximum speed measured in Revolutions Per...

Page 83: ...aytime RFC 867 format the Switch displays the day month year and time with no time zone adjustment When you use this format it is recommended that you use a Daytime timeserver within your geographical...

Page 84: ...24 hour format Here are a couple of examples Daylight Saving Time starts in most parts of the United States on the second Sunday of March Each time zone in the United States starts using Daylight Sav...

Page 85: ...ey age out and must be relearned ARP Aging Time Aging Time Enter a time from 60 to 1000000 seconds This is how long dynamically learned ARP entries remain in the ARP table before they age out and must...

Page 86: ...assigned to higher index queues gets through faster while traffic in lower index queues is dropped if the network is congested Priority Level The following descriptions are based on the traffic types...

Page 87: ...IP address of the DNS server Source This field displays whether the DNS server address is configured manually Static or obtained automatically using DHCPv4 IP Interface Index This field displays the...

Page 88: ...in dotted decimal notation for example 192 168 1 1 IP Subnet Mask This is the IP subnet mask of your Switch in dotted decimal notation for example 255 255 255 0 Lease Time This displays the length of...

Page 89: ...uting domains on the Switch DHCP Client Select this option if you have a DHCP server that can assign the Switch an IP address subnet mask a default gateway IP address and a domain name server IP addre...

Page 90: ...ds to your previous configuration Index This field displays the index number of an entry IP Address This field displays the IP address of the Switch in the IP domain IP Subnet Mask This field displays...

Page 91: ...meric characters are allowed for the Server except or Port Enter the port number of the proxy server 1 65535 Authentication Select this option to enable proxy server authentication using a Username an...

Page 92: ...ed by detecting the signal on the cable and using half duplex mode When the Switch s auto negotiation is turned off a port uses the pre configured speed and duplex mode when making a connection thus r...

Page 93: ...r device through an Ethernet port In the figure below the IP camera and IP phone get their power directly from the Switch Aside from minimizing the need for cables and wires PoE removes the hassle of...

Page 94: ...ust have at least 16 W of remaining power in order to supply power to a PoE device even if the PoE device needs less than 16 W Port This is the port index number State This field shows which ports can...

Page 95: ...s Out if PoE is currently disabled on the port It shows if no schedule is applied to the port PoE is enabled by default Table 31 Basic Setting PoE Status continued LABEL DESCRIPTION Table 32 Basic Set...

Page 96: ...ndex number of the port Click a port number to change the schedule settings Time Range Profiles This field displays the name of the schedule which is applied to the port PoE is enabled at the specifie...

Page 97: ...s This helps check if the power interface PI range of the connected PD is within the IEEE 802 3af at standard range and ensures it is an IEEE PD Power Up Sequence Delay Select this to allow PoE ports...

Page 98: ...er higher than a standard power limit Max Power mW Specify the maximum amount of power the PD could use from the Switch on this port If you leave this field blank the Switch refers to the standard or...

Page 99: ...interface To have IPv6 function properly you should configure a static VLAN with the same ID number in the Advanced Application VLAN screens Add Click this to create a new entry This saves your chang...

Page 100: ...status and detailed information Click an interface index number in the Basic Setting IPv6 screen The following screen opens Table 35 Basic Setting IPv6 LABEL DESCRIPTION IPv6 Status Domain Name Serve...

Page 101: ...t in a given time interval If the bucket is full subsequent error messages are suppressed ICMPv6 Rate Limit Error Interval This field displays the time period in milliseconds during which ICMPv6 error...

Page 102: ...the DHCPv6 T1 timer After T1 the Switch sends the DHCPv6 server a Renew message An IA_NA option contains the T1 and T2 fields but an IA_TA option does not The DHCPv6 server uses T1 and T2 to control...

Page 103: ...ch IPv6 Addressing IPv6 Link Local Address Setup Click the link to go to a screen where you can configure the IPv6 link local address for an interface IPv6 Global Address Setup Click the link to go to...

Page 104: ...which ICMPv6 error messages of up to the bucket size can be transmitted 0 means no limit Apply Click Apply to save your changes to the Switch s run time memory The Switch loses these changes if it is...

Page 105: ...asic Setting IPv6 IPv6 Configuration IPv6 Link Local Address Setup LABEL DESCRIPTION Interface Select the IPv6 interface you want to configure Link Local Address Manually configure a static IPv6 link...

Page 106: ...n IPv6 prefix length that specifies how many most significant bits start from the left in the address compose the network address EUI 64 Select this option to have the interface ID be generated automa...

Page 107: ...rtisement messages to check whether an IPv6 address is already in use before assigning it to an interface Specify the number of consecutive neighbor solicitations from 0 to 600 the Switch sends for th...

Page 108: ...you want to configure Flags Select the Managed Config Flag option to have the Switch set the managed address configuration flag the M flag to 1 in IPv6 router advertisements which means IPv6 hosts use...

Page 109: ...done configuring Cancel Click Cancel to begin configuring this screen afresh Clear Click Clear to reset the fields to the factory defaults Index This is the interface index number Click an index numbe...

Page 110: ...ation Select No Advertise Flag to set the Switch to not include the specified IPv6 prefix prefix length in router advertisements for this interface Add Click this to create a new entry or to update an...

Page 111: ...vice which can be reached through the interface Add Click this to create a new entry or to update an existing one This saves your changes to the Switch s run time memory The Switch loses these changes...

Page 112: ...ain a list of domain names from the DHCP server Information Refresh Minimum Specify the time interval from 600 to 4294967295 seconds at which the Switch exchanges other configuration information with...

Page 113: ...re 85 Basic Setting Cloud Management 8 11 1 Nebula Center Control Discovery Click Basic Setting Cloud Management Nebula Control Center Discovery to display this screen Figure 86 Basic Setting Cloud Ma...

Page 114: ...his screen Figure 87 Basic Setting Cloud Management Nebula Switch Registration This screen has a QR code containing the Switch s serial number and MAC address for handy NCC registration of the Switch...

Page 115: ...ou can specify a mask for the MAC address to create a MAC address filter and enter a weight to set the VLAN rule s priority Use the Port Based VLAN Setup screen Section 9 9 on page 127 to set up VLANs...

Page 116: ...e default PVID is VLAN 1 for all ports but this can be changed A broadcast frame or a multicast frame for a multicast group that is known by the system is duplicated only on ports that are members of...

Page 117: ...s Figure 88 Port VLAN Trunking 9 2 0 3 Select the VLAN Type Select a VLAN type in the Basic Setting Switch Setup screen Table 47 IEEE 802 1Q VLAN Terminology VLAN PARAMETER TERM DESCRIPTION VLAN Type...

Page 118: ...AN group as normal depending on its VLAN tag sent to a group whether it has a VLAN tag or not blocked from a VLAN group regardless of its VLAN tag You can also tag all outgoing frames that were previo...

Page 119: ...ANs Index This is the VLAN index number Click an index number to view more VLAN details VID This is the VLAN identification number that was configured in the corresponding VLAN configuration screen Na...

Page 120: ...me This field shows how long it has been since a normal VLAN was registered or a static VLAN was set up Status This field shows how this VLAN was added to the Switch Dynamic using GVRP Static added as...

Page 121: ...in this row apply to all ports Use this row only if you want to make some settings the same for all ports Use this row first to set the common settings and then make adjustments on a port by port bas...

Page 122: ...ain VID This field displays the ID number of the VLAN group Click the number to edit the VLAN settings Active This field indicates whether the VLAN settings are enabled Yes or disabled No Name This fi...

Page 123: ...discards incoming frames on a port for VLANs that do not include this port in its member set Clear this check box to disable ingress filtering PVID A PVID Port VLAN ID is a tag that adds to incoming...

Page 124: ...lobal Setup Voice VLAN Click the second radio button if you want to enable the Voice VLAN feature Enter a VLAN ID number that is associated with the Voice VLAN Click the Disable radio button if you do...

Page 125: ...ecified IP phone manufacturer s OUI MAC address to determine which bits a packet s MAC address should match Enter f for each bit of the specified MAC address that the traffic s MAC address should matc...

Page 126: ...t the priority level that the Switch assigns to frames belonging to this VLAN The higher the numeric value you assign the higher the priority for this vendor ID based VLAN entry Weight Enter a number...

Page 127: ...a data packet leaves for both ports Port based VLANs are specific only to the Switch on which they were created Note When you activate port based VLAN the Switch uses a default VLAN ID of 1 You canno...

Page 128: ...as mentioned above You can still customize these settings by adding or deleting incoming or outgoing ports but you must also click Apply at the bottom of the screen Incoming These are the ingress por...

Page 129: ...loses these changes if it is turned off or loses power so use the Save link on the top navigation panel to save your changes to the non volatile memory when you are done configuring Cancel Click Canc...

Page 130: ...e Static MAC Forwarding A static MAC address is an address that has been manually entered in the MAC address table Static MAC addresses do not age out When you set up static MAC address rules you are...

Page 131: ...the top navigation panel to save your changes to the non volatile memory when you are done configuring Cancel Click Cancel to reset the fields to their last saved values Clear Click Clear to begin co...

Page 132: ...group A static multicast address is a multicast MAC address that has been manually entered in the multicast table Static multicast addresses do not age out Static multicast forwarding allows you the a...

Page 133: ...orwarding to Multiple Ports 11 2 Configure Static Multicast Forwarding Use this screen to configure rules to forward specific multicast frames such as streaming or control frames to specific ports Cli...

Page 134: ...5 and 7 Add Click this to create a new entry or to update an existing one This saves your rule to the Switch s run time memory The Switch loses this rule if it is turned off or loses power so use the...

Page 135: ...rce and or destination MAC addresses and VLAN group ID 12 1 1 What You Can Do Use the Filtering screen Section 12 2 on page 135 to create rules for traffic going through the Switch 12 2 Configure a Fi...

Page 136: ...e an existing one This saves your changes to the Switch s run time memory The Switch loses these changes if it is turned off or loses power so use the Save link on the top navigation panel to save you...

Page 137: ...se the Multiple Spanning Tree Protocol screen Section 13 6 on page 143 to configure MSTP Use the Multiple Spanning Tree Protocol Status screen Section 13 7 on page 147 to view the MSTP status 13 1 2 W...

Page 138: ...or connected LANs and disables all other ports that participate in STP Network packets are therefore only forwarded between enabled ports eliminating any possible network loops STP aware switches exch...

Page 139: ...in a region 13 2 Spanning Tree Protocol Status The Spanning Tree Protocol status screen changes depending on what standard you choose to implement on your network Click Advanced Application Spanning...

Page 140: ...his screen 13 4 Rapid Spanning Tree Protocol Status Figure 107 Advanced Application Spanning Tree Protocol Table 61 Advanced Application Spanning Tree Protocol Configuration LABEL DESCRIPTION Spanning...

Page 141: ...ceived frames or learn MAC addresses but still listens for BPDUs Learning The port learns MAC addresses and processes BPDUs but does NOT forward frames yet Forwarding The port is operating normally It...

Page 142: ...Switch with the highest priority lowest numeric value becomes the STP root switch If all Switches have the same priority the Switch with the lowest MAC address will then become the root switch Select...

Page 143: ...configure a port as an edge port when it is directly attached to a computer An edge port changes its initial STP port state from blocking state to forwarding state immediately without going through l...

Page 144: ...Click Port to display the MSTP Port screen Active Select this check box to activate MSTP on the Switch Clear this check box to disable MSTP on the Switch Note You must also activate Multiple Spanning...

Page 145: ...Use this section to configure MSTI Multiple Spanning Tree Instance settings Instance Enter the number you want to use to identify this MST instance on the Switch The Switch supports instance numbers...

Page 146: ...e link on the top navigation panel to save your changes to the non volatile memory when you are done configuring Cancel Click Cancel to begin configuring this screen afresh Instance This field display...

Page 147: ...nfigure a port as an edge port when it is directly attached to a computer An edge port changes its initial STP port state from blocking state to forwarding state immediately without going through list...

Page 148: ...t and Our Bridge if the Switch is the root switch Hello Time second This is the time interval in seconds at which the root switch transmits a configuration message The root bridge determines Hello Tim...

Page 149: ...t is operating normally It learns MAC addresses processes BPDUs and forwards received frames Port Role This field displays the role of the port in STP Root A forwarding port on a non root bridge which...

Page 150: ...travel on different paths The following figure shows the network example using MSTP Figure 113 MSTP Network Example 13 8 2 MST Region An MST region is a logical grouping of multiple network devices th...

Page 151: ...egions 1 and 2 have two spanning tree instances Figure 114 MSTIs in Different Regions 13 8 4 Common and Internal Spanning Tree CIST A CIST represents the connectivity of the entire network and it is e...

Page 152: ...ining a maximum allowable bandwidth for incoming and or out going traffic flows on a port 14 1 1 What You Can Do Use the Bandwidth Control screen Section 14 2 on page 152 to limit the bandwidth for tr...

Page 153: ...as you make them Active Select this check box to activate ingress rate limits on this port Ingress Rate Specify the maximum bandwidth allowed in kilobits per second Kbps for the incoming traffic flow...

Page 154: ...llowable broadcast multicast and or DLF packets is reached per second the subsequent packets are discarded Enable this feature to reduce broadcast multicast and or DLF packets in your network You can...

Page 155: ...settings and then make adjustments on a port by port basis Note Changes in this row are copied to all the ports as soon as you make them Broadcast pkt s Select this option and specify how many broadca...

Page 156: ...to a monitor port the port you copy the traffic to in order that you can examine the traffic from the monitor port without interference 16 2 Port Mirroring Setup Click Advanced Application Mirroring i...

Page 157: ...rts Use this row only if you want to make some settings the same for all ports Use this row first to set the common settings and then make adjustments on a port by port basis Note Changes in this row...

Page 158: ...transmitting data as one logical link in the trunk group and so on Use the Link Aggregation Setting screen Section 17 3 on page 160 to configure static link aggregation Use the Link Aggregation Contro...

Page 159: ...pology loops Link Aggregation ID LACP aggregation ID consists of the following information1 17 2 Link Aggregation Status Click Advanced Application Link Aggregation in the navigation panel The Link Ag...

Page 160: ...ity and port number The ID displays only when there is a port belonging to this trunk group and LACP is also enabled for this group Criteria This shows the outgoing traffic distribution algorithm used...

Page 161: ...ls in this screen Table 73 Advanced Application Link Aggregation Link Aggregation Setting LABEL DESCRIPTION Link Aggregation Setting This is the only screen you need to configure to enable static link...

Page 162: ...MAC address Select src dst mac to distribute traffic based on a combination of the packet s source and destination MAC addresses Select src ip to distribute traffic based on the packet s source IP ad...

Page 163: ...ble Link Aggregation Control Protocol LACP System Priority LACP system priority is a number between 1 and 65535 The switch with the lowest system priority and lowest port number if system priority is...

Page 164: ...ow only if you want to make some settings the same for all ports Use this row first to set the common settings and then make adjustments on a port by port basis Note Changes in this row are copied to...

Page 165: ...Chapter 17 Link Aggregation XGS1930 Series User s Guide 165 Figure 123 Trunking Example Configuration Screen Your trunk group 1 T1 configuration is now complete EXAMPLE...

Page 166: ...You must configure a RADIUS server before enabling port authentication Note If you enable IEEE 802 1x authentication and MAC authentication on the same port the Switch performs IEEE 802 1x authentica...

Page 167: ...client provides the login credentials the Switch sends an authentication request to a RADIUS server The RADIUS server validates whether this client is allowed access to the port Figure 124 IEEE 802 1...

Page 168: ...er settings in the AAA RADIUS Server Setup screen Click Advanced Application Port Authentication in the navigation panel to display the screen as shown Select a port authentication method s link in th...

Page 169: ...w first to set the common settings and then make adjustments on a port by port basis Note Changes in this row are copied to all the ports as soon as you make them Active Select this to permit 802 1x a...

Page 170: ...f seconds the port remains in the HELD state and rejects further authentication requests from the connected client after a failed authentication exchange Tx period secs Specify the number of seconds t...

Page 171: ...MAC addresses used as the account user name and password Password Type Select Static to have the Switch send the password you specify below or MAC Address to use the client MAC address as the password...

Page 172: ...nistrator configures switches or routers with the guest network feature Figure 129 Guest VLAN Example Use this screen to enable and assign a guest VLAN to a port In the Port Authentication screen clic...

Page 173: ...he guest VLAN Make sure this is a VLAN recognized in your network Host mode Specify how the Switch authenticates users when more than one user connect to the port using a hub Select Multi Host to auth...

Page 174: ...ividual ports other than the sum cannot exceed 32K For maximum port security enable this feature disable MAC address learning and configure static MAC addresses for a port It is not recommended you di...

Page 175: ...rity feature The Switch forwards all packets on this port Address Learning MAC address learning reduces outgoing broadcast traffic For MAC address learning to occur on a port the port itself must be a...

Page 176: ...pes of schedules are based on the current date and time in the Switch The time range can be configured in two ways Absolute and Periodic Absolute is a fixed time range with a start and end time Period...

Page 177: ...the week hour and minute when the schedule begins and ends respectively Select the second option if you want to define a recurring schedule for multiple non consecutive time periods You need to select...

Page 178: ...Need to Know Quality of Service QoS refers to both a network s ability to deliver data with minimum delay and the networking methods used to control the use of bandwidth Without QoS all traffic data i...

Page 179: ...umber of the rule Click an index number to edit the rule Active This field displays Yes when the rule is activated and No when it is deactivated Weight This field displays the rule s weight This is to...

Page 180: ...Chapter 21 Classifier XGS1930 Series User s Guide 180 Figure 134 Advanced Application Classifier Classifier Configuration...

Page 181: ...Any to apply the rule to all trunk groups To specify a trunk group select the second choice and type a trunk group ID Layer 2 Specify the fields below to configure a layer 2 classifier VLAN VLAN Selec...

Page 182: ...255 in the field provided IP Protocol Select an IPv4 protocol type or select Other and enter the protocol number in decimal value You may select Establish Only for TCP protocol type This means that th...

Page 183: ...the Save link on the top navigation panel to save your changes to the non volatile memory when you are done configuring Cancel Click Cancel to reset the fields back to your previous configuration Clea...

Page 184: ...n Use this screen to configure the match order and enable logging on the Switch In the Classifier Configuration screen click Classifier Global Setting to display the configuration screen as shown Tabl...

Page 185: ...nfigured in the rule Layer 4 items have the highest priority and layer 2 items has the lowest priority For example you configure a layer 2 item VLAN ID in classifier A and configure a layer 3 item sou...

Page 186: ...ssifier XGS1930 Series User s Guide 186 Figure 137 Classifier Example After you have configured a classifier you can configure a policy in the Policy screen to define actions on the classified traffic...

Page 187: ...78 for more information A policy rule ensures that a traffic flow gets the requested treatment in the network 22 1 1 What You Can Do Use the Policy Rule screen Section 22 2 on page 187 to enable the p...

Page 188: ...To select more than one classifier press SHIFT and select the choices at the same time Parameters Set the fields below for this policy You only have to set the fields that is related to the actions yo...

Page 189: ...o forward the packets to the egress port Policy 2 applies to Class 2 and the action is to enable bandwidth limitation the Switch will forward the packets Forwarding Select No change to forward the pac...

Page 190: ...e The figure below shows an example Policy screen where you configure a policy to limit bandwidth and discard out of profile traffic on a traffic flow classified using the Example classifier refer to...

Page 191: ...Q6 empties and then traffic is transmitted on Q5 and so on If higher priority queues never empty then traffic on lower priority queues never gets sent SPQ does not automatically adapt to changing netw...

Page 192: ...traffic than it can handle Queues with larger weights get more service than queues with smaller weights This queuing mechanism is highly efficient in that it divides any available bandwidth across th...

Page 193: ...in the Weight field Queues with larger weights get more guaranteed bandwidth than queues with smaller weights Weighted Round Robin Scheduling services queues on a rotating basis based on their queue w...

Page 194: ...mation Use the IGMP Snooping screen Section 24 3 1 on page 196 to enable IGMP snooping to forward group multicast traffic only to ports that are members of that group Use the IGMP Snooping VLAN screen...

Page 195: ...en performs IGMP snooping on the first 16 VLANs that send IGMP packets This is referred to as auto mode Alternatively you can specify the VLANs that IGMP snooping should be performed on This is referr...

Page 196: ...lticast IPv4 Multicast LABEL DESCRIPTION Index This is the index number of the entry VID This field displays the multicast VLAN ID Port This field displays the port number that belongs to the multicas...

Page 197: ...er the VLAN ID numbers to discard the frames on the specified VLANs Use a dash to specify consecutive VLANs and a comma no spaces to specify non consecutive VLANs For example 51 53 includes 51 52 and...

Page 198: ...allowed to join Once a port is registered in the specified number of multicast groups any new IGMP join report frames is dropped on this port Throttling IGMP throttling controls how the Switch deals w...

Page 199: ...cast IPv4 Multicast IGMP Snooping screen first Apply Click Apply to save your changes to the Switch s run time memory The Switch loses these changes if it is turned off or loses power so use the Save...

Page 200: ...p VID This field displays the ID number of the VLAN group Select an entry s check box to select a specific entry Otherwise select the check box in the table heading row to select all entries Delete Ch...

Page 201: ...d displays the end of the multicast address range Delete Profile Select a profile s check box to select a specific profile Otherwise select the check box in the table heading row to select all profile...

Page 202: ...s used to authenticate users accessing the Switch and which database the Switch should use first 25 1 2 What You Need to Know Authentication is the process of determining who a user is and validating...

Page 203: ...d to the memory capacity of the device In essence RADIUS authentication allows you to validate an unlimited number of users from a central location 25 2 AAA Screens The AAA screens allow you to enable...

Page 204: ...e RADIUS servers that it sends authentication requests to Timeout Specify the amount of time in seconds that the Switch waits for an authentication request response from the RADIUS server If you are u...

Page 205: ...ting server in dotted decimal notation UDP Port The default port of a RADIUS accounting server for accounting is 1813 You need not change this value unless your network administrator instructs you to...

Page 206: ...other source for administrator accounts specify them in the Method 2 field Select local to have the Switch check the administrator accounts configured in the Access Control Logins screen Select radius...

Page 207: ...em accounting is enabled system accounting is disabled Dot1x Configure the Switch to send information when an IEEE 802 1x client begins a session authenticates through the Switch ends a session as wel...

Page 208: ...UTE Ingress Bandwidth Assignment Vendor Id 890 Vendor Type 1 Vendor data ingress rate Kbps in decimal format Egress Bandwidth Assignment Vendor Id 890 Vendor Type 2 Vendor data egress rate Kbps in dec...

Page 209: ...ormat associated with it the format is specified 25 5 3 Attributes Used for Authentication The following sections list the attributes sent from the Switch to the RADIUS server when performing authenti...

Page 210: ...ook at various statistics about the DHCP snooping database Use this DHCP Snooping Configure screen Section 26 3 on page 213 to enable DHCP snooping on the Switch not on specific VLAN specify the VLAN...

Page 211: ...IPTION Database Status This section displays the current settings for the DHCP snooping database You can configure them in the DHCP Snooping Configure screen See Section 26 3 on page 213 Agent URL Thi...

Page 212: ...es the Switch successfully or unsuccessfully read or updated the DHCP snooping database Total attempts This field displays the number of times the Switch has tried to access the DHCP snooping database...

Page 213: ...displays the number of bindings the Switch ignored because the VLAN ID does not exist anymore Last ignored time This field displays the last time the Switch ignored any bindings for any reason from th...

Page 214: ...Select Disable if you do not want the Switch to forward DHCP packets to a specific VLAN Database If Timeout interval is greater than Write delay interval it is possible that the next update is schedul...

Page 215: ...to load it You can use this to load dynamic bindings from a different DHCP snooping database than the one specified in Agent URL When the Switch loads dynamic bindings from a DHCP snooping database it...

Page 216: ...port Untrusted Trusted ports are connected to DHCP servers or other switches and the Switch discards DHCP packets from trusted ports only if the rate at which DHCP packets arrive is too high Untruste...

Page 217: ...Yes to enable DHCP snooping on the VLAN You still have to enable DHCP snooping on the Switch and specify trusted ports Note If DHCP is enabled and there are no trusted ports DHCP requests will not su...

Page 218: ...ion 82 Profile Select a pre defined DHCP option 82 profile that the Switch applies to the specified ports in this VLAN The Switch adds the information such as slot number port number VLAN ID and or sy...

Page 219: ...external TFTP server If you set up the DHCP snooping database the Switch can reload the dynamic bindings from the DHCP snooping database after the Switch restarts You can configure the name and locati...

Page 220: ...ng for each source VLAN This setting is independent of the DHCP relay settings 26 4 1 4 Configuring DHCP Snooping Follow these steps to configure DHCP snooping on the Switch 1 Enable DHCP snooping on...

Page 221: ...on the edge of your network This can occur when a port is connected to a Switch that is in a loop state Loop state occurs as a result of human error It happens when two ports on a switch are connected...

Page 222: ...eturns to port N on A The Switch then shuts down port N to ensure that the rest of the network is not affected by the switch in loop state Figure 158 Loop Guard Probe Packet The Switch also shuts down...

Page 223: ...s row only if you want to make some settings the same for all ports Use this row first to set the common settings and then make adjustments on a port by port basis Note Changes in this row are copied...

Page 224: ...packets 28 1 2 What You Need to Know Layer 2 protocol tunneling L2PT is used on the service provider s edge devices L2PT allows edge switches 1 and 2 in the following figure to tunnel layer 2 STP Spa...

Page 225: ...ling Mode Each port can have two layer 2 protocol tunneling modes Access and Tunnel The Access port is an ingress port on the service provider s edge device 1 or 2 in Figure 162 on page 225 and connec...

Page 226: ...eld displays the port number means all ports Use this row to make the setting the same for all ports Use this row first and then make adjustments on a port by port basis Note Changes in this row are c...

Page 227: ...of a link Mode Select Access to have the Switch encapsulate the incoming layer 2 protocol packets and forward them to the tunnel ports Select Access for ingress ports at the edge of the service provi...

Page 228: ...in PPPoE screen Use the Intermediate Agent screen Section 29 3 on page 231 to enable the PPPoE Intermediate Agent on the Switch Use the PPPoE IA Per Port screen Section 29 3 1 on page 232 to set the p...

Page 229: ...rcuit ID Syntax with Identifier String and Variables If you do not configure a Circuit ID string for a VLAN on a specific port or for a specific port the Switch adds the user defined identifier string...

Page 230: ...erminate packet is sent from a PPPoE server and received on a trusted port the Switch forwards it to all other ports If a PADI or PADR packet is sent from a PPPoE client but received on a trusted port...

Page 231: ...cific VLAN on a port in the Advanced Application PPPoE Intermediate Agent Port VLAN screen has priority over this That means if you also want to configure PPPoE IA Per Port or Per Port Per VLAN settin...

Page 232: ...es the labels in this screen Apply Click Apply to save your changes to the Switch s run time memory The Switch loses these changes if it is turned off or loses power so use the Save link on the top na...

Page 233: ...s PADO and PADS packets which are sent from a PPPoE server but received on an untrusted port Circuit id Enter a string of up to 63 ASCII characters that the Switch adds into the Agent Circuit ID sub o...

Page 234: ...is field displays the VLAN ID of each VLAN in the range specified above If you configure the VLAN the settings are applied to all VLANs Use this row to make the setting the same for all VLANs Use this...

Page 235: ...are applied to all VLANs Use this row to make the setting the same for all VLANs Use this row first and then make adjustments on a VLAN by VLAN basis Changes in this row are copied to all the VLANs as...

Page 236: ...p guard or CPU protection allow the Switch to shut down a port or discard specific packets on a port when an error is detected on the port For example if the Switch detects that packets sent out the p...

Page 237: ...o Errdisable Status in the Advanced Application Errdisable screen to display the screen as shown Table 114 Advanced Application Errdisable LABEL DESCRIPTION Errdisable Status Click this link to view w...

Page 238: ...inactive reason mode you want to reset here Reset Press to reset the specified ports to handle ARP BPDU or IGMP packets instead of ignoring them if the ports is in inactive reason mode Errdisable Stat...

Page 239: ...ol packets such as BPDU on the port rate limitation The Switch drops the additional control packets the ports has to handle in every one second Rate This field displays how many control packets this p...

Page 240: ...d to all the ports as soon as you make them Rate Limit pkt s Enter a number from 0 to 256 to specify how many control packets this port can receive or transmit per second 0 means no rate limit You can...

Page 241: ...the Switch s run time memory The Switch loses these changes if it is turned off or loses power so use the Save link on the top navigation panel to save your changes to the non volatile memory when yo...

Page 242: ...to the Switch s run time memory The Switch loses these changes if it is turned off or loses power so use the Save link on the top navigation panel to save your changes to the non volatile memory when...

Page 243: ...e sent a WAKE signal is sent to the link partner to return the link to active mode Auto Power Down Auto Power Down turns off almost all functions of the port s physical layer functions when the link i...

Page 244: ...e same for all ports Use this row first and then make adjustments to each port if necessary Changes in this row are copied to all the ports as soon as you make them EEE Select this to activate Energy...

Page 245: ...Us LLDP data units in the form of TLV Type Length Value Device information carried in the received LLDPDUs is stored in the standard MIB The Switch supports these basic management TLVs End of LLDPDU m...

Page 246: ...nd easy trouble shooting for mis configured IP addresses There are three classes of endpoint devices that the LLDP MED supports Class I IP Communications Controllers or other communication related ser...

Page 247: ...next Figure 177 Advanced Application LLDP The following table describes the labels in this screen Table 120 Advanced Application LLDP LABEL DESCRIPTION LLDP LLDP Local Status Click here to show a scr...

Page 248: ...ED LLDP MED Configuration Click here to show a screen to configure LLDP MED Link Layer Discovery Protocol for Media Endpoint Devices parameters LLDP MED Network Policy Click here to show a screen to c...

Page 249: ...itch System Capabilities Supported Bridge System Capabilities Enabled Bridge Management Address TLV The Management Address TLV identifies an address associated with the local LLDP agent that may be us...

Page 250: ...XGS1930 Series User s Guide 250 Figure 179 Advanced Application LLDP LLDP Local Status LLDP Local Port Status Detail...

Page 251: ...ation AN Enabled The current auto negotiation status of the port AN Advertised Capability The auto negotiation capabilities of the port Oper MAU Type The current Medium Attachment Unit MAU type of the...

Page 252: ...cation Identifier Number Table 122 Advanced Application LLDP LLDP Local Status LLDP Local Port Status Detail continued LABEL DESCRIPTION Table 123 Advanced Application LLDP LLDP Remote Status LABEL DE...

Page 253: ...for example 1 in the Index column in the LLDP Remote Status screen to display the screen as shown next Figure 181 Advanced Application LLDP LLDP Remote Status LLDP Remote Port Status Detail Basic TLV...

Page 254: ...ed when its corresponding TTL expires The TTL value is to multiply the TTL multiplier by the LLDP frames transmitting interval Port Description TLV This displays the remote port description System Nam...

Page 255: ...d Application LLDP LLDP Remote Status LLDP Remote Port Status Detail Dot1 and Dot3 TLV LABEL DESCRIPTION Dot1 TLV Port VLAN ID TLV This displays the VLAN ID of this port on the remote device Port Prot...

Page 256: ...negotiation capabilities of the port Oper MAU Type The current Medium Attachment Unit MAU type of the port Link Aggregation TLV The Link Aggregation TLV indicates whether the link is capable of being...

Page 257: ...Chapter 32 Link Layer Discovery Protocol LLDP XGS1930 Series User s Guide 257 Figure 183 Advanced Application LLDP LLDP Remote Status LLDP Remote Port Status Detail MED TLV...

Page 258: ...se LCI latitude and longitude coordinates of the Location Configuration Information LCI Civic LCI IETF Geopriv Civic Address based Location Configuration Information ELIN Emergency Location Identifier...

Page 259: ...ed when its corresponding TTL expires The TTL value is to multiply the TTL multiplier by the LLDP packets transmitting interval Transmit Delay Enter the delay in seconds between successive LLDPDU tran...

Page 260: ...vigation panel to save your changes to the non volatile memory when you are done configuring Cancel Click Cancel to begin configuring this screen afresh Table 127 Advanced Application LLDP LLDP Config...

Page 261: ...figuration Org specific TLV Setting LABEL DESCRIPTION Port This displays the Switch s port number Use this row to make the setting the same for all ports Use this row first and then make adjustments t...

Page 262: ...ll ports simultaneously Use this row to make the setting the same for all ports Use this row first and then make adjustments to each port if necessary Changes in this row are copied to all the ports a...

Page 263: ...defined from 0 through 63 with the 0 representing use of the default DSCP value Priority Enter the priority value for the network policy Add Click Add after finish entering the network policy informat...

Page 264: ...P MED Network Policy continued LABEL DESCRIPTION Table 132 Advanced Application LLDP LLDP MED Location LABEL DESCRIPTION Port Enter the port number you want to set up the location within the LLDP MED...

Page 265: ...et Direction Street Suffix Trailing Street Suffix House Number House Number Suffix Landmark Additional Location Name Zip Code Building Unit Floor Room Number Place Type Postal Community Name Post Offi...

Page 266: ...Identification Number ELIN which is used to identify endpoint devices when they issue emergency call services The valid length is form 10 to 25 characters Select an entry s check box to select a spec...

Page 267: ...en sending SNMP traps or using ping to test IP connectivity This figure shows a Telnet session coming in from network N1 The Switch sends reply traffic to default gateway R1 which routes it back to th...

Page 268: ...ls you use to create a static route Table 133 IP Application Static Routing IPv4 Static Route LABEL DESCRIPTION Active This field allows you to activate or deactivate this static route Name Enter a de...

Page 269: ...vious configuration Clear Click Clear to set the above fields back to the factory defaults Index This field displays the index number of the route Click a number to edit the static route entry Active...

Page 270: ...The Switch loses these changes if it is turned off or loses power so use the Save link on the top navigation panel to save your changes to the non volatile memory when you are done configuring Cancel...

Page 271: ...n 82 profile to certain ports on the Switch Use the VLAN Setting screen Section 34 4 6 on page 278 to configure your DHCPv4 settings based on the VLAN domain of the DHCPv4 clients Use the DHCPv4 VLAN...

Page 272: ...ication DHCP DHCPv4 in the navigation panel The DHCP Status screen displays Figure 195 IP Application DHCP DHCPv4 The following table describes the labels in this screen Table 135 IP Application DHCP...

Page 273: ...ss based on this information Please refer to RFC 3046 for more details The DHCP Relay Agent Information feature adds an Agent Information field also known as the Option 82 field to DHCP requests The O...

Page 274: ...P DHCPv4 Option 82 Profile The following table describes the labels in this screen Table 138 DHCP Relay Agent Circuit ID Sub option Format SubOpt Code Length Value 1 1 byte N 1 byte Slot ID Port ID VL...

Page 275: ...d Add Click this to create a new entry or to update an existing one This saves your changes to the Switch s run time memory The Switch loses these changes if it is turned off or loses power so use the...

Page 276: ...ox to enable DHCPv4 relay Remote DHCP Server 1 3 Enter the IP address of a DHCPv4 server in dotted decimal notation Option 82 Profile Select a pre defined DHCPv4 option 82 profile that the Switch appl...

Page 277: ...y over the one you select in the DHCP DHCPv4 Global screen Add Click this to create a new entry or to update an existing one This saves your changes to the Switch s run time memory The Switch loses th...

Page 278: ...DHCP server This allows the DHCP server to assign the appropriate IP address according to the VLAN ID Figure 200 DHCP Relay Configuration Example 34 4 6 DHCPv4 VLAN Setting Use this screen to configur...

Page 279: ...orts in this VLAN The Switch adds the Circuit ID sub option and or Remote ID sub option specified in the profile to DHCP requests that it relays to a DHCP server Add Click this to create a new entry o...

Page 280: ...profile that the Switch applies to the specified ports in this VLAN The Switch adds the Circuit ID sub option and or Remote ID sub option specified in the profile to DHCP requests that it relays to a...

Page 281: ...DHCP server with an IP address of 172 16 10 100 Figure 203 DHCP Relay for Two VLANs For the example network configure the VLAN Setting screen as shown Figure 204 DHCP Relay for Two VLANs Configuration...

Page 282: ...ings for a specific VLAN on the Switch Click IP Application DHCP DHCPv6 DHCPv6 Relay in the navigation panel to display the screen as shown Figure 205 IP Application DHCP DHCPv6 Relay The following ta...

Page 283: ...v6 requests from clients in this VLAN Remote ID This field displays whether the remote ID option is added to DHCPv6 requests from clients in this VLAN Select an entry s check box to select a specific...

Page 284: ...this chapter 35 1 2 1 How ARP Works When an incoming packet destined for a host device on a local area network arrives at the Switch the Switch looks in the ARP Table and if it finds the address it se...

Page 285: ...rwards host A s ICMP request to host B After the Switch gets the ICMP reply from host B it sends out an ARP request to get host A s MAC address and updates the ARP table with host A s ARP reply The Sw...

Page 286: ...etting host B s MAC address and ICMP reply 35 2 ARP Setup Click IP Application ARP Setup in the navigation panel to display the screen as shown Click the link next to ARP Learning to open a screen whe...

Page 287: ...n make adjustments on a port by port basis Changes in this row are copied to all the ports as soon as you make them ARP Learning Mode Select the ARP learning mode the Switch uses on the port Select AR...

Page 288: ...off or loses power so use the Save link on the top navigation panel to save your changes to the non volatile memory when you are done configuring Cancel Click Cancel to begin configuring this screen a...

Page 289: ...n Section 36 2 1 on page 291 to reset the configuration to the Zyxel default configuration settings Use the Save Configuration screen Section 36 2 2 on page 291 to save the current configuration setti...

Page 290: ...ttings to a customized default file on the Switch This file can be used instead of the Zyxel factory default configuration file Reboot System Click Config 1 to reboot the Switch and load Configuration...

Page 291: ...figurations are set up according to your network environment Click Config 2 to save the current configuration settings permanently to Configuration 2 on the Switch These configurations are set up acco...

Page 292: ...4 Factory Default Follow the steps below to reset the Switch back to the factory defaults 1 Click the Factory Default button 2 Click OK to continue or Cancel to abort Figure 211 Load Factory Default...

Page 293: ...e Be sure to upload the correct model firmware as uploading the wrong model firmware may damage your device Click Management Maintenance Firmware Upgrade to view the screen as shown next Figure 213 Ma...

Page 294: ...tting Firmware 1 shows its version number and model code and MM DD YYYY creation date Firmware 2 shows its version number and model code and MM DD YYYY creation date Current Boot Image This displays w...

Page 295: ...ave As to save the file to a specific place If a dialog box pops up asking whether you want to open or save the file click Save or Save File to download it to the default downloads folder on your comp...

Page 296: ...Mbuf 50 means a log will be created when the Mbuf utilization is over 50 The higher the Mbuf threshold number the fewer logs will be created and the less data technical support will have to analyze an...

Page 297: ...gurator See Section 37 7 3 on page 316 for more information about HTTPS Certificates are based on public private key pairs A certificate contains the certificate owner s identity and public key Certif...

Page 298: ...om your computer to the Switch Service This field displays the service type that this certificate is for Subject This field displays identifying information about the certificate s owner such as CN Co...

Page 299: ...rom the Switch using FTP commands First understand the filename conventions 36 8 2 Filename Conventions The configuration file also known as the romfile or ROM contains the Zyxel factory default confi...

Page 300: ...user name 4 Enter your password as requested the default is 1234 5 Enter bin to set transfer mode to binary 6 Use put to transfer files from the computer to the Switch for example put firmware bin ra...

Page 301: ...Commands for GUI based FTP Clients COMMAND DESCRIPTION Host Address Enter the address of the host server Login Type Anonymous This is when a user I D and password is automatically supplied to the serv...

Page 302: ...e User Information screen Section 37 3 3 on page 306 to create SNMP users for authentication with managers using SNMP v3 and associate them to SNMP groups Use the Logins screens Section 37 4 on page 3...

Page 303: ...Management Access Control SNMP Table 155 Management Access Control LABEL DESCRIPTION SNMP Click this link to configure your SNMP settings Logins Click this link to assign which users can access the Sw...

Page 304: ...the Set Community which is the password for incoming Set requests from the management station The Set Community string is only used by SNMP managers using SNMP version 2c or lower Trap Community Ente...

Page 305: ...pe Select the categories of SNMP traps that the Switch is to send to the SNMP manager Options Select the individual SNMP traps that the Switch is to send to the SNMP station The traps are grouped by c...

Page 306: ...elect this check box to enable the trap type of SNMP traps on this port The Switch sends the related traps received on this port to the SNMP manager Clear this check box to disable the sending of SNMP...

Page 307: ...SNMP managers in one group are assigned common access rights to MIBs Specify in which SNMP group this user is admin Members of this group can perform all types of system configuration including the ma...

Page 308: ...ies depending on the user s privilege level Click Management Access Control Logins to view the screen as shown Figure 225 Management Access Control Logins The following table describes the labels in t...

Page 309: ...r status 13 Configure features except for login accounts SNMP user accounts the authentication method sequence and authorization settings multiple logins administrator and enable passwords and configu...

Page 310: ...the new port number for that service Timeout Enter how many minutes from 1 to 255 a management session can be left idle before the session times out After it times out you have to log in with your pa...

Page 311: ...you wish to temporarily disable the set without deleting it Start Address End Address Configure the IP address range of trusted computers from which you can manage this Switch The Switch checks if the...

Page 312: ...anaged objects that define each piece of information to be collected about a Switch Examples of variables include number of packets received node port status and so on A Management Information Base MI...

Page 313: ...asheet at www zyxel com Support Download Library Datasheet To get the private MIBs supported by your Switch download and unzip the correct model MIB from www zyxel com Support Download Library MIB Fil...

Page 314: ...s sent when a single ping probe fails pingTestFailed 1 3 6 1 2 1 80 0 2 This trap is sent when a ping test consisting of a series of ping probes fails pingTestCompleted 1 3 6 1 2 1 80 0 3 This trap is...

Page 315: ...7 2 1 How SSH Works The following table summarizes how a secure connection is established between two remote hosts Figure 230 How SSH Works 1 Host Identification The SSH client sends a connection req...

Page 316: ...s a web protocol that encrypts and decrypts web pages Secure Socket Layer SSL is an application level protocol that enables secure transactions of data by ensuring confidentiality an unauthorized part...

Page 317: ...ages Internet Explorer 6 When you attempt to access the Switch HTTPS server a Windows dialog box pops up asking if you trust the server certificate You see the following Security Alert screen in Inter...

Page 318: ...you log in you will see the red address bar with the message Certificate Error Click on Certificate Error next to the address bar and click View certificates Figure 234 Certificate Error Internet Exp...

Page 319: ...rnet Explorer 11 Mozilla Firefox Warning Messages When you attempt to access the Switch HTTPS server a Your connection is not secure screen may display If that is the case click I Understand the Risks...

Page 320: ...the Web Configurator login screen Figure 237 Security Alert Mozilla Firefox 37 7 4 Google Chrome Warning Messages When you attempt to access the Switch HTTPS server a Your connection is not private sc...

Page 321: ...Google Chrome 58 0 3029 110 37 7 4 1 Main Settings After you accept the certificate and enter the login user name and password the Switch main screen appears The lock displayed in the bottom right of...

Page 322: ...Chapter 37 Access Control XGS1930 Series User s Guide 322 Figure 239 Example Lock Denoting a Secure Connection EXAMPLE...

Page 323: ...c screen You can use this screen to help you identify problems 38 2 Diagnostic Click Management Diagnostic in the navigation panel to open this screen Use this screen to ping IP addresses run a tracer...

Page 324: ...ith an IPv6 address IP Address Host Name Enter the IP address or host name of a device to which you want to perform a traceroute Click Trace Route to have the Switch perform the traceroute function Th...

Page 325: ...Switch chipset supports this feature This shows N A if the Pair status is Open or Short Check the Distance to fault This shows Unsupported if the Switch chipset does not support to show the cable leng...

Page 326: ...ches the maximum number of log messages new log messages automatically overwrite existing log messages starting with the oldest existing log message first Figure 241 Management System Log The summary...

Page 327: ...everity levels 40 1 1 What You Can Do Use the Syslog Setup screen Section 40 2 on page 327 to configure the device s system logging settings and configure a list of external syslog servers 40 2 Syslog...

Page 328: ...gation panel to save your changes to the non volatile memory when you are done configuring Cancel Click Cancel to begin configuring this screen afresh Syslog Server Setup Active Select this check box...

Page 329: ...not to send logs to the syslog server IP Address This field displays the IP address of the syslog server UDP Port This field displays the port of the syslog server Log Level This field displays the s...

Page 330: ...communicate with one another In the following example switch A in the basement is the cluster manager and the other switches on the upper floors of the building are cluster members Figure 243 Cluster...

Page 331: ...you see this if you access this screen in the cluster member Switch directly and not through the cluster manager None neither a manager nor a member of a cluster Manager This field displays the clust...

Page 332: ...hen its Status is displayed as Error in the Cluster Management Status screen and a warning icon appears in the member summary list below Name Type a name to identify the Clustering Manager You may use...

Page 333: ...be managed from the Cluster Manager Its Status is displayed as Error in the Cluster Management Status screen If multiple devices have the same password then hold SHIFT and click those switches to sele...

Page 334: ...Figure 246 Cluster Management Cluster Member Web Configurator Screen 41 4 1 1 Uploading Firmware to a Cluster Member Switch You can use FTP to upload firmware to a cluster member switch through the cl...

Page 335: ...ftp 297 bytes received in 0 00Seconds 297000 00Kbytes sec ftp bin 200 Type I OK ftp put 460ABPI0 bin fw 00 a0 c5 01 23 46 200 Port command okay 150 Opening data connection for STOR fw 00 a0 c5 01 23...

Page 336: ...now The Switch uses the MAC Table to determine how to forward frames See the following figure 1 The Switch examines a received frame and learns the port on which this source MAC address came 2 The Swi...

Page 337: ...screen to search specific MAC addresses You can also directly add dynamic MAC addresses into the static MAC forwarding table or MAC filtering table from the MAC table using this screen Click Managemen...

Page 338: ...e data according to VLAN group Select PORT to display and arrange the data according to port number Transfer Type Select Dynamic to MAC forwarding and click the Transfer button to change all dynamical...

Page 339: ...1 The Switch examines a received packet and learns the port from which this source IP address came 2 The Switch checks to see if the packet s destination IP address matches a source IP address alread...

Page 340: ...is button to display and arrange the data according to IP address VID Click this button to display and arrange the data according to VLAN group Port Click this button to display and arrange the data a...

Page 341: ...ble and if it finds the address it sends it to the device If no entry is found for the IP address ARP broadcasts the request to all the devices on the LAN The Switch fills in its own MAC and IP addres...

Page 342: ...ncel to return the fields to the factory defaults Index This is the ARP table entry number IP Address This is the IP address of a device connected to a Switch port with the corresponding MAC address b...

Page 343: ...main screen as shown Click the link next to IPv4 Routing Table to open a screen where you can view the IPv4 routing table information Click the link next to IPv6 Routing Table to open a screen where...

Page 344: ...ys the cost of the route Type This field displays the method used to learn the route STATIC added as a static entry LOCAL added as a local interface entry Uptime This field displays how long the route...

Page 345: ...een to view IPv6 path MTU information on the Switch Click Management Path MTU Table in the navigation panel to display the screen as shown Figure 256 Management Path MTU Table The following table desc...

Page 346: ...7 1 Overview This chapter shows you how you can copy the settings of one port onto other ports 47 2 Configure Clone Cloning allows you to copy the basic and advanced settings from a source port to a d...

Page 347: ...the source port You can enter individual ports separated by a comma or a range of ports by using a dash Example 2 4 6 indicates that ports 2 4 and 6 are the destination ports 2 6 indicates that ports...

Page 348: ...emory The Switch loses these changes if it is turned off or loses power so use the Save link on the top navigation panel to save your changes to the non volatile memory when you are done configuring C...

Page 349: ...figuration IPv6 Neighbor Setup screen When the Switch needs to send a packet it first consults other table to determine the next hop Once the next hop IPv6 address is known the Switch looks into the n...

Page 350: ...initial request The field displays this also when the Switch receives an unrequested response from the neighbor s interface delay D The neighboring interface is no longer known to be reachable and tra...

Page 351: ...en Table 184 Management Port Status LABEL DESCRIPTION Port This identifies the Ethernet port Click a port number to display the Port Details screen Name This is the name you assigned to this port in t...

Page 352: ...Pkts This field shows the number of transmitted frames on this port RxPkts This field shows the number of received frames on this port Errors This field shows the number of received errors on this por...

Page 353: ...r the combo ports This field displays Down if the port is not connected to any device State If STP Spanning Tree Protocol is enabled this field displays the STP state of the port If STP is disabled th...

Page 354: ...one collision Multiple This is a count of successfully transmitted packets for which transmission was inhibited by more than one collision Excessive This is a count of packets for which transmission f...

Page 355: ...erating parameters on the SFP port The parameters include for example transmitting and receiving power and module temperature Click a number in the Port column in the DDMI screen to view current trans...

Page 356: ...ver was manufactured Transceiver This displays details about the type of transceiver installed in the SFP slot Calibration This field is available only when an SFP transceiver is inserted into the SFP...

Page 357: ...m Threshold This displays the high value alarm threshold for each monitored DDMI parameter An alarm signal is reported to the Switch if the monitored DDMI parameter reaches this value High Warn Thresh...

Page 358: ...F for full duplex This field displays Down if the port is not connected to any device Tx kB s This field shows the transmission speed of data sent on this port in kilobytes per second Tx Utilization T...

Page 359: ...359 PART III Troubleshooting and Appendices...

Page 360: ...2 Make sure the power adapter or cord is connected to the Switch and plugged in to an appropriate power source Make sure the power source is turned on 3 Disconnect and re connect the power adapter or...

Page 361: ...the user name and or password 1 The default user name is admin and the default password is 1234 2 If this does not work you have to reset the device to its factory defaults See Section 4 8 on page 63...

Page 362: ...ou have configured a secured client IP address your computer s IP address must match it Refer to the chapter on access control for details 3 Disconnect and re connect the cord to the Switch 4 If this...

Page 363: ...Configurator to save the configuration permanently See also Section 36 2 2 on page 291 for more information about how to save your configuration I accidentally unplugged the Switch I am not sure which...

Page 364: ...on Please have the following information ready when you contact an office Required Information Product model and serial number Warranty Information Date that you received your device Brief description...

Page 365: ...lippines Zyxel Philippines http www zyxel com ph Singapore Zyxel Singapore Pte Ltd http www zyxel com sg Taiwan Zyxel Communications Corporation https www zyxel com tw zh Thailand Zyxel Thailand Co Lt...

Page 366: ...Zyxel Communications A S https www zyxel com dk da Estonia Zyxel Estonia https www zyxel com ee et Finland Zyxel Communications https www zyxel com fi fi France Zyxel France https www zyxel fr German...

Page 367: ...and Zyxel Communications Poland https www zyxel com pl pl Romania Zyxel Romania https www zyxel com ro ro Russia Zyxel Russia https www zyxel com ru ru Slovakia Zyxel Communications Czech s r o organi...

Page 368: ...erica Argentina Zyxel Communications Corporation https www zyxel com co es Brazil Zyxel Communications Brasil Ltda https www zyxel com br pt Colombia Zyxel Communications Corporation https www zyxel c...

Page 369: ...unications Corporation https www zyxel com me en North America USA Zyxel Communications Inc North America Headquarters https www zyxel com us en Oceania Australia Zyxel Communications Corporation http...

Page 370: ...ons in which this service is used Table 189 Commonly Used Services NAME PROTOCOL PORT S DESCRIPTION AH IPSEC_TUNNEL User Defined 51 The IPSEC AH Authentication Header tunneling protocol uses this serv...

Page 371: ...hat sends out ICMP echo requests to test whether or not a remote host is reachable POP3 TCP 110 Post Office Protocol version 3 lets a client computer get e mail from a POP3 server through a temporary...

Page 372: ...S UDP 49 Login Host Protocol used for Terminal Access Controller Access Control System TELNET TCP 23 Telnet is the login and terminal emulation protocol common on the Internet and in UNIX environments...

Page 373: ...1a2f 0015 2001 db8 1a2f 0 0 15 or 2001 db8 0 0 1a2f 15 Prefix and Prefix Length Similar to an IPv4 subnet mask IPv6 uses an address prefix to represent the network address An IPv6 prefix length specif...

Page 374: ...wing table describes some of the predefined multicast addresses The following table describes the multicast addresses which are reserved and cannot be assigned to a multicast group Table 191 Predefine...

Page 375: ...ing UDP Each DHCP client and server has a unique DHCP Unique IDentifier DUID which is used for identification when they are exchanging DHCPv6 messages The DUID is generated from the MAC address time v...

Page 376: ...uplink router for its LAN The Switch uses the received IPv6 prefix for example 2001 db2 48 to generate its LAN IP address Through sending Router Advertisements RAs regularly by multicast the Switch p...

Page 377: ...as the next hop Otherwise the Switch determines the next hop from the default router list or routing table Once the next hop IP address is known the Switch looks into the neighbor cache to get the li...

Page 378: ...DHCPv6 for IP address assignment you have to additionally install a DHCPv6 client software on your Windows XP Note If you use static IP addresses or Router Advertisement for IPv6 address assignment in...

Page 379: ...Example Enabling IPv6 on Windows 7 Windows 7 supports IPv6 by default DHCPv6 is also enabled when you enable IPv6 on a Windows 7 computer To enable IPv6 in Windows 7 1 Select Control Panel Network and...

Page 380: ...DHCPv6 is enabled when you enable IPv6 on a Windows 10 PC To enable IPv6 in Windows 10 1 Select Control Panel Network and Sharing Center 2 On the left side of the Network and Sharing Center select Cha...

Page 381: ...our computer 1 Select Start Settings Network Internet 2 On the left side of the Network Internet select Ethernet Then select the Ethernet network you are connected to 3 Under IP assignment select Edit...

Page 382: ...C rules Operation is subject to the following two conditions 1 This device may not cause harmful interference 2 This device must accept any interference received including interference that may cause...

Page 383: ...nformation about recycling of this product please contact your local city office your household waste disposal service or the store where you purchased the product Use ONLY power wires of the appropri...

Page 384: ...den rtlichen Bestimmungen getrennt vom Hausm ll entsorgt werden muss Wenden Sie sich an eine Recyclingstation wenn dieses Produkt das Ende seiner Lebensdauer erreicht hat Zum Zeitpunkt der Entsorgung...

Page 385: ...Symbols Various symbols are used in this product to ensure correct usage to prevent danger to the user and others and to prevent property damage The meaning of these symbols are described below It is...

Page 386: ...ing conditions Note Repair or replacement as provided under this warranty is the exclusive remedy of the purchaser This warranty is in lieu of all other warranties express or implied including any imp...

Page 387: ...RP how it works 284 learning mode 284 overview 284 setup 286 ARP Address Resolution Protocol 341 ARP Learning screen 286 ARP Setup screen 286 ARP Table screen 341 ARP Reply 285 ARP Request 286 ATM Asy...

Page 388: ...see CIST 151 configuration 267 back up 26 change running config 291 saving 62 configuration file backup 295 restore 294 save 291 Configure Clone screen 346 contact information customer support 364 co...

Page 389: ...E egress port 128 egress rate 153 electrical inspection authority 36 electrician 37 electrostatic discharge ESD 32 Environment Statement 384 Errdisable Detect screen 240 Errdisable Recovery screen 24...

Page 390: ...6 implementation 316 public keys private keys 316 HTTPS Certificates screen 298 HTTPS example 317 I IANA Internet Assigned Number Authority 370 Identity Association IA 375 IEEE 802 1x activate 168 por...

Page 391: ...Setup screen 105 IPv6 Neighbor Setup screen 111 IPv6 Neighbor Table screen 349 IPv6 screen 100 IPv6 static route configuration 269 J Java permission 40 362 JavaScript 40 362 L L2PT 224 access port 22...

Page 392: ...urrent configuration 290 firmware 293 main screen 290 restore configuration 294 Maintenance screen 289 Management Information Base MIB 312 management IP address 66 management mode 20 change 21 managem...

Page 393: ...y Unique Identifiers OUI 124 Org specific TLV Setting screen 261 overheating prevention 27 P PAgP 227 password 61 administrator 43 308 change 26 change through Wizard 50 write down 26 password change...

Page 394: ...t 229 tag format 228 trusted ports 230 untrusted ports 230 VLAN 234 PPPoE Intermediate Agent 228 prefix delegation 376 priority level queue assignment 86 priority queue assignment 86 priority and OSPF...

Page 395: ...object variables 312 protocol operations 312 security 307 security level 307 setup 303 traps 304 users 306 version 3 and security 312 versions supported 312 SNMP agent enable through Wizard 50 SNMP tr...

Page 396: ...upport 295 log enhancement 295 Tech Support screen 295 temperature indicator 82 time current 83 daylight saving 84 format 83 Time RFC 868 83 time range 176 time server 83 time service protocol 83 trad...

Page 397: ...g Protocol see VTP VLAN unaware devices 65 voice VLAN 123 Voice VLAN Setup screen 124 VSA 207 VTP 226 W warranty 386 note 386 Web browser pop up window 40 362 Web Configurator getting help 63 home 57...

Reviews: