background image

USER GUIDE

EdgeSafe Bypass | M100G1xx

4. System management overview

A user can use a username and password to access the M100G1AC management interface via COM, SSH or
Web. The initial user name is admin and the default password is Garland2015.

The M100G1AC supports multiple users’ login.

The M100G1AC defines three types of user privileges to restrict user access:

-

Admin: Full read-write access to all configurations (Bypass Configuration/System/User/ SNMP);
privileges to add, delete, or modify local users on the M100G1AC. The initial user account

admin

is

the only administrator account and no other administrator accounts are allowed to be created. This
administrator account cannot be deleted, and the privileges cannot be modified.

-

Normal: Full read-write access to Bypass Configurations and read-only access to other
configurations (System/User/SNMP).

-

Readonly: Read-only access to all configurations.

The Admin user can change everyone’s password. The Normal users and Readonly users can change only
their own password.

The M100G1AC supports RADIUS/ remote login. RADIUS and  cannot be enabled at the
same
time. To enable either, the other needs to be disabled first.

RADIUS users share the same privilege level, which can be configured through Web or CLI.

 user or user group privilege can be configured on server side by adding a service tag (default is
“silc-system”, which can be configured through Web or CLI) to  server configuration as below:

service = silc-system {

# 1: readonly; 5: normal; 10: admin

user-privilege = 10

}

And  user will be assigned Readonly privilege if the service tag is missing in server configuration.

Garland Technology  |  716.242.8500  | garlandtechnology.com/support
Copyright © 2021 Garland Technology, LLC. All rights reserved.

7

Содержание M100G1AC

Страница 1: ...Garland Technology EdgeSafeTM 100G Bypass Modular Network TAP User Guide M100G1AC M100G1DC Office 716 242 8500 support garlandtechnology com garlandtechnology com...

Страница 2: ...hased products services and features are stipulated by the contract made between Garland Technology and the customer All or part of the products services and features described in this document may no...

Страница 3: ...host system which supports up to two 100G modules A 100G module supports one segment The following figure shows a Garland M100G1AC 1U Unit with two 100G modules Figure 1 M100G1AC 1U Unit with two 100G...

Страница 4: ...with bypass will show BCSR4 BCLR4 BCSR10 Blank 90 240 V AC Redundant hot swap 48V DC Blank No power cord EU US CN The following table explains different models of the Garland M100G1AC 1U Unit Part nu...

Страница 5: ...Chapter 4 Theory of operation System management overview A user can use a username and password to access the M100G1AC management interface via COM SSH or Web The initial user name is admin and the de...

Страница 6: ...packets No driver or management port is required to generate pulses Sets to Bypass when inline system failure is detected Sets to Bypass when inline system link failure is detected Sets to Bypass when...

Страница 7: ...t 5ms Verify packets received every 10ms 50sec Default 20ms Double Bypass Transmit heartbeat packets every 300ms 60sec Default 7sec Verify packets received every 1S 253sec Default 20sec 3 2 Bypass spe...

Страница 8: ...ions and read only access to other configurations System User SNMP Readonly Read only access to all configurations The Admin user can change everyone s password The Normal users and Readonly users can...

Страница 9: ...lates switch router cable disconnection By default the M100G1AC operate in Inline mode When traffic is received on the NET ports it will be forwarded to the Appliance Ports via the corresponding MON p...

Страница 10: ...inject packets into the network Since that network appliance may have down time so it will affect the connection between the two external Switch router ports This is where heartbeat and bypass mode w...

Страница 11: ...ettings of the Heartbeat Active Expire OP Mode parameter In Active Bypass or TAP mode the network traffic continues to flow through the network ports and is not diverted to the monitor ports As soon a...

Страница 12: ...port will be forwarded to the device connected to NET1 port Packets received from Net1 port will be forwarded to the device connected to NET0 port The mode is also called Active Bypass mode as packets...

Страница 13: ...G1AC resumes Inline mode after detecting the heartbeat packets for a period of time set by the Heartbeat Expire Timer parameter Note The Heartbeat Expire Timer parameter can be change via management p...

Страница 14: ...Mon0 and incoming traffic in port Net1 is mirrored to port Mon1 The following diagram illustrates the working mechanism of TAP mode EdgeSafe Bypass TAP TAP mode Figure 6 M100G1xx TAP mode Garland Tec...

Страница 15: ...t1 is mirrored to port Mon1 Packets can be injected from port Mon0 to port Net0 and from port Mon1 to port Net1 The following diagram illustrates the working mechanism of TAPI12 mode EdgeSafe Bypass T...

Страница 16: ...Mon0 Mon1 and incoming traffic in port Net1 also is mirrored to both monitor ports Mon0 Mon1 The following diagram illustrates the working mechanism of TAPA mode EdgeSafe Bypass TAP TAPA mode Figure 8...

Страница 17: ...red to both monitor ports Mon0 Mon1 Packets can be injected from port Mon0 Injected packets from Mon0 will be sent to both network ports Net0 Net1 The following diagram illustrates the working mechani...

Страница 18: ...t Net1 also is mirrored to both monitor ports Mon0 Mon1 Packets can be injected from port Mon1 to both network ports Net0 Net1 The following diagram illustrates the working mechanism of TAPAI2 mode Ed...

Страница 19: ...t1 also is mirrored to both monitor ports Mon0 Mon1 Packets can be injected from each monitor port to both network ports Net0 Net1 The following diagram illustrates the working mechanism of TAPAI12 mo...

Страница 20: ...rk ports Net0 Net1 The M100G1AC simulates switch router cable disconnection The following diagram illustrates the working mechanism of Linkdrop mode Linkdrop mode Figure 12 M100G1xx Linkdrop mode Garl...

Страница 21: ...y to recover from an Application Failure When Application Active Restore is turned on the M100G1AC will keep sending Heartbeat packet from its Mon ports to the connected Network Appliance in order to...

Страница 22: ...3 M1001Gxx Two port Link 2PL Illustration 5 4 2 M2N The M2N feature makes the link of a Net port to be in a slave state of its corresponding Mon ports The M2N mode can be set independently on each mon...

Страница 23: ...USER GUIDE EdgeSafe Bypass M100G1xx Figure 14 M1001Gxx M2N Illustration Garland Technology 716 242 8500 garlandtechnology com support Copyright 2021 Garland Technology LLC All rights reserved 22...

Страница 24: ...port will also be dropped When the port that has its link failed recovers from the link failure the link of the other port will also be turned back on again Figure 15 M1001Gxx M2M Illustration 5 4 4...

Страница 25: ...1AC modules The following figure shows the M100G1AC 1U Unit front panel a host system with two M100G1AC modules Figure 16 M100G1xx 1U Unit front panel host system with two modules 6 1 1 Host system fr...

Страница 26: ...ont panel of the host system 6 1 2 100G module front panel The following figure shows the LEDs switches and connectors on one M100G1AC module Figure 18 M100G1xx SR4 module Front panel Garland Technolo...

Страница 27: ...ront panel The following figure shows the LEDs switches and connectors on one M100G1xx module Figure 19 M100G1xx LR4 module Front panel Garland Technology 716 242 8500 garlandtechnology com support Co...

Страница 28: ...switches and connectors on one M100G1AC module Figure 20 M100G1xx SR10 module Front panel The following table explains the LEDs and connectors on the front panel of an M100G1xx module Garland Technolo...

Страница 29: ...en Standby AC DC in only 5VSB output Red Power is off Blinking red Internal fan error 7 Installation This chapter provides instructions on how to install the M100G1xx To install the M100G1xx do the fo...

Страница 30: ...lation software Minicom HyperTerminal etc to connect to the CLI 4 Set the following terminal communication parameters 115200 default or 9600 if set by CLI command 8 bits no parity 1 stop bit no flow c...

Страница 31: ...the default to access the CLI Username admin Default Password gtadmin1 Once logged in the system prompt will be shown M1001Gxx 8 3 Command modes The CLI command mode structure is hierarchical and eac...

Страница 32: ...ent configuration 8 4 1 11 show name configured Display serial console configuration 8 4 1 12 show session configured Display session configuration 8 4 1 13 show users Display a list of user accounts...

Страница 33: ...d Display all bypass configuration 8 4 2 13 show bypass configured segment select from list Display bypass configuration for a segment 8 4 2 14 show bypass state Display all bypass runtime state 8 4 2...

Страница 34: ...guration 8 4 2 28 show name configured Display device name configuration 8 4 2 29 show ntp configured Display NTP configuration 8 4 2 30 show radius configured Display RADIUS configuration 8 4 2 31 sh...

Страница 35: ...it is busy noconfirm Reboot the system without asking whether to save changes 8 4 2 42 write memory Save running configuration to the active configuration file 8 4 3 Command Mode configure Dis 8 4 3 1...

Страница 36: ...ect from list hb active mode disable enable Enable or disable heartbeat checking for a bypass segment Parameters segment The segment to configure disable Disable heartbeat checking enable Enable heart...

Страница 37: ...t select from list hb fail detect uni bi Configure heartbeat failure detection for a bypass segment Parameters segment The segment to configure uni Detect unidirectional heartbeat failure bi Detect bi...

Страница 38: ...ss segment select from list hb packet op mode select from list hex string hex string Configure heartbeat packet operation mode by using hex string for a bypass segment Parameters segment The segment t...

Страница 39: ...t automatically 1g Set speed to 1 Gb 10g Set speed to 10Gb 40g Set speed to 40Gb 100g Set speed to 100Gb 8 4 3 19 bypass segment select from list port two ports link disable enable Configure two ports...

Страница 40: ...Parameters segment The segment to configure disable Disable trap enable Enable trap 8 4 3 24 bypass segment select from list rx tx errors timeout 0 msec Configure the minimal time between traps for a...

Страница 41: ...eed to 57600 115200 Set speed to 115200 8 4 3 37 com terminal type terminal type such as vt100 Configure serial console terminal type 8 4 3 38 configurations save Save current configuration to a file...

Страница 42: ...err crit alert emerg Configure the system log level Parameters debug DEBUG info INFO notice NOTICE warn WARNING err ERROR crit CRITICAL alert ALERT emerg EMERGENCY 8 4 3 50 log max size 1 10 MB Confi...

Страница 43: ...4 3 59 management permitted ip IP address mask IP net mask Add a permitted IP address Parameters mask Permitted IP net mask 8 4 3 60 management whoami off on Turn on off the whoami function which is...

Страница 44: ...le NTP Parameters disable Disable NTP enable Enable NTP 8 4 3 72 ntp server Host or IP address Configure NTP server 8 4 3 73 radius disable enable 8 4 3 74 Disable or enable RADIUS remote login For de...

Страница 45: ...er which an idle session is expired Parameters expired time The time in seconds after which an idle session is expired 8 4 3 80 show bypass configured Display all bypass configurations 8 4 3 81 show b...

Страница 46: ...ay log or its configuration Parameters filter Display log with filter realtime Display realtime log configured Display log configuration 8 4 3 95 show management configured Display system management c...

Страница 47: ...s command for any of the following configuration to take effect snmp community community name disable enable full access read only snmp host select from list disable enable snmp user disable enable fu...

Страница 48: ...e SHA1 hash algorithm 8 4 3 114 snmp trap disable all application fan power sensor switch system terminal Disable SNMP trap type Parameters all Disable all trap types application Disable application t...

Страница 49: ...vice enable Enable SSH service 8 4 3 119 ssh port Port number default is 22 Configure SSH service port 8 4 3 120 tacacs disable enable Disable or enable TACACS remote login For details refer to 3 Syst...

Страница 50: ...x x path file user user name Upgrade system from an SCP URL Parameters user SCP user name 8 4 3 128 user change password new password Password 6 40 symbols Change local user s password Parameters new...

Страница 51: ...ed time 60 3600 seconds Specify the time in seconds after which an idle Web session is expired 8 4 3 135 web http disable enable Configure HTTP service Parameters disable Disable HTTP service enable E...

Страница 52: ...s device_ip_address https_port where device_ip_address is the M100G1xx Ethernet management port IP address where device_ip_address is the M100G1xx Ethernet management port IP address Notes If the Web...

Страница 53: ...b interface is displayed which contains the following tabs Each tab will be explained in subsequent sections 9 3 Status The Status tab provides access to the following status information pages System...

Страница 54: ...Load average The average system load over a period of time It conventionally appears in the form of three numbers which represent the system load during the last one five and fifteen minute periods C...

Страница 55: ...ame Fault Yes No Warning Yes No Status Unknown Green Yellow Orange Red Speed Run Time 9 3 2 Module status Navigate to Status Module X X indicates the module number The status page of the corresponding...

Страница 56: ...lays the following information Module Type Bypass Switch Media Type LR SR Transceiver Type Monitor 0 Mon0 MAC address Monitor 1 Mon1 MAC address Garland Technology 716 242 8500 garlandtechnology com s...

Страница 57: ...Up Down Link Monitor Mon0 Mon1 State Up Down The Clear Rx Tx Error area provides a Clear button for clearing Rx Tx errors The Port Signal Strength area shows the signal strength of network ports and...

Страница 58: ...he system log is displayed as shown Tips for reviewing the system log The log is displayed in backward scheduling order The latest events are displayed on the first page while the earliest events on t...

Страница 59: ...e statistics Navigate to Statistics Module X X indicates the module number to view the statistics of the corresponding module The following explanations use Module 1 as an example The following screen...

Страница 60: ...umulative Click this tab to view accumulated statistics since last statistics clear operation or system bootup Realtime Click this tab to view real time statistics which is updated every second To cle...

Страница 61: ...the past 1200 seconds Tips for viewing the realtime traffic statistics To view the realtime traffic statistics of a specific segment select the segment from the drop down list box Two tabs are provid...

Страница 62: ...ng Module Configuration page is displayed Users can configure the various module settings The following explanations take Module 1 as an example The following screenshot shows the configuration menus...

Страница 63: ...USER GUIDE EdgeSafe Bypass M100G1xx Garland Technology 716 242 8500 garlandtechnology com support Copyright 2021 Garland Technology LLC All rights reserved 62...

Страница 64: ...l work 2 Set the Active OP Mode option to Inline 3 Select the Heartbeat Active Mode option to enable the mode Heartbeat Interval The M100G1AC generates heartbeat packets to monitor port 0 Mon0 every H...

Страница 65: ...at Fail Detect criteria can be set to Bidirectional The M100G1AC will change its state if neither monitor ports receive the heartbeat packets The M100G1AC will restore to its default state if at least...

Страница 66: ...Enable or disable the M2M feature See Figure 15 M2M for reference Device Power Off Mode The M100G1AC supports Disconnect or Bypass default mode at system power off When Disconnect is selected in any...

Страница 67: ...NET1 ports must be configured the same Monitor 0 FEC need input Turn on FEC for MON0 only valid for SR4 LR4 modules Monitor 1 FEC need input Turn on FEC for MON1 only valid for SR4 LR4 modules For FEC...

Страница 68: ...lowing heartbeat packet configuration page is displayed This page enables users to change or to load new heartbeat packet content The packet file can be a binary file or a hex text file txt for a norm...

Страница 69: ...nt interface Configurations System Dump Upgrade Reboot Halt 9 6 1 General configuration Navigate to System General to view or configure general system settings The following screenshot shows the Gener...

Страница 70: ...USER GUIDE EdgeSafe Bypass M100G1xx Garland Technology 716 242 8500 garlandtechnology com support Copyright 2021 Garland Technology LLC All rights reserved 69...

Страница 71: ...re available including DEBUG INFO NOTICE WARNING ERROR CRITICAL ALERT and EMERGENCY Max Log File Size Configure the maximum log file size Remote Log Enabled Select whether to enable the remote log fun...

Страница 72: ...nerate SSH Keys button Web Configure the Web Session Timeout value in seconds HTTP Enable or disable the http protocol and configure the listening port HTTPS Enable or disable the https protocol and c...

Страница 73: ...the new address accordingly 9 6 3 Management interface configuration Navigate to System Management Interface to view or configure management settings The following screenshot shows the Management Int...

Страница 74: ...erver area the user can add DNS server IP addresses to make DNS service work 9 6 4 Configurations Navigate to System Configurations to save your configuration restore a previous configuration or to re...

Страница 75: ...er wishes to upload it later back to the M100G1AC device However sometimes the user may like to copy a current configuration and change some specific configuration like IP address 9 6 5 System Dump Na...

Страница 76: ...owse to navigate to the intended firmware image file 2 Click Upload image If the image is correct a confirmation window will be displayed asking whether to proceed or not Note If the user closes the c...

Страница 77: ...to view the result 4 When upgrade is finished click Reboot to restart the system for the new image to take effect 9 6 7 Reboot Halt To reboot or halt the system navigate to System Reboot Halt The foll...

Страница 78: ...guration System User SNMP privileges to add delete or modify local users on the M100G1AC The initial user account admin is the only administrator account and no other administrator accounts are allowe...

Страница 79: ...user can configure the following Enable Enable RADIUS remote login User Privilege Set the user privilege Retry Specify how many times to re send a packet when there is no response from the server Loca...

Страница 80: ...service tag default is silc system which can be configured through web or cli to tacacs server configuration as below service silc system 1 readonly 5 normal 10 admin user privilege 10 And TACACS user...

Страница 81: ...onds For more information refer to 3 System management overview 9 7 4 Change Password Navigate to User Change Password to access the password configuration page as shown The Admin user ID admin can ch...

Страница 82: ...tion page as shown The SNMP trap control is designed to enable or disable SNMP trap groups including Application Fail Bypass Monitor Link Network Link Terminal Error and Update All these SNMP traps ar...

Страница 83: ...ration In the Communities area and Users area a Full Access option is provided Select it to grant communities or users write access In the Trap Hosts area the user can define the IP address of the SNM...

Страница 84: ...M100G1AC Web interface click the Logout tab 9 10 Save To save your configurations click the Save tab The Save Configuration page allows the user to save current configurations to the non volatile memo...

Страница 85: ...ons of one fan in maximum operation condition SPL 61dB A Current 0 92A Air flow 28 6 CFM EMC certifications Class B FCC CE VCCI MTBF 150 000 hours M1001Gxx 50um M1001Gxx Fiber 40Gigabit Ethernet speci...

Страница 86: ...Blinking Green Heartbeat is active Off Heartbeat is not active Connectors Network 2 MPO Monitor 2 CFP4 M1001Gxx M1001Gxx Fiber 100Gigabit Ethernet specifications 100GBase LR4 Adapters IEEE standard Ne...

Страница 87: ...he used battery Be sure to replace the battery with the same type There is a risk of explosion if the battery is replaced by an incorrect type To avoid the possibility of electric shock all power cord...

Страница 88: ...LIED WARRANTIES OF MERCHANTABILITY AND FITNESS IN NO EVENT SHALL CMU OR THE REGENTS OF THE UNIVERSITY OF CALIFORNIA BE LIABLE FOR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVE...

Страница 89: ...erived from this software without specific prior written permission THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS AS IS AND ANY EXPRESS OR IMPLIED WARRANTIES INCLUDING BUT NOT LI...

Отзывы: