Layer 2 Workgroup Switch
with 24 100BASE-BX (SFP) Ports, 2 1000BASE-T (RJ-45)
and 2 Combination Gigabit (RJ-45/SFP) Ports
ES3528M-SFP
E122007-DG-R01
149100035500A
About This Guide
Purpose
This guide gives specific information on how to operate and use the management
functions of the switch.
Audience
The guide is intended for use by network administrators who are responsible for operating
and maintaining network equipment; consequently, it assumes a basic working
knowledge of general switch functions, the Internet Protocol (IP), and Simple Network
Management Protocol (SNMP).
Conventions
The following conventions are used throughout this guide to show information:
Note: Emphasizes important information or calls your attention to related features or
instructions.
Caution: Alerts you to a potential hazard that could cause loss of data, or damage the
Warning: Alerts you to a potential hazard that could cause personal injury.
Related Publications
The following publication details the hardware features of the switch, including the
physical and performance-related characteristics, and how to install the switch:
The Installation Guide
Also, as part of the switch’s software, there is an online web-based help that describes all
management related features.
system or equipment.
Revision History
This section summarizes the changes in each revision of this guide.
November 2007 Revision
This is the second revision of this guide. This guide is valid for software release v1.1.0.7.
v
vi
Contents
Chapter 1: Introduction 1-1
Key Features 1-1
Description of Software Features 1-2
System Defaults 1-6
Community Strings (for SNMP version 1 and 2c clients) 2-6
Trap Receivers 2-7
Configuring Access for SNMP Version 3 Clients 2-8
Saving Configuration Settings 2-8
Managing System Files 2-9
Chapter 3: Configuring the Switch 3-1
Using the Web Interface 3-1
Navigating the Web Browser Interface 3-2
Home Page 3-2
Configuration Options 3-3
Panel Display 3-3
Main Menu 3-4
Basic Configuration 3-12
Displaying System Information 3-12
Displaying Switch Hardware/Software Versions 3-13
Displaying Bridge Extension Capabilities 3-15
Setting the Switch’s IP Address 3-16
Manual Configuration 3-17
Using DHCP/BOOTP 3-18
Enabling Jumbo Frames 3-19
Managing Firmware 3-19
Downloading System Software from a Server 3-20
i
Contents
Saving or Restoring Configuration Settings 3-21
Downloading Configuration Settings from a Server 3-22
Console Port Settings 3-23
Telnet Settings 3-25
Configuring Event Logging 3-28
Displaying Log Messages 3-28
System Log Configuration 3-28
Remote Log Configuration 3-30
Simple Mail Transfer Protocol 3-31
Resetting the System 3-33
Setting the System Clock 3-34
Setting the Time Manually 3-34
Configuring SNTP 3-34
Configuring NTP 3-35
Setting the Time Zone 3-37
Simple Network Management Protocol 3-38
Setting Community Access Strings 3-39
Specifying Trap Managers and Trap Types 3-40
Enabling SNMP Agent Status 3-41
Configuring SNMPv3 Management Access 3-42
Setting the Local Engine ID 3-42
Specifying a Remote Engine ID 3-43
Configuring SNMPv3 Users 3-43
Configuring Remote SNMPv3 Users 3-45
Configuring SNMPv3 Groups 3-46
Setting SNMPv3 Views 3-49
User Authentication 3-51
Configuring User Accounts 3-51
Configuring Local/Remote Logon Authentication 3-53
Configuring Encryption Keys 3-57
AAA Authorization and Accounting 3-58
Configuring AAA RADIUS Group Settings 3-59
Configuring AAA TACACS+ Group Settings 3-59
Configuring AAA Accounting 3-60
AAA Accounting Update 3-62
AAA Accounting 802.1X Port Settings 3-62
AAA Accounting Exec Command Privileges 3-63
AAA Accounting Exec Settings 3-65
AAA Accounting Summary 3-65
Authorization Settings 3-67
Authorization EXEC Settings 3-68
Authorization Summary 3-68
Configuring HTTPS 3-69
Replacing the Default Secure-site Certificate 3-70
Configuring the Secure Shell 3-71
ii
Contents
Configuring the SSH Server 3-74
Generating the Host Key Pair 3-75
Importing User Public Keys 3-76
Configuring Port Security 3-80
Configuring 802.1X Port Authentication 3-81
Displaying 802.1X Global Settings 3-83
Configuring 802.1X Global Settings 3-83
Configuring Port Settings for 802.1X 3-84
Displaying 802.1X Statistics 3-87
Web Authentication 3-88
Configuring Web Authentication 3-89
Configuring Web Authentication for Ports 3-90
Displaying Web Authentication Port Information 3-91
Re-authenticating Web Authenticated Ports 3-92
Network Access – MAC Address Authentication 3-93
Configuring the MAC Authentication Reauthentication Time 3-94
Configuring MAC Authentication for Ports 3-94
Configuring Port Link Detection 3-96
Displaying Secure MAC Address Information 3-97
MAC Authentication 3-98
Configuring MAC authentication parameters for ports 3-98
Access Control Lists 3-99
Configuring Access Control Lists 3-100
Setting the ACL Name and Type 3-100
Configuring a Standard IP ACL 3-101
Configuring an Extended IP ACL 3-102
Configuring a MAC ACL 3-105
Binding a Port to an Access Control List 3-106
Filtering IP Addresses for Management Access 3-107
Port Configuration 3-110
Displaying Connection Status 3-110
Configuring Interface Connections 3-112
Creating Trunk Groups 3-114
Statically Configuring a Trunk 3-115
Enabling LACP on Selected Ports 3-116
Configuring LACP Parameters 3-118
Displaying LACP Port Counters 3-120
Displaying LACP Settings and Status for the Local Side 3-122
Displaying LACP Settings and Status for the Remote Side 3-124
Setting Broadcast Storm Thresholds 3-125
Configuring Port Mirroring 3-127
Configuring Rate Limits 3-128
Rate Limit Configuration 3-128
Showing Port Statistics 3-129
Address Table Settings 3-133
iii
Contents
Setting Static Addresses 3-133
Displaying the Address Table 3-134
Changing the Aging Time 3-136
Spanning Tree Algorithm Configuration 3-136
Displaying Global Settings 3-138
Configuring Global Settings 3-141
Displaying Interface Settings 3-144
Configuring Interface Settings 3-147
Configuring Multiple Spanning Trees 3-149
Displaying Interface Settings for MSTP 3-151
Configuring Interface Settings for MSTP 3-153
VLAN Configuration 3-155
IEEE 802.1Q VLANs 3-155
Enabling or Disabling GVRP (Global Setting) 3-158
Displaying Basic VLAN Information 3-159
Displaying Current VLANs 3-159
Creating VLANs 3-161
Adding Static Members to VLANs (VLAN Index) 3-162
Adding Static Members to VLANs (Port Index) 3-164
Configuring VLAN Behavior for Interfaces 3-165
Configuring IEEE 802.1Q Tunneling 3-167
Enabling QinQ Tunneling on the Switch 3-170
Adding an Interface to a QinQ Tunnel 3-172
Protocol VLAN Group Configuration 3-179
Protocol VLAN System Configuration 3-180
Link Layer Discovery Protocol 3-181
Setting LLDP Timing Attributes 3-181
Configuring LLDP Interface Attributes 3-183
Displaying LLDP Local Device Information 3-186
Displaying LLDP Remote Port Information 3-187
Displaying LLDP Remote Information Details 3-188
Displaying Device Statistics 3-189
Displaying Detailed Device Statistics 3-190
Class of Service Configuration 3-191
Layer 2 Queue Settings 3-191
Setting the Default Priority for Interfaces 3-191
Mapping CoS Values to Egress Queues 3-192
Enabling CoS 3-194
iv
Contents
Selecting the Queue Mode 3-195
Setting the Service Weight for Traffic Classes 3-195
Layer 3/4 Priority Settings 3-196
Mapping Layer 3/4 Priorities to CoS Values 3-196
Enabling IP DSCP Priority 3-197
Mapping DSCP Priority 3-198
Quality of Service 3-199
Configuring Quality of Service Parameters 3-200
Configuring a Class Map 3-200
Creating QoS Policies 3-203
Attaching a Policy Map to Ingress Queues 3-206
VoIP Traffic Configuration 3-207
Configuring VoIP Traffic 3-207
Configuring VoIP Traffic Port 3-208
Configuring Telephony OUI 3-210
Multicast Filtering 3-212
Layer 2 IGMP (Snooping and Query) 3-212
Configuring IGMP Snooping and Query Parameters 3-213
Enabling IGMP Immediate Leave 3-215
Displaying Interfaces Attached to a Multicast Router 3-216
Specifying Static Interfaces for a Multicast Router 3-217
Displaying Port Members of Multicast Services 3-218
Assigning Ports to Multicast Services 3-219
IGMP Filtering and Throttling 3-220
Enabling IGMP Filtering and Throttling 3-221
Configuring IGMP Filter Profiles 3-222
Configuring IGMP Filtering and Throttling for Interfaces 3-223
Multicast VLAN Registration 3-225
Configuring Global MVR Settings 3-226
Displaying MVR Interface Status 3-227
Displaying Port Members of Multicast Groups 3-228
Configuring MVR Interface Status 3-229
Assigning Static Multicast Groups to Interfaces 3-231
DHCP Snooping 3-232
DHCP Snooping Configuration 3-233
DHCP Snooping VLAN Configuration 3-233
DHCP Snooping Information Option Configuration 3-234
DHCP Snooping Port Configuration 3-235
DHCP Snooping Binding Information 3-236
IP Source Guard 3-237
IP Source Guard Port Configuration 3-237
Static IP Source Guard Binding Configuration 3-238
Dynamic IP Source Guard Binding Information 3-239
IP Clustering 3-240
Cluster Configuration 3-241
v
Contents
Cluster Member Configuration 3-242
Cluster Member Information 3-243
Cluster Candidate Information 3-243
UPnP 3-245
UPnP Configuration 3-245
Chapter 4: Command Line Interface 4-1
Using the Command Line Interface 4-1
Accessing the CLI 4-1
Console Connection 4-1
Telnet Connection 4-2
Entering Commands 4-3
Keywords and Arguments 4-3
Minimum Abbreviation 4-3
Command Completion 4-3
Getting Help on Commands 4-3
Showing Commands 4-4
Partial Keyword Lookup 4-6
Negating the Effect of Commands 4-6
Using Command History 4-6
Understanding Command Modes 4-6
Exec Commands 4-7
Configuration Commands 4-8
Command Line Processing 4-10
Command Groups 4-11
Line Commands 4-12
line 4-13
login 4-13
password 4-14
timeout login response 4-15
exec-timeout 4-15
password-thresh 4-16
silent-time 4-17
databits 4-17
parity 4-18
speed 4-19
stopbits 4-19
disconnect 4-20
show line 4-20
General Commands 4-21
enable 4-21
disable 4-22
configure 4-23
show history 4-23
vi
Contents
reload 4-24
reload cancel 4-24
show reload 4-25
end 4-25
exit 4-26
quit 4-26
ip http port 4-42
ip http server 4-42
ip http secure-server 4-43
ip http secure-port 4-44
Telnet Server Commands 4-45
ip telnet port 4-45
ip telnet server 4-45
Secure Shell Commands 4-46
ip ssh server 4-48
ip ssh timeout 4-49
ip ssh authentication-retries 4-49
ip ssh server-key size 4-50
delete public-key 4-50
ip ssh crypto host-key generate 4-51
ip ssh crypto zeroize 4-51
vii
Contents
ip ssh save host-key 4-52
show ip ssh 4-52
show ssh 4-53
show public-key 4-54
Event Logging Commands 4-55
logging on 4-55
logging history 4-56
logging host 4-57
logging facility 4-57
logging trap 4-58
clear logging 4-58
show logging 4-59
show log 4-60
access-list ip 4-140
permit, deny (Standard ACL) 4-141
permit, deny (Extended ACL) 4-141
show ip access-list 4-143
x
Contents
ip access-group 4-143
show ip access-group 4-144
MAC ACLs 4-144
access-list mac 4-145
permit, deny (MAC ACL) 4-146
show mac access-list 4-147
mac access-group 4-148
show mac access-group 4-148
ACL Information 4-149
show access-list 4-149
show access-group 4-149
SNMP Commands 4-150
snmp-server 4-151
show snmp 4-151
snmp-server community 4-152
snmp-server contact 4-153
snmp-server location 4-153
snmp-server host 4-154
snmp-server enable traps 4-156
snmp-server engine-id 4-157
show snmp engine-id 4-158
snmp-server view 4-159
show snmp view 4-160
snmp-server group 4-160
show snmp group 4-161
snmp-server user 4-163
show snmp user 4-165
Interface Commands 4-166
interface 4-166
description 4-167
speed-duplex 4-167
negotiation 4-168
capabilities 4-169
flowcontrol 4-170
shutdown 4-171
switchport packet-rate 4-172
clear counters 4-172
show interfaces status 4-173
show interfaces counters 4-174
show interfaces switchport 4-175
protocol-vlan protocol-group (Configuring Groups) 4-261
protocol-vlan protocol-group (Configuring VLANs) 4-262
show protocol-vlan protocol-group 4-263
show protocol-vlan protocol-group-vid 4-263
Priority Commands 4-264
Priority Commands (Layer 2) 4-264
queue mode 4-265
switchport priority default 4-265
queue bandwidth 4-266
queue cos-map 4-267
show queue mode 4-268
show queue bandwidth 4-268
show queue cos-map 4-269
Priority Commands (Layer 3 and 4) 4-269
map ip dscp (Global Configuration) 4-269
map ip dscp (Interface Configuration) 4-270
show map ip dscp 4-271
Quality of Service Commands 4-272
class-map 4-273
xiv
Contents
match 4-274
policy-map 4-275
class 4-276
set 4-277
police 4-277
service-policy 4-278
show class-map 4-279
show policy-map 4-279
show policy-map interface 4-280
ip igmp snooping 4-288
ip igmp snooping vlan static 4-288
ip igmp snooping version 4-289
ip igmp snooping leave-proxy 4-289
ip igmp snooping immediate-leave 4-290
show ip igmp snooping 4-291
show mac-address-table multicast 4-291
IGMP Query Commands (Layer 2) 4-292
ip igmp snooping querier 4-292
ip igmp snooping query-count 4-293
ip igmp snooping query-interval 4-293
ip igmp snooping query-max-response-time 4-294
ip igmp snooping router-port-expire-time 4-295
Static Multicast Routing Commands 4-295
ip igmp snooping vlan mrouter 4-296
show ip igmp snooping mrouter 4-296
IGMP Filtering and Throttling Commands 4-297
ip igmp filter (Global Configuration) 4-298
ip igmp profile 4-298
permit, deny 4-299
range 4-299
ip igmp filter (Interface Configuration) 4-300
ip igmp max-groups 4-300
ip igmp max-groups action 4-301
show ip igmp filter 4-302
xv
Contents
show ip igmp profile 4-302
show ip igmp throttle interface 4-303
ip address 4-309
ip default-gateway 4-310
ip dhcp restart 4-311
show ip interface 4-311
show ip redirects 4-312
ping 4-312
IP Source Guard Commands 4-313
ip source-guard 4-313
ip source-guard binding 4-315
show ip source-guard 4-316
show ip source-guard binding 4-316
DHCP Snooping Commands 4-317
ip dhcp snooping 4-317
ip dhcp snooping vlan 4-319
ip dhcp snooping trust 4-320
ip dhcp snooping verify mac-address 4-321
ip dhcp snooping information option 4-321
ip dhcp snooping information policy 4-322
ip dhcp snooping database flash 4-323
show ip dhcp snooping 4-323
show ip dhcp snooping binding 4-324
IP Cluster Commands 4-324
cluster 4-324
cluster commander 4-325
cluster ip-pool 4-326
cluster member 4-326
rcommand 4-327
show cluster 4-327
show cluster members 4-328
show cluster candidates 4-328
Appendix A: Software Specifications A-1
Software Features A-1
Management Features A-2
Standards A-2
Management Information Bases A-3
xvi
Contents
Appendix B: Troubleshooting B-1
Problems Accessing the Management Interface B-1
Using System Logs B-2