background image

 

 

 
50 

 

 Two directional MAC address with all VLAN permit filtering. 

 
Step 1

: Create a new ACL Profile. (Profile Name: AllowSomeMac) 

 

Step 2

: Create a new ACL Entry rule under this ACL profile. (Allow SrcMAC: 13 and DesMAC: 11) 

 

Step 3

: Bind this ACL profile to a GE port. (PORT-3) 

 

 

 
 

Содержание MLB-E4200 Series

Страница 1: ...1 MLB E4200 series 8 14 Port Managed Industrial Ethernet Switch User Guide Version Number 1 0 Issue 1 2r1 July 2019...

Страница 2: ...t and Save Configure 26 LED STATUS INDICATIONS 29 VLAN ApPoEication Guide 32 ExamPoEe 1 Default VLAN Settings 32 ExamPoEe 2 Port based VLANs 33 ExamPoEe 3 IEEE 802 1Q Tagging 36 Security ApPoEication...

Страница 3: ...ng Reset 95 LIST OF TABLES Table 1 LED Status Indicators 29 LIST OF FIGURES Figure 1 MLB E4200 DIN Rail Mounting 14 Figure 2 MLB E4200 Wall Mounting 15 Figure 3 LED Indicators 30 Preface Scope Audienc...

Страница 4: ...primary hazards of exposure to laser radiation from an optical fiber communication system are Damage to the eye by accidental exposure to a beam emitted by a laser source Damage to the eye from viewi...

Страница 5: ...5 Overview Overview Faceplate Panel Introduction Technical Specifications...

Страница 6: ...Ethernet solutions deliver high quality wide operation temperature range extended power input range and advanced VLAN QoS features It s ideal for harsh environments and mission critical applications...

Страница 7: ...7 8 10 Port POE series 12 Port POE series...

Страница 8: ...t status RR RS LED Device info status Models L2 Managed Switch MLB E4200 POE SFP MLB E4200 POE SFP MLB E4200 POE SFP MLB E4200 POE SFP MLB E4200 POE SFP Total Gigabit Ethernet Ports 8 10 12 12 14 10 1...

Страница 9: ...9 Technical Specifications...

Страница 10: ...ynamic via LACP Link Aggregation Control Protocol Bridge VLANs Protocols Flow control IEEE 802 3x Full Duplex and Back Pressure Half Duplex VLAN Types Port based VLANs IEEE 802 1Q tag based VLANs IEEE...

Страница 11: ...g SFP with DDM Digital Diagnostic Monitoring MIBs RMON 1 2 3 9 Q Bridge MIB RFC 1213 MIB II RFC 4188 Bridge MIB DHCP Client Server Relay Snooping Option 82 NTP SNTP Yes Environmental ComPoEiances Oper...

Страница 12: ...Code 255 RADIUS Server 5 TACACS Server 5 MAC based VLAN Entry 256 IP subnet based VLAN Entry 128 Protocol based VLAN Group 125 Voice VLAN OUI 16 QCE 256 IP Interface 8 IP Route 32 Security Access Mana...

Страница 13: ...13 Quick Installation Equipment Mounting Cable Connecting Equipment Configuration...

Страница 14: ...ail Mounting step 1 Screw the DIN Rail bracket on with the bracket and screws in the accessory kit 2 Hook the unit over the DIN rail 3 Push the bottom of the unit towards the DIN Rail until it snaps i...

Страница 15: ...15 Mounting the MLB E4200 Wall mount Mounting step 1 Screw on the wall mounting Plate on with the Plate and screws in the accessory kit Figure 2 MLB E4200 Wall Mounting...

Страница 16: ...16 Ground Connections MLB E4200 must be properly grounded for optimum system performance...

Страница 17: ...l only RJ45 To connect to a PC use a straight through or a cross over Ethernet cable To connect the MLB E4200 copper Port to an Ethernet device use UTP Unshielded Twisted Pair or STP Shielded Twisted...

Страница 18: ...he normal operational LED status Fiber optics cable with LC duplex connector Connect the optical fiber to the SFP socket DANGER Never attempt to view optical connectors that might be emitting laser en...

Страница 19: ...gns on the top panel The MLB E4200 can be powered from two power supply input range 12V 58V The DC power connector is a 6 pin terminal block There is alarm contact on the middle terminal block Refer t...

Страница 20: ...al management by using a terminal emulator or a computer with terminal emulation software DB9 connector connect to computer COM port Baud rate 115200bps 8 data bits 1 stop bit None Priority None flow...

Страница 21: ...E4200 the DB9 connector of the cable is connected to the PC COM port The pin assignment of the Console cable is shown below SYSTEM RESET The Reset button is provided to reboot the system without the...

Страница 22: ...d Web page font Times New Roman PoEain text font Courier New Encoding Unicode UTF 8 Text size Medium Firefox with the following default settings is recommended Web page font Times New Roman Encoding U...

Страница 23: ...23 Connect Login to MLB E4200 1 Connecting to MLB E4200 Ethernet port RJ45 Ethernet port 2 Factory default IP 192 0 2 1 3 Login with default account and password Username admin Password none...

Страница 24: ...J45 Ethernet port 2 Key in the command under Telnet telnet 192 0 2 1 3 Login with default account and password Username admin Password none 4 Change the IP with commands listed below CLI Command enabl...

Страница 25: ...s By SFP Refer to Figure 3 for monitoring 4 Gigabit Ethernet with SFP connector Also refer to Table 1 for the normal operational LED status Up Downgrade Software 1 In Web UI go to Maintenance Software...

Страница 26: ...command reload defaults keep ip 2 check interface VLAN and IP address confirm only management IP setting kept 3 Execute this command copy running config startup config If manager want to reset the al...

Страница 27: ...s pagination to Click Yes button 2 Go to Maintenance Configuration Save startup config pagination then click Save Configuration button then reset successfully If manager want to reset the all configur...

Страница 28: ...ress belong to 192 0 2 X networks 3 Change WEB s IP be 192 0 2 1 default IP to login DUT s Web UI 4 Go to Maintenance Configuration Save startup config pagination then click Save Configuration button...

Страница 29: ...nk down Copper ports Speed On Yellow A 100 Mbps or a 1000Mbps connection is detected Off No link or a 10 Mbps connection is detected S SF FP P p po or rt t L Li in nk k A Ac ct t O On n G Gr re ee en...

Страница 30: ...30 Figure 3 LED Indicators PWR LED Indicator ALM LED Indicator Copper Link Act LED Copper Speed LED SFP Speed LED Indicator SFP Link LED Indicator...

Страница 31: ...31 Application Guide VLAN Application Guide Security Application Guide Ring Protection Application Guide QoS Application Guide Link Fail Alarm Application Guide 802 1x Authentication Application Guide...

Страница 32: ...ports in the same VLAN Example 1 Default VLAN Settings Each port in the MLB E4200 has a configurable default VLAN number known as its PVID This Places all ports on the same VLAN initially although eac...

Страница 33: ...ure the untagged packet is marked tagged as it leaves the MLB E4200 through Port 2 which is configured as a tagged member of VLAN100 The untagged packet remains unchanged as it leaves the MLB E42xx th...

Страница 34: ...nsmit untagged unicast packets from Port 1 to Port 2 and Port 7 The MLB E4200 should tag it with VID 100 The packet has access to Port2 and Port 7 The outgoing packet is stripped of its tag to leave P...

Страница 35: ...tag native switchport mode trunk exit interface GigabitEthernet 1 2 switchport access vlan 100 switchport trunk native vlan 100 switchport trunk allowed vlan 1 100 switchport trunk vlan tag native sw...

Страница 36: ...y to VLAN 100 and VLAN 200 because of the tag assignment in the packet Port 2 is configured as a tagged member of VLAN 100 and Port 7 is configured as an untagged member of VLAN 200 Hosts in the same...

Страница 37: ...VID 200 The packet only has access to Port7 The outgoing packet on Port 7 is stripped of its tag as an untagged packet Step4 Transmit unicast packets with VLAN tag 100 from Port 2 to Port 1 and Port...

Страница 38: ...g native switchport mode trunk exit interface GigabitEthernet 1 1 switchport access vlan 100 switchport trunk allowed vlan 1 100 switchport trunk vlan tag native switchport mode trunk exit interface G...

Страница 39: ...rames set in ACL entry h Deny all frames i Deny all frames j Deny all frames but to copy frame which set in ACL entry to a defined GE port Case 1 ACL for MAC address For MAC address ACL it can filter...

Страница 40: ...address with one VLAN deny filtering Step 1 Create a new ACL Profile Profile Name DenySomeMac Step 2 Create a new ACL Entry rule under this ACL profile Deny MAC 11 and VLAN 4 Step 3 Bind this ACL prof...

Страница 41: ...GigabitEthernet 1 4 policy 1 vid 4 frametype etype smac 00 00 00 00 00 11 action deny exit interface GigabitEthernet 1 3 switchport trunk allowed vlan 4 5 switchport trunk vlan tag native interface G...

Страница 42: ...ress with all VLAN deny filtering Step 1 Create a new ACL Profile Profile Name DenySomeMac Step 2 Create a new ACL Entry rule under this ACL profile Deny SrcMAC 13 and DesMAC 11 Step 3 Bind this ACL p...

Страница 43: ...Ethernet 1 3 policy 0 frametype etype smac 00 00 00 00 00 13 dmac 00 00 00 00 00 11 action deny exit interface GigabitEthernet 1 3 switchport trunk allowed vlan 4 5 switchport trunk vlan tag native in...

Страница 44: ...1 d User can set default ACL Rule of GE port as Permit then to bind a suitable profile with CoS Marking action for some ACL function It means GE port can remark CoS of the VLAN frame received from th...

Страница 45: ...terface GigabitEthernet 1 4 policy 1 vid 4 frametype etype smac 00 00 00 00 00 11 action deny exit interface GigabitEthernet 1 3 switchport trunk allowed vlan 4 5 switchport trunk vlan tag native inte...

Страница 46: ...rames from binding GE Port to analyzer port Two directional MAC address with Copy Frame action Don t care VLAN ID Ether Type Step 1 Create a new ACL Profile Profile Name CopyFrameTest Step 2 Create a...

Страница 47: ...cy 0 frametype etype smac 00 00 00 00 00 13 dmac 00 00 00 00 00 11 action deny mirror redirect interface GigabitEthernet 1 5 exit interface GigabitEthernet 1 3 switchport trunk allowed vlan 4 5 switch...

Страница 48: ...Permit action for ACL It means GE port can not pass through all packets but ACL entry of the profile binding One directional MAC address with one VLAN permit filtering Step 1 Create a new ACL Profile...

Страница 49: ...face GigabitEthernet 1 4 policy 3 tag tagged vid 4 frametype etype smac 00 00 00 00 00 11 exit interface GigabitEthernet 1 3 switchport trunk allowed vlan 4 5 switchport trunk vlan tag native interfac...

Страница 50: ...ss with all VLAN permit filtering Step 1 Create a new ACL Profile Profile Name AllowSomeMac Step 2 Create a new ACL Entry rule under this ACL profile Allow SrcMAC 13 and DesMAC 11 Step 3 Bind this ACL...

Страница 51: ...GigabitEthernet 1 3 policy 5 frametype etype smac 00 00 00 00 00 13 dmac 00 00 00 00 00 11 exit interface GigabitEthernet 1 3 switchport trunk allowed vlan 4 5 switchport trunk vlan tag native interfa...

Страница 52: ...opy Frame action for mirror analyzer used It means the system will copy frames from binding GE Port to analyzer port There is no frame received from the denied GE port but the mirror analyzer port One...

Страница 53: ...53 Step 5 Send frames between PORT 3 and PORT 4 see test result E4200 E4200 E4200...

Страница 54: ...00 00 13 dmac 00 00 00 00 00 11 Exit monitor destination interface GigabitEthernet 1 5 monitor source cpu both exit interface GigabitEthernet 1 3 switchport trunk allowed vlan 4 5 switchport trunk vl...

Страница 55: ...elect exact one Protocol from UDP or TCP When it filters on both directional IP address and L4 port packets coincident with both rules will take effect In other words it does not do filter if it only...

Страница 56: ...tant to Ethernet applications especially in Industrial domain MLB E4200 provides a mini second grade failover ring protection this feature offers a seamless working network even if encountering some m...

Страница 57: ...e both ring ports are forward port Group 2 It support configuration of the ring coupling and dual homing Ring it could be master or slave CouPoEing it could be primary and backup When role is coupling...

Страница 58: ...cing chain Chain it could be head tail or member When role is chain head one ring port is head port and another is member port Both ring ports are forwarded in normal state When role is chain tail one...

Страница 59: ...terminal 1 2 one ring port is terminal port and another is member port Both ring ports are forwarded in normal state When role is balancing chain member both ring ports are member port Both ring ports...

Страница 60: ...other switch For example choose PORT 1 and PORT 2 that means PORT 1 is one of the ports connected with other switch so is PORT 2 Then choose one of ring connection devices be Master which you can acc...

Страница 61: ...ng dual homing chain and balancing chain Note 1 It must enable group1 before configure group2 as coupling Note 2 When group1 or group2 is enabled the configuration of group3 is invisible Note 3 When g...

Страница 62: ...aster 3 Select one port as a Forward Port another is Block Port Ring Slave 1 Go to Configuration RingV2 Web page 2 Enable Index1 and Select Role as Ring Slave 3 Select two ports as Forward Port Coupli...

Страница 63: ...nd Select Role as Ring Slave 3 Select two ports as a Forward Port 4 Enable Index2 and Select Role as Coupling Backup 5 Select one port as a Backup Port Dual Homing 1 Go to Configuration RingV2 Web pag...

Страница 64: ...ex2 then enable Index3 3 Select Role to Chain Member 4 Select two member ports for this chain member switch Chain Head 1 Go to Configuration RingV2 Web page 2 Disable Index1 and Index2 then enable Ind...

Страница 65: ...Web page 2 Disable Index1 and Index2 then enable Index3 3 Select Role to Chain Tail 4 Select a member port and a tail port for this chain tail switch Balance Chain Configuration Balance Chain Central...

Страница 66: ...member port and a block port for this central block switch Balance Chain Terminal 1 and 2 1 Go to Configuration RingV2 Web page 2 Disable Index1 and Index2 then enable Index3 3 Select Role to Balancin...

Страница 67: ...oS queue User needs to bind VLAN priority queue mapping profile to each port for every VLAN priority need assign a traffic descriptor for it The traffic descriptor defines the shape parameter on every...

Страница 68: ...d Result We expect PORT 2 only can receive 100Mbps of Stream1 and Stream0 will be discarded This case will help user to know how SPQ works on the MLB E4200 Gigabit port VLAN Priority Queue mapping Str...

Страница 69: ...p1 Go to Configuration Ports set port 2 link speed to 100Mbps full duplex Step2 Select Configuration VLANs Create a VLAN with VLAN ID 100 Enter a VLAN name in the Name field Here we set tagged VLAN100...

Страница 70: ...t trunk native vlan 100 switchport trunk allowed vlan 1 100 switchport trunk vlan tag native switchport mode trunk interface GigabitEthernet 1 2 switchport trunk native vlan 100 switchport trunk allow...

Страница 71: ...traffic are not flooding Expected Result We expect PORT 2 only can receive 20Mbps of Stream1 and 80Mbps of Stream0 This case will help user to know how SPQ works on the MLB E4200 VDSL port VLAN Prior...

Страница 72: ...20 01 Vlan 100 Vlan prio 0 Send rate 10Mbps Packet length 1518bytes Stream4 for Learning Dst Mac 00 00 00 00 10 02 Src Mac 00 00 00 00 20 02 Vlan 100 Vlan prio 0 Send rate 10Mbps Packet length 1518byt...

Страница 73: ...r queue 0 and queue 7 as below CLI configuration command interface GigabitEthernet 1 2 switchport trunk native vlan 100 switchport trunk allowed vlan 1 100 switchport trunk vlan tag native switchport...

Страница 74: ...t routers to establish multicast group memberships It is an integral part of the IP multicast specification like ICMP for unicast connections IGMP can be used for online video and gaming and allows mo...

Страница 75: ...75...

Страница 76: ...of Snooping Enable 2 Un select the check box of Unregistered IPMCv4 Flooding Enabled 3 If Multicast stream is from L3 switch then the uplink port have to be Router Port Notice If an aggregation member...

Страница 77: ...77 4 Go to Configuration IPMC VLAN Configuration to select the check box of Snooping Enable and set VLAN ID of port14...

Страница 78: ...78...

Страница 79: ...cenario these clients belong to multiple vlans you have to create more one vlan to be the agent for all client vlans 1 To create a vlan go to Configuration VLANs Allow Access VLANs then set port 14 be...

Страница 80: ...the check box of Snooping Enable and set VLAN ID of port14 3 If there is no querier on the L3 switch you have to select Querier Election and set the Querier Address the IP address is in the same netwo...

Страница 81: ...81 How to Configuration VLC VLC Configure on IGMP Server 1 In Media area of top tool bar to select Stream 2 Select a video or voiced file to Play...

Страница 82: ...82 3 Confirm the file is right then click Next twice...

Страница 83: ...83 4 Select stream type as UDP and click Add button 5 Set stream IP the range is 224 0 0 1 to 239 255 255 254 and protocol port is 1234 Here I set stream IP is 255 0 0 1...

Страница 84: ...84 6 Select Sort out all stream and click Stream button then the stream start to send to switch VLC Configure on IGMP Client 1 In Media area of top tool bar to select open network stream...

Страница 85: ...otocol port as previous setting on server the protocol type is UDP the format should as below circle then click POEAY button Back to management switch Go to Monitor IPMC Groups Information you will se...

Страница 86: ...ng any service from the network Please see the following description 802 1x Timer in ML E4200 Item Parameter sec Description 1 ReAuth Period MLB E4200 will restart authentication after each Reauth Per...

Страница 87: ...87 Step 2 Edit secret key for Radius server Setting client 20 20 20 0 24 secret a1b2c3d4 The secret in the MLB E4200 should be the same with this one...

Страница 88: ...uthentication via MLB E4200 to be authenticated by RADIUS server In a basic example we take port 1 as a testing port which enables 802 1x in MLB E4200 With default configuration use the following Web...

Страница 89: ...89 Step1 Go to Configuration Security AAA Radius Click Add New Server Input 20 20 20 20 for server and a1b2c3d4 for secret key Then click Save button...

Страница 90: ...e ter interface vlan 1 ip address 20 20 20 120 255 0 0 0 exit exit radius server host 20 20 20 20 timeout 5 retransmit 3 key a1b2c3d4 dot1x re authentication dot1x system auth control interface Gigabi...

Страница 91: ...k box then to configure EAP type to MD5 Challenge After setting this function in NIC supplicant should enter a correct pair of account and password in order to use this Ethernet port service from E420...

Страница 92: ...peration mode contains 802 3af 15 4W 802 3at 30W and 802 3at with 4 pair used 60W 60 watt only can be applied for port 1 and 2 Each port has 5 classes for selection class 0 4 And total power budget of...

Страница 93: ...Five different port classes exist and one for 4 7 15 4 or 30 Watts 2 Allocated mode In this mode the user allocates the amount of power that each port may reserve The allocated reserved power for each...

Страница 94: ...port has higher priority 2 Reserved Power In this mode the ports are shut down when total reserved powered exceeds the amount of power that the power supply can deliver In this mode the port power is...

Страница 95: ...te devices require more power than the power supply can deliver In this case the port with the lowest priority will be turn off starting from the port with the highest port number 6 Maximum Power The...

Страница 96: ...nutes 3 Action Power On Select the radio button to apply power on during the interval Power Off Select the radio button to apply power off during the interval 4 PoE Power Reset The entry is used to co...

Страница 97: ...Web Configuration 5 Test Result PoE port status can be monitored by Web Monitor PoE In the following table it can be seen if system budget is not enough for all PoE device port with higher priority po...

Страница 98: ...PoE Splitter Port 2 1 3 watt PoE VoIP Phone Port 3 3 8 watt PoE WiFi AP 4 Web Configuration 5 Test Result PoE port status can be monitored by Web Monitor PoE Since power has reserved for each port in...

Отзывы: