Intellinet 561198 User Manual
Displayed below is the user manual for 561198 by Intellinet which is a product in the Network Switches category. This manual has pages.
Related Manuals
16‐PORTGIGABITETHERNETPOE+WEB‐
MANAGEDSWITCHWITH2SFPPORTS
UserManual
Model561198
INT‐561198‐UM‐0517‐1
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
2
1 TABLEOFCONTENTS
2ProductIntroduction........................................................................................................................................4
2.1ProductOverview................................................................................................................................................4
2.2Features...............................................................................................................................................................4
2.3Specifications.......................................................................................................................................................5
2.4ExternalComponentDescription.......................................................................................................................6
2.4.1FrontPanel................................................................................................................................................................6
2.4.2RearPanel.................................................................................................................................................................8
2.5PackageContents................................................................................................................................................8
3InstallingandConnectingtheSwitch...............................................................................................................9
3.1DesktopInstallation.............................................................................................................................................9
3.2Rack‐mountableInstallationin19‐inchCabinet................................................................................................9
3.3PowerontheSwitch.........................................................................................................................................10
4ConnectiontotheSwitch...............................................................................................................................11
4.1ConnectingComputer.......................................................................................................................................11
4.2HowtoLogintotheSwitch..............................................................................................................................11
5SavingtheConfiguration................................................................................................................................13
6SwitchConfiguration......................................................................................................................................14
6.1Home..................................................................................................................................................................14
6.1.1PortInformation.....................................................................................................................................................14
6.2QuickSetup........................................................................................................................................................16
6.3PortSettings......................................................................................................................................................17
6.3.1BasicConfig.............................................................................................................................................................17
6.3.2PortAggregation.....................................................................................................................................................19
6.3.3PortMirroring.........................................................................................................................................................20
6.3.4Portspeedlimit.......................................................................................................................................................21
6.3.5Broadcaststorm......................................................................................................................................................22
6.3.6Portisolation...........................................................................................................................................................23
6.4VLAN...................................................................................................................................................................26
6.4.1TrunkPortSettings.................................................................................................................................................28
6.4.2HybridPortSettings................................................................................................................................................29
6.4.3SetupExample........................................................................................................................................................30
6.5Fault/Safety........................................................................................................................................................33
6.5.1AntiAttack..............................................................................................................................................................33
6.5.2ChannelDetection..................................................................................................................................................40
6.5.3ACLAccessControlList...........................................................................................................................................42
6.6PoweroverEthernet(PoE)...............................................................................................................................45
6.6.1PoEConfiguration...................................................................................................................................................45
6.6.2PoEPortConfiguration...........................................................................................................................................47
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
3
6.6.3PoEDelayConfig.....................................................................................................................................................49
6.7SpanningTreeProtocol(STP)...........................................................................................................................50
6.7.1MSTPRegion...........................................................................................................................................................53
6.7.2MSTPBridge............................................................................................................................................................54
6.8DHCPRelayAgent..............................................................................................................................................56
6.8.1DHCPRelay.............................................................................................................................................................56
6.8.2Option82.................................................................................................................................................................56
6.9DHCPServer.......................................................................................................................................................58
6.9.1DHCPConfig............................................................................................................................................................58
6.10IGMPSnooping..................................................................................................................................................61
6.10.1IGMPConfig............................................................................................................................................................62
6.10.2IGMPFilterPolicyConfig........................................................................................................................................64
6.11TerminalAccessControllerAccess‐ControlSystem(TACACS+)......................................................................65
6.12Radius.................................................................................................................................................................67
6.12.1RadiusGeneralConfig.............................................................................................................................................67
6.12.2RadiusServerConfig...............................................................................................................................................68
6.13AAA.....................................................................................................................................................................69
6.13.1EnableConfig..........................................................................................................................................................69
6.13.2RegionConfig..........................................................................................................................................................69
6.13.3ServerConfig...........................................................................................................................................................70
6.13.4AAAAuthentication................................................................................................................................................71
6.14QoS–QualityofService....................................................................................................................................73
6.14.1QoSRules................................................................................................................................................................73
6.14.2QueueConfig..........................................................................................................................................................74
6.14.3QueueMapping......................................................................................................................................................75
6.15AddressTable....................................................................................................................................................76
6.15.1AddressTableConfig..............................................................................................................................................76
6.16SNMP..................................................................................................................................................................78
6.16.1SNMPConfig...........................................................................................................................................................78
6.16.2RMONConfig..........................................................................................................................................................83
6.17System................................................................................................................................................................87
6.17.1SystemConfig.........................................................................................................................................................87
6.17.2SystemUpdate........................................................................................................................................................91
6.17.3ConfigurationManagement...................................................................................................................................92
6.17.4ConfigSave..............................................................................................................................................................93
6.17.5UserAccounts.........................................................................................................................................................93
6.17.6InformationCollect.................................................................................................................................................94
7Warranty.........................................................................................................................................................95
8Copyright........................................................................................................................................................96
9FederalCommunicationCommissionInterferenceStatement.....................................................................97
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
4
2 PRODUCTINTRODUCTION
Congratulationsonyourpurchaseofthe16‐PortPoE+Web‐ManagedPoE+GigabitEthernetSwitch.Beforeyouinstall
andusethisproduct,readthismanualcarefullyforafullunderstandingofitsfunctions.
2.1 PRODUCTOVERVIEW
TheWeb‐ManagedGigabitEthernetSwitchprovidesseamlessnetworkconnections.Itintegrates1000MbpsGigabit
Ethernet,100MbpsFastEthernetand10MbpsEthernetnetworkcapabilitiesinahighlyflexiblepackage.Eachofthe16
10/100/1000MbpsAuto‐NegotiationRJ45portssupportAutoMDI/MDIXfunction.Theswitchisahigh‐performance
upgradefromyouroldnetworktoa1000MbpsGigabitnetwork.Itisessentialinsolvingnetworkbottlenecksthat
frequentlydevelopasmoreadvancedcomputerusersandnewerapplicationsdemandgreaternetworkresources.For
efficientmanagement,theswitchisequippedwitharemoteWebinterface.Theswitchcanbeprogrammedfor
advancedmanagementfunctionssuchasPortManagement,LinkAggregation,VLAN,SpanningTree,Multicast,QoS,
Security,AccessControl,MACAddressTable,Diagnostics,RMONandMaintenance.ItsPoEportscanautomatically
detectandsupplypowertoIEEE802.3at‐compliantPoweredDevices(PD)suchasWirelessAccessPoints,network
camerasorVoiceoverIPphones.
2.2 FEATURES
•
Providespoweranddataconnectionforupto16
PoEnetworkdevices
•
Saveinstallationcostsbydeliveringdataandpoweroverexistingnetworkcables
•
IEEE802.3at/af‐compliantRJ45PoE
/
PoE+outputports
•
PoEpowerbudgetof374watts
•
Poweroutputupto30wattsperport
•
SupportsIEEE802.3at/afdetectionandshortcircuit,overloadandhigh‐voltageprotection
•
SupportsSNMPmanagement
•
Twosmallform‐factorpluggableGBICmoduleslots(SFP)
•
SupportsVLAN(tag‐basedandport‐based)
•
ProvidesIEEE802.1xport‐basedsecurity
•
Supportslinkaggregation(trunking
)
•
Supportsportmirroring
•
Supportsjumboframesupto9kBytes
•
SupportsRapidSpanningTree/SpanningTreeprotocol
•
Broadcaststormcontrolwithmulticastpacketratesettings
•
SupportstwotypesofQoS:port‐basedandDSCP
•
LEDsforpower,link/activityandPoE
•
Includes19"rackmountbrackets
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
5
2.3 SPECIFICATIONS
Standards
•IEEE802.1d(SpanningTreeProtocol)
•IEEE802.1p(TrafficPrioritization)
•IEEE802.1q(VLANTagging)
•IEEE802.1w(RapidSpanningTreeProtocol)
•IEEE802.3ad(LinkAggregation)
•IEEE802.3(10Base‐TEthernet)
•IEEE802.3ab(TwistedPairGigabitEthernet)
•IEEE802.3ad(LinkAggregationControlProtocolLACP)
•IEEE802.3az(EnergyEfficientEthernetEEE)
•IEEE802.3af(PoweroverEthernet802.3atType1)
•IEEE802.3at(PoweroverEthernet802.3atType2)
•IEEE802.3u(100Base‐TXFastEthernet)
•IEEE802.3x(flowcontrol,forfullduplexmode)
Power
•Input:90–260VAC,50–60Hz
•Powerconsumption:410watts(maximum)
Environmental
•Metalhousing
•Dimensions:440(L)x208(W)x44(H)[mm] (17.32(L)x8.19(W)x1.73(H)[in])
•Weight:2.5kg(5.5lbs.)
•Operatingtemperature:0–40°C(32–104°F)
•Operatinghumidity:10–90%RH,non‐condensing
•Storagetemperature:‐20–90°C(‐4–194°F)
PackageContents
•16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwithTwoSFPPorts
•Powercable
•Usermanual
•19"rackmountbrackets
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
6
2.4 EXTERNALCOMPONENTDESCRIPTION
2.4.1 FrontPanel
Thefrontpaneloftheswitchconsistsof1610/100/1000MbpsRJ‐45ports,twoSFPports,oneConsoleport,one
ResetbuttonandaseriesofLEDindicatorsasshownbelow.
10/100/1000MbpsRJ‐45ports(1~16):
Designedtoconnecttothedevicewithabandwidthof10Mbps,100Mbpsor1000Mbps.Eachhasacorresponding
10/100/1000MbpsLED.
SFPports(SFP1,SFP2):
DesignedtoinstalltheSFPmoduleandconnecttothedevicewithabandwidthof1000Mbps.Bothportshavea
corresponding1000MbpsLED.
Consoleport(Console):
Designedtoconnectwiththeserialportofacomputerorterminalformonitoringandconfiguringtheswitch.
Resetbutton(Reset):
Torestorethesystemfactorydefaultsettings,presstheresetbuttonforfivesecondswhilethedeviceispoweredon.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
7
LEDindicators:
TheLEDindicatorswillallowyoutomonitor,diagnoseandtroubleshootanypotentialproblemwiththeswitch,its
connectionorattacheddevices.
ThefollowingchartshowstheLEDindicatorsoftheswitchalongwithexplanationofeachindicator.
LED COLOR STATUS STATUSDESCRIPTION
Power Red On PowerOn
Off PowerOff
LINK/ACT/
Speed
(1~16)
10/100Mbps:
Amber
On Adeviceisconnectedtotheport
Off Nodeviceisconnectedtotheport
1000Mbps:
Green
Flashing Sendingorreceivingdata
SFP1
SFP2
Green On Adeviceisconnectedtotheport
Off Nodeviceisconnectedtotheport
Flashing Sendingorreceivingdata
POE Orange On AnIEEE802.3af/at‐compliantpowereddevice(PD)is
connectedtotheport,andthePoEswitchsupplies
powersuccessfully.
Off Nopowereddeviceisconnectedtotheport.
Flashing
TheremaybeashortcircuitorPoEpower
overload.Disconnectthedevicefromthisport
immediately.
Reset
Pressfor15seconds–20secondsinorderto
resetallsettingstofactorydefaultvalues.
Releasethebutton,oncetheLEDsstartflashing.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
8
2.4.2 RearPanel
ACPowerConnector:
PowerissuppliedthroughanexternalACpoweradapter.ItsupportsAC100‐240V,50/60Hz.
GroundingTerminal:
GroundtheswitchthroughthePEcableontheACcordorwithaseparategroundwire.
2.5 PACKAGECONTENTS
Beforeinstallingtheswitch,makesurethatthefollowingitemsareenclosed.Ifanypartismissingordamaged,contact
yourIntellinetagentimmediately.
• 16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
• Powercable
• QuickInstallationGuide
• Usermanual(onCD)
• Twomountingearsandeightsscrews
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
9
3 I
NSTALLINGAND
C
ONNECTINGTHE
S
WITCH
ThischapterdescribeshowtoinstallyourWeb‐ManagedGigabitEthernetPoE+Switchandmakeconnectionstoit.The
followingstepswillhelppreventdamagetothedeviceandmaintainpropersecurity:
Placetheswitchonastablesurfaceordesktoptominimizethechancesofitfalling.
MakesuretheswitchworksintheproperACinputrangeandmatchesthevoltagelabeledontheswitch.
Topreventelectrocution,donotopentheswitch’schassis,evenifitfailstoreceivepower.
Makesurethatthereisproperheatdissipationfromandadequateventilationaroundtheswitch.
Makesurethesurfaceonwhichtheswitchisplacedcansupporttheweightoftheswitchanditsaccessories.
3.1 D
ESKTOP
I
NSTALLATION
Wheninstallingtheswitchonadesktop(ifnotinarack),attachtheenclosedrubberfeettothebottomcornersofitto
minimizevibration.Allowadequatespaceforventilationbetweenthedeviceandtheobjectsaroundit.
Figure4‐DesktopInstallation
3.2 R
ACK
‐
MOUNTABLE
I
NSTALLATIONIN
19‐
INCH
C
ABINET
TheswitchcanbemountedinanEIAstandard‐sized,19‐inchrack,whichcanbeplacedinawiringclosetwithother
equipment.Toinstalltheswitch,follow these steps:
Attachthemountingbracketsontheswitch’ssidepanels(oneoneachside)andsecurethemwiththescrewsprovided.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
10
Figure5‐BracketInstallation
Usethescrewsprovidedwiththeequipmentracktomounttheswitchontherackandtightenit.
Figure6‐RackInstallation
3.3 P
OWERONTHE
S
WITCH
TheswitchispoweredonbyconnectingittoanoutletusingtheAC100‐240V50/60Hzinternalhigh‐performancepower
supply.
ACElectricalOutlet:
Itisrecommendedtouseasingle‐phase,three‐wirereceptaclewithaneutraloutletormultifunctionalprofessional
receptacle.Besuretoconnectthemetalgroundconnectortothegroundingsourceontheoutlet.
ACPowerCordConnection:
ConnecttheACpowerconnectoronthebackpaneloftheswitchtoanexternalreceptaclewiththeincludedpowercord,
thencheckthatthepowerindicatorisON.WhenitisON,thecorrespondingLEDisilluminated.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
11
4 CONNECTIONTOTHESWITCH
4.1 CONNECTINGCOMPUTER
UsestandardCat5/5eEthernetcables(UTP/STP)toconnecttheswitchtoendnodesasdescribedbelow.Switchports
willautomaticallyadjusttothecharacteristics(MDI/MDI‐X,speed,duplex)ofthedevicetowhichtheyareconnected.
Figure7‐PCConnect
TheLNK/ACT/SpeedLEDsforeachportareilluminatedwhenthelinkisavailable.
4.2 HOWTOLOGINTOTHESWITCH
AstheswitchprovidesWeb‐basedmanagementlogin,configureyourcomputer’sIPaddressmanuallytologontothe
switch.Thedefaultsettingsoftheswitchareshownbelow.
Parameter DefaultValue
DefaultIPaddress 192.168.2.1
DefaultUsername admin
DefaultPassword 1234
Logontotheconfigurationwindowoftheswitchthroughfollowingsteps:
1. ConnecttheswitchwiththecomputerNICinterface.
2. Powerontheswitch.
3. CheckwhethertheIPaddressofthecomputeriswithinthisnetworksegment:192.168.2.xxx(“xxx”rangeis2‐
254);forexample,192.168.2.100.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
12
Openthebrowser,andgototheURLhttp://192.168.2.1.Theswitchloginwindowappears,asshownbelow.
EntertheUsernameandPassword(thefactorydefaultUsernameisadminandthePasswordis1234),andthenclick
“LOGIN”tologintotheswitchconfigurationwindowasbelow.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
13
5 SAVINGTHECONFIGURATION
The Intellinet 16‐PortGigabitEthernetPoE+Web‐ManagedSwitchprovidesamyriadofconfigurationoptions,manyof
whicharedesignedforexperiencednetworkadministratorsandaren’teasytoconfigure.Itwouldbearealshameifall
theconfigurationdatawaslostafterapowerfailureoraftertheswitchwasrestarted.Inordertomaketheconfiguration
permanent,itneedstobesaved.
Hereishow:
Ifyoudonotperformthisfunction,yourisklosingallthesettingsaftertheswitchrestarts.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
14
6 SWITCHCONFIGURATION
Thischapterdescribeshowtousetheweb‐basedmanagementinterface(WebUI)forthisswitch.
6.1 HOME
6.1.1 PortInformation
AgreensquaresindicatetheportlinkisupatGigabitspeeds(port1intheexampleabove).Aredsquaresindicatesthata
PoEdeviceisconnected(port2).Agraysquaresindicatetheportlinkisdown.
6.1.1.1 PortInformation,EquipmentConfigurationandPortStatistics
Thissectionprovidesreal‐timeinformationabouttheports,basicsettingsandtrafficstatistics.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
15
Item Description
PortInformation Displaystheportnumber.Thenomenclatureisasfollows:
Gi=GigabitEthernet
0/=Switch0(whichmeansthisdevice)
1‐18=Portnumber.Ports17and18areSFPmoduleslots.
Description Optionaldescriptionfortheport,asenteredinthebasicportconfiguration.
InputFlow(bps) Inboundtrafficrate,measuredin"bitspersecond.”
OutputFlow(bps) Outboundtrafficrate,measuredin"bitspersecond.”
OpenState ON=Portisactivatedinthebasicportconfigurationandwillacceptconnections
fromnetworkingdevices.
OFF=Portisdeactivatedinbasicportconfiguration.
Status Connect:Anetworkingdeviceisconnectedtotheportandhasanactivelink.
Disconnect:Nodeviceisconnectedtotheport.
VLAN IftheportbelongstoaVLAN,itsIDisdisplayedhere.ID1=default.
TrunkPort Yes=TheportispartofanLACPtrunkinggroup.
No=TheportisnotpartofanLACPtrunkinggroup.
Thistabdisplaysinformationaboutvariousfunctionsandprovidesashort‐cutthatallowsdirectconfigurationofthat
partoftheswitchsettings.
Thistabdisplaysreal‐timeinformationaboutthedatapacketsforeachport.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
16
6.2 QUICKSETUP
TheIntellinet16‐PortGigabitEthernetPoE+Web‐ManagedSwitchprovidesasettingthatoffersdirectaccesstosomeof
thecorefunctionsofthedevice,namelyVLAN,trunking,deviceIPaddressandadminpassword.Eventhoughthe
functioniscalled“QuicklySet,”thereisnoneedtorush.Takeasmuchtimeasyoulikewiththeconfiguration.
Refertosubsequentsectionsinthisuserguideforadditionalinformationabouttheindividualfunctions.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
17
6.3 PORTSETTINGS
6.3.1 BasicConfig
Accesstheparametersrelatedtoeachofthe18ports.Thescreenisdividedintotwosections.Theuppersectiondisplays
animageofthe18portsoftheIntellinetswitch.Inordertomakechangestoaport,simplyclicktoselectit.
Createaselectionofmultipleportsatonce:
Onceoneportormultipleportsareselected,makechangestotheportsettings.
Item Description
Portdescription Optionaldescriptionfortheport.Amaximumof80characterscanbeprovided.No
specialcharactersorspacesareallowed.
Portspeed 10M:Forceaconnectiontobemadeat10Mbps.
100M:Forceaconnectiontobemadeat100Mbps.
1000M:Forceaconnectiontobemadeat1000Mbps.
Auto:Theswitchandconnecteddevicenegotiatethebestpossibleconnectionspeed.
Flowcontrol IEEE802.3xflowcontrolistheprocessofmanagingtherateofdatatransmission
betweentwonodes(i.e.,theswitchandaconnectednetworkclient)topreventafast
senderfromoverwhelmingaslowreceiver.Itprovidesamechanismforthereceiver
tocontrolthetransmissionspeed,sothatthereceivingnodeisnotoverwhelmedwith
datafromthetransmittingnode.Thatsoundslikeitisagoodthing,anditis.Sowhyis
theoptionbydefaultsetto“disabled"?Theshortanswerisbecauseyounormally
don’tneeditandbecauseitcan,inveryrareinstances,haveanegativeimpactonthe
overallperformanceinyournetwork.TheTCPprotocolalreadyprovidesitsownflow
controlmechanism,allowingasendertothrottlebackthespeedifthereceiveris
havingproblemskeepingup.
Portstatus ON:Activatetheport.
OFF:Disablestheport.Noconnectionstoitcanbemade.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
18
Item Description
Workingmode Thisparametercontrolstheduplexmode.Inafull‐duplexsystem,bothpartiescan
communicatetotheothersimultaneously.Anexampleofafull‐duplexdeviceisa
telephone;thepartiesatbothendsofacallcanspeakandbeheardbytheotherparty
simultaneously.Innetworkingterms,fullduplexallowsreceivingandtransmittingof
dataatthesametime,whereashalfduplexdoesnot.Ifthetelephoneisanexample
forfullduplex,thenapush‐to‐talkCBradioor"walkie‐talkie"representshalfduplex.
Theswitchcaneitherreceiveorsenddata,butitcanneverhappensimultaneously.
Unlessyouhaveaspecificreasonnottodoso,thisshouldbeleftin“Auto”mode.
Crosslineorder AutoMDI‐Xautomaticallydetectstherequiredcable‐connectiontypeandconfigures
theconnectionappropriately,removingtheneedforcrossovercablestointerconnect
switchesorforconnectingPCspeer‐to‐peer.Aslongasitisenabledoneitherendofa
link,eithertypeofcablecanbeused.ForautoMDI‐Xtooperatecorrectly,thedata
rateontheinterfaceandduplexsettingmustbesetto"auto."WhentwoautoMDI‐X
portsareconnectedtogether,whichisnormalformodernproducts,thealgorithm
resolutiontimeistypically<500ms.However,a~1.4secondasynchronoustimeris
usedtoresolvetheextremelyrarecase(withaprobabilityoflessthan1in5×1021)ofa
loopwhereeachendkeepsswitching.Ifyoudon’tunderstandanyofthis,simplyleave
thisvalueon“Auto.”
Thescreenalsoshowsatablethatlistsall18portsalongwiththeirparameters.The“megaframe”valuereferstojumbo
frames,whichareEthernetframeswithmorethan1500bytesofpayload.Definethesizeofthejumboframesinthe
sectionSYSTEM‐>SYSTEMCONFIG.
Clickingthepencilallowseditingtheportsettings,exactlythesamewayasdirectlyselectingtheport(s)as
shownonthepreviouspage.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
19
6.3.2 PortAggregation
PortaggregationisamethodofusingmultipleEthernetportsinparalleltoincreasethroughputbeyondwhatasingle
connectioncouldsustainandtoprovideredundancyincaseoneofthelinksshouldfail.Asthisisessentiallyagroupingof
portsintoonelogicalunit,wecallthemLinkAggregationGroups,or“LAG”forshort.
ThispageisusedtosetupLAGs.CreateuptoeightdifferentLAGs;eachcanhaveuptoeightmemberports.EachLAG
canbegivenacustomname,andyoumustselecttheportsfortheLAG.TheexamplebelowshowsanLAGgroupsetup
withfourmemberports.
Item Description
Aggregateportnumber Thisisthelinkaggregationgroup(LAG)number
Pleaseselecttheporttojointheaggregateport SelectthememberportsthatbelongtothisLAG
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
20
6.3.3 PortMirroring
Portmirroringistheabilityofanetworkswitchto
sendacopyofnetworkpacketsseenonaswitch
portorportstoanetwork‐monitoringdevice
connectedtoanotherswitchport(i.e.,a
computerequippedwithapacketsnifferutility).
TheIntellinet16‐PortGigabitEthernetPoE+Web‐
ManagedSwitchprovidesuptofourgroupsfor
port‐mirroringsettings.
Theexamplebelowshowssettinguponemirror
groupwherealltrafficoccurringonport1isbeing
mirroredtoport16.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
21
6.3.4 Portspeedlimit
ThisfeatureallowsyoutolimitthedataratesforaparticularportontheIntellinet16‐PortGigabitEthernetPoE+Web‐
ManagedSwitch.Whenthedatarateexceedsuser‐configuredvalues,theIntellinetswitchdropspacketsimmediately.
Ratelimitingisconfiguredfortwotypesoftransmissions,whichareingressandegress.Ingresstrafficisreceivedonany
givenport(incoming,inbound,downloadorinputspeed),whereasegresstrafficistrafficsentout(outgoing,outbound,
uploadoroutputspeed)toanothernetworkclient.
TheIntellinetswitchallowscontrollingtheavailablebandwidthforeachportindividually.Thespeedismeasuredinkbps,
whichstandsforkilobitspersecond.Thedefaultis1million,whichistheequivalentof1Gigabitpersecond.Values
enteredmustbemultiplesof“16”(e.g.,16,32,48,…,512,….,1024,etc.).
Item Description
Portnumber1‐18 Selectindividualportsorarangeofports.
Inputspeedlimit(multipleof16) Providetheingressrateinkbps.
Outputspeedlimit(multipleof16) Providetheegressrateinkbps.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
22
6.3.5 Broadcaststorm
StormcontrolpreventsLANinterfacesfrombeingdisruptedbyabroadcaststorm.Abroadcaststormoccurswhen
broadcastpacketsfloodthesubnet,creatingexcessivetrafficanddegradingnetworkperformance.Errorsinthe
protocol‐stackimplementationorinthenetworkconfigurationcancauseabroadcaststorm.TheIntellinetswitchallows
configuringmaximumallowedppsratesforthreedifferenttypesofpackets.It'spossibletosetall18portstothesame
valueorprovideindividualvalues.
Item Description
Portnumber1‐18 Selectindividualportsorarangeofports.
Broadcastlimit Enterthemaximumpps(packetspersecond)forbroadcastpackets.
Multicastlimit Enterthemaximumpps(packetspersecond)formulticastpackets.
Unicastlimit Enterthemaximumpps(packetspersecond)forunicastpackets.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
23
6.3.6 Portisolation
TheportisolationfunctionallowsyoutoconfiguretheIntellinetswitchinaway,thatpreventsPCsondifferentports
fromcommunicatingwitheachother,andallthatwithoutconfiguringaVLAN.
Item Description
SourcePort Selecttheportyouwishtoisolate.
IsolationPort Selecttheport(s)towhichpacketsfromthesourceportcanbe
forwarded.Morethanoneportcanbeselectedhere.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
24
6.3.6.1 ConfigurationExample:
1. ThreePCs,oneNAS,andonerouterareconnected
totheIntellinetswitch
2. PC1isconnectedtoPort1
3. PC2isconnectedtoPort2
4. PC3isconnectedtoPort3
5. TheNASisconnectedtoPort4
6. TherouterisconnectedtoPort5
7. PC1canaccesstheNASandtherouter
8. PC2andPC3canonlyaccesstherouter
PC1onport1:
PC2onport2:
PC3onport3:
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
25
NASonPort4:
RouteronPort5:
Whencompleted,theconfigurationwilllooklikethis.Tobetterunderstandwhatishappening,ithelpstoconsiderthe
isolatedportsastheportswithwhichthesourceportscancommunicate.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
26
6.4 VLAN
AvirtualLAN(VLAN)isanybroadcastdomainthatispartitionedandisolatedinacomputernetworkatthedatalinklayer
(OSIlayer2).VLANsaredatalinklayer(OSIlayer2)constructs,analogoustoIPsubnets,whicharenetwork‐layer(OSI
layer3)constructs.VLANscanbeusedtopartitionalocalnetworkintoseveraldistinctivesegments.
VLANtechnologyprovidesthefollowingadvantages:
1. BroadcasttrafficdoesnotcrossintodifferentVLANs,whichreducesbandwidthutilizationandimproves
networkperformance.
2. SecurityinyourLANcanbeimproved,sincepacketsindifferentVLANscannotcommunicatewitheachother
directly.
3. WithVLAN,clientscanbeallocatedtodifferentworkinggroups,andusersfromthesamegroupdonothaveto
bewithinthesamephysicalarea,whichmakesnetworkmaintenancemucheasierandmoreflexible.
VLANtechnologyknowsthreetypesofports—access,trunkandhybridports.
1. AccessPorts(untagged)
a. AccessportsaredesignedtotaganyincomingpacketwiththeVLANIDtheporthasbeenassignedto.
b. TaggedVLANpacketsarrivingattheaccessportaredroppedbytheswitch.
c. AsfarastheIntellinetswitchisconcerned,anyportthatisn’tdefinedasatrunkorhybridportis
consideredanaccessport.
2. TrunkPorts(tagged)
a. TrunkportsaredesignedtofilteroutpacketsthathaveeithernoVLANtagorVLANtagsthatarenot
ontheallowedVLANIDlist.
b. TrunkportsdonotremoveanyexistingVLANtagsfromincomingpackets.
c. TrunkportsdonotaddaVLANtagtoanyincominguntaggedpacket.
d. Trunkportsareidealforswitch‐to‐switchconnectionsorfordevicesthathavetheabilitytotagpackets
bythemselvessuchasVoIPphones.
3. HybridPorts
a. Theseareacombinationofaccessandtrunkports.
b. HybridportswilltaganyincomingpacketthathasnoVLANIDwiththeVLANIDtheporthasbeen
assignedto.
c. HybridportswillalsoactastrunkportsforpacketsthathaveaVLANtag.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
27
NewVLAN:
Item Description
VLANID TypeintheIDforthenewVLAN.Thisvaluecannotbe“1”noranyID
alreadysetupontheswitch.
VLANName ProvideadescriptivenamefortheVLAN(e.g.,“VOICE”).
ChoosetojointheVLANport SelectalltheportsyouwishtobeapartofthisVLAN.Notethatthese
portswillactasaccessports.TheywilladdtheVLANIDtoanyuntagged
packetandrejectanyincomingpacketsthathaveaVLANtag.
Note:VLANID1isthedefaultVLAN,whichcannotberemoved.However,accessportsthatareassignedtoanother
VLANwillbeautomaticallyremovedfromVLAN1.Thescreenshotbelowshowswhatthesetuplookslikeaftertheabove
VLANhasbeenadded:
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
28
6.4.1 TrunkPortSettings
Atrunkporttransmitstaggedpacketsandisusedtoconnectdifferentswitcheswithoneanother.
NewTrunk‐Port:
Item Description
NativeVLANID ThenativeVLANIDistheuntaggedVLANonanIEEE802.1qtrunkedport.
ThenativeVLANandmanagementVLAN(seeSYSTEM‐>SYSTEMCONFIG)
canbethesame,butintermsofsecurity,itisbetterthattheyaren't.Ifa
switchreceivesanuntaggedframeonatrunkport,itisassumedtobe
partoftheNativeVLANthatisdesignatedontheswitchtrunkport.
AllowingVLAN EntertheIDsofallVLANs,whichyouwishthetrunkporttoforward.All
othertaggedpacketswillbedropped.
NotethatanyvalueyouenterheremustfirstbedefinedasaVLANinthe
previousVLANsettingspage.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
29
6.4.2 HybridPortSettings
AHybridportisacombinationofatrunkandanaccessport.
Item Description
NativeVLANID Seeprevioustrunkportsection.
VLANTAG VLANIDthatisaddedtoanyuntaggedpacketarrivingattheport.Note:
YoucannotentermultipleIDsorrangesofIDs.Whilethewebinterface
mayshowthis,itisincorrect.
AllowedVLANIDS EntertheIDsofallVLANs,whichyouwishthehybridporttoforward.All
othertaggedpacketswillbedropped.
PortDescription Thenameoftheportasdefinedinsection6.3.1.
AddTAGVLAN VLANIDthatisaddedtountaggedVLANpackets.
AllowedTAGVLAN TaggedVLANpacketsthatareallowedtopassthrough,allothertagged
packetswillbedropped.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
30
6.4.3 SetupExample
Thissectionprovidesareal‐lifeexampleandthecorrespondingsetupoftheIntellinetswitch,orinthiscase,switches.
TherearethreeVLANsinthenetwork
o VLANID100–InternaldatanetworkwithaccesstoInternet
o VLANID200–VoIPnetwork
o VLANID300–GuestnetworkprovidesInternetaccess,butnothingelse
LANSwitch#1:
o Port2:VoIPphoneusingVLANID200,PCconnectedtobackofphone
o Port6:VoIPphoneusingVLANID200
o Port8:PC
o Port10:WirelessaccesspointforinternalnetworkandaccesstoInternet
o Port12:GuestwirelessaccesspointprovidesInternetaccessonly
o Port16:ConnectiontoLANswitch#2
LANSwitch#2:
o Port1:ConnectiontoLANswitch#1
o Port2:MailServer
o Port3:FileServer
o Port4:VoIPGateway/PBX
o Port8:Internetgateway,firewall,modem
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
31
6.4.3.1 SetupLANSwitch#1:
Trunkportsettings:
Port6:VoIPphone.Thisphonetagsallpacketsbyitself.Theswitchdoesnotneedtotagthepackets.
Port16:ConnectiontoLANswitch#2.ThisportpassesonalltrafficforVLANIDs100,200and300.Allothertrafficwill
bedropped.
Hybridportsettings:
Port2isaspecialcasebecausetwonetworkingdevicesareconnected‐‐theVoIPphoneandaPC,whichisconnectedto
thebackofthephone.TheVoIPphonetagsthepacketsitself,andtheswitchmustletthemgothrough,justlikea
normaltrunkportwould.However,thePCconnectedtoitcannottagthepacketsbyitselfandthereforemustrelyonthe
Intellinetswitchtodoso.
TheIntellinetswitchaddstheVLANID100toallpacketsthatarenottaggedasVLANID200.Portnumbertwoactsasan
untaggedport(VLANID100)andtaggedport(VLANID200)atthesametime,hencethenamehybrid.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
32
6.4.3.2 SetupLANSwitch#2:
VLANID1(defaultVLAN)onlycontainsportsthatarenototherwiseassigned.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
33
6.5 F
AULT
/S
AFETY
6.5.1 AntiAttack
6.5.1.1 DHCPSnooping
DHCPsnoopingisasecuritytechnologybuiltintotheoperatingsystemofacapablenetworkswitchthatdropsDHCP
trafficdeterminedtobeunacceptable.ThefundamentaluseforDHCPsnoopingistopreventunauthorized(rogue)DHCP
serversofferingIPaddressestoDHCPclients.
CommandUsage
NetworktrafficmaybedisruptedwhenmaliciousDHCPmessagesarereceivedfromanoutsidesource.DHCPsnoopingis
usedtofilterDHCPmessagesreceivedonanon‐secureinterfacefromoutsidethenetworkorfirewall.WhenDHCP
snoopingisenabledgloballyandenabledonaVLANinterface,DHCPmessagesreceivedonanuntrustedinterfacefroma
devicenotlistedintheDHCPsnoopingtablewillbedropped.
Tableentriesareonlylearnedfortrustedinterfaces.AnentryisaddedorremoveddynamicallytotheDHCPsnooping
tablewhenaclientreceivesorreleasesanIPaddressfromaDHCPserver.EachentryincludesaMACaddress,IPaddress,
leasetime,VLANidentifierandportidentifier.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
34
WhenDHCPsnoopingisenabled,DHCPmessagesenteringanuntrustedinterfacearefilteredbasedupondynamic
entrieslearnedviaDHCPsnooping.
Item Description
NativeProtectionStatus Closed:AllDHCPrelatedtrafficwillpassthroughtheIntellinetswitch
withoutanyinterference.
Open:ActivatesDHCPsnooping.DHCPtrafficisnowsubjecttocertain
rules.
DHCPTrustedPort Thesearetrustedportsonyournetwork,whichareunderyourdirect
administratorcontrol.Connectedtotheseportsaretypicallyswitches,
routers,andserversinthenetwork.DHCPtrafficfromtrustedportsis
consideredsafe.
ProhibitDHCPForAddress Anyportbeyondthefirewalloroutsidethenetworkisuntrusted.DHCP
trafficfromtrustedportsisconsideredunsafe.DHCPresponsepacketson
theseportswillbedropped,thuspreventingapossibleman‐in‐the‐middle
attack.
Item Description
SourceMACVerify DHCPsnoopingMACaddressVerifyensuresthattheIntellinetswitch
verifiesthatthesourceMACaddressandtheclienthardwareaddress
matchinDHCPpacketsthatarereceivedonuntrustedports.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
35
SourceMACVerifyEnable ChecktoactivateMACaddressverification.
MACAddress TypeintheMACaddress(formatxx:xx:xx:xx:xx:xx).
Verify/NoVerify Verify:AddsMACaddresstotheconfiguration.
NoVerify:RemovespreviouslyenteredMACaddressfromconfiguration.
EnableOption82support.
ClientOption82enabledtrustmode.
Option82AgentCircuitID(suboption1)
Item Description
CircuitName CircuitID,anASCIIstringthatidentifiestheinterfaceonwhichtheclient
DHCPpacketisreceived.
VLANID SpecifytheOption82foraspecificVLANID(use1fordefaultVLAN).
Option82AgentRemoteID(suboption2)
Item Description
RemoteName RemoteID,anASCIIstringassignedbytheDHCPrelayagentthatsecurely
identifiestheclient.
VLANID SpecifytheOption82foraspecificVLANID(use1fordefaultVLAN).
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
36
WhenDHCPsnoopingisenabled,theleaseinformationfromtheswitchingdeviceisusedtocreatetheDHCPsnooping
database,alsoknownastheDHCPsnoopingbindingtable.ThetableshowstheIP‐MACbinding,aswellastheleasetime
fortheIPaddress,typeofbinding,VLANnameandinterfaceforeachhost.Theinformationinthistableisgathered
duringrun‐timeasclientsjointhenetworkandrequestIPaddressesviaDHCP.Whentheswitchreboots,theinformation
islost,exceptforstaticbindings.
Item Description
MACAddress MACaddressforstaticentry.
VLANID SpecifytheVLANIDforthestaticentry.
PortNumber Selecttheport(1–18)forthestaticentry.
DHCPSnooping
BindingTable
Containsrun‐timeinformationofconnectedDHCPclients,includingtheirMAC
address,theportnumbertowhichtheyareconnected,theIPaddresstheyhave
beengiven,etc.
Item Description
DHCPSnoopingVLAN VLANtowhichyouwanttoapplyDHCPsnooping.
ServerIPAddress DHCPserveraddress.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
37
6.5.1.2 DoS
Adenial‐of‐service(DoS)attackisanattempttomakeamachineornetworkresourceunavailabletoitsintendedusers
suchastotemporarilyorindefinitelyinterruptorsuspendservicesofahostconnectedtotheInternet.TheIntellinet
switchhasintegratedmechanismstocounterpossibleDoSattackssuchaslandattacksorillegalTCP/IPpackets.There
areconfigurationoptions.Yousimplyactivateordeactivatethisfeature.
6.5.1.3 IPSourceGuard
IPSourceGuardisasecurityfeaturethatrestrictsIPtrafficonuntrustedLayer2portsbyfilteringtrafficbasedonthe
DHCPsnoopingbindingtable(seesection6.5.1.1)ormanuallyconfiguredIPsourcebindings.Equippedwiththisfeature,
theIntellinetswitchhelpspreventIPspoofingattacks.AnIPspoofingattackiswhenahosttriestospoof(fake)anduse
theIPaddressofanotherhostinordertointercepttrafficboundforthathost.
IfyouenableIPSourceGuardforaportinitially,allIPtrafficontheprotectedportisblockedexceptforDHCPpackets.
AfteraclientreceivesanIPaddressfromtheDHCPserveralltrafficwiththatIPsourceaddressispermittedfromthat
client.InsteadofaDHCPserver,it'spossibletoprovidestaticIPsourcebinding,whichiscalled“newsecurityport”on
theIntellinetswitchwebadminUI.
Item Description
PleaseselecttheIPsourceto
protecttheport:
Selecttheport(orports)thatyouwishtoprotectbyIPSourceGuard.The
exampleaboveshowsthatIPSourceGuardisenabledforport14.Note
thatIPSourceGuardisn’tsupportedonTrunkoraggregatedports.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
38
Item Description
VLANID SpecifytheVLANIDforthestaticentry.Leave1forthedefaultVLAN.
SourceIPAddress SpecifytheIPaddressoftheclientforthestaticentry.
SourceMACAddress SpecifytheMACaddressoftheclientforthestaticentry.
Ports Selecttheporttowhichtheclientisconnected(port14intheexampleabove).
Youcanonlyselectoneport.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
39
6.5.1.4 IPMACPortBinding
TheIntellinet16‐PortGigabitEthernetPoE+Web‐ManagedSwitchfeaturesIP‐MAC‐PortBinding.Thisisapowerful
authenticationfunctionthatensuresthecorrectnessofhardware(MACaddress),software/user(IPaddress),and
location(Connectedport)fordevicesconnectedtothenetwork.Thisfeatureensurestheyareallfromlegalsourcesto
preventthedataleakagefromhackersfakingthelegalnetworkdevices.
Item Description
BindingEnable ChecktoactivateIPMacportbinding.
Scanning Clicktoscanforconnectednetworkclients.
Binding SelecttheclientsyouwishtoaddtotheIPMacportbindingtable,thenclickon
“Binding”.
ApplicationList Allcurrent,staticIP‐MAC‐portbindingentriesarelistedhere.Notethatthis
informationwillbelostaftertheswitchisrestarted.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
40
6.5.2 ChannelDetection
TheIntellinetswitchisequippedwithasetofnetworktoolsthatcanaidthenetworkadministratorintroubleshooting
problems.
6.5.2.1 Ping
Item Description
DestinationIPaddress IPaddressyouwishtoping.
TimeoutPeriod Definethemaximumallowedresponsetime(s)beforetheresponseisconsidered
tohavetimed‐out.
Repeatnumber DefinehowmanypingrequestsyouwanttheIntellinetswitchtosendtothe
destinationIPaddress.
6.5.2.2 Tracert
Item Description
DestinationIPaddress IPaddressyouwishtorunatracertfor.
TimeoutPeriod Definethemaximumallowedresponsetime(s)beforetheresponseisconsidered
tohavetimed‐out.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
41
6.5.2.3 CableTest
Thecabletestutilityallowsaquickcheckoftheconnectedcables.
Item Description
SelectPort Selectoneofthe18ports,thenclickon“Starttest.”
TestResults Displaystheresultsofthecabletest.Notethatifyoutestaporttowhichnocable
isconnected,thetestreturnsthevalue“circuitbreaker.”
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
42
6.5.3 ACLAccessControlList
ACEisanacronymforAccessControlEntry.ItdescribesaccesspermissionassociatedwithaparticularACEID.Thereare
threeACEframetypes(EthernetType,ARPandIPv4)andtwoACEactions(permitanddeny).TheACEalsocontains
manydetailed,differentparameteroptionsthatareavailableforindividualapplication.
ACLisanacronymforAccessControlList.ItisthelisttableofACEs,containingaccesscontrolentriesthatspecify
individualusersorgroupspermittedordeniedtospecifictrafficobjects,suchasaprocessoraprogram.Eachaccessible
trafficobjectcontainsanidentifiertoitsACL.Theprivilegesdeterminewhethertherearespecifictrafficobjectaccess
rights.
ACLimplementationscanbequitecomplex;forexample,whentheACEsareprioritizedforvarioussituations.In
networking,theACLreferstoalistofserviceportsornetworkservicesthatareavailableonahostorserver,eachwitha
listofhostsorserverspermittedordeniedtousetheservice.ACLcangenerallybeconfiguredtocontrolinboundtraffic,
andinthiscontext,theyaresimilartofirewalls.
6.5.3.1 Timetables
Thissectiondescribeshowtosetupatimeframe.ThistimeframecanbeappliedtoACLrulestoeitherallowordeny
access.Thetimetabledoesnotdirectlyspecifywhetheraccessisdeniedorallowed.Rather,itissimplyawaytocreate
aneasilyaccessibletimeframethatcanbeappliedtoACLrules.Theexamplebelowshowsthesetupofatimetable
called“WorkingHours.”NotethattheIntellinetswitchmustbesetupwithapropersystemtime(seesectionSystem
Config).
Item Description
NewTimetableName Provideadescriptivenameforthetimetable.
TimeInterval Specifythedaysoftheweekandstartandendtime.Clickonthe toadd
additionaltimeframes.Click“Save”tosavethetimetable.
Timetableslist Drop‐downlistcontainsalltimetablespreviouslysetup.
Timeweek Selectedweekdaysfortheselectedtimetable.
TimeInterval Timeintervalforselectedtimetable.
Operation
Editselectedtimetable
Deledselectedtimetable
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
43
6.5.3.2 ACL
Inthissection,setuptheactualaccesscontrollist(ACL).TheACLconnectsIPaddressandportinformationwitha
timetable(seesection6.5.3.1)andanactiontoeitherallowordenyaccesstothenetworkthroughtheswitch.The
examplebelowcreatesanACL,whichallowsaccesstothenetworkforanycomputer
Item Description
ACLNumber EachACLrulegetsanumber.Selecttheonefromthedrop‐downlistforwhich
youwanttocreatethisACE(AccessControlEntry).
Action Definewhetherthisrulegrantsaccess(“allow”)tothenetwork,orprohibitsit
(“deny”).
SRC/DESTIPAddress SpecifythesourceanddestinationIPaddressforthisACE.Youcanprovidea
singleIPaddress(e.g.,192.168.2.100)oraspecificnetwork(e.g.,255.255.255.0).
SRC/DESTPort ThisoptionisonlyvisibleiftheACEiscreatedforTCPorUDP.Itwillnotshowfor
IPACLs(seenextparameter).Youcanprovideasingleportorarangeofports.
ProtocolMatching IP:TheACEisappliedtopacketsbasedontheirsourceand/ordestinationIP
address.
TCP/UDP:TheACEisappliedtopacketsbasedontheirsourceand/ordestination
IPaddressandtheportnumberfortheselectedprotocol.
Time IfyouwanttolimittheACEtoaspecifictimetable(seesection6.5.3.1),youcan
selectitfromthedrop‐downlist.
Example1–Disallowaccesstothenetworkforanycomputeroutsideoftheworkinghours.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
44
Example2–DisallowaccesstothenetworkforanindividualIPaddressduringtheworkinghours.
6.5.3.3 ApplicationACL
WiththisfunctionyoucanlinkanACLtooneormoreofthe18availableswitchports.
SelecttheportsandACLlist,andclick“Save”inordertoactivate.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
45
6.6 POWEROVERETHERNET(POE)
TheIntellinet16‐PortGigabitEthernetPoE+Web‐ManagedSwitchisequippedwithsophisticatedPoE‐monitoringand
configurationoptions.
6.6.1 PoEConfiguration
6.6.1.1 Management
Item Description
WorkingStatus Displaysthevalue“On‐line,”indicatingthatthePoEfunctionisworkingproperly.
Ratedtotalpower Thisnumberrepresentsthemaximumpowerthatthepowersupplywithinthe
switchcanoutput.NotethatnotallofthatpowerisavailableforconnectedPoE
devices.Someofthepowerisrequiredfortheswitchitselftofunction.This
switchhasaPoEbudgetof374watts.
PowerOutput ThisvaluerepresentsthetotalpowerdrawofallconnectedPoEdevices.
AlarmPower TheIntellinetswitchcanalertthenetworkadministratorviaSNMPmessagesifa
certainPoEpowerdrawvaluehasbeenreached.Thisthresholdcanbeconfigured
underthePoEalarmconfiguration.
VoltageLevel Displaysthecurrentoutputvoltage.
Alarm‐notification Definethealarmnoticevalue,which,whenexceeded,causestheswitchtosend
outSNMPtrapmessages.Settoenabletoactivatethisfeature.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
46
6.6.1.2 TemperatureDistribution.
ThisfunctionmonitorsthetemperatureofthetwoPoEchipsintheIntellinetswitchandsendsoutSNMPtrapmessages
ifathresholdyousetwillbeexceeded.
Click inordertoeditthetemperaturethresholdofthePoEchips.NotethatinorderfortheIntellinetPoEswitchto
sendourSNMPtraps,SNMPmustbeactivatedandconfigured.
6.6.1.3 PoweredDeviceMonitor
TheIntellinetPoE+switchhastheabilitytomonitorallconnectedPoEdevices.IfaPoEdevicestopssendingnetwork
packetsforaspecifiedamountoftime,theswitchcanturnoffpowertotheportforabriefmoment,andthenre‐apply
powerinordertorestarttheconnectedPoEdevice.TheconfigurationconsistsofenablingordisablingthePD
monitoringfunction,andsettingthemonitortimeoutperiodinseconds.ThetimeoutperioddefineshowlongaPoE
devicehastostopsendinganynetworktraffic,beforetheswitchrestartsthePoEportthatthedeviceisconnectedto.
Warning:
Whenupdatingthefirmwareofaconnectedpowereddevice,suchasaPoEnetworkcamera,thedevicemaybecome
unresponsiveforextendedperiodsoftime.Ifthemonitortimeissettooshort,thePoEswitchcouldaccidentallyturnoff
powertotheporttowhichthepowereddeviceisconnectedto,andthiscouldrenderthepowereddeviceinoperable.It
isrecommendeddisablingPDMonitoringduringtimeswheresuchfirmwareupdatesandsimilarservicetasksaretobe
performed.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
47
6.6.2 PoEPortConfiguration
ThissectiondescribeshowtoedittheparametersofindividualPoEports.
Uponopeningtheconfigurationscreen,anoverviewofthePoEportsandtheircurrentstatusesappears.Clickon in
ordertomodifyindividualports.Clickon inordertomodifytheparametersforallports
onthecurrentpage(1‐8)atthesametime.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
48
Item Description
PortID DisplaystheIDoftheportyouareeditingor“CurPageAllports”ifyouareediting
allportsonthecurrentpage.
Portenable ActivateordeactivatePoEsupport.
PortPriority Youcanchoosefromthreevalues:low,midandhigh.Theprioritycanbeusedto
definewhichportwon’tbereceivingpower,intheeventthatthemaximumPoE
powerhasbeenexceeded.
Example:It'spossibletosetthevalueto"high"forportswithsecuritycameras
connectedtothem.Thisensuresthatthesecameraswillalwaysbesuppliedwith
power,evenifthetotalpowerdrawontheIntellinetswitchexceedsthe
maximumavailablePoEpower.Portsthataresettolowormidwillbe
disconnectedfirst–inthatorder.
Detectionmode SomegoodadviceistoleavethisAT&AF.YoucanenableAF‐onlymode,ifyour
olderIEEE802.3afPoEdevicesarenotabletocommunicatewiththeIntellinetPoE
switch.
Maximumpower Definethemaximumoutputpoweravailablefortheport(s)inrangefrom1to32
watts.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
49
6.6.3 PoEDelayConfig
ThePoEdelayfunctionallowsanadministratortoprogramastartupsequenceforyourPoE‐compliantdevicesand
eliminatepotentialproblemscausedbytheincreasedpowerdrawatstartup.Thesequentialpower‐upguaranteesa
smoothstartupprocedureforallconnectednetworkingdevices(i.e.,yourPoE‐enablednetworkcameras).Therestart
timeallowstocutpowertothePSEportsoftheIntellinetswitchinordertorestartaconnectedpowereddevice.This
canbeusedinordertopreventivelyrebootpowereddevicestokeepthemfromfailing.
Item Description
RestartWeeks
Selection
Despitethenameofthisitem,youdonotdefinetheweeks,buttheweekdayonwhich
youwishpowertobecuttotheconnecteddevice.
RestartTime Definethetimeofdaywhenyouwantpowertobecuttotheconnectedpowered
device.Thetimeisenteredin24hourtimeformat,forexample15:00:00represents3
pm.
PortDelayTime Definehowlongtheswitchwillhavetowaitbeforeitactivatestheport(s)aftera
systemrestart.Enterthedelayvalueinseconds.
TheexampleaboveshowsthatthePoEdelaytimeforport2issettwoseconds,andthatport2isrebootedSundaynight
on5minutespastmidnight.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
50
6.7 SPANNINGTREEPROTOCOL(STP)
TheSpanningTreeProtocolcanbeusedtodetectanddisablenetworkloopsandtoprovidebackuplinksbetween
switches,bridgesorrouters.Thisallowstheswitchtointeractwithotherbridgingdevicesinyournetworktoensurethat
onlyonerouteexistsbetweenanytwostationsonthenetwork.Italsoprovidesbackuplinks,whichautomaticallytake
overwhenaprimarylinkgoesdown.Thespanningtreealgorithmssupportedbythisswitchincludetheseversions:
STP–SpanningTreeProtocol(IEEE802.1D)
RSTP–RapidSpanningTreeProtocol(IEEE802.1w)
MSTP–MultipleSpanningTreeProtocol(IEEE802.1s)
TheIEEE802.1DSpanningTreeProtocolandIEEE802.1wRapidSpanningTreeProtocolallowfortheblockingoflinks
betweenswitchesthatformloopswithinthenetwork.Whenmultiplelinksbetweenswitchesaredetected,aprimary
linkisestablished.Duplicatedlinksareblockedfromuseandbecomestandbylinks.Theprotocolallowsfortheduplicate
linkstobeusedintheeventofafailureoftheprimarylink.OncetheSpanningTreeProtocolisconfiguredandenabled,
primarylinksareestablishedandduplicatedlinksareblockedautomatically.Thereactivationoftheblockedlinks(atthe
timeofaprimarylinkfailure)isalsoaccomplishedautomaticallywithoutoperatorintervention.Thisautomaticnetwork
reconfigurationprovidesmaximumuptimetonetworkusers.However,theconceptsoftheSpanningTreeAlgorithmand
protocolareacomplicatedandcomplexsubjectandmustbefullyresearchedandunderstood.Itispossibletocause
seriousdegradationtonetworkperformanceiftheSpanningTreeisincorrectlyconfigured.Pleasereadthefollowing
beforemakinganychangesfromthedefaultvalues.
TheSwitchSTPperformsthefollowingfunctions:
Createsasinglespanningtreefromanycombinationofswitchingorbridgingelements.
Createsmultiplespanningtrees–fromanycombinationofportscontainedwithinasingleswitch,inuser
specifiedgroups.
Automaticallyreconfiguresthespanningtreetocompensateforthefailure,additionorremovalofanyelement
inthetree.
Reconfiguresthespanningtreewithoutoperatorintervention.
BridgeProtocolDataUnits
ForSTPtoarriveatastablenetworktopology,thefollowinginformationisused:
Theuniqueswitchidentifier
Thepathcosttotherootassociatedwitheachswitchport
Theportidentifier
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
51
STPcommunicatesbetweenswitchesonthenetworkusingBridgeProtocolDataUnits(BPDUs).EachBPDUcontainsthe
followinginformation:
Theuniqueidentifieroftheswitchthatthetransmittingswitchcurrentlybelievesistherootswitch
Thepathcosttotherootfromthetransmittingport
Theportidentifierofthetransmittingport
TheswitchsendsBPDUstocommunicateandconstructthespanning‐treetopology.AllswitchesconnectedtotheLAN
onwhichthepacketistransmittedwillreceivetheBPDU.BPDUsarenotdirectlyforwardedbytheswitch,butthe
receivingswitchusestheinformationintheframetocalculateaBPDU,and,ifthetopologychanges,initiatesaBPDU
transmission.
ThecommunicationbetweenswitchesviaBPDUsresultsinthefollowing:
Oneswitchiselectedastherootswitch
Theshortestdistancetotherootswitchiscalculatedforeachswitch
Adesignatedswitchisselected.Thisistheswitchclosesttotherootswitchthroughwhichpacketswillbe
forwardedtotheroot.
Aportforeachswitchisselected.Thisistheportprovidingthebestpathfromtheswitchtotherootswitch.
PortsincludedintheSTPareselected.
CreatingaStableSTPTopology
IfallswitcheshaveSTPenabledwithdefaultsettings,theswitchwiththelowestMACaddressinthenetworkwill
becometherootswitch.Byincreasingthepriority(loweringtheprioritynumber)ofthebestswitch,STPcanbeforcedto
selectthebestswitchastherootswitch.WhenSTPisenabledusingthedefaultparameters,thepathbetweensource
anddestinationstationsinaswitchednetworkmightnotbeideal.Forinstance,connectinghigher‐speedlinkstoaport
thathasahighernumberthanthecurrentrootportcancausearoot‐portchange.
STPPortStates
BPDUstakesometimetopassthroughanetwork.Thispropagationdelaycanresultintopologychangeswhereaport
thattransitioneddirectlyfromaBlockingstatetoaForwardingstatecouldcreatetemporarydataloops.Portsmustwait
fornewnetworktopologyinformationtopropagatethroughoutthenetworkbeforestartingtoforwardpackets.They
mustalsowaitforthepacketlifetimetoexpireforBPDUpacketsthatwereforwardedbasedontheoldtopology.The
forwarddelaytimerisusedtoallowthenetworktopologytostabilizeafteratopologychange.Inaddition,STPspecifiesa
seriesofstatesaportmusttransitionthroughtofurtherensurethatastablenetworktopologyiscreatedaftera
topologychange.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
52
EachportonaswitchusingSTPexistsisinoneofthefollowingfivestates:
Blocking–theportisblockedfromforwardingorreceivingpackets
Listening–theportiswaitingtoreceiveBPDUpacketsthatmaytelltheporttogobacktotheblockingstate
Learning–theportisaddingaddressestoitsforwardingdatabase,butnotyetforwardingpackets
Forwarding–theportisforwardingpackets
Disabled–theportonlyrespondstonetworkmanagementmessagesandmustreturntotheblockingstatefirst
Aporttransitionsfromonestatetoanotherasfollows:
Frominitialization(switchboot)toblocking
Fromblockingtolisteningortodisabled
Fromlisteningtolearningortodisabled
Fromlearningtoforwardingortodisabled
Fromforwardingtodisabled
Fromdisabledtoblocking
It'spossibletomodifyeachportstatebyusingmanagementsoftware.WhenyouenableSTP,everyportoneveryswitch
inthenetworkgoesthroughtheblockingstateandthentransitionsthroughthestatesoflisteningandlearningatpower
up.Ifproperlyconfigured,eachportstabilizestotheforwardingorblockingstate.Nopackets(exceptBPDUs)are
forwardedfromorreceivedbySTPenabledports,untiltheforwardingstateisenabledforthatport.
TheSwitchallowsfortwolevelsofoperation:theswitchlevelandtheportlevel.Theswitchlevelformsaspanningtree
consistingoflinksbetweenoneormoreswitches.Theportlevelconstructsaspanningtreeconsistingofgroupsofone
ormoreports.TheSTPoperatesinmuchthesamewayforbothlevels.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
53
6.7.1 MSTPRegion
Item Description
MSTPRegionConfiguration EachswitchrunningMSTinthenetworkhasasingleMSTconfigurationthat
consistsofthesetwoattributes:
1. Regionname
a. Analphanumericconfigurationname
2. RevisionLevel
InstanceMapping Atablethatassociateseachofthepotential4096VLANIDstoagiven
instance.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
54
6.7.2 MSTPBridge
Item Description
inst‐priority Prioritycanbeconfiguredforaspecifiedinstance.
inst‐id SelecttheinstanceIDforwhichyouwanttodefineapriority.
Priority SelecttheprioritylevelfortheinstanceID.
Enable Enable/disableSTP.
Mode STP–SpanningTreeProtocol(IEEE802.1D)
RSTP–RapidSpanningTreeProtocol(IEEE802.1w)
MSTP–MultipleSpanningTreeProtocol(IEEE802.1s)
Hello‐time ThehellotimeristhetimeintervalbetweeneachBridgeProtocolDataUnit(BPDU)that
issentonaport.Thedefaulthellotimeris2seconds.AdjusttheSpanningTreeProtocol
(STP)hellotimertoanyvaluebetween1and10seconds.
f‐delay Theforwarddelaytimeristhetimeintervalthatisspentinthelisteningandlearning
state.Thedefaultforwarddelaytimeris10seconds.SettheSpanningTreeProtocol
(STP)forwarddelaytimertoanyvaluebetween4and30seconds.
Max‐age ThemaxagetimercontrolsthemaximumlengthoftimeintervalthatanSTPswitch
portsavesitsconfigurationBridgeProtocolDataUnit(BPDU)information.Thedefault
maxagetimeris10seconds.Adjustthemaxagetimertoanyvaluebetween6and40
seconds.
Max‐hops ForMultipleSpanningTreeProtocol(MSTP),configurethemaximumnumberofhopsa
BPDUcanbeforwardedintheMSTPregion.Thedefaultvalueis10.Possiblevalues
rangefrom1to40.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
55
Item Description
inst SelecttheinstanceID.
port‐fast ThetimeSpanningTreeProtocol(STP)takestotransitionportsovertotheforwarding
statecancauseproblems.Port‐fastisafunctiontoresolvethisproblem.Port‐fastsolves
theproblemofdelayswhenclientcomputersareconnectingtoswitches.Withport‐fast
enabledonaport,youeffectivelypreventtheimplementationofSTPonthatport.
auto‐edge Bydefault,“auto‐edge”isenabledonallports.ThiswilllookforBPDUsfor3secondsand,
ifnonearefound,willbeginforwardingpackets,andtheportissetas“edge.”Ifthereare
BPDUs,theportissetas“non‐edge.”
bdpu‐guard BPDUguarddisablestheportuponBPDUreceptionifport‐fastisenabledontheport.This
effectivelydeniesdevicesconnectedtotheseportsfromparticipatinginthedesignedSTP,
thusprotectingyourdata‐centercore.
bdpu‐filter EnablingBPDUfilteringforaportstopssendingorreceivingBPDUonthisinterface;thisis
thesameasdisablingspanningtreeontheinterface.Itisariskychoice,unlessyouaresure
thatnoswitchcaneverbeconnectedtothisport.
tc‐guard Incertainsituationsitcanbedesirabletopreventtopologychangesoriginatingator
receivedatagivenportfrombeingpropagatedtotherestofthenetwork.Thismaybethe
casewhenthenetworkisnotunderasingleadministrativecontrolanditisbeneficialto
preventdevicesexternaltothecoreofthenetworkfromcausingMAC‐addressflushingin
thecore.ThisbehaviorcanbeenabledbyconfiguringTopologyChangeGuard(TCGuard)
ontheport.
priority Ifaloopoccursinthenetwork,MSTPusestheportpriorityparameterwhenselectingan
interfacetoputintotheforwardingstate.Assignhigherpriorityvalues(lowernumbers)to
interfacesthatyouwantselectedfirstandlowerpriorityvalues(highernumbers)thatyou
wantselectedlast.Ifallinterfaceshavethesamepriorityvalue,MSTPputstheportwith
thelowestinterfacenumberintheforwardingstateandblockstheotherports.
path‐cost TheMSTPpathcostdefaultvalueisderivedfromthemediaspeedofaninterface.Ifaloop
occurs,MSTPusescostwhenselectinganinterfacetoputintheforwardingstate.Assign
lowercostvaluestointerfacesthatyouwantselectedfirstandhighercostvaluesthatyou
wantselectedlast.Ifallinterfaceshavethesamecostvalue,MSTPputstheinterfacewith
thelowestinterfacenumberintheforwardingstateandblockstheotherinterfaces.
point‐to‐point AdminPoint‐to‐PointLink‐‐SpecifywhetherthisportisconnectedtoasharedLANsegment
(value“off”)orapoint‐to‐pointLANsegment(value“on”).Apoint‐to‐pointLANsegmentis
connectedtoexactlyoneotherbridge(normallywithadirectcablebetweenthem).Only
point‐to‐pointlinksandedgeportscanrapidlytransitiontoforwardingstate.
Ifyousetthisvalueto“auto,”theswitchautomaticallydetectswhethertheportis
connectedtoasharedlinkorapoint‐to‐pointlink.
Rootguard Root‐guardensuresthatanunintendedswitchdoesnotbecomeanewrootbridge.Root
guardallowsthedevicetoparticipateinSTPaslongasthedevicedoesnottrytobecome
theroot.Ifrootguardblockstheport,subsequentrecoveryisautomatic.Recoveryoccurs
assoonastheoffendingdeviceceasestosendsuperiorBPDUs.
tc‐ignore Ignoretechnologychange(TC)onoroff.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
56
6.8 DHCPRELAYAGENT
ADHCPclientisanInternethostusingDHCPtoobtainconfigurationparameterssuchasanIPaddress.ADHCPrelay
agentisanyhostthatforwardsDHCPpacketsbetweenclientsandservers.Relayagentsareusedtoforwardrequests
andrepliesbetweenclientsandserverswhentheyarenotonthesamephysicalsubnet.TheIntellinetswitchcanfulfill
theroleofsucharelayagent.
6.8.1 DHCPRelay
Item Description
DHCPrelayenable EnableordisableDHCPrelay.
DHCPOPTIONtrustfieldenable: Whenenabled,theclientthatreceivestheDHCPmessagewith
option82informationwillforwardit;otherwise,itwillbediscarded.
DHCPServerIP ProvidetheIPaddressoftheDHCPserver,andclick“add.”
6.8.2 Option82
6.8.2.1 CircuitControl
Item Description
CircuitControl ProvidethecircuitIDnumber.Possiblevaluesrangefrom3to63.
VLANID TypeintheVLANID.Usevalue1forthedefaultVLAN..
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
57
6.8.2.2 ProxyRemote
Item Description
ProxyRemote ASCIIRemoteIDstring,upto63characters.
VLANID TypeintheVLANID.Usevalue1forthedefaultVLAN.
6.8.2.3 IPAddress
Item Description
IPAddress IPaddressofDHCPserver.
VLANID TypeintheVLANID.Usevalue1forthedefaultVLAN.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
58
6.9 DHCPSERVER
TheDynamicHostConfigurationProtocol(DHCP)isa
standardizednetworkprotocolusedonInternetProtocol(IP)
networksfordynamicallydistributingnetworkconfiguration
parameterssuchasIPaddressesforinterfacesandservices.A
typicalDHCPserverisarouteroraWindowsserver.The
Intellinet16‐PortGigabitEthernetPoE+Web‐ManagedSwitch
canalsofulfilltheroleofaDHCPserver.
6.9.1 DHCPConfig
6.9.1.1 EnableConfig
Setthisoptionto“Open”inordertoactivatetheDHCPserverfunction.Notethatwhenyou
wanttousetheDHCPServerfunction,youcannotusetheDHCPrelayfeature(seesection6.8
DHCPRelayAgent)atthesametime.
6.9.1.2 PoolConfig
Item Description
PoolID IdentifiesthedynamicaddresspoolfromwhichtheDHCPrequestsareserved.
Domain Ifyouareonadomainnetwork,thedomainnameshouldgohere.
NetworkIP ThisisthefirstIPaddressofthesubnetendingin“.0”.Itcan’tbeassignedtoanactual
networkclient.
NetworkMask Providethenetworkmaskofchoiceforyournetwork.
StartIP DefinethelowestIPaddressoftheIPaddresspool.
EndIP DefinethehighestIPaddressoftheIPaddresspool.
LeaseTime DefineshowlongtheclientisallowedtokeeptheIPaddress.Whenthetimehaselapsed,
theswitchwillissueanewIPaddresstotheclient.
Note:TheDHCPIPaddressrangemustbeinthesamerangeastheIntellinetswitch'sLANIPrange(e.g.,192.168.2.xxx).
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
59
6.9.1.3 OptionConfig
ThispageallowsmodificationoftheDHCPoptions,asstatedinRFC2132.Theexamplebelowshowshowtospecifya
specificNTPserver.
Item Description
PoolID IdentifiesthedynamicaddresspoolfromwhichtheDHCPrequestsareserved.
Code Possiblevaluesare–to255.ThesearethecodesortagsperRFC2132.
CodeValueType
Selecttheappropriatevalue(i.e.,selectIPifyouenteranIPaddressinthecodevalue
fieldbelow).
CodeValue Providethevaluefortthetag(code)youselected.
6.9.1.4 BindConfig
ThispagedisplaysallclientsthathaveobtainedanIPaddressfromtheIntellinetswitch.Clickon tosetthelease
timetoexpired,forcingtheconnectclienttoobtainanewIPaddressinstantly.
6.9.1.5 GatewayConfig
Onthispage,providetheGatewayIPaddressthatyouwishtoprovidetotheDHCPclients.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
60
6.9.1.6 DNSConfig
Onthispage,providetheDNSIPaddress(es)thatyouwishtoprovidetotheDHCPclients.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
61
6.10 IGMP
S
NOOPING
TheInternetGroupManagementProtocol(IGMP)letshostsandroutersshareinformationaboutmulticastgroup
memberships.IGMPsnoopingisaswitchfeaturethatmonitorstheexchangeofIGMPmessagesandcopiesthemtothe
CPUforfutureprocessing.TheoverallpurposeofIGMPSnoopingistolimittheforwardingofmulticastframestoonly
portsthatareamemberofthemulticastgroup.
Computersandnetworkdevicesthatwanttoreceivemulticasttransmissionsneedtoinformnearbyroutersthatthey
willbecomemembersofamulticastgroup.TheInternetGroupManagementProtocol(IGMP)isusedtocommunicate
thisinformation.IGMPisalsousedtoperiodicallycheckthemulticastgroupformembersthatarenolongeractive.In
thecasewherethereismorethanonemulticastrouteronasubnetwork,onerouteriselectedasthe"queried."This
routerthenkeepstrackofthemembershipofthemulticastgroupsthathaveactivemembers.Theinformationreceived
fromIGMPisthenusedtodetermineifmulticastpacketsshouldbeforwardedtoagivensubnetworkornot.Using
IGMP,theroutercanchecktoseeifthereisatleastonememberofamulticastgrouponagivensubnetwork.Ifthere
arenomembersonasubnetwork,packetswillnotbeforwardedtothatsubnetwork.
MulticastService
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
62
6.10.1 IGMPConfig
6.10.1.1 IGMPConfigOptions
Item Description
OpenIGMPSnooping ActivatetoenableIPMPsnooping.
Forwardingmode SelecttheforwardingmodetobeeitherIP‐basedorMAC‐based.
Filteringmode EnableordisableIGMPfiltering.
Querymode EnableordisabletheMLDquerierfunction.
Queryinterval EnableMLDsnooping(MulticastListenerDiscovery)forIPv6.
Unknowgroupsuppression Flood:Unknownmulticastdataisflooded.
Drop:Unknownmulticastdataisdropped.
Defaultpolicy: Setthedefaultpolicytoeither“Allow”or“Refush”(Chinesefor“Refuse”).
Queryresponsetime Definethetimeinseconds.
Queryresponseinterval Definetheintervalin1/10thofasecond.
Multicastagingtime Definethemulticastagingtimeinseconds.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
63
6.10.1.2 IGMPPortConfig
Item Description
Maximummulticastnumber Typeinthemulticastnumberfrom1‐254.
Policy Assignapolicy(strategy).
6.10.1.3 IGMPLANConfig
Item Description
VLAN SelecttheVLANIDforwhichyouwishtoenableIGMPsnooping.
IGMPSnoopingVLAN ClicktoenableIGMPSnoopingfortheaboveVLANID.
IGMPSnoopingLeaveQuery SetIGMPsnoopingfast‐leave.
IGMPSnoopingDyanmicLearn DynamicallylearntheIPmulticastgroupsthroughIGMPsnooping.
IGMPSnoopingQuerier Innetworks/VLANsdonothavearouterthatcantakeonthemulticast
routerroleandprovidethemrouter(staticmulticastrouter)discoveryon
theswitches,turnontheIGMPsnoopingquerierfeature.
Querierversion Definesthequerierversion.2=IGMPv2,3=IGMPv3.
QuerierIP Snoopingquerieronaninterfacewhenthereisnomulticastrouterinthe
VLANtogeneratequeries.
QuerierMax‐Responsetime Definethetimeinseconds.
QuerierResponseInterval Definethetimeinseconds.
Queriertimeout Definethetimeinseconds.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
64
6.10.2 IGMPFilterPolicyConfig
Item Description
Createanewstrategy Selectthisifyouwishtosetupanewstrategy.
Selecttheexistingstrategy Selectthisinordertoeditastrategypreviouslysetup.
Defaultpolicy Settoeitheralloworrefuse.
MulticastIPaddress IPv4addressesthatarereservedforIPmulticastingandregisteredwith
theInternetAssignedNumbersAuthority(IANA).Forexample224.0.0.1=
allhostsonthesamenetworksegment;224.0.0.13=Protocol
IndependentMulticast(PIM)Version2.Possiblevaluesrangefrom
224.0.0.0through239.255.255.255.
Mask Providethenetworkmask.
Mode Settoeitheralloworrefuse.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
65
6.11 TERMINALACCESSCONTROLLERACCESS‐CONTROLSYSTEM(TACACS+)
TerminalAccessControllerAccess‐ControlSystem(TACACS,usuallypronouncedlike
"tack‐axe")referstoafamilyofrelatedprotocolshandlingremoteauthenticationand
relatedservicesfornetworkedaccesscontrolthroughacentralizedserver.Theoriginal
TACACSprotocol,whichdatesbackto1984,wasusedforcommunicatingwithanauthenticationserver,commonin
olderUNIXnetworks;itspawnedrelatedprotocols.
TerminalAccessControllerAccess‐ControlSystemPlus(TACACS+)isaprotocolreleasedasanopenstandardbeginningin
1993.AlthoughderivedfromTACACS,TACACS+isaseparateprotocolthathandlesauthentication,authorizationand
accounting(AAA)services.ComparedtotheopenstandardRADIUSauthentication(section6.12Radius),TACACS+
encryptstheentirepayloadwhereasRADIUSonlyencryptspasswords.
Item Description
GlobalConfig Globalparametersthatcanbeoverwrittenbyport‐specificconfiguration.
Servertimeout TheglobaltimeoutintervaldetermineshowlongtheIntellinetswitchwaitsfor
responsesfromTACACS+serversbeforedeclaringatimeoutfailure.
Serverretry
count
SpecifiesthenumberofretryattemptsthatwillbemadetoestablishaTransmission
ControlProtocol(TCP)connectionbetweenaTACACS+clientandtheTACACS+server.
Thedefaultvalueis3.
Conversation/
Connect
Thisparameterdefineshowmanyconnectionstherewillbebetweenrouterdaemon.
Only:“single‐connection"
Thedaemonmustsupportsingle‐connectionmodeforthistobeeffective;otherwise,
theconnectionbetweenthenetworkaccessserverandthedaemonwilllockuporyou
willreceivespuriouserrors.
Keytype 0:Keyvalueincleartextformat
7:Keyvalueistype‐7encrypted.
Key Typeinthekeyvalue.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
66
Item Description
PortConfig Globalparametersthatcanbeoverwrittenbyport‐specificconfiguration.
ServerIP IPAddressfortheTACSACS+server.
Authenticationport DefinetheTCPportnumberoftheTACSACS+serverconnection.
Servertimeout ThetimeoutintervaldetermineshowlongtheIntellinetswitchwaitsforresponses
fromaspecificTACACS+serverbeforedeclaringatimeoutfailure.Ifleftempty,the
globalservertimeoutvaluewillbeused;otherwise,theservertimeouttakes
precedence.
Keytype 0:Keyvalueincleartextformat
7:Keyvalueistype‐7encrypted.
Key Keyvalue.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
67
6.12 RADIUS
RemoteAuthenticationDial‐InUserService(RADIUS)isanetworkingprotocolthat
providescentralizedAuthentication,AuthorizationandAccounting(AAAorTripleA)
managementforuserswhoconnectanduseanetworkservice.RADIUSisaclient/server
protocolthatrunsintheapplicationlayerandcanuseeitherTCPorUDPastransport.Networkaccessservers,the
gatewaysthatcontrolaccesstoanetwork,usuallycontainaRADIUSclientcomponentthatcommunicateswiththe
RADIUSserver.RADIUSisoftentheback‐endofchoicefor802.1Xauthenticationaswell.TheRADIUSserverisusuallya
backgroundprocessrunningonaUNIXorMicrosoftWindowsserver.
6.12.1 RadiusGeneralConfig
Item Description
Serverrepeatnumber Specifiesthenumberofretryattemptsthatwillbemadetoestablishaconnection
betweenaRADIUSclientandtheRADIUSserver.Thedefaultvalueis3.
Servertimeout ThetimeoutintervaldetermineshowlongtheIntellinetswitchwaitsforresponsesfrom
RADIUSserverbeforedeclaringatimeoutfailure.
Serverquiettime IftheIntellinetswitchisunabletoauthenticatetheclient,it’llwaitaspecifiedamount
oftimebeforetryingagain.Theamountoftimeisspecifiedwiththequiet‐period
parameter.Enteredinminutes;max.1440minutes(24hours).
Dead‐criteriaretrycount SetthenumberoftimesthattheIntellinetswitchdoesnotgetavalidresponsefrom
theRADIUSserverbeforetheserverisconsideredunavailable.
Dead‐criteriatimeout SetthetimeinsecondsduringwhichtheIntellinetswitchdoesnotneedtogetavalid
responsefromtheRADIUSserver.Therangeisfrom1to120seconds.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
68
6.12.2 RadiusServerConfig
Item Description
Serveraddress TypeintheaddressoftheRADIUSserver.
Chargingport TypetheaccountingportnumberontheRADIUSserver’shostcomputer.
Thedefaultportnumberis1813.
Authenticationport TypetheaccountingportnumberontheRADIUSserver’shostcomputer.
Thedefaultportnumberis1812.
Key Thekeyparameterintheradius‐servercommandisusedtoencryptRADIUS
packetsbeforetheyaresentoverthenetwork.Thevalueforthekey
parameterontheIntellinetswitchdeviceshouldmatchtheoneconfigured
ontheRADIUSserver.Thedefaultvalueis“radius”.
Activedetection EnablesordisablesactivedetectionofRADIUSserver.
Testname Theusernameforactivedetection.
Idletime TheintervaltimeforRADIUSsecurityserversendmessageonaccessible
state.Thedefaultvalueis60minutes.Possiblevaluesrangefrom0to1440
minutes(24hours).
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
69
6.13 AAA
Authentication,authorizationandaccounting(AAA)isasystemfortrackinguseractivitiesonanIP‐basednetworkand
controllingtheiraccesstonetworkresources.AAAisoftenisimplementedasadedicatedserver.
6.13.1 EnableConfig
EnableordisableAAA.
6.13.2 RegionConfig
Item Description
DomainnameTypeinthenameoftheISPdomain.AnInternetserviceprovider(ISP)domainisagroup
ofuserswhobelongtothesameISP.Forausernameintheformatofuserid@isp‐name
oruserid.isp‐name,theisp‐namefollowingthe"@"or“.”characteristheISPdomain
name.Theaccessdeviceusesuseridastheusernameforauthentication,andisp‐name
asthedomainname.
StatusSettoeither“block”or“active.”Bydefault,anISPdomainisintheactivestate,which
meansthatalltheusersinthedomainareallowedtorequestnetworkservice.
Verifythatthe
user…
Verifythattheuseriscarryingthedomainname.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
70
6.13.3 ServerConfig
Item Description
Servername Typeinthenamefortheserver.Thiscanbeadescriptivenameforeasier
identification.
ServerIPaddr ProvidetheIPaddressoftheRADIUSorTACACS+server.
Selectserver SettoeitherRADIUSorTACACS+.
Authenticationport ThisisanoptionalparameterforRADIUSservers.IfTACACS+isselected,the
portisfixedtoTCPport49.
ThescreenshotbelowshowsaRADIUSserverthathasbeenaddedtotheconfigurationusingthestandard
authenticationport1813(UDP).
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
71
6.13.4 AAAAuthentication
6.13.4.1 LoginAuthentication
Item Description
Chooseadomain SelecttheISPdomain.
LoginAuthentication Checktoactivateit.
First–FourthMethod None:Eliminatestherequirementforanyauthenticationmethod.
Local:Usesthelocalpasswordconfiguredonthedevicetograntaccess.
GroupRADIUS:UsesthelistofallRADIUSserversforauthentication.
GroupTACACS+:UsesthelistofallTACACS+serversforauthentication.
CustomServerGroup:Usesauthenticationofacustomservergroup.
6.13.4.2 EnableAuthentication
Thispagedescribeshowtoadd,editordeleteenableauthenticationlistsettings(the“default”listcannotbedeleted).
Thelinecombinedtothislistwillauthenticateauserwhoisissuingthe"enable"commandbyoneofthefourmethodsin
thislist.Ifthefirstmethodfails,thenextprioritymethodwillbetriedtoauthenticate,andsoon.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
72
6.13.4.3 Dot1xAuthentication
The802.1xstandarddefinesaclient‐server‐basedaccesscontrolandauthenticationprotocolthatpreventsunauthorized
clientsfromconnectingtoaLANthroughpubliclyaccessibleports,unlesstheyareproperlyauthenticated.The
authenticationserverauthenticateseachclientconnectedtoaswitchportbeforemakingavailableanyservicesoffered
bytheswitchortheLAN.
Note:Ifyouactivatethisbuthavenotconfiguredanyoftheauthenticationmethods(i.e.,RADIUS)correctly,youwilllose
accesstotheIntellinetswitch,andyoumayneedtoperformahardwareresetinordertore‐gainaccesstotheweb
admininterface.Seesection2.4.1FrontPanel.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
73
6.14 QOS–QUALITYOFSERVICE
QualityofService(QoS)isanadvancedtrafficprioritizationfeaturethatallowsyoutoestablishcontrolovernetwork
traffic.QoSenablestheassigningofvariousgradesofnetworkservicetodifferenttypesoftrafficsuchasmulti‐media,
video,protocol‐specific,timecriticalandfile‐backuptraffic.QoSreducesbandwidthlimitations,delay,lossandjitter.It
alsoprovidesincreasedreliabilityfordeliveryofdataandallowsfortheprioritizationcertainapplicationsacrossyour
network.Defineexactlyhowyouwanttheswitchtotreatselectedapplicationsandtypesoftraffic.
UseQoSonyoursystemtocontrolawidevarietyofnetworktrafficby:
• Classifyingtrafficbasedonpacketattributes.
• Assigningprioritiestotraffic(e.g.,tosethigherprioritiestotime‐criticalorbusiness‐criticalapplications).
• Applyingsecuritypolicythroughtrafficfiltering.
• ProvidingpredictablethroughputformultimediaapplicationssuchasvideoconferencingorVoiceoverIPby
minimizingdelayandjitter.
• Improvingperformanceforspecifictypesoftrafficandpreservingperformanceastheamountoftrafficgrows.
• Reducingtheneedtoconstantlyaddbandwidthtothenetwork.
• Managingnetworkcongestion.
6.14.1 QoSRules
Despitethename“Remark”or“QoSMulti‐Label,"thissectionactuallyallowsyoutocreateyourQualityofServicerules.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
74
Item Description
RuleIndex Keyintherulenumber.
Operationtype Setto“Equal”or“Alwaysmatch.”
Valuetype Thisvaluedefinesthekindofvalueyouintendtousefor
theQoSrule.
Value Keyinthevaluethatcorrespondstothevaluetypeyouselectedabove.
CoSmapping CoSstandsforClassofService.Thereareeightvaluestochoosefrom.
Priorityremark AsanalternativetoCoS
mapping,definethepriority
valuehere,values0–7.
Chooseporttoconfig SelecttheportorportsfortheQoSrule.Selectallportsifyouwanttheruleto
applytowhicheverportthedevicesareconnectedto.
6.14.2 QueueConfig
Inthissection,definewhichpriorityalgorithmyouwishtheIntellinetswitchtoutilize.
Item Description
Queuemode SP=StrictPriority,RR=RoundRobin,WRR=WeightedRoundRobinandWFQ=
WeightedFairQueuing.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
75
6.14.3 QueueMapping
6.14.3.1 CoS‐Queue‐Map
ThispageallowsthenetworkadministratortoclassifyCoSsettingstotrafficqueues.TheserverIDrepresentstheCoS
(ClassofServer)ID.
6.14.3.2 DSCP‐CoS‐Map
ThisallowsnetworkmanagerstodeterminetheoutputqueuethatisassignedperaspecificDSCPfield.TheDSCPfieldID
isrepresentedbytheserverID,andtheQUEUEIDislistedastheserverlistonthescreen.
6.14.3.3 Port‐CoS‐Map
ThispageallowsthenetworkadministratortoclassifyCoSsettingstothe18physicalportsontheIntellinetswitch.The
serverIDrepresentstheCoSID.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
76
6.15 ADDRESSTABLE
ToswitchdatapacketsbetweenLANportsefficiently,theIntellinetswitchmaintainsanaddresstable.Whentheswitch
receivesaframe,itassociatesthemediaaccesscontrol(MAC)addressofthesendingnetworkdevicewiththeLANport
onwhichitwasreceived.Indoingso,theswitchdrasticallycutsdownonunnecessarynetworktraffic,becauseinsteadof
floodingallLANportsofthesameVLANwiththeinformation,itonlysendsittotheportwheretherecipientis
connected.
6.15.1 AddressTableConfig
6.15.1.1 MACAdd&Delete
Thescreenisdividedintothreesections.
Section1(“clearMacaddrlist”)allowsyoutocleartheMACaddresstable.
Section2canbeusedtomanuallyenteraVLAN–MACAddress–Portpairing.
Section3displaysallMACaddressesthatarecurrentlyintheMACaddresstable.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
77
6.15.1.2 MACstudy&aging
ThissectionallowsthenetworkadministratortospecifythemaximumamountofMACaddressesthatcanbelearnedper
port,thedefaultinterfacemaximumbeing8191addresses.Interfacemaximumscannotexceedthedevicemaximum,
whichisalso8191.
Item Description
Ports SelectoneormultipleportsforwhichyouwanttodefinetheMACaddress
studylimit
MACaddressstudylimit KeyinthemaximumMACaddresslimitfortheselectedport(s).
TheIntellinetswitchalsoprovidesamechanismtoadjusttheagingtimeforstoredMACaddresses.Theagingtime
controlshowlongtheswitchkeepsstoringtheMACaddressintheMACaddresstable.Everytimeaclientsendsor
receivestraffic,theagingtimefortheclient’sMACaddressisreset.IfthereisnotrafficforaMACaddressinatime
framethatexceedsthetimedefinedintheagingtimefield,theMACaddressisremovedfromtheMACaddresstable.
Thedefaultagingtimeis300seconds.Settingthevalueto“0”disablestheagingtimemechanism,whichmeansthatthe
MACaddresstablewillkeepthelearnedaddressuntiltheswitchisreset.SincetheIntellinetswitchhasonlyfinitespace
toholdMACaddresses,itisrecommendedtokeeptheagingtimeatoraroundthedefaultvalue.
6.15.1.3 MACFilter
WiththisfeaturethenetworkadministratorcanpreventaccesstothenetworkforselectedMACaddressesandVLANIDs
(1=defaultVLAN).
Item Description
MACAddress TypeintheMACaddressthatyouwanttoblock.
MACaddressstudylimit TypeintheVLANIDifapplicable.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
78
6.16 SNMP
SimpleNetworkManagementProtocol(SNMP)isanOSILayer7(ApplicationLayer)designedspecificallyformanaging
andmonitoringnetworkdevices.SNMPenablesnetworkmanagementstationstoreadandmodifythesettingsof
gateways,routers,switchesandothernetworkdevices.UseSNMPtoconfiguresystemfeaturesforproperoperation,
monitorperformanceanddetectpotentialproblemsintheswitch,switchgroupornetwork.
6.16.1 SNMPConfig
ActivateordeactivateSNMP.
6.16.1.1 CommunityConfig
Item Description
Communityname SNMPCommunitystring.TheSNMPread‐onlycommunitystringislikea
password.ItissentalongwitheachSNMPGet‐Requestandallows(ordenies)
accesstodevice.
Accessauthority Settoread‐onlyorread‐write.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
79
6.16.1.2 GroupConfig
TheIntellinetswitchusesaview‐basedaccesscontrolmodelthatallowsthenetworkadministratortoconfigurethe
accessprivilegesgrantedtoagroup.
Item Description
Groupname Provideagroupname.
Securitylevel Selectthedesiredsecuritylevel.
Readview
Readandwriteview
Notifyview
Assignthedesiredview(aviewmustbecreatedfirst‐seeSNMPViewConfig).
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
80
6.16.1.3 UserConfig
ThissectionallowssettingupSNMPusersandassigningthemtoanSNMPgroup.
Item Description
Username Provideagroupname.
Securitylevel Selectthedesiredsecuritylevel.
Groupname Provideagroupname.
Authenticationmode Selectthehashfunctionofchoice.
Authenticationpassword Keyinthepassword.
Encryptionmode SelecteitherAESorDEStoencryptthepassword.
Encryptedpassword Keyintheencryptedpassword.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
81
6.16.1.4 TrapConfig
SNMPtrapsarealertsgeneratedbyagentsonamanageddevice.
Item Description
DestinationIPAddress TheIPaddressoftheSNMPmanager(TRAPviewer).
Addresstype IPv4(andperhapslaterIPv6willbesupported)
Securityname Whenusingsecuritymodev3,selectauserfromadropdownlist.That
userwascreatedintheSNMPuserconfig.
UDPportnumber PortforSimpleNetworkManagementProtocolTrap(SNMPTRAP).
Securitymode Selectthesecuritymode(V1,V2orV3).
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
82
6.16.1.5 ViewConfig
SNMPv3definestheconceptofManagementInformationBase(MIB)viewsinRFC3415,View‐basedAccessControl
Model(VACM)forSNMP.MIBviewsprovideanagentbettercontroloverwhocanaccessspecificbranchesandobjects
withinitsMIBtree.AviewconsistsofanameandacollectionofSNMPobjectidentifiers,whichareeitherexplicitly
includedorexcluded.Oncedefined,aviewisthenassignedtoanSNMPgroup‐seeSNMPGroupConfig.
Onceaviewhasbeencreated,createarulefortheview.
Item Description
Rule Alsoreferredtoasthe'"Type."Specifieswhethertoincludeorexcludetheview
subtreeorfamilyofsubtreesfromtheMIBview.
MIBsubtreeOID EnteranOIDstringforthesubtreetoincludeorexcludefromtheview.AnOID
stringis256charactersinlength.Forexample,thesystemsubtreeisspecifiedby
theOIDstring1.3.6.1.2.1.1.
Subtreemask ProvidetheOIDmaskhere.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
83
6.16.2 RMONConfig
RemoteMonitoring(RMON)isastandardmonitoringspecificationthatenablesvariousnetworkmonitorsandconsole
systemstoexchangenetwork‐monitoringdata.RMONisthemostimportantexpansionofthestandardSNMP.RMONis
asetofMIBdefinitionsusedtodefinestandardnetworkmonitorfunctionsandinterfaces,enablingthecommunication
betweenSNMPmanagementterminalsandremotemonitors.RMONprovidesahighlyefficientmethodtomonitor
actionsinsidethesubnets.
MIDofRMONconsistsof10groups.TheIntellinet16‐PortGigabitEthernetPoE+Web‐ManagedSwitchsupportsthe
mostfrequentlyusedgroups1,2,3and9:
Statistics:CollectsEthernet,FastEthernet,andGigabitEthernetstatisticsonaninterface.
History:CollectsahistorygroupofstatisticsonEthernet,FastEthernet,andGigabitEthernetinterfacesfora
specifiedpollinginterval.
Alarm:MonitorsaspecificMIBobjectforaspecifiedinterval,triggersanalarmataspecifiedvalue(rising
threshold),andresetsthealarmatanothervalue(fallingthreshold).Alarmscanbeusedwithevents;thealarm
triggersanevent,whichcangeneratealogentryoranSNMPtrap.
Event:Determinestheactiontotakewhenaneventistriggeredbyanalarm.Theactioncanbetogeneratea
logentryoranSNMPtrap.
RMONisspecifiedaspartoftheMIBinRFC1757asanextensionoftheSNMP.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
84
6.16.2.1 StatisticsGroup
Item Description
Index Specifythehistorytableindexnumber.
Interfacename SelectoneoftheeighteenGigabitportfromthedrop‐downlist.
Owner Optionalfieldthatallowsthenetworkadministratortoenterthenameofthe
owneroftheStatisticsRMONgroup.
6.16.2.2 HistoryGroup
Item Description
Index Specifythehistorytableindexnumber.
Interfacename Selectoneofthe18Gigabitportsfromthedrop‐downlist.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
85
Maximumnumberof
samples
Thisisthenumberofsamples("buckets")tokeepbeforetheyareoverwritten.
Sampleperiod Thenumberofsecondsineachpollingcycle.
6.16.2.3 AlarmGroup
Item Description
Index Specifythealarmtableindexnumber.
Statictable SpecifytheMIBvariablethatismonitoredbythealarmentry.
Statisticalgroupindex Thisisthenumberofsamples("buckets")tokeepbeforetheygetoverwritten.
Samplingtime
interval
Thenumberofsecondsineachpollingcycle.
Sampletype Thisisthemethodofsamplingtheselectedvariableandcalculatingthevaluetobe
comparedagainstthethresholds.
Owner Optionalfieldthatallowsthenetworkadministratortoenterthenameofthe
owneroftheAlarmRMONgroup.
Thealarmthreshold
limit
Thisistherisingthreshold,anumberatwhichthealarmistriggered.Thisvalue
rangesbetween0and2147483647.
Eventsexceeding
threshold
Theeventnumbertotriggerwhentherisingthresholdexceedsitslimit.
Alarmthresholdlimit Thisisthefallingthreshold,anumberatwhichthealarmisreset.Thisvalueranges
between0and2147483647.
Eventsbelow
thresholdlimit
Theeventnumbertotriggerwhenthefallingthresholdexceedsitslimit.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
86
6.16.2.4 EventGroup
Item Description
Index Specifytheeventtableindexnumber.
Description Adescriptivenameoftheevent.
Owner Optionalfieldthatallowsthenetworkadministratortoenterthenameofthe
owneroftheEventRMONgroup.
Action Settoeither"Log"ifyouwanttogeneratealogentry,or"Trap"inordergenerate
atrapmessage.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
87
6.17 SYSTEM
6.17.1 SystemConfig
6.17.1.1 SystemSettings
Item Description
VLAN ThedefaultVLANIDoftheswitch("1:bydefault).
IP TheLANIPaddressoftheswitch.ThedefaultIPaddressis"192.168.2.1".
Mask Thedefaultnetworkmaskis255.255.255.0.
DefaultGateway TheoptionaldefaultgatewayonlyisneededwhenyourequireInternetaccessfor
theIntellinetswitch,forexampleinordertoobtaintimeinformationfromanNTP
server.
Jumboframe HereyoucanspecifythemaximumframesizesupportedbytheIntellinetswitch.
Themaximumis9216(kB).
DNSServer TheoptionalDNSserverisonlyneededwhenyourequireInternetaccessforthe
Intellinetswitch,forexampleinordertoobtaintimeinformationfromanNTP
server.
Logintimeout ThisparameterappliestothewebadministratorUI.Bydefault,userswillbe
automaticallyloggedoutafter30minutesofinactivity.
IPv6address OptionalIPv6addressfortheIntellinetswitch.
Devicename DevicenamefortheIntellinetswitch.
Deviceposition,
contactsandcontact
information
OptionaladditionalinformationyoucanprovidefortheIntellinetswitch.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
88
Item Description
Settime ClickinordertosetthetimefortheIntellinetswitchmanually.
[]NTPServer ActivatethisoptionfortheIntellinetswitchtoobtainthesystemtimefromanNTP
server.Forthattowork,besuretoprovideapropergatewayandDNSserver
address.
SNTPServerIP ProvidetheIPaddressoftheNTPserveryouwishtouse.Thiscanbeaninternal,or
externaladdress.
TimeZone Adjustthetimezoneforyourcurrentlocation.
6.17.1.2 SystemRestart
Click
"Restart"inordertohavetheIntellinetswitchperformasystemrestart.
6.17.1.3 Password
This
screenallowyoutochangetheadministratorpassword.Thedefaultpasswordis"1234".
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
89
6.17.1.4 EEEEnable
Energy‐
EfficientEthernet(EEE)isasetofenhancementstothetwisted‐pairandbackplaneEthernetfamilyofcomputer
networkingstandardsthatallowforlesspowerconsumptionduringperiodsoflowdataactivity.Theintentionwasto
reducepowerconsumptionby50%ormore,whileretainingfullcompatibilitywithexistingequipment.TheInstituteof
ElectricalandElectronicsEngineers(IEEE),throughtheIEEE802.3aztaskforce,developedthestandard.EEEworksby
poweringdowncircuitswhenthereisnotraffic.
Whenaportispowereddowntosavepower,theoutgoingtrafficisstoredinabufferuntiltheportispoweredup
again.Usingthistechnique,morepowercanbesavedifthetrafficcanbebufferedupuntilalargeburstoftrafficcan
betransmitted.Keepinmindthatbufferingtrafficwillgivesomelatencyinthetraffic.
ShouldyouencounterproblemsrelatedtoEEE(e.g.,relatedtoautonegotiation),disableEEEsupportandtheIntellinet
switchwillnolongeruseit.
6.17.1.5 SSHLogin
Activate
SSHsupportbysettingtheSSHCONFIGto"OPEN".
6.17.1.6 TelnetLogin
Activate
TelnetsupportbysettingtheTELNETCONFIGto"OPEN".
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
90
6.17.1.7 SystemLog
TheIntellinetPoEswitchcancreateahistorylogofimportantevents.Theselogscanbestoredeitherintheswitch's
ownmemoryoronaremoteSyslogserver.Inordertoutilizetheloggingservice,youmustfirstenableit.
Item Description
Logswitch SelectoneoftheeighteenGigabitportfromthedrop‐downlist.
ServerIP ProvidetheIPaddressoftheSyslogserver.NotethattheSyslogservermustbeset
toUDPport514.
Sendloglevel DefinetheamountofdetailyouwishtheIntellinetswitchtolog.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
91
6.17.2 SystemUpdate
Intellinetmayreleaseanewfirmwareforthisswitchprovingnewfunctionsandperhapsbugfixes.Installthenew
firmwareonthisscreen.Shouldanewfirmwarebemadeavailable,itwillbeavailableathttp://intellinet‐
network.com/search?q=561198.
Howto
installthenewfirmware:
1. Downloadthefirmwarefromthewebsite.
2. IfthefirmwareisacompressedfilesuchasRAR,7ZorZIP,uncompressthefilefirst,beforeitcanbeinstalledon
theIntellinetswitch.
3. Thecorrectfileextensionforthefirmwareis".bix".
4. Click"Browse"andselectthe".bix"filefromyourcomputer'sHDD.
5. Click"StartUpgrade".
6. ConfirmyourdecisionbyclickingOK.Theupgradewillnowbegin.
7. Hopethattherewon'tbeapoweroutageduringthenext3minutes.
Notethatifyoustillseethemessageaboveafter5minutes,openanewbrowserwindowandre‐connecttotheIP
addressoftheIntellinetswitch(default=http://192.168.2.1).
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
92
6.17.3 ConfigurationManagement
6.17.3.1 ConfigExportandImport
Thisfunctionallowsforbacking‐upandrestoringtheconfigurationdataoftheIntellinetswitch.
Item Description
Showcurrentconfig Showsthecurrentswitchconfigurationinapop‐upwindow.
ExportConfig Letsyousavethecurrentconfigurationdatatoafileonyourcomputer'sHDD.
Backup Whenafilenameisprovided(seebelow),clickthisbuttontocreateabackupof
theconfiguration,whichtheIntellinetswitchwillkeepinitsmemory.Theconfig
restorefunctionprovidesaccesstothesebackupsandletsyourestorethem,
deletethem,renamethemorsavethemtoyourcomputer'sHDD.
Filename Filenameforbacklup,e.g.,backup.
Importconfiguration Inordertouploadapreviouslysavedconfiguration,activatethisoption,thenclick
on"Browse"andselectthecorrect".conf"fromyourcomputer'sHDD.Clickthe
"ImportConfiguration"buttontobegin.
6.17.3.2 ConfigRestore
Theconfigrestorefunctionprovidesaccesstobackupsthatwerecreatedpreviouslyinordertorestorethem,delete
them,renamethemorsavethemtoyourcomputer'sHDD.
6.17.3.3 FactoryReset
This
featureallowsforrestoringallsettingstofactorydefaultvalues.Ifyou'relockedoutfromconfiguringtheswitchand
havelostaccesstothewebadmininterface,reinstatethefactorydefaultsettingsbypressingtheresetbuttononthe
frontoftheswitchfor20seconds.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
93
6.17.4 ConfigSave
TheIntellinet16‐PortGigabitEthernetPoE+Web‐ManagedSwitchprovidesamyriadofconfigurationoptions,manyof
whicharedesignedforexperiencednetworkadministratorsandaren’teasytoconfigure.Itwouldbearealshameifall
theconfigurationdatawaslostafterapowerfailureoraftertheswitchwasrestarted.Inordertomaketheconfiguration
permanent,itneedstobesaved.
6.17.5 UserAccounts
Thispageisdesignedtoconfigureuseraccounts.Auseraccountthatdoesnothaveadministratorrightscanonly
monitorthemainstatusinformationoftheIntellinetswitch,butcannotmakeanychangestotheconfiguration.
Item Description
Username Whencreatinganewaccount,typeinthenewusername.Ifeditingan
existingaccount,thefieldwillberead‐only.
Newpassword Typeinthenewpassword.
Confirmnewpassword Repeatthenewpassword.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
94
6.17.6 InformationCollect
Clickonthe buttoncreateafilethatcontainstheconfigurationdataoftheIntellinetswitch.Afewsecondslater,
youwillbeaskedtoopenorsavethefile(orwhateverwebbrowserdefaultactionforunknownfilesisinplaceonyour
system).Thisinformationcanbeusefulwhenitcomestotroubleshootingtechnicalproblems.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
95
7 WARRANTY
Deutsch‐ GarantieinformationenfindenSiehierunterintellinetnetwork.com/warranty.
English‐Forwarrantyinformation,gotointellinetnetwork.com/warranty.
Español‐Sideseaobtenerinformaciónsobrelagarantía,visiteintellinetnetwork.com/warranty.
Français‐Pourconsulterlesinformationssurlagarantie,rendezvousàl’adresseintellinetnetwork.com/warranty.
Italiano‐Perinformazionisullagaranzia,accedereaintellinetnetwork.com/warranty.
Polski‐Informacjedotyczącegwarancjiznajdująsięnastronieintellinetnetwork.com/warranty.
México‐PólizadeGarantíaIntellinet—DatosdelimportadoryresponsableanteelconsumidorICIntracomMéxico,
S.A.P.I.deC.V.•Av.InterceptorPoniente#73,Col.ParqueIndustrialLaJoya,CuautitlanIzcalli,EstadodeMéxico,C.P.
54730,México.•Tel.(55)1500‐4500
Lapresentegarantíacubrelossiguientesproductoscontracualquierdefectodefabricaciónensusmaterialesymanode
obra.
A.GarantizamoscámarasIPyproductosconpartesmóvilespor3años.
B.Garantizamoslosdemásproductospor5años(productossinpartesmóviles),bajolassiguientescondiciones:
1.Todoslosproductosaqueserefiereestagarantía,amparasucambiofísico,sinningúncargoparaelconsumidor.
2.Elcomercializadornotienetalleresdeservicio,debidoaquelosproductosquesegarantizannocuentancon
reparaciones,nirefacciones,yaquesugarantíaesdecambiofísico.
3.Lagarantíacubreexclusivamenteaquellaspartes,equipososub‐ensamblesquehayansidoinstaladasdefábricayno
incluyeenningúncasoelequipoadicionalocualesquieraquehayansidoadicionadosalmismoporelusuarioo
distribuidor.
Parahacerefectivaestagarantíabastaráconpresentarelproductoaldistribuidoreneldomiciliodondeueadquiridoo
eneldomiciliodeICIntracomMéxico,S.A.P.I.deC.V.,juntoconlosaccesorioscontenidosnsuempaque,acompañado
desupólizadebidamentellenadayselladaporlacasavendedoraindispensableelselloyfechadecompra)dondelo
adquirió,obien,lafacturaoticketdecompraoriginaldondesemencioneclaramenteelmodelo,numerodeserie
(cuandoaplique)yfechadeadquisición.Estagarantíanoesválidaenlossiguientescasos:Sielproductosehubiese
tilizadoencondicionesdistintasalasnormales;sielproductonohasidooperadoconformealosinstructivosdeuso;osi
elproductohasidoalteradootratadodeserreparadoporelconsumidoroterceraspersonas.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
96
8 COPYRIGHT
Copyright©2015ICIntracom.Allrightsreserved.Nopartofthispublicationmaybereproduced,transmitted,
transcribed,storedinaretrievalsystem,ortranslatedintoanylanguageorcomputerlanguage,inanyformorbyany
means,electronic,mechanical,magnetic,optical,chemical,manualorotherwise,withoutthepriorwrittenpermissionof
thiscompany
Thiscompanymakesnorepresentationsorwarranties,eitherexpressedorimplied,withrespecttothecontentshereof
andspecificallydisclaimsanywarranties,merchantabilityorfitnessforanyparticularpurpose.Anysoftwaredescribedin
thismanualissoldorlicensed"asis".Shouldtheprogramsprovedefectivefollowingtheirpurchase,thebuyer(andnot
thiscompany,itsdistributor,oritsdealer)assumestheentirecostofallnecessaryservicing,repair,andanyincidentalor
consequentialdamagesresultingfromanydefectinthesoftware.Further,thiscompanyreservestherighttorevisethis
publicationandtomakechangesfromtimetotimeinthecontentsthereofwithoutobligationtonotifyanypersonof
suchrevisionorchanges.
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
97
9 FEDERALCOMMUNICATIONCOMMISSIONINTERFERENCESTATEMENT
ThisequipmenthasbeentestedandfoundtocomplywiththelimitsforaClassBdigitaldevice,pursuanttoPart15ofFCCRules.
Theselimitsaredesignedtoprovidereasonableprotectionagainstharmfulinterferenceinaresidentialinstallation.Thisequipment
generates,uses,andcanradiateradiofrequencyenergyand,ifnotinstalledandusedinaccordancewiththeinstructions,maycause
harmfulinterferencetoradiocommunications.However,thereisnoguaranteethatinterferencewillnotoccurinaparticular
installation.Ifthisequipmentdoescauseharmfulinterferencetoradioortelevisionreception,whichcanbedeterminedbyturning
theequipmentoffandon,theuserisencouragedtotrytocorrecttheinterferencebyoneormoreofthefollowingmeasures:
1.Reorientorrelocatethereceivingantenna.
2.Increasetheseparationbetweentheequipmentandreceiver.
3.Connecttheequipmentintoanoutletonacircuitdifferentfromthattowhichthereceiverisconnected.
4.Consultthedealeroranexperiencedradiotechnicianforhelp.
FCCCaution
Thisdeviceanditsantennamustnotbeco‐locatedoroperatinginconjunctionwithanyotherantennaortransmitter.Thisdevice
complieswithPart15oftheFCCRules.Operationissubjecttothefollowingtwoconditions:(1)thisdevicemaynotcauseharmful
interference,and(2)thisdevicemustacceptanyinterferencereceived,includinginterferencethatmaycauseundesiredoperation.
Anychangesormodificationsnotexpresslyapprovedbythepartyresponsibleforcompliancecouldvoidtheauthoritytooperate
equipment.
FCCRadiationExposureStatement:
ThisequipmentcomplieswithFCCradiationexposurelimitssetforthforanuncontrolledenvironment.Thisequipmentshouldbe
installedandoperatedwithminimumdistance20cmbetweentheradiator&yourbody.
Safety
Thisequipmentisdesignedwiththeutmostcareforthesafetyofthosewhoinstallanduseit.However,specialattentionmustbepaid
tothedangersofelectricshockandstaticelectricitywhenworkingwithelectricalequipment.Allguidelinesofthisandofthe
computermanufacturemustthereforebeallowedatalltimestoensurethesafeuseoftheequipment.
EUCountriesIntendedforUse
TheETSIversionofthisdeviceisintendedforhomeandofficeuseinAustria,Belgium,Bulgaria,Cyprus,Czech,Denmark,Estonia,
Finland,France,Germany,Greece,Hungary,Ireland,Italy,Latvia,Lithuania,Luxembourg,Malta,Netherlands,Poland,Portugal,
Romania,Slovakia,Slovenia,Spain,Sweden,Turkey,andUnitedKingdom.TheETSIversionofthisdeviceisalsoauthorizedforusein
EFTAmemberstates:Iceland,Liechtenstein,Norway,andSwitzerland.
EUCountriesNotIntendedforUse
None
16‐PortGigabitEthernetPoE+Web‐ManagedSwitchwith2SFPPorts
98
intellinetnetworkcom
©ICIntracom.Allrightsreserved.
IntellinetisatrademarkofICIntracom,registeredintheU.S.andothercountries.