ZyXEL MES3500-24 User Guide
ZyXEL MES3500-24 Manual
| View all ZyXEL MES3500-24 manuals |
ZyXEL MES3500-24 manual content summary:
- ZyXEL MES3500-24 | User Guide — Page 1
MES3500-24/24F Layer 2 Management Switch Default Login Details IP Address http://192.168.1.1 User Name admin Password 1234 Firmware Version 4.00 Edition 1, 12/2011 www.zyxel.com www.zyxel.com Copyright © 2011 ZyXEL Communications Corporation - ZyXEL MES3500-24 | User Guide — Page 2
- ZyXEL MES3500-24 | User Guide — Page 3
Guide The Command Reference Guide explains how to use the Command-Line Interface (CLI) and CLI commands to configure the Switch. Note: It is recommended you use the web configurator to configure the Switch. • Support Disc Refer to the included CD for support documents. MES3500-24/24F User’s Guide - ZyXEL MES3500-24 | User Guide — Page 4
things you may need to configure or helpful tips) or recommendations. Syntax Conventions • The MES3500-24/24F may be referred to as the «Switch», the «device», the «system» or the «product» in this User’s Guide. • Product labels, screen names, field labels and field choices are all in bold font - ZyXEL MES3500-24 | User Guide — Page 5
cables to the correct ports. • Place connecting cables carefully so that no one will step on them or stumble over them. • Always disconnect all cables from this device before servicing or disassembling. • and electronic equipment should be treated separately. MES3500-24/24F User’s Guide 5 - ZyXEL MES3500-24 | User Guide — Page 6
Safety Warnings 6 MES3500-24/24F User’s Guide - ZyXEL MES3500-24 | User Guide — Page 7
Guide . 21 Getting to Know Your Switch . 23 Hardware Installation and Connection 27 Hardware Overview . 30 The Web Configurator . 39 Initial Setup Example . 49 Tutorials . 53 Technical Reference . 79 System Status and Port . 265 Differentiated Services . 268 MES3500-24/24F User’s Guide 7 - ZyXEL MES3500-24 | User Guide — Page 8
Contents Overview DHCP . 276 Maintenance . 283 Access Control . 290 Diagnostic . 312 Syslog . 313 Cluster Management . 316 MAC Table . 322 ARP Table . 325 Configure Clone . 327 Troubleshooting . 329 8 MES3500-24/24F User’s Guide - ZyXEL MES3500-24 | User Guide — Page 9
27 2.3.2 Attaching the Mounting Brackets to the Switch 28 2.3.3 Mounting the Switch on a Rack 29 Chapter 3 Hardware Overview . 30 3.1 Front Panel . 30 3.1.1 Console Port . 31 3.1.2 Ethernet Ports . 32 3.1.3 Transceiver Slots . 32 3.1.4 Power Connector . 34 MES3500-24/24F User’s Guide 9 - ZyXEL MES3500-24 | User Guide — Page 10
on the Switch 66 6.5 How to Set Up a Guest VLAN 68 6.5.1 Creating a Guest VLAN 68 6.5.2 Enabling IEEE 802.1x Port Authentication 71 6.5.3 Enabling Guest VLAN 72 6.6 How to Do Port Isolation in a VLAN 73 6.6.1 Creating a VLAN . 74 6.6.2 Creating a Private VLAN Rule 76 10 MES3500-24/24F User - ZyXEL MES3500-24 | User Guide — Page 11
. 89 8.4.1 Smart Isolation . 90 8.5 Switch Setup . 91 8.6 IP Setup . 93 8.6.1 Management IP Addresses 93 8.7 Port Setup . 95 Chapter 9 VLAN . 97 9.10 Create an IP-based VLAN Example 109 9.11 Port-based VLAN Setup 110 9.11.1 Configure a Port-based VLAN 111 MES3500-24/24F User’s Guide 11 - ZyXEL MES3500-24 | User Guide — Page 12
of Contents Chapter 10 Static MAC Forward Setup 114 10.1 Overview . 114 10.2 Configuring Static MAC 122 13.1.1 STP Terminology 122 13.1.2 How STP Works . 123 13.1.3 STP Port States . 123 13.1.4 Multiple RSTP . 124 13.1.5 Multiple STP . 124 13 Control Setup 144 12 MES3500-24/24F User’s Guide - ZyXEL MES3500-24 | User Guide — Page 13
VLAN . 160 18.2.3 Activate MAC Authentication 162 Chapter 19 Port Security . 164 19.1 About Port Security . 164 19.2 Port Security Setup . 164 Chapter 20 Classifier. 166 20.1 About the Policy Rules 171 21.3 Viewing and Editing Policy Configuration 174 MES3500-24/24F User’s Guide 13 - ZyXEL MES3500-24 | User Guide — Page 14
Types of MVR Ports 194 24.6.2 MVR Modes . 194 24.6.3 How MVR Works . 194 24.7 General MVR Configuration 195 24.8 MVR Group Configuration 197 24.8.1 MVR Configuration Example 198 Chapter 25 AAA . 201 25.1 Authentication, Authorization and Accounting (AAA 201 14 MES3500-24/24F User’s Guide - ZyXEL MES3500-24 | User Guide — Page 15
Attribute 209 25.2.5 Tunnel Protocol Attribute 210 25.3 Supported RADIUS Attributes 210 25.3.1 Attributes Used for Authentication 211 . 220 26.5 DHCP Snooping Configure 222 26.5.1 DHCP Snooping Port Configure 224 26.5.2 DHCP Snooping VLAN Configure 225 26.6 ARP MES3500-24/24F User’s Guide 15 - ZyXEL MES3500-24 | User Guide — Page 16
30 sFlow. 245 30.1 sFlow Overview . 245 30.2 sFlow Port Configuration 246 30.2.1 sFlow Collector Configuration 247 Chapter 31 PPPoE . 249 31.1 PPPoE Intermediate Agent Overview 249 265 34.2 Configuring Static Routing 266 Chapter 35 Differentiated Services. 268 16 MES3500-24/24F User’s Guide - ZyXEL MES3500-24 | User Guide — Page 17
Load Factory Default . 284 37.3 Save Configuration . 284 37.4 Reboot System . 284 37.5 Firmware Upgrade . 285 37.6 Restore a Configuration File 286 37.7 Backup a Configuration File 286 37.8 288 Chapter 38 Access Control . 290 38.1 Access Control Overview 290 MES3500-24/24F User’s Guide 17 - ZyXEL MES3500-24 | User Guide — Page 18
316 41.1 Cluster Management Status Overview 316 41.2 Cluster Management Status 317 41.2.1 Cluster Member Switch Management 318 41.3 Clustering Management Configuration 320 Chapter 42 MAC Table . 322 42.1 MAC Table Overview . 322 42.2 Viewing the MAC Table 323 18 MES3500-24/24F User’s Guide - ZyXEL MES3500-24 | User Guide — Page 19
Clone. 327 44.1 Configure Clone . 327 Chapter 45 Troubleshooting. 329 45.1 Power, Hardware Connections, and LEDs 329 45.2 Switch Access and Login 330 45.3 Switch Configuration . 332 Appendix A Common Services 333 Appendix B Legal Information 337 Index . 341 MES3500-24/24F User’s Guide 19 - ZyXEL MES3500-24 | User Guide — Page 20
Table of Contents 20 MES3500-24/24F User’s Guide - ZyXEL MES3500-24 | User Guide — Page 21
PART I User’s Guide 21 - ZyXEL MES3500-24 | User Guide — Page 22
22 - ZyXEL MES3500-24 | User Guide — Page 23
This chapter introduces the main features and applications of the Switch. 1.1 Introduction The Switch is a layer-2 standalone Ethernet switch. The MES3500-24 has 24 10/100 Mbps fast Ethernet ports. The MES3500-24F has 24 100 Mbps fast Ethernet SFP slots. Both also have four GbE dual personality - ZyXEL MES3500-24 | User Guide — Page 24
same bandwidth as ATM at much lower cost while still being able to use existing adapters and switches. Moreover, the current LAN structure can be retained as all ports can freely communicate with each other. Figure 3 High Performance Switched Workgroup Application 24 MES3500-24/24F User’s Guide - ZyXEL MES3500-24 | User Guide — Page 25
perform diagnostic functions, such as «ping» • IPv4/IPv6 dual stack; the Switch can run IPv4 and IPv6 at the same time • DHCPv6 client and relay • Multicast Listener Discovery (MLD) snooping and proxy For more information on IPv6, refer to the CLI Reference Guide. MES3500-24/24F User’s Guide 25 - ZyXEL MES3500-24 | User Guide — Page 26
or even crashes. If you forget your password, you will have to reset the Switch to its factory default settings. If you backed up an earlier configuration file, you would not have to totally re-configure the Switch. You could simply restore your last configuration. 26 MES3500-24/24F User’s Guide - ZyXEL MES3500-24 | User Guide — Page 27
M3 flat head screws and a #2 Philips screwdriver. • Four M5 flat head screws and a #2 Philips screwdriver. Failure to use the proper screws may damage the unit. MES3500-24/24F User’s Guide 27 - ZyXEL MES3500-24 | User Guide — Page 28
screwdriver, install the M3 flat head screws through the mounting bracket holes into the Switch. 3 Repeat steps 1 and 2 to install the second mounting bracket on the other side of the Switch. 4 You may now mount the Switch on a rack. Proceed to the next section. 28 MES3500-24/24F User’s Guide - ZyXEL MES3500-24 | User Guide — Page 29
side of the rack. Figure 6 Mounting the Switch on a Rack 2 Using a #2 Philips screwdriver, install the M5 flat head screws through the mounting bracket holes into the rack. 3 Repeat steps 1 and 2 to attach the second mounting bracket on the other side of the rack. MES3500-24/24F User’s Guide 29 - ZyXEL MES3500-24 | User Guide — Page 30
MES3500-24 Front Panel: DC Model Power Switch LEDs Signal slot Dual Personality Interfaces Console Port Power Connection Fast Ethernet Ports Figure 9 MES3500-24F Front Panel: AC Model LEDs Signal slot Dual Personality Interfaces Console Port Power Connection MES3500-24/24F User’s Guide - ZyXEL MES3500-24 | User Guide — Page 31
Panel Connections LABEL Power Switch Power Connection 24 10/100 Mbps RJ-45 Fast Ethernet Ports (MES3500-24) 24 100 Mbps Fast SFP Slots (MES3500-24F) Four Dual Personality Interfaces Console Port Signal slot DESCRIPTION This is for DC model only. After you connect the DC power properly (see Section - ZyXEL MES3500-24 | User Guide — Page 32
is a single unit that houses a transmitter and a receiver. The Switch does not come with transceivers. You must use transceivers that comply with the SFP Transceiver MultiSource Agreement (MSA). See the SFF committee’s INF-8074i specification Rev 1.0 for details. 32 MES3500-24/24F User’s Guide - ZyXEL MES3500-24 | User Guide — Page 33
board facing down. 2 Press the transceiver firmly until it clicks into place. 3 The Switch automatically detects the installed transceiver. Check the LEDs to verify that it is functioning properly the transceiver. 2 Open the transceiver’s latch (latch styles vary). MES3500-24/24F User’s Guide 33 - ZyXEL MES3500-24 | User Guide — Page 34
on the power. Use only power wires of the required diameter for connecting the Switch to a power supply. 3.1.4.1 AC Power Connection Connect the female end of the power cord to the power socket of your Switch. Connect the other end of the cord to a power outlet. 34 MES3500-24/24F User’s Guide - ZyXEL MES3500-24 | User Guide — Page 35
. • The Switch can be configured to create an error log of the alarm. See Section 40.1 on page 313 for more information on using the system log. 3.1.5.1 Connect a Sensor to the Signal Slot This section shows you how to connect an external sensor device to the Switch. MES3500-24/24F User’s Guide 35 - ZyXEL MES3500-24 | User Guide — Page 36
pairs of signal input pins on the Switch’s Signal connector—(4,5) (6,7) (8,9) (10,11). The pin numbers run from the ZyXEL Switch which supports the external alarm feature. If daisy-chaining to a ZyXEL switch that is a different model, check your switch ZyXEL Switch. 36 MES3500-24/24F User’s Guide - ZyXEL MES3500-24 | User Guide — Page 37
Off The link to an Ethernet network is down. 100 Mbps Fast SFP Ports (MES3500-24F) 1
24 Amber On The port has a successfule connection. Off No Ethernet device is connected to this port. Blinking This port is receiving or transmitting data. Mini-GBIC Slots MES3500-24/24F User’s Guide 37
100 Mbps Ethernet network. On The link to a 10 Mbps or a 100 Mbps Ethernet network is up. Off The link to an Ethernet network is down. FDX Amber On The Gigabit port is negotiating in full-duplex mode. Off The Gigabit port is negotiating in half-duplex mode. 38 MES3500-24/24F User’s Guide
enabled by default). • Java permissions (enabled by default). 4.2 System Login 1 Start your web browser. 2 Type «http://» and the IP address of the Switch (for example, the default management IP address is 192.168.1.1) in the Location or Address field. Press [ENTER]. MES3500-24/24F User’s Guide 39
is 1234. The date and time display as shown if you have not configured a time server nor manually entered a time and date in the General Setup screen. Figure 18 Web Configurator: Login 4 Click OK configurator screen. Figure 19 The Web Configurator Layout B C DE A 40 MES3500-24/24F User’s Guide
settings to a specific configuration file. C — Click this link to go to the status page of the Switch. D — Click this link to log out of the web configurator. E — Click this link to Sub-links Overview BASIC SETTING ADVANCED APPLICATION IP APPLICATION MANAGEMENT MES3500-24/24F User’s Guide 41
queue weights for each port. VLAN Stacking This link takes you to screens where you can activate and configure VLAN stacking. Multicast This link takes you to screen where you can configure various multicast features, IGMP snooping and create multicast VLANs. 42 MES3500-24/24F User’s Guide
authorization and accounting services via external servers. how the Switch should forward traffic by configuring the TCP/IP parameters manually. DiffServ Management Maintenance This link takes you to screens where you can perform firmware port to (an)other port(s). MES3500-24/24F User’s Guide 43
(managing through the data ports) if you do one of the following: 1 Delete the management VLAN (default is VLAN 1). 2 Delete all port-based VLANs with the CPU port as a member. The «CPU port» is the management port of the Switch. 3 Filter all traffic to the CPU port. 44 MES3500-24/24F User’s Guide
all services from accessing the Switch. 8 Change a service port number but forget it. Note: Be careful not to lock yourself and others out of the Switch. If you do lock yourself out, try using out-of-band management (via the management port) to configure the Switch. 4.6 Resetting the Switch If
configuration file upload, type atgo to restart the Switch. Figure 21 Resetting the Switch: Via the Console Port Bootbase Version: V1.00 | 11/02/2011 log out. This is recommended after you finish a management session for security reasons. Figure 22 Web Configurator: Logout MES3500-24/24F User’s Guide
Chapter 4 The Web Configurator MES3500-24/24F User’s Guide 47
Chapter 4 The Web Configurator 48 MES3500-24/24F User’s Guide
broadcast frames to the VLAN group in which the port(s) belongs. You can do this with port-based VLAN or tagged static VLAN with fixed port members. In this example, you want to configure port 1 as a member of VLAN 2. Figure 23 Initial Setup Network Example: VLAN MES3500-24/24F User’s Guide 49
run-time memory. Settings in the run-time memory are lost when the Switch’s power is turned off. 5.1.2 Setting Port VID Use PVID to add a tag to incoming untagged frames received on that port so that the frames are forwarded to the VLAN group that the tag defines. 50 MES3500-24/24F User’s Guide
Switch Management IP Address The default management IP address of the Switch is 192.168.1.1. You can configure another IP address in a different subnet for management purposes. The following figure shows an example. Figure 25 Initial Setup Example: Management IP Address MES3500-24/24F User’s Guide
you want this management IP address to belong. This is the same as the VLAN ID you configure in the Static VLAN screen. 7 Click Add to save your changes back to the run-time memory. Settings in the run-time memory are lost when the Switch’s power is turned off. 52 MES3500-24/24F User’s Guide
Client (B) 6 DHCP Client (C) 7 VLAN 1 and 100 1 and 100 1 and 100 PVID 100 100 100 DHCP SNOOPING PORT TRUSTED Yes No No 1 Access the Switch through http://192.168.1.1. Log into the Switch by entering the username (default: admin) and password (default: 1234). MES3500-24/24F User’s Guide 53
Tx Tagging because you don’t want outgoing traffic to contain this VLAN tag. Click Add. 3 Go to Advanced Application > VLAN > VLAN Port Setting, and set the PVID of the ports 5, 6 and 7 to 100. This tags untagged incoming frames on ports 5, 6 and 7 with the tag 100. 54 MES3500-24/24F User’s Guide
the top right corner. 6 The DHCP Snooping Port Configure screen appears. Select Trusted in the Server Trusted state field for port 5 because the DHCP server is connected to port 5. Keep ports 6 and 7 Untrusted because they are connected to DHCP clients. Click Apply. MES3500-24/24F User’s Guide 55
Port —— 7 6.2 How to Use DHCP Relay on the Switch This tutorial describes how to configure your Switch to forward DHCP client requests to a specific DHCP server. The DHCP server can then assign a specific IP address based on the information in the DHCP requests. 56 MES3500-24/24F User’s Guide
steps below to configure port 2 as a member of VLAN 102. 1 Access the web configurator through the Switch’s port which is not in VLAN 102. 2 Go to Basic Setting > Switch Setup and set the VLAN type to 802.1Q. Click Apply to save the settings to the run-time memory. MES3500-24/24F User’s Guide 57
sending. 7 Click Add to save the settings to the run-time memory. Settings in the run-time memory are lost when the Switch’s power is turned off. 8 Click the VLAN Status link in the Static VLAN screen and then the VLAN Port Setting link in the VLAN Status screen. 58 MES3500-24/24F User’s Guide
port 2 to add a tag to incoming untagged frames received on that port so that the frames are forwarded to the VLAN group that the tag defines. 10 the steps below to enable DHCP relay on the Switch and allow the Switch to add relay agent information (such as the VLAN MES3500-24/24F User’s Guide 59
the Switch to have your settings take effect. 6.3 How to Use PPPoE IA on the Switch You want to configure PPPoE Intermediate Agent on the Switch (A) to pass a subscriber’s information to a PPPoE server (S). There is another switch (B) between switch A and server S. 60 MES3500-24/24F User’s Guide
userC N/A N/A N/A REMOTE-ID 00134900000A N/A N/A N/A PPPOE IA PORT TRUSTED Untrusted Trusted Trusted Trusted 6.3.1 Configuring Switch A 1 Click Advanced Application > PPPoE > Intermediate Agent. Select Active then click Apply. Click Port on the top of the screen. MES3500-24/24F User’s Guide 61
userC as Circuit-id and 00134900000A as Remote-id. Select Trusted for port 12 and then leave the other fields empty. Click Apply. Then Click Intermediate Agent on the top of the screen. 3 The Intermediate Agent screen appears. Click VLAN on the top of the screen. 62 MES3500-24/24F User’s Guide
to enable PPPoE IA in VLAN 1 and also select Circuit-id and Remote-id to allow the Switch to add these two strings to frames tagged with VLAN 1 and pass to the PPPoE server. Click Apply. 6.3.2 Configuring Switch B The example uses another MES3500-24/24F as switch B. MES3500-24/24F User’s Guide 63
Chapter 6 Tutorials 1 Click Advanced Application > PPPoE > Intermediate Agent. Select Active then click Apply. Click Port on the top of the screen. 2 Select Trusted for ports 11 and 12 and then click Apply. Then Click Intermediate Agent on the top of the screen. 64 MES3500-24/24F User’s Guide
and End VID. Click Apply. 5 Then select Yes to enable PPPoE IA in VLAN 1 and also select Circuit-id and Remote-id to allow the Switch to add these two strings to frames tagged with VLAN 1 and pass to the PPPoE server. Click Apply. MES3500-24/24F User’s Guide 65
on a port You also want the Switch to wait for a period of time (10 minutes) before resuming the port automatically, after the problem(s) are gone the Switch. Then select the Active option of the first entry (port *) to enable loop guard for all ports. Click Apply. 66 MES3500-24/24F User’s Guide
inactive-port as the mode. Then click Apply. 4 Click Advanced Application > Errdisable > Errdisable Recovery, select Active and Timer Status for loopguard and ARP entries. Also enter 180 (180 seconds = 3 minutes) in the Interval field for both entries. Then click Apply. MES3500-24/24F User’s Guide
or local data base. VLAN 1 Guest VLAN 200 Ports 1, 2, 3 and 10 Internet 6.5.1 Creating a Guest VLAN Follow the steps below to configure port 1, 2, 3 and 10 as a member of VLAN 200. 1 Access the web configurator through the Switch’s port which is not in VLAN 200. 68 MES3500-24/24F User’s Guide
Chapter 6 Tutorials 2 Go to Basic Setting > Switch Setup and set the VLAN type to 802.1Q. ports 1, 2, 3 and 10 to be permanent members of this VLAN. 6 Clear the TX Tagging check box to set the Switch to remove VLAN tags before sending frames out of these ports. MES3500-24/24F User’s Guide
screen and then the VLAN Port Setting link in the VLAN Status screen. 9 Enter 200 in the PVID field for ports 1, 2, 3 and 10 to add a tag to incoming untagged frames received on these ports so that the frames are forwarded to the VLAN group that the tag defines. 70 MES3500-24/24F User’s Guide
. 6.5.2 Enabling IEEE 802.1x Port Authentication Follow the steps below to enable port authentication to validate access to ports 1
8 to clients based on a RADIUS server. 1 Click Advanced Application > Port Authentication and then the Click Here link for 802.1x. MES3500-24/24F User’s Guide 71
the first Active checkbox to enable 802.1x authentication on the Switch. Select the Active checkboxes for ports 1 to 8 to turn on 802.1x authentication on the selected ports. Click Apply. 6.5.3 Enabling Guest VLAN 1 Click the Guest Vlan link in the 802.1x screen. 72 MES3500-24/24F User’s Guide
communicate with devices in VLAN 1. 6.6 How to Do Port Isolation in a VLAN You want to prevent communications between ports in a VLAN but still allow them to access the Internet or network resources through the uplink port in the same VLAN. You use private VLAN to MES3500-24/24F User’s Guide 73
and 25 as a member of VLAN 123. 1 Access the web configurator through the Switch’s port which is not in VLAN 123. 2 Go to Basic Setting > Switch Setup and set the VLAN type to 802.1Q. Click Apply to save the settings field and enter 123 in the VLAN Group ID field. 74 MES3500-24/24F User’s Guide
ports. 7 Click Add to save the settings to the run-time memory. Settings in the run-time memory are lost when the Switch’s power is turned off. 8 Click the VLAN Status link in the Static VLAN screen and then the VLAN Port Setting link in the VLAN Status screen. MES3500-24/24F User’s Guide 75
in the PVID field for ports 2, 3, 4 and 25 to add a tag to incoming untagged frames received on these ports so that the frames are forwarded to the VLAN group that the tag defines. 10 Click Apply to save VLAN for VLAN 123. 1 Click Advanced Application > Private VLAN. 76 MES3500-24/24F User’s Guide
permanently. Ports 2, 3 and 4 in this VLAN will be added to the isolated port list automatically and cannot send traffic to each other. From port 2, 3, or 4, you should be able to access the device that attachs to port 25, such as a server or default gateway. MES3500-24/24F User’s Guide 77
Chapter 6 Tutorials 78 MES3500-24/24F User’s Guide
PART II Technical Reference 79
80
web configurator displays a port statistical summary with links to each port showing statistical details. 7.2 Port Status Summary To view the port statistics, click Status in all web configurator screens to display the Status screen as shown next. Figure 26 Status MES3500-24/24F User’s Guide 81
on this port. This field shows the total amount of time in hours, minutes and seconds the port has been up. Enter a port number and then click Clear Counter to erase the recorded statistical information for that port, or select Any to clear statistics for all ports. 82 MES3500-24/24F User’s Guide
port on the Switch. Figure 27 Status > Port Details The following table describes the labels in this screen. Table 8 Status: Port Details LABEL Port Info Port NO. Name Link DESCRIPTION This field displays the port Down if the port is not connected to any device. MES3500-24/24F User’s Guide 83
Protocol) is enabled, this field displays the STP state of the port (see Section 13.1 on page 122 for more information). LACP defined as the number of maximum collisions before the retransmission count is reset. Late This is the number of times a late collision is 84 MES3500-24/24F User’s Guide
Chapter 7 System Status and Port Statistics Table 8 Status: Port Details (continued) LABEL 128-255 256-511 512-1023 1024-1518 Giant DESCRIPTION and the maximum frame size. The maximum frame size varies depending on your switch model. See Chapter 46 on page 333. MES3500-24/24F User’s Guide 85
server) for management purposes. The Port Setup screen allows you to enable or disable a port on the Switch and configure the port settings, such firmware version number and monitor the Switch temperature and voltage in this screen. Figure 28 Basic Setting > System Info MES3500-24/24F User’s Guide
of the Switch. ZyNOS F/W Version This field displays the version number of the Switch ‘s current firmware including the Switch still works. Status Normal indicates that the voltage is within an acceptable operating range at this point; otherwise Error is displayed. MES3500-24/24F User’s Guide
of your timeserver. The Switch searches for the timeserver for up to 60 seconds. If you select a timeserver that is unreachable, then this screen will appear locked for 60 seconds. Please wait. This field displays the time you open this menu (or refresh the menu). 88 MES3500-24/24F User’s Guide
select 2:00 because Germany’s time zone is one hour ahead of GMT or UTC (GMT+1). Click Apply to save your changes to the Switch’s run-time memory. The Switch loses these changes if it is turned off or printers and hard disks of another user in the same building. MES3500-24/24F User’s Guide 89
received on designated port 8 from switch C will not be forwarded to any other isolated ports on switch B. A B Before Smart Isolation: Isolated ports: 2
6 Root port: 7 Designated port: 8 After Smart Isolation: Isolated ports: 2
6, 8 Root port: 7 Designated port: 8 90 C MES3500-24/24F User’s Guide
802.1Q VLAN port isolation or private VLAN and (M)RSTP on the Switch. Smart isolation does not work with MSTP and/or port-based VLAN. MAC address learning reduces outgoing traffic broadcasts. For MAC address learning to occur on a port, the port must be active. MES3500-24/24F User’s Guide 91
the Switch’s run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Cancel Click Cancel to reset the fields. 92 MES3500-24/24F User’s Guide
. The factory default subnet mask is 255.255.255.0. You can configure up to 64 IP addresses which are used to access and manage the Switch from the ports belonging to the pre-defined VLAN(s). Note: You must configure a VLAN first. Figure 31 Basic Setting > IP Setup MES3500-24/24F User’s Guide 93
which are used to access and manage the Switch from the ports belonging to the pre-defined VLAN(s). You must configure a VLAN first. IP Address Enter the IP address for managing the Switch by the members of the VLAN displays the IP address of the default gateway. 94 MES3500-24/24F User’s Guide
this port. You can enter up to 64 alpha-numerical characters. Type Note: Due to space limitation, the port name may be truncated in some web configurator screens. This field displays 10/100M for Fast Ethernet connections and 10/100/1000M for Gigabit connections. MES3500-24/24F User’s Guide 95
run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. 96 MES3500-24/24F User’s Guide
switches ports, but this can be changed. A broadcast frame (or a multicast frame for a multicast group that is known by the system) is duplicated only on ports that are members of the VID (except the ingress port itself), thus confining the broadcast to a specific domain. MES3500-24/24F User’s Guide
frames that this port received. You may choose to accept both tagged and untagged incoming frames, just tagged incoming frames or just untagged incoming frames on a port. If set, the Switch discards incoming frames for VLANs that do not have this port as a member. 98 MES3500-24/24F User’s Guide
drop frames with unknown VLAN group tags. However, with VLAN Trunking enabled on a port(s) in each intermediary switch you only need to create VLAN groups in the end devices (A and B). C, frames (that were previously untagged) from a port with the specified VID. MES3500-24/24F User’s Guide 99
to the Switch; dynamic — using GVRP, static added as a permanent entry or other — added in another way such as via Multicast VLAN Registration (MVR). Click Previous or Next to show the previous/next screen if all status information cannot be seen in one screen. 100 MES3500-24/24F User’s Guide
it has been since a normal VLAN was registered or a static VLAN was set up. This field shows how this VLAN was added to the Switch; dynamic — using GVRP, static added as a permanent entry or other — added in another way such as via Multicast VLAN Registration (MVR). MES3500-24/24F User’s Guide 101
for the Switch. See Section port to dynamically join this VLAN group using GVRP. This is the default selection. Select Fixed for the port to be a permanent member of this VLAN group. Select Forbidden if you want to prohibit the port from joining this VLAN group. 102 MES3500-24/24F User’s Guide
VLAN Registration Protocol) is a registration protocol that defines a way for switches to register necessary VLAN members on ports across the network. Port Select this check box to permit VLAN groups beyond the local Switch. This field displays the port number. MES3500-24/24F User’s Guide 103
services). You can also have a subnet based VLAN with priority 5 and VID of 200 for traffic received from IP subnet 192.168.1.0/24 (video services). Lastly, you can configure VLAN with priority 3 and VID of 300 for traffic received from IP subnet 10.1.1.0/24 (data 104 MES3500-24/24F User’s Guide
Example Tagged Frames Internet Untagged Frames 172.16.1.0/24 VID = 100 192.168.1.0/24 VID = 200 10.1.1.0/24 VID = 300 9.7 Configuring Subnet Based VLAN Click Subnet Based VLAN in the VLAN Port Setting screen to display the configuration screen as shown. MES3500-24/24F User’s Guide 105
IEEE 802.1Q tagged VLAN. Figure 40 Advanced Application > VLAN > VLAN Port Setting > Subnet Based VLAN The following table describes the labels in this screen. Table 19 Advanced screens. Select the priority level that the Switch assigns to frames belonging to this VLAN. 106 MES3500-24/24F User’s Guide
2 and 3 will be grouped together, and all upstream Apple Talk traffic from port 6 and 7 will be in another group and have higher priority than ARP traffic when they go through the uplink port to a backbone switch C. Figure 41 Protocol Based VLAN Application Example MES3500-24/24F User’s Guide 107
run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. 108 MES3500-24/24F User’s Guide
Click Cancel to begin configuring this screen afresh. 9.10 Create an IP-based VLAN Example This example shows you how to create an IP VLAN which includes ports 1, 4 and 8. Follow these steps using the we already created a static VLAN with an ID of 5. Type 5. MES3500-24/24F User’s Guide 109
Switch uses a default VLAN ID of 1. You cannot change it. Note: In screens (such as IP Setup and Filtering) that require a VID, you must enter 1 as the VID. The port-based VLAN setup screen is shown next. The CPU management port forms a VLAN with all Ethernet ports. 110 MES3500-24/24F User’s Guide
Port Isolated if you want to restrict users from communicating directly. Click Apply to save your settings. The following screen shows users on a port-based, all-connected VLAN configuration. Figure 44 Advanced Application > VLAN > Port Based VLAN Setup (All Connected) MES3500-24/24F User’s Guide
Chapter 9 VLAN The following screen shows users on a port-based, port-isolated VLAN configuration. Figure 45 Advanced Application > VLAN: Port Based VLAN Setup (Port Isolation) 112 MES3500-24/24F User’s Guide
run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. MES3500-24/24F User’s Guide 113
a port to access the Switch. See Chapter 19 on page 164 for more information on port security. Click Advanced Applications > Static MAC Forwarding in the navigation panel to display the configuration screen as shown. Figure 46 Advanced Application > Static MAC Forwarding MES3500-24/24F User’s Guide
. This field displays the ID number of the VLAN group. This field displays the port where the MAC address shown in the next field will be forwarded. Click Delete to remove the selected entry from the summary table. Click Cancel to clear the Delete check boxes. MES3500-24/24F User’s Guide 115
that has been manually entered in the multicast switch will either flood the multicast frames to all ports 24.3 on page 188). Figure 47 shows such unknown multicast frames flooded to all ports. With static multicast forwarding, you can forward these multicasts to port(s) MES3500-24/24F User’s Guide
Forwarding to A Single Port Figure 49 Static Multicast Forwarding to Multiple Ports 11.2 Configuring Static Multicast Forwarding Use this screen to configure rules to forward specific multicast frames, such as streaming or control frames, to specific port(s). MES3500-24/24F User’s Guide 117
hyphen (). For example, enter «3-5» for ports 3, 4, and 5. Enter «3,5,7» for ports 3, 5, and 7. Add Click Add to save your rule to the Switch’s run-time memory. The Switch loses this rule if it is turned off the specified multicast MAC address will be forwarded. 118 MES3500-24/24F User’s Guide
displays the port(s) within a identified VLAN group to which frames containing the specified multicast MAC address will be forwarded. Delete Click Delete to remove the selected entry from the summary table. Cancel Click Cancel to clear the Delete check boxes. MES3500-24/24F User’s Guide 119
MAC address port filtering. 12.1 Configure a Filtering Rule Configure the Switch to filter Switch can still receive frames originating from the MAC address. Select Discard source and Discard destination to block traffic to/from the MAC address specified in the MAC field. MES3500-24/24F User’s Guide
to remove in the Delete column and then click the Delete button. Cancel Click Cancel to clear the selected checkbox(es) in the Delete column. MES3500-24/24F User’s Guide 121
Tree Protocol The Switch supports Spanning Tree Protocol Multiple Spanning Tree Protocol The Switch also allows you to set up multiple STP configurations (or trees). Ports can then be assigned to 10 to 60 ALLOWED RANGE 1 to 65535 1 to 65535 1 to 65535 1 to 65535 MES3500-24/24F User’s Guide 122
RANGE 3 to 10 1 to 5 ALLOWED RANGE 1 to 65535 1 to 65535 On each bridge, the bridge communicates with the root through the root port. The root port is the port on this Switch with the lowest processed. All information frames are received and forwarded. MES3500-24/24F User’s Guide 123
MRSTP (Multiple RSTP) is ZyXEL’s proprietary feature that is compatible with RSTP and STP. With MRSTP, you can have more than one spanning tree on your Switch and assign port(s) to each tree. Each as traffic from different VLANs can use distinct paths in a region. 124 MES3500-24/24F User’s Guide
Network Example The following figure shows a network example where two VLANs are configured on the two switches. If the switches are using STP or RSTP, the link for VLAN 2 will be blocked as STP and RSTP region) is increased by one when BPDUs traverse the region. MES3500-24/24F User’s Guide 125
single spanning tree devices. A network may contain multiple MST regions and other network segments running RSTP. Figure 56 MSTP and Legacy RSTP Network Example 126 MES3500-24/24F User’s Guide
Spanning Tree Configuration Use the Spanning Tree Configuration screen to activate one of the STP modes on the Switch. Click Configuration in the Advanced Application > Spanning Tree Protocol. Figure 58 Advanced Application > Spanning Tree Protocol > Configuration MES3500-24/24F User’s Guide 127
122 for background information on STP. Apply Click Apply to save your changes to the Switch’s run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save screen. Figure 59 Advanced Application > Spanning Tree Protocol > RSTP 128 MES3500-24/24F User’s Guide
the priority for each port here. Priority decides which port should be disabled when more than one port forms a loop in a switch. Ports with a higher priority numeric value are disabled first. The allowed range is between 0 and 255 and the default value is 128. MES3500-24/24F User’s Guide 129
port. switch transmits a configuration message. The root bridge determines Hello Time, Max Age and Forwarding Delay. Max Age (second) This is the maximum time (in seconds) a switch can wait without receiving a configuration message before attempting to reconfigure. 130 MES3500-24/24F User’s Guide
. This is the path cost from the root port on this Switch to the root switch. This is the priority and number of the port on the Switch through which this Switch must communicate with the root of the Spanning Tree This is a read-only index number of the STP trees. MES3500-24/24F User’s Guide 131
LAN through that port. It is recommended that you assign this value according to the speed of the bridge. The slower the media, the higher the cost — see Table 25 on page 122 for more information. Select which STP tree configuration this port should participate in. 132 MES3500-24/24F User’s Guide
a switch can wait without receiving a configuration message before attempting to reconfigure. This is the time (in seconds) the root switch will wait before changing states (that is, listening to learning to forwarding). Note: The listening state does not exist in RSTP. MES3500-24/24F User’s Guide
port on the Switch through which this Switch must communicate with the root of the Spanning Tree. Topology Changed This is the number of times the spanning tree has been reconfigured. Times Time Since Last Change This is the time since the spanning tree was last reconfigured. 134 MES3500-24/24F
Advanced Application > Spanning Tree Protocol screen. See Section 13.1.5 on page 124 for more information on MSTP. Figure 63 Advanced Application > Spanning Tree Protocol > MSTP MES3500-24/24F User’s Guide 135
the Switch will be chosen as the root bridge within the spanning tree instance. Enter priority values between 0 and 61440 in increments of 4096 (thus valid values are 4096, 8192, 12288, 16384, 20480, 24576, 28672, 32768, 36864, 40960, 45056, 49152, 53248, 57344 and 61440). 136 MES3500-24/24F User
) to which the MST instance is mapped. This field display the ports configured to participate in the MST instance. Check the rule(s) that you want to remove in the Delete column and then click the Delete button. Click Cancel to begin configuring this screen afresh. MES3500-24/24F User’s Guide 137
run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. 138 MES3500-24/24F User’s Guide
a configuration message before attempting to reconfigure. This is the time (in seconds) the root switch will wait before changing states (that is, listening to learning to forwarding). This is the path cost from the root port on this Switch to the root switch. MES3500-24/24F User’s Guide 139
root switch. Internal Cost Port ID This is the path cost from the root port in this MST instance to the regional root switch. This is the priority and number of the port on the Switch through which this Switch must communicate with the root of the MST instance. 140 MES3500-24/24F User’s Guide
incoming and/or out-going traffic flows on a port. 14.1.1 CIR and PIR The Committed Information Rate port exceeding the CIR will be marked for drop. Note: The CIR should be less than the PIR. Note: The sum of CIRs cannot be greater than or equal to the uplink bandwidth. MES3500-24/24F User’s Guide
bandwidth allowed in kilobits per second (Kbps) for the incoming traffic flow on a port. Select this check box to activate egress rate limits on this port. Specify the maximum bandwidth allowed in kilobits per second (Kbps) for the out-going traffic flow on a port. 142 MES3500-24/24F User’s Guide
memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Cancel Click Cancel to begin configuring this screen afresh. MES3500-24/24F User’s Guide 143
labels in this screen. Table 36 Advanced Application > Broadcast Storm Control LABEL DESCRIPTION Active Select this check box to enable traffic storm control on the Switch. Clear this check box to disable this feature. Port This field displays a port number. MES3500-24/24F User’s Guide 144
run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. MES3500-24/24F User’s Guide 145
. Monitor Port The monitor port is the port you copy the traffic to in order to examine it in more detail without interfering with the traffic flow on the original port(s). Type the port number of the monitor port. Port This field displays the port number. MES3500-24/24F User’s Guide 146
run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. MES3500-24/24F User’s Guide 147
You must connect all ports point-to-point to the same Ethernet switch and configure the ports for LACP trunking. • LACP only works on full-duplex links. • All ports in the same trunk group must have the same media type, speed, duplex mode and flow control settings. MES3500-24/24F User’s Guide 148
activated and there is a port belonging to this group. These are the ports that are currently transmitting data as one logical link in this trunk group. 1. Port Priority and Port Number are 0 as it is the aggregator ID for the trunk group, not the individual port. MES3500-24/24F User’s Guide 149
‘s source and destination IP addresses. This field displays how these ports were added to the trunk group. It displays: • Static — if the ports are configured as static members of a trunk group. • LACP — if the ports are configured to join a trunk group via LACP. 150 MES3500-24/24F User’s Guide
you need to configure to enable static link aggregation. Group ID The field identifies the link aggregation group, that is, one logical link containing multiple ports. Active Select this option to activate a trunk group. MES3500-24/24F User’s Guide 151
address. Port Group Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. 152 MES3500-24/24F User’s Guide
a number to set the priority of an active port using Link Aggregation Control Protocol (LACP). The smaller the number, the higher the priority level. Group ID The field identifies the link aggregation group, that is, one logical link containing multiple ports. MES3500-24/24F User’s Guide 153
Make your physical connections — make sure that the ports that you want to belong to the trunk group are connected to the same destination. The following figure shows ports 2-5 on switch A connected to switch B. Figure 72 Trunking Example — Physical Connections B A 154 MES3500-24/24F User’s Guide
algorithm used by this group and select the ports that should belong to this group as shown in the figure below. Click Apply when you are done. Figure 73 Trunking Example — Configuration Screen EXAMPLE Your trunk group 1 (T1) configuration is now complete. MES3500-24/24F User’s Guide 155
its identity request. When the client 2. At the time of writing, IEEE 802.1x is not supported by all operating systems. See your operating system documentation. If your operating system does not support 802.1x, then you may need to install 802.1x client software. MES3500-24/24F User’s Guide 156
the Switch sends an authentication request to a RADIUS server. The RADIUS server validates whether this client is allowed access to the port. Figure main difference is that the Switch does not prompt the client for login credentials. The login credentials are based MES3500-24/24F User’s Guide 157
AAA > Radius Server Setup screen. To activate a port authentication method, click Advanced Application > Port Authentication in the navigation panel. Select a port authentication method in the screen that appears. Figure 76 Advanced Application > Port Authentication 158 MES3500-24/24F User’s Guide
does not respond to the first authentication request, the Switch tries again. If the client still does not respond to the second request, the Switch sends the client to the Guest VLAN. The client needs to send a new request to be authenticated by the Switch again. MES3500-24/24F User’s Guide 159
re-enter his or her username and password to stay connected to the port. Reauth-period Specify the length of time required to pass before a client switches or routers with the guest network feature. Figure 78 Guest VLAN Example VLAN 100 2 A VLAN 102 Internet 160 MES3500-24/24F User’s Guide
-authenticated users to access limited network resources through the Switch. You must also enable IEEE 802.1x authentication on the Switch and the associated ports. Enter the number that identifies the guest VLAN. Make sure this is a VLAN recognized in your network. MES3500-24/24F User’s Guide 161
. 18.2.3 Activate MAC Authentication Use this screen to activate MAC authentication. In the Port Authentication screen click MAC Authentication to display the configuration screen as shown. Figure 80 Advanced Application > Port Authentication > MAC Authentication 162 MES3500-24/24F User’s Guide
run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. MES3500-24/24F User’s Guide 163
default, MAC address learning is still enabled even though the port security is not activated. 19.2 Port Security Setup Click Advanced Application > Port Security in the navigation panel to display the screen as shown. Figure 81 Advanced Application > Port Security MES3500-24/24F User’s Guide 164
run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. MES3500-24/24F User’s Guide 165
to configure the packet classifier on the Switch. 20.1 About the Classifier and QoS Quality of Service (QoS) refers to both a network’s traffic from the same protocol port (such as Telnet) to form a flow. Configure QoS on the Switch to group and prioritize MES3500-24/24F User’s Guide 166
rule to all MAC addresses. To specify a source, select the second choice and type a MAC address in valid MAC address format (six hexadecimal character pairs). MES3500-24/24F User’s Guide 167
enter a TCP/UDP protocol port number. Add Cancel Clear Click Add to insert the entry in the summary table below and save your changes to the Switch’s run-time memory. The Switch loses these changes if it is settings of a rule, click a number in the Index field. 168 MES3500-24/24F User’s Guide
X.25 Level 3 0805 XNS Compat 0807 Banyan Systems 0BAD BBN Simnet 5208 IBM SNA 80D5 AppleTalk AARP 80F3 Some of the most common IP ports are: Table 50 Common IP Ports PORT NUMBER PORT NAME 21 FTP 23 Telnet 25 SMTP 53 DNS 80 HTTP 110 POP3 MES3500-24/24F User’s Guide 169
00:50:ba:ad:4f:81 on port 2. Figure 84 Classifier: Example EXAMPLE After you have configured a classifier, you can configure a policy to define action(s) on the classified traffic flow. See Chapter 21 on page 171 for information on configuring a policy rule. 170 MES3500-24/24F User’s Guide
is going. 21.1.2 DSCP and Per-Hop Behavior DiffServ defines a new DS (Differentiated Services) field to replace the Type of Service (TOS) field in the IP header. The DS field contains a 2-bit unused field . Refer to Section 20.2 on page 166 for more information. MES3500-24/24F User’s Guide 171
fields below for this policy. You only have to set the field(s) that is related to the action(s) you configure in the Action field. 172 MES3500-24/24F User’s Guide
DESCRIPTION Type the number of an outgoing port. Specify a priority level. Specify a DSCP (DiffServ Code Point) number between 0 and 63. Specify the type of service (TOS) priority level. You can Click Clear to set the above fields back to the factory defaults. MES3500-24/24F User’s Guide 173
this policy applies. Delete Click Delete to remove the selected entry from the summary table. Cancel Click Cancel to clear the Delete check boxes. 174 MES3500-24/24F User’s Guide
Chapter 21 Policy Rule 21.4 Policy Example The figure below shows an example Policy screen where you configure a policy to limit bandwidth on a traffic flow classified using the Example classifier (refer to Section 20.4 on page 170). Figure 87 Policy Example MES3500-24/24F User’s Guide EXAMPLE 175
is 2, for Q2 is 3, and so on. The weights range from 1 to 15 and the actual guaranteed bandwidth is calculated as follows: 2(Weight -1) x 10 KB If the weight setting is 5, the actual quantum guaranteed to the associated queue would be as follows: 24 x 10KB = 160 KB MES3500-24/24F User’s Guide 176
amount of bandwidth. WRR is activated only when a port has more traffic than it can handle. Queues with larger weights get more service than queues with smaller weights. This queuing mechanism is the navigation panel. Figure 88 Advanced Application > Queuing Method MES3500-24/24F User’s Guide 177
run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. 178 MES3500-24/24F User’s Guide
, both A and B are Service Provider’s Network (SPN) customers with VPN tunnels between their head offices and branch offices respectively. Both have an identical VLAN tag for their VLAN group. The service provider can separate these two VLANs within its network by MES3500-24/24F User’s Guide 179
network. All VLANs belonging to a customer can be aggregated into a single service provider’s VLAN (using the outer VLAN tag defined by the Service Provider’s (SP) VLAN ID (VID)). Note: Static VLAN Tx Tagging MUST be enabled on a port where you choose Tunnel Port. 180 MES3500-24/24F User’s Guide
stacking port role is Access Port, then the Switch adds the SP TPID tag to all incoming frames on the service provider’s Service Provider) Tag Protocol IDentifier Data VID VLAN ID FCS 802.1p Priority Length and type of Ethernet frame Frame data Frame Check Sequence MES3500-24/24F User’s Guide
-tagged. The value of this field is 0x8100 as defined in IEEE 802.1Q. If the Switch needs to communicate with other vendors’ devices, they should use the same TPID. Note: You can define up to four different tunnel TPIDs (including 8100) in this screen at a time. 182 MES3500-24/24F User’s Guide
run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. MES3500-24/24F User’s Guide 183
based. It allows the Switch to add different outer VLAN tags to the incoming frames received on one port according to their inner from 0 to 7). This is the service provider’s priority level that adds to the frames received on this port. Add Cancel Index «0» is the lowest MES3500-24/24F User’s Guide
for this rule. Port This is the port number to which this service provider’s priority level in the packets. Delete Check the rule(s) that you want to remove in the Delete column and then click the Delete button. Cancel Click Cancel to clear the Delete check boxes. MES3500-24/24F User’s Guide
network. IGMP (Internet Group Management Protocol) is a network-layer manually configured) to ports that are members of that group. IGMP snooping generates no additional network traffic, allowing you to significantly reduce multicast traffic passing through your Switch. MES3500-24/24F User’s Guide
as fixed mode. In fixed mode the Switch does not learn multicast group membership of any VLANs other than those explicitly added Port This field displays the port number that belongs to the multicast group. Multicast Group This field displays IP multicast group addresses. MES3500-24/24F User’s Guide
only to ports that are members of that group. Querier Select this option to allow the Switch to port can join. Note: If you enable IGMP filtering, you must create and assign IGMP filtering profiles for the ports that you want to allow to join multicast groups. 188 MES3500-24/24F User’s Guide
to limit the number of multicast groups this port is allowed to join. Enter the number of multicast groups this port is allowed to join. Once a port is registered in the specified number of multicast groups, any new IGMP join report frame(s) is dropped on this port. MES3500-24/24F User’s Guide 189
run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. 190 MES3500-24/24F User’s Guide
add VLANs upon which the Switch is to perform IGMP snooping. Enter the descriptive name of the VLAN for identification purposes. Enter the ID of a static VLAN; the valid range is between 1 and 4094. Note: You cannot configure the same VLAN ID as in the MVR screen. MES3500-24/24F User’s Guide 191
profile. A profile can be assigned to multiple ports. Click Advanced Applications > Multicast > Multicast Setting > IGMP Filtering Profile link to display the screen as shown. Figure 96 Advanced Application > Multicast > Multicast Setting > IGMP Filtering Profile 192 MES3500-24/24F User’s Guide
the Switch’s run-time memory. The Switch loses service provider management. MVR only responds to IGMP join and leave control messages from multicast groups that are configured under MVR. Join and leave reports from other multicast groups are managed by IGMP snooping. MES3500-24/24F User’s Guide
channel or turns off the computer, an IGMP leave message is sent to the Switch to leave the multicast group. The Switch sends a query to VLAN 1 on the receiver port (in this case, an uplink port on the Switch). If there is another subscriber device connected to this 194 MES3500-24/24F User’s Guide
the receiver port(s) and a source port for each multicast VLAN. Click Advanced Applications > Multicast > Multicast Setting > MVR link to display the screen as shown next. Note: You can create up to five multicast VLANs and up to 256 multicast rules on the Switch. MES3500-24/24F User’s Guide 195
all ports. Use this row only if you want to make some settings the same for all ports. Use this row first to set the common settings and then make adjustments on a port-by-port basis. Note: Changes in this row are copied to all the ports as soon as you make them. 196 MES3500-24/24F User’s Guide
Configuration All source ports and receiver ports belonging to a multicast group can receive multicast data sent to this multicast group. Configure MVR IP multicast group address(es) in the Group Configuration screen. Click Group Configuration in the MVR screen. MES3500-24/24F User’s Guide 197
the checkbox(es) in the table. 24.8.1 MVR Configuration Example The following figure shows a network example where ports 1, 2 and 3 on the Switch belong to VLAN 1. In addition, port 7 belongs to the multicast group with VID 200 to receive multicast traffic (the 198 MES3500-24/24F User’s Guide
A B 3 News: 224.1.4.10
224.1.4.50 Multicast VID 200 Movie: 230.1.2.50
230.1.2.60 7 S C To configure the MVR settings on the Switch, create a multicast group in the MVR screen and set the receiver and source ports. Figure 102 MVR Configuration Example EXAMPLE MES3500-24/24F User’s Guide 199
Chapter 24 Multicast To set the Switch to forward the multicast group traffic to the subscribers, configure multicast group settings in the Group VLAN 200. Figure 103 MVR Group Configuration Example Figure 104 MVR Group Configuration Example EXAMPLE 200 EXAMPLE MES3500-24/24F User’s Guide
By storing user profiles locally on the Switch, your Switch is able to authenticate and authorize users without interacting with a network AAA server. However, there is a limit on the number of users you may authenticate in this way (See Chapter 38 on page 290). MES3500-24/24F User’s Guide 201
AAA screens allow you to enable authentication, authorization, accounting or all of them on the Switch. First, configure your authentication and accounting server settings (RADIUS, TACACS+ or both) and Section 25.3 on page 210 for RADIUS attributes utilized by the 202 MES3500-24/24F User’s Guide
multiple RADIUS servers. Select index-priority and the Switch tries to authenticate with the first configured RADIUS server, port of a RADIUS server for authentication is 1812. You need not change this value unless your network administrator instructs you to do so. MES3500-24/24F User’s Guide
memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Cancel Click Cancel to begin configuring this screen afresh. 204 MES3500-24/24F User’s Guide
then the Switch waits for a response from the first TACACS+ server for 15 seconds and then tries the second TACACS+ server. This is a read-only number representing a TACACS+ server entry. Enter the IP address of an external TACACS+ server in dotted decimal notation. MES3500-24/24F User’s Guide 205
memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Cancel Click Cancel to begin configuring this screen afresh. 206 MES3500-24/24F User’s Guide
access privilege level specify them in Method 2 and Method 3 fields. Select local to have the Switch check the access privilege configured for local authentication. Select radius or tacacs+ to have the Switch check the access privilege via the external servers. MES3500-24/24F User’s Guide 207
servers at the same time. If you don’t select this and you have two accounting servers set up, then the Switch sends information to the first accounting server and if it doesn’t get a response from the accounting server then it tries the second accounting server. 208 MES3500-24/24F User’s Guide
Switch supports VSAs that allow you to perform the following actions based on user authentication: • Limit bandwidth on incoming or outgoing traffic for the port the user connects to. • Assign account privilege levels (see the CLI Reference Guide the RADIUS server. MES3500-24/24F User’s Guide 209
Remote Authentication Dial-In User Service (RADIUS) attributes are data used to define specific authentication, and accounting elements in a user profile, which is stored on the RADIUS server. This section lists the RADIUS attributes supported by the Switch. 210 MES3500-24/24F User’s Guide
is set to Ethernet(15) on the Switch. Calling-Station-Id Frame-MTU EAP-Message State Message-Authenticator 25.3.2 Attributes Used for Accounting The following sections list the attributes sent from the Switch to the RADIUS server when performing authentication. MES3500-24/24F User’s Guide 211
INTERIM-UPDATE User-Name NAS-Identifier NAS-IP-Address Service-Type Calling-Station-Id Acct-Status-Type Acct-Delay-Time Acct-Session-Id Acct-Authentic Acct-Session-Time Acct-Terminate-Cause STOP 212 MES3500-24/24F User’s Guide
-UPDATE NAS-IP-Address NAS-Port Class Called-Station-Id Calling-Station-Id NAS-Identifier NAS-Port-Type Acct-Status-Type Acct-Terminate-Cause Acct-Input-Gigawords Acct-Output-Gigawords STOP MES3500-24/24F User’s Guide 213
port is either a trusted port or an untrusted port for DHCP snooping. This setting is independent of the trusted/untrusted setting for ARP inspection. You can also specify the maximum number for DHCP packets that each port (trusted or untrusted) can receive each second. MES3500-24/24F User’s Guide
if you enable DHCP snooping and there are no trusted ports. Untrusted ports are connected to subscribers. The Switch discards DHCP packets from untrusted ports in the following situations: • The packet is a DHCP that binding and all others after it are ignored. MES3500-24/24F User’s Guide 215
provides the DHCP server more information about the source of the requests. The Switch can add the following information: • Slot ID (1 byte), port ID (1 byte), and source VLAN ID (2 bytes) • System name for computer A. Then, computer X does the following things: 216 MES3500-24/24F User’s Guide
day before you enable ARP inspection so that the Switch has enough time to build the binding table. 2 Enable ARP inspection on each VLAN. 3 Configure trusted and untrusted ports, and specify the maximum number of ARP packets that each port can receive per second. MES3500-24/24F User’s Guide 217
to manage static bindings for DHCP snooping and ARP inspection. Static bindings are uniquely identified by the MAC address and VLAN ID. Each MAC address and VLAN ID can only be in one static binding. If you try to create a static binding with the same MAC address and VLAN 218 MES3500-24/24F User
displays the source VLAN ID in the binding. This field displays the port number in the binding. If this field is blank, the binding applies to all ports. Select this, and click Delete to remove the specified entry. Click this to clear the Delete check boxes above. MES3500-24/24F User’s Guide 219
in the DHCP Snooping Configure screen. See Section 26.5 on page 222. Agent URL This field displays the location of the DHCP snooping database. 220 MES3500-24/24F User’s Guide
writes This field displays the number of times the Switch was unable to update the bindings in the DHCP snooping database. Database detail First successful access This field displays the first time the Switch accessed the DHCP snooping database for any reason. MES3500-24/24F User’s Guide 221
enable DHCP snooping on the Switch (not on specific VLAN), specify the VLAN where the default DHCP server is located, and configure the DHCP snooping database. The DHCP snooping database stores the current bindings on a secure, external TFTP server so that they are 222 MES3500-24/24F User’s Guide
how long (10-65535 seconds) the Switch waits to update the DHCP snooping database the first time the current bindings change after an update. Once the next update is scheduled, additional changes in current bindings are automatically included in the next update. MES3500-24/24F User’s Guide 223
. You can also specify the maximum number for DHCP packets that each port (trusted or untrusted) can receive each second. To open this screen, click Advanced Application > IP Source Guard > DHCP Snooping > Configure > Port. Figure 116 DHCP Snooping Port Configure 224 MES3500-24/24F User’s Guide
the labels in this screen. Table 80 DHCP Snooping VLAN Configure LABEL DESCRIPTION Show VLAN Use this section to specify the VLANs you want to manage in the section below. Start VID Enter the lowest VLAN ID you want to manage in the section below. MES3500-24/24F User’s Guide 225
reset the values in this screen to their last-saved values. 26.6 ARP Inspection Status Use this screen to look at the current list of MAC address filters that were created because the Switch . Port This field displays the source port of the discarded ARP packet. 226 MES3500-24/24F User’s Guide
specified above. Received This field displays the total number of ARP packets received from the VLAN since the Switch last restarted. Request This field displays the total number of ARP Request packets received from the VLAN since the Switch last restarted. MES3500-24/24F User’s Guide 227
Port This field displays the source port Switch consolidates identical log messages generated by ARP packets in the log consolidation interval into one log message. You can configure this interval in the ARP Inspection Configure screen. See Section 26.7 on page 229. 228 MES3500-24/24F User’s Guide
also configure the length of time the Switch stores records of discarded ARP packets and global settings for the ARP inspection log. To open this screen, click Advanced Application > IP Source Guard > ARP Inspection > Configure. Figure 121 ARP Inspection Configure MES3500-24/24F User’s Guide 229
to their last-saved values. 26.7.1 ARP Inspection Port Configure Use this screen to specify whether ports are trusted or untrusted ports for ARP inspection. You can also specify the maximum rate at which the Switch receives ARP packets on each untrusted port. To 230 MES3500-24/24F User’s Guide
Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click this to reset the values in this screen to their last-saved values. MES3500-24/24F User’s Guide 231
Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click this to reset the values in this screen to their last-saved values. 232 MES3500-24/24F User’s Guide
affected by the switch in loop state in the following way: • It will receive broadcast messages sent out from the switch in loop state. • It will receive its own broadcast messages that it sends out as they loop back. It will then rebroadcast those messages again. MES3500-24/24F User’s Guide 233
example, the probe packet is sent from port N and returns on another port. As long as loop guard is enabled on port N. The Switch will shut down port N if it detects that the probe packet has returned to the Switch. Figure 127 Loop Guard — Network Loop A P P N P 234 MES3500-24/24F User’s Guide
port. The Switch sends probe packets from this port to check if the Switch it is connected to is in loop state. If the Switch that this port is connected is in loop state the Switch will shut down this port. Clear this check box to disable the loop guard feature. MES3500-24/24F User’s Guide 235
memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Cancel Click Cancel to begin configuring this screen afresh. 236 MES3500-24/24F User’s Guide
forwarding the packets. Any packets carrying a VLAN tag other than 12 (such as 10) and received on port 3 will be forwarded in the individual VLAN network respectively (such as VLAN 10). Figure 129 VLAN mapping example 12 10 Port 3 123 Service Provider Network 10 MES3500-24/24F User’s Guide 237
run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. 238 MES3500-24/24F User’s Guide
reset the fields to your previous configuration. Index This is the number of the VLAN mapping entry in the table. Active This shows whether this entry is activated or not. Name This is the descriptive name for this rule. Port This is the port check boxes. MES3500-24/24F User’s Guide 239
Chapter 28 VLAN Mapping 240 MES3500-24/24F User’s Guide
example, if you enable L2PT for STP, you can have switches A, B, C and D in the same spanning tree, even though switch A is not directly connected to switches B, C and D. Topology change information can be propagated throughout the service provider’s network. MES3500-24/24F User’s Guide 241
tunnel ports. • The Tunnel port is an egress port at the edge of the service provider’s network and connected to another service provider’s switch. Incoming encapsulated layer-2 protocol packets received on a tunnel port are decapsulated and sent to an access port. 242 MES3500-24/24F User’s Guide
-by-port basis. CDP Note: Changes in this row are copied to all the ports as soon as you make them. Select this option to have the Switch tunnel CDP (Cisco Discovery Protocol) packets so that other Cisco devices can be discovered through the service provider’s network. MES3500-24/24F User’s Guide
run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. 244 MES3500-24/24F User’s Guide
monitor network traffic and create reports for network performance analysis and troubleshooting. For example, you can use it to know which IP address or which type of traffic caused network congestion. Figure 135 sFlow Application sFlow Agent sFlow Collector MES3500-24/24F User’s Guide 245
(N) from 256 to 65535. The Switch captures every one out of N packets for this port and creates sFlow datagram. Specify a time interval (from 20 to 120 in seconds) the Switch waits before sending the sFlow datagram and packet counters for this port to the collector. 246 MES3500-24/24F User’s Guide
Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Cancel Click Cancel to reset the fields to your previous configuration. MES3500-24/24F User’s Guide 247
UDP Port This field displays port number the Switch uses to send sFlow datagram to the collector. Delete Check the rule(s) that you want to remove in the Delete column and then click the Delete button. Cancel Click Cancel to begin configuring this screen afresh. 248 MES3500-24/24F User’s Guide
port-per-VLAN basis before forwarding them to the PPPoE server. PPPoE Client PPPoE IA PPPoE Server 31.1.1 PPPoE Intermediate Agent Tag Format If the PPPoE Intermediate Agent is enabled, the Switch SubOpt 0x01 (1 byte) Length N (1 byte) String (63 bytes) Value MES3500-24/24F User’s Guide 249
Switch takes the Circuit ID string you manually configure for a VLAN on a port as the highest priority and the Circuit ID string for a port as the second priority. In addition, the Switch remote ID) that the Switch adds to PADI and PADR packets from PPPoE clients. 250 MES3500-24/24F User’s Guide
untrusted port, the Switch adds a vendor-specific tag to the packet and then forwards it to the trusted port(s). • The Switch Switch to give a PPPoE termination server additional subscriber information that the server can use to identify and authenticate a PPPoE client. MES3500-24/24F User’s Guide
The Switch enters a zero into the PADI and PADR packets for the slot value. Select a delimiter to separate the identifier-string, slot ID, port number and/or VLAN ID from each other. You can use a pound key (#), semi-colon (;), period (.), comma (,), forward slash (/) or space. 252 MES3500-24/24F
DESCRIPTION Port This field displays the port number. * Use this row to make the setting the same for all ports. Use this row first and then make adjustments on a port-by-port basis. Note: Changes in this row are copied to all the ports as soon as you make them. MES3500-24/24F User’s Guide
client but received on a trusted port, the Switch forwards it to other trusted port(s). Untrusted ports are downlink ports connected to subscribers. Circuit-id • Port Per-VLAN Use this screen to configure PPPoE IA settings that apply to a specific VLAN on a port. 254 MES3500-24/24F User’s Guide
run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. MES3500-24/24F User’s Guide 255
run-time memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Click Cancel to begin configuring this screen afresh. 256 MES3500-24/24F User’s Guide
you need to enable the port(s) or allow the packets on a port manually via the web configurator or the commands. With error-disable recovery, you can set the disabled port(s) to become active or start receiving the packets again after the time interval you specify. MES3500-24/24F User’s Guide 257
the maximum number of control packets (ARP, BPDU and/or IGMP) that the Switch can receive or transmit on a port. Click the Click Here link next to CPU protection in the Advanced Application > screen. Figure 144 Advanced Application > Errdisable > CPU protection 258 MES3500-24/24F User’s Guide
Use screen to have the Switch detect whether the control packets exceed the rate limit configured for a port and configure the action to Switch detect if the configured rate limit for a specific control packet is exceeded and take the action selected below. MES3500-24/24F User’s Guide 259
the error-disable recovery function on the Switch. Reason This field displays the supported features that allow the Switch to shut down a port or discard packets on a port according to the feature requirements and what to all the entries as soon as you make them. 260 MES3500-24/24F User’s Guide
memory. The Switch loses these changes if it is turned off or loses power, so use the Save link on the top navigation panel to save your changes to the non-volatile memory when you are done configuring. Cancel Click Cancel to begin configuring this screen afresh. MES3500-24/24F User’s Guide 261
port 25. Figure 147 Private VLAN Example 2 3 25 VLAN 123 Isolated ports: 1
Источник