TigerSwitchTM 10/100
24-Port 10/100 Managed Switch with
PoE, IP Clustering and 4 Gigabit Ports
TigerSwitch 10/100
Management Guide
From SMC’s Tiger line of feature-rich workgroup LAN solutions
20 Mason
Irvine, CA 92618
Phone: (949) 679-8000
Pub. # 149100032800A
March 2008
E032008-EK-R04
Information furnished by SMC Networks, Inc. (SMC) is believed to be accurate and
reliable. However, no responsibility is assumed by SMC for its use, nor for any
infringements of patents or other rights of third parties which may result from its use. No
license is granted by implication or otherwise under any patent or patent rights of SMC.
SMC reserves the right to change specifications at any time without notice.
SMC is a registered trademark; and EZ Switch, TigerStack, TigerSwitch, and TigerAccess
are trademarks of SMC Networks, Inc. Other product and company names are
trademarks or registered trademarks of their respective holders.
Limited Warranty
Limited Warranty Statement: SMC Networks, Inc. (“SMC”) warrants its products to be
free from defects in workmanship and materials, under normal use and service, for the
applicable warranty term. All SMC products carry a standard 90-day limited warranty from
the date of purchase from SMC or its Authorized Reseller. SMC may, at its own discretion,
repair or replace any product not operating as warranted with a similar or functionally
equivalent product, during the applicable warranty term. SMC will endeavor to repair or
replace any product returned under warranty within 30 days of receipt of the product.
The standard limited warranty can be upgraded to a Limited Lifetime* warranty by
registering new products within 30 days of purchase from SMC or its Authorized Reseller.
Registration can be accomplished via the enclosed product registration card or online via
the SMC Web site. Failure to register will not affect the standard limited warranty. The
Limited Lifetime warranty covers a product during the Life of that Product, which is
defined as the period of time during which the product is an “Active” SMC product. A
product is considered to be “Active” while it is listed on the current SMC price list. As new
technologies emerge, older technologies become obsolete and SMC will, at its discretion,
replace an older product in its product line with one that incorporates these newer
technologies. At that point, the obsolete product is discontinued and is no longer an
“Active” SMC product. A list of discontinued products with their respective dates of
discontinuance can be found at:
http://www.smc.com/index.cfm?action=customer_service_warranty.
All products that are replaced become the property of SMC. Replacement products may
be either new or reconditioned. Any replaced or repaired product carries either a 30-day
limited warranty or the remainder of the initial warranty, whichever is longer. SMC is not
responsible for any custom software or firmware, configuration information, or memory
data of Customer contained in, stored on, or integrated with any products returned to
SMC pursuant to any warranty. Products returned to SMC should have any
customer-installed accessory or add-on components, such as expansion modules,
removed prior to returning the product for replacement. SMC is not responsible for these
items if they are returned with the product.
Customers must contact SMC for a Return Material Authorization number prior to
returning any product to SMC. Proof of purchase may be required. Any product returned
to SMC without a valid Return Material Authorization (RMA) number clearly marked on
the outside of the package will be returned to customer at customer’s expense. For
warranty claims within North America, please call our toll-free customer support number
at (800) 762-4968. Customers are responsible for all shipping charges from their facility to
SMC. SMC is responsible for return shipping charges from SMC to customer.
WARRANTIES EXCLUSIVE: IF AN SMC PRODUCT DOES NOT OPERATE AS
WARRANTED ABOVE, CUSTOMER’S SOLE REMEDY SHALL BE REPAIR OR
REPLACEMENT OF THE PRODUCT IN QUESTION, AT SMC’S OPTION. THE
FOREGOING WARRANTIES AND REMEDIES ARE EXCLUSIVE AND ARE IN LIEU OF
ALL OTHER WARRANTIES OR CONDITIONS, EXPRESS OR IMPLIED, EITHER IN
FACT OR BY OPERATION OF LAW, STATUTORY OR OTHERWISE, INCLUDING
WARRANTIES OR CONDITIONS OF MERCHANTABILITY AND FITNESS FOR A
PARTICULAR PURPOSE. SMC NEITHER ASSUMES NOR AUTHORIZES ANY OTHER
PERSON TO ASSUME FOR IT ANY OTHER LIABILITY IN CONNECTION WITH THE
SALE, INSTALLATION, MAINTENANCE OR USE OF ITS PRODUCTS. SMC SHALL
v
NOT BE LIABLE UNDER THIS WARRANTY IF ITS TESTING AND EXAMINATION
DISCLOSE THE ALLEGED DEFECT IN THE PRODUCT DOES NOT EXIST OR WAS
CAUSED BY CUSTOMER’S OR ANY THIRD PERSON’S MISUSE, NEGLECT,
IMPROPER INSTALLATION OR TESTING, UNAUTHORIZED ATTEMPTS TO REPAIR,
OR ANY OTHER CAUSE BEYOND THE RANGE OF THE INTENDED USE, OR BY
ACCIDENT, FIRE, LIGHTNING, OR OTHER HAZARD.
LIMITATION OF LIABILITY: IN NO EVENT, WHETHER BASED IN CONTRACT OR
TORT (INCLUDING NEGLIGENCE), SHALL SMC BE LIABLE FOR INCIDENTAL,
CONSEQUENTIAL, INDIRECT, SPECIAL, OR PUNITIVE DAMAGES OF ANY KIND, OR
FOR LOSS OF REVENUE, LOSS OF BUSINESS, OR OTHER FINANCIAL LOSS
ARISING OUT OF OR IN CONNECTION WITH THE SALE, INSTALLATION,
MAINTENANCE, USE, PERFORMANCE, FAILURE, OR INTERRUPTION OF ITS
PRODUCTS, EVEN IF SMC OR ITS AUTHORIZED RESELLER HAS BEEN ADVISED
OF THE POSSIBILITY OF SUCH DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OF IMPLIED WARRANTIES OR
THE LIMITATION OF INCIDENTAL OR CONSEQUENTIAL DAMAGES FOR
CONSUMER PRODUCTS, SO THE ABOVE LIMITATIONS AND EXCLUSIONS MAY
NOT APPLY TO YOU. THIS WARRANTY GIVES YOU SPECIFIC LEGAL RIGHTS,
WHICH MAY VARY FROM STATE TO STATE. NOTHING IN THIS WARRANTY SHALL
BE TAKEN TO AFFECT YOUR STATUTORY RIGHTS.
* SMC will provide warranty service for one year following discontinuance from the active
SMC price list. Under the limited lifetime warranty, internal and external power supplies,
fans, and cables are covered by a standard one-year warranty from date of purchase.
SMC Networks, Inc.
20 Mason
Irvine, CA 92618
vi
About This Guide
Purpose
This guide gives specific information on how to operate and use the management
functions of the switch.
Audience
The guide is intended for use by network administrators who are responsible for operating
and maintaining network equipment; consequently, it assumes a basic working
knowledge of general switch functions, the Internet Protocol (IP), and Simple Network
Management Protocol (SNMP).
Conventions
The following conventions are used throughout this guide to show information:
Note: Emphasizes important information or calls your attention to related features or
instructions.
Caution: Alerts you to a potential hazard that could cause loss of data, or damage the
Warning: Alerts you to a potential hazard that could cause personal injury.
Related Publications
The following publication details the hardware features of the switch, including the
physical and performance-related characteristics, and how to install the switch:
The Installation Guide
Also, as part of the switch’s software, there is an online web-based help that describes all
management related features.
system or equipment.
Revision History
This section summarizes the changes in each revision of this guide.
March 2008 Revision
This is the fourth revision of this guide. This guide is valid for software release v1.1.0.3.
vii
viii
Contents
Chapter 1: Introduction 1-1
Key Features 1-1
Description of Software Features 1-2
System Defaults 1-6
Configuring the SSH Server 3-76
Generating the Host Key Pair 3-77
Importing User Public Keys 3-79
Configuring Port Security 3-82
Configuring 802.1X Port Authentication 3-83
Displaying 802.1X Global Settings 3-85
Configuring 802.1X Global Settings 3-86
Configuring Port Settings for 802.1X 3-86
Displaying 802.1X Statistics 3-89
Web Authentication 3-90
Configuring Web Authentication 3-91
Configuring Web Authentication for Ports 3-92
Displaying Web Authentication Port Information 3-93
Re-authenticating Web Authenticated Ports 3-94
Network Access – MAC Address Authentication 3-95
Configuring the MAC Authentication Reauthentication Time 3-96
Configuring MAC Authentication for Ports 3-97
Configuring Port Link Detection 3-98
Displaying Secure MAC Address Information 3-99
MAC Authentication 3-101
Configuring MAC authentication parameters for ports 3-101
Access Control Lists 3-102
Configuring Access Control Lists 3-102
Setting the ACL Name and Type 3-102
Configuring a Standard IP ACL 3-103
Configuring an Extended IP ACL 3-104
Configuring a MAC ACL 3-107
Binding a Port to an Access Control List 3-109
Filtering IP Addresses for Management Access 3-110
Port Configuration 3-112
Displaying Connection Status 3-112
Configuring Interface Connections 3-114
Creating Trunk Groups 3-116
Statically Configuring a Trunk 3-117
Enabling LACP on Selected Ports 3-118
Configuring LACP Parameters 3-120
Displaying LACP Port Counters 3-122
Displaying LACP Settings and Status for the Local Side 3-124
Displaying LACP Settings and Status for the Remote Side 3-126
Setting Broadcast Storm Thresholds 3-127
Configuring Port Mirroring 3-129
Configuring Rate Limits 3-130
Rate Limit Configuration 3-130
Showing Port Statistics 3-131
Power Over Ethernet Settings 3-135
iii
Contents
Switch Power Status 3-136
Setting a Switch Power Budget 3-137
Displaying Port Power Status 3-137
Configuring Port PoE Power 3-138
Address Table Settings 3-140
Setting Static Addresses 3-140
Displaying the Address Table 3-141
Changing the Aging Time 3-142
Spanning Tree Algorithm Configuration 3-143
Configuring Port and Trunk Loopback Detection 3-145
Displaying Global Settings 3-146
Configuring Global Settings 3-148
Displaying Interface Settings 3-152
Configuring Interface Settings 3-155
Configuring Multiple Spanning Trees 3-157
Displaying Interface Settings for MSTP 3-160
Configuring Interface Settings for MSTP 3-162
VLAN Configuration 3-163
IEEE 802.1Q VLANs 3-163
Enabling or Disabling GVRP (Global Setting) 3-166
Displaying Basic VLAN Information 3-167
Displaying Current VLANs 3-168
Creating VLANs 3-169
Adding Static Members to VLANs (VLAN Index) 3-170
Adding Static Members to VLANs (Port Index) 3-172
Configuring VLAN Behavior for Interfaces 3-173
Configuring IEEE 802.1Q Tunneling 3-175
Enabling QinQ Tunneling on the Switch 3-178
Adding an Interface to a QinQ Tunnel 3-180
Protocol VLAN Group Configuration 3-187
Protocol VLAN System Configuration 3-188
Link Layer Discovery Protocol 3-189
Setting LLDP Timing Attributes 3-189
Configuring LLDP Interface Attributes 3-191
Displaying LLDP Local Device Information 3-194
Displaying LLDP Remote Port Information 3-195
Displaying LLDP Remote Information Details 3-196
Displaying Device Statistics 3-197
iv
Contents
Displaying Detailed Device Statistics 3-198
Class of Service Configuration 3-199
Layer 2 Queue Settings 3-199
Setting the Default Priority for Interfaces 3-199
Mapping CoS Values to Egress Queues 3-201
Enabling CoS 3-202
Selecting the Queue Mode 3-203
Setting the Service Weight for Traffic Classes 3-203
Layer 3/4 Priority Settings 3-204
Mapping Layer 3/4 Priorities to CoS Values 3-204
Enabling IP DSCP Priority 3-205
Mapping DSCP Priority 3-206
Quality of Service 3-207
Configuring Quality of Service Parameters 3-208
Configuring a Class Map 3-208
Creating QoS Policies 3-211
Attaching a Policy Map to Ingress Queues 3-214
VoIP Traffic Configuration 3-215
Configuring VoIP Traffic 3-215
Configuring VoIP Traffic Port 3-216
Configuring Telephony OUI 3-219
Multicast Filtering 3-220
Layer 2 IGMP (Snooping and Query) 3-220
Configuring IGMP Snooping and Query Parameters 3-221
Enabling IGMP Immediate Leave 3-223
Displaying Interfaces Attached to a Multicast Router 3-225
Specifying Static Interfaces for a Multicast Router 3-226
Displaying Port Members of Multicast Services 3-227
Assigning Ports to Multicast Services 3-228
IGMP Filtering and Throttling 3-229
Enabling IGMP Filtering and Throttling 3-229
Configuring IGMP Filter Profiles 3-230
Configuring IGMP Filtering and Throttling for Interfaces 3-232
Multicast VLAN Registration 3-234
Configuring Global MVR Settings 3-235
Displaying MVR Interface Status 3-236
Displaying Port Members of Multicast Groups 3-237
Configuring MVR Interface Status 3-238
Assigning Static Multicast Groups to Interfaces 3-239
DHCP Snooping 3-240
DHCP Snooping Configuration 3-241
DHCP Snooping VLAN Configuration 3-242
DHCP Snooping Information Option Configuration 3-243
DHCP Snooping Port Configuration 3-244
DHCP Snooping Binding Information 3-245
v
Contents
IP Source Guard 3-246
IP Source Guard Port Configuration 3-246
Static IP Source Guard Binding Configuration 3-247
Dynamic IP Source Guard Binding Information 3-249
Switch Clustering 3-250
Cluster Configuration 3-250
Cluster Member Configuration 3-251
Cluster Member Information 3-252
Cluster Candidate Information 3-253
UPnP 3-254
UPnP Configuration 3-254
Chapter 4: Command Line Interface 4-1
Using the Command Line Interface 4-1
Accessing the CLI 4-1
Console Connection 4-1
Telnet Connection 4-2
Entering Commands 4-3
Keywords and Arguments 4-3
Minimum Abbreviation 4-3
Command Completion 4-3
Getting Help on Commands 4-3
Showing Commands 4-4
Partial Keyword Lookup 4-5
Negating the Effect of Commands 4-5
Using Command History 4-5
Understanding Command Modes 4-5
Exec Commands 4-6
Configuration Commands 4-7
Command Line Processing 4-8
Command Groups 4-9
Line Commands 4-10
line 4-11
login 4-11
password 4-12
timeout login response 4-13
exec-timeout 4-14
password-thresh 4-14
silent-time 4-15
databits 4-16
parity 4-16
speed 4-17
stopbits 4-17
disconnect 4-18
vi
Contents
show line 4-18
General Commands 4-19
enable 4-20
disable 4-20
configure 4-21
show history 4-21
reload 4-22
reload cancel 4-23
show reload 4-23
end 4-24
exit 4-24
quit 4-25
ip http port 4-41
ip http server 4-41
ip http secure-server 4-42
ip http secure-port 4-43
Telnet Server Commands 4-44
ip telnet port 4-44
ip telnet server 4-44
Secure Shell Commands 4-45
ip ssh server 4-47
vii
Contents
ip ssh timeout 4-48
ip ssh authentication-retries 4-48
ip ssh server-key size 4-49
delete public-key 4-49
ip ssh crypto host-key generate 4-50
ip ssh crypto zeroize 4-50
ip ssh save host-key 4-51
show ip ssh 4-51
show ssh 4-52
show public-key 4-53
Event Logging Commands 4-54
logging on 4-54
logging history 4-55
logging host 4-56
logging facility 4-56
logging trap 4-57
clear logging 4-57
show logging 4-58
show log 4-59
access-list ip 4-140
permit, deny (Standard ACL) 4-141
permit, deny (Extended ACL) 4-142
show ip access-list 4-143
ip access-group 4-144
show ip access-group 4-144
MAC ACLs 4-145
access-list mac 4-145
permit, deny (MAC ACL) 4-146
show mac access-list 4-147
mac access-group 4-148
show mac access-group 4-148
ACL Information 4-149
show access-list 4-149
show access-group 4-149
SNMP Commands 4-150
snmp-server 4-150
show snmp 4-151
snmp-server community 4-152
snmp-server contact 4-152
snmp-server location 4-153
snmp-server host 4-153
snmp-server enable traps 4-155
snmp-server engine-id 4-156
show snmp engine-id 4-157
snmp-server view 4-158
show snmp view 4-159
snmp-server group 4-159
show snmp group 4-161
snmp-server user 4-162
show snmp user 4-163
Interface Commands 4-166
interface 4-166
description 4-167
speed-duplex 4-167
negotiation 4-168
capabilities 4-169
flowcontrol 4-170
shutdown 4-171
switchport packet-rate 4-172
clear counters 4-172
show interfaces status 4-173
show interfaces counters 4-174
power mainpower maximum allocation 4-190
power inline compatible 4-191
power inline 4-192
power inline maximum allocation 4-192
power inline priority 4-193
show power inline status 4-194
show power mainpower 4-195
Address Table Commands 4-195
mac-address-table static 4-196
clear mac-address-table dynamic 4-197
show mac-address-table 4-197
mac-address-table aging-time 4-198
show mac-address-table aging-time 4-198
show queue mode 4-272
show queue bandwidth 4-272
show queue cos-map 4-272
Priority Commands (Layer 3 and 4) 4-273
map ip dscp (Global Configuration) 4-273
map ip dscp (Interface Configuration) 4-274
show map ip dscp 4-275
Quality of Service Commands 4-276
class-map 4-277
match 4-278
policy-map 4-279
class 4-279
set 4-280
police 4-281
service-policy 4-282
show class-map 4-283
show policy-map 4-283
show policy-map interface 4-284
ip igmp snooping 4-292
ip igmp snooping vlan static 4-292
ip igmp snooping version 4-293
ip igmp snooping leave-proxy 4-293
ip igmp snooping immediate-leave 4-294
show ip igmp snooping 4-295
show mac-address-table multicast 4-295
IGMP Query Commands (Layer 2) 4-296
ip igmp snooping querier 4-296
ip igmp snooping query-count 4-297
ip igmp snooping query-interval 4-297
ip igmp snooping query-max-response-time 4-298
ip igmp snooping router-port-expire-time 4-299
Static Multicast Routing Commands 4-299
ip igmp snooping vlan mrouter 4-300
show ip igmp snooping mrouter 4-300
xv
Contents
IGMP Filtering and Throttling Commands 4-301
ip igmp filter (Global Configuration) 4-302
ip igmp profile 4-302
permit, deny 4-303
range 4-303
ip igmp filter (Interface Configuration) 4-304
ip igmp max-groups 4-305
ip igmp max-groups action 4-305
show ip igmp filter 4-306
show ip igmp profile 4-307
show ip igmp throttle interface 4-307
ip address 4-314
ip default-gateway 4-315
ip dhcp restart 4-315
show ip interface 4-316
show ip redirects 4-316
ping 4-317
IP Source Guard Commands 4-318
ip source-guard 4-318
ip source-guard binding 4-320
show ip source-guard 4-321
show ip source-guard binding 4-321
DHCP Snooping Commands 4-322
ip dhcp snooping 4-322
ip dhcp snooping vlan 4-324
ip dhcp snooping trust 4-325
ip dhcp snooping verify mac-address 4-325
ip dhcp snooping information option 4-326
ip dhcp snooping information policy 4-327
ip dhcp snooping database flash 4-327
show ip dhcp snooping 4-328
show ip dhcp snooping binding 4-328
Switch Cluster Commands 4-328
cluster 4-329
cluster commander 4-329
cluster ip-pool 4-330
cluster member 4-331
rcommand 4-331
show cluster 4-332
show cluster members 4-332