background image

User Manual 

67 

authentication in 802.1x port security application.

Parameter description: 

Mode: 

Enable or disable 802.1X function. 

RADIUS IP: 

RADIUS server IP address for authentication. 

Default: 0.0.0.0 

RADIUS UDP Port: 

The port number to communicate with RADIUS server for the 
authentication service. The valid value ranges 1-65535. 

Default port number is 1812. 

RADIUS Secret: 

The secret key between authentication server and authenticator. It is a 
string with the length 1 – 15 characters. The character string may contain 
upper case, lower case and 0-9. It is character sense. It is not allowed for 
putting a blank between any two characters. 

Default: None 

Admin State: 

This is used to set the operation mode of authorization. There are three 
type of operation mode supported, Force Unauthorized, Force 
Authorized, Auto. 

y

  

Force Unauthorized: 

  The controlled port is forced to hold in the unauthorized state. 

y

  

Force Authorized: 

The controlled port is forced to hold in the authorized state. 

y

 

 

Auto: 

The controlled port is set to be in authorized state or unauthorized 
state depends on the result of the authentication exchange between 
the authentication server and the supplicant. 

   Default: Force Authorized 

Port State: 

Show the port status of authorization. 

Re-authenticate: 

Specify if subscriber has to periodically re-enter his or her username and 
password to stay connected to the port. 

Re-authenticate All: 

     Re-authenticate for all ports in at once. 

Force Reinitialize: 

Force the subscriber has to reinitialize connected to the port. 

Force Reinitialize All: 

Содержание SGR24W4

Страница 1: ...SGR24W4 24 port Gigabit Web Smart Switch with 4 combo RJ45 SFP ports User s Guide Release 1 05...

Страница 2: ...o part of this publication may be reproduced in any form or by any means or used to make any derivative such as translation transformation or adaptation without permission as stipulated by the United...

Страница 3: ...WHAT S THE ETHERNET 23 3 2 MEDIA ACCESS CONTROL MAC 26 3 3 FLOW CONTROL 32 3 4 HOW DOES A SWITCH WORK 35 3 5 VIRTUAL LAN 39 3 6 LINK AGGREGATION 45 4 OPERATION OF WEB BASED MANAGEMENT 47 4 1 WEB MANA...

Страница 4: ...NCE 93 4 4 1 Warm Restart 94 4 4 2 Factory Reset 95 4 4 3 Software Upgrade 96 4 4 4 Configuration File Transfer 97 Fig 4 37 Configuration Upload Download 97 5 Trouble Shooting 99 5 1 RESOLVING NO LINK...

Страница 5: ...v Revision History Release Date Revision 1 00 02 10 2007 A1 1 01 03 13 2007 A1 1 02 06 23 2007 A2 1 03 07 13 2007 A2 1 04 09 04 2007 A3 1 05 2 1 2008 A1...

Страница 6: ...Statement This equipment has been tested and found to comply with the limits for a class A computing device pursuant to Subpart J of part 15 of FCC Rules which are designed to provide reasonable prote...

Страница 7: ...tch This guide also covers management options and detailed explanation about hardware and software functions Overview of this user s manual Chapter 1 Introduction describes the features of 24 Gigabit...

Страница 8: ...ansceiver 1000Mbps LC 10km SFP Fiber transceiver 1000Mbps LC 30km SFP Fiber transceiver 1000Mbps LC 50km SFP Fiber transceiver 1000Mbps BiDi SC 20km 1550nm SFP Fiber WDM transceiver 1000Mbps BiDi SC 2...

Страница 9: ...10 100 1000Mbps Auto negotiation Gigabit Ethernet TP ports 4 10 100 1000Mbps TP or 1000Mbps SFP Fiber dual media auto sense 400KB on chip frame buffer Jumbo frame support Programmable classifier for...

Страница 10: ...rap event while monitored events happened Supports default configuration which can be restored to overwrite the current configuration which is working on via Web UI and Reset button of the switch Supp...

Страница 11: ...tes the power status and 24 ports working status of the switch LED Indicators LED Color Function System LED POWER Green Lit when 3 3V power is coming up 10 100 1000Ethernet TP Port 1 to 24 LED LINK AC...

Страница 12: ...SFP LINK ACT Green Lit when SFP connection with remote device is good Blinks when any traffic is present Table1 1 RESET Button RESET button is used to restore the system default setting 1 4 2 User In...

Страница 13: ...10km SFP Fiber transceiver SFP 0LC 212 10 1000Mbps LC SM 30km SFP Fiber transceiver SFP 0LC 212 30 1000Mbps LC SM 50km SFP Fiber transceiver SFP 0LC 212 50 1000Mbps LC SM 70km SFP Fiber transceiver S...

Страница 14: ...source Installing Optional SFP Fiber Transceivers to the 24 Port GbE Web Smart Switch Note If you have no modules please skip this section Connecting the SFP Module to the Chassis The optional SFP mo...

Страница 15: ...ing the switch in operation Power On The switch supports 100 240 VAC 50 60 Hz power supply The power supply will automatically convert the local AC power source to DC power It does not matter whether...

Страница 16: ...f connector type there mainly are LC and BIDI SC Gigabit Fiber with multi mode LC SFP module Gigabit Fiber with single mode LC SFP module Gigabit Fiber with BiDi SC 1310nm SFP module Gigabit Fiber wit...

Страница 17: ...Cable 10 10 m TP to fiber Converter 56 Bit Time unit 1ns 1sec 1000 Mega bit Bit Time unit 0 01 s 1sec 100 Mega bit Table 2 2 Sum up all elements bit time delay and the overall bit time delay of wires...

Страница 18: ...ch supports both port based VLAN and tag based VLAN They are different in practical deployment especially in physical location The following diagram shows how it works and what the difference they are...

Страница 19: ...VLAN3 members but they could access VLAN4 members 3 VLAN3 members could not access VLAN1 VLAN2 and VLAN4 4 VLAN4 members could not access VLAN1 and VLAN3 members but they could access VLAN2 members C...

Страница 20: ...the way of web user is allowed to startup the switch management function Users can use any one of them to monitor and configure the switch You can touch them through the following procedures Section 2...

Страница 21: ...p a physical path between the configured the switch and a PC by a qualified UTP Cat 5 cable with RJ 45 connector Note If PC directly connects to the switch you have to setup the same subnet mask betwe...

Страница 22: ...into predefined address classes or categories Each class has its own network range between the network identifier and host identifier in the 32 bits address Each IP address comprises two parts network...

Страница 23: ...ult route and 127 0 0 0 8 is reserved for loopback function 0 Class B IP address range between 128 0 0 0 and 191 255 255 255 Each class B network has a 16 bit network prefix followed 16 bit host addre...

Страница 24: ...2 3 it may have a subnet mask 255 255 0 0 in default in which the first two bytes is with all 1s This means more than 60 thousands of nodes in flat IP address will be at the same network It s too larg...

Страница 25: ...23 512 510 22 1024 1022 21 2048 2046 20 4096 4094 19 8192 8190 18 16384 16382 17 32768 32766 16 65536 65534 Table 2 3 According to the scheme above a subnet mask 255 255 255 0 will partition a networ...

Страница 26: ...ess known as default router Basically it is a routing policy For assigning an IP address to the switch you just have to check what the IP address of the network will be connected with the switch Use t...

Страница 27: ...please refer to Appendix A The switch is suitable for the following applications Central Site Remote site application is used in carrier or ISP See Fig 2 10 Peer to peer application is used in two rem...

Страница 28: ...User Manual 22 Fig 2 12 Office Network Connection Fig 2 11 Peer to peer Network Connection...

Страница 29: ...Ethernet was rolled out and provided 1000Mbps Now 10G s Ethernet is under approving Although these Ethernet have different speed they still use the same basic functions So they are compatible in softw...

Страница 30: ...or bridge relay entity Logical link control supports the interface between the Ethernet MAC and upper layers in the protocol stack usually Network layer which is nothing to do with the nature of the L...

Страница 31: ...or response The DSAP and SSAP pair with some reserved values indicates some well known services listed in the table below 0xAAAA SNAP 0xE0E0 Novell IPX 0xF0F0 NetBios 0xFEFE IOS network layer PDU 0xF...

Страница 32: ...long and locally unique address Since this type of address is applied only to the Ethernet LAN media access control MAC they are referred to as MAC addresses The first three bytes are Organizational...

Страница 33: ...t is a broadcast which means all network device except the sender itself can receive the frame and response Ethernet Frame Format There are two major forms of Ethernet frame type encapsulation and len...

Страница 34: ...psulation and Netware 802 3 RAW encapsulation Each of them has different fields following the Length field If the Length Type value is greater than 1500 it means the Length Type acts as Type Different...

Страница 35: ...ings summarize what a MAC does before transmitting a frame 1 MAC will assemble the frame First the preamble and Start of Frame delimiter will be put in the fields of PRE and SFD followed DA SA tag ID...

Страница 36: ...the two most distant devices This maximum time is traded off by the collision recovery time and the diameter of the LAN In the original 802 3 specification Ethernet operates in half duplex only Under...

Страница 37: ...mode both transmitting and receiving frames are processed simultaneously This doubles the total bandwidth Full duplex is much easier than half duplex because it does not involve media contention colli...

Страница 38: ...er signal on the medium at that time the device will wait for a period of time known as an inter frame gap time to have the medium clear and stabilized as well as to have the jobs ready such as adjust...

Страница 39: ...omewhere or an interface malfunctioned in the LAN When detecting the case the MAC drops the packet and goes back to the ready state 2 If the DA of the received frame exactly matches the physical addre...

Страница 40: ...special value 0x8100 at the location of the Length Type field of the normal non VLAN frame it will interpret the received frame as a tagged VLAN frame If this happens in a switch the MAC will forward...

Страница 41: ...bitrate who can transmit data to the station s attached in the LAN When more than one station transmits data within the same slot time the signals will collide referred to as collision The arbitrator...

Страница 42: ...n operating in full duplex mode the distance can reach farther than half duplex because it is not limited by the maximum propagation delay time 512 bits time If fiber media is applied the distance can...

Страница 43: ...not exist have the packet broadcasted Due to the size of the MAC address limited MAC address aging function is applied When the MAC address has resided and keeps no update in the table for a long time...

Страница 44: ...chips may support different schedule algorithms Most common schedulers are FCFS First Come First Service Strictly Priority All High before Low Weighted Round Robin Set a weight figure to the packet wi...

Страница 45: ...AN a router is needed which always lies on the edge of the LAN For a layer 2 VLAN it assumes it is a logical subset of a physical LAN separated by specific rules such as tag port MAC address and so on...

Страница 46: ...configure the network easily according to the criteria needed for example financial accounting R D and whatever you think it necessary You can also easily move a user to a different location or join a...

Страница 47: ...rying a tag field following the source MAC address is four bytes long and contains VLAN protocol ID and tag control information composed of user priority Canonical Format Indicator CFI and optional VL...

Страница 48: ...th VID assigned by a port is called PVID Each port can only be assigned a PVID The default value for PVID is 1 the same as VID Ingress filtering The process to check a received packet and compare its...

Страница 49: ...riority accordingly If enabled an egress port will transmit out a tagged packet if the port is connected to a 802 1Q compliant device If an egress port is connected to a non 802 1Q device or an end st...

Страница 50: ...isabled VLAN bridge will only check the MAC address table to see if the destination VLAN exists If VLAN does not exist then drop the packet and if both DA and VLAN do not exist forwards the packet If...

Страница 51: ...t and the solution caused by the limitation of hardware performance may not be scalable If the item 2 is the case now you do not have to pay much more extra cost and can keep flexible according to the...

Страница 52: ...to station and station to station Here station may be a host or a router Link Aggregation called port trunking sometimes has two types of link configuration including static port trunk and dynamic po...

Страница 53: ...Address 192 168 1 1 Subnet Mask 255 255 255 0 Default Gateway 192 168 1 254 Password admin Table 4 1 When the configuration of your Web Smart Switch is finished you can browse it by the IP address you...

Страница 54: ...and shows you the basic information of the switch including Switch Status TP Port Status Fiber Port Status Aggregation VLAN Mirror SNMP and Maximum Packet Length With this information you will know t...

Страница 55: ...e ones you insert Vice versa if ports are disconnected they will show just in black On the left side the main menu tree for web is listed in the page According to the function name in boldface all fun...

Страница 56: ...Configuration VLAN Group Configuration Aggregation LACP RSTP 802 1X IGMP Snooping Mirror QoS Filter Rate Limit Storm Control and SNMP System Configuration Ports Configuration VLAN Mode Configuration...

Страница 57: ...ress active subnet mask active gateway DHCP server and Lease time left Set device name DHCP enable fallback IP address fallback subnet mask fallback gateway management VLAN password and inactivity tim...

Страница 58: ...ew values Then click Apply button to update Default 192 168 1 1 Fallback Subnet Mask Subnet mask is made for the purpose to get more network address because any IP device in a network must own its IP...

Страница 59: ...her pre defined path it must be forwarded to a default router on a default path This means any packet with undefined IP address in the routing table will be sent to this device unconditionally Default...

Страница 60: ...and Disable If the media is TP the Speed Duplex is comprised of the combination of speed mode 10 100 1000Mbps and duplex mode full duplex and half duplex The following table summarized the function th...

Страница 61: ...e or Disable you can choose one of them by pulling down list and pressing the Downward arrow key Then click Apply button the settings will take affect immediately Parameter description VLAN Mode Port...

Страница 62: ...be assigned VLAN name and VLAN ID Valid VLAN ID is 1 4094 User can create total up to 24 Tag VLAN groups Double tag Double tag mode belongs to the tag based mode however it would treat all frames as...

Страница 63: ...n which keeps the default data You can easily create and delete a VLAN group by pressing Add and Delete function buttons or click the Group ID directly to edit it Parameter description ID Group ID Whe...

Страница 64: ...User Manual 58 Fig 4 8 Add or Remove VLAN Member Delete Group Just tick the check box beside the ID then press the Delete button to delete the group Fig 4 9 Port Based VLAN Configuration...

Страница 65: ...hernet ports are aggregated into a logical port then this logical port s bandwidth would be as three times high as a single Fast Ethernet port s Function name Aggregation Configuration Function descri...

Страница 66: ...LACP also allows port redundancy that is if an operational port fails then one of the standby ports become operational without user intervention Function name LACP Port Configuration Function descrip...

Страница 67: ...h the highest priority lowest numeric value becomes the STP root switch If all switches have the same priority the switch with the lowest MAC address will then become the root switch Select a vale fro...

Страница 68: ...e port x to enable RSTP protocol then press the Apply button to apply Edge Just tick the check box beside the port x to enable edge function Path Cost Path cost is the cost of transmitting a frame on...

Страница 69: ...tion message when the Authenticator PAE request to it Authenticator An entity facilitates the authentication of the supplicant entity It controls the state of the port authorized or unauthorized accor...

Страница 70: ...henticator connecting to PC A and A is a PC outside the controlled port running Supplicant PAE In this case PC A wants to access the services on device B and C first it must exchange the authenticatio...

Страница 71: ...or PAE 7 The supplicant will convert user password into the credential information perhaps in MD5 format and replies an EAP Response with this credential information as well as the specified authentic...

Страница 72: ...device s MAC address and its VID The following table is the summary of the combination of the authentication status and the port status versus the status of port mode set in 802 1x Port mode port con...

Страница 73: ...sed to set the operation mode of authorization There are three type of operation mode supported Force Unauthorized Force Authorized Auto y Force Unauthorized The controlled port is forced to hold in t...

Страница 74: ...02 1X Configuration Statistics Choose the port which you want to show of 802 1X statistics the screen include Authenticator counters backend Authenticator counters dot1x MIB counters and Other statist...

Страница 75: ...nected to the port Parameter description Reauthentication Enabled Choose whether regular authentication will take place in this port Default disable Reauthentication Period 1 65535 s A non zero number...

Страница 76: ...t disable Router Ports Just tick the check box beside the port x to enable router ports then press the Apply button to start up Default none Unregistered IGMP Flooding enabled Just tick the check box...

Страница 77: ...ample we assume that Port A and Port B are Source Ports and Port C is Mirror Port respectively thus the traffic passing through Port A and Port B will be copied to Port C for monitor purpose Parameter...

Страница 78: ...Layer 3 of network framework Fig 4 21 QoS Configuration Function name QoS Configuration Function description While setting QoS function please select QoS Mode in drop down menu at first Then you can...

Страница 79: ...ty The QoS setting would apply to all ports on the switch if one of the following values is selected All Low Priority All Normal Priority All Medium Priority or All High Priority Port Number When Cust...

Страница 80: ...kinds of Class that belong to any of queue low normal medium high Parameter description Prioritize Traffic Five Prioritize Traffic values are provided Custom All Low Priority All Normal Priority All...

Страница 81: ...rop down menu Default is disabled Disabled Allow all IP Address login to this switch and manage it Static Just allow the IP Address which set by administrator to login to this switch and manage it DHC...

Страница 82: ...User Manual 76 Fig 4 24 Filter Configuration...

Страница 83: ...ta Rate field Pause frames are also generated if flow control is enabled The format of the packet limits to unicast broadcast and multicast Valid value of Port 1 24 ranges from 128 3968 kbps Default N...

Страница 84: ...on Parameter description ICMP Rate To enable the ICMP Storm capability User can use drop down menu to select number of frames Default is No Limit The setting range is 1k 1024k per second Learn Frames...

Страница 85: ...mit The setting range is 1k 1024k per second Flooded unicast Rate To enable the Flooded unicast Storm capability User can use drop down menu to select number of frames Default is No Limit The setting...

Страница 86: ...l as the throttle of SNMP A SNMP manager must pass the authentication by identifying both community names then it can access the MIB information of the target device So both parties must have the same...

Страница 87: ...User Manual 81 Default community name for Set private Default community name for Trap public Fig 4 27 SNMP Configuration...

Страница 88: ...time If the counting is overflow the counter will be reset and restart counting Function name Statistics Overview Function description Display the summary counting of each port s traffic including Tx...

Страница 89: ...User Manual 83 Number of bad packets transmitted Rx Errors Number of bad packets received Fig 4 28 Statistics Overview for all ports...

Страница 90: ...Broadcast Show the counting number of the received broadcast packet Rx Multicast Show the counting number of the received multicast packet Rx Broad and Multicast Show the counting number of the recei...

Страница 91: ...ytes Number of 1024 max_length byte frames in good and bad packets received Tx 64 Bytes Number of 64 byte frames in good and bad packets transmitted Tx 65 127 Bytes Number of 65 126 byte frames in goo...

Страница 92: ...nvalid CRC Rx Drops Frames dropped due to the lack of receiving buffer Tx Collisions Number of collisions transmitting frames experienced Tx Drops Number of frames dropped due to excessive collision l...

Страница 93: ...window can show LACP information and status for all ports in the same time Parameter description LACP Aggregation Overview Show the group port status Default will set to red sign for port link down u...

Страница 94: ...dress of this switch Hello Time Show the current hello time of the root bridge Hello time is a time interval specified by root bridge used to request all other bridges periodically sending hello messa...

Страница 95: ...User Manual 89 Fig 4 31 RSTP Status...

Страница 96: ...up to which it belongs It Calculate the number of times of IGMPV1 report V2 Reports When a host receives a group membership query it identifies the groups associated with the query and determines to w...

Страница 97: ...s Target IP address Set up a Target IP address to ping Count Use drop down menu to set number of echo requests to send Four type of number can choose there are 1 5 10 and 20 Default 1 Time Out in secs...

Страница 98: ...ddress Status Show the result of the ping status Received replies Show the received replies number of times Request timeouts Show the timeout of request Average Response times In ms Show the average r...

Страница 99: ...User Manual 93 4 4 Maintenance There are five functions contained in the maintenance function Warm Restart Factory Default Maintenance Software Upgrade Configuration File Transfer Logout...

Страница 100: ...ult settings After upgrading software you have to reboot the device to have new configuration take effect The function being discussed here is software reset Function name Warm Restart Function descri...

Страница 101: ...t the IP address setting all settings will be restored to the factory default values when Factory Default function is performed If you want to restore all configurations including the IP address setti...

Страница 102: ...ual 96 4 4 3 Software Upgrade Function name Software Upgrade Function description You can just click Browse button to retrieve the file you want in your system to upgrade your switch Fig 4 36 Software...

Страница 103: ...ransfer Function description You can backup your switch s configuration file into your computer folder in case accident happens In addition uploading backup configuration file into a new or a crashed...

Страница 104: ...do not logout and exit the browser the switch will automatically have you logout Besides this manually logout and implicit logout you can set up the parameter of Auto Logout Timer in system configurat...

Страница 105: ...Computer C 2 The uplink connection function fails to work 9 The connection ports on another must be connection ports Please check if connection ports are used on that 24 Port GbE Web Smart Switch 9 P...

Страница 106: ...able mode force mode or auto polling mode Supports Head of Line HOL blocking prevention Supports broadcast storm filtering Web based management provides the ability to completely manage the switch fro...

Страница 107: ...ver Transmission Mode 10 100Mbps support full or half duplex 1000Mbps support full duplex only Transmission Speed 10 100 1000Mbps for TP 1000Mbps for Fiber Full Forwarding Filtering Packet Rate PPS pa...

Страница 108: ...o 24 LINK ACT 10 100 1000Mbps 1000M SFP Fiber Port 21 22 23 24 SFP LINK ACT Power Requirement AC Line Voltage 100 240 V Frequency 50 60 Hz Consumption 20W Ambient Temperature 0 to 40 C Humidity 10 to...

Страница 109: ...VLAN group set Trunk Connection VLAN Function Port Base 802 1Q Tagged allowed up to 24 active VLANs in one switch Trunk Function Ports trunk connections allowed Bandwidth Control Supports by port Egre...

Страница 110: ...GESM SW24LProduces OBJECT IDENTIFIER GESM SW24LProductId 1 GESM SW24LIllegalLogin TRAP TYPE ENTERPRISE GESM SW24LProductId DESCRIPTION Send this trap when the illegal user try to login the Web managem...

Страница 111: ......

Отзывы: