background image

 INS_RLXE4GE24MODMS_REV–     20 Dec 2017     PAGE 141

INSTALLATION AND OPERATION MANUAL 

RLXE4GE24MODMS

TECH SUPPORT: 1.888.678.9427

Admin State

If NAS is globally enabled, this selection controls the port’s authentication mode. The following modes are available:

Force Authorized

In this mode, the switch will send one EAPOL Success frame when the port link comes up, and any client on the port will be allowed 
network access without authentication. 

Force Unauthorized

In this mode, the switch will send one EAPOL Failure frame when the port link comes up, and any client on the port will be disallowed 
network access. 

Port-based 802.1X

In the 802.1X-world, the user is called the supplicant, the switch is the authenticator, and the RADIUS server is the authentication server. 
The authenticator acts as the man-in-the-middle, forwarding requests and responses between the supplicant and the authentication 
server. Frames sent between the supplicant and the switch are special 802.1X frames, known as EAPOL (EAP Over LANs) frames. EAPOL 
frames encapsulate EAP PDUs (RFC3748). Frames sent between the switch and the RADIUS server are RADIUS packets. RADIUS packets 
also encapsulate EAP PDUs together with other attributes like the switch’s IP address, name, and the supplicant’s port number on the 
switch. EAP is very flexible, in that it allows for different authentication methods, like MD5-Challenge, PEAP, and TLS. The important 
thing is that the authenticator (the switch) doesn’t need to know which authentication method the supplicant and the authentication 
server are using, or how many information exchange frames are needed for a particular method. The switch simply encapsulates the 
EAP part of the frame into the relevant type (EAPOL or RADIUS) and forwards it. 
When authentication is complete, the RADIUS server sends a special packet containing a success or failure indication. Besides 
forwarding this decision to the supplicant, the switch uses it to open up or block traffic on the switch port connected to the supplicant. 
Note: Suppose two backend servers are enabled and that the server timeout is configured to X seconds (using the AAA 
configuration page), and suppose that the first server in the list is currently down (but not considered dead). Now, if the 
supplicant retransmits EAPOL Start frames at a rate faster than X seconds, then it will never get authenticated, because the switch 
will cancel on-going backend authentication server requests whenever it receives a new EAPOL Start frame from the supplicant. 
And since the server hasn’t yet failed (because the X seconds haven’t expired), the same server will be contacted upon the next 
backend authentication server request from the switch. This scenario will loop forever. Therefore, the server timeout should be 
smaller than the supplicant’s EAPOL Start frame retransmission rate. 
Single 802.1X 
In port-based 802.1X authentication, once a supplicant is successfully authenticated on a port, the whole port is opened for network 
traffic. This allows other clients connected to the port (for instance through a hub) to piggy-back on the successfully authenticated client 
and get network access even though they really aren’t authenticated. To overcome this security breach, use the Single 802.1X variant. 
Single 802.1X is really not an IEEE standard, but features many of the same characteristics as does port-based 802.1X. In Single 
802.1X, at most one supplicant can get authenticated on the port at a time. Normal EAPOL frames are used in the communication 
between the supplicant and the switch. If more than one supplicant is connected to a port, the one that comes first when the port’s 
link comes up will be the first one considered. If that supplicant doesn’t provide valid credentials within a certain amount of time, 
another supplicant will get a chance. Once a supplicant is successfully authenticated, only that supplicant will be allowed access. 
This is the most secure of all the supported modes. In this mode, the Port Security module is used to secure a supplicant’s MAC 
address once successfully authenticated. 
Multi 802.1X 
In port-based 802.1X authentication, once a supplicant is successfully authenticated on a port, the whole port is opened for network 
traffic. This allows other clients connected to the port (for instance through a hub) to piggy-back on the successfully authenticated client 
and get network access even though they really aren’t authenticated. To overcome this security breach, use the Multi 802.1X variant. 
Multi 802.1X is really not an IEEE standard, but features many of the same characteristics as does port-based 802.1X. Multi 802.1X 
is – like Single 802.1X – not an IEEE standard, but a variant that features many of the same characteristics. In Multi 802.1X, one 
or more supplicants can get authenticated on the same port at the same time. Each supplicant is authenticated individually and 
secured in the MAC table using the Port Security module. 
In Multi 802.1X it is not possible to use the multicast BPDU MAC address as destination MAC address for EAPOL frames sent from the 
switch towards the supplicant, since that would cause all supplicants attached to the port to reply to requests sent from the switch. 
Instead, the switch uses the supplicant’s MAC address, which is obtained from the first EAPOL Start or EAPOL Response Identity frame 
sent by the supplicant. An exception to this is when no supplicants are attached. In this case, the switch sends EAPOL Request Identity 
frames using the BPDU multicast MAC address as destination – to wake up any supplicants that might be on the port. 
The maximum number of supplicants that can be attached to a port can be limited using the Port Security Limit Control functionality. 

MAC-based Auth.

 

Unlike port-based 802.1X, MAC-based authentication is not a standard, but merely a best-practices method adopted by the industry. In 
MAC-based authentication, users are called clients, and the switch acts as the supplicant on behalf of clients. The initial frame (any kind 
of frame) sent by a client is snooped by the switch, which in turn uses the client’s MAC address as both username and password in the 
subsequent EAP exchange with the RADIUS server. The 6-byte MAC address is converted to a string on the following form “xx-xx-xx-xx-
xx-xx”, that is, a dash (-) is used as separator between the lower-cased hexadecimal digits. The switch only supports the MD5-Challenge 
authentication method, so the RADIUS server must be configured accordingly. 
When authentication is complete, the RADIUS server sends a success or failure indication, which in turn causes the switch to open 
up or block traffic for that particular client, using the Port Security module. Only then will frames from the client be forwarded on 
the switch. There are no EAPOL frames involved in this authentication, and therefore, MAC-based Authentication has nothing to 
do with the 802.1X standard. 
The advantage of MAC-based authentication over port-based 802.1X is that several clients can be connected to the same port (e.g. 
through a 3rd party switch or a hub) and still require individual authentication, and that the clients don’t need special supplicant 
software to authenticate. The advantage of MAC-based authentication over 802.1X-based authentication is that the clients don’t need 
special supplicant software to authenticate. The disadvantage is that MAC addresses can be spoofed by malicious users – equipment 
whose MAC address is a valid RADIUS user can be used by anyone. Also, only the MD5-Challenge method is supported. The maximum 
number of clients that can be attached to a port can be limited using the Port Security Limit Control functionality.

Содержание RLXE4GE24MODMS

Страница 1: ...P ports The switch is designed for security ITS power substation and rolling stock applications and is fully compliant with the requirement of IEC 61850 3 and IEEE 1613 as well as NEMA TS1 TS2 The RLX...

Страница 2: ...ng RJ 45 Module in RLXE4GE24MODMS 10 Installing SFP Module in RLXE4GE24MODMS 10 Installing 10 Gbps SFP Module in RLXE4GE24MODMS 11 Installing Power Module in RLXE4GE24MODMS 11 Hardware Overview 12 Fro...

Страница 3: ...39 Port Trunk 40 LACP 42 Loop Protection Configuration 46 General Settings 46 Port Configuration 46 Loop Protection Status 47 C Ring 48 C Chain Configuration 49 Legacy Ring 50 MEP 51 Maintenance Enti...

Страница 4: ...iguration 125 Stream Check Configuration 126 Security 127 AAA 131 RADIUS Overview 133 TACACS Server Configuration Help 145 Warning 146 System Warning 147 SMTP Configuration 148 Monitor and Diag 150 Po...

Страница 5: ...tection Switching Example Configuration 190 Introduction 190 Configuring ERPS from the Web GUI 191 Initial Switch Configuration 191 Creating a MEP on Switch 1 191 Configuring Switch 2 193 Configuring...

Страница 6: ...rkets the next generation of video solutions for the CCTV defense and homeland security markets At the core of ComNet s solutions are a variety of high end video servers and the ComNet IVS software wh...

Страница 7: ...ernet Redundancy protocol C Ring recovery time 30ms over 250 units of connection and MSTP RSTP STP compatible It can protect your mission critical applications from network interruptions or temporary...

Страница 8: ...nnection MSTP RSTP STP compatible for Ethernet Redundancy IEEE 1588v2 clock synchronization Provides HTTPS SSH protocol to enhance network security IP based bandwidth management application based QoS...

Страница 9: ...um 3 slots 8 x 10 100 1000Base T X RJ 45 Module Supports maximum 3 slots 8 x 100 1000Base X SFP Module Supports maximum 1 slot 2 4 x 10G SFP Module or 2 4 x 1G SFP Module 19 inch rack mountable design...

Страница 10: ...um of three RJ 45 Modules To install the module users must turn off the RLXE4GE24MODMS Power and plug in the RJ 45 Module into Slot 1 Slot 3 Once installed turn on the power Installing SFP Module in R...

Страница 11: ...tall the module users must turn off the RLXE4GE24MODMS Power and plug in the SFP Module into Slot 4 Once installed turn on the power Installing Power Module in RLXE4GE24MODMS Each RLXE4GE24MODMS Switc...

Страница 12: ...r PW2 When the PWR2 links the green led will be light on LED for PWR This LED lights on when the power module is activated LED for R M Ring master When the LED lights on this switch is designated as t...

Страница 13: ...DMS_REV 20 Dec 2017 PAGE 13 INSTALLATION AND OPERATION MANUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 RJ 45 Module 8 10 100 1000Base T X SFP Module 8 100 1000Base X SFP 10 Gbps Module 4 10 Gigbit S...

Страница 14: ...DMS TECH SUPPORT 1 888 678 9427 Power Panel RLXE4GE24MODMS are redundant power switches with support for two power inputs Note At the factory power GND and chassis GND are connected as shown in the pi...

Страница 15: ...INSTALLATION AND OPERATION MANUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 Rack mount kit assembly You can find the rack mount kit and the screws in the packing box Please assembly the rack mount ki...

Страница 16: ...d Specifications Cable Type Max Length Connector 10BASE T Cat 3 4 5 100 ohm UTP 100 m 328 ft RJ 45 100BASE TX Cat 5 100 ohm UTP UTP 100 m 328 ft RJ 45 1000BASE TX Cat 5 Cat 5e 100 ohm UTP UTP 100 m 32...

Страница 17: ...ot used 5 Not used Not used 6 RD receive TD transmit 7 Not used Not used 8 Not used Not used 1000 Base T MDI MDI X pins assignment Pin Number MDI port MDI X port 1 BI_DA BI_DB 2 BI_DA BI_DB 3 BI_DB BI...

Страница 18: ...5 GD Pin 5 GD Pin 5 Pin Male Connector Female Connector 1 Received Line Signal Detect Received by DTE Device Received Line Signal Detect Transmitted from DCE Device 2 Received Data Received by DTE Dev...

Страница 19: ...anagement features and allows you to manage the switch from anywhere on the network through a standard web browser such as Microsoft Internet Explorer The Web Based Management function supports Intern...

Страница 20: ...888 678 9427 System Login 1 Launch Internet Explorer 2 Type http and the IP address of the switch Press Enter 3 The login screen appears Login screen 4 Key in the username and password The default us...

Страница 21: ...INS_RLXE4GE24MODMS_REV 20 Dec 2017 PAGE 21 INSTALLATION AND OPERATION MANUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 Main Interface Main interface...

Страница 22: ...first character must be an alpha character And the first or last character must not be a minus sign The allowed string length is 0 to 255 System Description The device Description System Location The...

Страница 23: ...assword required to access the web pages or log in from CLI Label Description Old Password Enter the current system password If this is incorrect the new password will not be set New Password The syst...

Страница 24: ...thods can be set to one of the following values none authentication is disabled and login is not possible local use the local user database on the switch for authentication radius use a remote RADIUS...

Страница 25: ...ntil a valid lease is obtained Legal values are 0 to 4294967295 seconds IPv4 DHCP Current Lease For DHCP interfaces with an active lease this column show the current interface address as provided by t...

Страница 26: ...tes Only a default route will have a mask length of 0 as it will match anything Gateway The IP address of the IP gateway Valid format is dotted decimal notationor a valid IPv6 notation Gateway and Net...

Страница 27: ...browser to an HTTP connection Possible modes are Enabled Enable HTTPS mode operation Disabled Disable HTTPS mode operation Save Click to save changes Reset Click to undo any changes made locally and r...

Страница 28: ...r to inspect and configure the current LLDP port settings Label Description Port The switch port number of the logical LLDP port Mode Select LLDP mode Disabled The switch will not send out LLDP inform...

Страница 29: ...by the neighbor unit Port Description Port Description is the port description advertised by the neighbor unit System Capabilities System Capabilities describes the neighbor unit s capabilities The p...

Страница 30: ...Label Description Neighbor entries were last changed at Shows the time for when the last entry was last deleted or added It is also shows the time elapsed since last change was detected Total Neighbo...

Страница 31: ...ed within the table Entries are removed from the table when a given port links down an LLDP shutdown frame is received or when the entry ages out TLVs Discarded Each LLDP frame can contain multiple pi...

Страница 32: ...RATION MANUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 Modbus TCP This page shows Modbus TCP support of the switch For more information regarding Modbus please visit http www modbus org Label Descri...

Страница 33: ...888 678 9427 Port Alias Configure the port alias name for each port Label Description Port This is the logical port number for this row Port Alias Enter the port name you wish to use for this port Sav...

Страница 34: ...ion You can save view or load the switch configuration The configuration file is in XML format with a hierarchy of tags Firmware Update This page facilitates an update of the firmware controlling the...

Страница 35: ...n is activated the system will collect the DHCP client information and display in here DHCP Client List You can assign the specific IP address which is in the assigned dynamic IP range to the specific...

Страница 36: ...y are not in the same subnet domain Relay Information Mode Indicates the DHCP relay information mode option operation The option 82 circuit ID format as vlan_id module_id port_no The first four charac...

Страница 37: ...ion it will enforce the policy The Replace policy is invalid when relay information mode is disabled Possible policies are Replace Replace the original relay information when a DHCP message that alrea...

Страница 38: ...packets whose Circuit ID option did not match known circuit ID Receive Bad Remote ID The number of packets whose Remote ID option did not match known Remote ID Client Statistics Transmit to Client The...

Страница 39: ...lect any available link speed for the given switch port Auto Speed selects the highest speed that is compatible with a link partner Disabled disables the switch port operation configuration of all por...

Страница 40: ...ess is enabled Destination MAC Address The Destination MAC Address can be used to calculate the destination port for the frame Check to enable the use of the Destination MAC Address or uncheck to disa...

Страница 41: ...oup ID Normal indicates there is no aggregation Only one group ID is valid per port Port Members Each switch port is listed for each group ID Select a radio button to include a port in an aggregation...

Страница 42: ...65535 The Auto setting will set the key as appropriate by the physical link speed 10Mb 1 100Mb 2 1Gb 3 Using the Specific setting a user defined value can be entered Ports with the same Key value can...

Страница 43: ...id is shown as isid aggr id and for GLAGs as aggr id Partner System ID The system ID MAC address of the aggregation partner Partner Key The Key that the partner has assigned to this aggregation ID Las...

Страница 44: ...p means that the port could not join the aggregation group but will join if other port leaves Meanwhile it s LACP status is disabled Key The key assigned to this port Only ports with the same key can...

Страница 45: ...itch port number LACP Transmitted Shows how many LACP frames have been sent from each port LACP Received Shows how many LACP frames have been received at each port Discarded Shows how many unknown or...

Страница 46: ...t will be kept disabled in the event of a loop is detected and the port action shuts down the port Valid values are 0 to 604800 seconds 7 days A value of zero will keep a port disabled until next devi...

Страница 47: ...he switch port number of the logical port Action The currently configured port action Transmit The currently configured port transmit mode Loops The number of loops detected on this port Status The cu...

Страница 48: ...port when this switch is Ring Master 2nd Ring Port The backup port when this switch is Ring Master Coupling Ring Mark to enable Coupling Ring Coupling Ring can be used to divide a big ring into two sm...

Страница 49: ...upper LAN could be C Ring RSTP Single Switch or any backbone Label Description Enable Check this box to enable C Chain Uplink Port There are two uplink ports for every devices in the chain The user m...

Страница 50: ...e failure The switch supports the function and interface for setting the switch as the ring master or not The ring master can negotiate and place command to other switches in the X Ring group If there...

Страница 51: ...Entity Intermediate Point Direction Down This is a Down MEP monitoring ingress OAM and traffic on Residence Port Up This is a Up MEP monitoring egress OAM and traffic on Residence Port Residence Port...

Страница 52: ...ated MPLS Link This is a MEP in the MPLS Link Domain MPLS Tunnel This is a MEP in the MPLS Tunnel Domain MPLS PW This is a MEP in the MPLS Pseudo Wires Domain MPLS LSP This is a MEP in the MPLS LSP Do...

Страница 53: ...is not used MEG id must be max 13 char IEEE String This is defined by IEEE 802 1ag Section 21 6 5 Domain Name can be max 16 char MEG id Short MA Name can be max 16 char ITU CC ICC This is defined by I...

Страница 54: ...Functional Configuration Continuity Check Enable Continuity Check based on transmitting receiving CCM PDU can be enabled disabled The CCM PDU is always transmitted as Multi cast Class 1 Priority The p...

Страница 55: ...in the CCM is supported Organization Specific OUI First The transmitted first value in the OS TLV OUI field Organization Specific OUI Second The transmitted second value in the OS TLV OUI field Organ...

Страница 56: ...TLV Value field CC Interface Status Last RX IS TLV was received in the last received CCM PDU Link State Tracking Enable When LST is enabled in an instance Local SF or received isDown in CCM Interface...

Страница 57: ...T 1 888 678 9427 MEP Fault Management Configuration This page allows the user to inspect and configure the Fault Management of the current MEP Instance Note that the sub tables of Link Trace Link Trac...

Страница 58: ...viour This is HW based LBM LBR and Requires VOE Size The LBM frame size This is entered as the wanted size in bytes of a un tagged frame containing LBM OAM PDU including CRC four bytes Example when Si...

Страница 59: ...The transaction id is incremented for each LTM send This value is inserted the transmitted LTM PDU and is expected to be received in the LTR PDU Received LTR with wrong transaction id is ignored There...

Страница 60: ...ame size all inclusive possible to copy to CPU of 15261526 Bytes Consider that the Peer MEP must be able to handle the selected frame size Consider that in order to calculate the RX rate a received TS...

Страница 61: ...transmitting LCK in each client flow Priority resulting in highest possible PCP can be selected AIS Enable Insertion of AIS signal AIS PDU transmission in client layer flows can be enable disabled Fr...

Страница 62: ...eer MEP configured Priority The priority to be inserted as PCP bits in TAG if any In case of enable of Continuity Check and Loss Measurement both implemented on SW based CCM Priority has to be the sam...

Страница 63: ...The result is given in percent Clear Set of this check and save will clear the accumulated counters and restart ratio calculation Delay Measurement Enable Delay Measurement based on transmitting 1DM...

Страница 64: ...ast clear Av Delay Var Tot The average total delay variation since last clear Av Delay Var last N The average delay variation of the last n packets since last clear Delay Var Min The minimum delay var...

Страница 65: ...range during a Measurement Interval If the measurement threshold is 5000 us and the total number of Measurement Bins is four we can give an example as follows Bin Threshold Range bin0 0 us 0 us measur...

Страница 66: ...SF MEP is associated with interconnected sub ring without virtual channel it is configured as 0 for such ring instances 0 in this field indicates that no Port 1 SF MEP is associated with this instance...

Страница 67: ...NUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 Add New Protection Group Click to add a new Protection group entry Refresh Click to refresh the page immediately Apply Click to apply changes Reset Clic...

Страница 68: ...1 SF MEP The Port 1 Signal Fail reporting MEP As only one SF MEP is associated with interconnected sub ring without virtual channel it is configured as 0 for such ring instances 0 in this field indic...

Страница 69: ...tion of the Protection Group Click on the VLAN Config link to configure VLANs for this protection group RPL Configuration RPL Role It can be either RPL owner or RPL Neighbor RPL Port This allows to se...

Страница 70: ...S Received RAPS PDU is not received from the other end Port 0 Block Status Block status for Port 0 Both traffic and R APS block status R APS channel is never blocked on sub rings without virtual chann...

Страница 71: ...a New VLAN Click Add New Entry to add a new VLAN ID Legal values for a VLAN ID are 1 through 4095 The VLAN is enabled on the selected switch unit when you click on Save A VLAN without any port members...

Страница 72: ...e maximum age of the information transmitted by the Bridge when it is the Root Bridge Valid values are in the range 6 to 40 seconds and MaxAge must be FwdDelay 1 2 Maximum Hop Count This defines the i...

Страница 73: ...r to share spanning trees for MSTI s Intra region The name is at most 32 characters Configuration Revision The revision of the MSTI configuration named above This must be an integer between 0 and 6553...

Страница 74: ...ly change them as well Label Description MSTI The bridge instance The CIST is the default instance which is always active Priority Controls the bridge priority Lower numerical values have better prior...

Страница 75: ...control priority of ports having identical port cost See above OpenEdge state flag Operational flag describing whether the port is connecting directly to edge devices No Bridges attached Transitionin...

Страница 76: ...etwork administrator to prevent bridges external to a core region of the network causing address flushing in that region possibly because those bridges are not under the full control of the administra...

Страница 77: ...tings are stack global Label Description Port The switch port number of the corresponding STP CIST and MSTI port Path Cost Controls the path cost incurred by the port The Auto setting will set the pat...

Страница 78: ...idge ID The Bridge ID of this Bridge instance Root ID The Bridge ID of the currently elected root bridge Root Port The switch port currently assigned the root port role Root Cost Root Path Cost For th...

Страница 79: ...gical STP port CIST Role The current STP port role of the CIST port The port role can be one of the following values AlternatePort BackupPort RootPort DesignatedPort State The current STP port state o...

Страница 80: ...BPDU s received transmitted on the port STP The number of legacy STP Configuration BPDU s received transmitted on the port TCN The number of legacy Topology Change Notification BPDU s received transmi...

Страница 81: ...ry is a function for port redundancy The port has the highest recovery priority the lowest number will be the active port others will be blocked if included Enable Enable Fast Recovery function Recove...

Страница 82: ...The VLAN ID for the entry VLAN Name The descriptive name for the VLAN entry Port Members Check marks indicate which ports are members of the entry Check or uncheck as needed to modify the entry Addin...

Страница 83: ...INS_RLXE4GE24MODMS_REV 20 Dec 2017 PAGE 83 INSTALLATION AND OPERATION MANUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 VLAN Port Configuration...

Страница 84: ...untagged frames received on the port are discarded By default the field is set to All Port VLAN Mode Configures the Port VLAN Mode The allowed values are None or Specific This parameter affects VLAN i...

Страница 85: ...obtain a tag based on PVID and is forwarded When the port received tagged frames 1 If a tagged frame with TPID 0x8100 it is forwarded 2 If the TPID of tagged frame is not 0x8100 ex 0x88A8 it will be...

Страница 86: ...ID 8100 Packet VID 5 TPID 8100 VID PVID TPID 8100 Packet VID 5 TPID 88A8 Packet Discarded QinQ S custom port is used for user defined TPID If the Ethertype for Custom S ports is configured to 8123 the...

Страница 87: ...VLAN Access Mode Setting P7 P7 P2 P2 P1 P1 P8 P8 RLXE4GE24MODMS Switch A RLXE4GE24MODMS Switch B RLXE4GE24MODMS Switch C VLAN Trunk 10 20 VLAN 10 VLAN 10 VLAN 20 VLAN 20 VLAN Trunk 10 20 In the topolo...

Страница 88: ...Q Trunk mode P7 P7 P2 P2 P1 P1 P8 P8 RLXE4GE24MODMS Switch A RLXE4GE24MODMS Switch B RLXE4GE24MODMS Switch C VLAN Trunk 10 20 VLAN 10 VLAN 10 VLAN 20 VLAN 20 VLAN Trunk 10 20 In the topology above for...

Страница 89: ...ged 10 20 Configure the VLAN for the Switch as shown VLAN QinQ mode Below is an example of the VLAN QinQ Mode which is typically used in an environment with unknown VLAN VLAN X Unknown VLAN P2 P2 P1 P...

Страница 90: ...INS_RLXE4GE24MODMS_REV 20 Dec 2017 PAGE 90 INSTALLATION AND OPERATION MANUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427...

Страница 91: ...Delete Check to delete the entry It will be deleted during the next save Private VLAN ID Indicates the ID of this particular private VLAN Port Members A row of check boxes for each port is displayed...

Страница 92: ...E24MODMS TECH SUPPORT 1 888 678 9427 Label Description Port Number A check box is provided for each port of a private VLAN When checked port isolation is enabled for that port When unchecked port isol...

Страница 93: ...feature enables voice traffic forwarding on the Voice VLAN then the switch can classify and schedule network traffic It is recommended that there be two VLANs on a port one for voice one for data Bef...

Страница 94: ...All traffic on the Voice VLAN will apply this class Port Mode Indicates the Voice VLAN port mode Possible port modes are Disabled Disjoin from Voice VLAN Auto Enable auto detect mode It detects wheth...

Страница 95: ...will be deleted during the next save Telephony OUI A telephony OUI address is a globally unique identifier assigned to a vendor by IEEE It must be 6 characters long and the input format is xx xx xx x...

Страница 96: ...e allowed content is the ASCII characters from 33 to 126 The field only suits to SNMPv1 and SNMPv2c SNMPv3 is using USM for authentication and privacy and the community string will associated with SNM...

Страница 97: ...enerate authentication failure traps Possible modes are Enabled Enable SNMP trap authentication failure Disabled Disable SNMP trap authentication failure Trap Link up and Link down Indicates the SNMP...

Страница 98: ...decimal digits but all zeros and all F s are not allowed Trap Security Name Indicates the SNMP trap security name SNMPv3 traps and informs using USM for authentication and privacy A unique security na...

Страница 99: ...urity model that this entry should belong to Possible security models are NoAuth NoPriv None authentication and none privacy Auth NoPriv Authentication and none privacy Auth Priv Authentication and pr...

Страница 100: ...A string identifying the security name that this entry should belong to The allowed string length is 1 to 32 and the allowed content is the ASCII characters from 33 to 126 Group Name A string identif...

Страница 101: ...during the next save Group Name A string identifying the group name that this entry should belong to The allowed string length is 1 to 32 and the allowed content is the ASCII characters from 33 to 12...

Страница 102: ...figuration indicates the permitted packet rate for unicast broadcast or unknown traffic across the switch Note Frames which are sent to the CPU of the switch are always limited to approximately 4 kpps...

Страница 103: ...ro has the lowest priority If the port is VLAN aware and the frame is tagged then the frame is classified to a QoS class that is based on the PCP value in the tag as shown below Otherwise the frame is...

Страница 104: ...are classified to a PCP value If the port is VLAN aware and the frame is tagged then the frame is classified to the PCP value in the tag Otherwise the frame is classified to the default PCP value DEI...

Страница 105: ...QoS Egress Port Tag Remarking for all switch ports Label Description Port The logical port for the settings contained in the same row Click on the port number in order to configure tag remarking Mode...

Страница 106: ...Ingress settings you can change ingress translation and classification settings for individual ports There are two configuration parameters available in Ingress 1 Translate 2 Classify 1 Translate To E...

Страница 107: ...ding on the DP level of the frame the remapped DSCP value is either taken from the DSCP Translation Egress Remap DP0 table or from the DSCP Translation Egress Remap DP1 table Port Policing This page a...

Страница 108: ...100 1000000 when the Unit is kbps and it is restricted to 1 3300 when the Unit is Mbps This field is only shown if at least one of the queue policers are enabled Unit Controls the unit of measure for...

Страница 109: ...shaper rate e g 800 Mbps Qn Shows disabled or actual port shaper rate e g 800 Mbps DSCP Based QoS This page allows you to configure the basic QoS DSCP based QoS Ingress Classification settings for al...

Страница 110: ...for QoS class and DPL map There are two configuration parameters for DSCP Translation 1 Translate 2 Classify 1 Translate DSCP at Ingress side can be translated to any of 0 63 DSCP values 2 Classify Cl...

Страница 111: ...XE4GE24MODMS TECH SUPPORT 1 888 678 9427 DSCP Classification This page allows you to configure the mapping of QoS class and Drop Precedence Level to DSCP value Label Description QoS Class Actual QoS c...

Страница 112: ...w Tag Value of Tag field can be Any Untag or Tag VID Valid value of VLAN ID can be any value in the range 1 4095 or Any user can enter either a specific value or a range of VIDs PCP Priority Code Poin...

Страница 113: ...all bits following the first zero must also be zero DSCP Diffserv Code Point value DSCP It can be a specific value range of values or Any DSCP values are in the range 0 63 including BE CS1 CS7 EF or...

Страница 114: ...678 9427 QoS Counters This page provides statistics for the different queues for all switch ports Label Description Port The logical port for the settings contained in the same row Qn There are 8 QoS...

Страница 115: ...s IPv6 The QCE will match only IPV6 frames Port Indicates the list of ports configured with the QCE Action Indicates the classification action taken on ingress frame if parameters configured are match...

Страница 116: ...bled Enable the Global IGMP Snooping Unregistered IPMCv4Flooding enabled Enable unregistered IPMC traffic flooding Router Port Specify which ports act as router ports A router port is a port on the Et...

Страница 117: ...ds allow the user to select the starting point in the VLAN Table Clicking the Refresh button will update the displayed table starting from that or the next closest VLAN Table match The will use the la...

Страница 118: ...Querier status is ACTIVE or IDLE Querier Receive The number of Transmitted Querier V1 Reports Receive The number of Received V1 Reports V2 Reports Receive The number of Received V2 Reports V3 Reports...

Страница 119: ...PORT 1 888 678 9427 IGMP Snooping Groups Information Entries in the IGMP Group Table are shown on this page The IGMP Group Table is sorted first by VLAN ID and then by group Label Description VLAN ID...

Страница 120: ...rejected Label Description Port Port number of remote client IP Address IP address of remote client Keeps this field 0 0 0 0 means Any IP Web Check this item to enable Web management interface Telnet...

Страница 121: ...k When enabled switch will ping the device continually Alive Check Status Indicates the Alive Check status Possible statuses are Disable Got Reply Got ping reply from device that means the device is s...

Страница 122: ...C Address Specify the MAC Address of device Save Click to save changes Alias IP Address Configuration This page provides Alias IP Address related configuration Some device might have more IP addresses...

Страница 123: ...n when alive check failed Possible actions are Do nothing Link Change Link down the port and link up once Shunt Down the Port Shut down the port No Link and log the event Only Log it Just log the even...

Страница 124: ...ast Unicast ingress packets RX Multicast Multicast ingress packets RX Broadcast Broadcast ingress packets TCP TCP ingress packets UDP UDP ingress packets Socket Number If packet type is UDP or TCP ple...

Страница 125: ...ttack happened Save Click to save changes Device Description Configuration This page provides Device Description related configuration Label Description Device Type Indicates the type of device Possib...

Страница 126: ...ORT 1 888 678 9427 Stream Check Configuration This page provides Stream Check related configuration Label Description Mode Enable Disable stream monitor of the port Action Indicates the action when st...

Страница 127: ...r to apply to this port The allowed values are Disabled or the values 1 through 15 The default value is Disabled Port Copy Select which port frames are copied to The allowed values are Disabled or a s...

Страница 128: ...ers Configure the rate limiter for the ACL of the switch Label Description Rate Limiter ID The rate limiter ID for the settings contained in the same row Rate The rate unit is packet per second pps co...

Страница 129: ...can match this ACE The IEEE 802 3 specifies the value of Length Type Field specifications should be greater than or equal to 1536 decimal equal to 0600 hexadecimal ARP Only ARP frames can match this...

Страница 130: ...y the VLAN ID filter for this ACE Any No VLAN ID filter is specified VLAN ID filter status is don t care Specific If you want to filter a specific VLAN ID with this ACE choose this value A field for e...

Страница 131: ...iable by design In order to cope with lost frames the timeout interval is divided into 3 subintervals of equal length If a reply is not received within the subinterval the request is transmitted again...

Страница 132: ...ication Server If the port is set to 0 zero the default port 1812 is used on the RADIUS Authentication Server Secret The secret up to 29 characters long shared between the RADIUS Authentication Server...

Страница 133: ...his server Status The current status of the server This field takes one of the following values Disabled The server is disabled Not Ready The server is enabled but IP communication is not yet up and r...

Страница 134: ...p and running and the RADIUS module is ready to accept accounting attempts Dead X seconds left Accounting attempts were made to this server but it did not reply within the configured timeout The serve...

Страница 135: ...RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 Label Description Packet Counters RADIUS authentication server packet counter There are seven receive and four transmit counters Other Info This section cont...

Страница 136: ...ION MANUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 Label Description Packet Counters RADIUS accounting server packet counter There are five receive and four transmit counters Other Info This sectio...

Страница 137: ...s the man in the middle forwarding requests and responses between the supplicant and the authentication server Frames sent between the supplicant and the switch are special 802 1X frames known as EAPO...

Страница 138: ...authenticated because the switch will cancel on going backend authentication server requests whenever it receives a new EAPOL Start frame from the supplicant And since the server hasn t yet failed bec...

Страница 139: ...ADIUS server must be configured accordingly When authentication is complete the RADIUS server sends a success or failure indication which in turn causes the switch to open up or block traffic for that...

Страница 140: ...iod This setting applies to the following modes i e modes using the Port Security functionality to secure MAC addresses MAC Based Auth When the NAS module uses the Port Security module to secure MAC a...

Страница 141: ...id credentials within a certain amount of time another supplicant will get a chance Once a supplicant is successfully authenticated only that supplicant will be allowed access This is the most secure...

Страница 142: ...ect Reauthenticate Schedules a reauthentication whenever the quiet period of the port runs out EAPOL based authentication For MAC based authentication reauthentication will be attempted immediately Th...

Страница 143: ...istics for a specific switch port running port based authentication For MAC based ports it shows selected backend server RADIUS Authentication Server statistics only Use the port select box to select...

Страница 144: ...nd Server Counters These backend RADIUS frame counters are available for the following administrative states 802 1X MAC based Auth Last Supplicant Client Info Information about the last supplicant cli...

Страница 145: ...p the switch from continually trying to contact a server that it has already determined as dead Setting the Deadtime to a value greater than 0 zero will enable this feature but only if more than one s...

Страница 146: ...he table and the TACACS server can be configured as needed Up to 5 servers are supported The button can be used to undo the addition of the new server Save Click to save changes Reset Click to undo an...

Страница 147: ...de operation When the mode operation is enabled the syslog message will send out to syslog server The syslog protocol is based on UDP communication and received on UDP port 514 and the syslog server w...

Страница 148: ...il Alert Enable Disable transmission system warning events by e mail SMTP Server Address The SMTP server IP address or domain name address Sender E mail Address The sender s E mail address of the mail...

Страница 149: ...checked when SYSLOG is disabled System Warning Event Selection interface The following table describes the labels in this screen Label Description System Cold Start Alert when system restart Power St...

Страница 150: ...s for entries in the dynamic MAC Table and configure the static MAC table here Aging Configuration By default dynamic entries are removed from the MAC after 300 seconds This removal is also called agi...

Страница 151: ...ble before changing to secure learning mode otherwise the management link is lost and can only be restored by using another non secure port or by connecting to the switch via the serial interface Stat...

Страница 152: ...arting point in the MAC Table Clicking the Refresh button will update the displayed table starting from that or the closest next MAC Table match In addition the two input fields will upon a Refresh bu...

Страница 153: ...eived and transmitted packets per port Bytes The number of received and transmitted bytes per port Errors The number of frames received in error and the number of incomplete transmissions per port Dro...

Страница 154: ...ts Rx and Tx Multicast The number of received and transmitted good and bad multicast packets Rx and Tx Broadcast The number of received and transmitted good and bad broadcast packets Rx and Tx Pause A...

Страница 155: ...or destination mirroring Port to mirror also known as the mirror port Frames from ports that have either source rx or destination tx mirroring enabled are mirrored to this port Disabled disables mirro...

Страница 156: ...r level of the system log All All levels Time The time of the system log entry Message The MAC Address of this switch Auto Refresh Check this box to enable an automatic refresh of the page at regular...

Страница 157: ...page refreshes automatically and you can view the cable diagnostics results in the cable status table Note that VeriPHY is only accurate for cables of length 7 140 meters 10 and 100 Mbps ports will be...

Страница 158: ...STALLATION AND OPERATION MANUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 SFP Monitor DDM function can pass SFP module which supports DDM function measure the temperature of the apparatus and manage...

Страница 159: ...y until responses to all packets are received or until a timeout occurs PING6 server 10 10 132 20 64 bytes from 10 10 132 20 icmp_seq 0 time 0ms 64 bytes from 10 10 132 20 icmp_seq 1 time 0ms 64 bytes...

Страница 160: ...2 Input Enable the 1 pps clock input 3 Disable Disable the 1 pps clock in out put External Enable This Selection box will allow you to configure the External Clock output The following values are pos...

Страница 161: ...step Sync events and Pdelay_Resp events are used Clock Identity It shows unique clock identifier One Way If true one way measurements are used This parameter applies only to a slave In one way mode no...

Страница 162: ...figuration is retained Label Description Yes Click to reset the configuration to Factory Defaults No Click to return to the Port State page without resetting the configuration System Reboot You can re...

Страница 163: ...s CLI management You can use console or telnet to management the switch by CLI CLI Management by RS 232 Serial Console 115200 8 none 1 none Before Configuring by RS 232 serial console use an DB 9 M to...

Страница 164: ...INS_RLXE4GE24MODMS_REV 20 Dec 2017 PAGE 164 INSTALLATION AND OPERATION MANUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 Step 2 Input a name for new connection Step 3 Select to use COM port number...

Страница 165: ...78 9427 Step 4 The COM port properties setting 115200 for baud rate 8 for Data bits None for Parity 1 for Stop bits and none for Flow control Step 5 The Console login screen will appear Use the keyboa...

Страница 166: ...Address 192 168 10 1 Subnet Mask 255 255 255 0 Default Gateway 192 168 10 254 User Name admin Password admin Follow the steps below to access the console via Telnet Step 1 Telnet to the IP address of...

Страница 167: ...24MODMS TECH SUPPORT 1 888 678 9427 Commander Groups System System Configuration all port_list Reboot Restore Default keep_ip Contact contact Name name Location location Description description Passwo...

Страница 168: ...nable disable Mode port_list auto 10hdx 10fdx 100hdx 100fdx 1000fdx sfp_auto_ams Flow Control port_list enable disable MaxFrame port_list max_frame Power port_list enable disable actiphy dynamic Exces...

Страница 169: ...tomSport etype Add vid name ports_list Forbidden Add vid name port_list Delete vid name Forbidden Delete vid name Forbidden Lookup vid name name Lookup vid name name combined static nas all Name Add n...

Страница 170: ...radius enable disable Security Switch SSH Security switch ssh Configuration Mode enable disable Security Switch HTTPS Security switch ssh Configuration Mode enable disable Security Switch RMON Securit...

Страница 171: ...HCP Dynamic Host Configuration Protocol Security Network Psec Security Network Psec Switch port_list Port port_list Security Network NAS Security Network NAS Configuration port_list Mode enable disabl...

Страница 172: ...mp_type icmp_code ip_flags udp sip dip sport dport ip_flags tcp sip dip sport dport ip_flags tcp_flags permit deny rate_limiter port_redirect mirror logging shutdown Delete ace_id Lookup ace_id Clear...

Страница 173: ...clear Msti Add msti vid Port Configuration port_list Port Mode port_list enable disable Port Edge port_list enable disable Port AutoEdge port_list enable disable Port P2P port_list enable disable aut...

Страница 174: ...n dscp_list trans_dscp DSCP Trust dscp_list enable disable DSCP Classification Mode dscp_list enable disable DSCP Classification Map class_list dpl_list dscp DSCP EgressRemap dscp_list dpl_list dscp S...

Страница 175: ...st macbased auto authorized unauthorized Authenticate port_list now Reauthentication enable disable Period reauth_period Timeout eapol_timeout Statistics port_list clear eapol radius Clients port_list...

Страница 176: ...vid tag_prio dmac_type etype etype smac dmac arp sip dip smac arp_opcode arp_flags ip sip dip protocol ip_flags icmp sip dip icmp_type icmp_code ip_flags udp sip dip sport dport ip_flags tcp sip dip s...

Страница 177: ...ip_mask Community Delete index Community Lookup index User Add engineid user_name MD5 SHA auth_password DES priv_password User Delete index User Changekey engineid user_name auth_password priv_ passw...

Страница 178: ...tDataSet clockinst port_list announceintv announceto syncintv delaymech minpdelayreqintv delayasymmetry ingressLatency LocalClock clockinst update show ratio clockratio Filter clockinst def_delay_filt...

Страница 179: ...ble Router igmp port_list enable disable Status igmp vid Groups igmp vid Version igmp vid Fault Fault Alarm PortLinkDown port_list enable disable Alarm PowerFailure pwr1 pwr2 pwr3 enable disable Event...

Страница 180: ...RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 Ring Ring Mode enable disable Master enable disable 1stRingPort port 2ndRingPort port Couple Mode enable disable Couple Port port Dualhoming Mode enable dis...

Страница 181: ...yer 3 Switch B VLAN 1 192 168 10 1 PC 1 192 168 10 X PC 2 192 168 20 X VLAN 10 192 168 20 1 Two PCs in different subnets use static route function for routing between the two subnets L3 Switch by VLAN...

Страница 182: ...ATION AND OPERATION MANUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 Port 1 PVID 1 Port 2 PVID 10 2 Static Routing Setting Mode Router Create IP interfaces VLAN 1 192 168 10 1 VLAN 10 192 168 20 1 Se...

Страница 183: ...INS_RLXE4GE24MODMS_REV 20 Dec 2017 PAGE 183 INSTALLATION AND OPERATION MANUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 PC 1 can ping to PC 2 192 168 10 X routing to 192 168 20 X...

Страница 184: ...SUPPORT 1 888 678 9427 RIP Routing Setting Example P1 P2 P3 P4 RLXE4GE24MODMS L3 Switch VLAN 1 192 168 10 1 VLAN 10 192 168 20 1 PC 3 192 168 30 X PC 4 192 168 40 X PC 1 192 168 10 X PC 2 192 168 20 X...

Страница 185: ...4GE24MODMS_REV 20 Dec 2017 PAGE 185 INSTALLATION AND OPERATION MANUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 Port 1 PVID 1 Port 2 PVID 10 Port 3 PVID 1 Port 4 PVID 10 2 Static Routing Setting Mode...

Страница 186: ...8 9427 Create IP interfaces VLAN 1 192 168 10 1 VLAN 10 192 168 20 1 3 RIP Routing Setting RIP Mode Enabled Setup is complete PC 1 192 168 10 X PC 2 192 168 20 X PC 3 192 168 30 X PC 4 192 168 40 X PC...

Страница 187: ...STP Multiple Spanning Tree Protocol IEEE 802 1x for Authentication IEEE 802 1AB for LLDP Link Layer Discovery Protocol MAC Table 32k Priority Queues 8 Processing Store and Forward Switch Properties Sw...

Страница 188: ...mpatible Redundant Ring C Ring with recovery time less than 30ms over 250 units TOS Diffserv supported Quality of Service 802 1p for real time traffic VLAN 802 1Q with VLAN tagging IGMP v2 v3 Snooping...

Страница 189: ...em Link Act LINK Speed SPD Duplex FDX Remote RMT Green LED 4 Mode Select Button MODE Link Act LINK Speed SPD Duplex FDX Remote RMT select button Ports 1 through 28 Link Act LK ACT Green LED 28 Fault c...

Страница 190: ...ng Protection Switching Example Configuration Introduction This section shows how to configure the Ethernet Ring Protection Switching ERPS for ComNet switches using the Web GUI and the CLI commands Th...

Страница 191: ...to avoid creating a loop The web client is connected to switch 1 3 To avoid conflict with ERPS disable spanning tree on all switches if it is enabled 4 Enable VLAN tag aware on all three switches In V...

Страница 192: ...MAC can remain empty because it will be learned by receiving the CCM from the peer side On ComNet switches before they are learned the CCM frame rate cannot be changed to above 100 sec If known enter...

Страница 193: ...switch 2 Figure 5 Switch 2 Port 1 and 2 MEP Configuration 2 Edit MEP1 of switch 2 by clicking 1 under Instance of the MEP table Configure the MEP as shown and click Save or Apply Figure 6 Switch 2 ME...

Страница 194: ...t 1 and 2 of switch 3 Figure 8 Switch 3 Port 1 and 2 MEP Configuration 2 Edit MEP1 of switch 3 by clicking 1 under Instance of the MEP table Configure the MEP as shown and click Save or Apply Figure 9...

Страница 195: ...ew Protection Group Switch 1 Configuration 2 Edit ERPS1 by clicking 1 Set the configuration as shown and click Save or Apply Figure 12 ERPS 1 Switch 1 Configuration 3 Click VLAN Config to edit the pro...

Страница 196: ...tch 2 the RPL Neighbor 1 On switch 2 click ERPS followed by Add New Protection Group Figure 15 Add New Protection Group Switch 2 Configuration 2 Edit ERPS1 by clicking 1 Configure the device as shown...

Страница 197: ...g ERPS on Switch 3 1 On switch 3 click ERPS followed by Add New Protection Group Figure 18 Add New Protection Group Switch3 2 Edit ERPS1 by clicking 1 No action is required on switch 3 Keep the RPL ow...

Страница 198: ...1 888 678 9427 Ethernet Ring Protection Switching Configuration Verifying ERPS 1 Change the CCM rate starting from switch 3 Click on MEP 2 and then use the frame rate pull down to select 300 f sec Fig...

Страница 199: ...N MANUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 3 Change the CCM rate on switch 1 Click on MEP 1 and then use the frame rate pull down to select 300 f sec Figure 23 Edit MEP 1 CCM Rate Switch 1 4...

Страница 200: ...N MANUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 5 Change the CCM rate on switch 2 Click on MEP 1 and then use the frame rate pull down to select 300 f sec Figure 25 Edit MEP 1 CCM Rate Switch 2 6...

Страница 201: ...7 On Switch 1 check ERPS status by clicking ERPS to ensure normal link status Figure 27 Switch 1 ERPS Status 8 Disconnect the normal link for switch 1 and switch 3 Figure 28 Disconnect Normal Link 9 R...

Страница 202: ...4GE24MODMS_REV 20 Dec 2017 PAGE 202 INSTALLATION AND OPERATION MANUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427 10 After WTR timeout and clicking Refresh it should show as Idle Figure 30 Refresh ERPS...

Страница 203: ...INS_RLXE4GE24MODMS_REV 20 Dec 2017 PAGE 203 INSTALLATION AND OPERATION MANUAL RLXE4GE24MODMS TECH SUPPORT 1 888 678 9427...

Страница 204: ...RATE DRIVE DANBURY CT 06810 USA T 203 796 5300 F 203 796 5303 TECH SUPPORT 1 888 678 9427 INFO COMNET NET 8 TURNBERRY PARK ROAD GILDERSOME MORLEY LEEDS UK LS27 7LE T 44 0 113 307 6400 F 44 0 113 253 7...

Отзывы: