Allied Telesis AT-S63 User Manual

Management Software
AT-S63
Web Browser Interface
®
User’s Guide
AT-9424T/SP AND AT-9424T/GB LAYER 2+ GIGABIT ETHERNET SWITCHES
PN 613-50592-00 Rev A
Copyright © 2004 Allied Telesyn, Inc.
All rights reserved. No part of this publication may be reproduced without prior written permission from Allied Telesyn, Inc.
Microsoft and Internet Explorer are registered trademarks of Microsoft Corporation. Netscape Navigator is a registered trademark of Netscape Communications Corporation. All other product names, company names, logos or other designations mentioned herein are trademarks or registered trademarks of their respective owners.
Allied Telesyn, Inc. reserves the right to make changes in specifications and other information contained in this document without prior written notice. The information provided herein is subject to change without notice. In no event shall Allied Telesyn, Inc. be liable for any incidental, special, indirect, or consequential damages whatsoever, including but not limited to lost profits, arising out of or related to this manual or the information contained herein, even if Allied Telesyn, Inc. has been advised of, known, or should have known, the possibility of such damages.

Contents

Figures .......................................................................................................................................................................................................................9
Tables ...................................................................................................................................................................................................................... 13
Preface .................................................................................................................................................................................................................... 15
How This Guide is Organized .......................................................................................................................................................................... 15
Document Conventions .................................................................................................................................................................................... 17
Where to Find Web-based Guides ................................................................................................................................................................ 18
Contacting Allied Telesyn .................................................................................................................................................................................19
Online Support ........................................................................................................................................................................................... 19
Email and Telephone Support .............................................................................................................................................................. 19
For Sales or Corporate Information ..................................................................................................................................................... 19
Management Software Updates .................................................................................................................................................................... 20
Chapter 1
Overview ............................................................................................................................................................................................................... 21
Management Overview .................................................................................................................................................................................... 22
Local Management Session ............................................................................................................................................................................. 24
Telnet Management Session ........................................................................................................................................................................... 25
Web Browser Management Session ............................................................................................................................................................. 26
SNMP Management Session ........................................................................................................................................................................... 27
Management Access Levels ............................................................................................................................................................................. 28

Section I

Basic Features .................................................................................................................................. 29
Chapter 2
Starting a Web Browser Management Session .................................................................................................................................. 31
Starting a Web Browser Management Session ........................................................................................................................................ 32
Web Browser Tools ............................................................................................................................................................................................. 35
Saving Your Parameter Changes ................................................................................................................................................................... 36
Quitting a Web Browser Management Session ........................................................................................................................................ 37
Chapter 3
Basic Switch Parameters ................................................................................................................................................................................39
Configuring an IP Address and Switch Name ........................................................................................................................................... 40
Activating the BOOTP and DHCP Client Software ................................................................................................................................... 43
Displaying System Information ...................................................................................................................................................................... 44
Configuring the Manager and Operator Passwords ............................................................................................................................... 46
3
Contents
Rebooting a Switch .............................................................................................................................................................................................48
Pinging a Remote System .................................................................................................................................................................................49
Returning the AT-S63 Management Software to the Factory Default Values ...............................................................................50
Chapter 4
SNMPv1 and SNMPv2c ....................................................................................................................................................................................53
Enabling or Disabling SNMP Management ................................................................................................................................................54
Creating a New SNMPv1 and SNMPv2c Community ..............................................................................................................................56
Modifying an SNMPv1 and SNMPv2c Community ..................................................................................................................................59
Deleting an SNMPv1 and SNMPv2c Community ......................................................................................................................................61
Displaying the SNMPv1 and SNMPv2c Communities .............................................................................................................................62
Chapter 5
Enhanced Stacking ............................................................................................................................................................................................65
Setting a Switch’s Enhanced Stacking Status ............................................................................................................................................66
Selecting a Switch in an Enhanced Stack ....................................................................................................................................................68
Returning to the Master Switch ......................................................................................................................................................................71
Displaying the Enhanced Stacking Status ...................................................................................................................................................72
Chapter 6
Port Parameters ..................................................................................................................................................................................................73
Configuring Port Parameters ...........................................................................................................................................................................74
Displaying Port Status ........................................................................................................................................................................................81
Displaying Port Statistics ...................................................................................................................................................................................85
Resetting a Port to the Default Settings ......................................................................................................................................................88
Chapter 7
MAC Address Table ...........................................................................................................................................................................................89
Adding Static Unicast and Multicast MAC Addresses .............................................................................................................................90
Deleting Unicast and Multicast MAC Addresses .......................................................................................................................................92
Deleting All Dynamic MAC Addresses ..........................................................................................................................................................93
Displaying the MAC Address Tables ..............................................................................................................................................................94
Changing the Aging Time .................................................................................................................................................................................97
Chapter 8
Port Trunking .......................................................................................................................................................................................................99
Creating a Port Trunk ....................................................................................................................................................................................... 100
Modifying a Port Trunk ................................................................................................................................................................................... 103
Deleting a Port Trunk ....................................................................................................................................................................................... 105
Displaying the Port Trunks ............................................................................................................................................................................ 106
Chapter 9
Port Mirroring ...................................................................................................................................................................................................109
Creating a Port Mirror ...................................................................................................................................................................................... 110
Modifying a Port Mirror ................................................................................................................................................................................... 113
Disabling a Port Mirror .................................................................................................................................................................................... 114
Deleting a Port Mirror ...................................................................................................................................................................................... 115
Displaying the Port Mirror .............................................................................................................................................................................. 116

Section II

Advanced Features ......................................................................................................................119
Chapter 10
File Downloads and Uploads .................................................................................................................................................................... 121
Downloading a File ........................................................................................................................................................................................... 122
Uploading a File ................................................................................................................................................................................................. 125
4
AT-S63 Management Software Web Browser Interface User’s Guide
Chapter 11
Event Log ............................................................................................................................................................................................................127
Enabling or Disabling the Event Log ..........................................................................................................................................................128
Displaying Events ..............................................................................................................................................................................................130
Disabling the Event Log ..................................................................................................................................................................................137
Clearing the Event Log ....................................................................................................................................................................................138
Saving the Event Log to a File .......................................................................................................................................................................139
Chapter 12
Quality of Service ............................................................................................................................................................................................141
Configuring CoS .................................................................................................................................................................................................142
Mapping CoS Priorities to Egress Queues ................................................................................................................................................145
Configuring Egress Scheduling ....................................................................................................................................................................148
Displaying the CoS Settings ..........................................................................................................................................................................150
Displaying the QoS Schedule ........................................................................................................................................................................152
Chapter 13
IGMP Snooping ................................................................................................................................................................................................153
Configuring IGMP Snooping .........................................................................................................................................................................154
Displaying a List of Host Nodes ....................................................................................................................................................................157
Displaying a List of Multicast Routers ........................................................................................................................................................160
Chapter 14
STP and RSTP .....................................................................................................................................................................................................163
Enabling or Disabling a Spanning Tree Protocol ...................................................................................................................................164
Configuring STP .................................................................................................................................................................................................166
Displaying the STP Settings ................................................................................................................................................................. 170
Resetting STP to the Default Settings .............................................................................................................................................. 172
Configuring RSTP ...............................................................................................................................................................................................174
Resetting RSTP to the Default Settings ............................................................................................................................................ 178
Displaying RSTP Settings ...................................................................................................................................................................... 178
Chapter 15
MSTP ......................................................................................................................................................................................................................181
Enabling MSTP ....................................................................................................................................................................................................182
Configuring MSTP .............................................................................................................................................................................................184
Configuring MSTP Parameters ............................................................................................................................................................ 184
Configuring the CIST Priority ............................................................................................................................................................... 187
Creating, Deleting, or Modifying MSTI IDs ...............................................................................................................................................189
Creating an MSTI ID ................................................................................................................................................................................ 189
Deleting an MSTI ID ................................................................................................................................................................................ 190
Modifying an MSTI ID ............................................................................................................................................................................. 190
Adding, Removing, or Modifying VLAN Associations to MSTIs ........................................................................................................192
Adding a VLAN Association ................................................................................................................................................................. 192
Removing a VLAN Association ............................................................................................................................................................ 192
Modifying a VLAN Association ............................................................................................................................................................ 193
Configuring MSTP Port Parameters ............................................................................................................................................................195
Displaying the MSTP Port Configuration ..................................................................................................................................................197
Displaying the MSTP Port Status ..................................................................................................................................................................200
Resetting MSTP to the Default Settings ....................................................................................................................................................202
Chapter 16
SNMPv3 ................................................................................................................................................................................................................203
Configuring the SNMPv3 Protocol ..............................................................................................................................................................204
Enabling or Disabling SNMP Management ..............................................................................................................................................205
Configuring the SNMPv3 User Table .............................................................................................
.............................................................207
Creating a User Table Entry .................................................................................................................................................................. 207
Deleting a User Table Entry .................................................................................................................................................................. 210
5
Contents
Modifying a User Table Entry .............................................................................................................................................................. 211
Configuring the SNMPv3 View Table ......................................................................................................................................................... 214
Creating a View Table Entry ................................................................................................................................................................. 214
Deleting a View Table Entry ................................................................................................................................................................. 217
Modifying a View Table Entry ............................................................................................................................................................. 218
Configuring the SNMPv3 Access Table ..................................................................................................................................................... 220
Creating an Access Table ...................................................................................................................................................................... 220
Deleting an Access Table Entry .......................................................................................................................................................... 224
Modifying an Access Table Entry ....................................................................................................................................................... 224
Configuring the SNMPv3 SecurityToGroup Table ................................................................................................................................. 227
Creating a SecurityToGroup Table Entry ........................................................................................................................................ 227
Deleting a SecurityToGroup Table Entry ........................................................................................................................................ 230
Modifying a SecurityToGroup Table Entry ..................................................................................................................................... 230
Configuring the SNMPv3 Notify Table ......................................................................................................................................................233
Creating a Notify Table Entry .............................................................................................................................................................. 233
Deleting a Notify Table Entry .............................................................................................................................................................. 235
Modifying a Notify Table Entry ........................................................................................................................................................... 236
Configuring the SNMPv3 Target Address Table .................................................................................................................................... 238
Creating a Target Address Table Entry ............................................................................................................................................ 238
Deleting a Target Address Table Entry ............................................................................................................................................ 241
Modifying Target Address Table Entry ............................................................................................................................................ 242
Configuring the SNMPv3 Target Parameters Table .............................................................................................................................. 245
Creating a Target Parameters Table Entry ...................................................................................................................................... 245
Deleting a Target Parameters Table Entry ...................................................................................................................................... 248
Modifying a Target Parameters Table Entry .................................................................................................................................. 249
Configuring the SNMPv3 Community Table ........................................................................................................................................... 252
Creating an SNMPv3 Community Table Entry .............................................................................................................................. 252
Deleting an SNMPv3 Community Table Entry .............................................................................................................................. 255
Modifying an SNMPv3 Community Table Entry ........................................................................................................................... 255
Displaying SNMPv3 Tables ............................................................................................................................................................................ 258
Displaying User Table Entries .............................................................................................................................................................. 259
Displaying View Table Entries ............................................................................................................................................................. 261
Displaying Access Table Entries ......................................................................................................................................................... 262
Displaying SecurityToGroup Table Entries ..................................................................................................................................... 263
Displaying Notify Table Entries .......................................................................................................................................................... 264
Displaying Target Address Table Entries ........................................................................................................................................ 265
Displaying Target Parameters Table Entries .................................................................................................................................. 266
Displaying SNMPv3 Community Table Entries ............................................................................................................................. 267

Section III

VLANs .................................................................................................................................................269
Chapter 17
Virtual LANs ....................................................................................................................................................................................................... 271
Creating a New Port-Based or Tagged VLAN .......................................................................................................................................... 272
Modifying a VLAN ............................................................................................................................................................................................. 276
Deleting a VLAN ................................................................................................................................................................................................. 278
Selecting a VLAN Mode ................................................................................................................................................................................... 279
Displaying VLANs .............................................................................................................................................................................................. 281
Specifying a Management VLAN ................................................................................................................................................................. 283
Chapter 18
GARP VLAN Registration Protocol (GVRP) .........................................................................................................................................285
Configuring GVRP ............................................................................................................................................................................................. 286
Enabling or Disabling GVRP on a Port ....................................................................................................................................................... 288
Displaying the GVRP Configuration ........................................................................................................................................................... 289
6
AT-S63 Management Software Web Browser Interface User’s Guide
Displaying the GVRP Port Configuration ..................................................................................................................................................291
Displaying the GVRP Database .....................................................................................................................................................................292
Displaying the GVRP State Machine ...........................................................................................................................................................293
Displaying the GVRP Counters .....................................................................................................................................................................296
Displaying the GIP Connected Ports Ring ................................................................................................................................................300

Section IV

Security .............................................................................................................................................303
Chapter 19
Port Security ......................................................................................................................................................................................................305
Displaying the MAC Address Security Level ............................................................................................................................................306
Chapter 20
Encryption Keys, PKI, and SSL ...................................................................................................................................................................309
Displaying the Encryption Keys ....................................................................................................................................................................310
Displaying the PKI Settings and Certificates ............................................................................................................................................312
Displaying the SSL Settings ...........................................................................................................................................................................315
Chapter 21
Secure Shell (SSH) ...........................................................................................................................................................................................317
Configuring SSH .................................................................................................................................................................................................318
Displaying the SSH Settings ..........................................................................................................................................................................320
Chapter 22
TACACS+ and RADIUS ...................................................................................................................................................................................323
Enabling or Disabling TACACS+ or RADIUS .............................................................................................................................................324
Configuring TACACS+ .....................................................................................................................................................................................325
Displaying the TACACS+ Settings ...............................................................................................................................................................327
Configuring RADIUS .........................................................................................................................................................................................329
Displaying the RADIUS Settings ................................................................................................................................................................... 331
Chapter 23
802.1x Port-based Network Access Control .......................................................................................................................................333
Setting Port Roles ..............................................................................................................................................................................................334
Enabling or Disabling 802.1x Port-based Network Access Control ................................................................................................336
Configuring Authenticator Port Parameters ...........................................................................................................................................337
Configuring Supplicant Port Parameters ..................................................................................................................................................340
Displaying the Port-based Network Access Control Parameters .....................................................................................................342
Displaying the Port Status .................................................................................................................................................................... 342
Displaying the Port Settings ................................................................................................................................................................ 343
RADIUS Accounting ..........................................................................................................................................................................................346
Configuring RADIUS Accounting ....................................................................................................................................................... 346
Displaying the RADIUS Accounting Settings ................................................................................................................................. 347
Chapter 24
Denial of Service Defense ...........................................................................................................................................................................351
Configuring Denial of Service Defense ......................................................................................................................................................352
Displaying the DoS Settings ..........................................................................................................................................................................355
Appendix A
AT-S63 Default Settings ...............................................................................................................................................................................357
Basic Switch Default Settings ........................................................................................................................................................................359
Boot Configuration File Default Setting .......................................................................................................................................... 359
Management Access Default Settings ............................................................................................................................................. 359
Management Interface Default Settings ......................................................................................................................................... 359
RJ-45 Serial Terminal Port Default Settings .................................................................................................................................... 360
SNTP Default Settings ............................................................................................................................................................................ 360
7
Contents
Switch Administration Default Settings .......................................................................................................................................... 361
System Software Default Settings ..................................................................................................................................................... 361
Enhanced Stacking Default Setting ............................................................................................................................................................ 362
SNMP Default Settings .................................................................................................................................................................................... 363
Port Configuration Default Settings ........................................................................................................................................................... 364
Event Log Default Settings ............................................................................................................................................................................ 365
Quality of Service .............................................................................................................................................................................................. 366
IGMP Snooping Default Settings ................................................................................................................................................................. 367
Denial of Service Prevention Default Settings ........................................................................................................................................ 368
STP, RSTP, and MSTP Default Settings ....................................................................................................................................................... 369
Spanning Tree Switch Settings ........................................................................................................................................................... 369
STP Default Settings ............................................................................................................................................................................... 369
RSTP Default Settings ............................................................................................................................................................................ 369
MSTP Default Settings ........................................................................................................................................................................... 370
VLAN Default Settings ..................................................................................................................................................................................... 371
GVRP Default Settings ..................................................................................................................................................................................... 372
Port Security Default Settings ...................................................................................................................................................................... 373
802.1x Port-Based Network Access Control Default Settings ...........................................................................................................374
Web Server Default Settings ......................................................................................................................................................................... 375
SSL Default Settings ......................................................................................................................................................................................... 376
PKI Default Settings .......................................................................................................................................................................................... 377
SSH Default Settings ........................................................................................................................................................................................ 378
Server-Based Authentication Default Settings ....................................................................................................................................... 379
Server-Based Authentication Default Settings ............................................................................................................................. 379
RADIUS Default Settings ....................................................................................................................................................................... 379
TACACS+ Client Default Settings ...................................................................................................................................................... 379
Management Access Control List Default Setting ................................................................................................................................ 380
Index ..................................................................................................................................................................................................................... 381
8

Figures

Figure 1: Entering a Switch’s IP Address in the URL Field ..................................................................................................................... 32
Figure 2: AT-S63 Login Page ............................................................................................................................................................................ 33
Figure 3: Home page .......................................................................................................................................................................................... 34
Figure 4: Save Changes Button in the General Tab (Configuration) ................................................................................................. 36
Figure 5: General Tab (Configuration) ......................................................................................................................................................... 40
Figure 6: General Tab (Monitoring) ............................................................................................................................................................... 44
Figure 7: Ping Client Tab (Monitoring) ........................................................................................................................................................ 49
Figure 8: System Utilities Tab (Configuration) .......................................................................................................................................... 51
Figure 9: SNMP Tab (Configuration) ............................................................................................................................................................. 54
Figure 10: SNMPv1 & SNMPv2c Communities Tab ................................................................................................................................. 56
Figure 11: Add New SNMPv1 & SNMPv2c Community Page ............................................................................................................... 57
Figure 12: Modify SNMPv1 & SNMPv2c Community Page ................................................................................................................... 59
Figure 13: SNMP Tab (Monitoring) ................................................................................................................................................................ 62
Figure 14: SNMPv1 & SNMPv2c Communities Tab (Monitoring) ....................................................................................................... 63
Figure 15: Enhanced Stacking Tab (Configuration) ................................................................................................................................ 67
Figure 16: Stacking Switches Page ................................................................................................................................................................ 69
Figure 17: Enhanced Stacking Tab (Monitoring) ...................................................................................................................................... 72
Figure 18: Port Settings Tab (Configuration) ............................................................................................................................................. 74
Figure 19: Port Configuration Page .............................................................................................................................................................. 75
Figure 20: Port Settings Tab (Monitoring) .................................................................................................................................................. 81
Figure 21: Port Status Page .............................................................................................................................................................................. 82
Figure 22: Port Statistics Page ......................................................................................................................................................................... 85
Figure 23: MAC Address Tab (Configuration) ............................................................................................................................................ 90
Figure 24: Add MAC Address Page ............................................................................................................................................................... 91
Figure 25: MAC Address Tab (Monitoring) ................................................................................................................................................. 94
Figure 26: View MAC Addresses Page .......................................................................................................................................................... 96
Figure 27: Port Trunking Tab (Configuration) .........................................................................................................................................100
Figure 28: Add New Trunk Page ...................................................................................................................................................................101
Figure 29: Modify Trunk Page ....................................................................................................................................................................... 104
Figure 30: Port Trunking Tab (Monitoring) ..............................................................................................................................................106
Figure 31: Port Mirroring Tab (Configuration) ........................................................................................................................................110
Figure 32: Modify Mirror Page ......................................................................................................................................................................111
Figure 33: Example of a Modify Mirror Page ............................................................................................................................................112
Figure 34: Port Mirroring Tab (Monitoring) ..............................................................................................................................................116
Figure 35: System Utilities Tab (Configuration) ......................................................................................................................................123
Figure 36: Event Log Tab (Configuration) ................................................................................................................................................128
Figure 37: Event Log Tab (Monitoring) ......................................................................................................................................................130
9
Figures
Figure 38: Event Log Example Displayed in Normal Mode ................................................................................................................ 134
Figure 39: Event Log Example Displayed in Full Mode ....................................................................................................................... 135
Figure 40: CoS Tab (Configuration) ............................................................................................................................................................142
Figure 41: CoS Setting for Port Page .......................................................................................................................................................... 143
Figure 42: QoS Scheduling Tab (Configuration) .................................................................................................................................... 146
Figure 43: CoS Tab (Monitoring) ..................................................................................................................................................................150
Figure 44: CoS Setting for Port Page .......................................................................................................................................................... 150
Figure 45: QoS Scheduling Tab (Monitoring) .......................................................................................................................................... 152
Figure 46: IGMP Tab (Configuration) .......................................................................................................................................................... 154
Figure 47: IGMP Tab (Monitoring) ............................................................................................................................................................... 157
Figure 48: View Multicast Hosts List Page ................................................................................................................................................ 158
Figure 49: View Multicast Routers List Page ............................................................................................................................................ 160
Figure 50: View (Static) Multicast Routers List Page ............................................................................................................................. 161
Figure 51: Spanning Tree Tab (Configuration) ....................................................................................................................................... 164
Figure 52: Configure STP Parameters Tab (Configuration) ................................................................................................................ 167
Figure 53: STP Settings - Port(s) Page ........................................................................................................................................................ 169
Figure 54: Spanning Tree Tab (Monitoring) ............................................................................................................................................ 171
Figure 55: Monitor STP Parameters Tab (Monitoring) ......................................................................................................................... 171
Figure 56: STP Settings Page ......................................................................................................................................................................... 172
Figure 57: Configure RSTP Parameters Tab (Configuration) ............................................................................................................. 175
Figure 58: RSTP Settings - Port(s) Page .....................................................................................................................................................177
Figure 59: Monitor RSTP Parameters Tab (Monitoring) ....................................................................................................................... 179
Figure 60: RSTP Settings Page ...................................................................................................................................................................... 179
Figure 61: Spanning Tree Tab (Configuration) ....................................................................................................................................... 182
Figure 62: Configure MSTP Parameters Tab (Configuration) ............................................................................................................185
Figure 63: Add New MSTI Page .................................................................................................................................................................... 189
Figure 64: Modify MSTI Page ......................................................................................................................................................................... 191
Figure 65: MSTP Settings - Port(s) Page .................................................................................................................................................... 195
Figure 66: Monitor MSTP Parameters Tab (Monitoring) ..................................................................................................................... 198
Figure 67: MSTP Settings - Port(s) Page .................................................................................................................................................... 198
Figure 68: MSTP Port Status - Port(s) Page ............................................................................................................................................... 200
Figure 69: SNMP Tab (Configuration) ........................................................................................................................................................ 205
Figure 70: SNMPv3 User Table Tab (Configuration) .............................................................................................................................208
Figure 71: Add New SNMPv3 User Page ................................................................................................................................................... 208
Figure 72: Modify SNMPv3 User Page ........................................................................................................................................................ 211
Figure 73: SNMPv3 View Table Tab (Configuration) ............................................................................................................................. 215
Figure 74: Add New SNMPv3 View Page .................................................................................................................................................. 215
Figure 75: Modify SNMPv3 View Page ....................................................................................................................................................... 218
Figure 76: SNMPv3 Access Table Tab (Configuration) ......................................................................................................................... 221
Figure 77: Add New SNMPv3 Access Page ............................................................................................................................................... 221
Figure 78: Modify SNMPv3 Access Page ...................................................................................................................................................225
Figure 79: SNMPv3 SecurityToGroup Table Tab (Configuration) .................................................................................................... 228
Figure 80: Add New SNMPv3 SecurityToGroup Page .......................................................................................................................... 228
Figure 81: Modify SNMPv3 SecurityToGroup Page ............................................................................................................................... 231
Figure 82: SNMPv3 Notify Table Tab (Configuration) .......................................................................................................................... 234
Figure 83: Add New SNMPv3 Notify Page ................................................................................................................................................ 234
Figure 84: Modify SNMPv3 Notify Page .................................................................................................................................................... 236
Figure 85: SNMPv3 Target Address Table Tab (Configuration) ........................................................................................................239
Figure 86: Add New SNMPv3 Target Address Page .............................................................................................................................. 239
Figure 87: Modify SNMPv3 Target Address Page .................................................................................................................................. 242
Figure 88: SNMPv3 Target Parameters Table Tab (Configuration) .................................................................................................. 245
Figure 89: Add New SNMPv3 Target Parameters Page ....................................................................................................................... 246
Figure 90: Modify SNMPv3 Target Parameter Page .............................................................................................................................. 249
Figure 91: SNMPv3 Community Table Tab (Configuration) .............................................................................................................. 253
Figure 92: Add New SNMPv3 Community Page .................................................................................................................................... 253
10
AT-S63 Management Software Web Browser Interface User’s Guide
Figure 93: Modify SNMPv3 Community Page .........................................................................................................................................256
Figure 94: SNMP Tab (Monitoring) ..............................................................................................................................................................259
Figure 95: SNMPv3 User Table Tab (Monitoring) ...................................................................................................................................260
Figure 96: SNMPv3 View Table Tab (Monitoring) ..................................................................................................................................261
Figure 97: SNMPv3 Access Table Tab (Monitoring) ..............................................................................................................................262
Figure 98: SNMPv3 SecurityToGroup Table Tab (Monitoring) ..........................................................................................................263
Figure 99: SNMPv3 Notify Table Tab (Monitoring) ................................................................................................................................264
Figure 100: SNMPv3 Target Address Table Tab (Monitoring) ...........................................................................................................265
Figure 101: SNMPv3 Target Parameters Table Tab (Monitoring) .....................................................................................................266
Figure 102: SNMPv3 Community Table Tab (Monitoring) ..................................................................................................................267
Figure 103: VLAN Tab (Configuration) .......................................................................................................................................................272
Figure 104: Add New VLAN Page .................................................................................................................................................................273
Figure 105: VLAN Tab (Monitoring) ............................................................................................................................................................281
Figure 106: GVRP Tab (Configuration) .......................................................................................................................................................286
Figure 107: GVRP Port Configuration Page ..............................................................................................................................................288
Figure 108: GVRP Tab (Monitoring) ............................................................................................................................................................289
Figure 109: GVRP Port Configuration Page ..............................................................................................................................................291
Figure 110: GVRP Database Page ................................................................................................................................................................292
Figure 111: GVRP State Machine for VLAN Page ....................................................................................................................................293
Figure 112: GVRP Counters Page .................................................................................................................................................................296
Figure 113: GIP Connected Ports Ring Page ............................................................................................................................................300
Figure 114: Port Security Tab (Monitoring) ..............................................................................................................................................306
Figure 115: Security for Port(s) Page ..........................................................................................................................................................307
Figure 116: 802.1x Port Access Tab (Monitoring) ..................................................................................................................................310
Figure 117: Keys Tab (Monitoring) ..............................................................................................................................................................311
Figure 118: PKI Tab (Monitoring) .................................................................................................................................................................312
Figure 119: X509 Certificate Details Page .................................................................................................................................................313
Figure 120: SSL Tab (Monitoring) ................................................................................................................................................................315
Figure 121: Secure Shell Tab (Configuration) ..........................................................................................................................................318
Figure 122: Secure Shell Tab (Monitoring) ...............................................................................................................................................320
Figure 123: Server-based Authentication Tab (Configuration) ........................................................................................................324
Figure 124: TACACS+ Client Configuration Page .................................................................................................................................. 325
Figure 125: Server-Based Authentication Tab (Monitoring) ..............................................................................................................327
Figure 126: TACACS+ Client Configuration Page .................................................................................................................................. 328
Figure 127: RADIUS Client Configuration Page ......................................................................................................................................329
Figure 128: RADIUS Client Configuration Page ......................................................................................................................................331
Figure 129: 802.1x Port Access Tab (Configuration) .............................................................................................................................334
Figure 130: Port Role Configuration Page ................................................................................................................................................335
Figure 131: Authenticator Parameters Page ...........................................................................................................................................337
Figure 132: Supplicant Parameters Page ..................................................................................................................................................340
Figure 133: 802.1x Port Access Tab (Monitoring) ..................................................................................................................................342
Figure 134: Port Access Port Status Page .................................................................................................................................................343
Figure 135: Authenticator Port Parameters Page ..................................................................................................................................344
Figure 136: Supplicant Port Parameters Page .........................................................................................................................................345
Figure 137: 802.1x Port Access Tab (Configuration) .............................................................................................................................346
Figure 138: 802.1x Port Access Tab (Monitoring) ..................................................................................................................................348
Figure 139: DoS Tab (Configuration) ..........................................................................................................................................................352
Figure 140: DoS Configuration for Ports Page ........................................................................................................................................353
Figure 141: DoS Tab (Monitoring) ...............................................................................................................................................................355
Figure 142: DoS Monitor for Ports Page ....................................................................................................................................................356
11
Figures
12

Tables

Table 1: AT-S63 Software Modules .............................................................................................................................................................132
Table 2: Event Severity Levels ......................................................................................................................................................................134
Table 3: Default Mappings of IEEE 802.1p Priority Levels to Priority Queues ............................................................................. 143
Table 4: Example of Weighted Round Robin Priority ..........................................................................................................................148
Table 5: Bridge Priority Value Increments ...............................................................................................................................................168
Table 6: Port Priority Value Increments ....................................................................................................................................................169
Table 7: GVRP State Machine Parameters ................................................................................................................................................293
Table 8: GVRP Counters ..................................................................................................................................................................................297
13
Tables
14

Preface

This guide contains instructions on how to configure an AT-9400 Series Layer 2+ Gigabit Ethernet Switch using the AT-S63 management software and the web browser user interface.

How This Guide is Organized

This manual is divided into three sections.
Section I: Basic Features
The chapters in this section explain how to start a local management session and perform some basic tasks such as configuring switch and port parameters, port trunking, and enhanced stacking.
Section II: Advanced Features
The Advanced Features section includes procedures for working with the file system, spanning tree, IGMP, Quality of Service, the event log, and VLANs.
Section III: Security
The chapters in this section explain how to use a wide variety of switch security features including management ACLs, encryption, web server, port-based access control, denial of service defense, TACACS+, and RADIUS.
For information about managing an AT-9400 Series switch using the menus interface, refer to the AT-S63 Management Software Menus Interface User’s Guide.
15
Preface
To manage the switch using the command line interface, refer to the
AT-S63 Management Software Command Line Interface User’s Guide.
Caution
The software described in this documentation contains certain cryptographic functionality and its export is restricted by U.S. law. As of this writing, it has been submitted for review as a “retail encryption item” in accordance with the Export Administration Regulations, 15 C.F.R. Part 730-772, promulgated by the U.S. Department of Commerce, and conditionally may be exported in accordance with the pertinent terms of License Exception ENC (described in 15 C.F.R. Part 740.17). In no case may it be exported to Cuba, Iran, Iraq, Libya, North Korea, Sudan, or Syria. If you wish to transfer this software outside the United States or Canada, please contact your local Allied Telesyn sales representative for current information on this product’s export status.
16

Document Conventions

This document uses the following conventions:
Note
Notes provide additional information.
Caution
Cautions inform you that performing or omitting a specific action may result in equipment damage or loss of data.
Warning
Warnings inform you that performing or omitting a specific action may result in bodily injury.
AT-S63 Management Software Web Browser Interface User’s Guide
17
Preface

Where to Find Web-based Guides

The installation and user guides for all Allied Telesyn products are available in portable document format (PDF) from on our web site at www.alliedtelesyn.com. You can view the documents online or download them onto a local workstation or server.
18
AT-S63 Management Software Web Browser Interface User’s Guide

Contacting Allied Telesyn

This section provides Allied Telesyn contact information for technical support as well as sales or corporate information.

Online Support You can request technical support online by accessing the Allied Telesyn

Knowledge Base at www.alliedtelesyn.com/kb. You can use the Knowledge Base to submit questions to our technical support staff and review answers to previously asked questions.
Email and
Telephone
Support
For Sales or
Corporate
Information
For Technical Support via email or telephone, refer to the Support & Services section of the Allied Telesyn web site, www.alliedtelesyn.com.
You can contact Allied Telesyn for sales or corporate information at our web site: www.alliedtelesyn.com. To find the contact information for your country, select Contact Us -> Worldwide Contacts.
19
Preface

Management Software Updates

New releases of management software for our managed products can be downloaded from either of the following Internet sites:
Allied Telesyn web site: www.alliedtelesyn.com
Allied Telesyn FTP server: ftp://ftp.alliedtelesyn.com
If you prefer to download new software from the Allied Telesyn FTP server using your workstation’s command prompt, you need the FTP client software and you must log in to the server. Enter “anonymous” as the user name and your email address for the password.
20

Chapter 1

Overview

This chapter describes the AT-S63 software functions, the types of sessions you can use to access the software, and the management access levels. This chapter contains the following sections:
”Management Overview” on page 22
”Local Management Session” on page 24
”Telnet Management Session” on page 25
”Web Browser Management Session” on page 26
”SNMP Management Session” on page 27
”Management Access Levels” on page 28
21
Chapter 1: Overview

Management Overview

The AT-S63 management software is intended for the AT-9400 Series switches. You use the software to monitor and adjust the switch’s operating parameters. Some of the functions you can perform with the software include:
Enable and disable ports
Configure port parameters, such as speed and duplex mode
Create virtual LANs (VLANs)
Create port trunks and port mirrors
Assign an Internet Protocol (IP) address and subnet mask
Activate and configure the Spanning Tree Protocol (STP), Rapid
Spanning Tree Protocol (RSTP), or Multiple Spanning Tree Protocol (MSTP)
Activate enhanced stacking functions
Configure Quality of Service (QoS)
Enable and configure Internet Group Management Protocol
(IGMP) snooping
Download and upload image, configuration, and system files
Configure port security
The AT-S63 management software is preinstalled on the switch with default settings for all operating parameters. If the default settings are adequate for your network, you can use the device as an unmanaged switch by connecting it to your network, as explained in the hardware installation guide, and powering on the switch.
Note
The default settings for the management software can be found in Appendix A, ”AT-S63 Default Settings” on page 357.
To actively manage a switch by adjusting its operating parameters, you must access the AT-S63 management software. The AT-S63 management software provides a menu interface that makes it very easy to use (see the AT-S63 Management Software Menus Interface User’s Guide), and an interface for managing a switch using a web browser (described in this guide). It also features a command line interface (see the AT-S63 Management Software Command Line Interface User’s Guide).
22
AT-S63 Management Software Web Browser Interface User’s Guide
There are four ways to access the management software on an AT-9400 Series switch. These methods are referred to in this guide as management sessions. They are:
Local management session
Telnet management session
Web browser management session
SNMP management session
The following sections in this chapter briefly describe each type of management session.
23
Chapter 1: Overview

Local Management Session

You establish a local management session with an AT-9400 Series switch by connecting a terminal or a PC with a terminal emulator program to the terminal port on the switch, using the RJ-45 to RS-232 management cable included with the switch. The terminal port is located on the front panel of the AT-9400 Series switch.
This type of management session is referred to as “local” because you must be physically close to the switch, such as in the wiring closet where the switch is located.
After the session starts, a menu is displayed from which you can make selections to configure and monitor the switch. You can configure all of a switch’s operating parameters from a local management session using the menus or CLI interface.
Note
For instructions on starting a local management session, refer to Chapter 2, “Starting a Local or Telnet Management Session” in the AT-S63 Management Software Menus Interface User’s Guide.
A switch does not need an Internet Protocol (IP) address for you to manage it locally. You can start a local management session on a switch at any time. It does not affect the forwarding of frames by the device.
Assigning an AT-9400 Series switch an IP address and designating it as a master switch allows you to manage more than that switch. You can manage all of the switches that support enhanced stacking that reside in the same subnet, all from the same local management session.
Note
For further information on enhanced stacking, refer to Chapter 5, “Enhanced Stacking,” in the AT-S63 Management Software Menus
Interface User’s Guide.
24

Telnet Management Session

You can use any management station on your network that has the Telnet application to manage an AT-9400 Series switch. This type of management session is referred to in this guide as a remote management session because you do not need to be in the wiring closet where the switch is located. You can manage the switch from any workstation on the network that has the application protocol.
To establish a Telnet management session with a switch, there must be at least one enhanced stacking switch in the subnet to which you assigned an IP address. Only one switch in a subnet needs to have an IP address. After you have established a Telnet management session with the switch that has an IP address, you can use the enhanced stacking feature of the management software to access all other switches that support enhanced stacking that reside in the same subnet.
Note
For further information on enhanced stacking, refer to Chapter 5, “Enhanced Stacking,” in the AT-S63 Management Software Menus
Interface User’s Guide.
AT-S63 Management Software Web Browser Interface User’s Guide
Note
For instructions on how to start a Telnet management session, refer to Chapter 2, “Starting a Local or Telnet Management Session” in the
AT-S63 Management Software Menus Interface User’s Guide.
A Telnet management session provides access to nearly all of a switch’s operating parameters. You can perform nearly all the same functions from a Telnet management session as you can from a local management session.
25
Chapter 1: Overview

Web Browser Management Session

You can also use a web browser to manage a switch. This too is referred to as remote management, just like a Telnet management session. You can manage a switch from any workstation on your network that has a web browser. It also uses the enhanced stacking feature. This means there needs to be just one switch on the subnet with an Internet Protocol (IP) address for you to be able to manage all the switches with a web browser. For instructions on starting this type of management session, refer to Chapter 2, ”Starting a Web Browser Management Session” on page 31.
26

SNMP Management Session

Another way to remotely manage the switch is with an SNMP management program. A familiarity with using management information base (MIB) objects is necessary for this type of management.
The AT-S63 software supports the following MIBs:
SNMP MIB-II (RFC 1213)
Bridge MIB (RFC 1493)
Interface Group MIB (RFC 1573)
Ethernet MIB (RFC 1643)
Remote Network MIB (RFC 1757)
Allied Telesyn managed switch MIBs
You must download the Allied Telesyn managed switch MIBs (atistackinfo.mib and atiswitch.mib) file from the Allied Telesyn web site and compile the files with your SNMP program. For instructions, refer to your SNMP management documentation.
AT-S63 Management Software Web Browser Interface User’s Guide
Note
SNMP management does not use the enhanced stacking feature of the switch. Therefore, you must assign an IP address to each switch that you want to manage with an SNMP program.
27
Chapter 1: Overview

Management Access Levels

There are two levels of management access in the AT-S63 management software: manager and operator. When you log in as a manager, you can view and configure all of a switch’s operating parameters. When you log in as an operator, you can only view the operating parameters; you cannot change any values.
You log in as a manager or an operator by entering the appropriate username and password when you start an AT-S63 management session. To log in as a manager, type “manager” as the login name. The default password is “friend.” The username for operator is “operator” and the default password is also “operator.” The usernames and passwords are case sensitive.
To change the passwords, refer to ”Configuring the Manager and Operator Passwords” on page 46.
28
Section I

Basic Features

The chapters in this section provide information and procedures for basic switch setup and include:
Chapter 2, ”Starting a Web Browser Management Session” on
page 31
Chapter 3, ”Basic Switch Parameters” on page 39
Chapter 4, ”SNMPv1 and SNMPv2c” on page 53
Chapter 5, ”Enhanced Stacking” on page 65
Chapter 6, ”Port Parameters” on page 73
Chapter 7, ”MAC Address Table” on page 89
Chapter 8, ”Port Trunking” on page 99
Chapter 9, ”Port Mirroring” on page 109
29
30
Loading...
+ 358 hidden pages