Net Optics 96547iTP, 96542iTP User Manual

User Guide
iTap GigaBit Dual Port Aggregator
Models 96542iTP and 96547iTP
Doc. PUB542iTPU Rev. 1, 3/06
PLEASE READ THESE LEGAL NOTICES CAREFULLY.
By using a Net Optics iTap GigaBit Dual Port Aggregator you agree to the terms and conditions of usage set forth by Net Optics, Inc.
No licenses, express or implied, are granted with respect to any of the technology described in this manual. Net Optics retains all intellectual property rights associated with the technology described in this manual. This manual is intended to assist with installing Net Optics products into your network.
Trademarks and Copyrights
© 2006 by Net Optics, Inc. Net Optics® is a registered trademark of Net Optics, Inc. iTapTM is a trade­mark of Net Optics, Inc. Additional company and product names may be trademarks or registered trade­marks of the individual companies and are respectfully acknowledged.
Additional Information
Net Optics, Inc. reserves the right to make changes in specifi cations and other information contained in this document without prior notice. Every effort has been made to ensure that the information in this document is accurate.
Chapter 1 Introduction
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1
Memory . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
Unpacking and Inspection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .6
About this Guide . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .6
Chapter 2 Installing the iTap
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
Planning the Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9
Confi guring the iTap . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9
Using the Command Line Interface (CLI) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
Mounting the iTap . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .13
Connecting the Management Port . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .14
Connecting to the Network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .14
Connecting to the Monitoring Device . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .16
Connecting Power . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .17
Checking the Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .18
iTap GigaBit Dual Port Aggregator
Contents
Chapter 3 Using the Front Panel Interface
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19
Display . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .19
Utilization Alarm LEDs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .20
Link LEDs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .20
Power LEDs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .20
Reset Button . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
Chapter 4 Using Web Manager
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
Accessing Web Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
Viewing System Status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
Viewing Statistics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .24
Confi guring the iTap . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .25
Chapter 5 Using System Manager
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
Installing System Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .27
Exploring System Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .31
Creating a Group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32
Deleting a Group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
Adding iTaps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .33
Deleting an iTap . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36
Confi guring an iTap . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .37
Viewing iTap Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38
Modifying an iTap . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .40
iTap GigaBit Dual Port Aggregator
Appendix A Specifi cations and Models
Specifi cations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .41
Available Models . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .43
Appendix B Command Line Interface
Overview
Thank you for purchasing the latest innovation in Tap technology – the iTap GigaBit Dual Port Aggregator. Net Optics' GigaBit Dual Port Aggregator Taps provide ultra-effi cient access to critical GigaBit links using only one NIC on the monitoring device. Net Optics’ iTap is a port aggregator Tap that gives you a quick visual reference of link performance. The iTap GigaBit Port Aggregator monitors and displays link bandwidth utilization on its front panel so you can see exactly what is happening on both sides of the network link.
iTap GigaBit Dual Port Aggregator
Chapter 1
Introduction
Intelligent Tap
The iTap Port Aggregator displays the link utilization level, last peak with time right on the front panel so you can see real-time utilization on both directions of the network link. The iTap Port Aggregator is accessible from remote interfaces that provide information and control from anywhere in the network. The iTap gives you the information and the passive access point you need to respond quickly to network events.
Performance Aggregation
The iTap Port Aggregator combines and regenerates both directions of a full­duplex stream, sending all aggregated traffi c out one or two separate passive moni- toring ports. Typically, full-duplex monitoring with a network tap requires two NICs (or a dual channel NIC)–one interface for each side of the full-duplex link. Net Optics’ iTap Port Aggregator enables one or two devices to simultaneously monitor a full-duplex link using only one NIC per device.
After the traffi c has been aggregated to a single fl ow, it is no longer possible to distinguish the utilization levels of each side of the bi-directional link. The iTap Port Aggregator tracks the utilization levels before aggregation, keeping this vital information easily accessible from its remote and command line interfaces.
Buffers Absorb Bursts
When the traffi c levels exceed the capacity of the receiving NIC, the iTap Port Aggregator stores the overfl ow traffi c in buffer memory. For high-load links, the iTap Port Aggregator has 256MB of buffer memory. The buffers clear automati-
TM
1
iTap GigaBit Dual Port Aggregator
cally when the traffi c volume falls below the receiving capacity of the NIC. These buffers allow the iTap Port Aggregator to absorb traffi c bursts without dropping packets.
Traffi c Monitoring
The iTap Port Aggregator monitors the utilization levels of both sides of the full­duplex link. This information is displayed on the front panel and is available from the remote interfaces. The iTap Port Aggregator allows you to set a threshold for each side of the full-duplex link at which an alarm is triggered. For example, the iTap Port Aggregator can warn you when the utilization in either direction passes the 30% level. When a threshold level is exceeded, the alarm LED illuminates and the remote interfaces record the event. The iTap Port Aggregator records the level of the highest peak along with the date and time. Since the iTap Port Aggregator is monitoring the utilization levels, this information is always available regardless of the aggregation process.
Seeing is Believing
The display and alarm LEDs provide a quick visual check that the utilization levels are not exceeding the capacity of the monitoring device or a pre-determined threshold. From the display, you can view the current bandwidth utilization of each side of a full-duplex link with the size and time of the highest peak. A quick check of the display lets you know if there was an event that requires further investiga­tion. After taking action on a utilization or peak event, you can reset the data from a recessed reset button on the front panel or from a remote interface.
Access Information Anywhere
The Web Manager and System Manager allow you to remotely set parameters, view status information, and monitor traffi c statistical data. These interfaces provide security and performance information such as the number of over- and under-sized packets, packet collisions, and CRC errors. You can remotely set the alarm thresholds, clear the traffi c data counters, and turn on or off a Monitor Port. This access is also available via an optional wireless link from your wireless PDA or laptop.
Web Manager
Net Optics' Web Manager is the browser-based interface that allows you to change settings, view status, and retrieve data remotely with simple-to-use controls. When you access an iTap Port Aggregator with Web Manager, all confi gurations, status, and traffi c data are displayed on a single page. Changes to the confi guration can be made with a few clicks of the mouse.
2
iTap GigaBit Dual Port Aggregator
System Manager
iTap Port Aggregators can be used as a system managed via Simple Network Man­agement Protocol (SNMP) from a single interface. Net Optics' System Manager is an SNMP management tool that offers central management of all Net Optics iTap devices in the network. You can organize iTaps into groups according to workgroup, location, or any other criteria. As with Web Manager, you can view all status, confi guration, and traffi c information and make changes quickly to any iTap in the system. The iTap Port Aggregator generates SNMP alarm traps for system status, threshold alarm, link status, and power status. If you are already using an SNMP management tool, iTap Port Aggregators can be fully accessed after loading Net Optics' Management Information Base (MIB) fi le.
Security, Visibility, and Reliability
You have the option of setting the iTap Port Aggregator so that it will not display data on the LCD and you can turn off the Management Port, thus preventing it from being accessed from the network. The Monitor Ports can also be turned off to prevent unauthorized access to the network link. The monitoring device connected to the iTap Port Aggregator sees all full-duplex traffi c including Layer 1 and Layer 2 errors. Redundant power connections provide uptime protection.
Ease of Use
Display alternately shows link utilization, highest peak, and when the
• highest peak occurred
LED indicators show redundant power, link status, and utilization alarm
IEEE 802.11b wireless communication optional
Front-mounted connectors support easy installation and operation
Silk-screened application diagram illustrates all connections for easy
• deployment
All necessary network and monitor cables included
Optional 19-inch rack frames hold up to two iTaps
Tested and compatible with all major manufacturers’ monitoring devices, includ-
• ing protocol analyzers, probes, and intrusion detection/prevention systems
Support
Net Optics offers free technical support throughout the lifetime of your pur-
• chase. Our technical support team is available from 8 am to 5 pm Pacifi c Time, Monday through Friday at +1 (408) 737-7777 and via email at ts-support@ netoptics.com. FAQs are also available on Net Optics' website at www.netoptics. com.
3
Memory
All traffi c that passes through the iTap is sent to the monitoring device NIC on a fi rst-in-fi rst-out basis, including traffi c that is temporarily stored in memory. If two packets enter at the same time then one packet is processed while the other is stored briefl y in memory, preventing collisions.
When there is a burst of data, traffi c in excess of the NIC’s capacity is sent to the iTap’s memory. Memory continues to fi ll until its capacity is reached, or the burst ends, whichever comes fi rst. For controlling bursts, the iTap has 256 MB of total memory.
In both cases, the iTap applies a fi rst-in-fi rst-out procedure, processing stored data before new data from the link. If memory fi lls before the burst ends, the memory stays fi lled as the stored data is processed – data that leaves the buffer is immedi- ately replaced. If the burst ends before the memory fi lls, memory clears until the full memory capacity is available, or until another burst in excess of the NIC’s capacity requires additional memory.
The following diagrams illustrate a simple example of a 1000 Mbps NIC mov­ing from 80% utilization to 140% utilization, then back to 80% utilization. In this example, Side A begins as 300 Mbps and Side B is at 500 Mbps, The aggregated traffi c is 800 Mbps, well below the capacity of the 1000 Mbps NIC.
iTap GigaBit Dual Port Aggregator
Side A
iTap GigaBit Dual
Port Aggregator
TM
Dual Port Aggregator
www.netoptics.com
®
Network
B12A
2BA
1
RESET
GigaBit Copper
LINKACT
LINKACT
LINKACT LINKACT
Monitor
FirewallRouter
Side B
1
Side A + Side B
Each using a single NIC, the monitoring devices both receive all combined traffic from Side A and Side B, including physical
Monitoring
layer errors.
Device 1
Monitoring
Device 2
Figure 1: Side A plus Side B is less or equal to 100% of the NIC’s receive capacity
4
iTap GigaBit Dual Port Aggregator
The NIC receives 800 Mbps (80% utilization), so no memory is required for the monitoring device's NIC to process all full-duplex traffi c.
If there is burst of traffi c on Side A of 900 Mbps and Side B remains at 500 Mbps, the aggregated traffi c equals 1400 Mbps, 400 Mbps over the capacity of the NIC. The excess traffi c is put in memory on a fi rst-in-fi rst-out basis until either the buf- fer is full or the burst passes.
Side A
iTap GigaBit Dual
Port Aggregator Tap
TM
Dual Port Aggregator
www.netoptics.com
®
Network
B12A
2BA
1
RESET
GigaBit Copper
LINKACT
LINKACT
LINKACT LINKACT
Monitor
FirewallRouter
Side B
Side A + Side B
2
Memory
The extra 400 Mbps of traffic is stored in buffer memory.
Monitoring
Device 1
Memory continues to fill until capacity is reached, or the burst ends.
Monitoring
Device 2
Figure 2: Side A plus Side B becomes greater than 100% of the NIC’s receive capacity
After the burst has passed and the buffers have passed all the stored traffi c, each monitoring device resumes receiving traffi c directly from the link.
Note: ____________________________________________________________________
Utilization statistics and alarms are monitored before buffering and aggregation.
__________________________________________________________________________
5
Unpacking and Inspection
Carefully unpack the iTap GigaBit Dual Port Aggregator and check for damaged or missing parts. The iTap ships with the following:
iTap GigaBit Dual Port Aggregator (96542iTP or 96547iTP)
Two power supplies with cords
iTap GigaBit Dual Port Aggregator User Guide
iTap Software CD
Pads for surface mounting
Network and monitor cables
RS232 DB-9 cable for use with the Command Line Interface
You may have also ordered a one rack unit panel for rack mounting the iTap GigaBit Port Aggregator and an extended warranty. Carefully check the packing slip against parts received.
If any part is missing or damaged, contact Net Optics' Customer Service immedi­ately.
About this Guide
This Guide provides you all the information you need to confi gure and operate the iTap GigaBit Copper Dual Port Aggregator and the iTap GigaBit Fiber Dual Port Aggregator. Please read the entire Guide before attempting to install or operate the iTap.
iTap GigaBit Dual Port Aggregator
The Guide is organized into the following chapters:
Chapter 1 Introduction
Chapter 2 Installing the iTap
Chapter 3 Using the Front Panel Interface
Chapter 4 Using Web Manager
Chapter 5 Using System Manager
• Appendix A Specifi cations and Models
Appendix B Command Line Interface
This guide can be found in PDF format on the iTap CD.
6
Overview
This chapter describes how to install and connect the iTap GigaBit Dual Port Aggregator. The procedure for installing the iTap follows these basic steps:
After the iTap is installed, you can remotely monitor and control the iTap from Web Manager or System Manager.
iTap Physical Features
Figures 3 and 4 show the front panels of the fi ber and copper versions of the iTap GigaBit Dual Port Aggregator. Figure 5 shows the rear panel of both models.
iTap GigaBit Dual Port Aggregator
Chapter 2
Installing the iTap
Plan the installation Confi gure iTap parameters
Mount the iTap
Connect the Management Port
Connect iTap to the network
Connect iTap to the monitoring device(s)
Apply power to the iTap
Check the installation
Power
Link
LEDs
®
www.netoptics.com
2x16 Character Display
Status
LINK
A
B
A
1
B
2
Utilization
Alarms
Figure 3 : 96542iTP Front Panel Features
Reset
Button
Network
2
1
A
RESET
OUT IN OUT IN OUT OUT
Network
Ports
7
B
TM
Dual Port Aggregator
12
Monitor
GigaBit Fiber
Monitor
Ports
iTap GigaBit Dual Port Aggregator
Power Status
®
www.netoptics.com
2x16 Character Display
Reset
Button
2BA
1
Utilization
Alarms
Figure 4: 96547iTP Front Panel Features
Management
Port
Management Port
for Remote Interfaces
RS232
RS232 Port for Command Line
Interface
Figure 5: Rear panel features
iTap Port Aggregator LEDs
Link Indicators: If a good link is established, the LED illuminates a steady green.
RESET
Network
Ports
Network
A
LINKACT
B
LINKACT LINKACT
Activity
LED
Monitor
Ports
TM
12
Monitor
Dual Port Aggregator
LINKACT
Link
LED
Redundant
Power Supplies
GigaBit Copper
Activity Indicators: If there is current activity on this link, the LED ashes.
Utilization Alarms A and B: These LEDs illuminate red when the threshold
utilization level exceeds the set threshold level. The Utilization Alarm LEDs remain illuminated until reset with the Reset button or remotely reset via Web Manager or System Manager.
PWR 1/ PWR 2: Main and Redundant Power. If the iTap is deployed with both power supplies, both LEDs illuminate when the iTap is connected to power. An off power LED indicates that the corresponding power supply is not functioning or not connected.
8
Planning the Installation
Before you begin the installation of your iTap, you should determine the following information:
IP address of the iTap or, if you are deploying multiple iTaps, a range of IP addresses.
Net Mask for the iTaps.
IP address of the remote management console, if deployed over a WAN.
Gateway to the remote management console, if deployed over a WAN.
Also make sure you have a suitable location to install the iTap(s). For maximum power redundancy, use two independent power sources.
Confi guring the iTap
The iTap is confi gured with default values that allow you to install the iTap and then modify parameters from Web Manager or System Manager.
The defaults values are:
IP Address: 10.60.0.123 Netmask: 255.255.0.0 Threshold Port A: 50% Threshold Port B: 50% Port A: Gigabit Port B: Gigabit CLI username: netoptics CLI password: netoptics
You can set all parameters, check status, and view statistics from the Command Line Interface. You can change most settings later from one of the remote inter­faces (for more information on remote interfaces, see Chapters 4 and 5).
iTap GigaBit Dual Port Aggregator
Using the Command Line Interface (CLI)
All confi guration options, status, and statistics are accessible from the iTap's Command Line Interface. You must set a new username and password, IP address for the iTap, utilization threshold levels for Port A and B, and the current date and time. Other parameters are optional and dependent on your installation.
9
iTap GigaBit Dual Port Aggregator
For security reasons, some parameters can only be set with the CLI.
Use these commands to:
Set CLI username and password
Enable or disable the remote interfaces and display
Turn character echo to the terminal emulation software on or off
You will fi nd a complete list of CLI commands in Appendix B.
If you wish to disable the Management Port and remote interfaces, you can do so from the CLI using the Display command.
To access the iTap CLI:
1. Make sure power to the iTap is off.
2. Connect a PC with terminal emulation software, such as HyperTerminal, to the
iTap using the RS232 DB-9 cable supplied with the iTap.
3. Launch terminal emulation software and set the communication parameters to:
19200 baud 8 data bits No parity 1 stop bit No fl ow control
3. Connect power to the iTap. The CLI banner and login prompt appears.
Figure 6: Login and Password Prompts
4. Type netoptics and press Enter.
5. At the password prompt, type netoptics and press Enter. The NetOptics:
prompt appears.
10
iTap GigaBit Dual Port Aggregator
To change the username and password:
1. Change the username by typing the following command:
set username <username>
where <username> is your new username.
2. Change the password by typing the following command:
set password <password>
where <password> is your new password.
3. Record the username and password in a secure location.
To set the iTap IP address:
1. Type set ip <ip address> where <ip address> is the IP address you are assign-
ing to the iTap and press Enter.
For example, typing set ip 10.60.0.100 sets the iTap IP address to 10.60.0.100.
To set the utilization threshold levels:
1. Type set threshold port a <level> where <level> is the percentage of the
available bandwidth at which the utilization alarm for Port A is triggered. Press Enter.
For example, typing set threshold port a 30 sets the alarm threshold level for traffi c received on Port A to 30%.
2. Type set threshold port b <level> where <level> is the percentage of the
available bandwidth at which the utilization alarm for Port B is triggered. Press Enter.
For example, typing set threshold port b 30 sets the alarm threshold level for traffi c received on Port B to 30%.
Tip! _____________________________________________________________________
You can set the utilization threshold levels at any time from the remote interfaces. See Chapters 4 and 5 for more information.
__________________________________________________________________________
11
iTap GigaBit Dual Port Aggregator
To set the current date and time:
1. Type set time <mm/dd/yyyy-hh:mm:ss> where mm is the month, dd is the day
of the month, yyyy is the year, hh is the hour, mm is minutes of the hour, and ss is seconds. Press Enter. Time is based on the 24-hour clock.
To display current settings:
1. Type show set and press Enter. The CLI displays the current setting similar to
the example in Figure 7.
Figure 7: Show Set Command Example
To disable the display and remote interfaces:
1. Type show display to view the current setting. The default value is Display:
ON.
2. Type display and press Enter. Access to the tap from remote interfaces will be
blocked and the front panel will not display link utilization or peak information.
3. Type display and press Enter again to restore the display and remote intefaces.
12
Loading...
+ 36 hidden pages