background image

 

page 7 of 21 

SW1020A in order to create the required normal and/or bypass paths through the SW1020A, and to allow the 
PING packets from the internal Ethernet node on the SW1020A to travel to the desired external Ethernet node 
on the user’s network. See figures 1 & 2 above for examples of typical network connections to the SW1020A 
Auto Bypass Switch. 

 

In a typical IPS environment, the NETWORK port on the SW1020A would be connected to an unused port 
on the edge router/switch as noted in the example configuration in figure 1 above. To provide auto bypass 
switching, the SW1020A should be configured to use the firewall’s IP and MAC addresses for the monitor IP 
address and monitor MAC address parameters. With this configuration, if the SW1020A detects a problem 
thru the normal path and the IPS to the firewall, it will automatically switch to the bypass path. The auto 
recovery switching function is typically not used in this type of application, and would normally be disabled. 
This approach allows the network security manager to verify that when a problem occurs in the normal path 
thru the IPS (causing the SW1020A to switch to the bypass path), that any problems related to the IPS and the 
normal path are resolved before the IPS is reconnected to the network. Once these problems have been 
resolved, the network security manager can then issue a “set system B” command to the SW1020A to switch 
back to the normal path. 
 
In a typical failover environment, the NETWORK port on the SW1020A would be connected to a layer 2 
switch or HUB as described in the example configuration in figure 2 above. To provide auto 
failover/recovery, the SW1020A should be configured to use the IP and MAC addresses of a device on the 
“normal” network for the monitor IP address and monitor MAC address parameters. With this configuration, 
the auto bypass switching function will cause the SW1020A to automatically switch to the failover network if 
it detects a problem thru the normal path to the device being monitored.  And if the auto recovery switching 
function is enabled, it will cause the SW1020A to automatically switch back from the failover network 
connection to the normal network connection once the normal network operation is restored (the SW1020A is 
able to PING the device again on the normal network path). 

 

When using the auto bypass and auto recovery features, the monitorip address and monitormac address 
parameters can be configured to monitor connectivity to any device within, or outside of the user’s network 
environment. The monitormac address has two modes of operation – it can be manually configured, or it can 
be set to automatic mode. For automatic mode, simply set the monitormac address parameter to 00 00 00 00 
00 00. Then set the monitorip address parameter to the IP address of the device you want to PING in order to 
monitor the normal network path connections. The SW1020A will issue an ARP request to the gateway router 
to get the appropriate MAC address it needs to use in the PING packet. Alternately, you can manually enter 
the appropriate MAC address. If monitoring connectivity to a device on the same subnet as the SW1020A’s 
internal Ethernet node, set the SW1020A’s monitorip address and monitormac address parameters to the IP 
address and MAC address of the device being monitored. If monitoring connectivity to a device on a different 
subnet/network than the SW1020A’s internal Ethernet node, set the SW1020A’s monitormac address 
parameter to the MAC address of the gateway router on the SW1020A’s subnet, and set the monitorip address 
parameter to the IP address of the device being monitored. This allows the PING packet issued by the 
SW1020A to be routed through the gateway router to the target device on a different subnet/network. 
 

4.7 

Once you have configured the TCP/IP parameters, you may also want to configure the SW1020A’s access 
control related parameters. The SW1020A has an internal http server that provides access to its command 
interface via any web browser. This internal http server can be enabled or disabled. If enabled, a password 
can also be set, its TCP/IP port number can be configured, and an inactivity timeout can be configured to 
prevent  unauthorized access. The SW1020A also provides telnet access, and SNMP access to its command 
interface. These interfaces also have additional configuration parameters to restrict unauthorized access. See 
section 7 for a complete description of theses access control related commands. 

 
 
 
 
 

Содержание SW1020A

Страница 1: ...Order toll free in the U S 877 877 BBOX outside U S call 724 746 5500 FREE technical support 24 hours a day 7 days a week Call 724 746 5500 or fax 724 746 0746 Mail order Black Box Corporation 1000 Park Drive Lawrence PA 15055 1018 Web site www blackbox com E mail info blackbox com ...

Страница 2: ...rference Regulation of Industry Canada Le présent appareil numérique n émet pas de bruits radioélectriques dépassant les limites applicables aux appareils numériques de la classe A prescrites dans le Règlement sur le brouillage radioélectrique publié par le Industrie Canada 1 Specifications Connectors Ethernet 6 RJ45 for network path connections 1 RJ45 for Ethernet remote control interface and pat...

Страница 3: ...g network problems As noted previously the Auto Bypass Switch can automatically switch connection states using its auto bypass and auto recovery switching functions Or the user can remotely issue switch commands via the SW1020A Ethernet interface or RS232 serial interface If using the Ethernet interface three different options exist for remotely controlling the SW1020A the SW1020A supports telnet ...

Страница 4: ...e SW1020A Auto Bypass Switch is to monitor in order to determine when to switch between the normal and the bypass paths A value of 0 0 0 0 for the monitor IP address disables the auto bypass and auto recovery switching functions Monitor interval this is the time interval between PINGs issued by the internal Ethernet node in the SW1020A measured in 100 msec increments For example if you want the SW...

Страница 5: ...h Thus the BYPASS or A to COMMON or C connections are typically used for the bypass failover path connections and the NORMAL or B to COMMON or C connections are used for the normal path connections For example when used with an Intrusion Prevention System or similar devices the two BYPASS or A ports on the SW1020A are typically connected together with a short patch cable The NORMAL or B ports on t...

Страница 6: ...Bypass Switch are in the BYPASS or A to COMMON or C connection state and the NORMAL B LED lights when both switching elements within the SW1020A are in the NORMAL or B to COMMON or C connection state If one A B switch element is in the BYPASS or A position and the other is in the BORMAL or B position neither LED will be lit this would occur only if the user issues a set port n command that switche...

Страница 7: ...etwork connection to the normal network connection once the normal network operation is restored the SW1020A is able to PING the device again on the normal network path When using the auto bypass and auto recovery features the monitorip address and monitormac address parameters can be configured to monitor connectivity to any device within or outside of the user s network environment The monitorma...

Страница 8: ... line The parameters of the DB9 RS232 console port are fixed at 9600 baud 8 data bits no parity 1 stop and no flow control commonly abbreviated as 9600 8 N 1 NONE When the SW1020A powers up it will send a sign on message followed by a prompt character to your serial terminal device After each command and any associated response from the unit it will again issue a prompt character For systems where...

Страница 9: ...P variables and their functions The SW1020A also supports telnet access and can be controlled via a telnet session using the same commands as used by the RS232 serial interface The SW1020A also includes a built in http server that allows all of the commands that are available via the RS232 serial port to be accessed via a web browser interface See section 8 for a detailed description of this featu...

Страница 10: ...to enter an IP address and subnet mask gateway address read and write SNMP community names if using SNMP or a web password for browser access These parameters then need to be saved into non volatile memory and the system will then need to be reset to allow it to reconfigure with the new settings Any time one or more of these parameters is changed they must be saved followed by a system reset The f...

Страница 11: ...et Port 23 Monitor IP Address 192 168 1 113 Monitor MAC Address 00 00 00 00 00 00 Monitor Interval 10 Monitor Fail Count 5 Monitor Ok Count 5 Read Community Name public Write Community Name private Authentication Trap Disabled Alert Type TRAP SW1020A 2 9f SEP 2007 SW1020A Rev D SNMP Managers 1 192 168 1 113 2 192 168 1 115 3 192 168 1 149 GET VERSION Displays the software revision of the system SW...

Страница 12: ...have no physical connections associated with them and are not used Setting the switch state of any of the other 14 positions is not meaningful SET IPADDRESS X X X X GET IPADDRESS Set or display the current IP address of the network module Any change will not become permanent until a SAVE operation is performed SET SUBNETMASK X X X X GET SUBNETMASK Set or display the current subnet mask of the netw...

Страница 13: ...current telnet password Note that this is a case sensitive field Any change will not become permanent until a SAVE operation is performed SET TELNETTIMEOUT seconds GET TELNETTIMEOUT Set or display the current telnet timeout in seconds After a period of inactivity of this many seconds the network module will disconnect any current telnet session Note that the telnet timeout cannot be disabled it ca...

Страница 14: ...ration is performed SET MONITOROKCOUNT N GET MONITOROKCOUNT Set or display the number of successive PING attempts that must succeed before the SW1020A Auto Bypass Switch automatically switches back to the normal path and removes the bypass connection path The valid range is 1 to 255 A value of 0 disables only the automatic recovery function automatic bypass will still operate if enabled If auto re...

Страница 15: ...splay the message Request timed out SAVE Save settings for next startup All settings are stored in non volatile memory and restored upon power on Changes to parameters will not become permanent unless a SAVE operation is performed RESET Causes a network system reboot and reloads all parameters from stored settings HELP Displays a list of available commands The help display output is shown below he...

Страница 16: ...onds 0 to disable GET SET MONITORFAILCOUNT N 0 to disable GET SET MONITOROKCOUNT N 0 no auto recover GET SET AUTHENTICATIONTRAP ON OFF GET SET ALERTTYPE TRAP SYSLOG GET SET MANAGER N X X X X 0 0 0 0 to disable an entry GET MANAGER display all SNMP managers PING X X X X ICMP ECHO to remote host SAVE save settings for next startup RESET restart use after SAVE ...

Страница 17: ...lar Figure 8 2 Initial Command Screen IMPORTANT Do NOT click on the submit button or press the enter key on your keyboard multiple times The web browser interface on the SNMP module typically takes 5 to 10 seconds to process a command and return a response Clicking on submit or hitting enter multiple times while the SNMP module is processing a command can cause the SNMP module to decide that the i...

Страница 18: ...he network controller will allow only one web access session at a time To free up a session without waiting for the web timeout click Logoff For this reason the web timeout should be set to a workable time Resetting the unit will clear any current web session ...

Страница 19: ...via the auto bypass feature or the auto recovery feature 10 Syslog Messages The SW1020A Auto Bypass Switch can be configured to issue a syslog message rather than an SNMP trap when certain events occur To configure the SW1020A to issue syslog messages you must use the SET ALERTTYPE command to select SYSLOG messages and you need to specify the IP address es of the device s that will be receiving th...

Страница 20: ...sition port 4 change from A to B via S P 4 B command Jan 1 00 00 00 192 168 1 151 Auto Bypass Switch Port switch from A to B position port 3 change from B to A via S P 3 A command Jan 1 00 00 00 192 168 1 151 Auto Bypass Switch Port switch from B to A position port 4 change from B to A via S P 4 A command Jan 1 00 00 00 192 168 1 151 Auto Bypass Switch Port switch from B to A position applied powe...

Страница 21: ...page 21 of 21 Copyright 2007 Black Box Corporation All rights reserved 1000 Park Drive Lawrence PA 15055 1018 724 746 5500 Fax 724 746 0746 ...

Отзывы: