background image

 

Telephone Support .............................................................................................. 32

 

Optional Support Services .................................................................................... 32

 

Appendix ................................................................................................................. 33

 

ProCurve Networking Adaptive EDGE Architecture™ .................................................... 33

 

ProCurve Switch Positioning..................................................................................... 34

 

Positioning for the ProCurve 5308xl Switch ............................................................. 35

 

Positioning for the ProCurve 5304xl Switch ............................................................. 35

 

ProCurve Networking Web Site................................................................................. 35

 

 
 

Содержание J8166A

Страница 1: ...re and Design 5 Hardware Architecture 5 N Chip 6 F Chip 7 The Master CPU 7 Packet Buffer Memory Management 7 Performance 8 IP Routing L3 RFC 2285 Fully Meshed Throughput Test 8 Copper Gigabit ports 8 100BT Ports 9 Throughput Test Comments 9 IP Routing L3 RFC 2245 Latency Test 9 Copper Gig Ports 9 100BT Ports 9 Latency Test Comments 9 Features and Benefits 10 Feature Set Summary 10 High Availabilit...

Страница 2: ...Identity Driven Management IDM 22 TACACS Authentication 22 Port Security MAC Lockdown 23 Secure Shell SSH v1 and v2 23 SSL Secure Sockets Layer 23 Management VLAN 23 SNMPv3 24 Manager Authorized List 24 Custom Banner Page 24 Intrusion Logs 24 Bandwidth Management 25 Port Trunking Link Aggregation 25 VLANs 25 IGMP 26 Guaranteed Minimum Bandwidth GMB 26 Network Management 28 MIB Support 29 RMON Supp...

Страница 3: ...pport Services 32 Appendix 33 ProCurve Networking Adaptive EDGE Architecture 33 ProCurve Switch Positioning 34 Positioning for the ProCurve 5308xl Switch 35 Positioning for the ProCurve 5304xl Switch 35 ProCurve Networking Web Site 35 ...

Страница 4: ...ons resellers and end user sites evaluate the merits of the ProCurve 5300 switches ProCurve Networking ProCurve Networking has an extensible line of products working together to provide the control network administrators need to deliver the network uptime and performance that their organizations require This guide describes one part of ProCurve Networking the ProCurve 5300xl Switch Series products...

Страница 5: ...3A ProCurve Switch xl 10 100 TX PoE Power over Ethernet module J8161A 24 auto sensing 10 100 IEEE 802 3af PoE Power over Ethernet ready ports ProCurve Switch xl 16 Port 10 100 1000 module J4907A 14 ports of auto sensing 10 100 1000 ports and 2 dual personality ports 10 100 1000 or mini GBIC ProCurve Switch xl mini GBIC module J4878B 4 ports of mini GBIC connectivity ProCurve Gigabit SX LC Mini GBI...

Страница 6: ...teristics its addresses VLAN affiliation any priority specification etc The packet is stored in input memory lookups into the table memory are done to determine routing information and a N Chip specific packet header is created for this packet with this information This header is then forwarded to the programmable section of the N Chip N Chip Programmability As mentioned in the previous section on...

Страница 7: ...pt fresh via this CPU Other per port protocols such as Spanning Tree and LACP are also run on this CPU The local CPU being a full function microprocessor allows functionality updates through future software releases F Chip The fabric or F Chip which is located on the backplane of the switch provides the crossbar fabric for interconnecting the modules together The use of a crossbar allows wire spee...

Страница 8: ...does better with larger queue depths but even here there is a concern with queues that are too deep You don t want to hang on to a packet too long as the latency the packet accumulates in the switch has potential network effects such as retransmission requests or session timeouts In the case of VoIP packets and streaming video packets this latency can cause stream dropouts at the destination The 5...

Страница 9: ... 067 21 104 23 940 100BT Ports Port pairs active full duplex 192 All latencies in microseconds Frame Size 64 128 256 512 1024 1280 1518 AvgLatency μs 24 36 36 26 42 38 81 44 136 46 166 42 200 82 Latency Test Comments Latency is measured as the time it takes for a byte inside a packet to enter and then leave the switch This measurement includes both the processing time of the switch as it makes its...

Страница 10: ... Discovery Protocol support to discover neighboring devices IGMP Internet Group Management Protocol controls IP multicast and reduce unnecessary bandwidth usage on a per port basis Prioritization QoS Four priority queues Traffic prioritization based on UDP TCP Application Type port number Device Priority destination or source IP address IP Type of Service ToS Diffserv field IP packets only Protoco...

Страница 11: ...onfiguration of VLANs throughout a layer 2 environment IGMPv3 IGMP snooping data driven IGMP Guaranteed Minimum Bandwidth GMB Ensures a minimum bandwidth for the outbound traffic on a given switch port to prevent from been starved by high volumes of higher priority traffic Network Management Web based management for anytime anywhere configuration access ProCurve Manager and ProCurve Manager Plus f...

Страница 12: ...y port Useful for security routed sections of the network can be made invisible to the rest of the network o OSPF traps RFC 1850 o OSPF Route Authentication uses plain text passwords or MD5 encryption The MD5 keys are time sensitive the 5300 must have the correct time date set particularly after a reboot It is recommended that when using OSPF route authentication TimeP or SNTP time setting protoco...

Страница 13: ... While the ProCurve 5300xl Switch Series can perform Layer 3 routing there is an easier solution in Switch Meshing which is described in the next section The second concern is on link failure or loss of the STP root switch Spanning Tree can take up to 45 seconds to re establish network connections In many networks a potential outage of 45 seconds is unacceptable While many switch vendors in the pa...

Страница 14: ...Curve 5300xl Switch Series to form a virtual backplane between the switches allowing reliable high port density environments to be made inexpensively Up to 12 switches can participate in a Switch Meshing domain with up to 5 switch hops between the most distant switches in the mesh Multiple Switch Meshing domains can exist in a single LAN environment but not within the same switch Routing switches ...

Страница 15: ...n domains allowed per VLAN 16 Time to failure detection and switchover default 15 seconds Minimum time by making a configuration change 3 seconds If a VLAN is lost on one of the 5300 pairs but the 5300 doesn t go down fail over occurs in under 1 second as the 5300 with the failed VLAN reports the loss directly to the other 5300 via a different VLAN Backed up interfaces should be configured identic...

Страница 16: ...specified based on the following classifiers This list is in order of precedence if there are multiple classifiers that apply to a specific packet the one that is highest on this list takes effect Layer 4 TCP UDP port numbers allows prioritization based on the application associated with the packet This allows for instance VoIP packets using fixed port numbers to be prioritized higher than other t...

Страница 17: ...th available to traffic through higher speed connections While QoS for congestion control in the local local network has had marginal value the ability of QoS to deal with applications that are sensitive to varying latencies through a network is of value Delay sensitive applications depend on isochronous or time dependent data Applications of this type include VoIP streaming voice or video data st...

Страница 18: ...ading For virus throttling to work IP routing and multiple VLANs with member ports must first be configured Some protocols such as NetBIOS and WINS and some applications such as network management scanners notification services and p2p file sharing are not appropriate for virus throttling because they initiate a broad burst of network traffic that could be misinterpreted by virus throttling techno...

Страница 19: ...econds Connection rate ACL Connection rate ACLs are used to exclude legitimate high rate inbound traffic from the connection rate filtering policy A connection rate ACL consisting of a series of access control entries ACEs creates exceptions to these per port policies by creating special rules for individual hosts groups of hosts or entire subnets See Filtering section below for more details Thus ...

Страница 20: ... 5300xl Switch Series documentation located at http www procurve com under the Technical Support section Static Filters Static filtering can be used to provide security and or bandwidth control within the network When a static filter is defined it can be applied to any or all ports on the switch The following three types of static filters can be defined Source port Packets coming from a particular...

Страница 21: ...all is to use the Port Security MAC Address Lockdown feature on the ProCurve 5300xl Switch Series which is described in a following section ProCurve 5300xl Switch Series supports concurrent authentication methods per port The switch allows concurrent operation of 802 1x and either Web Authentication or MAC Authentication The combined client limit for a port configured for concurrent authentication...

Страница 22: ...itch then applies them to the client access port for the duration of the connection With ProCurve IDM solution ProCurve 5300xl Switch Series can dynamically apply VLAN QoS and bandwidth rate limit policies to the users based on location time and system The figure below illustrates the typical IDM user experience After the network administrator establishes the appropriate users groups and access ru...

Страница 23: ... pairs one pair for host authentication and one pair for each SSH session that is initiated The host key pair is used to authenticate the SSH client and switch to each other The host key pair is stored in flash so is not lost on reboot power cycle or by clearing the config file Although not necessary or recommended a new host key pair can be generated through the CLI The session key pair is used t...

Страница 24: ... packet snooping can turn on encryption allowing secure communication between the network management application and the switch Manager Authorized List The ProCurve 5300xl Switch Series Manager Authorized List can be configured with up to ten IP addresses that have management access to the switch The list along with Management VLANs and console passwords provides a way to tightly limit who has acc...

Страница 25: ...active mode Once the user configures active LACP links can be moved to different ports or new links can be added with LACP detecting this and reconfiguring to reestablish the LACP trunk LACP like the other forms of trunking supports 4 links per trunk LACP does allow the configuration of standby links Standby links carry no data unless one of the active links in the trunk fails Standby links are us...

Страница 26: ...ve One of the advantages of 802 1X is the ability for the user to login anywhere in the network If she is assigned to a VLAN that also has services members that VLAN will have to be defined all along the path between the user and those services GVRP will automatically do this GVRP will also delete that VLAN along the path once it is no longer needed The ProCurve 5300xl Switch Series has a configur...

Страница 27: ...27 to the highest priority traffic Guaranteed Minimum Bandwidth operates at the port or switch level with values specified as desired for each priority queue ...

Страница 28: ...ProCurve 5300xl Switch Series It provides mapping and polling capabilities device auto discovery and topology device configuration and management and troubleshooting data and alerts for the ProCurve network Figure 5 PCM user experience ProCurve Manager Plus PCM A complete Windows based network management solution that provides both basic and advanced management features for ProCurve devices In add...

Страница 29: ... number of enterprise specific MIBs are also supported for such things as VLANs XRRP and multiple bridge groups RMON Support For those customers that use RMON applications the ProCurve 5300xl Switch Series support RMON groups 1 Ethernet statistics 2 Ethernet history 3 Alarm and 9 Event These four groups are available for all ports The Ethernet statistics group provides counters for packet counts b...

Страница 30: ... to 115 200 baud Modems are also supported through the RS 232 port using a straight through cable Alert Log The ProCurve 5300xl Switch Series like most other switches in the ProCurve line look for the following common port based network problems Too many undersized giant packets Excessive jabbering Excessive CRC alignment errors Excessive late collisions High collision or drop rate Excessive broad...

Страница 31: ...itch operating system and is particularly useful when doing an OS upgrade If problems are found when moving to the new OS the switch can be immediately rebooted using the older OS Multiple Configuration Files The ProCurve 5300xl Switch Series supports up to three different startup config files on the switch with options for selecting which startup config file to use during reboot This enables user...

Страница 32: ...ellers through the ProCurve Customer Care Centers located world wide Optional Support Services In addition to free support services such as the warranty and telephone support ProCurve offers an extensive range of fee based support services to meet more specialized needs The following optional services are available for the ProCurve 5300xl Switch Series Onsite next business day Onsite in 4 hours sa...

Страница 33: ...and complexity In addition this opens the network to security attacks between where access is physically attained and where authorization is granted The intelligent control to the edge must be done in the switches closest to the users Since these switches constitute the highest number of network ports in a network they must also be cost effective The Adaptive EDGE Architecture is not just a future...

Страница 34: ...work in a building or for small networks across a campus Core switches provide the focal point of the local network aggregating the distribution switches providing connectivity for central site data centers and providing connectivity in many cases to the external network Access switch requirements vary depending on the use model of the customer Some customers just want basic aggregation with high ...

Страница 35: ...ot chassis switch targeted primarily at high performance access tier applications The ProCurve 5304xl Switch provides up to to 64 10 100 1000 ports or 96 10 100 TX with ProCurve Auto MDIX ports Voice video and data ready the Switch 5300xl series offers extensive prioritization features that bring full convergence down to the desktop The chassis comes standard with a routing engine and power supply...

Страница 36: ...ined herein is subject to change without notice The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services Nothing herein should be construed as constituting an additional warranty HP shall not be liable for technical or editorial errors or omissions contained herein 4AA0 0750ENW Rev 3 5 2006 ...

Отзывы: