D-Link DES-3528 - xStack Switch - Stackable User Manual - Dns Relay

Manual is about: Layer 2 Managed Stackable Fast Ethernet Switch CLI

Summary of DES-3528 - xStack Switch - Stackable

  • Page 1

    ® user manual product model: xstack ® des-3528/des-3552 series layer 2 managed stackable fast ethernet switch release 2.0

  • Page 2

    ©copyright 2009. All rights reserved. _________________________________________________________________________________ information in this document is subject to change without notice. © 2009 d-link corporation. All rights reserved. Reproduction in any manner whatsoever without the written permissi...

  • Page 3: Table Of Contents

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual ii table of contents web-based switch configuration ............................................................................................... 11 introduction ..............................................

  • Page 4

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual iii time settings ........................................................................................................................................................................... 38 timezone setti...

  • Page 5

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual iv voice vlan port settings ........................................................................................................................................................ 80 voice vlan oui settings...

  • Page 6

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual v stp bridge global settings ................................................................................................................................................... 118 stp port settings ...........

  • Page 7

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual vi dhcp server global settings ................................................................................................................................................ 148 dhcp server excluded addres...

  • Page 8

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual vii radius attributes assignment .............................................................................................................................................. 191 guest vlan configuration .....

  • Page 9

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual viii monitoring .................................................................................................................................. 259 device status .............................................

  • Page 10

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual ix wac authentication state ........................................................................................................................................ 290 arp & fdb table .........................

  • Page 11: Intended Readers

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual x intended readers the des-3528/des-3552 series manual contains information for setup and management of the switch. This manual is intended for network managers familiar with network management concepts and ...

  • Page 12: Section 1

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 11 section 1 web-based switch configuration introduction login to web manager web-based user interface web pages introduction all software functions of the switch can be managed, configured and monitored via...

  • Page 13: Web-Based User Interface

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 12 web-based user interface the user interface provides access to various switch configuration and management windows, allows you to view performance statistics, and permits you to graphically monitor the sy...

  • Page 14: Web Pages

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 13 area 3 presents switch information based on your selection and the entry of configuration data. Notice: any changes made to the switch configuration during the current session must be saved in the save ch...

  • Page 15: Section 2

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 14 section 2 configuration device information system information serial port settings ip address port configuration static arp settings user accounts system log configuration system severity settings dhcp re...

  • Page 16: Device Information

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 15 device information this window contains the main settings for all major functions on the switch and appears automatically when you log on. To return to the device i nformation window, click the des-3528 w...

  • Page 17: Serial Port Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 16 click apply to implement changes made. Serial port settings the following window contains information about the serial port settings to view this window click configuration > serial port settings. Figure ...

  • Page 18

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 17 you will need to enter the management vlan name of the vlan that contains the port connected to the management station that will access the switch. The switch will allow management access from stations wi...

  • Page 19

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 18.

  • Page 20: Port Configuration

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 19 port configuration this section contains information for configuring various attributes and properties for individual physical ports, including port speed and flow control. Port settings click configurati...

  • Page 21

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 20 a 1000base-t cable for connection between the switch port and other device capable of a gigabit connection. The mastersetting (1000m/full_m) will allow the port to advertise capabilities related to duplex...

  • Page 22: Port Description

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 21 port description the switch supports a port description feature where the user may name various ports on the switch. To assign names to various ports, click configuration > port configuration > port descr...

  • Page 23: Static Arp Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 22 figure 2 - 7 port error disabled window the following parameters are displayed: parameter description port displays the port that has been error disabled. Port state describes the current running state of...

  • Page 24: User Accounts

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 23 note: the switch supports up to 255 static arp entries. User accounts use the user account m anagement window to control user privileges, create new users and view existing user accounts. To view this win...

  • Page 25: System Log Configuration

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 24 the access authentication control feature, discussed later in this document. Once the user has logged in to the switch in the operator level, certain security screens and windows will not be made availabl...

  • Page 26: System Log Server

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 25 system log server the switch can send syslog messages to up to four designated servers using the system log server. To configure the system log settings click configuration > system log configuration > sy...

  • Page 27: System Severity Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 26 system severity settings the switch can be configured to allow alerts be logged or sent as a trap to an snmp agent or both. The level at which the alert triggers either a log entry or a trap message can b...

  • Page 28: Dhcp Relay

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 27 dhcp relay the relay hops count limit allows the maximum number of hops (routers) that the dhcp messages can be relayed through to be set. If a packet’s hop count is equal to or more than the hop count li...

  • Page 29

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 28 check and policy settings will have no effect. Dhcp relay agent information option 82 check this field can be toggled between enabled and disabled using the pull-down menu. It is used to enable or disable...

  • Page 30

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 29 note: for the circuit id sub-option of a standalone switch, the module field is always zero. Circuit id sub-option format: 1. 2. 3. 4. 5. 6. 7. 1 6 0 4 vlan module port 1 byte 1 byte 1 byte 1 byte 2 bytes...

  • Page 31

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 30 dhcp relay interface settings this window allows the user to set up a server, by ip address, for relaying dhcp/ bootp information to the dhcp server. The user may enter a previously configured ip interfac...

  • Page 32

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 31 dhcp relay option 60 settings this window is used to configure option 60 relay rules on the switch. Different strings can be specified for the same relay server, and the same string can be specified with ...

  • Page 33

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 32 dhcp relay option 61 default settings this window is used to configure the dhcp relay option 61 default settings. These settings are used to determine the rule to process those packets that have no option...

  • Page 34: Dhcp Local Relay Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 33 appropriate information into the box provided. Click add to create a new entry. To remove an entry, enter the appropriate client id information and click delete. To delete all entries click delete all. Dh...

  • Page 35: Mac Address Aging Time

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 34 mac address aging time this table specifies the length of time a learned mac address will remain in the forwarding table without being accessed (that is, how long a learned mac address is allowed to remai...

  • Page 36: Clipaging Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 35 figure 2 - 25 password encryption window clipaging settings clipaging status can be enabled or disabled in this window, it is enabled by default. Clipaging settings are used when issuing a command which c...

  • Page 37

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 36 downloaded to the switch. R – if the ip address has this letter attached, it denotes a firmware upgrade through the serial port rs232. T - if the ip address has this letter attached to it, it denotes a fi...

  • Page 38: Ping Test

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 37 boot click the set boot button under this heading to use this configuration file as the boot up firmware for the switch. This will apply upon the next reboot of the switch. Active click the active button ...

  • Page 39: Sntp Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 38 sntp settings the simple network time protocol (sntp) is a protocol for synchronizing computer clocks through the internet. It provides comprehensive mechanisms to access national time and frequency disse...

  • Page 40: Timezone Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 39 timezone settings the following window is used to configure time zones and daylight savings time settings for sntp. To configure the time zone settings for the switch, click configuration > sntp settings ...

  • Page 41: Mac Notification Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 40 from: day of the week enter the day of the week that dst will start on. From: month enter the month dst will start on. From: time in hh:mm enter the time of day that dst will start on. To: which week of t...

  • Page 42

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 41 the following parameters may be viewed and modified: parameter description state enable or disable mac notification globally on the switch. Interval (1-2147483647 sec) the time in seconds between notifica...

  • Page 43: Poe

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 42 poe the des-3528p switch supports power over ethernet (poe) as defined by the ieee 802.3af. Ports 1-8 can support poe up to 35w. Ports 1-24 can supply about 48 vdc power to powered devices (pds) over cate...

  • Page 44: Poe System Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 43 poe system settings to configure poe for the switch, click configuration > poe > poe system settings, which will reveal the following window for the user to configure: figure 2 - 35 poe system settings wi...

  • Page 45: Poe Port Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 44 poe port settings to configure the poe port settings on the switch, click configuration > poe > poe port settings, which will reveal the following window for the user to configure: figure 2 - 36 poe port ...

  • Page 46: Snmp Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 45 snmp settings simple network management protocol (snmp) is an osi layer 7 (application layer) designed specifically for managing and monitoring network devices. Snmp enables network management stations to...

  • Page 47: Snmp Global Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 46 snmp settings are configured using the menus located on the snmp v3 folder of the web manager. Workstations on the network that are given snmp access privileged to the switch can be restricted with the se...

  • Page 48: Snmp Group Table

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 47 snmp group table an snmp group created with this table maps snmp users (identified in the snmp user table) to the views created in the previous menu. To view this window, click configuration > snmp settin...

  • Page 49: Snmp User Table

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 48 snmp user table this window displays all of the snmp user's currently configured on the switch and also allows you to add new users. To view this window, click configuration > snmp settings > snmp user ta...

  • Page 50: Snmp Community Table

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 49 to implement changes made, click apply. Snmp community table use this table to view existing snmp community table configurations and to create a snmp community string to define the relationship between th...

  • Page 51: Snmp Host Table

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 50 snmp host table use the snmp h ost t able window to set up snmp trap recipients. To configure snmp host table entries, click configuration > snmp settings > snmp host table figure 2 - 42 snmp host table w...

  • Page 52: Snmp Trap Configuration

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 51 snmp trap configuration the following window is used to enable and disable trap settings for the snmp function on the switch. To view this window for configuration, click configuration > snmp settings > s...

  • Page 53

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 52 sflow analyzer server settings this window is used to configure the sflow analyzer server settings. You can specify more than one analyzer server with the same ip address but with different udp port numbe...

  • Page 54

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 53 figure 2 - 47 sflow flow sampler settings window the following parameters can be configured: parameter description from port / to port specifies the port or list of ports to be configured. Analyzer server...

  • Page 55: Stacking

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 54 stacking from firmware release v2.00 of this switch, the des-3528/des-3552 series now supports switch stacking, where a set of eight switches can be combined to be managed by one ip address through telnet...

  • Page 56

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 55 which determines the second lowest mac address and then will assign that switch as the backup master, if all priorities are the same. Slave – slave switches constitute the rest of the switch stack and alt...

  • Page 57: Stacking Mode Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 56 note: if there is a box id conflict when the stack is in the discovery phase, the device will enter a special standalone topology mode. Users can only get device information, configure box ids, save and r...

  • Page 58: Single Ip Management

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 57 single ip management simply put, d-link single ip management is a concept that will stack switches together over ethernet instead of using stacking ports or modules. There are some advantages in implement...

  • Page 59: Single Ip Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 58 the upgrade to v1.6 to better improve sim management, the des-3528/des-3552 series has been upgraded to version 1.6 in this release. Many improvements have been made, including: 1. The commander switch (c...

  • Page 60: Topology

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 59 figure 2 - 54 single ip settings window (enabled) the following parameters can be set: parameters description sim state use the pull-down menu to either enable or disable the sim state on the switch. Disa...

  • Page 61

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 60 figure 2 - 55 single ip management window - tree view the tree view window holds the following information under the data tab: parameter description device name this field will display the device nameof t...

  • Page 62

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 61 figure 2 - 56 topology view this window will display how the devices within the single ip management group are connected to other groups and devices. Possible icons in this screen are as follows: icon des...

  • Page 63: Tool Tips

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 62 tool tips in the topology view window, the mouse plays an important role in configuration and in viewing device information. Setting the mouse cursor over a specific device in the topology window (tool ti...

  • Page 64: Right-Click

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 63 right-click right-clicking on a device will allow the user to perform various functions, depending on the role of the switch in the sim group and the icon associated with it. Group icon figure 2 - 59 righ...

  • Page 65

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 64 click close to close the property window. Commander switch icon figure 2 - 61 right-clicking a commander icon the following options may appear for the user to configure: collapse - to collapse the group t...

  • Page 66: Menu Bar

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 65 collapse - to collapse the group that will be represented by a single icon. Expand - to expand the sim group, in detail. Add to group - add a candidate to a group. Clicking this option will reveal the fol...

  • Page 67: Firmware Upgrade

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 66 topology - display the topology view. Help about - will display the sim information, including the current sim version. Figure 2 - 67 about window firmware upgrade this screen is used to upgrade firmware ...

  • Page 68

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 67 save this file. Click upload to initiate the file transfer. To view this window click configuration > single ip management > upload log file figure 2 - 70 upload log file window.

  • Page 69: Section 3

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 68 section 3 l2 features jumbo frame 802.1q vlan voice vlan subnet vlan qinq 802.1v protocol vlan rspan settings gvrp settings gvrp timer settings asymmetric vlan settings mac-based vlan settings pvid auto a...

  • Page 70: Vlans

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 69 click apply to implement changes made. Vlans understanding ieee 802.1p priority priority tagging is a function defined by the ieee 802.1p standard designed to provide a means of managing traffic on a netw...

  • Page 71: Ieee 802.1Q Vlans

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 70 ieee 802.1q vlans some relevant terms: tagging - the act of putting 802.1q vlan information into the header of a packet. Untagging - the act of stripping 802.1q vlan information out of the packet header. ...

  • Page 72

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 71 figure 3 - 3 ieee 802.1q tag the ethertype and vlan id are inserted after the mac source address, but before the original ethertype/length or logical link control. Because the packet is now a bit longer t...

  • Page 73

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 72 every physical port on a switch has a pvid. 802.1q ports are also assigned a pvid, for use within the switch. If no vlans are defined on the switch, all ports are then assigned to a default vlan with a pv...

  • Page 74: Double Vlans

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 73 note: if no vlans are configured on the switch, then all packets will be forwarded to any destination port. Packets with unknown source addresses will be flooded to all ports. Broadcast and multicast pack...

  • Page 75

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 74 now has over 4000 vlans that can be placed, and this greatly expands the vlan network and enables greater support of customers utilizing multiple vlans on the network. Double vlans are basically vlan tags...

  • Page 76: 802.1Q Vlan

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 75 2. All ports must be configured as access ports or uplink ports. Access ports can only be ethernet ports while uplink ports must be gigabit ports. 3. Provider edge switches must allow frames of at least 1...

  • Page 77

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 76 figure 3 - 7 802.1q vlan window – add/edit vlan tab window to return to the 802.1q v lan window, click the vlan l ist tab at the top of the window. To change an existing 802.1q vlan entry, click the corre...

  • Page 78

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 77 advertisement enabling this function will allow the switch to send out gvrp packets to outside sources, notifying that they may join the existing vlan. Port settings allows an individual port to be specif...

  • Page 79

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 78 figure 3 - 10 802.1q vlan window – vlan batch settings window the following fields can be set in the vlan batch settings window: parameter description vid list (e.G 2-5) enter a vlan id list that can be a...

  • Page 80: Voice Vlan

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 79 voice vlan voice vlan is a vlan used to carry voice traffic from ip phones. Because the sound quality of an ip phone call will be deteriorated if the data is unevenly sent, the quality of service (qos) fo...

  • Page 81: Voice Vlan Port Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 80 voice vlan name click the radio button and enter a name for a voice vlan. Voice vlan id (1-4094) click the radio button and enter a vlan id for a voice vlan. Priority use the pull down menu to set the pri...

  • Page 82: Voice Vlan Oui Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 81 mode select the mode between auto and manual. If the mode is auto, the port may become the voice vlan member port by auto-learning. If the mac address of the the received packet matches the configured oui...

  • Page 83: Subnet-Based Vlan

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 82 subnet-based vlan the switches uses ip subnet-based vlan claasification to group devices. Figure 3 - 15 application of subnet vlan the above figure is an example of subnet-based vlan. The ip address of cu...

  • Page 84: Subnet-Based Vlan Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 83 subnet-based vlan settings the subnet-based vlan settings are used to create, find or delete a subnet-based vlan entry. A subnet-based vlan entry is an ip subnet-based vlan classification rule. If an unta...

  • Page 85: Vlan Precedence Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 84 vlan precedence settings the vlan precedence settings are used to configure vlan classification precedence on each port. You can specify the order of mac-based vlan classifications and subnet-based vlan c...

  • Page 86: Q-In-Q

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 85 q-in-q q-in-q settings this function allows the user to enable or disable the q-in-q function. Q-in-q is designed for service providers to carry traffic from multiple users across a network. Q-in-q is use...

  • Page 87: Vlan Translation Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 86 from port / to port a consecutive group of ports that are part of the vlan configuration starting with the selected port. Role the user can choose between uni or nni role. Uni – to select a user-network i...

  • Page 88: 802.1V Protocol Vlan

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 87 q-in-q and vlan translation rules for ingress untagged packets at uni ports: 1. The switch does not reference the vlan translation table. 2. Check the switch vlan tables. The sequence is mac-based vlan ->...

  • Page 89

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 88 802.1v protocol vlan settings the table allows the user to configure protocol vlan settings. The lower half of the table displays any previously created settings. To view this window click l2 features > 8...

  • Page 90: Rspan Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 89 rspan settings this table controls the rspan function. The purpose of the rspan function is to mirror the packets to a remote switch. The packet travels from the switch where the monitored packet is recei...

  • Page 91: Gvrp Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 90 gvrp settings the garp vlan registration protocol (gvrp) is a mechanism that dynamically maintain vlan information on the switch, share the information to other gvrp-enabled switches and update switch inf...

  • Page 92: Gvrp Timer Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 91 ingress checking this field can be toggled using the space bar between enabled and disabled. Enabled enables the port to compare the vid tag of an incoming packet with the pvid number assigned to the port...

  • Page 93: Mac-Based Vlan Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 92 figure 3 - 26 asymmetric vlan settings window click apply to implement changes. Mac-based vlan settings this table is used to create mac-based vlan entries on the switch. A mac address can be mapped to an...

  • Page 94: Vlan Trunk Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 93 vlan trunk settings this window allows the user to configure the vlan trunk on the port of the switch. When the vlan trunk function is enabled, the vlan trunk ports shall be able to forward all tagged fra...

  • Page 95: Port Trunking

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 94 port trunking understanding port trunk groups port trunk groups are used to combine a number of ports together to make a single high-bandwidth data pipeline. Des-3528/des-3552 series supports up to 8 port...

  • Page 96

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 95 ports, which can only belong to a single link aggregation group. All of the ports in the group must be members of the same vlan, and their stp status, static multicast, traffic control; traffic segmentati...

  • Page 97: Lacp Port Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 96 lacp port settings the lacp port settings window is used to create port trunking groups on the switch. Using the following window, the user may set which ports will be active and passive in processing and...

  • Page 98: Traffic Segmentation

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 97 traffic segmentation traffic segmentation is used to limit traffic flow from a single port to a group of ports on either a single switch or a group of ports on another switch in a switch stack. This metho...

  • Page 99: Igmp Snooping

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 98 igmp snooping internet group management protocol (igmp) snooping allows the switch to recognize igmp queries and reports sent between network stations or devices and an igmp host. When enabled for igmp sn...

  • Page 100

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 99 the following fields can be set. Parameter description vlan id this is the vlan id that, along with the vlan name, identifies the vlan for which the user wishes to modify the igmp snooping settings. Vlan ...

  • Page 101

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 100 figure 3 - 35 igmp snooping router ip settings – edit window igmp snooping rate limit settings this table allows the user to configure the rate of igmp snooping control packets that are allowed per port ...

  • Page 102

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 101 igmp snooping static group settings this table is used to configure the current igmp snooping static group information on the switch. To view this window, click l2 features > igmp snooping > igmp snoopin...

  • Page 103

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 102 figure 3 - 40 igmp multicast group profile settings window – group list enter the multicast address list and click add the new information will be displayed in the table. Click to return to the igmp mult...

  • Page 104

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 103 untagged source port (e.G.:1-4,6) select the untagged source port to add to the multicast vlan. Remap priority the remap priority is associated with the data traffic to be forwarded on the multicast vlan...

  • Page 105

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 104 figure 3 - 44 ipv4 multicast profile settings – edit window to configure the group list settings click the hyperlinked group list . Figure 3 - 45 ipv4 multicast address group list settings – group list w...

  • Page 106: Multicast Filtering Mode

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 105 figure 3 - 47 ipv4 max multicast group settings window the following fields can be set: parameter description ports / vlan id use the drop-down menu to choose ports or vlan id. Max group (1-1024) enter t...

  • Page 107

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 106 to add a new multicast filter enter the information and click apply. To view all the vlans, click the view all button. Cpu filter l3 control packet settings the cpu filter l3 control packet settings is u...

  • Page 108: Mld Snooping Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 107 from port / to port check the corresponding boxes for the port(s) to filter control packets. State use the drop-down menu to enable or disable the filtering function. Igmp query tick the check box to set...

  • Page 109

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 108 figure 3 - 51 mld snooping settings window the following parameters may be viewed or modified: parameter description mld snooping state click the redio button to enable or disable the mld snooping functi...

  • Page 110

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 109 query interval (1-65535) the query interval field is used to set the time (in seconds) between transmitting mld queries. Entries between 1 and 65535 seconds are allowed. Default = 125. Max response time ...

  • Page 111

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 110 mld snooping rate limit settings this window is used to configure the rate of mld control packets that are allowed per port or per vlan. To view this window, click l2 features > mld snooping > mld snoopi...

  • Page 112

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 111 mld snooping static group settings this window is used to configure the mld snooping static group information on the swtich: to view this window, click l2 features > mld snooping > mld snooping static gr...

  • Page 113

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 112 mld snooping multicast vlan settings this window is used to configure the mld snooping multicast vlan settings on the switch. To view this window, click l2 f eatures > m ld s nooping > mld s nooping mult...

  • Page 114: Port Mirror

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 113 port mirror the switch allows you to copy frames transmitted and received on a port and redirect the copies to another port. You can attach a monitoring device to the mirrored port, such as a sniffer or ...

  • Page 115: Loopback Detection Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 114 loopback detection settings the loopback detection function is used to detect the loop created by a specific port. This feature is used to temporarily shutdown a port on the switch when a ctp (configurat...

  • Page 116

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 115 bpdu attack protection settings the bridge protocol data unit (bpdu) protection settings is to protect a port from receiving stp packets. Certain ports on the switch do not need to receive stp packets. W...

  • Page 117: Spanning Tree

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 116 note: the bpdu attack protection commands and stp function commands are mutually exclusivly. Therefore, when the stp function is enabled on a particular port, bpdu attack protection cannot be enabled. If...

  • Page 118

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 117 edge port the edge port is a configurable designation used for a port that is directly connected to a segment where a loop cannot be created. An example would be a port connected directly to a single wor...

  • Page 119: Stp Bridge Global Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 118 stp bridge global settings to open the following window, click l2 features > spanning tree > stp bridge global settings figure 3 - 62 stp bridge global settings window the following parameters can be set...

  • Page 120

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 119 max hops (6-40) used to set the number of hops between devices in a spanning tree region before the bpdu (bridge protocol data unit) packet sent by the switch will be discarded. Each switch on the hop co...

  • Page 121: Stp Port Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 120 stp port settings stp can be set up on a port per port basis. To view the following window click l2 features > spanning tree > stp port settings figure 3 - 63 stp port settings window in addition to sett...

  • Page 122

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 121 migrate setting this parameter as yes will set the ports to send out bpdu packets to other bridges, requesting information on their stp setting if the switch is configured for rstp, the port will be capa...

  • Page 123: Stp Instance Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 122 the window above contains the following information: parameter description configuration name a previously configured name set on the switch to uniquely identify the msti (multiple spanning tree instance...

  • Page 124: Mstp Port Information

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 123 figure 3 - 66 stp instance settings - view window mstp port information this window displays the current mstp port information and can be used to update the port configuration for an msti id. If a loop o...

  • Page 125: Forwarding & Filtering

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 124 forwarding & filtering this folder contains windows for unicast forwarding and multicast forwarding. Unicast forwarding to view this window, click l2 features > forwarding & filtering > unicast forwardin...

  • Page 126: Lldp

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 125 port settings allows the selection of ports that will be members of the static multicast group and ports either that are forbidden from joining dynamically, or that can join the multicast group dynamical...

  • Page 127: Lldp Port Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 126 delay (1-10) reinitializing after receiving an lldp disable command. To change the lldp reinit delay, enter a value in seconds (1 to 10). Lldp tx delay (1-8192) lldp tx delay allows the user to change th...

  • Page 128

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 127 tx and rx: the local lldp agent can both transmit and receive lldp frames. Disabled: the local lldp agent can neither transmit nor receive lldp frames. The defaut value is tx and rx. Ipv4 address the add...

  • Page 129: Lldp Basic Tlvs Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 128 lldp basic tlvs settings tlv stands for type-length-value, which allows the specific sending information as a tlv element within lldp packets. This window is used to enable the settings for the basic tlv...

  • Page 130: Lldp Dot1 Tlvs Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 129 lldp dot1 tlvs settings lldp dot1 tlvs are organizationally specific tlvs which are defined in ieee 802.1 and used to configure an individual port or group of ports to exclude one or more of the ieee 802...

  • Page 131: Lldp Dot3 Tlvs Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 130 lldp dot3 tlvs settings this window is used to configure an individual port or group of ports to exclude one or more ieee 802.3 organizational specific tlv data type from outbound lldp advertisements. To...

  • Page 132: Lldp Statistics System

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 131 lldp statistics system lldp statistics system allows you an overview of neighbor detection activity, lldp stastics and the settings for individual ports on the switch. Use the drop-down menu to check a s...

  • Page 133

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 132 figure 3 - 78 lldp local port information (show normal) window use the drop-down menu to select a port and click find the information will be displayed on the lower half of the window. To return to the p...

  • Page 134: Cfm

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 133 cfm connectivity fault management (cfm) is defined by ieee 802.1ag, which is a standard for detecting, isolating and reporting connectivity faults in a network. Cfm is an end-to-end per-service-instance ...

  • Page 135: Cfm Mps Reply Ltrs

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 134 figure 3 - 83 cfm ccm pdus forwarding mode window use the drop-down menu to forward by software or hardware and click apply. Cfm mps reply ltrs this window is used to enable the cfm maintenance point rep...

  • Page 136

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 135 connectivity fault management settings this window is used to configure the cfm settings on the switch. To view this window, click l2 features > cfm > connectivity fault management settings as shown belo...

  • Page 137: Cfm Loopback Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 136 cfm loopback settings this window is used to configure the cfm loopback settings on the switch. To view this window, click l2 features > cfm > cfm loopback settings as shown below: figure 3 - 87 cfm loop...

  • Page 138: Cfm Linktrace Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 137 cfm linktrace settings this window is used to configure the cfm linktrace settings on the switch. To view this window, click l2 features > cfm > cfm linktrace settings as shown below: figure 3 - 88 cfm l...

  • Page 139: Cfm Packet Counter List

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 138 cfm packet counter list this window is used to show the cfm packet counter list on the switch. To view this window, click l2 features > cfm > cfm packet counter list as shown below: figure 3 - 89 cfm pac...

  • Page 140: Browse Cfm Fault Mep

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 139 browse cfm fault mep this window is used to display the cfm fault mep on the switch. To view this window, click l2 features > cfm > browse cfm fault mep as shown below: figure 3 - 91 broose cfm fault mep...

  • Page 141: Ethernet Oam Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 140 the major features of ethernet oam are: oam discovery, link monitoring, remote fault indication and remote loopbacks. Ethernet oam settings this window is used to configure the ports ethernet oam mode. I...

  • Page 142

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 141 ethernet oam configuration settings this window is used to configure and display the primary controls and status information for ethernet oam on the switch. To view this window, click l2 features > ether...

  • Page 143: Section 4

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 142 section 4 l3 features ipv4 interface settings ipv4 default route settings gratuitous arp arp spoofing prevention settings dns relay dhcp server policy route settings the following section will aid the us...

  • Page 144

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 143 figure 4 - 3 ipv4 interface settings window - edit the following parameters can be configured: parameter description get ip from select static, bootp, or dhcp protocols to assign ipv4 address, subnet mas...

  • Page 145: Gratuitous Arp

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 144 parameter description ip address the ipv4 address of the default route. Subnet mask the corresponding subnet mask of the ip address entered into the table. Gateway the corresponding gateway of the ip add...

  • Page 146: Gratuitous Arp Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 145 gratuitous arp settings this window allows you to have more detailed settings for the gratuitous arp. To view this window, click l3 features > gratuitous arp > gratuitous arp settings as shown below: fig...

  • Page 147: Dns Relay

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 146 parameter description gateway ip address enter the ip address of the gateway. Gateway mac address enter the mac address of the gateway. Ports specify the switch ports for which to configure this arp spoo...

  • Page 148: Dns Relay Static Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 147 figure 4 - 8 dns relay global settings window the following fields can be configured: parameter description dnsr status this field can be toggled between disabled and enabled using the pull-down menu, an...

  • Page 149

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 148 receives this request, it returns a response to the client, containing the previously mentioned ip information that the dhcp client then utilizes and sets on its local configurations. The user can config...

  • Page 150: Dhcp Server Pool Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 149 dhcp server excluded address settings the following window will allow the user to set an ip address, or a range of ip addresses that are not to be included in the range of ip addresses that the switch wi...

  • Page 151

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 150 parameter description pool name denotes the name of the dhcp pool for which you are currently adjusting the parameters. Ip address enter the ip address to be assigned to requesting dhcp clients. The ip a...

  • Page 152

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 151 dhcp server manual binding the following windows will allow users to view and set manual dhcp entries. Manual dhcp entries will bind an ip address with the mac address of a device within a dhcp pool. The...

  • Page 153: Policy Route Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 152 policy based routing is a method used by the switch to give specified devices a cleaner path to the destination network. Used in conjunction with the access profile feature, the switch will identify traf...

  • Page 154

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 153 to add a new policy route, enter a name in policy route name field and click the create button. Click the corresponding edit button of the entry to see the following window. Figure 4 - 17 policy route se...

  • Page 155: Section 5

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 154 section 5 qos hol blocking pevention bandwidth control traffic control 802.1p default priority 802.1p user priority qos scheduling mechanism qos scheduling cos bandwidth control settings sred the des-352...

  • Page 156: Understanding Qos

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 155 figure 5 - 1 mapping qos on the switch the picture above shows the default priority setting for the switch. Class-7 has the highest priority of the eight priority queues on the switch. In order to implem...

  • Page 157: Hol Blocking Pevention

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 156 priority 5 is assigned to the switch's q5 queue. Priority 6 is assigned to the switch's q6 queue. Priority 7 is assigned to the switch's q6 queue. Note: in the des-3528/des-3552 series, the q7 is reserve...

  • Page 158: Bandwidth Control

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 157 bandwidth control the bandwidth control settings are used to place a ceiling on the transmitting and receiving data rates for any selected port. The transmitting rate (tx rate) and receiving rate (rx rat...

  • Page 159

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 158 until the storm has subsided. This method can be utilized by selecting the drop option of the action field in the window below. The switch will also scan and monitor packets coming into the switch by mon...

  • Page 160

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 159 action select the method of traffic control from the pull-down menu. The choices are: drop – utilizes the hardware traffic control mechanism, which means the switch’s hardware will determine the packet s...

  • Page 161: 802.1P Default Priority

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 160 note: ports that are in shutdown forever mode will be seen as link down in all windows and screens until the user recovers these ports. 802.1p default priority the switch allows the assignment of a defau...

  • Page 162: 802.1P User Priority

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 161 802.1p user priority the switch allows the assignment of a user priority to each of the 802.1p priorities. To view this window click qos > 802.1p user priority. Figure 5 - 6 802.1p user priority window o...

  • Page 163: Qos Scheduling Mechanism

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 162 qos scheduling mechanism changing the output scheduling used for the hardware queues in the switch can customize qos. As with any changes to qos implementation, careful consideration should be given to h...

  • Page 164: Qos Scheduling

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 163 qos scheduling this window allows the user to configure the way the switch will map an incoming packet per port based on its 802.1p user priority, to one of the eight available hardware priority queues a...

  • Page 165

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 164 cos bandwidth control settings this window allows to set the bandwidth control for specific cos on specific port. To view this window, click qos > cos bandwidth control settings as shown below: figure 5 ...

  • Page 166: Sred

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 165 sred simple random early detection (sred) is a simplified red mechanism based on asic capability. Random early detection (red) is a congestion avoidance mechanism at the gateway in packet switched networ...

  • Page 167: Sred Drop Counter

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 166 and probabilistic drop yellow colored packets if the queue depth is above the upper threshold. Green packets will not be dropped even it reach the threshold. Threshold low threshold low refers to the dro...

  • Page 168: Dscp Trust Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 167 dscp trust settings this window is used to enable dscp trust settings. To view this window click qos > sred > dscp trust settings figure 5 - 12 dscp trust settings window.

  • Page 169: Dscp Map Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 168 dscp map settings the dscp-to- priority mapping is used to determine the priority of the packet (which will then be used to determine the scheduling queue) when the port is in dscp trust state. The dscp-...

  • Page 170

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 169 figure 5 - 15 dscp map settings window – dscp to color the following parameters may be set: parameter description from port / to port a consecutive group of ports may be configured starting with the sele...

  • Page 171: 802.1P Map Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 170 802.1p map settings this window is used to enable 802.1p map settings. To view this window click qos > sred > 802.1p map settings figure 5 - 16 dscp map settings window the following parameters may be se...

  • Page 172: Section 6

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 171 section 6 security safeguard engine trusted host ip-mac-port binding port security dhcp server screening settings 802.1x guest vlan configuration ssl settings ssh access authentication control mac-based ...

  • Page 173

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 172 figure 6 - 1 mapping qos on the switch for every consecutive checking interval that reveals a packet flooding issue, the switch will double the time it will accept a few ingress arp and ip broadcast pack...

  • Page 174: Trusted Host

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 173 to configure the switch’s safeguard engine, change the state to enabled when the safeguard engine is enabled a green light will show on the gray bar at the top of this window, next to safeguard. To set t...

  • Page 175

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 174 imp binding global settings this window is used to enable or disable the trap log state and dhcp snoop state on the switch. The trap/log field will enable and disable the sending of trap log messages for...

  • Page 176: Imp Binding Port Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 175 imp binding port settings select a port or a range of ports with the from port and to port fields. Enable or disable the port with the state, allow zero ip and forward dhcp packet field, and configure th...

  • Page 177: Imp Binding Entry Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 176 dhcp packet by default, the dhcp packet with broadcast da will be flooded. When set to disable, the broadcast dhcp packet received by the specified port will not be forwarded. Mode the user may set the m...

  • Page 178: Dhcp Snooping Entries

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 177 dhcp snooping entries this table is used to view dynamic entries on specific ports. To view particular port settings, enter the port number and click find. To view all entries click view all, and to dele...

  • Page 179

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 178 figure 6 - 9 port security settings window the following parameters can be set: parameter description from port/to port a consecutive group of ports may be configured starting with the selected port. Adm...

  • Page 180: Port Security Fdb Entries

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 179 port security fdb entries this table is used to clear the port lock entries by individual ports, to clear entries enter the range of ports and click clear. To view the following window click, security > ...

  • Page 181

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 180 dhcp screening port settings the following window will allow users to enable ports on the switch to be used in dhcp server screening. To view this window, click security > dhcp server screening > dhcp sc...

  • Page 182: Dhcp Offer Filtering

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 181 dhcp offer filtering the following window will allow users to configure the dhcp server settings on the switch. To view this window, click security > dhcp server screening > dhcp offer filtering: figure ...

  • Page 183

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 182 figure 6 - 14 the three roles of 802.1x the following section will explain the three roles of client, authenticator and authentication server in greater detail. Authentication server the authentication s...

  • Page 184

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 183 figure 6 - 16 the authenticator note: when configuring the authentication protocol as local, the switch has two roles: authenticator and authentication server. Client the client is simply the endstation ...

  • Page 185

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 184 figure 6 - 18 the 802.1x authentication process the d-link implementation of 802.1x allows network administrators to choose between two types of access control used on the switch, which are: 1. Port-base...

  • Page 186

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 185 port-based network access control figure 6 - 19 example of typical port-based configuration once the connected device has been successfully authenticated, the port then becomes authorized, and all subseq...

  • Page 187: 802.1X Force Disconnect

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 186 host-based network access control figure 6 - 20 example of typical host-based configuration in order to successfully make use of 802.1x in a shared media lan segment, it would be necessary to create “log...

  • Page 188

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 187 to view this window, click security > 802.1x > 802.1x global settings as shown below: figure 6 - 22 802.1x global settings window this window allows you to set the following features: parameter descripti...

  • Page 189: 802.1X Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 188 802.1x settings to configure the 802.1x settings, click security > 802.1x > 802.1x settings figure 6 - 23 802.1x settings window this window allows you to set the following features: parameter descriptio...

  • Page 190: 802.1X User

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 189 portcontrol this allows you to control the port authorization state. Select forceauthorized to disable 802.1x and cause the port to transition to the authorized state without any authentication exchange ...

  • Page 191

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 190 authentication radius server the radius feature of the switch allows you to facilitate centralized user administration as well as providing protection against a sniffing, active hacker. To configure the ...

  • Page 192

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 191 radius attributes assignment the radius attributes assignment is used in the following modules: 802.1x (port-based and host-based), mac- based access control, web-based access control, and jwac (japanese...

  • Page 193

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 192 note: it is rfc description. Tunnel-medium-type the transport medium is used 6(802) required tunnel-private-group-id the group id for a particular tunneled session. A string (vlan name or vid) required a...

  • Page 194: Guest Vlan Configuration

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 193 on 802.1x security enabled networks, there is a need for non 802.1x supported devices to gain limited access to the network, due to lack of the proper 802.1x software or incompatible devices, such as com...

  • Page 195: Guest Vlan

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 194 guest vlan to view the following window click, security > 802.1x > guest vlan figure 6 - 27 guest vlan window the following fields may be modified to enable the 802.1x guest vlan: parameter description v...

  • Page 196: Download Certificate

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 195 and implementation of the certificate file and can be downloaded to the switch by utilizing a tftp server. The switch supports sslv3 and tlsv1. Other versions of ssl may not be compatible with this switc...

  • Page 197

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 196 rsa with rc4_128_md5 this ciphersuite combines the rsa key exchange, stream cipher rc4 encryption with 128- bit keys and the md5 hash algorithm. Use the pull-down menu to enable or disable this ciphersui...

  • Page 198: Ssh

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 197 ssh ssh is an abbreviation of secure shell, which is a program allowing secure remote login and secure network services over an insecure network. It allows a secure login to remote host computers, a safe...

  • Page 199

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 198 tcp port number (1-65535) specifies the tcp port used to communication between ssh client and server. The default value is 22. Rekey timeout using the pull-down menu uses this field to set the time perio...

  • Page 200

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 199 aes256-cbc check the box to enable the advanced encryption standard aes-256 encryption algorithm with cipher block chaining. The default is enabled. Arc4 check the box to enable the arcfour encryption al...

  • Page 201

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 200 auth. Mode the administrator may choose one of the following to set the authorization for users attempting to access the switch. Host based – this parameter should be chosen if the administrator wishes t...

  • Page 202

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 201 access authentication control the tacacs/xtacacs/tacacs+/radius commands allow users to secure access to the switch using the tacacs/xtacacs/tacacs+/radius protocols. When a user logs in to the switch or...

  • Page 203

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 202 authentication policy settings this command will enable an administrator-defined authentication policy for users trying to access the switch. When enabled, the device will check the login method list and...

  • Page 204: Authentication Server Group

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 203 login method list using the pull-down menu, configure an application for normal login on the user level, utilizing a previously configured method list. The user may use the default method list or other m...

  • Page 205: Authentication Server

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 204 figure 6 - 36 authentication server group settings edit window to add an authentication server host to the list, enter its ip address in the ip address field, choose the protocol associated with the ip a...

  • Page 206: Login Method Lists

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 205 configure the following parameters to add an authentication server host: parameter description ip address the ip address of the remote server host the user wishes to add. Port (1-65535) enter a number be...

  • Page 207: Enable Method Lists

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 206 figure 6 - 38 login method lists window the switch contains one method list that is set and cannot be removed, yet can be modified. To delete a login method list defined by the user, click the corresspon...

  • Page 208

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 207 figure 6 - 39 enable method list window to delete an enable method list defined by the user, click the the delete button. To modify an enable method list, click on its corresponding edit button. To defin...

  • Page 209: Radius Accounting Services

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 208 parameter description old local enable password if a password was previously configured for this entry, enter it here in order to change it to a new password new local enable password enter the new passw...

  • Page 210: Mac-Based Access Control

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 209 mac-based access control mac-based access control is a method to authenticate and authorize access using either a port or host. For port- based mac, the method decides port access rights, while for host-...

  • Page 211

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 210 figure 6 - 42 mac-based access control settings the following parameters may be viewed or set: parameter description settings state use the pull-down menu to globally enable or disable the mac-based acce...

  • Page 212

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 211 radius authorization used to enable or disable the accepting of authorized configuration. When this is enabled, the authorized data assigned by the raduis server will be accepted if the global authorizat...

  • Page 213: Web Authentication

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 212 web authentication web-based authentication login is a feature designed to authenticate a user when the user is trying to access the internet via the switch. The authentication process uses the http prot...

  • Page 214

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 213.

  • Page 215

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 214 conditions and limitations 1. If the client is utilizing dhcp to attain an ip address, the authentication vlan must provide a dhcp server or a dhcp relay function so that client may obtain an ip address....

  • Page 216

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 215 virtual ip is enabled, the tcp packets sent to the virtual ip or physical ipif’s ip address will both get a reply. When the virtual ip is set to 0.0.0.0 the fuction will be disabled. To ensure that this ...

  • Page 217

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 216 password enter the password the administrator has chosen for the selected user. This field is case sensitive and must be a complete alphanumeric string. This field is for administrators who have selected...

  • Page 218: Jwac Global Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 217 enter a value between 1 and 1440 minutes. A value of infinite indicates the idle state of the authenticated host on the port will never be checked. The default setting is infinite. Block time (1-300) if ...

  • Page 219

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 218 virtual ip this parameter specifies the jwac virtual ip address that is used to accept authentication requests from an unauthenticated host. Only requests sent to this ip will get a correct response. Not...

  • Page 220: Jwac Port Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 219 the jwac switch will monitor the quarantine server to ensure the server is okay. If the switch detects no quarantine server, it will redirect all unauthenticated http access attempts to the jwac login pa...

  • Page 221: Jwac User Settings

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 220 session timeout (1-1440 minutes) this parameter specifies the period of time a host will keep in authenticated state after it successes to authenticate. Enter a value between 1 and 1440 minutes. The defa...

  • Page 222: Jwac Customize Page

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 221 figure 6 - 50 jwac customize page language window jwac customize page to view jwac customize page for the switch, go to the security > jwac > jwac customize page figure 6 - 51 jwac customize page window ...

  • Page 223: Multiple Authentication

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 222 figure 6 - 52 netbios filtering settings window multiple authentication multiple authentication setting allows for multiple authentication to be supported on the switch. Previously 802.1x, mac-based acce...

  • Page 224

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 223 802.1x & impb mode figure 6 - 54 802.1x & impb mode this mode adds an extra layer of security by checking the ip mac-port binding (impb) table before trying one of the supported authentication methods. T...

  • Page 225

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 224 impb & jwac mode figure 6 - 55 impb & jwac mode this mode adds an extra layer of security by checking the ip mac-port binding (impb) table before trying one of the supported authentication methods. The i...

  • Page 226: Guest Vlan

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 225 figure 6 - 56 multiple authentication settings window guest vlan this window is used to display and configure the guest vlan settings on the switch. To view this window, click security > multiple authent...

  • Page 227: Section 7

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 226 section 7 acl acl configuration wizard access profile list cpu access profile list acl finder acl flow meter access profiles allow you to establish criteria to determine whether or not the switch will fo...

  • Page 228

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 227 figure 7 - 1 acl configuration wizard the following parameters can be configured. Parameter description type select the type of acl you wish to create, either normal or cpu. Profile name select a unique ...

  • Page 229: Access Profile List

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 228 access profile list creating an access profile is divided into two basic parts. The first is to specify which part or parts of a frame the switch will examine, such as the mac source address or the ip de...

  • Page 230

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 229 figure 7 - 4 add ethernet acl profile window click on the boxes at the top of the table, which will then turn red and reveal parameters for configuration. To create a new entry enter the correct informat...

  • Page 231

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 230 ethernet type selecting this option instructs the switch to examine the ethernet type value in each frame's header. Click create to view the new access profile list entry in the access profile list table...

  • Page 232

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 231 figure 7 - 7 access profile ethernet to set the access rule for ethernet, adjust the following parameters and click apply. Parameter description access id (1-128) type in a unique identifier number for t...

  • Page 233

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 232 the value entered in the priority field, which meets the criteria specified previously in this command, before forwarding it on to the specified cos queue. Otherwise, a packet will have its incoming 802....

  • Page 234

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 233 figure 7 - 10 add ipv4 acl profile click on the boxes at the top of the table, which will then turn red and reveal parameters for configuration. To create a new entry enter the correct information and cl...

  • Page 235

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 234 code value. Select igmp to instruct the switch to examine the internet group management protocol (igmp) field in each frame's header. Select type to further specify that the access profile will apply an ...

  • Page 236

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 235 figure 7 - 12 access profile details (ipv4) to return to the access profile list click show all profiles, to add a rule to a previously configured entry click on the corresponding add/view rules and then...

  • Page 237

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 236 switch and will be filtered. Select mirror to specify that packets that match the access profile are mirrored to a port defined in the config mirror port command. Port mirroring must be enabled and a tar...

  • Page 238

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 237 to configure the ipv6 ac l select ipv6 in the add acl profile window, enter the profile id and profile name into the top half of the screen in the add acl profile window and click select, the following w...

  • Page 239

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 238 click create to view the new access profile list entry in the access profile list table shown below. To add another access profile click add acl profile. To delete a profile click the corresponding delet...

  • Page 240

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 239 figure 7 - 19 access profile (ipv6) the following parameters may be configured for the ip (ipv4) filter. Parameter description access id (1-128) type in a unique identifier number for this access. This v...

  • Page 241

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 240 precedence header. Rx rate (1-15624) use this to limit rx bandwidth for the profile being configured. This rate is implemented using the following equation: 1 value = 64kbit/sec. (ex. If the user selects...

  • Page 242

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 241 figure 7 - 22 add packet content acl profile click on the boxes at the top of the table, which will then turn red and reveal parameters for configuration. To create a new entry enter the correct informat...

  • Page 243

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 242 note: only one packet_content_mask profile can be created. With this advanced unique packet content mask (also known as packet content access control list - acl), the d-link xstack ® switch family can ef...

  • Page 244

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 243 figure 7 - 25 access profile (packet content) the following parameters may be configured for the packet content filter. Parameter description access id (1-128) type in a unique identifier number for this...

  • Page 245: Cpu Interface Filtering

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 244 then the ingress rate is 640kbit/sec.) the user many select a value between 1 and 15624 or tick the no limit check box. The default setting is no limit. Time range name tick the check box and enter the n...

  • Page 246: Cpu Access Profile List

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 245 cpu access profile list in the following window, the user may globally enable or disable the cpu interface filtering state mechanism by using the radio buttons to change the running state. To access this...

  • Page 247

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 246 figure 7 - 29 add cpu acl profile window for ethernet parameter description select profile id (1-5) use the drop-down menu to select a unique identifier number for this profile set. This value can be set...

  • Page 248

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 247 figure 7 - 30 cpu access profile detail information window for ethernet the window shown below is the add cpu acl profile window for ip (ipv4). Figure 7 - 31 add cpu acl profile window for ip (ipv4) the ...

  • Page 249

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 248 protocol selecting this option instructs the switch to examine the protocol type value in each frame's header. You must then specify what protocol(s) to include according to the following guidelines: sel...

  • Page 250

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 249 figure 7 - 33 add cpu acl profile window for ipv6 the following parameters may be configured for the ipv6 filter. Parameter description select profile id use the drop-down menu to select a unique identif...

  • Page 251

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 250 figure 7 - 34 cpu access profile detail information window for ipv6 the window shown below is the add cpu acl profile window for packet content. Figure 7 - 35 add cpu acl profile window for packet conten...

  • Page 252

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 251 • 48-63 – enter a value in hex form to mask the packet from byte 48 to byte 63. • 64-79 – enter a value in hex form to mask the packet from byte 64 to byte 79. Click apply to set this entry in the switch...

  • Page 253

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 252 vlan id allows the entry of a vlan id for a previously configured vlan. 802.1p (0-7) enter a value from 0 to 7 to specify that the access profile will apply only to packets with this 802.1p priority valu...

  • Page 254

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 253 figure 7 - 41 add access rule window for ipv4 to set the access rule for ip, adjust the following parameters and click apply parameter description access id (1-100) type in a unique identifier number for...

  • Page 255

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 254 to establish the rule for a previously created cpu access profile: to configure the access rules for ip, open the cpu access profile list window and click add/view rules for an ipv6 entry. This will open...

  • Page 256

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 255 name configured in the time range settings window. This will set specific times when this access rule will be implemented on the switch. Ports specifies the access rule can take effect on one port or a r...

  • Page 257: Acl Finder

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 256 parameter description access id (1-100) type in a unique identifier number for this access. This value can be set from 1 to 100. Action select permit to specify that the packets that match the access pro...

  • Page 258

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 257 to open this window, click acl > acl flow meter figure 7 - 50 acl flow meter window the following fields may be configured: parameter description profile id / profile name the pre-configured profile id/n...

  • Page 259

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 258 • pir (64kbps) –specifies the peak information rate of the packet. Tha range is from 0 to 15624. The unit is 64kbps. That is to say, 1 means 64kbps. • cbs (kbyte) – specifies the committed burst size of ...

  • Page 260: Section 8

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 259 section 8 monitoring device status cable diagnostics cpu utilization port utilization packet size packets errors port access control browse arp table browse route table browse vlan show vlan ports browse...

  • Page 261: Cable Diagnostics

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 260 cable diagnostics this window displays the details of copper cables attached to specific ports on the switch. If there is an error in the cable this feature can determine the type of error and the positi...

  • Page 262: Cpu Utilization

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 261 figure 8 - 2 cable diagnostics window – various status enter the port number you wish to test and click test, the results will be display on the lower half of the table. Cpu utilization the cpu u tilizat...

  • Page 263: Port Utilization

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 262 port utilization the port utilization window displays the percentage of the total available bandwidth being used on the port. To view this window, click monitoring > port utilization: figure 8 - 4 port u...

  • Page 264: Packet Size

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 263 packet size the web manager allows packets received by the switch, arranged in six groups and classed by size, to be viewed as either a line graph or a table. Two windows are offered. To select a port to...

  • Page 265

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 264 value is one second. Record number select number of times the switch will be polled between 20 and 200. The default value is 200. 64 the total number of packets (including bad packets) received that were...

  • Page 266: Packets

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 265 packets the web manager allows various packet statistics to be viewed as either a line graph or a table. Six windows are offered. Received (rx) this table displays the rx packets on the switch. To select...

  • Page 267

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 266 the following fields may be set or viewed: parameter description port use the drop-down menu to choose the port that will display statistics. Time interval select the desired setting between 1s and 60s, ...

  • Page 268: Umb_Cast (Rx)

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 267 umb_cast (rx) this table displays the umb_cast rx packets on the switch. To select a port to view these statistics for, select the port by using the port pull-down menu. The user may also use the real-ti...

  • Page 269: Transmitted (Tx)

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 268 parameter description port use the drop-down menu to choose the port that will display statistics. Time interval select the desired setting between 1s and 60s, where "s" stands for seconds. The default v...

  • Page 270

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 269 figure 8 - 12 transmitted (tx) table window (for bytes and packets) the following fields may be set or viewed: parameter description port use the drop-down menu to choose the port that will display stati...

  • Page 271: Errors

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 270 errors the web manager allows port error statistics compiled by the switch's management agent to be viewed as either a line graph or a table. Four windows are offered. Received (rx) to select a port to v...

  • Page 272

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 271 the following fields can be set: parameter description port use the drop-down menu to choose the port that will display statistics. Time interval select the desired setting between 1s and 60s, where "s" ...

  • Page 273: Transmitted (Tx)

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 272 transmitted (tx) to select a port to view these statistics for, select the port by using the port pull-down menu. The user may also use the real-time graphic of the switch at the top of the web page by s...

  • Page 274: Port Access Control

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 273 record number select number of times the switch will be polled between 20 and 200. The default value is 200. Exdefer counts the number of packets for which the first transmission attempt on a particular ...

  • Page 275: Radius Authentication

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 274 radius authentication this table contains information concerning the activity of the radius authentication client on the client side of the radius authentication protocol. To view the radius authenticati...

  • Page 276: Radius Account Client

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 275 authentication server. Accessaccepts the number of radius access-accept packets (valid or invalid) received from this server. Accessrejects the number of radius access-reject packets (valid or invalid) r...

  • Page 277

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 276 figure 8 - 18 radius account client window the user may also select the desired time interval to update the statistics, between 1s and 60s, where “s” stands for seconds. The default value is one second. ...

  • Page 278: Authenticator State

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 277 responses. Badauthenticators the number of radius accounting-response packets, which contained invalid authenticators, received from this server. Pendingrequests the number of radius accounting-request p...

  • Page 279

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 278 figure 8 - 20 authenticator statistics window the user may also select the desired time interval to update the statistics, between 1s and 60s, where “s” stands for seconds. The default value is one secon...

  • Page 280

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 279 authenticator session statistics this window contains the session statistics objects for the authenticator pae associated with each port. An entry appears in this table for each port that supports the au...

  • Page 281: Authenticator Diagnostics

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 280 terminate cause the reason for the session termination. There are eight possible reasons for termination. 1) supplicant logoff 2) port failure 3) supplicant restart 4) reauthentication failure 5) authcon...

  • Page 282

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 281 disconnected as a result of receiving an eapol-logoff message. Auth enter counts the number of times that the state machine transitions from connecting to authenticating, as a result of an eap-response/i...

  • Page 283: Browse Arp Table

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 282 browse arp table this window displays current arp entries on the switch. To search a specific arp entry, enter an interface name or an ip address at the top of the window and click find. Click the show s...

  • Page 284: Show Vlan Ports

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 283 show vlan ports this window allows the vlan status for each of the switch's ports to be viewed by vlan. Select a port from the drop- down menu at the top of the window and click the find button. To view ...

  • Page 285: Browse Dhcp Conflict Ip

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 284 life time (sec) this field will display, in seconds, the time remaining on the lease for this ip address. Browse dhcp conflict ip this window displays dhcp conflict ip address on the switch. To view the ...

  • Page 286: Mld Snooping Group

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 285 mld snooping group the following window allows the user to view mld snooping groups present on the switch. Mld snooping is an ipv6 function comparable to igmp snooping for ipv4. The user may browse this ...

  • Page 287: Igmp Snooping

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 286 browse mld snooping counter this window is used to display the current mld snooping counter information on the switch. To view this window, click monitoring > mld snooping > browse mld snooping counter a...

  • Page 288: Igmp Snooping Group

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 287 igmp snooping group this window allows the switch’s igmp snooping group table to be viewed. Igmp snooping allows the switch to read the multicast group ip address and the souce ip address from igmp packe...

  • Page 289: Igmp Snooping Forwarding

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 288 igmp snooping forwarding this window will display the current igmp forwarding information on the switch. To view this window, click monitoring > igmp snooping > igmp snooping forwarding as shown below: f...

  • Page 290

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 289 figure 8 - 39 browse ethernet oam event log window browse ethernet oam statistics this window displays the ethernet oam statistic information on each port of the switch. To clear information for a partic...

  • Page 291: Jwac Authentication State

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 290 jwac authentication state this window allows the user to view the japanese web access control authentication information. Specify the port list you wish to view and click find. To remove an entry, enter ...

  • Page 292: Arp & Fdb Table

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 291 arp & fdb table this window displays current arp & fdp entries on the switch. To search a specific arp or fdb entry, select a port from the pull down menu, or enter a(n) mac/ip address at the top of the ...

  • Page 293: Mac Address Table

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 292 mac address table this allows the switch's dynamic mac address forwarding table to be viewed. When the switch learns an association between a mac address and a port number, it makes an entry into its for...

  • Page 294: System Log

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 293 system log the web manager allows the switch's history log, as compiled by the switch's management agent, to be viewed. To view the switch history log, click monitoring > system log figure 8 - 46 system ...

  • Page 295: Section 9

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 294 section 9 save services and tools save configuration id 1 save configuration id 2 save log save all configuration file backup & restore upload log file reset download firmware reboot system the four save...

  • Page 296: Save Configuration Id 2

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 295 save configuration id 2 open the save drop-down menu at the top of the web manager and click save c onfiguration i d 2 to open the following window: figure 9 - 2 save configuration id 2 window save log o...

  • Page 297: Upload Log File

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 296 configuration file backup & restore the switch supports dual image storage for configuration file backup and restoration. The firmware and configuration images are indexed by id number 1 or 2. To change ...

  • Page 298: Download Firmware

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 297 figure 12- 3. Reset system window download firmware the following window is used to download firmware for the switch. Figure 12- 4. Download firmware window enter the server ip address in the first field...

  • Page 299: Appendix A

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 298 appendix a mitigating arp spoofing attacks using packet content acl address resolution protocol (arp) is the standard method for finding a host's hardware address (mac address) when only its ip address i...

  • Page 300

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 299 address ff-ff-ff-ff-ff-ff 00-20-5c-01-11-11 table-2 (ethernet frame format) when the switch receives the frame, it will check the “source address” in the ethernet frame’s header. If the address is not in...

  • Page 301

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 300 when pc b replies to the arp request, its mac address will be written into “target h/w address” in the arp payload shown in table-3. The arp reply will be then encapsulated into the ethernet frame again ...

  • Page 302

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 301 how arp spoofing attacks a network arp spoofing, also known as arp poisoning, is a method to attack an ethernet network which may allow an attacker to sniff data frames on a lan, modify the traffic, or s...

  • Page 303

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 302 destination address source address ethernet type h/w type protocol type h/w address length protocol address length operation sender h/w address sender protocol address target h/w address target protocol ...

  • Page 304: Example Topology

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 303 • prevent arp spoofing via packet content acl concerning the common dos attack today caused by the arp spoofing, d-link managed switch can effectively mitigate it via its unique packet content acl. For t...

  • Page 305

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 304 offset chunk offset chunk0 offset chunk1 offset chunk2 offset chunk3 offset chunk4 offset chunk5 offset chunk6 offset chunk7 offset chunk8 offset chunk9 offset chunk10 offset chunk11 offset chunk12 offse...

  • Page 306

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 305.

  • Page 307: Appendix B

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 306 appendix b system log and trap list system log entries the following table lists all possible entries and their corresponding meanings that will appear in the system log of this switch. Category event de...

  • Page 308

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 307 configuration upload was unsuccessful configuration upload by console was unsuccessful! (username: ) warning log message successfully uploaded log message successfully uploaded by console (username: ) in...

  • Page 309

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 308 string stp topology changed topology changed informational new root selected new root selected informational bpdu loop back on port bpdu loop back on port warning spanning tree protocol is enabled spanni...

  • Page 310

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 309 aaa local method ) successful login through telnet authenticated by aaa local method successful login through telnet from authenticated by aaa local method (username: ) informational login failed through...

  • Page 311

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 310 login failed through web(ssl) due to aaa server timeout or improper configuration login failed through web(ssl) from due to aaa server timeout or improper configuration (username: ) warning successful lo...

  • Page 312

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 311 successful enable admin through console authenticated by aaa none method successful enable admin through console authenticated by aaa none method (username: ) informational successful enable admin throug...

  • Page 313

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 312 improper configuration. ) login failed through web from user due to aaa server timeout or improper configuration. Login failed through web from due to aaa server timeout or improper configuration (userna...

  • Page 314

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 313 broadcast storm cleared port broadcast storm has cleared informational multicast storm occurrence port multicast storm is occurring warning multicast storm cleared port multicast storm has cleared inform...

  • Page 315

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 314 system recover learning wac recovers from stop learning state. Warning mac login ok mac-ac login successful (mac: , port: , vid: ) information login fail mac-ac login rejected (mac: , port: , vid: ) warn...

  • Page 316: Proprietary Trap List

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 315 port recover from bpdu under attacking state automatically port recover from bpdu under attacking state automatically informational dhcp detect untrusted dhcp server ip address detected untrusted dhcp se...

  • Page 317

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 316 swipmacbindingstoplearningtrap 1.3.6.1.4.1.171.12.23.5.0.2 swipmacbindingnotifyprefix v2 ipmacbind-mib warning swipmacbindingrecoverlearningtrap 1.3.6.1.4.1.171.12.23.5.0.3 swipmacbindingnotifyprefix v2 ...

  • Page 318

    Xstack ® des-3528/des-3552 series layer 2 stackable fast ethernet managed switch user manual 317 agentgratuitousarptrap 1.3.6.1.4.1.171.12.1.7.2.0.5 agentnotifyprefix v2 genmgmt-mib warning.

  • Page 319: Appendix C

    318 appendix c glossary 1000base-sx: a short laser wavelength on multimode fiber optic cable for a maximum length of 2000 meters 1000base-lx: a long wavelength for a "long haul" fiber optic cable for a maximum length of 10 kilometers 1000base-t: 1000mbps ethernet implementation over category 5e cabl...

  • Page 320

    319 half duplex: a system that allows packets to be transmitted and received, but not at the same time. Contrast with full duplex. Ip ad dress: internet protocol address. A unique identifier for a device attached to a network using tcp/ip. The address is written as four octets separated with full-st...

  • Page 321

    320 udp - user datagram protocol: an internet standard protocol that allows an application program on one device to send a datagram to an application program on another device. Vlan - virtual l an: a group of location- and topology-independent devices that communicate as if they are on a common phys...

  • Page 322: Appendix D

    321 appendix d password recovery procedure this document describes the procedure for resetting passwords on d-link switches. Authenticating any user who tries to access networks is necessary and important. The basic authentication method used to accept qualified users is through a local login, utili...